Enterprise buyers now score suppliers on evidence they can verify from outside. Which answers move the score, and which ones quietly disqualify you.
---
The short answer
The supplier questionnaire changed, and what changed is not the questions. It is the consequence.
Under NIS2 Article 21(2)(d), your regulated customer must manage the security of their supply chain. Your answers stop being a procurement formality and become evidence in someone else's compliance file — with your company name on it.
before a vague answer slowed the deal down
now a vague answer creates a gap in their auditThey are not being difficult. They are answerable for you.
---
The three answers that carry the most weight
All three share one property: they are verifiable from outside, without trusting you.
1. A published vulnerability disclosure policy
A security@ address and a page describing how you triage and disclose.
Cost: a page and an inbox. Anyone can check it exists in ten seconds — including a buyer who has not contacted you yet, during vendor shortlisting, before you know you are being evaluated.
This is the highest ratio of credibility to effort available to any supplier.
2. A stated support period
How long you will provide security updates.
Your customer cannot declare their own support period until you declare yours. This is not a scoring item — it is a blocking item, and it is the one most often missing.
3. An SBOM you can regenerate
Not a document you produce on request. An artefact that exists for every version you shipped.
The question that actually gets asked during an incident is *which shipped versions contain the affected component*. Only an archive answers it.
---
What scores badly, and why
"We follow ISO 27001 principles." Principles are not a certificate. If you hold one, name the body and the scope. If you do not, say what you do instead — that answer scores better than an implied claim that unravels.
"Available under NDA." Sometimes legitimate. Often read as *we do not have it yet*. If the artefact exists, the disclosure policy and support period at minimum should be public.
A policy document where an artefact was requested. A policy states an intention; an artefact shows the intention was executed. A buyer counting artefacts sees the substitution immediately.
Silence on a question. An unanswered question is scored as a no, not as pending.
---
What quietly disqualifies you
No named security contact. It suggests there is no process behind the answers.
A support period shorter than the buyer's product lifetime. They cannot use you, regardless of everything else.
Refusing component disclosure entirely. Increasingly read as inability rather than confidentiality — SBOM formats support redaction and VEX statements, so a flat refusal signals you do not have the data.
An answer that contradicts your public site. Buyers check. A claim in the questionnaire that your own pages do not support is worse than a gap, because it puts every other answer in question.
---
The reframe that changes how you answer
Stop answering as though the buyer is testing you. Answer as though the buyer is building a file they will have to defend.
what they need an answer they can paste into their own assessment
with a source and a date
what they get an assertion they must take on trustThe supplier who supplies the second is creating work. The one who supplies the first is removing it — and that is what actually drives the score, far more than the strength of any individual control.
Date everything. An undated answer forces them to re-ask next quarter.
---
The speed signal nobody scores explicitly
A buyer who asks for three artefacts and receives them the same day has learned something no certification communicates.
It tells them the artefacts exist as by-products of how you work, not as documents assembled for them. That is the difference between a programme that runs and a programme that was written, and experienced buyers read it accurately.
Slow but complete is still a warning. It means the evidence had to be created.
---
What to prepare before the next questionnaire
- 1Publish the disclosure policy. Free, external, and it works while you sleep.
- 2Decide and publish the support period. You are blocking your customers until you do.
- 3Generate SBOMs in CI and archive one per shipped release.
- 4Write a standing answer pack — dated, sourced, reusable — instead of re-improvising each time.
- 5Reconcile the pack against your public site, so nothing contradicts.
---
The commercial reading
Right now this evidence is rare enough to be a reason to choose you.
Buyers under supply chain obligations need it to close their own files. A supplier who supplies it reduces their workload; a supplier who cannot becomes a documented risk in their assessment.
That window closes. In two years these artefacts will be table stakes, and their absence will simply be disqualifying rather than distinguishing.
---
Check what you can produce today — free, no account
- [Free readiness assessment](/assess) — which artefacts you can produce, and which are missing
- [Compliance responsibility mapper](/resources/responsibility-mapper) — an owner per artefact
- [Penalty calculator](/resources/penalty-calculator) — exposure on your own turnover
---
Further reading
→ Essential versus important under NIS2 → How to build an SBOM → What counts as evidence → Third-party attestations → Audit-ready evidence for the CRA
---
*This is regulatory information, not legal advice, and nothing here constitutes a compliance guarantee. Supply chain obligations under NIS2 arrive through national transposition and differ between Member States. Verify against the applicable texts and consult your competent authority or a qualified adviser.*
