GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

VND-002 Security Requirements in Vendor Contracts

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Contracts with all vendors who access, process, store or transmit organisational data include binding security and privacy requirements. These requirements address information security obligations, incident notification timelines, audit rights, data handling and deletion, right to subcontract, applicable law and exit provisions. Contracts with suppliers of ICT products and components include provenance, anti-tamper and component authenticity obligations, and contracts for outsourced development include the organisation's right to direct, monitor and review the work. Contracts for supplied components and external services require the supplier to describe the functional properties of the security controls the component or service implements, to provide design and implementation information for those controls at an agreed level of detail and to declare the functions, ports, protocols and services it uses. Agreements for alternate processing capacity carry priority-of-service provisions set against the recovery time objective they support.

Rationale

Contractual requirements are the primary enforcement mechanism for supplier security obligations; without written requirements the organisation has no recourse when a supplier causes a breach. The control information clauses exist because a receiving organisation cannot secure what it cannot describe: a component whose ports and protocols are undeclared cannot be fitted to a hardening baseline, and a control whose functional properties are unstated cannot be relied on or tested. Priority of service is the clause that decides whether alternate capacity is available in the event everyone else is also invoking it.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredrisk class duty

Art.25(4) reaches a general vendor contract wherever what the vendor supplies is used in or integrated into a high-risk system: the contract has to carry the information, capabilities, technical access and other assistance the high-risk provider needs to comply, which is a positive duty owed by the supplier and not one of the security, audit and exit clauses this control enumerates. AIG-032 holds the AI-specific assessment and the agreement with an AI provider; the row here exists because a component or service contract signed by procurement, with no AI review in front of it, can be the Art.25(4) agreement and usually lacks the clause.

Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
HIPAA Business Associate (US)stablerequiredrole duty

164.308(b)(3) and 164.314(a)(2)(iii) make the written subcontractor agreement and its terms a required specification, not a commercial preference. Assurances given in a questionnaire or a security review do not discharge it.

NIS2 Cloud Provider (EU)stablerequiredrole duty

Annex point 5.1.4 fixes eight contract terms and three are not in the control: requirements on the awareness, skills, training and where appropriate certifications of the supplier employees, verification of the background of those employees, and an obligation on the supplier to handle vulnerabilities that present a risk to the entity network and information systems, which is distinct from notifying an incident. Point 6.1.2(b) adds terms on security updates through the lifetime of an acquired product or replacement after end of support.

Framework Mappings (36)

STA-11Primary Service and Contractual Agreementfull
STA-12Supply Chain Agreement Reviewinformative
STA-11Primary Service and Contractual Agreementfull
STA-12Supply Chain Agreement Reviewinformative
DORA-Art.28.7Termination grounds in contractual arrangementsinformative
DORA-Art.30.1Written allocation of rights and obligationsinformative
DORA-Art.30.2.hTermination rights and minimum notice periodsinformative
EU-AI-Art.25.2Value Chain Responsibilities — Supply Chain Agreementspartial
GDPR-Art.28.3Data Processing Agreement (DPA) Requirementspartial
GDPR-Art.33.2Processor Notification of a Breach to the Controllerinformative
HIPAA-164.308.b.2Subcontractor Assurancesinformative
HIPAA-164.308.b.3Written Contract or Other Arrangementfull
HIPAA-164.314.a.2.i.BBusiness Associate Contract Subcontractor Terminformative
HIPAA-164.314.a.2.iiiBusiness Associate Contracts with Subcontractorsfull
5.20Addressing information security within supplier agreementsfull
8.30Outsourced developmentpartial
NIS2-Art.21.2.dSupply Chain Securityinformative
NIS2-CIR-10.2Verification of Backgroundinformative
NIS2-CIR-5.1Supply Chain Security Policypartial
NIS2-CIR-6.1Security in Acquisition of ICT Services or ICT Productspartial
NIS2-CIR-8.1Awareness Raising and Basic Cyber Hygiene Practicesinformative
CA-3Information Exchangepartial
CP-7(3)Alternate Processing Site | Priority of Servicefull
SA-4(1)Acquisition Process | Functional Properties of Controlsfull
SA-4(2)Acquisition Process | Design and Implementation Information for Controlsfull
SA-4(9)Acquisition Process | Functions, Ports, Protocols, and Services in Usefull
SA-9External System Servicesfull
SA-9(2)External System Services | Identification of Functions, Ports, Protocols, and Servicesfull
SR-11Component Authenticitypartial
SR-3Supply Chain Controls and Processespartial
SR-5Acquisition Strategies, Tools, and Methodspartial
SR-8Notification Agreementsfull
GV-6.1-004Third-Party AI Risk Policies | GV-6.1-004partial
GV-6.1-006Third-Party AI Risk Policies | GV-6.1-006full
GV-6.2-007Third-Party Failure Contingency Processes | GV-6.2-007partial
P6.4Third-Party Agreementsfull

Evidence (4)

contractdocumentmanual

Executed vendor contracts or Master Services Agreements containing binding security, privacy and incident notification requirements.

Example: Executed MSA with a key SaaS vendor (e.g. Salesforce, Zendesk, AWS), containing: information security obligations clause, data handling and deletion requirements, incident notification SLA (e.g. 24/48 hours), audit rights clause, sub-processor approval requirement, and exit/termination data return provisions

Test: Request contracts for 5 vendors with access to organisational or customer data. Verify each contract contains: (1) a binding information security obligations clause, (2) a defined incident notification timeline (acceptable: ≤72 hours), (3) a data handling and deletion clause specifying obligations on termination, (4) an audit right (direct audit or third-party certification acceptance), (5) a sub-processor approval clause, (6) applicable law and jurisdiction.

contractdocumentmanual

Executed Data Processing Agreements (DPAs) with all vendors who process personal data, satisfying GDPR Art.28.3 requirements.

Example: Executed DPAs (standalone documents or DPA appendices within MSAs) with all personal data processors, each covering the GDPR Art.28.3 mandatory clauses: processing only on instructions, confidentiality, security measures, sub-processing controls, data subject rights assistance, deletion/return of data, and audit cooperation

Test: Request DPAs for all vendors identified in the RoPA as processors. Verify: (1) a DPA is in place for every vendor that processes personal data, (2) each DPA includes all GDPR Art.28.3 mandatory clauses, (3) DPAs are signed by authorised representatives of both parties, (4) DPAs reference or annex appropriate technical and organisational measures.

contractdocumentmanual

Contract clauses for supplied components and external services covering control descriptions, design and implementation information and the declared functions, ports, protocols and services, with the supplier deliverables produced under them.

Example: Component supply agreement schedule 4, plus supplier control description pack v2

Test: Select in-scope supplier contracts for components and external services. Verify: (1) each carries the three obligations: functional properties of the controls, design and implementation information at an agreed level of detail and a declaration of functions, ports, protocols and services, (2) the deliverable the supplier produced under each obligation is on file and dated, (3) the declared ports, protocols and services match what the receiving hardening baseline permits, (4) a gap between the declaration and the traffic observed during the period was raised with the supplier and resolved, (5) the agreed level of detail is stated in the contract rather than left to the supplier.

contractdocumentmanual

Alternate processing agreement showing the priority-of-service provision and the recovery time objective it supports.

Example: Alternate capacity agreement, clause 9 priority of service, executed 2026-01-15

Test: Request the alternate processing agreement. Verify: (1) it names a priority of service rather than best efforts, (2) the priority is set against a stated recovery time objective that matches the one in the continuity plan, (3) the provision holds in a region-wide or area-wide event rather than applying only to a single-customer failure, (4) the agreement is current and its renewal date has not passed, (5) the capacity the provision reserves matches the capacity the recovery plan assumes.

Questions (3)

boolean

Do contracts with all vendors who access, process, store or transmit organisational data include binding security and privacy obligations?

Contracts should include at minimum: information security obligations, incident notification timelines (72 hours or less), audit rights, data handling and deletion requirements, sub-processor controls, and exit provisions.

multi

Which of the following clauses are included as standard in your vendor contracts?

Binding information security obligationsIncident notification timeline (72 hours or less)Data handling and deletion obligations on terminationAudit rights (direct audit or acceptance of third-party certification)Sub-processor approval requirementApplicable law and jurisdictionData Processing Agreement (DPA) satisfying GDPR Art.28.3Exit provisions and data portabilityNone of the above

All eight clauses are expected in contracts with vendors processing personal or sensitive data. Absence of a DPA for any personal data processor is a direct GDPR compliance gap.

multi

Which of the following do your contracts for supplied components and external services require?

A description of the functional properties of the security controls the component or service implementsDesign and implementation information for those controls at an agreed level of detailA declaration of the functions, ports, protocols and services the component or service usesPriority-of-service provisions set against the recovery time objective, in alternate processing agreementsNone of the above

Options run from the most commonly required to the least. A receiving organisation cannot secure what it cannot describe: a component whose ports and protocols are undeclared cannot be fitted to a hardening baseline, and a control whose functional properties are unstated cannot be relied on or tested. Priority of service decides whether alternate capacity is there when everyone else is invoking theirs too.