How to Answer a Customer Security Questionnaire (Without Losing the Deal)

Ulises Paiz

Ulises Paiz is the owner and sole engineer at Ghosxt, a Salinas, CA managed IT and cybersecurity provider. He holds an M.S. in Cybersecurity and Information Assurance (WGU, 2026) and nine industry certifications including CompTIA SecurityX, CySA+, and Microsoft AZ-104, with prior DoD and federal contractor infrastructure experience. More about Ulises →

The email usually arrives right when a deal is going well. A new customer, often a larger company, a school, a healthcare group, or a government contractor, has a vendor onboarding step, and part of it is a spreadsheet with 80 to 300 questions about your security. Do you enforce multi-factor authentication? Do you encrypt laptops? Who can access our data? How fast do you report a breach?

For a small business this can feel out of proportion, and it can stall a signed-off deal for weeks. It does not have to. A security questionnaire is a risk screen, and with a little preparation you can answer one in an afternoon. Here is how to do it well.

Why customers send them

Your customer is trying to answer one question: if this vendor is breached, how badly does it hurt us? Attackers routinely go after smaller suppliers because they are easier to reach, which is why larger organizations now screen vendors before giving them access to data or systems. We cover the same pressure from the other side in our guide to vendor and third-party risk management.

That context helps you answer. The reviewer is not looking for perfection. They are looking for evidence that you have the basics covered and that you will be honest with them if something goes wrong.

1. Answer honestly, and show what you do instead

The most expensive mistake is answering "yes" to a control you do not really run. Questionnaires often become part of the contract, so an unsupported answer can turn into a liability after an incident. It also tends to surface later in a follow-up call, where an inflated answer costs you more trust than a "no" ever would.

When the honest answer is no, write the "no" and add one sentence of context: what you do instead, and when you plan to close the gap. For example: "We do not run a 24/7 security operations center. Endpoints are monitored by a managed detection and response service, and alerts are reviewed by our engineer." Reviewers read many of these. A candid, specific answer reads as competence.

2. Gather evidence once, reuse it everywhere

Most questionnaires ask for the same dozen things in different words. Collect the evidence once and keep it in a single folder:

  • Identity: a screenshot of your multi-factor authentication policy for all users, and your admin account list. Our multi-factor authentication guide covers what good looks like.
  • Devices: proof of disk encryption, endpoint protection, and patching, such as a management console export.
  • Backups: a description of what is backed up, how often, and the date of your last restore test.
  • Policies: short written policies for acceptable use, access control, and incident response. Our incident response plan guide is a good starting point.
  • People: a record of security awareness training and your onboarding and offboarding steps.

Attaching a screenshot to a "yes" answers the reviewer's next question before they ask it. It also forces you to confirm the control really is on.

3. Build an answer library

After your first questionnaire, save every answer in one document or spreadsheet, grouped by topic: access control, data protection, incident response, vendors, and business continuity. When the next one arrives, you will find that most questions are already answered. Copy the answers over, check each one against how things work today, and write fresh responses only for what is new.

Two practical rules keep the library trustworthy. Date every answer so stale ones are obvious, and give one person ownership of it. Review the whole library at least once a year, and again whenever you change a major tool such as your email platform or backup provider.

It also helps to ask a customer whether they will accept a completed standard questionnaire, such as the SIG Lite or the CAIQ, instead of their own custom form. Some will, which saves everyone time.

Common mistakes to avoid

  • Letting the questionnaire sit for a week because it feels like a chore. Slow responses signal slow security.
  • Copying answers from a template written for a company ten times your size.
  • Answering about the tools you plan to buy rather than the ones you run today.
  • Having several people answer different sections with no final review.

The takeaway

Treat the security questionnaire as part of selling. Answer honestly, back your answers with evidence, and keep a reusable library, and what feels like a roadblock becomes a short, repeatable step that signals to customers that you take their data seriously. If the exercise reveals gaps, such as no enforced MFA or no tested backups, you now have a clear, customer-driven reason to fix them.

Frequently asked questions

How long should it take to complete a vendor security questionnaire?

Once you have a reusable answer library, most questionnaires take a few hours rather than days. The first one is the slow one, because you are gathering evidence and writing honest answers from scratch. After that, each new questionnaire is mostly copying, updating, and flagging what is new.

Do I need SOC 2 or ISO 27001 to answer a security questionnaire?

No. Many customers send questionnaires precisely because a small vendor has no formal audit report. A clear, accurate description of the controls you actually run, backed by screenshots or policy documents, is usually enough for smaller deals. Some larger customers will require a formal attestation, and it is better to learn that early.

What if the honest answer is no?

Say no, then say what you do instead and when you plan to close the gap. Reviewers read hundreds of these and are far more suspicious of a perfect score than of a candid one with a short remediation note. Claiming a control you do not run is also the answer that can create contract and liability problems later.

What are SIG Lite and CAIQ?

They are standardized security questionnaires. The SIG Lite comes from the Shared Assessments program and the CAIQ from the Cloud Security Alliance. If a customer accepts a completed standard questionnaire instead of their own custom spreadsheet, offering one can save time, but ask first which format they will accept.

Who should sign off on the answers?

One accountable person, usually the owner or whoever runs IT. Questionnaires often become part of the contract, so the person answering should be able to stand behind each statement and check it against how the business actually operates.

Got a customer questionnaire sitting in your inbox?

Ghosxt helps small businesses document the controls they already run, close the gaps a questionnaire exposes, and answer with evidence. You talk directly to the owner. See current pricing, our cybersecurity services, or IT for audited companies.

Book your free assessment

Prefer to talk first? Email sales@ghosxt.com or call (831) 204-0501.

Book free assessment Call (831) 204-0501