---
title: "Compliance questionnaires | Guardian360"
description: "Standard NIS2/Cbw and CRA questionnaires in Lighthouse. Prove your own compliance and ask your suppliers to prove theirs, with evidence, an audit trail and a live view of where your supply chain stands."
url: https://guardian360.net/compliance/questionnaires/
locale: en
source: guardian360.net
---
Compliance questionnaires

# Prove your compliance down the chain, and ask your suppliers to prove theirs

NIS2 and the Cyber Resilience Act make you responsible for more than your own security: you have to show your supply chain is in order too. Lighthouse gives you standard questionnaires to prove your own compliance and to assess the suppliers you depend on, with evidence, an audit trail and a live view of where everyone stands.

Get started with questionnaires[See compliance recommendations](https://guardian360.net/compliance/recommendations/)

## Four standard questionnaires, ready to send

Two norms today, each with two variants, so the questionnaire matches the situation. New norms bring the questionnaires that fit them, and new ones are straightforward to add.

NIS2 / CbwEssential entity

### Suppliers of an essential entity

The full organisational questionnaire: governance, incident response, business continuity, supply chain, access, cryptography and MFA, mapped to the ten duty-of-care measures.

NIS2 / CbwImportant entity

### Suppliers of an important entity

A lighter, proportionate subset of the same set, for suppliers whose client is an important rather than an essential entity.

CRADefault product

### A default product

Product-level questions on secure-by-design, vulnerability handling, SBOM, the support period and Article 14 reporting, for products a manufacturer may self-assess.

CRAImportant / critical

### Important or critical products

The fuller product questionnaire for Annex III and IV products, which may also require third-party conformity assessment by a notified body.

Which variant fits depends on your role in the chain and, for the CRA, the product’s classification. Lighthouse defaults to the lighter variant and lets you pick the fuller one when it applies.

## One engine, three ways to use it

### Get your own compliance in order

Use a questionnaire as a self-assessment, alongside your daily recommendations, to see where you stand and close the gaps before anyone asks.

### Assess your supply chain

Register the suppliers you depend on, send each the right questionnaire, and review their evidence. A live dashboard shows where the whole chain stands, and re-assessment is one click at the next cycle.

### Answer once, reuse the proof

Asked by a customer to prove your compliance? Answer with evidence, keep a timestamped record, and reuse that attested proof the next time someone asks.

## How it works

1

### Register

Add the suppliers you depend on, one by one or by uploading a list.

2

### Send

Each supplier gets a secure link to the right questionnaire, in your name, with a clear deadline.

3

### Answer with evidence

Answers are more than yes or no: Yes, No, Unclear or In progress, each with evidence or an explanation and an expected date.

4

### Review & monitor

Every answer is timestamped with an audit trail, reported per supplier and across the chain, and easy to repeat next cycle.

## A readiness tool, not a certificate

Guardian360 is not a legal adviser, an auditor, a supervisory authority, a certification body or a notified body. The questionnaires help you ask the right questions, collect evidence and show where you and your suppliers stand. They do not replace a formal audit, certification or conformity assessment.

Get started

## Get started with compliance questionnaires

Tell us how you want to use the questionnaires, whether that is proving your own compliance, assessing your suppliers, or both. Guardian360 is delivered through partners, so we’ll set you up with your partner. Already a partner yourself? You can get going straight away.
