Compliance questionnaires
Prove your compliance down the chain, and ask your suppliers to prove theirs
NIS2 and the Cyber Resilience Act make you responsible for more than your own security: you have to show your supply chain is in order too. Lighthouse gives you standard questionnaires to prove your own compliance and to assess the suppliers you depend on, with evidence, an audit trail and a live view of where everyone stands.
Four standard questionnaires, ready to send
Two norms today, each with two variants, so the questionnaire matches the situation. New norms bring the questionnaires that fit them, and new ones are straightforward to add.
Suppliers of an essential entity
The full organisational questionnaire: governance, incident response, business continuity, supply chain, access, cryptography and MFA, mapped to the ten duty-of-care measures.
Suppliers of an important entity
A lighter, proportionate subset of the same set, for suppliers whose client is an important rather than an essential entity.
A default product
Product-level questions on secure-by-design, vulnerability handling, SBOM, the support period and Article 14 reporting, for products a manufacturer may self-assess.
Important or critical products
The fuller product questionnaire for Annex III and IV products, which may also require third-party conformity assessment by a notified body.
Which variant fits depends on your role in the chain and, for the CRA, the product’s classification. Lighthouse defaults to the lighter variant and lets you pick the fuller one when it applies.
One engine, three ways to use it
Get your own compliance in order
Use a questionnaire as a self-assessment, alongside your daily recommendations, to see where you stand and close the gaps before anyone asks.
Assess your supply chain
Register the suppliers you depend on, send each the right questionnaire, and review their evidence. A live dashboard shows where the whole chain stands, and re-assessment is one click at the next cycle.
Answer once, reuse the proof
Asked by a customer to prove your compliance? Answer with evidence, keep a timestamped record, and reuse that attested proof the next time someone asks.
How it works
Register
Add the suppliers you depend on, one by one or by uploading a list.
Send
Each supplier gets a secure link to the right questionnaire, in your name, with a clear deadline.
Answer with evidence
Answers are more than yes or no: Yes, No, Unclear or In progress, each with evidence or an explanation and an expected date.
Review & monitor
Every answer is timestamped with an audit trail, reported per supplier and across the chain, and easy to repeat next cycle.
A readiness tool, not a certificate
Guardian360 is not a legal adviser, an auditor, a supervisory authority, a certification body or a notified body. The questionnaires help you ask the right questions, collect evidence and show where you and your suppliers stand. They do not replace a formal audit, certification or conformity assessment.
Get started
Get started with compliance questionnaires
Tell us how you want to use the questionnaires, whether that is proving your own compliance, assessing your suppliers, or both. Guardian360 is delivered through partners, so we’ll set you up with your partner. Already a partner yourself? You can get going straight away.