In this piece
The answer sheet
Copy this block, keep the field order, and fill each bracket with what is actually true of your site. This is the template a small team fills out for any vendor security assessment questionnaire, not a finished answer for one specific customer.
Answer sheet, seven fields
Q: How quickly are security updates to core, themes and plugins applied?
A: Critical and high-severity updates applied within days of release. Updates tested in before going live, with rollback available if one breaks something.
Q: Is the site backed up, and can it actually be restored?
A: Backups run , covering the database, media and files. Stored . Last full restore tested on .
Q: Who can log in to the site’s admin area, and how is that controlled?
A: active admin accounts, reviewed . Multi-factor authentication on admin logins.
Q: Is the whole site served over HTTPS, not just checkout?
A: TLS enforced site-wide, including the login and admin paths, verified on .
Q: Is the site actively watched for downtime or unauthorised changes?
A: Uptime monitored . File-integrity changes alert within .
Q: Who gets contacted if something goes wrong, and how fast do they respond?
A: Named contact is . Response time is , as set out in .
Q: What data does the site collect, and where does it live?
A: The site collects . Stored in . Processed under .
Date _____________
See the three plans and what each covers for what a managed WordPress care plan can supply as a documented answer to the technical fields above, patching cadence, backup location, and monitoring among them.
The seven questions, at a glance
| Field | What it’s really asking | Answer with |
|---|---|---|
| Patching | Do known vulnerabilities get closed inside a bounded window? UK Cyber Essentials sets 14 days for critical or high-severity, CVSS v3 7.0 and above. | A cadence in days, plus whether updates are staged |
| Backups | Is a restore actually possible, not just does a file exist? | Cadence, coverage, storage location, last test-restore date |
| Access control | Does an old contractor or former staff member still have wp-admin? | Account count, review cadence, whether MFA is enforced |
| Encryption | Is TLS enforced across the admin and login paths, not only checkout? | Site-wide scope, plus the date it was verified |
| Monitoring | Is anything actively watched, or would you notice eventually? | What triggers an alert, and who receives it |
| Incident response | Is there a named contact and a defined response time? | A person or role, a time, and the document it’s written in |
| Data handling | What does the site collect, and where does that data live? | Data types, storage region, and the agreement it’s processed under |
How to fill each section
A supplier security assessment rewards a number and a mechanism over a confident adjective, so each field below is worth understanding rather than guessing at.
Patch and update management
This question is really testing whether known vulnerabilities in core, themes, and plugins get closed inside a bounded window, not whether updates happen “regularly.” If the questionnaire references the UK’s Cyber Essentials scheme specifically, that scheme sets one hard, checkable number: security updates rated critical or high, or scoring 7.0 or above on CVSS v3, have to be applied within 14 days of release. That figure belongs to Cyber Essentials and should be labelled as such wherever it appears, not treated as a general rule every questionnaire enforces.
See how patching is scoped across the three plans for what a managed cadence actually looks like.
Confirm the actual patch cadence in use by asking whoever manages the site directly, before writing a number down.
Backup and recovery
This question tests whether a restore is actually possible, not whether a backup file exists somewhere. A complete answer covers the database, uploaded media, and the full file system, stored off the origin server, with a defined retention window. A backup that only covers the database, or that lives on the same server as the site itself, fails a restore test even though “we have backups” reads as true on the form.
See how backups and rollback actually work for the mechanism behind that answer.
Confirm the backup covers all three parts, database, media, and files, and that it has been test-restored at least once.
Access control
This question is testing who can log in to wp-admin, whether multi-factor authentication is enforced, and whether a former staff member or an agency contractor from an old project still has access.
Pull the current admin user list and confirm every account still belongs to someone active.
Encryption in transit
This question tests whether TLS is enforced across the whole site, including the admin area, the login page, and any upload path, not only the page where a customer enters payment details.
Check the login and admin URLs directly rather than assuming the homepage padlock covers everything behind it.
Monitoring and detection
This question tests whether uptime and file-integrity changes are actively watched, as opposed to a passive “we would notice eventually” if something changed.
Confirm what actually triggers an alert and who receives it.
Incident response
This question tests whether there is a named point of contact and a defined response time, not a general promise that “someone would deal with it.”
Name the person and the response time in writing, rather than leaving it as a shared assumption.
What reviewers or auditors actually check
A reviewer reading a stack of these forms has seen every version of “yes, we take security seriously.” What holds up on review is specificity: a cadence instead of “regularly,” a named location instead of “we have backups,” and a named person instead of “our team handles that.” A cyber security assessment questionnaire answered in adjectives gets sent back with follow-up questions. One answered with a number, and a mechanism for each of the seven fields, usually does not.
Get the answer sheet, or have NoDrama walk through it with you.
No pitch attached.
What this does not cover
Filling in the seven technical fields above does not complete the whole form. Most questionnaires, and most customer contracts behind them, also carry an organisational layer that a maintenance provider cannot answer on the site owner’s behalf.
Backups and restore testing
Monitoring and alerting
Admin access review
Encryption in transit
Staff security training records
A formal, written incident response policy
A business continuity plan
A supplier’s technical answer sheet does not, by itself, complete a data protection or business continuity section. Those stay the site owner’s own paperwork.
It is also worth separating this sheet from the Cyber Essentials certification itself. Certification is a separate, formal process, assessed and renewed on its own 12-month cycle. This sheet supports answering the technical questions that sit inside that process; it is not the certification, and completing it does not certify anything on its own.
Where teams get this wrong
Three patterns account for most of the questionnaires that come back with follow-up questions.
Filling the form from memory or asking whoever built the site originally, rather than checking what is actually true today. A site changes hands, plugins get added, and the person who built it three years ago is not the person who can confirm the current backup cadence.
Copying a generic template and answering every field “yes” with no number attached. A reviewer reads that as a form filled in to get past the form, not as an accurate account of the site.
Treating “we have a maintenance provider” as a complete answer to the whole form. It answers the technical mechanism question well, but it says nothing about the data processing agreement, the staff training record, or the written incident response policy the same form usually also asks for.
Conclusion
Most vendor security questionnaires, whichever named framework they borrow their wording from, are asking about the same seven things: patching, backups, access control, encryption, monitoring, incident response and data handling. Answer each with a cadence, a location, or a named person rather than a plain “yes”; verify the answer is actually true before writing it down; and treat the organisational fields, the data processing agreement, the staff training record, and the incident response policy, as your own paperwork rather than something a maintenance provider fills in for you.