Side-by-sideGLOBALNIST SP 800-161 Rev. 1

NIST SP 800-161 Rev. 1 vs ISO/IEC 27036 supplier relationships: practical side-by-side comparison

Compare NIST SP 800-161 Rev. 1 and ISO/IEC 27036 supplier relationships with side-by-side scope, owner, trigger, evidence, cadence, assurance, and decision-rule rows.

SP 800-161 provides an enterprise C-SCRM model; ISO/IEC 27036 addresses supplier relationships through a multipart standard. Select applicable requirements and guidance from each rather than claiming automatic equivalence.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
1

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use NIST SP 800-161 Rev. 1 to organize cybersecurity supply chain risk management (C-SCRM) across the enterprise; use and the rest of the ISO/IEC 27036 series to define and manage information security in a specific acquirer-supplier relationship. The acquirer procures or obtains the product or service from the supplier. NIST Rev. 1 was published in May 2022 and Update 1 includes changes through 1 November 2024; ISO/IEC 27036-2:2022 is the current second edition of the requirements document. The two can share evidence, but they have different structures and neither creates automatic conformity with the other.

Side-by-side comparison

NIST SP 800-161 Rev. 1 vs ISO/IEC 27036 supplier relationships: practical side-by-side comparison

Compare NIST SP 800-161 Rev. 1 and ISO/IEC 27036 supplier relationships with side-by-side scope, owner, trigger, evidence, cadence, assurance, and decision-rule rows.

Review all sources
First framework
NIST SP 800-161 Rev. 1

NIST SP 800-161 Rev. 1 is tailorable C-SCRM guidance structured around three risk-management levels, acquisition and system life cycles, SP 800-53 controls, and practical program templates.

Second framework
ISO/IEC 27036 supplier relationships

ISO/IEC 27036 is a multipart supplier-relationship series: Part 2:2022 contains supplier and acquirer relationship requirements, while Parts 1, 3, and 4 provide concepts or guidance. The series is not a stand-alone management-system certification standard.

Comparison row 1

Scope and covered activity

NIST SP 800-161 Rev. 1

SP 800-161 provides C-SCRM practices across enterprise, mission, and operational levels. Use NIST SP 800-161 Rev. 1 to define the in-scope system, product, service, supplier, release, incident, or governance process before mapping evidence.

ISO/IEC 27036 supplier relationships

ISO/IEC 27036 addresses information security in acquirer-supplier relationships. Part 2:2022 specifies requirements; Part 1:2021 explains concepts; Part 3:2023 covers hardware, software, and services supply-chain guidance; Part 4:2016 covers cloud-service relationships.

Operational implication

Record the NIST risk-management level and system boundary, then record the ISO part, edition, acquirer, supplier, product or service, and relationship stage. These scope statements are related but not interchangeable.

Comparison row 2

Who must act

NIST SP 800-161 Rev. 1

SP 800-161 distributes responsibility across enterprise leadership and risk, mission/business owners, acquisition, legal, engineering, security, privacy, system owners, operations, and assessors at three connected levels.

ISO/IEC 27036 supplier relationships

ISO/IEC 27036 centers the acquirer and supplier relationship. Governance, business, procurement, contract, information-security, service, and relationship owners cooperate through establishment, operation, monitoring, change, and termination.

Operational implication

A shared team can support both sides, but the accountable owner should be named separately for NIST SP 800-161 Rev. 1 and ISO/IEC 27036 supplier relationships.

Comparison row 3

Trigger or threshold

NIST SP 800-161 Rev. 1

Use SP 800-161 when an organization adopts C-SCRM for enterprise risk, mission or business processes, systems, products, services, acquisition, or supplier assurance. The adopting law, policy, contract, or internal decision determines whether its use is mandatory.

ISO/IEC 27036 supplier relationships

Use the relevant ISO/IEC 27036 part when establishing or managing an acquirer-supplier relationship whose information security risks need requirements, treatment, agreement, monitoring, transition, or termination controls.

Operational implication

Reassess the mapping when the system boundary, product or service, supplier, subcontracting, risk, relationship stage, agreement, or applicable edition changes.

Comparison row 4

Core obligations

NIST SP 800-161 Rev. 1

SP 800-161 guides the organization to establish C-SCRM strategy, policy, plans, assessments, acquisition practices, tailored controls, monitoring, and risk response across three organizational levels.

ISO/IEC 27036 supplier relationships

requires activities for relationship planning, supplier selection, the supplier relationship agreement, and relationship management. Agreement work covers roles, security requirements, service measures, subcontracting, transition, changes, incidents, monitoring, corrective action, termination, and asset handling.

Operational implication

Map NIST program actions to the applicable process. Keep ISO requirements that have no complete NIST counterpart as separate contract or relationship-management actions.

Comparison row 5

Evidence and records

NIST SP 800-161 Rev. 1

NIST evidence includes C-SCRM strategy and policy, plans, risk assessments, criticality and supplier records, selected controls, acquisition records, contract clauses, assessment results, monitoring, incidents, risk responses, metrics, and plans of action.

ISO/IEC 27036 supplier relationships

ISO/IEC 27036 evidence includes the relationship plan, selection criteria, tender and response records, risk assessment and treatment plan, signed agreement, roles, transition and termination plans, monitoring and enforcement plan, assurance reports, corrective actions, incident and change records, and asset return or destruction evidence.

Operational implication

For each mapped claim, record the source clause, actor, product or service, artifact, owner, review date, and whether the evidence is complete, partial, or missing.

Comparison row 6

Timing and cadence

NIST SP 800-161 Rev. 1

NIST SP 800-161 Rev. 1 treats C-SCRM as a living program: strategy, policies, plans, controls, and evidence should be reviewed and refreshed periodically, and monitoring should continue across the life cycle.

ISO/IEC 27036 supplier relationships

does not impose one universal calendar. The acquirer and supplier set monitoring frequency, reporting, review, transition, incident, change, corrective-action, and termination timing according to the relationship, agreement, risk, and applicable legal or regulatory duties.

Operational implication

Keep the NIST program review cadence separate from the relationship's contractual and risk-based clocks. Record the trigger, owner, due date, evidence, and source for each.

Comparison row 7

Enforcement or assurance route

NIST SP 800-161 Rev. 1

NIST does not certify SP 800-161 adoption. Assurance comes from the adopting context, such as governance review, system authorization, contract assessment, customer review, internal audit, control testing, or monitoring.

ISO/IEC 27036 supplier relationships

ISO/IEC 27036 is a voluntary multipart standard, not a law or stand-alone certifiable management-system standard. Part 2 contains relationship requirements, but applicable assurance and consequences usually come through the acquirer-supplier agreement, assessment rights, customer expectations, or a broader management system.

Operational implication

Do not claim 'ISO 27036 certified.' State the actual assessment, contractual, audit, or management-system context and show which relationship practices were evaluated.

Comparison row 8

Overlap and reuse

NIST SP 800-161 Rev. 1

NIST supplier inventories, risk assessments, acquisition requirements, contract controls, assessments, monitoring, incident records, and response decisions can support relationship management.

ISO/IEC 27036 supplier relationships

ISO/IEC 27036 can reuse those artifacts when they address the same acquirer, supplier, product or service, risk, relationship stage, and requirement. The ISO process outputs and bilateral agreement details still need direct evidence.

Operational implication

Map artifacts one by one. Record partial coverage instead of assuming that a NIST control satisfies every requirement.

Comparison row 9

Practical decision rule

NIST SP 800-161 Rev. 1

Choose NIST SP 800-161 Rev. 1 to design and govern the enterprise C-SCRM program, including acquisition, controls, supplier assurance, monitoring, and response.

ISO/IEC 27036 supplier relationships

Choose the relevant ISO/IEC 27036 part to define the acquirer-supplier relationship, especially selection, agreement content, operating responsibilities, assurance, transition, and termination.

Operational implication

When both apply, keep NIST as the program layer and ISO/IEC 27036 as the relationship layer. Approve the map only after every cited requirement has complete, partial, or missing evidence recorded.

Practical decision rule

When should teams use NIST SP 800-161 Rev. 1 first versus ISO/IEC 27036 supplier relationships first?

  • Use NIST SP 800-161 Rev. 1 first to design or improve the enterprise C-SCRM program, acquisition controls, supplier assurance, monitoring, and response.
  • Use :2022 first to define requirements, the agreement, responsibilities, monitoring, transition, or termination for a specific acquirer-supplier relationship.
  • Use both when the relationship sits inside the C-SCRM program. State which ISO part and edition applies, then record the requirements that remain unique to each side.
Section 1

Which document should drive the supplier decision?

Start with SP 800-161 Rev. 1 Update 1 when the organization needs a C-SCRM strategy, policy, plan, risk assessment, control selection, acquisition practice, or monitoring process across enterprise, mission or business-process, and operational levels.

Start with :2022 when an acquirer and supplier need requirements for planning, selecting, agreeing, operating, monitoring, changing, or terminating a supplier relationship. Part 1:2021 supplies the concepts; Part 3:2023 gives guidance for hardware, software, and services supply-chain security; Part 4:2016 gives cloud-service guidance.

Part 2 applies to organizations of any type or size and to procurement or supply such as manufacturing, business-process services, software or hardware components, knowledge services, build-operate-transfer arrangements, and cloud services. It expects foundational business, risk, operational, human-resource, and information-security processes; it does not supply a universal risk threshold or contract cadence.

contains requirements, while Parts 1, 3, and 4 have different purposes. Cite the part, edition, clause, actor, and relationship stage. A general reference to "ISO 27036" is too imprecise for an audit or contract decision.

  • Enterprise risk and security: set the NIST C-SCRM strategy, risk appetite, criticality method, system boundary, control baseline, monitoring, and response.
  • Acquirer and procurement: document supplier selection criteria, security requirements, due diligence, audit and assurance terms, subcontractor conditions, service levels, change and incident procedures, and termination requirements.
  • Supplier: assess the proposed supply, identify treatment work, accept or negotiate security requirements, assign responsible personnel, and maintain the agreed evidence.
  • Do not claim "ISO/IEC 27036 certified." The series is not a stand-alone management-system certification standard; state the actual contract, assessment, audit, or broader certification context.
Primary sources

References and citations

iso.org
Referenced sections
  • Official ISO page for supplier and acquirer relationship requirements.
"fundamental information security requirements for defining, implementing, operating, monitoring, reviewing, maintaining and improving supplier and acquirer relationships"
doi.org
Referenced sections
  • Primary NIST source for the C-SCRM side of this comparison, including supply-chain risk practices, risk-management levels, and supplier assurance evidence.
"identifying, assessing, and mitigating cybersecurity risks"
Related guides

Explore more topics

How should teams handle counterfeits under NIST SP 800-161 Rev. 1 supply-chain risk management?
Prioritize critical items, use traceable sources, verify authenticity and tamper protection, quarantine suspected counterfeits, and reassess affected risk.
How should teams handle critical suppliers under NIST SP 800-161 Rev. 1 supply-chain risk management?
Identify critical suppliers through mission dependency, component importance, access, concentration, substitutability, and potential impact, not spend alone.
How should teams handle monitoring under NIST SP 800-161 Rev. 1 supply-chain risk management?
Run risk-based supplier monitoring with scheduled revalidation, event triggers, operating signals, escalation thresholds, corrective action, and evidence.
How should teams handle provenance under NIST SP 800-161 Rev. 1 supply-chain risk management?
Collect and verify traceable origin, build, dependency, custody, authenticity, and change evidence for critical systems, components, software, and data.
How should teams handle supplier incidents under NIST SP 800-161 Rev. 1 supply-chain risk management?
Coordinate supplier incidents through joint triage, evidence preservation, containment, recovery, contract communication, corrective action, and reassessment.
How should teams handle supply chain risk response under NIST SP 800-161 Rev. 1 supply-chain risk management?
Choose and document whether to accept, avoid, mitigate, share, or transfer supply-chain risk, with authority, actions, residual risk, and review triggers.
How should teams handle tiering under NIST SP 800-161 Rev. 1 supply-chain risk management?
Build supplier risk categories that drive assurance treatment while keeping them distinct from SP 800-161 risk-management levels and CSF Tiers.
NIST SP 800-161 Rev. 1 C-SCRM Governance Checklist
A NIST SP 800-161 Rev. 1 checklist for assigning C-SCRM decisions across enterprise, mission/business-process, and operational levels.
NIST SP 800-161 Rev. 1 C-SCRM Governance Guide
Design NIST SP 800-161 Rev. 1 C-SCRM governance across the enterprise, mission/business-process, and operational levels with accountable roles and feedback loops.
NIST SP 800-161 Rev. 1 Contract and Monitoring Controls
Translate C-SCRM risk decisions into supplier clauses, subcontractor flow-down, evidence delivery, revalidation, monitoring, incident, continuity, and exit terms.
NIST SP 800-161 Rev. 1 Criticality Analysis Guide
Identify mission-critical functions, systems, components, products, services, suppliers, and single-source dependencies so C-SCRM effort follows potential impact.
NIST SP 800-161 Rev. 1 FAQ: practical implementation questions
NIST SP 800-161 Rev. 1 answers with cited implementation steps, decision criteria, and evidence guidance.
NIST SP 800-161 Rev. 1 implementation playbook
Build a tailored C-SCRM program with strategy, policy, plans, assessments, acquisition controls, monitoring, and evidence across NIST's three risk-management levels.
NIST SP 800-161 Rev. 1 Provenance and SBOM Supplier Controls
Use provenance, SBOM, build integrity, authenticity, and supplier evidence together to manage software and component risk under NIST SP 800-161 Rev. 1.
NIST SP 800-161 Rev. 1 supplier assessment evidence: risk-based records and evaluation criteria
Choose and validate supplier evidence based on criticality, risk, contract requirements, source reliability, freshness, and proof of operating effectiveness.
NIST SP 800-161 Rev. 1 Supplier Risk Tiering
Group suppliers by mission dependency and cyber risk, then tie each category to proportionate due diligence, evidence, contracts, monitoring, and response.
NIST SP 800-161 Rev. 1 vs DORA ICT third-party risk: practical side-by-side comparison
Compare NIST SP 800-161 Rev. 1 and DORA ICT third-party risk with side-by-side scope, owner, trigger, evidence, cadence, assurance, and decision-rule rows.
NIST SP 800-161 Rev. 1: workflow for collecting and validating C-SCRM supplier evidence
A risk-based NIST SP 800-161 supplier evidence workflow from relationship scope and criticality through request, validation, decision, remediation, and monitoring.
Which contract controls should teams define under NIST SP 800-161 Rev. 1?
Translate supplier risk into measurable security, flow-down, evidence, monitoring, incident, continuity, remediation, and exit clauses under SP 800-161.