Selling Case Management Software to Law Firms? The Pen Test Questions to Expect

Selling Case Management Software to Law Firms? The Pen Test Questions to Expect

By EJN Labs · 21 Aug 2026 · 8 min read

Law firms buying case management software will ask you for penetration test evidence because SRA standards security assurance duties make them accountable for client confidentiality, even when data sits in your platform. Expect questions on test scope, tester accreditation, retest evidence and report age. A web application and API test from a CREST-accredited firm typically takes 5 to 8 days at £1,100 to £1,400 per day, so £5,500 to £11,200.

Why SRA standards security assurance lands on your desk, not the firm’s

SRA security assurance lands on your desk because regulated firms stay accountable to the Solicitors Regulation Authority for client information held in your platform, and the only way a compliance officer can discharge that accountability is to demand assurance evidence from you, the vendor.

If you sell case management, practice management or legal accounting software into SRA-regulated firms, you have probably noticed the security questionnaires getting longer. The SRA holds firms to strict confidentiality and client money duties under its Standards and Regulations, and those duties do not stop at the firm’s own network when case files, privileged correspondence and client account ledgers sit in your platform.

To be straight about it: the SRA Standards and Regulations contain no clause saying “your software supplier must commission a penetration test”. The regime is outcomes based: firms must keep client affairs confidential and safeguard money entrusted to them. Penetration testing has become the standard evidence firms request from suppliers because it is the most direct way to show those outcomes are met by the systems that hold the data. Treat the pen test as a sales asset, not a regulator’s tick box.

What the law firm is actually worried about

Understanding the buyer’s exposure helps you answer well. Three things keep legal compliance officers awake:

  • Confidentiality of privileged material. A breach of your platform is, in the client’s eyes and the SRA’s, a breach of the firm. Firms cannot outsource the duty even though they have outsourced the hosting.
  • Client money. Many case management suites integrate with legal accounting and client account workflows. Anything that touches payment details or ledgers gets extra scrutiny, because the SRA Accounts Rules make firms strictly responsible for client funds.
  • Their own audit trail. Insurers, lenders’ panels and large commercial clients question firms about supplier assurance. Your pen test report becomes part of their evidence pack, which is why its age, scope and author matter.

We cover the firm’s side of this picture in our guide to penetration testing for law firms; it is essentially the brief your prospect’s compliance officer is working from.

The pen test questions law firms will ask you

These questions come up again and again in legal sector due diligence, roughly in this order:

  1. When was your last penetration test, and can we see the report or a summary letter? Reports older than twelve months usually fail review. Many firms now ask for the executive summary plus a remediation confirmation rather than the full technical report.
  2. Who performed it? Testing by a CREST-accredited firm carries far more weight than an internal review or an automated scan. Expect the accreditation to be checked.
  3. What was in scope? A test of your marketing website will not satisfy anyone. Firms want the production application, its APIs, the authentication layer and the cloud environment that hosts their data.
  4. Does the test cover multi-tenancy? This is the question that separates legal buyers from generic ones. They want evidence that one firm’s users cannot reach another firm’s matters, documents or ledgers.
  5. Were findings fixed and retested? A report full of open highs is worse than no report. Retest evidence closes the loop.
  6. How do you handle client account and payment flows? If your product touches money movement, expect the questioning to go a level deeper on authorisation controls and audit logging.

What to test before the questionnaire arrives

For a typical legal SaaS platform, the assurance package that satisfies law firm due diligence has three layers:

First, the web application and its APIs. Case management products are document heavy and role heavy, so authorisation testing is the core of the engagement: matter level permissions, document sharing links, conflict walls, and the API endpoints that mobile apps and integrations call. Our API penetration testing work on legal and professional services platforms consistently finds the highest severity issues in object level authorisation, where one tenant’s record identifiers can be read or modified from another tenant’s session.

Second, the cloud environment. Firms ask where UK client data lives and how hosting is configured. A cloud penetration test of your AWS or Azure estate covers storage permissions, identity boundaries between environments, and backup exposure.

Third, the external perimeter: admin panels, VPN endpoints, staging systems. These are cheap to test and exactly where attackers look first.

What it costs and how scope drives the price

UK penetration testing is priced by tester days. Typical day rates run from £1,100 to £1,400, and the day count is driven by the size of the application, the number of user roles and API endpoints, and whether cloud configuration is included. Typical ranges for a legal software vendor look like this:

EngagementTypical effortTypical cost
Web application and API test (core product)5 to 8 days£5,500 to £11,200
Cloud configuration review (AWS or Azure)3 to 5 days£3,300 to £7,000
External infrastructure test2 to 4 days£2,200 to £5,600

These are typical UK ranges rather than a quote; a short scoping call fixes the day count before any work starts. For a fuller breakdown of what moves the numbers, see our guide to penetration testing cost in the UK. One commercial note: an annual test of the core product plus a retest usually costs less than a single lost enterprise law firm deal, and the same report can be reused across every prospect’s due diligence for the following twelve months.

EJN Labs is a CREST-accredited penetration testing firm, certified to ISO 27001 and Cyber Essentials Plus, with UK-based testers only. When we scope a case management or legal accounting platform, we start from the buyer’s perspective: we ask for your role model and tenant architecture up front, then build test cases around the boundaries that matter to a law firm reviewer, such as cross-tenant access to matters and documents, privilege escalation between fee earner and admin roles, and the integrity of audit logs that firms rely on for their own SRA evidence. We test against staging with production-equivalent configuration where possible, so client data is never put at risk during the engagement.

Deliverables are written for two audiences: a technical report your engineers can action, and an executive summary you can hand to a prospect’s compliance officer without redaction anxiety. We include a free retest of fixed findings, so the document you share shows closure, not just discovery. If you are comparing suppliers, our notes on choosing the best UK penetration testing provider set out the questions worth asking, and our CREST penetration testing page explains what the accreditation covers.

Frequently Asked Questions

Do the SRA Standards and Regulations require my software to be penetration tested?

Not directly. The SRA Standards and Regulations impose confidentiality and client money duties on regulated firms, not on their suppliers, and no clause names penetration testing. In practice, though, firms discharge those duties by requiring security assurance from their software vendors.

An independent penetration test is the evidence most commonly requested during due diligence and contract renewal.

What does a penetration test cost for a case management vendor?

Expect £5,500 to £11,200 for a web application and API test of a case management product, which usually takes 5 to 8 days at UK day rates of £1,100 to £1,400. A cloud configuration review adds £3,300 to £7,000 and an external infrastructure test £2,200 to £5,600.

In day terms the cloud configuration review adds 3 to 5 days and the external infrastructure test 2 to 4 days. Exact pricing comes from a short scoping call.

How recent does the pen test report need to be for law firm due diligence?

Within the last twelve months is what most law firm reviewers expect, covering the current major version of the product. Annual testing aligned to your release cycle is the practical standard for keeping a report of that age always on hand.

If you have shipped significant changes to authentication, tenancy or payment flows since the last test, expect sharper questions and consider a targeted retest of those areas.

Should I share the full penetration test report with prospects?

No, usually not. Full reports contain technical detail that helps attackers if leaked. Share an executive summary or attestation letter stating scope, methodology, tester accreditation and confirmation that findings were remediated and retested, keeping the full report for NDA-backed requests.

The full report is commonly made available under NDA for enterprise buyers who insist, and a well written summary satisfies most legal sector reviews.

Does multi-tenancy testing matter if each firm has its own database?

Yes. Separate databases reduce risk but do not remove it, because the application layer, APIs, shared services and admin tooling still span tenants. Testers look for flaws in session handling, object references and background jobs that could cross firm boundaries regardless of the storage model.

Law firm reviewers ask about tenancy testing because privilege makes cross-firm exposure uniquely damaging.

If law firm due diligence is slowing your deals, the fastest fix is a current test from an accreditation your buyers recognise. Tell us about your platform and we will come back with a fixed scope and day count. Get a CREST penetration testing quote and turn the security questionnaire into a closing asset rather than a blocker.

Leave a Reply

Your email address will not be published. Required fields are marked *