ISO supplier-security standard enters systematic review
ISO/IEC 27036-1 remains the published supplier-relationship standard while its 2026 review determines whether the current edition should be confirmed, revised, or withdrawn.
6 min read
Current reporting and analysis with clear distinctions between primary-source facts, provider-reported claims, and Third Party Current interpretation.
ISO/IEC 27036-1 remains the published supplier-relationship standard while its 2026 review determines whether the current edition should be confirmed, revised, or withdrawn.
The finalized C-SCRM quick-start guide gives organizations a clearer floor for evaluating technology suppliers before risk teams build a larger program around it.
APRA's operational-risk standard now requires regulated entities to connect material service-provider oversight with critical operations, formal agreements, monitoring, and continuity planning.
SP 800-18 Revision 2 treats cybersecurity supply-chain risk planning as part of the broader system risk record, raising the importance of traceable ownership and evidence.
The April package adds limited contractual exemptions, clarifies their management, and updates the material service-provider register ahead of the July commencement date.
The UK policy expands reporting beyond outsourcing, separates notification from register templates, and gives firms a year to govern the data behind material third-party arrangements.
Coverage is attached to the companies, capabilities, and standards it affects so that market records change with evidence rather than headlines alone.