FAQGlobalISO/IEC 27036

ISO/IEC 27036 FAQ Supplier Incidents

How should supplier incidents be handled under ISO/IEC 27036?

Part 2 contains supplier and acquirer relationship requirements; the other parts provide concepts or guidance. Apply the relevant part proportionately and verify contractual, legal, and customer duties separately.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Agree incident contacts, triggers, information sharing, investigation support, evidence preservation, containment and recovery coordination, corrective action, and review before an occurs. ISO/IEC 27036 does not set one universal notification deadline; applicable law, regulation, policy, or contract supplies mandatory timing.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

How should supplier incidents be handled under ISO/IEC 27036?

Agree incident contacts, triggers, information sharing, investigation support, evidence preservation, containment and recovery coordination, corrective action, and review before an occurs. ISO/IEC 27036 does not set one universal notification deadline; applicable law, regulation, policy, or contract supplies mandatory timing.

ISO/IEC 27036-2:2022 requires the supplier agreement to contain an incident-management procedure and requires both parties to follow the agreed procedure. The standard calls for immediate reporting within that procedure, but the parties and applicable authorities still determine the reportable trigger, recipient, clock, and required content. Part 3:2023 adds supply-chain concerns, including sharing incident information upstream and downstream, responding to vulnerabilities, and examining whether the underlying weakness also affects other components or services.

  • Define reportable events, severity or impact triggers, primary and backup contacts, secure channels, initial information, update cadence, closure criteria, and escalation when facts are incomplete.
  • Require enough information to identify affected products, services, versions, systems, data, locations, accounts, time periods, upstream dependencies, indicators, containment, and customer actions.
  • Assign responsibility for investigation support, evidence preservation, vulnerability remediation, recovery, communications, legal or regulatory assessment, and corrective-action tracking.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 requires incident-management terms in the agreement and coordinated incident handling, records, corrective actions, and agreement updates.

Question 2

What should the first supplier notification contain?

The first notice should identify what happened or is suspected, when it was detected, the affected service or product, known time window and scope, current operational and information-security impact, containment already taken, whether an upstream supplier is involved, actions the acquirer should take, and the next update time. Mark unknown facts as unknown rather than delaying all notice for a complete investigation.

The contract or incident procedure should say how the supplier protects sensitive investigation material while still giving the acquirer enough information to assess impact and meet its own duties. Where law imposes a deadline or content requirement, record that source separately and make the contractual process capable of supporting it.

  • Log every notice, update, decision, evidence item, request, response, and responsible owner against a common incident identifier.
  • Preserve relevant logs, images, samples, timelines, communications, and chain of custody according to the agreed procedure and applicable duties.
  • Do not require the supplier to state an unsupported root cause in the first notice; require corrections when material facts change.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 requires agreed incident procedures, exchange of needed information, incident history, corrective actions, and updated agreement terms where needed.

ISO/IEC 27036-3:2023 standard page

Part 3 supports traceability, incident information sharing, secure exchange of logs and error information, vulnerability response, and supply-chain impact analysis.

Question 3

What happens after containment?

Track eradication, recovery, affected-version or service status, corrective actions, owners, due dates, and evidence of completion. Reassess the relationship risk, supplier controls, upstream dependencies, monitoring, assurance, agreement terms, and any downstream commitment the acquirer has made to customers or authorities.

Close the incident only when the agreed closure criteria are met or an authorized owner accepts the remaining actions and risk. Preserve a record of the incident and related decisions for the period required by the agreement, policy, and applicable law.

  • Test whether the same vulnerability, component, credential, process, or upstream supplier affects other products or relationships.
  • Update playbooks, contacts, monitoring, acceptance criteria, and agreement language when the incident exposes a gap.
  • Do not describe ISO/IEC 27036 as setting a universal reporting clock, regulator notice, or liability rule.
Citations
ISO/IEC 27036-3:2023 standard page

Part 3 guides vulnerability remediation, incident response support, traceability, verification, and review across hardware, software, and service dependencies.

Recommended next step

Put ISO/IEC 27036 FAQ: Supplier Incidents into practice

Capture owners, evidence, decisions, and review dates in one workflow record so supplier security controls and escalation points stay auditable over time.

Primary sources

References and citations

iso.org
Referenced sections
  • Part 2 requires incident records, corrective actions, monitoring and enforcement, risk reassessment, and agreement updates.
iso.org
Referenced sections
  • Part 3 guides vulnerability remediation, incident response support, traceability, verification, and review across hardware, software, and service dependencies.
Related guides

Explore more topics

ISO/IEC 27036 Assurance Evidence FAQ
Collect evidence that answers a defined relationship-risk or agreement question and matches the product or service, period, location, controls, and dependencies in scope. A certificate, audit report, questionnaire, or attestation is an input, not automatic proof.
ISO/IEC 27036 Cloud Suppliers FAQ
Treat cloud as a supplier relationship with cloud service customer and provider perspectives. Apply Part 2 relationship requirements and Part 4 cloud guidance, then document how responsibility changes with the service and deployment model, configuration, data, interfaces, and nested cloud services.
ISO/IEC 27036 Contract Controls FAQ
Include controls selected from the relationship risk treatment and responsibilities, not a generic clause library. The agreement should make scope, performance, evidence, communication, exceptions, change, incident coordination, continuity, and exit reviewable by both parties.
ISO/IEC 27036 Contract Security Clauses Guide
Build ISO/IEC 27036-aligned supplier security clauses from relationship risk, responsibilities, assurance, change, incidents, and exit.
ISO/IEC 27036 Fourth Parties FAQ
Use the direct supplier relationship to obtain proportionate visibility and assurance over upstream dependencies that can materially affect security or delivery. ISO/IEC 27036 describes multi-layer supply chains; it does not require the same questionnaire or direct audit right for every remote tier.
ISO/IEC 27036 ICT Supply Chain Lifecycle Guide
Apply ISO/IEC 27036 across ICT supply-chain planning, acquisition, delivery, operation, change, and disposal.
ISO/IEC 27036 Indirect and Fourth Party Suppliers Guide
Manage indirect supplier dependencies under ISO/IEC 27036 using risk-based visibility, flow-down expectations, monitoring, and contingency planning.
ISO/IEC 27036 Onboarding and Offboarding Workflow
Run ISO/IEC 27036 supplier onboarding and offboarding with approval gates, evidence, access control, continuity, and verified closure.
ISO/IEC 27036 Risk Tiers FAQ
No fixed low, medium, or high tier model is prescribed by ISO/IEC 27036. Organizations can use tiers to scale due diligence, agreement terms, assurance, monitoring, approvals, and exit planning, but the criteria and decisions must reflect their own context and risk appetite.
ISO/IEC 27036 Supplier Assurance Framework Guide
Design risk-based ISO/IEC 27036 supplier assurance with defined evidence scope, monitoring, findings, and reassessment.
ISO/IEC 27036 Supplier Monitoring Evidence Workflow
Build ISO/IEC 27036 supplier monitoring that turns agreed measures, assurance, incidents, changes, and findings into decisions.
ISO/IEC 27036 Supplier Monitoring FAQ
ISO/IEC 27036 does not prescribe one universal monitoring interval. Set scheduled and event-driven reviews according to risk, agreement terms, service criticality, evidence availability, and the speed at which the relationship can change.
ISO/IEC 27036 Supplier Relationship Types Guide
Classify ISO/IEC 27036 relationships by product, service, ICT supply chain, and cloud context to select proportionate controls.
ISO/IEC 27036 Supplier Security FAQ
Plain-language answers about ISO/IEC 27036 scope, parts, roles, agreements, assurance, monitoring, incidents, indirect suppliers, cloud services, and exit.
ISO/IEC 27036 Termination and Offboarding FAQ
Plan termination before the relationship starts. Coordinate continuity and transition, revoke physical and logical access, rotate shared secrets, disable integrations, recover assets, return or delete information subject to retention duties, preserve required records, and verify surviving obligations.
ISO/IEC 27036 Third Party Risk Checklist
Use an ISO/IEC 27036 supplier-risk checklist across scope, assessment, agreement, operation, change, incidents, and termination.
ISO/IEC 27036 vs NIST SP 800-161 Comparison
Compare ISO/IEC 27036 supplier-relationship security with NIST SP 800-161 Rev. 1 cyber supply-chain risk management.
Using the ISO/IEC 27036 Supplier Relationship Series
Understand how to apply the four-part ISO/IEC 27036 series without treating it as a law or standalone certification.