---
title: "ISO/IEC 27036 Supplier Relationship Security Guide"
canonical_url: "https://www.sorena.io/artifacts/global/iso-27036"
source_url: "https://www.sorena.io/artifacts/global/iso-27036"
author: "Sorena AI"
description: "Plain-language ISO/IEC 27036 guide to supplier relationships, ICT supply chains, cloud services, agreements, monitoring, and evidence."
published_at: "2026-03-04"
updated_at: "2026-07-16"
keywords:
  - "ISO/IEC 27036"
  - "supplier relationship security"
  - "ISO/IEC 27036-2 requirements"
  - "ICT supply chain security"
  - "cloud supplier security"
  - "supplier assurance"
  - "supplier lifecycle"
  - "ISO/IEC 27036 Supplier Relationship Security"
  - "global standards"
  - "compliance evidence"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# ISO/IEC 27036 Supplier Relationship Security Guide

Plain-language ISO/IEC 27036 guide to supplier relationships, ICT supply chains, cloud services, agreements, monitoring, and evidence.

![ISO/IEC 27036 artifact preview](https://cdn.sorena.io/cdn-cgi/image/width=1200,quality=88,format=auto/images/3rd-parties/iso.jpg)

*ISO/IEC 27036* *Free Resource*

## ISO/IEC 27036 Practical guidance, FAQs, comparisons, and audit-ready evidence

Use ISO/IEC 27036 to manage information-security risk that arises when an acquirer depends on a supplier for a product or service, including multi-tier ICT supply chains and cloud services.

The current parts used here are Part 1:2021 overview and concepts, Part 2:2022 requirements, Part 3:2023 hardware, software, and services supply-chain guidance, and Part 4:2016 cloud-service guidance, confirmed in 2022. The series is not a law or standalone certification scheme; apply the relevant parts alongside your ISMS, contracts, risk criteria, and legal duties.

[Jump to guides](#topics)

## What this hub helps you do

- **Relationship types**: Identify the acquirer, supplier, product or service, information access, dependencies, and leverage. The same organization can be an acquirer upstream and a supplier downstream.
- **Contract and assurance**: Translate risk treatment into an agreement: responsibilities, access, assurance, change control, incident coordination, sub-supplier conditions, continuity, and exit.
- **Lifecycle governance**: Keep the relationship under review from planning and selection through delivery, change, renewal, termination, information return or deletion, and access removal.

By Sorena AI | Updated 2026 | No signup required

### Quick scan

*ISO/IEC 27036*

- **Relationship types**: Map both parties, the supplied product or service, access, business dependence, and upstream or downstream relationships.
- **Contract and assurance**: Use Part 2 requirements and risk treatment to define responsibilities, controls, assurance, change, incident, continuity, and exit terms.
- **Lifecycle governance**: Retain approvals, due diligence, agreement versions, operating measures, reviews, incidents, changes, exceptions, and termination evidence.

Start with the relationship and risk, select the relevant part of the series, agree responsibilities, then preserve evidence across operation, change, and termination.

| Value | Metric |
| --- | --- |
| Guides | Deep pages |
| FAQ | Standalone answers |
| Compare | Side-by-side |
| Evidence | Reusable |

**Key highlights:** Scope | Evidence | Review

## Primary sources

- [ISO/IEC 27036-1:2021 standard page](https://www.iso.org/standard/82905.html?ref=sorena.io) - Primary ISO listing for supplier relationship security overview and concepts.
  - Quote: "overview of the guidance intended to assist organizations"
- [ISO/IEC 27036-2:2022 standard page](https://www.iso.org/standard/82060.html?ref=sorena.io) - Primary ISO listing for supplier and acquirer relationship requirements.
  - Quote: "fundamental information security requirements for defining, implementing, operating, monitoring, reviewing, maintaining and improving supplier and acquirer relationships"
- [ISO/IEC 27036-3:2023 standard page](https://www.iso.org/standard/82890.html?ref=sorena.io) - Primary ISO listing for hardware, software, and service supply-chain guidance.
  - Quote: "multi-layered hardware, software, and services supply chains"
- [ISO/IEC 27036-4:2016 standard page](https://www.iso.org/standard/59689.html?ref=sorena.io) - Primary ISO listing for cloud-service supplier relationship guidance; ISO records it as confirmed in 2022.
  - Quote: "Guidelines for security of cloud services"

*Recommended reading path*

## Move from relationship scope to lifecycle evidence

Start by identifying the parties and dependency. Then assess risk, translate treatment into agreements and controls, monitor delivery and change, and close the relationship without losing information or evidence.

### 1. Start here: series, scope, and roles

Understand what each part covers, how acquirer and supplier roles work, and which product, service, cloud, or supply-chain relationship is in scope.

1. [Using the ISO/IEC 27036 Supplier Relationship Series](/artifacts/global/iso-27036/compliance.md): Understand how to apply the four-part ISO/IEC 27036 series without treating it as a law or standalone certification.
2. [ISO/IEC 27036 Supplier Relationship Types Guide](/artifacts/global/iso-27036/supplier-relationship-types.md): Classify ISO/IEC 27036 relationships by product, service, ICT supply chain, and cloud context to select proportionate controls.
3. [ISO/IEC 27036 Supplier Security FAQ](/artifacts/global/iso-27036/faq.md): Plain-language answers about ISO/IEC 27036 scope, parts, roles, agreements, assurance, monitoring, incidents, indirect suppliers, cloud services, and exit.

### 2. Assess risk and agree controls

Tier the relationship using your risk criteria, investigate direct and indirect dependencies, and make selected security requirements enforceable and reviewable.

4. [ISO/IEC 27036 Third Party Risk Checklist](/artifacts/global/iso-27036/third-party-risk-checklist.md): Use an ISO/IEC 27036 supplier-risk checklist across scope, assessment, agreement, operation, change, incidents, and termination.
5. [ISO/IEC 27036 Indirect and Fourth Party Suppliers Guide](/artifacts/global/iso-27036/indirect-and-fourth-party-suppliers.md): Manage indirect supplier dependencies under ISO/IEC 27036 using risk-based visibility, flow-down expectations, monitoring, and contingency planning.
6. [ISO/IEC 27036 Contract Security Clauses Guide](/artifacts/global/iso-27036/contract-security-clauses.md): Build ISO/IEC 27036-aligned supplier security clauses from relationship risk, responsibilities, assurance, change, incidents, and exit.
7. [ISO/IEC 27036 Supplier Assurance Framework Guide](/artifacts/global/iso-27036/supplier-assurance-framework.md): Design proportionate ISO/IEC 27036 supplier assurance using risk tiers, evidence scope, monitoring, findings, and reassessment.

### 3. Operate the supplier lifecycle

Connect planning, selection, contracting, delivery, change, incident coordination, monitoring, renewal, and termination to named owners and evidence.

8. [ISO/IEC 27036 ICT Supply Chain Lifecycle Guide](/artifacts/global/iso-27036/ict-supply-chain-lifecycle.md): Apply ISO/IEC 27036 across ICT supply-chain planning, acquisition, delivery, operation, change, and disposal.
9. [ISO/IEC 27036 Onboarding and Offboarding Workflow](/artifacts/global/iso-27036/onboarding-and-offboarding-workflow.md): Run ISO/IEC 27036 supplier onboarding and offboarding with approval gates, evidence, access control, continuity, and verified closure.
10. [ISO/IEC 27036 Supplier Monitoring Evidence Workflow](/artifacts/global/iso-27036/supplier-monitoring-evidence-workflow.md): Build ISO/IEC 27036 supplier monitoring that turns agreed measures, assurance, incidents, changes, and findings into decisions.

### 4. Compare complementary approaches

Use the comparison to decide how ISO/IEC 27036 relationship practices and NIST cyber supply-chain risk management can share evidence without treating either as automatic conformity with the other.

11. [ISO/IEC 27036 vs NIST SP 800-161 Comparison](/artifacts/global/iso-27036/iso-27036-vs-nist-sp-800-161.md): Compare ISO/IEC 27036 supplier-relationship security with NIST SP 800-161 Rev. 1 cyber supply-chain risk management.

### 5. More guides

Additional guidance related to this artifact.

12. [ISO/IEC 27036 Assurance Evidence FAQ](/artifacts/global/iso-27036/faq/assurance-evidence.md): Collect evidence that answers a defined relationship-risk or agreement question and matches the product or service, period, location, controls, and dependencies in scope. A certificate, audit report, questionnaire, or attestation is an input-not automatic proof.
13. [ISO/IEC 27036 Cloud Suppliers FAQ](/artifacts/global/iso-27036/faq/cloud-suppliers.md): Treat cloud as a supplier relationship with cloud service customer and provider perspectives. Apply Part 2 relationship requirements and Part 4 cloud guidance, then document how responsibility changes with the service and deployment model, configuration, data, interfaces, and nested cloud services.
14. [ISO/IEC 27036 Contract Controls FAQ](/artifacts/global/iso-27036/faq/contract-controls.md): Include controls selected from the relationship risk treatment and responsibilities, not a generic clause library. The agreement should make scope, performance, evidence, communication, exceptions, change, incident coordination, continuity, and exit reviewable by both parties.
15. [ISO/IEC 27036 Fourth Parties FAQ](/artifacts/global/iso-27036/faq/fourth-parties.md): Use the direct supplier relationship to obtain proportionate visibility and assurance over upstream dependencies that can materially affect security or delivery. ISO/IEC 27036 describes multi-tier supply chains; it does not require the same questionnaire or direct audit right for every remote tier.
16. [ISO/IEC 27036 Risk Tiers FAQ](/artifacts/global/iso-27036/faq/risk-tiers.md): No fixed low, medium, or high tier model is prescribed by ISO/IEC 27036. Organizations can use tiers to scale due diligence, agreement terms, assurance, monitoring, approvals, and exit planning, but the criteria and decisions must reflect their own context and risk appetite.
17. [ISO/IEC 27036 Supplier Incidents FAQ](/artifacts/global/iso-27036/faq/supplier-incidents.md): Agree incident contacts, triggers, information sharing, investigation support, evidence preservation, containment and recovery coordination, corrective action, and review before an incident occurs. ISO/IEC 27036 does not set one universal notification deadline; applicable law, regulation, policy, or contract supplies mandatory timing.
18. [ISO/IEC 27036 Supplier Monitoring FAQ](/artifacts/global/iso-27036/faq/supplier-monitoring.md): ISO/IEC 27036 does not prescribe one universal monitoring interval. Set scheduled and event-driven reviews according to risk, agreement terms, service criticality, evidence availability, and the speed at which the relationship can change.
19. [ISO/IEC 27036 Termination and Offboarding FAQ](/artifacts/global/iso-27036/faq/termination-and-offboarding.md): Plan termination before the relationship starts. Coordinate continuity and transition, revoke physical and logical access, rotate shared secrets, disable integrations, recover assets, return or delete information subject to retention duties, preserve required records, and verify surviving obligations.

## Explore ISO/IEC 27036 guides

*Guides*

Use these pages to move from ISO/IEC 27036 overview to practical evidence, FAQ answers, comparisons, and workflows.

*Next step*

## Turn ISO/IEC 27036 guidance into a cited workflow

Route ISO/IEC 27036 implementation into owned tasks, evidence requests, and review checkpoints so standards work does not remain scattered across documents.

- Start from the ISO/IEC 27036 page that matches the decision or evidence gap.
- Use Research Copilot for interpretation questions tied to cited sources.
- Use SSOT to keep evidence, owners, and review history governed.

- [Open Research Copilot](/solutions/research-copilot.md): Answer ISO/IEC 27036 scope and interpretation questions with cited outputs.
- [Open SSOT](/solutions/ssot.md): Keep ISO/IEC 27036 evidence, decisions, and control records in one governed system.
- [Talk through implementation](/contact.md): Review scope, evidence gaps, and next implementation steps.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/global/iso-27036.md
