How to answer a security questionnaire as a small software company
Use a short process: send an overview first, mark what is true today, answer gaps honestly with a date, and reuse your answers.
Why these questionnaires are hard for a small team
Bigger clients send vendor security questionnaires before they sign. They can run to 100 or more questions, they ask about policies a small team never wrote down, and they arrive while you are busy with client work. The questions fall into the same 16 areas every time: governance, people, access control, devices, data protection, encryption, backups and continuity, logging and monitoring, vulnerability management, secure development, incident response, vendors and subprocessors, privacy, physical security, change management, ai tools. The kit's 86 prepared questions are grouped the same way.
The 6 steps
- Read the questionnaire and ask which sections apply. Questions are worded differently in every questionnaire, but they ask about the same controls. Ask the client which sections apply to a vendor of your size and ask for more time if you need it.
- Send a Security Overview first. A one-page overview of the controls you have in place often answers many questions before the client opens the questionnaire.
- Write down what is true today. Go through the controls one by one and mark each as in place, partly or missing. The free builder asks 26 such questions. Your answers must match what you actually do.
- Answer gaps honestly, with a date. For a control you do not have, say so, say what you do instead, and give a target date. The kit's answers for missing controls follow this pattern.
- Fix the cheap gaps. Most fixes for a small team are settings you can change in an hour: MFA, disk encryption and automatic updates.
- Reuse the answers. Find the matching answer for each question, copy it, or export all answers as CSV and paste them into the client's own spreadsheet.
What honesty looks like in an answer
Take a question such as "Is MFA enforced for all users?". If MFA is on every system, say which systems. If it is not, the kit's honest answer says it is not on every system yet, names enabling it everywhere as the first priority and gives a date. A client can work with a dated gap. A claim that turns out to be false ends the deal.
If the client asks for a certification
A certification is not required to answer. If you hold no SOC 2 report or ISO 27001 certificate, say so and describe the controls you have in place instead. The guide on governance questions shows what a good answer to that question contains.
Where to go next
Pick the area your questionnaire is asking about from the guide hub, or start with the free Security Overview builder.
Guidance and templates, not legal advice. The kit does not certify you. Your answers must match what you actually do.