HireACISO

A security questionnaire and nobody owns it

Answer it yourself, this week, honestly. A first questionnaire takes a founder or a senior engineer 6 to 14 hours and no outside help. The reason to bring someone in is the second one, and the third, not this one.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

A customer has sent you a security questionnaire, nobody at your company has security in their job title, and the sales lead wants it back by Friday. Fill it in yourself. At 15 to 80 people a first questionnaire takes 6 to 14 hours of one competent person's time. Paying a consultant $200 to $400 CAD an hour is the wrong purchase. Most of those hours go on finding out things only your own people know.

Do not guess. In most procurement processes the questionnaire is contractual and the answers get attached to the agreement. A wrong yes is worse than an honest no with a date beside it. The craft is knowing which questions you can answer no to without losing the deal.

6 to 14 hours First questionnaire, done internally

2 to 4 hours Each one after that, once you have an answer library

Who should actually fill this in?

One person: whoever can answer the infrastructure questions without asking anyone. At 15 to 50 people that is the technical founder, the first engineering hire, or whoever set up the cloud account. The person who knows is rarely the person with the title. Not sales. Sales answers optimistically, and the optimistic answer is the one that comes back at renewal.

Give that person the deal context first: what the contract is worth, when it has to close, and who at the customer is reading the response. Without knowing which questions gate the deal, it goes slowly.

What to do this week

  1. Read the whole thing before answering anything. Count the questions and mark the ones you cannot answer yes to. That count is the real scope, and it is usually between 8 and 20 out of a 150 question spreadsheet.
  2. Ask the customer which sections are mandatory. Most questionnaires are one template sent to every supplier regardless of what they do. A security reviewer will usually tell you which twenty questions they care about for a vendor holding what you hold, and that conversation saves more time than any tool.
  3. Answer the easy two thirds from what is already true. Multi-factor authentication on the cloud console, encrypted storage, laptop disk encryption, an offboarding process. Write the answer once, in a shared document, in full sentences.
  4. For each no, write a date rather than an excuse. "No. We have a written incident response plan drafted and it will be approved by 31 October 2026" is an answer a reviewer can accept. "Not applicable" on a question that plainly applies is the answer that escalates.
  5. Have one other person read it before it goes back. The most common defect is a yes that the person answering believed was true and nobody had checked in a year.
  6. Keep the file. The next customer will send you 70 percent of the same questions, and the second questionnaire should take a quarter of the time. If it does not, you threw the file away.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

Which questions can you answer no to?

What a reviewer at a mid-sized Canadian or American buyer will and will not accept from a supplier of your size.

Common questionnaire items and whether a no is survivable at 15 to 80 staff
QuestionA no isWhat to write instead of an excuse
Do you enforce multi-factor authentication on all administrative access? Fatal Nothing. Turn it on before you send the response. It takes an afternoon
Do you hold a SOC 2 Type 2 report? Usually survivable once No, with the target date for your first audit and the auditor if you have engaged one
Do you have a named individual accountable for security? Fatal, and easy Name a real person with a real title. It does not have to be a CISO
Do you carry cyber liability insurance? Sometimes fatal, contract dependent Check the contract's insurance schedule first. This one has a dollar figure attached
Do you conduct annual penetration testing? Survivable with a date No, scheduled for a named quarter. A first external test runs $8,000 to $25,000 CAD
Do you have a formal security awareness training program? Survivable No, or an honest description of what you actually do at onboarding
Do you perform background checks on employees? Survivable, and often misunderstood in Canada Say what you do. Canadian employment and privacy law constrains this more than the American template assumes
Do you have a documented incident response plan? Survivable once, fatal on renewal No, with a date. This is four pages of work, not a project
Where is customer data stored? Not a yes or no Name the regions. Canadian public sector and health buyers care about this answer specifically

The pattern behind the table

A reviewer forgives an absent artifact and does not forgive an absent owner. Every fatal row above asks whether anyone is accountable, not whether you have bought something. Naming a person is the cheapest thing on this page, which makes who owns security when there is no CISO the decision to make before the next one arrives.

Before you send it back

When is it worth paying someone?

Not for the first questionnaire. Bring in help when one of four things is true.

The questionnaire is the third one this quarter
You now have a recurring job rather than an event. That is 10 to 20 hours a month of somebody's time, which is the point where a small advisory retainer at $3,000 to $6,000 CAD a month starts being cheaper than the distraction.
The customer has asked for a SOC 2 report by a date
That is not a questionnaire problem. That is a nine to twelve month program with an auditor at the end of it, covered on vCISO work for a SOC 2 and priced on what a SOC 2 costs in Canada.
You cannot honestly answer without changing something first
If the truthful answers would lose the deal, the purchase is remediation work, not questionnaire help. Buy the fix and answer honestly afterward.
The buyer wants a call with your security leader
This is the request that most often triggers a first engagement, because the founder can answer the spreadsheet and does not want to be the person on that call. A named fractional owner is a legitimate answer to it.

The six question check is built to tell you no when the answer is no. The hours calculator sizes the retainer if it turns out to be yes.

Need someone to own the next one

Tell us how many questionnaires you have had this quarter and what the biggest customer is asking for. We will tell you whether this is a retainer, a one-off project, or something you should keep doing yourselves.

Get matched

The same owner usually ends up running the company's trust centre too. Who should run the trust centre sets out the roles and the hours.

Common questions

Can I just say we are working toward SOC 2?

Only if you are. Naming a target framework with no auditor engaged and no start date is the answer reviewers see most often and trust least. A first SOC 2 is nine to twelve months from a standing start, so a founder promising one this quarter is telling a reviewer something unhelpful about how the rest of the relationship will go. If you have not started, write that you have not started and give the quarter you plan to. A supplier who is honest about a gap and specific about the date is a lower risk to a reviewer than one who is vague about both.

Who signs the questionnaire if we have no CISO?

Whoever can be held to it. At 15 to 80 people that is usually the CEO, the CTO or a VP of engineering, and any of those is acceptable to a reviewer. What is not acceptable is a signature from someone who cannot describe the controls they just attested to, because the follow-up call will expose it. If you name a fractional security lead, name them with their firm and make sure they will take the call.

Should we buy a compliance platform to answer questionnaires?

Not for this. Compliance platforms cost $8,000 to $30,000 CAD a year and they are built to collect evidence for an audit, not to answer prose questions from a buyer. Under about 50 people, a shared document with your answers in it does the same job for the questionnaire problem. Buy the platform when you have committed to an audit, not when you have received a spreadsheet.

The customer sent a 300 question questionnaire and we have 22 employees. Is that normal?

It is common and it is usually a template applied without thought. Ask the reviewer directly which sections apply to a supplier of your size and data exposure. Most will scope it down, and the ones who will not are telling you something useful about how the rest of the relationship will go. Answering 300 questions properly is 30 to 40 hours, and it is worth knowing that before you agree to Friday.

What if we answer honestly and lose the deal?

Some deals are genuinely out of reach until you have done the work, and a security review is a cheap way to find that out. The failure mode worth avoiding is winning the deal on answers you cannot support, because the contract will contain the commitments and the first audit right or incident will surface the difference. If a specific deal is the reason you are reading this, a deal blocked on a security review is the page for the situation.