VND-002 Security Requirements in Vendor Contracts
Description
Contracts with all vendors who access, process, store or transmit organisational data include binding security and privacy requirements. These requirements address information security obligations, incident notification timelines, audit rights, data handling and deletion, right to subcontract, applicable law and exit provisions. Contracts with suppliers of ICT products and components include provenance, anti-tamper and component authenticity obligations, and contracts for outsourced development include the organisation's right to direct, monitor and review the work. Contracts for supplied components and external services require the supplier to describe the functional properties of the security controls the component or service implements, to provide design and implementation information for those controls at an agreed level of detail and to declare the functions, ports, protocols and services it uses. Agreements for alternate processing capacity carry priority-of-service provisions set against the recovery time objective they support.
Rationale
Contractual requirements are the primary enforcement mechanism for supplier security obligations; without written requirements the organisation has no recourse when a supplier causes a breach. The control information clauses exist because a receiving organisation cannot secure what it cannot describe: a component whose ports and protocols are undeclared cannot be fitted to a hardening baseline, and a control whose functional properties are unstated cannot be relied on or tested. Priority of service is the clause that decides whether alternate capacity is available in the event everyone else is also invoking it.
Applicability (9 profiles)
Art.25(4) reaches a general vendor contract wherever what the vendor supplies is used in or integrated into a high-risk system: the contract has to carry the information, capabilities, technical access and other assistance the high-risk provider needs to comply, which is a positive duty owed by the supplier and not one of the security, audit and exit clauses this control enumerates. AIG-032 holds the AI-specific assessment and the agreement with an AI provider; the row here exists because a component or service contract signed by procurement, with no AI review in front of it, can be the Art.25(4) agreement and usually lacks the clause.
164.308(b)(3) and 164.314(a)(2)(iii) make the written subcontractor agreement and its terms a required specification, not a commercial preference. Assurances given in a questionnaire or a security review do not discharge it.
Annex point 5.1.4 fixes eight contract terms and three are not in the control: requirements on the awareness, skills, training and where appropriate certifications of the supplier employees, verification of the background of those employees, and an obligation on the supplier to handle vulnerabilities that present a risk to the entity network and information systems, which is distinct from notifying an incident. Point 6.1.2(b) adds terms on security updates through the lifetime of an acquired product or replacement after end of support.
Framework Mappings (36)
| STA-11 | Primary Service and Contractual Agreement | full |
| STA-12 | Supply Chain Agreement Review | informative |
| STA-11 | Primary Service and Contractual Agreement | full |
| STA-12 | Supply Chain Agreement Review | informative |
| DORA-Art.28.7 | Termination grounds in contractual arrangements | informative |
| DORA-Art.30.1 | Written allocation of rights and obligations | informative |
| DORA-Art.30.2.h | Termination rights and minimum notice periods | informative |
| EU-AI-Art.25.2 | Value Chain Responsibilities — Supply Chain Agreements | partial |
| GDPR-Art.28.3 | Data Processing Agreement (DPA) Requirements | partial |
| GDPR-Art.33.2 | Processor Notification of a Breach to the Controller | informative |
| HIPAA-164.308.b.2 | Subcontractor Assurances | informative |
| HIPAA-164.308.b.3 | Written Contract or Other Arrangement | full |
| HIPAA-164.314.a.2.i.B | Business Associate Contract Subcontractor Term | informative |
| HIPAA-164.314.a.2.iii | Business Associate Contracts with Subcontractors | full |
| 5.20 | Addressing information security within supplier agreements | full |
| 8.30 | Outsourced development | partial |
| NIS2-Art.21.2.d | Supply Chain Security | informative |
| NIS2-CIR-10.2 | Verification of Background | informative |
| NIS2-CIR-5.1 | Supply Chain Security Policy | partial |
| NIS2-CIR-6.1 | Security in Acquisition of ICT Services or ICT Products | partial |
| NIS2-CIR-8.1 | Awareness Raising and Basic Cyber Hygiene Practices | informative |
| CA-3 | Information Exchange | partial |
| CP-7(3) | Alternate Processing Site | Priority of Service | full |
| SA-4(1) | Acquisition Process | Functional Properties of Controls | full |
| SA-4(2) | Acquisition Process | Design and Implementation Information for Controls | full |
| SA-4(9) | Acquisition Process | Functions, Ports, Protocols, and Services in Use | full |
| SA-9 | External System Services | full |
| SA-9(2) | External System Services | Identification of Functions, Ports, Protocols, and Services | full |
| SR-11 | Component Authenticity | partial |
| SR-3 | Supply Chain Controls and Processes | partial |
| SR-5 | Acquisition Strategies, Tools, and Methods | partial |
| SR-8 | Notification Agreements | full |
| GV-6.1-004 | Third-Party AI Risk Policies | GV-6.1-004 | partial |
| GV-6.1-006 | Third-Party AI Risk Policies | GV-6.1-006 | full |
| GV-6.2-007 | Third-Party Failure Contingency Processes | GV-6.2-007 | partial |
| P6.4 | Third-Party Agreements | full |
Evidence (4)
Executed vendor contracts or Master Services Agreements containing binding security, privacy and incident notification requirements.
Example: Executed MSA with a key SaaS vendor (e.g. Salesforce, Zendesk, AWS), containing: information security obligations clause, data handling and deletion requirements, incident notification SLA (e.g. 24/48 hours), audit rights clause, sub-processor approval requirement, and exit/termination data return provisions
Test: Request contracts for 5 vendors with access to organisational or customer data. Verify each contract contains: (1) a binding information security obligations clause, (2) a defined incident notification timeline (acceptable: ≤72 hours), (3) a data handling and deletion clause specifying obligations on termination, (4) an audit right (direct audit or third-party certification acceptance), (5) a sub-processor approval clause, (6) applicable law and jurisdiction.
Executed Data Processing Agreements (DPAs) with all vendors who process personal data, satisfying GDPR Art.28.3 requirements.
Example: Executed DPAs (standalone documents or DPA appendices within MSAs) with all personal data processors, each covering the GDPR Art.28.3 mandatory clauses: processing only on instructions, confidentiality, security measures, sub-processing controls, data subject rights assistance, deletion/return of data, and audit cooperation
Test: Request DPAs for all vendors identified in the RoPA as processors. Verify: (1) a DPA is in place for every vendor that processes personal data, (2) each DPA includes all GDPR Art.28.3 mandatory clauses, (3) DPAs are signed by authorised representatives of both parties, (4) DPAs reference or annex appropriate technical and organisational measures.
Contract clauses for supplied components and external services covering control descriptions, design and implementation information and the declared functions, ports, protocols and services, with the supplier deliverables produced under them.
Example: Component supply agreement schedule 4, plus supplier control description pack v2
Test: Select in-scope supplier contracts for components and external services. Verify: (1) each carries the three obligations: functional properties of the controls, design and implementation information at an agreed level of detail and a declaration of functions, ports, protocols and services, (2) the deliverable the supplier produced under each obligation is on file and dated, (3) the declared ports, protocols and services match what the receiving hardening baseline permits, (4) a gap between the declaration and the traffic observed during the period was raised with the supplier and resolved, (5) the agreed level of detail is stated in the contract rather than left to the supplier.
Alternate processing agreement showing the priority-of-service provision and the recovery time objective it supports.
Example: Alternate capacity agreement, clause 9 priority of service, executed 2026-01-15
Test: Request the alternate processing agreement. Verify: (1) it names a priority of service rather than best efforts, (2) the priority is set against a stated recovery time objective that matches the one in the continuity plan, (3) the provision holds in a region-wide or area-wide event rather than applying only to a single-customer failure, (4) the agreement is current and its renewal date has not passed, (5) the capacity the provision reserves matches the capacity the recovery plan assumes.
Questions (3)
Do contracts with all vendors who access, process, store or transmit organisational data include binding security and privacy obligations?
Contracts should include at minimum: information security obligations, incident notification timelines (72 hours or less), audit rights, data handling and deletion requirements, sub-processor controls, and exit provisions.
Which of the following clauses are included as standard in your vendor contracts?
All eight clauses are expected in contracts with vendors processing personal or sensitive data. Absence of a DPA for any personal data processor is a direct GDPR compliance gap.
Which of the following do your contracts for supplied components and external services require?
Options run from the most commonly required to the least. A receiving organisation cannot secure what it cannot describe: a component whose ports and protocols are undeclared cannot be fitted to a hardening baseline, and a control whose functional properties are unstated cannot be relied on or tested. Priority of service decides whether alternate capacity is there when everyone else is invoking theirs too.