A security addendum arrives from a customer. They want incident notification within 24 hours, the right to audit you on site, approval before you change a subcontractor, and cooperation with their penetration testing. These are cybersecurity flow-down clauses: contractual terms that push a customer’s own regulatory obligations down onto its suppliers. You ask which law requires it. Procurement cannot say, and their legal team sends you a regulation you never thought applied to you.

Two questions:

  1. What do I owe directly?
  2. What am I being asked to undertake contractually to support somebody else’s compliance?

First, check whether you are directly in scope

‘That regulation is about our customers, not us’ is where suppliers get into trouble. Scope is neither binary nor single.

  • NIS2 covers essential and important entities. Not being essential tells you little (an important entity carries substantially the same duties). As a directive, its scope must be read with the applicable national law, particularly on enforcement and management liability, and transposition is incomplete.
  • The GDPR binds processors directly, including on security and on notifying the controller of a personal data breach without undue delay (Article 33(2)).
  • The Cyber Resilience Act directly regulates manufacturers, importers, and distributors of products with digital elements within its scope. Article 14 applies from 11 September 2026, the rest generally from 11 December 2027.
  • DORA creates direct EU oversight for designated critical ICT third-party service providers.

The question is not whether you are regulated, but in which capacity and where. Get that wrong, and every cybersecurity flow-down clause that follows gets assessed against the wrong baseline.

Why cybersecurity flow-down clauses are landing in your inbox now

NIS2 requires management bodies to approve and oversee cybersecurity risk-management measures and to ensure those measures address supply chain security, including relationships with direct suppliers (Articles 20 and 21(2)(d)). DORA prescribes contractual provisions for ICT services. Many of those duties cannot be discharged without information, commitments, and cooperation from suppliers.

Signing alone does not make you subject to NIS2 or DORA in the regulatory sense. It makes you contractually responsible for specified parts of your customer’s compliance model, which may be narrower than the regulation, broader, or simply different. That is what a cybersecurity flow-down clause actually does: it moves risk and duty down the chain by contract, not by statute.

Three kinds of cybersecurity flow-down clauses

Not every clause has the same authority.

  • Legally prescribed. The law specifies minimum contractual content, as Article 28 of the GDPR does for processors and DORA does through Articles 30(2) and 30(3). You cannot negotiate away the required substance, but you can negotiate its scope, drafting, operation, evidence requirements, and proportionality.
  • Outcome-mandated. The law sets a risk-management outcome without prescribing wording. The clause is your customer’s chosen route to it, so the wording may be negotiable even where the objective is not.
  • Diligence-driven. Article 13(5) of the Cyber Resilience Act requires manufacturers to exercise due diligence over integrated third-party components, so you may be asked for documentation, warranties, and vulnerability information. You do not thereby assume the manufacturer’s obligations, which remain its own.

You cannot classify a clause by naming the regulation, because the same regime can fall into either category, depending on your customer’s entity type. Commission Implementing Regulation (EU) 2024/2690 covers specified digital, infrastructure, and trust-service entities, including cloud, data centre, and managed service providers. Point 5.1.4 of its Annex requires them, based on their supply chain security policy and risk assessment, to specify matters in supplier contracts, including incident notification, audit rights or audit reports, vulnerability handling, subcontracting, and termination, where appropriate, through service-level agreements. So check whether it reaches your customer before assuming discretion.

What to accept, and what to push back on, in cybersecurity flow-down clauses

Where no law requires an inspection right, a broad on-site audit clause is often a customer preference and can be narrowed to an assurance report or to an on-site right triggered by a material incident. Where you act as a GDPR processor, Article 28(3)(h) requires you to permit and contribute to audits, including inspections, though notice, frequency, confidentiality, and costs remain negotiable.

Article 30(3) of DORA needs a different analysis: it requires cooperation in threat-led penetration testing and describes access, inspection, and audit rights as unrestricted. Their exercise is still risk-based: Article 28(6) requires the financial entity to predetermine audit frequency and areas and to follow commonly accepted audit standards. Parties may agree alternative assurance levels where other clients’ rights are affected (Article 30(3)(e)(ii)), but a SOC 2 report or ISO certificate does not, by itself, extinguish the underlying rights. Whether a function is critical or important is the financial entity’s determination, not a commercial variable, so request the mapping and query unsupported classifications.

Actions you can take next

  • Establish your own scope first. GDPR processor, NIS2 essential or important entity under national law, CRA economic operator, or DORA-designated critical ICT third-party service provider?
  • Classify each clause as legally prescribed, outcome-mandated, or diligence-driven before commenting.
  • Negotiate triggers, not just deadlines, since your customer’s clock runs from its own awareness of a qualifying incident. Define when awareness begins and what the first notice must contain.
  • Align your downstream contracts so they give you the rights, information, and notification speed you need upstream. Verbatim duplication is not the goal, though under Article 28(4) of the GDPR, the relevant data protection obligations must carry through to sub-processors.
  • Get the addendum reviewed. Before you sign, ask our team to assess your cybersecurity flow-down clauses.

South Africa has its own version of this. Section 21(1) of POPIA requires a written contract obliging the operator to maintain the section 19 security measures, and section 21(2) requires immediate notification of unauthorised access. Read with sections 20 and 22, that is more than one clause, though far shorter than DORA’s list — see our POPIA compliance guidance for the broader picture.