
What Happens When a Client Runs a Security Assessment on You
A growing company usually spends its energy managing risk in one direction: vetting its own vendors, reviewing its own contracts, watching its own attack surface. Then a prospective or existing client's procurement team sends a questionnaire, sometimes a full assessment with a deadline attached, and the scrutiny suddenly runs the other way. For a company that has never been on the receiving end of one, the request itself is often the first sign that something has changed about how that client does business.
Why Clients Are Doing This Now
This isn't a compliance fad. Verizon's 2025 Data Breach Investigations Report found that third-party involvement in confirmed data breaches doubled year over year, from roughly 15% to 30%. When a breach traces back to a vendor instead of the company itself, the company that got breached still absorbs the notification costs, the regulatory exposure, and the reputational damage. Procurement and security teams have responded by pushing verification further down the supply chain, and that verification now reaches vendors far smaller than it used to.
A company with 25 to 200 employees is a common target for this shift. It's large enough to hold meaningful client data, connect to client systems, or process payments on a client's behalf, but usually too small to have a dedicated security team producing polished documentation on demand. Larger enterprise vendors already expect these requests and have a standard response ready. Growth-stage companies often don't, which makes the first assessment request land harder than it should.
What a Client Security Assessment Actually Looks Like
The exact format varies by client, but most fall into a few recognizable patterns.
A standardized questionnaire. Many larger clients use an industry-standard format rather than writing their own from scratch. The Standardized Information Gathering (SIG) questionnaire, maintained by Shared Assessments, is the most common general-purpose version and covers risk domains ranging from access control to physical security to business continuity. If the relationship is cloud-specific, a client may instead send the Consensus Assessments Initiative Questionnaire (CAIQ) from the Cloud Security Alliance, which focuses more narrowly on cloud service provider controls. Both come in shorter "lite" versions aimed at smaller vendors, though not every client bothers to send the lighter version.
A custom questionnaire. Some clients, particularly in healthcare, financial services, and government-adjacent industries, write their own questionnaire tailored to their specific regulatory obligations. These tend to ask more pointed questions about your subprocessors, your data retention practices, and your incident notification timelines.
A document and evidence request. Beyond the questionnaire itself, expect requests for your security policy, your incident response plan, your most recent penetration test summary, your SOC 2 report if you have one, and proof of cyber liability insurance. A client is rarely satisfied with a checkbox answer alone; they want something they can file as evidence.
An interview or call. For larger contracts, a questionnaire response sometimes triggers a follow-up call with the client's security or risk team, where they ask clarifying questions or push on anything that reads as vague.
What Clients Are Actually Checking For
Despite the variety in format, most assessments converge on the same underlying concerns. The table below covers the domains that show up most consistently.
| Domain | What They're Checking | Evidence They'll Ask For |
|---|---|---|
| Identity and access | Who can reach client data, and how access is removed | Access review policy, offboarding process |
| Data protection | Encryption in transit and at rest, data retention limits | Encryption standards, data flow diagram |
| Incident response | Whether you'd detect and report a breach quickly | Written incident response plan, notification SLA |
| Business continuity | Whether an outage on your end becomes an outage on theirs | Backup and disaster recovery plan |
| Subprocessor management | Who else touches their data through your vendors | Subprocessor list, your own vendor risk process |
| Endpoint and patch hygiene | Whether unpatched devices are a live entry point | Patch management policy, EDR coverage |
None of these individually require a large company to satisfy. They require a company that has written its practices down, keeps them current, and can produce evidence without scrambling.
What Happens If You're Not Ready
The immediate consequence is rarely a lost deal outright. It's delay. A questionnaire that should take a few days turns into a few weeks because answers require pulling information from three different people, none of whom has it fully documented. Deadlines slip, and in the meantime the deal sits in limbo rather than closing.
If the answers reveal a real gap, the response usually isn't a flat rejection either. Most clients issue a remediation request or a corrective action plan with a deadline attached, and some contracts include a right-to-audit clause that lets the client revisit the same questions on a recurring basis. A pattern of vague or inconsistent answers across a company's history with different clients is its own red flag, since it signals the responses were improvised rather than pulled from a maintained source of truth.
The businesses that struggle most with this aren't the ones with genuinely weak security. They're the ones whose actual practices are reasonable but were never written down anywhere a questionnaire response could point to. A slow, disorganized response to a security assessment reads to a procurement team as risk, whether or not the underlying controls are actually fine.
It Rarely Stops After the First Pass
Passing an initial assessment doesn't close the file permanently. Many enterprise clients reassess vendors annually, and some contracts include a right-to-audit clause that lets the client request updated evidence or run a follow-up review at any point during the relationship, not just at signing. A vendor risk profile also isn't static from the client's side: a client that expands the data or systems you touch, or that faces a new regulatory requirement of its own, may come back with a longer or more specific questionnaire than the one you answered the first time.
This is the part that catches unprepared companies off guard a second time. A company that scrambled through its first assessment and treated it as a one-time hurdle often has to scramble again a year later, because nothing from the first round was kept in a state that could simply be updated and resent. A company that built a maintained evidence library the first time can usually turn a renewal around in a fraction of the effort, since most of the underlying answers haven't changed, only the dates and a handful of details need refreshing.
How to Get Ahead of It
A growing company doesn't need to build an enterprise compliance program to handle this well. It needs a repeatable process.
- Build an evidence library once, and reuse it. Keep a current copy of your security policy, incident response plan, most recent penetration test or vulnerability scan summary, cyber insurance certificate, and a one-page architecture or data flow diagram. Most questionnaires ask for some combination of these five documents.
- Name a single owner. Someone should be responsible for receiving these requests, coordinating the response, and keeping the evidence library current. Without an owner, a questionnaire gets forwarded around until it lands on whoever seems least busy that week, which is rarely the person best positioned to answer it accurately.
- Keep your own subprocessor list current. Clients increasingly ask what vendors touch their data through you. If you can't produce that list quickly, it suggests you haven't been tracking it internally either, which is its own finding.
- Track what you've already answered. Save completed questionnaires so future responses stay consistent. Contradicting a previous answer to a different client is a common, avoidable way to trigger follow-up scrutiny.
- Decide your answer in advance for gaps you know exist. If a control isn't in place yet, have a short, honest statement ready: what the gap is, and the realistic timeline to close it. A prepared answer reads as a company that knows its own posture. An improvised one under deadline pressure rarely does.
Who Should Coordinate the Response
This is operational work, but it's not the kind of task most managed service providers are scoped to own. Your MSP keeps infrastructure running, patches systems, and manages day-to-day IT support, which is essential and separate from writing security policy narrative, coordinating an evidence library across departments, or deciding how to frame an honest answer about a gap. Most MSP contracts don't include that ownership, and expecting it to happen without a specific owner is how the evidence library never gets built in the first place.
Fractional technology leadership fills that specific gap. A fractional leader works alongside your existing MSP, which continues handling infrastructure day to day, while owning the questionnaire response process, the evidence library, and the judgment calls about how to represent your actual security posture accurately and consistently across clients.
Frequently Asked Questions
How long does it usually take to respond to a client's security assessment?
It depends heavily on preparation. A company with a current evidence library and a clear owner can often turn around a standard questionnaire in a few days. A company answering for the first time, pulling information from multiple people who haven't documented their own practices, can easily take several weeks, which is often longer than the client's procurement timeline allows.
Does having cyber insurance or a SOC 2 report already answer most of these questions?
They help significantly but don't replace the questionnaire itself. A SOC 2 report or cyber insurance certificate is strong supporting evidence for several domains at once, particularly incident response and data protection, but most clients still want their specific questions answered directly rather than accepting a report as a full substitute.
What if we don't have a formal control a client is asking about?
Answer honestly rather than implying a control exists that doesn't. Most clients expect some gaps from a growth-stage vendor and are more concerned with whether you have a credible plan and timeline to close it. A vague or evasive answer is read far more negatively than an honest one with a remediation date attached.
Does our MSP handle this for us?
Usually not fully. Your MSP manages infrastructure and day-to-day IT support, which is necessary but different from owning the questionnaire response, the evidence library, and the narrative around your security posture. Fractional technology leadership is designed to work alongside your MSP to close that specific gap, not to take over the infrastructure work your MSP already handles well.
Is a SIG or CAIQ questionnaire harder to answer than a custom one?
Not necessarily. Standardized questionnaires like SIG and CAIQ are longer but predictable, since the same domains show up across every client that uses them, which makes a reusable evidence library especially effective. A custom questionnaire can actually take longer the first time, since it requires interpreting what a client's specific wording is really asking for.
How do we get started building a repeatable process for this?
Start by assembling the five core documents most questionnaires ask for: security policy, incident response plan, recent penetration test or vulnerability scan summary, cyber insurance certificate, and a data flow diagram. Naming a single owner for that library and for coordinating future responses is the second step, and it's the one most growing companies skip until the second or third assessment request forces the issue.
Ready to Put This Into Practice?
Schedule a free consultation and let's talk through what this means for your organization specifically.
Schedule a Free Consultation