Is a non-compete necessary for compliance to standard 5.2.3, or is an NDA on its own sufficient?

The non-compete is necessary.  Seems ISO/IEC wants to make sure that folks don’t leave you and apply the knowledge they got to a competitor.

Hard to enforce… but that’s what 17024 suggests.  Note that your lawyer may inform you that your state makes non-compete agreements unenforceable.