By David Chernitzky, CEO, Armour Cybersecurity · Serving Toronto and organizations across North America · Last updated August 25, 2026
[IMAGE: Hero. Alt: “Accounting firm SOC 2 and ISO 27001 evidence answering an enterprise client security questionnaire”]
Quick Answer
Enterprise audit and advisory clients now routinely send security questionnaires before engaging an accounting firm, and many require evidence of SOC 2 or ISO 27001 attestation as a condition of the mandate. Firms that cannot respond credibly risk losing engagements to competitors who can. A compliance readiness programme builds the documented controls that questionnaires require and gives partners a defensible answer at every renewal, turning what used to be an awkward RFP section into a competitive advantage.
Key Takeaways
- Client security questionnaires for accounting firms typically map to SOC 2, ISO 27001, or NIST CSF and cover access management, encryption, incident response, vendor risk, and security testing.
- Failing to respond or responding without supporting evidence creates a competitive disadvantage in enterprise audit, advisory, and M&A mandates.
- SOC 2 Type II attestation is the most commonly accepted credential for Canadian and US enterprise clients.
- Compliance readiness is not just a checkbox exercise. The controls built during the process reduce real security risk to client data.
- A managed compliance programme prepares firms for questionnaire responses, formal audits, and cyber insurance renewals from a single evidence base.
Why Are Clients Sending Security Questionnaires to Their Accounting Firms?
Boards and audit committees at public companies, financial institutions, and large private organizations have become significantly more focused on third-party cyber risk. Their accounting firm holds the financial records, audit working papers, and advisory documents that represent their most sensitive internal data. A breach at the firm is a breach of that data.
The response from enterprise procurement and legal teams has been to add cybersecurity due diligence to the firm selection and renewal process. Questionnaires that once appeared only in technology vendor contracts are now standard in audit and advisory RFPs.
The questionnaires are not symbolic. They ask specific questions about encryption standards, multi-factor authentication deployment, incident response procedures, third-party vendor assessment, business continuity capabilities, and independent security testing. A firm that answers these questions with “we use a trusted IT provider” will not retain a sophisticated enterprise client.
What Do These Questionnaires Actually Ask?
Access Management and Authentication
Questionnaires consistently ask whether the firm enforces multi-factor authentication on all systems containing client data, how access is provisioned and deprovisioned for staff and contractors, whether privileged access is separately managed, and how access reviews are conducted. These controls map directly to SOC 2 Common Criteria CC6 and ISO 27001:2022 Annex A.5.15.
A firm that can document its MFA policy, show evidence of quarterly access reviews, and demonstrate a formal offboarding procedure will answer these questions confidently. A firm running on default settings and informal practices will not.
Data Protection and Encryption
Clients ask how client data is classified, encrypted in transit and at rest, and protected from unauthorized access. Cloud storage configurations, email encryption, laptop encryption policies, and document management platform settings are all within scope. These questions map to the SOC 2 Confidentiality criteria and ISO 27001:2022 Annex A.8.24, the control covering the use of cryptography.
Incident Response
A documented incident response plan with defined roles, notification timelines, and tested procedures is a standard questionnaire requirement. Enterprise clients want to know that if a breach involves their data, the firm has a process that limits damage and provides timely notification. A plan that exists only on paper and has never been tested will not satisfy a sophisticated procurement team.
Vendor and Third-Party Risk
Accounting firms use tax software vendors, e-filing services, payroll platforms, cloud storage, and outsourced bookkeeping providers. Questionnaires ask how these vendors are assessed, what contractual protections govern data handling, and whether vendor access to client data is limited and monitored. A formal vendor risk programme is now a baseline expectation for enterprise engagements.
Security Testing
Annual penetration testing of firm infrastructure, practice management systems, and remote access is increasingly required rather than optional. Questionnaires ask when the last test was conducted, by whom, and what findings were remediated. A firm that cannot produce a recent penetration test report from an independent provider is unlikely to satisfy enterprise security requirements.
What Is the Difference Between SOC 2 and ISO 27001?
SOC 2 is a North American standard that produces an auditor’s report on the operating effectiveness of a firm’s controls against the AICPA Trust Services Criteria. Type I covers controls as designed; Type II covers controls as operated over a period of six to twelve months. Enterprise US and Canadian clients typically accept SOC 2 Type II as the standard evidence of a compliance programme. Choosing SOC 2 or ISO 27001 first is largely a question of where a firm’s enterprise clients are based.
ISO 27001 is an international standard that certifies the design and operation of an information security management system. It is required by some European clients and is increasingly accepted alongside SOC 2 as global enterprise procurement becomes more sophisticated. The two standards have significant overlap and can be pursued together more efficiently than sequentially.
For most Canadian accounting firms serving Canadian and US enterprise clients, SOC 2 Type II is the priority. Firms with UK or European clients, or those seeking to position themselves for international advisory work, benefit from pursuing ISO 27001 alongside or shortly after SOC 2.
How Long Does Compliance Readiness Take?
SOC 2 Type I, which attests that controls are appropriately designed, typically requires three to six months of preparation depending on the firm’s starting point. Type II, which requires evidence that controls operated effectively over a monitoring period, adds a further six to twelve months of operation after Type I. How long compliance readiness take depends heavily on the firm’s starting posture and how the evidence work is resourced.
Firms that attempt compliance preparation without a structured programme consistently underestimate the documentation burden, spend significant partner and management time on evidence gathering, and delay the audit start. A managed compliance programme runs the process with dedicated resources, allowing firm leadership to focus on practice operations while compliance progresses in parallel.
What Does a Compliance Readiness Programme Look Like in Practice?
Armour Cybersecurity’s Integrated Compliance Audit Programme begins with a gap assessment against SOC 2 Trust Services Criteria and, where applicable, ISO 27001 Annex A controls. The assessment identifies which controls are in place, which are partially implemented, and which are absent, and produces a remediation roadmap with timelines.
Remediation covers policy documentation, technical control implementation, staff training, and vendor risk assessment. Armour works alongside the firm to build the evidence base that the audit requires, rather than producing reports and leaving implementation to the firm.
The result is a documented compliance programme that can respond to client questionnaires with evidence, support formal audits, and provide the attestation that cyber insurers request at renewal.
How Does Compliance Readiness Affect Cyber Insurance?
Cyber insurers are increasingly declining coverage or applying exclusions to firms that cannot demonstrate documented controls. Questionnaires at renewal now ask many of the same questions as client security questionnaires, and insurers verify responses through technical checks and third-party assessments.
A firm with documented SOC 2-aligned controls, evidence of MFA deployment, a tested incident response plan, and an annual penetration test presents a significantly more favourable risk profile to insurers. Coverage terms and premium levels reflect that risk profile.
Across the 260+ organizations Armour Cybersecurity protects in 52+ industries, the accounting firms that sail through client questionnaires are the ones that built the evidence base once and reused it everywhere, the same documented controls answering the RFP, satisfying the auditor, and lowering the insurance premium, so compliance stops being three separate fire drills a year and becomes a single asset the firm already owns.
Frequently Asked Questions
Do we need a formal SOC 2 audit, or is a questionnaire response enough?
It depends on the client. Many enterprise clients accept a well-completed questionnaire with supporting evidence for initial engagements and request a formal SOC 2 report at audit renewal. Others require the report before the first mandate. Building the compliance programme prepares the firm for both; the formal audit simply validates what the programme has already built.
Can we use our IT provider’s SOC 2 report to answer client questionnaires?
A vendor’s SOC 2 report covers the vendor’s controls, not the firm’s. Clients asking about the accounting firm’s security programme want evidence of the firm’s own controls: how the firm manages access, protects data, and responds to incidents. Relying on a vendor’s report as a substitute for the firm’s own programme will not satisfy a sophisticated procurement team.
How do we handle questionnaires while our compliance programme is in progress?
Armour provides questionnaire support during the readiness period, helping firms respond accurately to current controls while documenting the remediation roadmap. Transparency about an active compliance programme is more credible than a questionnaire that overstates current capabilities. Many enterprise clients accept firms at different stages of a compliance journey, provided the journey is documented and progressing.
What happens if we lose an engagement because we cannot answer a questionnaire?
The lost engagement cost typically far exceeds the cost of a compliance programme. More importantly, the underlying risk that the questionnaire is designed to identify, inadequate controls over client financial data, remains. A compliance programme addresses both the competitive requirement and the actual risk at the same time. Building the compliance programmes that questionnaires require protects the client relationship and the client data in one move.
The Bottom Line
Client security questionnaires are no longer a formality that a reassuring sentence can satisfy. Enterprise audit and advisory clients want documented evidence that their accounting firm manages access, protects data, tests its defenses, and can respond to an incident, and they increasingly want SOC 2 Type II or ISO 27001 behind those answers. The firms that win and keep enterprise mandates treat compliance as an asset built once and reused across every questionnaire, audit, and insurance renewal, rather than a scramble triggered by each new RFP. Armour Cybersecurity helps accounting firms and CPA practices build the cybersecurity and compliance programmes accounting firms need, so the security section of the next RFP becomes a reason clients choose the firm rather than a reason they look elsewhere.
About the author
David Chernitzky is the CEO and Co-Founder of Armour Cybersecurity, a Toronto-based firm that protects organizations across North America from advanced cyber threats. He brings more than 25 years of cybersecurity and military cyber intelligence experience, having served as an officer in an elite technology unit before co-founding Armour. Armour’s team of military-intelligence veterans and senior advisors serves 260+ clients across 52+ industries with a 97% client retention rate. Learn more about Armour Cybersecurity.

