A security questionnaire is the document that sits between you and a signature. It is a procurement gate wearing compliance clothing, and it usually lands with a deadline attached.
The short answer
A security questionnaire is a set of questions a prospective customer, partner or insurer sends to assess how you handle their data before agreeing to work with you. Length ranges from a dozen questions to several hundred. The answers are contractual, so what you claim in one becomes something you have to keep true.
Nobody enjoys them, but they are worth understanding properly for one reason: the security questionnaire is the point where security stops being an internal cost and becomes revenue you either close or lose.
On this page
The security questionnaire formats you will meet
| Format | Who sends it | What to expect |
|---|---|---|
| SIG and SIG Lite | Large enterprises, financial services | An extensive standardised set, with the Lite version used for lower-risk vendors |
| CAIQ | Cloud buyers | Cloud-specific questions aligned to the Cloud Security Alliance control matrix |
| Custom enterprise questionnaire | Most mid-market and enterprise buyers | A spreadsheet built by their security team, unique to them, often the longest of the lot |
| Insurer questionnaire | Cyber insurance underwriters | Focused on controls that correlate with claims, with answers that affect terms |
| Investor diligence pack | VCs during a round | Lighter on technical detail, heavier on governance and whether anything is about to blow up |
| Regulatory vendor assessment | Regulated customers in banking, markets and health | Mapped to the framework their own regulator holds them to |
What a security questionnaire asks
The wording varies wildly. The underlying sections almost never do.
| Section | What sits behind it |
|---|---|
| Governance and policy | Named owner, approved policies, and a GRC arrangement that is reviewed |
| Access control | Identity management, MFA, joiner and leaver process, and privileged access |
| Data protection | Encryption in transit and at rest, retention, deletion, and where data physically sits |
| Application security | Secure development, code review, dependency handling and release process |
| Testing | VAPT, scan cadence, and how findings are tracked to closure |
| Monitoring and response | Logging, alerting, and a tested incident response plan with notification timelines |
| People | Background checks and security awareness training with completion records |
| Third parties | Your own subprocessors, because their risk becomes your customer’s risk |
| Certifications | SOC 2, ISO 27001, PCI DSS or DPDP alignment, with the report attached |
How to answer a security questionnaire faster
The practical rule is that a security questionnaire is an evidence retrieval problem, not a writing problem. Teams that keep control evidence in one place answer in hours. Teams that reconstruct it from four vendors and a shared drive answer in weeks, and the deal waits.
Answers are contractual
A completed security questionnaire is usually referenced in the contract or attached to it. Saying you rotate keys quarterly creates an obligation to rotate keys quarterly, and it is one of the first things examined if there is ever an incident. Answer what is true now and mark planned work as planned, with a date.
Why a security questionnaire stalls deals
| Cause | What happens |
|---|---|
| No evidence library | Every question becomes a research task, and a two-day job takes three weeks |
| Sales answers alone | Optimistic answers get corrected later, which costs more credibility than a straight no |
| Genuine control gaps | MFA coverage, logging retention or a tested incident plan turn out to be missing under questioning |
| No named owner | The questionnaire circulates between engineering, legal and sales with nobody accountable for returning it |
| Inconsistent history | This answer contradicts what a different person told the same buyer last quarter |
| Missing report | The buyer asks for the SOC 2 report and the process pauses until one exists |
Does a SOC 2 report replace it
It reduces it substantially and rarely removes it. A SOC 2 Type II report or an ISO 27001 certificate answers whole sections at once and moves you into a lighter review tier with many buyers. What survives is anything specific to that customer: where their data sits, which subprocessors touch it, what your notification timeline is, and how the arrangement maps to their own regulator.
Two of Osto’s customers ended up here from opposite directions. One cleared an insurer’s security questionnaire inside 48 hours to close a deal, covered in the Insybit case study. Another met investor security requirements during a funding round, covered in the Handpickd case study. The questionnaire guide for startups works through the process in detail.
How Osto handles security questionnaires
Osto answers security questionnaires from your live control state rather than from a document library that drifts. Because access, endpoint, cloud, application and testing controls run in the same platform, an answer about MFA coverage or log retention is drawn from the system enforcing it, not from somebody’s recollection of how it was configured last year.
The same control set maps across 200 or more frameworks, so a question phrased in SIG language, CAIQ language or a regulator’s language resolves to the same underlying evidence. Answers are banked and reused, which is what turns the second security questionnaire into a short task instead of another three-week project.
Platform walkthrough
Stop losing weeks to spreadsheets
Osto answers from your live control state and banks every answer for the next buyer. The deal moves at the speed of the deal, not the questionnaire.
Book a demo200+ frameworks mapped · Evidence from your own stack · One platform, everything
Frequently asked questions
What is a security questionnaire?
A set of questions a prospective customer, partner or insurer sends to assess how you protect their data before agreeing to work with you. It covers governance, access control, data protection, testing and incident response, and the answers usually become contractual.
How long does a security questionnaire take to complete?
Anywhere from a few hours to several weeks. The variable is not question count but how quickly you can retrieve evidence. Teams with a single control platform and a bank of previous answers finish quickly. Teams reconstructing evidence across several vendors do not.
Does SOC 2 mean I can skip security questionnaires?
No, though it shortens them considerably. A SOC 2 Type II report answers entire sections and often moves you into a lighter review tier. Buyer-specific questions about data location, subprocessors and notification timelines still need answering.
What happens if I answer a security questionnaire inaccurately?
The answers are typically referenced in or attached to the contract, so an inaccurate claim is a contractual misstatement. It is also among the first documents reviewed after an incident. Mark planned controls as planned with a target date rather than describing them as in place.
Who should own the security questionnaire process?
One named person, usually whoever owns security or compliance, with input from engineering and sign-off before it goes back. Questionnaires that circulate without an owner are the ones that sit unreturned while the buyer waits.

