Security Questionnaire

Security questionnaire formats and 4-step answering process explained

A security questionnaire is the document that sits between you and a signature. It is a procurement gate wearing compliance clothing, and it usually lands with a deadline attached.

  • Glossary
  • Compliance

The short answer

A security questionnaire is a set of questions a prospective customer, partner or insurer sends to assess how you handle their data before agreeing to work with you. Length ranges from a dozen questions to several hundred. The answers are contractual, so what you claim in one becomes something you have to keep true.

Nobody enjoys them, but they are worth understanding properly for one reason: the security questionnaire is the point where security stops being an internal cost and becomes revenue you either close or lose.

The security questionnaire formats you will meet

FormatWho sends itWhat to expect
SIG and SIG LiteLarge enterprises, financial servicesAn extensive standardised set, with the Lite version used for lower-risk vendors
CAIQCloud buyersCloud-specific questions aligned to the Cloud Security Alliance control matrix
Custom enterprise questionnaireMost mid-market and enterprise buyersA spreadsheet built by their security team, unique to them, often the longest of the lot
Insurer questionnaireCyber insurance underwritersFocused on controls that correlate with claims, with answers that affect terms
Investor diligence packVCs during a roundLighter on technical detail, heavier on governance and whether anything is about to blow up
Regulatory vendor assessmentRegulated customers in banking, markets and healthMapped to the framework their own regulator holds them to

What a security questionnaire asks

The wording varies wildly. The underlying sections almost never do.

SectionWhat sits behind it
Governance and policyNamed owner, approved policies, and a GRC arrangement that is reviewed
Access controlIdentity management, MFA, joiner and leaver process, and privileged access
Data protectionEncryption in transit and at rest, retention, deletion, and where data physically sits
Application securitySecure development, code review, dependency handling and release process
TestingVAPT, scan cadence, and how findings are tracked to closure
Monitoring and responseLogging, alerting, and a tested incident response plan with notification timelines
PeopleBackground checks and security awareness training with completion records
Third partiesYour own subprocessors, because their risk becomes your customer’s risk
CertificationsSOC 2, ISO 27001, PCI DSS or DPDP alignment, with the report attached

How to answer a security questionnaire faster

1. Triage Split into answered before, new, and gaps 2. Map Point each question at a control and its evidence 3. Answer State what is true today, flag what is planned 4. Reuse Bank the answer for the next one Step 4 is where the time is won. The second questionnaire should cost a fraction of the first.

The practical rule is that a security questionnaire is an evidence retrieval problem, not a writing problem. Teams that keep control evidence in one place answer in hours. Teams that reconstruct it from four vendors and a shared drive answer in weeks, and the deal waits.

Answers are contractual

A completed security questionnaire is usually referenced in the contract or attached to it. Saying you rotate keys quarterly creates an obligation to rotate keys quarterly, and it is one of the first things examined if there is ever an incident. Answer what is true now and mark planned work as planned, with a date.

Why a security questionnaire stalls deals

CauseWhat happens
No evidence libraryEvery question becomes a research task, and a two-day job takes three weeks
Sales answers aloneOptimistic answers get corrected later, which costs more credibility than a straight no
Genuine control gapsMFA coverage, logging retention or a tested incident plan turn out to be missing under questioning
No named ownerThe questionnaire circulates between engineering, legal and sales with nobody accountable for returning it
Inconsistent historyThis answer contradicts what a different person told the same buyer last quarter
Missing reportThe buyer asks for the SOC 2 report and the process pauses until one exists

Does a SOC 2 report replace it

It reduces it substantially and rarely removes it. A SOC 2 Type II report or an ISO 27001 certificate answers whole sections at once and moves you into a lighter review tier with many buyers. What survives is anything specific to that customer: where their data sits, which subprocessors touch it, what your notification timeline is, and how the arrangement maps to their own regulator.

Two of Osto’s customers ended up here from opposite directions. One cleared an insurer’s security questionnaire inside 48 hours to close a deal, covered in the Insybit case study. Another met investor security requirements during a funding round, covered in the Handpickd case study. The questionnaire guide for startups works through the process in detail.

How Osto handles security questionnaires

Osto answers security questionnaires from your live control state rather than from a document library that drifts. Because access, endpoint, cloud, application and testing controls run in the same platform, an answer about MFA coverage or log retention is drawn from the system enforcing it, not from somebody’s recollection of how it was configured last year.

The same control set maps across 200 or more frameworks, so a question phrased in SIG language, CAIQ language or a regulator’s language resolves to the same underlying evidence. Answers are banked and reused, which is what turns the second security questionnaire into a short task instead of another three-week project.

Platform walkthrough

Stop losing weeks to spreadsheets

Osto answers from your live control state and banks every answer for the next buyer. The deal moves at the speed of the deal, not the questionnaire.

Book a demo

200+ frameworks mapped · Evidence from your own stack · One platform, everything

Frequently asked questions

What is a security questionnaire?

A set of questions a prospective customer, partner or insurer sends to assess how you protect their data before agreeing to work with you. It covers governance, access control, data protection, testing and incident response, and the answers usually become contractual.

How long does a security questionnaire take to complete?

Anywhere from a few hours to several weeks. The variable is not question count but how quickly you can retrieve evidence. Teams with a single control platform and a bank of previous answers finish quickly. Teams reconstructing evidence across several vendors do not.

Does SOC 2 mean I can skip security questionnaires?

No, though it shortens them considerably. A SOC 2 Type II report answers entire sections and often moves you into a lighter review tier. Buyer-specific questions about data location, subprocessors and notification timelines still need answering.

What happens if I answer a security questionnaire inaccurately?

The answers are typically referenced in or attached to the contract, so an inaccurate claim is a contractual misstatement. It is also among the first documents reviewed after an incident. Mark planned controls as planned with a target date rather than describing them as in place.

Who should own the security questionnaire process?

One named person, usually whoever owns security or compliance, with input from engineering and sign-off before it goes back. Questionnaires that circulate without an owner are the ones that sit unreturned while the buyer waits.