ArmourIQ LogoArmourIQ
Cyber News

How to Answer a Security Questionnaire

By ArmourIQ Security TeamOctober 1, 20268 min read
Guides

Sooner or later a customer you want will send you a security questionnaire: a list of questions about how you protect data, sometimes a few dozen, sometimes several hundred. The deal usually pauses until you send it back. If your security is not written down, the first one is painful. This is a practical guide to answering one well, and to making sure the next one takes hours rather than days.

What a security questionnaire is, and why you are getting one

A security questionnaire is how a prospective customer checks that you will not become their next breach before they trust you with their data or connect you to their systems. It usually appears during procurement or vendor onboarding, often just before a contract is signed. The larger the customer, the more detailed it tends to be.

Some arrive in a standard format. The most common are the SIG (Standardized Information Gathering) questionnaire from Shared Assessments, which is long and widely used by financial institutions and large enterprises; the CAIQ (Consensus Assessments Initiative Questionnaire) from the Cloud Security Alliance, aimed at cloud providers; and the VSA (Vendor Security Alliance) questionnaire, a shorter set focused on technology vendors. Many buyers skip the standards and send their own spreadsheet instead. Investment firms meet the same thing in another form, when allocators and institutional clients run operational due diligence that asks these questions directly.

Why the first one is hard

The questionnaire itself is rarely the real problem. The questions assume you already have written policies, a named owner for security, and evidence you can point to. When a firm does not have those yet, the questionnaire simply exposes the gap, and the rush to answer becomes a rush to build the programme under deal pressure. That is the worst time to do it.

A practical way to answer

The approach below works whether you have a mature programme or you are starting from very little.

1. Read the whole thing first, then triage. Before answering anything, go through every question and sort it into three groups: answers you can give now, answers that need evidence you have to locate, and things you genuinely do not do. This tells you the real size of the job and stops you rewriting answers later.

2. Answer truthfully, and never overclaim. A security questionnaire usually becomes part of the contract, so a generous yes you cannot back up is a liability, not a shortcut. If you do something only partially, say so plainly. Accuracy is what protects you later.

3. Tie each answer to evidence. For every control you claim, know where the proof is: the policy document, the configuration, the access log, or an attestation such as a SOC 2 report or ISO 27001 certificate if you hold one. Buyers increasingly ask for the evidence, not just the yes.

4. Handle gaps with a plan, not a bluff. When the honest answer is not yet, say what you are doing about it and by when. Most buyers accept a clear remediation plan far more readily than they forgive a claim that turns out to be untrue.

5. Build an answer library as you go. Keep every answer, with its evidence, in one place. The first questionnaire is slow; the tenth should mostly be assembly. This one habit turns questionnaires from a recurring fire drill into a routine task.

6. Have the right person review it before it goes back. Someone who understands both the technical reality and the commitment being made should check the final answers. A wrong answer sent to a customer is hard to walk back.

Where SOC 2 and ISO 27001 help

A recognised attestation or certification does not answer the questionnaire for you, but it shortens it. A SOC 2 Type II report or an ISO 27001 certificate lets you answer whole sections by reference and shows that an independent party has checked your controls. It is worth pursuing once questionnaires are a regular part of your sales cycle. Until then you can still answer honestly and well without one, and plenty of firms do.

For investment firms

If you are a registered investment adviser or a fund, the security questionnaire arrives as part of an investor or allocator's due diligence, and the same discipline applies. It also connects to your own obligations. Under the SEC's amended Regulation S-P, advisers are expected to oversee the service providers that handle client data, which means asking your own vendors the same kind of questions you are being asked. A single, current view of your controls serves both sides of that: the questions you answer and the questions you put to others.

What we recommend

The firms that handle questionnaires calmly are not the ones with the most controls. They are the ones that have written their security down once, keep it current, and can produce evidence on request. If questionnaires are slowing your deals, or you are staring at your first one, the useful work is to stand up that foundation: a right-sized security programme, the policies and evidence behind it, and a reusable answer set. That is advisory work we do with growing firms, and it tends to pay for itself the first time a deal does not stall.

Frequently asked questions

Frequently asked questions

What is the difference between a SIG, a CAIQ and a VSA?

They are three common standard questionnaires. The SIG, from Shared Assessments, is long and widely used by financial institutions and large enterprises. The CAIQ, from the Cloud Security Alliance, is aimed at cloud service providers. The VSA, from the Vendor Security Alliance, is a shorter set focused on technology vendors. Many buyers use their own custom spreadsheet instead of any of these.

Do we need SOC 2 or ISO 27001 to answer a security questionnaire?

No. A SOC 2 report or an ISO 27001 certificate makes questionnaires faster and more convincing, but you can answer honestly and completely without one. An attestation becomes worth the cost once questionnaires are a regular part of your sales cycle.

How long does a security questionnaire take to complete?

The first one is usually the slowest, because it doubles as an audit of what you have in place. Once you have documented your controls and built an answer library, later questionnaires are mostly reuse and take a fraction of the time.

What do we do if we cannot answer yes to a question?

Answer truthfully and add a short plan: what you do today, what you are putting in place, and by when. A clear remediation plan is almost always received better than an overstated yes you cannot evidence, which can come back on you once it is in the contract.

Can someone help us respond?

Yes. We help firms answer questionnaires accurately, build the policies and evidence behind the answers, and set up a reusable answer set so future ones are quick. The aim is to make questionnaires a routine task rather than a fire drill.

Conclusion

A security questionnaire is really a request for evidence that you take your customers' data as seriously as they do. Treat the first one as the prompt to write your security down properly, answer honestly, and keep the answers in one place. Do that, and questionnaires stop being the thing that holds up your deals and become a routine part of winning them.