GuideGlobalISO/IEC 27036

ISO/IEC 27036 Using the Series

Apply the relevant part of ISO/IEC 27036 to supplier relationships from definition and agreement through operation, review, change, and termination.

Use Part 2 for supplier and acquirer relationship requirements and Parts 1, 3, and 4 for concepts or guidance. The series is voluntary; assess contracts, law, customer commitments, and certification scopes separately.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

ISO/IEC 27036 is a four-part series for security. Use Part 1:2021 for concepts, Part 2:2022 for requirements, Part 3:2023 for hardware, software, and services supply-chain guidance, and Part 4:2016 for cloud-service guidance. Part 2 applies to procurement and supply relationships in organizations of any type or size. The series can support an ISMS and contracts, but it does not itself create a legal duty or a standalone ISO/IEC 27036 certification.

Section 1

What does each part of the ISO/IEC 27036 series cover?

Start with Part 2 when the organization needs requirements for defining, implementing, operating, monitoring, reviewing, maintaining, or improving supplier and acquirer relationships. Part 1 explains the vocabulary and relationship types. Part 3 adds guidance for physically dispersed, multi-layer hardware, software, and service supply chains. Part 4 adds guidance for cloud service customers and providers.

Part 2 covers procurement and supply of products and services, including manufacturing, business processes, software and hardware components, build-operate-transfer arrangements, and cloud services. Its requirements address both acquirer and supplier perspectives; a supplier assessment that records only the acquirer's risks is incomplete.

Example: a software-as-a-service purchase uses Part 2 for the relationship requirements, Part 3 when upstream software, infrastructure, build, update, or support dependencies affect risk, and Part 4 for cloud customer-provider responsibilities. Using Part 3 or Part 4 does not replace Part 2 or make every recommendation mandatory; record which provisions the organization selected and why.

  • Scope owner: record the acquirer, supplier, supplied product or service, information and system access, locations, subcontractors, business dependence, and accountable owners.
  • Security and procurement: select the relevant Part 2 lifecycle requirements, then add Part 3 or Part 4 guidance where ICT supply-chain or cloud conditions change the risk.
  • Legal and assurance owners: record which duties come from law, contract, or customer commitments, and which assurance claims are limited by an ISO/IEC 27001 certification scope, instead of attributing them to ISO/IEC 27036.
Section 3

Which evidence supports a supplier-relationship decision?

Evidence should follow the decision. For planning, retain the relationship scope, risk assessment and treatment plan, legal or regulatory review, approvals, and selection criteria. For selection and agreement, retain due diligence, tender and response records, assurance limits, accepted exceptions, and the signed agreement.

During operation, retain service and security measures, access reviews, incident and change records, assurance results, corrective actions, and reassessments. At termination, retain transition decisions, access removal, asset return, information return or disposal, surviving retention duties, and closure approval.

A certificate, policy, or audit report is supporting evidence only. Record its issuer, scope, period, covered entity and service, qualifications, reviewer conclusion, and any gap that remains for the specific relationship.

  • Procurement owner: preserve the approved supplier-selection decision and agreement version.
  • Control owner: preserve operating evidence for the period and scope being reviewed.
  • Risk owner: record a gap as remediation, a compensating control, avoidance, transfer, or an explicitly approved residual risk.
Section 4

When should the relationship and its controls be reassessed?

Set a planned review interval from the relationship's risk and contract, then add event-driven review. Part 2 calls for periodic re-examination and review when significant business, legal, regulatory, architectural, policy, or contractual changes occur.

Reopen the assessment when the service, information, access, location, ownership, subcontracting, technology, threat exposure, control performance, or business dependence changes. An incident or missed service measure may require correction without changing the contract, while a changed responsibility or risk allocation may require an amendment.

Termination is a controlled lifecycle process. Coordinate continuity and transition, remove access, recover assets, return or dispose of information subject to retention duties, preserve required records, and record unresolved obligations before closure.

  • Assign the trigger and decision owner in advance.
  • Test high-impact continuity and exit assumptions before they are needed.
  • Close the record only when exit actions and remaining exceptions are documented.
Primary sources

References and citations

Related guides

Explore more topics

ISO/IEC 27036 Assurance Evidence FAQ
Collect evidence that answers a defined relationship-risk or agreement question and matches the product or service, period, location, controls, and dependencies in scope. A certificate, audit report, questionnaire, or attestation is an input, not automatic proof.
ISO/IEC 27036 Cloud Suppliers FAQ
Treat cloud as a supplier relationship with cloud service customer and provider perspectives. Apply Part 2 relationship requirements and Part 4 cloud guidance, then document how responsibility changes with the service and deployment model, configuration, data, interfaces, and nested cloud services.
ISO/IEC 27036 Contract Controls FAQ
Include controls selected from the relationship risk treatment and responsibilities, not a generic clause library. The agreement should make scope, performance, evidence, communication, exceptions, change, incident coordination, continuity, and exit reviewable by both parties.
ISO/IEC 27036 Contract Security Clauses Guide
Build ISO/IEC 27036-aligned supplier security clauses from relationship risk, responsibilities, assurance, change, incidents, and exit.
ISO/IEC 27036 Fourth Parties FAQ
Use the direct supplier relationship to obtain proportionate visibility and assurance over upstream dependencies that can materially affect security or delivery. ISO/IEC 27036 describes multi-layer supply chains; it does not require the same questionnaire or direct audit right for every remote tier.
ISO/IEC 27036 ICT Supply Chain Lifecycle Guide
Apply ISO/IEC 27036 across ICT supply-chain planning, acquisition, delivery, operation, change, and disposal.
ISO/IEC 27036 Indirect and Fourth Party Suppliers Guide
Manage indirect supplier dependencies under ISO/IEC 27036 using risk-based visibility, flow-down expectations, monitoring, and contingency planning.
ISO/IEC 27036 Onboarding and Offboarding Workflow
Run ISO/IEC 27036 supplier onboarding and offboarding with approval gates, evidence, access control, continuity, and verified closure.
ISO/IEC 27036 Risk Tiers FAQ
No fixed low, medium, or high tier model is prescribed by ISO/IEC 27036. Organizations can use tiers to scale due diligence, agreement terms, assurance, monitoring, approvals, and exit planning, but the criteria and decisions must reflect their own context and risk appetite.
ISO/IEC 27036 Supplier Assurance Framework Guide
Design risk-based ISO/IEC 27036 supplier assurance with defined evidence scope, monitoring, findings, and reassessment.
ISO/IEC 27036 Supplier Incidents FAQ
Agree incident contacts, triggers, information sharing, investigation support, evidence preservation, containment and recovery coordination, corrective action, and review before an incident occurs. ISO/IEC 27036 does not set one universal notification deadline; applicable law, regulation, policy, or contract supplies mandatory timing.
ISO/IEC 27036 Supplier Monitoring Evidence Workflow
Build ISO/IEC 27036 supplier monitoring that turns agreed measures, assurance, incidents, changes, and findings into decisions.
ISO/IEC 27036 Supplier Monitoring FAQ
ISO/IEC 27036 does not prescribe one universal monitoring interval. Set scheduled and event-driven reviews according to risk, agreement terms, service criticality, evidence availability, and the speed at which the relationship can change.
ISO/IEC 27036 Supplier Relationship Types Guide
Classify ISO/IEC 27036 relationships by product, service, ICT supply chain, and cloud context to select proportionate controls.
ISO/IEC 27036 Supplier Security FAQ
Plain-language answers about ISO/IEC 27036 scope, parts, roles, agreements, assurance, monitoring, incidents, indirect suppliers, cloud services, and exit.
ISO/IEC 27036 Termination and Offboarding FAQ
Plan termination before the relationship starts. Coordinate continuity and transition, revoke physical and logical access, rotate shared secrets, disable integrations, recover assets, return or delete information subject to retention duties, preserve required records, and verify surviving obligations.
ISO/IEC 27036 Third Party Risk Checklist
Use an ISO/IEC 27036 supplier-risk checklist across scope, assessment, agreement, operation, change, incidents, and termination.
ISO/IEC 27036 vs NIST SP 800-161 Comparison
Compare ISO/IEC 27036 supplier-relationship security with NIST SP 800-161 Rev. 1 cyber supply-chain risk management.