- Actual control
- Dated evidence
- Open limitation
A first enterprise questionnaire usually asks more than a young company can honestly answer “yes” to. The commercial mistake is not immaturity. It is treating aspiration as implementation and creating a representation the team cannot support.
Use the legal and operations chapter for the broader responsibilities. This guide is a buyer-readiness pack, not a compliance certification.
Build an evidence index before the questionnaire
Create a table with control, owner, current state, evidence link, evidence date, gap, and remediation date. Start with identity and access, asset inventory, data flow, backups, incident response, vulnerability handling, software dependencies, vendors, and employee offboarding.
NIST CSF 2.0 organizes cybersecurity outcomes under Govern, Identify, Protect, Detect, Respond, and Recover. NIST says the framework is outcome-based and non-prescriptive; using it does not make a company “NIST certified” (NIST CSF 2.0). Use those functions as coverage headings, not a badge.
Prove four basics
Access. Export the current user list for production, cloud, source control, support, and finance systems. Show MFA coverage, privileged roles, and the last access review. Remove stale accounts before taking the screenshot.
Backups. Record what is backed up, frequency, retention, encryption, owner, and the last successful restore. A backup job’s green icon proves a job ran; a restore test proves usable recovery.
Incidents. Name an incident commander, technical lead, customer-communications owner, and legal/insurance escalation path. Keep a short severity matrix and call tree. Do not promise a notification deadline until contract and legal requirements are reviewed.
Vendors and data. List subprocessors and critical vendors, what data each receives, region where known, contract/DPA status, and exit method. The FTC’s business guidance recommends need-to-know access and written security expectations for service providers; it is guidance grounded in enforcement experience, not a certification checklist (FTC Start with Security).
Worked hypothetical: answer the gap, not the fantasy
Worked hypothetical. A buyer asks, “Do you review privileged access quarterly?” The startup has MFA, two production administrators, and no recorded quarterly review. “Yes” is false. “No” without context may end the sale.
A defensible response is: “MFA is enforced for production administrators. Two named staff currently hold privileged access. We completed and recorded our first access review on September 15; quarterly review is now scheduled, but we do not yet have a quarter of operating history.” Attach the user export, review record, and policy owner. This is commercially useful because it distinguishes a missing control from missing evidence and from a new process.
Triage the questionnaire
Classify every question: implemented with evidence; partially implemented; not implemented; not applicable with reason; or requires legal/technical interpretation. Route privacy, breach-notification, audit-right, indemnity, and regulatory representations to qualified review. Keep a canonical answer library, but re-check volatile facts before every submission.
Never claim SOC 2, ISO 27001, HIPAA compliance, GDPR compliance, penetration testing, encryption everywhere, or 24/7 monitoring unless the exact statement is true and documented. A platform subscription or control mapping is not an independent attestation.
Buyer packet checklist
Prepare a current architecture/data-flow diagram; access-control evidence; restore-test record; incident plan and exercise note; vulnerability/dependency process; vendor/subprocessor list; retention/deletion summary; security contact; and dated gap register. Share sensitive evidence under appropriate access controls rather than attaching the entire internal security folder.
Limitations: this pack does not establish legal compliance or assurance. Buyer risk varies by data, integration, geography, and sector. A truthful “not yet, planned by date” can still be rejected, but a false “yes” compounds commercial and legal risk.
Sources & scope
Sources checked 19 September 2026. Worked scenarios are illustrative; recommendations are editorial analysis. These checks do not re-verify the entire original notebook.
- The NIST Cybersecurity Framework (CSF) 2.0 — National Institute of Standards and Technology
CSF 2.0 is organized around six functions including Govern and Recover. NIST describes the framework as outcome-based and non-prescriptive.
- Start with Security: A Guide for Business — Federal Trade Commission
FTC guidance recommends restricting sensitive-data access to need-to-know use. FTC guidance recommends written security expectations and oversight for service providers.
Developed from the original notebook
- 12. Security obligations and breach notification — Turns the chapter baseline into a small evidence pack and owner matrix.
- 19. Terms of service, privacy policies, DPAs and subprocessors — Adds vendor and customer-data boundaries to questionnaire answers.