How to answer a vendor security questionnaire (when a buyer just sent you one)

A practical playbook for small SaaS teams. Written for the first few questionnaires, when you have no dedicated security person.

A prospect's procurement team has emailed a spreadsheet with a deadline. Perhaps it is 80 questions, perhaps 400. The deal is real and the clock is running. This guide walks through what to do in the first hour, the first two days, and the last mile before you send it back.

1. Triage in the first hour

Do not start answering. Spend an hour deciding what you are dealing with.

2. Assign owners before you assign answers

The usual failure is one person (often the CTO) answering everything from memory. Instead, split by domain and name one owner per block:

DomainTypical owner in a small SaaS
Infrastructure, encryption, backups, loggingCTO or lead engineer
Access control, MFA, SSO, offboardingEngineering or IT lead
HR security, training, background checksFounder or people lead
Privacy, DPA, subprocessors, retentionFounder or whoever handles contracts
Insurance, legal, certificationsFounder / finance

Pick one person as the single editor of the final file. Everyone else sends answers to them. That person also decides ties.

3. Gather evidence first, then answer

For each domain, collect what actually exists, in this order of strength:

  1. Third-party attestations: SOC 2 report, ISO certificate, pen-test report or summary letter.
  2. Written, approved policies with version and date.
  3. System configuration you can screenshot or export (cloud console encryption setting, MFA enforcement, backup schedule).
  4. Past answers someone senior approved.
  5. Memory. Treat this as a lead, not evidence. Go and check.

Give each document a stable code and version (for example SEC-POL-007 v2.0) so every answer can say where it came from. If a reviewer asks "where does this come from?", you should be able to answer in ten seconds.

4. Answer rules that keep you out of trouble

Rule of thumb: every "Yes" should have a document, a setting or a person who can prove it. If none exists, it is not yet a "Yes".

5. How to say "no" or "in progress" honestly

Most buyers expect gaps from a small vendor. What they react badly to is a gap discovered later. A clear, specific "not yet" with a compensating control usually reads better than a vague "Yes". The pattern is:

  1. State plainly what you do not have.
  2. State what you do instead.
  3. If a date is real and committed, give it. If not, leave it out.

Example only (replace with your own facts). Question: "Do you undergo an annual independent penetration test?"

We do not yet have an independent annual penetration test. We run automated dependency and container scanning on every build, and we review findings weekly. We are scoping a third-party test and can share the scope and, once complete, the summary letter under NDA.

Example only. Question: "Do you hold SOC 2 Type II?"

No. We have not completed a SOC 2 audit. Our controls are documented in our security policy set (available under NDA), and we can complete your questionnaire in full and walk through our controls on a call.

Notice what is missing: no "industry-standard", no "best-in-class", no promise we cannot keep. If you say "in progress", make sure something is in fact in progress: a signed engagement with an auditor, a tool being configured, a ticket with an owner.

6. Consistency checks before you send

Inconsistent answers are the most common self-inflicted wound. Before sending:

7. Deadline tactics

8. After you send it

Save the final answers as your approved answer library, with the source document and version next to each. Next time, you start from 60 to 80 percent done rather than from zero. Put a review date on the library, since policies change. See what enterprise buyers ask SaaS companies for the 20 topics worth preparing evidence for in advance.

A short checklist

If you are weighing tools to speed this up, this comparison of options sets out the trade-offs without a sales pitch.

Got a questionnaire on your desk? Run the free complexity check (the file stays in your browser), or start a free workspace and try 10 answers on your own documents. Prefer to look first? Try the 97-question DemoCo demo, no signup.