Book an Appointment
GRC · Supplier Risk

ISO/IEC 27036 Master supply chain and third-party risk

The international framework for information security in supplier relationships – from selection to termination. We translate the standard into robust Third-Party Risk Management (TPRM) that underpins NIS2 and DORA at the normative level.

27036-1:2021 – -4:2016Multi-part standard family (Parts 1–4)
Framework & guidanceRequirements (Part 2) + guidelines
Not certifiableNo standalone certificate
NIS2 · DORA · ISO 27001Covers supply chain measures

What ISO/IEC 27036 is about

ISO/IEC 27036 (Cybersecurity – Supplier relationships) is the internationally recognised family of standards for information security in supplier and third-party relationships. It structures the management of supplier risk across the entire lifecycle of a business relationship – from planning and selection, through the contractual agreement and ongoing operation, to orderly termination.

The family comprises four parts: Part 1 (27036-1:2021) provides overview and concepts, Part 2 (27036-2:2022) defines the binding requirements for acquirers and suppliers, Part 3 (27036-3:2023) addresses ICT supply chain security (hardware, software and services), and Part 4 (27036-4:2016) specifically covers the security of cloud services. ISO/IEC 27036 is a guidance and requirements framework – not certifiable on its own – and complements the supplier controls A.5.19–A.5.23 of ISO/IEC 27001.

The four parts of the standard family

Structure and building blocks of ISO/IEC 27036

01

Part 1 – Overview & concepts (27036-1:2021)

Defines terms, principles and a shared understanding of security risks in supplier relationships. It forms the conceptual foundation for the remaining parts.

02

Part 2 – Requirements (27036-2:2022)

Specifies the fundamental information security requirements for defining, implementing, operating, monitoring and improving supplier and acquirer relationships. The normative core of the family.

03

Part 3 – ICT supply chain (27036-3:2023)

Guidelines for the security of the hardware, software and services supply chain. Addresses transparency, provenance and integrity across multi-tier supply chains.

04

Part 4 – Cloud services (27036-4:2016)

Guidance for cloud customers and cloud providers to gain visibility into and manage the security risks arising from cloud use, across public, hybrid and private models.

05

Relationship lifecycle

All parts follow the lifecycle: planning, selection, agreement, operation and termination. Security requirements are anchored at every phase rather than checked only at onboarding.

06

Roles: acquirers and suppliers

The standard addresses both sides of the relationship with mirrored obligations – producing balanced, auditable agreements instead of one-sided clause sets.

The bridging anchor: ISO/IEC 27036 in your compliance landscape

Why the standard is becoming mandatory in the DACH region

NIS2 – supply chain security

Article 21(2)(d) requires measures on supply chain security and relationships with providers. ISO/IEC 27036 supplies the normative methodology to meet this obligation in a structured, auditable way.

DORA – ICT third-party risk

DORA demands comprehensive management of ICT third-party risk across the entire contractual lifecycle. The lifecycle logic of ISO/IEC 27036 (planning to termination) mirrors exactly this expectation.

ISO/IEC 27001 – controls A.5.19–A.5.23

The supplier controls in ISO/IEC 27001:2022 (supplier relationships, agreements, ICT supply chain, monitoring, cloud) are methodically underpinned and given depth by ISO/IEC 27036.

CRA & M&A due diligence

The Cyber Resilience Act (CRA) shifts software supply chain duties to the manufacturer; in M&A, third-party risk becomes a deal factor. ISO/IEC 27036 gives both fields a common language.

How we work together

From baseline assessment to a lived TPRM process

01

1 – Baseline & criticality

We map your supplier and service-provider landscape, classify by criticality and match existing contracts against the requirements in Part 2.

02

2 – Gap analysis & risk picture

We compare your processes against ISO/IEC 27036 as well as NIS2 and DORA obligations. You receive a prioritised risk picture and a concrete remediation roadmap.

03

3 – Processes & contracts

We anchor the relationship lifecycle in your processes – selection criteria, security clauses, audit rights and exit provisions – and integrate them into your ISMS.

04

4 – Operation & continuous monitoring

Ongoing monitoring, recurring supplier assessments and KPI reporting that delivers evidence for audits and supervisors – available as GRC as a Service.

Frequently asked questions

ISO/IEC 27036 answered concisely

Can you get certified against ISO/IEC 27036?

No. ISO/IEC 27036 is a guidance and requirements framework and is not certifiable on its own. Certification runs through ISO/IEC 27001, where ISO/IEC 27036 methodically underpins the supplier controls A.5.19–A.5.23.

How does ISO/IEC 27036 relate to NIS2?

NIS2 Article 21(2)(d) explicitly requires supply chain security measures. ISO/IEC 27036 provides the recognised methodology to implement this obligation in a structured, documented and auditable manner.

Does it also cover DORA third-party risk?

Yes, at the normative level. DORA requires management of ICT third-party risk across the entire contractual lifecycle – exactly the lifecycle logic of ISO/IEC 27036 from planning to termination.

Which part do we need first?

Part 2 (Requirements) is the normative core and usually the starting point. Part 1 provides the terminology, Part 3 deepens the ICT supply chain, and Part 4 becomes relevant as soon as cloud services are involved.

How does ISO/IEC 27036 relate to the CRA?

The Cyber Resilience Act mainly addresses product and software supply chain duties of manufacturers. ISO/IEC 27036 provides the organisational framework for the relationships behind them – the two complement each other.

Put supply chain and third-party risk on a solid footing

We bring ISO/IEC 27036 into your processes – aligned with NIS2, DORA and your existing ISMS. Talk to our consultants.