What is ISO 28000?

ISO 28000 is the international standard for a security management system for the supply chain. It gives an organization a structured, risk-based way to identify security threats across the flow of goods, people, information and finance — and to put controls, roles and review in place to manage them. The current edition, ISO 28000:2022, is the version certification bodies audit against today.

The idea behind it is straightforward. Supply chains are long, exposed and full of handoffs — warehouses, ports, carriers, subcontractors, border crossings — and each link is a place where cargo can be stolen, tampered with, smuggled through, or disrupted. ISO 28000 asks you to understand those threats in your context, decide how to treat them, and run a management system that keeps those decisions working over time rather than reacting after an incident.

Because it shares the same high-level structure as ISO 9001 and other modern ISO standards, it fits neatly alongside quality, environmental and safety systems. Certification is granted by an accredited certification body after a two-stage audit, and the certificate is typically valid for three years with annual surveillance visits in between. It is sector-neutral, so it suits a logistics operator, a manufacturer, a port terminal or a distributor equally well.

Who needs ISO 28000?

ISO 28000 is not legally mandatory, but it has become a recognized way to prove that security is managed rather than assumed. If your customers, insurers or regulators keep asking how you protect goods in transit and storage, this is usually the answer they are looking for. It is especially valuable for:

  • Logistics, freight forwarding and transport operators moving cargo across borders and modes.
  • Ports, terminals, warehouses and distribution centres where goods are handled, stored and transferred.
  • Manufacturers and exporters whose products move through long or high-value supply chains.
  • Importers and distributors that need confidence in the security of their upstream partners.
  • Shipping lines, airlines and courier firms whose whole value proposition is safe, uninterrupted delivery.
  • Any organization bidding for contracts, tenders or partnerships that name supply-chain security as a prerequisite.

A useful test: if theft, tampering, smuggling or a disrupted shipment would seriously hurt your customers, your margins or your reputation, ISO 28000 is worth having.

What ISO 28000 requires

ISO 28000 follows the familiar management-system pattern, so the core clauses will feel recognizable if you already hold ISO 9001. In plain terms, it asks you to:

  • Understand your context and interested parties — the security environment you operate in, and who has a stake in it, from customers to regulators to insurers.
  • Define the scope of your security management system — which sites, operations and parts of the supply chain are covered.
  • Show leadership and set a security policy that top management genuinely owns, with clear roles and responsibilities.
  • Run a security risk assessment and treatment process — identify threats such as theft, tampering, unauthorized access, smuggling and disruption, evaluate them consistently, and decide how to treat each one.
  • Plan resources, competence and awareness so people understand their part in keeping the chain secure.
  • Operate security controls day to day — access control, cargo and facility security, vetting of personnel and suppliers, incident handling and business continuity, sized to your risks.
  • Monitor, measure, audit and review — internal audits, management reviews, and handling of nonconformities, incidents and corrective actions.

Crucially, the depth of each control should match your risk, not a checklist. A regional distributor and a global freight forwarder can both be compliant with very different implementations. The standard is about proving you have thought through your threats and manage them deliberately — not about applying a fixed set of measures everywhere.

Why get ISO 28000 certified

The strongest reason most of our clients pursue ISO 28000 is commercial: it wins and protects business. Customers and partners increasingly want assurance that the goods passing through your hands are secure, and a recognized certificate can replace repeated custom security audits and questionnaires — shortening the vetting that used to stall partnerships for weeks.

Beyond deals, certification gives you a genuine reduction in risk. Going through a real security risk assessment surfaces gaps you did not know you had — an unmonitored loading bay, an unvetted subcontractor, no tested response plan for a hijacked shipment — and forces them to be owned and closed. It also demonstrates due diligence to insurers and regulators, and can support smoother dealings with customs and trade programs.

Internally, a security management system ends the guesswork. Protecting cargo stops being one person's vigilance and becomes a repeatable system with clear ownership, measurable objectives and a review rhythm. And because ISO 28000 shares its structure with other ISO standards, it becomes a backbone you can extend toward quality, continuity and safety obligations without starting over.

How QSE gets you certified

We have spent more than 30 years helping organizations get certified, with 900+ clients certified and a 100% first-time pass rate at the certification audit. Our 10-Step Approach turns ISO 28000 from an intimidating framework into a clear, week-by-week path.

We start by understanding your operations, your supply-chain flow and your real threats — not a generic template. Then we run a gap assessment against ISO 28000:2022, build a right-sized security management system, and facilitate the risk assessment with your team so the decisions are genuinely yours. Our documentation is deliberately lean: a single-level system, typically under 200 pages, written for the people who actually use it rather than to impress an auditor.

From there we help you implement the selected controls, train your staff, run internal audits and a management review, then support you through both Stage 1 and Stage 2 of the certification audit. A typical project runs 4–9 months depending on your size, number of sites and starting maturity. When we are done, you hold the certificate — and you own a system your team can actually run afterward, without depending on us forever.

Common pitfalls we help you avoid

  • Buying a template pack and calling it a system. Auditors spot generic documentation instantly, and it will not reflect your real supply-chain threats. We build the system around your operations.
  • Treating it as a guard-and-gate exercise. ISO 28000 covers people, suppliers, information and continuity too — not just physical fences. It needs leadership ownership, not only the security team.
  • A risk assessment nobody understands. If your team cannot explain how threats were scored, the audit will expose it. We facilitate it so it is yours.
  • Ignoring subcontractors and partners. Your chain is only as secure as its weakest link; unvetted third parties are a common gap. We help you extend controls across the handoffs.
  • Skipping internal audits and management review. These are mandatory and are common reasons for a failed or delayed audit. We run them with you before the certification body arrives.
  • Over-documenting. Thick manuals no one reads become findings, not strengths. Lean, usable documentation passes audits and survives real life.
  • Forgetting it is ongoing. Surveillance audits come every year. We leave you with a system that keeps working, not a one-off scramble.