Triaging a 300-question security questionnaire before you answer
A 48-hour triage process that groups questions by security domain and sorts them into answered, partial, and exposed tiers before your team types a single response.
By Kellwick Team · September 26, 2026 · 5 min read
A 300-question security questionnaire lands in your inbox. The enterprise prospect wants it back in five business days. Your first instinct is to open the spreadsheet and start typing. Resist that instinct. The teams that answer fastest are rarely the teams that answer best, and inconsistent or poorly scoped answers will follow you into a contract negotiation - or deeper into a due-diligence process - where they are very hard to walk back.
This post walks through the 48-hour triage process Kellwick uses when helping SaaS companies respond to large questionnaires. The goal is not speed. The goal is to enter the answering phase with a clear picture of what you actually have, what you do not, and which questions carry real risk if answered badly.
Why triage at all
A 300-question questionnaire is not 300 equal questions. It is, in practice, three or four dozen questions repeated across different frameworks and phrasings, plus a cluster of questions that are genuinely hard and probably expose a gap, plus filler that any company can answer in a sentence.
If you start answering question one and work your way down, you will hit a genuinely difficult question in the middle of the spreadsheet, guess at an answer because the deadline is pressing, and then contradict yourself three tabs later when the same topic comes up again. The buyer's security team will notice. That inconsistency creates more scrutiny than the underlying gap would have.
Triage separates the questionnaire into these buckets before a single answer is typed.
The first pass: strip duplicates and map to domains
Open the questionnaire and read every question once without answering. As you read, assign each question a rough domain label: identity and access management, encryption, incident response, business continuity, vendor management, physical security, and so on.
Most large questionnaires draw from multiple frameworks simultaneously - SOC 2, ISO 27001, NIST CSF, CAIQ - and the overlap is substantial. You will often find that 80 of your 300 questions are asking about access control in different words. Grouping by domain makes that visible.
Once grouped, identify your canonical answer for each domain. That canonical answer is the source of truth every person who touches this questionnaire must use. Without it, your head of engineering will write one thing about MFA enforcement and your head of security will write something subtly different two tabs later.
The second pass: classify by difficulty and risk
Within each domain group, classify questions into three tiers.
Tier one is answered. You have the policy, the evidence, and the practice. These questions take ten minutes total and should be delegated.
Tier two is partially answered. You have something but it is incomplete, undocumented, or inconsistent with what the question is asking. These questions need a short internal conversation before anyone types a word. The risk here is overstating your control and creating a contractual representation you cannot support.
Tier three is exposed. You do not do this. The questionnaire is asking about a control or practice you have not implemented. These questions must surface to leadership before the questionnaire is returned. The decision of how to answer - with a compensating control, a timeline for remediation, or an honest "not applicable to our architecture" - is not a decision the person filling in the spreadsheet should be making alone.
In a typical 300-question questionnaire, Tier one will be around 60 percent, Tier two around 30 percent, and Tier three will be 10 percent or fewer. That 10 percent is where deals are won or lost.
The 48-hour triage process in practice
Hours 0-4: One person reads the entire questionnaire and produces the domain grouping and tier classification. This person should not start typing answers. Their output is a structured triage summary: domains, question counts per tier, and a flagged list of Tier three items.
Hours 4-8: The triage summary goes to whoever owns the commercial relationship and whoever owns security. They make decisions on Tier three together. What compensating controls exist? Is there a genuine remediation underway with a defensible timeline? Is the question actually out of scope for your architecture? Every Tier three question needs a decision and a note before the answering team sees it.
Hours 8-24: Assign Tier one and Tier two questions to subject-matter owners by domain. Each owner gets their domain group, the canonical answer for that domain, and the triage notes. They answer. They do not deviate from the canonical answer without checking first.
Hours 24-48: One person does a consistency pass across all tabs. They check that MFA is described the same way in every section. That your encryption standard is named consistently. That your incident response timescale matches in the access control section and the security incident section. This pass catches the contradictions that the buyer's team will otherwise find first.
What not to do in the first 48 hours
Do not answer Tier three questions optimistically because the questionnaire feels like a formality. Enterprise buyers increasingly have dedicated vendor risk teams whose job is to probe exactly those answers in follow-up calls. An optimistic answer in the questionnaire becomes a false representation in a follow-up call, which becomes a problem in the contract.
Do not let the sales team answer security questions without input from whoever owns the technical controls. The sales team will answer in good faith, but they are not positioned to know whether your encryption-at-rest claim covers backup storage as well as production.
Do not skip the consistency pass. The most common finding Kellwick sees when reviewing questionnaire drafts is that the same control is described differently across sections. Buyers notice this and it triggers deeper investigation.
Scope questions deserve special attention
Many questionnaires include questions about your certifications, and if you hold an ISO 27001 certificate, the follow-up will be about scope. What systems are in scope? Does scope include your production environment? Your development environment? Your support tooling?
Answer scope questions with precision. A vague answer - "our information security management system covers our core product" - will prompt a follow-up, and the follow-up will be more specific than the original question. Answer it specifically the first time: which systems, which environments, which data types.
The outcome of good triage
A well-triaged questionnaire is faster to complete, more consistent, and more defensible. The answering team spends their time on answers rather than on deciding what to answer. Leadership is not surprised by Tier three disclosures that were buried in the middle of the spreadsheet. And when the buyer's team asks follow-up questions - which they will - the answers given in the questionnaire and the answers given in conversation are the same.
Where Kellwick fits: Kellwick works with SaaS companies as an independent advisory when large questionnaires arrive and internal bandwidth is limited. We run the triage, surface Tier three items with context, and help draft answers that are accurate and consistent. If your team needs structured support through a high-stakes questionnaire response, learn more about how Kellwick can unblock security questionnaires.
Need a second pair of eyes before the auditor does?
A readiness review shows exactly where your ISMS stands - and what to fix first - while there is still time to act on it.
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.