How to Answer a Security Questionnaire from an Enterprise Client: A Guide for the 2 Weeks You Have
Daniel Sarica
Published: May 27, 2026
First thing: do not panic
Two weeks is enough for an honest, professional, acceptable response. Not enough to build from scratch what does not exist. The strategy is not to fake maturity you do not have - good clients discover that at the first audit. The strategy is to be honest about your current state, with a clear improvement plan for what is missing.
The answer “we do X partially and plan to formalize it by [date]” lands far better than a false “we do X completely.”
What a real questionnaire looks like
50 questions, spread across 6 sections. Each question asks for one of three types of answers
- Yes/No: do you have MFA? Do you have a backup policy?
- Description: how do you handle the accounts of departing employees?
- Evidence: attach your backup policy
Many companies answer the first two types and get stuck on the third. Because evidence requires documentation that does not exist in written form. If you need help, we can support you with cybersecurity services
Days 1-2: Triage
Do not start answering questions yet. Read the entire questionnaire, twice, without answering. Then classify each question into 3 categories.
Green (40-60% of questions): you have a solid answer and evidence available. The policy exists, the process exists, you can attach the document.
Yellow (25-40%): you have the practice but formal documentation is missing. You run backups but there is no written policy. You have MFA on email but not on all systems. The offboarding process exists in HR’s head, but not on paper.
Red (10-25%): you have neither the practice nor the documentation. Usually areas like: business continuity plan, vendor assessment, formal incident reporting.
This triage tells you where you can answer solidly (green), where you can build in 7-10 days (yellow), and where you owe an honest answer with a plan (red).
Days 3-7: Build the yellow documentation
This is the biggest chunk of the work. For each yellow area, you need to turn existing practice into a document.
The one-page backup policy
[COMPANY NAME] - Backup Policy
Version 1.0, approved by [Executive] on [date]
What gets backed up
- ERP and CRM databases, other critical applications
- Company file shares
- Email (via Microsoft 365 / Google Workspace)
- System configurations of critical servers
Frequency
- Databases: daily (incremental), weekly (full)
- Files: daily
- Configurations: at every major change, at least quarterly
Backup location
- Primary copy: [location]
- Isolated copy: [location - specifying that it is not accessible from the production network]
Testing
- Real restore of a database quarterly
- Documented restore time and issues identified
Ownership
- [Name]: execution and monitoring
- [Name]: monthly verification
Reporting
- Backup status reported monthly to [responsible manager]
One page. 30-45 minutes to write it. Approve it, date it, sign it. You now have a formal backup policy.
Apply the same pattern to
- Access management policy (how access is granted, how it is revoked at departure, who approves)
- AI usage policy (see our guide on shadow AI)
- Incident response procedure (even at 2 pages, with phone numbers and roles)
- Equipment usage policy (phones, laptops, USB drives)
- Password and MFA policy
None of these takes more than 1-2 hours of work. In total, 4-5 days spread across team members (IT, HR, executive) cover most of the yellow areas.
Days 5-10: Gather the evidence
In parallel with building the new documents, collect the evidence that already exists
- Screenshots from the Microsoft 365 / Google Workspace admin panel - active users, MFA enabled, password policies
- Antivirus / EDR reports - protection status, alerts from the last 90 days
- Emails or meeting minutes confirming quarterly reviews
- Backup logs showing successful jobs from the last 3 months
- Contracts with key vendors (for the third-party section)
- The incident list (even minor ones) with the actions taken
Everything in a single folder, organized by questionnaire section. Each document ready to be attached as evidence.
Days 8-12: The actual answers
Now you have the raw material. Start answering.
For green questions
Solid answer + attached evidence. “Yes, we have a formal backup policy - see attachment 1. Frequency and process are detailed in section 3. Last real restore test: [date], with a documented positive result.”
For yellow questions (now with new documentation)
Honest answer + attached evidence + context. “Yes, we formalized the policy in [previous month]. The process previously existed informally. The document is attached (attachment 4). The practical implementation has been operational since [date].”
Honesty about the formalization date matters. If the policy is dated yesterday and you answer that you have had it for 2 years, that is contract fraud. If you say “we recently formalized existing practice,” that is maturity.
For red questions
Honest answer + plan + deadline. “We do not yet have a formal business continuity plan. We recognize the need and have included its development in our Q3 2026 roadmap, with a completion deadline of [date], following the ISO 22301 standard. We will be able to share the finished plan as part of the contractual relationship.”
That answer is far stronger than a flat “No,” or a false “Yes.” It shows the company knows what it is missing and has a plan.
Days 11-13: The final review
Before sending
Check consistency. Answers to similar questions in different sections must be consistent. If in one section you say you run quarterly reviews and in another you say you have no formal process, the contradiction gets noticed.
Check the evidence. Does each attachment match the question where it is referenced? Is it legible? Redacted where it needs to be?
Check the terminology. If the questionnaire talks about an “incident response plan,” your answers use the same term. Small terminology mismatches raise suspicion.
Check the tone. Professional answers, not defensive ones. Do not complain that the questions are too hard or too many. Answer what you can, plan what you cannot.
Read everything as if you were the client. If you received this questionnaire back, what would you think about the company? Mature, professional, in control? Or confused, defensive, evasive?
Days 13-14: Send it and prepare for questions
Send it 1-2 days before the deadline, so you have room to answer clarification questions. Reply quickly to any follow-up email - response speed is part of the evaluation.
Prepare for the possible next steps
- Phone or video audit: the client wants to talk to your IT team about a few points. Prepare the person who will speak.
- On-site visit: possible for large contracts. Prepare access, the contact person, demos of the relevant systems.
- Request for additional documents: be ready to respond fast with any standard document.
Mistakes that cancel out all the effort
IT answers alone. Questionnaires require management decisions (prioritization, improvement plans, budget allocations, contractual decisions). IT alone cannot commit the company. Always involve the executive and, for legal questions, your attorney.
You answer “yes” to everything. The risk is high. False answers get discovered at the first audit. Plus, if an incident happens involving practices you declared but do not have, you are in contract fraud territory.
You answer too defensively. “We do not see the need” or “that is for bigger companies” - answers that signal immaturity. Better: “we have implemented this partially; the expansion plan is […]”
You do not ask for clarification when needed. If a question is unclear or ambiguous, ask. Clients appreciate it.
You do not keep your answers. The first questionnaire is the hardest. The second, if it comes from another client, overlaps 60-70%. Build an internal knowledge base with your standard answers and the related documents.
After sending: what comes next
Scenario A: the response is accepted and you move on to negotiations. Congratulations - it is not an ending, it is a beginning. The documents you just built now have to be maintained. The backup policy dated today will be audited 12 months from now - make sure it stays updated and applied in the meantime.
Scenario B: the client requires specific improvements before moving forward. “You need an implemented business continuity plan before we can sign.” Now you have a clear deadline and a commercial motivation to make the investment you have been postponing. Communicate a realistic timeline (usually 3-4 months) and ask the client for understanding about the process.
In both scenarios, the long-term benefit outweighs the stress of these weeks. The documents you build now serve the next questionnaire that comes, and the one after that. And over time, the company becomes one of those that respond professionally - which is a commercial differentiator.
How much you save with preventive preparation
If you have done the preparation ahead of time (a 60-90 day exercise), a security questionnaire becomes 3-4 days of work, not 2 weeks of crisis. And the answers are better, because they were not built under pressure.
Companies entering a commercial growth cycle receive 5-10 questionnaires per year. The difference between “every questionnaire is a crisis” and “every questionnaire is a standard process” is the difference between operationally efficient and inefficient. Over 12 months, that is weeks of work saved.