Skip to content

Requirements

Agreeing concrete security requirements with vendors

Control objectives only become manageable when scope, deadline, evidence, reporting path and the consequences of a deviation fit the specific service.

Back to Third-party risk

9 minute read · Content as of 21.07.2026

Requirements must be phrased so they can be verified

Statements such as “appropriate security” need operational substance. Define, for example, deadlines for critical vulnerabilities, reporting paths for incidents, required recovery objectives and the evidence to be provided.

Technology and governance belong together

UP KRITIS structures possible requirements through, among others, vulnerability and patch management, system hardening, remote access, secure development, operations, incident reporting, audits and non-technical security.

  • roles, contacts and escalation
  • vulnerability, patch and incident deadlines
  • subcontractors and change notification
  • audit, data return, deletion and exit

Sources used

Back to Third-party risk