GuideGlobalISO/IEC 27036

ISO/IEC 27036 Indirect and Fourth Party Suppliers

Identify upstream suppliers that can materially affect delivery, then obtain proportionate visibility and assurance through the direct supplier.

Use Part 2 for supplier and acquirer relationship requirements and Parts 1, 3, and 4 for concepts or guidance. The series is voluntary; assess contracts, law, customer commitments, and certification scopes separately.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

ISO/IEC 27036 describes successive supplier relationships in a multi-layer ; it does not define a mandatory "fourth-party" register. Identify the upstream products, services, processes, and organizations whose compromise, outage, substitution, or loss of support could materially affect the acquired product or service. Obtain proportionate visibility and assurance through the direct supplier, and record what remains unknown.

Section 1

Which indirect suppliers and dependencies matter?

Start with the acquired product or service and trace security-relevant dependencies upstream. Prioritize a dependency when it handles sensitive information, has privileged or production access, supplies a critical component or platform, controls updates or signing, creates geographic or provider concentration, is difficult to replace, or can interrupt a critical function.

The supply-chain view is relative: an organization can be the acquirer of an upstream component and the supplier of a downstream product. The end customer often has limited control over its direct supplier's requirements and no direct control over suppliers farther upstream, so the direct agreement is the main route for visibility, flow-down, assurance, and change notice.

Example: a software-as-a-service provider can rely on a cloud infrastructure provider, an identity service, external software components, and a separate support operator. Investigate the dependencies that can expose customer information, interrupt the service, control privileged access or updates, or prevent safe exit; do not require the same evidence for an immaterial office supplier.

  • Relationship and technical owners: map critical components, hosted or managed services, privileged access, update paths, locations, concentration, alternatives, and known visibility limits.
  • Procurement and legal owners: define whether subcontracting is allowed and set notice or approval, flow-down, confidentiality, assurance, audit, incident, continuity, and remediation terms.
  • Risk owner: record unmanaged opacity or concentration and choose architecture changes, restricted access, redundancy, inventories, substitution, monitoring, or explicit residual-risk acceptance.
Section 2

How should acquirers address risks they cannot govern directly?

Ask the direct supplier for information that supports a decision, not an unlimited list of every subcontractor. Depending on risk, this can include named critical sub-suppliers, dependency categories, service and data locations, access roles, component or service inventories, assurance coverage, incident dependencies, continuity arrangements, and the process for notifying material changes.

ISO/IEC 27036-2 includes subcontractor transparency in supplier selection criteria, including use of subcontractors, access to the acquirer's information, personnel, changes, assurance, audit, and confidentiality. The specific contract should define which of those items apply and what the acquirer may do after an unacceptable change.

If direct visibility is unavailable, reduce the uncertainty with independent assurance, technical isolation, telemetry, tested portability, alternative sources, inventory and provenance controls, or a time-limited risk acceptance. Do not describe an unknown dependency as controlled.

  • Define "material change" for the relationship, including changes to critical dependencies, access, data location, control responsibility, ownership, support, or concentration.
  • Assign who reviews a notice, what evidence is required, and whether the response is approval, treatment, restricted use, substitution, or exit.
  • Use applicable law and the agreement, not ISO/IEC 27036, for mandatory notice periods.
Section 3

Which evidence supports an indirect-dependency decision?

Keep a dependency map that names critical direct and known indirect suppliers or, where names cannot be disclosed, the dependency category, function, location, access, concentration, and assurance route. Record the map's source, date, owner, confidence, and known gaps.

Link each critical dependency to agreement terms, supplier evidence, monitoring, incident and continuity arrangements, change notices, corrective actions, and the current risk decision. A direct supplier's general certificate does not prove that every upstream provider, location, component, or service is in scope.

For an accepted visibility limit, record why more detail is unavailable, which decisions the limit affects, the compensating controls, the approving risk owner, and the next review trigger.

  • Version maps and inventories so changes in upstream dependencies remain reviewable.
  • Protect supplier-confidential dependency information while keeping enough access for security, continuity, procurement, and audit owners.
  • Escalate missing, stale, conflicting, or out-of-scope assurance instead of treating the document request as complete.
Recommended next step

Put ISO/IEC 27036 Indirect and Fourth Party Suppliers into practice

Capture owners, evidence, decisions, and review dates in one workflow record so supplier security controls and escalation points stay auditable over time.

Section 4

When should the dependency map and treatment be reviewed?

Review the map and treatment at the planned risk-based interval and after a material sub-supplier notice, serious incident, critical vulnerability, ownership change, service or data-location move, component substitution, concentration increase, loss of support, control failure, or continuity test failure.

A change does not always require termination. The response can be updated assurance, remediation, a technical restriction, a replacement component, an alternative provider, reduced use, or approved residual risk. Record the decision and effective date.

At termination, confirm whether indirect providers retain information, credentials, support access, backups, logs, or other assets. Route return, disposal, retention, and verification through the direct supplier unless a separate agreement gives the acquirer a direct right.

  • Assign the trigger and decision owner in advance.
  • Test high-impact continuity and exit assumptions before they are needed.
  • Close the record only when exit actions and remaining exceptions are documented.
Primary sources

References and citations

Related guides

Explore more topics

ISO/IEC 27036 Assurance Evidence FAQ
Collect evidence that answers a defined relationship-risk or agreement question and matches the product or service, period, location, controls, and dependencies in scope. A certificate, audit report, questionnaire, or attestation is an input, not automatic proof.
ISO/IEC 27036 Cloud Suppliers FAQ
Treat cloud as a supplier relationship with cloud service customer and provider perspectives. Apply Part 2 relationship requirements and Part 4 cloud guidance, then document how responsibility changes with the service and deployment model, configuration, data, interfaces, and nested cloud services.
ISO/IEC 27036 Contract Controls FAQ
Include controls selected from the relationship risk treatment and responsibilities, not a generic clause library. The agreement should make scope, performance, evidence, communication, exceptions, change, incident coordination, continuity, and exit reviewable by both parties.
ISO/IEC 27036 Contract Security Clauses Guide
Build ISO/IEC 27036-aligned supplier security clauses from relationship risk, responsibilities, assurance, change, incidents, and exit.
ISO/IEC 27036 Fourth Parties FAQ
Use the direct supplier relationship to obtain proportionate visibility and assurance over upstream dependencies that can materially affect security or delivery. ISO/IEC 27036 describes multi-layer supply chains; it does not require the same questionnaire or direct audit right for every remote tier.
ISO/IEC 27036 ICT Supply Chain Lifecycle Guide
Apply ISO/IEC 27036 across ICT supply-chain planning, acquisition, delivery, operation, change, and disposal.
ISO/IEC 27036 Onboarding and Offboarding Workflow
Run ISO/IEC 27036 supplier onboarding and offboarding with approval gates, evidence, access control, continuity, and verified closure.
ISO/IEC 27036 Risk Tiers FAQ
No fixed low, medium, or high tier model is prescribed by ISO/IEC 27036. Organizations can use tiers to scale due diligence, agreement terms, assurance, monitoring, approvals, and exit planning, but the criteria and decisions must reflect their own context and risk appetite.
ISO/IEC 27036 Supplier Assurance Framework Guide
Design risk-based ISO/IEC 27036 supplier assurance with defined evidence scope, monitoring, findings, and reassessment.
ISO/IEC 27036 Supplier Incidents FAQ
Agree incident contacts, triggers, information sharing, investigation support, evidence preservation, containment and recovery coordination, corrective action, and review before an incident occurs. ISO/IEC 27036 does not set one universal notification deadline; applicable law, regulation, policy, or contract supplies mandatory timing.
ISO/IEC 27036 Supplier Monitoring Evidence Workflow
Build ISO/IEC 27036 supplier monitoring that turns agreed measures, assurance, incidents, changes, and findings into decisions.
ISO/IEC 27036 Supplier Monitoring FAQ
ISO/IEC 27036 does not prescribe one universal monitoring interval. Set scheduled and event-driven reviews according to risk, agreement terms, service criticality, evidence availability, and the speed at which the relationship can change.
ISO/IEC 27036 Supplier Relationship Types Guide
Classify ISO/IEC 27036 relationships by product, service, ICT supply chain, and cloud context to select proportionate controls.
ISO/IEC 27036 Supplier Security FAQ
Plain-language answers about ISO/IEC 27036 scope, parts, roles, agreements, assurance, monitoring, incidents, indirect suppliers, cloud services, and exit.
ISO/IEC 27036 Termination and Offboarding FAQ
Plan termination before the relationship starts. Coordinate continuity and transition, revoke physical and logical access, rotate shared secrets, disable integrations, recover assets, return or delete information subject to retention duties, preserve required records, and verify surviving obligations.
ISO/IEC 27036 Third Party Risk Checklist
Use an ISO/IEC 27036 supplier-risk checklist across scope, assessment, agreement, operation, change, incidents, and termination.
ISO/IEC 27036 vs NIST SP 800-161 Comparison
Compare ISO/IEC 27036 supplier-relationship security with NIST SP 800-161 Rev. 1 cyber supply-chain risk management.
Using the ISO/IEC 27036 Supplier Relationship Series
Understand how to apply the four-part ISO/IEC 27036 series without treating it as a law or standalone certification.