Contract clause

Cyber security clause: the controls a supplier must keep

A cyber security clause requires a supplier to maintain stated technical and organisational measures that protect the customer's systems and data, such as multi factor authentication, patching, encryption, backups and testing. It turns a general promise to keep data secure into specific controls that can be evidenced, tested and enforced during the contract.

Reasonable security means little until someone writes down what it includes. A good clause names the controls, the standard they are measured against, and how the customer will know they are still in place a year later.

· Co-founder

4 min read · Published

Sample clause

a managed IT agreement between Kurrajong Systems and Merriwa Legal, a fictional four partner law practice in Orange with remote access to client files

10. Cyber Security 10.1 Kurrajong Systems must implement and maintain the mitigation strategies in the Australian Cyber Security Centre's Essential Eight at Maturity Level Two across all systems it uses to provide the Services. 10.2 Without limiting clause 10.1, Kurrajong Systems must: (a) require multi factor authentication for all remote and administrative access; (b) encrypt Client Data at rest and in transit; (c) apply security patches rated critical within 48 hours of release; (d) keep daily backups of Client Data, with at least one copy offline, and test restoration each quarter; and (e) engage an independent tester to carry out a penetration test of the Services each year. 10.3 Kurrajong Systems must give Merriwa Legal a summary of each penetration test and its remediation plan within 20 business days of receiving the results. 10.4 Kurrajong Systems must notify Merriwa Legal before making any change that would reduce the level of protection required by this clause.

Sample wording, not legal advice.

Variants

Standard referenced

The supplier already works to a recognised framework and both sides prefer a benchmark to a bespoke list.

The Supplier must maintain an information security management system that meets the requirements of ISO/IEC 27001 for the scope of the Services, and must keep that system under review throughout the Term. The Supplier must provide the Customer with a copy of its current certificate or independent assessment report on request, and must notify the Customer promptly if the certificate lapses, is suspended or no longer covers the Services.

Controls listed

A small supplier with no certification, where the customer needs to see exactly what will be done.

The Contractor must: use a unique account with multi factor authentication for every person who accesses Customer systems; restrict administrative privileges to named personnel; install operating system and application security updates within 14 days of release, or within 48 hours where rated critical; run supported endpoint protection on every device used for the Services; and keep an access log for each Customer system that it retains for 12 months.

Questionnaire based

The customer runs a vendor assessment program and wants the supplier's own answers to become contractual promises.

The Supplier warrants that its responses to the Customer's security questionnaire dated 14 July 2026, attached as Schedule 5, are accurate and complete. The Supplier must maintain the controls described in those responses for the Term, must notify the Customer within 10 business days if any response ceases to be accurate, and must complete an updated questionnaire each year on request.

What to negotiate

The risk of leaving it out

Without the clause the customer relies on a general duty of care and whatever security the supplier chooses to buy. After an incident there is no agreed benchmark to show the supplier fell short, and the customer's own obligation under APP 11 to take reasonable steps is harder to show it met.

The controls, one line each

The Essential Eight groups eight mitigation strategies. Patch applications and patch operating systems close known weaknesses quickly. Multi factor authentication stops a stolen password being enough. Restrict administrative privileges limits what a compromised account can do. Application control stops unapproved programs running. Restrict Microsoft Office macros and user application hardening close two common delivery routes for malicious code. Regular backups make recovery possible after ransomware. A contract table beside these usually adds encryption at rest and in transit, access logging, endpoint protection and an annual independent penetration test, each with an owner, a frequency and the evidence the customer receives.

How the clause meets APP 11

APP 11 requires an entity covered by the Privacy Act to take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. When a supplier holds that information, the customer's reasonable steps include choosing a capable supplier and binding it to specific controls. A cyber security clause is therefore part of the customer's own compliance record, not only a commercial protection, and after an incident it is the written evidence of what the customer actually required. Article 32 of the UK GDPR takes a similar approach, requiring measures appropriate to the risk and naming encryption, resilience, restoration and regular testing as examples.

Where it sits in a generated document

A generated agreement can set this out as a numbered clause, with each control as its own sub clause so a reviewer can check them one by one. Where the description asks for the controls as a table, the document can carry a table with columns for control, frequency and evidence. Since the chat edits text only, tightening a patch window from 14 days to 48 hours is a change to existing wording, not a new clause.

Documents that carry this clause

IT support services agreement with response times by priority exampleIT support services agreement with response times by priorityManaged support is sold on a monthly fee and judged on how fast the phone gets answered when nobody can work. This agreement grades every ticket into four priorities with a published response and resolution target, credits the fee when the target is missed, and writes down exactly what the provider hands back on the way out.Software development agreement with sprints and an acceptance test exampleSoftware development agreement with sprints and an acceptance testCustom software goes wrong in the space between delivered and accepted, where one side thinks a sprint is finished and the other is still writing a list. This agreement fixes a ten business day acceptance window against criteria written before the sprint started, and assigns the intellectual property sprint by sprint as each invoice is paid.UK data processing agreement template with sub-processors exampleUK data processing agreement template with sub-processorsA data processing agreement is what a UK controller has to have in writing before a processor touches personal data. This one covers a hosted order management platform for a UK retailer, with the processing annex, a table of five named sub-processors and their transfer safeguards, eight security measures, and a breach notice of 48 hours rather than 72.Software licence agreement template with seats, term and support exampleSoftware licence agreement template with seats, term and supportA software licence agreement has to answer three questions before anything else: what a seat is, what happens when the software is down, and who gets the data at the end. This one licenses a hosted practice management suite to a medical practice for 25 named users at $9,600 a year, with a support table, uptime credits and a 30 day export.

Questions people ask

What is the Essential Eight?

A set of eight mitigation strategies published by the Australian Cyber Security Centre as a baseline for making systems harder to compromise. It covers patching applications and operating systems, multi factor authentication, restricting administrative privileges, application control, restricting Office macros, user application hardening and regular backups, with a maturity model for measuring implementation.

Is the Essential Eight a legal requirement for private businesses?

Not as a general rule. It is guidance, although many government customers expect it. Businesses covered by the Privacy Act must still take reasonable steps to secure personal information under APP 11, and naming a recognised framework in a contract is a practical way to show what reasonable steps means for a given supplier.

Should the clause name a standard or list controls?

A named standard suits suppliers that already work to one and gives a benchmark that updates over time. A list of controls suits smaller suppliers and makes compliance easy to check. Many clauses do both: a framework as the baseline, and a short list of non negotiable controls such as multi factor authentication and tested backups.

Can a customer see the supplier's penetration test report?

Only if the contract says so. Suppliers often resist sharing full reports because they describe vulnerabilities in detail. A summary of findings by severity, with a remediation plan and target dates, is the common compromise. The clause should also require critical findings affecting the customer to be fixed within a set period.

What happens if the supplier stops meeting the controls?

That is a breach of the clause. Well drafted versions require the supplier to tell the customer before reducing protection, set a period to remedy any gap, and give the customer a right to terminate if a serious gap is not fixed. Without a notice duty, the customer may only discover the gap after an incident.

Does a cyber security clause replace breach notification?

No. Security controls aim to stop incidents, while notification deals with what happens after one. A contract needs both, and they should use consistent definitions so that an event the security clause describes as an incident is also caught by the notification clause. Audit rights then let the customer check the controls are real.

Put the clause in a finished document

The button opens the document generator with a starting description already filled in. Change it to match your own agreement before you run it.

Create a document with OneCraft

Related clauses

For everything the document generator can do, see the document maker.

Step by step in the builder: Create a document with AI, then Document builder components.

Sources

Written and checked by the OneCraft team. Last checked .