FAQGlobalISO/IEC 27036

ISO/IEC 27036 FAQ

Direct answers to common ISO/IEC 27036 supplier-relationship security questions.

The series supports risk-based supplier governance; it is not a law and does not create a standalone ISO/IEC 27036 certification.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
FAQ modules
8

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

is the four-part international standards series for information security in supplier relationships. Start with the relationship: who acquires and supplies what, which information or systems are exposed, how dependent the parties are, and which direct or indirect suppliers affect delivery. Then select the relevant part of the series and preserve the resulting decision and evidence.

Browse sub-FAQs

Choose the question set you need

These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.

Browse all FAQ items24
Focused FAQ modules
8
Showing 8 of 8
FAQ module

ISO/IEC 27036 Assurance Evidence FAQ

Collect evidence that answers a defined relationship-risk or agreement question and matches the product or service, period, location, controls, and dependencies in scope. A certificate, audit report, questionnaire, or attestation is an input, not automatic proof.

3 items
FAQ module

ISO/IEC 27036 Cloud Suppliers FAQ

Treat cloud as a supplier relationship with cloud service customer and provider perspectives. Apply Part 2 relationship requirements and Part 4 cloud guidance, then document how responsibility changes with the service and deployment model, configuration, data, interfaces, and nested cloud services.

3 items
FAQ module

ISO/IEC 27036 Contract Controls FAQ

Include controls selected from the relationship risk treatment and responsibilities, not a generic clause library. The agreement should make scope, performance, evidence, communication, exceptions, change, incident coordination, continuity, and exit reviewable by both parties.

3 items
FAQ module

ISO/IEC 27036 Fourth Parties FAQ

Use the direct supplier relationship to obtain proportionate visibility and assurance over upstream dependencies that can materially affect security or delivery. ISO/IEC 27036 describes multi-layer supply chains; it does not require the same questionnaire or direct audit right for every remote tier.

3 items
FAQ module

ISO/IEC 27036 Risk Tiers FAQ

No fixed low, medium, or high tier model is prescribed by ISO/IEC 27036. Organizations can use tiers to scale due diligence, agreement terms, assurance, monitoring, approvals, and exit planning, but the criteria and decisions must reflect their own context and risk appetite.

3 items
FAQ module

ISO/IEC 27036 Supplier Incidents FAQ

Agree incident contacts, triggers, information sharing, investigation support, evidence preservation, containment and recovery coordination, corrective action, and review before an incident occurs. ISO/IEC 27036 does not set one universal notification deadline; applicable law, regulation, policy, or contract supplies mandatory timing.

3 items
FAQ module

ISO/IEC 27036 Supplier Monitoring FAQ

ISO/IEC 27036 does not prescribe one universal monitoring interval. Set scheduled and event-driven reviews according to risk, agreement terms, service criticality, evidence availability, and the speed at which the relationship can change.

3 items
FAQ module

ISO/IEC 27036 Termination and Offboarding FAQ

Plan termination before the relationship starts. Coordinate continuity and transition, revoke physical and logical access, rotate shared secrets, disable integrations, recover assets, return or delete information subject to retention duties, preserve required records, and verify surviving obligations.

3 items
Question 1

What is the ISO/IEC 27036 series?

Part 1:2021 provides overview and concepts; Part 2:2022 specifies fundamental requirements for supplier and acquirer relationships; Part 3:2023 guides hardware, software, and services supply-chain security; and Part 4:2016 guides cloud service customers and providers. ISO lists all four editions as published; Part 4 was confirmed in 2022, while Part 1 entered systematic review on 15 July 2026.

Use the series throughout the relationship life cycle and alongside the organization's risk management, procurement, security, operational, and human-resources processes. Identify legal, regulatory, customer, and contract duties separately; the series is not legislation.

  • Part 2 applies to procurement and supply of products and services across organizations of any type, size, or nature, including manufacturing, business processes, software, hardware, and cloud services.
  • An acquirer procures a product or service; a supplier agrees to provide it. The parties can belong to the same organization, and one organization can be an acquirer in one relationship and a supplier in another.
  • The series does not establish a standalone certification scheme. ISO/IEC 27001 certification or other assurance can inform a supplier decision only within its actual scope.
Question 2

What implementation sequence should teams follow?

Define the product or service, parties, information, systems, locations, access, dependencies, criticality, and applicable duties. Assess inherent risk, set the acceptable level, choose treatment, and document management's decision before procurement proceeds.

Then select the supplier against stated security criteria, agree roles and controls, define evidence and acceptance, manage transition, monitor performance and change, coordinate incidents and corrective actions, and execute renewal or termination from a pre-agreed plan.

  • Planning: relationship scope, risk assessment, treatment, minimum requirements, owner, and approval.
  • Selection and agreement: supplier evidence, audit and assurance terms, subcontractors, service measures, change, incidents, enforcement, transition, and termination.
  • Management and exit: scheduled and event-driven review, findings and corrective actions, agreement updates, asset and access control, transfer or cancellation, and verified closure.
Recommended next step

Put ISO/IEC 27036 FAQ into practice

Capture owners, evidence, decisions, and review dates in one workflow record so supplier security controls and escalation points stay auditable over time.

Question 3

Which part should be used for a specific decision?

Use Part 1 to understand terms, roles, relationship types, supply chains, cloud context, and the structure of the series. Use Part 2 for the fundamental requirements that govern an individual supplier relationship and the organizational processes supporting it. Add Part 3 when hardware, software, services, components, provenance, vulnerabilities, or multi-layer supply-chain risk matter. Add Part 4 for cloud customer-provider risks and responsibilities.

Part 3 and Part 4 both exclude business-continuity management or resiliency from their specific scope and point to ISO/IEC 27031 for ICT readiness for continuity. The supplier agreement and applicable obligations can still contain continuity and recovery requirements.

  • Before procurement, use the risk-tier FAQ to scale the assessment and the contract-controls FAQ to translate treatment into reviewable commitments.
  • During operation, use the assurance-evidence, supplier-monitoring, supplier-incidents, cloud-suppliers, and fourth-parties FAQs for the relevant decision.
  • Before renewal or exit, use the termination-and-offboarding FAQ to verify transfer, access removal, asset handling, retained duties, and closure evidence.
Primary sources

References and citations

iso.org
Referenced sections
  • Part 3 covers hardware, software, and services supply-chain guidance and excludes business-continuity management or resiliency from its scope.
iso.org
Referenced sections
  • Part 4 covers cloud supplier-relationship guidance, remains current after 2022 confirmation, and excludes cloud business-continuity management or resiliency from its scope.
Related guides

Explore more topics

ISO/IEC 27036 Contract Security Clauses Guide
Build ISO/IEC 27036-aligned supplier security clauses from relationship risk, responsibilities, assurance, change, incidents, and exit.
ISO/IEC 27036 ICT Supply Chain Lifecycle Guide
Apply ISO/IEC 27036 across ICT supply-chain planning, acquisition, delivery, operation, change, and disposal.
ISO/IEC 27036 Indirect and Fourth Party Suppliers Guide
Manage indirect supplier dependencies under ISO/IEC 27036 using risk-based visibility, flow-down expectations, monitoring, and contingency planning.
ISO/IEC 27036 Onboarding and Offboarding Workflow
Run ISO/IEC 27036 supplier onboarding and offboarding with approval gates, evidence, access control, continuity, and verified closure.
ISO/IEC 27036 Supplier Assurance Framework Guide
Design risk-based ISO/IEC 27036 supplier assurance with defined evidence scope, monitoring, findings, and reassessment.
ISO/IEC 27036 Supplier Monitoring Evidence Workflow
Build ISO/IEC 27036 supplier monitoring that turns agreed measures, assurance, incidents, changes, and findings into decisions.
ISO/IEC 27036 Supplier Relationship Types Guide
Classify ISO/IEC 27036 relationships by product, service, ICT supply chain, and cloud context to select proportionate controls.
ISO/IEC 27036 Third Party Risk Checklist
Use an ISO/IEC 27036 supplier-risk checklist across scope, assessment, agreement, operation, change, incidents, and termination.
ISO/IEC 27036 vs NIST SP 800-161 Comparison
Compare ISO/IEC 27036 supplier-relationship security with NIST SP 800-161 Rev. 1 cyber supply-chain risk management.
Using the ISO/IEC 27036 Supplier Relationship Series
Understand how to apply the four-part ISO/IEC 27036 series without treating it as a law or standalone certification.