Skip to content

Vendor Security Questionnaire


PoleHodnota
Vendor Name[PLACEHOLDER]
Service Description[PLACEHOLDER]
Questionnaire Date[PLACEHOLDER: DD.MM.YYYY]
Completed By[PLACEHOLDER: Name, Role]
Reviewer[PLACEHOLDER: Name, Role]

#OtázkaOdpověď
1.1Legal name of company
1.2Headquarters location
1.3Year established
1.4Number of employees
1.5Annual revenue
1.6Primary contact (security)
1.7Website

#OtázkaOdpověď
2.1Do you have ISO 27001 certification?☐ Yes / ☐ No / ☐ In progress
2.2If yes, provide certificate number and expiry
2.3Do you have SOC 2 Type II report?☐ Yes / ☐ No / ☐ In progress
2.4Are you GDPR compliant?☐ Yes / ☐ No / ☐ In progress
2.5Are you NIS2 compliant (if applicable)?☐ Yes / ☐ No / ☐ N/A
2.6List other relevant certifications
2.7Have you had any regulatory actions in last 3 years?☐ Yes / ☐ No
2.8If yes, describe

#OtázkaOdpověď
3.1What personal data will you process?
3.2What is the legal basis for processing?
3.3Where will data be stored? (country/region)
3.4Will data be transferred outside EU/EEA?☐ Yes / ☐ No
3.5If yes, what transfer mechanism?☐ SCCs / ☐ Adequacy / ☐ BCR / ☐ Other
3.6Do you have a DPO?☐ Yes / ☐ No
3.7DPO contact
3.8Do you have a privacy policy?☐ Yes / ☐ No
3.9Can you support DSAR requests?☐ Yes / ☐ No
3.10What is your data retention policy?

#OtázkaOdpověď
4.1.1Do you use MFA for all admin access?☐ Yes / ☐ No
4.1.2Do you use role-based access control (RBAC)?☐ Yes / ☐ No
4.1.3How often are access rights reviewed?
4.1.4What is your password policy?
4.1.5Do you have privileged access management (PAM)?☐ Yes / ☐ No
#OtázkaOdpověď
4.2.1Is data encrypted at rest?☐ Yes / ☐ No
4.2.2If yes, what algorithm/key length?
4.2.3Is data encrypted in transit?☐ Yes / ☐ No
4.2.4What TLS version is supported?
4.2.5How are encryption keys managed?
#OtázkaOdpověď
4.3.1Do you use firewalls?☐ Yes / ☐ No
4.3.2Do you have IDS/IPS?☐ Yes / ☐ No
4.3.3Is network segmentation implemented?☐ Yes / ☐ No
4.3.4Do you use DDoS protection?☐ Yes / ☐ No
#OtázkaOdpověď
4.4.1How often do you scan for vulnerabilities?
4.4.2What is your patch management SLA?Critical: / High: / Medium:
4.4.3Do you conduct penetration testing?☐ Yes / ☐ No
4.4.4How often?
4.4.5Do you have a bug bounty program?☐ Yes / ☐ No
#OtázkaOdpověď
4.5.1Do you use SIEM?☐ Yes / ☐ No
4.5.2What is your log retention period?
4.5.3Do you have 24/7 security monitoring?☐ Yes / ☐ No
4.5.4Can you provide audit logs to customers?☐ Yes / ☐ No

#OtázkaOdpověď
5.1Do you have an incident response plan?☐ Yes / ☐ No
5.2How quickly can you notify customers of breach?
5.3Have you had any breaches in last 3 years?☐ Yes / ☐ No
5.4If yes, describe
5.5Do you conduct incident response exercises?☐ Yes / ☐ No
5.6Do you have cyber insurance?☐ Yes / ☐ No

#OtázkaOdpověď
6.1Do you have a BCP/DRP?☐ Yes / ☐ No
6.2What is your RTO?
6.3What is your RPO?
6.4How often are backups taken?
6.5Are backups encrypted?☐ Yes / ☐ No
6.6How often is DR tested?
6.7What is your SLA uptime guarantee?

#OtázkaOdpověď
7.1Do you use sub-processors?☐ Yes / ☐ No
7.2List all sub-processors with access to data
7.3How do you assess sub-processor security?
7.4Can customers object to new sub-processors?☐ Yes / ☐ No

#OtázkaOdpověď
8.1Does your service use AI/ML?☐ Yes / ☐ No
8.2If yes, describe AI functionality
8.3Is customer data used for training?☐ Yes / ☐ No
8.4Can customers opt-out of AI training?☐ Yes / ☐ No
8.5How do you address AI bias?
8.6Are you prepared for AI Act compliance?☐ Yes / ☐ No / ☐ N/A

#OtázkaOdpověď
9.1Where are your data centers located?
9.2Do you own or lease data center space?☐ Own / ☐ Lease / ☐ Cloud
9.3Data center certifications
9.4Physical access controls in place

#OtázkaOdpověď
10.1Do you conduct background checks?☐ Yes / ☐ No
10.2Is security training mandatory?☐ Yes / ☐ No
10.3How often is training conducted?
10.4Do employees sign NDAs?☐ Yes / ☐ No
10.5What is your offboarding process?

Section 11: Data Act Compliance (EU 2023/2854)

Section titled “Section 11: Data Act Compliance (EU 2023/2854)”

Vyplňte pro cloud/SaaS služby a connected products. Data Act platí od 12.9.2025.

#OtázkaOdpověď
11.1.1Je vendor poskytovatelem cloud služeb (IaaS/PaaS/SaaS)?☐ Yes / ☐ No
11.1.2Je vendor výrobcem connected products (IoT)?☐ Yes / ☐ No
11.1.3Je vendor regulován DORA? (pokud ano, DORA = lex specialis)☐ Yes / ☐ No

11.2 Cloud Switching Rights (Kapitola VI Data Act)

Section titled “11.2 Cloud Switching Rights (Kapitola VI Data Act)”

Vyplňte pokud 11.1.1 = Yes

#OtázkaOdpověď
11.2.1Jsou switching rights explicitně uvedena ve smlouvě?☐ Yes / ☐ No
11.2.2Jaká je maximální notice period pro switching?☐ ≤2 měsíce (compliant) / ☐ >2 měsíce (non-compliant)
11.2.3Existuje self-service data export funkce?☐ Yes / ☐ No / ☐ Partial
11.2.4V jakém formátu jsou data exportovatelná?☐ Standard (JSON, CSV, SQL) / ☐ Proprietary
11.2.5Jsou switching costs transparentně dokumentovány?☐ Yes / ☐ No
11.2.6Jaká je výše switching fees?☐ 0 (compliant od 2027) / ☐ Reasonable / ☐ High
11.2.7Poskytuje vendor technickou asistenci při switchingu?☐ Yes, v SLA / ☐ Best effort / ☐ No
11.2.8Existuje dokumentace pro migraci?☐ Yes / ☐ No
11.2.9Jsou API standardizovaná a interoperabilní?☐ Yes / ☐ Partial / ☐ No

Cloud Switching Compliance Score:

  • 8-9 odpovědí “compliant”: ✅ Vysoká compliance
  • 5-7 odpovědí “compliant”: ⚠️ Střední - vyžaduje pozornost
  • <5 odpovědí “compliant”: ❌ Nízká - riziko lock-in
#OtázkaOdpověď
11.3.1Lze exportovat VŠECHNA zákaznická data?☐ Yes / ☐ Partial / ☐ No
11.3.2Jsou exportovatelná i metadata a konfigurace?☐ Yes / ☐ No
11.3.3Jaký je SLA pro dokončení exportu?
11.3.4Je export dostupný i po ukončení smlouvy?☐ Yes (doba: ___) / ☐ No
11.3.5Lze data exportovat programaticky (API)?☐ Yes / ☐ No

11.4 IoT / Connected Products (Kapitola II-III Data Act)

Section titled “11.4 IoT / Connected Products (Kapitola II-III Data Act)”

Vyplňte pokud 11.1.2 = Yes

#OtázkaOdpověď
11.4.1Mají uživatelé real-time přístup k datům ze zařízení?☐ Yes / ☐ On request / ☐ No
11.4.2Je přístup k datům bezplatný?☐ Yes / ☐ Partial / ☐ No
11.4.3Jsou data v machine-readable formátu?☐ Yes / ☐ No
11.4.4Mohou uživatelé sdílet data s třetími stranami?☐ Yes / ☐ No
11.4.5Je produkt navržen s “data access by design”?☐ Yes / ☐ In progress / ☐ No
11.4.6Jsou před-nákupní informace o datech dostupné?☐ Yes / ☐ No

11.5 Unfair Terms Protection (Kapitola IV Data Act)

Section titled “11.5 Unfair Terms Protection (Kapitola IV Data Act)”
#OtázkaOdpověď
11.5.1Obsahuje smlouva klauzule umožňující jednostranné změny?☐ No (good) / ☐ Yes (review needed)
11.5.2Obsahuje smlouva výlučná práva na data?☐ No (good) / ☐ Yes (potential issue)
11.5.3Jsou penále za předčasné ukončení proporcionální?☐ Yes / ☐ No (review needed)
11.5.4Byla smlouva revidována pro Data Act compliance?☐ Yes / ☐ In progress / ☐ No
KritériumStatusPoznámka
Cloud Switching Rights☐ Compliant / ☐ Partial / ☐ Non-compliant
Data Portability☐ Compliant / ☐ Partial / ☐ Non-compliant
IoT Data Access☐ Compliant / ☐ Partial / ☐ N/A
Unfair Terms☐ Compliant / ☐ Partial / ☐ Non-compliant
Overall Data Act☐ Compliant / ☐ Partial / ☐ Non-compliant

Data Act Risk Assessment:

  • Low Risk - Vendor je Data Act compliant, nízké lock-in riziko
  • Medium Risk - Částečná compliance, doporučeno vyjednávání
  • High Risk - Non-compliant, vysoké lock-in riziko, zvážit alternativy

Please provide the following documents:

DocumentProvidedNotes
ISO 27001 certificate
SOC 2 Type II report
Privacy policy
DPA template
Penetration test summary
Insurance certificate
Sub-processor list
Data Act documentation:
Data export procedure
Switching process documentation
Switching costs breakdown
Migration guide

AreaScore (1-5)Notes
Certifications
Data Protection
Access Control
Encryption
Network Security
Vulnerability Mgmt
Incident Response
Business Continuity
Data Act Compliance
Lock-in RiskLow/Medium/High
Overall

Data Act Specific Assessment:

KritériumStatus
Switching Rights☐ OK / ☐ Negotiate / ☐ Block
Data Portability☐ OK / ☐ Negotiate / ☐ Block
Exit Costs☐ Acceptable / ☐ High / ☐ Prohibitive
Unfair Terms☐ None / ☐ Some / ☐ Many

Recommendation: ☐ Approve / ☐ Approve with conditions / ☐ Reject

Conditions (if applicable):

  1. [PLACEHOLDER]
  2. [PLACEHOLDER]

Data Act Specific Conditions:

  1. [PLACEHOLDER: e.g., “Require Data Act compliant switching clause”]
  2. [PLACEHOLDER: e.g., “Negotiate switching fees reduction”]

RoleNameDateSignature
Security Reviewer
CISO
DPO (if personal data)
DSO (if cloud/SaaS)
Procurement


Verze: 1.1 | Datum: Prosinec 2025 Changelog:

  • v1.1: Přidána Section 11 - Data Act Compliance Licence: CC BY-SA 4.0