ISO/IEC 27036 – Cybersecurity – Supplier Relationships (Parts 1–4)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
ISO/IEC 27036, Cybersecurity – Supplier relationships, is the multi-part international standard for managing information security in the relationships between acquirers and suppliers. Part 1 (2021) gives the overview and concepts, Part 2 (2022) specifies the fundamental information security requirements for defining, implementing, operating, monitoring, reviewing, maintaining, and improving supplier and acquirer relationships, Part 3 (2023) gives guidelines for hardware, software, and services supply chain security, and Part 4 (2016) gives guidelines for the security of cloud services.
The International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) publish the series through ISO/IEC JTC 1/SC 27, the committee responsible for the ISO/IEC 27000 family. The standard is voluntary and applies to all organizations, regardless of type, size, and nature, in the role of acquirer, supplier, or both; Part 2 expects the organization to have foundational processes for business management, risk management, operational and human resources management, and information security already in place or in planning.
Organizations implement ISO/IEC 27036 by setting an information security policy for supplier relationships, assessing the risks of each acquisition or supply, building security requirements into agreements, monitoring supplier performance and changes through the life of the relationship, and managing termination and transition. Part 3 extends this to multi-tier hardware, software, and services supply chains and integrates security into the system and software life cycle processes of ISO/IEC/IEEE 15288 and 12207, while Part 4 applies the approach to acquiring and providing cloud services.
Why it Matters
Most organizations now depend on suppliers for the products, services, software, and cloud platforms that process their information, and many of the largest security incidents of the past decade began in a supplier. ISO/IEC 27036 gives acquirers and suppliers a shared, internationally recognized way to specify, agree, and verify the security of those relationships across their whole life cycle.
Key benefits include:
- A common language for both sides
Because the standard addresses the perspectives of both acquirers and suppliers, security requirements can be written, understood, and evidenced consistently across a contract.
- Requirements that can be audited
Part 2 states requirements rather than advice, so an organization can build supplier security into its ISO/IEC 27001 management system and have it assessed.
- Visibility into multi-tier supply chains
Part 3 addresses the risks of physically dispersed and multi-layered hardware, software, and services supply chains, not just the direct supplier.
- Cloud-specific guidance
Part 4 covers gaining visibility into the risks of using cloud services and responding to risks specific to acquiring or providing them.
- Life-cycle coverage
Requirements run from planning and agreement through monitoring and termination, so supplier security does not end at onboarding.
How it Works
ISO/IEC 27036-1:2021 introduces the concepts used across the series and explains how supplier relationship security fits with an information security management system. ISO/IEC 27036-2:2022 sets the fundamental requirements, covering any procurement and supply of products and services, such as manufacturing or assembly, business process procurement, software and hardware components, knowledge process procurement, build-operate-transfer, and cloud computing services, and structures them around the organization's supplier relationship processes and the life cycle of each agreement. ISO/IEC 27036-3:2023 provides guidance for acquirers and suppliers of hardware, software, and services on gaining visibility into and managing supply chain information security risks, responding to those risks, and integrating security processes into system and software life cycle processes while supporting the controls of ISO/IEC 27002. ISO/IEC 27036-4:2016 provides cloud service customers and providers with guidance on identifying and managing the information security risks of using cloud services.
Implementation begins with governance: a policy and objectives for supplier relationship security, roles for procurement, legal, security, and business owners, and a risk assessment approach that rates each supplier by the information and services it touches. For each relationship the acquirer defines security requirements, evaluates candidate suppliers against them, agrees the requirements contractually, monitors delivery and change through the operating period, and plans the return or destruction of information at termination. Suppliers implement the mirror-image processes so they can demonstrate conformance to their customers. Part 3 adds supply chain mapping and controls for component provenance and integrity; Part 4 adds the shared-responsibility considerations of cloud services.
Within SmartSuite, teams run ISO/IEC 27036 as a supplier security program: each supplier record carries its risk tier, the requirements agreed in the contract, the evidence collected at due diligence and on each review, and the incidents, changes, and findings that arise during the relationship. Requirements map to the ISO/IEC 27001 and ISO/IEC 27002 supplier controls and to NIST SP 800-161 practices, so one assessment serves several frameworks.
Key Elements
- Overview and concepts (Part 1)
Defines the terms and concepts of supplier relationship security and how they relate to an information security management system, from both the acquirer's and the supplier's perspective.
- Fundamental requirements (Part 2)
Specifies the information security requirements for defining, implementing, operating, monitoring, reviewing, maintaining, and improving supplier and acquirer relationships.
- Supplier relationship life cycle
Requirements follow the agreement from planning and selection through contracting, delivery, monitoring, change, and termination.
- Hardware, software, and services supply chain security (Part 3)
Guides acquirers and suppliers on visibility into multi-layered supply chains and on integrating security into ISO/IEC/IEEE 15288 and 12207 life cycle processes.
- Cloud services security (Part 4)
Guides cloud service customers and providers on identifying and managing the risks specific to acquiring or providing cloud services.
- Risk-based supplier assessment
Each relationship is assessed for the information security risks it introduces, and requirements and monitoring are scaled to that risk.
- Alignment with ISO/IEC 27002 controls
The series supports and elaborates the supplier relationship controls in ISO/IEC 27002 rather than replacing them.
Framework Scope
ISO/IEC 27036 applies to any organization that acquires or supplies products and services that involve information or information systems, regardless of type, size, and nature. Part 2 covers procurement and supply of every kind, including manufacturing, business and knowledge process procurement, software and hardware components, build-operate-transfer arrangements, and cloud services. Parts 3 and 4 narrow the focus to hardware, software, and services supply chains and to cloud services respectively. The series does not cover business continuity or resilience of the supply chain, which ISO/IEC 27031 addresses, and Part 4 does not tell a cloud provider how to operate its own security, which ISO/IEC 27002 and ISO/IEC 27017 cover.
Framework Objectives
The series exists so that acquirers and suppliers can manage the information security risks of working together in a consistent, verifiable way.
Establish a shared understanding of supplier relationship security concepts for acquirers and suppliers.
Define the information security requirements that govern each supplier relationship across its life cycle.
Give organizations visibility into the risks of physically dispersed and multi-layered supply chains.
Integrate information security into system and software life cycle processes and into procurement.
Address the risks specific to acquiring and providing cloud services.
Support the supplier relationship controls of ISO/IEC 27002 within an ISO/IEC 27001 management system.
Framework in Context
ISO/IEC 27036 is the supplier relationship member of the ISO/IEC 27000 family and elaborates the supplier controls of ISO/IEC 27002:2022 within an ISO/IEC 27001:2022 information security management system, with ISO/IEC 27005 supplying the risk assessment method. Its Part 3 covers the same ground as NIST SP 800-161 Rev. 1 on cybersecurity supply chain risk management and the Govern and Identify functions of the NIST Cybersecurity Framework 2.0, and its Part 4 aligns with ISO/IEC 27017 for cloud security controls and the CSA Cloud Controls Matrix. Third-party assessment questionnaires such as the Shared Assessments SIG and sector rules such as IEC 62443 for industrial suppliers draw on the same requirements.
Common Framework Mappings
ISO/IEC 27036 is commonly mapped to the ISO/IEC 27000 family it belongs to and to the supply chain and cloud security frameworks that address the same supplier risks.
Mapped frameworks include:
ISO 27001:2022
ISO 27002:2022
ISO 27005:2022
ISO 27017
NIST SP 800-161 Rev.1
NIST CSF 2.0
NIST 800-53 Rev.5
CSA CCM v4
SIG v2024
IEC 62443
- ClassificationCategorySupply Chain SecurityDomainSupply Chain SecurityFramework FamilyISO 27000 Series
- Regulatory ContextTypeStandardLegal InstrumentStandardSectorCross-SectorIndustryCross-Industry
- Region / PublisherRegionGlobalRegion DetailInternationalPublisherInternational Organization for Standardization (ISO) and International Electrotechnical Commission (IEC)
- VersioningVersionPart 1:2021, Part 2:2022, Part 3:2023, Part 4:2016Effective Date2021–2023 (current editions of Parts 1–3); 2016 (Part 4)Issue DateOctober 2016 (Part 4) to June 2023 (Part 3)
- AdoptionAdoption ModelVoluntaryImplementation ComplexityMedium
- Official ReferenceOpen Link in New TabSource
License included / downloadable: No
The four parts of ISO/IEC 27036 are sold by ISO, IEC, and their national member bodies, and their text is not included with the platform.
Framework text is licensed by its publisher and is included only where stated above.
How SmartSuite Supports ISO/IEC 27036
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
For ISO/IEC 27036, SmartSuite tiers every supplier by risk, records the security requirements agreed in each contract, and tracks due diligence, monitoring, incidents, and termination evidence across the life of the relationship.
Supplier Security Requirements Library
Hold the Part 2 requirements and the Part 3 and Part 4 guidance as reusable requirement sets applied to each supplier by type and risk tier.
Ownership, Cadence, and Accountability
Assign relationship owners across procurement, security, and the business, and schedule due diligence, reviews, and contract renewals.
Evidence Collection and Audit Trail
Attach questionnaires, certificates, audit reports, and contract clauses to each supplier with timestamps and reviewers.
Supplier Assessment and Monitoring
Run risk-tiered assessments, track findings and remediation, and record changes in the supplier's services or sub-suppliers.
Supply Chain and Cloud Alignment
Map supplier requirements to ISO/IEC 27001, NIST SP 800-161, and cloud shared-responsibility controls so one assessment serves several frameworks.
Third-Party Risk Reporting
Report supplier risk posture, open findings, and concentration across the supply chain to security leadership and the board.
Related frameworks

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

ISO/IEC 27017 provides cloud-specific security controls to help organizations protect data and manage cloud-related risks.

ISO/IEC 27018 provides guidelines for protecting personally identifiable information processed in public cloud services.

NIST SP 800-161 Rev. 1 guides organizations to identify, assess, and mitigate cybersecurity risks across their supply chains.

The CSA Cloud Controls Matrix v4 is a cloud security control framework of 17 domains, mapped to ISO/IEC 27001, NIST SP 800-53, PCI DSS, CIS Controls, and SOC 2.
Frequently Asked Questions For ISO/IEC 27036
ISO/IEC 27036, Cybersecurity – Supplier relationships, is a four-part international standard for managing information security in the relationships between acquirers and suppliers. It covers concepts, requirements, hardware, software, and services supply chain security, and the security of cloud services.
Part 1 (2021) gives the overview and concepts; Part 2 (2022) specifies the requirements; Part 3 (2023) gives guidelines for hardware, software, and services supply chain security; and Part 4 (2016) gives guidelines for the security of cloud services.
The series is not certified on its own. Part 2 states requirements that organizations build into an ISO/IEC 27001 information security management system, where they can be assessed as part of that certification; Parts 1, 3, and 4 are guidance.
ISO and IEC publish it through ISO/IEC JTC 1/SC 27. It is voluntary and applies to all organizations, regardless of type, size, and nature, whether they act as acquirer, supplier, or both.
It elaborates the supplier relationship controls of ISO/IEC 27002 and is designed to operate within an ISO/IEC 27001 management system, using the risk management approach of ISO/IEC 27005.
The series does not address business continuity or resilience of the supply chain, which ISO/IEC 27031 covers, and Part 4 does not tell a cloud provider how to implement, manage, and operate its own information security, which ISO/IEC 27002 and ISO/IEC 27017 cover.
SmartSuite manages supplier relationships as risk-tiered records with agreed security requirements, due diligence and monitoring evidence, findings, and termination tasks, mapped to ISO/IEC 27001 and NIST SP 800-161 so one supplier assessment serves several frameworks.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

