‹‹ Back

6 Contractual Security Clauses to Limit Supplier Cyber Risks

Companies and public-sector organisations are now fully dependent on their supply chain for almost all their activities. This is because it is impossible to operate efficiently without relying on tools and experts to run every department within an organisation: IT, HR, logistics, food services, transport, finance, and more.

Cyberattackers clearly understand the contribution made by service providers, primarily technology providers (SaaS vendors, Cloud providers, hosting providers, etc.), to business operations. They carry out assignments involving access to data or the information system.

As a result, security can no longer be limited to the internal information system and must address the "extended" enterprise.

So, how can you involve all your service providers in their clients' security initiatives?

Compliance with your Information Systems Security Policy (ISSP), security measures specific to your business, and more. They themselves may manage dozens or hundreds of clients. Scalable approaches such as cyber ratings and the inclusion of contractual security clauses are becoming increasingly relevant.

Contractual Security Clauses: Why Does the Supplier Contract Remain the Central Tool for Managing Cyber Risk?

A Legal and Operational Framework for Protecting the Supplier Relationship

The supplier contract is a key lever for managing supplier cyber risk. It defines the scope of work, governs responsibilities and sets out service-level commitments. However, it cannot cover all technical and functional cybersecurity requirements.

In a regulatory environment shaped by NIS2 and DORA, the supplier contract remains a highly effective tool for controlling third-party risks (Third-Party Cyber Risk Management). Indeed, 60% of surveyed companies now involve their legal department in their cyber strategy. This collaboration not only helps ensure suppliers' financial stability and reliability, but also increases transparency regarding the provider's security practices and commits them to complying with legal obligations and security requirements. Together, these elements strengthen cybersecurity governance and compliance within the business relationship.

Contractual clauses must provide the minimum means to assess supplier practices and impose a common framework to reduce the risk of security failures.

A Way to Hold Suppliers Accountable in Cyber Risk Management

The rise in cyberattacks targeting supply chains is forcing companies and public-sector organisations to strengthen their control mechanisms. Contractual security clauses establish the rules in this area: subcontracting controls, audit rights, incident notification obligations, pentests, prior notifications in the event of changes to certifications, hosting arrangements, controls, and more.

According to the 2025 Cyber Risk Observatory, 9 out of 10 companies consider contractual security clauses to be the primary lever for managing supplier cyber risk. Far more than a legal tool, they define commitments and responsibilities in the event of cyberattacks and impose preventive actions to limit cyber risks.

These contractual security clauses help structure the supplier's cyber maturity. They specify the provider's mandatory commitments to maintain a level of security consistent with the risks associated with the service provided. In the event of an incident or failure, the supplier contract becomes an enforceable instrument, often due to the resulting service unavailability, ensuring the means needed to understand, remediate and limit the impact on the company, its information system and its supply chain.

Finally, Article 30 of the DORA Regulation describes the contractual security clauses to be included when a provider is deemed critical or has a significant impact on the company's business activities. These clauses specify requirements regarding audits, reversibility, security, termination and data protection. Examples include:

  • a precise description of the ICT functions and services that the supplier must provide, particularly with regard to subcontracting;
  • practices relating to the availability, authenticity, integrity and confidentiality of personal data, as well as provisions concerning access to, recovery of and return of data processed by the financial entity;
  • a detailed description of service levels;
  • the ICT provider's obligation to assist the financial entity in the event of a cyber incident related to the service provided, as well as its full cooperation;
  • termination conditions and notice periods;
  • participation in cybersecurity awareness and operational resilience training programmes.

The Six Essential Contractual Security Clauses in a Supplier Contract

1. Audit Clauses

The audit and control clause gives the client company the right to verify the proper performance of the obligations set out in the contract. It therefore makes it possible to monitor the supplier's commitments or security maturity, whether in relation to compliant use of the service or data, operational quality, or compliance with security requirements.

In cybersecurity, Cloud computing, the use of APIs and outsourced services, and the growing number of digital solutions require organisations to engage many technology third parties. This ecosystem of providers requires risk areas to be managed through regular security testing. Through this contractual security clause, CISOs can organise controls, conduct regular audits or require pentests.

If this clause is used, the third party must undergo an audit, depending on the context: a documentary and on-site audit or a penetration test. It must also commit to a corrective action plan if significant deviations are identified from its commitments, as defined in its security assurance plan, or from security good practices.

Finally, the security clause must specify a notice period and notification conditions. It may also state that only one audit may be conducted per year.

Example of an audit clause:

"The Client may arrange, through an audit firm bound by professional secrecy and subject to 30 days' prior notice, for the examination of any element required to ensure the proper performance of the obligations set out in the Contract, particularly the Services. This audit shall take place during the Provider's business hours, no more than twice per year. Audit costs shall be borne by the Client."

2. Subcontracting Clause

The use of a subcontractor requires contractual transparency. Any involvement of a subcontractor must therefore be subject to prior disclosure and approval by the client. Accordingly, security requirements must be passed down within the supplier contract. According to CNIL recommendations, the supplier must obtain prior authorisation before engaging a subcontractor.

In order to limit vulnerabilities, managing subcontractors' cyber risks is equally essential. Each subcontractor must therefore be subject to the same security requirements as the supplier that engages it. This is a requirement of the DORA Regulation. Indeed, if an IT service provider relies on a third party to fulfil its commitments, that third party becomes part of the company's digital dependency chain. The Regulation therefore requires it to be included in the register of ICT providers, in the same way as the main supplier.

The subcontractor contractual security clause applies to both technical and organisational safeguards: data encryption, authentication, audits, and more. In most cases, this clause protects the use of personal or sensitive data collected, used and stored by subcontractors.

Example clauses: https://www.cnil.fr/fr/sous-traitance-exemple-de-clauses

3. Liability Clause

The liability clause clarifies each party's obligations in the event of an incident. It defines liability limits, specifies notification deadlines and may include certification or qualification requirements. The liability clause may also include business continuity and disaster recovery arrangements (BCP/DRP), as well as remediation terms.

This security clause is essential to clarify the scope of responsibilities in the event of failures or cyberattacks. The company's civil and criminal liability may therefore be engaged, hence the value of obtaining additional cyber insurance. Above all, it should commit the supplier to strengthening the security of its technologies in line with the client company's cyber requirements.

For example, it may require the supplier to supplement its service commitments, such as Service-Level Agreements (SLAs) or software maintenance commitments.

4. Penalty Clause

It sets out the financial penalties applicable in the event of breach, non-performance or delay. It establishes contractual liquidated damages in order to encourage the provider to comply with the contract's requirements. This contractual penalty is provided for by the penalty clause.

In cybersecurity, the penalty clause sets out the financial sanctions applicable in the event of non-compliance with security rules, including protective measures, compliance requirements and incident notifications. Its purpose is to hold suppliers accountable and ensure the implementation of the cyber risk management measures set out in the contract.

Example: "If the PROVIDER's service is unavailable for a period exceeding [x], the PROVIDER shall be deemed to have failed to meet its commitments, resulting in the application of a fixed penalty of EUR 1,000 per day."

5. End-of-Contract Reversibility Clause

The reversibility clause governs the return, transfer or destruction of data when the supplier contract ends. Its purpose is to ensure that the client can recover its digital assets and maintain business continuity. This security clause is essential to ensure continuity of operations when changing technology providers or SaaS suppliers.

The reversibility mechanism therefore enables an organisation to recover its data or access to applications. Recovering this data is essential, especially when it is critical and may have financial, legal or reputational impacts.

This end-of-contract reversibility clause also responds to the increasing fragility of technology providers in the face of numerous cyberattacks. The risk of failures or even business shutdowns at an IT third party can directly affect the company's operations. The reversibility clause helps limit these effects by defining the technical arrangements for data transfer, expected formats, timeframes and security commitments. With evolving European requirements (NIS2, DORA, etc.), this contractual security clause is becoming a compliance standard.

Example clause:

When the Contract ends, for any reason whatsoever:

  • (i) amounts due by the Client to the Provider shall be calculated pro rata up to the effective termination date; and
  • (ii) the Provider undertakes to ensure, at its own expense, the full or partial reversibility, at the Client's discretion, of the Data and Confidential Information.

The return of all the aforementioned items shall be carried out free of charge within a maximum period of sixty (60) days following the end of the Contract, to the Client or to a third party of its choice.

For this purpose, the Provider shall provide all items in an easily usable and portable format. Failing this, the Provider shall provide technical assistance, free of charge, to the Client and/or to the third party designated by the Client for the recovery of the Data.

In all cases, at the end of the reversibility operation, the Provider undertakes to destroy all Data and Confidential Information in its possession, as well as any copies and backups that may have been made, and to provide evidence of such destruction upon the Client's first request.

6. Security Incident Management Clause

A security incident management clause requires the supplier to alert its client as soon as a security event occurs. According to the CNIL, the provider must implement defined procedures to detect, classify and report incidents, including data breaches affecting confidentiality, integrity or availability. This clause therefore requires the supplier to provide detailed information on the nature of the event, its impact and the corrective measures being considered.

The objective is both to prevent incidents and to ensure a rapid and structured response when a cyberattack occurs. The contractual incident management clause must provide for a maximum notification period to the client. It must also formalise a remediation plan, ensure the traceability of actions and organise coordination with the client's CISO teams. This remediation plan includes root cause analysis, the implementation of corrective measures and collaboration with the client to restore security.

Finally, as part of the incident management clause, the supplier must maintain a register of security incidents. This register records each cybersecurity event, its classification, its resolution and the corrective actions applied.

The Cloudflare service disruption on 18 November prevented access to a number of websites and web services. This is a textbook case where the presence of an incident management clause is essential.

Example clause: "When the Provider becomes aware of a security incident, including unauthorised access by third parties, loss of Data, compromise of Data integrity, introduction of malware and/or non-compliant use of the Solution, it must notify the Client's CISO no later than forty-eight (48) hours after detecting the incident.

The Provider shall take appropriate measures to contain the security incident, limit its impact and restore normal operation of the Services as soon as possible.

The Provider shall, in particular, provide the Client with all information necessary for notification to the competent authorities and the data subjects, where applicable."

Contractual Security Clauses Complement the Cyber Toolkit

Technological dependence, regulatory pressure and the growing risk of supply-chain cyberattacks are forcing companies to strengthen their suppliers' cybersecurity requirements. Contractual security clauses are a simple and effective tool for defining each party's responsibilities.

These clauses - audit, subcontracting, liability, reversibility and incident management - create a clear operational framework. They are therefore a prerequisite for any third-party risk management programme (TPCRM). They complement other levers, such as obtaining certifications, periodic assessments and cyber ratings.

In addition, the Security Assurance Plan (SAP) provides an operational and enforceable view of the supplier's cyber commitments. This legal and technical document formalises the measures required to protect the information systems and data processed as part of the service delivery. The SAP specifies the security controls applied, incident management procedures and confidentiality, integrity and availability safeguards. When incorporated into the supplier contract, it provides a shared framework for assessing the third party's cyber maturity, managing its IT risk and strengthening its accountability throughout the contractual relationship.

However, implementing these clauses may slow down the signing process and create some tension with business teams. A pragmatic approach is needed to accept certain concessions, such as response times or incident management arrangements, and enable the service to begin.

To ensure their effectiveness, contractual security clauses should be defined with the legal department or an external expert.

FAQ

What Are the Most Important Contractual Security Clauses in a Supplier Contract?

Security clauses cover audit and control, subcontracting, liability and penalties, reversibility, and security incident management. They establish a shared framework for managing supplier obligations, ensuring transparency and maintaining an appropriate level of cybersecurity.

Why Are Contractual Security Clauses Essential for Reducing Cyber Risk?

They make it possible to govern supplier practices, verify their level of cyber maturity and impose measurable commitments. In the event of an incident, they also provide a contractual basis for requiring remediation and improving cyber resilience.

What Are Contractual Security Clauses?

Contractual security clauses are provisions included in a supplier contract to govern the protection of information systems, data and cyber risk management.

They define the requirements that the provider must comply with to ensure a level of security consistent with the company's expectations.

How Can Security Clauses Be Incorporated into a Comprehensive TPCRM Approach?

Contractual security clauses are a pillar of TPCRM. They should be enhanced by other tools: security questionnaires, audits, CTI monitoring, periodic reviews and cyber rating solutions. These levers make it possible to assess the supplier's actual level of risk, strengthen supply-chain resilience and ensure cyber compliance with regulations such as NIS2 or DORA.

Enjoyed this article? Subscribe to our newsletter so you never miss a new post!

Subscribe