How to answer a security questionnaire with no SOC 2

Twelve recurring questions, each with the answer that is true today and the answer that is true once a report exists, plus the four sentences that turn a delay into a misrepresentation.

How to answer a security questionnaire before your SOC 2 report exists: write every answer yourself, mark anything not true yet as not yet, and put a date on it. The form runs long because the frameworks under it do. The Cloud Security Alliance’s Cloud Controls Matrix version 4.1, which the CAIQ is built from, carries 197 control objectives across 17 domains (cloudsecurityalliance.org, read 1 August 2026).

A report retires more of that form than any autofill can, for a structural reason. It changes who is asserting.

This is the form in your inbox with a due date. The one you send your own vendors is a different document, and it lives at the vendor security questionnaire.

Why the same twelve questions keep coming back

Three sources generate nearly all of them. The CAIQ, published by the Cloud Security Alliance and mapped onto the Cloud Controls Matrix. The SIG, published by Shared Assessments and licensed to its members. And the spreadsheet a buyer’s security engineer built from those two.

Underneath, they converge hard. Encryption, access, people, incidents, vendors, recovery. Answer the twelve below once, properly, and the next form is mostly written.

One move is available before any report exists. A CAIQ self assessment published to the CSA STAR Registry is complimentary and public (cloudsecurityalliance.org/star, read 1 August 2026). It carries no third party testing. It does mean a reviewer can read your posture without emailing you.

The answer library

Two columns, because the true answer changes on the day the report is issued. Bracketed text is yours to fill. Nothing here is worth pasting if it is not true of your company.

What they askAnswer while no report existsAnswer once it is issued
Do you hold a SOC 2 report?Not yet. A Type 1 examination is under way, as of [date]. Control matrix, policies and a walkthrough are available today. The report follows on issue.Yes. Security criteria, period [dates], issued by [CPA firm]. Under NDA, with a bridge letter for the months since it closed.
Is our data encrypted in transit and at rest?TLS 1.2 or above in transit. AES-256 at rest with [provider] managed keys. If either is not true today, name which and give the date it lands.Same, tested across the period. The tests print in Section 4.
Is multi factor authentication enforced?Enforced for every employee on the identity provider, cloud console and code repository. Name any system where it is not, and what covers it.Same, sampled across the period. Any exception prints in Section 4.
How often do you review user access?[Interval], owned by [name], on a dated review sheet. Write the interval you will keep. Quarterly beside one completed review reads worse than annual.Same, and the auditor sampled the reviews in the period.
How fast is access removed when someone leaves?Within [n] business day of the termination ticket, on an offboarding checklist with a named approver and a timestamp.Same, tested against a sample of leavers in the period.
Do you run background checks?Yes, before start date, through [vendor]. Where contractor screening is limited, say so and name what you do instead.Same, sampled from hires inside the period.
Do you have an incident response plan, and how fast do you notify us?Yes, with severity tiers, a named on call owner and a post incident review. We notify affected customers within [n] hours of confirming a breach. If it has never run, say so.Same, and the plan was tested. Incidents in the period appear in the report.
Which subprocessors handle our data?The current list is at [url]. We give [n] days notice before adding one that touches customer data, and you may object.Same list. The report also names the subservice organizations carved out.
When was your last penetration test?[Date], by [firm], summary under NDA. If you have never had one, say so and give the booked date. A vulnerability scan is not a penetration test.Same, read by the auditor as a separate evaluation under CC4.1.
Are backups taken, and have restores been tested?Automated [frequency] backups, encrypted, retained [n] days. Last restore test [date]. If none has ever been tested, book one and say so.Same, evidenced across the period with Availability in scope.
What happens to our data when we terminate?Deleted within [n] days of a written request, backup copies expiring [n] days after that. Deletion confirmed in writing.Same, and the disposal control is tested with Confidentiality in scope.
Do employees complete security training?On hire and [interval] after, with per person completion records. Give the real figure if asked.Same, sampled from records inside the period.

Where each answer is supposed to come from

Every row traces to a criterion in the Trust Services Criteria2 and to a document you either own or do not. If you cannot point at the document, that is the gap. The names below are the pack in the SOC 2 policy list.

SubjectCriteriaSource document
EncryptionCC6.1, CC6.7Cryptography Policy
Multi factor authenticationCC6.1Access Control Policy
Access review, offboardingCC6.2, CC6.3Access Control Policy
Background checks, trainingCC1.4, CC2.2Human Resources Security Policy
Incidents, notificationCC7.3, CC7.4, CC2.3Incident Response Policy
SubprocessorsCC9.2Third Party and Vendor Management Policy
Penetration testingCC4.1Risk Management Policy
Backups, restoreCC9.1, plus A1.2 with Availability in scopeBusiness Continuity and Disaster Recovery Policy
Deletion on terminationCC6.5, plus C1.2 with Confidentiality in scopeData Management Policy

The line between not yet and misrepresentation

Not yet is a fine answer. Four sentences are not. Each is cheap to avoid and expensive to walk back.

  1. We are SOC 2 certified. There is no certificate. A SOC 2 is an attestation report carrying an opinion for one date or one stated period.1 A reviewer who reads these daily catches the word.
  2. We are SOC 2 compliant. There is no compliance status to be in. There is an issued report, or there is not.
  3. Our report is available under NDA, written while the examination is running. Offer it the day it exists.
  4. Yes, to a control you intend to build. The expensive one, easiest to type.

The cost is not the awkward correction. Questionnaire answers are commonly attached to the master agreement or incorporated by reference, which turns each row into a representation you have warranted. A wrong yes resurfaces twice. Once when the buyer’s own auditor tests their vendor file, again at renewal, when your answer has to change.

A dated not yet reads as a roadmap. Ours is public: what we do with your evidence carries a section for what we have not done yet.

What the report actually retires

An issued report does not fill in the form. It changes the signature under the answers. Before it, you are the only party saying your access reviews happen. After it, a licensed CPA firm has tested a sample and written an opinion.1

So rows 2 through 12 collapse into one attachment for much of the review. What survives are the questions about your contract rather than your system: data location, deletion, notice before a new subprocessor, and your notification window. Read a vendor’s report the same way, using how to verify a SOC 2 report you were sent.

Polara G.R.C. writes the thirteen policies these answers cite from your own stack, then assembles the evidence the examination runs on. A Type 1 is $4,000 one time, first examination and independent partner auditor fee included. If a live deal set the date, the customer asking for a SOC 2 report covers the calendar.

Say this accurately

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Questions

How do you answer a security questionnaire when you have no SOC 2 report?
Answer every question in your own words, mark anything that is not true yet as not yet, and attach a date. Send your written policies, your control matrix and an offer of a walkthrough call alongside the form. A dated not yet is a normal answer in enterprise procurement. A yes you cannot evidence becomes a contract problem later.
What is the difference between the CAIQ and the SIG?
The CAIQ is published by the Cloud Security Alliance and maps onto the Cloud Controls Matrix, which carries 197 control objectives across 17 domains in version 4.1. The SIG is published by Shared Assessments and licensed to its members. Buyers also send spreadsheets of their own. The underlying subjects are the same twelve either way.
Can you say you are SOC 2 certified while the examination is running?
No, and not afterwards either. There is no SOC 2 certificate. A SOC 2 is an attestation report carrying an opinion for a single date or for a stated period, so the accurate sentence is that an examination is under way, naming the date your controls are being examined as of.
Which questionnaire answers does a SOC 2 report actually replace?
The ones about how your system operates: encryption, access reviews, offboarding, incident response, change management, backups. A reviewer who accepts the report reads a CPA firm test of those controls instead of your self assertion. Questions about your contract stay open, including data location, deletion on termination, subprocessor notice and your breach notification window.
Is there anything worth publishing before you have a report?
A CAIQ self assessment published to the CSA STAR Registry is complimentary and public, so a reviewer can read your answers without emailing you a form. It carries no third party testing, so it does not do what a report does. It is available on day one, and it is checkable.

Sources

  1. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.
  2. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.

Get audit-ready without a compliance team.

$4,000 one time for SOC 2 Type 1, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.

Get started

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

polara labs

Polara Labs builds both sides of the small end of the compliance market: the readiness platform startups use to earn a SOC 2, and the practice software boutique firms use to run the examination. Prices are published on each product page.

© 2026 Polara Labs Inc. All rights reserved.Contact: founder@polaralabs.com

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms in our network; the audit opinion is theirs alone and is not regulated by Polara Labs. We generate custom policies, evidence checklists, and remediation guidance. You remain responsible for implementing controls and owning audit outcomes. Replace placeholders with your actual controls and have final documents reviewed by qualified professionals before your audit.

Built by Surya Shetty