What is ISO 28000?
ISO 28000 is the international standard for security management systems, giving organizations in and around global supply chains a structured way to identify security threats, assess the risk they pose, and put controls in place to manage them. Think of it as the security counterpart to standards like ISO 14001 or ISO 9001, built specifically for the risks that move goods, people, and information through ports, warehouses, carriers, and customs points.
At its core, ISO 28000 doesn't dictate a fixed list of security measures. Instead it provides a risk-based framework, built on the same Plan-Do-Check-Act cycle used across ISO management system standards, that requires you to assess your specific supply-chain threats (theft, tampering, smuggling, cargo diversion, cyber-physical intrusion) and design controls proportionate to them.
Simple Analogy: If ISO 9001 is about consistently making a good product, ISO 28000 is about consistently protecting that product, and the people and information around it, as it moves through every hand-off in your supply chain, from raw material supplier to final customer.
Historical Context: ISO 28000 was first published in 2007 as "Specification for security management systems for the supply chain." It was revised in 2022 and retitled "Security and resilience, Security management systems, Requirements," broadening its scope beyond supply chains specifically, while remaining the standard most widely used by manufacturers, logistics providers, freight forwarders, ports, and customs intermediaries to demonstrate supply-chain security.
Why is ISO 28000 Certification Important?
Supply chains are attractive targets precisely because they are distributed: goods change hands between manufacturers, freight forwarders, carriers, warehouses, and customs brokers, and each hand-off is a point where cargo can be tampered with, stolen, or used to smuggle contraband. ISO 28000 gives you a way to assess those risks systematically across every link you control, rather than relying on the physical security practices of whichever partner happens to be weakest. Certification is also a trade-facilitation tool. It aligns with, and often supports qualification for, customs-security programs such as the US Customs-Trade Partnership Against Terrorism (C-TPAT) and the EU's Authorized Economic Operator (AEO) status, both of which can mean faster customs clearance and fewer cargo inspections. Large shippers, ports, and government contracts increasingly require ISO 28000 or an equivalent security certification from logistics partners before they'll do business with them. Beyond compliance, a working security management system reduces the direct cost of cargo theft, loss, and disruption, and shortens recovery time when an incident does occur, because response and continuity plans already exist instead of being improvised after the fact.
Key Insight
ISO 28000 certification signals to partners, customers, and customs authorities that your organization actively manages supply-chain security risk, rather than reacting to incidents after they happen. That distinction matters most at the moments it's tested: a theft, a tender requiring a security-certified vendor, or a customs audit.
What Are the Key Requirements of ISO 28000?
ISO 28000 sets out the requirements for a security management system for the supply chain. At its core, it asks your organization to identify security threats across your supply chain, assess their risk, put controls in place, and continually improve them. Key requirements include a documented security management policy, security risk assessment, defined roles and responsibilities, operational controls, and management review, all structured so an accredited auditor can verify them.
What Is the First Step in Implementing ISO 28000?
The first step is a gap analysis: a structured review of your current supply-chain security practices against the ISO 28000 requirements. It shows exactly where you already comply and where work is needed, and becomes the basis for your implementation roadmap. From there, Avantcert follows a four-stage path, Gap Analysis → Implementation → Internal Audit → Certification.
How Long and How Much Does ISO 28000 Certification Cost?
Most organizations achieve ISO 28000 certification in 8 to 16 weeks, with cost driven by the number of sites and the complexity of your supply chain. Avantcert gives you a tailored timeline and estimate up front, request a free ISO 28000 quote for a same-day number.
Key Principles
ISO 28000 is built around risk-based security management, guided by a set of principles that shape how the standard is implemented:
Risk-Based Security Assessment
Threats and vulnerabilities across the supply chain, theft, tampering, smuggling, cargo diversion, are systematically identified and assessed before controls are chosen.
Leadership & Security Policy
Top management commits to a documented security policy and objectives, and makes security an organizational priority rather than a delegated afterthought.
Operational Controls
Physical, procedural, and personnel security controls are applied consistently across facilities, transport, and information systems handling cargo data.
Emergency Preparedness & Resilience
Documented plans exist to detect, respond to, and recover from security incidents and supply-chain disruptions with minimal downtime.
Continuous Improvement
Incidents, near-misses, and audit findings are reviewed and fed back into the system so security controls strengthen over time rather than staying static.
Partner & Stakeholder Collaboration
Security requirements are coordinated with suppliers, carriers, and customs authorities, aligning with programs such as C-TPAT and AEO where relevant.
Risk-Based Security Assessment
Threats and vulnerabilities across the supply chain, theft, tampering, smuggling, cargo diversion, are systematically identified and assessed before controls are chosen.
Why it matters
Without a structured assessment, security spending tends to concentrate on whatever incident happened most recently rather than the risks that actually threaten the business. A documented threat and vulnerability assessment, covering facilities, transport routes, personnel, and information systems, ensures controls are targeted at your organization's real exposure, and gives auditors evidence that risk decisions were made deliberately.
Leadership & Security Policy
Top management commits to a documented security policy and objectives, and makes security an organizational priority rather than a delegated afterthought.
Why it matters
Supply-chain security fails at the hand-offs, between shifts, sites, and partner organizations, so it only holds together when leadership funds it, assigns clear ownership, and reviews performance directly. A security management system without visible leadership commitment tends to degrade into a paperwork exercise that lapses the moment budgets tighten.
Operational Controls
Physical, procedural, and personnel security controls are applied consistently across facilities, transport, and information systems handling cargo data.
Why it matters
A single unsecured hand-off, an unlocked yard, an unvetted driver, an unmonitored warehouse door, can undo controls everywhere else in the chain. ISO 28000 requires controls to be applied consistently end to end, including access control, seal and container integrity checks, and background screening for personnel with access to high-risk cargo or shipment data.
ISO 28000 Implementation Process
Avantcert implements your security management system end to end so your operations can keep running:
1. Scope & context, define the sites, transport modes, and supply-chain partners covered. 2. Threat & risk assessment, identify security threats and vulnerabilities and rank the significant ones. 3. Security policy & objectives, set the documented policy, roles, and measurable targets. 4. Operational controls & training, implement physical, procedural, and personnel controls and build security awareness. 5. Internal audit & management review, verify the system works before the certification audit.
ISO 28000 Certification Process
ISO 28000 certification is awarded by an independent, accredited certification body through a two-stage audit:
Stage 1, a documentation and readiness review of your security management system. Stage 2, the main audit, where the auditor tests that your risk assessments, policies, and operational controls are implemented and working across your sites and supply-chain partners. Surveillance, annual audits keep the certificate valid, with full recertification every three years.
Avantcert runs a pre-assessment and closes any gaps first, so both stages are a formality rather than a gamble.
Benefits of ISO 28000 Certification
Reduce cargo theft, tampering, and disruption losses; support qualification for trade-facilitation programs such as C-TPAT and AEO; win tenders and shipper contracts that require a certified security management system; and cut recovery time when a security incident does occur because response plans already exist.
Conclusion
ISO 28000 is more than a certificate to show freight partners. It's a structured way to find and close the security gaps that cargo theft, tampering, and supply chain disruption exploit, before they turn into losses, missed shipments, or failed customs audits. The journey to ISO 28000 certification requires a genuine risk assessment and leadership commitment, but the payoff, fewer incidents, faster customs clearance, and eligibility for security-conscious shippers' tenders, makes it a practical investment for any organization moving goods through a multi-party supply chain. Whether you're a single-site manufacturer or a multi-country logistics operator, ISO 28000 provides the framework to manage supply-chain security risk deliberately rather than reactively.
Getting Started with ISO 28000
Avantcert has supported 3,000+ organizations across 40+ markets on their certification and compliance journeys. For ISO 28000, our experts handle the heavy lifting, from gap analysis through implementation to accredited ISO 28000 certification, so your team can stay focused on the business.
Your timeline and cost depend on your size, scope, and current maturity. See our certification cost guide for the cost drivers, or use the free estimator for a tailored figure. When you’re ready, talk to an Avantcert ISO 28000 expert for a free quote and a clear roadmap.
ISO 28000 Certification FAQs
What is ISO 28000?
ISO 28000 is the international standard for a security management system for the supply chain. It helps organizations identify supply-chain security threats, control the associated risks, and demonstrate that control through accredited certification.
What is the first step in implementing ISO 28000?
A gap analysis, a structured review of your current supply-chain security practices against the ISO 28000 requirements. It identifies what already complies and what needs work, forming the basis of your implementation roadmap.
What are the key requirements of ISO 28000?
A documented security management policy, supply-chain security risk assessment, defined roles and responsibilities, operational controls, and management review, structured so an accredited auditor can verify them.
How long does ISO 28000 certification take?
Typically 8-16 weeks, depending on the number of sites and supply-chain complexity. A gap analysis gives you a precise, milestone-based timeline up front.
How much does ISO 28000 certification cost?
Cost depends on sites in scope and supply-chain complexity. Avantcert provides a tailored estimate rather than a generic quote, request a free quote.
About Avantcert
Avantcert is an accredited ISO and compliance certification consultancy that helps organizations achieve ISO 28000 certification through gap analysis, implementation, and accredited audit support. Avantcert has supported 3,000+ organizations across 40+ markets, following a proven four-stage methodology, Gap Analysis, Implementation, Internal Audit, and Certification. To begin your ISO 28000 certification, request a free quote or talk to an Avantcert expert.
Related certifications
Avantcert also helps organizations achieve these related standards, often alongside ISO 28000 as part of one programme: ISO 27001, SOC 2, SOC 1, CMMC 2.0, NIST CSF, HITRUST. Not sure which you need? Use the free estimator or talk to an expert.
Official reference: ISO, ISO 28000.
Ready to start your ISO 28000 journey?
Get expert guidance and resources to implement ISO 28000 in your organization