PDRIGHT Book a fit call

Home / Insights / Security questionnaire

Your Client Just Sent You a Security Questionnaire. Here's Exactly What to Do.

Guide · Security reviews · 6 min read

A big client — maybe your biggest — just emailed you a spreadsheet with 80, 150, sometimes 300 questions about your security. It's due in a week. Half the questions don't seem to make sense, and the deal (or the renewal) is quietly on hold until you send it back.

First: this is normal now, and it is not a sign that anything is wrong with your agency. It's a sign your client is big enough that their security and legal teams have to vet every vendor who touches their data — and that now includes you. Handled right, it's a formality. Handled wrong — or ignored — it's how agencies lose accounts they've had for years.

Here's what it actually is, what they're really checking, and how to get it back without stalling the relationship.

What a security questionnaire actually is

It's your client's way of asking one question in a hundred different ways: "If we hand you our data and our brand, can we trust how you'll protect it?"

The format varies — a custom spreadsheet, a standardized industry questionnaire (you'll see names like SIG or CAIQ), or a portal you log into. The good news: most questionnaires overlap heavily. The large majority of what you'll ever be asked is the same core set of controls, asked in different words. Answer that core once, well, and you can reuse it for the next client.

They're checking a handful of themes:

  • Access — who can get into your systems, and is it locked down (multi-factor, unique logins, offboarding)?
  • Devices — are the laptops your team uses protected, updated, and encrypted?
  • Threat detection & response — if something malicious happens, will you catch it and act?
  • Data handling — where does their data live, who can see it, and how is it backed up?
  • Process — do you have written policies, and do you follow them?

The 7 steps to answer it without losing the account

1. Don't ignore it, and don't panic-answer it. The two ways to lose points are silence and bluffing. A late or empty questionnaire reads as "they don't take this seriously." A questionnaire full of confident "yes" answers you can't back up is worse — because the one thing that ends the relationship is getting caught overstating. Reply to your client the same day with a realistic date. That alone buys goodwill.

2. Find out who's really asking and why. Ask your client contact: is this a new requirement, a renewal condition, or tied to a specific project? Is there a deadline behind the deadline (a contract, an audit, an insurance renewal)? Knowing the real driver tells you how deep you need to go.

3. Read the whole thing before you answer anything. Skim all the questions first. You'll notice the same theme asked five ways. Group them. This turns 150 scary questions into about 8 topics you actually have to speak to.

4. Answer only what's true — and say how. For each question, a strong answer has three parts: a clear yes or no, one sentence on how you do it, and what you can show as proof. "Yes — every team member signs in with multi-factor authentication, and we can provide a configuration export" beats a bare "Yes." A truthful "Not yet, here's our plan and timeline" is a perfectly acceptable answer and builds more trust than a shaky "yes."

5. Never overstate. Flag the gaps honestly. If you don't have something, say so — and say what you're doing about it. Security teams expect a few gaps from a small vendor. What they're really scoring is whether you know your own posture and take it seriously. Honesty is the thing that keeps the account.

6. Attach evidence where you can. A short policy, a screenshot of a setting, a one-page summary. Evidence turns a claim into a fact and cuts the back-and-forth follow-up questions that drag these out for weeks.

7. Save your answers to reuse. Once you've answered well, keep it. The next client's questionnaire will be 70% the same. Your first one is the hard one.

The mistakes that actually cost agencies the account

  • Bluffing a "yes." The fastest way to lose trust — and, if their data is ever involved in an incident, the fastest way to a legal problem.
  • Going silent because it feels overwhelming. Non-response reads as negligence.
  • Having no written policies. Many questions map directly to "send us your [X] policy." If none exist, whole sections fail by default.
  • Treating it as one-time. These recur — new clients, renewals, insurance. Agencies that build the habit stop dreading them.

When it's worth getting help

If you have the controls in place and just need to translate them into the questionnaire's language, you can do this yourself with the steps above. Get help when: the questionnaire is long or high-stakes, you're not sure which answers are true, you have gaps you don't know how to close, or the deal is too important to risk a weak response.

FAQ

How long do I have to answer a security questionnaire?

Whatever your client sets — often a week or two. If you need more time, ask for it early with a specific date. A realistic date is almost always granted; silence is not.

What if I have to answer "no" to some questions?

That's normal and fine. A truthful "no, and here's our plan" builds more trust than a "yes" you can't back up. Security teams expect a few gaps from a small vendor — they're scoring honesty and awareness.

Do I need SOC 2 to pass a security questionnaire?

Usually not — a questionnaire and a SOC 2 report are different things, and most agencies are asked for the questionnaire first. Answer it well before you spend on a formal audit you may not need yet.

Can someone just do this for me?

Yes. PDRight completes client security questionnaires for agencies — grounded in your real controls, with evidence, reviewed before it's returned. Book a fit call.