Customer security questionnaire response template for small teams
It usually arrives the week the deal is supposed to close: a spreadsheet from the big customer's procurement or security team, forty to ninety questions about your MFA policy, your backups, your incident response plan, your subprocessors — with a note that processing can't begin until this is returned. Most small teams do one of two things and both are bad: they panic-send half-true one-word answers ("yes", "yes", "N/A"), or they let it sit for two weeks because every question feels like a homework assignment. The questionnaire is not a test of whether you're a security giant — it's a test of whether you know your own operations. A small team that knows its controls answers faster than a large one that has to convene a meeting.
This playbook turns the questionnaire into an afternoon: build the evidence folder once, write the twelve answers that repeat on every form, learn the honest answers that don't kill the deal, and set the reuse rule so questionnaire #2 costs ninety minutes, not two weeks.
1. What the questionnaire is actually scoring
Buyer-side security teams aren't looking for enterprise-grade everything. They're applying a vendor tier — you're a small vendor with limited data access — and scoring four things:
- Do the controls exist and does someone own them? "Yes" from a named person with a date beats "yes" alone. Anonymous yeses read as copy-paste.
- Are the answers consistent? Questionnaires are graded by people who read dozens of them. A "yes" to MFA in question 4 and a "we don't track" in question 31 gets flagged as an inconsistency — and inconsistency is what moves a vendor into the "request a call" pile.
- Can you prove the basics? Not a certificate — a screenshot of the MFA enforcement page, a copy of the incident response plan, the backup restore test log. Evidence folders win questionnaires.
- Do you know your own limits? The rarest and most persuasive answer in a small-vendor questionnaire is an honest one. Security reviewers trust vendors who say "not yet, here's the compensating control" — they've seen a thousand vendors who say "yes" to everything and mean nothing.
2. Build the evidence folder once (two hours, reused forever)
Before answering a single question, create a folder — literally security-evidence/ — with these files. Almost every questionnaire answer maps to one of them:
- controls.md — a one-page inventory: what you run, where it's hosted, who has admin access, what's encrypted where, what MFA covers. This is the master document; the questionnaire is a reading-comprehension test against it. If your inventory is stale, run the annual security review first — it produces most of this page.
- evidence/ — screenshots: MFA enforcement toggle, backup dashboard, password manager policy, EDR status. Screenshots dated within the last quarter.
- plans/ — the incident response plan (one page is enough — the small-team IR plan template is exactly this), the breach notification sequence, and the severity matrix.
- subprocessors.md — every third party that touches customer data, what it receives, and where it's hosted. This one question kills more small-vendor deals than any other, because "I'd have to check" is the answer reviewers can't write down.
- log.md — a running record of the controls you've tested this year: the backup restore test, the offboarding drill, the tabletop exercise. Dated entries. "We tested it in March and here's the log" outranks "we have a policy."
3. The twelve answers that repeat on every questionnaire
Eighty percent of every security questionnaire is the same twelve questions in different clothes. Write each answer once, in full sentences, and reuse verbatim:
- MFA: "MFA is enforced for all employees on email, cloud storage, source control, and all administrative access." (If it isn't yet, the MFA rollout checklist is a weekend's work — do that before returning the questionnaire, not after.)
- Passwords: "A password manager is mandatory; unique credentials per system; no shared personal-vault logins."
- Backups: "Daily automated backups; restore tested [month/year] with results logged." Untested backup answers are the ones reviewers flag — test once and the answer becomes evidence-backed.
- Incident response: "A written IR plan with severity levels, on-call rotation, and customer notification sequence exists and was exercised [date]."
- Breach notification: "Affected customers are notified within [72 hours / agreed SLA] of confirmed breach involving their data, with what happened, what data, and what we're doing." Commit to a number you can actually meet.
- Encryption: "Data encrypted in transit (TLS) and at rest (disk encryption on all endpoints; cloud provider default AES-256)."
- Access control: "Least-privilege access; admin access limited to named roles; access reviewed [quarterly]."
- Offboarding: "Access revoked within one business day of departure; a checklist covers accounts, devices, and shared credentials."
- Data deletion: "Customer data is deleted on request within [30] days, including from backups per our retention schedule" — which assumes you've actually thought about the deletion-request clock.
- Vendor management: "Third-party tools that handle customer data are reviewed before adoption and annually" — this is the mirror of your buyer's questionnaire: you answer theirs better if you run a vendor security review yourself.
- Patching: "OS and application updates applied within [30 days]; critical vulnerabilities within [7 days]." A simple patch cadence answers this honestly.
- Personnel: "Security responsibilities are assigned to [founder / named role]; all staff complete security training at onboarding." For a five-person team this is true and acceptable — say it plainly.
4. The honest answers that don't kill the deal
Some questions will ask for things a small team genuinely doesn't have: SOC 2, penetration tests, ISO 27001, dedicated security staff. The failure modes are lying (fatal when discovered) and ghosting the question (reads as hiding something). The honest answer has a three-part shape:
- State the status plainly. "Not yet" is a complete sentence. Reviewers score evasion worse than absence.
- Name the compensating control. "We don't hold SOC 2; as a team of 6 with no direct production data access, we complete this questionnaire and provide the evidence folder instead. Our next control investment is [X]."
- Give the date if one exists. "SOC 2 Type I is planned for [quarter/year]" only if it's real. A date you invent becomes a procurement record — reviewers check back.
Answers of this shape survive review because they're verifiable. The vendors who stall deals are the ones whose answers can't survive one follow-up question.
5. Red flags on your side: when the questionnaire is telling you something
Read the form as intelligence about the buyer before you answer it:
- A mandatory SSO question ("Do you support SAML SSO?") means their IT team plans to manage your app. If you can't, answer honestly and expect it to surface later — better to price it into the deal now than discover it in rollout.
- A 100-question form for a $5k/year deal is a proportionality mismatch. It's fair to answer it all — but also fair to note in the cover note that you've tiered your answers so their security team can focus on the sections that matter for your data access level.
- Questions about your subprocessors' subprocessors mean their legal team is involved. Slow, careful, committee-driven. Set the deal timeline accordingly: questionnaire review at big companies takes weeks and you won't accelerate it by answering in an hour.
- A requirement for a penetration test report you don't have: "not yet" plus compensating controls works for the pilot tier; it will not survive a production rollout of regulated data. Know which one this deal is.
6. Close in writing, and version everything
- Cover note with the return. Three sentences: what's attached, what's changed since the last version, who to contact for follow-ups. Reviewers process dozens of returns; the readable one gets processed first.
- Version the answer set. Questionnaire answers are a living document with a version and date. Next quarter's customer asks overlapping questions; you answer from the file, not from memory. Keep answers in a plain table: question text, your answer, evidence link, last reviewed.
- Log what you promised. Every date and number in a questionnaire is now a commitment. If you wrote "access reviews quarterly," that belongs in the annual review checklist as a standing item. A questionnaire answer is a small, written contract with the buyer.
7. Make the second questionnaire cost ninety minutes
- The reuse rule: before answering anything new, search the answer file first. In practice 70–90% of any new questionnaire is already written. The afternoon version of this playbook happens once; after that it's find-and-replace.
- Refresh quarterly: the answers rot quietly — a tool added, an admin changed, a backup window moved. Tie the refresh to the same quarterly pass that reviews vendor access, so the evidence folder stays truthful without a special project.
- Feed wins back into operations: every question you answered badly in round one is a gap a real customer has already surfaced. Fixing them is cheaper now than during the next deal — and the fixes (MFA, tested backups, a written IR plan) are the same controls the cyber insurance application and every future buyer will check.