GuardVest · September 19, 2026
A prospective customer sends a security questionnaire. Some questions are easy; others ask for policies, technical evidence or testing your startup has not completed. The useful next step is to establish what is true today, what the customer requires and who will close the gaps.
Start with the actual requirement
Ask which product, environment and data the review covers. Find out whether the customer needs a completed questionnaire, a particular test, an independent assurance report or a contractual commitment. These are different requests. Do not commission an audit simply because a questionnaire mentions a framework; clarify the acceptance criteria first.
Build a small, accurate evidence pack
Gather the current materials you can support with evidence. Keep confidential details in an approved sharing channel and limit access to the people reviewing them.
- Systems and data: what you operate, what customer information you handle and where it flows.
- Access: who approves access, how accounts are protected and how departing staff lose access.
- Operating practices: how you identify weaknesses, approve changes and maintain recovery arrangements.
- Response: who makes incident decisions and how you would communicate with customers.
- Gaps: what is incomplete, who owns it and the realistic next milestone.
A policy describes an intended practice; it is not proof the practice is operating. Pair your description with appropriate evidence, such as a dated access review or recovery exercise record. Never describe planned work as already implemented.
Prioritize security as well as paperwork
Basic protections still matter while you prepare documents. NIST recommends measures including multifactor authentication, software updates, protected and tested backups, and employee awareness. Its small-business cybersecurity guidance is a useful starting point.
For each unresolved question, record the business impact, accountable owner, action and target date. Discuss blockers with the customer rather than promising a deadline your team cannot meet. Requirements vary by customer; a completed checklist does not guarantee approval.
Choose help that matches the gap
If you do not yet know your priorities, GuardVest’s Security Assessment produces findings and a 90-day action roadmap. If you also need operating documents and a response rehearsal, explore the Security Readiness Program. For a defined questionnaire or policy assignment, a Single-Purpose Engagement may be a better fit.
Already have a specific decision to discuss? Ask GuardVest provides a paid expert consultation. Independent audits, certifications and penetration tests are separate from the readiness deliverables described on this site.