Vendor Register
Standards ยท ISO 27001

ISO/IEC 27001:2022

Rendered when the buyer ticks "ISO/IEC 27001 certified". The register cites 6 of its 93 clauses, behind 8 findings: single-source vendors with no fallback named, concentration at or above the threshold, hardware with an unconfirmed country of origin, contracts ending inside 90 days with no re-tender noted, critical vendors with no contract end recorded, nis2 supplier assessment not evidenced, cloud services with no exit plan, sub-outsourcing chains longer than one hop, and on the obligation rows of every vendor it reaches.

Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. Framework page. What it attaches to a vendor: the ISO 27001 regime page.

Clauses cited

6 of 93
ISO 27001 5.19 Information security in supplier relationships

Define and apply processes to manage the security risk suppliers introduce.

Evidence an auditor accepts: supplier_risk_assessment; contractual_security_requirements; supplier_security_monitoring
Common gap: Treating all suppliers as low risk
Source framework: ISO/IEC 27001:2022
ISO 27001 5.22 Monitoring, review and change management of supplier services

Regularly monitor, review and manage change in supplier security practice and service delivery.

Evidence an auditor accepts: supplier_security_monitoring_reports; supplier_service_review_meetings; supplier_change_management_records
Common gap: relying on informal verbal updates
Source framework: ISO/IEC 27001:2022
ISO 27001 5.21 Managing information security in the ICT supply chain

Extend security requirements down the ICT products and services supply chain.

Evidence an auditor accepts: supplier_security_requirements; contractual_security_clauses; supply_chain_risk_assessments
Common gap: Treating supplier security as one-off check
Source framework: ISO/IEC 27001:2022
ISO 27001 5.20 Addressing information security within supplier agreements

Establish and agree the relevant security requirements in each supplier contract.

Evidence an auditor accepts: contract_security_clauses; supplier_risk_assessment; security_incident_reporting
Common gap: missing explicit security clauses
Source framework: ISO/IEC 27001:2022
ISO 27001 5.23 Information security for use of cloud services

Govern acquisition, use, management and exit of cloud services against your security requirements.

Evidence an auditor accepts: cloud_service_selection; cloud_contract_management; cloud_security_monitoring
Common gap: Relying solely on provider's security assurances
Source framework: ISO/IEC 27001:2022
ISO 27001 8.30 Outsourced development

Direct, monitor and review outsourced system development.

Evidence an auditor accepts: outsourced_development_contracts; vendor_security_assessments; development_process_monitoring
Common gap: contracts lack specific security obligations
Source framework: ISO/IEC 27001:2022

See which clauses your list engages

Paste the list and every vendor names the clauses behind it, filtered to the regimes that apply to you. Eight vendors free, no account.

Build my vendor register