Subcontractor Cyber Requirements in Your Contracts: A Guide

General contractors increasingly pass cyber duties to subs. Learn what to include, how to keep terms realistic, and how subs can prepare to meet them.

3 min readBy Ironfield Cyber Team

A general contractor shares plans, schedules, payment data, and sometimes sensitive owner information with dozens of subcontractors. Each of them is a path into the GC's data. At the same time, subcontractors are asked to sign agreements with security language they may not fully understand. Both sides benefit from clear, realistic cyber terms.

This guide helps general contractors write sensible requirements and helps subcontractors read and respond to them. It is not legal advice; your attorney should review any contract language.

Why It Matters

Problems rarely start at the GC's headquarters. A small trade partner's compromised email account sends a convincing invoice change request. A shared project folder remains open to a former subcontractor employee. A subcontractor's laptop with downloaded drawings is stolen or infected. Contract terms will not prevent these events, but they set expectations, speed response, and clarify who is responsible.

For General Contractors: What to Include

Keep requirements proportional

A ten-person specialty trade cannot run a security operations center. Scale requirements to the sensitivity of the project and the access the sub receives. A tiered approach works well: a baseline for everyone and added requirements for subs with deeper access or sensitive projects.

A reasonable baseline

  1. Multi-factor authentication on email and any systems used to access project data.
  2. Unique accounts for every individual with access to project platforms.
  3. Prompt removal of access when someone leaves the project or the company.
  4. Basic device protection, including current operating system updates and endpoint security software.
  5. Phishing awareness for staff who handle project communications and payments.
  6. Incident notification, requiring the sub to inform you within a stated period if an incident may affect your data or your payment communications.
  7. Payment verification, committing both parties to confirm banking changes through a known phone number before any payment is redirected.

Handling sensitive projects

For defense, utility, healthcare, or other sensitive work, flow down the specific obligations that your own contract requires. If your prime contract involves Controlled Unclassified Information, subs that handle it must meet the applicable requirements, and the flow-down language must be accurate and specific. Get your attorney and compliance lead involved early.

Ask for evidence, not just promises

Consider requesting a short security questionnaire or attestation at onboarding. Do not demand lengthy audits from small subs unless the risk justifies them.

Plan for offboarding

Include terms on return or deletion of project data at completion, and make sure your own team removes platform access promptly.

For Subcontractors: How to Respond

Read before you sign

Highlight any clause mentioning security, data, insurance, indemnification, or notification. If a term is unclear, ask for clarification rather than signing and hoping.

Know what you can honestly promise

Do not agree to requirements you cannot meet. Overpromising creates contractual liability. If you lack multi-factor authentication or endpoint protection, make a plan to implement it and tell the GC your timeline.

Build a simple security summary

Keep a one-page document describing your practices: MFA, backups, device management, training, and incident contact. Reusing it across bids saves time and builds credibility.

Check insurance

Understand what your cyber and crime coverage includes, especially social engineering and funds transfer fraud. Policies often have conditions, and an unmet condition can affect a claim.

Common Pitfalls

  • Copy-and-paste clauses that reference standards or technologies that do not apply
  • Unlimited liability language that a small sub cannot accept
  • Notification windows that are unrealistic, such as demanding notice within hours without a way to contact anyone
  • No path to compliance, where subs are penalized rather than helped
  • Ignoring the human side, such as who actually receives notifications at the GC

Make Communication Easy

Provide a named security contact and a simple way to report issues. Subs are more likely to disclose a problem quickly if they know where to send it and are not afraid of immediate punishment.

A Collaborative Approach

The best programs treat security as a shared interest. Offer a short onboarding guide, a checklist, or a brief call explaining expectations. Subs who feel supported tend to follow through.

How Ironfield Cyber Helps

Ironfield Cyber works with general contractors to design tiered security requirements and with subcontractors to meet them. If you are preparing contract language or trying to answer a questionnaire, we can help you do it accurately and without unnecessary burden.