What enterprise buyers ask SaaS companies: the 20 topics and the evidence to prepare
Based on common patterns in vendor security reviews, not on any single buyer's list. Your buyer's questions will differ.
Most security questionnaires, whatever the format, are the same twenty or so topics asked in different words. If you prepare a short, dated, accurate piece of evidence for each, you will answer the next questionnaire in a fraction of the time and, more importantly, give answers that agree with each other. Below, each topic has what buyers usually want to know and what to have ready.
Data protection
1. Encryption in transit
Buyers ask which protocol versions you use and whether internal traffic is encrypted. Prepare: a note of minimum TLS version on public endpoints, a scan or configuration export, and what applies between internal services.
2. Encryption at rest
They ask what is encrypted (database, object storage, backups, laptops) and how keys are managed. Prepare: cloud console settings for storage and database encryption, who manages the keys (you or the provider), and whether backups inherit it.
3. Data retention and deletion
How long you keep customer data, what happens at contract end, and whether backups are purged. Prepare: one authoritative number, in one policy, matching your DPA. This is the topic where old answers and new policies most often disagree, so check them against each other.
4. Data residency
Where data is stored and processed, and whether you can restrict it to a region. Prepare: the regions you use, and whether support staff or subprocessors access data from elsewhere.
5. Privacy, GDPR and the DPA
They want a signed data processing agreement, how you handle data subject requests, and transfer mechanisms. Prepare: your standard DPA, privacy policy, and a short note on how you handle access and deletion requests. If you are not sure whether something applies to you, ask a qualified privacy lawyer rather than guessing.
6. Subprocessors
The list of third parties that touch customer data, what each does, and how you notify of changes. Prepare: a maintained subprocessor list with purpose and location, and a stated notification process.
Access and people
7. Multi-factor authentication and SSO
Whether staff use MFA, and whether customers can use SSO or MFA on your product. Prepare: identity provider enforcement settings, and a clear statement on which SSO options your product supports and on which plans.
8. Access control and reviews
Least privilege, role-based access, and periodic review of who can see production. Prepare: an access policy, and a dated record of your last access review (even a simple spreadsheet export with reviewer and date).
9. Endpoint security
Disk encryption, screen lock, patching, anti-malware, and device management on staff laptops. Prepare: a device policy and a screenshot or export from whatever tool enforces it. If you rely on policy without enforcement, say so.
10. HR security and training
Background checks, confidentiality agreements, security awareness training, and offboarding. Prepare: the template employment clause, training completion records, and a leaver checklist.
Resilience and response
11. Backups
Frequency, retention, location, encryption, and whether restores are tested. Prepare: backup configuration, and a record of the last restore test, if one exists. Answer "we back up" and "we test restores" separately.
12. Business continuity and disaster recovery (RTO and RPO)
Targets for recovery time and data loss, and whether the plan has been exercised. Prepare: a DR plan with stated RTO and RPO that reflect what you can actually deliver. Do not copy a number from a template.
13. Incident response and breach notification
Whether you have a documented process, who is on call, and how fast you notify customers. Prepare: the incident response plan, a severity scale, and the notification commitment you are willing to be held to (and that your contracts match).
14. Logging and monitoring
What is logged, how long logs are kept, who can read them, and what alerts exist. Prepare: a short description of log sources and retention, with the actual retention setting.
Engineering
15. Secure development lifecycle
Code review, separation of environments, dependency scanning, secrets handling, change management. Prepare: a short SDLC document and evidence such as branch protection settings and scanner output.
16. Vulnerability management
How you find, rank and fix vulnerabilities, with target timelines. Prepare: a policy stating timelines by severity, and a recent scan summary. Only state timelines you meet in practice.
17. Penetration testing
Whether an independent party tests you, how often, and whether findings are fixed. Prepare: the report or a summary letter, plus a remediation record. If you have not had one, plan to say so plainly (see the example below).
Assurance and risk
18. SOC 2 and ISO 27001 status
Whether you hold a report or certificate, its scope and period, and whether it is current. Prepare: the report or certificate with dates, or an accurate statement of where you stand (not started, readiness assessment, audit window under way).
19. Insurance
Cyber liability and professional indemnity cover, and limits. Prepare: a certificate of insurance. Check limits directly with your broker rather than quoting from memory.
20. AI usage and training on customer data
Increasingly common: do you use AI features, which providers, and is customer data used to train models? Prepare: a one-page AI statement. Our guide to AI security questions covers this in depth.
Example of an honest answer when the evidence is missing
Example only. Replace with your own facts.
Question: Do you conduct regular access reviews of privileged accounts?
Answer: Not on a fixed schedule yet. Production access is limited to three engineers and is managed through our identity provider. We review the list whenever someone joins or leaves, and we are moving to a documented quarterly review. We can share the current list of privileged roles under NDA.
How to turn this list into an evidence pack
- Create one document per topic area (or a few combined policies), each with a code, version, owner and last-reviewed date.
- Put the facts in once. Retention periods, RTO and RPO, TLS version, subprocessor list and similar facts belong in one place. Everything else references them.
- Mark gaps as gaps. A short "not yet in place" list is useful. It tells you what to say and what to fix.
- Set a review date. A policy older than a year without review reads as neglected, even when still true.
- Keep a library of approved answers, each linked to its source document.
When a questionnaire arrives, the response playbook covers triage, owners and deadline tactics. The evidence above is what makes that process quick.
Priorities if you only have a week
If you have limited time before a deal review, work on these in order, because they are the topics most likely to block sign-off: encryption in transit and at rest, MFA and access control, incident response and notification, backups and recovery, subprocessors, and retention and deletion. Then pen testing and SOC 2/ISO status, which are less about writing and more about what you can honestly state.
Not sure how your documents measure up? The 24-question readiness check shows where your evidence is thin. To size a real file, use the free analyser, or start a free workspace. You can also see a worked example in the demo.