Scope
Define covered systems, data types, locations, and third parties; state exclusions and versioning rules for the document.
Clear security requirements reduce ambiguity, align expectations between parties, and create objective criteria for procurement, audits, and incident response. Well-written requirements support enforceability, lower legal risk, and make technical validation and third-party assessments more efficient.
This document is used by organizations that contract for IT, cloud, or professional services and need to set binding security and compliance terms.
Collaboration across these groups ensures technical accuracy, legal enforceability, and operational feasibility before signing.
Define covered systems, data types, locations, and third parties; state exclusions and versioning rules for the document.
Specify encryption standards, access controls, MFA requirements, logging retention, and secure development practices with measurable thresholds.
Describe classification levels, permitted processing, data minimization, storage limits, cross-border transfer rules, and destruction procedures.
Require breach notification timelines, point-of-contact info, forensic cooperation, and remediation commitments including timelines and evidence preservation.
State audit frequency, types of acceptable evidence (SOC 2, penetration test reports), on-site audit rights, and reporting cadence.
Include warranty language, indemnity for breaches, insurance minima, termination rights, and assignment or subcontracting restrictions.
| Field | Configuration |
|---|---|
| Authentication | Email link + optional SMS code for signer validation |
| Signature Type | ESIGN-compliant electronic signature with audit trail |
| Retention | Export signed PDF/A and store audit log |
| Notarization | Enable RON or in-person notary options where required |
Choose delivery channels that preserve the audit trail and integrate with existing systems such as CRM or contract repositories.
Ensure the selected platform supports export of signed PDFs, immutable audit logs, and secure long-term storage consistent with compliance needs.
14 calendar days to respond to security questionnaires
Security and legal review within 30 days
30–90 days for agreed corrective actions
Annual review or upon material change
Maintain supporting evidence per retention policy
| Criteria | Electronic Signature | Digital (PKI) Signature |
|---|---|---|
| Legal Status | valid under esign/ueta | valid under esign/ueta |
| Authentication | audit trail and email/sms | certificate-based authentication |
| Non-repudiation | evidence-based | strong cryptographic non-repudiation |
| Common Use | general contracts and approvals | regulated records and fda/21 cfr uses |
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial, no credit card required | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes (Business Premium) | Yes | Yes | Yes | Varies by plan |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |