NDA term length: why 3 years, 5 years, or perpetual
NDA duration isn't arbitrary. A walkthrough of why 3-year, 5-year, and perpetual terms show up where they do, and the trade-offs each hides.
Open any stack of NDAs and the confidentiality period will cluster around a small set of values: two years, three years, five years, seven years, perpetual. Occasionally ten. Almost never six or eight. The distribution isn't random, each of those numbers carries a set of assumptions about what the information is, how long it stays sensitive, and which side of the table the drafter sat on.
NDA duration is one of the most negotiated and least understood parts of a confidentiality agreement. Teams often accept whatever number is in the template, or push back by one increment without a clear reason why. This is a walkthrough of where those numbers come from, which fits which situation, and the structural choices hiding inside the term clause that matter more than the number itself.
Two clocks, not one
Before getting to the numbers, a distinction that trips up a surprising amount of NDA review: most confidentiality agreements actually have two time periods, and they do different things.
- The term of the agreement. The window during which new disclosures are covered. While the agreement is in force, any information shared counts as Confidential Information under the contract.
- The survival period. How long confidentiality obligations continue after the agreement ends. This is the clock that governs what the Recipient can and can't do with information that's already been disclosed.
A typical clause reads something like: "This Agreement shall remain in effect for two (2) years from the Effective Date. The confidentiality obligations set forth in Section 3 shall survive termination or expiration of this Agreement for a period of five (5) years."
The "NDA duration" conversation is almost always about the survival period, not the term. A short term with a long survival is common and sensible, the parties only actively share for a defined window, but the information they shared stays protected much longer. A long term with no distinct survival is unusual and usually a drafting error.
Why 3 years
Three-year survival periods are the standard for routine vendor NDAs, sales conversations, and most low-to-medium sensitivity exchanges. The reasoning is mostly about information half-life: customer lists, pricing strategies, internal workflows, and product roadmaps tend to decay in value over two to three years. Roadmaps ship or get scrapped. Pricing gets restructured. Customer lists churn.
A three-year NDA duration implicitly assumes that if the information hasn't been used (or leaked) within three years, it probably isn't going to matter. That's a defensible assumption for a lot of commercial information.
Three years is also the sweet spot for negotiation friction. Most Recipients will sign a three-year survival without pushback; most Disclosers feel it's long enough to cover the window in which a breach would realistically surface. It's the default that generates the fewest redline rounds.
Why 5 years
Five-year survival shows up in NDAs tied to deeper commercial relationships: partnership discussions, integration work, early-stage M&A conversations, and any context where the disclosed information is more strategic than tactical.
The assumption behind five years is that the information being shared, a multi-year product roadmap, financial model, or strategic plan, has a longer useful life than a customer list or pricing sheet. An acquirer's valuation model disclosed during a failed acquisition is still potentially damaging three and four years later. A partner's unreleased product strategy still matters well past year three.
Five years is also the period where the Recipient's operational burden starts to get real. Employees leave, systems migrate, and the institutional memory of "this information is subject to an NDA" decays. Five years is roughly the outer edge of what most companies can actually track with confidence through a standard document retention process.
Why 7 or 10 years
Seven and ten-year terms are less common and usually appear in one of three contexts:
- Technology licensing and joint development. When the shared information includes technical specifications, know-how, or processes that take years to commercialize, the protection period lengthens to match.
- Government or defense-adjacent work. Project lifecycles are long, classification regimes compound on top, and a standard three-year NDA would expire mid-program.
- Pharma, biotech, and regulated industries. Clinical trial data, formulation details, and regulatory strategy all have multi-year development timelines before any public disclosure.
The push-back on seven or ten-year periods is usually about tracking burden: a Recipient has to maintain confidentiality through an unusually long window, often spanning multiple changes of personnel, systems, and even corporate structure.
Why perpetual
Perpetual confidentiality isn't a period at all, it's the absence of an expiration. The obligation continues indefinitely, until the information falls into a defined exception (becomes public through no fault of the Recipient, is independently developed, etc.).
Perpetual survival is standard, and appropriate, for one specific category: trade secrets. A trade secret is, by legal definition, information that derives value from not being generally known. Its protection is tied to its secrecy, not to a clock. If an NDA caps trade-secret confidentiality at five years, the information stops being a trade secret at year five, regardless of whether anyone has actually disclosed it.
The common drafting pattern is a bifurcated survival clause:
"The confidentiality obligations with respect to Confidential Information shall survive for five (5) years following termination of this Agreement, provided that with respect to any Confidential Information that constitutes a Trade Secret under applicable law, such obligations shall survive for so long as such information continues to qualify as a Trade Secret."
That structure gives the Discloser perpetual protection for the genuinely sensitive material without saddling the Recipient with a forever-obligation on every email and spreadsheet exchanged during diligence.
Perpetual NDAs without the bifurcation are a red flag in routine commercial contexts. A perpetual obligation on "all Confidential Information" regardless of category turns a Recipient into a permanent steward of potentially enormous volumes of information, with all the tracking and audit burden that implies. Most negotiators will push back.
The "survives for so long as" pattern
A variation worth knowing: some NDAs tie the survival period not to a fixed number but to the nature of the information. Language like "confidentiality obligations shall survive for as long as the information remains confidential" sounds reasonable but is actually harder to operate than a fixed term.
The practical problem is verification. Under a fixed-year clause, the Recipient knows the obligation ends on a specific date. Under a "for as long as it remains confidential" clause, the Recipient has to assess the current status of the information at any given point, and that assessment shifts over time. For trade secrets, this phrasing is fine. For general business information, it creates more ambiguity than it resolves.
What drives the number in practice
Leaving aside the template defaults, a few substantive factors actually drive NDA duration:
- Information half-life. How long does the shared information retain commercial value? Pricing sheets decay fast; formulation data does not.
- Deal type. Vendor diligence and sales conversations lean shorter; M&A, licensing, and strategic partnerships lean longer.
- Industry norms. Software and SaaS tend toward 3–5 years. Pharma, biotech, hardware, and defense lean toward 7+.
- Regulatory overlays. HIPAA, GDPR, and sector-specific rules may impose confidentiality obligations that outlast the NDA. Where those apply, the NDA duration is less consequential.
- The Recipient's tracking capacity. A long NDA that can't actually be operationalized is theater. Realistic durations match realistic record-keeping.
Common redlines
Teams that review a lot of NDAs tend to push in predictable directions:
- Shortening perpetual to a fixed term with a trade-secret carve-out. The bifurcated structure described above.
- Aligning term and survival with deal timeline. A 30-day sales conversation doesn't need a 5-year term; a 2-year partnership exploration probably does.
- Defining "public" carefully. The survival period only matters until the information becomes public. A tight definition of public-domain keeps the Recipient from having to defend against informal or partial disclosures.
- Making the survival start on termination, not on disclosure. Otherwise, information shared in year 1 of a 3-year term with a 5-year survival is only protected until year 6, while information shared in year 3 is protected until year 8. Starting the survival clock on termination is cleaner.
The bottom line
NDA duration looks like a single number but is really a structural choice about two separate clocks, how they interact, and what categories of information they cover. Three years, five years, and perpetual aren't interchangeable, each signals a different assumption about what's being shared and how long it matters.
The cleanest NDAs tend to have a short, defined term for active disclosures; a fixed survival period (usually three or five years) for general Confidential Information; and perpetual protection carved out specifically for trade secrets. That structure matches how information actually behaves: most of it decays within a few years, a small subset stays sensitive much longer, and the parties can tell the difference when they draft the clause instead of arguing about it after a leak.
Getting the duration right at signature is a drafting conversation. Getting it wrong is a litigation conversation.