By David Chernitzky, CEO, Armour Cybersecurity · Serving Toronto and organizations across North America · Last updated August 26, 2026
Quick Answer
Enterprise legal departments, financial institutions, and government contractors are routinely requiring law firms to pass a security questionnaire before engaging them on sensitive matters. These questionnaires map to SOC 2, ISO 27001, or NIST CSF and ask about controls that most law firms have not formally documented. Firms that cannot answer credibly lose matters to competitors who can. A compliance readiness programme builds the documented controls that turn a law firm security questionnaire from guesswork into evidence.
Key Takeaways
- Client security questionnaires for law firms typically cover access management, encryption, incident response, vendor risk, business continuity, and security testing.
- SOC 2 Type II attestation is the most commonly requested credential from enterprise US and Canadian clients engaging law firms on sensitive matters.
- Questionnaires are increasingly pass/fail criteria for matter selection, not negotiating points. Firms that cannot respond forfeit the work.
- A compliance readiness programme built against SOC 2 or ISO 27001 standards simultaneously satisfies Law Society obligations, client requirements, and cyber insurance conditions.
- The time to begin a compliance programme is before a large client sends a questionnaire, not after losing a matter because of an inadequate response.
Why Are Enterprise Clients Sending Security Questionnaires to Their Law Firms?
General counsel and legal operations teams at large corporations, financial institutions, and government agencies have recognized that their outside law firms hold the most sensitive information their organizations generate. M&A strategy, litigation position, regulatory exposure, and IP disputes sit in law firm document management systems that the client has limited visibility into and no direct control over.
The questionnaire is the client’s mechanism for assessing whether the firm has the controls to protect that information. It is driven by the same third-party risk management logic that has pushed vendor security requirements across every industry. A law firm is a vendor holding client data, and clients are applying the same scrutiny to their legal service providers that they apply to their technology vendors.
The stakes for firms are concrete. A questionnaire response that reveals the absence of MFA, no tested incident response plan, and no independent security testing will cost the firm the matter. This is not a future risk. Law firm partners across North America are reporting that major clients have declined or conditioned engagements on security questionnaire responses for the first time, and the volume of questionnaires is increasing year over year.
What Do These Questionnaires Actually Ask?
Access Management and Authentication
Questionnaires consistently ask whether the firm enforces multi-factor authentication on all systems containing client data, how access is provisioned for new lawyers and staff, how access is revoked when people leave, and whether privileged access to IT systems is separately managed. These questions map directly to SOC 2 Common Criteria 6 and ISO 27001:2022 access control (A.5.15 and related technological controls). A firm that can describe its access management controls with documented policies and evidence of implementation answers these questions with confidence.
Data Classification and Encryption
Enterprise clients ask how client data is classified, encrypted when stored, and protected in transit. The question extends to email communications, document management platforms, portable devices, and cloud storage. Firms that send unencrypted client documents by default, store files on unencrypted laptops, or use cloud storage with default settings rather than configured encryption will struggle to answer these questions satisfactorily.
Incident Response
A documented incident response plan with defined roles, communication procedures, notification timelines for clients and regulators, and evidence of testing is a standard questionnaire requirement. Clients want to know that if their matter files are compromised, the firm will detect it promptly, contain it effectively, and notify them in a timeline that allows them to manage their own response. A plan that has never been tested and exists only as a document does not satisfy this requirement.
Vendor and Third-Party Risk
Law firms use legal technology vendors, e-discovery providers, court e-filing platforms, cloud storage services, and outsourced support functions. Questionnaires ask how these vendors are assessed before engagement, what contractual security standards govern their access to client data, and how vendor access is monitored. A firm that has not formally assessed the security of its legal technology stack and does not have documented vendor risk procedures cannot answer these questions accurately.
Security Testing
Annual independent penetration testing of firm systems, document management, remote access infrastructure, and client portals is increasingly expected as a baseline rather than an optional practice. Questionnaires ask when the last penetration test was conducted, who conducted it, and what findings were addressed. A firm that cannot provide a recent penetration test report from an independent provider is unlikely to pass the security questionnaire of a sophisticated enterprise client.
What Is SOC 2 and Why Is It the Most Requested Standard?
SOC 2 is a report produced by an independent auditor that attests to the design and operating effectiveness of an organization’s controls against the AICPA Trust Services Criteria. The criteria cover security, availability, processing integrity, confidentiality, and privacy. For law firms, the security and confidentiality criteria are most relevant to client questionnaire requirements.
SOC 2 Type I covers controls as designed at a point in time. SOC 2 Type II covers controls as operated over a defined period, typically six to twelve months. Enterprise clients requesting SOC 2 attestation almost always want Type II, which demonstrates that controls have been consistently operating, not just that they were in place on the day of the audit. This means the compliance journey involves building and operating the controls, not just documenting them.
ISO 27001 is an international certification that validates the design and operation of an information security management system against an international standard. It is accepted alongside SOC 2 by most enterprise clients and is required by some European clients and multinational corporations. For firms advising on cross-border matters or seeking to expand into international client markets, ISO 27001 provides credibility that SOC 2 alone may not deliver in all jurisdictions.
What Does a Compliance Readiness Programme Actually Look Like?
A compliance readiness programme begins with a gap assessment that measures the firm’s current controls against the SOC 2 Trust Services Criteria or ISO 27001 Annex A requirements. The assessment identifies which controls are in place, which are partially implemented, and which are absent, and produces a remediation roadmap with priorities and timelines.
Remediation covers policy documentation, technical control implementation, staff training, vendor risk assessment, and incident response plan development and testing. For a law firm, the most common gaps are MFA enforcement that is optional rather than mandatory, document management platforms with default configurations rather than security-hardened settings, and the absence of a tested incident response plan.
After remediation, the firm operates its controls through the monitoring period required for Type II attestation, with evidence collected by the compliance programme rather than assembled under audit pressure. The result is a control environment that can respond to questionnaires with evidence, support a formal SOC 2 or ISO 27001 audit, and produce the documentation that cyber insurers request at renewal.
Armour Cybersecurity’s Integrated Compliance Audit Programme manages this process end to end. The programme covers gap assessment, remediation roadmap, control implementation support, evidence collection, and audit preparation, delivered as part of the law firm cybersecurity services Armour provides, with ongoing governance to maintain the programme as the firm’s technology environment and client security requirements evolve.
How Does Compliance Readiness Interact With Law Society Obligations?
The controls that SOC 2 compliance requires are largely the same controls that Law Society professional conduct rules expect lawyers to implement as reasonable safeguards for client confidential information. Building a SOC 2 compliance programme simultaneously addresses the professional responsibility obligation to take reasonable steps to protect client data, and produces the documented evidence that demonstrates those steps were taken.
In the US, the documented controls and evidence that SOC 2 produces are directly relevant to the reasonable-effort standard under ABA Rule 1.6(c). A firm that can demonstrate a SOC 2-aligned control environment has a defensible position in a professional discipline or negligence proceeding following a breach. A firm that cannot document its controls has no such position.
Across the 260+ organizations Armour Cybersecurity protects in 52+ industries, the law firms that answer these questionnaires in an afternoon rather than a fire drill are the ones who built the programme before a client asked. They ran the gap assessment, closed the MFA and document-management gaps, tested the incident response plan, and let the evidence accumulate on its own, so when a general counsel sends fifteen pages of security questions, the firm attaches its SOC 2 report and a current penetration test instead of scrambling to invent answers it cannot support.
Frequently Asked Questions
How long does it take to become SOC 2 Type II ready?
SOC 2 Type I, which covers controls as designed, typically requires three to six months of preparation from the gap assessment, depending on how many controls need to be built from scratch. Type II adds a monitoring period of six to twelve months during which the controls must operate consistently before the auditor can attest to their effectiveness. The full Type II journey from starting a compliance programme to having an attestation report typically takes twelve to eighteen months. Starting now means having the attestation when the next large client questionnaire arrives.
What if a client sends a questionnaire before our programme is complete?
Transparency about an active compliance programme is more credible than a questionnaire that overstates current capabilities. A firm that can describe its gap assessment results, show a remediation roadmap with progress against it, and demonstrate that controls are being built systematically presents a more compelling picture than a firm that cannot account for its current state at all. Armour provides questionnaire support throughout the readiness period, helping firms respond accurately and constructively.
Can we use a vendor’s SOC 2 report to answer questionnaire questions about our firm?
A vendor’s SOC 2 report covers the vendor’s controls, not the firm’s. Clients asking about the law firm’s security programme want evidence of the firm’s own access management, encryption, incident response, and testing. Relying on a cloud storage vendor’s SOC 2 as the firm’s security attestation will not satisfy an enterprise client’s questionnaire and may raise questions about the firm’s understanding of what the questionnaire is asking.
Does compliance readiness require replacing our current IT provider?
Not necessarily. Compliance readiness is about the firm’s documented controls and evidence, not a specific IT infrastructure. Armour works alongside existing IT providers to build the security programme layer that sits above infrastructure management. The IT provider manages systems; the compliance programme documents the controls, collects evidence, and produces the attestations that clients and auditors require. In some cases, existing IT configurations need to change to meet specific control requirements, but those changes are identified during the gap assessment and scoped as part of the remediation roadmap.
The Bottom Line
The client security questionnaire has quietly become a gate on legal work: pass it and win the matter, fumble it and watch the mandate go to a firm that can prove its controls. The questions are not mysterious, they map to SOC 2, ISO 27001, and NIST CSF and cover access, encryption, incident response, vendor risk, and testing, but they demand evidence, not assurances. The firms that answer with confidence are the ones that treated compliance as a programme built ahead of demand: a gap assessment, a remediation roadmap, controls that actually operate, and evidence that accumulates on its own. That same programme satisfies Law Society obligations and cyber insurance conditions in one build. Armour Cybersecurity helps law firms build law firm cybersecurity services and the SOC 2 or ISO 27001 readiness behind them, so a security questionnaire becomes a reason the firm wins sensitive work rather than a reason it loses it.
About the author
David Chernitzky is the CEO and Co-Founder of Armour Cybersecurity, a Toronto-based firm that protects organizations across North America from advanced cyber threats. He brings more than 25 years of cybersecurity and military cyber intelligence experience, having served as an officer in an elite technology unit before co-founding Armour. Armour’s team of military-intelligence veterans and senior advisors serves 260+ clients across 52+ industries with a 97% client retention rate. Learn more about Armour Cybersecurity.



