ISO 27036
ISO/IEC 27036 is a multi-part international standard that offers guidance for managing information security within relationships between organizations and their suppliers. It helps both the organizations acquiring products or services and the suppliers providing them address security risks that arise from working together. The series covers supplier relationships broadly, including specific guidance for hardware, software, services, and the use of cloud services.
ISO/IEC 27036 is a series of international standards addressing information security in supplier relationships. It comprises multiple parts: Part 1 (ISO/IEC 27036-1:2021) provides an introductory overview of the guidance for securing information in supplier relationships; Part 2 (ISO/IEC 27036-2:2022) specifies fundamental information security requirements for defining, implementing, operating, monitoring, reviewing, maintaining, and improving supplier relationships; Part 3 (ISO/IEC 27036-3:2023) provides guidance for acquirers and suppliers of hardware, software, and services and is structured to be harmonized with other parts of the series; and Part 4 (ISO/IEC 27036-4:2016) defines guidelines supporting information security management for the use of cloud services. The scope of the series is limited to information security aspects of supplier relationships and does not, on its own, address financial, operational, geopolitical, or ESG risk dimensions. As a guidance and requirements standard rather than a certification scheme within the evidence provided, conformance to 27036 does not by itself confer independent verification or a compliance guarantee.
Why it matters
Supplier relationships create information security exposure that neither party fully controls on its own: an acquirer shares data, systems access, or intellectual property with suppliers, and suppliers in turn integrate the acquirer's information into their own environments. ISO/IEC 27036 matters because it gives both sides a common reference for defining, implementing, operating, monitoring, reviewing, maintaining, and improving the security aspects of those relationships, rather than leaving each organization to negotiate expectations ad hoc. This shared vocabulary and structure can help reduce ambiguity in contracts, onboarding, and ongoing oversight.
The series is deliberately scoped to information security in supplier relationships. That focus is a strength for programs seeking depth on data and system protection, but it also marks a clear boundary: on its own, 27036 does not address financial, operational, geopolitical, or ESG risk dimensions that many third-party risk programs must also manage. Organizations that rely on it should treat it as one component of a broader risk framework rather than a comprehensive supplier risk standard.
Within the evidence provided, 27036 functions as guidance and requirements rather than a certification scheme, so aligning with its parts does not by itself constitute independent verification or a compliance guarantee. Programs typically pair its guidance with independent assessment, contractual controls, and continuous monitoring to close the gap between documented alignment and verified security posture.
Who it's relevant to
Inside ISO 27036
Common questions
Answers to the questions practitioners most commonly ask about ISO 27036.
