Skip to main content
Category: Regulatory Frameworks

ISO 27036

Also known as: ISO/IEC 27036, ISO/IEC 27036 series
Simply put

ISO/IEC 27036 is a multi-part international standard that offers guidance for managing information security within relationships between organizations and their suppliers. It helps both the organizations acquiring products or services and the suppliers providing them address security risks that arise from working together. The series covers supplier relationships broadly, including specific guidance for hardware, software, services, and the use of cloud services.

Formal definition

ISO/IEC 27036 is a series of international standards addressing information security in supplier relationships. It comprises multiple parts: Part 1 (ISO/IEC 27036-1:2021) provides an introductory overview of the guidance for securing information in supplier relationships; Part 2 (ISO/IEC 27036-2:2022) specifies fundamental information security requirements for defining, implementing, operating, monitoring, reviewing, maintaining, and improving supplier relationships; Part 3 (ISO/IEC 27036-3:2023) provides guidance for acquirers and suppliers of hardware, software, and services and is structured to be harmonized with other parts of the series; and Part 4 (ISO/IEC 27036-4:2016) defines guidelines supporting information security management for the use of cloud services. The scope of the series is limited to information security aspects of supplier relationships and does not, on its own, address financial, operational, geopolitical, or ESG risk dimensions. As a guidance and requirements standard rather than a certification scheme within the evidence provided, conformance to 27036 does not by itself confer independent verification or a compliance guarantee.

Why it matters

Supplier relationships create information security exposure that neither party fully controls on its own: an acquirer shares data, systems access, or intellectual property with suppliers, and suppliers in turn integrate the acquirer's information into their own environments. ISO/IEC 27036 matters because it gives both sides a common reference for defining, implementing, operating, monitoring, reviewing, maintaining, and improving the security aspects of those relationships, rather than leaving each organization to negotiate expectations ad hoc. This shared vocabulary and structure can help reduce ambiguity in contracts, onboarding, and ongoing oversight.

The series is deliberately scoped to information security in supplier relationships. That focus is a strength for programs seeking depth on data and system protection, but it also marks a clear boundary: on its own, 27036 does not address financial, operational, geopolitical, or ESG risk dimensions that many third-party risk programs must also manage. Organizations that rely on it should treat it as one component of a broader risk framework rather than a comprehensive supplier risk standard.

Within the evidence provided, 27036 functions as guidance and requirements rather than a certification scheme, so aligning with its parts does not by itself constitute independent verification or a compliance guarantee. Programs typically pair its guidance with independent assessment, contractual controls, and continuous monitoring to close the gap between documented alignment and verified security posture.

Who it's relevant to

Acquirers of products and services
Organizations that purchase hardware, software, or services from suppliers can use the series, particularly Parts 2 and 3, to define information security requirements and to structure how supplier relationships are monitored and reviewed over time. It offers a reference for setting expectations at onboarding and for maintaining security-related oversight through the life of the relationship.
Suppliers of hardware, software, and services
Part 3 explicitly addresses suppliers as well as acquirers, giving providers guidance on the information security expectations they may need to meet in supplier relationships. This can help suppliers align their internal practices with what acquirers reference, though alignment on its own does not confer independent verification of their security posture.
Teams managing cloud service usage
Part 4 provides guidelines supporting information security management specifically for the use of cloud services. It is relevant to organizations acquiring or operating cloud services that need to address the information security implications of those arrangements within the broader supplier relationship context.
Third-party risk and security governance functions
Risk, compliance, and security governance teams can use the series as one input to their information security controls for supplier relationships. Because 27036 is scoped to information security and does not by itself cover financial, operational, geopolitical, or ESG risk, these teams typically integrate it with other frameworks and with independent assessment and monitoring processes.

Inside ISO 27036

Multi-part structure
ISO/IEC 27036 is a multi-part standard addressing information security in supplier relationships, spanning overview and concepts, common requirements, guidance for both acquirers and suppliers, and guidance applicable to specific supply arrangements such as cloud services. Practitioners should confirm which part addresses their use case rather than treating the standard as a single monolithic document.
Information security focus
The standard concentrates on managing information security risks arising from supplier and acquirer relationships. It does not comprehensively address financial, operational continuity, geopolitical, or ESG dimensions of third-party risk, which typically require separate frameworks and controls.
Relationship lifecycle coverage
It provides guidance across the supplier relationship lifecycle, from planning and establishing agreements through ongoing management and termination, rather than covering only onboarding or a single point in time.
Acquirer and supplier perspectives
The standard offers guidance addressed to both parties in the relationship, recognizing that responsibilities and controls differ depending on whether an organization is procuring or providing goods and services.
Alignment with the broader ISO/IEC 27000 family
It is intended to complement information security management standards in the ISO/IEC 27000 family, extending their concepts specifically to the context of supplier relationships rather than replacing them.

Common questions

Answers to the questions practitioners most commonly ask about ISO 27036.

Does ISO 27036 certification prove a supplier is secure?
No. ISO 27036 is a guidance standard for information security in supplier relationships, not a certifiable management system standard in the way ISO/IEC 27001 is. There is no ISO 27036 certificate that a supplier can hold to demonstrate conformance, and even where its guidance is applied, it addresses how supplier relationships are governed rather than guaranteeing any particular security outcome. Treat references to ISO 27036 as evidence of an approach or practice, not as independent verification that a supplier is secure.
Does ISO 27036 cover all types of third-party risk?
No. ISO 27036 is scoped to information security in supplier relationships. It does not, on its own, address financial, operational, geopolitical, ESG, or broader business-continuity risks arising from third parties, and it is not a general supply chain risk management framework. Programs typically pair it with other standards and controls to cover the risk domains it leaves out of scope.
How does ISO 27036 relate to ISO/IEC 27001 in a supplier program?
In many programs the two are used together but serve different purposes. ISO/IEC 27001 defines the requirements for an information security management system that an organization can be certified against, while ISO 27036 provides guidance specifically on managing information security within supplier relationships. Organizations often apply ISO 27036 to operationalize the supplier-related aspects of an ISO/IEC 27001-aligned program, but conformance to one does not imply conformance to the other.
At what stage of the supplier lifecycle does ISO 27036 apply?
The guidance is generally framed to span the supplier relationship lifecycle, including acquisition, agreement, operation, and termination phases, rather than being limited to onboarding due diligence alone. Depending on how a program adopts it, emphasis may fall on defining security requirements in agreements and on ongoing management, so implementers should confirm that both the initial and the continuing phases are addressed rather than assuming a single point-in-time review suffices.
Does adopting ISO 27036 give visibility into fourth-party or Nth-party risk?
Its guidance centers on the information security aspects of an organization's relationships with its direct suppliers. Extending visibility into fourth-party or Nth-party dependencies typically requires additional contractual provisions, flow-down requirements, and monitoring beyond what the standard's direct-relationship focus provides. Implementers should not assume that applying it to a first-tier supplier automatically extends assurance across deeper tiers.
How can ISO 27036 be incorporated into an existing TPRM program?
Many programs use it as reference guidance to shape supplier security requirements, agreement clauses, and lifecycle governance rather than as a standalone control. Because it does not confer certification and does not cover non-security risk domains, it is typically combined with assessment mechanisms such as questionnaires and independent evidence, and with other frameworks addressing financial, operational, and continuity risk. Adoption should account for how supplier attestations against its guidance are validated, since the guidance itself does not substitute for independent verification.

Common misconceptions

Conformance to ISO 27036 results in a certification comparable to ISO/IEC 27001 certification.
ISO/IEC 27036 is primarily guidance rather than a certifiable management system specification. Practitioners should not present alignment with it as an accredited certification, and should verify what any supplier claim of adherence actually means.
Implementing ISO 27036 addresses the full spectrum of third-party risk.
The standard is scoped to information security in supplier relationships. Financial stability, operational resilience, concentration risk, geopolitical exposure, and ESG concerns generally fall outside its scope and require complementary frameworks.
ISO 27036 gives visibility across all supply chain tiers.
The standard centers on the direct supplier relationship. Fourth-party and Nth-party exposure is not automatically covered; extending assurance beyond the first tier typically depends on contractual flow-down and additional monitoring that the standard alone does not guarantee.

Best practices

Identify which specific part of the multi-part standard applies to your context (for example acquirer guidance, supplier guidance, or cloud-specific guidance) before designing controls around it.
Use ISO 27036 to inform contractual security requirements and lifecycle management, but pair it with frameworks addressing financial, operational, geopolitical, and ESG risk to avoid scope gaps.
Treat any supplier claim of alignment as an attestation to be independently validated rather than as evidence of certification or compliance.
Apply the standard's lifecycle orientation by extending assessment beyond onboarding into ongoing monitoring, so point-in-time evaluations do not become stale.
Where multi-tier exposure matters, use contractual flow-down and supplemental assurance mechanisms to address fourth-party and Nth-party risk that first-tier-focused guidance does not cover.
Cross-reference implementation with the broader ISO/IEC 27000 family and adjust for jurisdiction- and sector-specific regulatory expectations rather than assuming uniform applicability.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.