The security annex, clause by clause: what a prime contractor is really asking for

The questionnaire is a filter. The annex is the contract. Ten clauses that now appear in almost every prime contractor security schedule, what each one costs a supplier to satisfy, and the three that are genuinely negotiable.

Daniel Grigorovich
Daniel Grigorovich
Founder · 16 Sept 2026 · 9 min read
SpaceSupply chainGRC
The security annex, clause by clause

Who should read this: a supplier of twenty to two hundred people that has just received a draft contract from a prime contractor, a satellite operator or an agency, with a security annex attached and a signature date two weeks out.

The questionnaire and the annex are different instruments and get confused constantly. A questionnaire is a filter: it decides whether you proceed. The annex is a contract: it decides what you are liable for afterwards. Suppliers spend weeks on the questionnaire and sign the annex on the assumption that it says the same things.

It does not. The questionnaire asks whether you have a control. The annex tells you what happens when you do not, and attaches a clock, an audit right and a termination trigger to each one. The experience of not being able to answer the first document is covered in the security questionnaire you cannot answer. This is about the second one.

Why the annex got longer

Two things changed and both push obligations down the chain.

Under NIS2, supply chain security is not advisory. Commission Implementing Regulation (EU) 2024/2690 sets out, at point 5 of its Annex, that an entity must operate a supply chain security policy governing its relationships with direct suppliers: selection criteria, contractual requirements, and a maintained directory of suppliers monitored across the life of the relationship. ENISA’s Technical Implementation Guidance of 26 June 2025 breaks that into the security requirements a contract is expected to carry, which read almost exactly like the annex you have just been sent: confidentiality, integrity and availability commitments, incident notification, audit and verification rights, vulnerability disclosure and handling, and termination procedures.

In space specifically there is a second source. The Commission’s EU Space Act proposal of June 2025 puts supply chain obligations in Article 92 and Annex VII point 6: operators must include contractual information security requirements for manufacturers and service providers, reduce supply chain risk, and inventory critical non-EU origin assets. The Council and Parliament texts disagree about whether this should be a separate regime or folded into NIS2, and the trilogue has not concluded, so nothing here binds you yet. That does not matter commercially. Your customer is drafting for the regime they expect, not the one in force, and the four overlapping regimes a space supplier now sits under are mapped in space suppliers and the four regimes.

Clause one: compliance with a named standard, or equivalent

The clause names ISO 27001, or a sector standard, or NIST, and adds “or equivalent”. The word “equivalent” is where suppliers relax and should not.

Equivalent means the customer decides, later, usually during an audit, whether what you have is equivalent. An uncertified supplier can satisfy this, but only by being able to show the control set and the evidence behind it on demand. If there is a certificate the conversation ends; without one it becomes a demonstration, every time.

What it costs: nothing to sign, considerable to satisfy without a certificate. This is the clause that turns into an annual workload.

Clause two: incident notification within a fixed period

Usually twenty four hours from becoming aware, sometimes twelve, occasionally as tight as four for anything touching the customer’s environment. Increasingly the clause defines an incident broadly enough to include a suspected compromise, not a confirmed one.

Two traps. The first is that the clock starts on awareness, and awareness is a function of detection you may not have. The second is that most annexes require notification of incidents affecting your own estate even when the customer’s systems are untouched, which is a much wider duty than suppliers assume. The regulatory clocks these clauses mirror are set out in the NIS2 incident reporting timeline.

What it costs: a named contact who is reachable, a written internal trigger for what counts, and logging with retention long enough to answer the questions that follow the notification. A twelve hour clock is meaningless if the logs roll off in seven days.

Clause three: audit and inspection rights

The customer reserves the right to audit you, on notice, sometimes with a third party, sometimes on site. Some annexes extend this to your subcontractors.

Most primes never exercise it. The ones that do, do it after an incident somewhere else in their supply chain, which means the audit arrives at the worst possible time and with a short notice period.

What it costs: the ability to produce evidence within the notice period stated. If the notice is ten business days and your evidence takes three weeks to assemble, you are in breach of a clause you thought you had satisfied.

Clause four: vulnerability disclosure and patching commitments

A duty to accept vulnerability reports, to have a route for a researcher or the customer to reach you, and to remediate within stated windows by severity. Critical in seven days is common, high in thirty.

The window is measured from disclosure, not from when you noticed. If you do not track what you run, you cannot know whether the clock is running.

What it costs: a published contact, a triage owner, and a dependency inventory for anything you ship.

Clause five: personnel screening and named access

Background checks to a stated level, nationality or residency requirements on some programmes, and a named list of individuals with access rather than a headcount. Changes to the list require notification and sometimes approval.

What it costs: an access list that is true. This is the clause most often failed, and the failure is structural rather than negligent, because access is granted precisely and revoked from memory. What an operator checks, and how the list is tested, is set out in ground segment access and what operators check.

Clause six: subcontractor flow-down and disclosure

You must impose equivalent terms on anyone you use, disclose them in advance, and often obtain written consent before adding one. Some annexes require the customer to be able to veto a subcontractor.

Read this one carefully, because “subcontractor” is frequently drafted to include cloud and SaaS providers. A supplier that has not listed its hosting provider, its CI service and its ticketing tool is already non-compliant on signature. The buyer-side view of the same obligation, which is what your customer is working from, is in NIS2 supply chain security and vendor risk.

What it costs: a maintained supplier register with security terms and review dates, which you needed anyway.

Clause seven: data location, sovereignty and export control

Where data may be stored and processed, which jurisdictions are excluded, and who may access it from where. On defence and institutional programmes this extends to export control classifications and to staff nationality.

What it costs: knowing which of your tools store data where, including the backup and log copies that are easy to forget.

Clause eight: return and destruction at termination

On the end of the contract, return or destroy all customer data within a stated period and certify it in writing.

The certificate is the problem. Certifying destruction requires knowing every copy: production, backups, the analytics warehouse, the engineer’s laptop, the support ticket with an attachment.

What it costs: a data map. Most suppliers sign this clause and could not honour it today.

Clause nine: liability, indemnity and insurance

A carve-out from the general liability cap for security breaches, an indemnity for regulatory fines and third-party claims, and a requirement to carry cyber insurance at a stated limit.

What it costs: real money, and it is the clause your insurer and your lawyer should see. It is also the clause most likely to be negotiated successfully, because primes expect it to be.

Clause ten: termination on a material security incident

The right to terminate, sometimes immediately, on a material incident or a failure to meet the annex. Occasionally paired with a right to suspend access pending investigation.

What it costs: nothing until it happens, and everything when it does. “Material” is almost never defined, and defining it is worth more than shaving a day off the notification clock.

The three clauses that are actually negotiable

Primes expect resistance on some clauses and not others. Push on the wrong ones and you look unprepared.

  • Liability and indemnity. Uncapped indemnity for regulatory fines is standard drafting and routinely reduced to a multiple of contract value.
  • The definition of a material incident, and of an incident at all. Getting a threshold written in is usually accepted, and it converts an open obligation into a bounded one.
  • Audit notice periods and frequency. Ten business days rather than five, once a year rather than on demand, and remote rather than on site for routine checks.

What is rarely negotiable: the notification clock, the flow-down duty, and the named standard. Those come from the customer’s own regulatory obligation, and they have no discretion to waive them for you.

What to build once, so the next annex is free

Across primes, operators and agencies, these annexes ask overlapping questions in different words. The common core is small.

An access list generated from systems and reconciled against contracts and payroll. A supplier register with security terms and review dates. Logging with retention that survives an investigation rather than retention that satisfies a default. A dependency inventory for anything you ship. A data map that makes a destruction certificate honest. A named contact with a written trigger for what counts as an incident.

Build that and the next annex is a mapping exercise rather than a project. Build it per customer and you will do the same work three more times, which is the argument made generally in evidence that assembles itself. If you want the gap measured before a prime measures it for you, an independent security audit starts there, and the space sector page sets out how the obligations stack up.

The technical reality: the annex asks about state, your records describe intent

Every clause above is written in the present tense about a live condition. Who has access right now. What is running right now. Which suppliers touch customer data right now.

What a supplier brings to the conversation is a set of documents describing what was decided. The access list was true when it was written. The supplier register was accurate at the last review. The dependency inventory was generated at the last release. Each one is a photograph of an intent, and the annex is asking about the present.

That gap is why supplier access keeps appearing in incident reports while supplier questionnaires keep coming back clean. The questionnaire asks whether you have a leaver process and you truthfully answer yes. Nobody asks whether the process ran last month, and the answer is often no.

Closing it is specific work: the access list generated continuously from your identity systems and reconciled against HR and contract end dates, orphaned accounts raised as findings rather than discovered at audit, dependencies and their known vulnerabilities tracked against what you actually ship, and the evidence a prime asks for produced by the work rather than assembled the fortnight before. That runs continuously and automatically, with nothing to install on your side. The difference it makes to an annex is that the answers stay true between reviews, which is the only version of compliance a prime contractor is actually buying.

Daniel Grigorovich

Daniel Grigorovich · Founder

I believe that no business should suffer from "compliance checklists" or navigating vague regulatory text. While I still stand by the principle that all software products should be reliable and secure, I want to give companies a way to overcome the challenges faced when implementing these requirements.