CheckoryCheckory
Security exhibit with SOC 2 Type II and 72-hour notice circled, no face

Vendor Security Addendum Review Checklist Before You Sign

Review a vendor security addendum before you sign: Type II not a badge, hours not promptly, pen-test plus fix days, then keep, attach or escalate.

9 min readArticle
💡

Key takeaway in 30 seconds

A vendor security addendum review checklist before signing is a keep / attach / escalate log for the security schedule, not the privacy contract. Ask for a current SOC 2 Type II report — an AICPA attestation over a period, not a Trust Centre badge. Replace promptly with hours that leave room for the ICO 72-hour clock. Lock annual pen-test plus fix days, then take report-first audit rights you will actually use.

Legal already filed the DPA — a data processing agreement. Sales said we are SOC 2. The security exhibit — the attached schedule — still says industry-standard controls and notify promptly. Nobody opened the Type II. Finance wants the tool live this week. Treat Exhibit C as its own paper: hours, evidence, then keep, attach, or escalate.

In September 2026, Nadia — Ops, 31-person UK health-tech — has Finance’s yes on a care-coordination SaaS. Tuesday she opens Exhibit C: industry-standard measures, SOC 2 upon request, notice promptly after confirmation. Sales sent a Trust Centre badge. The last Type II ended fourteen months ago. Go-live is Friday. Typical mistake: treating the badge as the report and promptly as a clock. The hidden risk is a weekend incident that burns the ICO 72-hour window.

Disclaimer: Checkory provides AI support, not legal advice. Consult a qualified lawyer for binding decisions.

Why is this not the DPA — only controls, evidence, and notice?

The DPA answers who is controller and where data may go. The security exhibit answers which controls, which evidence, how fast they tell you, and which audit you will use. If security lives only as industry-standard measures inside the DPA, treat that as a gap.

For Art. 28 roles, instructions, sub-processors and transfers, open the data processing agreement checklist. ICO contracts guidance is the DPA floor: Art. 28(3)(c) and (h) require security measures and audits. For auto-renew, cap and SLA, use the SaaS agreement red flags checklist.

  • Do: freeze the packet — the exact file set that will be signed — MSA — the master services agreement — plus order form, DPA, and Exhibit C.
  • Do not: skip Exhibit C because Legal already filed the DPA.

How do you tell a SOC 2 Type II from a marketing badge?

SOC 2 is an AICPA attestation by a CPA, not a UK law and not a website badge. Type I is control design as of a date. Type II is design and operating effectiveness over a period, typically 3–12 months. Ask for the full current Type II under NDA — a non-disclosure agreement.

AICPA’s SOC suite (2026): evaluate SOC services; “fast and easy” is a credibility risk. Drata Help: most customers ask for Type 2; there is no legal duty to have SOC 2. Scrut: treat a report as current for twelve months from the period end — Nadia’s 14-month-old Type II fails. Check type, period, scope and exceptions. ISO 27001 is a different artefact — parallel evidence, not a silent swap.

  • Do: ask for the current Type II and read scope, exceptions, and complementary user-entity controls.
  • Do not: accept a Trust Centre badge or a Type I on care data.
Type I versus Type II versus badge table: 14-month-old period and Trust Centre PDF fail
Type I versus Type II versus badge table: 14-month-old period and Trust Centre PDF fail

Type I vs Type II vs a badge

AskType IType IIBadge
What it isDesign as of one dateDesign plus effectiveness over 3–12 monthsMarketing, not the report
Nadia’s Friday testNot enough on care data14-month-old period failsTrust Centre PDF fails

Badge is not the report

Treating a Trust Centre badge as the Type II, and promptly after confirmation as a clock.

Why does incident notice need hours, not promptly?

Promptly is not a clock. Under UK GDPR Art. 33(1) the controller — Nadia’s Ltd, if they decide purposes — must notify the ICO without undue delay and, where feasible, not later than 72 hours after becoming aware. Art. 33(2) only makes the processor tell the controller without undue delay. No hours. Write a number.

ICO’s breach guide: the processor must inform you so you can still hit 72 hours; fail to notify when required and the fine colour is up to £8.7 million or 2% of global turnover. UK GDPR Art. 33 is statute (current to 29 August 2026). ContractKen: add 24 / 48 / 72 hours — often 24–48 so you still have investigation room. Start at awareness or reasonable suspicion, not confirmation. For example, Friday confirmation after Wednesday awareness burns the weekend. Pause wording: “Vendor shall notify Customer promptly after Vendor has confirmed a Security Incident.”

  • Do: write hours from awareness or reasonable suspicion, plus a named channel.
  • Do not: accept promptly or after confirmation as the only clock.
72-hour controller clock versus promptly after confirmation, hours from awareness
72-hour controller clock versus promptly after confirmation, hours from awareness

How do you lock pen-test cadence and fix windows?

Periodic and at Vendor’s discretion are not a cadence. Ask for an annual independent test, plus a retest after a material change. Take a written summary. Then lock fix days.

ComplyJet (2026 practitioner colour, not a law): a pen test usually needs to fall inside the Type II window; critical and high findings often sit at 7–14 days, medium at 30. If they only share “no criticals,” log the gap. Nadia’s “at Vendor’s discretion” with no fix window should pause Friday.

  • Do: lock annual (or after a material change) plus critical/high fix days.
  • Do not: accept periodic, vendor-discretion, or a one-line “no criticals.”

Which audit rights will you actually use (report first)?

Nadia’s 31-person team will not fly for an on-site. Write report-first rights: current Type II on request; a questionnaire annually; pen-test summary plus open high findings. Keep on-site as a fallback after a stale report or an incident.

Atlas on audit rights: start with the SOC 2 or pen-test they already have. Read complementary user-entity controls so she does not accept controls her team cannot run. Do not spend capital on “Customer pays everything, once every two years, only if no SOC 2 exists.”

  • Do: take annual Type II plus questionnaire plus summary.
  • Do not: accept theatre audit rights her team will never use.

Keep / attach / escalate

TrackKeep whenAttach a short addendumEscalate
EvidenceCurrent Type II, in scopeDelivery SLA for the next reportBadge only; Type I on care data; stale Type II
NoticeHours from awarenessReplace promptly / after confirmationClock starts only after confirmation
TestsAnnual pen-test plus fix daysAdd cadence and remediation daysAt vendor discretion; no fix window
AuditReport-first with a delivery SLAQuestionnaire plus summaryBuyer-pays theatre once in two years

Keep, attach your addendum, or escalate?

Keep when the Type II is current and in scope, hours run from awareness, pen-test is annual with fix days, and report-first evidence wins on precedence. Attach a short buyer schedule when the paper still says industry standard or promptly. Escalate when they refuse to attach, or when Friday would rest on a badge.

UK Government “Contracting securely” (updated 25 June 2026) is the idea — pick a short schedule. If Exhibit C also says they may improve the service from your files, that is a different review: vendor AI training rights. Pause wording: promptly after confirmation; SOC 2 upon request; pen-test at Vendor’s discretion. Those are a High flag — wording a human must verify before anyone signs — for counsel — a qualified lawyer. Success bar: a one-page log and one sentence that would pause signature. Workflow: packet → exhibit ≠ DPA → Type II not badge → hours not promptly → pen-test + fix days → report-first → keep / attach / escalate. Checkory can run a first-pass — a first machine pass — on the same file at document analysis. A named human still opens every High sentence.

  • Do: highlight one High sentence, then keep, attach your addendum, or escalate.
  • Do not: tell Finance the paper is closed because Legal filed the DPA.
Keep, attach, or escalate board for Type II, hours, pen-test, and report-first rights
Keep, attach, or escalate board for Type II, hours, pen-test, and report-first rights

Security addendum review

1

Freeze the exhibit, not the DPA

Lock MSA + order form + DPA + Exhibit C. Search security, SOC 2, incident, promptly, pen-test, audit.

2

Ask for the current Type II

Full report under NDA. Check type, period, scope, exceptions. A badge is not the report.

3

Put hours on notice

Replace promptly / after confirmation with hours from awareness. Name the channel.

4

Lock pen-test plus fix days

Annual and after a material change. Independent tester. Written summary. Critical/high fix days.

5

Write report-first audit rights

Type II + questionnaire + summary on a delivery SLA. On-site only if the report is stale.

6

Keep, attach, or escalate

Circle one High sentence. Attach a short addendum if promptly stays. Escalate if they refuse.

Frequently asked questions

Is SOC 2 Type I enough for a vendor that will touch care data?
No. Type I is design as of a date. For care-adjacent data ask for a current Type II in scope.
What if they only share a SOC 2 summary or Trust Centre badge?
Ask for the full current Type II under NDA. If they refuse, attach your addendum or escalate.
What is the difference between a security addendum and a DPA?
The DPA is Art. 28: roles, instructions, sub-processors, transfers. The addendum is controls, evidence and hours. Open the data processing agreement checklist for that walk.
Is promptly after confirmation enough for the ICO 72-hour clock?
No. Write hours from awareness or reasonable suspicion. UK GDPR Art. 33(2) gives the processor no hours.
How do you review a vendor security schedule before Friday?
Freeze Exhibit C. Type II not badge. Hours not promptly. Annual pen-test plus fix days. Then keep, attach or escalate.

Highlight Security

Upload the same exhibit. A human still reads every High gap.

Start document analysis

What to do next

Sources

Read also

Related guides

Updated: September 1, 2026