Management System Certification

ISO 28000 – Security Management System for the Supply Chain

Secure the cargo, the route and the handover — not just the warehouse gate.

  • ISO 28000
  • Recognised internationally

About ISO 28000

What is ISO 28000?

ISO 28000:2022 specifies requirements for a security management system, with particular relevance to the supply chain. It addresses security threats across the whole movement of goods — facilities, storage, cargo handling, transport, transhipment, documentation and the partners involved at every handover.

The system requires a security risk assessment covering theft, pilferage, tampering, contraband and stowaway insertion, cyber threats to logistics systems, sabotage, and the security implications of your suppliers and subcontractors. From that assessment you apply controls: physical security and access control, personnel screening, cargo seal integrity, container inspection, transport route risk management, and security incident response.

The 2022 revision aligned the standard fully with the High Level Structure and broadened its framing beyond logistics operators to any organisation with security risk in its supply chain. It sits naturally alongside customs security programmes such as AEO in India and C-TPAT in the United States, which examine substantially overlapping controls.

Who needs this?

  • Freight forwarders, 3PL providers, CHAs and logistics operators
  • Warehousing, container freight station and inland container depot operators
  • Exporters and importers pursuing AEO or C-TPAT status
  • Port, terminal and shipping line operators
  • Manufacturers of high-value or theft-attractive goods
  • Organisations with extended or cross-border supplier networks

Why organisations certify

Key benefits of ISO 28000

What certification actually returns, stated specifically rather than generically.

Credibility

Certification is verifiable evidence of supply chain security governance for customers, insurers and customs authorities.

Market Access

Supports AEO and C-TPAT applications and is frequently required by international principals for logistics partner selection.

Risk Reduction

Systematic risk assessment across cargo, personnel and route reduces theft, tampering, contamination and contraband exposure.

Operational Efficiency

Fewer security incidents means fewer detentions, inspections and delayed shipments — the real cost of a security failure is usually the delay.

Customer Trust

Shippers entrusting high-value consignments select partners on demonstrable security, not on rate alone.

Regulatory Compliance

Provides structured evidence for customs, transport security and dangerous-goods security obligations.

How it works

Our process for ISO 28000

Every stage has a defined purpose, a realistic duration and a stated output.

  1. 01

    Application & Quotation

    2–3 working days

    You submit an application form covering scope, headcount, sites and shift pattern. We review complexity, confirm audit-day allocation against accreditation rules and issue a fixed quotation.

  2. 02

    Contract & Audit Planning

    1 week

    On acceptance we appoint a lead auditor with verified technical competence for your sector, agree audit dates and share the audit plan in advance.

  3. 03

    Stage 1 — Readiness Review

    1 day (typical)

    A documentation and readiness assessment: scope confirmation, review of your management system documents, internal audit and management review evidence, and identification of anything that would block Stage 2.

  4. 04

    Stage 2 — Certification Audit

    2–5 days (scope dependent)

    On-site assessment of the system in operation. We sample processes, interview staff, examine records and raise findings graded as major, minor or opportunity for improvement.

  5. 05

    Corrective Action & Decision

    2–4 weeks

    You close out any nonconformities with root-cause analysis and evidence. An independent certification decision-maker — not the audit team — reviews the file and grants certification.

  6. 06

    Certificate Issue

    3–5 working days

    A three-year certificate is issued and your organisation is listed on our public certified-client directory for verification by your customers.

  7. 07

    Surveillance & Recertification

    Annual

    Surveillance audits at 12 and 24 months confirm the system remains effective. A full recertification audit is completed before the three-year expiry.

Preparation

Documents required

What we will ask to see. Having these ready before Stage 1 is the single biggest factor in a certification that runs to schedule.

  • Completed and signed application form
  • Certificate of incorporation / business registration
  • Organisation chart and scope statement
  • Management system manual or equivalent documented information
  • Documented processes, procedures and work instructions
  • Internal audit reports covering the full scope
  • Management review minutes
  • Records of corrective actions and continual improvement
  • Applicable legal and regulatory licences for your activity
  • Security management policy and security objectives
  • Security risk assessment covering facilities, cargo, transport and partners
  • Physical security plan: access control, perimeter, CCTV, lighting
  • Personnel security screening and background verification records
  • Cargo handling, seal control and container inspection procedures
  • Transport and route security risk assessment records
  • Business partner security requirements and verification records
  • Security incident register, investigation and response records
  • Security awareness and training records

Not sure whether your scope is right?

Scope is the single thing most often got wrong, and it appears verbatim on your certificate. We will review yours before you apply, at no charge — it costs us less than fixing it at recertification.

Talk to a specialist

Common questions

ISO 28000 — frequently asked questions

Direct answers, including where the honest answer is inconvenient for us.

No. AEO status is granted by Indian Customs under CBIC following their own application and validation process. ISO 28000 certification does not confer it, but the control evidence overlaps substantially and organisations holding ISO 28000 typically find the AEO application materially easier to complete.

Any organisation with security risk in its supply chain can certify. The 2022 revision explicitly broadened the framing beyond logistics operators to manufacturers, retailers and service providers.

Question not answered here? Ask a certification specialist — we answer technical questions without requiring an enquiry first.

Talk to us

Talk to a certification expert

Tell us your scope and headcount and we will send a fixed quotation for ISO 28000 with the audit-day calculation shown.

  • Quotation within 2–3 working days
  • IAF MD 5 audit-day calculation included
  • Full three-year cycle cost, not just the first audit
  • Your details are used only to answer this enquiry

Including contractors and shift staff — this sets your audit days.

Tell us your scope, whether design is included, and any deadline you are working to.

Your details are used only to answer this enquiry. We do not sell or share them.

Next step

Ready to certify to ISO 28000?

We will scope it honestly, show you the calculation behind the price, and tell you plainly if the timeline you need is not achievable.