I do a lot of these myself (technical founder, willing to do dirty work) but there comes a point where it's not a good use of my time for all but the biggest opportunities, because these things are so time intensive and I need to wear many hats. In fact, I wouldn't be surprised if that's what's going on at Framework now.
I would love to hear if anyone has different suggestions. For reference, we already employ outsourced ciso/cyber vendors (think of vanta, strikegraph) but, while they can help draft responses to these things, they can't do the last mile of certifying and submitting on your behalf, so in practice we still need some skilled internal resources to accomplish these