Not all key suppliers need to be ISO 27001 certified. Whether you require it depends on what they do for you, what data and systems they can access, and what your own regulatory and customer obligations are.
When ISO 27001 certification is typically justified
Requiring ISO 27001 (or an equivalent, formally audited information security framework) is more common when a supplier:
- Hosts or processes your production, quality, or product data in their own cloud or data center (for example, SaaS MES, IIoT, QMS, data historian, PLM integrations).
- Has remote access into your plant network or OT systems (for example, equipment vendors with remote diagnostics, integrators, managed service providers).
- Handles sensitive technical data (for example, export-controlled, ITAR/EAR, defense, or customer-classified drawings and specifications).
- Acts as a critical dependency for regulated records (for example, batch records, device history records, electronic signatures, NC/CAPA systems).
- Is explicitly required by your customers or contracts to hold ISO 27001 or equivalent certification.
In these cases, certification can provide a structured baseline, audit evidence, and some assurance that the supplier has a managed information security program. It does not guarantee security or compliance outcomes, but it reduces some third-party risk and assessment burden.
When ISO 27001 is usually not required
For many suppliers in manufacturing supply chains, ISO 27001 is not strictly necessary, for example:
- Make-to-print parts suppliers with no direct access to your systems, and who only receive limited drawings and work instructions.
- Suppliers providing standard catalog components with minimal or no proprietary information.
- Local service and maintenance providers with on-site-only access under supervision and no remote connectivity.
These suppliers still need appropriate controls, but that may be achieved through contractual requirements, basic security expectations, and periodic checks rather than full ISO 27001 certification.
Risk-based approach instead of a blanket requirement
In regulated, brownfield environments, a blanket requirement that all key suppliers be ISO 27001 certified is often impractical and may not be risk-proportionate. A more realistic pattern is:
- Classify suppliers by information and system risk
Segment suppliers by the sensitivity of data they handle, level of connectivity to your environment, and their role in regulated records or safety-relevant functions. - Define tiered requirements
For higher-risk tiers, require stronger evidence (for example, ISO 27001, SOC 2, IEC 62443 alignment for OT vendors, or customer-specific frameworks). For lower-risk tiers, require basic security controls and contractual commitments. - Use multiple assurance mechanisms
Combine ISO 27001 (when applicable) with security questionnaires, technical validations (for example, penetration tests, OT network segregation), and audit rights, rather than relying solely on a certificate. - Align with your own controls and architecture
Supplier security posture needs to be compatible with how your MES, ERP, PLM, QMS, and OT networks are actually integrated, not how you wish they were. Weak segmentation or legacy systems may change how risky a given supplier connection really is.
Constraints specific to regulated and long-lifecycle environments
In aerospace, defense, medical device, and similar sectors, insisting on ISO 27001 for all critical suppliers can conflict with other realities:
- Limited supplier pool: Niche process or special-geometry suppliers may be technically unique; excluding them for lack of ISO 27001 can be infeasible.
- Long equipment lifecycles: OEMs of legacy equipment that require remote support or firmware updates may not have ISO 27001 but are operationally irreplaceable.
- Validation and qualification burden: Shifting to an ISO 27001-certified alternative supplier can trigger requalification, validation, or recertification of parts, processes, or systems, with high cost and schedule impact.
As a result, many plants accept some suppliers without ISO 27001 and compensate with stricter technical and contractual controls, such as tighter OT segmentation, controlled file exchanges, and documented risk acceptance under change control.
Practical minimums to require even without ISO 27001
For key suppliers that are not certified, it is still reasonable to expect and verify:
- Documented information security responsibilities and basic policies.
- Access control practices (user management, MFA where applicable, role-based access).
- Patch and vulnerability management for systems that interact with your environment.
- Incident reporting obligations, including timelines and scope of notification.
- Secure data handling and retention for your drawings, NC programs, and records.
- Change control practices where their changes could affect your validated state.
These can be captured through contracts, security addenda, supplier quality agreements, or specific clauses in purchase orders, and can be tied into your existing supplier quality and audit programs.
How this coexists with existing MES/ERP/QMS stacks
In brownfield environments with mixed MES, ERP, PLM, QMS, and OT vendors, it is usually not realistic to replace tools or suppliers just to align everyone to ISO 27001. Instead, plants typically:
- Maintain a supplier-criticality and security-risk register.
- Use network segmentation, jump hosts, and controlled data interfaces to reduce reliance on supplier-side controls alone.
- Integrate supplier security checks into existing supplier quality and audit processes, rather than standing up a separate track.
- Apply change control when adding new cloud services or remote access paths, including explicit review of supplier certifications and security posture.
This approach acknowledges integration debt and regulatory constraints, while still driving the supply base toward better security practices, including ISO 27001 where it is most justified.
Bottom line
Your key suppliers do not all need to be ISO 27001 certified. For high-risk suppliers that host your critical data, have remote access, or handle sensitive regulated information, ISO 27001 (or equivalent) is often appropriate and sometimes contractually required. For others, a documented, risk-based set of security expectations and verification activities is usually more practical and better aligned to the realities of regulated, long-lifecycle manufacturing.