Reviewing a security schedule in a customer's contract

Review of an information security schedule or security addendum a customer requires a supplier to sign, marked up with a written explanation, for a fixed fee of £495 in three working days.

Share

Reviewing a security schedule in a customer's contract

A supplier-side review of the information security schedule a customer has attached to its contract, covering the standards and certifications required, the technical controls you must operate, breach notification periods, audit and penetration testing rights, the personnel and sub-contractor obligations, and the liability the schedule adds. £495, in three working days.

Buy now, £495

A security schedule sets out the customer's information security requirements: certifications the supplier must hold, controls it must operate, breach notification within hours, audit and penetration testing rights, and a liability position that may sit outside the cap. It is a contractual commitment to each of those and needs to be read as one. I review the schedule from the supplier's side and return it marked up with a written explanation of what the supplier can meet, what it cannot, and what a customer will accept in its place, for a fixed fee of £495 in three working days.

Who this is for

Software and SaaS suppliers, IT services businesses, consultancies, outsourcers and any supplier in England and Wales that handles a customer's data or connects to its systems and has been sent a security schedule, a security requirements annex or a data security addendum to sign. The supplier and the customer are businesses; the schedule sits alongside the data protection obligations both owe.

What to look for in a security schedule

Standards, certifications and the ones you do not hold

The schedule will require the supplier to hold and maintain certifications, ISO 27001, Cyber Essentials Plus, SOC 2, PCI DSS where card data is involved, and to comply with the customer's own policies by reference. The review lists what the supplier holds, what it could obtain and what it cannot, and asks for the requirement to be limited to the certifications the supplier holds or an equivalent, for a period to obtain any it has agreed to, and for the customer's policies to be attached rather than incorporated by reference to documents that change.

The controls: what the schedule says you must do

Security schedules list technical and organisational controls: encryption at rest and in transit, multi-factor authentication, patching within set periods, logging and monitoring, vulnerability scanning, backup and recovery targets, secure development practices and data segregation. Article 32 of the UK GDPR and the Data Protection Act 2018 require measures appropriate to the risk, and the schedule turns that into specifics. The review checks each control against what the supplier operates, asks for the schedule to describe the supplier's controls rather than the customer's ideal, and for a compensating control to be acceptable where a listed control does not fit the supplier's architecture.

Breach notification: hours, content and what counts

The schedule will require notification of a security incident within hours, with a root cause analysis and remediation plan to follow, and will define an incident widely. The review asks for the definition to be limited to incidents affecting the customer's data or systems, for the notification period to run from the supplier's confirmation of the incident and to be measured in working hours, for the content of the first notice to be what the supplier knows at the time, and for the period to be short enough for the customer to meet its own 72-hour duty to the ICO under Article 33 of the UK GDPR without requiring the supplier to report suspicions it has not verified.

Audit, penetration testing and access to your systems

The customer will reserve rights to audit the supplier's security, to conduct or commission penetration tests, and to require remediation of findings. The review asks for audits on reasonable notice, no more than once a year, during working hours, by auditors bound by confidentiality, limited to systems used for the customer, with reliance on the supplier's existing audit reports where they cover the point; for penetration testing to be by agreement on scope, timing and rules of engagement, since testing without authority is unauthorised access under section 1 of the Computer Misuse Act 1990; and for remediation timescales to be agreed by reference to severity.

Personnel, sub-contractors and the supply chain

The schedule will require vetting of the supplier's staff, security training, background checks to a stated standard, and the same obligations imposed on sub-contractors and sub-processors. The review checks the vetting standard against what the supplier can lawfully do, asks for the obligation to flow down to be limited to sub-contractors with access to the customer's data, and checks the interaction with the sub-processor provisions required by Article 28 of the UK GDPR. Where the supplier is itself a relevant digital service provider under the Network and Information Systems Regulations 2018, its own statutory obligations should be reflected rather than duplicated.

Liability, the cap and the cost of the customer's response

Security schedules add obligations to indemnify the customer for the costs of a breach, including notification, credit monitoring, regulatory fines and the customer's own investigation, and place those obligations outside the liability cap in the main agreement. The review asks for breach-related liability to sit within a separate cap the supplier's cyber insurance supports, for regulatory fines to be recoverable only where the supplier's breach caused them and to the extent the law allows, for the customer's own costs to be reasonable and evidenced, and for the exclusions in the main agreement to apply to claims under the schedule, so that the schedule does not reopen a liability position already negotiated. The Late Payment of Commercial Debts (Interest) Act 1998 continues to apply to the fees.

What it costs

Standard review, £495. Marked-up document and a written explanation of the changes. Three working days.

Complex review, £895. Heavily negotiated or unusually complex documents. Five working days.

Buying online forms the engagement on payment. The scope is what the contract review page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • Your own contract returned with my amendments as tracked changes, plus a clean version with every change accepted, ready to send to the other side
  • Comments in the document where a point needs explaining
  • A written explanation of what I have changed and why, by email or as an attachment if it is lengthy, marking the points I would hold firm on and the ones that are negotiable
  • A view on what is normal market practice and what is the other side pushing their luck
  • One round of follow-up questions by email, included

What is not included

  • Negotiating directly with the other side, which I quote separately once I know who is on the other side. Where the other side is willing to share a live document, I can work in that document directly
  • Drafting a replacement contract from scratch
  • Advice on the law of any jurisdiction other than England and Wales
  • Tax, accounting or regulatory advice
  • Disputes about a contract that is already signed

Questions I am often asked

The schedule requires ISO 27001 and we do not have it. Do we have to get it?

Only if you agree to. The review asks for the requirement to be limited to the certifications you hold or an equivalent, with a period to obtain any you commit to, and for the customer to accept your existing audit reports and questionnaire answers as evidence in the meantime.

They want breach notification within twenty-four hours. Is that reasonable?

A short period is common because the customer has its own duty to the ICO within seventy-two hours. The review asks for the period to run from your confirmation of an incident affecting the customer's data, in working hours, with the first notice limited to what you know, and for the definition of an incident to exclude unverified suspicions.

The security schedule puts data breach liability outside the cap. Can we change that?

Customers negotiate this, because they know an uncapped indemnity is uninsurable. The review asks for a separate higher cap supported by your cyber insurance, limits fines and costs to those your breach caused, and keeps the main agreement's exclusions.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: September 2026. Email geoffrey@caesar.co.uk.