Skip to content
← Field notes
Sales · Procurement

How to pass a buyer's security review as an offshore agency.

The security review is not a technical test. It is a documentation test with a deadline, and offshore agencies fail it on paperwork rather than posture. Here is the six-document packet, what buyers accept instead of SOC 2, and the answers that quietly escalate you into a nine-month cycle.

By · Guest expertAgencies9 min read

The pattern is always the same. Two good calls, a champion who likes you, a scope everyone agrees on, and then an email with a spreadsheet attached. Nobody on the buyer's side calls it a gate. They call it "just a formality our security team runs." Three weeks later the deal has not moved, your champion has stopped replying with the same energy, and a domestic competitor who answered the same spreadsheet in two days is in the room you were in.

You did not lose on security. You lost on the speed and shape of your answers. Buyer security reviews are graded on whether the reviewer can close a row without asking you a question. Every question she has to ask is a delay, and delays are what get a vendor set aside.

02

The six documents that clear most reviews

Assemble these once and the review stops being an event. First, a written information security policy with a date inside the last twelve months and a named owner. Two pages is enough if the two pages are true. Second, a data processing agreement scoped to the data you actually touch, not a template that claims coverage of things you never handle. Third, a subprocessor list: every third-party tool that can see client data, named, with its purpose and its hosting region. Slack, GitHub, your error tracker, your CI provider.

Fourth, a joiner and leaver checklist showing how access is granted and how it is revoked, with a stated deadline. One business day is the bar buyers expect. Fifth, a third-party penetration test or security assessment report from inside the last twelve months. Sixth, a cyber liability insurance certificate with visible coverage limits. That packet answers between sixty and eighty percent of any questionnaire you will be handed, and it turns the rest into one-line entries rather than explanations.

03

What buyers take instead of SOC 2

Most agencies under a hundred people do not have SOC 2 Type II, and the honest answer to that row is not "in progress." Buyers hear "in progress" as "not started." The answer that holds is a substitution offer: name the framework whose controls you follow (ISO 27001 control set, NIST CSF, or the CIS Top 18), attach the recent pen test, attach the insurance certificate, and add a signed attestation from your principal confirming the ten or twelve control areas the reviewer cares about are enforced today.

This does not clear a bank, an insurer, or a healthcare buyer with a compliance department. It does clear most mid-market SaaS and commerce buyers, and it buys you the runway to complete a real audit during onboarding rather than during the sales cycle. Say the substitution out loud and in writing. Reviewers are far more comfortable accepting a package you proposed than a gap they discovered.

04

The answers that escalate you

Four answer shapes reliably move a row from the reviewer's desk to the CISO's queue. "We can discuss this on a call" reads as an answer you do not have. "Not applicable" without a sentence of reasoning reads as an answer you did not read. "We follow industry best practices" reads as no policy exists. And any answer longer than three sentences reads as a control you are describing rather than running.

The replacement for all four is a short factual sentence plus a document reference. "MFA is enforced on all administrative interfaces including source control and cloud consoles, via our identity provider. See Section 4 of the attached policy." That row closes. Nobody escalates a row that closes.

05

Residency, subcontractors, and the two questions offshore agencies fumble

Where does the data sit, and who else touches it. Those two questions carry more weight for an offshore vendor than any encryption row, because they are the two where the buyer's risk story and your operating reality most often diverge. Answer residency with place names and regions, not with a paragraph about how the data is encrypted. Encryption is not a residency answer; encrypted bytes in the wrong region are still in the wrong region.

Answer subcontractors with a complete list, including any sister entity, any contractor who is not on your payroll, and any founder or CTO who holds organisation-level admin from a country the buyer did not expect. Reviewers find these later through access logs, and finding one after signature is how a routine engagement turns into a contract dispute. Disclose it, scope it, and put a control around it before anyone signs.

06

Send the packet before it is asked for

The strongest move available to an offshore agency is unilateral: attach a two-page security summary to the proposal. Policy date, framework, residency, subprocessor count, pen test date, insurance limits, and a line saying the full packet is available on request. It costs nothing and it removes the round trip that turns a three-week review into a two-month one.

It also changes what your champion writes in the internal memo. A champion who has to compile your security story from call notes produces a weaker memo than a champion who can paste your summary. You will never read that memo. You can decide what raw material it is built from.

Takeaways
  • 01Security reviews are graded on how few questions the reviewer has to ask you, not on how strong your posture is.
  • 02Six documents clear most mid-market reviews: dated policy, scoped DPA, subprocessor list, leaver checklist, recent pen test, insurance certificate.
  • 03Offer a written substitute for SOC 2 rather than answering "in progress": named framework, pen test, insurance, signed principal attestation.
  • 04Residency answers use place names, not encryption claims. Disclose every subcontractor and non-local admin before signature.
  • 05Attach a two-page security summary to the proposal. It shortens the review and improves the memo you never get to read.
Questions this post answers

Related
Turn this into a shortlist

Get vetted. Get listed. Get the paper that survives the memo.

Twelve-minute intake, three-day turnaround. A passing scorecard is the shortest path from a good deck to a serious shortlist.