Passwords are stored in DES, but i suspect that is not what they are really asking since that only covers data at rest for one specific data point, most business users are more concerned about SSL protection of over the wire than a rogue employee at a known vendor stealing a password from the data layer.
Also if you do not use SSL, DES is irrelevant, since every time the client logs in they are sending the password in clear text.