ISO/IEC 27036Free Resource

ISO/IEC 27036 Supplier relationship scope, agreements, controls, and evidence

Use ISO/IEC 27036 to manage information-security risk that arises when an depends on a supplier for a product or service, including and cloud services.

By Sorena AIUpdated 2026No signup required
Quick scan
ISO/IEC 27036
Relationship types
Map both parties, the supplied product or service, access, business dependence, and upstream or downstream relationships.
Contract and assurance
Use Part 2 requirements and risk treatment to define responsibilities, controls, assurance, change, incident, continuity, and exit terms.
Lifecycle governance
Retain approvals, due diligence, agreement versions, operating measures, reviews, incidents, changes, exceptions, and termination evidence.

Define the relationship and risks to both parties, select the relevant requirements and guidance, agree responsibilities and evidence, then keep the decision current through operation, change, and termination.

Key dates
Guides
Deep pages
FAQ
Standalone answers
Compare
Side-by-side
Evidence
Reusable
What this hub helps you do
Relationship types
Identify the , supplier, product or service, information access, locations, business dependence, and upstream relationships. Procurement need not involve payment, and one organization can be an acquirer upstream and a supplier downstream.
Contract and assurance
Translate approved risk treatment into measurable agreement terms for responsibilities, access, assurance, change, incidents, subcontractors, continuity, and exit. Record any rejected term and the residual-risk decision.
Lifecycle governance
Manage the Part 2 lifecycle from planning and supplier selection through agreement, operation, change, renewal, and termination. Reassess periodically and after significant business, legal, regulatory, architectural, policy, or contractual change.
Scope
Evidence
Review
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Mar 4, 2026
Updated
Jul 16, 2026

Use Part 1:2021 for concepts, Part 2:2022 for requirements, Part 3:2023 for hardware, software, and services supply-chain guidance, and Part 4:2016 for cloud-service guidance. Part 2 applies to procurement and supply relationships in organizations of any type or size. The series is not a law or a standalone certification scheme; apply it with your ISMS, contracts, risk criteria, and legal duties.

Recommended reading path

Move from relationship scope to lifecycle evidence

Start by identifying the parties, covered product or service, information and system access, locations, and dependencies. Assess risks to both parties, turn treatment into agreements and controls, monitor delivery and change, and close the relationship with verified exit evidence.

2

Assess risk and agree controls

Assess the relationship using your risk criteria, investigate material direct and indirect dependencies, and put selected security treatments into measurable, reviewable agreement terms.

4

Compare complementary approaches

Use the comparison to decide how ISO/IEC 27036 relationship practices and NIST cyber supply-chain risk management can share evidence without treating either as automatic conformity with the other.

Next step

Turn ISO/IEC 27036 guidance into a cited workflow

Route ISO/IEC 27036 implementation into owned tasks, evidence requests, and review checkpoints so standards work does not remain scattered across documents.

What this unlocks
  • Start from the ISO/IEC 27036 page that matches the decision or evidence gap.
  • Use Research Copilot for interpretation questions tied to cited sources.
  • Use SSOT to keep evidence, owners, and review history governed.