Join our Newsletter — 33% off our NHI Course

Non-Compete Agreement

A non-compete agreement is a contract that limits an employee’s ability to work for a competitor or start competing work after leaving a company. In practice, it is used to reduce risk around trade secrets, customer relationships, and competitive knowledge, but its enforceability depends on jurisdiction and current legal constraints.

What a non-compete agreement actually does

A non-compete agreement is a post-employment restriction, so its security value is indirect: it tries to slow the transfer of commercially sensitive knowledge after separation rather than control access during employment. That makes it part legal guardrail, part deterrent, and part signal of what the organisation considers strategically sensitive.

For security teams, the practical boundary is important. A non-compete does not replace confidentiality controls, access revocation, logging, or data handling rules; it only attempts to reduce downstream competitive reuse after a worker leaves. Its strength depends on enforceability, notice, scope, duration, and the jurisdiction in which it is signed.

Why organisations use them

Employers typically use non-competes to protect customer relationships, product strategy, pricing knowledge, roadmap details, and other competitive information that may not be fully protected by a secrecy clause alone. They are most common where a role provides broad market insight or repeated exposure to sensitive business context.

In practice, the agreement is often part of a wider exit and confidentiality posture. It may sit alongside non-disclosure obligations, intellectual property assignment, access cutoff, and device return requirements. Those other controls are usually more operationally important because they address what the person can still reach, retain, or copy at the point of departure.

How enforceability changes the real-world effect

The real security and business effect of a non-compete is shaped by local law, court interpretation, and public-policy limits. A clause that looks strong on paper may be narrowed, paused, or struck down entirely if it is broader than the law allows or if the role does not justify the restraint.

That means the clause should be treated as a jurisdiction-sensitive governance instrument, not a universal control. Organisations that operate across states or countries often need different templates, and they should avoid assuming that a standard form will survive scrutiny everywhere.

How it relates to broader confidentiality and exit controls

A non-compete is most useful when it complements, rather than substitutes for, other safeguards around confidential information. A well-run exit process still needs immediate access removal, credential and token revocation, device and account return, and clear handling of customer and source-material data.

For teams managing sensitive operational knowledge, the agreement can also influence how onboarding, role design, and offboarding are structured. If a role is unusually sensitive, organisations usually get better risk reduction from strong access controls and documented information-handling rules than from relying on a later legal restriction alone.

For a related governance lens on protecting sensitive access material during lifecycle events, see NHI Mgmt Group’s Ultimate Guide to Non-Human Identities, which is useful when the discussion shifts from contractual restraint to operational control of access and secrets.

Risk and Threat Considerations

Non-competes can create false confidence if organisations treat them as a substitute for technical and contractual containment. The main risk is not just legal unenforceability, but the gap between what the clause says and what the former worker can still remember, retain, or leverage after departure.

Failure mechanism: Sensitive knowledge is exposed through normal work, then the organisation relies on a post-employment covenant instead of preventing copy, exfiltration, or continued access before the person leaves. If the clause is overbroad, it may be unenforceable, which leaves the organisation with weaker protection than expected.

Impact: The business may still face customer loss, competitive harm, or misuse of confidential strategy, while also spending time and money on a restriction that does little to reduce the immediate security exposure around offboarding.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AC — Access Control Non-competes complement access control by reducing post-exit exposure to sensitive knowledge.
Recommendation — Pair PR.AC with offboarding controls to cut access before post-employment restrictions matter.
CIS Controls v8 6 — Access Control Management This term sits alongside revocation and access removal after employment ends.
Recommendation — Use Control 6 to revoke access paths and limit residual exposure at separation.

Practitioner Guidance

Governance implication: Treat non-competes as a legal and people-risk control, not a primary security control. Security, legal, and HR should align on when the clause is appropriate, how it fits local law, and which sensitive roles need stronger operational offboarding instead.

What to watch for: The clause is most fragile when it is broad, poorly documented, or used for roles that do not genuinely justify restraint. In those cases, organisations should expect the clause to carry less practical weight than their access, data-handling, and exit procedures.