We signed an NDA for a customer's drawings and data. Does ISO 9001 cover how we protect them?
Partly. Clause 8.5.3 names intellectual property and personal data as customer property you must identify, verify, protect and safeguard. How is set by your contract, not by the standard.
What to do now
Two documents, one afternoon.
Re-read the agreement you signed. Most manufacturers sign a confidentiality or proprietary information agreement at the start of a customer relationship and never open it again. It usually specifies more than people remember: how the customer's information must be stored, who may access it, whether it can leave your systems, what happens at the end of the program, and how fast you must report a loss. That document, not ISO 9001, is where your actual obligations live.
Then read clause 8.5.3. It says you shall exercise care with property belonging to customers or external providers while it is under your control, and that you shall identify, verify, protect and safeguard it. The note underneath is the part almost nobody has read: customer property can include materials, components, tools and equipment, premises, intellectual property, and personal data.
So the standard does reach the drawings. It just does not tell you how to protect them, and it never audits your file permissions.
Then inventory what you hold. Which customers' information, in what form, in which locations. Shared drives, the ERP, email, the estimating folder, engineering laptops, the supplier you send models to for quoting. If you cannot produce that list, you cannot protect, return, or report on any of it, and every one of those four verbs in the clause assumes you can.
What it costs
Most of what closes this gap is process rather than purchase.
An inventory of customer information costs a few days of somebody's attention. Restricting access to a drawings folder costs an afternoon of your IT provider's time. Writing down who may send a customer's model to a supplier, and how, costs a meeting. None of that is a capital project.
What does cost money is discovering the gap through a customer's security questionnaire rather than on your own schedule. That arrives as a deadline, usually attached to a program award, and it asks questions your quality system was never built to answer.
The other cost to weigh: a gap assessment that covers customer property properly runs alongside a standard readiness review, which benchmarks at $2,500 to $5,000 in this market. If your customer is heading toward asking for ISO 27001 as well, the first certification for a mid-market manufacturer typically takes nine to eighteen months, and the United States held about 4,260 ISO 27001 certificates in 2024 against roughly 28,800 for ISO 9001. Starting the information half early is materially cheaper than starting it when the questionnaire lands.
What good looks like
The same four verbs applied to files that you already apply to consigned material.
Identify. You can list whose information you hold and where it lives. Folders and records carry the customer's name and the program.
Verify. When a customer sends a revision, somebody confirms it is the revision the order calls for, and the superseded one is removed from where people work. This is documented information control applied to somebody else's document.
Protect. Access is limited to the people who need it. Not because a standard says so, but because your agreement almost certainly says so and because a drawings folder open to every login is the first thing a customer's questionnaire asks about.
Safeguard. It is backed up, it is recoverable, and you know what happens to it when an employee with access leaves or when the program ends and the contract requires return or certified destruction.
And when something goes wrong, you report it. Clause 8.5.3 requires you to tell the customer when their property is lost, damaged, or found unsuitable. Most agreements set a deadline for that notification, and it is usually short.
When to bring in outside help
When a customer security questionnaire has arrived. They are written for software companies and land badly on manufacturers. Answering them accurately without over-committing takes someone who has read both the questionnaire and your contract.
When the information half has no owner. Quality owns the material. IT owns the network. Nobody owns the customer's file. That gap is the single most common finding in this area and it is an organizational problem rather than a technical one.
When a customer is asking for both standards. The management system skeleton is shared, so sequencing the two properly saves real money, and doing them as unrelated projects wastes it.
You do not need help to read your own agreement or to make a list of where files live. Those two steps close more exposure than anything you could buy.
How ARG does it
We look at customer property as one obligation with two halves, because that is how the clause is written and how your contract reads.
On the floor, the usual review: identification of consigned material, controlled storage, verification on receipt, and the loss-or-damage reporting the clause requires. In the system, the same questions applied to files: what you hold, who can reach it, what leaves the building and how, what happens when someone leaves, and whether your practice matches the agreement you signed.
James Wall leads this work. He is a quality engineer with a supply chain background and hands-on IT infrastructure experience, which is the combination this specific problem needs: most people who understand the shelf do not understand the server, and the reverse.
Where the answer runs past what a quality management system is designed to carry, our security practice, Adversarial Risk Group, does that work on the same site with the same people. We prepare you for the audits and the questionnaires. We never issue a certificate for either.
FAQ
Does ISO 9001 require us to encrypt customer files?
No. The standard requires you to protect and safeguard customer property and to report loss or damage. Specific controls come from your contract, or from an information security standard if your customer asks for one.
Will an ISO 9001 auditor look at our file permissions?
Usually not in depth. The clause reaches the obligation, but a quality auditor's competence and focus are elsewhere. Your customer's supplier quality or security team is the one that looks.
Is signing the agreement enough?
Signing creates the obligation. The audit question, from a customer or an auditor, is what you do differently because you signed it.
What happens at the end of a program?
Most agreements require return or certified destruction of the customer's information. Companies that never inventoried what they hold cannot do either, and that becomes visible exactly when the relationship is ending.
Our customer's customer owns the data. Does that change anything?
It usually makes the requirements stricter. Prime contractor terms flow down through your customer's contract to you, and they can impose obligations well beyond anything in ISO 9001.
Sources
- ISO 9001:2015 clause 8.5.3 and its note naming intellectual property and personal data.
- ARG market research 2026, section 2.1 for United States certificate counts, section 7.1 for gap assessment benchmarks, section 5.5 for the 27001 adjacency.
- ISO 27001 first-certification timeline: adversarialrisk.com security glossary, ISO 27001 entry.
Tell us which audit is on your calendar.
A gap assessment is a flat-fee, on-site project led by a certified ISO 9001 lead auditor. Three founding-client spots are open for the quality practice.
We prepare you for certification. We never issue it. Your registrar's independence is the point.