Supply Chain Security
DETAIL

ISO/IEC 27036 – Cybersecurity – Supplier Relationships (Parts 1–4)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

ISO/IEC 27036, Cybersecurity – Supplier relationships, is the multi-part international standard for managing information security in the relationships between acquirers and suppliers. Part 1 (2021) gives the overview and concepts, Part 2 (2022) specifies the fundamental information security requirements for defining, implementing, operating, monitoring, reviewing, maintaining, and improving supplier and acquirer relationships, Part 3 (2023) gives guidelines for hardware, software, and services supply chain security, and Part 4 (2016) gives guidelines for the security of cloud services.

The International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) publish the series through ISO/IEC JTC 1/SC 27, the committee responsible for the ISO/IEC 27000 family. The standard is voluntary and applies to all organizations, regardless of type, size, and nature, in the role of acquirer, supplier, or both; Part 2 expects the organization to have foundational processes for business management, risk management, operational and human resources management, and information security already in place or in planning.

Organizations implement ISO/IEC 27036 by setting an information security policy for supplier relationships, assessing the risks of each acquisition or supply, building security requirements into agreements, monitoring supplier performance and changes through the life of the relationship, and managing termination and transition. Part 3 extends this to multi-tier hardware, software, and services supply chains and integrates security into the system and software life cycle processes of ISO/IEC/IEEE 15288 and 12207, while Part 4 applies the approach to acquiring and providing cloud services.

Why it Matters

Most organizations now depend on suppliers for the products, services, software, and cloud platforms that process their information, and many of the largest security incidents of the past decade began in a supplier. ISO/IEC 27036 gives acquirers and suppliers a shared, internationally recognized way to specify, agree, and verify the security of those relationships across their whole life cycle.

Key benefits include:

  • A common language for both sides

Because the standard addresses the perspectives of both acquirers and suppliers, security requirements can be written, understood, and evidenced consistently across a contract.

  • Requirements that can be audited

Part 2 states requirements rather than advice, so an organization can build supplier security into its ISO/IEC 27001 management system and have it assessed.

  • Visibility into multi-tier supply chains

Part 3 addresses the risks of physically dispersed and multi-layered hardware, software, and services supply chains, not just the direct supplier.

  • Cloud-specific guidance

Part 4 covers gaining visibility into the risks of using cloud services and responding to risks specific to acquiring or providing them.

  • Life-cycle coverage

Requirements run from planning and agreement through monitoring and termination, so supplier security does not end at onboarding.

How it Works

ISO/IEC 27036-1:2021 introduces the concepts used across the series and explains how supplier relationship security fits with an information security management system. ISO/IEC 27036-2:2022 sets the fundamental requirements, covering any procurement and supply of products and services, such as manufacturing or assembly, business process procurement, software and hardware components, knowledge process procurement, build-operate-transfer, and cloud computing services, and structures them around the organization's supplier relationship processes and the life cycle of each agreement. ISO/IEC 27036-3:2023 provides guidance for acquirers and suppliers of hardware, software, and services on gaining visibility into and managing supply chain information security risks, responding to those risks, and integrating security processes into system and software life cycle processes while supporting the controls of ISO/IEC 27002. ISO/IEC 27036-4:2016 provides cloud service customers and providers with guidance on identifying and managing the information security risks of using cloud services.

Implementation begins with governance: a policy and objectives for supplier relationship security, roles for procurement, legal, security, and business owners, and a risk assessment approach that rates each supplier by the information and services it touches. For each relationship the acquirer defines security requirements, evaluates candidate suppliers against them, agrees the requirements contractually, monitors delivery and change through the operating period, and plans the return or destruction of information at termination. Suppliers implement the mirror-image processes so they can demonstrate conformance to their customers. Part 3 adds supply chain mapping and controls for component provenance and integrity; Part 4 adds the shared-responsibility considerations of cloud services.

Within SmartSuite, teams run ISO/IEC 27036 as a supplier security program: each supplier record carries its risk tier, the requirements agreed in the contract, the evidence collected at due diligence and on each review, and the incidents, changes, and findings that arise during the relationship. Requirements map to the ISO/IEC 27001 and ISO/IEC 27002 supplier controls and to NIST SP 800-161 practices, so one assessment serves several frameworks.

Key Elements

  • Overview and concepts (Part 1)

Defines the terms and concepts of supplier relationship security and how they relate to an information security management system, from both the acquirer's and the supplier's perspective.

  • Fundamental requirements (Part 2)

Specifies the information security requirements for defining, implementing, operating, monitoring, reviewing, maintaining, and improving supplier and acquirer relationships.

  • Supplier relationship life cycle

Requirements follow the agreement from planning and selection through contracting, delivery, monitoring, change, and termination.

  • Hardware, software, and services supply chain security (Part 3)

Guides acquirers and suppliers on visibility into multi-layered supply chains and on integrating security into ISO/IEC/IEEE 15288 and 12207 life cycle processes.

  • Cloud services security (Part 4)

Guides cloud service customers and providers on identifying and managing the risks specific to acquiring or providing cloud services.

  • Risk-based supplier assessment

Each relationship is assessed for the information security risks it introduces, and requirements and monitoring are scaled to that risk.

  • Alignment with ISO/IEC 27002 controls

The series supports and elaborates the supplier relationship controls in ISO/IEC 27002 rather than replacing them.

Framework Scope

ISO/IEC 27036 applies to any organization that acquires or supplies products and services that involve information or information systems, regardless of type, size, and nature. Part 2 covers procurement and supply of every kind, including manufacturing, business and knowledge process procurement, software and hardware components, build-operate-transfer arrangements, and cloud services. Parts 3 and 4 narrow the focus to hardware, software, and services supply chains and to cloud services respectively. The series does not cover business continuity or resilience of the supply chain, which ISO/IEC 27031 addresses, and Part 4 does not tell a cloud provider how to operate its own security, which ISO/IEC 27002 and ISO/IEC 27017 cover.

Framework Objectives

The series exists so that acquirers and suppliers can manage the information security risks of working together in a consistent, verifiable way.

Establish a shared understanding of supplier relationship security concepts for acquirers and suppliers.

Define the information security requirements that govern each supplier relationship across its life cycle.

Give organizations visibility into the risks of physically dispersed and multi-layered supply chains.

Integrate information security into system and software life cycle processes and into procurement.

Address the risks specific to acquiring and providing cloud services.

Support the supplier relationship controls of ISO/IEC 27002 within an ISO/IEC 27001 management system.

Framework in Context

ISO/IEC 27036 is the supplier relationship member of the ISO/IEC 27000 family and elaborates the supplier controls of ISO/IEC 27002:2022 within an ISO/IEC 27001:2022 information security management system, with ISO/IEC 27005 supplying the risk assessment method. Its Part 3 covers the same ground as NIST SP 800-161 Rev. 1 on cybersecurity supply chain risk management and the Govern and Identify functions of the NIST Cybersecurity Framework 2.0, and its Part 4 aligns with ISO/IEC 27017 for cloud security controls and the CSA Cloud Controls Matrix. Third-party assessment questionnaires such as the Shared Assessments SIG and sector rules such as IEC 62443 for industrial suppliers draw on the same requirements.

Common Framework Mappings

ISO/IEC 27036 is commonly mapped to the ISO/IEC 27000 family it belongs to and to the supply chain and cloud security frameworks that address the same supplier risks.

Mapped frameworks include:

ISO 27001:2022

ISO 27002:2022

ISO 27005:2022

ISO 27017

NIST SP 800-161 Rev.1

NIST CSF 2.0

NIST 800-53 Rev.5

CSA CCM v4

SIG v2024

IEC 62443

At a Glance
ISO/IEC 27036 – Cybersecurity – Supplier Relationships (Parts 1–4)
  • Classification
    Category
    Supply Chain Security
    Domain
    Supply Chain Security
    Framework Family
    ISO 27000 Series
  • Regulatory Context
    Type
    Standard
    Legal Instrument
    Standard
    Sector
    Cross-Sector
    Industry
    Cross-Industry
  • Region / Publisher
    Region
    Global
    Region Detail
    International
    Publisher
    International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC)
  • Versioning
    Version
    Part 1:2021, Part 2:2022, Part 3:2023, Part 4:2016
    Effective Date
    2021–2023 (current editions of Parts 1–3); 2016 (Part 4)
    Issue Date
    October 2016 (Part 4) to June 2023 (Part 3)
  • Adoption
    Adoption Model
    Voluntary
    Implementation Complexity
    Medium
  • Official Reference
License Information

License included / downloadable: No

The four parts of ISO/IEC 27036 are sold by ISO, IEC, and their national member bodies, and their text is not included with the platform.

Framework text is licensed by its publisher and is included only where stated above.

Official Resources
ISO/IEC 27036-1:2021 – Overview and concepts
The ISO catalogue entry for Part 1, the introductory part of the series that sets out its concepts.
ISO/IEC 27036-2:2022 – Requirements
The ISO catalogue entry for Part 2, which specifies the fundamental information security requirements for supplier and acquirer relationships.
ISO/IEC 27036-3:2023 – Hardware, software, and services supply chain security
The ISO catalogue entry for Part 3, the guidelines for multi-layered supply chain security.
ISO/IEC 27036-4:2016 – Security of cloud services
The ISO catalogue entry for Part 4, the guidelines for cloud service customers and providers.
SMARTSUITE

How SmartSuite Supports ISO/IEC 27036

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.

For ISO/IEC 27036, SmartSuite tiers every supplier by risk, records the security requirements agreed in each contract, and tracks due diligence, monitoring, incidents, and termination evidence across the life of the relationship.

Supplier Security Requirements Library

Hold the Part 2 requirements and the Part 3 and Part 4 guidance as reusable requirement sets applied to each supplier by type and risk tier.

Ownership, Cadence, and Accountability

Assign relationship owners across procurement, security, and the business, and schedule due diligence, reviews, and contract renewals.

Evidence Collection and Audit Trail

Attach questionnaires, certificates, audit reports, and contract clauses to each supplier with timestamps and reviewers.

Supplier Assessment and Monitoring

Run risk-tiered assessments, track findings and remediation, and record changes in the supplier's services or sub-suppliers.

Supply Chain and Cloud Alignment

Map supplier requirements to ISO/IEC 27001, NIST SP 800-161, and cloud shared-responsibility controls so one assessment serves several frameworks.

Third-Party Risk Reporting

Report supplier risk posture, open findings, and concentration across the supply chain to security leadership and the board.

Related frameworks

ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

ISO 27002:2022

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

ISO 27017

ISO/IEC 27017 provides cloud-specific security controls to help organizations protect data and manage cloud-related risks.

ISO 27018

ISO/IEC 27018 provides guidelines for protecting personally identifiable information processed in public cloud services.

NIST SP 800-161 Rev.1

NIST SP 800-161 Rev. 1 guides organizations to identify, assess, and mitigate cybersecurity risks across their supply chains.

CSA CCM v4

The CSA Cloud Controls Matrix v4 is a cloud security control framework of 17 domains, mapped to ISO/IEC 27001, NIST SP 800-53, PCI DSS, CIS Controls, and SOC 2.

SIG v2024

SIG 2024 Standardized Information Gathering standardizes collection of vendors' security, privacy, and compliance information for third-party risk assessments.

IEC 62443

ISA/IEC 62443 is the international series of standards for securing industrial automation and control systems across asset owners, integrators, and product suppliers.

ONBOARDING FAQS

Frequently Asked Questions For ISO/IEC 27036

What is ISO/IEC 27036?

ISO/IEC 27036, Cybersecurity – Supplier relationships, is a four-part international standard for managing information security in the relationships between acquirers and suppliers. It covers concepts, requirements, hardware, software, and services supply chain security, and the security of cloud services.

What are the four parts of ISO/IEC 27036?

Part 1 (2021) gives the overview and concepts; Part 2 (2022) specifies the requirements; Part 3 (2023) gives guidelines for hardware, software, and services supply chain security; and Part 4 (2016) gives guidelines for the security of cloud services.

Is ISO/IEC 27036 certifiable?

The series is not certified on its own. Part 2 states requirements that organizations build into an ISO/IEC 27001 information security management system, where they can be assessed as part of that certification; Parts 1, 3, and 4 are guidance.

Who publishes ISO/IEC 27036 and who does it apply to?

ISO and IEC publish it through ISO/IEC JTC 1/SC 27. It is voluntary and applies to all organizations, regardless of type, size, and nature, whether they act as acquirer, supplier, or both.

How does ISO/IEC 27036 relate to ISO/IEC 27001 and 27002?

It elaborates the supplier relationship controls of ISO/IEC 27002 and is designed to operate within an ISO/IEC 27001 management system, using the risk management approach of ISO/IEC 27005.

What does ISO/IEC 27036 not cover?

The series does not address business continuity or resilience of the supply chain, which ISO/IEC 27031 covers, and Part 4 does not tell a cloud provider how to implement, manage, and operate its own information security, which ISO/IEC 27002 and ISO/IEC 27017 cover.

How does SmartSuite support ISO/IEC 27036?

SmartSuite manages supplier relationships as risk-tiered records with agreed security requirements, due diligence and monitoring evidence, findings, and termination tasks, mapped to ISO/IEC 27001 and NIST SP 800-161 so one supplier assessment serves several frameworks.

Operationalize ISO/IEC 27036 with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.