Security questionnaire readiness check
Paste a vendor security questionnaire. Find out how much of it you could answer today, where the gaps sit, and roughly how many hours are left.
Nothing is sent anywhere. Press Ctrl+Enter to run.
0 questions found across 0 security domains.
For each domain, how much of it is already written down in a form you could hand a reviewer today?
Questionnaire readiness
- 0answerable today
of 0 questions - 0questions with
no documentation - ~0 hestimated effort
to close the gap
Where the work is
Estimate only. This is not a compliance assessment, an audit or legal advice.
I couldn't read that
🔒 100% private — your questionnaire is processed on your device and is never uploaded, stored or logged. No account, no cookies for the tool itself.
Works with pasted text of any length. Questions are classified by security vocabulary, so unusual wording may land in “Unclassified” — the count stays correct either way.
How it works
-
Paste the questions
Copy the question column out of the spreadsheet, document or portal the customer sent you. Numbering and bullets are stripped automatically.
-
Rate what you have
Each question is sorted into a security domain. You say whether that domain is documented, partly there, or missing — twelve clicks, not two hundred.
-
See the real number
You get a readiness percentage, the count of questions you cannot currently answer, and a conservative estimate of the hours needed to close them.
Why questionnaires decide deals you thought were won
A vendor security questionnaire arrives late in the sales cycle, usually from someone you have never spoken to, usually with a deadline attached. It is rarely the deciding factor on its own — but the delay it causes is. Industry surveys put the damage plainly: a majority of companies report losing deals because they could not complete a security questionnaire in time, and most organisations take more than two weeks to work through a vendor assessment by hand.
The reason is structural rather than technical. The questions are not hard; they are scattered. Answering two hundred of them means pulling facts from engineering, IT, HR and legal, then writing each one up in a form a reviewer will accept. Teams that do this repeatedly report spending well over ten hours a week on it, and four to six hours on each individual questionnaire once you count everyone who touches it.
What this tool actually measures
It measures one thing: how much of the questionnaire you could answer from documentation that already exists. That is the variable that decides whether a response takes an afternoon or three weeks. It does not judge whether your controls are good, whether you would pass an audit, or whether the reviewer will be satisfied — those are different questions and no automated tool should pretend to answer them.
Every question you paste is matched against the vocabulary of twelve common security domains: access control, encryption, business continuity, incident response, vendor risk, application security, network security, logging, governance, personnel, physical security and privacy. You then rate each domain once instead of each question individually, which is the whole point — the score comes from twelve honest answers rather than two hundred rushed ones.
Why it runs in your browser
A security questionnaire is a description of your defences and, more usefully to an attacker, of their weak points. Uploading that to a free web tool is exactly the behaviour the questionnaire is asking you about. So this page never sends it anywhere: all the parsing, classification and scoring happens in JavaScript on your own machine. You can verify it — load the page, disconnect from the internet, and use it as normal.
Where to go after the score
If your readiness lands above eighty percent, your bottleneck is assembly rather than substance: build a reusable answer library so the next questionnaire is a copy edit. Between fifty and eighty, pick the two domains with the largest gaps and write those policies first — they will recur in every future questionnaire. Below fifty, and with a deal actually waiting, be honest with the customer about timing while you work; a realistic date beats a missed one.
Did it read your questionnaire correctly?
This is free and there is nothing to sell you. If the classifier put your questions into odd categories, missed some, or there is something you wish it did, say so — that feedback is what decides whether this gets improved.
Send feedbackFrequently asked questions
Is my questionnaire uploaded anywhere?
No. The text you paste is processed by JavaScript inside your own browser and never leaves your device. There is no server, no account and no database. You can confirm it by disconnecting from the internet after the page loads — the tool still works.
How accurate is the readiness score?
It is an estimate, not an assessment. The tool classifies questions by keyword and multiplies each domain by how you rated your own documentation. It is designed to show you where the gaps concentrate and roughly how much work is left — not to certify anything.
Which questionnaire formats does it handle?
Any text you can paste: a vendor's custom Word or Excel questionnaire, a standard framework, or a list pasted from a portal. Copy the question column and paste it in. Numbering and bullets are stripped automatically.
Why do questions land in the wrong category sometimes?
The classifier matches security vocabulary, so a question that uses unusual wording may fall into “Unclassified”. That does not affect the total question count, only which bucket it sits in.
How is the time estimate calculated?
One hour of fixed overhead for routing, review and sign-off, plus twelve minutes for every question you cannot answer from existing documentation. It is deliberately conservative and assumes you are writing from scratch.
Does a high score mean I will pass the review?
No. It means you could respond quickly. Reviewers judge the substance of your controls, not the speed of your reply — though responding first demonstrably helps, since most B2B buyers move with whoever answers first.
Do I need a SOC 2 report to answer these?
Not to answer them, but a clean report removes a large share of the detailed follow-up questions, because the reviewer can rely on the auditor instead of asking you directly.