ISO 27001A.6 — Confidentiality or non-disclosure agreements
A.6.6
Confidentiality or non-disclosure agreements
ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026
Objective
Ensure personnel and relevant third parties acknowledge confidentiality obligations protecting organizational information.
Points of focus
- NDA or confidentiality clause before access
- Cover employees and contingent workers
- Retain signed records
- Refresh when roles materially change
Implementation notes
Gate IdP provisioning on NDA completion in HRIS. Use standard templates for full-time and contractors. Flow confidentiality into vendor DPAs where they process customer data. Re-acknowledge on promotion into privileged roles if counsel requires.
Audit tip: Sample ten active privileged users and show dated confidentiality acknowledgements. Missing early-employee paperwork is a common finding.
Evidence auditors typically request:
- Signed NDA or offer-letter confidentiality clause
- Contractor MSA confidentiality schedule
- CLM or HRIS record of signature date
- Access provisioning gated on NDA complete
Common gaps
- Access granted before signature
- Vendors without flow-down confidentiality
- Missing records for early hires
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.6.6 | This control |
| SOC 2 | CC1.1 | Related SOC 2 themes (CC1.1) — map in your crosswalk; not identical requirements. |
| GDPR | Article 28, Article 32 | Related GDPR themes (Article 28, Article 32) — map in your crosswalk; not identical requirements. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.6.6)
Frequently Asked Questions
Usually you need an individual acknowledgement or contract clause, not only a shared PDF.
Yes if they can access customer or production data.
Confidentiality duties support Article 32 and processor instructions; they do not replace a DPA.
Even without owned data centers, confidentiality or non-disclosure agreements still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.
Start with signed nda or offer-letter confidentiality clause, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.