ComplianceISO 27001Questionnaire blocking a deal
ISO 27001 · Deal Blocked

Security Questionnaire Response and Deal Acceleration

The Short Answer

Questionnaires probe a predictable set of areas — logging, monitoring, vulnerability management, policies, incident response, access control — and reviewers score risk rather than collect certificates. Controls that verifiably run today, plus a dated certification plan, pass reviews that unevidenced claims fail. The response that keeps the deal moving is a complete, accurate answer inside the week.

What security questionnaires probe

Almost every questionnaire covers the same areas, which are the areas ISO 27001’s Annex A covers. That overlap is why answers convert readily between the two.

What they ask about What the question tests What a passing answer points to
Logging Whether you could reconstruct events after an incident Central log collection with defined retention — the substance of ISO 27001 A.8.15
Monitoring Whether an attack would be noticed while in progress Alerting on anomalous behaviour, and a named person who responds
Vulnerability management How long known vulnerabilities stay open Regular scanning plus remediation with dates, rather than a single penetration test from two years ago
Policies Whether security decisions have been made and recorded Short, current, approved documents staff have read
Incident response Whether a documented process exists Steps, contact points, and evidence of a past incident or test handled
Access control Who can reach the data, and who verifies it MFA, joiner/leaver process, and a recent access review

Reviewers score risk. The certificate question is one row, and the remaining rows are answerable and verifiable with or without it.

Why a committed certification date often passes

A security reviewer is deciding whether your organisation is an acceptable risk to connect to their business. A certificate is convenient shorthand for independent verification, and a committed certification date backed by evidence they can inspect today answers the same underlying question.

The distance between a stalled questionnaire and a pass is usually not twelve months of certification work. It is whether the answers in the document are backed by something a reviewer can check. A statement that logs are centrally collected and retained, with a configuration screenshot attached, scores differently from a general claim about following best practice.

That evidence also frames the certification conversation. Where the answers show operating controls plus a dated plan, “not certified yet” reads as a program in progress — see what to say when a customer asks for ISO 27001 directly.

How to answer accurately

  1. Answer everything, inside the week. A complete questionnaire with disclosed gaps moves through review. A complete one that arrives after procurement’s window closes does not.
  2. Use three states per question: yes, partially, planned. Yes only where it is true and evidence could be produced tomorrow. Partially, with what exists and what is missing. Planned, with a date.
  3. Attach evidence to the strongest answers. A handful of verifiable attachments establishes the credibility of the whole document; every answer does not need one.
  4. Name compensating controls against the gaps. An organisation without a formal incident response plan, but with on-call alerting and a written post-incident review from a real incident, should describe that position.
  5. Put the certification plan in the comments field. One line: the standard, the quarter, and who is engaged to deliver it. That converts each “planned” into a schedule. The cost of that plan is in our ISO 27001 cost guide.

“We stopped writing promises in the spreadsheet and started attaching evidence. The reviewer’s follow-up call was a formality.” — CTO, B2B SaaS

Inflated answers are re-tested later

Under deal pressure the reflex is to round up — recording yes where the accurate answer is partially, or where a tool was purchased but never operated.

Questionnaire answers are referenced in contract warranties and re-tested at renewal, at the next annual review, or after an incident. An accurate answer costs a harder conversation during the sale. An inflated one costs the customer relationship at the point it is tested, which is the outcome the whole exercise exists to prevent.

How Secure60 handles this

Secure60 answers the questionnaire and operates the security behind the answers. The questionnaire rows that stall deals — logging, monitoring, vulnerability management, evidence — are the operations Secure60 runs for you, with the governance layer keeping answers and evidence current for the next questionnaire as well as this one. Where Vanta or Drata is already in place, we run the security those platforms report on. Secure60 holds ISO 27001:2022 certification, and we complete these documents from live systems.

Frequently Asked Questions

Should we answer 'yes' to a control that's planned but not implemented?

No. Questionnaire answers are routinely warranted in the contract, so a yes that was a commitment becomes a breach conversation at renewal or after an incident. Answer ‘partially’ or ‘planned’ with a date. Reviewers handle disclosed gaps better than discovered ones.

Will a stated plan to certify next year pass a security review?

Often, where evidence exists now. A committed certification date backed by controls the reviewer can verify today — logs retained, monitoring running, vulnerabilities managed — scores as low risk. The same commitment with nothing behind it scores as a delay.

What evidence do reviewers want to see?

Evidence of operation: log retention settings, a monitoring alert that fired and was handled, a vulnerability report with remediation dates, last quarter’s access review, your incident response steps. Policies matter, and policies combined with operating evidence are what passes.

Who should fill in the questionnaire?

One owner who can chase answers, usually the CTO or founder at a small company, with each answer checked by whoever runs that control. Sales teams should not estimate answers to security questions, because those estimates end up warranted in the contract.

Can we push back on questions that don't apply to us?

Yes. ‘Not applicable’ with one sentence of reasoning is a normal, credible answer, since questionnaires are written to cover every vendor type at once. It does not extend to questions that do apply.

We already have a compliance platform. Why is the questionnaire still hard?

A platform tracks whether controls exist; a questionnaire asks you to demonstrate that they operate. Where the platform’s task list was never staffed, the accurate answers remain no. That execution gap is what we take on.

Accelerate the Questionnaire Blocking the Contract

A readiness call establishes what the customer will accept, what certification requires, and which answers to return first.

30 days, every feature switched on. No credit card.