Satmz
Security

A Customer Sent You a Security Questionnaire. Here Is What to Do

Sooner or later a customer asks you to prove your IT is secure — usually with a contract attached and a deadline. Here is where those questions come from, and the seven documents that answer almost all of them.

10 September 20268 min readSatmz Team

A customer — probably a large one, possibly a government body — has sent you a spreadsheet of security questions and attached it to a contract you want. This article is about answering it, and about not being caught out by the next one.

The short version: almost every question on that sheet is answered by a document, not by buying software. Most fifty-person companies already do the underlying work. What they cannot do, at two days’ notice, is prove it.

Where the questions come from

The Essential Cybersecurity Controls (ECC) are Saudi Arabia’s baseline for organisational cybersecurity, published by the National Cybersecurity Authority (NCA). They are a legal requirement for government entities and for organisations that own or operate critical national infrastructure — banks, telecoms, utilities, health authorities and the like.

If you are a fifty-person professional services firm, retailer, clinic group or logistics operator, the NCA is almost certainly not going to audit you. You are not one of the organisations the controls legally bind.

But the entities that *are* bound have to account for the security of their suppliers — anyone holding their data, connecting to their systems, or delivering a service into them. There is a whole domain of the ECC about exactly that. And they discharge that obligation the way obligations are always discharged: by sending you the spreadsheet.

What the sheet will ask about

The controls are grouped into a handful of domains. At that level they cover:

  • Cybersecurity governance — who is responsible, what the policies say, how risk is assessed, whether staff are trained.
  • Cybersecurity defence — asset management, identity and access, protecting systems and devices, email and network security, data protection, encryption, backup, vulnerability management and event logging.
  • Cybersecurity resilience — the security side of business continuity and disaster recovery.
  • Third-party and cloud cybersecurity — what you require of *your* suppliers, and what applies when you use cloud services.
  • Industrial control systems — only where operational technology is in play, which for an office-based business it is not.

Read that as a fifty-person company and the shape becomes clear. Very little of it is exotic security technology. Most of it is ordinary IT operations, written down — and the writing down is the part that is usually missing.

The seven things you will be asked to produce

When a company this size fails a supplier assessment, it is almost never because it lacks antivirus. It is because nobody can produce:

  1. An asset register — what devices and systems exist, who owns them, where they are. Accurate today, not last year.
  2. A joiner-mover-leaver process, with evidence that leavers actually lose access on the day they leave.
  3. Proof that patching happens on a schedule — a record, not an assurance that it gets done.
  4. A backup that has been restored from, with a date and a result. An untested backup is a belief, not a control.
  5. Logs that exist, are retained for a stated period, and could be looked at after an incident.
  6. An incident response process, written down: who is called, in what order, and who talks to the customer.
  7. A list of your own third parties — the obligation passes down from you as well.

Every one of those is a by-product of running IT properly. If your IT is run informally — one person, no documentation, changes made from memory — you may well have the security posture and none of the evidence. In an assessment those are the same thing.

The PDPL is separate, and it does apply to you

Do not conflate the two. The Personal Data Protection Law (PDPL) governs personal data in the Kingdom and, unlike the ECC, applies broadly rather than to a defined set of entities. If you hold staff records, customer details or patient information, it is relevant to you regardless of size or sector.

The two overlap in practice — access control, encryption, retention and breach handling serve both — which is why doing the work once is cheaper than doing it twice under two labels. Get advice on the PDPL specifically. It is a legal obligation rather than an IT project, even though most of the delivery lands on IT.

What to do this month

If nobody has sent you a spreadsheet yet, you are in the best possible position. Doing this work under a deadline costs several times what doing it calmly costs, and the deadline usually arrives attached to revenue you want.

Start with the asset register and the leaver process. They take the longest to reconstruct and they are the two most likely to be asked about first. Then work down the list of seven.

Where we come in

Satmz — the short name of SAT Microsystems, delivering IT across Saudi Arabia since 2003 — runs support from ISO 27001- and ISO 9001-certified, ITIL-aligned operations, which is itself one of the answers on most of these sheets.

A support contract with us produces the asset register, the patch records, the backup and restore reports, the access control and the monthly reporting, because those are how the service is run rather than something added on top. Identity and endpoint controls — multi-factor sign-in, privileged accounts, EDR, encryption — are priced openly and per component under security and identity support. Governance, risk decisions and legal obligations stay yours; the evidence should not have to be a project.

Topics

  • NCA ECC
  • Essential Cybersecurity Controls
  • supplier security questionnaire
  • NCA compliance Saudi Arabia
  • cybersecurity compliance KSA
  • vendor security assessment

Questions

Frequently asked questions

Keep reading

Related guides

Two-factor authentication prompt protecting an account login
Security6 min read

5 Common Cybersecurity Mistakes Businesses Make

Most breaches do not require sophisticated attacks — they exploit ordinary, avoidable mistakes. Here are the five we see most often, and the simple fixes.

9 Jun 2026Read more

The evidence should be a by-product, not a project

Asset registers, patch records, tested backups and monthly reporting come with the support contract. Find out what covering your estate costs.