Compare NIST SP 800-161 Rev. 1 and ISO/IEC 27036 supplier relationships with side-by-side scope, owner, trigger, evidence, cadence, assurance, and decision-rule rows.
SP 800-161 provides an enterprise C-SCRM model; ISO/IEC 27036 addresses supplier relationships through a multipart standard. Select applicable requirements and guidance from each rather than claiming automatic equivalence.
Use NIST SP 800-161 Rev. 1 to organize cybersecurity supply chain risk management (C-SCRM) across the enterprise; use and the rest of the ISO/IEC 27036 series to define and manage information security in a specific acquirer-supplier relationship. The acquirer procures or obtains the product or service from the supplier. NIST Rev. 1 was published in May 2022 and Update 1 includes changes through 1 November 2024; ISO/IEC 27036-2:2022 is the current second edition of the requirements document. The two can share evidence, but they have different structures and neither creates automatic conformity with the other.
NIST SP 800-161 Rev. 1 is tailorable C-SCRM guidance structured around three risk-management levels, acquisition and system life cycles, SP 800-53 controls, and practical program templates.
Second framework
ISO/IEC 27036 supplier relationships
ISO/IEC 27036 is a multipart supplier-relationship series: Part 2:2022 contains supplier and acquirer relationship requirements, while Parts 1, 3, and 4 provide concepts or guidance. The series is not a stand-alone management-system certification standard.
SP 800-161 provides C-SCRM practices across enterprise, mission, and operational levels. Use NIST SP 800-161 Rev. 1 to define the in-scope system, product, service, supplier, release, incident, or governance process before mapping evidence.
ISO/IEC 27036 addresses information security in acquirer-supplier relationships. Part 2:2022 specifies requirements; Part 1:2021 explains concepts; Part 3:2023 covers hardware, software, and services supply-chain guidance; Part 4:2016 covers cloud-service relationships.
Record the NIST risk-management level and system boundary, then record the ISO part, edition, acquirer, supplier, product or service, and relationship stage. These scope statements are related but not interchangeable.
SP 800-161 distributes responsibility across enterprise leadership and risk, mission/business owners, acquisition, legal, engineering, security, privacy, system owners, operations, and assessors at three connected levels.
ISO/IEC 27036 centers the acquirer and supplier relationship. Governance, business, procurement, contract, information-security, service, and relationship owners cooperate through establishment, operation, monitoring, change, and termination.
A shared team can support both sides, but the accountable owner should be named separately for NIST SP 800-161 Rev. 1 and ISO/IEC 27036 supplier relationships.
Use SP 800-161 when an organization adopts C-SCRM for enterprise risk, mission or business processes, systems, products, services, acquisition, or supplier assurance. The adopting law, policy, contract, or internal decision determines whether its use is mandatory.
Use the relevant ISO/IEC 27036 part when establishing or managing an acquirer-supplier relationship whose information security risks need requirements, treatment, agreement, monitoring, transition, or termination controls.
Reassess the mapping when the system boundary, product or service, supplier, subcontracting, risk, relationship stage, agreement, or applicable edition changes.
SP 800-161 guides the organization to establish C-SCRM strategy, policy, plans, assessments, acquisition practices, tailored controls, monitoring, and risk response across three organizational levels.
requires activities for relationship planning, supplier selection, the supplier relationship agreement, and relationship management. Agreement work covers roles, security requirements, service measures, subcontracting, transition, changes, incidents, monitoring, corrective action, termination, and asset handling.
Map NIST program actions to the applicable process. Keep ISO requirements that have no complete NIST counterpart as separate contract or relationship-management actions.
ISO/IEC 27036 evidence includes the relationship plan, selection criteria, tender and response records, risk assessment and treatment plan, signed agreement, roles, transition and termination plans, monitoring and enforcement plan, assurance reports, corrective actions, incident and change records, and asset return or destruction evidence.
For each mapped claim, record the source clause, actor, product or service, artifact, owner, review date, and whether the evidence is complete, partial, or missing.
NIST SP 800-161 Rev. 1 treats C-SCRM as a living program: strategy, policies, plans, controls, and evidence should be reviewed and refreshed periodically, and monitoring should continue across the life cycle.
does not impose one universal calendar. The acquirer and supplier set monitoring frequency, reporting, review, transition, incident, change, corrective-action, and termination timing according to the relationship, agreement, risk, and applicable legal or regulatory duties.
Keep the NIST program review cadence separate from the relationship's contractual and risk-based clocks. Record the trigger, owner, due date, evidence, and source for each.
NIST does not certify SP 800-161 adoption. Assurance comes from the adopting context, such as governance review, system authorization, contract assessment, customer review, internal audit, control testing, or monitoring.
ISO/IEC 27036 is a voluntary multipart standard, not a law or stand-alone certifiable management-system standard. Part 2 contains relationship requirements, but applicable assurance and consequences usually come through the acquirer-supplier agreement, assessment rights, customer expectations, or a broader management system.
Do not claim 'ISO 27036 certified.' State the actual assessment, contractual, audit, or management-system context and show which relationship practices were evaluated.
ISO/IEC 27036 can reuse those artifacts when they address the same acquirer, supplier, product or service, risk, relationship stage, and requirement. The ISO process outputs and bilateral agreement details still need direct evidence.
Choose NIST SP 800-161 Rev. 1 to design and govern the enterprise C-SCRM program, including acquisition, controls, supplier assurance, monitoring, and response.
Choose the relevant ISO/IEC 27036 part to define the acquirer-supplier relationship, especially selection, agreement content, operating responsibilities, assurance, transition, and termination.
When both apply, keep NIST as the program layer and ISO/IEC 27036 as the relationship layer. Approve the map only after every cited requirement has complete, partial, or missing evidence recorded.
SP 800-161 provides C-SCRM practices across enterprise, mission, and operational levels. Use NIST SP 800-161 Rev. 1 to define the in-scope system, product, service, supplier, release, incident, or governance process before mapping evidence.
ISO/IEC 27036 addresses information security in acquirer-supplier relationships. Part 2:2022 specifies requirements; Part 1:2021 explains concepts; Part 3:2023 covers hardware, software, and services supply-chain guidance; Part 4:2016 covers cloud-service relationships.
Record the NIST risk-management level and system boundary, then record the ISO part, edition, acquirer, supplier, product or service, and relationship stage. These scope statements are related but not interchangeable.
SP 800-161 distributes responsibility across enterprise leadership and risk, mission/business owners, acquisition, legal, engineering, security, privacy, system owners, operations, and assessors at three connected levels.
ISO/IEC 27036 centers the acquirer and supplier relationship. Governance, business, procurement, contract, information-security, service, and relationship owners cooperate through establishment, operation, monitoring, change, and termination.
A shared team can support both sides, but the accountable owner should be named separately for NIST SP 800-161 Rev. 1 and ISO/IEC 27036 supplier relationships.
Use SP 800-161 when an organization adopts C-SCRM for enterprise risk, mission or business processes, systems, products, services, acquisition, or supplier assurance. The adopting law, policy, contract, or internal decision determines whether its use is mandatory.
Use the relevant ISO/IEC 27036 part when establishing or managing an acquirer-supplier relationship whose information security risks need requirements, treatment, agreement, monitoring, transition, or termination controls.
Reassess the mapping when the system boundary, product or service, supplier, subcontracting, risk, relationship stage, agreement, or applicable edition changes.
SP 800-161 guides the organization to establish C-SCRM strategy, policy, plans, assessments, acquisition practices, tailored controls, monitoring, and risk response across three organizational levels.
requires activities for relationship planning, supplier selection, the supplier relationship agreement, and relationship management. Agreement work covers roles, security requirements, service measures, subcontracting, transition, changes, incidents, monitoring, corrective action, termination, and asset handling.
Map NIST program actions to the applicable process. Keep ISO requirements that have no complete NIST counterpart as separate contract or relationship-management actions.
ISO/IEC 27036 evidence includes the relationship plan, selection criteria, tender and response records, risk assessment and treatment plan, signed agreement, roles, transition and termination plans, monitoring and enforcement plan, assurance reports, corrective actions, incident and change records, and asset return or destruction evidence.
For each mapped claim, record the source clause, actor, product or service, artifact, owner, review date, and whether the evidence is complete, partial, or missing.
NIST SP 800-161 Rev. 1 treats C-SCRM as a living program: strategy, policies, plans, controls, and evidence should be reviewed and refreshed periodically, and monitoring should continue across the life cycle.
does not impose one universal calendar. The acquirer and supplier set monitoring frequency, reporting, review, transition, incident, change, corrective-action, and termination timing according to the relationship, agreement, risk, and applicable legal or regulatory duties.
Keep the NIST program review cadence separate from the relationship's contractual and risk-based clocks. Record the trigger, owner, due date, evidence, and source for each.
NIST does not certify SP 800-161 adoption. Assurance comes from the adopting context, such as governance review, system authorization, contract assessment, customer review, internal audit, control testing, or monitoring.
ISO/IEC 27036 is a voluntary multipart standard, not a law or stand-alone certifiable management-system standard. Part 2 contains relationship requirements, but applicable assurance and consequences usually come through the acquirer-supplier agreement, assessment rights, customer expectations, or a broader management system.
Do not claim 'ISO 27036 certified.' State the actual assessment, contractual, audit, or management-system context and show which relationship practices were evaluated.
ISO/IEC 27036 can reuse those artifacts when they address the same acquirer, supplier, product or service, risk, relationship stage, and requirement. The ISO process outputs and bilateral agreement details still need direct evidence.
Choose NIST SP 800-161 Rev. 1 to design and govern the enterprise C-SCRM program, including acquisition, controls, supplier assurance, monitoring, and response.
Choose the relevant ISO/IEC 27036 part to define the acquirer-supplier relationship, especially selection, agreement content, operating responsibilities, assurance, transition, and termination.
When both apply, keep NIST as the program layer and ISO/IEC 27036 as the relationship layer. Approve the map only after every cited requirement has complete, partial, or missing evidence recorded.
When should teams use NIST SP 800-161 Rev. 1 first versus ISO/IEC 27036 supplier relationships first?
Use NIST SP 800-161 Rev. 1 first to design or improve the enterprise C-SCRM program, acquisition controls, supplier assurance, monitoring, and response.
Use :2022 first to define requirements, the agreement, responsibilities, monitoring, transition, or termination for a specific acquirer-supplier relationship.
Use both when the relationship sits inside the C-SCRM program. State which ISO part and edition applies, then record the requirements that remain unique to each side.
Which document should drive the supplier decision?
Start with SP 800-161 Rev. 1 Update 1 when the organization needs a C-SCRM strategy, policy, plan, risk assessment, control selection, acquisition practice, or monitoring process across enterprise, mission or business-process, and operational levels.
Start with :2022 when an acquirer and supplier need requirements for planning, selecting, agreeing, operating, monitoring, changing, or terminating a supplier relationship. Part 1:2021 supplies the concepts; Part 3:2023 gives guidance for hardware, software, and services supply-chain security; Part 4:2016 gives cloud-service guidance.
Part 2 applies to organizations of any type or size and to procurement or supply such as manufacturing, business-process services, software or hardware components, knowledge services, build-operate-transfer arrangements, and cloud services. It expects foundational business, risk, operational, human-resource, and information-security processes; it does not supply a universal risk threshold or contract cadence.
contains requirements, while Parts 1, 3, and 4 have different purposes. Cite the part, edition, clause, actor, and relationship stage. A general reference to "ISO 27036" is too imprecise for an audit or contract decision.
Enterprise risk and security: set the NIST C-SCRM strategy, risk appetite, criticality method, system boundary, control baseline, monitoring, and response.
Acquirer and procurement: document supplier selection criteria, security requirements, due diligence, audit and assurance terms, subcontractor conditions, service levels, change and incident procedures, and termination requirements.
Supplier: assess the proposed supply, identify treatment work, accept or negotiate security requirements, assign responsible personnel, and maintain the agreed evidence.
Do not claim "ISO/IEC 27036 certified." The series is not a stand-alone management-system certification standard; state the actual contract, assessment, audit, or broader certification context.
Official ISO page for supplier and acquirer relationship requirements.
"fundamental information security requirements for defining, implementing, operating, monitoring, reviewing, maintaining and improving supplier and acquirer relationships"
Primary NIST source for the C-SCRM side of this comparison, including supply-chain risk practices, risk-management levels, and supplier assurance evidence.
"identifying, assessing, and mitigating cybersecurity risks"