What is ISO 28001?

ISO 28001 is the best-practice standard for security management in the international supply chain. Its full framing is instructive: best practices for implementing supply chain security, assessments and plans. Where ISO 28000 gives you a management system, ISO 28001 gives you the method for the two things that system exists to produce — a documented security assessment and a documented security plan.

The standard works through the supply chain as a sequence of stages and asks, at each one, what could go wrong and what you have done about it: cargo handling, storage, transport, transfers of custody, documentation and information flows. It is explicitly aligned with the concept of the Authorized Economic Operator used by customs administrations worldwide, and with the WCO Framework of Standards — which is why it maps well onto programmes like C-TPAT.

Put simply: ISO 28000 is the system, ISO 28001 is the analysis. Most organizations should implement them together, and in practice we usually do.

Who needs ISO 28001

It is a fit for:

  • Manufacturers and exporters shipping internationally
  • Freight forwarders, consolidators, NVOCCs and third-party logistics providers
  • Carriers across sea, air, road and rail
  • Port and terminal operators and warehouse operators
  • Importers needing to evidence security across a multi-tier supply chain
  • Organizations pursuing AEO status or a national equivalent
  • Companies already in or applying to C-TPAT who want an internationally recognized standard behind the same work

The common trigger is a customer or a customs administration asking for documented evidence that you have assessed your supply-chain security risk — not merely that you have locks and cameras, but that you know where your chain is vulnerable and what you decided to do.

What ISO 28001 requires

The core of it is a disciplined, documented method:

  • Define the scope of the supply chain you are securing — the origin points, routes, custody transfers and destinations
  • Identify security threat scenarios at each stage: theft, tampering, unauthorized access, smuggling, contamination, stowaways, unmanifested cargo, information compromise
  • Assess the risk of each scenario — likelihood and consequence
  • Select countermeasures proportionate to the assessed risk, rather than applying uniform controls everywhere
  • Produce the supply chain security plan, documenting the controls, who owns them and how they are verified
  • Designate a security officer with defined responsibility
  • Control custody transfers — the points where cargo changes hands, which is where most loss and tampering occurs
  • Manage business partners — security requirements passed to and verified with carriers, suppliers and service providers
  • Verify and review — testing that the plan works and updating it as routes, partners and threats change
  • Document evidence sufficient to support an AEO or customs application

The graded, risk-proportionate approach is the point. A shipment moving through a stable route with a long-standing partner does not need the controls appropriate to a high-risk transhipment.

Why implement it

Customs and trade facilitation. ISO 28001 is designed to support AEO applications and aligns with the WCO framework, so the assessment work you do feeds directly into applications for customs benefits — reduced inspections, faster clearance, priority treatment.

One assessment, many audiences. Customers, insurers, customs authorities and internal risk committees all ask versions of the same question. A properly documented ISO 28001 assessment answers all of them from a single source, rather than being re-derived for each request.

Loss reduction. Cargo theft and tampering are real costs, and they cluster at custody transfers — exactly where ISO 28001 forces you to look. Clients frequently find the assessment surfaces vulnerabilities nobody had articulated, often at handover points that everyone assumed were somebody else's responsibility.

Credibility with partners. Being able to hand a customer a documented security assessment and plan is materially more persuasive than a statement that you take security seriously.

How QSE implements it

We bring 30+ years of building management systems and 900+ organizations certified. Our default recommendation is to implement ISO 28001 together with ISO 28000, so you get the certifiable management system and the assessment method as one project with one set of documentation — rather than paying twice to document the same risks.

We start by mapping your actual supply chain, which is often the most revealing part of the exercise: routes, partners, custody transfers and information flows, as they really operate rather than as the process document describes. Then we run the threat-scenario identification and risk assessment with your team, select proportionate countermeasures, and write the security plan.

We build in business-partner requirements and verification, train your security officer and the staff handling cargo and documents, then audit the plan against reality before a certification body or customs authority does. Where you are also pursuing C-TPAT or AEO status, we align the evidence so one body of work serves all of them.

Most organizations complete implementation in about 4 to 7 months.

Common pitfalls we help you avoid

  • Implementing ISO 28000 with no real ISO 28001 assessment underneath it — a management system managing nothing in particular
  • A generic threat list copied from a template instead of scenarios specific to your routes and partners
  • Uniform controls everywhere, which wastes money on low-risk stages and under-protects high-risk ones
  • Ignoring custody transfers, where most loss and tampering actually happens
  • Security requirements sent to business partners with no verification that they were met
  • A security plan written once and never updated as routes, carriers and threats change
  • Documenting the same risks separately for ISO 28000, ISO 28001, C-TPAT and AEO — do it once
  • Treating information and documentation security as out of scope, when manifest and document manipulation is a primary attack route