Part 1 – Overview & concepts (27036-1:2021)
Defines terms, principles and a shared understanding of security risks in supplier relationships. It forms the conceptual foundation for the remaining parts.
The international framework for information security in supplier relationships – from selection to termination. We translate the standard into robust Third-Party Risk Management (TPRM) that underpins NIS2 and DORA at the normative level.
ISO/IEC 27036 (Cybersecurity – Supplier relationships) is the internationally recognised family of standards for information security in supplier and third-party relationships. It structures the management of supplier risk across the entire lifecycle of a business relationship – from planning and selection, through the contractual agreement and ongoing operation, to orderly termination.
The family comprises four parts: Part 1 (27036-1:2021) provides overview and concepts, Part 2 (27036-2:2022) defines the binding requirements for acquirers and suppliers, Part 3 (27036-3:2023) addresses ICT supply chain security (hardware, software and services), and Part 4 (27036-4:2016) specifically covers the security of cloud services. ISO/IEC 27036 is a guidance and requirements framework – not certifiable on its own – and complements the supplier controls A.5.19–A.5.23 of ISO/IEC 27001.
Structure and building blocks of ISO/IEC 27036
Defines terms, principles and a shared understanding of security risks in supplier relationships. It forms the conceptual foundation for the remaining parts.
Specifies the fundamental information security requirements for defining, implementing, operating, monitoring and improving supplier and acquirer relationships. The normative core of the family.
Guidelines for the security of the hardware, software and services supply chain. Addresses transparency, provenance and integrity across multi-tier supply chains.
Guidance for cloud customers and cloud providers to gain visibility into and manage the security risks arising from cloud use, across public, hybrid and private models.
All parts follow the lifecycle: planning, selection, agreement, operation and termination. Security requirements are anchored at every phase rather than checked only at onboarding.
The standard addresses both sides of the relationship with mirrored obligations – producing balanced, auditable agreements instead of one-sided clause sets.
Why the standard is becoming mandatory in the DACH region
Article 21(2)(d) requires measures on supply chain security and relationships with providers. ISO/IEC 27036 supplies the normative methodology to meet this obligation in a structured, auditable way.
DORA demands comprehensive management of ICT third-party risk across the entire contractual lifecycle. The lifecycle logic of ISO/IEC 27036 (planning to termination) mirrors exactly this expectation.
The supplier controls in ISO/IEC 27001:2022 (supplier relationships, agreements, ICT supply chain, monitoring, cloud) are methodically underpinned and given depth by ISO/IEC 27036.
The Cyber Resilience Act (CRA) shifts software supply chain duties to the manufacturer; in M&A, third-party risk becomes a deal factor. ISO/IEC 27036 gives both fields a common language.
From baseline assessment to a lived TPRM process
We map your supplier and service-provider landscape, classify by criticality and match existing contracts against the requirements in Part 2.
We compare your processes against ISO/IEC 27036 as well as NIS2 and DORA obligations. You receive a prioritised risk picture and a concrete remediation roadmap.
We anchor the relationship lifecycle in your processes – selection criteria, security clauses, audit rights and exit provisions – and integrate them into your ISMS.
Ongoing monitoring, recurring supplier assessments and KPI reporting that delivers evidence for audits and supervisors – available as GRC as a Service.
Primary sources and related VamiSec services
ISO/IEC 27036 answered concisely
No. ISO/IEC 27036 is a guidance and requirements framework and is not certifiable on its own. Certification runs through ISO/IEC 27001, where ISO/IEC 27036 methodically underpins the supplier controls A.5.19–A.5.23.
NIS2 Article 21(2)(d) explicitly requires supply chain security measures. ISO/IEC 27036 provides the recognised methodology to implement this obligation in a structured, documented and auditable manner.
Yes, at the normative level. DORA requires management of ICT third-party risk across the entire contractual lifecycle – exactly the lifecycle logic of ISO/IEC 27036 from planning to termination.
Part 2 (Requirements) is the normative core and usually the starting point. Part 1 provides the terminology, Part 3 deepens the ICT supply chain, and Part 4 becomes relevant as soon as cloud services are involved.
The Cyber Resilience Act mainly addresses product and software supply chain duties of manufacturers. ISO/IEC 27036 provides the organisational framework for the relationships behind them – the two complement each other.
We bring ISO/IEC 27036 into your processes – aligned with NIS2, DORA and your existing ISMS. Talk to our consultants.