SOC 2 Questionnaire — Vendor Reply
Reply to a SIG Lite questionnaire using your SOC 2 report. Cite controls.
Prompt
**Role:** Senior Security & Trust lead at a B2B SaaS. Voice: peer-to-peer, no marketing, no hedging.
**Context:** Vendor: [name]. Procurement contact: [name + role]. Questionnaire type: SIG Lite / CAIQ / custom. Their deadline: [date]. Your SOC 2 Type II report period: [period]. Documents available under NDA: [SOC 2, ISO 27001 cert if any, pentest report, etc.].
**Task:** Reply to the security questionnaire.
1. Para 1: Acknowledge their ask + tell them what they're getting (SOC 2 report attached, signed NDA confirmed).
2. Para 2: Walk through how we control for the risk they care about. Cite specific SOC 2 controls (CC1.1, CC6.1, etc.). Reference exhibit numbers in the NDA bundle.
3. Para 3: Any gaps or exceptions — be honest. If we don't have ISO 27001, say so. Suggest compensating controls.
4. Para 4: Offer a 30-min call AFTER they've reviewed the materials. Never propose a call instead of answering.
5. Signature: name + title + direct email.
**Constraints:**
- Cite specific SOC 2 controls (CC1.1 etc.), not generic "we have controls"
- Reference exhibit numbers in the NDA bundle
- Stay ≤ 850 words total
- Never hedge ("I think", "maybe", "we're working on")
- Never reveal infrastructure specifics
- Never use marketing language
**Output format:** Email · 4 short paragraphs + signature · ≤850 words.How to use this prompt
- 1
Copy the prompt above and paste it into ChatGPT, Claude, or Gemini — or open it in the visual Studio to edit each part on a canvas and run it with your own key.
- 2
Replace any bracketed placeholders with your specifics. The more concrete your context and constraints, the sharper the result — see the 5-part prompt structure.
- 3
Run it, then refine. Ask the model to critique and improve its own answer with self-critique prompting.
Techniques in this prompt
Assigns the model an expert persona so it adopts the right vocabulary, depth, and standards for the task.
Learn this techniqueSets the rules and boundaries — tone, length, what to avoid — that keep the output on-target.
Learn this techniqueSpecifies the exact shape of the result — sections, a table, JSON, a word count — so the output is predictable and ready to use.
Learn this techniqueRecommended models
Build on this prompt
Open it in the visual Studio to wire it into a full workflow with your own API key — or learn the craft behind prompts like this.
More in Legal
NDA Red-line — Vendor-Sent
Flag the clauses that matter: mutuality, term, IP carveouts, governing law.
Policy Doc — From First Principles
Write a policy doc (e.g., remote work, AI usage) that's clear, lived, and won't gather dust.
NDA Red-line (Vendor MSA)
**Role:** In-house counsel at B2B SaaS. **Context:** Vendor NDA: [PASTE]. Relationship: [WHAT will be shared]. **Task:** Walk through sectio…
MSA Negotiation Memo
**Role:** In-house counsel + outside counsel hybrid. **Context:** MSA: [PASTE]. Counterparty: [WHO]. Deal size: [$X]. **Task:** Per critical…