Founder-led content plan
Teach: cost of a slipped quarter; SIG Lite vs CAIQ; how buyers catch inconsistent answers; what trust centers do/don’t deflect; DORA/NYDFS why volume rose; gap-memo examples; overclaiming risks.
Done-for-you completion of enterprise security questionnaires (SIG Lite, CAIQ, custom DDQs, buyer portals) that unblocks SaaS deals in 48–120 hours — AI drafts from your live evidence; a human security reviewer signs every packet.
QuestClose sells a done-for-you Completed Security Questionnaire Packet to Series A–C B2B SaaS companies (20–200 employees) whose enterprise deals stall when a buyer sends a 100–300 question SIG Lite, CAIQ, or custom DDQ. The customer experiences an expert desk that returns a buyer-ready workbook plus evidence citation sheet in 48–120 hours — not another self-serve AI copilot.
Why now: third-party risk mandates (DORA, NYDFS 500, CMMC 2.0, PCI DSS 4.0, SEC cyber disclosure) have roughly doubled questionnaire volume since 2022; TrustMind cites Whistic’s 2025 TPRM data showing assessment requests up ~26% YoY; industry surveys report 9–40 hours per questionnaire and 2–6 weeks of sales-cycle delay. Existing budgets already flow to SecurityPal (~$33k/yr median), vCISO.com ($1.5k/questionnaire), BARE (€600–€2k), Loopio ($20k+/yr), and Conveyor ($9.6k+/yr). QuestClose wins the mid-market wedge where software alone still leaves a human review gap and full GRC retainers are too expensive.
First wedge: SIG Lite / CAIQ ≤150 questions for SOC 2 Type II SaaS vendors with an active enterprise deal in security review. Pricing is per completed packet ($1,200 standard / $2,400 long-form / $3,000+ portal-rush), never hourly. Human chokepoint: named security reviewer signs off on every factual claim and flags gaps that would create contractual misrepresentation.
Enterprise buyers will keep sending questionnaires regardless of trust centers. The scarce resource is not “an AI that drafts answers” — it is a reliable, evidence-grounded, human-reviewed completion that sales can submit without burning CTO/GRC calendar. An AI-native desk that treats the knowledge base as operations product, and the signed packet as the SKU, decouples revenue from headcount while staying more trustworthy than raw automation and cheaper than a $150k GRC hire.
This run steered away from the manifest’s heavy regulatory-filing-engine skew (200+ prior). Fresh searches across restaurant grade recovery, SB 1383 (already RecoverPack), dig-ticket SaaS, exemption certificates (already claimed), DQ files (inside fmcsa-dot-compliance-engine), CBAS IPC, confined-space permits, and hotel TOT led to two strong underexplored options: LA letter-grade OII packs and SaaS security-questionnaire response. Questionnaire response clears CODE and the six gates with clearer outcome pricing, stronger existing budget proof, zero physical labor, and higher novelty versus prior blueprints (only a Fannie Mae condo questionnaire pack exists — different ICP/outcome).
| Candidate | Score /100 | Verdict |
|---|---|---|
| QuestClose — SaaS security questionnaire response desk | 84 | Winner |
| GradeLift — LA restaurant FOIR→OII letter-grade recovery pack | 76 | Strong runner-up; PoolLog-adjacent pattern; deferred |
| BAAVault — HIPAA BAA inventory completeness desk | 68 | Near SRA engine; software-heavy; deferred |
| ConfinedPermit — OSHA 1910.146 PRCS program desk | 58 | Gate 5 / one-shot consulting risk; deferred (prior memory) |
| HotelTOT — independent hotel multi-city TOT remittance | 61 | Tax-practice boundary + Avalara software; deferred |
Scoring dimensions (1–5 each, summed→normalized): trust burden, judgment, intelligence threshold, regulation moat, no physical labor, Sam Altman test, outcome pricing, GM potential, urgency, whitespace, novelty vs manifest, AI fit, demand evidence, budget proof, lead-magnet potential, MVP clarity, distribution, licensing, repeatability, speed to revenue.
Six-gate total: 27/30 (rubric ~84/100 with novelty and demand bonuses).
ICP: US B2B SaaS, Series A–C, 20–200 employees, SOC 2 Type II (or in progress), selling $50k–$500k ACV into mid-market/enterprise, receiving ≥1 security questionnaire per active late-stage deal.
Economic buyer: VP Sales / CRO (deal at risk) co-buying with Head of Security / CTO / fractional vCISO. Day-to-day champion: Sales Engineer or RevOps.
Trigger: Buyer sends SIG Lite / CAIQ / custom spreadsheet / OneTrust/Whistic portal with a <10-business-day deadline tied to a verbal or papered deal.
Security questionnaires sit on the critical path of 22–38% of enterprise deals (TrustMind survey; industry blogs citing Safe Security/Whistic). Manual completion burns 9–40 hours of blended SE/GRC/CTO time ($700–$2,000 labor) and commonly adds 2–6 weeks of cycle delay. Mid-market SaaS cannot justify a $141k–$162k GRC hire or a $20k–$33k software/managed stack until volume explodes — yet a single slipped $150k ARR deal dwarfs the cost of a $1.2k packet.
A buyer-ready Completed Security Questionnaire Packet: filled workbook or portal export, evidence citation index (policy/SOC 2/architecture paragraph references), conflict & gap memo, and signed reviewer attestation. Optional: one 30-minute buyer security call support. We do not sell a customer-operated AI chat, a trust-center product, or a SOC 2 audit.
| Element | Definition |
|---|---|
| ICP | SOC 2 Type II B2B SaaS, 20–120 employees, US |
| Trigger | Inbound SIG Lite or CAIQ ≤150 questions on an active deal |
| Pain | CTO/SE bottleneck; risk of inaccurate or late answers |
| One-feature MVP | DFY Completed Packet for one questionnaire |
| Input | Questionnaire file + SOC 2 report + policy pack + architecture one-pager + prior answers (if any) |
| Output | Completed file + citation sheet + gap memo + reviewer sign-off |
| Human chokepoint | Named security reviewer (CISSP/CCSP/ex-CISO preferred) approves every claim |
| Success metric | ≤5 business days turnaround; ≤5% buyer clarification rate; ≥40% repeat within 90 days |
| Next asks | Portal completion, Monthly Desk retainer, trust-center content pack, MSA security exhibit review (legal partner) |
| Claim | Label | Confidence |
|---|---|---|
| Enterprise security reviews commonly add 2–6 weeks to sales cycles | Verified | High (multiple 2025–26 practitioner sources) |
| Manual questionnaire effort often 9–40 hours | Verified | High |
| Whistic 2025: assessment requests +26% YoY; ~37/mo average vendor | Verified | Med-High (via TrustMind citing Whistic; confirm primary if pitching investors) |
| TrustMind: 24 questionnaires/quarter median; 11% deals lost/slipped | Verified | Med (vendor survey n=142) |
| SecurityPal median spend ~$33k/yr (Vendr) | Verified | Med (third-party procurement data) |
| BARE/Optimum/vCISO public per-questionnaire pricing | Verified | High |
| Beachhead TAM $40–100M service spend | Inferred | Med (firm-count × spend assumptions) |
| QuestClose can sustain 55–70% GM at scale | Inferred | Med (model-dependent) |
| Exact count of US SaaS firms in ICP | Unverified | Low — do not use as core go reason |
| Claim | Label | Source | Type | Date | Section |
|---|---|---|---|---|---|
| 2–6 week security-review delay | Verified | FillBase deal-velocity analysis | Industry analysis | 2025–26 | Pain / CODE |
| 24 Qs/quarter; 11% slip/loss | Verified | TrustMind sales-cycle survey | Vendor survey | 2026 | Demand |
| +26% YoY assessment volume | Verified | TrustMind citing Whistic 2025 TPRM | Secondary | 2025–26 | CODE |
| Conveyor $9.6k; Loopio $20k+; SecurityPal ~$33k | Verified | TrustMind pricing table | Market pricing | 2026 | Budget |
| BARE from €600 / retainer €2k | Verified | BARE Consulting | Vendor pricing | 2026 | Pricing |
| vCISO $1,500–$3,000/questionnaire | Verified | vCISO.com | Vendor pricing | 2026 | Pricing |
| Optimum from €600 | Verified | Optimum | Vendor pricing | 2026 | Pricing |
| SIG Lite vs SIG Core scoping | Verified | Shared Assessments PDF | Primary standards | 2023–24 | MVP |
| CAIQ / CCM cloud focus | Verified | Workstreet CAIQ vs SIG | Industry explainer | 2025–26 | Compete |
| DORA third-party ICT rules | Verified | Regulation (EU) 2022/2554 | Primary law | 2022/app 2025 | Regulatory |
| NYDFS 500.11 third-party assessment | Verified | 23 NYCRR 500 | Primary reg | 2023–25 | Regulatory |
| Manual cost $700–$900 mid-complexity | Verified | Wolfia cost analysis | Industry analysis | 2026 | Unit economics |
| GRC analyst fully loaded $141–162k | Verified | TrustMind citing Salary.com/Robert Half | Labor benchmark | 2026 | Unit economics |
| ~5k beachhead SOC2 SaaS firms | Inferred | Derived from market structure | Inference | 2026 | Sizing |
Buyer-side TPRM programs are expanding under overlapping frameworks; vendor-side questionnaire load is rising faster than security headcount. Public services and software with five-figure annual spend prove budget exists. Mid-market SaaS (too big for founder-only answers, too small for SecurityPal enterprise retainers) is the underserved band.
Paid conversion still must be proven in pilots — waitlists ≠ PMF.
| Player | Type | Gap QuestClose exploits |
|---|---|---|
| Loopio, Conveyor, Velocibid, TrustMind, Vendict | Software / AI automation | Customer still operates the tool; portal UX and review discipline remain painful |
| Vanta/Drata + SafeBase bundles | Compliance platform add-on | Caps and weak portal automation; not DFY |
| SecurityPal | Managed analysts | Enterprise pricing; overkill for 8–20 Qs/year |
| BARE / Optimum / vCISO.com | Boutique managed | Closest comps — win on AI throughput + US mid-market packaging + packet productization |
| Fractional vCISOs / GRC freelancers | Hourly talent | Unpredictable turnaround; not ops-as-product |
Budgets already exist: SE/CTO labor, software seats, outsourced questionnaire filling, and vCISO retainers. QuestClose redirects the “emergency deal unblock” budget first, then expands into a Monthly Desk that replaces ad-hoc freelancers. It is not a clone of Loopio (customer-operated) nor SecurityPal (enterprise BPO); it is a productized DFY packet for the mid-market volume band.
| SKU | Price | Unit |
|---|---|---|
| Gap Scan (lead magnet upgrade) | Free / $149 | One questionnaire triage memo |
| Standard Packet (≤150 Q) | $1,200 | Per completed questionnaire |
| Long-form Packet (151–300 Q) | $2,400 | Per completed questionnaire |
| Portal Rush (buyer portal + <72h) | $3,000–$4,500 | Per event |
| Monthly Desk (4 packets/mo) | $3,500–$5,500/mo | Retainer |
| Buyer call add-on | $350 | Per 30-min call |
Never hourly. Outcome = completed, reviewed packet. Customer pays county/state fees? N/A — no government filing.
QuestClose does not file with regulators. Buyer-side frameworks (DORA, NYDFS 500, CMMC, PCI DSS 4.0 Req 12.8, SEC cyber disclosure) create demand. Seller-side risk is misrepresentation if answers overclaim controls. Mitigations: evidence grounding, gap memos, reviewer attestation, refusal to invent certifications, legal escalation for MSA security exhibits.
AI changes unit economics by collapsing draft time from hours to minutes, enabling one reviewer to supervise 4–8 packets/day at day 90 vs 1–2 manually. Personalization comes from client-specific retrieval, not generic ChatGPT answers. As models improve, draft quality and portal parsing improve — the moat is the versioned evidence graph, conflict library, and reviewer SOPs.
Checked restored manifest (413 runs) and root *-blueprint.html files. No prior blueprint for B2B SaaS security questionnaire / SIG / CAIQ / DDQ response desks. Nearest: Fannie Mae 1076 condo questionnaire (real-estate lender form — different buyer/outcome); HIPAA SRA engine (risk analysis report, not deal questionnaire); TripShield/NEMT and FMCSA engines (transport compliance). QuestClose is novel on buyer+workflow+outcome.
If frontier models make drafting free, buyers still need (1) a maintained evidence graph, (2) conflict control across packets, (3) accountable human review, (4) portal labor, (5) turnaround SLAs. QuestClose wins as the ops layer + liability interface, not as “ChatGPT for SIG.” Trust centers deflect some volume but do not eliminate questionnaires for regulated buyers.
SOPs for intake evidence lists, forbidden claims, confidence thresholds, exception queues, reviewer assignment by vertical, audit trails of every answer change, versioned gold-standard packets, red-team weekly quizzes, root-cause on buyer clarifications.
| Task | License | Min launch | Min day 90 | Automation path | Quality risk | Cannot automate | Audit trail |
|---|---|---|---|---|---|---|---|
| Evidence completeness gate | None | 20 | 8 | Checklist bot | Low | Judging sufficiency of weird artifacts | Gate log |
| Draft review & edit | Preferred CISSP/equiv | 90 | 35 | Higher-confidence auto-approve | High if skipped | Truth of control claims | Per-answer approval |
| Gap memo authorship | None/security | 25 | 12 | Template fill | Med | Prioritization for client roadmap | Memo version |
| Buyer security call | None | 30 | 30 | N/A | Med | Live trust | Call notes |
| Contractual exhibit escalate | Refer counsel | 15 | 10 | Classifier | High | Legal advice | Escalation ticket |
“SIG Lite / CAIQ Packet — $1,200, 5-business-day SLA” for SOC 2 SaaS with an active deal. Includes completed workbook, citation sheet, gap memo, reviewer sign-off. Excludes: inventing certifications; portal rush; legal MSA exhibits; ongoing monitoring.
Day one: Google Drive/Dropbox, Notion, Excel, LLM API, Linear, Stripe, Calendly, DocuSign, 1Password, Zoom. Later: custom parser, portal assistant, client portal. No heavy platform before revenue.
Mandatory reviewer approval on 100% of packets at launch. Auto-approve only answers with confidence ≥0.9 and exact gold match after day 90, still with packet-level sign-off. Contractual-adjacent questions always human.
| Metric | Launch | Day 90 | Year 1 |
|---|---|---|---|
| Reviewer minutes / standard packet | 120–180 | 45–70 | 30–50 |
| AI+ops COGS / $1,200 packet | $420–$550 | $280–$360 | $200–$300 |
| Gross margin | 45–55% | 55–65% | 60–70% |
| Automation % | 40% | 65% | 75–80% |
| Throughput / reviewer / day | 1–2 | 4–6 | 6–8 |
| Rework / clarification rate | <15% | <8% | <5% |
| Revenue / FTE target | — | $250k | $400k+ |
COGS breakdown: model inference $15–40; tooling $10–25; operator prep $40–80; reviewer $120–280; QA $20–40; support/sales follow-up $30–60; rework reserve $40. CAC payback: content+outbound CAC $400–900 → payback on first packet or first Desk month. Conversions (assumptions): lead-magnet→consult 12–20%; consult→paid packet 25–40%; packet→Desk 20–30% within 90 days; Desk monthly retention 90%+.
| Channel | Why ICP reachable | First angle | Conv. assumption | Proof | Measure | Follow-up |
|---|---|---|---|---|---|---|
| CRO/SE/security follow founders | Teardown of a redacted SIG Lite gap | 2–4% profile→waitlist | Competitor content engagement | CTR, waitlist | DM + Gap Scan offer | |
| Search / AEO | “How to fill SIG Lite” queries | Guides + calculator | 1–3% visit→lead | Keyword volume proxies | Organic leads | Email nurture |
| Outbound | Clearbit lists of SOC2 SaaS | Personalized “deal unblock” note | 3–6% reply | vCISO outbound norms | Replies, meetings | Free Gap Scan |
| Partner | SOC2 auditors, fractional CISOs | White-label rush packets | 1–2 intros/mo/partner | Existing referral markets | Partner-sourced revenue | Rev share 10–15% |
| Communities | Pavilion, RevOps Slack, YC | AMA on questionnaire delays | Variable | Active threads | Attributed signups | Office hours |
Offer page: one outcome, three SKUs, SLA clock, sample redacted packet. Pitch: “Your deal is in security review. We return a reviewed SIG Lite in 5 days.” Outreach leads with a 5-line diagnosis of their likely gaps (SSO, logging retention, subprocessors) — not a demo ask.
Teach: cost of a slipped quarter; SIG Lite vs CAIQ; how buyers catch inconsistent answers; what trust centers do/don’t deflect; DORA/NYDFS why volume rose; gap-memo examples; overclaiming risks.
Free Gap Scan: upload one questionnaire (or 20 sample questions) + policy index → 1-page readiness score + top 10 likely gaps. Waitlist CTA for 48h rush slots. Follow-up within 1 business day. Sales-ready when: active deal + deadline ≤10 days + SOC 2 evidence available.
Convert Gap Scan users, founder network SaaS operators, SOC 2 auditor referrals, and prior SE colleagues. Offer first packet discount ($900) for case-study rights.
List: SOC 2-listed SaaS on directory sites + recently hired Enterprise AE/SE. Message: diagnosis + Gap Scan, not “book a demo.” Cap 40 highly personalized notes/day.
Publish citation-rich pages answering: “How long should SIG Lite take?”, “SIG vs CAIQ”, “What is a security questionnaire for SaaS?”, “How to respond to OneTrust vendor assessment.” Structure with FAQ schema-like headings; no fake schema spam. Goal: become the cited explainer that funnels to Gap Scan.
Every clarification or edit becomes a gold answer, rule, or checklist item within 48h. Weekly SOP review. Distinguish: evidence missing (client) vs draft wrong (us) vs buyer unique question (library expansion).
Complete content calendar; 40 outbound/week; 2 partner conversations (SOC 2 auditor, vCISO collective); 6 paid packets; first case study; measure cycle time and clarification rate.
20–30 packets cumulative; launch Monthly Desk with 3 retainers; hire/contract second reviewer; automate citation export; hit ≥55% GM on standard packets; decide portal SKU go/no-go.
Primary risks: overclaiming controls; software commoditization; reviewer bottleneck; portal access friction; seasonality around quarter-end. Mitigations detailed in register below.
Go. Clears evidence threshold: clear buyer, painful specific problem, spend/labor proof, active demand, competitors/budgets, narrow MVP, path to first sale without heavy platform, 50%+ GM path, distribution path, no fatal licensing blocker, not a customer-operated copilot, novel vs manifest.
Launch QuestClose as a DFY security questionnaire response desk for SOC 2 B2B SaaS. Sell per-packet outcomes first; expand to Monthly Desk. Keep humans at the claim-truth chokepoint. Measure ruthlessly against the kill criteria above.