An AI-built product can answer an enterprise security questionnaire in 30 days if it treats the questionnaire as a list of evidence requests: fix the handful of real gaps, attach proof to every yes, and answer every no with a dated plan. A SOC 2 report does not fit in 30 days, since even Type 1 takes 3 to 6 months, so the honest answer is a roadmap, not a promise. Pilots are won on credible answers, not on a perfect score.
- You will not have SOC 2 in 30 days. Type 2 includes an observation period of at least 3 months; say so and date the plan
- Most questions are evidence requests. Answer with a document, a screenshot, or a test, not an adjective
- AI-built products fail the same six questions: isolation, restore, incident plan, production access, admin logging, subprocessors
- Week by week: triage, fix, write the evidence pack, answer and walk the reviewer through it
- Say how AI was used and what controls sit around it; vagueness is the real red flag
Why this deadline feels impossible
The questionnaire arrives the week the pilot gets real. The buyer’s team does this at volume: Vanta’s State of Trust 2025, a survey of 3,500 IT and business leaders released October 29, 2025, found organizations spend 9 working weeks a year on vendor security reviews and risk assessments, up from 7 the year before (Vanta via Yahoo Finance).
Your reviewer has seen hundreds. They are not reading for perfection. They are reading for whether you know your own system.
The formats vary. It may be the buyer’s own spreadsheet, the Shared Assessments SIG, whose 2026 edition adds ISO 42001 references for AI governance, or the CSA’s CAIQ v4 with 261 questions. If your product sends customer data to a model, expect AI questions too: the CSA’s AI-CAIQ v1.1 has 320, mapped to 247 control objectives.
The 30-day path
arrives"] --> T["Week 1: triage
yes / fixable / plan"] T --> F["Week 2: fix the
fixable gaps"] F --> E["Week 3: write the
evidence pack"] E --> A["Week 4: answer,
then a 30-minute call"] T -. "needs months,
e.g. SOC 2 Type 2" .-> R["Dated roadmap
in the answer"] R --> A A --> P["Pilot signed with
conditions and dates"]
Sort every question into three piles on day one: already true (needs evidence), fixable this month, and needs a dated plan. The third pile is usually short, and SOC 2 is almost always in it.
The four weeks
Week 1: triage
Week 2: fix
Week 3: evidence pack
Week 4: answer and walk through
The six questions AI-built products usually answer “no”
These are the gaps we see most often when a working AI-built product meets its first enterprise reviewer. Every one of them is small.
| What the questionnaire asks | Evidence that answers it |
|---|---|
| How is customer data isolated between tenants? | A test with two tenants that fails if A can read B, run in CI |
| Are backups tested? | A restore log: date, source, duration, who ran it |
| Do you have an incident response plan? | Two pages: who is called, how customers are told, within what time |
| Who has write access to production? | A list of people and machines, with MFA, and no AI agent on it |
| Are administrative actions logged? | Where the logs live, how long they are kept, one sample entry |
| List your subprocessors | Hosting, database, email, and every AI model provider that sees customer data |
The production-access row matters more for AI-built products than for others. In July 2025 an AI agent deleted SaaStr’s production database during a code freeze; the dated incident list shows that pattern and two others reviewers now ask about by name.
How to answer the questions you cannot say yes to
Every questionnaire has questions you will answer “no” in week four. A dated plan beats a hopeful yes, every time. Reviewers verify the yeses during the pilot; a yes that turns out to be false ends the relationship.
For SOC 2 specifically, be exact about the calendar. Drata’s March 13, 2026 figures: Type 1 takes 3 to 6 months and costs $7,500 to $60,000; Type 2 takes 6 to 15 months, including a 3 to 12 month observation period (Drata). The same page notes mid-market buyers may accept a commitment to reach Type 2 within a set timeframe, which is exactly what a dated roadmap is.
Say how the product was built
Questionnaires increasingly ask about AI directly: in the product, and in how it was made. Answer plainly. Name the tools, then the controls around them: every change reviewed by a named person, dependency and secret scans in CI, no AI tool holding production credentials, a senior review on a date.
This is the same evidence an investor’s reviewer asks for in technical due diligence, and the same architecture map answers both. Build the evidence pack once; the next questionnaire takes days, not weeks.
When this is worth outside help
The enterprise pilot is one of five trigger moments, with due diligence, first engineering hires, an incident, and scale. The questionnaire asks the same things the other four do, just with a deadline. If the fixable pile is large, the work is a fixed-scope fix pass of two to three weeks; what that costs in 2026 is published.
If you want a senior architect to sort your pile against your actual code first, that is what the free teardown is: three findings and a verdict, recorded, within 72 hours.
Sources
- Vanta, State of Trust 2025, via Yahoo Finance / Business Wire, October 29, 2025: 3,500 respondents, 9 working weeks a year on vendor security reviews (7 the year before)
- Drata, SOC 2 Type 1 vs. Type 2, March 13, 2026: timelines, observation periods, cost ranges, buyer expectations
- Shared Assessments, 2026 SIG workbook updates, July 18, 2025: ISO 42001 reference, Lite, Core and Detail scoping modes
- Cloud Security Alliance, What is CAIQ, September 1, 2021: CAIQ v4, 261 questions, STAR Level 1
- Cloud Security Alliance, AI Controls Matrix v1.1, July 14, 2026: 247 control objectives, 18 domains, AI-CAIQ with 320 questions
- Fortune, Replit wiped SaaStr’s database, July 23, 2025