Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security

How to Run a Security Questionnaire Engagement

Running a security questionnaire engagement means assigning an owner, building a source-of-truth evidence library, drafting answers against the actual SIG, CAIQ, or VSA template the buyer sent, getting a technical reviewer to sign off, and submitting on the buyer's timeline, typically inside two to three weeks for a first pass and days for repeat questionnaires once your evidence library exists.

Why Security Questionnaires Derail Deals in Toronto, Waterloo, and Ottawa SaaS Companies

Every enterprise buyer, bank, and insurer now runs a vendor risk review before signing. For Canadian SaaS companies selling into the US or into regulated Canadian sectors, that review usually lands as a SIG (Standardized Information Gathering) questionnaire, a CAIQ (Consensus Assessments Initiative Questionnaire) from the Cloud Security Alliance, or a bank-specific VSA (Vendor Security Assessment). These documents run anywhere from 150 to 1,800 questions. The problem is not the security posture, it is the process. Founders and CTOs at growing companies in Toronto, Waterloo, and Ottawa lose weeks scrambling to answer a questionnaire that lands mid-deal cycle, and the delay itself becomes the reason the sale stalls.

A structured engagement fixes that. The work is repeatable once you build it correctly the first time, and the goal is to never again treat a questionnaire as a fire drill.

Step 1: Assign a Single Owner and Set a Realistic Timeline

Questionnaires fail when they get split across five people with no one accountable for the finished document. Before opening the spreadsheet, name one owner, usually a technical lead or the person managing compliance, who is responsible for the full submission.

  • First-ever questionnaire: budget 2 to 4 weeks depending on length and how much evidence already exists.
  • Repeat questionnaire from a new buyer: 5 to 10 business days once you have a reusable answer library.
  • Short-form CAIQ-Lite or VSA: 2 to 5 business days.

Tell the prospect's procurement or security team the realistic date up front. A specific date builds more trust than a vague promise, and it keeps the deal from quietly stalling in someone's inbox.

Step 2: Inventory What You Already Have Before Writing a Single Answer

Most of a SIG or CAIQ can be answered from documents that already exist: your SOC 2 report or readiness package, penetration test results, access control policy, incident response plan, subprocessor list, and data flow diagrams. Pull these into one folder before touching the questionnaire itself. Skipping this step is the single biggest cause of inconsistent answers, where the questionnaire says one retention period and the actual policy document says another. Auditors and buyer security teams cross-check for exactly this kind of mismatch.

If you have gaps, for example no formal vendor management policy or no documented change management process, this is also the point to flag them honestly rather than answer around them. Buyers see far more red flags in vague or evasive answers than in a documented control that is still maturing.

Step 3: Map the Questionnaire to Your Control Set

SIG, CAIQ, and VSA questionnaires ask the same underlying questions in different words and different orders. Once you have mapped one questionnaire to your control environment, reuse that mapping every time, only adjusting wording and format. Build a master answer library organized by domain (access control, encryption, incident response, business continuity, vendor management, application security) rather than by questionnaire, so any future SIG, CAIQ, or bank-specific VSA can pull from the same source.

This is also where scoring matters. CAIQ answers map directly to CSA Cloud Controls Matrix domains, and SIG uses its own tiered structure (SIG Core vs. SIG Lite). Getting the mapping wrong the first time means redoing it on every subsequent questionnaire, which is where most of the wasted hours actually go.

Stuck on a buyer review? We answer SIG, CAIQ and bespoke security questionnaires, and set up the trust center that stops most of them arriving. Talk to us

Step 4: Draft Answers, Then Get a Technical Reviewer to Sign Off

Whoever drafts the answers, often someone in sales engineering or customer success who is under deal pressure, should not be the final reviewer. A technical owner (your CTO, head of engineering, or an external security lead) needs to check every answer against what is actually deployed in production, not what was true a year ago or what is aspirational. This step catches the most common and most damaging error: overstating a control that does not exist yet.

For companies without in-house security depth to do this review quickly, this is exactly where a partner earns its keep. Bringing in outside help for SIG, CAIQ, and VSA questionnaire completion means someone who has seen hundreds of these documents drafts and reviews the answers against your actual environment, catches inconsistencies before the buyer does, and hands back a submission-ready document instead of a partially completed spreadsheet.

Step 5: Submit, Then Track the Follow-Up Questions

Buyer security teams almost always come back with clarifying questions, especially on encryption specifics, subprocessor locations, and incident response timelines. Treat these follow-ups as part of the same engagement, not a separate fire drill. Log every follow-up question and answer back into your master control library so the next questionnaire arrives pre-answered.

If the questionnaire is tied to a Canadian buyer or a Canadian data residency requirement, be specific about PIPEDA obligations and, if the buyer operates in Quebec, Law 25 requirements around consent and breach notification. US buyers increasingly ask Canadian vendors about this directly, and a confident, specific answer here differentiates you from vendors who only know US frameworks.

Where a Partner Fits Into the Engagement

A boutique partner is most useful in three spots: building the initial evidence library and control mapping so you are not starting from zero, reviewing drafted answers for technical accuracy before submission, and handling the volume when multiple questionnaires land at once during a busy sales quarter. That is different from a self-serve compliance platform, which gives you a template but still expects your team to do the drafting and the judgment calls. For a Canadian company, working with a Canadian-based team also means the person reviewing your answers understands Canadian compliance context like PIPEDA alongside the US-centric frameworks most of these questionnaires were built around.

Companies in Vancouver and Calgary selling into US fintech and healthtech buyers see this most acutely, since those verticals run the longest and most detailed VSAs. Having a control library that already speaks both the US framework language and the Canadian regulatory language saves real time on every subsequent deal.

Building a Reusable Process, Not a One-Time Scramble

The real measure of success is not how well you answered this one questionnaire, it is whether the next one takes days instead of weeks. That means keeping your evidence library current as your environment changes, updating answers when policies change, and treating questionnaire response as an ongoing operational function rather than a reactive sales task. Companies that get this right stop losing deal momentum to vendor risk review and start using a fast, accurate questionnaire turnaround as a competitive signal to enterprise buyers.

If your team is facing a SIG, CAIQ, or VSA deadline right now and needs it done accurately and on time, contact traztech to talk through the questionnaire, your timeline, and where we can take the work off your plate.

Know Which Template You Were Actually Sent

The word questionnaire covers documents that differ by an order of magnitude in effort, and the first mistake is quoting a timeline before reading the file. SIG Lite runs a few hundred questions as a screening pass, while SIG Core is several times that and expects evidence references rather than prose. CAIQ is structured against the Cloud Controls Matrix, so if you have mapped your controls to CCM the answers fall out quickly and if you have not it is slow. HECVAT appears when you sell to universities and carries accessibility and student records questions no other template asks. Many enterprises also keep a bespoke spreadsheet built by their own risk team, which is the hardest kind, because there is no published mapping and half the questions use the buyer's internal vocabulary.

So ask the buyer which sections are actually in scope, because procurement teams routinely send the full template when only the hosting and access management sections apply to your deployment model. Then ask whether they will accept your completed CAIQ or SOC 2 report in place of the form. A surprising number will, and the person who sent the spreadsheet often does not know their own policy permits it.

How to Answer a Question Where the Honest Answer Is No

Nothing damages a review faster than a wall of confident Yes answers that the follow-up round dismantles, and a single overstatement makes a reviewer re-examine everything else you wrote. The pattern that works is short: what you do not currently do, what you do instead and why it addresses the same risk, and when the gap closes if it is scheduled. If you do not run a formal data loss prevention product, say so, describe the egress restrictions and access model that limit what could leave, and note the review date. Reviewers are allowed to accept compensating controls. They are not allowed to accept an answer they later find untrue.

Two related habits. Never write not applicable without a clause of explanation, because an unexplained N/A reads as evasion and generates a follow-up. And do not reuse a competitor's published answers or a template library's model wording, since reviewers see the same phrasing repeatedly and read it as a sign that nobody internal checked the claim.

The Answer Library Is a Versioned Artefact, Not a Document

The first questionnaire is expensive and every later one should be cheap, which only happens if the library is built for reuse. Store each answer as a record with the canonical text, the control it maps to, the evidence file it points at, the owner, and the date it was last verified. Then expire them. An answer about backup frequency that was true in March is a liability in November if the team moved providers, and a quarterly re-confirmation by each owner takes an hour per person and prevents the worst outcome, which is a stale answer your own SOC 2 report contradicts.

Keep evidence separate from answers and current: the latest SOC 2 or ISO certificate, a penetration test summary letter suitable for external sharing, an architecture diagram with data flows marked, the subprocessor list, and the policy set. Most follow-up rounds request one of those attachments rather than dispute an answer. A shared workspace where sales can see what exists without asking security removes a category of internal delay.

Where the Second Round Comes From

Assume a follow-up. It usually comes from a security architect rather than the procurement analyst who sent the form, and it concentrates on four things: access to production and who approves it, encryption key custody, incident notification timelines against what your contract promises, and subprocessors that appeared in your answers but not on your published list. Prepare those before you submit and the second round closes in days. A careful reviewer also reads your answers, your trust page, the SOC 2 system description and the contract together, and any daylight between them becomes a redline.

When Not to Buy Questionnaire Support

If you receive four or five questionnaires a year, do not buy an answer-automation platform. The licence and setup cost more than the hours you would spend, and the automation is only as good as the library you would have had to write anyway.

Equally, if the controls do not exist yet, questionnaire help is the wrong purchase. Careful answers about a control environment you have not built produce a submission that fails at the evidence stage and cost you credibility with a buyer you will face again. Build the controls, get the report, then let the questionnaire become a lookup exercise. Our compliance work starts there for that reason, and the fixed-scope options are on pricing.

Stuck on a buyer review? We answer SIG, CAIQ and bespoke security questionnaires, and set up the trust center that stops most of them arriving.

Talk to usOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on vendor risk and security questionnaires. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.