The enterprise security questionnaire: how to pass VSA/SIG/CAIQ without stalling the deal
The deal is almost closed, and then procurement sends over "a short security questionnaire" — a spreadsheet with 200–400 questions about encryption, access, backups and incidents. For many product teams it is their first ever contact with corporate security — and a frequent reason deals stall for months. Here is how vendor security assessment works and how to get through it fast.
Why the customer needs your questionnaire
An enterprise is accountable for its vendors' risks: a leak at the vendor is a leak of the customer's data, and the regulator does not care whose server leaked. So procurement must assess your security before signing. The standard formats: SIG (several hundred questions, beloved by the financial sector), CAIQ (cloud services), VSA, and endless homemade Excel sheets "inspired by ISO 27001".
Understand the questionnaire's role: it is not an exam in perfection but a risk record. The customer is almost always willing to work with a vendor that has gaps — if they are honestly named and there is a plan to close them. The worst move is lying: it surfaces in an audit or an incident and kills not the deal but the relationship.
How to answer: three rules
- ◇Do not lie, but do not self-sabotage either. To "do you have a 24/7 SOC" a small company's honest answer is "no, our monitoring works like this: …". A description of the real process is almost always accepted; a bare "no" without context is a red flag for the reviewer.
- ◇Answer the question that was asked, not a neighboring one. The reviewer processes hundreds of questionnaires; vague "we are secure" answers guarantee a clarification round and +2 weeks to the deal.
- ◇One source of truth. Maintain an internal document with canonical answers (policies, diagrams, facts) — and assemble every next questionnaire from it rather than from scratch. The second questionnaire takes a day instead of two weeks.
What gets asked most — and what to prepare in advance
- ◇Organization: a person responsible for security, policies (access, passwords, incidents, backup), employee training. A minimal policy set takes a week to write — but must match reality.
- ◇Access: MFA, least privilege, offboarding (how fast a departed employee is cut off), secrets management.
- ◇Data: encryption in transit and at rest, customer data segregation, retention and deletion, where the data physically lives.
- ◇Development: code review, dependency management, test environments without production data, CI/CD access.
- ◇Verification: a pentest within the last 12 months is almost always a mandatory item; the report's executive summary is often requested. A vulnerability scanner is a plus but does not replace a pentest.
- ◇Incidents: a response process, a commitment to notify the customer within an agreed window, an escalation contact.
The pentest's role in the questionnaire
"Date of the last pentest and the report summary" is an item words cannot close: you need a document from an independent vendor. A good pentest report works across multiple deals: the executive summary goes to customers under NDA, the findings and retest demonstrate process maturity. It is the most expensive questionnaire item — and the most convertible: one pentest closes the question in every questionnaire for a year.
If the deadline is burning and there is no pentest: the honest answer "a pentest is scheduled for [date], the vendor is selected", backed by a contract, is usually accepted as a compensating measure. In that scenario we quote within 24 hours and start in the nearest window.
FAQ
We fill in VSA/SIG/CAIQ or the customer's homemade questionnaire, prepare the documents and a pentest report to attach. A quote in 24 hours.
Get a quote