ISO/IEC 27036, "Cybersecurity - Supplier relationships," is the ISO/IEC standard written specifically for information security in supplier and acquirer relationships - distinct from ISO/IEC 27001, which covers an organization's information security management system (ISMS) broadly. It is published in four parts, each revised on its own schedule, and most TPRM programs only need to know two things about it going in: which part answers their specific question, and that 27036 is implementation guidance to apply, not a certificate to buy.
The four parts, as they stand today
| Part | Current edition | What it covers |
|---|---|---|
| Part 1 - Overview and concepts | 2021, 2nd ed. | Terminology and the acquirer/supplier relationship model, plus the motivations - cost, specialization, cloud enablement - that make supplier risk a security question at all. Not prescriptive; it exists to get a team aligned on vocabulary before writing policy. |
| Part 2 - Requirements | 2022, 2nd ed. | Information security requirements for defining, implementing, operating, monitoring, reviewing, maintaining and improving supplier and acquirer relationships, structured against the lifecycle processes in ISO/IEC/IEEE 15288. It assumes the acquirer and supplier already run foundational processes - governance, risk management, human-resources security - and builds the supplier-specific layer on top. |
| Part 3 - Guidelines for hardware, software, and services supply chain security | 2023, 2nd ed. | Visibility into multi-tier, physically dispersed supply chains: not just your direct supplier's controls but the sub-tier manufacturers, integrators, and component sources behind them. The 2023 edition broadened the original 2013 edition's "ICT supply chain" framing to hardware, software, and services generally. |
| Part 4 - Guidelines for security of cloud services | 2016, 1st ed. | Risk to the cloud service customer from acquiring and using cloud services - visibility, shared responsibility, provider transparency. It has not been revised since 2013's Part 3 and 2014's Part 1 and 2 were, so its title still carries the series' old "Information technology - Security techniques" name rather than the newer "Cybersecurity" rebrand. |
That last detail trips people up in practice: search ISO's own catalog for the series and the parts do not share a title. Parts 1 through 3 have been re-issued under the shorter "Cybersecurity - Supplier relationships" title as JTC 1/SC 27 has worked through a broader revision cycle; Part 4 has not yet had its turn, so it is still filed under the original, longer name. It is the same series, just mid-revision.
How it fits with ISO/IEC 27001 Annex A
Most programs first meet supplier-relationship requirements through ISO/IEC 27001's 2022 Annex A, which groups them under five controls: 5.19 (information security in supplier relationships, the parent objective), 5.20 (addressing security within supplier agreements), 5.21 (managing security in the ICT supply chain), 5.22 (monitoring, review, and change management of supplier services), and 5.23 (security for use of cloud services). Annex A states the objective; it does not tell an implementer how to run a supplier risk assessment, draft an agreement clause, or gain visibility into a multi-tier supply chain. That is what 27036 supplies - 5.21's territory maps closely onto Part 3, and 5.23's onto Part 4, almost control-for-part. A team that already holds ISO 27001 certification and is asking "what do we actually do to satisfy 5.19 through 5.23" is the audience 27036 was written for.
Is it something you get certified against?
Not in the way ISO/IEC 27001 certification works. There is no single, universally recognized accredited-certification scheme for ISO/IEC 27036 comparable to the IAF-recognized accreditation bodies that certify 27001 ISMS audits, though a handful of national and regional certification bodies offer conformity assessment against individual parts. In practice, almost every organization that engages with 27036 does so as implementation guidance underneath an existing ISO 27001 certification or a NIST SP 800-161-based C-SCRM program, rather than by pursuing a standalone "ISO 27036 certificate." If a vendor or broker offers to sell one, ask which accreditation body actually stands behind it.
Where it overlaps with NIST SP 800-161
NIST SP 800-161 and ISO/IEC 27036 cover overlapping ground - lifecycle-based supply chain risk management - from different institutional traditions. NIST's is a US-government-rooted control catalog with cybersecurity supply chain risk management (C-SCRM) overlays; 27036 is an international, sector-neutral ISO standard organized as acquirer/supplier process guidance. Organizations that answer to both - a US federal contractor with an EU parent, for example - typically pick one as the primary control framework and treat the other as a supporting reference, rather than trying to satisfy both from scratch in parallel.
27036-4 is also worth distinguishing from a standard it is frequently confused with: ISO/IEC 27017. 27036-4 addresses the cloud customer's side - assessing and managing the risk of acquiring and using a cloud service. 27017 is a code of practice for the cloud provider's own information security controls. A vendor questionnaire that asks about "cloud security certifications" is usually really asking about 27017 (or an equivalent SOC 2 or CSA STAR attestation) on the provider side; 27036-4 is the standard that tells your own team how to evaluate that provider relationship in the first place.
Turning 27036 into TPRM actions
- Use Part 1's vocabulary to scope what counts as a "supplier." Its definition deliberately extends past software vendors to any relationship with information security implications - consulting engagements, outsourced business processes, and Build-Operate-Transfer arrangements included - which is a useful check against inventories that only track SaaS.
- Treat Part 2 as the process audit checklist behind Annex A 5.19-5.20. If your supplier agreements do not name who owns risk assessment, monitoring, and review across the relationship's lifecycle, that is the specific gap Part 2 is written to close.
- Pull Part 3 when a vendor's supply chain has real depth - hardware, firmware, or components sourced through multiple tiers - where a questionnaire answer about the direct supplier tells you nothing about who actually built the parts. This is the same territory covered generally in fourth-party risk.
- Pull Part 4 specifically for the acquisition decision, not the provider's internal controls - use it alongside a provider's own SOC 2, ISO 27001, or 27017 evidence rather than instead of it.
- Keep the mapping to Annex A explicit in your ISMS documentation so an auditor can trace a control (5.19-5.23) to the specific 27036 part your procedure actually follows.
Where this sits among TPRM platforms
27036 is a paper standard - what a platform contributes is turning its guidance into an operating process. OneTrust and ProcessUnity are strong at the governance layer this implies: documenting the ISMS-mapped procedures, agreement clauses, and review cadence Part 2 calls for. BitSight, SecurityScorecard, and UpGuard help with the externally observable half of Part 3 and Part 4's risk picture - visibility into a provider's posture that does not depend on the provider self-reporting it. Rescana's approach pairs continuous, evidence-based monitoring with automated evidence collection so that the Annex A 5.19-5.23 mapping stays backed by current, verifiable signal rather than a procedure document nobody has revisited since the last certification audit - the same gap covered generally in evidence-based risk scoring.
Frequently asked questions
What is ISO/IEC 27036?
ISO/IEC 27036, "Cybersecurity - Supplier relationships," is a four-part ISO/IEC standard giving guidance on managing information security risk in supplier and acquirer relationships. Part 1 (2021) covers overview and concepts, Part 2 (2022) sets requirements for defining and running the relationship lifecycle, Part 3 (2023) covers hardware, software, and services supply chain security, and Part 4 (2016) covers the risk of acquiring and using cloud services. It complements ISO/IEC 27001, which covers an organization's information security management system broadly rather than supplier relationships specifically.
How does ISO/IEC 27036 relate to the supplier controls in ISO/IEC 27001 Annex A?
ISO/IEC 27001's 2022 Annex A sets five supplier-relationship control objectives - 5.19 through 5.23, covering the relationship generally, agreements, the ICT supply chain, ongoing monitoring, and cloud services - but states the objective without prescribing how to meet it. ISO/IEC 27036 supplies that operational detail: its Part 3 maps closely onto Annex A control 5.21 (ICT supply chain) and its Part 4 onto control 5.23 (cloud services). An organization already certified to ISO 27001 typically turns to 27036 specifically to answer how it should satisfy those five controls in practice.
Is ISO/IEC 27036 a certifiable standard?
Not in the way ISO/IEC 27001 is. There is no single, widely recognized accredited-certification scheme for ISO/IEC 27036 comparable to the international accreditation bodies that certify ISO 27001 ISMS audits, although some national or regional bodies offer conformity assessment against individual parts. Most organizations that use 27036 treat it as implementation guidance underneath an existing ISO 27001 certification or a NIST SP 800-161-based supply chain risk management program, rather than pursuing a standalone ISO 27036 certificate. Anyone offering one should be asked which accreditation body backs it.
What is the difference between ISO/IEC 27036-4 and ISO/IEC 27017 for cloud services?
ISO/IEC 27036-4 addresses the cloud customer's side of the relationship - assessing and managing the risk of acquiring and using a cloud service, including visibility and shared-responsibility questions. ISO/IEC 27017 is a code of practice for the cloud provider's own information security controls, extending ISO/IEC 27002. A vendor's claim of 'cloud security certification' is typically about 27017 (or an equivalent attestation like SOC 2), on the provider's side; 27036-4 is the standard that guides how the acquiring organization evaluates and manages that provider relationship in the first place.