Security reviews

What does law firm vendor due diligence ask of legal tech sellers?

Expect a security questionnaire, a request for your security documents and contract terms, and pointed questions on data retention and breach notice. Larger firms report more security demands from their own clients (ABA, 2023), so their reviews typically go deeper.

Book a demo

The short answer

Law firm vendor due diligence typically means a security questionnaire, a request for your security documents and terms, and questions on data retention and breach notice. Firms ask because lawyers must make reasonable efforts to protect client information, and their own clients ask the same of them. Clean finds law firms and legal teams with a real reason to buy what you sell.

Key takeaways

  • Expect a security questionnaire, a request for security documents and terms, and questions on retention and breach notice.
  • In the ABA's 2023 survey, half of respondents at firms over 100 lawyers had been asked for a security questionnaire.
  • ABA Opinion 512 lists vendor checks: credentials, security policies, hiring, confidentiality agreements, conflicts checks, a legal forum.
  • No bar rule we found requires SOC 2. Florida Bar cloud notes name SOC 2 Type 2 and ISO 27001.
  • CLOC tells in-house legal operations teams to do due diligence on prospective vendors and to partner with internal IT.
01

What does law firm vendor due diligence ask for?

Expect a security questionnaire, a request for your security documents and contract terms, and direct questions about how long you keep the firm's data, who owns it and how fast you will report a problem. The documents are typically your security policies, any independent audit report or certificate, your terms of use, privacy policy and a confidentiality agreement. Larger firms report more security demands from their own clients, so their reviews typically go deeper.

The review runs in both directions. Clients send law firms security requirements. Firms then vet their own vendors, because ABA Model Rule 1.6(c) says a lawyer shall make reasonable efforts to prevent unauthorized disclosure of, or access to, client information, and ABA ethics opinions spell out what that means for outside vendors. Part of what a firm asks you can trace back to what its own clients ask it.

The ethics opinions and bar guidance below are context, not legal or compliance advice. Read each rule's own text and check with your own counsel. AI-specific questions are covered in selling AI to law firms; who runs the evaluation at each firm size is in how to sell to law firms.

02

Clients push security reviews down to law firms, larger firms most

The ABA's 2023 Cybersecurity TechReport (December 18, 2023) summarizes a single survey, the ABA's 2023 Legal Technology Survey, including what clients and potential clients asked of firms. Overall, 27% of respondents had been asked for the firm's security requirements document or guidelines, and 22% had been asked to complete a security questionnaire. At firms of over 100 lawyers, both figures were 50%. Only 14% had a client request an actual security audit or review.

The same report's 29% "security breach" figure counts lost or stolen devices and break-ins alongside hacking. The author warns a security breach is not necessarily a data breach, so never quote it as a breach rate.

The ILTA Technology Survey 2026 (508 responding firms, released September 14, 2026) says the high cost of technology now shares top billing among leadership concerns with security compliance and risk management, and generative AI entered its security challenge list for the first time in second place. Expect price and security to be weighed together.

Clients asking law firms for security proof, by firm size (ABA 2023 Cybersecurity TechReport, single survey)

Firm sizeAsked for the firm's security requirementsAsked to complete a security questionnaire
Solo9%4%
2 to 9 lawyers15%14%
10 to 49 lawyers41%27%
50 to 99 lawyers59%48%
Over 100 lawyers50%50%
All respondents27%22%
03

What the ABA tells lawyers to check in a vendor

ABA Formal Opinion 477R (revised May 22, 2017, on securing client communications) lists steps lawyers should take, including: "Conduct due diligence on vendors providing communication technology. Take steps to ensure that any outside vendor's conduct comports with the professional obligations of the lawyer." The rules bind lawyers, not vendors, but they decide what a lawyer has to ask you.

ABA Formal Opinion 512 (July 29, 2024) is about generative AI, but it restates the vendor checks from the ABA's earlier outsourcing opinions: reference checks and vendor credentials; the vendor's security policies and protocols; its hiring practices; confidentiality agreements; its conflicts check system; and a legal forum for relief if the vendor breaks the agreement. Drawing on cloud computing opinions, it adds checks any software seller will hear: is the confidentiality obligation enforceable, will the lawyer be notified of a breach or of service of process seeking client information, does the tool keep information after the service ends or claim rights in it, and what limits the vendor puts on its liability. It notes lawyers may need IT or cybersecurity experts to read those terms, one reason firm IT joins the review.

ABA Formal Opinion 483 (October 17, 2018) covers what happens after a breach. Lawyers must notify clients when a breach involves, or has a substantial likelihood of involving, material client information, must make reasonable efforts to monitor external vendors that handle data, and should consider an incident response plan. A firm cannot meet those duties if its vendor tells it late, which is why breach notice clauses get negotiated hard. This is background for why firms ask, never a selling angle: do not approach a firm about its own incident.

04

Do law firms require SOC 2?

No bar rule we found requires SOC 2. Neither Opinion 483 nor Opinion 512 names it, and no source we found measures how many firms require it. The closest written standard is from The Florida Bar's Standing Committee on Technology. Its "Due Diligence Considerations for Lawyers Evaluating Cloud Computing Service Providers" (March 2017, updated August 2021) says cloud service providers should host on reputable cloud services that have obtained one of a list of certifications or met similar indicia. The list starts with Type 2 SOC 2 and ISO 27001; the standards come from the Legal Cloud Computing Association, annotated by the committee.

Two lines in the same document matter: The Florida Bar takes no position on whether these standards define a lawyer's ethical or legal obligations, and its commentary says these certifications are sometimes requested by clients. Treat SOC 2 as an ask to expect, not a requirement.

The first question it tells lawyers to ask is whether you have obtained and maintained any of these certifications and, if not, what similar ones you hold. The standard is written about where you host, so your cloud provider's reports answer part of it, though a firm with a security team may want one on your own controls. No report yet? Say so and show what you have: written policies, your host's attestations, penetration test summaries and a dated plan. Ask early who signs off on vendor security, so a hard requirement comes up before contract.

05

What is in a law firm security questionnaire?

Each firm writes its own, but the Florida Bar's cloud notes are a fair preview. They ask where data is physically stored and backed up; whether it is encrypted at rest and in motion, and who holds the keys; what security testing you run, such as vulnerability scans and penetration tests, and who runs it; which third parties and subcontractors can reach client data; how data is returned and deleted when the relationship ends; login controls such as multi-factor authentication, user administration and audit logs; uptime commitments; and who owns the data.

The breach questions are specific: a clause requiring immediate notice of suspected unauthorized access (preferably within 48 hours of discovery, the notes say), what the notice will contain, cooperation in the investigation, indemnity for investigation costs and third-party claims, mandatory arbitration, and whether you carry cyber insurance. If anyone demands the firm's data, the notes say the provider must tell the firm as soon as possible unless the law prohibits it. Firms with healthcare clients may ask you to sign a HIPAA business associate agreement.

07

What to have ready before a law firm security review

A typical list, not a required one: every firm and legal department runs its own process. Keep one owner for every security answer, so the questionnaire, the contract and the sales call say the same thing.

Law firm vendor due diligence: what to have ready (typical, not a requirement)

You will be asked forWhy the buyer asksWhat to have ready
A security questionnaireClients send firms theirs; Opinion 512 names vendor security policiesA completed standard questionnaire, kept current, with one owner
Security policies and an independent report or certificateFlorida Bar cloud notes name SOC 2 Type 2 and ISO 27001Your report, your host's, or an account of what you have instead
Terms of use, privacy policy, confidentiality agreementOpinion 512 tells lawyers to read them and use confidentiality agreementsCurrent versions, and a view on signing the firm's NDA
Data retention, return and ownership termsOpinion 512 asks whether a tool keeps data after service ends or claims rights in itA retention schedule, return and deletion on exit, and firm ownership of its data
Breach notice and incident responseOpinion 483 requires lawyers to notify clients of breaches of material client informationA notice clause, a named contact, an incident response summary, cyber insurance details
Notice of legal processOpinion 512 says lawyers should be told of process seeking client informationA clause to tell the firm if anyone demands its data
Limits on liabilityOpinion 512 tells lawyers to check limits on a vendor's liabilityA liability and indemnity position you can defend
Hiring practices, references, conflicts screeningOpinion 512 lists hiring, references, conflicts checks and a legal forumBackground check and access policies, references, a governing law clause

Common questions

What security documents do law firms ask vendors for?

Typically a completed security questionnaire, your security policies, a SOC 2 Type 2 report or ISO 27001 certificate if you have one, your terms of use and privacy policy, and a confidentiality agreement. Expect questions on data retention, ownership, breach notice and incident response. ABA Formal Opinion 512 lists the vendor checks lawyers are told to make, and most requests map to that list.

Do law firms require SOC 2?

No bar rule we found requires SOC 2, and no source we found measures how many firms demand it. The Florida Bar's technology committee notes, updated August 2021, name Type 2 SOC 2 and ISO 27001 among indicia for cloud hosting and say clients sometimes request them, but the Bar takes no position on whether they define a lawyer's obligations. Have a report ready, or an honest account of what you have instead.

How do law firms vet software vendors?

They work from the diligence the ABA describes. Opinion 477R tells lawyers to do due diligence on vendors providing communication technology, and Opinion 512 lists reference checks, security policies, hiring practices, confidentiality agreements, the vendor's conflicts check and a legal forum for relief. Larger firms typically add a questionnaire and contract review, partly because their own clients send them security requirements and questionnaires.

What is in a law firm security questionnaire?

Each firm uses its own. The Florida Bar's cloud due diligence notes preview it: where data is stored, encryption and key access, security testing, third-party and subcontractor access, retention and deletion, login controls and audit logs, uptime, data ownership, breach notice (preferably within 48 hours of discovery), indemnity and cyber insurance. Keep one current set of answers.

Do in-house legal teams run the same security review?

Similar questions, different people. CLOC's Core 12 guidance tells legal operations teams to do due diligence on prospective vendors and to partner with the internal IT team, so the company's security team typically reviews you alongside procurement while legal operations runs the evaluation. Expect the company's own security standards to apply.

Sources

  1. 012023 Cybersecurity TechReport, American Bar Association, Law Practice Division, 2023-12-18
  2. 02ABA Formal Opinion 477R: Securing communication of protected client information, American Bar Association, YourABA, 2017-06
  3. 03Formal Opinion 512: Generative Artificial Intelligence Tools, ABA Standing Committee on Ethics and Professional Responsibility, 2024-07-29
  4. 04Formal Opinion 483: Lawyers' Obligations After an Electronic Data Breach or Cyberattack (third-party copy of the opinion text), ABA Standing Committee on Ethics and Professional Responsibility, hosted by lalegalethics.org, 2018-10-17
  5. 05ABA ethics opinion offers guidance on data breaches, ABA Journal, 2018-10-17
  6. 06Due Diligence Considerations for Lawyers Evaluating Cloud Computing Service Providers, The Florida Bar Standing Committee on Technology, 2021-08
  7. 07The ILTA Technology Survey 2026 Executive Summary, International Legal Technology Association, 2026-09-14
  8. 08ILTA Releases 2026 Legal Technology Survey Results: Revealing the Year Ahead, International Legal Technology Association, 2026-09-14
  9. 09CLOC Core 12: Firm and Vendor Management, CLOC (Corporate Legal Operations Consortium), 2024-09-27
  10. 10CLOC Core 12: Technology, CLOC (Corporate Legal Operations Consortium), 2024-09-27
  11. 11CLOC Releases 2026 State of the Industry Report, CLOC (Corporate Legal Operations Consortium), 2026-03-02

Next