Questionnaires probe a predictable set of areas — logging, monitoring, vulnerability management, policies, incident response, access control — and reviewers score risk rather than collect certificates. Controls that verifiably run today, plus a dated certification plan, pass reviews that unevidenced claims fail. The response that keeps the deal moving is a complete, accurate answer inside the week.
Almost every questionnaire covers the same areas, which are the areas ISO 27001’s Annex A covers. That overlap is why answers convert readily between the two.
| What they ask about | What the question tests | What a passing answer points to |
|---|---|---|
| Logging | Whether you could reconstruct events after an incident | Central log collection with defined retention — the substance of ISO 27001 A.8.15 |
| Monitoring | Whether an attack would be noticed while in progress | Alerting on anomalous behaviour, and a named person who responds |
| Vulnerability management | How long known vulnerabilities stay open | Regular scanning plus remediation with dates, rather than a single penetration test from two years ago |
| Policies | Whether security decisions have been made and recorded | Short, current, approved documents staff have read |
| Incident response | Whether a documented process exists | Steps, contact points, and evidence of a past incident or test handled |
| Access control | Who can reach the data, and who verifies it | MFA, joiner/leaver process, and a recent access review |
Reviewers score risk. The certificate question is one row, and the remaining rows are answerable and verifiable with or without it.
A security reviewer is deciding whether your organisation is an acceptable risk to connect to their business. A certificate is convenient shorthand for independent verification, and a committed certification date backed by evidence they can inspect today answers the same underlying question.
The distance between a stalled questionnaire and a pass is usually not twelve months of certification work. It is whether the answers in the document are backed by something a reviewer can check. A statement that logs are centrally collected and retained, with a configuration screenshot attached, scores differently from a general claim about following best practice.
That evidence also frames the certification conversation. Where the answers show operating controls plus a dated plan, “not certified yet” reads as a program in progress — see what to say when a customer asks for ISO 27001 directly.
“We stopped writing promises in the spreadsheet and started attaching evidence. The reviewer’s follow-up call was a formality.” — CTO, B2B SaaS
Under deal pressure the reflex is to round up — recording yes where the accurate answer is partially, or where a tool was purchased but never operated.
Questionnaire answers are referenced in contract warranties and re-tested at renewal, at the next annual review, or after an incident. An accurate answer costs a harder conversation during the sale. An inflated one costs the customer relationship at the point it is tested, which is the outcome the whole exercise exists to prevent.
Secure60 answers the questionnaire and operates the security behind the answers. The questionnaire rows that stall deals — logging, monitoring, vulnerability management, evidence — are the operations Secure60 runs for you, with the governance layer keeping answers and evidence current for the next questionnaire as well as this one. Where Vanta or Drata is already in place, we run the security those platforms report on. Secure60 holds ISO 27001:2022 certification, and we complete these documents from live systems.
Should we answer 'yes' to a control that's planned but not implemented?
No. Questionnaire answers are routinely warranted in the contract, so a yes that was a commitment becomes a breach conversation at renewal or after an incident. Answer ‘partially’ or ‘planned’ with a date. Reviewers handle disclosed gaps better than discovered ones.
Will a stated plan to certify next year pass a security review?
Often, where evidence exists now. A committed certification date backed by controls the reviewer can verify today — logs retained, monitoring running, vulnerabilities managed — scores as low risk. The same commitment with nothing behind it scores as a delay.
What evidence do reviewers want to see?
Evidence of operation: log retention settings, a monitoring alert that fired and was handled, a vulnerability report with remediation dates, last quarter’s access review, your incident response steps. Policies matter, and policies combined with operating evidence are what passes.
Who should fill in the questionnaire?
One owner who can chase answers, usually the CTO or founder at a small company, with each answer checked by whoever runs that control. Sales teams should not estimate answers to security questions, because those estimates end up warranted in the contract.
Can we push back on questions that don't apply to us?
Yes. ‘Not applicable’ with one sentence of reasoning is a normal, credible answer, since questionnaires are written to cover every vendor type at once. It does not extend to questions that do apply.
We already have a compliance platform. Why is the questionnaire still hard?
A platform tracks whether controls exist; a questionnaire asks you to demonstrate that they operate. Where the platform’s task list was never staffed, the accurate answers remain no. That execution gap is what we take on.