Last updated: July 26, 2026
Getting Ready · Compliance Q&A

How do I respond to a security questionnaire without a SOC 2?

Answer honestly, describe the controls you already have, and share supporting documents like a security policy or pentest summary. State that a SOC 2 is planned or in progress with a target date if true.

The full answer

You can respond to a security questionnaire before you hold a SOC 2 — many companies do, especially early on. The key is to answer accurately based on the controls you actually operate, and to back your answers with whatever documentation you have. Enterprise buyers commonly ask for a SOC 2 Type 2, but a thoughtful, evidence-backed response often keeps a deal moving while yours is in progress.

Start by describing your real controls: access management, encryption, logging, backups, incident response, and how you manage vendors. Where you have supporting artifacts — a written security policy, a recent penetration test summary, or your cloud provider's own SOC 2 report — offer to share them, typically under NDA. If a questionnaire uses a standard format, answering it directly and completely signals maturity even without a certification attached.

Be transparent about gaps rather than overstating. If a SOC 2 is planned or underway, say so and give a realistic target date; never claim a report you do not have, because buyers verify. Framing your roadmap honestly builds more trust than vague assurances.

If questionnaires are becoming a recurring blocker, starting a SOC 2 is often the fastest fix. A Type 1 covers a point in time and typically takes one to three months, giving you a report to share sooner. SOC 2 audits booked through the AuditNex network start at $2,500 and average about $5,000, per the AuditNex network rate card (2026), and GRC platforms speed up the preparation that questionnaires probe.

Go deeper

Short answer not enough? These pages cover the full picture:

Complete SOC 2 guide ›  ·  SOC 2 timeline estimator ›

Get matched with the right auditor

Answer a few questions about your scope and see transparent, comparable pricing from vetted audit firms — no sales calls.

Get instant pricing →

Talk to auditors who handle this every week

Every firm on AuditNex is listed on identical terms — placement cannot be bought, and credentials are independently checked.

All auditor profiles ›

Related questions

Can a two-person startup get SOC 2?

Yes. SOC 2 has no minimum headcount; a two-person startup can earn a report. Controls simply scale to your size — the auditor assesses whether your controls fit your operations, not whether you have a large team.

Do I need a penetration test for SOC 2?

Not strictly. The AICPA's SOC 2 framework never names a penetration test as a required control, but most auditors and enterprise buyers expect one as evidence of vulnerability management, so in practice it is nearly standard.

Does SOC 2 cover remote work and BYOD?

Yes. SOC 2's Security criteria apply wherever your team works, so remote work and BYOD fall in scope. Auditors expect controls like endpoint protection, encryption, MDM or access policies, and secure authentication regardless of device location.

Does SOC 2 require MFA?

Effectively yes, though not by name. SOC 2's Trust Services Criteria require strong logical access controls without naming MFA, but auditors and customers treat multi-factor authentication as the baseline, so nearly every SOC 2 program enables it.

Does SOC 2 require a vendor management program?

Yes, in practice. SOC 2's Common Criteria include managing risks from vendors and subservice organizations, so auditors expect a vendor management process — inventory, risk-based due diligence, and monitoring — even though no single rule dictates its exact form.

Does SOC 2 require annual security training?

Not by a named rule. SOC 2's Trust Services Criteria require security awareness training but never specify a frequency; auditors and customers treat training at onboarding plus at least annually as the standard, so most companies run it yearly.

All compliance questions ›

Sources: AuditNex network rate card (2026); AICPA SSAE No. 18 attestation standards; Enterprise security questionnaire market practice (2026). Answer written and maintained by the AuditNex research team; last reviewed July 26, 2026. AuditNex is a marketplace — accredited firms price and scope engagements independently.