
Answering customer security questionnaires
Security questionnaires arrive from enterprise customers during procurement, from existing customers at renewal, and from insurers. They are long, they overlap heavily, and they are usually answered under time pressure by whoever is available.
The result is a familiar pattern: the same questions answered slightly differently each time, by different people, with no record of what was said last time. That inconsistency is itself a risk, because a customer comparing this year's answers to last year's will ask about anything that changed.
The fix is to build the answers once, properly, and treat them as a maintained asset.
Build an answer library
Almost every questionnaire is a rearrangement of the same underlying questions. Once you have answered forty or fifty of them well, most future questionnaires are assembly rather than authorship.
Structure the library by topic rather than by questionnaire:
- Governance and policy
- Access control and identity
- Data protection and encryption
- Network and infrastructure security
- Application security and development
- Logging, monitoring and incident response
- Business continuity and recovery
- Supplier and third-party management
- Physical security
- Personnel security and training
- Compliance and certification
For each entry, hold the canonical answer, a longer version for when detail is requested, the evidence that supports it, an owner, and a last-reviewed date.
The date field matters more than it looks. It is what stops an answer that was true two years ago being sent to a customer today.
Write answers that survive scrutiny
The temptation under deadline is to answer optimistically. This is the single most damaging habit, because these answers frequently end up in contracts as representations, and a customer audit that contradicts them is a much worse conversation than a qualified answer would have been.
Three principles.
Answer what was asked. If the question is whether you encrypt data at rest, the answer is yes or no for the systems in scope, not a paragraph about your commitment to security.
Qualify honestly rather than answering no. "Partially: implemented for production systems, scheduled for the remaining internal systems by Q3" is a better answer than either an unqualified yes or a bare no. It is accurate, it shows a plan, and most reviewers accept it.
Never claim a certification you do not hold. Including implying one. "Aligned with ISO 27001" and "certified to ISO 27001" are very different statements and reviewers know the difference. If you are working towards certification, say so with a date.
Attach evidence up front
The slowest questionnaires are the ones that generate follow-up requests. Pre-empting them shortens the cycle considerably.
Keep a current pack ready to attach:
- Current certifications, with certificate numbers and expiry dates.
- Your most recent penetration test summary: the executive summary, not the full technical report.
- An architecture or data flow overview.
- Sub-processor list, if you handle customer data.
- Business continuity and incident response summaries.
- Insurance certificates if relevant.
Check the dates on this pack quarterly. An expired certificate attached to a questionnaire creates a worse impression than no attachment.
Handle the questions you cannot answer well
Every organisation has areas that are weaker than they would like. How you handle those questions matters more than the underlying gap.
What works: acknowledge the gap, describe the compensating control, state the plan and the date.
What does not work: leaving it blank, answering something adjacent, or claiming it is not applicable when it plainly is. Reviewers see hundreds of these and recognise evasion immediately. A gap with a plan is normal. A gap that appears to be hidden raises questions about everything else.
Assign owners, not a single person
Questionnaires typically get dumped on one person (often in sales, sometimes in engineering) who does not know all the answers and guesses at the rest.
Assign each topic area an owner who is genuinely responsible for that domain. They maintain their section of the library. When a questionnaire arrives, most answers are already written and only the unusual ones need routing.
This also fixes the consistency problem, because there is one source rather than several people's recollections.
Keep it current
The library decays quietly. Three habits keep it useful:
Review on a schedule. Every answer reviewed at least annually, with owners notified. Stale answers are the main risk.
Update on change. New certification, new sub-processor, architectural change, incident. Anything that would change an answer should trigger an update at the time, not at the next review.
Record what was sent. Which customer received which version and when. When they come back at renewal, you need to know what you told them, particularly if something has changed since.
The wider benefit
Building the library well has a side effect that is often more valuable than the time saved: it surfaces the gaps.
Working through a comprehensive questionnaire honestly, with owners, produces a list of things you cannot currently claim. That list is a better input to your security roadmap than most formal assessments, because it is defined by what your customers actually care about rather than by a generic framework.
Several organisations find their first serious questionnaire response is the most useful security review they have done, precisely because it is answered under the discipline of having to be true.
Want this looked at in your own environment?
Talk to an expert →Keep reading

