Skip to content
  • ISO 27001
  • Annex A

ISO 27001 Annex A 5.21: Managing information security in the ICT supply chain

Updated 5 min read

Your suppliers have suppliers. The SaaS tool that holds your customer data runs on someone’s cloud, sends email through someone else, and is built from open-source components nobody at the vendor wrote. Annex A 5.21 asks you to manage the security risk that comes with that chain for ICT products and services — without pretending you can audit all of it yourself.

This page covers what the control requires, a proportionate way to meet it, what auditors look for and an evidence checklist. For the five supplier controls together, see ISO 27001 supplier relationships: meeting Annex A 5.19–5.23 with evidence.

What Annex A 5.21 requires

The control, paraphrased: processes and procedures should be defined and implemented to manage the information security risks associated with the ICT products and services supply chain. Its full title is Managing information security in the information and communication technology (ICT) supply chain, and it replaced A.15.1.3 in the 2013 edition.

The ISO/IEC 27002:2022 guidance, summarised, expects you to:

  • define security requirements for the ICT products and services you acquire;
  • require ICT service suppliers to propagate your requirements through their supply chain when they subcontract, and product suppliers to propagate appropriate security practices;
  • identify the components that are critical to the product or service, and obtain assurance that they and their origin can be traced;
  • monitor and validate that delivered ICT products and services work as expected, without unexpected or unwanted features;
  • agree rules for sharing information about the supply chain and potential issues;
  • manage lifecycle risks, such as components that become unavailable or unsupported because a supplier stops making them or goes out of business.

The ISO/IEC 27036 series (Cybersecurity — Supplier relationships) goes deeper; part 3 covers hardware, software and services supply chain security.

A proportionate implementation

For most organisations buying ICT services rather than building hardware:

  1. Three questions in the questionnaire for critical and high-tier ICT suppliers: who are your sub-processors or critical sub-suppliers for this service, how do you assess them, and how much notice do we get before one changes? Vendor risk assessment questionnaire: what to ask, and how to score the answers shows where they fit.
  2. A flow-down clause in agreements with those suppliers, requiring them to impose equivalent security obligations on their subcontractors. This links 5.21 to ISO 27001 Annex A 5.20: Addressing information security within supplier agreements.
  3. A dependency inventory for software you build or deploy: the components, their versions and whether they are still supported, with a patching process. That evidence also serves controls such as 8.8 (Management of technical vulnerabilities).
  4. A concentration view: which fourth parties sit behind several of your critical suppliers at once. One cloud region or one email provider behind half your stack is a risk no single supplier assessment will show.

For vendors that use AI models from another provider, that provider is a fourth party too; AI vendor due diligence: a checklist for vendors that use AI on your data lists the questions to ask.

What certification auditors look for

  • For a sampled ICT supplier: do you know its critical sub-suppliers, and how did you find out?
  • Is there a flow-down requirement in the agreement?
  • Has a sub-supplier change been notified in the period, and what did you do with it?
  • For software you build: how do you know what components you ship and use?

Evidence checklist for Annex A 5.21

  • Security requirements for ICT products and services, in the supplier procedure
  • Sub-processor or sub-supplier lists for critical and high-tier ICT suppliers
  • Questionnaire answers on how those suppliers assess their own suppliers
  • Flow-down clauses in the agreements of sampled ICT suppliers
  • Record of a sub-supplier change being reviewed, with the decision
  • Dependency inventory or SBOM for software you develop, with support status
  • Lifecycle and end-of-support tracking for critical ICT components

Also relevant: 8.30 (Outsourced development), when the supplier develops software for you, and the glossary entries on fourth-party and Nth-party risk.

Frequently asked questions

What is ISO 27001 Annex A 5.21?
Annex A 5.21, Managing information security in the information and communication technology (ICT) supply chain, requires processes and procedures to manage the information security risks associated with the ICT products and services supply chain. It replaced A.15.1.3 of ISO/IEC 27001:2013.
Do I have to assess my suppliers' suppliers under 5.21?
Not directly. The control expects you to require your ICT suppliers to pass your security requirements down their own chain, to know which of their suppliers are critical to the service you receive, and to be told about changes. You assess your supplier's management of its suppliers, not every fourth party yourself.
What is the difference between 5.19 and 5.21?
5.19 covers supplier relationships in general, including non-ICT suppliers. 5.21 adds requirements specific to ICT products and services: propagating requirements through the supply chain, tracing critical components and their origin, validating that delivered products work as expected, and managing component lifecycle risks such as end of support.
Is a software bill of materials (SBOM) required for ISO 27001?
No. ISO/IEC 27001:2022 does not mention SBOMs. An SBOM is one practical way to meet the 5.21 guidance on knowing the components in the ICT products you rely on and their origin, especially for software you build or ship, but a dependency inventory and supplier attestations can also do the job.