← All postsHow-to

Security questionnaire: answer it once, reuse it forever

Every enterprise buyer sends a different questionnaire asking the same forty things. The teams that answer in a day maintain an answer library; everyone else starts from nothing each time.

How-toS

A security questionnaire is the set of questions a prospective customer sends before buying software or a service, asking how you protect their data: access control, encryption, backups, incident response, subprocessors, personnel vetting, business continuity. It arrives late in the sales cycle, it has a deadline, and it is usually the last thing standing between the deal and signature.

The questions are broadly the same everywhere. The formats are not. One buyer sends a spreadsheet of four hundred rows, another a portal, another a two-page Word document written by someone who copied it from a template in 2019. Answering the same facts repeatedly, from scratch, by asking whichever engineer is least busy, is where the time goes — and it is entirely avoidable.

Build an answer library, not a folder of past questionnaires

  • One entry per question, phrased canonically, with the approved answer.
  • The evidence behind it: policy, screenshot, report — attached rather than referenced from memory.
  • An owner per topic area, because the person who can approve an access-control answer is not the person who owns backups.
  • A review date. Answers rot: the retention period changed, the subprocessor list moved, the penetration test is from two years ago.
  • A short form and a long form of each answer, since some questionnaires give you a cell and others a page.
  • A record of which customer received which version, which matters when a claim about your controls is later examined.

The standard questionnaires are worth pre-filling

Rather than waiting for whatever arrives, complete the common frameworks in advance and offer them proactively: the CAIQ for cloud services, the SIG for financial-sector buyers, and the shorter vendor questionnaires most enterprises derive from them. Buyers frequently accept a completed standard questionnaire in place of their own, and offering one before it is asked for changes the dynamic — you are supplying a document rather than being audited. The same applies to a summary of your own controls: a two-page security overview answers most small-buyer questionnaires outright.

Never answer a question with more confidence than the evidence supports. A questionnaire answer is a representation made during a sale, and if a later incident shows the control did not exist, the answer becomes the problem. Where a control is planned but not implemented, say so with a date — buyers accept that far more often than people expect.

Who answers a security questionnaire, and how fast

The fastest teams give one person ownership of the process, not of the answers. That person routes questions to the topic owners, chases, assembles and sends; the technical owners approve their own areas and nothing else. The slowest arrangement is the common one, where a sales engineer forwards the spreadsheet to engineering with a deadline and no structure. Target a turnaround measured in days, and measure it — the number is a sales metric, not an administrative one, because a questionnaire sitting for three weeks is a deal cooling.

Where the library lives

Ettex Records holds the answer library with the evidence attached per question and the review dates visible, Ettex Sheets carries the questionnaire being worked on with a status per row so the outstanding questions are obvious, and Ettex Docs holds the information security policy and the rest of the documents the answers point at, with version history so the version in force when an answer was given is recoverable. The two standard forms worth pre-filling are covered in caiq and vpat.

Being direct: this is a records and documents approach, not a security compliance platform. There is no control monitoring, no evidence collection from your infrastructure, no trust portal and no automated questionnaire answering. Those products exist and, past a certain volume of questionnaires, are worth the cost. What this replaces is answering the same question for the eleventh time.

Frequently asked

What is a security questionnaire?

A set of questions a prospective customer sends about how you protect their data — access control, encryption, backups, incident response, subprocessors and continuity — usually late in the sales cycle.

How do you answer them faster?

Maintain an answer library: one canonical answer per question with its evidence, an owner and a review date, and reuse it instead of restarting each time.

Should we pre-fill standard questionnaires?

Yes. Completing the CAIQ or SIG in advance and offering it proactively often satisfies a buyer’s own questionnaire and changes the exchange from an audit to a document handover.

What if a control is not implemented yet?

Say so, with a date. An overstated answer becomes a serious problem if an incident later shows the control did not exist.

MI
Written by Maria I.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.