SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.8.30Outsourced development

Direct and oversee security in software development that you outsource, holding external developers to the same standards you would apply in-house.

Mapping at a glance

A.8.30 is covered by 2 Sekit CSF controls. Open in the full graph

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

ISO/IEC 42001:2023 — Annex A counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Secure development policy
The rules the development team follows to build software securely: security requirements, code review and threat modeling.
Vendor due diligence and monitoring
How the company assesses a supplier's security before hiring and monitors it during the relationship, including the process when it ends.
From the Sekit evidence catalog

In practice

Outsourced development gets treated like any other supplier relationship: a documented security check before the contract is signed, and binding security clauses written into the contract itself rather than assumed based on the vendor's reputation. Auditors ask for the vendor due diligence record covering the specific development shop, plus proof that the same secure development expectations, code review, testing, and vulnerability handling, apply whether the code was written in-house or by a contractor. The failure mode is a fast-moving project where a contractor was engaged before procurement ran the security check, so the due diligence record gets backfilled after the fact or never completed at all.

Common gaps

An outsourced development vendor was engaged before the security due diligence check was completed, so the assessment record was backfilled after work had already started.
The master services agreement with the development contractor contains no specific security or data protection clauses beyond general confidentiality language.
Code delivered by the outsourced team is not put through the same secure code review process required for in-house development.

Questions your auditor will ask

Do you assess a development vendor's security posture before signing the contract?
Yes, a documented security check is required for every new supplier handling company data or connecting to company systems before the contract is signed.
What security obligations does an outsourced developer have contractually?
Binding security and data protection clauses are included in every contract with suppliers that handle company data or access company systems, including development vendors.
Does outsourced code go through the same security checks as in-house code?
Yes, code from a contractor is expected to meet the same secure development requirements, including code review and testing, as work done in-house.

Where regulation demands it

NIS2 art. 5.1 requires a supply chain security policy covering suppliers such as outsourced developers, and ENS op.ext.1 requires security terms in contracting and service-level agreements.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.8.30?”
Also via MCP, free with account