Blog

Vendor security questionnaire: how to respond when selling to enterprise

15 August 2026 · FPSEC security team

You have been chasing an enterprise deal for six months. Procurement has finally signed off, the legal redlines are mostly settled, and then an email lands asking you to fill out a 200-question vendor security questionnaire. Three weeks later you are still waiting on a pen test summary from engineering and the deal has stalled.

This post explains what is actually in a vendor security questionnaire, what enterprise buyers look at first, and how to set up an answer library so the next one takes days, not weeks. It is written for founders and security leads at Series A and B SaaS companies who are starting to sell into regulated verticals.

Key takeaways

  • A vendor security questionnaire is the form a buyer sends before they will sign a contract — usually 50 to 300 questions across security, privacy, infrastructure, and compliance.
  • Most questionnaires reuse the same 10 sections. You can answer 80% of incoming questionnaires with a maintained answer library, not a one-off scramble.
  • Buyers look at evidence, not narrative. A public security audit certificate with a verify URL closes more questions than a polished PDF.
  • The slowest part of the response is usually internal — collecting SOC 2 reports, pen test summaries, and architecture diagrams from your team.
  • A security audit certificate dated within the last 6 months resolves the application-security questions before the questionnaire even lands.

What a vendor security questionnaire actually is

A vendor security questionnaire is a structured form a buyer sends before signing a contract. It asks about your security program, your application, your infrastructure, your privacy posture, and your incident response. The buyer uses the answers to decide whether your company is an acceptable risk to onboard.

Most questionnaires are delivered through a vendor risk management platform — the common ones are Vanta, Drata, Whistic, and SecurityScorecard. The platform usually lets the buyer reuse answers from one vendor to the next, which means the same questions show up across dozens of buyers. That is good news for you: it means an answer library pays off after the second questionnaire, not the tenth.

Who sends one, and when

Enterprise buyers in regulated verticals (finance, healthcare, insurance, government) and any company with a procurement security team. Mid-market SaaS buyers are starting to send them too — especially once they have a security hire of their own. In practice the questionnaire usually lands after procurement has signed off commercially and before the contract is countersigned.

The trigger is almost always the first deal over a threshold — the buyer’s procurement policy kicks in once the contract is above a dollar figure or once the data they share with you crosses a sensitivity threshold. The questionnaire is not optional. If the buyer sends it, they will not sign without it.

The 10 sections every questionnaire covers

Questionnaires vary in length and tone, but they cluster around the same ten sections. Knowing the sections means you can answer most questionnaires from a maintained library instead of a one-off scramble.

Company & contact informationBuyer weight: Low

Legal entity, address, primary security contact, and the person who signs the response. Easy to fill out — most teams just paste it.

Information security programBuyer weight: High

Whether you have a written security policy, who owns it, how often it is reviewed, and how employees are trained. Buyers want to see this is not improvised.

Access control & identityBuyer weight: High

SSO, MFA enforcement, role-based access, just-in-time access for production, and how access is revoked when employees leave. The answers usually match what your engineering team actually does — buyers will spot the gap.

Encryption & key managementBuyer weight: High

TLS in transit, encryption at rest, key rotation, and where the keys live. Most questionnaires accept a sentence confirming TLS 1.2+ and AES-256 — what matters is the public evidence.

Application securityBuyer weight: High

Whether the application is tested, how often, by whom, and against what coverage matrix. This is the section a public security audit certificate answers better than any narrative.

Infrastructure & hostingBuyer weight: Medium

Where the application runs, who provides the underlying cloud, what regions, and how availability is engineered. Buyers in regulated verticals also ask about data residency.

Logging & monitoringBuyer weight: Medium

Retention windows, SIEM usage, alerting, and incident response runbooks. Buyers rarely dig deep here unless the questionnaire is from a regulated buyer.

Vulnerability managementBuyer weight: Medium

Patch cadence, dependency scanning, and how CVEs are triaged. A sentence is usually enough if your dependency scanner is running.

Incident response & breach notificationBuyer weight: High

Whether you have a runbook, who declares an incident, and how customers are notified. Most buyers want a contractual SLA — usually 72 hours.

Privacy, sub-processors, and data handlingBuyer weight: High

GDPR posture, sub-processor list, data retention, and where customer data is stored. This is usually the longest section and the one most likely to delay the deal.

What enterprise buyers actually look at

Most questionnaires are reviewed by a single analyst who is skimming for red flags, not reading every answer. They are looking for four things:

Recent, dated evidence

An audit certificate dated within the last 6 months. A pen test report dated within the last 12 months. A SOC 2 report with a current observation window. Anything older than a year triggers follow-up questions.

Public, verifiable artifacts

A certificate with a verify URL the buyer can click. A public trust page. A status page that shows uptime. Anything the buyer can resolve themselves, without scheduling a call.

Application-layer evidence, not just policy

SOC 2 covers operating controls. Buyers want to see that the actual application is tested, not just that your company has policies. This is the gap a security audit certificate fills.

Consistency across documents

If your trust page says you run quarterly pen tests, your questionnaire answer should match. Inconsistency is one of the top reasons questionnaires get escalated to a follow-up call.

How to prepare a response library

A response library is a single document (or wiki page) with a canonical answer for every common question. It is not a polished marketing document — it is a working reference that one person on your team owns and updates after each questionnaire.

The minimum useful structure has four columns: the question, the canonical answer, the evidence to attach (link to a policy, a certificate, a screenshot), and the date the answer was last verified. Anything older than six months gets flagged for review.

Once the library exists, responding to a new questionnaire is a matter of mapping the questions to your library entries and reviewing the gaps. Most teams cut their response time from two weeks to two days this way.

Mistakes that lose deals

Treating the questionnaire as one-off work

If you answer the same questions fresh for every buyer, you burn a week per deal and the answers drift. Maintain an answer library and reuse.

Writing paragraphs where a sentence is enough

Buyers scan questionnaires. A 200-word essay on your security philosophy does not help. Short factual answers with evidence attached do.

Sending a SOC 2 PDF and calling it done

SOC 2 covers operating controls, not application security. If your questionnaire is about application-layer testing, the SOC 2 PDF is a partial answer.

Hiding gaps behind hedging language

Buyers spot ‘we are working towards’ and ‘industry-standard’ within seconds. If you do not do something yet, say so, and say when you will.

Forgetting the verify URL

A security audit certificate that does not resolve to a public verify page is just a logo. The URL is the part that actually closes the question.

How a security audit certificate helps

The application-security section is the one most SaaS teams stumble on. SOC 2 does not cover it — SOC 2 attests to operating controls, not the security of the actual product. A pen test report covers it but is confidential, so you cannot share it freely. That leaves a gap, and the gap is exactly where most questionnaires stall.

A security audit certificate closes the gap. It is a public, dated attestation that the application was tested against a published coverage matrix on a specific date. The buyer can click the verify URL, see the score, the scope, and the coverage — without scheduling a call or signing an NDA. Most application-security questions resolve to one link.

A certificate dated within the last six months is the easiest evidence to attach. Re-issuance at the same scope is typically free within the first three months, which means the certificate you sent with last quarter’s questionnaire still answers this quarter’s.

Frequently asked questions

What is a vendor security questionnaire?

It is the form a buyer sends before signing a contract, asking about your security, privacy, and compliance posture. It is usually 50 to 300 questions and lives inside a vendor risk management (VRM) platform.

Who sends vendor security questionnaires?

Enterprise buyers in regulated verticals (finance, healthcare, government) and any company with a vendor risk management program. Mid-market SaaS buyers are starting to send them too, often via shared VRM platforms.

How long does it take to respond?

First response usually takes 5 to 15 business days. With a maintained answer library and current evidence (SOC 2, pen test, security audit certificate), most teams turn it around in 2 to 5 days.

Do I need a SOC 2 to pass a vendor security questionnaire?

Not always. Smaller questionnaires accept an audit certificate, a pen test summary, and a published security page in place of SOC 2. Larger enterprise questionnaires from regulated buyers usually do require SOC 2.

What is the difference between a vendor security questionnaire and a vendor security review?

The questionnaire is the form. The review is the broader process — questionnaire, follow-up calls, architecture review, contract redlines, and (sometimes) an on-site or virtual audit. The questionnaire is usually the first step.

How does a security audit certificate help with the questionnaire?

It resolves the application-security section in one link. The buyer sees a public certificate with a score, a scope, a coverage matrix, and a verify URL they can resolve themselves — without scheduling a call or signing an NDA.

Can I share a penetration test report instead of a certificate?

Pen test reports are confidential by design. Most buyers will accept a pen test summary or letter of attestation, but not the full report. A security audit certificate is the public-friendly artifact.

If you are about to receive your first enterprise questionnaire and do not yet have evidence to attach, AppCheck delivers a score, a fix list, and a public certificate for €500 per audit — in days, not weeks. The certificate comes with a verify URL that resolves to the full record, so you can paste it into the questionnaire once and stop chasing internal evidence for every deal. See how AppCheck works.

Responding to a questionnaire this week?

AppCheck issues a public certificate with a verify URL, dated and scoped to your app — ready to paste into the questionnaire before your buyer has to chase you.