Home Blog You've Been Sent a Vendor Security Questionnaire - What Now?

Security

You've Been Sent a Vendor Security Questionnaire - What Now?

Posted by Kevin Yun|August 12, 2026

A vendor security questionnaire means a buyer has moved you from "interesting" to "we need to check this before procurement will sign." It is a buying signal wearing intimidating clothes. The correct first move is not to start answering questions; it is to spend an hour working out what you have been sent, who is asking, what they will do with it, and what deadline you can actually hold.

This article covers how to triage a questionnaire in the first hour, who should own it at a company with no security team, what to do in the first forty-eight hours, how to handle the questions where your honest answer is no, and how to make sure the second questionnaire costs a fraction of the first.

The first hour is triage, not answering

Open the file and establish five things before you write anything.

What format is it. A standard template like a SIG or a CAIQ means the questions are known quantities and much of your answer is reusable. A bespoke spreadsheet written by the buyer means bespoke work. A vendor portal that requires you to create an account and answer in a web form means you cannot easily draft offline, and you should find out early whether it supports bulk import.

How long it actually is. Count populated rows, not the file's reputation. Questionnaires range from thirty questions to several hundred, and the difference determines everything downstream.

Who is asking, and why now. A security engineer running a genuine review behaves differently from a procurement analyst clearing a checklist. If the questionnaire arrived immediately after a pricing conversation, it is a gate. If it arrived from an unfamiliar name with no context, ask the account contact what triggered it.

What the real deadline is. The stated date is often the analyst's internal target rather than a hard stop. Ask. Buying two weeks at the start is trivially easy and asking for an extension at the deadline is not.

What else they want alongside it. Questionnaires usually travel with requests for a SOC 2 report, an ISO 27001 certificate, a penetration test summary, a DPA, or an architecture diagram. Finding out on day one that they also want a pen test report is very different from finding out on day nine.

Name one owner before the end of day one

The single most reliable predictor of a questionnaire being returned late is that it belonged to everybody. It sits in a shared drive, three people each answer the sections they find easy, the hard ones stay blank, and the deadline arrives with the document eighty percent done — which for this purpose is the same as zero percent.

So before anything else, put one name against it. That person does not need to be your most technical; they need to be the person who will notice on Thursday that nobody has answered the backup questions. Coordination is the larger half of this job and it is not an engineering skill. Our guide to who should own security questionnaires at a small SaaS company covers the ownership models in depth, including where each one breaks as you grow.

The first forty-eight hours

Four things, in order.

Acknowledge and set a date. Same day. A short reply confirming receipt and giving a realistic return date buys more goodwill than a fast partial answer.

Split the questions into three buckets. Known and documented; known but not written down; genuinely unknown. The first bucket is transcription. The second is a conversation with an engineer. The third is the real work, and it is usually a small fraction of the total. Sizing these three buckets tells you whether this is a two-day task or a two-week one, and you cannot know that without doing the split.

Gather the evidence pack in parallel. Whatever documents were requested alongside the questionnaire, start collecting them immediately, because they often depend on other people or on vendors who take days to respond.

Flag the noes early. If there is a question you will have to answer no to, and it looks material, raise it with the buyer before you return the document rather than letting them discover it. Reviewers respond very differently to a known gap raised proactively than to one they find themselves.

The questions you have to answer no to

Every small vendor has them. No formal penetration test yet. No SOC 2. No dedicated security personnel. No twenty-four-hour incident response rota.

A no is not automatically disqualifying. What determines the outcome is whether the reviewer believes you understand the gap. Three answers to the same question land very differently:

"No." — Reads as a gap with nothing behind it.

"No, but we take security seriously." — Reads worse, because it is a gap plus a deflection.

"No formal penetration test to date. We run automated dependency and container scanning on every build, our infrastructure is single-tenant per customer, and we have budgeted a third-party test for Q1. Happy to share the scanning configuration." — Reads as a company that knows its own posture.

The third answer takes ninety seconds longer to write and changes the reviewer's assessment of everything else in the document. The pattern is: state the gap plainly, describe what compensates, give a timeline if one genuinely exists, and offer the evidence. Do not invent the timeline. A reviewer who is told Q1 will check in Q2.

Making the second one cheap

The first questionnaire is expensive because you are discovering your own controls in writing for the first time. The second should not be, and for most small companies it is, because the answers were left inside a completed spreadsheet in a folder named after the customer.

Keep the answers somewhere they can be found by question rather than by customer. Even a simple document organised by topic — encryption, access control, backups, subprocessors, incident response, data retention, data residency — turns the next questionnaire from research into retrieval.

Publish the parts that can be public. A large portion of what buyers ask is not confidential: your subprocessor list, your DPA, your data retention policy, your security overview, how you handle data subject requests. Anything sitting at a public URL is an answer you supply with a link rather than a paragraph, and it is an answer the buyer can check without asking. Our GDPR compliance checklist covers much of the documentation that overlaps with these questions.

Common mistakes when responding to a security questionnaire

Starting to answer before triaging. An hour of scoping tells you the format, the length, the real deadline, and the accompanying document requests. Answering first means discovering the pen test request on day nine.

Accepting the stated deadline without asking. It is frequently an internal target. Asking for two extra weeks at the start is easy; asking on the due date is not.

Handing the whole document to an engineer. They will context-switch on it for weeks. Flag the questions needing technical judgment and book a session for those specifically.

Overstating to avoid a no. A generous yes that unravels under follow-up costs more than the gap would have. Reviewers have seen gaps before; they have not forgiven contradictions.

Filing the completed answers under the customer's name. Organise by topic instead, or the next questionnaire costs what this one did.

FAQ

How long does a vendor security questionnaire take to complete?

It depends almost entirely on length and on whether you have answered one before. A short template with existing documentation can be a day. A first-time Core-tier assessment with several hundred questions and no prior answer bank is realistically two to three weeks of part-time work across several people.

Do I need SOC 2 to answer a security questionnaire?

No. Questionnaires exist partly because not every vendor has a formal attestation. A SOC 2 report shortens the process considerably because it answers many questions by reference, but its absence is a gap to explain rather than a disqualification.

Who should fill out a security questionnaire at a small company?

Split it. Someone in operations or on the deal owns coordination, tracking, and return. Your most senior engineer answers the flagged technical questions in a bounded block of time. Single ownership by an engineer is the most common way these stall.

Can I refuse to complete a security questionnaire?

You can, and it usually ends the deal at any buyer with a formal procurement process. A more productive path is to negotiate scope: offer a published security page, a completed standard questionnaire, or an existing attestation in place of a bespoke document.

Closing thought

The uncomfortable thing about a first security questionnaire is that it is not really testing your security. It is testing whether you can describe your security, in writing, on a deadline, without contradicting yourself. Those are different capabilities, and the second one is what small vendors typically lack — not because their systems are bad, but because nobody has ever had to write it down.

The way that stops being painful is to write it down once, publicly, and keep it current. ComplyDog hosts a compliance portal on your own domain covering your DPA, subprocessor list, data subject request handling, and security posture, so the recurring questions arrive at a page instead of an inbox. It does not answer the questionnaire. It removes the portion of the questionnaire you were about to answer for the fourth time.