Information Security Addendum and Vendor Security Requirements — Negotiation and Closing (Customer Side)
Drafting and negotiation of an Information Security Addendum and Vendor Security Requirements on behalf of the customer, through to signature.
Includes the draft or markup, up to three rounds of exchanges with opposing counsel, and the execution version. Covers drafting through to the final approved version, including the review rounds it takes to get there.
Frequently asked questions
The fee covers the draft or the redline, as the posture requires, up to three rounds of negotiation with the other side's counsel, and signature-ready execution versions and a closing checklist. It is fixed at this scope: one vendor. 3 rounds of revisions are included. If your matter falls outside that scope we tell you before starting and quote the difference — we do not bill past a flat fee without agreeing it first.
1 to 2 weeks from a complete set of instructions, plus time for the 3 rounds of revisions included in the fee. If you are working to a court deadline or a closing date, tell us when you order and we will confirm in writing whether we can meet it before you commit.
$4,875 is $325/hour × 15 hours — the time this deliverable takes in an ordinary security matter, at the firm's standard rate. Because it is a flat fee, the risk of the work running long sits with the firm: you pay $4,875 whether it takes us the estimate or twice it.
Third-party costs are never inside a flat fee and are passed through at cost, never marked up: court and agency filing fees, court reporter and transcript charges, expert witness fees, search vendor and e-discovery hosting charges, process server fees, and travel.
What your business does, and who its users or customers are, the systems, vendors, and data flows the document has to describe accurately, any existing version, and what prompted this one, and any regulator, platform, or contract requirement you are working to. Send what you have — if something is missing we will tell you what else we need before the turnaround clock starts.
Clients also order
Other Security work MC Law prepares on a flat fee.
Information Security Addendum and Vendor Security Requirements — Negotiation and Closing (Vendor Side)
Drafting and negotiation of an Information Security Addendum and Vendor Security Requirements on behalf of the vendor, through to signature.
Data Breach Notification Package (Long Form)
A long-form Data Breach Notification Package that prepares the individual, regulator, and media notices a breach triggers, on the clock the statutes impose, built for a high-value or heavily negotiated transaction.
Information Security Addendum and Vendor Security Requirements — Long Form (Customer Side)
A detailed Information Security Addendum and Vendor Security Requirements written for the customer, the document that attaches concrete security controls to a contract instead of a vague promise of industry standards.
Information Security Addendum and Vendor Security Requirements — Long Form (Vendor Side)
A long-form, vendor-favorable Information Security Addendum and Vendor Security Requirements that attaches concrete security controls to a contract instead of a vague promise of industry standards.
Information Security Addendum and Vendor Security Requirements (Long Form)
A long-form Information Security Addendum and Vendor Security Requirements that attaches concrete security controls to a contract instead of a vague promise of industry standards, built for a high-value or heavily negotiated transaction.
Penetration Testing and Security Assessment Agreement — Negotiation and Closing (Company Side)
Full company-side negotiation of a Penetration Testing and Security Assessment Agreement, the document that authorizes security testing with a scope, safe harbor, and disclosure terms that protect both sides, from first draft to closing.