A client of mine, roughly 55 people, B2B software, sent me a Slack message in March that said "we lost the deal on paperwork." They had a €140,000 opportunity with a mid-sized insurer. Demo went well, champion was real, budget confirmed, procurement engaged. Then the buyer's IT security team sent over a spreadsheet with 312 questions and asked for a completed copy plus supporting evidence.
The CTO opened it, looked at it, and closed it. It sat for nine days. Then he spent two evenings on it, got through about a third, and stalled on a section about subprocessor notification periods that needed a legal answer nobody had written down. The completed file went back 26 days after it arrived. By then the buyer's project sponsor had moved the go-live date to the next fiscal year and the deal quietly slid into a stage nobody wanted to talk about on the forecast call.
Nothing about that deal was lost on product, price, or competition. It was lost on a queue.
I see this pattern constantly at Series A and B companies moving upmarket. The first few enterprise deals arrive, and with them arrives an operational load nobody staffed for. The security review is treated as an interruption to the sales process rather than a part of it. And because it lives outside the pipeline, nobody owns it, nobody measures it, and nobody notices it is eating three weeks off every deal that matters.
What the delay actually costs you
The numbers here are worse than most founders assume, because the damage compounds.
Industry turnaround for a full security questionnaire sits somewhere in the 14 to 28 day range for a company doing this ad hoc. Teams with a maintained answer library respond in one to three days. That gap is not a rounding error on your sales cycle. On mid-market deals a security review typically adds two to four weeks; on genuine enterprise deals, two to six.
Typical difference between an ad hoc security response and one drawn from a maintained answer library. On a company closing 40 enterprise deals a year, that is over two quarters of aggregate cycle time sitting in a queue.
Cycle time is the obvious cost. The one people miss is quarter-boundary risk. A deal that needs 21 extra days in week eight of a quarter does not close 21 days later. It closes next quarter, or it closes after the buyer's budget review, or it does not close at all because the champion changed roles in the meantime. Deals do not decay linearly. They decay at cliff edges, and a three-week stall is very good at pushing a deal over one.
Then there is the senior-time cost. In every company under 100 people I have worked with, the person answering security questions is the CTO or the one engineer who knows the infrastructure. That is your most expensive and most constrained resource, pulled into spreadsheet work at the exact moment they should be shipping. I costed this for one client: 11 hours of CTO time per questionnaire, 19 questionnaires that year. Just over five working weeks of the CTO's year, spent transcribing answers he had already written four times before.
Why it always arrives at the worst moment
Here is the structural problem. Security review sits at the end of a buying process but its inputs are needed at the beginning.
By the time the questionnaire lands, your champion has already spent political capital getting you this far. The deal has a close date in your CRM, probably tied to a quarter. The sales rep has no control over the security team's queue, no relationship with anyone in it, and often no visibility into whether the file has even been opened. Every check-in email your rep sends is a small withdrawal from the champion's patience.
Meanwhile procurement engagement has been shifting earlier in B2B buying cycles generally. Buyers now pull security, legal, and finance into evaluations sooner than they did five years ago, which means you are getting questionnaires on deals that would have been informal handshakes in 2021. Your process has not changed. Their process has.
Make it a stage, not an interruption
This is the single change that fixes most of the problem, and it costs nothing but a decision.
Add an explicit stage to your pipeline between "verbal commitment" and "contracting." Call it security review or technical validation. Give it entry criteria (questionnaire received, owner assigned), exit criteria (all answers returned and acknowledged by the buyer), and a target duration. Five business days is a reasonable internal SLA once you have a library. Ten is realistic in your first quarter.
The moment this becomes a stage, three things happen automatically. It shows up in your pipeline stage reporting, so days-in-stage becomes visible on the same dashboard as everything else. It gets an owner, because stages have owners and inboxes do not. And it appears in your forecast conversation, so a deal sitting there for 18 days becomes a question the sales leader has to answer rather than a surprise in week 11.
In HubSpot this is straightforward. A deal stage, a custom object or a set of properties on the deal for questionnaire received date, questionnaire type, question count, and owner, plus a workflow that creates a task and starts a countdown when the stage is entered. If you have already built custom objects for other parts of your process, a security review object gives you per-questionnaire history across deals, which is what you want when the same buyer comes back for an expansion.
The one thing I insist on: the AE is not the owner. Reps chase, reps escalate, reps manage the champion relationship. But if the person accountable for delivery is also the person with a quota, the work gets deprioritised the instant something more winnable appears. Put ownership with whoever runs RevOps, or with a customer-facing technical person, or with the deal desk if you have one. Our note on deal desk structure covers where this sits in slightly larger teams.
Anything that takes three weeks and is not in your CRM is not a process. It is a hope.
Security review is the last unmeasured stretch of most B2B sales cycles. Teams that instrument it usually find the median response time is roughly double what everyone assumed, and that half the delay was waiting for one specific person.
Build the answer library before you need it
The library is the actual work, and it is far less painful than people expect because the questions repeat. Across SIG, CAIQ, VSA, and the hundred bespoke spreadsheets that enterprise buyers write themselves, you are answering the same 150 underlying questions in different wording. Encryption at rest and in transit. Access control and offboarding. Backup and recovery targets. Subprocessor list and notification terms. Incident response timelines. Pen test cadence. Data residency. Employee background checks and security training. Business continuity.
Two details matter more than the format you store it in.
First, every answer needs a review date and an owner. A security answer library that is 14 months stale is worse than no library, because someone will paste an answer about a subprocessor you stopped using and now you have told a regulated buyer something untrue in writing. Set a quarterly review on the 30 answers most likely to drift (subprocessors, retention periods, staff counts, certifications) and an annual review on the rest.
Second, store the evidence next to the answer. Half the delay in a security review is not writing the answer, it is finding the pen test summary from November or the current SOC 2 report or the architecture diagram. Keep a single folder with current versions, named by date, and link each answer to its supporting document.
You can run this in a spreadsheet or Notion until you are past roughly 20 questionnaires a year. I have clients doing perfectly well on a two-tab Google Sheet with a filter. The tooling question comes later and matters less than people want it to.
The trust center question
The other move that works, and works differently, is publishing.
A trust center is a public or gated page carrying your SOC 2 report, subprocessor list, security whitepaper, pen test summary, uptime history, and a pre-filled standard questionnaire like CAIQ. Buyers self-serve. Some percentage of them then skip sending you a questionnaire at all, because their security team's requirement was "get the documentation," not "make the vendor fill in our form."
The vendors in this space claim large reductions. SafeBase has published figures around a 74% drop in inbound questionnaires for trust-center-first customers, which I would treat as a best case from a motivated source. More conservative reads put it at 15 to 25% of deals avoiding a questionnaire entirely. Even at the low end, that is worth doing, because the deals it removes friction from are disproportionately the fast ones where the buyer was ready to move.
What a trust center genuinely fixes is the pre-questionnaire stage. Your rep can send one link in the first technical call instead of promising to "check with the team on security." That changes the buyer's read of you from a startup improvising to a company that has done this before, which matters more in enterprise deals than any single answer in the spreadsheet.
What it does not fix: regulated buyers with mandated internal forms. Banks, insurers, and healthcare will send you their spreadsheet regardless of what you publish. Plan the library for them and the trust center for everyone else.
Tooling, and when it starts paying back
Rough guide from what I actually see working:
Under 10 questionnaires a year. A spreadsheet library and a named owner. Nothing else. Buying software here is a way to feel organised, not to be organised.
10 to 30 a year. A trust center is the highest-return purchase, ahead of questionnaire automation. If you are already running compliance in Vanta or Drata, their trust center and questionnaire assistance features are the cheapest path because your evidence already lives there and stays current automatically.
30 or more a year, or a dedicated response person. Purpose-built questionnaire automation (Conveyor, SecurityPal, and similar) earns its licence, mainly because of portal auto-fill. A meaningful share of enterprise buyers now send you into their third-party risk portal rather than emailing a file, and manually retyping 200 answers into a web form is the single most demoralising task in B2B sales operations.
One honest warning about the AI answer generation in all of these. It is good at drafting and bad at knowing when it is wrong. Every generated answer needs a human check against the library, because a confidently wrong statement about your data handling is a compliance problem, not a typo. Use it to draft, never to submit. The same discipline applies to any AI automation you put into the revenue process: the model proposes, a person with accountability disposes.
Measure four things
You do not need a dashboard project for this. Four numbers, reviewed monthly:
Median days in security review stage. Your headline number. Track the median, not the mean, because one 90-day monster from a bank will hide the improvement everywhere else.
Percentage of questions answered from the library. Start by measuring it manually on the next three questionnaires. Below 60% means the library needs work. Above 85% and you are in good shape.
Questionnaires received per closed-won deal. Rising means you are moving upmarket, which is fine, but it should change your staffing plan.
Deals where security review crossed a quarter boundary. The most useful number and the one nobody tracks. It converts an operations problem into a revenue number your board understands.
If you already report on sales cycle length, add security review as a component so the reduction shows up where leadership is already looking.
Deals sitting in security review with nobody watching the clock?
We will map your last ten security reviews, show you where the days went, and build the stage and library that gets them back. Free 30-minute session.
Book an audit →FAQ
What is a security questionnaire in B2B sales?
It is a document a prospective customer's security or risk team sends you before they will buy, asking how you protect their data. Formats range from published standards like the CAIQ and SIG to bespoke spreadsheets a company wrote internally. Length runs from about 40 questions for a light vendor review to 400 or more for a regulated buyer treating you as a critical supplier. Answering it is a condition of the sale, not an optional extra, and it usually arrives late enough in the process that the delay hits your forecast directly.
How long should it take to complete a security questionnaire?
With no library and no owner, expect 14 to 28 days, most of which is queue time rather than work time. With a maintained answer library and a named owner, one to three days is realistic for a standard questionnaire, and five business days is a sensible internal SLA including the genuinely novel questions that need a real answer from engineering. If your current median is above ten days, the fix is almost always ownership and a library, not more headcount.
Does having SOC 2 mean we stop getting questionnaires?
No, and this surprises founders who spent six months and a lot of money on the audit. SOC 2 shortens questionnaires and removes some sections, because the buyer can accept your report as evidence rather than asking you to describe each control. But most enterprise and regulated buyers have an internal policy requiring their own form regardless of certification. The certification changes the answers from prose to references. It does not remove the form.
Who should own security questionnaires in a company under 100 people?
Not the account executive and not the CTO, though both are involved. The owner should be whoever runs revenue operations, or a technical customer-facing person such as a solutions engineer. That person maintains the library, drafts the response, and escalates only the questions that genuinely need engineering or legal. The CTO's job is a quarterly verification pass and answering the handful of new questions each quarter. Split this way, CTO time drops by roughly 80% without any loss of accuracy.
Should we build a trust center or buy questionnaire automation first?
Trust center first, in almost every case. It is cheaper, faster to stand up, and it reduces the volume of work rather than making the work faster. Questionnaire automation only pays back once volume is high enough that speed is the binding constraint, which for most B2B companies means past 30 questionnaires a year. If you are running Vanta or Drata already, start with the trust center they include before evaluating anything standalone.
Security review is the last part of the B2B sales process that most companies leave entirely unmanaged. It sits outside the CRM, it has no owner, and it burns your scarcest people at the worst possible moment in the deal. None of that is a security problem. It is a process problem with a compliance costume on.
The fix is unglamorous: a stage, an owner, a library, a number you look at every month. Two weeks of setup, and the payback shows up in the first quarter as deals that close when you said they would.
If your enterprise deals keep stalling somewhere between verbal yes and signed contract, that gap is exactly what we fix in CRM and RevOps engagements. Get in touch and we will start by timing your last ten.