How to answer a security questionnaire with no SOC 2
Twelve recurring questions, each with the answer that is true today and the answer that is true once a report exists, plus the four sentences that turn a delay into a misrepresentation.
How to answer a security questionnaire before your SOC 2 report exists: write every answer yourself, mark anything not true yet as not yet, and put a date on it. The form runs long because the frameworks under it do. The Cloud Security Alliance’s Cloud Controls Matrix version 4.1, which the CAIQ is built from, carries 197 control objectives across 17 domains (cloudsecurityalliance.org, read 1 August 2026).
A report retires more of that form than any autofill can, for a structural reason. It changes who is asserting.
This is the form in your inbox with a due date. The one you send your own vendors is a different document, and it lives at the vendor security questionnaire.
Why the same twelve questions keep coming back
Three sources generate nearly all of them. The CAIQ, published by the Cloud Security Alliance and mapped onto the Cloud Controls Matrix. The SIG, published by Shared Assessments and licensed to its members. And the spreadsheet a buyer’s security engineer built from those two.
Underneath, they converge hard. Encryption, access, people, incidents, vendors, recovery. Answer the twelve below once, properly, and the next form is mostly written.
One move is available before any report exists. A CAIQ self assessment published to the CSA STAR Registry is complimentary and public (cloudsecurityalliance.org/star, read 1 August 2026). It carries no third party testing. It does mean a reviewer can read your posture without emailing you.
The answer library
Two columns, because the true answer changes on the day the report is issued. Bracketed text is yours to fill. Nothing here is worth pasting if it is not true of your company.
| What they ask | Answer while no report exists | Answer once it is issued |
|---|---|---|
| Do you hold a SOC 2 report? | Not yet. A Type 1 examination is under way, as of [date]. Control matrix, policies and a walkthrough are available today. The report follows on issue. | Yes. Security criteria, period [dates], issued by [CPA firm]. Under NDA, with a bridge letter for the months since it closed. |
| Is our data encrypted in transit and at rest? | TLS 1.2 or above in transit. AES-256 at rest with [provider] managed keys. If either is not true today, name which and give the date it lands. | Same, tested across the period. The tests print in Section 4. |
| Is multi factor authentication enforced? | Enforced for every employee on the identity provider, cloud console and code repository. Name any system where it is not, and what covers it. | Same, sampled across the period. Any exception prints in Section 4. |
| How often do you review user access? | [Interval], owned by [name], on a dated review sheet. Write the interval you will keep. Quarterly beside one completed review reads worse than annual. | Same, and the auditor sampled the reviews in the period. |
| How fast is access removed when someone leaves? | Within [n] business day of the termination ticket, on an offboarding checklist with a named approver and a timestamp. | Same, tested against a sample of leavers in the period. |
| Do you run background checks? | Yes, before start date, through [vendor]. Where contractor screening is limited, say so and name what you do instead. | Same, sampled from hires inside the period. |
| Do you have an incident response plan, and how fast do you notify us? | Yes, with severity tiers, a named on call owner and a post incident review. We notify affected customers within [n] hours of confirming a breach. If it has never run, say so. | Same, and the plan was tested. Incidents in the period appear in the report. |
| Which subprocessors handle our data? | The current list is at [url]. We give [n] days notice before adding one that touches customer data, and you may object. | Same list. The report also names the subservice organizations carved out. |
| When was your last penetration test? | [Date], by [firm], summary under NDA. If you have never had one, say so and give the booked date. A vulnerability scan is not a penetration test. | Same, read by the auditor as a separate evaluation under CC4.1. |
| Are backups taken, and have restores been tested? | Automated [frequency] backups, encrypted, retained [n] days. Last restore test [date]. If none has ever been tested, book one and say so. | Same, evidenced across the period with Availability in scope. |
| What happens to our data when we terminate? | Deleted within [n] days of a written request, backup copies expiring [n] days after that. Deletion confirmed in writing. | Same, and the disposal control is tested with Confidentiality in scope. |
| Do employees complete security training? | On hire and [interval] after, with per person completion records. Give the real figure if asked. | Same, sampled from records inside the period. |
Where each answer is supposed to come from
Every row traces to a criterion in the Trust Services Criteria2 and to a document you either own or do not. If you cannot point at the document, that is the gap. The names below are the pack in the SOC 2 policy list.
| Subject | Criteria | Source document |
|---|---|---|
| Encryption | CC6.1, CC6.7 | Cryptography Policy |
| Multi factor authentication | CC6.1 | Access Control Policy |
| Access review, offboarding | CC6.2, CC6.3 | Access Control Policy |
| Background checks, training | CC1.4, CC2.2 | Human Resources Security Policy |
| Incidents, notification | CC7.3, CC7.4, CC2.3 | Incident Response Policy |
| Subprocessors | CC9.2 | Third Party and Vendor Management Policy |
| Penetration testing | CC4.1 | Risk Management Policy |
| Backups, restore | CC9.1, plus A1.2 with Availability in scope | Business Continuity and Disaster Recovery Policy |
| Deletion on termination | CC6.5, plus C1.2 with Confidentiality in scope | Data Management Policy |
The line between not yet and misrepresentation
Not yet is a fine answer. Four sentences are not. Each is cheap to avoid and expensive to walk back.
- We are SOC 2 certified. There is no certificate. A SOC 2 is an attestation report carrying an opinion for one date or one stated period.1 A reviewer who reads these daily catches the word.
- We are SOC 2 compliant. There is no compliance status to be in. There is an issued report, or there is not.
- Our report is available under NDA, written while the examination is running. Offer it the day it exists.
- Yes, to a control you intend to build. The expensive one, easiest to type.
The cost is not the awkward correction. Questionnaire answers are commonly attached to the master agreement or incorporated by reference, which turns each row into a representation you have warranted. A wrong yes resurfaces twice. Once when the buyer’s own auditor tests their vendor file, again at renewal, when your answer has to change.
A dated not yet reads as a roadmap. Ours is public: what we do with your evidence carries a section for what we have not done yet.
What the report actually retires
An issued report does not fill in the form. It changes the signature under the answers. Before it, you are the only party saying your access reviews happen. After it, a licensed CPA firm has tested a sample and written an opinion.1
So rows 2 through 12 collapse into one attachment for much of the review. What survives are the questions about your contract rather than your system: data location, deletion, notice before a new subprocessor, and your notification window. Read a vendor’s report the same way, using how to verify a SOC 2 report you were sent.
Polara G.R.C. writes the thirteen policies these answers cite from your own stack, then assembles the evidence the examination runs on. A Type 1 is $4,000 one time, first examination and independent partner auditor fee included. If a live deal set the date, the customer asking for a SOC 2 report covers the calendar.
Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Questions
How do you answer a security questionnaire when you have no SOC 2 report?
What is the difference between the CAIQ and the SIG?
Can you say you are SOC 2 certified while the examination is running?
Which questionnaire answers does a SOC 2 report actually replace?
Is there anything worth publishing before you have a report?
Sources
Get audit-ready without a compliance team.
$4,000 one time for SOC 2 Type 1, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.
Get startedPolara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.