GetSOC2

Could you answer an enterprise security questionnaire today

A vendor risk questionnaire asks the same dozen things in a different order every time. Ten questions here tell you which sections you would answer well, which you would stall on, and what closes the gap.

Last reviewed 2026-09-14Written by Jacob Masse, TrazTech Inc.

Enterprise security questionnaires vary in length and not in substance. Under the hundreds of rows sit about ten subjects, and a reviewer is looking for the same thing in each one: a written statement, a control that operates, and evidence you could produce if asked. Answering "yes" without the third part is what turns a questionnaire into three rounds of follow-up.

This walks the ten subjects and scores what you could answer today with evidence in hand. It returns a readiness percentage, the sections you would fail, and the specific artefact that closes each one. Nothing is emailed anywhere unless you ask for it at the end.

Written security policies

Reviewers ask for the information security policy by name, and often for the acceptable use and incident response policies with it.

Access control and multi-factor authentication

Vulnerability management and testing

Incident response

Backups and recovery

Data handling, encryption and retention

Vendor and subprocessor management

Secure development and change management

People: screening, training and offboarding

Logging and monitoring

Privacy, residency and breach notification

Canadian buyers ask where data lives and what happens when something goes wrong, usually in the same section.

Who is asking, and what for?

How many people work there?

When is the answer due?

How the score is weighted

The ten sections are not equal. A reviewer who finds a gap in access control or incident response escalates it; a gap in security training gets a note and a request to fix it by renewal. The weighting below reflects what actually stops a deal rather than what takes up the most rows on the form.

Section weights, and what a reviewer is really checking
SectionWeightWhat they are checking
Access control14Whether a departed employee could still reach their data
Data handling and encryption13Where their data lives and what happens to it at the end
Incident response12Whether they would be told, and how fast
Vulnerability management11Whether anyone has looked for holes on purpose
Backups and recovery10Whether a restore has ever been proven
Secure development10Whether one engineer can push anything unreviewed
Vendor management9Who else touches their data through you
Logging and monitoring8Whether you would notice
Privacy and residency7Canadian buyers ask this first, and it is cheap to answer well
Policies6That something is written down and approved

What a reviewer does with your answers

Nobody reads all four hundred rows. A reviewer scans for the sections above, looks for internal contradictions, and picks two or three claims to ask evidence for. The fastest way through is to answer accurately, attach what you have, and mark the gaps as gaps with a date beside them. An honest "not yet, planned for Q3" moves through review faster than a "yes" that collapses under one follow-up question, because the second one costs the reviewer their own credibility.

The same material answers every questionnaire after the first one. Build the answer library once, keep the evidence with it, and the third questionnaire is an afternoon rather than a fortnight. That library is also most of what a SOC 2 report replaces, which is the actual argument for getting one. Why your customer wants a SOC 2 covers what the report does that a questionnaire cannot.

Common questions

Should we just answer yes to everything?

No, and not only for the obvious reason. A questionnaire answer usually ends up referenced in the contract as a representation, which turns an optimistic "yes" into a warranty you have breached from the day you signed. Reviewers also sample. The cost of being caught is the deal plus the relationship, and the cost of an honest gap with a date is a follow-up email.

Does a SOC 2 report replace the questionnaire?

Often it shortens it to a handful of rows, and at some buyers it replaces it entirely. What the report does that a questionnaire cannot is put an independent opinion behind the claims, which is why a vendor risk team will take it in place of asking you the same things again. How to read a SOC 2 report shows what they are looking at when they receive one.

What if we cannot answer a whole section?

Say so, name what you do instead, and give a date. A section answered "not currently, we use these compensating measures, planned for the second quarter" is a normal answer that reviewers see constantly. A blank cell is the one that gets escalated, because it reads as either a hidden problem or a company that did not take the request seriously.

How long does answering one take?

A first full questionnaire from a large enterprise is commonly twenty to forty hours spread over two to three weeks, most of it spent finding evidence rather than typing answers. Subsequent ones drop sharply if you kept the first set of answers and the artefacts together.

Is it worth getting SOC 2 instead of answering these?

Count the questionnaires. Three or four a year, each costing a fortnight of somebody senior, is a real number to compare against the cost of a report. Is SOC 2 worth it at our size works through that arithmetic, and what to offer instead covers the positions that hold while you decide.

Turn the gaps into a plan

Take the failing sections to Canadian firms and get the remediation priced against your own list.

Get matched