Security Questionnaire Without SOC 2: A Startup Response Guide
Answer a customer security questionnaire without a SOC 2 report by checking each claim against current systems, naming gaps, and agreeing on the next review.

You can answer a customer security questionnaire without a SOC 2 report if the buyer accepts that route. Say clearly that no report exists, answer from what your team does today, and mark planned work as planned. Ask the buyer which answers and supporting material it needs to make a decision. A completed questionnaire is your company’s statement, not an independent examination.
First, confirm what the buyer will accept
A questionnaire and a SOC 2 report answer different needs. The AICPA describes SOC 2 as an examination of a service organization’s system description and controls by a CPA firm. A buyer’s questionnaire contains questions that buyer selected for its own review. The buyer may accept your answers while a report is in progress, or it may require the report before signing.
Before filling in 150 cells, ask the buyer’s security or procurement owner:
- Is the questionnaire an accepted alternative for this decision, or an interim step before a required SOC 2 report?
- Which product, data flow, and legal entity do the questions cover?
- Which answers need a document, screenshot, export, or live discussion?
- Who may receive the material, and how should you deliver it?
- Who will confirm that the review is complete, and by what date?
If the buyer asks specifically for a report, use the first response plan for a SOC 2 request. Do not call a questionnaire, a policy set, or a penetration test equivalent to a SOC 2 report.
How to answer a security questionnaire without SOC 2
Assign one person to own the response. For each question, collect the current answer, the system or person that can prove it, and a reviewer. This is a practical process recommendation, not an audit standard.
| Buyer asks | Check before answering | Safe response pattern |
|---|---|---|
| Do you use multifactor authentication? | Identity provider settings, covered users, exceptions, and last review | “Yes, for [covered group] in [system]. [Exception] remains open.” |
| Do you review production access? | Actual review records, date, scope, reviewer, and follow-up | “We review [scope] on [cadence]. The last review finished [date].” |
| Do you test backups? | Backup platform and dated restore test result | “Backups run [schedule]; the last restore test was [date].” |
| Do you have a SOC 2 report? | Issued report, its service scope and date | “No SOC 2 report has been issued for this service.” |
Replace the bracketed text with verified facts. If a control is absent, answer “no” or “not yet” in the buyer’s format and explain the real remediation plan. Do not use a draft policy, a tool subscription, or a hoped-for report date as proof that a control operates. A policy can tell you what your company intends to do; the source system and dated work show what happened.
For each answer, keep a compact working record:
Question ID: ACCESS-04
Service in scope: Production application
Claim: Quarterly production access review
Status: Operating, with one open removal follow-up
Source: Identity provider export and approved review record
Source checked on: 2026-09-25
Fact owner: Engineering lead
External answer approved by: Founder
Shared material: Redacted review summary, via approved buyer channel
Keep the buyer’s raw questionnaire, contract terms, and sensitive exports in your approved sales or document system. A private GRC repository can hold the minimum reusable facts and references your team needs, subject to its access and retention rules. Do not commit credentials, private keys, tokens, or personal data that may need erasure to Git.
Separate current facts, gaps, and plans
Use three labels in your working copy: operating, partly operating, and planned. The label is internal; use the buyer’s required response format when you submit. This stops a yes/no cell from hiding a material exception.
For example, if engineers use multifactor authentication but one break-glass account has a different safeguard, describe the actual scope and exception. If a quarterly access review has a due date but no completed review, say it is planned. Ask the responsible owner to verify the statement before it leaves the company.
NIST’s Cybersecurity Supply Chain Risk Management guidance includes a scoping questionnaire for supplier assessments. That is one example of why a buyer’s questions depend on the service and risk it is evaluating. There is no single stock answer sheet that fits every product boundary.
Send a response the buyer can inspect
Send the completed questionnaire through the buyer-approved channel, with an owner for follow-up. A short cover note can prevent an answer from being read as a broader assurance claim:
We do not currently have a SOC 2 report for [service]. These answers describe the controls we operate as of [date] for [scope]. We have marked open work and exceptions in the questionnaire. Please tell us which items need more detail and whether this review meets your current procurement requirement.
Review each attachment before sharing it. Redact credentials, customer data, unrelated personnel details, and internal paths that the buyer does not need. Record which version you sent and when, so the next response does not repeat an old claim after the system changes.
If the buyer still requires a report, use its exact requirement to decide whether and when to start SOC 2. Discuss the report type, scope, and dates with a qualified CPA firm. Do not promise that the buyer will accept an interim questionnaire unless its owner confirms it.
Where Git and an agent can help
A Git-native GRC workspace can keep the reusable program record behind an answer: JSON for structured systems, controls, owners, and evidence references; Markdown for policies and long-form work; and Git for the change history. Git records when the files changed. Dated source records still need to show when an access review or restore test happened.
FileGRC can organize those records and validate their relationships. Its starter records are proposals, not claims about your company. It does not read your identity or backup system for you, fill out the buyer’s questionnaire, or decide whether the answer is enough. An agent can prepare a draft from reviewed records and point out missing evidence, but a person should verify the source facts and approve the external response. The AI agent workflow for SOC 2 shows that review path.
Run your SOC 2 program as files in Git.
Keep policies, controls, work, and evidence indexes in a repository your team and agents can inspect. Add optional hosted email and Slack reminders to keep work moving.
Frequently asked questions
Can I answer a security questionnaire without a SOC 2 report?
Yes, if the buyer accepts that review path. State that you do not have a SOC 2 report, answer each question from current facts, identify gaps, and provide only approved supporting material. A questionnaire does not replace a SOC 2 report.
What should I say if the questionnaire asks whether we are SOC 2 compliant?
Say whether an independent CPA firm has issued a SOC 2 report for the service in question. If no report exists, say so plainly and describe any real preparation or examination stage separately. Do not turn a plan or a policy into a report claim.
What if a security control is planned but not operating yet?
Mark it as planned or not yet implemented, name the owner and proposed next step, and give a date only when your team has approved a credible schedule. Do not answer yes based on a draft policy or future purchase.
Does a security questionnaire satisfy a buyer's SOC 2 requirement?
Only the buyer can decide whether another review meets its procurement or contract requirement. Ask its security or procurement owner to confirm the accepted interim evidence and any report deadline in writing.
Can an AI agent fill out a security questionnaire?
An agent can draft answers from approved records and flag missing support, but a person should verify current source-system facts, approve each external claim, and control what confidential material is shared.