How to Answer a Security Questionnaire (Without Losing a Week)
A 200-question spreadsheet lands in your inbox. It is blocking a deal. Somebody has to answer it, and that somebody is probably you.
This is a guide to doing that well, not quickly at the expense of accuracy, because a wrong answer in a security questionnaire is a false representation to a customer, and those have a way of resurfacing during an incident.
First: work out what you are actually holding
Not all questionnaires are the same, and knowing which one you have tells you how much work it is.
CAIQ (Consensus Assessments Initiative Questionnaire). The Cloud Security Alliance's standard, currently v4. Roughly 260 questions across 17 control domains, structured as yes/no/NA plus a comment. The most common questionnaire in SaaS procurement, and the most worth investing in. Answering CAIQ well means most other questionnaires become copy-paste.
SIG and SIG Lite. Shared Assessments' standard. SIG Core runs to thousands of questions; SIG Lite is a few hundred. If you receive SIG Core and you are under fifty people, it is entirely reasonable to ask whether SIG Lite would satisfy them. Often it will.
VSA (Vendor Security Alliance). Shorter, more opinionated, more focused on what you actually do than on what you have documented.
Bespoke. Someone's internal spreadsheet, usually assembled from the above plus whatever their last incident taught them. These are the awkward ones: unpredictable layout, unpredictable scope, and frequently questions that do not apply to you at all.
Second: read the whole thing before answering anything
This feels like a waste of time and is not.
Questionnaires repeat themselves. "Do you encrypt data at rest?" on the infrastructure tab and "Describe your encryption controls" on the data tab want the same answer, and if you write them on different days you will write them differently. Two contradictory security statements in one document is worse than a blank cell. It invites scrutiny of everything else you wrote.
Read through, group the duplicates, and answer each group once.
Third: separate "no" from "I don't know"
These feel similar when you are staring at a blank cell at 6pm. They are completely different.
"We do not do this" is a legitimate, finished answer. You do not offer SSO on the starter tier. You do not have a 24/7 SOC. Say so plainly. Buyers are far more comfortable with a clear no than a vague yes, and a vague yes is the one that becomes a problem later.
"I don't know" means someone has to go and find out. Flag it, route it to whoever knows, and move on. Do not fill it with something plausible.
The temptation to write something that sounds reassuring is strongest exactly where you are least certain. Resist it there specifically.
Fourth: answer from documents, not memory
Every answer should be traceable to something written down: your SOC 2 report, your access control policy, your incident response runbook. If you cannot point at the source, you are describing what you believe is true rather than what is.
This matters practically. When the customer's security team asks a follow-up in three weeks, "our access control policy section 4.2 says X" is an answer. "I think we do that" is not.
Fifth: keep the answers
This is the part almost everyone skips, and it is the one that compounds.
The first questionnaire takes days. The tenth should take an hour, but only if you kept the first nine. A maintained answer library means:
- The same question gets the same answer every time, so your submissions do not contradict each other across customers.
- A correction made once is applied everywhere, instead of being re-typed into each new spreadsheet.
- You can see which answers are stale. "We are SOC 2 Type II certified" reads fine until the report lapses.
Without one, every questionnaire starts from nothing and you re-derive the same answers forever.
The parts that actually take the time
If you are budgeting effort, it is rarely the writing:
- Finding the questions. Bespoke spreadsheets hide them in unpredictable columns, across multiple tabs, mixed with headings and instructions.
- Chasing subject-matter experts. The encryption question needs the infrastructure lead; the sub-processor question needs whoever owns vendor management. Every round-trip is a day.
- Assembling evidence. "Attach your most recent penetration test report" is not answered by prose. Someone has to find the file.
- Reviewing. You are signing your company's name to every statement in the document.
Automation helps most with the first and the last. It helps least with the second, which is a people problem.
What good looks like
A questionnaire you can return in a day, where every answer traces to a document you can produce, nothing contradicts anything else, and the answers you wrote are still there the next time someone asks.
That is achievable. It just requires treating the answers as an asset rather than as output.
FillTrust reads your security documentation and drafts answers from it, keeps every answer you approve, and reuses them automatically next time. See how it works.