Skip to content
SecuriFii

Regulation

Most of your security obligations will arrive in a contract

Organisations plan for regulation and are surprised by contracts. For most technology and services firms, the binding obligations are commercial ones.

Facts checked2026-09-11

Where do most security obligations come from?

A security schedule in a master services agreement commits you to specific controls, notification windows, audit rights, sub-processor approval and sometimes certification by a date. These are enforceable, they are frequently signed by someone who did not check whether the commitments were achievable, and they rarely reach the security team before signature.

The practical defence is a review step: whoever signs commercial agreements sends the security schedule to whoever will have to deliver it, before signing. It takes an afternoon and prevents the standing problem of discovering, a year in, that you promised an annual penetration test nobody budgeted for.

The bottom line

Read the security schedule before you sign it. Most of what you will be audited against is in there, not in a statute.

Related insights