The message arrives on a Tuesday, from your biggest client’s procurement department. Attached, a spreadsheet of eighty questions about your information security, to be returned within fifteen days. Next year’s contract depends on it.

The first reaction is almost always the same: a mix of irritation and concern, because half the questions seem to address a company ten times larger. That reaction is understandable, and it is also the wrong one. Handled well, this exercise works in your favour.

Why are you receiving this document now?

These questionnaires do not stem from excess bureaucracy. Three trends are converging, and they are lasting.

European regulation is passed on by contract. The NIS2 directive requires the European organisations it covers to manage risks linked to their supply chain, and to include security requirements in their supplier contracts. It does not apply to your Swiss SME, but your client must demonstrate that they have assessed you. The questionnaire is their proof. This mechanism is detailed in our article on NIS2 and Swiss SMEs.

Insurers have tightened their conditions. A company that takes out cyber insurance must describe its own setup, and increasingly that of its critical providers too. Your answers sometimes feed directly into your client’s insurance file.

Buyers have been burned. Supply chain attacks have become a common method of attack, and major clients have experienced this first hand. They no longer ask whether you are serious, they ask you to document it. The full reasoning is set out in our article on supply chain attacks.

The themes that recur in almost every one of these documents

Formats vary, from a homemade twenty-line file to a standardised framework of several hundred questions. The themes, however, repeat from one document to the next.

ThemeWhat is actually being asked
GovernanceWho is responsible for security at your company, are there written rules
Access and identityTwo-factor authentication, offboarding management, privileged accounts
Endpoint protectionAntivirus, updates, encryption of laptops
BackupsFrequency, offline copy, restoration testing
IncidentsIs there a procedure, within what timeframe do you notify your client
SubcontractorsWho has access to data, under what contracts
Personal dataWhat client data you hold, where it is hosted
ContinuityHow long to resume operations after a shutdown

One point often reassures business owners once it is pointed out to them: these themes cover almost exactly the measures described in our article on the 10 essential measures. The questionnaire is not asking you to be a bank. It checks the fundamentals.

Should you tick yes everywhere so as not to lose the contract?

That is the immediate temptation, and it is the costliest mistake.

Your answers do not stay in a drawer. They are generally appended to the contract, or referenced by it, and become statements your client will rely on. The day an incident occurs, the first thing their legal department will do is reread what you had claimed.

An inaccurate yes is far worse than a no

Declaring an offsite backup tested every year when it does not exist does not win you a contract: it turns a future technical incident into a demonstrable contractual failure, with the loss of trust and financial consequences that follow. An honest no rarely closes a door. A false yes slams it shut at the worst possible moment.

There is an even more practical reason. These questionnaires are read by people who process dozens of them. A twelve-employee SME that answers favourably to one hundred percent of the questions, including on permanent monitoring and quarterly penetration testing, does not look exemplary. It looks unreliable.

How do you answer honestly without disqualifying yourself?

The right response to a gap is not a flat no. It is a three-part answer that assessors recognise immediately and that reassures them.

The formula: "current state, compensation, deadline"

Instead of "no", write: "Not yet in place in this form. Our remote access is currently limited to three named individuals, and two-factor authentication is active on it. Full deployment is planned with our provider for the first quarter." You demonstrate three things in three lines: you understood the question, you know your actual situation, and you have a plan. That is exactly what the assessor is looking for.

A few principles round out this formula. Answer the question asked, not the one you would have preferred. If a question does not apply to your business, say so and explain why, rather than leaving a box blank. Have your IT provider review the technical elements, but keep control over the organisational, contractual, and data questions: they commit management.

A typical scenario: two answers, two outcomes

Two suppliers from French-speaking Switzerland receive the same questionnaire from a German industrial group. The first ticks yes on all seventy-two questions in an hour. The second answers yes to forty-five, no to eighteen with a deadline for each, and not applicable to nine, with a justification. The second one gets the contract, because their file is the only credible one and it exposes the buyer to no legal risk. The first one receives a request for supporting evidence they cannot answer.

What you should never do

Four mistakes come up again and again, and they are easy to fix once named.

Lying or embellishing. The point has already been made, and it bears repeating: it is the only genuinely serious risk in this whole exercise.

Sending the document back without reading it. Some questionnaires contain commitments slipped into the questions, notably incident notification deadlines of twenty-four or forty-eight hours, or a right to audit your premises. You accept them by ticking the box.

Delegating entirely to a third party. Handing the entire response to your IT technician or a consultant, without review, makes you sign statements you can neither explain nor uphold at the follow-up meeting.

Treating each questionnaire as an isolated event. This is the most common and most exhausting mistake: starting from scratch each time a request comes in, digging up the same information from the same emails as last year.

How can you turn this into a commercial advantage?

Flip the perspective. Your client has just given you, for free, the exact list of what they consider important, and what your competitors will also have to demonstrate.

Two uses follow from this. First, the questionnaire becomes your roadmap: the questions you answer no to, ranked by effort and importance, form a far more relevant action plan than any generic list found online. Second, the ability to respond quickly and cleanly becomes an argument in itself. In a tender where two suppliers are evenly matched, the one who submits a clear security file within forty-eight hours stands out immediately from the one who asks for a deadline extension.

Some SMEs in French-speaking Switzerland have made this part of their sales pitch, proactively attaching a two-page note on their security setup to offers aimed at major accounts.

The file to prepare once and for all

The goal is to build a reusable file, which you update twice a year rather than rebuilding for every request. Seven elements are enough.

  1. An identity card for your information system. Your main tools, your hosting providers, where your data is and in which country.
  2. The list of your critical providers, with what each one has access to.
  3. The name of the person responsible for security at your company, even if it is the director themselves. A box with no name always raises concern.
  4. Your IT charter and proof that it has been brought to staff’s attention.
  5. Your backup setup and the date of the last restoration test, described in the 3-2-1 rule.
  6. Your incident procedure, including the timeframe within which you commit to notifying an affected client. One page is enough, as explained in our article on the incident response plan.
  7. Your handling of personal data: what client data you hold, on what basis, and where it is hosted, consistent with your obligations under the FADP.

Building this file takes a few days the first time. It then serves for all your clients, for your insurer, and on the day an incident occurs.

One limitation still needs to be stated clearly. Honestly filling in a questionnaire tells you what you declare, not what actually protects your company. The two questions are different. A declared backup can fail silently, a forgotten provider access can remain open for years, and no form detects that. Verifying that your answers match reality requires a check by someone who knows where to look, and that verification is as valuable to you as it is to your client.

For an initial assessment of your situation before you start, the cyber check-up covers most of the themes you will find in these documents. The other requirements that can reach a Swiss SME are grouped in the Regulations pillar.