Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
ATL-027QUESTIONNAIREEDITORIAL REVIEW COMPLETE

Supplier Security Questionnaire

A plain-language questionnaire a small supplier can actually answer — one question per practice area, a Yes / Partial / No scale, and an evidence-requested column — with guidance on reading the answers honestly: a dated Partial beats an unsupported Yes.

Using this artifact

Purpose, inputs, and completion

Purpose. Your security now includes everyone who holds your drawings, ships you components, or dials into your machines — and most of them are small businesses who will never complete a 300-question spreadsheet honestly. This questionnaire asks one plain question per practice area, in language a two-person shop can answer truthfully, and requests evidence rather than promises. Its output is not assurance; it is information for your own vendor risk decisions.

When to use it. Send it to suppliers in order of what they can reach or break, addressed to a named person who can answer. When answers return, read them with the section-three guidance — the goal is an honest picture, not a perfect score — and carry the results into the vendor risk assessment worksheet (ATL-028) where decisions get made. Re-issue annually to critical suppliers and compare against last year's answers; the direction of change is the signal.

Required inputsHave these before you start
  • A supplier list ranked by what each supplier can reach or break — data, systems, production, deliveries
  • A named recipient at each supplier who can actually answer, not merely forward
  • Your own answers to these same questions, because suppliers will ask them back
Completion instructionsIn order
  • Send in criticality order — the machine shop holding your drawings before the office-supplies vendor.
  • Ask for evidence with every answer; a dated screenshot or policy page turns an assertion into information.
  • Read Partial answers charitably and unsupported Yes answers skeptically — a dated Partial beats an unsupported Yes.
  • Right-size for very small suppliers: a two-person shop answering honestly about MFA and backups is worth more than a boilerplate attestation package.
  • Decide before sending what you will do with weak answers, so results flow into vendor risk decisions (ATL-028) instead of a folder.
Keeping it honest

Evidence, validation, and failure modes

Evidence this producesWhat a reviewer could examine
  • Dated, answered questionnaires per supplier
  • An evidence file of supplier-provided attachments
  • Structured inputs feeding the vendor risk assessment (ATL-028)
Validation checksRun these before calling it complete
  • Pick one returned questionnaire and check every Yes for attached evidence; count how many are unsupported.
  • Confirm every critical supplier's answer set is under a year old; older answers are history, not posture.
What looks done but is not
  • The questionnaire goes to every supplier identically, burying the ten that matter under two hundred that do not.
  • Answers are filed unread, and the questionnaire becomes a ritual that produces paper instead of decisions.
  • It gets treated as a contract instrument — it is not a flowdown, it verifies nothing, and it cannot substitute for contract terms your counsel writes.
Mapped relationships

Practices and requirements this artifact relates to

Brilliant at the Basics practices

NIST SP 800-171 Rev. 2

NIST SP 800-171 Rev. 3

Relationships are mapped support, not equivalence: completing this artifact documents work relevant to these requirements and does not by itself address any of them. Retention: Retain returned questionnaires for the life of the supplier relationship plus one review cycle; the year-over-year change in a supplier's answers is the most honest trend data you will get.

Full document

Preview — exactly what prints

QUESTIONNAIRE · SUPPLY CHAIN & THIRD PARTIESv1.0 · REVIEWED 2026-08-06

Supplier Security Questionnaire

Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.

Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.

Purpose

Your security now includes everyone who holds your drawings, ships you components, or dials into your machines — and most of them are small businesses who will never complete a 300-question spreadsheet honestly. This questionnaire asks one plain question per practice area, in language a two-person shop can answer truthfully, and requests evidence rather than promises. Its output is not assurance; it is information for your own vendor risk decisions.

How to use it

Send it to suppliers in order of what they can reach or break, addressed to a named person who can answer. When answers return, read them with the section-three guidance — the goal is an honest picture, not a perfect score — and carry the results into the vendor risk assessment worksheet (ATL-028) where decisions get made. Re-issue annually to critical suppliers and compare against last year's answers; the direction of change is the signal.

Before you send it

Right-size it for very small suppliers

For a supplier of a handful of people, consider walking through the questions on a call and recording their answers rather than mailing a form. Honest, specific answers from a small shop — 'MFA on email, not yet on the ERP; last restore test in March' — are exactly what this instrument exists to collect.

Questionnaire

One question per practice area. Answer Yes, Partial, or No, and attach the requested evidence — a Partial with a date is a better answer than a Yes with nothing behind it.

Rows beginning EXAMPLE: show the expected shape — replace them with your own.

AreaQuestionAnswer (Yes / Partial / No)Evidence requested
EXAMPLE: Identity and MFADo all accounts that can reach systems used for our work require multi-factor authentication?Partial — MFA on email and VPN, not yet on the ERPMFA policy export, dated 2026-06
Identity and MFADo all accounts that can reach systems used for our work require multi-factor authentication? MFA policy or settings screenshot, dated
Asset inventoryDo you keep a current list of the computers and accounts used for our work? Inventory export date and device count (not the list itself)
PatchingAre the systems used for our work updated on a regular schedule — and what happens to systems too old to update? Patch cadence statement; end-of-life handling
Backup and restore testingAre those systems backed up, and when did you last successfully restore from a backup? Date and result of the last restore test
Remote accessHow do your staff and your vendors access your systems remotely, and is that access logged? Description of pathways; MFA and logging confirmation
Incident notificationIf you had a security incident affecting our data or our deliveries, when and how would you tell us? Named contact and committed timeframe
TrainingDo the people who handle our work receive security awareness training, including phishing? Date and audience of the last session
Supply chainDo you ask your own critical suppliers any of these questions? An example, or a statement of practice

Reading the answers

How to read what comes back

  • A dated Partial beats an unsupported Yes
    • 'Partial — MFA rollout finishes Q4' with a screenshot is a supplier telling the truth; a bare Yes across all eight rows is a supplier finishing a chore.
  • Read the evidence column first
    • Count answers with real evidence attached. That count, more than the Yes count, is the supplier's actual posture.
  • The incident-notification answer is the one you will personally need
    • A named contact and a committed timeframe are worth more to your worst week than any other row on the form.
  • No answer is an answer
    • A critical supplier who will not respond after two asks has told you something; record it in the vendor risk assessment (ATL-028).
Suppliers who touch the plant

For machine builders, maintenance contractors, and integrators, weight the remote-access and incident-notification answers heavily — their access reaches production, and a weak answer there is an uptime risk, not a paperwork gap. If an answer prompts you to change how such a vendor connects, schedule the change with the vendor and the process owner through a maintenance window rather than cutting off access mid-support-contract, and cross-check what they claim against their rows in your remote access pathway inventory (ATL-026).

Document control, version history, and approval

An artifact without an owner, a review date, and an approval trail is a snapshot, not a record. Complete this section before the document is used, and update it at every review.

FieldEntry
Document owner (named person) 
Suggested owner roleProcurement lead
Approval authorityExecutive sponsor
Review frequencyAnnual re-issue for critical suppliers; at onboarding for every new supplier
Next scheduled review 
Storage location of the completed document 
RetentionRetain returned questionnaires for the life of the supplier relationship plus one review cycle; the year-over-year change in a supplier's answers is the most honest trend data you will get.

Version history

VersionDateAuthorSummary of changeApproved by
     
     
     
     

Review and approval

Reviewed byRoleDateSignature / initials
    
    
Complete this offline — and mind what you write down

Fill this in inside your own environment, not on any public website or unapproved cloud tool. A completed copy may reveal your security posture: never include CUI, export-controlled data, credentials or keys, unremediated vulnerability details, network diagrams, or customer-sensitive information beyond what the artifact strictly needs, and store the completed document with the same care as the systems it describes.

Supplier Security Questionnaire · version 1.0 · reviewed 2026-08-06 · file name batb-supplier-security-questionnaire

Generated from the live artifact library at brilliantatthebasics.us/templates/supplier-security-questionnaire. Independent educational material published by inDirectIT, Inc. Tailor every section to your technical, operational, contractual, regulatory, and safety requirements.