Supplier and customer contract clauses

Your regulatory obligations do not stop at your technical perimeter: they depend on how fast your suppliers react. The contract is the only instrument that can guarantee that.

The deadline cascade principle

You must issue an early warning within 24 hours. If your supplier notifies you within 72 hours, you are in breach without having done anything wrong. Upstream contractual deadlines must therefore be strictly shorter than yours.

Your obligation Supplier deadline to require
Early warning within 24 h Notification within 8 h of any actively exploited vulnerability
Notification within 72 h Circumstantial information within 36 h
Final report within 14 d of a fix Fix or documented workaround within 7 d

Clauses for your purchase contracts

Software bill of materials

  • Supply of an SBOM in CycloneDX or SPDX format, at a specified minimum version.
  • With every version delivered, without you having to ask.
  • A commitment on depth — transitive dependencies included — and an honest completeness declaration.
  • Supply of licences as SPDX identifiers.

Security and vulnerabilities

  • Notification deadlines per the cascade above.
  • Fix deadlines by severity level, with penalties.
  • Supply of VEX statements or a reasoned position on uncorrected vulnerabilities.
  • Access to security advisories, in a machine-readable format where possible.

Life cycle

  • A support period at least aligned with the one you commit to your customers.
  • Notice of end of support, long enough to allow migration — twelve months minimum for a central component.
  • Notification of maintainer or licence change.

Compliance

  • A CRA compliance commitment for components that are themselves products within the meaning of the Regulation, and supply of the EU declaration of conformity.
  • Audit rights and access to security test results.
  • Warranty of title to the rights and licences, and supply of the information needed to meet attribution obligations.

Continuity

  • Reversibility and, for critical components, source code escrow with a third party, with release conditions including cessation of business and end of support.

Liability

  • Indemnity for non-compliance attributable to the supplier, including administrative penalties you would incur as a result.
  • Interaction with liability caps: a cap expressed as a percentage of the annual contract bears no relation to a fine assessed on your worldwide turnover. That imbalance must be identified and arbitrated, not ignored.

Clauses to negotiate in your sales contracts

  • Support scope: what is covered, what is not, and the end date of the support period, expressed at least as a month and year.
  • SBOM supply arrangements: format, frequency, channel, confidentiality — see Distribution and confidentiality.
  • Notification channel in the event of a vulnerability, and a customer commitment to keep contact details valid — you cannot inform a customer you cannot reach.
  • A duty to update on the customer side: your fixes only protect if they are applied.
  • Liability limitation consistent with your regulatory exposure.
  • Treatment of unmaintained versions after the end of the support period.

The case of free components

There is no contract, therefore no clause. No negotiation is possible with a community project, and asking it for a support commitment is meaningless.

The risk is therefore handled by other means:

  1. diligence at selection — see Integrating open source;
  2. continuous monitoring of project activity and maintainer changes;
  3. internal capability to take over maintenance, fork or replace;
  4. where appropriate, funding the upstream project, which improves its viability without creating any legal obligation towards you.

To say plainly internally. A critical free component, maintained by one person, in a product covered by a five-year support period, is a non-transferable risk. It can be neither insured nor contracted away — only provisioned for or removed.

The clause set

A standard clause set in French and English, kept by Legal, with, for each clause: the wording, the regulatory justification, how negotiable it is, and the acceptable fallback. That document is what lets procurement negotiate without calling Legal on every contract.