What an auditor, or Sekit's evidence engine, asks for.
Secure development policy
The rules the development team follows to build software securely: security requirements, code review and threat modeling.
Vendor due diligence and monitoring
How the company assesses a supplier's security before hiring and monitors it during the relationship, including the process when it ends.
From the Sekit evidence catalog
In practice
Outsourced development gets treated like any other supplier relationship: a documented security check before the contract is signed, and binding security clauses written into the contract itself rather than assumed based on the vendor's reputation. Auditors ask for the vendor due diligence record covering the specific development shop, plus proof that the same secure development expectations, code review, testing, and vulnerability handling, apply whether the code was written in-house or by a contractor. The failure mode is a fast-moving project where a contractor was engaged before procurement ran the security check, so the due diligence record gets backfilled after the fact or never completed at all.
Common gaps
An outsourced development vendor was engaged before the security due diligence check was completed, so the assessment record was backfilled after work had already started.
The master services agreement with the development contractor contains no specific security or data protection clauses beyond general confidentiality language.
Code delivered by the outsourced team is not put through the same secure code review process required for in-house development.
Questions your auditor will ask
Do you assess a development vendor's security posture before signing the contract?
Yes, a documented security check is required for every new supplier handling company data or connecting to company systems before the contract is signed.
What security obligations does an outsourced developer have contractually?
Binding security and data protection clauses are included in every contract with suppliers that handle company data or access company systems, including development vendors.
Does outsourced code go through the same security checks as in-house code?
Yes, code from a contractor is expected to meet the same secure development requirements, including code review and testing, as work done in-house.
Where regulation demands it
NIS2 art. 5.1 requires a supply chain security policy covering suppliers such as outsourced developers, and ENS op.ext.1 requires security terms in contracting and service-level agreements.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.