The client security questionnaire nobody warned you about
A corporate client sends forty questions about your technology, due in a fortnight, written for a company a hundred times your size. Here is how to answer it without either lying or losing the work.
It arrives from the client's procurement or risk team, usually attached to a renewal, and it is almost never negotiable. Forty to two hundred questions about encryption, access control, incident response and sub-processors, with a two-week deadline and a spreadsheet format that does not allow for nuance.
The document was written for suppliers with a security department. You are a firm of fifteen with a practice-management system and a managing partner who signs things. Both of those facts are fine. What decides the outcome is how you answer, not how big you are.
The three answers, and only one of them is fatal
Every question has three honest possible answers: yes with evidence, no with a date, or not applicable with a reason. Reviewers accept all three. What they do not accept, and what gets a supplier escalated rather than approved, is a yes that turns out to be aspirational.
- Yes, with evidence. Name the control and be ready to show it. 'Multi-factor authentication is enforced on all user accounts' should survive somebody asking for the policy export.
- No, with a date. 'Not currently in place; scheduled for Q1' is a legitimate answer and is routinely accepted. It is treated as a finding to track, not as a disqualification.
- Not applicable, with a reason. 'We hold no cardholder data, so PCI DSS requirements do not apply' closes the question properly. Leaving it blank does not.
What actually gets firms rejected
In our experience it is rarely the security posture. It is answering questions the person filling in the form did not understand, guessing at the technical detail, and producing a document that contradicts itself between question twelve and question thirty-eight. A reviewer who spots one contradiction re-reads the whole thing sceptically.
The second most common failure is missing the deadline because the form sat with the wrong person for ten days. These arrive addressed to whoever signed the last contract, not to whoever knows the answers.
The version to build once
Almost every questionnaire asks the same underlying thirty things in different words. A firm that has answered one carefully has answered most of the next one, provided the answers were written down somewhere reusable rather than typed straight into a client's spreadsheet and forgotten.
- Keep a master answer document, with the evidence each answer relies on attached to it.
- Date every answer. An eighteen-month-old 'yes' is a claim about a firm that may no longer exist.
- Record which client asked what. Outside counsel guidelines differ, and answering client B with client A's obligations is its own problem.
- Note the questions you could not answer. That list is the most useful security roadmap most firms will ever be handed, and a client paid to produce it.
Treat the questionnaire as free consulting rather than as an obstacle. A large client's risk team has just told you, in writing and for nothing, exactly what they think good looks like.