Skip to the assessment
Sylvan Assurance Questionnaire Readiness Check · Free

Your answers never leave your device

This check runs entirely in your browser. Nothing you enter is sent to us or stored on any server.

A customer sent you a security questionnaire. How ready are you to answer it?

Ten plain-English questions about the things security questionnaires actually ask for. You get a score, a readiness band, and a plan — in about three minutes.

No email required · Runs in your browser · Free

1. Do you have a written security policy?

Almost every questionnaire asks for this first — a document that says how your business handles security, even if it is only a few pages.

2. Is two-step login turned on for your important accounts?

Two-step login (a code or prompt on top of the password) for email, admin accounts, and anything that reaches customer data. Reviewers usually ask whether it is required, not just available.

3. Do you have a written plan for what happens when something goes wrong?

A short incident plan: who is in charge, who you call, and what you do first. Reviewers ask to see the document, not just hear that you would cope.

4. Do you back up your important data — and have you tested getting it back?

Questionnaires increasingly ask for proof that a restore actually works, not just that backups run.

5. Do you keep track of the other companies and tools your business relies on?

A list of your key vendors and online services, and a basic check on how they handle security. Buyers ask how you manage your own suppliers.

6. Do you know what customer data you hold, and where it lives?

A simple inventory: what data you collect, where it is stored, and who can see it. Many questionnaire answers start from this one document.

7. Does everyone on your team get basic security training?

Even a short yearly session on spotting scam emails and handling data counts — as long as it actually happens and you can say when.

8. Do you hold any security certification or independent audit?

For example SOC 2 (System and Organization Controls 2) or ISO 27001 (the international information-security management standard). "Not yet" is a common answer — what matters is answering it well.

9. Have you answered a customer security questionnaire before?

Past answers are reusable. If you have been through one, you likely have wording you can adapt instead of starting from a blank page.

10. Is one named person responsible for security at your business?

Questionnaires ask who owns security. It does not need to be a full-time role — it needs to be a name, not "all of us."