Solutions /  The situation

The questionnaire is not the problem. The deal behind it is.

Someone in your company is currently in a spreadsheet, guessing. The questions assume you have policies, an owner, an asset inventory, an access review, an incident plan: artefacts, not intentions. You can answer it honestly and lose the deal, or answer it optimistically and sign something you cannot defend later.

Get your free exposure assessment

Your customer is an enterprise, and their procurement team is being measured on supply-chain risk. They are not testing your security; they are collecting evidence they can put in a file. Every quarter more of your pipeline arrives with a questionnaire attached, and the questions get sharper each time.

What it is costing you

  • A deal in late stage stops moving, and the forecast slips a quarter, not because you lost, but because nobody answered.
  • Your CTO or VP R&D spends days reconstructing answers from memory instead of shipping.
  • Answers you cannot evidence become contractual representations. You are now on the hook in writing for controls you do not operate.
  • The next customer sends a different questionnaire, and you start over.

What we do

01

We take the questionnaire off your team

Send us the file. We answer it: every section, in your customer's format, with evidence references rather than adjectives. You review and sign; you do not draft.

02

We separate what is true, what is fixable this week, and what is a real gap

Most questionnaires split three ways: controls you already run but never documented, controls that are a two-week fix, and genuine gaps. You get that map in plain language before you answer anything.

03

We close the fast gaps so the answers become true

Policies, access reviews, asset inventory, an incident plan with a name on it. These are the questions that block deals, and they are the cheapest ones to make honest.

04

We build the answer library so the next one takes days, not weeks

One evidence base, mapped once, reused across ISO 27001, SOC 2, Amendment 13 and every customer questionnaire that follows.

05

We keep it current

Answers rot. Staff leave, cloud accounts change, vendors get added. The ROC keeps the evidence live so the answer you gave in March is still true in September.

How long it takes. A first-pass answer set usually comes back in days; making the weak answers genuinely true takes weeks, and we will tell you up front which is which.

How do you answer a customer security questionnaire without lying?

Answer only what you can evidence, and fix the rest before you sign. Split the questionnaire into three groups: controls you already operate but have not documented, gaps you can close in one to two weeks (policies, access reviews, asset inventory, an incident plan with a named owner), and real gaps that need a remediation plan. Document group one, close group two, and give the customer a dated plan for group three. Enterprise procurement accepts a credible plan; it does not accept an answer that turns out to be false at audit.

How long does it take to complete a 300-question security questionnaire?

An experienced team can produce a complete first-pass answer set in a few days. The work that takes longer is making weak answers true: typically two to six weeks for the controls that block deals, such as access reviews, asset inventory, documented policies and an incident response plan. Companies answering it themselves for the first time usually take four to eight weeks, most of it spent reconstructing evidence rather than writing answers.

Do we need ISO 27001 to answer a security questionnaire?

No. A certificate shortens the questionnaire but is not required to answer it. What is required is evidence: policies, an asset inventory, access controls, vendor reviews and an incident plan. If a specific customer contract demands ISO 27001 or SOC 2, that is a separate commercial requirement, and the evidence you build to answer the questionnaire is the same evidence the certification will need, so the work is not wasted.

Find out how far you have drifted.

A free exposure assessment. We connect to what you already have, and show you what your dashboards are not showing you.

No obligation. Results in 10 business days.