Compliance & Regulations

Are Vendor Questionnaires Enough for Regulatory Compliance?

Vendor questionnaires support due diligence, but NIS2 and DORA require ongoing supplier oversight and evidence.

ThingsRecon company logo with stylized wing icon on a dark blue background.

Sabrina Pagnotta

Cybersecurity Writer

August 27, 2026

August 27, 2026

Vendor questionnaires are useful compliance evidence, especially for contractual attestation, control design and accountability, but they are point-in-time and self-reported. NIS2 and DORA require organisations to maintain ongoing risk management and supplier oversight, so questionnaires need to sit alongside continuous evidence, monitoring and documented follow-up.

A questionnaire can document what a supplier says about its controls. Regulatory compliance also requires evidence that supplier risk is understood, monitored, and acted on over time.

That distinction matters for NIS2 and DORA. A completed form may support due diligence at onboarding, yet it cannot show what changed three months later, whether the supplier relationship evolved, or whether an external exposure appeared after the assessment.

A defensible programme uses questionnaires for the evidence they are good at collecting, then keeps the risk picture current with monitoring, validation, and documented decisions.

What vendor questionnaires are good for

Vendor questionnaires are useful for collecting supplier-declared evidence about policies, control design, certifications, responsibilities, and contractual commitments. They create a structured record of what the supplier has attested to and give risk teams a consistent basis for due diligence and follow-up.

Questionnaires earned their place in third-party risk management because many important controls cannot be observed from outside a supplier environment. A supplier can describe how privileged access is managed, which standards it follows, how incidents are escalated, where data is processed, and who owns specific responsibilities.

That evidence supports several practical parts of the supplier lifecycle:

  • Contractual attestation. The supplier formally states how particular controls, processes, and obligations are handled.
  • Control design. Security and risk teams can understand policies and safeguards that are invisible to external assessment.
  • Accountability. Responses create a documented basis for clarifications, remediation commitments, and contractual requirements.
  • Standardised due diligence. Frameworks such as SIG can make assessment more consistent across a large vendor population.

This fits naturally into a broader third-party risk management lifecycle where due diligence, contracting, monitoring and offboarding each produce different forms of evidence.

Where questionnaires fail as compliance evidence

Questionnaires become weak compliance evidence when they are treated as a complete record of supplier risk. They capture a supplier response at a specific moment, rely heavily on self-reporting, can be difficult to verify, and often age faster than formal reassessment cycles can keep up with.

The issue is less about the questionnaire itself and more about what happens after it is completed. A 200-question assessment can be thorough on the day it is submitted and still provide little evidence about the supplier six months later.

The main reasons why they fall short when treated as the only source:

1. They are point-in-time

A questionnaire records what was true, or what the supplier believed was true, when the answers were submitted. Cloud infrastructure, software, ownership, subcontractors, and exposed services can change between review cycles.

2. They are self-reported

The supplier controls the answer. Most programmes still need a way to validate material claims, especially where an answer affects supplier tiering, remediation or acceptance of residual risk.

3. Verification is uneven

Some answers can be supported with certifications, policies, test reports, or technical evidence. Others remain difficult to verify because the relevant controls are internal or because the organisation lacks independent telemetry.

4. Response friction limits coverage

Long assessments consume time on both sides. High-friction processes encourage lighter reviews for lower-tier suppliers and can delay reassessment when the vendor population is large.

The compliance gap appears when the organisation can show that a questionnaire was sent, yet cannot show how supplier risk was monitored after the response arrived.

What NIS2 and DORA expect that a questionnaire cannot produce

NIS2 and DORA place supplier risk inside an ongoing risk management process. A questionnaire can contribute evidence, but the wider programme needs current inventories, risk-based oversight, documented decisions, monitoring of relevant changes, and evidence that issues were followed through over time.

NIS2 makes supply chain security part of the cybersecurity risk management measures expected from essential and important entities. The practical evidence goes beyond a completed assessment: teams need to know which suppliers matter, how risks are handled, and how the programme stays current as dependencies and exposures change.

ThingsRecon's evidence-based NIS2 guidance frames this around identifiable suppliers and assets, continuous oversight, documented risk decisions and evidence that can be traced back to the underlying finding.

DORA is even more explicit for financial entities because ICT third-party risk sits inside the wider digital operational resilience framework. Organisations need visibility across ICT services and dependencies, ongoing oversight, contractual governance and records that support the management of third-party risk throughout the relationship lifecycle.

A questionnaire alone struggles to demonstrate several things a reviewer may reasonably ask for:

  • what changed in a supplier's external exposure after onboarding
  • which suppliers support critical or important services
  • how material findings were validated and remediated
  • whether monitoring occurred between scheduled reviews
  • which dependencies or subcontractors became relevant during the period
  • what evidence supports the organisation's current risk decision

The same issue appears when selecting a third-party risk tool for DORA and NIS2. The useful test is whether the platform helps maintain evidence between assessments, rather than producing a polished snapshot that immediately begins to age.

How continuous monitoring complements questionnaires

Continuous monitoring fills the time gap between questionnaires. It can surface changes in external assets, cyber hygiene, supplier relationships and business context, giving teams new evidence to validate, investigate, or use as a trigger for reassessment.

Questionnaires and continuous monitoring observe different parts of the supplier relationship. The questionnaire can capture internal policies and supplier attestations. External monitoring can keep watching observable conditions without waiting for the supplier to complete another review.

A useful monitoring programme can detect changes such as new internet-facing assets, certificate or DNS changes, exposed services, software changes, deterioration in cyber hygiene, relevant business events, and newly observable supplier connections.

The value comes from connecting those changes to an action. A new finding may trigger validation, supplier outreach, a remediation ticket, a risk-tier change or a formal reassessment. That gives the organisation a dated evidence trail showing how oversight continued after onboarding.

For supply chain risk, continuous supplier intelligence can also expose relationships that were missing from the original questionnaire or vendor inventory. That matters because a programme cannot assess a dependency it has never identified.

Can a TPRM programme run without questionnaires?

Some third party risk programmes can reduce questionnaire use substantially, especially for low-risk or externally observable controls. Higher-risk relationships still benefit from direct supplier evidence where internal controls, data handling, resilience arrangements or contractual responsibilities cannot be established externally.

The right amount of questionnaire activity depends on the supplier, the service and the evidence already available. A low-impact provider with no sensitive access may justify a lightweight assessment supported by external monitoring. A supplier supporting a critical service, processing regulated data or operating privileged integrations will usually require deeper due diligence.

External evidence can answer many questions efficiently. It can show what infrastructure is exposed, which technologies are visible, whether configurations changed and which digital relationships can be observed. It cannot confirm every internal policy, private control, or contractual obligation.

That creates a practical division of labour: use supplier engagement where the answer exists inside the supplier, and use independent evidence where the condition can be observed continuously from outside.

A defensible hybrid model

A defensible supplier assurance model combines risk-based questionnaires with independent evidence, continuous monitoring and documented follow-up. The aim is to preserve supplier accountability while maintaining a current view of the risks that can change between formal assessments.

For most organisations, the strongest model is layered rather than questionnaire-heavy:

  1. Discover and scope the supplier population, including relevant relationships that may be missing from procurement records.
  2. Tier suppliers by criticality, access, regulatory relevance and dependency so due diligence effort matches potential impact.
  3. Collect supplier evidence for controls, responsibilities and facts that cannot be established independently.
  4. Validate material claims where supporting documentation or external evidence is available.
  5. Monitor meaningful changes between formal assessments and define the triggers that require action.
  6. Record findings, ownership, remediation, exceptions and risk decisions so the oversight trail can be reconstructed later.

This model gives questionnaires a clear role without asking them to carry the whole compliance burden.

Questionnaire evidence vs continuous evidence: comparison table

Questionnaire alone

Questionnaire + external monitoring

Verdict for an auditor

Supplier control attestationStrong for declared policies and controlsStrong, with added evidence where claims can be validated externallyUseful evidence when scope, date and ownership are clear
Current external postureWeak after the submission dateStronger because observable changes can be tracked between reviewsShows oversight continued beyond onboarding
Change historyLimited to periodic reassessmentProvides dated evidence of relevant changes and follow-upSupports a reconstructable oversight trail
Supplier and dependency coverageDepends on the known vendor population and supplier disclosureCan reveal observable suppliers, assets and indirect relationships outside the original inventoryStronger when discovered relationships are validated and governed
Remediation evidenceCan record commitmentsCan connect changes and findings to investigation, tickets and reassessment triggersMost defensible when ownership and closure are documented
Overall assurancePoint-in-time supplier declarationLayered assurance using supplier evidence plus independent observationMore resilient evidence for ongoing supplier oversight

The auditor test: what could you prove about last quarter?

A useful compliance test is simple: if an auditor or regulator asked how a critical supplier was overseen last quarter, could you show more than its last questionnaire? A defensible answer includes the assessment, the evidence reviewed since then, changes detected, decisions made, remediation activity and the current risk position.

A questionnaire can be an important part of that file. The stronger record also shows what happened between the questionnaire date and today.

For a critical supplier, you should be able to reconstruct the period: when it was assessed, which evidence was accepted, what monitoring took place, which material changes were detected, who reviewed them, what action followed and why the current level of risk is considered acceptable.

That is the standard worth designing towards in both NIS2 supplier-risk programmes and DORA third-party ICT risk programmes. The objective is a current, evidence-backed record of supplier oversight that can survive scrutiny after the fact.

Frequently Asked Questions

Are security questionnaires required by NIS2?

NIS2 does not prescribe a specific security questionnaire. It requires essential and important entities to implement appropriate and proportionate cybersecurity risk-management measures, including supply chain security. A questionnaire can support supplier due diligence, while the wider programme still needs risk-based oversight, evidence, monitoring and documented action appropriate to the organisation and its suppliers.

Is a SIG questionnaire enough for regulatory compliance?

A SIG questionnaire can provide structured supplier assurance and help collect detailed information about controls, governance and security practices. It does not by itself demonstrate continuous oversight. Regulatory programmes still need to connect the answers to supplier criticality, supporting evidence, monitoring, remediation and current risk decisions.

What evidence do auditors accept for supplier oversight?

Useful supplier-oversight evidence is traceable, dated, and connected to a documented control or risk decision. Depending on the programme, this can include questionnaires, contracts, certifications, review records, technical findings, monitoring history, remediation tickets, exceptions, approvals and evidence of reassessment. The strongest record shows what was reviewed, who owned the decision and what happened when the supplier risk changed.

Can you verify a questionnaire answer externally?

Some questionnaire answers can be checked against external evidence. Examples include internet-facing assets, certificates, DNS configuration, exposed services, software fingerprints, security headers and observable supplier relationships. Internal controls such as access governance, network segmentation and recovery procedures usually require supplier evidence or internal validation. External monitoring is therefore most useful as an independent layer of assurance around claims that can be observed from outside.

How often should suppliers be reassessed?

Supplier reassessment frequency should be based on criticality, access, regulatory obligations, recent changes and risk appetite rather than one universal annual schedule. Critical or deeply integrated suppliers may require continuous monitoring plus formal review at least annually, while low-impact suppliers may justify a lighter cadence. Trigger events such as a breach, acquisition, service change or new integration should prompt reassessment. ThingsRecon provides ongoing external evidence between reviews and helps prioritise suppliers by Digital Proximity. In practice, teams should record the supporting evidence, confirm ownership and business criticality, and connect the finding to an accountable workflow. This prevents a useful observation from becoming another isolated score or dashboard alert.

Share on Linkedin
Follow us on LinkedIn to get the latest insights.
ThingsRecon logo
get a personalized demo
What’s connected to you right now?
ThingsRecon logo
Thank you! You are now susbribed to The Recon Log
Oops! Something went wrong while submitting the form.
ALL THINGS
CYBER
A ThingsRecon podcast
from the edges of
the internet.
Share on LinkedinShare on XShare on Facebook