Every enterprise deal reaches the same holy moment. The champion loves you. Legal has stopped screaming. And then, like a toll booth appearing out of the fog, someone from Procurement attaches a spreadsheet titled Vendor_Security_Assessment_v3_FINAL_FINAL.xlsx and the deal enters its true final boss.

We have filled out over 4,000 of these at B2B SaaS Guru, mostly for deals with ourselves, and we've come to a firm conclusion: the security questionnaire measures almost nothing about security. Here's what it actually measures.

1. Whether you have a person whose job is answering this

Row 12 asks if you encrypt data at rest. Row 187 asks it again, phrased as "Is data encrypted while not in transit?" Row 304 asks a third time, in a dropdown, with the options "Yes," "No," and "N/A," as if a fourth possibility exists in which your data achieves a state of grace beyond encryption. The questionnaire isn't testing your infrastructure. It's testing whether you're a company mature enough to have hired someone whose entire personality is now this spreadsheet.

2. Whether your SOC 2 report can be cited without being read

Nobody on the buying side is going to read your 94-page SOC 2 Type II report. What they want is the ability to write "Vendor provided SOC 2 Type II, see attached" in a column, so that six months from now, when something goes wrong, the sentence exists. This is not due diligence. This is due diligence's evidence locker. You are not being assessed; you are being filed.

3. Whether you'll say "penetration test" with confidence

There is a section, always, called "Application Security," and it always asks when you last conducted a third-party penetration test. The correct answer is a specific date, stated plainly, the way a defendant states their alibi. The incorrect answer — the one that ends deals — is any sentence containing the phrase "we do continuous security reviews internally," which Procurement has been trained, correctly, to read as "no."

4. Whether you understand this is theater too

The most senior move in the entire ritual is a call, thirty minutes before the questionnaire is due, in which their security lead says, off the record, "honestly just get us the SOC 2 and answer the red flags in section four, nobody's reading the rest." This is the actual security review. The spreadsheet is a receipt for a conversation that already happened, printed in advance so that both parties can point to something later.

5. Whether the relationship can survive a follow-up question

Every questionnaire ends with a free-text box: "Please describe your incident response process." You will write four sentences about a documented escalation path. They will not ask a follow-up question, because a follow-up question would require reading your answer, and reading your answer was never the plan. The box exists so that "we asked" is a true sentence in a future post-mortem.

What we are not saying

We are not saying security questionnaires are pointless. Some vendor really has left an S3 bucket open to the world with a README inside titled definitely_not_customer_data, and somewhere a 400-row spreadsheet caught it, and a real bad day was avoided. We are saying that for the other 96% of vendors, the questionnaire's actual function is procedural, not investigative — a way for two companies to agree, on paper, that due diligence occurred, so that everyone downstream of the deal can sleep.

Our recommendation

Answer every question in the affirmative voice, cite a document whenever possible, and never volunteer a caveat that wasn't asked for directly — a caveat is just an incident report with better timing. Keep your SOC 2 within arm's reach at all times, the way a magician keeps a card up their sleeve, ready to be produced with total confidence the instant anyone asks a question you would rather not answer in your own words.

If your security questionnaire response time is currently measured in "weeks" and you'd like it measured in "the time it takes someone to open an email," email us at contact@b2bsaas.guru. We'll send you a template. It will not make your infrastructure more secure. It will make it look, on a spreadsheet, exactly as secure as everyone else's.