Skip to main content
Category: Supplier and Third-Party

ICT Supply Chain Security (5.21)

Also known as: Managing information security in the ICT supply chain, Annex A 5.21, Control 5.21
Simply put

ICT Supply Chain Security refers to managing the information security risks that arise when an organization relies on suppliers of information and communications technology (ICT) products, software, and managed services. Because the ICT supply chain spans the entire life cycle of hardware, software, and services across many interconnected vendors, this control asks organizations to set expectations with those suppliers and confirm they maintain an agreed level of security. It is one of the reference controls listed in Annex A of ISO/IEC 27001 (2022 revision), typically implemented to protect the organization's information and associated assets throughout supplier relationships.

Formal definition

Annex A Control 5.21 in the ISO/IEC 27001:2022 revision, with implementation guidance elaborated in ISO/IEC 27002:2022, addresses the establishment and enforcement of processes to identify and treat information security risks associated with the acquisition and use of ICT products and services from suppliers. Its stated purpose is to maintain an agreed level of information security in supplier relationships and to protect the organization's information and associated assets across the ICT supply chain, which encompasses the full life cycle of ICT hardware, software, and managed services within a globally interconnected ecosystem. As a reference control, 5.21 is selected through the Statement of Applicability and informed by the organization's risk assessment rather than being universally mandatory; the specific supplier requirements, contractual security clauses, and verification measures adopted vary depending on scope. The control does not, on its own, guarantee freedom from supply chain compromise; maintaining documentation under 5.21 typically serves to evidence that reasonable security steps were taken in securing the digital supply chain.

Why it matters

Modern organizations rarely build and operate their technology in isolation. They depend on a globally interconnected ecosystem of ICT suppliers that spans the entire life cycle of hardware, software, and managed services. A weakness introduced anywhere along that chain, by a component manufacturer, a software vendor, or a managed service provider, can propagate downstream into the organization's own environment. Annex A Control 5.21 exists because information security risk does not stop at the organizational boundary; it extends across every supplier relationship the organization relies upon.

Because the ICT supply chain is layered and interconnected, an organization often has limited direct visibility into the security practices of its suppliers and their sub-suppliers. Control 5.21 addresses this by asking organizations to set clear security expectations with ICT suppliers and to confirm that an agreed level of security is maintained throughout the relationship. This helps protect the organization's information and associated assets from risks that originate outside its own direct control.

It is important to be realistic about what this control achieves. Implementing 5.21 does not, on its own, guarantee freedom from a supply chain compromise. Rather, maintaining the supplier requirements, contractual clauses, and verification measures under this control typically serves to evidence that the organization took reasonable steps to secure its digital supply chain. In the event of a breach, that documentation can demonstrate that appropriate security expectations were established and monitored, even though no single control can eliminate the risk entirely.

Who it's relevant to

GRC and Compliance Managers
Those responsible for maintaining an ISO 27001 ISMS need to decide whether Control 5.21 is applicable through the Statement of Applicability and, if so, ensure supplier security expectations, contractual clauses, and verification measures are documented and evidenced. This documentation typically supports the demonstration of reasonable security steps across the ICT supply chain.
Procurement and Vendor Management Teams
Teams that acquire ICT hardware, software, and managed services translate the control's requirements into practice by embedding agreed security standards into supplier selection and contracts. They help confirm that suppliers maintain the agreed level of security throughout the relationship, scaled to the organization's risk assessment.
Security Engineers and Architects
Practitioners assessing supplier products and services against defined security requirements help identify risks introduced across the interconnected ICT ecosystem and support the verification measures that confirm suppliers adhere to agreed standards over the product and service life cycle.
Internal Auditors and Certification Bodies
During ISO 27001 assessments, auditors examine whether an applicable Control 5.21 is implemented consistently with the organization's Statement of Applicability and risk assessment. They review the evidence that supplier security requirements were established and monitored, keeping in mind that the ISO 27001 certificate covers only the defined scope of the ISMS.

Inside ICT Supply Chain Security (5.21)

Annex A Reference Control 5.21 (ISO/IEC 27001:2022)
In the 2022 revision of ISO/IEC 27001, control 5.21 addresses the management of information security within the ICT (information and communication technology) supply chain. It is one of the Annex A reference controls, which are selected via the Statement of Applicability and informed by the organization's risk assessment rather than being universally mandatory.
Supplier and Product/Service Scope
The control typically concerns the acquisition of ICT products and services from suppliers, including where those suppliers themselves depend on further sub-suppliers. The intent is to address security risks that can propagate along the chain of providers supporting an organization's ICT.
Security Requirements in Agreements
In most implementations, organizations define and communicate information security requirements to be met by suppliers of ICT products and services, commonly expressed through contractual or agreement terms. The specific requirements depend on the organization's risk assessment and scope.
Monitoring and Verification
The control area generally supports ongoing monitoring, review, and verification that agreed security requirements are being met throughout the supplier relationship, though the depth and method vary by engagement and risk.
Relationship to Other Supplier Controls
Control 5.21 sits alongside other supplier-relationship controls within the 2022 Annex A set (such as those addressing supplier relationships generally and monitoring of supplier services). Detailed implementation guidance is found in the companion standard ISO/IEC 27002, which is not itself certifiable.

Common questions

Answers to the questions practitioners most commonly ask about ICT Supply Chain Security (5.21).

Is control 5.21 the same as the general supplier relationship controls in ISO 27001?
No. Control 5.21 in the ISO/IEC 27001:2022 Annex A specifically addresses information and communication technology (ICT) supply chain risks, such as the acquisition of ICT products and services and the dependencies on suppliers' own supply chains, rather than supplier relationships in general. Broader supplier management is covered by other Annex A controls in the same grouping. In practice, organizations select which of these reference controls apply through the Statement of Applicability, informed by their risk assessment, so the boundaries between them depend on how you scope your ISMS.
Does implementing control 5.21 mean my organization is certified as having a secure supply chain?
No. Annex A controls such as 5.21 are reference controls selected via the Statement of Applicability; they are not certifications in themselves. ISO/IEC 27001 certification is issued by an accredited certification body against the ISMS requirements in clauses 4 through 10, and any certificate covers only the defined scope of your ISMS. Applying 5.21 addresses ICT supply chain risk within that scope but does not guarantee freedom from supply chain incidents, and it does not extend certification to your suppliers themselves.
How do we decide whether control 5.21 applies to our ISMS?
Applicability is typically determined through your risk assessment and documented in the Statement of Applicability. Organizations that acquire ICT products or services, or that depend on suppliers whose own supply chains could affect the confidentiality, integrity, or availability of information, will generally find this control relevant. Where a control is excluded, most certification bodies expect a documented justification. The decision depends on your scope, dependencies, and identified risks rather than a universal rule.
What kinds of measures are commonly used to address ICT supply chain risk under this control?
In most implementations, measures may include defining security requirements for ICT acquisitions, assessing supplier security practices, addressing risks arising from suppliers' subcontractors and their supply chains, and monitoring and reviewing supplier arrangements over time. The specific measures depend on the nature of the ICT products and services, the criticality of the information involved, and the outcomes of your risk assessment. The standard describes the control objective rather than prescribing a fixed set of activities.
How does control 5.21 relate to guidance in ISO/IEC 27002?
ISO/IEC 27001 Annex A lists the reference controls, while ISO/IEC 27002 provides more detailed implementation guidance for them, including for ICT supply chain security. Organizations often consult ISO/IEC 27002 to inform how they operationalize 5.21, but 27002 is guidance rather than a certifiable standard. Certification is assessed against the ISO/IEC 27001 requirements and the controls you have selected as applicable.
Can evidence of ICT supply chain controls from a SOC 2 report support this control?
Mapping between frameworks is possible but partial. A SOC 2 report is an attestation examination performed by a licensed CPA firm under SSAE 18 and attests only to the controls and the period covered; it is not an ISO 27001 certification. Evidence gathered for one framework may inform work under the other, but satisfying SOC 2 does not automatically satisfy ISO 27001's requirements for control 5.21. How such evidence is treated depends on your certification body, auditor, and the scope of each engagement.

Common misconceptions

Control 5.21 is mandatory for every ISO 27001 certification.
Annex A controls, including 5.21, are reference controls selected through the Statement of Applicability based on risk assessment. An organization may justify excluding or tailoring a control where it is not applicable to its defined ISMS scope. The certifiable requirements are the ISMS clauses 4 through 10; Annex A controls are applied as informed by risk.
Meeting a SOC 2 supplier or vendor control automatically satisfies ISO 27001 control 5.21.
SOC 2 (an AICPA attestation examination under SSAE 18) and ISO/IEC 27001 (a management system certification) are distinct frameworks. Mapping between the Trust Services Criteria and Annex A controls is possible but partial, so satisfying supplier-related expectations in one framework does not automatically demonstrate conformity with 5.21 in the other.
The control number and structure are the same across ISO 27001 editions.
Control 5.21 refers to the 2022 revision, in which Annex A was restructured into four themes with 93 reference controls. The 2013 version organized 114 controls differently, so control numbering and grouping depend on the edition being cited. Always specify the version when referencing a control number.

Best practices

Confirm which ISO/IEC 27001 edition applies to your ISMS and reference control 5.21 specifically against the 2022 revision, documenting your basis for inclusion or exclusion in the Statement of Applicability.
Drive ICT supplier security requirements from your risk assessment, tailoring the depth of controls to the criticality of each supplier and product or service rather than applying a single uniform standard.
Define information security expectations in supplier agreements and, where appropriate to risk, extend consideration to sub-suppliers on whom your providers depend.
Establish monitoring and review activities to verify that agreed supplier security requirements continue to be met over the course of the relationship, with the frequency and rigor scaled to risk.
Consult ISO/IEC 27002 for detailed implementation guidance on 5.21, recognizing it is a guidance standard and not itself certifiable.
When aligning with SOC 2 vendor management or other frameworks, treat cross-framework mappings as partial and validate each requirement independently rather than assuming equivalence.