forumNew topic

Enterprise client requesting a pre-contract security audit — is there a checklist we can review?

SSerkan G***Expert
Job title
Penetration testing specialist
Organization type
a company within a holding
Joined
Nov 2023
Message
154
#1

We are a 9-person B2B software company based in London. We build a platform that streamlines HR workflows. Up until now, we've only worked with SMBs of 20 to 50 employees, and security never came up beyond standard, baseline questions. But last week, we reached the handshake stage on an £85,000/year licensing deal with a corporate retail chain that has 4,000 employees across the UK.

Before signing their procurement department stated that their infosec team needs to audit us and they sent over a massive 180-question vendor risk assessment questionnaire. We don't have SOC 2 or ISO 27001 certifications yet. Is there a concrete security audit checklist we should prepare so we don't lose the deal and can pass this enterprise review with flying colors? What kind of evidence and documentation do enterprise clients expect from smaller software vendors?

NNevinMember
Job title
Language school
Joined
Apr 2024
Message
92
Most Helpful#2

Short answer: You can win over an enterprise client even without certifications, because what they are really looking for is concrete proof that you take their data seriously, not necessarily a flawless certificate. Every answer you give the auditors must be backed by a written policy document, system screenshots, or a third-party report.

The core security audit checklist you need to assemble breaks down into these key areas: 1) Access Management. Provide procedural documentation showing that multi-factor authentication (MFA) is strictly enforced company-wide and on production systems, that role-based access control is in place, and that access for offboarded employees is revoked immediately. 2) Data Encryption and Backups. Confirm that data is encrypted both in transit (TLS) and at rest; prove that daily encrypted backups are taken and that these backups undergo restoration tests at least quarterly.

3) Vulnerability Management. An executive summary report from a recent third-party penetration test is pure gold in these negotiations. If you don't have one, at least attach your automated vulnerability scan results alongside a patch management policy detailing your remediation SLAs. 4) Incident Response and Business Continuity Plan. Share a concise 2–3 page document outlining how quickly you notify the client in the event of a breach and how your engineering team manages a crisis. Never just answer 'Yes' to any question; always cross-reference the relevant section of your policy.

SSelin K***Member
Job title
Human Resources Specialist
Sector
E-commerce
Organization type
workshop
Joined
Sep 2024
Message
42
#3

The thing enterprise auditors despise most is bluffing. If you claim to have a security control you don't actually have and hit a wall when they ask for proof, the deal is dead on the spot. Saying "This process is currently handled manually, with automation scheduled within the next 6 months" will earn you far more credibility than lying.

PPolat G***Member
Job title
Graphic Designer
Sector
Law
Organization type
workshop
Joined
Nov 2023
Message
29

Doki · SEO consulting · 2023

#4

Leverage your cloud provider's shared responsibility model to your advantage. For questions covering physical server security, data center certifications, and hardware redundancy, you can simply reference your cloud provider's compliance documentation. That easily takes care of at least thirty percent of the questionnaire.

TTaner N***MemberCommunity member
Joined
Dec 2025
Message
13
#5

Enforce password managers and MFA from your central admin panel across all corporate accounts used by your team right this weekend. Screenshots from the panel showing you've completed this step are the strongest evidence for the authentication section of the questionnaire.

ÖÖmerMember
Job title
Financial Analyst
Joined
Dec 2023
Message
126
#6

We got stuck on a similar questionnaire last year and the contract was delayed by 3 months. We paid 3,500 pounds for an urgent penetration test and got a clean, one-page executive summary. Once we attached that report, the security team approved half of the technical questions right away.

OOnur K***Expert
Job title
R&D Manager
Joined
Aug 2023
Message
142
#7

Please keep in mind that the enterprise client will require a Data Processing Agreement (DPA) from you as the data processor. It is recommended that you review the clauses regarding data residency, your sub-processors, and audit rights together with your legal counsel.

İİlknur G***VeteranCommunity member
Joined
Nov 2024
Message
80
#8

Not all 180 questions may apply to you. Big companies send the exact same generic template to every vendor. For questions outside the scope of your application (like physical office security or keycard access systems), just write 'Not Applicable (N/A)' and briefly explain why—don't needlessly box yourself in.

AAleyna E***Member
Job title
Intern
Sector
IT services
Organization type
workshop
Joined
Jan 2025
Message
140
#9

don't be intimidated these questionnaires have become a standard part of the sales routine but if you ask for a 30-minute call with the client's security lead and candidly convey that you're a small agile team that has all the essential safeguards in place to protect their data, the process will wrap up much faster.

Correction: I misremembered the figure, it was a bit lower.

CCansuMember
Job title
Digital marketing specialist
Joined
Jan 2024
Message
128
#10

The cheap-looking path usually ends up costing more later. If it's your first time, start small; scaling comes later.

Forgotten test environments are more often the entry point than live systems. Hope this helps.

NNeslihan B***Expert
Job title
Project manager
Sector
Cosmetics
Organization type
regional distributor
Joined
Jun 2025
Message
129
#11

It's rare to find an explanation this clear. btw when making a decision, first look at what data you have on hand.

This is my opinion Im not claiming its absolute truth.

DDilekNew member
Job title
Pastry Shop
Organization type
a company within a holding
Joined
Nov 2024
Message
19
#12

my perspective changed after experiencing that. if you scold false alarms, nobody will report again.

if you scold false alarms, noobdy will report again then proven by experience.

ZZehra D***Expert
Job title
IT manager
Sector
Food wholesale
Organization type
120-person company
Joined
Feb 2025
Message
44

Doki · Server maintenance contract · 2024

#13

I have a question, don't want to go off-topic though. If 2FA is on, a stolen password alone is useless.

Good luck with that.

ZZerrin D***New memberCommunity member
Joined
May 2026
Message
140
#14

We need to make a distinction here. Payment information changes are never verified through the channel they came from.

Start with a small trial; don't commit to everything at once. Proven by experience.

ÖÖmer Ö***Member
Job title
Social media manager
Sector
Textile
Organization type
workshop
Joined
Feb 2022
Message
76
#15

There's a common mistake people make when doing this. Solutions that work at a small scale collapse when you grow; I learned this late.

When you try to change everything at once, nothing settles. This is my opinion, I'm not claiming it's absolute truth.

GGizem A***MemberCommunity member
Joined
Oct 2025
Message
341
#16

I feel the same way. When making a decision, first look at what data you have on hand.

EElif K***Member
Job title
Customer Relations Manager
Sector
Logistics
Organization type
20-person company
Joined
Feb 2023
Message
74
#17

Let me summarize what's been said so far. The biggest time-waster for us was not knowing who had the final say.

Your time to detect an issue directly determines its cost. Good luck with that.

EEsra K***MemberCommunity member
Joined
Jul 2025
Message
1
#18

There's a part I don't understand. Payment information changes are never verified through the channel they came from.

If I were you, I'd go this route.

YYiğit E***Member
Job title
Customer service representative
Sector
Construction
Organization type
300-person organization
Joined
Mar 2023
Message
3

Doki · Brand identity · 2026

#19

I agree. Having backups accessible on the same network and with the same identity makes them part of the target.

If you have questions, write them; I'll answer as best I can.

ZZeynep T***MemberCommunity member
Joined
Sep 2024
Message
17
#20

I felt relieved reading this answer, so it's not just me. I mean if permission and scope aren't in writing don't start that test.

Correct me if I'm wrong.

Reply