Choosing
Security questionnaires, and what actually reduces them
The promise of certification is fewer questionnaires. It is largely true, and it depends on something people do not check until later.
Facts checked — 2026-09-11
Why do security questionnaires keep arriving after certification?
A certificate or SOC 2 report displaces a questionnaire when it covers the service the customer is buying, is current, and is accompanied by the supporting artefacts they ask for next — usually a recent penetration test summary and a policy set.
It does not displace it when the scope is narrower than the relationship, when the report has aged out, or when the customer’s own regulator obliges them to ask regardless. That last case is not solvable by certification and is worth recognising early rather than arguing.
The bottom line
Scope the certificate to the service customers buy. That single decision determines whether it ends the questionnaires or not.
Related services
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
SOC 2 Type 2 Readiness
Evidence that your controls ran for months, not that they existed on a date — the report enterprise procurement usually means.
Related insights
Choosing
SOC 2 Type 1 or Type 2: which one to get, and what each can evidence
A blocked contract argues for a Type 1. Very little else does — and the minimum period you have been told about is not a rule.
Choosing
SOC 2 or ISO 27001 first? A commercial question wearing a technical costume
Your pipeline decides this, not the frameworks — and the two produce very different things to hand a customer.
Choosing
Accredited and unaccredited certification are not the same product
Both produce a certificate. Only one carries independent oversight of the auditor — and it is checkable.