Skip to content

Security

Security questionnaires answered for you: CAIQ, SIG and RFP security sections

A key account sends its security questionnaire, or a tender asks for a security assurance plan. We write every answer from your policies and evidence, flag what only your CTO can decide, and you send back a complete file without stalling your engineering team.

From €390 excl. VAT · within 5 business days

What you receive

01

Every answer written and sourced

Each control points to a policy, procedure, configuration or report you already have.

02

The questions for your CTO

Anything that commits your architecture or your contract, listed separately with a suggested answer to approve.

03

A list of what's missing

The controls you don't have yet, so you never claim something you don't do.

04

One round of corrections

Included after your review.

What you send us

  • The questionnaire: an Excel file, a PDF or an export from your customer's portal.
  • Your security policies, your information security policy if you have one, and your audit reports or certifications.
  • A short description of your architecture and your subcontractors (hosting, tools).
  • The deadline.

How it works

  1. 1

    You show us the questionnaire

    We confirm the price, based on the number of questions, and the delivery date within 24 business hours.

  2. 2

    We match questions and evidence

    Each question is matched to the document that answers it: policy, procedure, configuration or report.

  3. 3

    We write

    AI drafts, and a person checks every answer against your documents and the framework the question cites.

  4. 4

    Your CTO approves, you send

    The file arrives within 5 business days of receiving your documents. If we're late, you get 20% off.

What we don't do

  • We never claim a control you don't apply: a security answer commits your company.
  • We are not an auditor or a certification body: we don't issue ISO 27001 certificates or SOC 2 reports.
  • We never log into your customer's portal: we work from an export, and you send the answers.

The CAIQ is published by the Cloud Security Alliance and the SIG by Shared Assessments. In French public IT contracts, the CCAG-TIC 2021 lets the buyer attach a security assurance plan (PAS) to the technical offer, and it becomes contractual once the contract is awarded. Sources: Cloud Security Alliance, Shared Assessments, CCAG-TIC 2021, art. 4.

Sources:cloudsecurityalliance.orgsharedassessments.orgmarche-public.fr

Prices

JobPriceDelivery
Questionnaire, up to 50 questions€390 excl. VAT2 business days
Questionnaire, 51 to 150 questions€690 excl. VAT3 business days
Questionnaire, 151 to 300 questions, or an RFP security sectionor a security assurance plan (PAS)€990 excl. VAT5 business days

Questions

What is a security assurance plan (PAS)?

It's the document in which you describe the technical, human and organisational security measures you will apply during the contract. French buyers often require it in IT tenders, and once signed, it commits you.

Which questionnaires do you handle?

Standard formats (the Cloud Security Alliance CAIQ, SIG and SIG Lite, HECVAT) as well as your customers' own sheets, in Excel, PDF or exported from a portal.

How much does it cost?

From €390 excl. VAT up to 50 questions, to €990 for 151 to 300 questions or a security assurance plan. The price is set before we start.

We have neither ISO 27001 nor SOC 2. Can you still answer?

Yes. We answer with what you actually apply and list the gaps, so you know what to put in place before the next questionnaire.

Who approves the answers?

Your CTO or security lead. A security answer commits your company contractually: we prepare, you approve and you send.

What happens to my documents?

They're used for your file and nothing else. We never use them to train AI models.

A security questionnaire is holding up a deal? Show it to us: price and delivery date confirmed within 24 business hours.