Guide

How to answer a security questionnaire fast, without overstating your posture.

A prospect's security review has landed as a spreadsheet with several hundred rows and a deadline. This is the process that gets it back in days instead of weeks, with answers you can defend if anyone checks.

Published 29 August 2026. About a 9 minute read.

First

Understand what the questionnaire is for.

A security questionnaire is not a marketing form. The reviewer on the other side is building a file that says "we checked this vendor, here is the evidence." They are scoring your answers against a control framework, and they are looking for the answers that would embarrass them later if they were wrong.

That changes how you write. The best answer is the one a reviewer can verify: a plain statement of what you do, where it is documented, and what the exception is. The worst answer is a confident Yes to a control you do not actually have. Yes answers become contract terms, and they get audited.

Everything below follows from one rule: answer from documents, not from memory. Speed comes from having the documents in one place. Defensibility comes from being able to point at them.

Process

The six steps.

  1. Triage before you answer anything.

    Open the file and take twenty minutes to understand it before touching a single answer.

    • Count the questions and find the format. A SIG Lite is a different day than a full SIG. A custom spreadsheet with merged cells and a dropdown per row needs to be flattened before anyone works on it.
    • Identify which sections apply. Standardized questionnaires cover physical security, HR, networks, and cloud in the same file. If you do not run your own data center, say so once and mark the section not applicable, rather than answering forty questions about badge readers.
    • Ask the sender two questions. Is N/A accepted with a reason? Will they accept a SOC 2 report or ISO certificate for any sections? A five-line email here regularly removes a third of the work.
    • Set the review deadline, not just the send deadline. Someone who signs contracts should read the finished answers before they leave the building. Leave a day for that.
  2. Gather the source documents into one folder.

    This is the step most teams skip, and it is why the questionnaire eats a week. Nearly every question on a security questionnaire is answered by a document you already maintain. Put them in one place before you start.

    DocumentAnswers questions about
    Information security policy (or ISMS policy set)Governance, roles, policy review cadence, risk management
    Access control and identity policyMFA, least privilege, joiner and leaver process, privileged access
    Encryption and key management standardData at rest, in transit, key rotation, certificate handling
    Incident response planDetection, escalation, customer notification timelines, post-incident review
    Business continuity and disaster recovery planBackups, RPO and RTO, failover testing, last test date
    Secure development and change management policyCode review, testing, deployment approvals, dependency scanning
    Vendor and subprocessor listThird parties, data flows, subprocessor review and notification
    Latest penetration test summaryTesting frequency, scope, remediation of findings
    SOC 2 report, ISO 27001 certificate, or bridge letterWhole sections, if the reviewer accepts them
    Data retention and deletion procedureRetention periods, deletion on termination, customer data return
    Privacy policy and DPA templatePersonal data handling, legal basis, cross-border transfer
    The last three completed questionnairesEverything you already answered once, and the wording legal approved

    If a document on this list does not exist, that is a finding in itself. Write it down. A one-page policy written this week, dated and approved, is a legitimate answer. A claim that a policy exists when it does not is not.

  3. Answer from the documents and note where each answer came from.

    Work through the questionnaire section by section, with the folder open. For each question, find the passage that supports the answer, write the answer in plain language, and record the source: file name and page or section. That reference is what makes review fast, and it is what you will hand the reviewer if they ask for evidence.

    A good answer has three parts and rarely needs more than three sentences:

    • The direct answer. Yes, No, Partial, or N/A, in the format the questionnaire asks for.
    • The control as practiced. "Production access requires SSO with MFA and is reviewed quarterly by the security lead."
    • The evidence. "Access Control Policy v3.2, section 4. Available on request."

    Resist the urge to write more. Reviewers are reading hundreds of answers. Long answers hide the fact that the control is missing, and reviewers know that.

  4. Handle the questions your documents do not answer.

    There will be some. How you handle them decides whether the reviewer trusts the rest of the file.

    • If you do not have the control, say No, then say what you do instead and, if there is a real plan, when it will change. "No. Backups are tested on restore every six months rather than quarterly; the next test is scheduled for October 2026."
    • If the question does not apply, say N/A and why in one line. "N/A. Mattercite does not operate physical data centers; infrastructure is hosted by Amazon Web Services in us-east-1."
    • If you do not know, find out before you answer. Ask the engineer or the vendor. Never fill the gap with a plausible guess. Most questionnaire disasters trace back to a guess that nobody flagged as a guess.

    A No with a compensating control reads as a mature program. A Yes that turns out to be untrue reads as a breach of contract. Reviewers expect gaps; they do not expect surprises.

  5. Review once, properly.

    One reviewer, one pass, with the sources beside them. The review has three jobs, in order:

    • Overstatement. For every Yes, is there a document that says so? If the source note is blank, the answer is a guess until proven otherwise.
    • Consistency. Questionnaires ask the same thing in three sections with different wording. Retention answered as 90 days in one section and 30 in another will be noticed.
    • Tone. Remove anything that reads as sales copy. The reviewer is not the buyer; they are the person who has to sign off on the buyer's risk.
  6. Export in their format and keep your own copy.

    Return the file in the shape it arrived. If it came as their Excel template, send their Excel template back with the columns intact. Reviewers who have to re-key your answers into their tool will remember it.

    Then keep a copy with your source notes attached. The next questionnaire will ask the same two hundred questions in a different order, and this file, together with the folder from step two, is what turns the next one into a same-day job.

Mistakes

What slows teams down.

  • Answering from memoryThe answers live in policies nobody has opened in a year. Memory produces confident answers that are six months out of date.
  • Copying the last questionnaire blindPrior answers are a source, not the truth. Controls change. Check that the policy still says what the old answer claims before reusing it.
  • Building an answer library firstCurating a Q&A bank before you answer anything moves the work, it does not remove it, and the bank starts drifting the day it is finished. Keep the documents current instead; they are the answer library.
  • Chasing SMEs one question at a timeBatch every unanswered question for a given owner into one message with the questions numbered. One interruption instead of thirty.
  • Skipping the sender emailAsking whether N/A is accepted and whether a SOC 2 report covers any sections is the highest-return five minutes in the process.
  • PaddingThree paragraphs where a sentence and a citation would do. It costs the reviewer time and hides gaps badly.

Tooling

Where a tool fits, and where it does not.

Nothing above requires software beyond a folder and a spreadsheet. A tool earns its place at step three, where finding the supporting passage for each of several hundred questions is the slow, repetitive part, and at step six, where reuse depends on the source notes actually being kept.

Mattercite is built for exactly this process. You upload the folder from step two, import the questionnaire in whatever format it arrived, and get an answer for each question that cites the source file and page. Questions the documents do not support are flagged as Needs Information rather than guessed, so step four stays honest. There is no answer library to build first, because the documents are the library. Read more on the security questionnaires page, or see how it compares to library-first tools.

Questions

Common questions.

How long should a security questionnaire take to answer?

It depends on the size and on how good your source documents are. A short custom review of 50 questions can be a same-day job for a team with current policies. A full SIG, with hundreds of questions, is commonly a week or more of someone's time when answered from memory and old spreadsheets. The biggest time savings come from answering from documents rather than from recall, and from not re-deriving answers every time.

Is it okay to answer N/A or No on a security questionnaire?

Yes, and it is far better than overstating. Reviewers expect gaps, and they expect to see them acknowledged. A No with a compensating control or a dated plan reads as a mature program. A Yes that turns out to be untrue is a contract and trust problem. Use N/A only when the question genuinely does not apply to your service, and say why in one line.

Should we share our SOC 2 report instead of filling in the questionnaire?

Offer it, but expect to fill in the questionnaire anyway. Many buyers accept a SOC 2 Type II report or an ISO 27001 certificate in place of some sections, and it is worth asking. Most still require their own form for the parts their report does not cover, and it is your source documents, not the certificate, that let you answer those parts accurately.

How does Mattercite help with security questionnaires?

You upload the policies and prior questionnaires you already have, import the questionnaire in the format it arrived (Excel, CSV, Word, or PDF), and review answers that cite the source file and page for each answer. Questions your documents do not support are flagged as Needs Information rather than guessed. It is built for the document-first process described on this page, without an answer library to build first.

Try it

Answer the next one from your documents.

Upload your policies, import the questionnaire as it arrived, and review answers that cite the source. Fourteen days free, 150 questions, no credit card.

Related: SIG vs SIG Lite vs CAIQ, what is a vendor DDQ, security questionnaires, buyer's guide to questionnaire automation.