ACloud.Solutions

ISO 27001 and compliance

How to answer security questionnaires: 240 questions, no lying

The spreadsheet has 240 rows across eleven tabs. Question 118 asks whether you have a documented process for secure disposal of physical media. Question 119 asks the same thing in different words. Question 174 asks about your SOC 2 Type II report, which you do not have, and the deal is waiting on this.

Learning how to answer security questionnaires quickly is the highest-return administrative skill in a small B2B software company, because the questionnaires never stop and the first one takes three days.

How to answer security questionnaires: the library is the technique

The second questionnaire should take a fraction of the first. That only happens if you build an answer library while doing the first one, which feels like overhead precisely when you have least patience for it.

Structure it by topic rather than by questionnaire: access control, encryption, secure development, incident response, business continuity, supplier management, data protection, physical security, personnel security, logging and monitoring.

For each answer store four things. The answer text, written to be reusable rather than tailored. The control reference it maps to, so a similar question finds it. The evidence that supports it and where that lives. And the last reviewed date, because a stale answer library is how you end up asserting something that stopped being true.

Two hundred and forty questions collapse to perhaps sixty distinct topics. Questionnaires overlap heavily because they descend from the same handful of industry templates, so the second one is largely a lookup and the fifth is mostly copy and paste with a check.

Mapping questions to controls and evidence

The reason to store the control reference is that it converts a wording problem into a lookup.

A question about "least privilege" and a question about "role-based access provisioning" and a question about "periodic entitlement review" are three phrasings of access control. Tag all three against the same control, and the library answers all three from one maintained entry.

If you hold ISO 27001, this mapping is already done: your Statement of Applicability records each control, the implementation, and where the evidence is. The questionnaire becomes a translation exercise from their wording to your control numbers, which is why certification pays for itself in sales cycle time independently of whether anyone asked for the certificate.

Not applicable, with a reason

"Not applicable" is a legitimate answer and most people are afraid of it, so they write something vague instead, which is worse.

A bare "N/A" reads as evasion. A justified one reads as competence, and it is the same pattern as justifying an SoA exclusion: state the factual circumstance, then say where the underlying risk is addressed.

"Not applicable. The company operates entirely remotely with no offices or data centres; all infrastructure is cloud-hosted. Physical security of the hosting environment is addressed through supplier assurance, and our provider's certifications are available on request."

That answer is better than describing a visitor sign-in book you do not have, and infinitely better than leaving it blank for somebody to chase.

The same applies to the honest negative. If you do not have a SOC 2 report, say so and say what you have instead. "We are certified to ISO/IEC 27001:2022, certificate available on request. We do not currently hold a SOC 2 Type II report." Procurement teams accept that far more often than people expect, because what they need is a documented basis for assurance rather than one specific document.

Certificate or Statement of Applicability

A judgement people get wrong in both directions.

Send the certificate by default. It is short, it is verifiable with the certification body, and it states the scope. Almost every questionnaire asking for evidence of certification is satisfied by it.

Send the Statement of Applicability when they ask specifically, or when your answer to a control question needs supporting. It is a much more revealing document: it shows what you excluded and why, and a thorough procurement analyst will read the exclusions.

Do not send the risk register. It is an internal document listing your weaknesses. Nobody needs it for assurance, and requests for it are usually a misunderstanding of what the standard produces. Offer the SoA instead.

The other thing to check on the certificate is that the scope matches what they are buying. A certificate whose scope excludes the product under discussion raises a harder question than not having one.

The question that always trips people up

Data residency, and specifically the difference between where data is stored and where it can be accessed from.

Most people answer the storage half correctly and stop. The follow-up, which arrives when the first answer is incomplete, is about access: does support personnel outside the region access production data, do sub-processors, is there onward transfer, and what safeguards apply.

For a UK company with EU customers, or vice versa, that is a real question with a real answer involving your transfer mechanism. The ICO's guidance on international transfers sets out what applies, and it is worth having a settled answer in the library because it comes up every time and improvising it is how you commit to something inaccurate.

Answer both halves unprompted. It saves a round trip and it signals that you understood the question.

Working through one at speed

Read every question first. Twenty minutes, and it stops you writing a long answer to question 40 that question 180 asks properly.

Answer from the library. Fill everything that matches, flag the rest.

Batch the genuine gaps and answer them by topic rather than in row order, because they cluster.

Never guess. An inaccurate questionnaire answer is a contractual representation. If you do not know, find out or say you will confirm. "Not currently, planned for Q3" is a survivable answer; a yes that turns out to be no is a different category of problem.

Add every new answer to the library before sending, while the reasoning is fresh.

Questions

How long should the first one take?

Two to three days for 240 questions if you are building the library at the same time. Half a day for the second. If the fifth still takes days, the library is not being maintained.

Should I use an AI tool to draft answers?

For rephrasing an answer you already have, yes. For generating answers about your own environment, no: it will produce plausible statements about controls you may not have, and you are the one signing them. The note on AI in a one-person security team covers where that line sits.

What if the questionnaire is clearly for a much larger company?

Say so politely and answer what applies. Questions about a dedicated SOC, a CISO or segregated development teams have honest answers at forty people, and compensating controls described plainly land better than pretending.

Can I refuse to complete one?

You can push back on scope, particularly on a questionnaire disproportionate to the contract value, and offering your certificate plus SoA in place of 240 questions sometimes works. Refusing entirely usually costs the deal.

Who should sign it off?

Whoever can commit the company, because the answers are representations. In practice you write it and a director reviews and sends it, which is also the leadership involvement an auditor expects to see around external commitments.