Back to BlogSecurity & Compliance

Your First Enterprise Security Questionnaire, With No SOC 2

Rupak Amin

Founder & Lead Engineer, RAITHub

12 min read

You can answer an enterprise security questionnaire without SOC 2, if every answer is true. Say you have no SOC 2 report, answer each control as Yes, Partial, No or Not applicable with evidence, point to your hosting providers' reports for infrastructure, and date a plan for each gap. An honest gap with a plan can be negotiated; a false yes cannot be taken back.

This guide is for a founder or CTO whose first large prospect has just sent a spreadsheet of security questions, and who has no audit report to attach. It covers the process: what the questionnaire will be, what SOC 2 actually proves, how to word answers you cannot say yes to, and which documents to prepare. The controls themselves, and the evidence that satisfies reviewers for each one, are in SaaS security best practices. This is general information, not legal or audit advice; confirm contract and compliance questions with your adviser.

What will the security questionnaire look like?

Usually one of three things: the Cloud Security Alliance's CAIQ, the Shared Assessments SIG, or the buyer's own spreadsheet or vendor portal. Knowing which one you have tells you how long it is and what it cares about.

QuestionnaireWho publishes itWhat it isWhat to expect
CAIQCloud Security AllianceYes/no questions mapped to the Cloud Controls MatrixCloud-focused; the CCM behind it has 197 control objectives in 17 domains
SIGShared AssessmentsA licensed third-party risk questionnaire, in a full "Core" and a shorter "Lite" formBroad: it covers the company as well as the product; common with banks and large enterprises
CustomThe buyer's security or procurement teamA spreadsheet or portal, often adapted from one of the aboveVaries from 30 questions to several hundred; often includes questions about the buyer's own policies

The CSA says the CAIQ gives "a simple set of 'yes/no' questions to assess cloud providers", and its current Cloud Controls Matrix page states that "Version 4.1 of the CCM and CAIQ are now combined" and that CCM v4.1 "is composed of 197 control objectives that are structured in 17 domains". The CCM is free to download for internal use. The same CAIQ is what a provider submits as a self-assessment to the CSA's STAR Level 1 registry. The SIG is maintained and licensed by Shared Assessments and updated periodically, so ask the buyer which version and which scope they sent.

If the buyer sends a custom sheet, ask whether they will accept a completed CAIQ instead. Some will, and a CAIQ you complete once can be reused for every later buyer.

What does a SOC 2 report actually prove?

That an independent CPA firm examined your company's controls against the AICPA's criteria and reported on them. It is a report about your organisation, not a badge on your product, and not something a vendor can hand you.

The AICPA describes SOC as "a suite of service offerings CPAs may provide in connection with system-level controls of a service organization" (AICPA SOC suite of services). SOC 2 is its report on "an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy" (AICPA SOC 2 page). A Type 1 report covers whether controls are suitably designed at a point in time; a Type 2 report also covers whether they operated effectively over a period, commonly several months.

Two consequences for your answers:

  • There is no such thing as being "SOC 2 compliant" without a report. If you have not been examined, the true answer is "no SOC 2 report". Words like "SOC 2 ready" or "aligned" need a list of which controls you mean, or a reviewer will read them as evasion.
  • A questionnaire is not an audit. It asks what you do. You can answer it truthfully today, with whatever controls you actually run.

How should you answer a control you can't say yes to?

With one of five answers, each with a short, specific explanation. "Partial" with a real description is far more useful to a reviewer than a bare "Yes" they will later find untrue.

AnswerUse it whenExample wording
YesThe control exists and you can show it"Yes. Tenant data is isolated with PostgreSQL row-level security; CI fails if a tenant table lacks a policy. Evidence available on a call."
PartialSome of it exists, or it exists informally"Partial. Access reviews happen when staff join or leave; there is no scheduled quarterly review yet. Scheduled review from Q1 2027."
NoIt does not exist"No. We have not had an external penetration test. We run automated dependency audits on every build and will commission a test before go-live if required."
Not applicableThe control cannot apply to you, and you can say why"N/A. We operate no offices or on-premises servers; all systems are cloud-hosted."
InheritedYour hosting provider runs the control"Inherited. Physical data-centre security is provided by our cloud provider, whose own audit reports are available under NDA."

Rules that keep answers safe:

  • Never answer for the future in the present tense. "We encrypt backups" must be true on the day you send it.
  • Date every plan, and only promise dates you will meet. A buyer may write them into the contract.
  • Use "N/A" sparingly. Reviewers push back on N/A without a reason more than on an honest No.
  • Keep answers consistent. Questionnaires ask the same thing in several places. Answer once in an answer library and reuse the wording.

What do you say when they ask for your SOC 2 report?

That you do not have one, what you have instead, and what would change that. A short, direct paragraph works better than a long defence:

"We do not currently hold a SOC 2 report or ISO 27001 certification. Attached is our security overview describing our controls for access, tenant isolation, encryption, logging, backups and incident response, and our list of subprocessors, whose own audit reports are available under NDA. We are happy to walk your team through the controls on a call, sign your DPA, and discuss contractual security commitments."

Then answer the rest of the questionnaire in full. Some buyers need a report as a hard gate; if so, you learn it in week one instead of month three, and you can ask what they accept instead, such as a completed CAIQ, a penetration test summary, or a contractual right to audit.

What about controls your cloud provider runs for you?

Mark them as inherited and name the provider, but only for the parts the provider really runs. A provider's report covers the provider's controls: its data centres, hardware and the platform services it operates. It does not cover how you configured them.

So physical security, hardware disposal and power are usually inherited. Who in your team can open the production database, whether storage buckets are private, whether backups are tested and whether logs are kept are yours, even on a fully managed platform. Most large providers make their audit reports available to customers through their compliance portals, often under NDA; download the current ones before you start.

Which documents should you prepare before you answer?

A small set of short documents answers most of any questionnaire. Write first versions that describe what you actually do today; a two-page true document beats a twenty-page template.

DocumentAnswers questions aboutA good first version
Security overviewEverything, at summary level2 to 4 pages: architecture, isolation, access, encryption, logging, backups, incidents
Architecture and data-flow diagramWhere data lives and moves; regionsOne diagram showing every system that stores customer data
Subprocessor listThird parties with access to dataProvider, purpose, data category, region
Access control policyWho can reach production, and how that is reviewedNamed roles, MFA requirement, joiner and leaver steps
Incident response planDetection, notification, contactsWho decides, who tells the customer, and within what time
Backup and restore recordRecovery objectivesThe date of your last restore test and how long it took
Vulnerability management notePatching, scanning, testingDependency audit on every build; penetration test status, even if "none yet"
DPA templatePersonal data processing termsYour standard data processing agreement, reviewed by your adviser

If you process personal data of people in the EU, the buyer will likely send a DPA and ask about transfers; outsourcing software development under GDPR covers the vendor side of that conversation.

How do you get through 200 questions without losing a month?

Triage first, answer from a library, and give one person the job of finishing it.

  1. Sort the questions by domain: product and data, people and access, infrastructure, policies, legal. Engineering answers the first three; the founder or an adviser owns the rest.
  2. Answer the product questions first. Tenant isolation, authentication and encryption carry the most weight with reviewers, and they are the ones you can prove.
  3. Build the answer library as you go: one approved answer per control, with its evidence link. The second questionnaire takes a fraction of the time.
  4. Collect evidence in one folder: screenshots of settings, a CI run showing security tests, the last restore test, the dependency audit output.
  5. Review every Yes against the question "could we show this on a call tomorrow?". Downgrade anything that fails to Partial.
  6. Send it with a cover note offering a call, which is often where the review is actually decided.

The product answers are strongest when the control is enforced by the system and tested. For tenant isolation, that means database-enforced policies and a test suite that tries to cross them; the detail is in the Postgres row-level security guide, and the multi-tenant SaaS guide covers the rest of the foundations reviewers ask about.

When do you actually need a SOC 2 report?

When deals you want keep stopping at "no report, no contract", not before. The signal is a pattern across buyers, not one prospect's checklist.

Plan for a Type 1 first if you need something soon, since it covers design at a point in time, then a Type 2 once controls have run for a period. Either way, the report is about your company: a development partner can build and evidence the controls, but only your organisation can be examined.

How RAITHub helps, and where it can't

RAITHub builds the product controls that questionnaires ask about and produces the engineering evidence. It is honest about its own position: RAITHub is not SOC 2 or ISO 27001 certified. It signs DPAs and SCCs and follows your controls, as described on the security page.

  • Controls built in, then tested. On Sundor Skin, buyer data sits behind PostgreSQL row-level security across 146 tables, 88 permission codes make up 12 staff roles, and 530+ automated tests run in CI.
  • Evidence you can attach. Architecture and data-flow descriptions, isolation test results and test reports for the product parts of your answers.
  • Gaps closed as fixed-scope work. If the questionnaire exposes a missing control, such as audit logging or tenant isolation, it is quoted as a defined job; see the SaaS development service or QA and test automation.

When to use someone else, or a tool, instead

  • You need the SOC 2 report itself. Only an independent CPA firm can examine you.
  • You need policies, contracts or a legal view. Use your lawyer or a compliance adviser; RAITHub gives no legal advice.
  • You mostly need to track policies and evidence over time. A compliance automation tool is built for that.

If a questionnaire has exposed gaps in your product's controls, book the free technical audit and send the questions you could not answer.

Written 29 September 2026. Sources checked on 29 September 2026. General information, not legal or audit advice; confirm with your adviser.

Frequently asked questions

Can I sell to enterprises without SOC 2?

Often, yes, especially for early deals. Many buyers accept a completed questionnaire, a security overview and a call. Some have a hard requirement for a report; ask early so you know which kind of buyer you have.

What is the CAIQ?

The Consensus Assessments Initiative Questionnaire from the Cloud Security Alliance: yes/no questions mapped to its Cloud Controls Matrix, which in version 4.1 has 197 control objectives in 17 domains. It is often used to assess cloud and SaaS providers.

What is the SIG questionnaire?

The Standardized Information Gathering questionnaire, maintained and licensed by Shared Assessments and used for third-party risk reviews. It comes in a full Core form and a shorter Lite form and covers the company as well as the product.

Is it acceptable to answer "Partial" or "No"?

Yes, with a specific explanation and, where you intend to fix it, a date. Reviewers expect gaps from a young company; they do not accept answers that turn out to be untrue.

What is the difference between SOC 2 Type 1 and Type 2?

Type 1 reports on whether controls are suitably designed at a point in time. Type 2 also reports on whether they operated effectively over a period, commonly several months, so it tells a buyer more about how the controls work in practice.

Can my development agency give me SOC 2?

No. A SOC 2 report covers the organisation that runs the service, which is you. A development partner can build and evidence the controls an auditor will test.

security questionnaireSOC 2CAIQSIG questionnairevendor security reviewenterprise sales

Ready to discuss your project?

Book a free 15-minute technical audit with our engineering team.