Skip to content
Cyber Horizon
All frameworks

// Security

ISO 27036 Supplier Relationships Compliance Software

Information security for supplier and ICT supply-chain relationships.

Framework at a glance

Short name

ISO 27036

Version

2021

Category

Security

Controls

18

What ISO 27036 covers

18 controls across 4 domains — every one tracked, owned and evidenced in Cyber Horizon.

Part 1 - Overview and Concepts

2 controls
  • 27036-1.1 Supplier Relationship Security Concepts
  • 27036-1.2 Supplier Relationship Management Framework

Part 2 - Requirements

10 controls
  • 27036-2.1 Supplier Relationship Planning
  • 27036-2.2 Supplier Relationship Security Policy
  • 27036-2.3 Supplier Relationship Risk Assessment
  • 27036-2.4 Supplier Selection and Due Diligence
  • 27036-2.5 Agreement Security Requirements

Part 3 - ICT Supply Chain Security

3 controls
  • 27036-3.1 ICT Supply Chain Visibility
  • 27036-3.2 ICT Supply Chain Risk Management
  • 27036-3.3 Product and Service Integrity and Provenance

Part 4 - Security of Cloud Services

3 controls
  • 27036-4.1 Cloud Service Acquisition Risk Management
  • 27036-4.2 Cloud Shared Responsibility and Provider Assurance
  • 27036-4.3 Cloud Service Agreement, Exit and Portability

How Cyber Horizon automates ISO 27036

Every ISO 27036 control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.

Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.

Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.

Frequently asked questions

What is ISO 27036 Supplier Relationships?

Information security for supplier and ICT supply-chain relationships.

How many controls does ISO 27036 Supplier Relationships have?

ISO 27036 Supplier Relationships (2021) has 18 controls in Cyber Horizon's catalogue, organised across 4 domains.

How does Cyber Horizon help with ISO 27036 Supplier Relationships?

Cyber Horizon maps ISO 27036 Supplier Relationships into a shared control library alongside every other framework you run, so evidence collected once counts towards ISO 27036 and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.

See ISO 27036 mapped to your environment

Start with the free 20-question readiness check — no signup — or get a personal walkthrough of ISO 27036 in Cyber Horizon.