The 200-question security questionnaire, and how to stop dreading it
The email always lands on a Friday. Your account exec forwards it with a cheerful "shouldn't take long, right?" and attached is a spreadsheet with 200 rows, six tabs, and a column headed Evidence that nobody on your side knows how to fill in.
We have watched this moment kill more deals than any actual vulnerability. Not because the company was insecure — because the questionnaire went back late, contradicted itself, or answered "yes" to a control that a five-minute call would have proven was a "sort of."
The mistake almost everyone makes
The instinct is to answer fast and generously. You want the deal. So the spreadsheet comes back with a wall of "Yes," a few "Compensating controls in place," and one heroic "N/A" on the question about your incident response plan.
Then the customer's security team reads it. These people do this for a living. They can smell an aspirational "Yes" from across the building, and the moment they catch one, they stop trusting the other 199. Now you are in a call defending answers you filled in at 6pm, and the deal has slipped a quarter.
Answer it slowly and truthfully the first time and you answer it once. Answer it fast and you answer it three times, with a nervous VP on the third call.
Treat it as a findings exercise, not a form
Here is the reframe that changes everything: the questionnaire is a free penetration test of your paperwork. Somebody has handed you a prioritised list of exactly what your buyer is worried about. That is worth more than the deal.
So when we run one of these with a client, we split every row into three buckets:
- True today. We have the control, and we can point at the evidence. Screenshot, config export, policy with a real revision date. Answer it and move on.
- True in two weeks. We do not have it yet, but it is a genuinely small piece of work. Enforce MFA on that last admin console. Turn on the audit log we forgot about. We note it, we do it, and we answer honestly with a date.
- Not true, and that is a decision. Sometimes the honest answer is "we do not do this, and here is why it does not apply to how we are built." A buyer will accept that far more often than you would think — as long as you say it plainly instead of hiding it behind an N/A.
The second bucket is where the value is. Half the "gaps" in a first-time questionnaire are not gaps in your security, they are gaps in your evidence. You do rotate credentials, you just never wrote down that you do. Fixing that is an afternoon.
Write the answer a human wants to read
A control answer has three parts and most people only write the first:
- What you do. "Production access requires SSO with hardware-backed MFA."
- How it is enforced. "Enforced by our identity provider; there is no local password path to production."
- How you would prove it. "Access logs and the IdP policy are available under NDA."
That third line is what a reviewer is actually asking for. "Yes" tells them nothing. "Yes, enforced this way, provable that way" tells them you have thought about it, which is the entire thing they are trying to find out.
Answer once, reuse forever
The last piece: keep the answers. Not in the customer's spreadsheet — in your own store, tied to the actual control and the actual evidence. The next questionnaire reuses eighty percent of it, and the twenty percent that is new becomes your next fortnight of work.
That is the quiet benefit nobody sells you on. Do this properly two or three times and the questionnaire stops being a fire drill. It becomes the roadmap your security programme never had budget to write. The buyer paid for it. You just have to read it that way.
If you are staring at one of these right now and the deadline is Thursday, that is usually the wrong week to start building a programme — but it is the right week to answer honestly and turn the gaps into a plan. We have sat on the far side of that call more than once. It goes better than you think.