ComplianceISO 27001Questionnaire blocking a deal
ISO 27001 · Deal blocked

A security questionnaire is holding up our deal

The short answer

Answer it this week, honestly, with evidence. Questionnaires probe a predictable set of areas — logging, monitoring, vulnerability management, policies, incident response, access control — and reviewers score risk, not certificates. Controls that verifiably run today, plus a dated certification plan, pass reviews that polished promises fail.

What security questionnaires actually probe

The questionnaire is sitting half-done in a shared spreadsheet, procurement won’t move without it, and every week it sits there the deal cools. Start with what it’s really testing. Under all those questions, almost every questionnaire probes the same areas — the same ground ISO 27001’s Annex A covers, which is why the two convert so readily.

What they ask about What the question is really testing What a passing answer points to
Logging Could you reconstruct what happened after an incident? Central log collection with defined retention — the substance of ISO 27001 A.8.15
Monitoring Would you notice an attack while it’s happening? Alerting on anomalous behaviour, and a named person who responds
Vulnerability management How long do known holes stay open? Regular scanning plus remediation with dates, not a one-off pen test from two years ago
Policies Has anyone decided how security works here? Short, current, approved documents people have actually read
Incident response When something goes wrong, is there a plan or a panic? Documented steps, contact points, and evidence of a past incident or test handled
Access control Who can touch our data, and who checks? MFA, joiner/leaver process, and a recent access review

Reviewers are scoring risk, not collecting certificates. The certificate question is one row. The other rows are answerable — and verifiable — with or without it.

Why “we’ll get certified next year” often passes

A security reviewer at your customer has one job: decide whether you’re an acceptable risk to connect to their business. A certificate is convenient shorthand for “someone independent checked”. But a committed certification date, backed by evidence they can inspect today, answers the same underlying question.

That’s the part founders miss when a deal jams: the gap between you and a pass is usually not twelve months of certification work. It’s whether the answers in that spreadsheet are backed by anything. “We centrally collect logs and retain them” with a screenshot behind it beats “we are pursuing best practice” with nothing behind it, every time.

It also sets up the certification conversation properly. If your answers show real controls plus a dated plan, “not certified yet” reads as a company mid-way through doing it right — see what to say when a customer asks for ISO 27001 directly.

How to answer honestly without killing the deal

Answer everything, this week. A complete questionnaire with some honest gaps moves through review. A perfect one that arrives after procurement’s window closes does not.

Three honest states per question: yes, partially, planned. “Yes” only when it’s true and you could show evidence tomorrow. “Partially” with what exists and what’s missing. “Planned” with a date. Reviewers read these documents all day; inflated answers have a texture they recognise.

Attach evidence to your strongest answers. You don’t need evidence on all of them — a handful of verifiable attachments makes the whole document credible.

Name compensating controls for the gaps. No formal incident response plan yet, but on-call alerting and a post-incident write-up from March? Say exactly that. A described real state beats a claimed ideal one.

Put the certification plan in the comments field. One line: the standard, the quarter, who’s engaged to deliver it. It converts every “planned” from a hope into a schedule. What that plan costs sits in our ISO 27001 cost guide.

“We stopped writing promises in the spreadsheet and started attaching evidence. The reviewer’s follow-up call was a formality.” — CTO, B2B SaaS

What most people get wrong

The reflex under deal pressure is to round up: “yes” where the truth is “mostly”, “yes” where the truth is “we bought a tool for that”. It feels like keeping the deal alive. It’s the opposite. Questionnaire answers get referenced in contract warranties, and they get re-tested — at renewal, at the next annual review, or in the worst case after an incident, when your answers are read back to you with lawyers present.

The honest version costs you a harder conversation now. The inflated version costs you the customer’s trust later, when trust is the entire product of the exercise.

How Secure60 handles this

Tools hand you a to-do list. We do the list — and run the security behind it. The questionnaire rows that stall deals — logging, monitoring, vulnerability management, evidence — are the operations Secure60 runs for you, with the governance layer keeping answers and evidence current for the next questionnaire, not just this one. Already have Vanta or Drata? We make them work and run the security they don’t. And because we’re ISO 27001:2022 certified ourselves, we fill in these spreadsheets from live systems, not from memory.

Frequently asked questions

Should we answer 'yes' to a control that's planned but not implemented?

No. Questionnaire answers routinely get warranted in the contract, and a ‘yes’ that was really a ‘soon’ becomes a breach conversation at renewal or after an incident. Answer ‘partially’ or ‘planned’ with a date — reviewers handle honest gaps far better than discovered ones.

Will 'we're getting ISO 27001 certified next year' pass a security review?

Often, yes — if evidence exists now. A committed certification date backed by controls the reviewer can verify today (logs retained, monitoring running, vulnerabilities managed) reads as low risk. The same sentence with nothing behind it reads as a stall.

What evidence do reviewers actually want to see?

Things that prove operation, not intent: log retention settings, a monitoring alert that fired and was handled, a vulnerability report with remediation dates, the access review from last quarter, your incident response steps. Policies matter, but policies plus operating evidence is what passes.

Who should fill in the questionnaire?

One owner who can chase answers — usually the CTO or founder at a small company — with each answer checked by whoever runs that control. Sales should never guess answers to security questions; those guesses end up warranted in the contract.

Can we push back on questions that don't apply to us?

Yes. ‘Not applicable’ with one sentence of reasoning is a normal, credible answer — questionnaires are written for every vendor type at once. What you can’t do is use N/A to dodge a question that does apply.

We already have a compliance platform. Why is the questionnaire still hard?

Because a platform tracks whether controls exist; a questionnaire asks you to prove they operate. If the platform’s to-do list never got staffed, the honest answers are still ’no’. That execution gap is exactly what we take on.

Unblock the deal that's sitting on it.

Book a readiness call — we'll go through the questionnaire with you, tell you which answers are already true, and fix the ones that aren't.

Book a readiness call Run a pilot