FAQGlobalISO/IEC 27036

ISO/IEC 27036 FAQ Assurance Evidence

What supplier assurance evidence should we collect?

Part 2 contains supplier and acquirer relationship requirements; the other parts provide concepts or guidance. Apply the relevant part proportionately and verify contractual, legal, and customer duties separately.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Collect that answers a defined relationship-risk or agreement question and matches the product or service, period, location, controls, and dependencies in scope. A certificate, audit report, questionnaire, or attestation is an input, not automatic proof.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What supplier assurance evidence should we collect?

Collect that answers a defined relationship-risk or agreement question and matches the product or service, period, location, controls, and dependencies in scope. A certificate, audit report, questionnaire, or attestation is an input, not automatic proof.

ISO/IEC 27036-2:2022 sets requirements for acquirers and suppliers across the relationship lifecycle. It identifies several forms of assurance, including performance reports, attestations, self-assessments, independent assessments, audits, tested continuity plans, and ISO/IEC 27001 certification. Part 3:2023 adds hardware, software, and service supply-chain guidance. The acquirer must decide what evidence is credible and sufficient for the selected supplier and requirement.

  • Start with the requirement and decision: identify the control or risk being tested, the acceptance criteria, the reviewer, and what happens if the evidence is missing or weak.
  • Check the evidence boundary: supplier legal entity, named product or service, sites, systems, control period, exclusions, qualifications, subcontractors, and upstream components.
  • Test the result: inspect findings and corrective actions, compare claims with the agreement and other evidence, and record any residual risk or follow-up.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 requires risk-based supplier selection and agreement management and identifies several possible assurance methods rather than one mandatory evidence package.

ISO/IEC 27036-3:2023 standard page

Part 3 guides acquirers to seek credible evidence, verify supplier claims, and assess what attestations or certifications mean for the intended use.

Recommended next step

Put ISO/IEC 27036 FAQ: Assurance Evidence into practice

Capture owners, evidence, decisions, and review dates in one workflow record so supplier security controls and escalation points stay auditable over time.

Question 2

How should each evidence type be used?

Use a certificate to confirm only the certified management-system scope and period. Use an independent audit or attestation report for the controls, system boundary, period, exceptions, and complementary responsibilities it actually covers. Use questionnaires and interviews to fill relationship-specific gaps, but verify consequential answers with records, demonstrations, tests, or other independent evidence when the risk warrants it.

Product evidence can differ from organization-level evidence. For hardware, software, and services, relevant evidence may include test results, vulnerability and remediation records, chain-of-custody records, provenance information, a software bill of materials, delivery verification, or proof that required security features work. A software bill of materials helps identify components and relationships, but it does not prove that the listed components are vulnerability-free or securely configured.

  • A policy shows intended practice; operating records show whether the practice occurred.
  • A point-in-time test does not establish performance throughout a longer review period.
  • A supplier-wide report may omit the service, region, platform, or subservice organization on which the acquirer relies.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 ties supplier assurance, audit terms, performance measures, corrective actions, and review records to the specific relationship and agreement.

ISO/IEC 27036-3:2023 standard page

Part 3 describes verification of supplier claims, attestations, certifications, product integrity, testing, provenance, and supply-chain transparency.

Question 3

What decision record should be retained?

Retain the relationship and requirement being assessed, the evidence requested and received, its scope and period, the reviewer, the conclusion against stated acceptance criteria, open findings, corrective-action owner and due date, residual-risk decision, approval, and next review or event trigger.

Reassess when evidence expires or the service, product, location, ownership, subcontracting, threat exposure, agreement, or intended use changes. An incident or material control failure can require an earlier review.

  • Do not treat ISO/IEC 27036 as a standalone certification scheme or as a fixed evidence checklist.
  • Do not silently convert missing visibility into a passing result; record the limitation and its effect on risk.
  • Escalate unresolved gaps to the person authorized to require remediation, add a compensating control, accept the residual risk, or reject or exit the relationship.
Citations
ISO/IEC 27036-3:2023 standard page

Part 3 supports reassessment through verification, monitoring, vulnerability response, change records, and evidence about multi-layer supply-chain dependencies.

Primary sources

References and citations

iso.org
Referenced sections
  • Part 2 requires documented risk, selection, agreement, monitoring, corrective-action, and termination outputs for the supplier relationship.
iso.org
Referenced sections
  • Part 3 supports reassessment through verification, monitoring, vulnerability response, change records, and evidence about multi-layer supply-chain dependencies.
Related guides

Explore more topics

ISO/IEC 27036 Cloud Suppliers FAQ
Treat cloud as a supplier relationship with cloud service customer and provider perspectives. Apply Part 2 relationship requirements and Part 4 cloud guidance, then document how responsibility changes with the service and deployment model, configuration, data, interfaces, and nested cloud services.
ISO/IEC 27036 Contract Controls FAQ
Include controls selected from the relationship risk treatment and responsibilities, not a generic clause library. The agreement should make scope, performance, evidence, communication, exceptions, change, incident coordination, continuity, and exit reviewable by both parties.
ISO/IEC 27036 Contract Security Clauses Guide
Build ISO/IEC 27036-aligned supplier security clauses from relationship risk, responsibilities, assurance, change, incidents, and exit.
ISO/IEC 27036 Fourth Parties FAQ
Use the direct supplier relationship to obtain proportionate visibility and assurance over upstream dependencies that can materially affect security or delivery. ISO/IEC 27036 describes multi-layer supply chains; it does not require the same questionnaire or direct audit right for every remote tier.
ISO/IEC 27036 ICT Supply Chain Lifecycle Guide
Apply ISO/IEC 27036 across ICT supply-chain planning, acquisition, delivery, operation, change, and disposal.
ISO/IEC 27036 Indirect and Fourth Party Suppliers Guide
Manage indirect supplier dependencies under ISO/IEC 27036 using risk-based visibility, flow-down expectations, monitoring, and contingency planning.
ISO/IEC 27036 Onboarding and Offboarding Workflow
Run ISO/IEC 27036 supplier onboarding and offboarding with approval gates, evidence, access control, continuity, and verified closure.
ISO/IEC 27036 Risk Tiers FAQ
No fixed low, medium, or high tier model is prescribed by ISO/IEC 27036. Organizations can use tiers to scale due diligence, agreement terms, assurance, monitoring, approvals, and exit planning, but the criteria and decisions must reflect their own context and risk appetite.
ISO/IEC 27036 Supplier Assurance Framework Guide
Design risk-based ISO/IEC 27036 supplier assurance with defined evidence scope, monitoring, findings, and reassessment.
ISO/IEC 27036 Supplier Incidents FAQ
Agree incident contacts, triggers, information sharing, investigation support, evidence preservation, containment and recovery coordination, corrective action, and review before an incident occurs. ISO/IEC 27036 does not set one universal notification deadline; applicable law, regulation, policy, or contract supplies mandatory timing.
ISO/IEC 27036 Supplier Monitoring Evidence Workflow
Build ISO/IEC 27036 supplier monitoring that turns agreed measures, assurance, incidents, changes, and findings into decisions.
ISO/IEC 27036 Supplier Monitoring FAQ
ISO/IEC 27036 does not prescribe one universal monitoring interval. Set scheduled and event-driven reviews according to risk, agreement terms, service criticality, evidence availability, and the speed at which the relationship can change.
ISO/IEC 27036 Supplier Relationship Types Guide
Classify ISO/IEC 27036 relationships by product, service, ICT supply chain, and cloud context to select proportionate controls.
ISO/IEC 27036 Supplier Security FAQ
Plain-language answers about ISO/IEC 27036 scope, parts, roles, agreements, assurance, monitoring, incidents, indirect suppliers, cloud services, and exit.
ISO/IEC 27036 Termination and Offboarding FAQ
Plan termination before the relationship starts. Coordinate continuity and transition, revoke physical and logical access, rotate shared secrets, disable integrations, recover assets, return or delete information subject to retention duties, preserve required records, and verify surviving obligations.
ISO/IEC 27036 Third Party Risk Checklist
Use an ISO/IEC 27036 supplier-risk checklist across scope, assessment, agreement, operation, change, incidents, and termination.
ISO/IEC 27036 vs NIST SP 800-161 Comparison
Compare ISO/IEC 27036 supplier-relationship security with NIST SP 800-161 Rev. 1 cyber supply-chain risk management.
Using the ISO/IEC 27036 Supplier Relationship Series
Understand how to apply the four-part ISO/IEC 27036 series without treating it as a law or standalone certification.