Insights · Marketing agencies

Our client sent us a security questionnaire. What are they actually asking for?

A client's security questionnaire asks one thing: can your agency be trusted with access to its accounts and data? Most questions cover six topics: who has access, multi-factor authentication, data handling, devices, incident response and your own subcontractors. Answer each with a short description plus evidence, and mark partial controls honestly rather than claiming them.

Why did our client send us a security questionnaire?

A client sends a security questionnaire because its own security program now expects it to assess suppliers before and during the relationship. The NIST Cybersecurity Framework 2.0, published on 26 February 2024, added a supply chain category to its new Govern function. Subcategory GV.SC-06 says planning and due diligence are performed before entering formal supplier relationships, and GV.SC-07 says supplier risks are assessed and monitored over the course of the relationship (NIST CSWP 29, consulted 1 October 2026). A marketing agency with logins to the client's ad accounts, website and customer lists is exactly the kind of supplier those lines describe, so the questionnaire is usually a routine step in the client's process rather than a sign of distrust.

The breach data explains why clients take the step seriously. Verizon's 2026 Data Breach Investigations Report found that third parties were involved in 48% of breaches, and that breaches involving an organization's supply chain rose by 60% in a year (via Help Net Security, 25 May 2026). Agencies have been part of that pattern. Dentsu confirmed in October 2025 that attackers took data from its subsidiary Merkle, including employee payroll and bank details and, in some cases, client and supplier information (BleepingComputer and The Register, 29 October 2025). A client reading those reports will want to know how its agency handles the same risk.

What topics does a security questionnaire actually cover?

Most security questionnaires are built from a common set of control areas, even when the client writes its own version in a spreadsheet. The Standardized Information Gathering questionnaire from Shared Assessments, one of the most widely used templates, lists 21 risk domains, from access control and endpoint security to privacy management and supply chain risk management (Shared Assessments, consulted 1 October 2026). An agency does not need to master all 21. For a marketing agency, the questions cluster into six practical topics, and each one is really a request for a short description plus a piece of evidence:

  • Access control. Who on your team can reach the client's accounts and data, how that access is granted, and how it is removed.
  • Authentication. Whether multi-factor authentication is required, not just available, on email and on every client platform.
  • Data handling. Where client files and customer lists are stored, who can download them, and how long you keep them.
  • Devices. Whether laptops are encrypted, updated and protected, including those used by freelancers.
  • Incident response. What you do if something goes wrong, and how quickly you tell the client.
  • Your own suppliers. Which tools and subcontractors touch the client's data, including freelancers and offshore teams.

Which questions matter most for a marketing agency?

Three topics carry the most weight for a marketing agency, because they map to how agencies are actually attacked. Account access comes first: clients want to see that access to their ad accounts runs through named users or partner links rather than shared passwords, and that someone removes it when a person leaves the project. Multi-factor authentication comes second, and the question is usually whether it is enforced for everyone, since an option that individual users can skip protects nothing on the accounts where they skipped it. Freelancers and subcontractors come third. A client that asks about "fourth parties" or "subcontractors" wants to know whether people outside your payroll can reach its data, and how you control them.

Incident notification is the question agencies most often answer too loosely. A reply such as "we would inform you promptly" says nothing a client can rely on. A stronger answer names who on your side decides that an incident has occurred, who contacts the client, and the time window you commit to. NIST CSF 2.0 subcategory GV.SC-08 says relevant suppliers are included in incident planning, response and recovery activities (NIST CSWP 29, consulted 1 October 2026), so a client following that framework expects its agency to have a plan the client fits into.

Can a small agency answer without a SOC 2 report?

A small agency can answer a security questionnaire honestly without a SOC 2 report. SOC 2 is an attestation examination performed by a CPA firm on a service organization's controls, and the AICPA describes it as reporting on five trust services categories: security, availability, processing integrity, confidentiality and privacy (AICPA and CIMA, consulted 1 October 2026). Many questionnaires ask for a SOC 2 report first, but the answer "we do not have one" is acceptable when it is followed by the evidence you do have. That evidence is usually a written access policy, a screenshot of enforced multi-factor authentication, an offboarding checklist with dates, and an incident contact plan.

The answer that causes damage is the one that claims more than exists. Never describe a control as in place because it is planned, and never imply a certification you do not hold. Under NIST CSF 2.0 subcategory GV.SC-05, clients integrate supplier security requirements into contracts and other agreements (NIST CSWP 29, consulted 1 October 2026), so a questionnaire answer can become a contract term. Where a control is partial, say "partially in place", describe what exists, and give the date by which the rest will be done. Clients that review many suppliers read a clear partial answer as a sign of maturity, while a perfect score from a small agency invites closer scrutiny.

What should an agency prepare before the next questionnaire arrives?

The best preparation is a short evidence pack that answers most questionnaires before they arrive. An agency that keeps these documents current can usually complete a client questionnaire in hours rather than weeks, and gives the same answers to every client:

  1. Access inventory. A list of every client platform, who has access, their role and the date granted.
  2. Authentication record. Screenshots showing multi-factor authentication enforced on email and key platforms.
  3. Offboarding checklist. The steps you follow when a staff member or freelancer leaves, with recent dated examples.
  4. Data handling note. Where client data is stored, who can export it, and how long it is kept.
  5. Incident contact plan. Who decides, who calls the client, and the notification window you commit to.
  6. Supplier list. The tools, subcontractors and freelancers that can reach client data.

Assign one person to own the pack and to review it every quarter, because a questionnaire answered from a stale document is worse than one answered slowly. When a new questionnaire arrives, start from the pack, flag every question that does not fit it, and answer those individually. If a question points to a real gap, such as no enforced multi-factor authentication or no written offboarding routine, fix the gap before you reply where the timeline allows, since the fix takes less effort than explaining its absence to a client reviewer.

Want to know where your own environment stands? The first step is a free, read-only security assessment.

Get a free security assessment
FAQ
Do we need a SOC 2 report to work with larger clients?
Not always. Many clients accept a completed questionnaire backed by evidence such as an access policy, proof of enforced multi-factor authentication and an incident contact plan. Some clients do require a SOC 2 report contractually, so ask the client early whether it is a requirement or a preference.
Can we say a control is in place if we are about to implement it?
No. Describe it as planned or partially in place, explain what exists today, and give a completion date. Questionnaire answers can be written into contracts, so an answer that overstates a control creates a commitment you have not met.
Who in the agency should fill in the questionnaire?
One named person who knows how client access, devices and tools are actually managed, with review from the agency owner before it is sent. Answers drafted by sales staff alone tend to describe intentions rather than the controls that exist.