Microsoft 365How-To & HardeningRetrospectives

How to Hold Your Cloud Providers Accountable With Security Contract Terms

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from April 2024, written in 2026 with the benefit of hindsight.

Cloud provider security failures can affect your data — but your contract often gives you little recourse. Here are security terms to negotiate or verify with your cloud and major SaaS providers.

Step 1: Know what you've already agreed to

Read the provider's data protection addendum (DPA), service terms, and security documentation. Microsoft, AWS and Google publish standard terms; enterprise agreements may allow negotiation.

Step 2: Key terms to look for or request

  • Incident notification: a specific timeframe (for example, within 72 hours of confirming an incident affecting your data) and content requirements.
  • Logging availability: access to security-relevant logs at no extra charge, with defined retention.
  • Independent audits: current SOC 2 Type II, ISO 27001/27017/27018 and relevant certifications (FedRAMP, C5, etc.).
  • Root cause reports after significant incidents.
  • Subprocessor transparency and notification of changes.
  • Data location and residency commitments.
  • Encryption key options (customer-managed keys where needed).
  • Termination and data return terms.

Step 3: Use shared responsibility documentation

Map which controls belong to the provider and which to you. Make sure you're implementing your half.

Step 4: Ask for transparency programs

Providers offer service trust portals (Microsoft Service Trust Portal, AWS Artifact) with audit reports and documentation. Review them annually.

Step 5: Track provider security commitments

Follow initiatives such as Microsoft's Secure Future Initiative and AWS security bulletins. Ask your account team for updates relevant to your services.

Step 6: Build independent verification

Don't rely only on the provider: keep your own logs, monitoring and backups so you can see and recover from provider-side issues.

cloud provider security contract termsCSRB report2024

More on this story