Requirements
Agreeing concrete security requirements with vendors
Control objectives only become manageable when scope, deadline, evidence, reporting path and the consequences of a deviation fit the specific service.
9 minute read · Content as of 21.07.2026
Requirements must be phrased so they can be verified
Statements such as “appropriate security” need operational substance. Define, for example, deadlines for critical vulnerabilities, reporting paths for incidents, required recovery objectives and the evidence to be provided.
Technology and governance belong together
UP KRITIS structures possible requirements through, among others, vulnerability and patch management, system hardening, remote access, secure development, operations, incident reporting, audits and non-technical security.
- roles, contacts and escalation
- vulnerability, patch and incident deadlines
- subcontractors and change notification
- audit, data return, deletion and exit
Sources used
- Best practice recommendations for supplier requirements · UP KRITIS / BSI · Version 4.0, 2023
- ISO/IEC 27036-2:2022 – Requirements · ISO · 2022
- Vendor, due diligence and exit patterns · KaitoSec