ISO/IEC 27036 vs NIST SP 800-161 side-by-sideSupplier security comparisonISO/IEC 27036

ISO/IEC 27036 ISO/IEC 27036 vs NIST SP 800-161

Use ISO/IEC 27036-2 for supplier-relationship requirements and the other ISO parts for relationship-specific guidance. Use NIST SP 800-161 Rev. 1 Update 1 to integrate cyber supply-chain risk management across enterprise, mission and business, and operational levels.

Use Part 2 for supplier and acquirer relationship requirements and Parts 1, 3, and 4 for concepts or guidance. The series is voluntary; assess contracts, law, customer commitments, and certification scopes separately.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use both when you need relationship-level requirements and an organization-wide cyber supply-chain risk management program. ISO/IEC 27036-2 defines requirements for supplier and acquirer relationships, while Parts 1, 3, and 4 add concepts or guidance. NIST SP 800-161 Rev. 1 Update 1 integrates into enterprise, mission and business process, and operational risk management and supplies tailored control guidance. Neither publication is a certification, and using one does not establish conformity with the other.

ISO/IEC 27036 vs NIST SP 800-161 side-by-side comparison

ISO/IEC 27036 vs NIST SP 800-161: scope, roles, evidence, and decision rule

Choose the publication from the decision you need to make. Use ISO/IEC 27036 for the supplier relationship, NIST SP 800-161 Rev. 1 Update 1 for the program, or both with a traceable crosswalk when the scopes overlap.

Review all sources
First framework
ISO/IEC 27036

A multipart supplier-relationship series: Part 2 contains requirements, while Parts 1, 3, and 4 provide concepts or guidance for relationship, supply-chain, and cloud contexts.

Second framework
NIST SP 800-161

NIST guidance for cybersecurity supply-chain risk management across enterprise, mission and business process, and operational levels, with control guidance and templates; it is not a certification scheme.

Comparison row 1

Scope and covered activity

ISO/IEC 27036

ISO/IEC 27036 structures supplier and acquirer security across relationship types, contracts, monitoring, supply-chain visibility, and exit.

NIST SP 800-161

NIST SP 800-161 is cybersecurity supply-chain risk-management guidance for systems and organizations.

Operational implication

Use ISO/IEC 27036 to define the supplier relationship and NIST SP 800-161 to organize the risk-management work around that relationship.

Comparison row 2

Primary actors

ISO/IEC 27036

ISO/IEC 27036 addresses both acquirers and suppliers. Part 2 allocates activities across the relationship lifecycle, while the organization assigns accountable business, procurement, security, legal, technical, and assurance owners.

NIST SP 800-161

NIST SP 800-161 addresses executives, enterprise and risk owners, mission and business owners, acquisition, security, privacy, engineering, system, operations, legal, and other stakeholders across three risk levels.

Operational implication

Map the owner of the supplier relationship separately from enterprise, mission or business process, and operational risk owners; one person or group may hold several roles.

Comparison row 3

Scope trigger

ISO/IEC 27036

Part 2 applies to procurement and supply of products and services. The organization selects and applies lifecycle requirements to its supplier and acquirer relationships and uses risk to determine the depth of supporting guidance and evidence.

NIST SP 800-161

NIST SP 800-161 applies when an organization integrates cybersecurity supply-chain risk into enterprise and system risk management. It uses multilevel risk, criticality, and tailoring rather than one universal supplier threshold.

Operational implication

Scope the relationship under ISO/IEC 27036 and the enterprise, mission or business process, and system under NIST before mapping controls or evidence.

Comparison row 4

Requirements and practices

ISO/IEC 27036

ISO/IEC 27036-2 contains requirements to define, implement, operate, monitor, review, maintain, and improve supplier and acquirer relationships; the other parts add concepts or guidance.

NIST SP 800-161

NIST SP 800-161 provides strategy, policy, implementation-plan, acquisition, information-sharing, training, risk-assessment, control, and monitoring guidance. Organizations tailor its guidance to their context.

Operational implication

Use ISO/IEC 27036-2 for the relationship requirements and NIST SP 800-161 for the surrounding program and tailored control work.

Comparison row 5

Evidence and records

ISO/IEC 27036

ISO/IEC 27036 evidence should show the relationship is being managed: contracts, due diligence, reviews, approvals, and supplier communications.

NIST SP 800-161

NIST SP 800-161 evidence should show the risk program is operating: strategy, policy, plans, risk assessments, controls, and monitoring outputs.

Operational implication

Keep supplier relationship records and risk-management records distinct unless the same artifact clearly satisfies both needs.

Comparison row 6

Timing and cadence

ISO/IEC 27036

Part 2 requires supplier-relationship risks to be addressed continuously and re-examined periodically or after significant business, legal, regulatory, architectural, policy, or contractual changes.

NIST SP 800-161

NIST SP 800-161 integrates into recurring enterprise, mission and business process, and operational risk activities, acquisition and system lifecycles, assessments, monitoring, and response.

Operational implication

Coordinate shared evidence dates, but preserve the review event and decision owner required by each scope.

Comparison row 7

Legal force and assurance

ISO/IEC 27036

ISO/IEC 27036-2 is a requirements standard, but adopting it does not by itself create a law or a standalone ISO/IEC 27036 certification. Agreements, customer assurance, internal review, or an ISMS can make selected requirements reviewable in context.

NIST SP 800-161

NIST SP 800-161 is guidance, not a certification scheme. A law, regulation, government policy, acquisition rule, or contract can separately require an organization to use some or all of its practices.

Operational implication

Record the source of each mandatory duty and the assurance route; do not label voluntary guidance as universally binding.

Comparison row 8

Overlap and reuse

ISO/IEC 27036

ISO/IEC 27036 can supply reusable supplier records, contract evidence, review outputs, and relationship decisions.

NIST SP 800-161

NIST SP 800-161 can reuse some of that evidence when the same artifact also supports a supply-chain risk decision.

Operational implication

Reuse evidence only where the same owner, scope, and purpose apply; otherwise keep the records separate.

Comparison row 9

Practical decision rule

ISO/IEC 27036

Use ISO/IEC 27036 when the main work is defining and managing the supplier relationship.

NIST SP 800-161

Use NIST SP 800-161 when the main work is building the supply-chain risk management program around that relationship.

Operational implication

If you need both, use ISO/IEC 27036-2 for applicable relationship requirements, the relevant guidance parts for context, and NIST SP 800-161 to organize supporting activities.

Practical decision rule

How should teams use ISO/IEC 27036 with NIST SP 800-161?

  • If the main question is how to govern the supplier relationship, start with ISO/IEC 27036.
  • If the main question is how to assess and manage supply-chain risk across the organization, start with NIST SP 800-161 Rev. 1 Update 1.
  • If both apply, use ISO/IEC 27036-2 for applicable supplier-relationship requirements, the relevant guidance parts for context, and NIST SP 800-161 Rev. 1 Update 1 for activities and control mapping.
Section 1

How do ISO/IEC 27036 and NIST SP 800-161 differ?

ISO/IEC 27036 starts from an acquirer-supplier relationship and its lifecycle. Part 2 contains requirements for planning, supplier selection, agreement, management, and termination. Part 3 adds guidance for multi-layer hardware, software, and service supply chains, and Part 4 addresses cloud customer and provider relationships.

NIST SP 800-161 Rev. 1 Update 1 starts from as an enterprise risk discipline. It organizes decisions across enterprise, mission and business process, and operational levels; integrates C-SCRM with acquisition and system development lifecycles; and provides controls, implementation guidance, and templates. Its audience extends beyond supplier managers to risk, acquisition, security, privacy, engineering, operations, legal, and executive roles.

The ISO comparison uses the 2021, 2022, 2023, and 2016 editions of Parts 1 through 4. The NIST comparison uses Rev. 1 Update 1, which includes updates through November 1, 2024 and supersedes the May 2022 Rev. 1 publication. Recheck the mapping when either source is revised.

  • Relationship deliverable: use ISO/IEC 27036-2 to define requirements, responsibilities, agreement terms, operating assurance, change, and termination.
  • Program deliverable: use NIST SP 800-161 Rev. 1 Update 1 for strategy, policy, implementation plans, multilevel risk decisions, lifecycle integration, and tailored controls.
  • Combined use: map evidence at the requirement or control level, record partial and missing coverage, and keep the owner, scope, period, and decision purpose attached.
Section 2

How can teams coordinate the two approaches?

Build one crosswalk with separate columns for the business objective, ISO/IEC 27036 requirement or guidance, NIST outcome or control, responsible owner, implementation, evidence, gap, and review trigger. Map only after scoping the ISO relationship and the NIST enterprise, mission or business process, and system context.

Keep legal and contractual duties separate. ISO/IEC 27036-2 uses requirements language for organizations that adopt it, while the other ISO parts and NIST SP 800-161 provide guidance. Neither publication creates a universal breach-notification deadline or becomes binding in every use. NIST states that nongovernmental organizations may use SP 800-161 voluntarily; a law, regulation, government mandate, acquisition rule, customer commitment, or contract may independently require selected practices.

  • Use ISO/IEC 27036 evidence for the specific relationship: scope, assessment, selection, agreement, assurance, changes, incidents, and exit.
  • Use NIST evidence for the program and risk level: strategy, policy, plans, roles, risk assessments, control tailoring, acquisition integration, system decisions, monitoring, and risk responses.
  • Where one artifact supports both, record the two mapped claims instead of marking the frameworks equivalent.
Section 3

Which evidence can be reused without claiming equivalence?

A supplier risk assessment can support ISO planning and selection and a NIST system-level risk assessment, but only if its scope, method, threats, dependencies, and risk criteria satisfy both uses. A contract can implement selected requirements and controls, but it does not prove that the supplier performs them.

An assurance report, component inventory, vulnerability record, incident exercise, continuity test, or monitoring result can be reused when the covered entity, product or service, location, period, control, and reviewer conclusion match both mapped claims.

Enterprise strategy, risk appetite, governance, and multilevel roles are NIST program evidence that a relationship contract usually cannot supply. Detailed mutual agreement, supplier-selection, and termination records are ISO relationship evidence that a high-level C-SCRM policy usually cannot supply. NIST also warns acquirers against a generic requirement to comply with all SP 800-161 controls: select controls for the specific product or service and write the needed contractual language.

  • Keep one evidence object and multiple traceable mappings when the same artifact supports both publications.
  • Mark a mapping as full, partial, not applicable with rationale, or missing; do not infer coverage from similar wording.
  • Version the crosswalk when either publication, the relationship, the system, or the implementation changes.
ISO/IEC 27036 vs NIST SP 800-161 next step

Put ISO/IEC 27036 vs NIST SP 800-161 into practice

Capture owners, evidence, decisions, and review dates in one workflow record so supplier security controls and escalation points stay auditable over time.

Section 4

When should the mapping be reviewed?

Review the mapping when the relationship scope, supplier, upstream dependency, system architecture, mission or business impact, control implementation, law, contract, or source publication changes. Also review it after a serious incident, material finding, failed control, renewal, or termination decision.

Use the relationship review cadence for ISO/IEC 27036 records and the applicable enterprise, mission or business process, and operational risk cadences for NIST records. Synchronize shared evidence dates, but do not force every decision into one cycle.

At termination, close the ISO relationship actions and update the NIST risk picture for replacement, transition, residual dependencies, retained information, and any new supplier or system exposure.

  • Assign the trigger and decision owner in advance.
  • Test high-impact continuity and exit assumptions before they are needed.
  • Close the record only when exit actions and remaining exceptions are documented.
Primary sources

References and citations

iso.org
Referenced sections
  • ISO overview source supporting the ISO/IEC 27036 side of the comparison against NIST SP 800-161.
"overview of the guidance intended to assist organizations"
iso.org
Referenced sections
  • Part 2 is the requirements source for the supplier and acquirer relationship lifecycle claims in this comparison.
"fundamental information security requirements for defining, implementing, operating, monitoring, reviewing, maintaining and improving supplier and acquirer relationships"
nvlpubs.nist.gov
Referenced sections
  • The official NIST publication supplies the C-SCRM scope, multilevel risk model, practices, controls, and implementation guidance used in this comparison.
"provides guidance to organizations on identifying, assessing, and mitigating cybersecurity risks throughout the supply chain at all levels of their organizations"
Related guides

Explore more topics

ISO/IEC 27036 Assurance Evidence FAQ
Collect evidence that answers a defined relationship-risk or agreement question and matches the product or service, period, location, controls, and dependencies in scope. A certificate, audit report, questionnaire, or attestation is an input, not automatic proof.
ISO/IEC 27036 Cloud Suppliers FAQ
Treat cloud as a supplier relationship with cloud service customer and provider perspectives. Apply Part 2 relationship requirements and Part 4 cloud guidance, then document how responsibility changes with the service and deployment model, configuration, data, interfaces, and nested cloud services.
ISO/IEC 27036 Contract Controls FAQ
Include controls selected from the relationship risk treatment and responsibilities, not a generic clause library. The agreement should make scope, performance, evidence, communication, exceptions, change, incident coordination, continuity, and exit reviewable by both parties.
ISO/IEC 27036 Contract Security Clauses Guide
Build ISO/IEC 27036-aligned supplier security clauses from relationship risk, responsibilities, assurance, change, incidents, and exit.
ISO/IEC 27036 Fourth Parties FAQ
Use the direct supplier relationship to obtain proportionate visibility and assurance over upstream dependencies that can materially affect security or delivery. ISO/IEC 27036 describes multi-layer supply chains; it does not require the same questionnaire or direct audit right for every remote tier.
ISO/IEC 27036 ICT Supply Chain Lifecycle Guide
Apply ISO/IEC 27036 across ICT supply-chain planning, acquisition, delivery, operation, change, and disposal.
ISO/IEC 27036 Indirect and Fourth Party Suppliers Guide
Manage indirect supplier dependencies under ISO/IEC 27036 using risk-based visibility, flow-down expectations, monitoring, and contingency planning.
ISO/IEC 27036 Onboarding and Offboarding Workflow
Run ISO/IEC 27036 supplier onboarding and offboarding with approval gates, evidence, access control, continuity, and verified closure.
ISO/IEC 27036 Risk Tiers FAQ
No fixed low, medium, or high tier model is prescribed by ISO/IEC 27036. Organizations can use tiers to scale due diligence, agreement terms, assurance, monitoring, approvals, and exit planning, but the criteria and decisions must reflect their own context and risk appetite.
ISO/IEC 27036 Supplier Assurance Framework Guide
Design risk-based ISO/IEC 27036 supplier assurance with defined evidence scope, monitoring, findings, and reassessment.
ISO/IEC 27036 Supplier Incidents FAQ
Agree incident contacts, triggers, information sharing, investigation support, evidence preservation, containment and recovery coordination, corrective action, and review before an incident occurs. ISO/IEC 27036 does not set one universal notification deadline; applicable law, regulation, policy, or contract supplies mandatory timing.
ISO/IEC 27036 Supplier Monitoring Evidence Workflow
Build ISO/IEC 27036 supplier monitoring that turns agreed measures, assurance, incidents, changes, and findings into decisions.
ISO/IEC 27036 Supplier Monitoring FAQ
ISO/IEC 27036 does not prescribe one universal monitoring interval. Set scheduled and event-driven reviews according to risk, agreement terms, service criticality, evidence availability, and the speed at which the relationship can change.
ISO/IEC 27036 Supplier Relationship Types Guide
Classify ISO/IEC 27036 relationships by product, service, ICT supply chain, and cloud context to select proportionate controls.
ISO/IEC 27036 Supplier Security FAQ
Plain-language answers about ISO/IEC 27036 scope, parts, roles, agreements, assurance, monitoring, incidents, indirect suppliers, cloud services, and exit.
ISO/IEC 27036 Termination and Offboarding FAQ
Plan termination before the relationship starts. Coordinate continuity and transition, revoke physical and logical access, rotate shared secrets, disable integrations, recover assets, return or delete information subject to retention duties, preserve required records, and verify surviving obligations.
ISO/IEC 27036 Third Party Risk Checklist
Use an ISO/IEC 27036 supplier-risk checklist across scope, assessment, agreement, operation, change, incidents, and termination.
Using the ISO/IEC 27036 Supplier Relationship Series
Understand how to apply the four-part ISO/IEC 27036 series without treating it as a law or standalone certification.