Business Risk
The Security Questionnaire That Cost a Deal
Enterprise buyers now audit their suppliers before signing. What they actually ask for, and why “we take security seriously” stopped being an answer.

The deal was done. Verbally agreed, budget approved, kickoff pencilled in. Then procurement sent over a spreadsheet with 180 questions about information security and asked for it back within the week.
Some version of this happens to smaller businesses constantly now, and it is one of the few places where cybersecurity stops being an IT topic and becomes a revenue one. The numbers back that up: in one 2026 industry benchmark, 46% of companies reported delayed sales because of missing certifications, 38% said they had lost revenue or bids outright, and 61% said compliance was required to win or renew contracts at all.
Security has become a procurement gate. If you sell to anyone larger than you, it is worth understanding what is on the other side of it.
Why buyers started asking
Large organizations learned the hard way that their weakest point is often a supplier. Some of the most damaging breaches of the past decade arrived through a third party with legitimate access and thin defenses. Regulators noticed, insurers noticed, and boards started asking who has access to what.
The result is that vendor risk assessment is now a standard step in enterprise buying. It is not personal, it is not a stalling tactic, and it does not go away if you are charming about it.
What they actually send
Broadly three things.
A custom questionnaire. The buyer's own spreadsheet, reflecting their particular concerns. Length varies from twenty questions to several hundred. These are the most work because nothing is reusable.
A standardized questionnaire. The two you will meet most often are the SIG (Standardized Information Gathering) and the CAIQ (Consensus Assessments Initiative Questionnaire). The advantage is that a completed one can be reused across multiple buyers.
A request for a SOC 2 report. This is different in kind. A questionnaire is a self-assessment — you telling them what you do. A SOC 2 is an independent audit by an accredited CPA firm, examining whether your controls actually operate as described over a period of time. It costs real money and takes months, which is exactly why buyers value it.
Notably, 70% of organizations still rely on questionnaires even though 73% say they need SOC 2 reports. Most businesses are living in the gap between those two numbers.
What the questions cover
Whatever the format, the ground is consistent: data protection and encryption, access controls, network security, physical security, incident response, employee security training, and policy compliance.
None of that is exotic. The difficulty is rarely that a business is doing something wrong. It is that nobody has ever written down what they do.
Why "we take security seriously" stopped working
Because it is not an answer to any of the questions.
A questionnaire asks whether you enforce multi-factor authentication on all remote access. Yes or no. Whether you have a documented incident response plan, and when it was last tested. Whether you encrypt data at rest, and with what. Whether background checks are performed. Whether you have a named security owner.
These are factual questions with factual answers, and the person reading your response is comparing it against other suppliers who answered the same questions. Vague reassurance reads as a no.
The other thing that reads badly is inconsistency. If question 14 says you have quarterly access reviews and question 96 says access is reviewed annually, you have just told a risk reviewer that nobody owns this.
The real cost is speed
The lost deals get the attention, but the more common damage is delay.
A questionnaire lands. Nobody owns it, so it sits. It gets forwarded to the IT contractor, who answers what they can and guesses at the rest. It goes back with gaps. Procurement asks follow-ups. Two weeks become six. The champion who wanted to buy from you loses momentum, and the quarter closes without your deal in it.
Businesses that answer in three days instead of three weeks are not necessarily more secure. They are just prepared.
How to get ahead of it
Build the answer file before you need it. Take a standard SIG or CAIQ, work through it once properly, and keep the completed version current. The first pass is genuinely hard work. Every one after that is copy, adapt, send.
Answer honestly, including the noes. A no with a date attached — "not currently in place, scheduled for Q4" — is respected. A yes that falls apart under follow-up questions ends the conversation, and in some contracts it creates liability.
Write the policies down. Most small businesses have reasonable practices and no documents. Questionnaires ask for documents. An access control policy, an incident response plan, a data retention policy and a security awareness program cover a surprising share of any questionnaire.
Name an owner. One person responsible for responding, keeping the answer file current, and knowing what is true. This is often the single highest-leverage change.
Know when SOC 2 is worth it. If you are repeatedly losing deals at the security gate, or selling into financial services or healthcare, the audit may pay for itself. If you receive two questionnaires a year, it probably does not. That is a commercial decision, not a security one.
The reframe worth making
It is easy to experience all this as bureaucratic friction invented to slow you down. It is more useful to see it as what it is: your customers doing exactly what you would want your own suppliers to do.
The businesses that treat security questionnaires as a sales asset rather than an IT chore end up with a genuine advantage. They answer faster, they answer better, and increasingly they win work from competitors who cannot.
If a questionnaire is sitting in someone's inbox right now with nobody obvious to hand it to, that is worth a conversation.

