Answer security questionnaires from your own scan evidence
A prospective customer's security questionnaire lands, and half the questions ask about things you have never measured. SecQon's Security Questionnaire Pack re-presents a real scan of your internet-facing assets as 42 answers in the style of the SIG Lite and CAIQ questionnaires. Answers come from what the scan observed, and the questions no external test can answer are marked as such, with a note on who in your company can.
The problem
A deal is waiting on a spreadsheet of security questions, and you do not know how to answer the ones about vulnerability management or TLS without guessing.
You want to answer honestly, but a blank or a "we believe so" reads badly to a buyer's security team.
The same questions come back from every enterprise customer, and you are rewriting the answers from memory each time.
How SecQon helps
42 questions in nine sections
The pack re-presents one assessment as 42 questions in nine sections, in the shape used by SIG Lite, CAIQ and the spreadsheets most buyers send. It is derived on demand from the scan itself, so it cannot drift from the evidence.
Three answer states, and no "probably"
Every question is answered, not externally assessable, or not assessed — with what would assess it. A control only reads as satisfied where the relevant check actually ran or filed a finding, and a check that could not complete blocks a "yes". There is no state for "probably fine".
Your testing practice, stated accurately
Vulnerability-management answers are generated from what happened: your scan cadence from scans that completed, your testing practice from the exploitation stages that actually ran — stated as automated, not human-led — and finding counts by how far each was verified.
The unanswerable questions, marked
Fourteen common questions cannot be answered by any external test: encryption at rest, background checks, training, access reviews, backups, incident response, logging, secure development, subprocessors, retention, certification, DKIM, MFA policy and remediation policy. The pack marks each one and names who in the company can answer it.
A report to attach
The pack sits alongside the written report, which has dated share links you can send with your answers. The pack itself is delivered as authenticated HTML or PDF; it has no public share link.
What SecQon does not do here
- The pack answers questions about your internet-facing assets only. For the 14 questions it marks as not externally assessable, you still write the answer.
- It is not a certification and does not replace a SOC 2 report or ISO 27001 certificate if a buyer requires one.
- An optional language model may rephrase answered rows for readability. Rewrites that add numbers, links or stronger claims are discarded, and the pack says when wording was rewritten.
- A questionnaire that asks about business-logic testing or human-led penetration testing needs a truthful "no" from us: we do not do either.
The plan we suggest
Starter $49 per month
Answering a customer security questionnaire.
1 verified asset, add more for $25 each (up to 4)
The checks that matter for this
- TLS & certificates
Certificate trust and expiry, and whether your server still accepts TLS 1.0 or 1.1.
- Security headers & cookies
Missing or ineffective HSTS, CSP, clickjacking, nosniff and Referrer-Policy headers, plus cookie flags.
- DNS & email security
SPF, DMARC, CAA and DNSSEC — the records that stop spoofed email and mis-issued certificates.
- Exposed ports & services
36 high-risk TCP ports — databases, container control planes, remote admin — checked with one connect each.
Questions people ask
Which plan includes the questionnaire pack?
Starter and above. Free shows findings but has no written report or questionnaire pack.
Can I paste the answers straight into a customer's spreadsheet?
That is what it is for. The pack follows the question families used by SIG Lite and CAIQ, and every answer is derived from your scan, so you can copy it across and attach the dated report.
What happens if a check could not run on my site?
The question it would have answered is marked not assessed, with what would assess it. A check that could not complete never produces a "yes".
Does it answer questions about encryption at rest or MFA?
No. Nothing outside your systems can see those. The pack marks them as not externally assessable and names who in your company can answer.
Is AI writing my answers?
The answers come from the scan evidence. A language model may optionally rephrase answered rows; any rewrite that adds a number, a link or a stronger claim is discarded, and rewritten wording is labelled.
Last reviewed on 24 Sep 2026.
See what a scan finds on your own asset
Free for one verified asset, no card needed. Paid plans add the written report, more assets and deeper scans.