Skip to content
All resources
ComplianceAugust 27, 2026·6 min read

Your Client Sent a Security Questionnaire. Now What?

A ninety-question security review from your biggest customer is a sales document, not a compliance chore. How to answer it honestly and win the work.

By Cohesive Security

The email comes from your largest client, or the one you are three weeks from signing. Attached is a spreadsheet with ninety questions about your security, a due date of Friday, and a tone that suggests this is routine for them even though it is the first time anyone has asked you.

The instinct is to treat it as paperwork and get it off your desk. That is the expensive read. A security questionnaire is a purchasing document: somebody has decided your business is a risk they now have to account for, and how you answer determines whether you stay on the approved list.

Key takeaways:

  • This is a sales document. Firms that answer quickly and credibly win work that firms who stall do not.
  • Never claim a control you cannot evidence. An inaccurate yes is far worse than an honest no with a date attached.
  • Most questionnaires are asking the same handful of things in different words. Answer them once properly and you can reuse the work for years.
  • The gaps that show up are almost always the same four, and none of them takes months to close.

Why this is landing on you now

Large organizations got tired of being breached through their suppliers, so they started pushing their own requirements down the chain. If you handle their data, connect to their systems, or could halt their operations by going down, you are part of their risk, and they are now required to show someone that they checked.

Whether it arrives as a spreadsheet, a portal login, a clause in the contract, or an insurance-style form, the underlying question is the same: if we trust you with this, what happens?

Read the whole thing before you answer anything

Two minutes of triage saves a week. Go through it once and sort every question into three piles: yes and I can prove it, no, and I do not understand what is being asked.

That third pile matters more than it looks. Guessing at a question you have misread is how businesses end up attesting to things they do not do. If a question is ambiguous, ask the client what they mean. Nobody has ever lost a contract for asking a clarifying question, and it signals that you are taking it seriously.

Also check what they actually want as proof. Some questionnaires accept your word. Others ask for evidence: a policy document, a screenshot of a setting, an attestation from your IT provider, a recent report. Knowing which one you are answering changes how long it takes.

What they are really asking

Behind the wording, nearly every questionnaire is probing the same areas, and it helps to have a map. NIST’s Cybersecurity Framework 2.0 Small Business Quick-Start Guide organizes security outcomes into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It is written for exactly the reader who is staring at a questionnaire with no security team, and it is free.

Sort the questions into those six and the shape becomes obvious. Who is responsible and what are your policies (Govern). What data and systems do you have (Identify). How do you keep people out (Protect). How would you know if something happened (Detect). What do you do about it (Respond). How do you get back (Recover).

Most small businesses answer Protect reasonably well and fall apart on Govern, Detect, and Respond, because those are the ones that need something written down rather than something installed.

The rule that matters most: answer honestly

If you take one thing from this: do not claim a control you cannot demonstrate.

We have written before about what happens on the insurance side, where an inaccurate answer about multi-factor authentication led to a policy being rescinded from inception after a ransomware claim. The client-contract version is less dramatic and still bad: your answers usually become a representation in the contract, and the gap between what you said and what you do surfaces at the worst possible moment, which is after an incident, in front of the customer whose data was involved.

An honest no is survivable and often barely noticed. “Not today, and here is when” is a normal answer that procurement teams see constantly. What they cannot forgive is finding out later that a yes was aspirational.

So work the form in this order: mark the honest noes, fix the ones that are cheap and quick, put dates against the rest, then fill it in from what is true on the day you sign it.

The four gaps that come up every time

From the questionnaires we help clients through, the same items are missing over and over.

A written incident response plan. Who declares an incident, who gets called, in what order, and where the document lives when the network is down. This costs an afternoon and it is on nearly every questionnaire.

Evidence, not assurances. Not “we patch” but “here is our standard and here is the report”. Not “we back up” but “here is the date of the last tested restore”. If you cannot produce the second version, that is the actual finding, and it is the same evidence a real restore test produces.

Access removal on departure. They will ask how quickly access is revoked when someone leaves, and whether it is documented. A dated offboarding record per departure answers it in one line.

MFA everywhere, not just email. The question is almost never “do you have MFA”. It is about remote access, administrator accounts, and increasingly the strength of the factor, which is where the difference between kinds of MFA starts to matter.

Make it an asset instead of a fire drill

The first questionnaire is painful. The tenth should not be, and it will not be if you do one thing: keep the answers.

Build a single document with your standing answers, your policies, and your evidence, kept current. Then each new questionnaire is a mapping exercise rather than an excavation. Firms that do this answer in two days instead of two weeks, and that speed is visible to the client at exactly the moment they are deciding about you.

It is also worth getting ahead of it. If you sell to corporates, hospitals, banks, or anyone regulated, this is coming whether or not it has arrived. The businesses that treat the questionnaire as their security roadmap end up with both the contract and the controls.

Where we come in

Plenty of this you can do yourself, particularly the triage and the writing down. Where it gets harder is producing evidence you do not currently generate, and answering the technical questions accurately rather than optimistically.

That is most of what our compliance and vCISO service does: own the questionnaire, close the gaps that are real, and give you answers you can defend, backed by the controls underneath them. For firms who win work this way, it is a standing part of business development rather than a one-off, which is how we handle it for our professional services clients.

Send us the questionnaire and we will tell you where you stand before you commit to answers. That is part of a free assessment, or email it to hello@cohesivesecurity.com.

#compliance#vendor risk#NIST CSF#questionnaires#MFA

Enjoyed this article?

Get more like it by email. Short, practical security tips for business owners. No jargon, no spam, unsubscribe anytime.

We only use your email to send the tips. Nothing else, and never shared.

Want help putting this into practice?

Our team can assess your environment and handle the heavy lifting. Start with a free, no-pressure conversation.