How to answer a security questionnaire before you have a SOC 2
Twelve questions come back on every form. Here are honest answers for today and for after your report, free to copy.
How to answer a security questionnaire with no report yet: write each answer yourself, mark what is not in place as “not yet” with a date, and attach your policies. Forms run long because the frameworks behind them are big. Version 4.1 of the Cloud Security Alliance’s Cloud Controls Matrix, the basis of the CAIQ, lists 197 control objectives across 17 domains (cloudsecurityalliance.org, read 1 August 2026).
Answer twelve questions once, then reuse them
Nearly every form you get comes from one of three places. The CAIQ, from the Cloud Security Alliance. The SIG, from Shared Assessments, licensed to its members. Or a spreadsheet a buyer’s security engineer assembled from both. The wording differs, the subjects do not: encryption, access, people, incidents, vendors and recovery. Write good answers to the twelve below and keep them in one document. The next form takes an hour instead of a week.
One free step works before any report exists. You can publish a CAIQ self assessment to the CSA STAR Registry at no charge (cloudsecurityalliance.org/star, read 1 August 2026). Nobody tests it, but a buyer can read it without emailing you.
This page is about forms you receive. For the form you send your own suppliers, use the vendor security questionnaire template.
Twelve answers to copy
Each question has two answers, because the honest one changes on the day your report is issued. Fill in the brackets. If a line is not true of your company, do not paste it.
| Question | Before you have a report | After it is issued |
|---|---|---|
| Do you have a SOC 2 report? | Not yet. Our Type 1 examination is in progress as of [date]. We can share our control list and policies now and walk you through them on a call. | Yes. Security category, covering [date or period], from [CPA firm]. Shared under NDA, with a bridge letter for the time since. |
| Is data encrypted in transit and at rest? | In transit with TLS 1.2 or higher. At rest with AES-256 using keys managed by [provider]. If either is not in place, say which, and when it will be. | Same answer, now tested. See the Section 4 results. |
| Do you enforce multi factor authentication? | Yes, for all staff on our identity provider, cloud console and code host. List any system without it and what protects it instead. | Same answer, sampled by the auditor. Exceptions appear in Section 4. |
| How often is user access reviewed? | Every [interval], led by [name], recorded on a dated sheet. Pick the pace you will keep. One quarterly review in a year looks worse than an annual one done on time. | Same, with reviews in the period sampled by the auditor. |
| How quickly is access removed for leavers? | Within [n] business days of the end date, tracked on a checklist with an approver and timestamps. | Same, tested against a sample of leavers. |
| Do staff pass background checks? | Yes, before the start date, through [provider]. If contractor checks are lighter, say so and describe what you do instead. | Same, sampled from new hires in the period. |
| Do you have an incident plan, and when would you tell us? | Yes: severity levels, a named lead and a review after each incident. We notify affected customers within [n] hours of confirming a breach. If the plan has never been used, say so. | Same, with the plan tested and any incidents in the period reported. |
| Who are your subprocessors? | Listed at [url]. We give [n] days notice before adding one that handles customer data, and you can object. | Same list. The report also names carved out subservice organizations. |
| When was your last penetration test? | [Date], by [firm], summary under NDA. If none yet, say so and give the booked date. A scan is not a pen test. | Same, read by the auditor as a separate evaluation under CC4.1. |
| Are backups taken and restores tested? | Encrypted [frequency] backups, kept [n] days. Last restore test on [date]. If you have never restored one, book it and say so. | Same, with evidence across the period when Availability is in scope. |
| What happens to our data when the contract ends? | Deleted within [n] days of written request. Backup copies expire [n] days later. We confirm deletion in writing. | Same, with disposal tested when Confidentiality is in scope. |
| Do staff take security training? | At hire and every [interval] after, with a completion record per person. | Same, sampled from records in the period. |
Four phrases that get you in trouble
“Not yet” is a normal answer. These four are not, and each is hard to take back once it sits in a signed contract.
- “We are SOC 2 certified.” No such certificate exists. A SOC 2 is an attestation report with an opinion covering one date or one period.1 Reviewers notice the word.
- “We are SOC 2 compliant.” There is no compliant status. You have an issued report or you do not.
- “Report available under NDA”, written while the examination is still running. Offer it the day it exists.
- “Yes” to a control you plan to build. The easiest to type and the costliest later.
Why it matters: answers are frequently attached to the master agreement or referenced in it, which turns each one into a promise. A wrong yes comes back when the buyer’s own auditor reviews their vendor files, and again at renewal. A dated “not yet” reads as a plan. We publish ours on our trust page, including what we have not done yet.
Where each answer should come from
Each subject traces to a Trust Services criterion2 and to a policy you either have or do not. If you cannot point at the policy, that is your gap. The names match the set in how many SOC 2 policies you need.
| Subject | Criteria | Policy |
|---|---|---|
| Encryption | CC6.1, CC6.7 | Cryptography Policy |
| Multi factor authentication | CC6.1 | Access Control Policy |
| Access review and offboarding | CC6.2, CC6.3 | Access Control Policy |
| Background checks and training | CC1.4, CC2.2 | Human Resources Security Policy |
| Incidents and notice | CC7.3, CC7.4, CC2.3 | Incident Response Policy |
| Subprocessors | CC9.2 | Third Party and Vendor Management Policy |
| Penetration testing | CC4.1 | Risk Management Policy |
| Backups and restores | CC9.1, plus A1.2 if Availability is in scope | Business Continuity and Disaster Recovery Policy |
| Deletion at contract end | CC6.5, plus C1.2 if Confidentiality is in scope | Data Management Policy |
What a report changes
A report does not fill in the form for you. It changes who stands behind the answers. Before, only you say your access reviews happen. After, a licensed CPA firm has tested a sample and given an opinion.1 Most of the operational rows shrink to one attachment. The contract questions stay: data location, deletion, subprocessor notice and breach notice timing. When a supplier sends you their report, read it the way how to tell if a SOC 2 report is real describes.
The cost of answering by hand
These answers are free to copy, and for your first few forms that may be all you need. Each new form still costs hours of a founder’s time, and a live deal usually sets the deadline, as a customer asking for a SOC 2 report explains.
When forms start arriving monthly, a report is the fix that costs less. The cybersoftware software writes the policies these answers cite and tracks the evidence behind them, at $199 a month, cancel any time. Audits come with access to our preferred pricing program. Start with the free readiness assessment or compare on pricing.
cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Questions
How do I answer a security questionnaire with no SOC 2 report?
How do the CAIQ and the SIG differ?
Can I say we are SOC 2 certified while the audit is underway?
Which questions does a SOC 2 report replace?
Is there something public I can share before I have a report?
Sources
Get audit-ready without a compliance team
The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.
Start with a free readiness assessmentcybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.