Consultancy agreement for a cybersecurity consultant
A consultancy agreement for a cybersecurity consulting engagement, drafted from whichever side instructs, £595 in five working days.
Consultancy agreement for a cybersecurity consultant
Buy now, £595A cybersecurity consultant is given access to a client's systems to find what is wrong with them, and the agreement has to make that access lawful, define what the consultant will and will not do with it, keep the findings confidential and the client responsible for acting on them, and say what the consultant promises, which is competent work rather than an unbreached business. For the business engaging the consultant or for the consultant's own use, the drafting is a fixed £595, delivered in five working days. Each engagement is checked against HMRC's Check Employment Status for Tax tool, and the agreement cannot guarantee how an individual's status will be decided.
Who this is for
Companies in England and Wales using an independent security specialist for assessments, penetration tests, architecture reviews, compliance programmes or a virtual CISO role, and the specialists themselves, whose work can cause damage when it goes wrong and who want an agreement that recognises it.
What matters in a cybersecurity consultant's agreement
The services and what is not guaranteed
The agreement should define the services (assessments, penetration tests, architecture review, policy and compliance work, a virtual CISO retainer) by a statement of work with the systems in scope, the methodology and the deliverables, and should say that no assessment finds every vulnerability, that the consultant does not guarantee that the client will not suffer a security incident, and that the consultant's obligation is to perform the services with reasonable care and skill under section 13 of the Supply of Goods and Services Act 1982 to the standard the statement of work sets.
Authorisation for testing and access to systems
Testing and scanning without authorisation is an offence under section 1 of the Computer Misuse Act 1990, and impairing a system under section 3, so the agreement should record the client's written authorisation for the consultant to access, test and, where agreed, exploit the systems in scope, warrant that the client has authority over them (including third-party hosted systems, whose owners must have consented), set rules of engagement with exclusions and stop conditions, and provide for the consultant to halt work where the authorisation is in doubt; the authorisation should be signed by someone entitled to give it.
Findings, confidentiality and disclosure
The consultant's findings describe how to attack the client, and the agreement should treat them as the client's confidential information, restrict the consultant's retention of them to what its records need, prohibit disclosure except as the client directs or the law requires, and address what happens when the consultant finds evidence of a breach already in progress, criminal activity or vulnerabilities in third-party products; the client should be responsible for remediation, and the agreement should say that the consultant's report is a snapshot as at the test date.
Incident response and the consultant's role
Where the consultant is retained for incident response, the agreement should set the response time, the scope (containment, investigation, advice on notification), the chargeable basis, and the consultant's role in the client's notifications to the Information Commissioner under Article 33 of the UK GDPR and to affected individuals, which remain the client's obligations; the consultant should preserve evidence to a standard that supports later proceedings and should not take decisions on the client's behalf without authority.
Status and the off-payroll question
Security consultants run their own businesses: a client list, their own tooling, their own way of working and associates they can bring in, and the agreement should describe that rather than a role in the client's team. A virtual CISO retainer needs particular care, drafted so that the consultant advises the client's management and does not direct its staff. Where a medium or large client engages the consultant's company, the off-payroll regime in Chapter 10 of Part 2 of the Income Tax (Earnings and Pensions) Act 2003 makes the client responsible for determining status, and HMRC's tool is applied to the engagement as it runs.
Payment, notice, liability and insurance
Fees and how they are invoiced, interest on late payment as the Late Payment of Commercial Debts (Interest) Act 1998 provides, a right for either party to end on notice, and a ceiling on liability at a multiple of the fees that leaves out consequential loss and the cost of any breach the consultant did not cause, drafted to satisfy section 11 of the Unfair Contract Terms Act 1977 and sitting on professional indemnity and cyber cover at stated levels; the client should indemnify the consultant for claims arising from testing performed within the authorisation, because a consultant who crashed a system while doing what was asked should not carry that cost.
What it costs
Consultancy or contractor agreement, £595. Drafted for your business. Five working days.
Template set for repeat use, £895. One master agreement plus a short-form schedule you can reuse for every engagement. Five working days.
Buying online forms the engagement on payment. The scope is what the consultancy and contractor agreements page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A clear, express assignment of intellectual property to your business
- Confidentiality provisions that protect your business information
- Restrictive covenants drafted at a scope a court will uphold
- Clear treatment of status, so the arrangement is not accidentally something else
- Payment, deliverables and termination provisions that match how you work
- A reusable structure, so the next engagement costs you nothing
What is not included
- Employment status determinations and off-payroll working assessments, which need your accountant
- Tax advice
- Disputes with a contractor you have already engaged
- Immigration and right to work compliance
Questions I am often asked
We want the consultant to test a system hosted by our software supplier. Can they?
Only with the supplier's consent, which the agreement requires the client to obtain and warrant. Testing a third party's system without its authorisation is an offence whatever your contract with the consultant says.
The penetration test took a production server down. Who pays?
If the consultant worked within the authorisation and rules of engagement, the client, which the agreement's indemnity provides. If the consultant exceeded them, the consultant, within the cap. Rules of engagement are what decide it.
Is the consultant liable if we are breached a month after their assessment?
Not for the breach itself, if the agreement says that no assessment finds everything and the report is a snapshot. For a vulnerability the consultant should have found with reasonable care, within the cap and the insurance.
Related guidance and services
- Consultancy and contractor agreements, £595, the service this page describes
- Contract review, £495
- Employment contracts and handbooks, £595
- Terms for a cybersecurity product
- Terms and conditions for a cybersecurity consultancy
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.