Proje vitrini hazırlanıyorPreparing project showcaseПодготавливаем витрину проекта

Sales

Answering security and compliance questionnaires

A two-hundred-line security questionnaire does not have to stall a deal: an answer library, a ready evidence set, how to say no, and the part that binds you.

Rocketly · 2026-09-02

Thursday afternoon. A deal six months in the making has reached signature stage when an email lands from the buyer's information security team: attached is a spreadsheet with two hundred and fourteen rows, due in five working days. The rep forwards the file to engineering, who are mid-sprint. They answer some rows with yes, mark others not applicable, and leave about thirty blank. Ten days later the buyer's legal team finds eleven contradictions between that spreadsheet and the draft contract. The deal slides into the next quarter, and what was lost is considerably more than a week of engineering time.

A security and compliance questionnaire is how an enterprise buyer transfers supplier risk onto their own records. It shows up in the last meters of a sale and stalls unprepared teams for weeks. This article covers, in order: what the questionnaire actually measures, who should own it, how to build an answer library, how to split questions by type, which documents to prepare in advance, the right way to say no, why sentences in the form carry contractual weight, how a team without certifications gets through, where the form belongs in the sales cycle, and which numbers to track.

1Received2Triage3Library4Expert check5Gap log6Delivered
The six stops between a questionnaire arriving and the completed version going back out.

What does a questionnaire actually measure?

The first misconception is that the form measures your security. What it largely measures is something else: whether the risk owner on the other side can defend you in writing to their own management. Their output is not a score but a short written assessment, and they are waiting for you to supply the sentences it will be built from. Fill the form in with that in mind and your answers get shorter, clearer and far more useful.

The second misconception is that every question is read carefully. What actually gets read is the inconsistencies: two different answers on the same topic, a commitment made in the form that appears nowhere in the contract, a control engineering says exists but no document reflects. The quality of a completed questionnaire is therefore measured not by how impressive the answers are but by how well they agree with each other and with your documents. We cover how procedural buyers operate more broadly in our article on negotiating with the procurement department.

Who owns the form?

The most common arrangement is also the worst: the form arrives at sales, sales forwards it to engineering, engineering fills it in when they have a moment. Three things break at once in that setup. Turnaround becomes unpredictable, answers vary with whoever happened to be free that day, and nobody remembers what was written last time. The form needs a single owner, and that person does not need to be a technical expert. They need to own the process.

The owner's job is not to write the answers but to gather them and hold them consistent. Technical questions go to engineering, contractual ones to whoever manages agreements, process ones to the relevant function; the owner merges them, removes contradictions and delivers from one hand. Taking this work off any single person's shoulders is one of the most concrete applications of process documentation and SOPs.

An answer library: never write the same answer twice

By the second questionnaire you notice it: most of the questions are the first questionnaire's questions in different words. How are access rights managed, where is data stored, how often are backups taken, who is notified within what time when an incident occurs. Instead of writing all this from scratch each time, build an answer library organized by topic and feed every new form from it.

The three parts every answer needs

Every answer that works has three parts. The first is the claim: what you do, in one sentence. The second is the evidence: which document, screen or setting demonstrates it. The third is the scope: where this control applies and where it does not. Answers with no stated scope come back more often than any other kind, because the reviewer cannot write their own note without knowing the boundary, so they open another round with you.

Maintaining the library matters as much as building it. Every answer needs an owner and a review date; an answer untouched for six months may still describe a setting engineering has since changed. The most dangerous kind of wrong answer is not the dishonest one but the one that used to be true, because nobody thinks to question it.

How many types of question are there, and who answers each?

Rather than reading the form row by row, sort the questions by type. That single move usually halves turnaround, because it makes parallel work possible and puts only their own domain in front of each expert. Five types cover very nearly everything you will meet.

Question typeWhat is really being askedWho produces the answer
Policy questionIs there a written rule, and is it followed?Process owner
Technical controlIs the control default, or switched on by setting?Engineering
Contractual commitmentWould you say the same in a signed document?Agreement owner
Subprocessors and locationWhose hands, and which country, does data pass through?Data owner
Incident and continuityWhen something breaks, who hears, and how fast?Operations owner

The split pays off most on access and identity: who can see what, how permissions are granted, when a departing employee's access is revoked. Answering those cleanly requires your own role and permission model to be written down; our article on role and permission management explains how to build that matrix. When the expectation of centralized authentication comes up, the ground your answer stands on is a single sign-on setup.

Which documents should you prepare in advance?

The attachments are assessed as seriously as the form itself, and many reviewers open them first. With the set below ready, writing answers takes noticeably less time. Without it, every questionnaire becomes a small project and the same scramble repeats each time.

  • Information security policy set: A few pages each on passwords, access, devices and suppliers, dated and approved; what is assessed is not length but currency and whether the policy is genuinely followed.
  • Architecture and data flow diagram: One page showing which components data travels between persuades far faster than ten lines of prose.
  • Access and permission matrix: Which role reaches which data, and how quickly a departing employee's access is closed, is the one question that never leaves these forms.
  • Subprocessor and supplier list: Who provides your hosting, email delivery and analytics, and where those services run, has to exist in writing.
  • Backup and recovery record: Frequency, retention and, above all, the date a restore was last actually tested; without that date a backup is only a promise.
  • Incident response procedure: Who is alerted, who decides, and who informs the customer through which channel; those three lines carry the heaviest weighting on most forms.
  • Vulnerability scan or penetration test summary: You are not obliged to share the full report; a summary with scope, date and remediation status is usually enough.

Two items in that set are missing in most small and mid-sized companies: the record of an actual restore test, and retention periods written down. That backups are being taken says nothing on its own; the date a restore was attempted says everything. We treat both subjects in detail in our articles on backup and disaster recovery and on the data retention and deletion policy.

The right way to say no

The answer teams fear most is no. In practice the answer that generates the most extra rounds is not applicable. Every row left blank or refused in a single word means the reviewer cannot write their own note, and that almost guarantees another round of questions. A well-constructed no, by contrast, usually closes in one.

A well-constructed no is three sentences: we do not have this control in that form; this compensating control operates in its place; we limit the associated risk in the following way. The risk team on the other side is not looking for perfection. They are looking for a justification they can accept and write down. We collected the baseline control set a small team can build with limited resources in our piece on cybersecurity for small businesses.

Why a sentence in the form is part of the contract

In many enterprise purchases the completed questionnaire is attached as an annex, or at minimum referenced as a representation. That means an optimistic sentence written to speed a deal up becomes an operational commitment later. The line you assumed nobody would read is the first document opened when something goes wrong.

Every sentence in the questionnaire is an unsigned annex to the contract, and the cost of exaggeration is paid months later by operations, not by sales.

The practical rule: nothing you commit to in the form should be something you would refuse to write into the contract itself. Statements about personal data deserve particular care, because there your answer stands not only in front of the buyer but in front of regulation; the CRM-side counterpart of this subject is covered in our article on data protection compliant CRM. The purpose here is to show the mechanism; make the final assessment for your own situation with your legal advisor.

How do you pass without a certification?

The reflex after a first punishing questionnaire is to start a certification process. For a small team that is usually the wrong first move: certification takes a long time, sales continues throughout, and you still have to pass the forms arriving in the meantime on evidence alone. What gets you through in the short run is not a badge but an orderly, consistent evidence set.

The limit deserves stating plainly too. In some segments, particularly large enterprise purchases, public tenders and parts of financial services, a specific certificate is a gate condition, and there you are screened out however good your evidence is. The right move then is not persistence; it is learning the requirement early and disqualifying the opportunity while it is still in qualification.

The question of where data physically resides frequently becomes a gate condition in this same section. Establish whether the buyer's expectation and your infrastructure line up without waiting for the form to ask. The detail sits in our article on data residency.

Where does the form belong in the sales cycle?

It is no accident that questionnaires arrive late; the buyer also treats them as the last step. But arriving late damages both sides: you write under time pressure, and they miss their own target date. The fix is to raise the subject much earlier in the sale.

The most elegant way to do that is one question before the proposal: do you run a security assessment process, who runs it, and how long does it typically take. That question does three things at once. It makes the timeline realistic, it surfaces the right person on the buyer's side, and it makes you look prepared. Meeting the person who will run the review in the middle of a cycle is always cheaper than meeting them at the end.

Which metrics to watch

Left unmeasured, every questionnaire feels like a fresh surprise. Four indicators are enough. Turnaround is the number of days between arrival and delivery, and it moves the close date directly. Library coverage shows what share of questions were answered from prepared material; as that rises, turnaround falls on its own. Round count is how many times the form came back, and it is the most honest measure of inconsistency. The number and age of open items in your gap log shows the real debt on the security side.

Most of these measurements assume changes in the system are recorded; if who changed what and when is invisible, you can neither answer the reviewer nor verify anything internally. That is exactly why audit logging is one of the most repeated topics in these forms.

Where to start

Do not wait for the next form. Open the last one you completed, pull out the twenty questions that recur, and write each a three-sentence answer containing claim, evidence and scope. Those twenty answers will cover roughly half of the next questionnaire; after the second one the library starts growing by itself and the process becomes predictable for the first time.

For that to hold, forms, owners, due dates and open items need to live on the deal record itself; a list kept in a separate spreadsheet stops being updated during the first busy week. Rocketly keeps deal-linked tasks, reminders, document attachments and permission settings in one place; open a free account and build your own questionnaire flow.