A customer’s security requirements are holding up the sale.
An enterprise customer sent a security questionnaire, a supplier assessment or a set of contractual security requirements. The product is good. Nobody on the team can answer in the form the buyer needs, and the deal is waiting.
- Indicative range
- Typically €4,000–9,000, fixed scope
- Shape
- Usually one to three weeks, remote.
What you are already seeing
- A questionnaire of 150 to 300 items is sitting with an engineer who has no time for it.
- Answers exist in people’s heads but not in any document a buyer would accept.
- The same questions arrive from every large customer, and each one is answered from scratch.
- Procurement has set a date, and the security section is the only thing still open.
What gets examined
- 01
What the buyer is actually asking for, separated from how their template words it.
- 02
Which answers are already true and only need evidence written down.
- 03
Which answers require a real change before they can be given honestly.
- 04
What can be committed to on a roadmap rather than claimed today.
What you are left holding
- 01
A completed response in the buyer’s own format.
- 02
A reusable answer set, so the next buyer costs a fraction of this one.
- 03
A short list of the gaps that need engineering work, with owners.
- 04
A written record of what was claimed, so the next audit does not contradict it.
Before you send anything
Plain language is enough — the system, who owns the outcome, and the date that matters. Keep confidential reports, credentials and production data out of a first message; a secure exchange route is agreed before any of it moves. Indicative ranges are exactly that: the scope, exclusions and price are confirmed in a written proposal before work starts.