The worst week to get homework is the week the deal is supposed to close. That's when the spreadsheet arrives: forty to ninety questions from the big customer's procurement team about your MFA, your backups, your incident response plan, your subprocessors — with a note that processing can't begin until this is returned.
Most small teams do one of two things, and both cost money: panic-send half-true one-word answers ("yes", "yes", "N/A"), or let it sit for two weeks because every question feels like homework. The buyer's security team isn't testing whether you're a security giant. They're testing whether you know your own operations — and a six-person team that knows its controls answers faster than a corporation that has to convene a meeting for each row.
We just shipped the playbook that turns the questionnaire into one afternoon: Customer Security Questionnaire Response Template for Small Teams.
Here's the shape of it — and the three moves that separate vendors who pass review from vendors who stall.
1. Build the evidence folder once; answer from it forever.
Before touching the spreadsheet, create security-evidence/: a one-page controls inventory, dated screenshots (MFA enforcement, backup dashboard, password policy), your incident response plan, and — the one that kills more small-vendor deals than any other — subprocessors.md: every third party that touches customer data, what it receives, where it's hosted. "I'd have to check" is the one answer a reviewer can't write down. Two hours to build, reused on every future form.
2. Twelve answers cover 80% of every questionnaire.
MFA, passwords, backups, incident response, breach notification, encryption, access control, offboarding, data deletion, vendor management, patching, personnel. Write each once, in full sentences, with a date where a date belongs ("restore tested March 2026, log attached"). Untested-backup answers are the ones reviewers flag — test once and the answer becomes evidence-backed instead of hopeful.
3. The honest answer has a three-part shape.
You'll be asked for things you don't have: SOC 2, pen tests, ISO 27001. Never lie (fatal when discovered) and never ghost the question (reads as hiding something). Instead: state it plainly ("not yet"), name the compensating control ("team of 6, limited data access, complete questionnaire + evidence folder provided"), and give a date only if it's real — reviewers check back on invented quarters.
One more thing worth reading into the form: a mandatory SSO question means their IT team plans to manage your app. A 100-question form for a $5k deal is a proportionality signal — tier your answers so their security team can focus on the sections that matter for your data access level. The form is intelligence about the buyer, not just homework.
The reuse rule is the part that compounds: 70–90% of the next questionnaire is already written in your answer file. The afternoon happens once. After that it's find-and-replace — and every question you answered badly in round one is a gap a real customer surfaced for free.
The full playbook — the evidence folder contents, all twelve answers with the exact sentence structures, the honest-answer template, and the red flags — is on the ops notes: hive80-lab.github.io/ops-notes. It's part of HIVE80lab's free ops library; the paid kits (incident response starter at $14, automation pack at $19) carry the templates that fill the blanks for you.
Top comments (0)