How to answer a customer security questionnaire without guessing
This guide is for non-engineers who need to complete a customer security questionnaire accurately and quickly. You will leave with a repeatable way to gather facts, mark unknowns safely, and return answers your software agency can stand behind.
TL;DR — Security questionnaires go wrong when people guess, copy old answers, or answer from memory. The fastest safe path is to build a fact sheet from your real systems, answer only from that sheet, and mark anything unverified as "Needs confirmation" with an owner and due date. Reading time: ~5 min
Goal
When you finish, you will have a completed security questionnaire where every answer is backed by a source you can point to: a policy document, a dashboard screenshot, a contract, or a named internal owner. Anything not yet verified will be clearly marked for follow-up instead of guessed.
Prerequisites
- Access to the customer's questionnaire file or portal
- Access to your agency's shared documents folder or wiki where policies, contracts, and architecture notes live
- Read access to the systems you need to reference, such as your cloud provider dashboard, identity provider (SSO, single sign-on) admin area, ticketing system, code hosting platform, and backup provider
- A spreadsheet app or document editor
- A place to save evidence, such as a folder named
security-questionnaire-YYYY-MM-DD - The name of one internal approver for each area: engineering, infrastructure, HR, and legal/privacy
- If available, your latest security policy, incident response policy, backup policy, access control policy, and data retention policy
- If available, your latest penetration test, vulnerability scan, SOC 2 / ISO 27001 report, DPA (data processing agreement), and subprocessors list
Steps
Step 1: Save a working copy and create an evidence folder
Create a copy of the questionnaire before editing it, and create one folder for supporting files.
Questionnaire file name: customer-security-questionnaire-working-copy-YYYY-MM-DD.xlsx
Evidence folder name: security-questionnaire-YYYY-MM-DD
What you should see when this succeeds: you have a separate working file and an empty folder ready for screenshots, PDFs, and notes.
Step 2: Build a simple answer tracker
Create a spreadsheet tab or separate sheet with these exact columns.
Question ID | Customer question | Draft answer | Status | Evidence source | System owner | Last verified date | Notes
Set Status to one of these exact values.
Answered
Needs confirmation
Not applicable
What you should see when this succeeds: every questionnaire item has a row in your tracker, even if the answer is blank.
Step 3: Sort each question into one evidence type
For each question, put one of these exact values in the Evidence source column.
Policy document
Dashboard setting
Contract or report
Internal owner confirmation
Not applicable
Use this quick mapping:
| If the question asks about... | Put this in Evidence source |
|---|---|
| MFA (multi-factor authentication), SSO, password rules, user access | Dashboard setting |
| Backups, logging, encryption, hosting region | Dashboard setting |
| Incident response, onboarding/offboarding, retention | Policy document |
| Pen test, SOC 2, ISO 27001, cyber insurance | Contract or report |
| Future roadmap, custom exception, unclear wording | Internal owner confirmation |
What you should see when this succeeds: each row has one evidence type, which tells you where to look next.
Step 4: Collect facts from dashboards first
Open the admin dashboards you already use and record only what you can see directly. Use your provider's dashboard paths; common examples are below.
Identity provider dashboard (e.g. Okta, Microsoft Entra, Google Workspace) → Security or Authentication → MFA
Cloud provider dashboard (e.g. AWS, Azure, GCP) → Storage / Backups / Logging / Regions
Code hosting (e.g. GitHub, GitLab) → Organization Settings → Security
Device management (if used) → Policies → Disk encryption / Screen lock
Ticketing system → Search for "termination", "offboarding", "incident"
Record answers in plain language. Examples:
"MFA is required for all staff in the identity provider. Verified in admin dashboard on 2026-08-10."
"Production data is hosted in eu-west-1. Verified in cloud dashboard on 2026-08-10."
"Audit logs are enabled for the code hosting organization. Verified in organization security settings on 2026-08-10."
What you should see when this succeeds: many rows move to Answered, and each one names the dashboard or screen where you found it.
Step 5: Pull exact wording from policies and reports
Open your existing documents and copy only the statement that answers the question. Do not rewrite a policy from memory.
Shared drive or wiki → Security Policies → Access Control Policy
Shared drive or wiki → Security Policies → Incident Response Policy
Shared drive or wiki → Security Policies → Backup and Retention Policy
Shared drive or wiki → Compliance → SOC 2 / ISO 27001 / Penetration Test
Shared drive or wiki → Legal → DPA / Subprocessors List
Use this answer pattern in the Draft answer column.
"Yes. See Access Control Policy, section 3.2, reviewed 2026-05-14."
"Annual penetration test performed by third party. Latest report date: 2026-03-22. Report available under NDA."
"Customer data retention is defined in Data Retention Policy, section 4.1."
What you should see when this succeeds: policy and compliance questions now cite a document name and date, not a vague statement.
Step 6: Mark unknowns safely instead of guessing
For any row you cannot verify in 5 minutes, enter this exact text in Draft answer and assign an owner.
Needs confirmation. Current best source is unavailable or not yet verified. Owner: <name>. Target date: YYYY-MM-DD.
Set Status to:
Needs confirmation
What you should see when this succeeds: no blank rows remain, and no answer depends on memory.
Step 7: Use safe wording for "not applicable" and "available under NDA"
When a question does not fit your service, use this exact wording.
Not applicable. This service does not process payment card data.
Not applicable. We do not provide customer-managed endpoint devices as part of this service.
When you have the document but should not attach it broadly, use this exact wording.
Available on request under NDA.
What you should see when this succeeds: exceptions are clear, narrow, and do not over-claim.
Step 8: Get named approvals before submission
Send only the rows marked Needs confirmation or high-risk topics to the right owner. Use this exact message template.
Subject: Security questionnaire confirmation needed by YYYY-MM-DD
Please confirm the answers below by replying with one of these exact phrases:
- Confirmed as written
- Replace with: <your corrected text>
- Not applicable
Questions:
1. <Question ID> — <Draft answer>
2. <Question ID> — <Draft answer>
What you should see when this succeeds: each uncertain answer has a written confirmation or corrected text from a named owner.
Step 9: Fill the customer form from your tracker, not from memory
Copy answers from the tracker into the customer's file or portal. If the portal has a free-text field, paste the exact approved wording. If it has yes/no only, keep the detailed evidence in your tracker.
For every "Yes" answer, keep one matching evidence line in your tracker.
For every "No" answer, add a short truthful explanation in Notes.
For every "Needs confirmation" item, do not submit until the owner replies or the customer accepts a follow-up answer.
What you should see when this succeeds: the submitted questionnaire matches your tracker line for line.
Verify it works
Use this checklist before you send the final file.
[ ] Every question has Status = Answered, Needs confirmation, or Not applicable
[ ] No row contains "I think", "probably", "usually", or "should"
[ ] Every "Yes" answer has an Evidence source and Last verified date
[ ] Every attached report or policy has a document date
[ ] Every unknown has an owner and target date
[ ] The final customer file matches the tracker wording
A successful result is: you can pick any answer in the questionnaire and immediately show where it came from.
Common pitfalls
Reusing an old questionnaire without re-checking dates
Mistake: copying last year's answers into the new form.
Symptom: answers mention expired reports, old staff counts, or outdated hosting details.
Fix: replace every reused answer with a current Last verified date and a current source.
Answering "Yes" because the team intends to do it
Mistake: treating planned work as already implemented.
Symptom: the customer asks for proof, and none exists.
Fix: change the answer to Needs confirmation or No, then add a short note such as Planned, not yet implemented.
Saying "encrypted" without stating where
Mistake: writing a broad claim like All data is encrypted.
Symptom: follow-up questions ask whether this means at rest, in transit, backups, laptops, or databases.
Fix: split the answer into exact scopes, for example TLS in transit and AES-256 at rest in cloud storage, only if you can verify both.
Marking a question "Not applicable" too broadly
Mistake: using N/A for a control that still applies to your service.
Symptom: the customer flags the response as evasive and asks for a rewrite.
Fix: replace N/A with a narrow truthful answer, such as We do not issue laptops, but staff devices must use disk encryption under the device policy.
Attaching sensitive reports too early
Mistake: uploading full pen test or audit reports to a broad portal without approval.
Symptom: legal or security asks you to retract the file.
Fix: replace the attachment with Available on request under NDA unless your process explicitly allows upload.
Leaving ownership unclear for unanswered items
Mistake: writing Need engineering input with no name.
Symptom: the questionnaire stalls because nobody knows who must reply.
Fix: add one named owner and one target date on the same line.
This article was written by an AI system and published pending human review. Verify anything you intend to act on.
Have a project in mind?
Get an instant AI price estimate for it, or talk directly to our team.
One email a month on what we learn building with AI