A client sends a security questionnaire: how FDEs use SOC 2 and ISO 27001 to get through review
Sometimes the thing blocking a project is not the hardest code but a spreadsheet with hundreds of rows. One compliance consultancy estimates that sending a SOC 2 report first can cut the 260-question CAIQ to roughly 78 to 104 questions you have to answer yourself.

In brief
- SOC 2 is a report containing a CPA's opinion on whether an organisation does what it says it does; ISO 27001 is a certificate that states the scope of the ISMS. They prove different things.
- Send the report before you start filling in the spreadsheet: one compliance consultancy estimates a SOC 2 Type II directly answers about 60-70% of CAIQ questions.
- Organise the answer library by topic, with an owner and a review date. An out-of-date library is riskier than no library at all.
In your first week on site, before you have run a single line of code, an email arrives: a spreadsheet with hundreds of security questions, and a note saying you will get access once it is filled in. If the client is a financial institution, it may be SIG Core, a questionnaire of more than 800 questions.
Appsierra, a company that supplies FDE staff, observes that access provisioning, security review and waiting for client approval often take longer than finding the engineer in the first place, though that is the view of a firm selling the service.
The good news is that this is a learnable skill. An FDE’s job is not to rewrite the company’s security policy. Your job is to put the right evidence, with the right scope, in front of the client at the right time, so their security team has enough grounds to say yes.
SOC 2 and ISO 27001 prove different things
To use evidence well, you first need to know what each kind proves. According to the audit firm Schellman, the output of SOC 2 is a report in which a CPA gives an opinion on whether the organisation actually does what it claims to do.
The AICPA says SOC reports give users information to assess and address the risks of outsourcing a service. Its SOC 2 materials are built around five categories: Security, Availability, Processing Integrity, Confidentiality and Privacy.
SOC 2 reports come in two types. According to Schellman, Type 1 assesses a single point in time, while Type 2 covers a period, usually 12 months. Type 2 therefore says more: the controls are examined across that whole period, not on one day.
ISO 27001 is different. Schellman says its output is a certificate stating the scope of the ISMS, including the departments and locations covered, on a three-year certification cycle with annual reviews.
Every client has its own requirements, so ask early which kind of evidence their security team needs.
| SOC 2 | ISO 27001 | |
|---|---|---|
| What you send the client | A report with a CPA’s opinion | A certificate |
| The question it answers | Does the organisation do what it committed to? | Is the information security management system certified? |
| What to check before sending | Type 1 or Type 2, and whether it is still current | Whether the ISMS scope covers the system you are about to deploy |
Send the report first, fill in the spreadsheet later
Do not open the file and start at row 1. Agency, a security compliance consultancy, advises leading with the SOC 2 report, because buyers sometimes accept it in place of the whole questionnaire. The source has a commercial interest, so treat this as a possibility, not a promise.
The same source says the Cloud Security Alliance’s CAIQ has about 260 questions across 17 domains. It also estimates that a current SOC 2 Type II report directly answers about 60-70% of CAIQ questions.
Run the numbers on that estimate: 60% of 260 is 156 questions, and 70% is 182. That leaves roughly 78 to 104 questions for you to write yourself, instead of 260.
Your own figures may differ. The way of thinking holds, though: a long questionnaire is really a part that already has evidence and a part that is still blank. The first job is to separate the two.
A worked example, end to end
Suppose you are an FDE deploying an agent that reads credit files for a bank. The client sends the CAIQ.
Before answering anything, you send your own security team three questions: is the latest SOC 2 report Type 1 or Type 2, what does the ISMS scope on the ISO 27001 certificate say, and does the company already have a completed CAIQ?
The second question is the one an FDE should watch most closely. If your agent runs in the bank’s cloud environment, or relies on a department or location not listed on the certificate, then the certificate’s scope does not cover the work you are about to do. Sending it without saying so can later be seen as misrepresentation.
Next, you mark every row in the spreadsheet with one of three labels: “answered by report” (citing the section of the report), “already in the library”, and “needs a new answer”. For the last group, each answer follows a fixed template:
Question: [the client's question, verbatim]
Answer: Yes / No / Partial
Explanation: [1-2 sentences, no marketing]
Evidence: [SOC 2 report section, policy name, configuration screenshot]
Scope: [which system/environment this applies to]
Owner: [who confirms this answer]
Last updated: [date]
The “Scope” and “Owner” fields are where an FDE makes the difference. You understand the actual deployment architecture; the security team understands the policy. A “Partial” with a clearly stated scope is far more credible than a vague “Yes”.
Here is what a completed answer might look like for the bank project above, assuming the credit files sit in the bank’s cloud:
Question: Is customer data encrypted at rest?
Answer: Partial
Explanation: Data in the company's environment is encrypted at rest. Credit files sit in the bank's cloud and follow the bank's encryption configuration.
Evidence: Encryption section of the latest SOC 2 Type 2 report; screenshot of the project's storage configuration
Scope: The company's environment; excludes the bank's cloud
Owner: Confirmed by the security lead, drafted by the project FDE
Last updated: [date of most recent review]
Reading this, the client’s security team knows at once which part your company is responsible for, which part is theirs, and which page of the report to open to check. They do not need to send another email asking.
A library by topic, and the cost of an old one
After a few questionnaires you will notice the same point asked in different ways: the CAIQ phrases it one way, the SIG another, and the bank’s own template a third.
So organise the answer library by topic, such as access management, encryption, logging or incident response, rather than by framework. An answer on access management then works for all three kinds of questionnaire.
But a library has a downside. The same source warns that an out-of-date library is riskier than having no library at all.
Imagine pasting in an answer written before the company changed infrastructure provider, and the client relies on it and signs the contract. From that moment the wrong answer becomes a commitment sitting in the client’s records, and when the truth comes out, your company may be seen as breaching what it promised them.
Every entry in the library therefore needs an owner and a review date.
Get ahead before the client asks
Drata notes that questionnaires are a burden on security teams that are already short-staffed. Some companies therefore send important prospects completed standard questionnaires up front to answer the common questions.
According to Drata, sharing these documents proactively both saves time and builds trust by demonstrating transparency.
If your company has nothing yet, CSA STAR Level 1 is a cheap place to start: it is a self-assessment using CAIQ v4, free and published on the Cloud Security Alliance registry.
Package the report, the certificate, the completed CAIQ and the project’s data-flow diagram into one pack, and send it at the kickoff meeting.
Mistakes that get a submission sent back
The first mistake is sending a Type 1 when the client needs to see controls maintained over time. The second is sending an ISO 27001 certificate without checking its scope against the real system. The third is answering “Yes” with no evidence, forcing the client to ask again and costing another round of emails.
Another mistake to avoid is the FDE answering alone to save time. You understand the system, but a security commitment is a commitment by the whole company. Where you are unsure, write “Partial” with the scope, then pass it to someone with authority to confirm.
If you want to move into an FDE role, this skill belongs on your CV, because security review can take longer than finding the right person. When reading job descriptions, look for phrases such as “security review”, “vendor assessment” or “SOC 2”.
On your CV, describe concrete results, such as how you triaged a questionnaire and how much you shortened the review, rather than just writing “familiar with security”.
The next time a long spreadsheet lands in your inbox, do not start on the first row. Work out what evidence already exists and how far its scope reaches, then deal with what is left blank.
Was this article useful?
Thanks for the feedback!
6 sources
- SOC 2 vs. ISO 27001: What are the Differences? (Schellman) · 2022-01-19
- Security Questionnaires Explained: CAIQ, SIG, and VSA Compared (Agency) · 2024-03-15
- A Brief Overview of Standardized Security Questionnaires (Drata) · 2026-02-13
- STAR | Cloud Security Alliance (CSA)
- System and Organization Controls: SOC Suite of Services (AICPA & CIMA)
- Hire Forward Deployed Engineers | Appsierra