ISO/IEC 27036-2:2022 applies to organizations of any type or size and to procurement and supply of products and services, including manufacturing, business-process procurement, software and hardware components, build-operate-transfer arrangements, and cloud services. It is a voluntary international standard unless law, regulation, policy, customer terms, or a contract makes selected requirements binding. The checklist does not replace those separate duties.
The assessment must describe the actual relationship before it scores risk. Identify the legal entities and accountable owners, the product or service, intended use, information and systems involved, access method and privilege, processing and support locations, business criticality, recovery need, planned term, and feasible alternatives.
Assess risks to both parties. ISO/IEC 27036-2 specifically includes business dependence, underlying technology, subcontractors, past performance, contractual arrangements, and the supplier's ability to demonstrate information-security capability. Add product provenance, component and update dependencies, and end-of-support exposure for an ICT supply chain.