Establishing secure connection…Loading editor…Preparing document…

Miscellaneous Select CII Form

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

MISCELLANEOUS SELECT CII FORM

Parties

Recitals

WHEREAS, Client Name: desires to retain Provider Name: to perform certain services described below; and

WHEREAS, the parties wish to document the scope, payment terms, confidentiality and other material terms by this Miscellaneous Select CII Form; and

WHEREAS, certain information exchanged under this agreement may be designated as Critical Infrastructure Information (CII) and the parties agree to handle such material in accordance with the confidentiality provisions set forth herein.

Scope of Work

The Provider shall perform the services and deliverables described below. The parties agree that the Scope of Work sets forth the Provider's obligations and deliverables.

Payment Terms

Total Fee: $ . The Provider shall invoice Client in accordance with the schedule below.

Deposit / Retainer (if any): $ payable upon execution.

Payment due within days of invoice date. Late payments shall incur interest at % per month or the maximum permitted by law, whichever is less. A minimum late fee of $ applies to overdue invoices.

Term and Termination

This Agreement shall commence on and shall continue until , unless earlier terminated as provided herein.

Either party may terminate this Agreement without cause upon days' prior written notice. Either party may terminate for material breach if the breaching party fails to cure such breach within days after receipt of written notice specifying the breach.

Confidentiality

"Confidential Information" means all non-public information disclosed by one party to the other, whether in written, oral, electronic or other form, that is designated as confidential or that reasonably should be understood to be confidential under the circumstances. Confidential Information includes information designated as CII.

Each party shall: (a) hold the other's Confidential Information in strict confidence; (b) use such information only for the purposes of performing under this Agreement; and (c) not disclose Confidential Information to any third party except to employees, contractors or advisors who have a need to know and who are bound by confidentiality obligations no less protective than those herein. The receiving party shall use at least the same degree of care to protect Confidential Information as it uses to protect its own confidential information, but in no event less than reasonable care.

Confidentiality obligations shall survive termination of this Agreement for a period of years, except that trade secrets shall be protected for so long as they remain trade secrets under applicable law.

Governing Law; Dispute Resolution

This Agreement shall be governed by and construed in accordance with the laws of the State of without regard to conflict of laws principles. The parties agree to attempt good faith negotiation of disputes; if unresolved, disputes shall be resolved by binding arbitration or litigation as selected by the parties in writing.

Representations; Entire Agreement

Each party represents and warrants that it has the authority to enter into this Agreement and perform its obligations hereunder. No party will disclose any materially false information in connection with performance.

Entire Agreement: This Agreement (including all schedules and attachments, if any) constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior and contemporaneous agreements and understandings, whether written or oral. Any amendment must be in writing and signed by authorized representatives of both parties.

Authority and Certification

Each signatory below certifies that they are an authorized representative of the party for which they sign and have authority to bind that party to the terms of this Agreement.

Client Printed Name:

By:

Date:

Provider Printed Name:

By:

Date:

Enter text✕

What the Miscellaneous Select CII Form Covers

The Miscellaneous Select CII Form is a standardized template for recording and transmitting Controlled Unclassified Information (CII) selections, handling instructions, and attestations between parties. It identifies the information type, defines handling requirements, records applicable classification or sensitivity markers, and captures the responsible party's attestation and signature. Organizations use it to document how CII must be stored, shared, or redacted, to meet contractual, regulatory, or internal policy obligations. The form is adaptable across industries and supports both paper and electronic signing workflows when legal conditions are met.

Why this form matters for compliant CII handling

The Miscellaneous Select CII Form provides a clear record of what information is treated as CII and how it must be protected, reducing misclassification and unauthorized disclosure risk. It helps align operational procedures with contractual or regulatory obligations and creates an auditable trail for security reviews.

Why this form matters for compliant CII handling

Typical users and signatories

Organizations and roles that commonly complete the Miscellaneous Select CII Form include legal, security, procurement, and contract teams.

  • Security Officers and Compliance Teams: complete handling instructions and attest to technical controls and access limitations in coordination with legal counsel.
  • Contract Managers and Procurement: include form with subcontractor agreements to mandate CII handling before data exchange.
  • Project Managers and System Owners: attach project-specific details and sign to confirm operational readiness and safeguards.

Different teams complete different sections; ensure the final signature block is assigned to an authorized representative with signing authority.

Core components of a professional CII selection form

A well-structured Miscellaneous Select CII Form groups identification, classification, handling rules, and attestations so reviewers and auditors can quickly verify protections and responsibilities.

Identification

Fields to capture document name, unique ID, owner, system of record, and related contract or PO numbers for traceability and retrieval.

CII Classification

Designated categories or sensitivity markers, including any applicable CUI or contract-defined labels, plus a brief justification for classification.

Handling Instructions

Specific storage, transmission, and disclosure rules (encryption, access lists, redaction) tied to the classification and technical controls required.

Retention and Disposal

Clear retention timeframe, archival location, and disposal procedures aligned to regulatory or contractual obligations.

Attestation

Signature block where an authorized party confirms accuracy, adherence to controls, and acknowledgement of penalties for misuse.

Attachments

Supporting exhibits such as data inventories, encryption key references, redaction examples, and contact information for escalation.

Step-by-step: completing and approving the CII form

Follow these sequential steps to ensure accurate completion, internal approvals, and legally valid execution of the Miscellaneous Select CII Form.

  • 01
    Prepare: Gather identifiers, classification rationale, and control requirements before filling fields.
  • 02
    Populate: Complete each field using required formats and attach supporting exhibits.
  • 03
    Review: Have compliance and legal teams review classification and handling instructions for alignment.
  • 04
    Execute: Obtain authorized signatures, date the form, and record the execution method (electronic or wet signature).

Configuring an online completion workflow

When you digitize the form, configure authentication, routing, and retention settings to match your security and legal requirements.

Field Configuration
Authentication Email plus SMS OTP or SAML SSO for higher assurance; KBA where required.
Conditional Fields Show or hide fields based on CII category to reduce signer errors.
Reminder Schedule Set automated reminders at configurable intervals until signing completes.
Retention Setting Set automated archival and deletion per retention policy when enabled.

Typical digital signing flow for the form

Digital execution follows a straightforward sender-to-signer flow; recordkeeping and audit trails ensure reproducibility and attribution.

  • Upload: Sender uploads the template and attaches exhibits.
  • Assign Fields: Place signature, date, and required data fields for each signer.
  • Invite Signers: Send secure signing links or emails with authentication steps.
  • Finalize: Signer completes form; system captures audit trail and delivers copies.

Technical considerations for eSubmission and eSignatures

Choose a platform that supports required integrations, strong authentication, and tamper-evident audit trails for CII workflows.

  • Integrations: Salesforce, NetSuite, Microsoft 365, Box, Procore supported for system workflows.
  • File formats: Accepts PDF, DOCX, and HTML with form-field support.
  • Authentication: Supports SSO, SMS OTP, and advanced signer verification.

Confirm platform security certifications and whether a Business Associate Agreement or equivalent is required before transmitting protected CII or PHI.

eSignature vendor pricing and feature snapshot

This table summarizes starting prices and key capability differences for common eSignature vendors; signNow is listed first per comparison conventions.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes (Business Premium) Yes Yes Yes Varies by plan
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No

Common deadlines and processing expectations

Timelines depend on contract terms and whether the form triggers downstream filings; use clear internal SLAs to avoid missed obligations.

Provide Upon Request:

Some parties require the completed form on demand; there is no universal statutory deadline for such requests.

Internal Review SLA:

Establish a 5–10 business day internal review window to allow legal and security checks.

Signer Response:

Set signer reminders at 3 and 7 days and consider expiration after 30 days.

Retention Start:

Retention typically begins on the effective date noted on the form.

RON Recordkeeping:

If notarized remotely, retain audio/video per state RON rules and provider settings.

Key milestones from draft to archived record

Track these numbered milestones to ensure timely approvals, execution, and secure long-term storage for the CII form.

01

Draft Completion

Form is populated and exhibits attached prior to formal review.

02

Compliance Review

Legal and security verify classification and controls.

03

Execution

Authorized signatures collected and audit trail captured.

04

Archival

Signed form and audit trail stored in secure repository.

Consequences of incorrect or missing information

Contract Breach: Potential contract remedies or termination.
Regulatory Penalties: Fines or enforcement where obligations are statutory.
Data Exposure: Increased risk of unauthorized disclosure.
Audit Findings: Negative findings during compliance reviews.
Legal Liability: Civil claims for negligence or breach.
Operational Disruption: Delays in project delivery or access restrictions.

Common mistakes to avoid when preparing the form

  • Using inconsistent identifiers or missing version numbers, which creates duplicate records and complicates audits.
  • Applying vague handling controls instead of specific technical requirements such as encryption standard or access role.
  • Allowing unauthorized staff to sign or failing to verify signer authority before execution.
  • Neglecting to attach supporting exhibits (inventory, redaction examples) required by contract or policy.

Security and compliance checkpoints to document

Encryption: AES-256 at rest
In-transit: TLS 1.2/1.3
Audit Trail: Tamper-evident logging
Certifications: SOC 2 Type II
HIPAA: BAA required where PHI
21 CFR Part 11: Support for FDA-regulated records

Real-world scenarios where this form is used

Two concise examples illustrate how organizations use a Miscellaneous Select CII Form to streamline compliance and recordkeeping.

Healthcare Intake Example

A clinic attached the CII form to patient transfer packets and specified redaction and encryption controls

  • The form required clinician and security officer initials for verification
  • As a result, the clinic standardized transfer steps, reduced classification disputes, and created a consistent audit trail for internal and external reviews.

Vendor Data Exchange

A contracting officer required subcontractors to complete the form before data access was granted

  • Subcontractors provided inventory and handling controls
  • This prevented unauthorized access, ensured contractual alignment, and simplified incident response by keeping a single canonical record per exchange.

Practical tips for accurate and efficient completion

Apply these best practices to reduce errors, accelerate approvals, and maintain defensible records for CII handling.

Use consistent identifiers
Adopt a standardized ID scheme across projects and versions so auditors can correlate documents and supporting exhibits without manual reconciliation.
Be specific about controls
Specify encryption standards, access roles, and retention times rather than generic phrases like 'securely stored' to avoid interpretation gaps.
Assign clear signatory authority
Document who may sign on behalf of each party and verify authority before execution to prevent later challenge to validity.
Keep attachments organized
Attach inventories, redaction templates, and escalation contacts directly to the form to ensure reviewers have necessary context.

Who typically signs the form

Chief Information Security Officer

The CISO or a designated security lead typically certifies that proposed handling controls are adequate and documents technical safeguards; their signature confirms alignment with organizational security standards and incident escalation procedures.

Authorized Contracting Officer

A contracting officer or authorized signatory for the business unit accepts contractual obligations tied to CII handling, ensuring legal and procurement teams have approved the classification and associated commitments.

Frequently asked questions about completing and signing the form

Answers below address common legal, technical, and process questions encountered when preparing, signing, and storing the Miscellaneous Select CII Form.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users