CIS Vulnerability and Web Application Assessment Service Terms and Conditions
The following terms and conditions apply to vulnerability assessment services (the “Vulnerability Services”) provided by CIS to Customer, as specified in the applicable Statement of Work (SOW).
I. CIS Responsibilities
A. CIS will schedule scans of Customer’s systems in the portal operated by a third-party provider Qualys, Inc. (“Qualys”) in accordance with the number and frequency of assessments specified in the SOW (the “Scans”).
B. Following completion of the Scans, CIS will provide Customer with reports showing the number and type of vulnerabilities identified, ranked in order of severity and will provide recommendations for mitigation of vulnerabilities. For web application scans, due to the likelihood of false positives being included in the initial third-party assessment, CIS shall conduct a manual analysis of vulnerabilities identified by such Scans, and provide Customer a report reflecting CIS’s analysis based on the Scans, and recommendations for mitigation. For the most serious vulnerabilities, CIS will open a ticket on the matter and will review subsequent scans to determine whether the vulnerability is still present and will work with Customer to effect mitigation measures. (Such Scans, the furnishing of reports and, if applicable, any mitigation assistance provided by CIS, together, the “Services.”)
II. Customer Obligations
A. Network IPs and Domain Information
(i) In order to perform the Services, Customer will provide CIS with either a list of live IPs used by Customer, if known, or the entire network range of public IPs used by Customer in assessment(s). Customer will also provide CIS with a list of domains it owns or uses and, if known, its subdomains.
2. If Customer uses a third-party provider to host its domain(s), Customer shall obtain the prior approval of that third-party provider for CIS to conduct the Scans.
3. If Customer is seeking the Services in response to a particular incident, Customer shall supply CIS with the affected IP or domain.
B. Customer acknowledges that CIS uses third-party provider Qualys to assist with the network and web application assessments and hereby consents to CIS’s use of Qualys in connection with its performance of the Services. In addition to the scheduled Scans analyzed by CIS as part of the Services, Customer will be given access to the Qualys portal and may run unlimited additional scans on its own during the term of the Services. Qualys will provide a limited scan report, which does not include the level of analysis and prioritization of vulnerabilities provided by CIS in its reports to Customer. Such additional scans, if any, are provided as a courtesy only and CIS makes no representation as to the accuracy or suitability of such third-party reports.
III. Pricing Assumptions; Payment Terms
In such event, the Parties will in good faith agree on an appropriate adjustment to the Fee, timeline, and/or any other elements in the SOW that require adjustment. Customer agrees to pay CIS any additional fees agreed upon as a result of such changes (an “Overage Fee”). CIS is not required to perform work beyond that described in the previously-agreed SOW unless and until the Parties agree to applicable adjustments in writing (email sufficient).
IV. Payment Terms
CIS will issue an invoice listing the Fee, along with any applicable taxes (the “Invoice”). Customer agrees to pay the Invoice within thirty (30) days of the Invoice date. Notwithstanding the foregoing, the Invoice must be paid in full before CIS provides any Services under this Agreement and CIS has no obligation to incur any costs or expenses, including but not limited to prepaid travel expenses, if any, until the Invoice has been paid. Additional payment terms, if any, are set forth in the applicable Invoice.If the Parties have agreed to an Overage Fee, Customer shall pay CIS such Overage Fee in full, no later than thirty (30) days after the date of the invoice.
V. Third-Party Provider Terms and Conditions
A. Customer acknowledges that the Service include use of a web-based security assessment and policy compliance suite of services provided by Qualys, Inc., designed to identify and analyze the security level and vulnerabilities of Internet connections and computer networks (the “Qualys Service”).
B. Ownership.
1. Qualys retains all ownership and intellectual property rights to the design and function of the Qualys Service and the reports generated pursuant to the Qualys Service (the “Reports”), other than the specific factual data gathered from Customer’s network IP addresses.
2. Customer acknowledges that the Qualys Service, the software that provides the Qualys Service and its structure, organization, and source code constitute valuable trade secrets of Qualys and Customer agrees not to: reverse engineer, decompile, disassemble or otherwise attempt to derive the source code of the software that provides the Qualys Service; or use the Qualys Service, and/or data or information contained therein, except for the purpose of vulnerability management with regard to Customer’s IP addresses.
C. Customer acknowledges and agrees that Qualys is an intended third-party beneficiary to this Agreement and as such may assert any applicable rights set forth herein as may be necessary to protect its intellectual property or other confidential or proprietary material.
D. Customer shall keep confidential its username and password for access to the Qualys Guard Enterprise Suite.
E. If requested, Qualys will provide customized reports designed to evaluate Customer’s compliance with the criteria of the PCI Security Standards Council (the “Card Program”). Customer acknowledges and agrees that third-party payment card organizations, and not Qualys, establish the security criteria and other terms and conditions of the Card Program.
F. Confidentiality. During the term of this Statement of Work, either Customer or Qualys (the “Disclosing Party”) may disclose to the other party (the “Receiving Party”) certain information, which the Disclosing Party considers proprietary or confidential. “Confidential Information” means analytical information provided in reports and any other confidential information or either party, including software, source code, software tools, trade secrets, know-how, inventions, processes, schematics, software source documents, query fields, testing criteria, usernames, passwords and financial information and any other confidential information of the Parties. Confidential Information shall not include information that is already in the public domain through no fault of the Receiving Party or was already known to the Receiving Party through no breach of a confidentiality obligation to the Disclosing Party. Without limitation of the foregoing: (1) all data and information contained within the Qualys Service or the Reports (other than the individual factual data gathered from Customer’s network IP addresses), and all information concerning or materially relating to the Hardware, are Confidential Information of Qualys; and (2) all data regarding Customer’s IP addresses or network characteristics (including data that Qualys obtains as a result of its provision of the Service hereunder), is Confidential Information of Customer. The Receiving Party will not use any Confidential Information of the Disclosing Party for any purpose not expressly permitted by the Statement of Work, and will disclosure the Confidential Information of the Disclosing Party only to those employees under a duty of confidentiality no less restrictive than the Receiving Party’s duty hereunder or is required to be disclosed by law, provided that the Receiving Party shall be required to make reasonable efforts, consistent with applicable law, to limit the scope and nature of such required disclosure. The Receiving party will protect the Disclosing Party’s Confidential Information from unauthorized use, access, or disclosure in the same manner as the Receiving Party protects its own confidential information of a similar nature, and with no less than reasonable care. Each party will return all Confidential Information to the other party after the other party requests that it be returned, or after this Statement of Work expires or is terminated.
G. LIMITATION OF LIABILITY. IN NO EVENT WILL QUALYS BE LIABLE TO CUSTOMER FOR ANY LOST PROFITS, LOSS OR CORRUPTION OF DATA, EQUIPMENT OR NETWORK DOWNTIME, OR FOR ANY CONSEQUENTIAL, INDIRECT, SPECIAL, EXEMPLARY, OR INCIDENTAL DAMAGES, WHETHER IN CONTRACT, TORT, OR OTHERWISE, ARISING FROM OR RELATING TO THIS AGREEMENT OR THE USE OF THE HARDWARE, QUALYS SERVICE OR REPORTS, EVEN IF QUALYS HAS BEEN ADVISED OF THE POSSIBILITY OR SUCH DAMAGES.
VI. Termination
Either Party may terminate the Services in the event that the other Party materially breaches this Agreement and such breach is not corrected within 30 days of receipt of written notice of such breach.
VII. Force Majeure
Neither Party shall be liable for performance delays or for non-performance due to causes beyond its reasonable control.VIII. Relationship of the Parties
Nothing in this Agreement creates an employment relationship, agency, joint venture or partnership between the Parties. Neither Party is authorized to make any representation or commitment on behalf of the other Party without its prior written consent. Each Party shall be responsible for its own employees, contractors and agents.IX. Governing Law
X. Entire Agreement
This Agreement, including the SOW that is incorporated and made a part hereof, constitutes the entire agreement between CIS and Customer with respect to the Services, superseding any prior representations, discussions, negotiations or other agreement, whether written or oral, between the Parties. Except as otherwise expressly stated, in the event that there is a conflict between the terms of Customer’s SOW and this Agreement, the provisions in the Agreement shall prevail.
XI. Waiver and Severability of Terms
The failure of either Party to exercise or enforce any right or provision of this Agreement shall not constitute a waiver of such right or provision. If any provision of the Agreement is found by a court of competent jurisdiction to be invalid, the Parties nevertheless agree that the court should endeavor to give effect to the Parties' intentions as reflected in the provision, and the other provisions of the Agreement remain in full force and effect.
Contract Version Date: 07/24/2026