"It Has to Go Through Security and Legal Review" — Keeping a Deal Warm Through Six Weeks of Paperwork
The technical win is done and the deal vanishes into InfoSec questionnaires and outside counsel redlines. Here is how to run that dead zone instead of waiting it out.
The moment the deal goes quiet
You did everything right. The technical win is locked. The champion has told you, in words, that you are the vendor they want. Procurement has a number they can live with. And then someone on the call says the sentence that eats your quarter:
"Great. It just has to go through security and legal review."
Everybody nods. The meeting ends on a high. And then nothing happens for six weeks.
This is the dead zone, and it is where more good deals die than in any competitive bake-off. Not because you lost. Because the deal stopped being a deal and became a document sitting in someone else's queue, and you had no way to touch it. Your champion goes quiet because they have nothing to report. You send a check-in email. They reply "still with InfoSec, will keep you posted." You send another one two weeks later. Now you are the vendor who nags.
Meanwhile the buying committee's memory of why they wanted this is decaying. The pain that drove the project is being managed around. Someone new joins the team. Budget cycles move. By the time the questionnaire clears, you are not closing a hot deal, you are restarting a lukewarm one.
The fix is not more follow-up. The fix is treating security and legal review as a workstream you run, with its own stakeholders, its own timeline, and its own set of calls, rather than a black box you wait outside of.
Start the questionnaire before you have a verbal
The single biggest change I would make to how most reps sell is this: stop treating the security questionnaire as a post-decision activity.
The conventional sequence is discovery, demo, technical validation, verbal commitment, then paperwork. Which means the clock on the longest, least controllable part of the deal does not start until everything else is finished. You have compressed all your risk into the end.
Flip it. The moment you have a real evaluation underway — not a first call, but an actual pilot or a technical deep-dive with the people who will use the thing — you ask this question:
"When you have brought in a tool like this before, at what point does security get involved? I would rather get them what they need early than surprise them at the end."
That question does three things. It signals you have done this before. It gets you the name of the security function. And it gives you permission to start the paperwork in parallel with the evaluation instead of after it.
Then you make the offer that almost nobody refuses:
"Here is what I can do. I will send you our SOC 2 report, our pen test summary, our subprocessor list and our standard DPA today. If your team has a questionnaire they use, send it over and I will have it back before we finish the pilot. Worst case you have a filled-out questionnaire for a vendor you did not pick. Best case we save a month at the end."
The objection you will hear is "we do not want to waste your time before we have decided." Answer it honestly. It is not a waste of your time. It is the cheapest month you will ever buy. Say that out loud.
In financial services this is close to mandatory rather than clever. Third-party risk management at a bank or a wealth manager is not a formality bolted onto the end of a purchase — it is the purchase, and the risk team has veto power the business side does not. When I am working a wealth management or asset management buyer, the vendor diligence conversation belongs in the first few calls alongside the business pain, which is why the discovery playbook I use for financial services buyers puts the "who has to approve this besides you" question early rather than saving it for a close plan at the end.
Find out who actually reviews it, and how deep the queue is
Here is what most reps know at the point their deal enters review: "it is with security."
Here is what you need to know:
Who is the individual reviewer. Not the department. A human with a name. Is it an internal InfoSec analyst, a GRC team, an outsourced vendor risk firm, or one overworked person who also runs the help desk?
What is in front of you in that queue. Vendor risk teams work a backlog. If there are eleven assessments ahead of yours and they clear a handful a week, that is your real timeline, and it has nothing to do with how good your SOC 2 is.
What tier your purchase falls into. Most mature risk programs classify vendors by data sensitivity and criticality. A tool that touches customer PII gets a different treatment than a tool that does not. A low-tier review might be a short questionnaire and a certificate check. A high-tier review might mean an architecture call, a pen test review, and a business continuity questionnaire. If you do not know which track you are on, you cannot forecast the deal.
Whether legal runs in series or parallel. This one kills timelines quietly. In a lot of organizations, legal will not start the redline until security signs off. If that is the case, your six weeks is actually security's three weeks plus legal's three weeks, back to back, and the only lever you have is asking whether they can overlap.
Whether outside counsel is involved. If the contract goes to an external firm, add time and subtract predictability. Outside counsel bills by the hour and prioritizes by client urgency, which means your deal moves when your champion's general counsel picks up the phone and says move it.
You get all of this by asking. Not by guessing. The call sounds like this:
"Before this goes over, help me understand the process on your side. Who does the review — is that an internal team or do you use a third party? Roughly how many of these do they have in front of them right now? And does legal start their part in parallel or do they wait for security to clear?"
No buyer has ever been offended by that. Most of them do not know the answers, which is itself useful — it means you are going to help them find out, and now you have a legitimate reason to be on the phone with someone new.
Get on a call with the reviewer
A questionnaire is a lossy format. Sixteen tabs of yes-no answers, and any one "no" or "partial" can bounce the whole thing back for another cycle.
So ask for the reviewer. Frame it entirely as service:
"Rather than us going back and forth on email, could we get twenty minutes with whoever is reviewing? I would rather they ask me the hard questions live. If there is something in our architecture they are going to flag, I would rather know in week one than week five."
On that call, do not sell. Nobody in a security review wants to hear about ROI. Bring your solutions engineer, bring your documentation, and let the reviewer drive. Take notes on every concern, and be straight when the answer is unflattering. If you do not do customer-managed encryption keys, say so, and say what compensating controls you have and what is on the roadmap. Reviewers have a very good ear for a rep who is bluffing, and the cost of getting caught is not a lost point, it is a formal exception process that adds a month.
The secondary benefit is that you now have a relationship inside the function that is holding your deal. When the file goes quiet, you have somebody to ask other than your champion.
Give your champion something they can forward
Your champion is not sitting in these meetings advocating for you. They are doing their actual job. When the review stalls, the reason is usually not opposition — it is that nobody has a reason to prioritize it, and your champion does not have the language to create one.
So write it for them.
After the reviewer call, send your champion a short internal summary. Not a marketing one-pager. Something that reads like it was written by an employee of their company. Five short paragraphs:
What we are buying and why, in one line. The business case in two sentences, with the dates that matter — the renewal we are replacing, the audit deadline we are ahead of, the headcount plan that assumes this is in place.
What the security posture is. Certifications held, where data lives, what the reviewer asked about and how we answered.
What is outstanding. Any open item, named honestly, with a date we will close it.
What happens if this slips. This is the paragraph most reps leave out, and it is the one that moves things. "If contracting is not complete by the 15th, onboarding pushes into the holiday freeze and go-live moves to February." A cost of delay expressed in dates, not in dollars you made up.
Who needs to do what next. One line per person.
Then tell your champion, explicitly: "Feel free to forward this or paste it into an email, no attribution needed. I wrote it so you do not have to."
I have watched deals move a month faster on the strength of one forwardable summary, because it turned a champion who had to reconstruct the argument from memory into a champion who could hit forward. Make it easy to advocate for you and people will.
Set milestone dates so you can call without nagging
The reason check-in emails feel like nagging is that they carry no information. "Just checking in" is a request for the buyer to do work on your behalf.
The alternative is a mutual timeline with named dates and named owners, agreed on a call before the deal enters review. It does not need to be a fancy mutual action plan document. It needs to be six lines in an email you both said yes to.
Questionnaire returned to InfoSec by the 4th, me. Reviewer call held by the 11th, them to schedule. Security sign-off by the 18th, their reviewer. MSA and DPA to legal by the 18th, parallel start, their counsel. Redline back to us by the 25th. Signature by the 31st.
Now every call you make has a purpose that is not "do you have news." On the 12th you call because the reviewer call was supposed to happen by the 11th and it did not, and the question is whether that pushes the sign-off date or whether we can hold it. That is not a nag. That is project management, and buyers who are drowning in this stuff are often grateful for it.
When a date slips — and one will — do not let it slip silently. Re-baseline out loud. "Sign-off moved to the 22nd, so unless legal starts in parallel this week we lose the 31st. Which of those two do you want to fight for?"
That question forces a choice and tells you a great deal about how real the deal is.
Protect your price while you wait
Six weeks of paperwork is six weeks during which the deal's economics are exposed. Procurement now has time. Somebody circles back to a competitor. A CFO asks whether the number could be smaller given how long this took.
The defense is set up early. Tie any concession you have already made to a date, and say it once, cleanly, without threatening: "The pricing we discussed assumes a signature this quarter. If we land in the next one I will have to re-approve it, and I would rather not go back and ask."
Then hold. The dead zone is when reps get soft, because the waiting makes them anxious and a discount feels like a way to make something happen. It is not. The delay is procedural, not economic, and giving money away does not shorten a security queue.
The same logic runs through the way I coach holding your number in legal-sector negotiations once the firm has already chosen you and holding price after a security team has cleared you. Once you have passed review, your leverage went up, not down. Reviewing a new vendor is expensive for them. Do not price as if you are still competing.
When review is a soft no
Sometimes "it has to go through security and legal" means exactly what it says. Sometimes it is the politest available way of saying we are not doing this and I do not want to tell you.
Here is how you tell the difference.
Real review has names attached. Fake review is always passive. "It is with security." "Legal is looking at it." Ask who and you get vagueness. If your champion cannot name the reviewer after two attempts, the deal is not in review, it is in a drawer.
Real review generates friction. Questions come back. Somebody wants a call about data residency. Somebody redlines the limitation of liability clause. Silence is not what a live process sounds like. A file moving through a real risk function makes noise.
Real review has a budget behind it. If nobody can tell you which cost center this is coming from or when the funds are available, security is not the obstacle.
Real champions will take a meeting. Offer a fifteen-minute call to review the timeline. A champion whose deal is alive will take it. A champion who is stalling you will keep it in email.
When you suspect a soft no, do not accuse. Give them a graceful exit and see whether they take it:
"I want to make sure I am reading this right. Sometimes when a review takes this long it is genuinely a queue problem, and sometimes it means priorities shifted and nobody wants to be the one to say it. Either is completely fine — I just want to know which one I am dealing with so I stop bothering you if it is the second one."
Almost everyone answers that honestly. The ones who say "no, it is real, it is just slow" will usually tell you something concrete right after, because you gave them the chance to be candid and they took the other branch. The ones who go quiet after that email have told you what you needed to know. Take them out of the forecast and stop spending your Tuesdays on them.
Diligence is not a formality, it is the relationship
There is an upside to all of this that reps in fast-moving segments never get to enjoy.
In banking, insurance, wealth management and law, getting through vendor risk assessment is a moat. It is slow and expensive and nobody wants to do it twice. Once you are an approved vendor with a signed MSA and a completed security file, you are structurally advantaged against every competitor who is not, and expansion conversations start from a completely different place — which is the whole premise behind expanding a financial services account without restarting vendor diligence.
So run the review well. Be the vendor whose questionnaire came back complete and accurate on the first pass. Be the one whose legal team did not fight over indemnity caps for three weeks. Reviewers talk to each other, and a reputation for being easy to diligence is worth more in these industries than a feature.
If you want to get better at the calls that hold a deal together through the dead zone — the reviewer call, the re-baseline call, the "is this real or is this a soft no" call — the thing I would do next is rehearse them out loud before you make them, because they are the calls reps have the least reps at. That is what we built DrillCall for: running the conversations you only get a handful of chances at each quarter until the words come out steady.
Six weeks of paperwork does not have to be six weeks of silence. It just has to be six weeks with dates on it.