A.5.20Addressing information security within supplier agreements
Write relevant security requirements into supplier contracts so expectations are clear and enforceable. Spell out responsibilities before problems arise, not after.
Mapping at a glance
A.5.20Addressing information security within supplier agreementsISO/IEC 27001:2022
In practice this is a contract clause library: standard security and data protection language legal or procurement pulls into every supplier agreement rather than negotiating from scratch each time. Auditors ask to see a sample contract from a supplier handling sensitive data and check whether the clauses made it into the signed document, not only the vendor's proposed terms. The common failure is a company with good clause language sitting in a template but never inserted into contracts signed before procurement adopted the template, leaving older, still-active suppliers uncovered.
Common gaps
Security clauses exist in the standard contract template, but several active supplier contracts predate the template and were never amended to include them.
The contract includes a right-to-audit clause, but it has never been exercised against any supplier since signing.
Breach notification terms in the contract do not specify a timeframe, leaving a vague promise as the only obligation on a supplier with real access to customer data.
Questions your auditor will ask
What security requirements are written into your supplier contracts?
Point to the standard clause set covering breach notification, data protection terms and audit rights, then show it present in a signed contract with a data-handling supplier.
Do older supplier contracts include the same protections as new ones?
Identify any contracts signed before the current clause template was adopted, and describe the plan or timeline for bringing them up to the same standard.
How do you know if a supplier is meeting the security obligations in their contract?
Show the tracking process that checks stated obligations against supplier behaviour and the escalation path for non-compliance.
Where regulation demands it
NIS2 art. 5.1 (Supply chain security policy) requires the same contractual approach A.5.20 asks organizations to take with suppliers.
ENS op.ext.1 (Contratación y acuerdos de nivel de servicio) is the equivalent baseline for security terms in service agreements.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.