The Security Review That Kills IT Staff Augmentation Deals at Week Six 

A US enterprise signs off on an IT staff augmentation engagement. Rates agreed, engineers named, a start date on the calendar. 

Five weeks later, the engagement still has not begun. The reason has nothing to do with the engineers. 

It is sitting in a vendor security questionnaire the supplier has never seen before. 

This is one of the more common ways augmentation deals stall in regulated US industries. It is also almost entirely predictable  it happens because of where security review sits in the buying process, and because most vendors prepare for the wrong conversation. 

Why it lands at week six 

Enterprise procurement runs in sequence, not in parallel. 

Commercial terms come first: rates, engagement model, notice periods, service levels. Legal reviews the contract language. Only then does the file move to information security and vendor risk. 

There is a reason for that order. Security teams are a constrained resource, and no organization spends their time reviewing suppliers who were never going to clear commercials. 

The consequence is that the hardest gate arrives last. By the time a vendor sees the questionnaire, both sides have invested weeks, and the buyer has communicated a start date internally. 

A vendor who cannot answer quickly is not merely delayed. They are delayed in front of an audience. 

For an engineering leader who needs capacity now, a six-week slip often kills the engagement regardless of how good the engineers are. 

What is actually in the questionnaire 

The document that arrives is rarely about firewalls. It is about governance, and it concentrates on a handful of areas. 

Certifications, and what each one proves. Vendors list credentials without distinguishing between them. Reviewers do distinguish. 

ISO/IEC 27001 certifies that an information security management system exists and has been independently audited. SOC 2 examines controls against trust services criteria — and Type I versus Type II matters, because Type I describes controls at a point in time while Type II tests whether they operate effectively across a period. 

A vendor who cites “SOC 2” without saying which, or who cannot produce a recent report under NDA, has answered nothing. 

Whose security policy governs. This is the question most often answered incorrectly. 

Vendors describe their own security posture at length. The reviewer wanted to know whether augmented engineers will onboard onto the client’s handbook, access controls, and data handling rules. 

The correct answer is that the client’s policy governs. An answer centered on the vendor’s own environment signals that their engineers work at arm’s length — precisely the arrangement enterprise security teams are trying to avoid. 

Obligations that flow to subcontractors. In healthcare, HIPAA responsibilities extend to business associates and their subcontractors through written agreement. An augmentation vendor is inside the compliance perimeter, not adjacent to it. 

Financial services carry analogous expectations. Organizations handling EU personal data need data processing terms and a lawful basis for transfer outside the EEA. 

A vendor unfamiliar with these mechanics has usually not worked in that sector, and reviewers read it that way. 

Background verification. US enterprises typically expect verification before deployment rather than on request and expect to know what it covers. 

Practices vary considerably across jurisdictions. Vendors who treat verification as an optional extra discover mid-review that it is a gating requirement. 

Access, devices, and where code lives. Reviewers ask whether engineers work on managed devices, how privileged access is granted and revoked, and whether client code sits in isolated repositories or shared infrastructure. 

They also ask whether all deliverables and documentation are assigned to the client without carve-outs for reusable components. The shared-repository question catches more vendors than the rest combined. 

Incident response. Not whether a policy exists, but what the notification obligations are, how fast, and to whom. 

Regulatory clocks are unforgiving; organizations subject to GDPR work to a 72-hour notification window to the supervisory authority. A client cannot meet an obligation their supplier has not agreed to support. 

What changes when delivery is offshore 

None of these are unique to offshore engagements. But the file is longer, for structural reasons rather than quality ones. 

The buyer’s questions multiply: data residency, cross-border transfer, time zone coverage for incident response, and whether local employment and verification practices meet the standard, the client’s own auditors will apply. 

A vendor whose credentials are strong in their home market may find those credentials unfamiliar to a US reviewer. Unfamiliar is not the same as weak but it produces the same delay unless the vendor has anticipated it and mapped their credentials to the frameworks the reviewer already knows. 

There is also a self-inflicted version, and it is not geographic at all. 

Vendors who sell primarily on rate and speed build their entire sales motion around those two variables. Their materials answer commercial questions well and governance questions badly. 

When the questionnaire arrives, they are assembling documentation for the first time, live, under pressure. 

Closing the gap 

The fix is unglamorous, and it happens before the contract rather than during the review. 

Buyers can move security review earlier. Sending the questionnaire or even a five-question subset during initial vendor conversations costs a week at the front and can save six at the back. 

It also works as a filter. How quickly and specifically a vendor answers governance questions is a reasonable proxy for whether they have operated inside regulated environments before. 

Vendors need the documentation to exist before it is requested. Current audit dates, reports available under NDA, a written position on whose policy governs, and verification completed as standard. 

Most persuasive of all: evidence of having cleared review at organizations of comparable size and sector. That demonstrates the vendor has been tested rather than merely certified. 

The strongest evidence is work a vendor already had to do for somebody else. 

Sahana Systems, for instance, delivers defense and public infrastructure programs alongside its commercial engagements; environments where documented audit trails and formal verification are conditions of operating rather than selling points. 

The company describes the result as defense-grade delivery applied to enterprise systems. In security review terms, that translates to something narrower and more useful: most of what a US questionnaire asks for already exists, because a different auditor required it first. 

Vendors carrying that kind of obligation tend to arrive at enterprise security review with the artifacts assembled rather than in progress. 

That is a useful test for buyers. Not whether a vendor holds certifications, but whether anything in their existing business would force them to maintain the practices behind those certifications when nobody is asking. 

The question worth asking in week one 

An engineering leader evaluating IT staff augmentation has limited time and a long list of criteria. 

If the security gate is the one most likely to derail the timeline, it deserves attention before the commercial terms rather than after. 

And the version of the question that surfaces the most information is not “are you certified.” 

It is: what did your most demanding client’s security team require of you, and can you show me what you produced for them? 

A vendor who can answer that in week one is unlikely to be the reason the engagement stalls in week six. 

Sahana System Limited (NSE: SAHANA) is an AI-driven technology and engineering company operating across Defence & DeepTech and Enterprise Technology. Its enterprise practices spanning AI and data, cloud engineering, quality engineering, enterprise transformation, IT staff augmentation, and project delivery for organizations in North America and internationally.