Selling to bigger companies
What security questions will enterprise clients ask my startup?
A large customer has sent you a forty-question security document and your deal is sitting behind it. Search for help and every page tells you to get SOC 2, which is American, expensive and slow. For a UK supplier it is usually the wrong first answer.
Start by asking what they actually require
Security questionnaires are often sent by procurement rather than written for your situation. The same document goes to a cloud platform with two thousand staff and to you. So before committing to anything, ask the buyer one question: is a specific certification required, or do you need satisfactory answers?
In a surprising number of cases the honest answer is the second, and a small supplier who answers clearly and admits what it does not do gets through faster than one that stalls for six months pursuing a standard nobody asked for.
Cyber Essentials, and what it costs
It is the UK government-backed scheme, it is cheap, it is recognised by British buyers, and it is mandatory for some central government contracts. For a small studio or a startup it is almost always the right first credential.
| Organisation size | Certification fee |
|---|---|
| Micro, 0–9 staff | £320 + VAT |
| Small, 10–49 | £440 + VAT |
| Medium, 50–249 | £500 + VAT |
| Large, 250+ | £600 + VAT |
Valid for twelve months, then renewed. The basic certification is a self-assessment questionnaire about your controls. Cyber Essentials Plus adds an independent technical audit of a representative set of devices, every internet gateway and every internet-facing server, and is priced case by case — you must hold the basic one first.
Be straight with yourself about what it proves: that five basic technical controls are in place. It is a floor, not a guarantee, and a buyer who needs real assurance will know the difference. It is still the best value credential available to a UK company of your size.
The five questions that actually block deals
Beneath the forty questions there are usually five that the buyer's security team genuinely cares about. Have an answer written down for each, before you are asked.
- Where does the data live? Name the regions, not the vendors. “Our database is in AWS eu-west-2, London” is an answer. “We use AWS” is not. If anything sits outside the UK or EU, say so and say what covers the transfer.
- Who are your sub-processors? Every third party that touches customer data: analytics, error reporting, email, payments, push notifications. A supplier who cannot produce this list does not know what is in their own product, and the buyer will conclude exactly that.
- What are your backups, and when did you last restore one? The second half is the real question. An untested backup is a belief, not a control, and a restore you have actually performed is one of the most convincing things you can put in a questionnaire.
- Who can get at production? How many people, how access is granted and removed, whether multi-factor is enforced, and what happens on the day someone leaves.
- What happens when something goes wrong? Who finds out, how fast you commit to telling the customer, and who makes the call. One page is enough. Having none is the answer that worries people.
The answer that works better than a certificate
Say what you do, say plainly what you do not, and say what you would do if it mattered to them. “We do not currently hold ISO 27001. We hold Cyber Essentials, our data is in London, here are our five sub-processors, and we test a restore quarterly” closes more deals than six months of vague reassurance. Security teams are used to being managed. They are not used to being told the truth, and they notice.
Sources. Fees, validity and the Plus audit scope: IASME, Cyber Essentials, retrieved 7 October 2026. IASME is the National Cyber Security Centre’s delivery partner for the scheme. The five questions, and the advice on how to answer them, are my own from going through these reviews rather than a published framework. Nothing here is a substitute for your own legal or compliance advice where a contract turns on it.
Stuck on a security questionnaire?
Send me the questionnaire. You get back which answers you can give today, which need work, and what that work actually is — usually the same day.
Start here →