Procurement NDA Checklist: 12 Points Before You Approve a Vendor
Security, subprocessors, survival, and flow-down language in enterprise procurement NDAs — a checklist for operators and legal ops.
Procurement NDAs are longer and more one-sided than founder-to-founder templates. Use this checklist before legal ops approves.
1. Scope matches the deal
Confidentiality should cover the RFP and pilot — not your entire product roadmap by default.
2. Security exhibit proportionality
Unlimited audit rights or sub-24-hour breach notification may exceed your SOC process.
3. Subprocessor flow-down
Prefer approved-sub list over per-person signature for small subs.
4. IP carve-outs
No assignment of improvements in the NDA — belong in the MSA/SOW.
5. Survival bounded
Align with survival period norms (2–3 years for commercial vendors).
6. Return / destroy
30-day window with backup carve-out is standard.
7. Indemnity capped
See indemnification — match cap to contract value.
8. Governing law
Negotiate forum where you perform work — see governing law.
9. Non-solicit hidden in NDA
Move to services agreement if present — non-solicit.
10. Liquidated damages
Flag uncapped liquidated damages clauses.
11. AI / data processing
If personal data is involved, pair with DPA — see NDA vs DPA.
12. Tooling
Upload to NDAShield for Burn Score + redlines. Compare Contracko and alternatives if evaluating AI review vendors.