Midnyte

Selling to bigger companies

What security questions will enterprise clients ask my startup?

A large customer has sent you a forty-question security document and your deal is sitting behind it. Search for help and every page tells you to get SOC 2, which is American, expensive and slow. For a UK supplier it is usually the wrong first answer.

Start by asking what they actually require

Security questionnaires are often sent by procurement rather than written for your situation. The same document goes to a cloud platform with two thousand staff and to you. So before committing to anything, ask the buyer one question: is a specific certification required, or do you need satisfactory answers?

In a surprising number of cases the honest answer is the second, and a small supplier who answers clearly and admits what it does not do gets through faster than one that stalls for six months pursuing a standard nobody asked for.

Cyber Essentials, and what it costs

It is the UK government-backed scheme, it is cheap, it is recognised by British buyers, and it is mandatory for some central government contracts. For a small studio or a startup it is almost always the right first credential.

Organisation sizeCertification fee
Micro, 0–9 staff£320 + VAT
Small, 10–49£440 + VAT
Medium, 50–249£500 + VAT
Large, 250+£600 + VAT

Valid for twelve months, then renewed. The basic certification is a self-assessment questionnaire about your controls. Cyber Essentials Plus adds an independent technical audit of a representative set of devices, every internet gateway and every internet-facing server, and is priced case by case — you must hold the basic one first.

Be straight with yourself about what it proves: that five basic technical controls are in place. It is a floor, not a guarantee, and a buyer who needs real assurance will know the difference. It is still the best value credential available to a UK company of your size.

The five questions that actually block deals

Beneath the forty questions there are usually five that the buyer's security team genuinely cares about. Have an answer written down for each, before you are asked.

The answer that works better than a certificate

Say what you do, say plainly what you do not, and say what you would do if it mattered to them. “We do not currently hold ISO 27001. We hold Cyber Essentials, our data is in London, here are our five sub-processors, and we test a restore quarterly” closes more deals than six months of vague reassurance. Security teams are used to being managed. They are not used to being told the truth, and they notice.

Sources. Fees, validity and the Plus audit scope: IASME, Cyber Essentials, retrieved 7 October 2026. IASME is the National Cyber Security Centre’s delivery partner for the scheme. The five questions, and the advice on how to answer them, are my own from going through these reviews rather than a published framework. Nothing here is a substitute for your own legal or compliance advice where a contract turns on it.

Stuck on a security questionnaire?

Send me the questionnaire. You get back which answers you can give today, which need work, and what that work actually is — usually the same day.

Start here →