
Vendor Security Addendum Review Checklist Before You Sign
Review a vendor security addendum before you sign: Type II not a badge, hours not promptly, pen-test plus fix days, then keep, attach or escalate.
Key takeaway in 30 seconds
A vendor security addendum review checklist before signing is a keep / attach / escalate log for the security schedule, not the privacy contract. Ask for a current SOC 2 Type II report — an AICPA attestation over a period, not a Trust Centre badge. Replace promptly with hours that leave room for the ICO 72-hour clock. Lock annual pen-test plus fix days, then take report-first audit rights you will actually use.
Legal already filed the DPA — a data processing agreement. Sales said we are SOC 2. The security exhibit — the attached schedule — still says industry-standard controls and notify promptly. Nobody opened the Type II. Finance wants the tool live this week. Treat Exhibit C as its own paper: hours, evidence, then keep, attach, or escalate.
In September 2026, Nadia — Ops, 31-person UK health-tech — has Finance’s yes on a care-coordination SaaS. Tuesday she opens Exhibit C: industry-standard measures, SOC 2 upon request, notice promptly after confirmation. Sales sent a Trust Centre badge. The last Type II ended fourteen months ago. Go-live is Friday. Typical mistake: treating the badge as the report and promptly as a clock. The hidden risk is a weekend incident that burns the ICO 72-hour window.
Disclaimer: Checkory provides AI support, not legal advice. Consult a qualified lawyer for binding decisions.
Why is this not the DPA — only controls, evidence, and notice?
The DPA answers who is controller and where data may go. The security exhibit answers which controls, which evidence, how fast they tell you, and which audit you will use. If security lives only as industry-standard measures inside the DPA, treat that as a gap.
For Art. 28 roles, instructions, sub-processors and transfers, open the data processing agreement checklist. ICO contracts guidance is the DPA floor: Art. 28(3)(c) and (h) require security measures and audits. For auto-renew, cap and SLA, use the SaaS agreement red flags checklist.
- Do: freeze the packet — the exact file set that will be signed — MSA — the master services agreement — plus order form, DPA, and Exhibit C.
- Do not: skip Exhibit C because Legal already filed the DPA.
How do you tell a SOC 2 Type II from a marketing badge?
SOC 2 is an AICPA attestation by a CPA, not a UK law and not a website badge. Type I is control design as of a date. Type II is design and operating effectiveness over a period, typically 3–12 months. Ask for the full current Type II under NDA — a non-disclosure agreement.
AICPA’s SOC suite (2026): evaluate SOC services; “fast and easy” is a credibility risk. Drata Help: most customers ask for Type 2; there is no legal duty to have SOC 2. Scrut: treat a report as current for twelve months from the period end — Nadia’s 14-month-old Type II fails. Check type, period, scope and exceptions. ISO 27001 is a different artefact — parallel evidence, not a silent swap.
- Do: ask for the current Type II and read scope, exceptions, and complementary user-entity controls.
- Do not: accept a Trust Centre badge or a Type I on care data.

Type I vs Type II vs a badge
| Ask | Type I | Type II | Badge |
|---|---|---|---|
| What it is | Design as of one date | Design plus effectiveness over 3–12 months | Marketing, not the report |
| Nadia’s Friday test | Not enough on care data | 14-month-old period fails | Trust Centre PDF fails |
Badge is not the report
Treating a Trust Centre badge as the Type II, and promptly after confirmation as a clock.
Why does incident notice need hours, not promptly?
Promptly is not a clock. Under UK GDPR Art. 33(1) the controller — Nadia’s Ltd, if they decide purposes — must notify the ICO without undue delay and, where feasible, not later than 72 hours after becoming aware. Art. 33(2) only makes the processor tell the controller without undue delay. No hours. Write a number.
ICO’s breach guide: the processor must inform you so you can still hit 72 hours; fail to notify when required and the fine colour is up to £8.7 million or 2% of global turnover. UK GDPR Art. 33 is statute (current to 29 August 2026). ContractKen: add 24 / 48 / 72 hours — often 24–48 so you still have investigation room. Start at awareness or reasonable suspicion, not confirmation. For example, Friday confirmation after Wednesday awareness burns the weekend. Pause wording: “Vendor shall notify Customer promptly after Vendor has confirmed a Security Incident.”
- Do: write hours from awareness or reasonable suspicion, plus a named channel.
- Do not: accept promptly or after confirmation as the only clock.

How do you lock pen-test cadence and fix windows?
Periodic and at Vendor’s discretion are not a cadence. Ask for an annual independent test, plus a retest after a material change. Take a written summary. Then lock fix days.
ComplyJet (2026 practitioner colour, not a law): a pen test usually needs to fall inside the Type II window; critical and high findings often sit at 7–14 days, medium at 30. If they only share “no criticals,” log the gap. Nadia’s “at Vendor’s discretion” with no fix window should pause Friday.
- Do: lock annual (or after a material change) plus critical/high fix days.
- Do not: accept periodic, vendor-discretion, or a one-line “no criticals.”
Which audit rights will you actually use (report first)?
Nadia’s 31-person team will not fly for an on-site. Write report-first rights: current Type II on request; a questionnaire annually; pen-test summary plus open high findings. Keep on-site as a fallback after a stale report or an incident.
Atlas on audit rights: start with the SOC 2 or pen-test they already have. Read complementary user-entity controls so she does not accept controls her team cannot run. Do not spend capital on “Customer pays everything, once every two years, only if no SOC 2 exists.”
- Do: take annual Type II plus questionnaire plus summary.
- Do not: accept theatre audit rights her team will never use.
Keep / attach / escalate
| Track | Keep when | Attach a short addendum | Escalate |
|---|---|---|---|
| Evidence | Current Type II, in scope | Delivery SLA for the next report | Badge only; Type I on care data; stale Type II |
| Notice | Hours from awareness | Replace promptly / after confirmation | Clock starts only after confirmation |
| Tests | Annual pen-test plus fix days | Add cadence and remediation days | At vendor discretion; no fix window |
| Audit | Report-first with a delivery SLA | Questionnaire plus summary | Buyer-pays theatre once in two years |
Keep, attach your addendum, or escalate?
Keep when the Type II is current and in scope, hours run from awareness, pen-test is annual with fix days, and report-first evidence wins on precedence. Attach a short buyer schedule when the paper still says industry standard or promptly. Escalate when they refuse to attach, or when Friday would rest on a badge.
UK Government “Contracting securely” (updated 25 June 2026) is the idea — pick a short schedule. If Exhibit C also says they may improve the service from your files, that is a different review: vendor AI training rights. Pause wording: promptly after confirmation; SOC 2 upon request; pen-test at Vendor’s discretion. Those are a High flag — wording a human must verify before anyone signs — for counsel — a qualified lawyer. Success bar: a one-page log and one sentence that would pause signature. Workflow: packet → exhibit ≠ DPA → Type II not badge → hours not promptly → pen-test + fix days → report-first → keep / attach / escalate. Checkory can run a first-pass — a first machine pass — on the same file at document analysis. A named human still opens every High sentence.
- Do: highlight one High sentence, then keep, attach your addendum, or escalate.
- Do not: tell Finance the paper is closed because Legal filed the DPA.

Security addendum review
Freeze the exhibit, not the DPA
Lock MSA + order form + DPA + Exhibit C. Search security, SOC 2, incident, promptly, pen-test, audit.
Ask for the current Type II
Full report under NDA. Check type, period, scope, exceptions. A badge is not the report.
Put hours on notice
Replace promptly / after confirmation with hours from awareness. Name the channel.
Lock pen-test plus fix days
Annual and after a material change. Independent tester. Written summary. Critical/high fix days.
Write report-first audit rights
Type II + questionnaire + summary on a delivery SLA. On-site only if the report is stale.
Keep, attach, or escalate
Circle one High sentence. Attach a short addendum if promptly stays. Escalate if they refuse.
Frequently asked questions
Is SOC 2 Type I enough for a vendor that will touch care data?▼
What if they only share a SOC 2 summary or Trust Centre badge?▼
What is the difference between a security addendum and a DPA?▼
Is promptly after confirmation enough for the ICO 72-hour clock?▼
How do you review a vendor security schedule before Friday?▼
Highlight Security
Upload the same exhibit. A human still reads every High gap.
Start document analysisWhat to do next
Review the exhibit
Upload the Exhibit C you will rely on.
RelatedData processing agreement checklist
Art. 28 roles, not this exhibit.
RelatedSaaS agreement red flags checklist
Whole MSA plus order form.
RelatedHow to Redline a Vendor Contract Before Signing
Open the sibling checklist after this screen.
RelatedVendor Contract Red Flags Checklist for Ops Teams
Open the sibling checklist after this screen.
Sources
Read also
Related guides





