ISO supplier-security standard enters systematic review
ISO/IEC 27036-1 remains the published supplier-relationship standard while its 2026 review determines whether the current edition should be confirmed, revised, or withdrawn.
Third Party Current editorial graphic. Source material: International Organization for Standardization; analysis and presentation by Third Party Current.
A lifecycle event, not a new requirement
The ISO status record is easy to overread. A systematic review is the standards-development process for deciding what happens to an existing edition; it is not evidence that the text has already changed. The 2021 edition remains the published reference while the responsible committee considers whether it should be confirmed, revised, or withdrawn.
That distinction matters for third-party risk records. Policies, control mappings, questionnaires, contracts, and provider marketing can all cite an edition without recording its lifecycle state. A maintained program should preserve the exact edition and the date it was used so a later revision does not silently rewrite the basis for an earlier decision.
What operators should do now
Teams do not need to launch a remediation program merely because the review opened. They should identify where ISO/IEC 27036 appears in standards libraries, supplier-security criteria, contract templates, internal policies, assessment frameworks, and product configurations. The useful result is an inventory of dependencies that can be reviewed if a revised edition is later published.
Software buyers can ask how a platform manages a standard through proposal, review, publication, transition, and supersession. The demonstration should show the exact version linked to a requirement, the affected controls and suppliers, the owner of a mapping decision, and the retained history after an update.
A test of standards intelligence
Many products say that they map to standards, but the more consequential capability is change management. A static label does not tell an operator whether a control interpretation is current, who approved it, or which supplier records rely on it. Versioned authority records are therefore part of the evidence architecture, not merely a content feature.
Third Party Current will follow the ISO lifecycle record and will not describe a future outcome until ISO publishes it. Any provider claim tied to ISO/IEC 27036 will remain a documented mapping claim rather than proof that the product or customer program satisfies the standard.
What we will watch next
Third Party Current will watch for later primary-source evidence that changes the maintained company, capability, or standards record. The next useful evidence may include implementation documentation, release details, regulator findings, corrected methods, product packaging, customer-observable workflow, or a subsequent company statement. Until then, the dated source and its stated boundary remain attached to this analysis.