Menu
CMMS and OEE Vendor Security Questionnaire: 2026 Buyer Guide

CMMS and OEE Vendor Security Questionnaire: 2026 Buyer Guide

The 12 questions to send every CMMS and OEE vendor before IT signs off: certification scope, hosting region, sub-processors, RTO and RPO, and exit terms.
CMMS and OEE Vendor Security Questionnaire: 2026 Buyer Guide

Key takeaways

  • An industrial software security review is not one document. It is four: an information security certification, a data processing agreement, a hosting and data residency statement, and a recovery objective.
  • Ask every vendor for its RTO and RPO in hours, not for the phrase "high availability". A number you can put in a contract is the only version of that answer that survives an audit.
  • The two questions that separate serious vendors from the rest: which cloud region holds the data, and who are the sub-processors. Both should be answerable in one sentence, in writing, without a call.
  • A certification badge on a website is not evidence. Ask for the certificate number, the issuing body and the scope statement, because a certificate can cover a head office and exclude the platform you are buying.
  • Run the security review in parallel with the functional evaluation, not after it. Reviews that start after a shortlist is chosen are the single most common reason a maintenance software rollout slips a quarter.

Our IT team will not approve a CMMS or OEE platform until it passes a security review. What do we actually need to collect?

Collect five things from every vendor on your shortlist, in writing, before you compare features. First, the information security certification with its certificate number, issuing body and scope statement, so you can confirm the platform itself is in scope and not just a corporate office. Second, a signed or signable data processing agreement naming every sub-processor. Third, the hosting region, stated as an actual cloud region rather than a continent. Fourth, the recovery objectives in hours: recovery time objective and recovery point objective, plus backup frequency. Fifth, the access control model: role based permissions, single sign-on support, and whether an audit log records who changed what.

Fabrico answers those five as follows: ISO 27001, ISO 9001 and ISO/IEC 20000-1 certification, a GDPR data processing agreement, hosting in an AWS EU region, a 4 hour recovery time objective and 4 hour recovery point objective with daily backups, and role based access control with SSO and SAML available plus a full audit log. Encryption is applied at rest and in transit, and the platform sits behind Cloudflare DDoS protection.

What an industrial software security review actually checks

Most manufacturers use a standard supplier questionnaire that was written for enterprise IT, then hand it to a plant team that has never filled one in. The six areas below are what those forms are really testing, translated into plant language.

1. Certification and scope. The reviewer wants an independent third party to have audited the vendor's security management system. In Europe that is normally ISO/IEC 27001. In North America a SOC 2 Type II report is more common. The two are not equivalent and neither is a substitute for the other, so ask which one a given vendor holds rather than assuming. Crucially, ask for the scope statement. A certificate can legitimately cover a company's development office while excluding a hosted service.

2. Data residency. Your machine data, work orders and employee names are personal and commercial data. The reviewer needs to know which legal jurisdiction physically holds them. "The cloud" and "Europe" are not answers. An AWS, Azure or Google Cloud region name is an answer. If you operate in the EU, this is also the question your data protection officer will ask first, and it is covered in more depth in our GDPR and data protection buyer guide for OEE and CMMS software.

3. Sub-processors. Every SaaS platform uses other vendors: a cloud host, an email service, an error monitoring tool, sometimes an AI provider. Each one is a place your data goes. A vendor that cannot produce a sub-processor list has not thought about this, and you cannot complete your own compliance record without it.

4. Availability and recovery. Two different numbers, routinely confused. Recovery time objective is how long the service can be down before it must be restored. Recovery point objective is how much data you can lose, measured in time. A vendor quoting 99.9 percent uptime has told you nothing about either. Ask for both in hours, and ask how often backups run.

5. Access control and audit. On a shop floor, dozens of people touch the same system, and some of them share a tablet. The reviewer wants role based access control so a technician cannot delete a plant, single sign-on so leavers lose access when HR disables the account, and an audit log so a disputed maintenance record can be traced to a person and a timestamp.

6. Integration surface. Every connection you add is a door. If the platform will sync with SAP PM, an ERP, or a historian, the reviewer wants to know how that connection authenticates and what it can reach. Read-only integrations pass review far faster than bidirectional ones, so know which you actually need before the meeting.

The 12 questions to send every vendor

Send these verbatim, to every vendor at once, and ask for written answers. Answers that arrive as a call invitation instead of a document are themselves a data point.

  1. Which information security certification do you hold? Please provide the certificate number, the issuing body and the scope statement.
  2. In which specific cloud region is our production data stored, and is any of it replicated outside that region?
  3. Please provide your current sub-processor list, including what each one processes.
  4. Can you sign our data processing agreement, or do you require yours to be used?
  5. What is your recovery time objective and your recovery point objective, in hours?
  6. How often are backups taken, how long are they retained, and when did you last test a restore?
  7. Is data encrypted at rest and in transit, and using what?
  8. Do you support single sign-on and SAML? Is that standard or a paid or custom configuration?
  9. Describe your role based access control model, and confirm whether an immutable audit log records configuration and record changes.
  10. How do integrations authenticate, and what scope of access does an integration credential have?
  11. What is your contractual support response time, and during which hours?
  12. On termination, in what format do we get our data back, and within how many days is it deleted from your systems and your backups?

Question 12 is the one buyers forget and the one procurement will insist on. Ask it early, because an unsatisfactory answer is much cheaper to discover in week one than in year three.

Three answers that should stop a purchase

"We are ISO 27001 aligned." Aligned is not certified. It means no external auditor has ever tested the claim. Ask for the certificate or treat the vendor as uncertified.

"We cannot share our sub-processor list." Under GDPR your organisation is the controller and remains accountable for where the data goes. A vendor unwilling to name its sub-processors is asking you to accept a liability you cannot quantify.

"We will get you those numbers later." Recovery objectives either exist as tested figures or they do not exist. A vendor that has run a restore test knows its numbers immediately.

Where Fabrico fits

Fabrico is a combined CMMS and OEE platform built and hosted in the EU. On the five review items above, the answers are: ISO 27001, ISO 9001 and ISO/IEC 20000-1 certified; a GDPR data processing agreement available; hosting in an AWS EU region; a 4 hour recovery time objective and 4 hour recovery point objective with daily backups; and role based access control with SSO and SAML available for custom configurations, plus an audit log. Encryption covers data at rest and in transit, and Cloudflare provides DDoS protection.

On the operational side, the contractual support response is under 2 hours, and the interface ships in English, Bulgarian, German, French and Polish, which matters when a security review is followed by a works council conversation about who can read what. Integration is available through a REST API, webhooks, Excel import and export, and a bidirectional SAP PM sync including S/4HANA.

Two things Fabrico does not claim, because being straight about them saves everyone a round of clarification: there is no SOC 2 report, and there is no offline mode. If your reviewer's form requires SOC 2 specifically, say so at the start of the evaluation rather than at the end.

Worked example: sequencing a review so it does not cost you a quarter

Take a supplier running three plants, evaluating a combined CMMS and OEE platform, with a corporate InfoSec form of roughly 40 questions and a data protection officer who must sign off separately.

Run sequentially, the usual shape is six weeks of functional demos, then the security pack goes out, then two to four weeks of back and forth per vendor, then legal review of the data processing agreement. Total elapsed time before a contract can be signed is commonly three to four months, and the plant team spends most of it waiting.

Run in parallel, the 12 questions above go out in week one, alongside the first demo invitations. By the time the functional shortlist is down to two vendors in week four, both security packs are already with InfoSec and the data processing agreement is with legal. The same three to four months compresses to roughly six to eight weeks, and, more importantly, you never discover in month three that your preferred vendor fails a mandatory control.

The cost of the parallel approach is one extra email in week one. The cost of the sequential approach is a rollout that starts a quarter late, which on a plant chasing an availability problem is a quarter of losses you had already agreed to stop.

How this connects to the rest of the evaluation

A security review tests whether a vendor can be trusted with your data. It does not test whether the platform will be used. Those are separate failures with separate causes, and both have to be cleared. If your IT function is small or shared across sites, our guide to choosing OEE and CMMS software without a dedicated IT department covers who actually carries the review work. If your plants sit in Germany, Austria, the Netherlands or France, the works council approval guide for OEE monitoring covers the parallel approval that catches most teams by surprise. For the functional requirements themselves, start from the CMMS software RFP template, and for the metric definitions the platform has to produce, see the OEE for manufacturing guide.

If you want the Fabrico security pack, including the certificate scope statements and the data processing agreement, book a demo and ask for it by name. It is sent as documents, not as a slide.

Frequently asked questions

Is ISO 27001 or SOC 2 better for a CMMS vendor?

Neither is better, they answer different questions. ISO 27001 certifies that a management system for information security exists and is audited against a standard. SOC 2 Type II is an attestation report describing how specific controls operated over a period, and it is read as a document rather than checked as a badge. European buyers usually require ISO 27001, North American buyers usually require SOC 2. Ask which one your reviewer's form actually requires before you shortlist, because it can eliminate vendors.

What is a reasonable RTO and RPO for maintenance software?

For a CMMS or OEE platform, a recovery time objective and recovery point objective in the range of a few hours is normal, and daily backups are standard. What matters more than the specific figure is that the vendor states it as a number and has tested a restore. Judge the answer by whether it is precise, not by whether it is impressive.

Do we need a data processing agreement if the software only holds machine data?

Almost certainly yes. A CMMS holds work orders assigned to named technicians, timestamps of who did what, and often shift patterns. That is personal data under GDPR regardless of how much machine data sits beside it. Assume you need a data processing agreement and confirm the scope with your data protection officer.

Who should own the security questionnaire, IT or maintenance?

Maintenance should send it and IT should score it. The maintenance team knows which integrations are genuinely needed, which is what determines the risk surface, and IT knows which answers are acceptable. When IT owns the whole process the questionnaire often demands controls the plant does not need, and when maintenance owns the whole process the answers get accepted without being checked.

How long should a vendor take to answer these 12 questions?

A vendor that has been through enterprise reviews before will return written answers within a few working days, because the documents already exist. Weeks of delay usually means the pack is being written for the first time. That is not automatically disqualifying for a young vendor, but it tells you what to expect from support later.

Last updated: 7 August 2026.

Latest from our blog

Define Your Reliability Roadmap
Validate Your Potential ROI: Book a Live Demo
Define Your Reliability Roadmap
By clicking the Accept button, you are giving your consent to the use of cookies when accessing this website and utilizing our services. To learn more about how cookies are used and managed, please refer to our Privacy Policy and Cookies Declaration