A Customer Sent You a Security Questionnaire: How to Answer Without Losing the Deal

The email that lands three days before signature

Your salesperson forwards a message from the buyer’s procurement analyst. Subject line: “Third-Party Information Security Assessment — Tier 2, required before contract execution.” Attached is a spreadsheet with four tabs and 214 numbered rows. Column C is a dropdown limited to Yes, No, Partially, and N/A. Row 41 asks whether you maintain a documented information security policy reviewed annually by management. Row 88 asks for your mean time to detect. The email closes with “please return by Friday.”

You are an eleven-person company. You do not have a mean time to detect.

The panic reaction is to mark everything Yes and get it back Friday. That is the worst thing you can do, and this article exists mostly to stop you. Next worst is leaving rows blank, or letting the salesperson fill it out alone.

What is actually happening: someone inside your buyer is accountable for the fact that your software will touch their data, and needs a file that justifies onboarding you to their auditor. A documented gap with an owner and a date is something they can write down. A blank is not. A confident lie is worse than either, because it follows you after the deal closes.

Direction of travel matters. Our guide to running a vendor security assessment on your own suppliers and the broader piece on third-party and supply chain risk management put you in the assessor’s chair. This one is the mirror image — you are the one being assessed.

Which security questionnaire did you get: SIG Lite, CAIQ, VSA, or a homemade spreadsheet

SIG and SIG Lite. The Standardized Information Gathering questionnaire comes from the Shared Assessments Program, is reissued annually, and is built as one question set with scoping presets — Lite, Core, and Detail — across roughly 21 risk domains. SIG Lite runs to about 125 questions and is a breadth pass; SIG Core is an order of magnitude larger, asking not just whether a control exists but how it is implemented and who reviews it. The 2026 release added AI governance mapped to ISO 42001, operational resilience content, and deeper NIST SP 800-171 mapping. A Lite means the buyer scoped you as lower risk; a Core means they think you touch something they answer for.

CAIQ. The Consensus Assessments Initiative Questionnaire comes from the Cloud Security Alliance and maps to the Cloud Controls Matrix; v4 is current, with a shorter CAIQ Lite for smaller providers. Its useful feature is that you can publish a completed one — CSA STAR Level 1 is a free self-assessment submission to the STAR Registry. STAR Level 2 is the audited tier, built on a SOC 2 attestation or ISO 27001 certification.

VSA. The Vendor Security Alliance questionnaires — VSA-Core and VSA-Full — are free, updated annually, and came from a buyer coalition including Airbnb, Atlassian, Dropbox, and Uber. They are scoped to a service rather than a whole company, so they carry fewer irrelevant rows.

The homemade spreadsheet. Most small businesses get this one: something the buyer assembled internally, often from a SIG they received years ago. Duplicate questions, rows that cannot apply to you, no answer key — and the most negotiable of the four.

What the reviewer actually weights

Reviewers do not score all 214 rows equally. A short list carries most of the weight, because those controls show up in breach post-mortems and in the buyer’s own insurance renewal. Get them right and a dozen soft “no” answers elsewhere will not sink you.

Control areaWhat the buyer is really askingA good small-business answer
Multi-factor authenticationCan one stolen password reach our data?“Yes. Enforced for all users on all cloud services via Conditional Access in Microsoft Entra ID, administrators included. No legacy authentication exemptions.”
Encryption in transit and at restDo you know where our data sits?“Yes. TLS 1.2+ in transit, AES-256 at rest. Laptops encrypted with BitLocker, enforced and reported through Intune.”
Access review and offboardingSomeone quits Friday. Is their access gone Monday?“Yes. Offboarding checklist owned by the Operations Manager; accounts disabled and sessions revoked same business day. Access reviewed quarterly.”
Logging and retentionIf we ask what happened on March 4th, can you tell us?“Yes. Microsoft Purview Audit retains records 180 days on current licensing; extended retention under evaluation.”
Backup and tested restoreNot whether you back up. Whether you have ever restored.“Yes. Daily backups, 30-day retention. Last full restore test 12 June 2026, restore time 3h40m, documented.”
Incident response and notificationHow fast do we hear from you?“Yes. Written IR plan, last tabletop April 2026. Notification within 48 hours of confirming an incident affecting your data.”
SubprocessorsWho else touches our data because we hired you?“Yes. List published on our security page, maintained by the CTO. 30 days’ notice of additions.”
Data handling and egressCan staff copy our data somewhere you cannot see?“Partially. Sharing is internal-only by default; broader controls in our data loss prevention rollout.”
Cyber insuranceIs there money behind the indemnity clause?“Yes. $2M cyber liability. Carrier and policy period available under NDA.”

How to answer a security questionnaire when the honest answer is no

This is the technique the article is built around, three parts in one cell:

No, not today + the compensating control that exists now + a dated remediation commitment with an owner.

Reviewers accept this far more often than owners expect, because it gives them something to file. What they reject is a blank, an evasion, or a Yes that unravels at the contract’s first security review. Three rewrites, none of which apologize, over-explain, or promise anything without a date:

The rowThe weak answerThe answer that works
“Does the organization perform annual penetration testing by an independent third party?” “Yes.” (You ran a vulnerability scan in 2024.) “No. We run authenticated vulnerability scanning monthly and remediate critical findings within 14 days. An external penetration test is scoped and budgeted for Q1 2027, owner J. Reyes, CTO; we will share the summary.”
“Is there a formally documented information security policy approved by management and reviewed annually?” “We take security very seriously.” “Partially. We maintain written acceptable use, access control, and incident response procedures approved by the owner in March 2026, not yet consolidated into one reviewed policy set. Consolidation complete by 31 January 2027, owner: Operations Manager.”
“Do you maintain a SIEM with 24/7 monitoring?” “Yes,” because your MSP mentioned a dashboard once. “No. We are an 11-person company with no 24/7 SOC. Compensating controls: Microsoft Defender for Business with automated remediation on all endpoints, alerting to two named administrators, and Entra ID risky sign-in policies set to block. Managed detection and response under evaluation for 2027.”

Negotiate scope before you answer 214 rows

It is legitimate — and reads as competence, not evasion — to reply before you start: “We provide a hosted scheduling application. We do not process cardholder data, operate a data center, or have physical access to your facilities. Can you confirm sections 5, 9, and 12 are out of scope?” Most reviewers agree; a wrongly scoped section makes work for them too.

When you mark a row N/A, put the reason in the comment column. “N/A” alone gets bounced back. “N/A — we neither store nor transmit cardholder data; payments are handled by Stripe as merchant of record” gets accepted.

Answering yes when it is not true is the mistake that outlives the deal

A completed questionnaire is rarely a casual document. It is typically incorporated into the contract by reference, or backed by a warranty that information provided during due diligence is accurate. A false answer there is a misrepresentation: it hands the buyer a breach claim, a termination right, and in a bad scenario a fraud argument that survives your limitation-of-liability cap.

The same exposure sits on the insurance side. In July 2022 Travelers sued in the Central District of Illinois to rescind a $1 million cyber policy issued to International Control Services, alleging the application attested that MFA was required across systems when it was deployed only on the firewall; the parties agreed to void the policy the following month. A casual attestation can remove your coverage at the moment you need it. Read our guide to small business cyber insurance alongside this one — the two forms overlap heavily and your answers must match.

If you already sent it back and the answers were wrong

Most people find this article after the spreadsheet went out. Pull your copy, re-read column C honestly, and flag every Yes you cannot evidence today. Then send a short, unemotional correction to the same contact: “In reviewing our 14 August submission for accuracy we identified three responses that overstated our position. Corrected responses attached, with compensating controls and remediation dates.” Correcting proactively is nearly always survivable; being discovered is not. If the contract is already signed and the misstatement is material, have your attorney review the wording first.

SOC 2, ISO 27001, and the artifacts that end the vendor assessment loop

Should you just get certified? Honest ranges, from 2026 practitioner cost breakdowns rather than sales pages:

SOC 2 Type II. Under 50 people, published 2026 ranges put auditor fees at roughly $15,000–$45,000, readiness at $5,000–$15,000, a compliance platform at $7,500–$25,000 a year, and the expected penetration test at $5,000–$15,000 — first-year all-in commonly $30,000 to $75,000. Timeline is 6–12 months, because a Type II requires an observation window (typically 3 to 12 months) during which controls must actually operate, plus 4–8 weeks of fieldwork.

ISO/IEC 27001. Small and mid-sized first-year certification is commonly quoted at $15,000–$60,000 including gap analysis, implementation, and the audit, on a three-year cycle with surveillance audits in years two and three.

CAIQ and STAR Level 1. The cheap option people miss. Completing a CAIQ and publishing it to the CSA STAR Registry costs nothing but time. No serious reviewer mistakes it for an audit, but it converts “a spreadsheet we filled out ourselves” into “our published self-assessment against a recognized control framework.”

The decision rule: get audited when deals require it, not before. If two enterprise prospects have told you in writing that a SOC 2 report is a procurement requirement, the math works. Otherwise spend the money on controls and answer honestly. A well-answered SIG Lite with three dated remediation items closes deals; a SOC 2 that ate a year of budget while the file server still has no MFA does not.

Build the answer library once, then 80% of the next one is done

Create one spreadsheet — the security answer library — with these columns: question topic, canonical answer text, status (Yes / Partially / No), evidence and where it lives, owner, last reviewed, next review. Populate it while completing your first questionnaire, writing each answer generically enough to reuse and specifically enough to be true. The next one becomes a matching exercise, not a cold start; the fifth takes an afternoon.

Two rules keep it from rotting: every answer has a named owner and a review date no more than six months out. A stale library is how honest companies end up making false statements: you answer “yes, quarterly access reviews” in February because it was true last October.

The public trust page that deflects a share of them entirely

Publish a page on your own site — /security or /trust — with your posture summary, your subprocessor list and what each processes, data location and retention, your notification commitment, and a named security contact. Mid-market buyers especially will often accept that page instead of a questionnaire; the rest use it to pre-fill rows.

Who owns this, and why it cannot be the salesperson

The salesperson gathers the questionnaire, tracks the deadline, and manages the relationship. They must not author the answers: their pay depends on the deal closing, and column C is where optimism becomes a contractual representation. The right owner is whoever actually runs your systems — an operations manager, the office manager who administers the tenant, or your fractional IT lead — with the owner signing off before it goes back. If you use an outside firm, make questionnaire response an explicit deliverable — our guide to hiring a cybersecurity contractor or consultant covers scoping that without paying enterprise rates for spreadsheet work.

What to do this week

  1. Monday. Acknowledge receipt, ask for a realistic due date (ten business days is normal), and request confirmation of which sections are out of scope for the service you provide.
  2. Tuesday. Name the internal owner in writing — not the salesperson — and give them two hours a day this week.
  3. Wednesday. Reality-check the nine control areas above in the admin console rather than assuming — MFA enforcement in Entra ID Conditional Access or Google Workspace 2-Step Verification, audit log retention, and when you last actually restored a backup.
  4. Thursday. Answer the heavy rows first, using no-plus-compensating-control-plus-date. Leave nothing blank; every N/A gets a reason.
  5. Friday. Owner and principal review the sheet together with one instruction: find every Yes we cannot evidence today and downgrade it. Send it back.
  6. Next week. Copy every answer into the reusable library with an owner and a review date, then draft the trust page. If most answers were “no,” work through the first 90 days of cybersecurity for a new business — the fastest route to turning that column into yes’s.

The questionnaire is not a test you pass or fail. It is a request for an accurate picture, read by someone who can spot an inflated one. Give them that picture with dates attached.

Get the IT Policy Bundle

Five editable policy templates covering the control areas security questionnaires ask about most — so you can answer yes with a real document behind it.

Get it on Gumroad →

Similar Posts