Security questionnaire help for Canadian software companies
A buyer sent a questionnaire and the deal is waiting on it. You can answer it yourself, hire someone to draft it from your evidence, or hand the whole review process to a managed service. Here is how to choose, and what each question actually needs.
A security questionnaire is a buyer's list of questions about how you protect their data: usually SIG Lite, the CAIQ, or the buyer's own spreadsheet. You can answer one without a SOC 2 report if every answer is accurate and backed by evidence you can show. Help usually means three things: drafting answers from your existing material, attaching the right evidence, and telling you which answers a reviewer will push on before they do.
$100 to $150 Loaded hourly cost of the senior person who usually answers, CAD
Hours, not weeks A 100-question custom questionnaire, once an answer library exists
What does security questionnaire help cover?
Good help covers the questionnaire in front of you and the next ten. For the one in front of you, that is reading it, sorting the questions into ones your material already answers and ones it does not, drafting answers in your voice, attaching evidence, and flagging every place where the honest answer is no so you can decide how to say it. For the next ten, it is leaving behind an answer library so the second questionnaire costs a fraction of the first.
What help should never do is invent a control. A reviewer who finds one inaccurate answer stops trusting the rest, and in an enterprise contract the questionnaire is often attached as a representation. If a provider offers to "make the answers pass", that is the wrong provider.
What are the ways to get it done?
| Approach | Who does the work | Best when | Watch for |
|---|---|---|---|
| Answer it yourselves | A founder, engineer or ops lead | One or two a quarter, and you already hold SOC 2 or ISO 27001 evidence | The hours land on your most expensive people, and answers drift between questionnaires |
| Project help | A consultant drafts from your evidence; you review and sign off | A large or unusual questionnaire (a full SIG, a bank's custom set) with a deal date attached | Make sure the answer library is yours at the end, in a format you can reuse |
| Managed review response | A provider answers inbound questionnaires and document requests on an ongoing basis | Several reviews a month, or a sales team blocked waiting on security | Response targets, who approves answers, and how the provider learns when your controls change |
The managed option is usually sold alongside a trust centre, because the same person who answers questionnaires also approves document requests. See managed trust centres for how that works and self-managed or managed for the decision.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
What does questionnaire help cost in Canada?
Price it against what the questionnaire costs you now. Count the hours your team spends per questionnaire, multiply by a loaded rate of $100 to $150 CAD an hour for a senior engineer or security lead, and add the cost of a deal slipping a quarter. The security review cost calculator does that arithmetic for a full quarter of reviews.
Project help is usually quoted per questionnaire, scaled by length and by how much evidence already exists. A short custom questionnaire answered from a current SOC 2 report is a small job. A full SIG Core with no prior library is several days of work. Managed response is quoted monthly, on volume. Treat any fixed price quoted before the provider has seen the questionnaire as a starting point, not a number.
Which questions come up most, and what evidence answers each?
These are the questions that appear in almost every questionnaire, whatever the template. Next to each is the evidence a reviewer expects to see or be offered. If you have the evidence, the answer writes itself. If you do not, that line is your gap list. For model wording, GetAudited keeps a security questionnaire answer bank.
- Do you have a written information security policy?
- The policy itself with its last review date and approver, and a record that staff acknowledged it.
- Who is responsible for information security?
- A named role, the person in it, and where that responsibility is written down. "The CTO, part time" is an acceptable answer if it is true.
- Is multi-factor authentication enforced?
- A screenshot or export of the identity provider policy, with the systems it covers and any exceptions listed.
- How do you manage access to production?
- The access policy, the list of people with production access, and the most recent access review showing who checked it and when.
- How quickly is access removed when someone leaves?
- The offboarding checklist, the time target, and one recent offboarding record showing access removed inside it.
- How is customer data encrypted at rest?
- The storage services used, the encryption setting on each, and who holds the keys (the cloud provider's managed keys or your own).
- How is data encrypted in transit?
- The minimum TLS version enforced on public endpoints, and an external scan result showing it.
- Where is customer data stored?
- The cloud regions for production, backups and logs, and where staff access it from. A Canadian buyer will usually ask whether it stays in Canada.
- Who are your subprocessors?
- A current subprocessor list: name, purpose, data received, location.
- Do you perform penetration testing?
- The latest test summary or letter: who tested, when, the scope, and the remediation status of the findings.
- How do you manage vulnerabilities?
- The scanning tools in use, the remediation targets by severity, and a recent report showing open items against those targets.
- Do you have an incident response plan?
- The plan, the date it was last tested or exercised, and the notification commitment you will put in a contract.
- Have you had a security incident or breach?
- An honest answer, the time window it covers, and if yes, what changed afterwards. Under PIPEDA you already keep a record of breaches of security safeguards, so the facts should exist.
- How are backups taken and tested?
- The backup schedule, retention, where copies live, and the date and result of the last restore test.
- Do you have a business continuity or disaster recovery plan?
- The plan with stated recovery time and recovery point objectives, and when it was last tested.
- How do you secure your software development?
- The change process: code review, branch protection, automated tests and security checks in the pipeline, and who can deploy to production.
- How are secrets and credentials stored?
- The secrets manager in use and a statement that secrets are not kept in source code, ideally backed by a scanner result.
- How are laptops and devices secured?
- The device management tool, the enforced settings (disk encryption, screen lock, updates) and the share of devices compliant.
- Do employees receive security training?
- The training content, frequency, and the completion record for the last cycle.
- Do you run background checks?
- What is checked, for which roles, and the provider. In Canada the honest answer is often limited checks for most roles; say exactly what you do.
- How do you assess your own vendors?
- The vendor review process, the list of critical vendors, and the reports you collected from them (their SOC 2 or ISO 27001 certificates).
- How do you log and monitor activity?
- What is logged, where logs are kept, how long, and who is alerted on what. Retention is the detail reviewers check.
- Is customer data separated between customers?
- A short description of tenant isolation in your architecture and how it is tested.
- How do you handle data deletion at contract end?
- The deletion procedure, the time it takes, backup expiry, and whether you issue a deletion confirmation.
- Do you hold SOC 2 or ISO 27001?
- The report type and period, or the certificate and its scope. If not yet, the dated plan. Nobody is "SOC 2 certified"; say Type 1 or Type 2.
- Which privacy laws apply to you?
- The statutes that actually govern you: PIPEDA for most Canadian private-sector companies, Law 25 for personal information of Quebec residents, PHIPA or its provincial equivalent for health information.
- Who is your privacy officer?
- The named person. Under Law 25 the most senior executive holds the role unless it is delegated in writing, so the answer should match what you have actually done.
- Do you use AI with customer data?
- Which features use which models or providers, whether customer data is used for training, and the contractual terms with the AI provider.
- Do you carry cyber insurance?
- The certificate: limit, carrier, and whether it extends to third-party claims.
- Can we see your security documents?
- The answer is a link: a trust centre page with public material open and reports behind an NDA gate.
What if it is a SIG or a CAIQ?
Standard questionnaires are easier than they look because their question sets are published and reusable. The SIG Lite versus CAIQ comparison covers which one you were sent and how much each takes. The detail on each is on the SIG and CAIQ pages. A completed standard questionnaire is also one of the most useful documents to keep, dated, in your trust centre, because the next buyer will often accept it instead of sending their own.
What should you have ready before you ask for help?
- The questionnaire itself and the deal date. Providers quote on length, format and deadline.
- Your existing evidence. SOC 2 report, ISO 27001 certificate and Statement of Applicability, policies, the last penetration test, the subprocessor list.
- Previous questionnaires you answered. Even inconsistent ones. They are the raw material of the library.
- A named approver on your side. Someone who can confirm a control is true. Help can draft; only you can attest.
- A view on the no answers. Decide in advance whether a gap gets a compensating control, a dated commitment or a plain no.
If you do not have a SOC 2 report yet, start with passing a security review before you have SOC 2 on GetSOC2, and use the questionnaire readiness tool to see where you stand.
Common questions
Can someone else answer our security questionnaire for us?
Yes, a provider can draft every answer, but someone at your company has to confirm each one is true before it is sent. The questionnaire is your statement about your controls, and buyers increasingly attach it to the contract as a representation.
How long does it take to answer a security questionnaire?
With a current answer library, a 100-question custom questionnaire is usually a few hours of matching and review. Without one, the first questionnaire often takes a senior person several days spread over a week or two, mostly spent finding evidence.
Can we answer a questionnaire without a SOC 2 report?
Yes. Most questionnaires ask about controls, not reports. Answer accurately, attach the evidence you have, and give a dated plan for the report if the buyer asks for one. An invented yes does more damage than an honest no.
Is AI good enough to answer security questionnaires?
AI tools are useful for matching questions to answers you have already approved. They are risky when they generate new answers from nothing, because a fluent wrong answer is worse than a blank. Treat AI output as a draft that a person checks against evidence.
Does a trust centre replace security questionnaires?
It replaces many of them and shortens the rest. Buyers who can read your controls, subprocessors and reports often skip their own questionnaire or send a shorter one, but large banks and public-sector buyers usually still require their own form.
Get questionnaire help quoted
Describe the questionnaire and the deal date once. Firms that do this work in Canada reply with a scope and a price.
Get matched