Part of technical pre-sales at Terravek is answering security questionnaires. I have done several hundred and they vary enormously in quality.
The bad ones ask whether we have a firewall. They are long, they are generic, they were bought as a template, and the answers are not read by anyone technical. Everyone involved knows this and completes the ritual anyway.
The good ones ask about our specific architecture: where the data resides, who inside Terravek can access it and under what control, what happens at end of contract, how we would notify them of a breach and within what time. They are shorter and they take longer to answer.
The single question that most distinguishes a serious buyer: 'describe an incident you have had and how you handled it'. It cannot be answered from a template, and the answer tells you a great deal about the organisation.
We answer it with the March 2021 delivery pipeline incident and the published post-incident review. Being able to point at a public document we wrote when it was inconvenient has closed more security reviews than the ISO certificate has.