What Enterprise Security Questionnaires Actually Ask — and Why Most Startups Fail Them
You've closed a Series A, hired an enterprise AE, and landed a call with a prospect that could be your first big logo. The call goes well. They want to move forward. Then their procurement team sends over a spreadsheet with 200 questions and a two-week deadline.
This is a SIG Lite — or something like it. And for most seed-to-Series A startups, it's the moment the deal stalls. Not because the product isn't good enough, and usually not because the code is insecure. It stalls because the startup can't answer basic questions about data governance, incident response, and vendor management — questions they've never had to answer before.
What SIG Lite and CAIQ actually are
SIG Lite is a simplified version of the Standard Information Gathering questionnaire, published by Shared Assessments. CAIQ is the Cloud Security Alliance's Consensus Assessments Initiative Questionnaire. Both are frameworks enterprise procurement and security teams use to assess vendors — you'll encounter one or the other, or a company-specific questionnaire that borrows heavily from both.
Neither is a technical audit. They're document and process reviews. The person filling out your questionnaire is not trying to break into your system. They're trying to establish whether you have the documentation and processes that a responsible vendor is expected to have. That distinction matters, because it means the gap is usually in what you've written down, not in what you've built.
The questions that kill startup enterprise deals
These aren't the hardest questions. They're the most common ones that startups can't answer:
"Can you provide a copy of your Data Processing Agreement?"
A DPA is required under GDPR whenever a processor handles personal data on behalf of a controller. If you're storing or processing any customer data on their behalf — and almost every B2B SaaS product is — you need one. Most enterprise buyers won't sign without one. Most early-stage startups have never written one.
"Please provide your list of subprocessors."
Subprocessors are the third-party services you use to process customer data: your database host, your email provider, your analytics tool, your LLM API. Enterprise buyers need to know what they are, where they're located, and what data they touch. If you've never written this list, you'll need to start from scratch — and it's longer than most founders expect.
"Where is our data stored, and in which country or region?"
This needs a specific answer. "In the cloud" doesn't work. "On AWS" doesn't work. They need the region (eu-west-1, for example) and confirmation that data isn't leaving it unexpectedly. If you're using a US-based LLM API and sending customer data through it, that needs to be disclosed — and it may be a blocker for customers with strict data residency requirements.
"What is your incident response plan?"
They want a document that describes what happens when something goes wrong: who gets notified, in what order, within what timeframes, and how customers are informed. If your current incident response plan is "the founders fix it and tweet an apology," that's not a document you can share with procurement.
"Who has access to production data, and how is that access controlled?"
At seed stage, the honest answer is often "the whole engineering team, via shared credentials." That answer will fail this question. The expected answer involves role-based access control, MFA enforcement, access reviews, and an audit log of who accessed what and when. This is one of the code-level findings that shows up in technical reviews — but it's also a documentation question, and you need both.
"Do you have a Business Continuity Plan?"
Another document most early-stage startups have never written. It describes how the business continues operating following a serious disruption — infrastructure outage, key person departure, office fire. The bar here is lower than it sounds: a BCP doesn't need to be 50 pages. But it needs to exist and be findable.
The pattern behind all of these
None of these are questions about whether your product is secure. They're questions about whether you've thought seriously about security as an organisational practice, documented it, and can demonstrate that documentation to a third party.
Enterprise procurement exists to reduce risk for the buyer. The documents they ask for are evidence that you've reduced the risk of being your customer's weakest link. A startup that ships fast and handles things carefully but has never written any of this down looks, to procurement, identical to one that doesn't handle things carefully at all.
What the timeline actually looks like
The typical pattern: you get the questionnaire, you can't answer half of it, you promise to come back with the answers, you spend three weeks writing policies from scratch while the AE manages an increasingly impatient champion, the deal slips a quarter, and by the time you're ready the buyer's budget has been reallocated.
The better pattern: you know what you'd fail before the first enterprise call, you produce the missing documents in advance, and when the questionnaire arrives you fill it out in a day.
That's what our Enterprise Readiness Audit is designed to produce: a gap list against SIG Lite and CAIQ before procurement asks, plus a fixed-price quote for producing the documents that close those gaps. The audit is £595; the policy and questionnaire pack is £900. Both together are cheaper than one lost quarter.