Advisory · Supplier requirements · Hungary
Has a customer sent you a security questionnaire?
We help you read what is being asked, gather the evidence you already have, and plan how to close what is missing.
Three situations, one deadline
All three come to the same thing: answering somebody else’s requirements credibly, on their schedule.
The questionnaire arrived
Fifty to two hundred questions. You can answer half of them and do not know what the other half mean. The deadline was set by the customer.
Security clauses in a contract
The new framework agreement carries security annexes, and somebody has to decide what you can commit to and what you cannot.
They are asking for proof
A certificate, a test result, a policy or an audit report — something you either have or do not, and the difference is worth knowing in advance.
Four things, each of them named
Not help filling in a form. Material that answers the next questionnaire too.
Requirement-to-evidence mapping
Line by line: what is asked, what it is meant to prove, what you already hold, and what is missing.
Substantiated answers
For the questions you can answer, an answer with a document behind it — not "yes", but "yes, and this shows it".
A gap list
What you cannot evidence today, itemised. That is not a failure; it is the list of next steps.
An agreed action plan
Closing the gaps, with owners and dates, in the order your customer’s requirement justifies.
What a requirement-to-evidence mapping looks like
An illustration, not client data. The fourth column is the point: a "yes" with no document behind it becomes a question again next round.
| The customer's question | What it proves | What you hold | Status |
|---|---|---|---|
| Do you have a documented incident response procedure? | That an incident does not depend on improvisation | Procedure, with its last review date | Answerable |
| Do you test restoring from backups? | That backups run and are usable | Backup policy — no restore test | Missing |
| Multi-factor authentication on remote access? | That a stolen password is not enough on its own | MFA configuration export from the identity system | Answerable |
| Do you hold a valid ISO/IEC 27001 certificate? | That an outside party reviewed the system | No — and we say so plainly | Missing |
The rows above are invented examples based on a typical supplier questionnaire. They are not a client’s data and not anonymised real answers.
Four steps, from questionnaire to agreed plan
First you have to understand what is actually being asked. Most of the time goes not on answering but on establishing what counts as acceptable evidence.
- 01
Reading the requirement
We go through the questionnaire or the contract annex and establish what is asked, what it is meant to prove, and which questions are the same thing worded differently.
- 02
What you already have
We collect the existing policies, configurations and records. Organisations can usually evidence more than they first think.
- 03
Separating answers from gaps
Where there is evidence, a substantiated answer. Where there is not, it goes on the gap list — not into a carefully worded "yes".
- 04
A plan for the gaps
Closing them in order, with owners and dates, matched to what your customer expects and by when.
Two things, in advance
We do not manufacture evidence
What does not exist does not get a document written for it after the fact. We name the gap and plan how to close it — those are different things, and they will be different at an audit too.
We cannot promise they accept it
Your customer decides what they accept. What we can achieve is that your answers are evidenced and consistent; whether that is enough is their standard.
A questionnaire does not mean NIS2 applies to you
When a regulated customer sends a questionnaire, that is about THEIR obligation: they have to assess their suppliers. It does not by itself make you directly in scope. These are two separate questions, and a different tool answers each.
Where does your security stand today?
A free five-minute self-assessment, twelve questions across eight areas. A general picture of your security — not a legal classification.
Five-minute quick checkAre you in scope under NISG 2026?
For organisations established in Austria: it follows the statute’s own order and tells you whether you are an essential entity, an important one, or neither.
NISG 2026 scope checkWhat happens if you get in touch
A 20-minute conversation
We go through what your customer is asking and by when, and end by saying whether we can help and in what scope. If the questionnaire is small and you can answer it yourselves, we say that too.
This service is for suppliers established in Hungary. Your own customer can sit anywhere, and usually does — a German, Austrian or Nordic buyer is the ordinary case. A supplier established in another country answers against a different legal background.
Frequently asked questions
The questions we hear most often from security and IT leaders.
Something not covered here? Ask us directly
It does not, and you are the reader this page was built for. That note says which market the service is built for and under whose law we contract; it says nothing about where your customer sits, and a Hungarian supplier answering a German, Austrian or Nordic customer is the ordinary shape of this work. Spirity is three registered companies — the head office in Budapest, Spirity GmbH in Vienna and Spirity Enterprise Middle East FZCO in Dubai — so a cross-border question is not an unusual one here. What your customer asks comes out of their obligations and your contract with them, and that contract is the document we read. We work in Hungarian, English and German and produce the materials in whichever of the three you need, so a German questionnaire is answered in German rather than translated by you at the most dangerous end of it.
The conversation costs nothing and commits you to nothing. The first thing that carries a fee is a piece of work with a written scope and a written price, quoted before it begins — not an open meter running until somebody declares the questionnaire finished, which is the shape you were right to be wary of. We do not publish a figure here, and we would rather admit that than print a range we would have to defend against a document we have not seen. Ask on the call and the number arrives in writing and holds for thirty days.
You sign it. It is a statement about your company and nobody outside it can make that statement for you. What arrives from us is the answer text for each question with the document that backs it named against it, the itemised list of what you cannot evidence yet, and the plan for closing it — so “not help filling in a form” means you get considerably more than a filled form, not that you are left to draft the wording at eleven at night. How the text is handed over is settled in the scope rather than assumed, because a spreadsheet you control and a portal that only admits your own login are two different jobs.
Four things on your side, and they are the whole difference between a tight window and a missed one: the questionnaire or contract annex itself, one named person who can answer for IT, access to your outsourced provider, and the policies, configuration exports and records that already exist gathered in one place rather than hunted down one at a time. On our side it is a capacity question and you get a straight answer to it in the first conversation rather than after a proposal — if we cannot hold your date we say so, and if it is a questionnaire you could finish yourselves we say that too. Book the 20-minute meeting directly on our booking page and bring the return date with you — it is online, and it is the quickest way to find out.
We sign a non-disclosure agreement before receiving any document from you, or the confidentiality terms are written into the engagement agreement itself — either way it is in place before anything moves rather than after. Nothing needs to be sent for the first conversation at all, and the enquiry form is not the route for a customer questionnaire or a gap list; we agree how material reaches us once there is something to look at. Our own ISO/IEC 27001 certificate, issued through a UKAS-accredited body for how we operate, covers the handling of information while it is with us, and the scope statement behind it is the document to ask for rather than the logo. What happens to the material when the work ends, and who inside our team can open it, belong in that agreement.
Yes, with one qualification worth hearing first. The scope can be the questions you cannot answer, but the reading step passes over the whole document anyway, because duplicate questions worded differently and two answers that contradict each other three pages apart are only visible across the full set. The sixty you are confident about are also where the expensive mistake lives — an unevidenced yes is the answer that comes back as a question next round, and it comes back to you rather than to us. Decide the split on the call with the document in front of both of us.
We cannot tell you that, and we will not quote you a success rate we do not have. What we can describe is the difference a security reviewer on the other side reacts to: a bare no reads as an unmanaged risk, while a no with the gap named, an owner against it and a date reads as a supplier who runs a programme and knows where it is. Their standard is theirs and they can still refuse. In our judgement the two answers that cost tenders fastest are the blank and the confident yes that collapses when somebody asks for the document behind it.
Agreed with you, and nothing goes to your customer from us. Every deliverable here is addressed to you, you decide what is sent, and we are not in contact with your customer unless you put us in the room — which some suppliers want for a technical call and others firmly do not. The ordering follows what your customer’s requirement justifies because that is the deadline you are answering, but which gaps you spend money on, and when, is your decision alone. On cost: the plan names an owner for every gap so that you can price it, and closing a gap is separate work from identifying it — we will not fold the remediation into the same invoice without saying so first.
Most of what is needed already exists somewhere, so their hours go on retrieval and on the questions only your own people can answer — how something is actually run, rather than how the policy says it is run. We can work with your outsourced provider directly once you authorise it, which is usually faster than routing every request through you; the alternative, which some clients prefer, is that we ask and you forward. Either way the chasing gets an owner in the plan, so the configuration export in the example above is somebody’s named task rather than a thing each party assumes the other is doing. Where nobody is named, it defaults to you, and that is worth knowing before the last week.
Ready to get started?
Partner with Spirity Enterprise to implement the right security and IT solutions for your organization.