GuideGlobalISO/IEC 27036

ISO/IEC 27036 Supplier Assurance Framework

Match assurance depth to risk and verify that evidence covers the supplied product or service, period, locations, controls, and dependencies that matter.

Use ISO/IEC 27036-2:2022 for relationship requirements, Part 1 for concepts, and Part 3 for hardware, software, and services supply-chain guidance. The organization defines assurance depth from risk; ISO/IEC 27036 does not prescribe fixed supplier tiers.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

should answer one decision: does current evidence show that this supplier can meet the security requirements for this product or service, within the accepted risk? Define the requirement and evidence scope before choosing a questionnaire, certificate, audit, test, attestation, or performance report.

Section 1

What assurance question must the evidence answer?

Tie each assurance request to a requirement, risk, and decision. State the product or service, relevant assets, legal entities, locations, systems, personnel, information, subcontractors, and period that the conclusion must cover. Then define the acceptance criterion, evidence source, reviewer, review frequency, change trigger, and response to a gap.

Both parties can create risk for the other. A supplier may handle acquirer information or provide vulnerable components; an acquirer may gain access to sensitive supplier information while inspecting production or service delivery. Scope assurance to the actual direction of access, control, and dependency.

  • Question: which requirement or risk is being tested, and what decision will the result support?
  • Coverage: which entity, product or service, system, location, period, and supply-chain dependency must the evidence include?
  • Conclusion: met, partly met, not met, or not verified, with limitations and the next action stated.
Section 2

How should assurance depth follow relationship risk?

Use the organization's risk method to categorize the relationship, then select the assessment type, level of detail, and frequency. Consider criticality, information sensitivity, privileged or physical access, technology exposure, business dependency, subcontractors, service location and jurisdiction, supplier history, incident history, and the supplier's ability to demonstrate security capability.

A practical model can use internally defined tiers, but label them as organizational categories rather than ISO/IEC 27036 tiers. A lower-risk relationship may need a scoped questionnaire and agreement review. Higher exposure may justify independent reports, technical tests, interviews, audit rights, on-site or remote audit, more frequent reporting, and deeper review of subcontractors. The right combination depends on the risk and what the agreement permits.

  • Before selection: use evidence to test security capability, acceptance of requirements, audit and assurance terms, transition readiness, and subcontractor transparency.
  • Before go-live: confirm that evidence gaps have treatment, contractual conditions, compensating controls, or an authorized risk decision.
  • During operation: use agreed measures, reports, audits, and event-driven reviews to check whether the original assurance conclusion still holds.
Section 3

How should reports, certificates, tests, and findings be evaluated?

Evaluate evidence against the question it is meant to answer. A questionnaire is management's representation unless corroborated. A certificate confirms conformity only for its named standard, certified scope, entities, sites, and validity period. An independent assurance report is limited by its control criteria, system description, period, testing, exceptions, and any excluded subservice organizations. A penetration test covers the tested targets, methods, and date, not every control in the relationship.

For each item, record provenance, version, period, scope, reviewer competence or independence where relevant, limitations, exceptions, and follow-up. Compare the evidence with the agreement and risk treatment plan. Evidence can support a conclusion without covering the entire relationship; mark uncovered requirements as not verified rather than treating the document title or logo as proof.

Example: if a supplier's ISO/IEC 27001 certificate covers its corporate ISMS but excludes the hosting location or managed service being acquired, the certificate can still support covered governance controls. It does not verify the excluded service. Request scoped evidence, add another control, restrict use, choose another supplier, or send the remaining risk to the authorized owner.

  • Certificate: check issuing body, standard and edition, certified entity, scope statement, sites, status, dates, and exclusions.
  • Audit or assurance report: check independence, criteria, period, system boundary, sample and test coverage, exceptions, management response, and downstream providers.
  • Technical test: check target inventory, environment, method, date, severity method, retest status, and whether untested assets remain in scope.
  • Finding: link the gap to the affected requirement and risk, then record interim protection, action, owner, due date, risk approval, and closure evidence.
Section 4

When should assurance be refreshed or escalated?

Refresh assurance on the agreed schedule and when the evidence or risk changes. Triggers include a security incident, audit nonconformity, failed measure, material change to scope or architecture, new service location or subcontractor, ownership or financial change, loss or scope reduction of relied-on certification, changed continuity capability, renewal, or a new legal, regulatory, or contractual requirement.

A gap does not by itself establish breach, certification failure, or legal noncompliance. Assess its impact on the specific requirement and relationship. The response can be better evidence, increased monitoring, an interim control, corrective action, an agreement update, residual-risk acceptance by the authorized owner, restriction of the service, or termination.

  • Refresh: obtain current evidence and repeat the scope and acceptance review.
  • Escalate: state what is unverified or failed, the affected risk, immediate protection, decision owner, and response deadline.
  • Close: retain the evidence that the acceptance condition was met or the authorized decision that records the accepted residual risk and next review.
Primary sources

References and citations

iso.org
Referenced sections
  • Clauses 6.3.4 and 7.4 require periodic and significant-change risk review, impact assessment for changes or audit nonconformities, corrective actions, and approved agreement updates where needed.
iso.org
Referenced sections
  • Part 3 supports ongoing supplier and product or service monitoring, risk-based compliance audits, documented results, and regular assurance reviews.
Related guides

Explore more topics

ISO/IEC 27036 Assurance Evidence FAQ
Collect evidence that answers a defined relationship-risk or agreement question and matches the product or service, period, location, controls, and dependencies in scope. A certificate, audit report, questionnaire, or attestation is an input, not automatic proof.
ISO/IEC 27036 Cloud Suppliers FAQ
Treat cloud as a supplier relationship with cloud service customer and provider perspectives. Apply Part 2 relationship requirements and Part 4 cloud guidance, then document how responsibility changes with the service and deployment model, configuration, data, interfaces, and nested cloud services.
ISO/IEC 27036 Contract Controls FAQ
Include controls selected from the relationship risk treatment and responsibilities, not a generic clause library. The agreement should make scope, performance, evidence, communication, exceptions, change, incident coordination, continuity, and exit reviewable by both parties.
ISO/IEC 27036 Contract Security Clauses Guide
Build ISO/IEC 27036-aligned supplier security clauses from relationship risk, responsibilities, assurance, change, incidents, and exit.
ISO/IEC 27036 Fourth Parties FAQ
Use the direct supplier relationship to obtain proportionate visibility and assurance over upstream dependencies that can materially affect security or delivery. ISO/IEC 27036 describes multi-layer supply chains; it does not require the same questionnaire or direct audit right for every remote tier.
ISO/IEC 27036 ICT Supply Chain Lifecycle Guide
Apply ISO/IEC 27036 across ICT supply-chain planning, acquisition, delivery, operation, change, and disposal.
ISO/IEC 27036 Indirect and Fourth Party Suppliers Guide
Manage indirect supplier dependencies under ISO/IEC 27036 using risk-based visibility, flow-down expectations, monitoring, and contingency planning.
ISO/IEC 27036 Onboarding and Offboarding Workflow
Run ISO/IEC 27036 supplier onboarding and offboarding with approval gates, evidence, access control, continuity, and verified closure.
ISO/IEC 27036 Risk Tiers FAQ
No fixed low, medium, or high tier model is prescribed by ISO/IEC 27036. Organizations can use tiers to scale due diligence, agreement terms, assurance, monitoring, approvals, and exit planning, but the criteria and decisions must reflect their own context and risk appetite.
ISO/IEC 27036 Supplier Incidents FAQ
Agree incident contacts, triggers, information sharing, investigation support, evidence preservation, containment and recovery coordination, corrective action, and review before an incident occurs. ISO/IEC 27036 does not set one universal notification deadline; applicable law, regulation, policy, or contract supplies mandatory timing.
ISO/IEC 27036 Supplier Monitoring Evidence Workflow
Build ISO/IEC 27036 supplier monitoring that turns agreed measures, assurance, incidents, changes, and findings into decisions.
ISO/IEC 27036 Supplier Monitoring FAQ
ISO/IEC 27036 does not prescribe one universal monitoring interval. Set scheduled and event-driven reviews according to risk, agreement terms, service criticality, evidence availability, and the speed at which the relationship can change.
ISO/IEC 27036 Supplier Relationship Types Guide
Classify ISO/IEC 27036 relationships by product, service, ICT supply chain, and cloud context to select proportionate controls.
ISO/IEC 27036 Supplier Security FAQ
Plain-language answers about ISO/IEC 27036 scope, parts, roles, agreements, assurance, monitoring, incidents, indirect suppliers, cloud services, and exit.
ISO/IEC 27036 Termination and Offboarding FAQ
Plan termination before the relationship starts. Coordinate continuity and transition, revoke physical and logical access, rotate shared secrets, disable integrations, recover assets, return or delete information subject to retention duties, preserve required records, and verify surviving obligations.
ISO/IEC 27036 Third Party Risk Checklist
Use an ISO/IEC 27036 supplier-risk checklist across scope, assessment, agreement, operation, change, incidents, and termination.
ISO/IEC 27036 vs NIST SP 800-161 Comparison
Compare ISO/IEC 27036 supplier-relationship security with NIST SP 800-161 Rev. 1 cyber supply-chain risk management.
Using the ISO/IEC 27036 Supplier Relationship Series
Understand how to apply the four-part ISO/IEC 27036 series without treating it as a law or standalone certification.