ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. NDA and Confidentiality Agreement Register

NDA and Confidentiality Agreement Register

1. Purpose

The NDA and Confidentiality Agreement Register provides a centralized record of confidentiality agreements entered into by the organization.

It helps the organization demonstrate that appropriate confidentiality agreements are:

  • Identified
  • Executed
  • Assigned to the correct parties
  • Linked to the relevant relationship or business purpose
  • Monitored for expiry and renewal
  • Reviewed when requirements change
  • Available as audit evidence
  • Properly closed when the relationship ends

Core Principle

Identify → Assess → Execute → Record → Monitor → Renew/Update → Close → Retain Evidence


2. Scope

This register may be used for:

  • Employee NDAs
  • Contractor NDAs
  • Consultant NDAs
  • Supplier confidentiality agreements
  • Vendor agreements
  • Customer confidentiality agreements
  • Mutual NDAs
  • One-way/unilateral NDAs
  • Partner confidentiality agreements
  • Investor NDAs
  • Advisor NDAs
  • Auditor confidentiality agreements
  • Professional adviser agreements
  • Temporary worker agreements
  • Intern confidentiality agreements
  • Other confidentiality arrangements

3. Register Ownership

Register Owner: ______________________________________

Business Owner: ______________________________________

Security/Compliance Owner: ____________________________

Legal Owner: _________________________________________

Review Frequency: _____________________________________

Approved By: _________________________________________


4. Master NDA and Confidentiality Agreement Register

NDA IDAgreement TypeParty NameInternal OwnerPurposeEffective DateExpiry DateStatusRiskDocument Location

5. Recommended Register Fields

The following fields should be maintained where applicable.

FieldDescription
NDA IDUnique identifier
Agreement TypeMutual, unilateral, employee, supplier, contractor, etc.
Party NameOrganization or individual covered
Party TypeEmployee, supplier, customer, contractor, partner, etc.
Internal OwnerResponsible internal person
Business UnitRelevant department
Business PurposeReason for information exchange
Information OwnerOwner of information being shared
Information ClassificationPublic, Internal, Confidential, Restricted
Effective DateDate agreement becomes effective
Expiry DateContractual expiry where applicable
Renewal DateDate renewal should be initiated
Agreement StatusDraft, Active, Expired, Terminated, Closed
Agreement ReferenceContract/agreement reference number
Legal ReviewWhether legal review was completed
Security ReviewWhether security review was required/completed
DPA RequiredWhether privacy agreement is required
DPA StatusStatus of DPA
Data TypeBusiness, customer, personal, technical, etc.
Access RequiredWhether system/information access is involved
Third PartyWhether external party is involved
SubcontractorWhether subcontractors are involved
Governing LawApplicable legal jurisdiction
Confidentiality PeriodDuration of confidentiality obligations
Termination DateActual termination date
Return/Delete RequiredWhether information must be returned/deleted
Deletion ConfirmationEvidence of deletion where applicable
Document LocationApproved repository
Evidence LocationSupporting evidence
Last ReviewMost recent review
Next ReviewNext scheduled review
NotesAdditional information

6. Agreement Type

Select the applicable type.

☐ Mutual NDA

☐ One-Way NDA

☐ Employee NDA

☐ Contractor NDA

☐ Consultant NDA

☐ Supplier Confidentiality Agreement

☐ Customer Confidentiality Agreement

☐ Partner NDA

☐ Investor NDA

☐ Advisor NDA

☐ Auditor Confidentiality Agreement

☐ Professional Adviser Agreement

☐ Temporary Worker NDA

☐ Intern NDA

☐ Other: ______________________________________


7. Party Type

Party TypeTypical Example
EmployeePermanent employee
ContractorContract developer
ConsultantSecurity consultant
SupplierTechnology supplier
SaaS ProviderCloud/SaaS provider
CustomerEnterprise customer
PartnerTechnology/business partner
InvestorPotential investor
AdvisorBusiness/legal/financial advisor
AuditorIndependent auditor
Certification BodyCertification organization
InternStudent/temporary intern
OtherOther external party

8. Agreement Status

Use standardized status values.

StatusMeaning
DraftAgreement is being prepared
Under ReviewLegal/security/business review is in progress
Pending SignatureAgreement is awaiting execution
ActiveAgreement is currently effective
Expiring SoonRenewal or review is approaching
ExpiredAgreement has reached its expiry date
TerminatedAgreement ended before normal expiry
ClosedRelationship and associated confidentiality obligations have been formally closed
SupersededReplaced by a newer agreement

9. Information Classification

Record the highest classification of information covered by the agreement.

☐ Public

☐ Internal

☐ Confidential

☐ Restricted

Information Description


10. Information Categories

Select applicable information categories.

☐ Business information

☐ Financial information

☐ Customer information

☐ Personal data

☐ Employee information

☐ Source code

☐ Product information

☐ Intellectual property

☐ Security information

☐ VAPT findings

☐ Security architecture

☐ Cloud architecture

☐ Credentials/secrets

☐ Contracts

☐ Pricing

☐ Business strategy

☐ Product roadmap

☐ Research

☐ Other: ______________________________________


11. Business Purpose

Record why confidential information is being exchanged.

Examples:

  • Service delivery
  • Supplier evaluation
  • Customer evaluation
  • Product integration
  • Partnership discussions
  • Due diligence
  • Security assessment
  • VAPT
  • Consulting
  • Software development
  • Investment evaluation
  • Proof of concept
  • Contract negotiation

Purpose


12. Effective Date and Expiry

Effective Date: __________________________

Expiry Date: _____________________________

Confidentiality End Date: _________________

Renewal Required: ☐ Yes ☐ No

Renewal Notice Period: ____________________

Some agreements may not have a fixed expiry date. In such cases, the register should record the continuing confidentiality period and applicable termination requirements.


13. Renewal Tracking

NDA IDPartyExpiry DateRenewal Notice DateOwnerRenewal Status

Renewal Status

☐ Not Yet Due

☐ Review Required

☐ Renewal in Progress

☐ Renewal Completed

☐ Not Required


14. Legal Review

Record whether legal review was required.

Legal Review Required: ☐ Yes ☐ No

Legal Reviewer: ______________________________

Review Date: _________________________________

Legal Review Status: __________________________

Review Considerations

☐ Parties correctly identified

☐ Confidential Information definition reviewed

☐ Purpose reviewed

☐ Confidentiality period reviewed

☐ Exceptions reviewed

☐ Intellectual-property terms reviewed

☐ Return/deletion provisions reviewed

☐ Governing law reviewed

☐ Liability provisions reviewed where applicable

☐ Termination provisions reviewed


15. Security Review

Security Review Required: ☐ Yes ☐ No

Security Reviewer: ____________________________

Review Date: _________________________________

Security Review

☐ Information classification assessed

☐ Access requirements assessed

☐ Customer data assessed

☐ Personal data assessed

☐ Source code assessed

☐ Security information assessed

☐ Credentials/secrets assessed

☐ Secure transfer requirements assessed

☐ Third-party security requirements assessed

☐ AI/external-service restrictions assessed

☐ Incident notification requirements assessed


16. Privacy and DPA Assessment

Where personal data is involved:

Personal Data Involved: ☐ Yes ☐ No

DPA Required: ☐ Yes ☐ No

DPA Status: __________________________________

Privacy Review Completed: ☐ Yes ☐ No

Consider:

☐ Data categories

☐ Data subjects

☐ Processing purpose

☐ Processing locations

☐ Retention

☐ Subprocessors

☐ International transfers

☐ Security requirements

☐ Breach notification


17. Access Requirements

Where the NDA relationship involves system access:

SystemEnvironmentAccess TypePrivilegedStart DateEnd Date

Access Controls

☐ Named accounts

☐ MFA

☐ Least privilege

☐ Temporary access

☐ Access expiry

☐ Logging

☐ Periodic review

☐ Access revocation


18. Third-Party NDA Requirements

For suppliers, contractors, consultants, or other external parties:

☐ Party identity verified

☐ Business purpose documented

☐ Information classified

☐ NDA executed

☐ Security requirements communicated

☐ Access requirements approved

☐ Subcontractor requirements assessed

☐ DPA assessed where applicable

☐ Incident requirements defined

☐ Return/deletion requirements defined

☐ Offboarding requirements defined


19. Agreement Evidence

Record where the executed agreement is stored.

Executed Agreement Location:


Contract Repository:


Supporting Evidence Location:


Evidence May Include

☐ Signed NDA

☐ Electronic signature record

☐ Legal approval

☐ Security approval

☐ DPA

☐ Contract

☐ Security addendum

☐ Information classification record

☐ Access approval

☐ Renewal record

☐ Termination record

☐ Deletion confirmation


20. Signature Status

PartyAuthorized SignatorySignature DateStatus
Organization
Counterparty

Status

☐ Not Started

☐ Sent for Signature

☐ Partially Signed

☐ Fully Executed


21. Confidentiality Period

Record how long confidentiality obligations continue.

Confidentiality Period: ______________________________

Examples:

  • During the relationship only
  • X years after termination
  • Indefinite for trade secrets
  • As required by applicable law
  • As specified in the agreement

Important

The agreement expiry date and confidentiality end date may be different.

An NDA may expire or be terminated while confidentiality obligations continue.


22. Termination Tracking

NDA IDPartyTermination DateReasonInformation Returned/DeletedAccess RevokedClosed

23. Return and Deletion Tracking

When the relationship ends or information is no longer required:

☐ Information returned

☐ Electronic information deleted

☐ Physical documents destroyed

☐ Devices/media returned

☐ Shared repositories reviewed

☐ Cloud access removed

☐ Source-code access removed

☐ Credentials/tokens addressed

☐ Backup retention considered

☐ Legal hold considered

☐ Deletion confirmation obtained where required


24. NDA Review Register

Conduct periodic review of active agreements.

NDA IDPartyLast ReviewReview ResultIssuesActionOwnerNext Review

Review Results

☐ No Change Required

☐ Update Required

☐ Renewal Required

☐ Additional Security Controls Required

☐ Legal Review Required

☐ DPA Required

☐ Agreement Termination Required


25. Agreement Change Tracking

NDA IDChange DateChangeReasonApproved ByNew Version

Examples:

  • New information type
  • New customer data
  • New system access
  • New geographic location
  • New subcontractor
  • Change in business purpose
  • Change in confidentiality period
  • Regulatory change
  • Contract renewal

26. Expiring Agreement Dashboard

Maintain a simple dashboard for upcoming expirations.

PeriodNumber of AgreementsAction
ExpiredImmediate review
0–30 daysRenewal/action
31–60 daysReview
61–90 daysMonitor
>90 daysNormal monitoring

27. Exception Register

Where an NDA or confidentiality requirement cannot be completed before information exchange:

Exception IDNDA IDRequirementReasonRiskCompensating ControlApproverExpiry

No exception should remain open indefinitely without review.


28. Missing Agreement Tracking

The organization should identify relationships where an NDA is required but has not yet been executed.

RelationshipPartyInformationRiskNDA RequiredCurrent StatusOwnerDue Date

Escalation

If Confidential or Restricted information is being exchanged without a required agreement, the matter should be escalated to the appropriate business, security, privacy, or legal owner.


29. Document Repository Requirements

The executed NDA should be stored in an approved repository.

Repository requirements should include:

☐ Access control

☐ Version control

☐ Backup

☐ Audit trail where appropriate

☐ Retention controls

☐ Restricted access for legal documents

☐ Protection against unauthorized modification

☐ Appropriate document classification

The register should contain a reference to the agreement rather than unnecessary copies of sensitive information.


30. AWS SaaS Startup Example

An AWS SaaS startup engages an external VAPT provider.

Register Entry

FieldExample
NDA IDNDA-2026-017
Agreement TypeSupplier NDA
PartyABC Security Pvt. Ltd.
Party TypeSecurity Provider
Internal OwnerCTO
PurposeVAPT and security assessment
InformationArchitecture, test data, VAPT findings
ClassificationConfidential/Restricted
Effective Date01-Oct-2026
Expiry Date30-Sep-2027
Confidentiality Period3 years after termination
Access RequiredYes
Privileged AccessNo
DPA RequiredNo
Security ReviewCompleted
StatusActive
Document LocationContract Repository
Next Review01-Jul-2027

After VAPT Completion

The organization should verify:

Testing Complete → Access Revoked → Information Returned/Deleted → Evidence Obtained → NDA Record Updated


31. Startup-Friendly NDA Governance

A startup does not need a complex contract-management system to maintain basic confidentiality governance.

A simple spreadsheet or approved contract repository can be sufficient initially.

Minimum Fields

At minimum, track:

  1. NDA ID
  2. Party
  3. Party Type
  4. Internal Owner
  5. Purpose
  6. Information Classification
  7. Effective Date
  8. Expiry Date
  9. Confidentiality Period
  10. Status
  11. Agreement Location
  12. Next Review Date

Recommended Controls

☐ Monthly expiry review

☐ Quarterly active-NDA review

☐ NDA requirement during onboarding

☐ NDA requirement before sensitive information exchange

☐ Exit/offboarding review

☐ Centralized repository

☐ Evidence retention


32. Common Mistakes

Avoid:

  • Maintaining signed NDAs without a central register.
  • Tracking only the expiry date and ignoring confidentiality survival periods.
  • Allowing sensitive information to be shared before execution.
  • Failing to identify who owns the relationship.
  • Losing track of agreements after employee or supplier changes.
  • Failing to renew agreements where required.
  • Failing to update an NDA when the business purpose changes.
  • Not assessing whether a DPA is also required.
  • Not linking supplier NDAs to supplier records.
  • Not tracking information return/deletion.
  • Storing executed agreements in unrestricted locations.
  • Treating the register itself as evidence that security controls are implemented.

33. Relationship With Other ISMS Documents

DocumentRelationship
Confidentiality and NDA PolicyDefines confidentiality requirements
Mutual NDA TemplateTemplate for two-way confidentiality
Employee NDAProtects employee information
Contractor NDAProtects contractor information
Supplier Confidentiality AgreementProtects supplier-related information
Confidentiality Requirements MatrixDefines handling requirements
Information Classification PolicyDefines classification
Supplier RegisterTracks supplier relationships
Supplier Risk AssessmentAssesses supplier risk
Access Management ProcedureControls access
Data Processing AgreementAddresses personal-data processing
Information Transfer ProcedureControls information exchange
Employee Offboarding PolicySupports exit confidentiality
Supplier Offboarding ChecklistSupports supplier exit
Legal & Regulatory Requirements RegisterTracks legal obligations

34. ISO 27001 / SOC 2 Connection

The NDA and Confidentiality Agreement Register provides evidence that confidentiality arrangements are being systematically managed.

It can support evidence relating to:

  • Confidentiality obligations
  • Information classification
  • Access control
  • Supplier relationships
  • Information transfer
  • Personnel security
  • Protection of customer information
  • Data protection
  • Contractual requirements
  • Offboarding
  • Secure disposal
  • Risk management

The register itself does not establish ISO 27001 or SOC 2 compliance. It is one governance record supporting the organization’s wider information-security control framework.


35. Quick Audit Checklist

☐ All relevant NDA types identified

☐ Central register maintained

☐ Unique NDA IDs assigned

☐ Parties identified

☐ Party type recorded

☐ Business purpose recorded

☐ Information classification recorded

☐ Effective date recorded

☐ Expiry date recorded

☐ Confidentiality period recorded

☐ Executed agreement available

☐ Legal review completed where required

☐ Security review completed where required

☐ DPA requirement assessed

☐ Access requirement assessed

☐ Third-party requirements assessed

☐ Renewal tracking established

☐ Periodic review established

☐ Termination tracked

☐ Information return/deletion tracked

☐ Access revocation tracked where applicable

☐ Exceptions tracked

☐ Evidence retained

☐ Register periodically reviewed


36. Document Control

FieldDetails
Document NameNDA and Confidentiality Agreement Register
Document Owner
Version
Effective Date
Review Frequency
Approved By
ClassificationInternal
Next Review Date
StatusDraft / Approved / Retired

37. Final Audit Trail

For every significant confidentiality relationship, the organization should be able to demonstrate:

Who is the other party?
Why is information being shared?
What type of NDA applies?
What information is covered?
What is the information classification?
When was the agreement executed?
Is it currently active?
When does it expire?
How long do confidentiality obligations survive?
Who owns the relationship?
Was legal/security review required?
Is a DPA required?
Does the party have system or data access?
Has the agreement been reviewed or renewed?
What happens when the relationship ends?
Has information been returned/deleted?
Has access been revoked?
Where is the evidence?

Final Principle

An NDA is only effective as part of a managed process. The NDA Register connects the agreement to the party, business purpose, information, risk, access, review, renewal, and exit process—creating a defensible audit trail for confidentiality management.