How to Answer a Client Security Questionnaire
A big client sent a security addendum and you have five people. What each question really asks, what a small team can honestly answer, and how to say no.
What's in this guide
A prospective client — bigger than you, with a procurement department — has sent a security questionnaire. It has forty questions, uses words like “subprocessor” and “control objective,” and it’s blocking a contract you want.
You have six people and no compliance team. Here’s how to get through it honestly.
Read this first. This guide is educational, not legal advice, and it is not a compliance certification. A security questionnaire attached to a contract is a binding legal document: your answers may become contractual representations. Never copy an answer from this page (or anywhere else) unless it is literally true of your business today. A false answer can breach the contract, void your cyber-insurance cover, and create personal liability. When the addendum has legal weight — and it usually does — have a lawyer review it. We are not affiliated with any of the frameworks named below.
Why the questions feel so oversized
Most enterprise questionnaires are cut down from one of three industry frameworks, all of which were designed for assessing large cloud vendors:
- SIG (Standardized Information Gathering, from Shared Assessments) — SIG Core runs to 850+ questions; SIG Lite is the trimmed set, around 150. Updated annually.
- CAIQ (Consensus Assessments Initiative Questionnaire, from the Cloud Security Alliance) — v4 has 261 questions mapped to 197 control objectives across 17 domains; CAIQ Lite is 124.
- VSA (Vendor Security Alliance) — publishes VSA-Full and VSA-Core, aimed specifically at SaaS vendor risk, updated annually.
That matters for your sanity: the questionnaire wasn’t written for a six-person firm. Whole sections will be irrelevant to you, and saying so plainly is a legitimate, expected answer. Procurement teams read hundreds of these; a clear “not applicable — we have no data centres, all systems are SaaS” is far better received than a vague yes.
The principle that gets you through
Answer truthfully, then say what you do instead.
The three-part answer that works:
- The honest status — yes, no, or not applicable
- What you actually do — the compensating control, in plain language
- What’s planned, with a date — only if it’s genuinely planned
Example — “Do you have SOC 2 Type II certification?”
“No. We are a 6-person firm and do not hold SOC 2 or ISO 27001 certification. We operate documented controls covering access management, MFA enforcement, backup and restore testing, and employee offboarding, and we can provide evidence of each on request. We have no current plans to pursue SOC 2.”
That answer loses no deals that a lie would have won — and it doesn’t create a representation you can’t support later.
What each recurring question is actually asking
Access control and MFA
Asking: can a stolen password get into your systems? Small-team honest answer: MFA enforced on email and all business systems that support it, via your identity provider. Evidence: admin-console screenshot of the enforcement policy.
Password management
Asking: are credentials shared, reused, or sitting in a spreadsheet? Honest answer: a team password manager with per-person accounts and shared vaults; no credentials in chat or email. Evidence: the member list from your admin view.
Access revocation / offboarding
Asking: can former staff still log in? This is one of the most heavily weighted questions, and one small firms most often fail. Honest answer: a written offboarding procedure executed within X hours of departure. Evidence: the checklist plus audit-log entries from the last departure. Generate one with our offboarding checklist tool.
Encryption
Asking: in transit and at rest. Honest answer for a cloud-first firm: TLS in transit via the SaaS platforms you use; at rest via those platforms’ own encryption plus full-disk encryption (FileVault/BitLocker) on every company device. Say that you rely on your providers’ encryption — that’s normal and expected.
Backup and recovery
Asking: could you recover client data, and have you proved it? Honest answer: versioned backups separate from primary storage, with a stated restore-test cadence and the date of the last test. If you’ve never tested a restore, the honest answer is no — and that’s fixable this week.
Incident response and breach notification
Asking: what happens in the first hours, and when do they hear about it? Watch this one carefully — it usually carries a contractual notification deadline (often 24, 48, or 72 hours). That is a commitment you must be able to meet. Honest answer: a documented contact list, a named decision-maker, and agreement to the stated notification window if you can genuinely meet it.
Endpoint protection and patching
Asking: are devices protected and updated? Honest answer at small scale: built-in protection (Microsoft Defender, macOS XProtect/Gatekeeper) with automatic OS and browser updates enforced. If they name a specific EDR product and you don’t run one, say so — don’t stretch.
Security awareness training
Asking: are your people trained on phishing? Honest answer: documented annual training, even if it’s a 30-minute session with a written one-pager. Undocumented training is, for questionnaire purposes, no training.
Subprocessors and fourth parties
Asking: who else touches their data through you? Honest answer: a list of the SaaS providers that would process their data — your email/office platform, file storage, CRM, backup provider. Keep this list current; it’s also useful internally.
Data location, retention, and deletion
Asking: where does the data live and when does it go away? Honest answer: the regions your providers store in, plus your own retention and deletion practice. A commitment such as “client files deleted 90 days after engagement close” is strong, cheap, and genuinely reduces your risk — but only promise what you’ll actually do.
Logging and monitoring
Asking: would you know if something happened? Honest answer at small scale: you rely on the audit logs and security alerts built into your SaaS platforms, with admin alerts enabled. Nobody expects a six-person firm to run a SIEM.
Cyber-liability insurance
Asking: can you cover a loss? Often a hard requirement with a stated minimum. Honest answer: your policy and coverage limit, or that you don’t carry it. If you’re buying cover to satisfy this, work through the cyber-insurance readiness guide first — the two questionnaires overlap almost completely.
Background checks, physical security, secure development
Frequently not applicable to a small remote services firm, and saying so is fine. Don’t invent a physical-security programme for an office you don’t have.
Before you sign
- Read what the answers commit you to. Notification windows, audit rights, deletion timelines and insurance minimums are obligations, not descriptions.
- Check nothing contradicts your insurance application. Telling a client you run managed EDR while telling your insurer you don’t is a genuinely dangerous inconsistency.
- Push back on irrelevance. “Sections 4 and 9 are not applicable — we operate no data centres and no customer-facing software” is a normal reply.
- Keep the answers. The next client will send a near-identical form. Store your answers alongside the evidence folder and reuse them.
- Get legal review where the addendum carries liability, indemnity, or audit clauses. This page cannot do that for you.
The reusable version
Keep a single dated document with your standard answers, refreshed whenever your stack changes. The 10-Minute Security Check covers most of the underlying controls, and the evidence folder template tells you what to screenshot for each.
Framework details above are from public documentation published by Shared Assessments, the Cloud Security Alliance, and the Vendor Security Alliance; question counts and versions change with each annual release — verify against the current edition. We are not affiliated with any of them. This page carries no affiliate links.
Get the small-business security foundations
Seven short emails: MFA, password sharing, real backup, restore testing, and the access list. Free options at every step. Unsubscribe in one click.