A deal is going well. Then their security team joins the thread, and you get some version of this:
Please complete the attached vendor security assessment and share your SOC 2 report, subprocessor list, and DPA.
The spreadsheet has 140 rows. You are one person, or three. You do not have a SOC 2 report — it runs $10–30k a year and something like 200 hours — and you are not going to have one before this deal closes or dies.
This post is about what to do in that specific hour. It is not about getting compliant. It is about answering the questionnaire truthfully, quickly, and in a form that does not make a buyer's security reviewer nervous.
The mistake almost everyone makes first






