Skip to main content

International standard · International

What ISO 27001 Annex A asks of your vendors

Organisations certified to, or aligning with, ISO/IEC 27001:2022; the Annex A controls apply where the statement of applicability includes them. Certificates to the 2013 edition lapsed on 31 October 2025, so the 2022 controls apply to every current certificate. ISO/IEC 27001:2022, Annex A controls 5.19 to 5.23

Check my vendors

4 requirements that reach your vendors

Each provision, the evidence that usually supports it, and how many vendors in the index publish that evidence. Reviewed 21 Sep 2026.

Annex A 5.19

Information security in supplier relationships

Processes are defined and implemented to manage the information security risks associated with the use of suppliers’ products or services.

  • Independent security assurance

    758 vendors in the index

    A current SOC 2 report or ISO/IEC 27001 certificate is the usual evidence that a supplier operates appropriate security measures.

Annex A 5.20

Security within supplier agreements

Relevant information security requirements are established and agreed with each supplier, based on the type of relationship.

  • Data processing agreement

    191 vendors in the index

    The DPA is where processing instructions, confidentiality, security, sub-processing and audit rights are written down.

Annex A 5.21

The ICT supply chain

Processes are defined to manage the information security risks associated with the ICT products and services supply chain.

  • Published subprocessor list

    436 vendors in the index

    A current list of subprocessors, with purpose and location, is how a customer knows who else touches its data.

Annex A 5.23

Information security for cloud services

Processes for acquiring, using, managing and exiting cloud services are established in line with the organisation’s information security requirements.

  • Cloud security assurance

    416 vendors in the index

    ISO/IEC 27017 and 27018 and the CSA STAR registry cover controls specific to cloud services.

  • Independent security assurance

    758 vendors in the index

    A current SOC 2 report or ISO/IEC 27001 certificate is the usual evidence that a supplier operates appropriate security measures.

Vendors publishing the most ISO 27001 Annex A evidence

Among the most-searched vendors in the index, ranked by how many of the requirements above their public evidence reaches. Open one to see each item with its date and source.

Questions buyers ask

What does ISO 27001 Annex A require from vendors?

Information security in supplier relationships (Annex A 5.19); Security within supplier agreements (Annex A 5.20); The ICT supply chain (Annex A 5.21); Information security for cloud services (Annex A 5.23). Each is listed below with the evidence that may support it.

Who does ISO 27001 Annex A apply to?

Organisations certified to, or aligning with, ISO/IEC 27001:2022; the Annex A controls apply where the statement of applicability includes them. Certificates to the 2013 edition lapsed on 31 October 2025, so the 2022 controls apply to every current certificate.

Is a SOC 2 report enough for ISO 27001 Annex A?

A SOC 2 report or ISO 27001 certificate may support the security parts of ISO 27001 Annex A, but security within supplier agreements, the ict supply chain need other evidence. Confirm sufficiency with your counsel or auditor.

Other regulations

All articles

This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.