Home Tools Basic VRM Form

The security questionnaire you send your suppliers, built in three minutes.

Classify the supplier, tick what they have access to and keep the questions that actually matter. Each one comes with the control it derives from in ISO 27001, NIST CSF 2.0, ENS, TISAX, GDPR, the AI Act and ISO 42001. At the end you take away a PDF with fillable fields, so the supplier can answer without printing anything.

76 questions 7 frameworks mapped Fillable PDF ≈ 3 minutes No sign-up No data sent

Build my questionnaire → Get help with this

Starting point

One questionnaire for everyone is the most expensive mistake

The bottled water supplier does not need the same questions as whoever administers your ERP with privileged access. Sending them both the same hundred-question form wastes your time, burns the relationship with the supplier and dilutes your attention on the few that genuinely matter. This tool does what has to happen before you ask anything: classify.

Mandatory
A core that always goes in, whoever the supplier is 16 questions go into every questionnaire and cannot be unticked: who owns security, an approved policy, where the data lives, encryption, MFA, how quickly access is removed, vulnerability remediation deadlines, incident notification deadlines, RTO and RPO, backups, subcontractors and certifications with their scope. If a supplier cannot answer these, you already have your information.
By applicability
The rest switches on according to what they access and what they provide Thirteen criteria: system access, cloud, personal data, special categories, transfers outside the EEA, artificial intelligence, software development, hardware and firmware, staff on your premises, subcontracting, being subject to NIS2, public sector and automotive. Tick the ones that apply and the tool assembles the questionnaire.
With the anchor in plain sight
Every question says which control it comes from ISO/IEC 27001:2022, NIST CSF 2.0, Spain's Esquema Nacional de Seguridad, TISAX (VDA ISA), GDPR, Regulation (EU) 2024/1689 on AI and ISO/IEC 42001. It serves to justify the questionnaire to an auditor, and to show the supplier you are not making it up.
And afterwards
The questionnaire is the beginning, not the end Receiving the answer is not the goal: the goal is to decide. Risks identified, control gaps, an action plan with an owner and a date, and a formal, traceable decision. It is all worked through in the article How do I assess my suppliers' cybersecurity?.

Legal notice

This tool generates an indicative questionnaire for educational purposes. It is not legal advice and does not replace a third-party risk management programme, which on top of the questionnaire needs an inventory, documented classification, contractual clauses, treatment of results, reassessment and an exit process. The mapping to each framework's controls is a working reference: the precise scope is set by each standard in its own text.

Everything runs in your browser: neither your selection nor the PDF leaves your device. There are no cookies, third-party resources or usage measurement: downloads and your interactions with the tool are not recorded. Regulatory content last reviewed: .

Step 1 of 3

What kind of supplier is this?

Two decisions. The first sets how deep the questionnaire goes; the second, which topic blocks make sense. This is phase 2 of the methodology: classify before you ask.

Criticality tier

Criteria for deciding it: access to systems, data handled, operational criticality if they disappeared tomorrow, permanent technical interconnection and how much replacing them would cost. Document the reasoning, not just the outcome: here is the inventory template in Excel with those columns already set up.

What applies to this supplier? (tick everything that fits)

Pick a criticality level to see how many questions I suggest.

Step 2 of 3

Keep the questions you are going to read

They come preselected from what you ticked. Remove the ones that are no use to you and add any you want: the ones marked mandatory stay. The rule is simple: do not send a question whose answer you are not going to analyse.

0questions chosen
— to answer, estimated — in the PDF
Step 3 of 3

Your questionnaire, ready to send

This is what you have built and what it covers. The two fields below are optional: if you fill them in, they are printed in the PDF; if you leave them blank, they stay as fillable fields for whoever receives it.

The questionnaire
0questions
Criticality
—
Applicability
—

Controls covered by framework

The number of distinct controls your selection touches in each reference framework. It is not a measure of compliance: it is the traceability of the questionnaire.

Take it away

The PDF carries fillable fields: the supplier answers in the document itself and sends it back, with no printing and no scanning. If you would rather paste it into an email, copy the text.

The PDF is generated in your browser. Nothing is sent to any server.

What comes next

The returned questionnaire is the beginning of the analysis

Most supplier assessment programmes are abandoned by the third round because nobody does this part. With the answers on the table, four things should come out.

Risks identified

Rated by likelihood and impact on your business, not on the supplier's. It is your operation that stops.

Control gaps

What should exist given their criticality tier and does not. What is missing, not what is surplus.

Action plan

With an owner and a date, agreed with the supplier. A finding with no owner does not get fixed.

Formal decision

Accept, accept with conditions, require mitigation before signing, or reject. In writing, and by someone with the authority to do it.

Get help with the analysis → Read the full methodology
The reference

The complete question bank

Every question available, with its regulatory anchor and the criticality tier from which I suggest it. You can read them here as a reference or build your questionnaire and take the PDF away.

«Mandatory» means it goes into every questionnaire, including those for low-risk suppliers. «Tier 2+» and «Tier 3+» are suggested from significant and critical suppliers respectively, and those carrying an applicability criterion only appear if that criterion is ticked in step 1.

Common questions

Frequently asked questions

Scope
How many questions should a supplier questionnaire have? For a low-risk supplier, between five and ten. For a significant one, fifteen to twenty-five. For a critical one with privileged access or sensitive data, thirty to fifty, backed by evidence. Ten well-chosen questions that get analysed are worth more than a hundred sent and filed.
Format
Can the PDF be filled in on a computer? Yes. It carries form fields, so the supplier types straight into the document in Acrobat Reader, macOS Preview, Firefox or Edge, and returns it without printing or scanning. Yes-or-no questions carry a dropdown with Yes, No, Partially and Not applicable, plus a detail field.
Standards
Where do the questions come from? From controls A.5.19 to A.5.23 of ISO/IEC 27001:2022, from the ISO/IEC 27036 series, from the GV.SC category of NIST CSF 2.0 and from the frameworks that apply to each domain: ENS, TISAX, GDPR, the AI Act and ISO 42001. Every question carries the control it comes from printed on it, in the PDF too.
Limits
Does this replace a TPRM programme? No. It solves the assessment phase, which is the one that eats the most time. The full programme also needs a third-party inventory, documented classification, contractual clauses, treatment of results, periodic reassessment and an exit process. It is all worked through in the article.
Privacy
Does the tool store anything? No. The whole selection and the PDF generation happen in your browser. There is no sign-up, no cookies and no data sent. You can check it with the developer tools open: the only things downloaded are from my own domain — a font and the library that composes the PDF — and neither carries a single piece of your data.