Who should read this: the person at a 40-person company who just received a spreadsheet with several hundred rows from a prospect’s procurement team, with a deadline attached.
The spreadsheet is not really a test of your security. It is a test of whether you have already written down what you do. Those are different things, and the difference is why the same document takes one company two days and another six weeks.
The three you will actually receive
Most questionnaires are one of three standard formats, or somebody’s edited copy of one.
| Format | Questions | First time | With an answer library |
|---|---|---|---|
| VSA, Vendor Security Alliance | 100 to 140 | 1 to 2 weeks | 1 to 2 days |
| CAIQ, Cloud Security Alliance | around 260 | 2 to 3 weeks | 2 to 4 days |
| SIG Core, Shared Assessments | 800 plus | 4 to 8 weeks | 1 to 3 weeks |
Two things in that table are worth staring at.
The first is that the range within a row is larger than the range between rows. A SIG with a library behind it is faster than a CAIQ without one. The format you receive matters far less than whether you have answered anything before.
The second is who sends what. VSA turns up when you sell to technology companies. CAIQ turns up when the buyer is cloud-centric. SIG turns up in financial services, and it reaches well beyond security into financial condition, enterprise risk and environmental factors, which is why it is four times the size.
What all of them are really asking
Strip the formats away and three questions remain. Every row in every one of those spreadsheets is a rephrasing of one of them.
1. Do you know what you have? Assets, data, suppliers, who has access to what. Perhaps a third of any questionnaire is this question in different clothes.
2. Can you show that a control is running, not just written? Not “do you have a password policy” but “when did you last review access, and can you show me”. This is the half that catches companies who have documents but no records, the distinction set out in evidence that assembles itself.
3. What happens when something goes wrong? Detection, response, notification to them specifically, recovery, and how fast.
A company that can answer those three properly can answer any questionnaire. A company that cannot will answer each one from scratch, differently, forever.
Why your answers are inconsistent, and why that is the real risk
Here is the failure that costs deals, and it is not a bad answer. It is three different answers.
The questionnaire arrives, gets split by section, and lands on three people. The engineer answers the technical rows from what is actually deployed. Someone in operations answers the process rows from what the policy says. A founder answers the governance rows optimistically because the deal matters.
The result is internally contradictory. Row 40 says access reviews are quarterly. Row 210 says annually. Row 15 says you have a documented incident response plan, row 300 says incident response is handled ad hoc by the CTO.
Reviewers on the other side notice. Their job is comparing answers, and inconsistency reads as either disorganisation or evasion. Both are worse than a plain “we do not do this yet, here is the compensating control and the date we will”.
Being honest about a gap almost never loses a deal at this size. Being caught contradicting yourself sometimes does.
What a certification actually saves you
This is the argument for ISO 27001 that nobody makes properly, because it is commercial rather than regulatory.
Holding ISO 27001 pre-answers a large share of every one of these formats:
| Format | Covered by SOC 2 | Covered by ISO 27001 |
|---|---|---|
| VSA | 70 to 80% | 75 to 85% |
| CAIQ | 60 to 70% | 75 to 80% |
| SIG | 40 to 50% | 50 to 65% |
Note the pattern. ISO 27001 outperforms SOC 2 on all three, and by the widest margin on CAIQ. Note also that even ISO 27001 tops out around 85%, and on a SIG it covers barely half. There is no certificate that makes questionnaires go away.
What the certificate really does is different from the coverage number. It gives you a control set with owners, statuses and evidence attached, so the residual questions have somewhere to be answered from. Without that, the coverage percentage is theoretical.
The full picture of getting there without a security team is in ISO 27001 for a company without a security team, and the honest budget is in what ISO 27001 actually costs an SME.
Build the answer library, once
The practical fix is unglamorous and it works.
Keep answers keyed to controls, not to questionnaires. The unit is “how we do access review”, not “row 212 of the CAIQ from that customer in March”. When the next format arrives, you map its rows onto your controls rather than starting again.
Every answer carries a date and an owner. An answer library that nobody maintains is worse than none, because it confidently reproduces a stale answer. The date tells you which entries to check before sending.
Write the gaps down as gaps, with a plan. The rows where the honest answer is no are the ones worth pre-writing carefully, because you will be asked them again. “Not currently, mitigated by X, planned for Q2” is a reusable answer. Silence is not.
Keep the scope boundary in the library too. A large share of questionnaire disputes are really scope disputes: the customer asks about a system that is not in the environment serving them. Being able to say clearly what is in and out is the same discipline as scope and the Statement of Applicability.
This is also the point of holding the control set, the evidence and the answers in the same place. Not because a tool beats a spreadsheet in principle, but because an answer that lives next to its control gets updated when the control changes, and an answer in last year’s spreadsheet does not.
The questions worth asking back
Two, and they save more time than any tooling.
“Which sections apply given what you are buying?” Most questionnaires are sent unedited. If you are supplying a single SaaS module, the physical security of your manufacturing sites is not in scope and the reviewer will usually agree if asked. This is a normal conversation, not pushback.
“Would our ISO 27001 certificate and Statement of Applicability satisfy part of this?” Frequently yes, particularly for the governance sections. It is worth asking before spending two weeks retyping the same content in their format.
The technical reality: the questionnaire is not the test
Worth being clear-eyed about what this exercise measures, because it shapes where you should invest.
A questionnaire tests documentation. It asks whether a control exists and whether you can describe it. Every question in every one of those formats can be answered truthfully by a company where logging is configured and never queried, where the vulnerability scanner runs monthly into a report nobody reads, and where no restore has ever been timed. All of those are yes answers.
The moment the test changes is the follow-up call. A security reviewer who is paying attention asks second questions: how long has your longest-open critical finding been open, when did you last restore from backup and how long did it take, what would tell you an account had been compromised. Those have numbers as answers, and the numbers are either there or they are not.
So the answer library gets you through the spreadsheet, and it is worth building. It does not get you through the call. That takes detection and exposure management actually running, producing findings with owners and deadlines, which is the same gap described in what a certificate leaves open. An independent security audit is the quickest way to find out which of your questionnaire answers would survive the follow-up question.