CloudCompliance

Answering cloud security questionnaires

The cloud section of a security questionnaire asks the same ten questions every time. Write the answers once, keep them true, and attach your evidence.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

Answer cloud questions precisely and briefly: name the provider and region, state what the provider's certifications cover, then describe the controls you run with a number or setting where you have one. Precise answers close questions. Vague ones generate follow-ups. Keep a maintained answer library so every questionnaire says the same thing.

Model answers

Adapt these to what is true for you. Never copy a control you do not run.

Where is our data hosted?
"Customer data is stored and processed in Amazon Web Services Canada (Central) region, ca-central-1, with backups in Canada West (Calgary), ca-west-1. Resource creation outside these regions is blocked by organization policy."
How is responsibility divided with your hosting provider?
"AWS is responsible for physical security, hardware and the virtualization layer, evidenced by its SOC 2 Type 2 and ISO 27001 certification, which we review annually. We are responsible for identity and access, configuration, encryption, logging, backups and application security."
Is data encrypted at rest and in transit?
"All data stores are encrypted at rest with AES-256 using AWS KMS. Connections use TLS 1.2 or higher; older protocols are disabled at the load balancer. Encryption is enforced and monitored by AWS Config rules."
Who has access to production?
"Production access is limited to [n] engineers through single sign-on with MFA. Changes are deployed through a CI/CD pipeline after peer review. Access is reviewed quarterly."
Do you log administrative activity?
"All administrative actions are logged by AWS CloudTrail across all regions, stored in a separate, access-restricted account with object lock, and retained for [n] months. High-risk events generate alerts."
How are backups handled?
"Production databases are backed up [daily] with point-in-time recovery for [n] days, copied to a second Canadian region in an immutable vault. Restores are tested at least annually."
How do you manage vulnerabilities?
"Hosts, container images and functions are scanned continuously with Amazon Inspector. Critical findings are remediated within [n] days and high within [n] days. An independent penetration test is performed annually."

What to attach

  • Your SOC 2 report or ISO 27001 certificate, under NDA.
  • A one-page responsibility matrix, as in shared responsibility.
  • A high-level architecture or data flow diagram.
  • A subprocessor list with locations.
  • The latest penetration test summary or attestation letter.

Without a report yet, the attachments above plus a dated plan for the audit often carry a deal. GetSOC2 covers what to say when a customer asks for a report you do not have.

Can we answer "yes" to a control we are implementing?

No. Answer with what is true today and add the planned date. Questionnaire answers often become contract representations, and a buyer's later review or an auditor will test them.

How do we speed up questionnaires?

Keep an answer library, publish a trust page with your standard documents, and answer from your SOC 2 report where possible. Many buyers accept the report in place of most of the questionnaire.

Questionnaires eating engineering time?

Firms in the network build answer libraries and trust pages.

Get matched