Skip to content
ResourcesSecurity

The security questionnaire that stalled your deal, and the one question behind it

13 July 20266 min read
WHERE THE DEAL STOPSDemowent wellPricingagreedProcurementquestionnaireSignaturewaitingTWO TO FOUR WEEKS ADDED

The demo went well. The price was agreed. Then procurement sent a spreadsheet with 140 questions about your security, and the deal has not moved in three weeks. This is the most common way a B2B software sale dies quietly.

Why this is happening to you now and not last year

Your customers are being audited. When a mid market or enterprise buyer takes on a supplier who touches their data, their own auditors and insurers want evidence that the supplier was assessed. That obligation runs downhill and lands on you.

In tax and accounting software it is sharper still, because HMRC's own guidance tells users to carry out due diligence on the developers of the software they use and to check it meets security standards. Your customers are being told to ask.

The question that stops everything

Most of a questionnaire can be answered honestly from what you already do. Then there is a version of this one:

“Do you undergo regular independent penetration testing? Please attach your most recent report.”

There is no clever answer. Either a report exists or it does not. Enterprise buyers expect to see a recent third party test alongside SOC 2, and for many it is a hard requirement rather than a preference.

What not to do

  • Do not claim you have one. They will ask for the PDF. A caught exaggeration in a security review does not lose you the deal, it loses you the account and the reference.
  • Do not send a vulnerability scan and call it a penetration test. Anyone who reads security reports for a living can tell in ten seconds.
  • Do not answer “our developers test everything thoroughly”. The question asks for independence. That answer confirms you have none.
  • Do not go silent. Silence reads as a problem being hidden.

What to do instead

Say plainly that an independent review is booked, give the date, and offer to share the report when it lands. Honest and scheduled beats vague every time, and buyers routinely accept a committed date. Being straight about a gap with a plan attached reads as maturity. Guessing reads as risk.

Getting ahead of it permanently

The reason this hurts is that it arrives as a surprise at the worst moment. It does not have to.

  • Keep one document with your standard answers, so the second questionnaire takes hours rather than weeks
  • Have a current independent test report on the shelf before procurement asks, not after
  • Have a re-test on record too, because a report full of unfixed findings is worse than none
  • Publish a short security page, so the easy questions are answered before anyone sends a spreadsheet

Where we come into it

A Build Review is £2,500 and takes about two weeks end to end. It produces two documents: a technical fix list for your developers, and a plain English report you can hand to a customer without editing it first. The re-test of anything your developers fix is included, so the report you send is a report of fixed problems.

If the questionnaire is already on your desk, say so on the call and we will tell you honestly whether we can turn it round in time.

FAQ

Quick answers

Why do security questionnaires stall B2B software deals?
Because they arrive after pricing is agreed, carry an aggressive deadline, and usually contain at least one question the vendor cannot answer, most often the request for a recent independent penetration test report. Preparation turns a multi week delay into a one to three day response.
What do I say if I have never had a penetration test?
Say so, state that an independent review is booked, give the date, and offer to share the report. Buyers routinely accept a committed date. Claiming a test you have not had is far worse, because they will ask for the PDF.
Can I send a vulnerability scan instead of a penetration test report?
No. Anyone who reads security reports for a living can tell the difference immediately, and being caught substituting one for the other damages trust more than having neither.
How long does it take to get a penetration test report?
Around two weeks end to end for a small platform: scoping and written authorisation, two to three days of testing, then the write up. Ask whether a re-test of the fixes is included, because a report of unfixed findings is worse to send than none.

Who checks what your developers ship?

An independent security and build review of what your agency delivered. £2,500, about two weeks, with a re-test of their fixes included.