Subcontractor Cyber Requirements: What to Put in Your Contracts

Your subs touch your data, systems, and payments. Here is how to write practical cyber expectations into subcontracts without scaring off good trades.

3 min readBy Ironfield Cyber Team

A general contractor shares a lot with its subcontractors: plans, schedules, pay applications, banking details, and sometimes access to project platforms. If a sub's email is compromised, the attacker can read your messages, impersonate that sub, and redirect payments. Yet many subcontract agreements say nothing at all about cybersecurity.

Adding reasonable expectations to contracts is not about burdening small trades. It is about making sure everyone in the chain handles shared information with the same baseline care. Here is a practical approach.

Start with what you actually share

Before drafting language, list what flows between you and subcontractors.

  • Drawings, specifications, and models
  • Schedules, RFIs, and submittals
  • Pay applications, lien waivers, and banking details
  • Access to a project platform or shared folders
  • Sensitive owner information or security-related details for certain facilities

Requirements should match the sensitivity. A sub receiving ordinary plans needs lighter obligations than one handling controlled information or access to critical facility systems.

A tiered approach works best

Baseline for all subcontractors

Keep it simple and achievable.

  • Use multifactor authentication on email and any shared project platform.
  • Keep software on company computers and phones updated.
  • Use unique accounts for each user on shared platforms, with no shared logins.
  • Verify any change in payment instructions through a known phone number before acting.
  • Notify you promptly if an account or device that handled your project information is compromised.
  • Remove access for personnel who leave the project or the company.

Enhanced requirements for higher-risk work

For subs with deeper access or sensitive information, you might add expectations like endpoint protection, encrypted devices, security awareness training for staff, and written incident response contacts. Where you are subject to government or customer requirements, such as handling controlled unclassified information, flow-down clauses may be mandatory. Have counsel confirm which clauses apply to your contracts.

Contract language to consider

Work with your attorney to draft the exact language. Topics commonly covered include:

  1. Safeguards: a short statement of the minimum security measures.
  2. Incident notification: a defined timeframe for telling you about a suspected compromise that affects your project.
  3. Payment verification: a statement that payment instruction changes must be confirmed by callback and that you may delay payment pending verification.
  4. Access and return of data: how access is granted, reviewed, and removed, and what happens to project data at project close.
  5. Cooperation: an obligation to help with investigation and notification when an incident affects shared information.
  6. Flow-down: a requirement that the sub pass relevant obligations to its own lower-tier subs.

Avoid vague promises of "industry standard security" that no one can measure. Specific, modest requirements are more enforceable and more likely to be followed.

Make it workable for small trades

A five-person trade company does not have an IT department. If your requirements are unrealistic, they will be ignored or you will lose good partners. Consider helping by:

  • Providing a one-page security expectations sheet in plain language
  • Offering a short, free training session or briefing during onboarding
  • Giving subs a simple way to report suspicious emails or incidents
  • Using your own platform's built-in controls, such as required sign-in methods, so the burden sits on the platform

Verify, lightly

You do not need a full audit of every sub. A short questionnaire at prequalification, with a few yes or no questions about multifactor authentication, backups, and incident reporting, gives you a useful view. For higher-risk subs, ask for more detail or documentation. Review answers and follow up on anything that concerns you.

Manage the payment channel

Because payment diversion often targets subs and general contractors alike, set a firm process for banking changes. Document who at the sub is authorized to request changes, require a callback to a known number, and apply the same rule to your own staff.

Review and update

Revisit your template language yearly. Threats and customer expectations change, and your clause library should keep up.

Where Ironfield Cyber fits

Ironfield Cyber can help you define a sensible tiered baseline, create a prequalification questionnaire, and prepare plain-language guides for your subcontractors. Your attorney handles the legal wording, and we help make sure the technical expectations are realistic.