GuideGlobalISO/IEC 27036

ISO/IEC 27036 Contract Security Clauses

Turn supplier-risk treatment into agreement terms that both acquirer and supplier can operate, measure, review, and enforce.

Use Part 2 for supplier and acquirer relationship requirements and Parts 1, 3, and 4 for concepts or guidance. The series is voluntary; assess contracts, law, customer commitments, and certification scopes separately.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Draft each from the approved relationship scope and risk treatment. State who must do what, for which product or service, by when, to what measure, with what evidence, and what happens after failure, change, or termination. This is a clause-content checklist, not official ISO wording or a substitute for jurisdiction-specific legal review.

Section 1

Which supplier risks and responsibilities need agreement terms?

The agreement should identify the parties, covered products and services, information and systems, locations, authorized access, security requirements, service measures, acceptance criteria, and the party responsible for each control. Attach a controlled schedule when detail will change more often than the main contract.

Address risks in both directions. The supplier may handle the acquirer's information or operate critical services; the acquirer may also access the supplier's sensitive production, assurance, or personnel information. Confidentiality, permitted use, access, evidence handling, and return or disposal terms should cover both.

Example clause design for remote maintenance: identify the systems that may be reached, authorized supplier roles, access approval and authentication, logging and review evidence, permitted support window, incident route, and access-removal trigger. The agreement should also state the response when evidence is missing or access falls outside those conditions. This is an example of translating risk treatment into measurable terms, not wording prescribed by ISO.

  • Scope and controls: define covered entities, service boundaries, information classification, access, locations, approved uses, security controls, measures, acceptance, and exception handling.
  • Assurance and events: define evidence frequency and scope, audit or independent-assessment terms, vulnerability and change handling, incident cooperation, escalation, remediation, and continuity tests.
  • Supply chain and exit: define whether subcontracting is allowed, notice or approval conditions, flow-down requirements, assurance, transition assistance, access removal, asset return, information return or disposal, retention, and surviving duties.
Section 2

How should teams select and negotiate security clauses?

Start with the tender, supplier response, assessment, treatment plan, and selected exceptions. ISO/IEC 27036-2 requires the relationship agreement to address security requirements, implementation responsibilities, service or performance measures, reporting, communication, compliance monitoring and enforcement, change, and termination. Include only terms that fit the actual relationship, but do not leave a selected treatment as an informal promise.

Write measurable obligations. Replace phrases such as 'appropriate security' or 'prompt notice' with the applicable control, actor, scope, evidence, and contractually agreed timing. Derive any statutory deadline from the governing law; the ISO/IEC 27036 series does not set a universal incident-notification period.

  • Assign business, security, privacy, continuity, procurement, and legal review to the owners relevant to the service.
  • Record rejected language, the resulting gap, any compensating control, the residual-risk approver, and an expiry or review trigger.
  • Check that schedules, order forms, online terms, and incorporated policies do not conflict with the negotiated security terms or allow unilateral change without the agreed response.
Section 3

Which records make the agreement reviewable?

Keep the approved risk treatment beside the executed agreement, schedules, incorporated policies, order forms, amendments, and exception approvals. A clause-to-risk record should show which obligation implements each selected treatment and who owns verification.

For each recurring obligation, record the evidence, period, covered entity and service, reviewer, result, limitation, and follow-up. Examples include access reviews, service reports, incident exercises, vulnerability or patch reports, independent assurance, continuity tests, and sub-supplier notices.

Preserve notices, waivers, breach or remediation correspondence, change decisions, and closure evidence. Without this history, a later reviewer cannot tell whether the parties used the enforcement and change mechanisms they agreed.

  • Contract owner: preserve the signed version and the hierarchy among the main agreement, schedules, orders, and online terms.
  • Control owner: retain evidence that matches the obligation's scope and review period.
  • Risk owner: approve unresolved deviations and record the compensating control, expiry, and next decision date.
Recommended next step

Put ISO/IEC 27036 Contract Security Clauses into practice

Capture owners, evidence, decisions, and review dates in one workflow record so supplier security controls and escalation points stay auditable over time.

Section 4

When should clauses be changed, renewed, or closed?

Use the agreement's change process when scope, access, data, location, ownership, technology, subcontracting, service measures, assurance, or law changes. A notice alone is not acceptance if the contract requires approval or gives the acquirer a right to object, require treatment, suspend use, or terminate.

At renewal, compare current operations with the contract and close undocumented side arrangements. At termination, apply the agreed transition, access removal, asset return, information return or disposal, retention, confidentiality, assistance, and verification terms.

  • Calendar recurring evidence, notice, renewal, and termination dates with named owners.
  • Test high-impact continuity, data export, replacement, and deletion-verification terms while the relationship is operating.
  • Close the contract record only when exit evidence and every surviving or unresolved obligation are recorded.
Primary sources

References and citations

Related guides

Explore more topics

ISO/IEC 27036 Assurance Evidence FAQ
Collect evidence that answers a defined relationship-risk or agreement question and matches the product or service, period, location, controls, and dependencies in scope. A certificate, audit report, questionnaire, or attestation is an input, not automatic proof.
ISO/IEC 27036 Cloud Suppliers FAQ
Treat cloud as a supplier relationship with cloud service customer and provider perspectives. Apply Part 2 relationship requirements and Part 4 cloud guidance, then document how responsibility changes with the service and deployment model, configuration, data, interfaces, and nested cloud services.
ISO/IEC 27036 Contract Controls FAQ
Include controls selected from the relationship risk treatment and responsibilities, not a generic clause library. The agreement should make scope, performance, evidence, communication, exceptions, change, incident coordination, continuity, and exit reviewable by both parties.
ISO/IEC 27036 Fourth Parties FAQ
Use the direct supplier relationship to obtain proportionate visibility and assurance over upstream dependencies that can materially affect security or delivery. ISO/IEC 27036 describes multi-layer supply chains; it does not require the same questionnaire or direct audit right for every remote tier.
ISO/IEC 27036 ICT Supply Chain Lifecycle Guide
Apply ISO/IEC 27036 across ICT supply-chain planning, acquisition, delivery, operation, change, and disposal.
ISO/IEC 27036 Indirect and Fourth Party Suppliers Guide
Manage indirect supplier dependencies under ISO/IEC 27036 using risk-based visibility, flow-down expectations, monitoring, and contingency planning.
ISO/IEC 27036 Onboarding and Offboarding Workflow
Run ISO/IEC 27036 supplier onboarding and offboarding with approval gates, evidence, access control, continuity, and verified closure.
ISO/IEC 27036 Risk Tiers FAQ
No fixed low, medium, or high tier model is prescribed by ISO/IEC 27036. Organizations can use tiers to scale due diligence, agreement terms, assurance, monitoring, approvals, and exit planning, but the criteria and decisions must reflect their own context and risk appetite.
ISO/IEC 27036 Supplier Assurance Framework Guide
Design risk-based ISO/IEC 27036 supplier assurance with defined evidence scope, monitoring, findings, and reassessment.
ISO/IEC 27036 Supplier Incidents FAQ
Agree incident contacts, triggers, information sharing, investigation support, evidence preservation, containment and recovery coordination, corrective action, and review before an incident occurs. ISO/IEC 27036 does not set one universal notification deadline; applicable law, regulation, policy, or contract supplies mandatory timing.
ISO/IEC 27036 Supplier Monitoring Evidence Workflow
Build ISO/IEC 27036 supplier monitoring that turns agreed measures, assurance, incidents, changes, and findings into decisions.
ISO/IEC 27036 Supplier Monitoring FAQ
ISO/IEC 27036 does not prescribe one universal monitoring interval. Set scheduled and event-driven reviews according to risk, agreement terms, service criticality, evidence availability, and the speed at which the relationship can change.
ISO/IEC 27036 Supplier Relationship Types Guide
Classify ISO/IEC 27036 relationships by product, service, ICT supply chain, and cloud context to select proportionate controls.
ISO/IEC 27036 Supplier Security FAQ
Plain-language answers about ISO/IEC 27036 scope, parts, roles, agreements, assurance, monitoring, incidents, indirect suppliers, cloud services, and exit.
ISO/IEC 27036 Termination and Offboarding FAQ
Plan termination before the relationship starts. Coordinate continuity and transition, revoke physical and logical access, rotate shared secrets, disable integrations, recover assets, return or delete information subject to retention duties, preserve required records, and verify surviving obligations.
ISO/IEC 27036 Third Party Risk Checklist
Use an ISO/IEC 27036 supplier-risk checklist across scope, assessment, agreement, operation, change, incidents, and termination.
ISO/IEC 27036 vs NIST SP 800-161 Comparison
Compare ISO/IEC 27036 supplier-relationship security with NIST SP 800-161 Rev. 1 cyber supply-chain risk management.
Using the ISO/IEC 27036 Supplier Relationship Series
Understand how to apply the four-part ISO/IEC 27036 series without treating it as a law or standalone certification.