Enterprise security questionnaires — also called vendor due diligence questionnaires, security assessment questionnaires, or third-party risk assessments — arrive before every significant enterprise deal. How you respond determines whether the deal progresses smoothly or gets stuck in procurement for months.
This article covers the most common question domains, what good answers look like, and how to build a master response that reduces the time to answer each new questionnaire from weeks to days.
The Most Common Question Domains
1. Governance and Organisation
What they ask:
- Who is responsible for information security (CISO, security lead)?
- Is there an Information Security Management System (ISMS)?
- When was your security policy last reviewed?
What good answers look like:
- Named individual (title and name) responsible for security
- Confirmation of ISMS — "We operate an ISMS aligned with ISO 27001" or "We are ISO 27001 certified (scope: [state scope])"
- Date of last security policy review — within the last 12 months
2. Access Control
What they ask:
- Is multi-factor authentication required for access to systems containing customer data?
- Is role-based access control (RBAC) in place?
- How often is access reviewed?
What good answers look like:
- MFA: "MFA is mandatory for all production system access, including all systems where customer data is held."
- RBAC: "Access is granted on a least-privilege basis using role-based access control. Access is reviewed quarterly."
- Specific, not vague. "We implement appropriate access controls" scores poorly.
3. Data Security
What they ask:
- Is data encrypted at rest and in transit?
- What encryption standards do you use?
- Where is customer data stored?
What good answers look like:
- "Data is encrypted at rest using AES-256. Data is encrypted in transit using TLS 1.2 minimum (TLS 1.3 preferred)."
- "Customer data is stored in [cloud provider] infrastructure in [EU/UK/US — specific regions]."
- Key management: "Encryption keys are managed in [AWS KMS/Azure Key Vault/equivalent] with rotation every [period]."
4. Penetration Testing
What they ask:
- Do you conduct penetration testing?
- When was the last test conducted?
- By whom?
- Were findings remediated?
What good answers look like:
- "We conduct annual penetration tests conducted by an external specialist (NCC Group / Pentest People / equivalent). The most recent test was conducted in [month year]. All critical and high findings have been remediated. Evidence of testing available under NDA."
- Never: "We conduct penetration testing" with no details. Procurement teams know what this means — it means you probably don't.
5. Vulnerability Management
What they ask:
- How do you identify and manage security vulnerabilities?
- What are your SLAs for patching?
What good answers look like:
- "Automated vulnerability scanning runs [weekly/daily]. Critical vulnerabilities are remediated within 72 hours. High vulnerabilities are remediated within 30 days."
- "Dependency scanning (SCA) is integrated into our CI/CD pipeline. Alerts on known CVEs are triaged by the engineering team."
6. Incident Response
What they ask:
- Do you have an incident response plan?
- When was it last tested?
- What is your notification commitment if a security incident affects our data?
What good answers look like:
- "We have a documented incident response procedure, tested annually (tabletop exercise in [date])."
- "We will notify affected customers of security incidents within [4/24] hours of detection. Major incidents are escalated immediately."
- Specific timelines that match what your contracts promise.
7. Business Continuity
What they ask:
- Do you have a business continuity plan?
- What are your RTO and RPO?
- When was the BCP last tested?
What good answers look like:
- "Recovery Time Objective (RTO): [X hours]. Recovery Point Objective (RPO): [Y hours]. BCP tested annually — most recent test [date]."
- If your RTO/RPO varies by service: specify for the relevant service.
8. Sub-Processors and Third Parties
What they ask:
- Who are your sub-processors?
- How are sub-processors assessed?
- Are sub-processors bound by equivalent obligations?
What good answers look like:
- "Our current sub-processor list is available at [URL] and was last updated [date]."
- "Sub-processors are assessed against our information security standards before onboarding. All sub-processors handling customer data are bound to equivalent data protection obligations."
9. Compliance and Certifications
What they ask:
- What security certifications do you hold?
- Are you GDPR compliant?
- Do you have a Data Processing Agreement?
What good answers look like:
- "ISO 27001 certified (scope: [scope], certificate valid until [date])."
- "SOC 2 Type II report available to customers under NDA (period ending [date])."
- "GDPR compliant. Our standard DPA is available at [URL]."
Building a Master Response Document
The fastest way to handle multiple enterprise questionnaires is to build a master response document that pre-answers all common questions. Maintain this as a living document updated at least annually.
Structure:
- Section 1: Governance and organisation
- Section 2: Access control
- Section 3: Data security and encryption
- Section 4: Vulnerability management
- Section 5: Penetration testing
- Section 6: Incident response
- Section 7: Business continuity
- Section 8: Third parties and sub-processors
- Section 9: Certifications and compliance
- Section 10: DORA-specific (for financial services customers)
When a new questionnaire arrives, map its questions to your master document. Most questionnaire answers can be adapted from the master in under an hour.
What Delays Enterprise Deals
Security questionnaire delays are almost always caused by one of:
- Questions you cannot answer — you lack the control or the documentation
- Answers that don't match your reality — a policy says X but you do X-minus
- Missing certifications — no ISO 27001, no SOC 2, no penetration test evidence
Address items 1 and 2 by building your compliance programme. Address item 3 by prioritising the certifications that your target customer segment requires — typically ISO 27001 or SOC 2 Type II.