Built for small MSPs
SIG, CAIQ or a bespoke vendor form lands right before a contract is signed. We complete it for you, so the deal can close, without you losing a day to a spreadsheet.
We'll be in touch shortly, usually within a couple of hours. If it's urgent, email [email protected].
The transformation
And this is the full job, not just five rows: a 400-row vendor form with every cell empty, returned submission-ready — every answer sourced, gaps flagged, signed off.
A security questionnaire usually arrives once the client has all but said yes. It's blocking your revenue, and it can swallow 10 to 40 hours copying technical detail into someone else's form. We make it disappear.
How it works
Forward the questionnaire and your existing security docs: ISO cert, policies, any prior answers.
We answer only from what your documents support, and flag anything that needs your sign-off. We never invent a control you don't have.
Review, confirm the flagged points, and submit. Submission-ready in 3 working days.
Why MSPs use us
Every answer ties back to your own documents. Genuine gaps are flagged for you, because a confident wrong answer is what fails a security review.
Not enterprise software repriced down. A single flat fee for the job in front of you, no platform to learn or subscribe to.
It comes back as a draft you own and sign off. Your name goes on it, so the final call is always yours.
Pricing
You only pay once it's submission-ready and you're happy.
A real worked example: a slice of a CAIQ, completed from a sample MSP's documents.
See a worked exampleYour data stays yours. Documents are handled in a private account, never used to train any AI model, never shared, and deleted after delivery. Happy to sign an NDA first, or work from a redacted set.
FAQ
You can, and for a single easy question it might be fine. The problem is a full questionnaire: a general tool will happily invent a control you don't actually have, and a confident wrong answer is exactly what fails a security review and stalls the deal. We answer only from your own documents, flag the genuine gaps instead of guessing, and hand you a draft that's ready to submit. You're paying to take a day off your plate and not have to check every line.
Yes. Your documents are handled in a private, access-controlled account, never used to train any AI model, never shared, and deleted once your questionnaire is delivered. We're happy to sign an NDA before you send anything, or to work from a redacted set. The full detail is on our privacy page.
Then you pay nothing. The £349 is due only once the questionnaire is submission-ready and you're happy with it. If the result isn't useful, it costs you nothing, no negotiation.
Three working days from when we have the questionnaire and your supporting documents. It takes about 15 minutes of your time: forward it over at the start, then review and sign off the flagged points at the end. If your deadline is tighter than three days, tell us and we'll say honestly whether we can hit it.
SIG (Standardized Information Gathering), CAIQ (Cloud Security Alliance), and bespoke vendor and client questionnaires, whether they arrive as a spreadsheet, a web portal, or a Word document. If you've been sent something in a format you're not sure about, send it over and we'll confirm we can complete it before you commit to anything.
Who's behind this
I'm James. I built ComplianceCrib after watching small MSPs lose whole days — usually a director's — to security questionnaires that land right before a deal signs.
I'm a final-year business student, not a big compliance firm, and I won't pretend otherwise. What you get is careful work: every answer drafted from your own documents, and I personally review every line before it comes back to you. Anything your documents don't support gets flagged, never guessed.
You review it, you sign it off, and you only pay if it's useful.