// Posted 2026-08-31

Your Security Questionnaire Queue Has 34 Open SIGs and Six Deals Slipping

Your CISO opens the SIG queue Monday, 34 open questionnaires, six deals slipping the quarter, median turnaround 14 days. A queue nobody staffed end to end.

Thirty-four translucent indigo questionnaire tokens stacked in a receding queue with six near the top glowing bright pink under amber deadline halos slipping past them, blue data threads drifting in from unseen document repository panels and tapering unresolved

It is Monday, 8:47 AM. Your CISO opens the security questionnaire tracker the security engineer keeps in a shared sheet. 34 open questionnaires. Six of them tagged red for a buying-committee review inside 14 days. The median turnaround across the trailing 90 days reads 14 business days from receipt to submission. Two of the six red rows carry the same prospect logo you watched slip from Q2 to Q3 last cycle.

She opens the deal-slip log the CRO shares every Friday. Q3 pushed nine late-stage opportunities into Q4 with a reason flagged in Salesforce. Six carry the reason "waiting on completed security questionnaire" or the softer variant "security review incomplete." Combined ACV on the six rows reads $3.4M. The security engineer worked 62 hours on questionnaires in August against a 40 percent stated allocation. The rest of her month was reactive.

The founders in this seat keep asking the CISO to "hire a GRC analyst" and wondering why the sales cycle keeps stretching two weeks on every deal above the enterprise threshold. Security questionnaires is not a spreadsheet the security engineer opens between real work. Security questionnaires is a six-stage queue that starts with a prospect procurement portal firing a SIG-Lite link on a Wednesday and ends with a signed control matrix landing back in the buying committee inbox inside 72 hours. Four surfaces feed the queue and none of them own it end to end.

The 34 open SIGs and the six that will slip the quarter

Sort the questionnaire tracker by prospect deal stage and days-open. Six rows sit at late-stage with a days-open count above 10. Twelve rows sit at mid-stage with a days-open count between 4 and 9. Sixteen rows sit at early-stage waiting on the AE to confirm the prospect needs the full SIG-Lite rather than the trust-center summary. The oldest late-stage row has been open 21 business days. The AE on that account has pinged the security channel four times. The security engineer replied once with "in the queue, aiming for end of week." That was three end-of-weeks ago.

The reason the queue never clears is not the security engineer's speed. She opens the questionnaire, scans 340 rows, hits row 47 asking about the SOC 2 Type II report scope, opens the SOC 2 evidence folder in a second tab, cannot find the exact scoping statement the auditor issued in April, pings the compliance vendor for a copy, waits two days, resumes at row 47 on Thursday, hits row 112 asking about encryption at rest for the analytics warehouse, opens Slack to ask the data engineer, waits a day, resumes Friday afternoon. The ramping security engineer who joined in July loses another day per questionnaire because she does not yet know which shared drive folder holds the current pen test scope. Every questionnaire eats one engineer week of context-switching against a real security backlog that includes vulnerability triage, access review, and the incident tabletop the CISO scheduled for next Tuesday.

The Series B version of this function reads every incoming questionnaire against a live evidence library on receipt. A CAIQ v4 landing Wednesday afternoon fires a match against 340 controlled answers already reconciled to the current SOC 2 scope, the current pen test report, the current data flow diagram, and the current subprocessor list. Answers 280 of the 340 rows inside two hours with a confidence score attached to each. Flags the 60 low-confidence or novel rows for the security engineer to review in a batch on Thursday morning. The 14-day median turnaround collapses to a 3-day median inside two months.

The five sources firing every quarter nobody wires into the answer library

The evidence surface fires updates every quarter the questionnaire tracker never reads. The compliance vendor pushes a new SOC 2 Type II bridge letter every 90 days. The pen test vendor delivers a fresh executive summary every six months. The cloud posture tool flips six control statuses every month as the platform team ships new services. The DPA template in the legal drive gets a redline every time a European prospect closes with a schedule addendum. The subprocessor list adds a vendor every time procurement approves a new tool.

None of the five updates promote into the questionnaire answer library inside the week. The security engineer owns the answer library, owns the vulnerability queue, owns the access reviews, and owns the incident response runbook. The library gets a manual refresh once a quarter after the SOC 2 bridge letter lands. The pen test summary sits in a folder the security engineer forgets to link. The cloud posture flips never route into the answer strings. The stuck version of this function ships a March answer to a September questionnaire on the encryption question and watches the prospect security team flag it as stale on the follow-up call.

The Series B version wires every source into an answer-library update loop that fires inside 24 hours of the source changing. A new bridge letter routes an update task to the seven answer rows that cite the SOC 2 report period. A cloud posture flip on the encryption control routes an update task to the twelve answer rows that cite encryption at rest. A subprocessor add routes an update task to the four answer rows that list current subprocessors. The library turns from a 340-row static sheet into a 340-row live surface with fresh evidence links attached inside the first sprint.

An indigo evidence vault visualized as a wall of hexagonal cells each holding a glowing amber policy artifact, pink retrieval beams shooting from a central hexagonal agent node to matched cells with blue confidence threads weaving between them

The 72-hour window that decides enterprise deals

The prospect procurement team drops the SIG-Lite link into the AE's inbox on Wednesday afternoon of the redlines call. The AE has 72 hours before the buying committee meets internally on Monday morning to submit a completed questionnaire, ship the SOC 2 report, and answer the six committee-specific follow-ups the security lead will fire on Friday. The stuck version of this function forwards the link into a Slack channel called sec-review, waits five days for the security engineer to open it, and lands a partial draft in the shared drive the following Wednesday. The buying committee already met Monday with three vendors returning a completed pack inside 48 hours and one vendor flagged as security review pending, resubmit next cycle.

The 72-hour window is where the win-rate delta against named competitors collapses on enterprise deals. The AE loses on procurement speed, not on product fit. The evidence exists. The SOC 2 Type II was reissued in June. The pen test summary from July covers the exact application scope. The DPA template supports the schedule the prospect asked for. None of the three artifacts land in the AE's hands inside 72 hours because no function owns the routing, and the artifacts live in three different repositories with three different owners nobody paged on a Wednesday afternoon.

The Series B version fires an intake agent the moment the SIG-Lite link lands in the AE's inbox or the shared sales-security channel. The agent parses the questionnaire format, matches every row against the live answer library, drafts the 280 confident rows in the prospect's requested spreadsheet format, drafts the cover email in the AE's voice with the SOC 2 report, pen test summary, and current subprocessor list attached, and drops a Slack card into the security engineer's channel with the 60 flagged rows, the source evidence links, and a one-click approve button. The completed pack lands in the prospect inbox Friday afternoon. The buying committee reads the security artifacts Monday morning.

The unit economics of a GRC Analyst against an agent stack

Run the two paths against the GRC Analyst req sitting in the CISO's drafts folder at $135K base plus 12 percent variable and equity refresh. Path A closes the req in October, ramps the analyst through Q1, and adds one body to the security team already carrying vulnerability triage, access reviews, and the annual SOC 2 audit. Loaded year-one cost lands $188K to $224K for the analyst. Questionnaire median turnaround moves from 14 days to 8. Late-stage slip rate on questionnaire-triggered deals moves from 22 percent to 14. The analyst holds one queue at 70 percent throughput by month 5 and drops the DPA redline queue on the GC.

Path B ships a two-sprint fractional AI security review function at $52K to $78K in build across the first 30 days and $4K to $6K a month to run. Sprint one lands the answer-library scoring layer against the current SOC 2 report, the current pen test summary, the DPA template, the subprocessor list, the cloud posture snapshot, and the trust-center content on the marketing site. Sprint two lands the 72-hour intake and drafting loop against the AE inbox, the sales-security Slack channel, the prospect portal APIs, and the security engineer's review queue. The whole build fits inside one 14-day sprint window on the calendar the security team already blocks for the quarterly audit prep.

The fractional AI department runs the questionnaire queue on the cadence the SIG-Lite links fire, not the cadence a GRC analyst can push in a weekly standup. Loaded year one lands $100K to $150K plus a fractional Head of GRC at $5K a month who owns the novel-question judgment, the escalation calls, and the exception review. Total $160K to $210K against a $188K to $224K path A. Questionnaire median turnaround moves from 14 days to 3. Late-stage slip rate on questionnaire-triggered deals moves from 22 percent to 5. Sourced revenue lift reads $2.4M in preserved late-stage ACV a quarter against the same security engineer headcount.

The four numbers a CISO runs before the next GRC analyst req

The founders reading this are three weeks from posting a GRC Analyst req on the strength of a "we need to staff security reviews" narrative. Before the offer letter goes out, run four numbers against the questionnaire function, not the headcount. Score the queue, not the hire. The numbers below are what the CISO reads in the Monday review before the CRO opens the deal-slip log.

Median days to submission. Measure the median business days from questionnaire receipt to completed pack sent back. A healthy function runs under 4 days. A stuck function runs 12 to 18, and every enterprise deal above the ACV threshold pushes a cycle.

Answer library freshness ratio. Divide the answer rows with an evidence link updated inside the trailing 90 days by total rows in the library. A healthy function runs above 80 percent. A stuck function runs 30 to 45 percent, and the security engineer ships a March answer to a September question on the encryption row.

Late-stage slip on questionnaire-triggered deals. Compare the slip rate on late-stage opportunities with an open security review against the slip rate on late-stage opportunities without one. A healthy function runs within 4 points. A stuck function runs 15 to 25 points wider, and the CRO opens the board pack asking why the enterprise segment keeps pushing every quarter.

Security engineer hours on questionnaire work. Measure the hours the security engineer spends drafting or reviewing questionnaires against total working hours in the trailing 30 days. A healthy function runs under 8 percent. A stuck function runs 30 to 45 percent, and the vulnerability queue that failed the last tabletop is the one paying for the enterprise sales cycle. Any two numbers in the stuck zone means the queue is the problem, not the headcount, and scope the security review function in a 30-minute call this week.

// Related notes