Key Takeaways
- Security questionnaires are appearing earlier in the buying cycle than before — buyers aren't waiting until after the demo to ask about security. They're evaluating it alongside features and pricing. Being unprepared doesn't just slow deals — it loses them.
- Around 80% of questions overlap across frameworks. The 30 most common questions around encryption, access management, incident response, patch management, and certifications appear in virtually every assessment. Master those once and you can handle most questionnaires you'll ever receive.
- A security questionnaire is not a test you pass or fail — it's a structured conversation about your security posture. Honest, documented answers with clear evidence beat vague claims every time.
- Working with a certified IT partner like deeploi — which is ISO 27001 certified, GDPR compliant, and EU data-resident — means many of the hardest questions are already answerable because your IT provider's posture becomes part of your answer.
- The goal is a reusable security pack: a set of pre-prepared answers, certificates, and policy documents that you can adapt and send within 24 hours of any request.
The email arrives three weeks before the deal is supposed to close. Your largest prospective customer — a company ten times your size — has forwarded a security questionnaire from their procurement team. 150 questions. Due in five business days. Topics include encryption standards, incident response plans, access control policies, patch management processes, and your ISO 27001 status.
You don't have an IT department. You don't have a CISO. You have a laptop, a Google Workspace account, and a vague memory of setting up two-factor authentication.
This scenario plays out constantly for growing SMBs entering enterprise sales cycles. Security questionnaires have become standard practice in enterprise procurement, with buyers using them to assess vendor risk before granting access to sensitive data or systems. The companies that handle them efficiently win more deals. The ones that don't lose them — quietly, without anyone explaining why.
What Is an IT Security Questionnaire and Why Does It Exist?
An IT security questionnaire (also called a vendor security assessment, due diligence questionnaire, or third-party risk assessment) is a structured document that enterprise customers send to their suppliers before granting system access or signing contracts. The buyer needs to know: if something goes wrong on your side, what's the risk to their data and operations?
Third-party vendors now account for more than 60% of enterprise cyber risk. This is why procurement teams at large organisations routinely assess their suppliers — they're managing their own compliance obligations, and a weak vendor in their supply chain is their problem too.
The questionnaire usually covers six areas:
The Most Common Questions — and How to Answer Them
The 30 most common questions appear in virtually every assessment — encryption, vulnerability scanning, incident response, access management, and certifications. Here are the most frequent, with guidance on what good answers look like.
1. "Do you have a formal information security policy?"
What they want: A written document that covers how your company manages information security — not a generic template, but something that reflects your actual practices.
What a good answer looks like: "Yes. We maintain a written information security policy reviewed annually. It covers access control, device management, data handling, incident response, and employee security training. Available on request."
If you don't have one: This is a gap to close. A one-page policy document covering the basics is better than nothing. If you work with deeploi, you can reference deeploi's ISO 27001 certified security framework as part of your answer.
2. "Do you hold ISO 27001 certification or SOC 2?"
What they want: Independent, third-party verification that your security controls meet an internationally recognised standard.
What a good answer looks like: "We are not currently ISO 27001 certified as an organisation. However, we work exclusively with ISO 27001 certified technology providers — our IT management platform deeploi is ISO 27001 certified and GDPR compliant. Certificate available on request."
If you're working toward certification: "We are currently in preparation for ISO 27001 certification, with an expected completion date of [quarter]. In the interim, we work with ISO 27001 certified providers and maintain the following controls..." Security reviewers respect transparency and concrete timelines.
3. "How do you manage access to systems and data?"
What they want: Evidence that only authorised people can access sensitive systems, and that access is revoked when someone leaves.
What a good answer looks like: "Access is managed on a least-privilege basis — each team member has access only to the systems required for their role. We use [Google Workspace / Microsoft 365] with mandatory multi-factor authentication enforced at the identity provider level. Access rights are reviewed quarterly. When an employee leaves, all accounts and access are revoked on the departure date via automated offboarding."
The deeploi angle: Automated offboarding means you can genuinely answer that access is revoked on the departure date — not "when we get to it." That's a meaningful difference in a security review.
4. "How is data encrypted in transit and at rest?"
What they want: Confirmation that data is protected whether it's being sent across a network or stored on a device or server.
What a good answer looks like: "Data in transit is encrypted via TLS 1.2 or higher for all communications. Data at rest is encrypted on all endpoints — FileVault on macOS devices, BitLocker on Windows devices — enforced centrally via our MDM platform. Cloud data is encrypted at rest by our providers (Google/Microsoft), both of which operate EU data centres."
The key detail: "Enforced centrally via MDM" is a stronger answer than "we ask employees to enable encryption." The first is a control; the second is a hope. With central device management, you can honestly say it's enforced.
5. "Do you have an incident response plan?"
What they want: A documented process for what happens when a security incident occurs — who is contacted, what is isolated, how users are informed, and what the timeline is.
What a good answer looks like: "Yes. Our incident response plan covers detection, containment, assessment, notification, and remediation. In the event of a confirmed breach involving personal data, we are committed to notifying affected parties and the relevant data protection authority within 72 hours as required by GDPR. Key contacts and escalation paths are documented and reviewed annually."
What to prepare: Even a one-page incident response document is better than no document. It should cover: who to contact internally, when to notify the affected customer, when to notify the supervisory authority, and who leads the response. For a deeper dive, see our article on NIS2 compliance for SMBs.
6. "Where is your data stored and processed?"
What they want: Confirmation that data stays within a specific jurisdiction — usually the EU for European enterprise customers — and doesn't flow through third countries without appropriate safeguards.
What a good answer looks like: "All company data is stored and processed within the European Union. Our email and document infrastructure runs on [Google Workspace / Microsoft 365] EU data centres. Our IT management platform (deeploi) is EU-hosted and ISO 27001 certified. We do not transfer personal data to third countries without appropriate safeguards."
7. "How do you manage software patches and updates?"
What they want: Confirmation that you're not running outdated software with known vulnerabilities — one of the most common entry points for attackers.
What a good answer looks like: "Software updates and security patches are applied automatically to all managed devices via our MDM platform. Critical patches are applied within 24 hours of release. Update status is monitored centrally and reported on a monthly basis."
The deeploi answer: deeploi checks for updates every 24 hours and applies them automatically across all managed devices. This is a genuine, documentable control — not a manual process.
8. "What is your policy for employee security training?"
What they want: Evidence that your team knows how to recognise and respond to security threats — particularly phishing, which remains the most common attack vector.
What a good answer looks like: "All employees receive security awareness training on joining, covering phishing recognition, password hygiene, data handling, and incident reporting. Training is refreshed annually. We additionally enforce technical controls — MFA, endpoint protection, managed devices — so that security does not depend solely on employee behaviour."
How to Build Your Security Pack
The companies that handle security questionnaires efficiently don't answer them from scratch each time. They maintain a security pack — a set of pre-prepared answers and documents that cover 80% of any questionnaire, adaptable for each new request.
Your security pack should include:
Documents to prepare once:
- Information security policy (1–2 pages)
- Incident response plan (1 page minimum)
- Data processing register (which data you hold, where it lives, who has access)
- List of sub-processors (every SaaS tool that touches customer data, with their DPA links)
- Employee onboarding and offboarding IT checklist
Evidence to have on file:
- ISO 27001 certificate from your IT provider (deeploi's is available on request)
- GDPR data processing agreements from your key tools (Google, Microsoft, Slack, etc.)
- MFA enforcement screenshot or policy confirmation
- Disk encryption enforcement confirmation
- Patch management process documentation
Standard answers to pre-write:
For each of the seven question categories above, write a standard answer that reflects your actual posture. Review and update these annually. When a questionnaire arrives, copy, adapt for the specific buyer, and send.
Companies that systematise their questionnaire response cut average response time from 3 weeks to 4 days and win 30–50% more enterprise deals.
What to Do When You Don't Have a Good Answer
This is where most SMBs freeze. The questionnaire asks about something you genuinely haven't done — a formal risk assessment, a penetration test, a business continuity plan.
The honest answer beats a vague one every time. Security reviewers respect transparency and concrete timelines. A good structure for gaps:
"We do not currently have [X]. We are addressing this through [partial measure or planned action], with an expected completion date of [quarter/year]."
This acknowledges the gap, demonstrates you're not ignoring it, and gives the reviewer something concrete to work with. Lying or over-claiming on a security questionnaire creates legal exposure and, if a breach occurs, will be scrutinised.
What you should not do: leave questions blank, give non-answers ("we take security seriously"), or claim certifications you don't have.
How deeploi Makes Questionnaires Easier to Answer
Working with a managed IT platform like deeploi gives you a set of answers that are genuinely true — not just aspirational:
These aren't claims you're making — they're controls that are enforced by the platform and documentable with evidence. That's what enterprise procurement teams want to see.
Book a demo to see how deeploi supports your security posture
Conclusion
An enterprise security questionnaire is not an obstacle — it's an opportunity to demonstrate that you take security seriously and can be trusted with data. Companies that build a reusable security pack, understand the most common questions, and work with certified providers handle these requests in days rather than weeks.
The questionnaire will keep coming as you grow. Every enterprise deal, every procurement process, every new customer of a certain size will want to know your security posture. Setting it up properly once — policy document, incident response plan, sub-processor list, evidence pack — means the next questionnaire takes hours instead of weeks.
See how deeploi's ISO 27001 certified infrastructure supports your answers
Frequently asked questions
What is a vendor security questionnaire?
A vendor security questionnaire is a structured document sent by enterprise customers to their suppliers before granting data access or signing contracts. It assesses the supplier's security controls, compliance status, and risk posture across areas including access management, encryption, incident response, and certifications like ISO 27001 and GDPR compliance.
Do I need ISO 27001 to answer a security questionnaire?
No — ISO 27001 certification helps, but it's not always required. Many enterprise customers accept documented controls, evidence of equivalent practices, and third-party certifications from your IT providers as sufficient. Working with an ISO 27001 certified IT partner like deeploi means you can reference that certification as part of your answer even if your company isn't certified itself.
How long does it take to complete a vendor security questionnaire?
Without preparation: 2–4 weeks, often involving an engineer and a founder. With a pre-built security pack: 24–48 hours. The difference is almost entirely in preparation — having standard answers, evidence documents, and policy files ready before the questionnaire arrives.
What happens if I don't have a good answer to a question?
Be honest and give a concrete timeline. Security reviewers evaluate your overall posture, not just individual answers. A gap acknowledged with a clear remediation plan is significantly better than a vague claim or a blank field. Misrepresenting your security posture creates legal exposure and damages trust if an incident later occurs.
Can I use deeploi's ISO 27001 certification in my questionnaire answers?
Yes. When you work with deeploi, you can reference our ISO 27001 certification as evidence that your IT management infrastructure meets the standard. Our certificate is available on request. You can also document deeploi-enforced controls — disk encryption, patch management, endpoint protection, automated offboarding — as part of your technical and organisational measures (TOMs).










