Supply Chain Features / Supplier Questionnaires

Supplier Questionnaires

Send security questionnaires per supplier — answers come back through a portal with no login required. The same answers also answer the questionnaires your own customers send you.

What is Supplier Questionnaires

Questionnaires with real delivery, not just a template.

Templates define which questions apply to which audience — a shortened first assessment before signing a contract, or an annual security and resilience assessment for critical ICT providers under NIS2 Art. 21(2)(d) and DORA Art. 28. Delivery goes out as an email invitation to a contact at the supplier; resending is available at any time.

The supplier answers through a portal without their own account — no extra login, no barrier. Every answer stays tied to the supplier and the submission date, with status moving visibly from sent to submitted to reviewed.

Answers you receive from suppliers and answers you give on inbound customer questionnaires share one answer pool: questions answered once can be reused for similar future questionnaires instead of being written again.

Core capabilities

What supplier questionnaires deliver.

Templates per audience

A short assessment for new suppliers, an annual security assessment for critical ICT providers — each with its own question set.

Delivery by email invitation

Direct delivery to a contact person, resending as needed, visible status per recipient.

Answer portal with no login

Suppliers answer without their own ReportAct account — lower barrier, higher response rate.

Answer reuse

Answers from inbound customer questionnaires and outbound supplier questionnaires share one pool.

Status traceable per recipient

Sent, submitted, reviewed — with a submission date, visible at any time.

Reuse

One answer, used more than once.

Security questionnaires look alike across customers — so do the answers.

Inbound & outbound from one pool

Questionnaires your customers send you and questionnaires you send to suppliers draw on the same answer pool.

No rewriting for every request

A precisely answered question — on encryption or incident response, say — can be reused directly for the next similar request.

Still traceable

Every answer stays tied to its original questionnaire and date — reuse doesn't replace traceability.

How it works

How Supplier Questionnaires works.

Choose a template

Short assessment or full security review — matched to the audience.

Send & track

Email invitation to the supplier, track status, resend if needed.

Review & reuse answers

Review submitted answers — and reuse them from the same pool for future questionnaires.

Connected regulations

A core building block for these regimes.

DORA

Security assessment of critical ICT providers as part of the due-diligence duty under Art. 28.

Regulation details →
NIS2 / NISG

Supply chain security as one of the ten risk-management measures under Art. 21(2)(d).

Regulation details →
ISO/IEC 27001

Supplier relationships and assessment under A.5.19–A.5.22.

Regulation details →
Next step

Questionnaires without endless email threads.

We'll show you what delivery, the answer portal and reuse look like with your own suppliers.