The pattern is familiar to anyone selling into companies of any size. The deal goes well, the champion is enthusiastic, terms are agreed — and then a spreadsheet arrives with 180 questions and the deal stops for three weeks.

Almost all of that delay is avoidable, and the avoidable part is preparation rather than compliance.

What the questionnaire is really for

Understanding the buyer's position changes what a good answer looks like.

The person sending it is usually not evaluating your security in any deep sense. They are discharging an obligation: someone in their organisation is accountable if a vendor causes an incident, and the questionnaire is the artefact proving diligence was done. They want it completed accurately and quickly so they can close their ticket.

Two consequences follow. First, speed is worth nearly as much as substance — a fast, honest “no, and here is what we do instead” often beats a slow, impressive answer. Second, an unanswerable question is worse than an unfavourable answer, because it leaves their obligation undischarged.

What actually gets asked

Questionnaires vary in length but converge on the same territory:

  • Data handling. What you collect, where it is stored, how long you keep it, who can access it, what happens on termination.
  • Access control. Authentication, internal access, offboarding, whether SSO exists.
  • Encryption. In transit and at rest, and key management if they are thorough.
  • Subprocessors. Who else touches the data. This is now asked almost universally and is the question most often unprepared for.
  • Incident response. Do you have a documented process and a notification commitment.
  • Business continuity. Backups, restore testing, availability history.
  • Compliance posture. Certifications, or a credible statement of where you are.
  • Personnel. Background checks, security training, contractor handling.

Prepare the answers once

The efficiency comes entirely from answering each question once and reusing it. Build an internal document organised by the categories above, with a maintained answer for each, dated and owned.

Three rules make it durable:

  • Write answers as prose, not as yes/no. You can shorten prose to fit a checkbox; you cannot expand a checkbox into an explanation.
  • Date every answer. Security posture changes and stale answers are how honest companies end up making false statements.
  • Name an owner. An unowned document is out of date within two quarters.

Answering honestly when the answer is no

This is where most companies handle themselves badly, in both directions — either overclaiming, or apologising so heavily that a minor gap reads as a serious one.

The effective structure is: state the gap, state the compensating control, state the plan.

“We do not currently hold SOC 2 Type II. We run [specific practices], and we have scoped an audit for [timeframe].”

That is a completely acceptable answer for most buyers below enterprise, and it is far better than either a vague deflection or a paragraph of anxiety. Buyers are used to gaps. They are not used to clarity about them.

A related point on severity: many questionnaire items are nice-to-haves rather than blockers, and treating an optional item as a crisis creates deal friction that did not need to exist. See ranking security gaps properly.

Publishing your way out of some of them

The highest-leverage move is making the questionnaire unnecessary for smaller deals. A public security page answering the common questions lets a buyer discharge their obligation without sending anything.

Worth publishing:

  • Where data is stored, by region
  • Encryption in transit and at rest, stated plainly
  • A current subprocessor list
  • Retention and deletion policy
  • Your incident notification commitment
  • Certification status, including honestly stated absences
  • A security contact address that is monitored

This page also functions as a trust signal for buyers who never ask — see what buyers check before they trust your site and which signals reduce deal friction.

The documents worth having on the shelf

Beyond the answer bank:

  • A one-page security overview for the champion to circulate internally.
  • A DPA template you are willing to sign. Available on request is fine; being asked and having nothing is not.
  • An architecture diagram showing data flow at a level you are comfortable sharing.
  • Whatever audit artefacts you hold, with a defined process for sharing them.

The real cost of being unprepared

It is not the questionnaire itself. It is that an unprepared response signals that nobody has thought about this before, which prompts the buyer to look harder — and looking harder finds more. A prepared response ends the enquiry; an improvised one extends it.

Our Trust & Security Audit assesses questionnaire readiness from the outside, ranking each gap by whether it will actually block a deal. It is a passive external read, not a penetration test, and involves no intrusive testing.