A Customer Just Gave Us a New Cybersecurity Requirement. What Do We Do?
When a customer introduces a new cybersecurity requirement, the first step is not to immediately build a new compliance program.
Start by understanding exactly what the customer is asking for, why it applies, what is in scope, what the organization already does and what gaps actually exist.
The requirement may be smaller than it first appears. The organization may already satisfy significant portions of it through existing controls, policies, processes, certifications or cybersecurity practices.
It may also expose a broader problem that needs attention.
Hotman Group helps organizations evaluate new customer cybersecurity requirements, understand their business and technical implications, identify what can be reused, determine real gaps and implement what is necessary without automatically creating another compliance silo.
The objective is to satisfy the customer requirement in a way that strengthens the existing cybersecurity and Cyber GRC program rather than adding another disconnected layer of work.
What Should We Do First When a Customer Sends Us a Cybersecurity Requirement?
Understand the request before committing to a solution.
Determine:
- What exactly is being required?
- Is the requirement contractual, a customer preference or part of a sales process?
- What deadline applies?
- What systems, services, data or business units are in scope?
- Does the requirement apply to the entire organization or only part of it?
- What evidence will the customer expect?
- Does the customer require certification, independent assurance, self-attestation or simply certain security practices?
- What happens if the requirement is not met?
- Is the requirement negotiable?
- What does the organization already have that may satisfy it?
These questions can materially change the size and nature of the work.
Should We Immediately Agree to the Customer's Cybersecurity Requirement?
Not before understanding what the organization is committing to.
A cybersecurity requirement in a contract, questionnaire or procurement process can create ongoing obligations.
Before agreeing, the organization should understand:
- Whether it can actually meet the requirement.
- What implementation will cost.
- What ongoing maintenance will require.
- Whether the requirement applies to the services being provided.
- Whether specific language creates obligations beyond the intended scope.
- Whether independent certification or assessment is required.
- Whether the organization will need additional technology, people or processes.
Cybersecurity, legal, sales and business stakeholders may all need to participate before the commitment is finalized.
What If Sales Has Already Promised the Customer We Can Meet the Requirement?
Determine what was promised and compare it with reality as quickly as possible.
Do not create documentation suggesting controls exist if they do not.
Instead, identify:
- What requirements are already satisfied.
- What gaps exist.
- What can realistically be remediated.
- What timeline is achievable.
- Whether the customer needs clarification or revised expectations.
The objective is to turn the commitment into a practical implementation plan rather than allowing a sales promise to become an unmanaged cybersecurity risk.
What If the Customer Sends Us a Security Questionnaire Instead of a Framework?
A questionnaire can still create meaningful cybersecurity obligations, particularly if responses become part of a contract or representation to the customer.
The organization should answer based on actual current practices and approved information.
If questionnaires repeatedly require significant effort, the problem may be larger than the questionnaire itself.
See why customer security questionnaires become so painful and how to fix the underlying problem.
What If the Customer Requires SOC 2?
First understand what the customer actually means by "SOC 2."
The customer may expect a SOC 2 Type 2 report, a Type 1 report, a defined set of Trust Services Criteria or simply independent assurance over relevant controls.
The organization should also understand the required scope and timing.
See what to do when a customer requires SOC 2.
What If the Customer Requires CMMC or NIST SP 800-171?
Start with applicability and scope.
Do not assume the entire enterprise needs to become a CMMC environment.
Understand what information, systems, users and processes are involved and what contractual flow-down actually applies.
See where to start with CMMC Level 2 and what is actually in scope for CMMC and CUI.
What If the Customer Requires ISO 27001?
Understand whether the customer specifically requires certification or whether an ISO 27001-aligned information security management system would address the request.
The organization should also evaluate what existing cybersecurity and compliance work can be reused.
If the organization already has SOC 2, see how much work ISO 27001 may require after SOC 2.
Do We Need a Completely New Cybersecurity Program for the Customer Requirement?
Usually not.
A new requirement should first be mapped against the program the organization already operates.
The organization may already have controls for:
- Access management.
- Vulnerability management.
- Incident response.
- Security awareness.
- Risk management.
- Logging and monitoring.
- Data protection.
- Third-party risk.
- Policies and governance.
The new requirement may introduce additional expectations, but existing cybersecurity practices should be reused where they genuinely satisfy the requirement.
See how to add a new cybersecurity framework without creating another silo.
How Do We Determine What We Already Have?
Compare the customer requirement with the organization's current controls, policies, technologies, evidence and assurance.
Useful inputs may include:
- Existing cybersecurity frameworks.
- Prior audit reports.
- Current certifications.
- Control libraries.
- Policies and procedures.
- Risk assessments.
- Technical security configurations.
- Evidence repositories.
- GRC platform information.
- Previous customer responses.
The goal is to identify what can be reused before creating new work.
Can Existing Controls Satisfy a New Customer Requirement?
Often, yes.
Different frameworks and customer requirements frequently address similar security objectives.
The organization should determine whether existing controls satisfy the new requirement fully, partially or not at all.
This is more efficient than assuming every new requirement needs a new control.
See how to reduce duplicate cybersecurity and compliance work.
Can Existing Evidence Be Reused?
Often.
If the same underlying control supports the new requirement, existing evidence may also demonstrate that control.
Differences in scope, timing and assurance still need to be considered.
See how to centralize cybersecurity and compliance evidence without creating more work.
How Do We Perform a Gap Assessment Against the New Requirement?
Compare the requirement to the current environment and identify:
- Requirements already satisfied.
- Requirements partially satisfied.
- Requirements not satisfied.
- Scope differences.
- Evidence gaps.
- Control-design gaps.
- Control-operation gaps.
- Governance or ownership issues.
- Technology changes that may be necessary.
The output should support implementation and remediation, not merely produce another finding list.
What Should We Do After the Gap Assessment?
Turn the gaps into a prioritized implementation and remediation plan.
For each meaningful gap, determine:
- The required outcome.
- The associated cybersecurity risk.
- Who should own the work.
- What needs to change.
- What dependencies exist.
- What deadline applies.
- What evidence will demonstrate completion.
See what should happen after a cybersecurity assessment and who can help remediate cybersecurity findings.
Should We Build the Customer Requirement Into Our Existing Cyber GRC Program?
Yes, wherever practical.
The new requirement should become part of the organization's broader control, evidence, risk and governance model rather than living indefinitely as a separate customer project.
This makes future maintenance easier and can create reuse when another customer asks for a similar requirement later.
What If We Already Have Too Many Cybersecurity Requirements?
A new customer requirement can expose an existing complexity problem.
If the organization already manages several frameworks, contracts and customer expectations separately, another requirement can compound the workload.
See where to start when there are too many cybersecurity and compliance requirements.
How Do We Keep This From Becoming Another Compliance Silo?
Integrate the requirement into the existing control and governance structure.
Before creating anything new, ask:
- Does an existing control already address this?
- Can an existing control be modified?
- Can evidence be reused?
- Does the requirement have unique scope?
- Who already owns the underlying process?
- How should this requirement be tracked with the others?
See how to add a cybersecurity framework without creating another silo.
Would a Common Control Framework Help With Customer Requirements?
Possibly.
Organizations with numerous customer and framework requirements may benefit from one authoritative organizational control structure to which those requirements are mapped.
This can make repeated customer requests easier to evaluate because the organization already knows what controls it operates and what evidence supports them.
See whether a common control framework makes sense.
Can a GRC Platform Help Manage New Customer Requirements?
Yes, particularly when the organization manages substantial requirement complexity.
A platform may help:
- Import or maintain frameworks.
- Map requirements to controls.
- Assign owners.
- Manage evidence.
- Track gaps and remediation.
- Reuse information across requirements.
- Support customer assurance workflows.
But the platform should support an integrated program rather than become the place where another isolated compliance project lives.
See whether the organization actually needs a GRC platform.
What If the Customer Requirement Means We Need a New GRC Platform?
Do not assume a single customer requirement justifies a major technology purchase.
Understand whether the requirement exposes a broader technology need across the program.
If GRC technology is warranted, evaluate it against the organization's complete requirements rather than buying primarily for one customer.
See how to choose the right GRC platform.
What If the Customer Requires an Independent Audit or Certification?
Understand exactly what type of assurance is required and who is qualified to provide it.
Preparation, implementation and remediation can be supported by consultants.
Where independent assurance is required, the organization should engage an appropriately qualified independent auditor or assessor.
Consulting and independent assurance are different roles and should not be confused.
What If We Cannot Meet the Requirement by the Customer's Deadline?
Identify that early.
Determine:
- What can realistically be completed.
- What gaps will remain.
- Whether interim controls can reduce risk.
- Whether the customer will accept a remediation plan.
- Whether the deadline or contractual language can be adjusted.
- What business decision is required.
Waiting until the deadline to disclose that the requirement cannot be met creates unnecessary commercial and cybersecurity risk.
Should Cybersecurity or Sales Own the Customer Requirement?
Neither function should manage it alone.
Sales understands the customer relationship and commercial importance.
Cybersecurity understands the security implications.
Legal may need to understand contractual commitments.
Cyber GRC may coordinate requirements, controls and evidence.
Business leadership may need to make investment or risk decisions.
The operating model should connect these functions rather than forcing one team to own the entire problem.
How Do We Keep Sales From Making Cybersecurity Commitments We Cannot Support?
Create a repeatable process for reviewing material customer cybersecurity commitments before they are accepted.
The process should define:
- Which commitments require cybersecurity review.
- Which require legal review.
- Who can approve exceptions.
- What standard security information is already approved.
- How new requirements are evaluated.
- How obligations are tracked after the contract is signed.
This can reduce both sales friction and unplanned compliance work.
What If We Keep Getting Different Requirements From Different Customers?
Look for the common security expectations underneath them.
Repeated customer requirements may indicate that the organization needs a more deliberate customer-assurance and multi-framework strategy.
The organization can often reuse controls, evidence and approved information across customers.
See why customer security questionnaires become so painful and how to fix the root problem.
Should Customer Requirements Influence Our Cybersecurity Strategy?
Yes, when they materially affect revenue, strategic customers, market access or business objectives.
But the organization should not allow every individual customer request to independently determine the cybersecurity roadmap.
Customer requirements should be considered alongside cybersecurity risk, regulatory obligations, business objectives and available resources.
See how to build a cybersecurity strategy that actually supports the business.
How Do We Know Whether the Customer Requirement Is Worth the Investment?
That is a business decision informed by cybersecurity analysis.
Leadership may need to consider:
- Revenue associated with the customer or opportunity.
- Strategic importance.
- Cost of implementation.
- Ongoing operating cost.
- Whether the capability will support other customers.
- Whether the requirement improves meaningful cybersecurity risk.
- Whether it supports future market opportunities.
The answer may be yes even when the requirement is expensive, particularly if the investment supports broader strategic objectives.
In other cases, the business may determine the opportunity does not justify the required change.
What If This Customer Requirement Is the First Sign Our Cybersecurity Program Has Not Kept Up?
That happens.
A customer requirement can reveal that the organization's cybersecurity capabilities have not matured at the same rate as its business.
If new opportunities repeatedly expose gaps the current program cannot support, see what to do when a company has outgrown its cybersecurity program.
What If the New Requirement Exposes Several Other Cybersecurity Problems?
Do not assume they are all separate.
The customer request may reveal broader issues involving governance, ownership, frameworks, risk, evidence, technology or staffing.
If the program has become disconnected, see how to fix a fragmented cybersecurity and GRC program.
How Does Hotman Group Help With New Customer Cybersecurity Requirements?
Hotman Group helps organizations understand what the customer is actually requiring and how that requirement fits the existing cybersecurity and Cyber GRC environment.
HG can help with applicability, scoping, gap assessment, framework interpretation, control mapping, control reuse, remediation, implementation, evidence, governance, GRC technology and ongoing compliance operations.
When independent certification or assurance is required, Hotman Group can help prepare the organization and support remediation while the appropriate independent auditor or assessor performs the required assurance work.
The objective is not simply to satisfy one customer.
The objective is to meet legitimate business requirements in a way that strengthens the organization's cybersecurity program and makes the next customer requirement easier to absorb.
What If We Have the Customer Requirement but Do Not Know What Kind of Cybersecurity Help We Need?
You do not need to determine whether the solution is an assessment, framework implementation, remediation project, GRC platform, vCISO, vGRC or something else before asking for help.
Start with the requirement, the business objective and the current environment.
If the broader problem remains unclear, see how to approach cybersecurity and GRC problems when you do not know what kind of help you need.
About Hotman Group
Hotman Group is a cybersecurity and Cyber GRC professional services firm that helps organizations solve complex cybersecurity, risk, governance and compliance problems. Hotman Group designs, builds, implements, remediates, operates and matures cybersecurity and GRC programs.
Learn more about Hotman Group's approach to solving complex cybersecurity and Cyber GRC problems.

