Protective Security Policy Framework (PSPF) Release 2026
Part Two: Risk (sections 5 to 8) – Protective Security Policy Framework (PSPF) Release 2026

Protective Security Policy Framework (PSPF) Release 2026 0042: 0042 Contracts require incident reporting and compliance with directions

Requirement 0042 (Part Two: Risk, section 6.1 Third Party Risk Management; applies to All entities; dated 31 October 2024; retained from Release 2025): Contractual security terms and conditions require service providers to report any actual or suspected security incidents to the entity, and follow reasonable direction from the entity arising from incident investigations. Providers report actual or suspected incidents to the entity and follow reasonable directions arising from investigations.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Part Two: Risk (sections 5 to 8) – Protective Security Policy Framework (PSPF) Release 2026

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.