Most general contractor security questionnaires run 25 to 60 questions, and 8 core controls answer roughly 80% of them. A subcontractor with 10 to 50 employees starting from scratch can typically become questionnaire-ready in 2 to 4 weeks, at a setup cost around $1,000 to $7,000 plus $100 to $350 per seat per month ongoing. The three items that fail subs most often are multi-factor authentication, tested backups, and a written incident response plan. Below is the exact list of what GCs ask about, what a passing answer looks like, and how to get there before your bid deadline.
What General Contractors Are Actually Asking For
Ten years ago, a subcontractor pre-qualification packet asked about bonding capacity, safety records, and insurance certificates. It now asks about your email security.
The reason is straightforward: general contractors and project owners have been breached through their vendors, and their own cyber insurance carriers now require them to verify the security of everyone touching project data. That requirement flows downhill. If you exchange drawings, submittals, pay applications, or lien waivers with a GC, you are part of their risk surface, and they have to be able to prove they checked.
Practically every questionnaire covers the same six categories:
- Account access and authentication. Who can log in, and what stops someone else from doing it
- Endpoint protection. What's running on the workstations and laptops that open project files
- Data backup and recovery. Whether you can get project data back, and whether you've proven it
- Patching and vulnerability management. How fast known security holes get closed
- Employee security training. Whether your people can recognize an attack
- Incident response and breach notification. What happens, and who you tell, when something goes wrong. This doesn't just include security incidents, it should also include natural disasters like hurricane season.
They arrive through a handful of channels like ISNetworld, Avetta, Procore vendor management, Building Connected, or a portal the GC built themselves, or a spreadsheet attached to an email from a project manager with a due date in the subject line. The format changes. The six categories don't.
The 8 Controls That Answer 80% of the Questions
You don't need a security program built from scratch for every questionnaire. You need eight things in place, documented, and provable. Put these in and most questionnaires become a data-entry exercise instead of a scramble.
| Control | What a passing answer looks like | Typical time to implement |
|---|---|---|
| Multi-factor authentication | Enforced on email, VPN, and every remote access path. No exceptions for owners or executives, those are the accounts attackers want. | 2-5 days |
| Managed endpoint detection and response (EDR) | EDR deployed on 100% of workstations, laptops, and servers, monitored around the clock. Consumer antivirus does not pass. | 3-7 days |
| Tested backups | Backups following a 3-2-1 approach, with a documented restore test performed within the last 90 days. The test is the part firms skip and the part questionnaires ask about. | 1-2 weeks |
| Patch management | Critical security patches applied within a stated service level with reporting that shows compliance. | 1 week |
| Security awareness training | Ongoing training for all staff plus phishing simulations, with completion records you can export. | 1 week |
| Written incident response plan | An actual document naming roles, contact numbers, and notification steps. "We'd call our IT guy" is not a plan. | 1-2 weeks |
| Email security and authentication | Advanced filtering in place, plus SPF, DKIM, and DMARC configured on your domain so nobody can convincingly spoof your firm. | 2-4 days |
| Access control and offboarding | A documented process granting access by role, with departing employees' access revoked within x hours. Questionnaires often ask this one specifically. | 1-2 weeks |
Notice how much of this is documentation rather than technology. Firms are frequently running six of the eight controls already and still fail the questionnaire, because nobody wrote anything down and nobody tested the backups. Managed network security closes both halves of that gap at once.
How to Answer Honestly When the Answer Is Currently "No"
This is the most important section on this page, so we'll be blunt about it: do not check a box you can't back up.
A completed security questionnaire usually becomes a contractual representation. You are telling the GC, in writing, that these controls exist. If you claim tested backups you don't have and you later suffer an incident, you are looking at a breach of contract, a possible insurance coverage denial, and a permanent removal from that GC's bidder list. The short-term win is not worth it.
The 4-Week Path from "We Can't Answer This" to Approved Sub
Here is the sequence we run for construction clients who arrive with a questionnaire and a deadline. It's ordered deliberately - the fastest, highest-impact controls go first, so that if the deadline moves up you've already covered the questions that carry the most weight.
Week 1: Assessment
We work through the actual questionnaire you received and determine which answers are yes, no, or partial using our network assessment analysis. That gap list becomes the project plan.
Week 2: Protect the email and train the people
Multi-factor authentication goes out across email and remote access, because it's the single control that most often turns a "no" into a "yes" and it takes days, not weeks. Security awareness training also launches which includes simulated phishing scenarios.
Week 3: Protect the endpoints and the domain
EDR is deployed to every workstation, laptop, and server, including the machines in the job trailer that nobody has inventoried in two years. Email authentication records like SPF, DKIM, and DMARC get configured, and the patch management service level is established.
Week 4: Prove the recovery and write the plan
This is where most firms discover their backups weren't covering what they assumed. We verify what's actually being backed up, fix the gaps, and run a documented restore test so you have a dated record to point at. The written incident response plan gets drafted, naming real people and real phone numbers.
That last step matters more than it sounds. A questionnaire submitted with supporting documentation attached tends to clear review the first time. One submitted as bare checkboxes tends to come back with follow-up questions, and follow-up questions cost you a week you may not have.
What It Costs to Become Questionnaire-Ready
There are two numbers, and they work differently.
The one-time remediation project typically runs $1,000 to $7,000 for a firm with 10 to 50 employees. That covers the gap assessment, deploying the controls you're missing, running the restore test, and writing the documentation. Firms already running some of the eight controls land at the lower end.
The ongoing monthly cost runs $100 to $350 per seat per month, because these controls are not one-time purchases. Backups have to keep getting tested. Patches have to keep getting applied. Training has to keep happening, and next year's questionnaire will ask you to prove all of it again.
Weigh both against the number that actually matters: the value of the work you lose by falling off an approved bidder list. For most subcontractors we talk to, a single project on that list is worth many times the annual cost of staying qualified for it. That's the comparison to bring to your partners, not the monthly invoice in isolation.
A real client example:
A 10-person firm kept all project files in a cloud platform, but did not have a backup solution in place. Most firms don't realize that cloud file storage platforms implement a shared responsibility model, and generally have a 30-to-60-day window to restore a file if it gets deleted. In these models, the customer remains responsible for protecting their own data, including backing it up. We implemented a backup solution to protect their projects files and now they have peace of mind that they will not lose critical firm files.
Why Construction Firms Work With Alexaur
We've supported architecture, engineering, and construction firms across the Katy, TX and Greater West Houston area since 2001, and we're still family-owned. That means the person who answers your call knows your job sites.
- 98% of support tickets resolved on the first call
- Average client tenure of more than 10 years
- 100+ combined years of cybersecurity experience on staff
- Clients who have implemented our full security and business continuity recommendations have not reported a business-disrupting security incident.
- Fluent in the software you actually run: AutoCAD, Revit, Bluebeam, SolidWorks, Procore, Navisworks, ProjectWise, and OnScreen Takeoff. See our IT solutions for AEC firms
- Dell & Lenovo Partner
- Managed Protection Security Suite Associate Accreditation
- MSP Pro
- Keeper Sales Professional
- Network+ Certified
- SonicWall Certified
Have a Questionnaire Due?
If a general contractor has sent you a security assessment and you're not sure how to answer it, the deadline is the problem, not the technology. Most of these controls go in faster than firms expect.
Start with the free readiness checklist to see where you stand, or book a 15-minute discovery call and bring the questionnaire with you. We'll tell you honestly what you can answer today, what needs work, and how long it will take.
Call 281-646-1200 or email results@alexaur.com.
