ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Contractor NDA Template

Contractor NDA Template

Contractor Non-Disclosure Agreement (NDA)

1. Purpose

This Contractor Non-Disclosure Agreement (NDA) establishes the confidentiality and information-security obligations of a contractor, consultant, freelancer, temporary worker, or other external individual engaged by the Company.

The purpose is to protect Company, customer, supplier, employee, technical, security, personal, and other confidential information that the Contractor may access during the engagement.

Core Principle

Authorize → Access Only What Is Required → Protect → Use Only for the Engagement → Do Not Disclose → Return/Delete → Revoke Access → Maintain Confidentiality After Exit


2. Parties

This Agreement is entered into between:

Company: __________________________________________

Contractor: ________________________________________

Contractor Company, if applicable: ____________________

Engagement/Contract ID: _____________________________

Service/Project: ____________________________________

Contract Start Date: ________________________________

Expected End Date: _________________________________

Contractor Contact: _________________________________

The Company and Contractor are collectively referred to as the “Parties.”


3. Purpose of Engagement

The Contractor is being engaged to provide:

The Contractor may receive access to Company or third-party information solely to perform the authorized services.

The Contractor must not use such information for any purpose unrelated to the engagement.


4. Definition of Confidential Information

Confidential Information means non-public information belonging to or entrusted to the Company, its customers, suppliers, employees, partners, or other authorized parties that the Contractor receives, accesses, creates, develops, or becomes aware of through the engagement.

Confidential Information includes, but is not limited to:

Business Information

  • Business plans
  • Strategy
  • Financial information
  • Pricing
  • Commercial information
  • Customer information
  • Supplier information
  • Contracts
  • Internal processes
  • Business reports
  • Product roadmaps
  • Sales and marketing information

Customer Information

  • Customer records
  • Customer contracts
  • Customer systems
  • Customer configurations
  • Customer credentials
  • Customer reports
  • Customer data
  • Customer security information
  • Customer technical information

Personal Information

  • Employee information
  • Customer personal data
  • Supplier information
  • Contact information
  • Identification information
  • Financial information
  • Other personal information processed by the Company

Technical Information

  • Source code
  • Software architecture
  • APIs
  • Database structures
  • System configurations
  • Infrastructure diagrams
  • Technical documentation
  • Scripts
  • Automation
  • Algorithms
  • Development processes
  • Deployment configurations

Information Security Information

  • Security architecture
  • Vulnerability information
  • Penetration-test results
  • Security findings
  • Risk assessments
  • Incident information
  • Security monitoring information
  • Security configurations
  • Security reports
  • Security procedures

Credentials and Secrets

  • Passwords
  • API keys
  • Access tokens
  • SSH keys
  • Cloud credentials
  • Database credentials
  • Certificates
  • Encryption keys
  • Service-account credentials
  • Recovery codes
  • Other authentication information

Intellectual Property

  • Designs
  • Product concepts
  • Inventions
  • Research
  • Documentation
  • Software
  • Proprietary methodologies
  • Technical developments
  • Trade secrets

5. Information Classification

The Contractor must comply with the Company’s information-classification requirements.

Information may be classified as:

ClassificationExample
PublicApproved public information
InternalInternal procedures and operational information
ConfidentialCustomer information, business plans, technical information
RestrictedCredentials, sensitive personal data, security findings, critical security information

The Contractor must apply the required protection appropriate to the information classification.


6. Confidentiality Obligations

The Contractor agrees to:

☐ Keep Confidential Information confidential.

☐ Use Confidential Information only for authorized engagement activities.

☐ Access information only when authorized.

☐ Limit access to the minimum required.

☐ Prevent unauthorized disclosure.

☐ Protect Company and customer information.

☐ Follow applicable Company security policies.

☐ Follow applicable contractual requirements.

☐ Not copy information unnecessarily.

☐ Not use information for personal purposes.

☐ Not sell, disclose, publish, or commercially exploit Confidential Information.

☐ Immediately report suspected unauthorized disclosure or loss.


7. Need-to-Know Principle

The Contractor must access Confidential Information only when necessary to perform the contracted services.

Access must follow:

Business Need + Authorization + Minimum Required Access

The Contractor must not attempt to access information merely because technical access is available.


8. Contractor Access

Where the Contractor requires access to Company systems, the Company may provide access based on the approved scope of work.

Access may include:

  • Email
  • Collaboration systems
  • VPN
  • Cloud platforms
  • AWS/Azure/GCP
  • Source-code repositories
  • CI/CD systems
  • Databases
  • SaaS applications
  • Security tools
  • Customer systems
  • Development environments
  • Production environments

The Contractor must not access systems or information outside the approved scope.


9. Named Accounts

Where technically feasible, Contractors must use individually assigned accounts.

The Contractor must not:

  • Share accounts
  • Share passwords
  • Use another person’s account
  • Create unauthorized accounts
  • Circumvent access controls
  • Share MFA codes
  • Use credentials belonging to another Contractor or employee

Shared or emergency accounts may only be used where formally authorized and appropriately controlled.


10. Credentials and Secrets

The Contractor must protect:

  • Passwords
  • MFA credentials
  • API keys
  • Tokens
  • SSH keys
  • Certificates
  • Cloud credentials
  • Database credentials
  • Encryption keys
  • Service-account credentials

The Contractor must not:

  • Store credentials in source code
  • Send credentials through unsecured channels
  • Store secrets in personal cloud storage
  • Share credentials
  • Use credentials outside the approved engagement
  • Retain credentials after access is revoked

Any suspected credential compromise must be reported immediately.


11. Customer and Personal Data

Where the Contractor accesses customer or personal information, the Contractor must:

  • Use the information only for authorized purposes
  • Access only the minimum required information
  • Follow applicable privacy requirements
  • Protect information against unauthorized disclosure
  • Avoid unnecessary copying
  • Avoid unauthorized downloads
  • Avoid unauthorized local storage
  • Follow Company data-protection requirements
  • Report suspected data breaches immediately

The Contractor must not use customer or personal information for personal purposes.


12. Source Code and Intellectual Property

Where the Contractor receives access to source code or technical materials, the Contractor must protect:

  • Source code
  • Git repositories
  • Architecture
  • Algorithms
  • APIs
  • Technical documentation
  • Build configurations
  • CI/CD configurations
  • Infrastructure-as-code
  • Deployment scripts
  • Security configurations

The Contractor must not copy or transfer source code to personal repositories or unauthorized systems.


13. External Services and AI Tools

The Contractor must not upload or submit Company or customer Confidential Information to:

  • Personal cloud storage
  • Personal email
  • Public repositories
  • Unauthorized SaaS applications
  • File-sharing services
  • Public AI tools
  • Generative AI platforms
  • External development platforms

unless expressly authorized.

Particular care must be taken with:

  • Source code
  • Customer data
  • Personal data
  • Security findings
  • Vulnerability information
  • Credentials
  • Architecture diagrams
  • Confidential documents
  • Internal business information

14. Contractor-Owned Devices

If the Contractor uses Contractor-owned equipment, the Contractor must comply with applicable Company security requirements.

Where permitted and required, the Contractor must ensure:

☐ Device encryption

☐ Strong authentication

☐ Security updates

☐ Malware protection

☐ Screen lock

☐ Secure configuration

☐ Protection against unauthorized access

☐ Secure handling of Company information

Company information must not be stored on Contractor-owned devices unless such storage is authorized.


15. Remote Working

When working remotely, the Contractor must:

  • Prevent unauthorized persons from viewing Company information
  • Use approved communication channels
  • Use approved storage locations
  • Protect Company devices
  • Secure confidential discussions
  • Avoid exposing confidential information in public locations
  • Follow applicable remote-working requirements

16. Physical Documents

The Contractor must appropriately protect physical Confidential Information.

The Contractor must not:

  • Leave confidential documents unattended
  • Photograph confidential documents without authorization
  • Copy confidential documents unnecessarily
  • Dispose of confidential documents in ordinary waste
  • Leave documents visible to unauthorized persons
  • Remove Company documents outside the engagement requirements

Confidential physical documents must be securely returned or destroyed as instructed.


17. Disclosure to Third Parties

The Contractor must not disclose Confidential Information to any third party without prior authorization from the Company.

This includes:

  • Friends
  • Family
  • Other contractors
  • Former contractors
  • Customers
  • Suppliers
  • Consultants
  • Subcontractors
  • Competitors
  • Other organizations

Disclosure to an authorized subcontractor requires prior approval where required by the contract.


18. Subcontractors

The Contractor must not appoint another individual or organization to perform services involving Company Confidential Information without prior written authorization.

Where subcontracting is approved:

☐ Subcontractor identified

☐ Scope defined

☐ Confidentiality obligations established

☐ Security requirements communicated

☐ Access approved

☐ Data-access requirements assessed

☐ Company approval recorded

The Contractor remains responsible for ensuring that approved subcontractors comply with applicable confidentiality obligations.


19. Security Incidents

The Contractor must immediately report suspected:

  • Unauthorized access
  • Information leakage
  • Data breach
  • Lost device
  • Lost document
  • Misdelivered email
  • Credential compromise
  • Source-code exposure
  • Malware infection
  • Security incident
  • Unauthorized disclosure

Company Security Contact

Name/Team: ________________________________________

Email: ____________________________________________

Phone: ____________________________________________

The Contractor must cooperate with investigation and remediation activities.


20. Incident Investigation and Evidence

Where a confidentiality or security incident occurs, the Contractor may be required to:

  • Provide relevant information
  • Preserve evidence
  • Identify affected information
  • Identify recipients
  • Support investigation
  • Follow containment instructions
  • Cooperate with corrective actions

The Contractor must not intentionally delete, modify, conceal, or destroy relevant evidence after becoming aware of an investigation unless authorized to do so.


21. Information Transfer

Confidential Information must only be transferred using approved methods.

Examples include:

  • Approved secure file-sharing systems
  • Approved corporate email
  • Secure APIs
  • Encrypted communication channels
  • Approved collaboration platforms

The Contractor must not use unauthorized personal email, messaging applications, file-sharing services, or removable media for Confidential Information.


22. Data Location

The Contractor must not intentionally store or process Company or customer information outside approved locations or systems.

Where geographic restrictions apply, the Contractor must comply with:

  • Contractual requirements
  • Privacy requirements
  • Customer requirements
  • Regulatory requirements
  • Company security requirements

23. Data Retention

The Contractor must retain Confidential Information only for as long as required to perform the engagement or as otherwise authorized.

The Contractor must not retain Company information:

  • For personal reference
  • For future projects
  • For portfolio use
  • For marketing
  • After the engagement ends
  • After authorization expires

unless expressly permitted.


24. Return and Deletion of Information

Upon completion or termination of the engagement, or upon Company request, the Contractor must return or securely delete Company information as instructed.

This may include:

☐ Documents

☐ Source code

☐ Customer data

☐ Personal data

☐ Security reports

☐ Credentials

☐ Configuration files

☐ Local files

☐ Printed documents

☐ Removable media

☐ Company equipment

☐ Copies maintained under Contractor control

Deletion must not occur where information must be preserved for legal, regulatory, investigation, contractual, or other authorized purposes.


25. Access Revocation

At the end of the engagement, the Contractor must immediately stop using Company systems and information.

The Company may revoke:

☐ Corporate identity

☐ Email

☐ VPN

☐ AWS/cloud access

☐ Source-code access

☐ Production access

☐ Database access

☐ SaaS access

☐ Customer access

☐ Security-tool access

☐ Physical access

☐ API credentials

☐ SSH keys

☐ Tokens

Access revocation is separate from the Contractor’s obligation to maintain confidentiality.


26. Production and Privileged Access

Where the Contractor receives production or privileged access:

☐ Business justification documented

☐ Access specifically approved

☐ Named account used

☐ MFA enabled where supported

☐ Access limited to required systems

☐ Logging enabled where appropriate

☐ Access expiry defined where practical

☐ Periodic review performed where required

☐ Access revoked when no longer required

The Contractor must not use privileged access for activities outside the approved scope.


27. Customer Environment Access

If the Contractor accesses a customer’s environment:

  • Access must be limited to the approved customer and scope.
  • Customer information must be protected.
  • Credentials must not be shared.
  • Customer systems must not be accessed for unrelated purposes.
  • Information must not be copied unnecessarily.
  • Security incidents must be reported immediately.
  • Access must be removed when the engagement or access requirement ends.

28. Publicity and Portfolio Use

The Contractor must not publicly identify the Company or its customers as clients, projects, references, or case studies without prior written authorization.

The Contractor must not publish:

  • Screenshots
  • Source code
  • Architecture
  • Customer information
  • Security reports
  • Internal documents
  • Project details
  • Confidential communications

without authorization.


29. Intellectual Property

Where applicable, ownership of work products created by the Contractor will be governed by the underlying services agreement, statement of work, employment/contractor agreement, or other applicable contract.

This NDA does not by itself determine ownership of intellectual property unless expressly stated in the applicable agreement.

The Contractor must protect Company intellectual property regardless of ownership provisions.


30. Confidentiality After Engagement

The Contractor’s confidentiality obligations continue after the Contractor’s engagement ends for as long as the information remains confidential or as otherwise required by applicable law or contract.

Termination of the engagement does not authorize the Contractor to:

  • Use Confidential Information
  • Disclose Confidential Information
  • Retain Company information
  • Access Company systems
  • Access customer systems
  • Use proprietary technical information

31. Exceptions to Confidential Information

Confidential Information does not generally include information that the Contractor can demonstrate:

  1. Was publicly available without breach of this Agreement;
  2. Was lawfully known to the Contractor before disclosure;
  3. Was lawfully received from an authorized third party without confidentiality restrictions; or
  4. Was independently developed without unauthorized use of Company Confidential Information.

The Contractor should consult the Company before relying on an exception.


32. Legally Required Disclosure

Nothing in this Agreement prevents the Contractor from making a disclosure required by applicable law, court order, or valid regulatory requirement.

Where legally permitted, the Contractor should notify the Company before disclosure so that the Company can determine whether appropriate protective measures are available.


33. Whistleblowing and Protected Reporting

Nothing in this Agreement is intended to prevent lawful reporting of:

  • Illegal activity
  • Fraud
  • Regulatory violations
  • Security concerns
  • Workplace misconduct
  • Other matters protected by applicable law

Such reporting should be made through appropriate lawful channels.


34. Compliance With Company Policies

The Contractor must comply with applicable Company security requirements communicated to the Contractor.

These may include:

  • Information Security Policy
  • Confidentiality and Non-Disclosure Policy
  • Access Management Procedure
  • Acceptable Use Policy
  • Information Classification Policy
  • Data Protection Policy
  • Remote Working Policy
  • Incident Management Procedure
  • Contractor Security Requirements
  • Contractor Offboarding Procedure

The Contractor is responsible for complying with the latest applicable requirements communicated during the engagement.


35. Security Training

Where required, the Contractor must complete appropriate security awareness or role-specific training.

Training may include:

  • Information classification
  • Confidentiality
  • Password security
  • MFA
  • Phishing
  • Secure remote working
  • Data protection
  • Incident reporting
  • Secure development
  • Cloud security
  • AI usage
  • Customer security requirements

36. Contractor Responsibilities

The Contractor is responsible for:

☐ Protecting Confidential Information

☐ Following Company security requirements

☐ Using only authorized access

☐ Following the need-to-know principle

☐ Protecting credentials

☐ Protecting customer information

☐ Protecting personal information

☐ Reporting security incidents

☐ Reporting suspected confidentiality breaches

☐ Protecting Company intellectual property

☐ Returning/deleting information when required

☐ Cooperating with investigations

☐ Maintaining confidentiality after engagement


37. Company Responsibilities

The Company should, where appropriate:

  • Define the Contractor’s authorized scope
  • Identify applicable security requirements
  • Provide appropriate access controls
  • Communicate relevant policies
  • Provide security awareness requirements
  • Define reporting channels
  • Monitor access where appropriate
  • Revoke access when no longer required

38. Security Exceptions

Any exception to this Agreement or applicable security requirements must be formally approved where required.

ExceptionBusiness ReasonRiskApprovalExpiry

An informal verbal agreement must not be treated as a permanent security exception.


39. Contractor Acknowledgement

The Contractor confirms that they:

☐ Have read this Agreement

☐ Understand the confidentiality obligations

☐ Understand the need-to-know principle

☐ Understand the requirements for protecting Company information

☐ Understand customer and personal-data requirements

☐ Understand credential-security requirements

☐ Understand restrictions on external and AI services

☐ Understand incident-reporting requirements

☐ Understand information return/deletion requirements

☐ Understand that confidentiality continues after the engagement

☐ Agree to comply with applicable Company security requirements


40. Contractor Declaration

I acknowledge that I may receive or access confidential, proprietary, customer, personal, technical, security, or other non-public information during my engagement with the Company.

I agree to use such information only for authorized purposes, protect it against unauthorized access or disclosure, and comply with applicable Company security requirements.

I understand that my confidentiality obligations continue after the end of my engagement.

I agree to return or securely delete Company information when required and to cooperate with security investigations and incident-response activities.

Contractor

Name: __________________________________________

Company: ________________________________________

Designation/Role: _________________________________

Signature: _______________________________________

Date: ____________________________________________


41. Company Representative

Name: __________________________________________

Designation: _____________________________________

Signature: _______________________________________

Date: ____________________________________________


42. Witness — Where Required

Name: __________________________________________

Designation: _____________________________________

Signature: _______________________________________

Date: ____________________________________________


43. Document Control

FieldDetails
Document NameContractor Non-Disclosure Agreement
Document ID
Version
Effective Date
Owner
Approved By
Review FrequencyAnnual / As Required
ClassificationInternal / Confidential
Related PolicyConfidentiality and Non-Disclosure Policy
Related ProcedureContractor Offboarding Procedure
RetentionAccording to Legal/Contractual Requirements

44. Contractor Onboarding Checklist

Before providing sensitive access:

☐ Contractor identity verified

☐ Contract/SOW completed

☐ NDA signed

☐ Confidentiality requirements communicated

☐ Security requirements communicated

☐ Security training completed where required

☐ Scope of work documented

☐ Information access identified

☐ System access identified

☐ Production access assessed

☐ Privileged access assessed

☐ Customer access assessed

☐ Personal-data access assessed

☐ Subcontractor use assessed

☐ Access approved

☐ MFA configured where required

☐ Named account created

☐ Access expiry defined where practical

☐ NDA record retained


45. Contractor Offboarding Checklist

At the end of the engagement:

☐ Engagement completion/termination confirmed

☐ Access inventory reviewed

☐ Corporate account disabled

☐ VPN access revoked

☐ AWS/cloud access revoked

☐ Source-code access revoked

☐ Production access revoked

☐ Database access revoked

☐ SaaS access revoked

☐ Customer access revoked

☐ API keys/tokens addressed

☐ SSH keys addressed

☐ Shared credentials reviewed

☐ Company assets returned

☐ Company information returned/deleted where required

☐ Subcontractor access addressed

☐ Confidentiality obligations communicated

☐ Exit Security Acknowledgement completed where applicable

☐ Evidence retained

☐ Contractor register updated


46. AWS SaaS Startup Example

A SaaS startup engages an external DevOps contractor for a three-month infrastructure project.

The Contractor requires temporary access to:

  • AWS
  • GitHub
  • Terraform/IaC repositories
  • CI/CD
  • Monitoring
  • Development environments
  • Selected production resources

Before Access

Contract/SOW → NDA → Security Requirements → Risk Assessment → Access Approval → MFA → Named Accounts

During Engagement

The Contractor:

  • Uses only approved accounts.
  • Accesses only authorized AWS resources.
  • Does not copy source code to personal repositories.
  • Does not upload customer data to personal or public AI tools.
  • Reports security incidents immediately.
  • Uses temporary access where practical.

At Exit

Engagement Ends → Revoke Access → Rotate Relevant Secrets → Recover Assets → Return/Delete Information → Verify → Record

The NDA establishes the confidentiality obligation, while technical and operational controls enforce it.


47. Startup-Friendly Model

For a startup, the minimum practical process should be:

Before Engagement

Contract → NDA → Scope → Security Requirements → Access Approval

During Engagement

Need-to-Know → Secure Access → Secure Information Handling → Incident Reporting

At Exit

Revoke → Recover → Return/Delete → Verify → Record

For high-risk contractors, add:

  • Enhanced due diligence
  • Background verification where appropriate
  • Privileged-access controls
  • Production-access approval
  • Customer-specific requirements
  • Security training
  • Periodic access review
  • Independent evidence review

48. Common Mistakes

Avoid:

  • Giving contractors access before signing required agreements.
  • Giving contractors permanent access for temporary work.
  • Allowing shared accounts.
  • Giving production access without business justification.
  • Allowing source code to be copied to personal repositories.
  • Allowing customer data to be uploaded to personal or public AI services.
  • Ignoring subcontractors.
  • Assuming an NDA replaces technical access controls.
  • Failing to revoke access when the engagement ends.
  • Failing to rotate credentials after high-risk contractor access.
  • Failing to recover Company information.
  • Failing to document offboarding evidence.
  • Allowing former contractors to continue accessing customer environments.

49. Relationship With Other ISMS Documents

DocumentRelationship
Confidentiality and Non-Disclosure PolicyDefines organizational confidentiality requirements
Employee NDAApplies confidentiality obligations to employees
Contractor NDAApplies confidentiality obligations to contractors
Contractor Security AgreementDefines broader security obligations
Supplier Security RequirementsDefines security requirements for external parties
Contractor Onboarding ProcedureControls contractor onboarding
Contractor Offboarding ProcedureControls contractor exit
Access Management ProcedureControls contractor system access
Access Revocation ChecklistProvides access-removal controls
Access Revocation Evidence RegisterRecords evidence of access removal
Information Classification PolicyDefines protection requirements
Incident Response ProcedureHandles contractor-related security incidents
Data Protection PolicyAddresses personal-data requirements
Exit Security AcknowledgementRecords continuing security obligations

50. ISO 27001 / SOC 2 Connection

A Contractor NDA supports the organization’s broader personnel and supplier-security framework by establishing confidentiality obligations for individuals who are not employees but may have access to organizational or customer information.

The NDA should be supported by operational controls such as:

  • Contractor screening where appropriate
  • Security requirements
  • Access control
  • Need-to-know
  • MFA
  • Security awareness
  • Information classification
  • Monitoring
  • Incident reporting
  • Access revocation
  • Asset return
  • Information return/deletion
  • Contractor offboarding

For ISO 27001, the organization should determine the applicable controls and documented information through its ISMS risk assessment and applicable contractual, legal, and regulatory requirements.


51. Quick Audit Checklist

☐ Contractor identified

☐ Engagement scope documented

☐ NDA approved

☐ NDA signed before sensitive access where required

☐ Security requirements communicated

☐ Security training completed where required

☐ Information classification communicated

☐ Need-to-know principle applied

☐ System access approved

☐ Privileged access assessed

☐ Production access assessed

☐ Customer access assessed

☐ Personal-data access assessed

☐ Subcontractors assessed

☐ AI/external-service restrictions communicated

☐ Incident reporting requirements communicated

☐ NDA record retained

☐ Access revoked at exit

☐ Credentials/secrets addressed

☐ Company assets returned

☐ Company information returned/deleted where required

☐ Exit evidence retained


52. Final Audit Trail

For every contractor handling sensitive information, the organization should be able to demonstrate:

Who is the Contractor?
What services are they providing?
What information can they access?
Why do they need that access?
Was confidentiality formally agreed?
Were security requirements communicated?
Was access appropriately authorized?
Was access limited to the required scope?
How is confidential information protected?
What happens if the Contractor has a security incident?
Are subcontractors controlled?
What happens when the engagement ends?
Was access revoked?
Were credentials and secrets addressed?
Was Company information returned/deleted where required?
Was evidence retained?

Final Principle

A Contractor NDA establishes the legal confidentiality obligation, but effective protection requires that obligation to be connected to contractor due diligence, access control, secure information handling, incident reporting, and verified offboarding.

Legal note: This is a practical information-security template. It should be reviewed by qualified legal counsel and adapted to the applicable jurisdiction, contractor agreement, statement of work, customer requirements, and applicable laws before execution.