Template By Deepti Karn and Avani Nagwann Last updated on September 8, 2026 7 min read

Security Questionnaire Answer Sheet for WordPress Sites

A vendor security questionnaire, whatever it calls itself, sitting somewhere between a cybersecurity assessment questionnaire and a plain form your biggest customer emailed you, almost always asks the same seven things about your website. Below is a copy-pasteable answer sheet for those seven, worded in plain language, with the honest version of each answer rather than a reassuring one.

TL;DR

A vendor questionnaire almost always asks the same seven things: patching, backups, access control, encryption, monitoring, incident response, and data handling. Answer each with a number and a mechanism, never a plain “yes.” This covers the technical control questions; the organisational ones, a written data processing agreement, staff security training, and a formal incident response policy document, still need the site owner’s own paperwork, since no hosting or maintenance provider answers those on the owner’s behalf. A backup that only covers the database or lives on the same server as the site fails a restore test even though “we have backups” reads as true on the form. NoDrama’s WordPress security plans document exactly this: what gets patched, how often, and where backups actually live.

In this piece

  1. 01Read this first
  2. 02Use the template, and how to fill each section
  3. 03Check it holds up

The answer sheet

Copy this block, keep the field order, and fill each bracket with what is actually true of your site. This is the template a small team fills out for any vendor security assessment questionnaire, not a finished answer for one specific customer.

Website security, vendor questionnaire
Answer sheet, seven fields

01
PATCH AND UPDATE MANAGEMENT
Q: How quickly are security updates to core, themes and plugins applied?

A: Critical and high-severity updates applied within   days of release. Updates tested in   before going live, with rollback available if one breaks something.

02
BACKUP AND RECOVERY
Q: Is the site backed up, and can it actually be restored?

A: Backups run  , covering the database, media and files. Stored  . Last full restore tested on  .

03
ACCESS CONTROL
Q: Who can log in to the site’s admin area, and how is that controlled?

A:   active admin accounts, reviewed  . Multi-factor authentication   on admin logins.

04
ENCRYPTION IN TRANSIT
Q: Is the whole site served over HTTPS, not just checkout?

A: TLS enforced site-wide, including the login and admin paths, verified on  .

05
MONITORING AND DETECTION
Q: Is the site actively watched for downtime or unauthorised changes?

A: Uptime monitored  . File-integrity changes alert   within  .

06
INCIDENT RESPONSE
Q: Who gets contacted if something goes wrong, and how fast do they respond?

A: Named contact is  . Response time is  , as set out in  .

07
DATA HANDLING
Q: What data does the site collect, and where does it live?

A: The site collects  . Stored in  . Processed under  .

Prepared by _____________________
Date _____________

See the three plans and what each covers for what a managed WordPress care plan can supply as a documented answer to the technical fields above, patching cadence, backup location, and monitoring among them.

The seven questions, at a glance

Field What it’s really asking Answer with
Patching Do known vulnerabilities get closed inside a bounded window? UK Cyber Essentials sets 14 days for critical or high-severity, CVSS v3 7.0 and above. A cadence in days, plus whether updates are staged
Backups Is a restore actually possible, not just does a file exist? Cadence, coverage, storage location, last test-restore date
Access control Does an old contractor or former staff member still have wp-admin? Account count, review cadence, whether MFA is enforced
Encryption Is TLS enforced across the admin and login paths, not only checkout? Site-wide scope, plus the date it was verified
Monitoring Is anything actively watched, or would you notice eventually? What triggers an alert, and who receives it
Incident response Is there a named contact and a defined response time? A person or role, a time, and the document it’s written in
Data handling What does the site collect, and where does that data live? Data types, storage region, and the agreement it’s processed under
A table listing the seven questions a vendor security questionnaire asks and how to answer each one. The 14-day patch window is specific to UK Cyber Essentials, not a universal rule.

How to fill each section

A supplier security assessment rewards a number and a mechanism over a confident adjective, so each field below is worth understanding rather than guessing at.

Patch and update management

This question is really testing whether known vulnerabilities in core, themes, and plugins get closed inside a bounded window, not whether updates happen “regularly.” If the questionnaire references the UK’s Cyber Essentials scheme specifically, that scheme sets one hard, checkable number: security updates rated critical or high, or scoring 7.0 or above on CVSS v3, have to be applied within 14 days of release. That figure belongs to Cyber Essentials and should be labelled as such wherever it appears, not treated as a general rule every questionnaire enforces.

See how patching is scoped across the three plans for what a managed cadence actually looks like.

Verification step

Confirm the actual patch cadence in use by asking whoever manages the site directly, before writing a number down.

Backup and recovery

This question tests whether a restore is actually possible, not whether a backup file exists somewhere. A complete answer covers the database, uploaded media, and the full file system, stored off the origin server, with a defined retention window. A backup that only covers the database, or that lives on the same server as the site itself, fails a restore test even though “we have backups” reads as true on the form.

See how backups and rollback actually work for the mechanism behind that answer.

Verification step

Confirm the backup covers all three parts, database, media, and files, and that it has been test-restored at least once.

Access control

This question is testing who can log in to wp-admin, whether multi-factor authentication is enforced, and whether a former staff member or an agency contractor from an old project still has access.

Verification step

Pull the current admin user list and confirm every account still belongs to someone active.

Encryption in transit

This question tests whether TLS is enforced across the whole site, including the admin area, the login page, and any upload path, not only the page where a customer enters payment details.

Verification step

Check the login and admin URLs directly rather than assuming the homepage padlock covers everything behind it.

Monitoring and detection

This question tests whether uptime and file-integrity changes are actively watched, as opposed to a passive “we would notice eventually” if something changed.

Verification step

Confirm what actually triggers an alert and who receives it.

Incident response

This question tests whether there is a named point of contact and a defined response time, not a general promise that “someone would deal with it.”

Verification step

Name the person and the response time in writing, rather than leaving it as a shared assumption.

What reviewers or auditors actually check

A reviewer reading a stack of these forms has seen every version of “yes, we take security seriously.” What holds up on review is specificity: a cadence instead of “regularly,” a named location instead of “we have backups,” and a named person instead of “our team handles that.” A cyber security assessment questionnaire answered in adjectives gets sent back with follow-up questions. One answered with a number, and a mechanism for each of the seven fields, usually does not.

Get the answer sheet, or have NoDrama walk through it with you.

No pitch attached.

Walk Me Through It

What this does not cover

Filling in the seven technical fields above does not complete the whole form. Most questionnaires, and most customer contracts behind them, also carry an organisational layer that a maintenance provider cannot answer on the site owner’s behalf.

A maintenance provider can confirm this
Patching cadence
Backups and restore testing
Monitoring and alerting
Admin access review
Encryption in transit
This still needs your own paperwork
A written data processing agreement
Staff security training records
A formal, written incident response policy
A business continuity plan
A two-column comparison of questionnaire sections a WordPress maintenance provider can answer versus sections that need the site owner’s own documentation.

A supplier’s technical answer sheet does not, by itself, complete a data protection or business continuity section. Those stay the site owner’s own paperwork.

It is also worth separating this sheet from the Cyber Essentials certification itself. Certification is a separate, formal process, assessed and renewed on its own 12-month cycle. This sheet supports answering the technical questions that sit inside that process; it is not the certification, and completing it does not certify anything on its own.

Where teams get this wrong

Three patterns account for most of the questionnaires that come back with follow-up questions.

01

Filling the form from memory or asking whoever built the site originally, rather than checking what is actually true today. A site changes hands, plugins get added, and the person who built it three years ago is not the person who can confirm the current backup cadence.

02

Copying a generic template and answering every field “yes” with no number attached. A reviewer reads that as a form filled in to get past the form, not as an accurate account of the site.

03

Treating “we have a maintenance provider” as a complete answer to the whole form. It answers the technical mechanism question well, but it says nothing about the data processing agreement, the staff training record, or the written incident response policy the same form usually also asks for.

Conclusion

Most vendor security questionnaires, whichever named framework they borrow their wording from, are asking about the same seven things: patching, backups, access control, encryption, monitoring, incident response and data handling. Answer each with a cadence, a location, or a named person rather than a plain “yes”; verify the answer is actually true before writing it down; and treat the organisational fields, the data processing agreement, the staff training record, and the incident response policy, as your own paperwork rather than something a maintenance provider fills in for you.

FAQs

They want the same seven technical mechanisms covered above: patch cadence, backup and restore, access control, encryption in transit, monitoring, and incident response, applied to the website itself rather than to the company's office network or its staff policies.
Say so and fix it before submitting the form. Confirm the backup covers the database, media and files, that it's stored off the origin server, and run a test restore; only then write down a cadence and location you can stand behind.
No. That answers the technical mechanism question at best, and most forms also ask for the organisational paperwork, the data processing agreement, staff training records and a written incident response policy, that a host or maintenance provider does not supply on your behalf.
Not by itself. Cyber Essentials is a separate, formal certification process on its own 12-month renewal cycle. It can support your answers to the technical fields on this sheet, but holding the certification is not the same as completing the questionnaire in front of you.
The US framework landscape here is less standardised than the UK's Cyber Essentials scheme, which sets one specific, checkable patch window. Where a US customer references NIST or CISA language, treat it as a request for the same seven mechanisms above, documented clearly, rather than assuming a single named standard applies.

Have Us Document The Technical Answers

Walk Me Through It
No credit card required to start a conversation
Cancel anytime
Real team behind every plan