Consider a Sydney SaaS company close to signing its first major US customer. Commercial terms are agreed. Then the buyer sent a security questionnaire and asked for evidence that nobody could find quickly. The deal slowed down, although nothing about the product had changed.
The immediate problem looked administrative. Someone needed to finish a form. But why does a form carry enough weight to hold up a sale? The answer starts on the buyer’s side of the table.
Choosing a supplier creates a dependency. The buyer may be entrusting it with customer information, access to systems or a service on which its own operations will depend. A demonstration proves the software does something useful. It says much less about what happens when access is misused, a system fails, or the people responsible for it leave. The questionnaire is one attempt to make that uncertainty manageable. Behind each request for evidence sits a decision that somebody else will have to defend in the end.
Security questionnaires have moved beyond banks and payments
The same question was raised at the Vanta Trust Tour where I represented DNX.
Where I agree with the room is that this pressure is now permanent and no longer confined to banks and payments. When a payments CIO, a currency CISO and a law firm CSO can share a stage (at this event) and address the same question from customers, boards and regulators, the problem is a property of the market, not of any one industry.
A green dashboard can’t explain why a control exists
Where I part company with the mood of the day is on how much the tooling can answer. Platforms like Vanta have become extremely capable, and tooling that collects evidence and keeps a trust page up to date removes real friction from the process. But the tooling is now ahead of most programmes’ ability to explain themselves, and that is the gap worth closing. A dashboard full of green does not answer a buyer’s question about why a control exists. A person who knows the answer does, and the platform makes that person faster.
The gap is hardest to close for the businesses now being asked the hardest questions, which are often the smallest, and the cost of the platforms that answer them has risen sharply over the past two years. The demand for proof is outpacing smaller companies’ budgets. A company of 20 people selling into the US now needs an answer to what used to be an enterprise problem, and it cannot buy its way out of it.
One named owner per control, and a person checking scope
What I would do instead, and what we do at DNX, is treat the platform as the place where evidence is displayed, not where responsibility lives. Three things matter more than the feature list. Every control has one named owner, not a committee. That owner can explain in plain language what the control protects and what would prompt us to reconsider it. And a person reviews scope, because tooling carries forward whatever it was last told. In our own SOC 2 renewal this month, the platform kept controls in the audit that do not apply to a professional services business, and it took someone reading last year’s report to notice. No test fails when the scope is wrong. That is exactly why scope needs an owner.
What gets a stalled deal unstuck
So back to the Sydney company example at the beginning. The deal does not get unstuck by a better questionnaire tool, although one would help. It gets unstuck when someone can send the buyer three things: this is what we protect, this is how we do it, and this is who answers for it, with evidence that was checked last month, not last year. That is what the buyer’s confidence is made of. The questionnaire was never the delay. The delay was that nobody could answer it.
Know who answers for every control
If a second set of eyes on control ownership and scope would be useful, we’re glad to walk through it with you.