// Security
ISO 27036 Supplier Relationships Compliance Software
Information security for supplier and ICT supply-chain relationships.
Framework at a glance
Short name
ISO 27036
Version
2021
Category
Security
Controls
18
What ISO 27036 covers
18 controls across 4 domains — every one tracked, owned and evidenced in Cyber Horizon.
Part 1 - Overview and Concepts
2 controls- 27036-1.1 Supplier Relationship Security Concepts
- 27036-1.2 Supplier Relationship Management Framework
Part 2 - Requirements
10 controls- 27036-2.1 Supplier Relationship Planning
- 27036-2.2 Supplier Relationship Security Policy
- 27036-2.3 Supplier Relationship Risk Assessment
- 27036-2.4 Supplier Selection and Due Diligence
- 27036-2.5 Agreement Security Requirements
Part 3 - ICT Supply Chain Security
3 controls- 27036-3.1 ICT Supply Chain Visibility
- 27036-3.2 ICT Supply Chain Risk Management
- 27036-3.3 Product and Service Integrity and Provenance
Part 4 - Security of Cloud Services
3 controls- 27036-4.1 Cloud Service Acquisition Risk Management
- 27036-4.2 Cloud Shared Responsibility and Provider Assurance
- 27036-4.3 Cloud Service Agreement, Exit and Portability
How Cyber Horizon automates ISO 27036
Every ISO 27036 control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.
Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.
Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.
Frequently asked questions
What is ISO 27036 Supplier Relationships?
Information security for supplier and ICT supply-chain relationships.
How many controls does ISO 27036 Supplier Relationships have?
ISO 27036 Supplier Relationships (2021) has 18 controls in Cyber Horizon's catalogue, organised across 4 domains.
How does Cyber Horizon help with ISO 27036 Supplier Relationships?
Cyber Horizon maps ISO 27036 Supplier Relationships into a shared control library alongside every other framework you run, so evidence collected once counts towards ISO 27036 and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.
More Security frameworks
See ISO 27036 mapped to your environment
Start with the free 20-question readiness check — no signup — or get a personal walkthrough of ISO 27036 in Cyber Horizon.