πŸ“ž +91 8882 213 680  |  βœ‰ [email protected]
Accredited Certification Body Β· IAS & IAF Member Β· Certificates Verifiable Online
Homeβ€ΊStandardsβ€ΊISO 28000

Get Your ISO 28000 Quote

Takes 30 seconds Β· a specialist responds within 2 business hours
Step 1 of 2
CertificationTrainingCompliance Audits
Not sure - guide me
ISO 28000
No spam. No obligation. A clear quote.
15,000+Certified Clients
30+Countries Served
IAS Β· IAFAccredited
ISO 28000:2022 Β· Supply Chain Security Management

ISO 28000 Certification cargo that arrives intact

Cargo goes missing, seals are broken, counterfeit parts turn up in a customer’s line. ISO 28000 certifies a security management system covering the whole movement of goods: threat assessment across routes and handovers, control over transporters and warehouses, and verification of the partners you never see.

You need ISO 28000 if…

  • !A customer contract now carries chain-of-custody, anti-counterfeit or cargo security clauses you cannot currently evidence.
  • !You are applying for or maintaining trusted trader status and need a documented security programme.
  • !A load was stolen, diverted or tampered with, and the investigation showed nobody owned the handover.
  • !Counterfeit components reached a customer and the source cannot be traced back through your supplier chain.
  • !High-value or pharmaceutical cargo is being tendered and shippers score security controls before price.
  • !Subcontracted hauliers and third-party warehouses operate outside any security requirement you have set.
What it is

A management system standard for security across the supply chain. It requires the organisation to assess security threats to people, goods, information and facilities along the flow of trade, and to control them through documented measures.

Who issues it

An accredited certification body such as SIS issues it. Customs authorisations are separate and granted by the customs authority, though much of the same evidence supports both.

Validity

Three-year certificate with annual surveillance audits covering the sites, routes and third parties inside the declared security scope.

Who gets asked for it

Manufacturers, freight forwarders, hauliers, warehouse operators, port and terminal businesses, exporters and importers moving valuable, regulated or easily counterfeited goods.

14of 25 industries

Where this certification is demanded

ISO 28000 is applicable across 14 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.

Defence IndustryFood and Food ProductsTransport and LogisticsSolar IndustryChemical IndustryElectricals and Electronics Industry+8 more

What ISO 28000 Actually Requires

The backbone an implementer has to build, in the order it usually gets built.

1
Security scope and context

Define the sites, routes, modes and third parties inside the system, along with the legal, customs and customer security requirements that apply to each of them.

2
Security risk assessment

Assess threats wherever goods change hands or stand still - loading, transit, transhipment, storage, delivery - against likelihood and the consequence of loss or tampering.

3
Policy and responsibility

Documented security policy, named responsibility for security decisions, and authority that reaches into transport and warehouse operations rather than stopping at the fence line.

4
Controls and countermeasures

Access control, seal integrity and inspection, driver identification, container checks, alarm and camera response, and screening of staff and contractors in security-sensitive roles.

5
Partner verification

Documented criteria for selecting and checking transporters, warehouses, agents and suppliers, with security requirements written into contracts and then verified rather than assumed.

6
Incident response and testing

Procedures for theft, tampering, seal discrepancy and diversion, exercised and reviewed, with findings driving changes to controls instead of a report that closes itself.

How ISO 28000 Certification Works

No black box. A defined, time-bound route from first call to certificate in hand.

Application & Proposal

We scope on the goods, transport modes, number of facilities, countries crossed and how much movement is subcontracted. Subcontracted legs usually drive most of the audit effort.

1–2 days

Gap Review & Readiness

Site security is usually the strong part. The exposure starts at the gate, where a subcontracted driver signs for a load and no one verifies the seal against the paperwork.

1–2 weeks

Stage 1 + Stage 2 Audit

Stage 1 examines scope, threat assessment and policy. Stage 2 follows a consignment through loading, sealing, transit records, storage and delivery, and tests the partner verification files.

Scheduled around operations

Certificate Issued

The certificate names the operations and locations covered. Surveillance then goes back to the routes and the third parties, because a haulier added mid-contract is where controls erode first.

Valid 3 years
Eight to fourteen weeks for most operators, longer where a large subcontractor base has to be brought under contractual security requirements - start those contract amendments now and you take weeks off the schedule.

Industries That Need ISO 28000

πŸ›‘οΈ
Defence Industry
Open full page β†’
Why it applies hereDefence supply chains face counterfeit parts, diversion and tampering in transit. ISO 28000 requires threat assessment across the movement of goods, controls over transporters and storage, and verification of upstream suppliers. This addresses the anti-counterfeit and chain-of-custody clauses that now appear routinely in defence procurement contracts.Typical trigger: Anti-counterfeit and chain-of-custody clauses
🍲
Food and Food Products
Open full page β†’
Why it applies hereFood supply chains face adulteration, substitution and temperature abuse in transit. ISO 28000 assesses these threats across transport, warehousing and third-party handlers and imposes verification controls, complementing the food defence and food fraud clauses that GFSI schemes require exporters to demonstrate.Typical trigger: Food defence; cold chain integrity
🚚
Transport and Logistics
Open full page β†’
Why it applies hereCargo faces theft, tampering, smuggling and diversion at every handover. ISO 28000 requires security threat assessment across routes, facilities and subcontractors, with access control, seal integrity and verification of partners. It aligns closely with AEO and customs trusted trader expectations and is often the deciding factor in high-value and pharmaceutical logistics contracts.Typical trigger: AEO alignment; high-value cargo
β˜€οΈ
Solar Industry
Open full page β†’
Why it applies hereSolar supply chains span multiple countries and face counterfeit components, cargo theft and increasingly strict scrutiny of upstream sourcing. ISO 28000 imposes threat assessment, supplier verification and chain-of-custody controls across transport and warehousing, supporting due diligence obligations buyers are now passing down.Typical trigger: Supply chain due diligence; component authenticity
βš—οΈ
Chemical Industry
Open full page β†’
Why it applies hereChemicals face theft, diversion for illicit use, tampering and transport incidents, with several product categories under precursor control regimes. ISO 28000 imposes threat assessment, transporter and warehouse controls and customer verification, supporting both regulatory and product stewardship obligations.Typical trigger: Precursor controls; product stewardship
πŸ”Œ
Electricals and Electronics Industry
Open full page β†’
Why it applies hereComponent supply chains face counterfeit parts, cargo theft and diversion, with counterfeit semiconductors a persistent industry problem. ISO 28000 imposes supplier verification, chain-of-custody and transport security controls, supporting the authenticity guarantees customers require in high-reliability applications.Typical trigger: Counterfeit components; high-reliability supply
⚑
Energy Industry
Open full page β†’
Why it applies hereFuel supply, spares and critical equipment movements face theft, tampering and disruption, while grid-connected assets face physical security threats. ISO 28000 imposes threat assessment across the supply chain with transporter and supplier verification, complementing critical infrastructure protection requirements.Typical trigger: Fuel and critical spares security
🧡
Textile Industry
Open full page β†’
Why it applies hereApparel supply chains face cargo theft, counterfeiting, transhipment fraud and increasingly strict origin verification. ISO 28000 imposes threat assessment, transporter and warehouse controls and supplier verification, supporting the chain-of-custody evidence buyers require for origin and duty preference claims.Typical trigger: Origin verification; cargo security
πŸš—
Automotive Industry
Open full page β†’
Why it applies hereAutomotive supply chains face counterfeit parts, cargo theft and tampering, with counterfeit safety-critical components a persistent liability concern. ISO 28000 imposes supplier verification, chain-of-custody and transport security controls, supporting the authenticity assurance OEMs and aftermarket distributors require.Typical trigger: Counterfeit parts; cargo security
πŸš†
Railways
Open full page β†’
Why it applies hereSpares, safety-critical components and fuel move through extended supply chains exposed to counterfeiting, theft and tampering, while freight operations carry customer cargo security obligations. ISO 28000 imposes threat assessment, supplier verification and transport controls across both.Typical trigger: Counterfeit components; freight cargo security
🚒
Import and Export Industry
Open full page β†’
Why it applies hereCross-border cargo faces theft, tampering, smuggling and diversion at every handover, and customs authorities reward verified security through trusted trader programmes. ISO 28000 requires threat assessment, transporter and warehouse controls and partner verification, aligning closely with AEO expectations and reducing inspection delays.Typical trigger: AEO alignment; customs facilitation
🏭
Manufacturing Industries
Open full page β†’
Why it applies hereInbound components and outbound finished goods face theft, counterfeiting, tampering and diversion. ISO 28000 requires threat assessment across transport, warehousing and third parties, with supplier verification and chain-of-custody controls that support the authenticity and security assurances customers now request.Typical trigger: Cargo security; component authenticity
πŸ›’οΈ
Oil and Gas Industry
Open full page β†’
Why it applies hereFuel, chemicals and critical spares move through supply chains exposed to theft, diversion and tampering, while facilities face physical security threats. ISO 28000 imposes threat assessment across transport, storage and third parties with supplier verification, complementing critical infrastructure protection requirements.Typical trigger: Fuel theft; critical infrastructure security
🚬
Tobacco Industry
Open full page β†’
Why it applies hereTobacco is a high-duty product facing theft, diversion into illicit trade and counterfeiting, with track-and-trace obligations in many markets. ISO 28000 imposes threat assessment, chain-of-custody, transporter controls and customer verification, supporting both regulatory and brand protection requirements.Typical trigger: Illicit trade; track and trace

Commonly taken alongside

Cargo security, continuity and information security fail through the same weak points - third parties, access and unverified people - so most operators certify them together and run one integrated audit programme instead of three.

Not Sure Which Certification You Need?

Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.

Question 1 of 3

Which sector best describes your organisation?

Scope the audit around who actually moves your freight

We do not quote supply chain security from a form. Owning the trucks or hiring them changes the audit more than tonnage does, and that needs a conversation.

Get My Free Quote β†’

What ISO 28000 Changes for Your Business

Certification is not a certificate on the wall. It is a working system that pays for itself.

πŸ“¦

Loss and shrinkage down

Sealed and verified handovers make theft visible at the point it happens instead of at the delivery gate, where blame turns into an insurance argument.

πŸ›ƒ

Customs facilitation supported

Trusted trader programmes assess much the same controls, so a certified system provides most of the evidence and reduces the questions raised during an application.

πŸ“

Security clauses answered with evidence

Chain-of-custody and anti-counterfeit clauses can be answered with an accredited certificate rather than a policy document and a promise about subcontractors.

πŸ”Ž

Counterfeits kept out

Supplier verification and controlled receipt make it far harder for a substituted component to enter production and reach a customer’s safety-critical assembly.

🚚

Subcontractors under control

Security requirements written into haulier and warehouse contracts, and then verified, close the gap where most cargo actually goes missing.

πŸ’Ό

Evidence at insurance renewal

Documented controls and honest incident records give underwriters something to price against, which usually helps at renewal on high-value cargo.

Knowledge Base - Downloads

Practical documents prepared by our auditors. Fill the short form once and every download on the page unlocks.

CHECKLIST

Cargo security threat assessment checklist

Handover points, dwell locations and transport legs, with the questions to ask about each before writing any controls into the plan.

TEMPLATE

Transporter security requirements clause set

Contract language covering seals, parking, route deviation, driver vetting and the right to audit a subcontracted haulier without notice.

PDF GUIDE

ISO 28000 and trusted trader alignment

Where certified controls map onto authorised operator criteria, and what customs will still want to inspect and see separately.

WHITEPAPER

Where consignments actually go missing

Patterns behind theft and diversion at transhipment, unplanned stops and third-party storage, and the controls that interrupt them.

πŸ”’ Documents are locked. Fill the form once to unlock every download.

Frequently Asked Questions

Straight answers to what buyers ask before they commit to ISO 28000.

Does ISO 28000 give us trusted trader or AEO status?
No. That status is granted only by a customs administration after its own assessment. What ISO 28000 does is build and evidence most of what those programmes examine: premises security, personnel checks, cargo handling controls, business partner assessment and incident procedures. Applicants with a certified system generally spend less time answering questions and reworking documentation during the application.
What changed in the 2022 edition?
The standard was restructured into the common management system format shared with ISO 9001 and ISO 45001, and its framing widened from supply chain security specifically towards security management generally, with the supply chain as the main application. In practice that means cleaner alignment with the systems you already hold and easier integration of context, leadership and audit requirements.
Do our hauliers need to be certified?
Not necessarily, but their performance sits inside your scope. The standard requires documented criteria for selecting transporters and warehouses, security requirements in their contracts, and verification that those requirements are met. Certified partners simplify that. Uncertified ones mean you assess and check them yourself, and the auditor will look for the records of it.
How does this differ from ISO/IEC 27001?
ISO/IEC 27001 protects information: systems, data and the confidentiality of what you hold. ISO 28000 protects the physical movement and storage of goods, plus the information that supports it, such as manifests and routing detail. They overlap where cargo data is exploited to plan a theft, which is why operators moving high-value freight often hold both.
How long does certification take?
Eight to fourteen weeks for a typical operator. The threat assessment and site controls come together quickly; the delay is usually contractual, because security requirements have to be added to haulier and warehouse agreements and then verified at least once. Start that conversation with your subcontractors before the audit is booked.
Will SIS advise on our security controls?
No. As an accredited certification body SIS audits, it does not consult, so it cannot design your controls, write the threat assessment or specify equipment. Security consultants do that work. SIS assesses the system against ISO 28000 and issues the certificate, which is what your customer, your insurer or a customs officer is actually asking to see.
πŸ’¬ WhatsApp Us
πŸ“ž CallGet Quote