General contractors invest in their own security, then share drawings, schedules, and project platforms with dozens of subcontractors who may have far less protection. A compromised sub can expose your project documents, send fraudulent invoices from a hijacked account, or provide a path into your systems.
Cyber requirements in subcontracts are no longer unusual. Owners, primes, and insurers increasingly ask about them. The key is writing terms that are meaningful, proportionate, and enforceable, without scaring off good trade partners.
Start With Risk Tiers
Not every subcontractor needs the same requirements. Group them by risk:
- High. Subs with access to your systems, sensitive project data, or controlled information, and those handling large payments
- Medium. Subs who receive and upload project documents through shared platforms
- Low. Small suppliers or short-duration trades with minimal data exchange
Scale the requirements accordingly. A small landscaping contractor should not receive the same questionnaire as a mechanical contractor with model access and a large contract.
Core Terms to Consider
Baseline Security Practices
Require reasonable safeguards, described in plain terms:
- Multifactor authentication on email and any shared platforms
- Current patching and endpoint protection on devices used for the project
- Unique user accounts, with no shared logins
- Basic employee security awareness training
- Secure handling and disposal of project information
Access and Account Management
- Named individuals for platform access, with prompt notice when someone leaves the project or company
- Rules against sharing credentials
- Agreement to follow your access procedures for project platforms
Payment and Banking Safeguards
- Banking changes must be requested in writing through a designated channel and verified by callback to a known number
- The sub must notify you immediately if their email is compromised, since fraudulent payment requests may follow
- Agreement that you may delay payment while verifying suspicious changes without being in breach
Incident Notification
Require prompt notice of security incidents affecting project information or your systems, with a defined timeframe and a named contact. Make sure that notification does not depend on email alone.
Flow-Down Obligations
If your prime contract or owner imposes security terms, such as handling of controlled information, pass them down. Confirm which clauses must flow down and have counsel review the language. For defense work, flow-down requirements can be specific, so rely on the contract text.
Data Return and Disposal
At project end, subs should return or securely delete project information as directed, subject to their own legal record requirements.
Audit and Cooperation
Reserve the right to ask for reasonable evidence of compliance, such as a completed questionnaire or confirmation of key controls, and require cooperation during an investigation.
Keep the Language Practical
Avoid requirements that smaller firms cannot meet or understand. Prefer clear, outcome-based statements over lengthy technical specifications. Offer a one-page summary in plain English alongside the legal terms. Consider providing guidance or resources so partners can improve.
Verify, Do Not Just Collect
A signed contract does not prove practice. Right-size verification:
- For high-risk subs, ask for documentation such as an insurance certificate showing cyber coverage, or evidence of MFA and training
- Use short questionnaires and review answers, following up on gaps
- Periodically review who from each sub still has access to your platforms
- Watch for warning signs, like unusual emails from a sub's account
Handle Gaps Constructively
When a sub falls short, work toward a fix rather than automatic disqualification where risk allows. For critical gaps, restrict their access to what is necessary until they improve.
Align With Insurance and Counsel
Talk to your insurance broker about how your policy treats losses originating with vendors, and what contractual protections matter. Have an attorney review the language to ensure it is enforceable and consistent with your overall contract structure.
Review Periodically
Update the terms annually as threats and expectations change. Track which requirements cause the most friction and adjust.
Where to Start
If you have nothing today, begin with three clauses: multifactor authentication for project accounts, written and verified banking changes, and prompt incident notification. Add tiers and verification over time.
Ironfield Cyber helps contractors define practical subcontractor security requirements and build lightweight verification processes. If you would like a sample requirements outline to review with your counsel, we can help you draft one.