How to Answer a Client Security Questionnaire

A big client sent a security addendum and you have five people. What each question really asks, what a small team can honestly answer, and how to say no.

By the founder — infrastructure engineer, 15 years (bio) · Updated

What's in this guide
  1. Why the questions feel so oversized
  2. The principle that gets you through
  3. What each recurring question is actually asking
  4. Before you sign
  5. The reusable version

A prospective client — bigger than you, with a procurement department — has sent a security questionnaire. It has forty questions, uses words like “subprocessor” and “control objective,” and it’s blocking a contract you want.

You have six people and no compliance team. Here’s how to get through it honestly.

Read this first. This guide is educational, not legal advice, and it is not a compliance certification. A security questionnaire attached to a contract is a binding legal document: your answers may become contractual representations. Never copy an answer from this page (or anywhere else) unless it is literally true of your business today. A false answer can breach the contract, void your cyber-insurance cover, and create personal liability. When the addendum has legal weight — and it usually does — have a lawyer review it. We are not affiliated with any of the frameworks named below.

Why the questions feel so oversized

Most enterprise questionnaires are cut down from one of three industry frameworks, all of which were designed for assessing large cloud vendors:

That matters for your sanity: the questionnaire wasn’t written for a six-person firm. Whole sections will be irrelevant to you, and saying so plainly is a legitimate, expected answer. Procurement teams read hundreds of these; a clear “not applicable — we have no data centres, all systems are SaaS” is far better received than a vague yes.

The principle that gets you through

Answer truthfully, then say what you do instead.

The three-part answer that works:

  1. The honest status — yes, no, or not applicable
  2. What you actually do — the compensating control, in plain language
  3. What’s planned, with a date — only if it’s genuinely planned

Example — “Do you have SOC 2 Type II certification?”

“No. We are a 6-person firm and do not hold SOC 2 or ISO 27001 certification. We operate documented controls covering access management, MFA enforcement, backup and restore testing, and employee offboarding, and we can provide evidence of each on request. We have no current plans to pursue SOC 2.”

That answer loses no deals that a lie would have won — and it doesn’t create a representation you can’t support later.

What each recurring question is actually asking

Access control and MFA

Asking: can a stolen password get into your systems? Small-team honest answer: MFA enforced on email and all business systems that support it, via your identity provider. Evidence: admin-console screenshot of the enforcement policy.

Password management

Asking: are credentials shared, reused, or sitting in a spreadsheet? Honest answer: a team password manager with per-person accounts and shared vaults; no credentials in chat or email. Evidence: the member list from your admin view.

Access revocation / offboarding

Asking: can former staff still log in? This is one of the most heavily weighted questions, and one small firms most often fail. Honest answer: a written offboarding procedure executed within X hours of departure. Evidence: the checklist plus audit-log entries from the last departure. Generate one with our offboarding checklist tool.

Encryption

Asking: in transit and at rest. Honest answer for a cloud-first firm: TLS in transit via the SaaS platforms you use; at rest via those platforms’ own encryption plus full-disk encryption (FileVault/BitLocker) on every company device. Say that you rely on your providers’ encryption — that’s normal and expected.

Backup and recovery

Asking: could you recover client data, and have you proved it? Honest answer: versioned backups separate from primary storage, with a stated restore-test cadence and the date of the last test. If you’ve never tested a restore, the honest answer is no — and that’s fixable this week.

Incident response and breach notification

Asking: what happens in the first hours, and when do they hear about it? Watch this one carefully — it usually carries a contractual notification deadline (often 24, 48, or 72 hours). That is a commitment you must be able to meet. Honest answer: a documented contact list, a named decision-maker, and agreement to the stated notification window if you can genuinely meet it.

Endpoint protection and patching

Asking: are devices protected and updated? Honest answer at small scale: built-in protection (Microsoft Defender, macOS XProtect/Gatekeeper) with automatic OS and browser updates enforced. If they name a specific EDR product and you don’t run one, say so — don’t stretch.

Security awareness training

Asking: are your people trained on phishing? Honest answer: documented annual training, even if it’s a 30-minute session with a written one-pager. Undocumented training is, for questionnaire purposes, no training.

Subprocessors and fourth parties

Asking: who else touches their data through you? Honest answer: a list of the SaaS providers that would process their data — your email/office platform, file storage, CRM, backup provider. Keep this list current; it’s also useful internally.

Data location, retention, and deletion

Asking: where does the data live and when does it go away? Honest answer: the regions your providers store in, plus your own retention and deletion practice. A commitment such as “client files deleted 90 days after engagement close” is strong, cheap, and genuinely reduces your risk — but only promise what you’ll actually do.

Logging and monitoring

Asking: would you know if something happened? Honest answer at small scale: you rely on the audit logs and security alerts built into your SaaS platforms, with admin alerts enabled. Nobody expects a six-person firm to run a SIEM.

Cyber-liability insurance

Asking: can you cover a loss? Often a hard requirement with a stated minimum. Honest answer: your policy and coverage limit, or that you don’t carry it. If you’re buying cover to satisfy this, work through the cyber-insurance readiness guide first — the two questionnaires overlap almost completely.

Background checks, physical security, secure development

Frequently not applicable to a small remote services firm, and saying so is fine. Don’t invent a physical-security programme for an office you don’t have.

Before you sign

The reusable version

Keep a single dated document with your standard answers, refreshed whenever your stack changes. The 10-Minute Security Check covers most of the underlying controls, and the evidence folder template tells you what to screenshot for each.

Framework details above are from public documentation published by Shared Assessments, the Cloud Security Alliance, and the Vendor Security Alliance; question counts and versions change with each annual release — verify against the current edition. We are not affiliated with any of them. This page carries no affiliate links.

Get the small-business security foundations

Seven short emails: MFA, password sharing, real backup, restore testing, and the access list. Free options at every step. Unsubscribe in one click.