Information Security Addendum and Vendor Security Requirements — Review and Redline (Customer Side)
A review and redline of an Information Security Addendum and Vendor Security Requirements from the customer position, for the document that attaches concrete security controls to a contract instead of a vague promise of industry standards.
We tell you which terms are genuinely unacceptable and which are just unfamiliar. You receive a marked-up document plus a ranked issues memo that separates what must change from what is merely preference.
Frequently asked questions
The fee covers a full read of the counterparty's document against your position, a tracked-changes redline you can send back, and a ranked issues memo separating deal-breakers from trade material. It is fixed at this scope: one vendor. 1 round of revisions are included. If your matter falls outside that scope we tell you before starting and quote the difference — we do not bill past a flat fee without agreeing it first.
3 to 5 business days from a complete set of instructions, plus time for the 1 round of revisions included in the fee. If you are working to a court deadline or a closing date, tell us when you order and we will confirm in writing whether we can meet it before you commit.
$1,475 is $325/hour × 4.5 hours — the time this deliverable takes in an ordinary security matter, at the firm's standard rate. Because it is a flat fee, the risk of the work running long sits with the firm: you pay $1,475 whether it takes us the estimate or twice it.
Third-party costs are never inside a flat fee and are passed through at cost, never marked up: court and agency filing fees, court reporter and transcript charges, expert witness fees, search vendor and e-discovery hosting charges, process server fees, and travel.
What your business does, and who its users or customers are, the systems, vendors, and data flows the document has to describe accurately, any existing version, and what prompted this one, and any regulator, platform, or contract requirement you are working to. Send what you have — if something is missing we will tell you what else we need before the turnaround clock starts.
Clients also order
Other Security work MC Law prepares on a flat fee.
Information Security Addendum and Vendor Security Requirements — Review and Redline (Vendor Side)
A vendor-side markup of an Information Security Addendum and Vendor Security Requirements you have been handed, the agreement that attaches concrete security controls to a contract instead of a vague promise of industry standards.
Information Security Addendum and Vendor Security Requirements (Short Form)
A streamlined Information Security Addendum and Vendor Security Requirements that attaches concrete security controls to a contract instead of a vague promise of industry standards, focused on the terms that carry the risk.
Penetration Testing and Security Assessment Agreement — Review and Redline (Company Side)
A redline of the counterparty's Penetration Testing and Security Assessment Agreement prepared for the company, covering the document that authorizes security testing with a scope, safe harbor, and disclosure terms that protect both sides.
Penetration Testing and Security Assessment Agreement — Review and Redline (Counterparty Side)
A review and redline of a Penetration Testing and Security Assessment Agreement from the counterparty position, for the document that authorizes security testing with a scope, safe harbor, and disclosure terms that protect both sides.
Penetration Testing and Security Assessment Agreement (Short Form)
A compact Penetration Testing and Security Assessment Agreement that authorizes security testing with a scope, safe harbor, and disclosure terms that protect both sides, sized for a lower-value or lower-risk transaction.