Get Your ISO 28000 Quote
ISO 28000 Certification cargo that arrives intact
Cargo goes missing, seals are broken, counterfeit parts turn up in a customer’s line. ISO 28000 certifies a security management system covering the whole movement of goods: threat assessment across routes and handovers, control over transporters and warehouses, and verification of the partners you never see.
You need ISO 28000 if…
- !A customer contract now carries chain-of-custody, anti-counterfeit or cargo security clauses you cannot currently evidence.
- !You are applying for or maintaining trusted trader status and need a documented security programme.
- !A load was stolen, diverted or tampered with, and the investigation showed nobody owned the handover.
- !Counterfeit components reached a customer and the source cannot be traced back through your supplier chain.
- !High-value or pharmaceutical cargo is being tendered and shippers score security controls before price.
- !Subcontracted hauliers and third-party warehouses operate outside any security requirement you have set.
A management system standard for security across the supply chain. It requires the organisation to assess security threats to people, goods, information and facilities along the flow of trade, and to control them through documented measures.
An accredited certification body such as SIS issues it. Customs authorisations are separate and granted by the customs authority, though much of the same evidence supports both.
Three-year certificate with annual surveillance audits covering the sites, routes and third parties inside the declared security scope.
Manufacturers, freight forwarders, hauliers, warehouse operators, port and terminal businesses, exporters and importers moving valuable, regulated or easily counterfeited goods.
Where this certification is demanded
ISO 28000 is applicable across 14 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.
What ISO 28000 Actually Requires
The backbone an implementer has to build, in the order it usually gets built.
Define the sites, routes, modes and third parties inside the system, along with the legal, customs and customer security requirements that apply to each of them.
Assess threats wherever goods change hands or stand still - loading, transit, transhipment, storage, delivery - against likelihood and the consequence of loss or tampering.
Documented security policy, named responsibility for security decisions, and authority that reaches into transport and warehouse operations rather than stopping at the fence line.
Access control, seal integrity and inspection, driver identification, container checks, alarm and camera response, and screening of staff and contractors in security-sensitive roles.
Documented criteria for selecting and checking transporters, warehouses, agents and suppliers, with security requirements written into contracts and then verified rather than assumed.
Procedures for theft, tampering, seal discrepancy and diversion, exercised and reviewed, with findings driving changes to controls instead of a report that closes itself.
How ISO 28000 Certification Works
No black box. A defined, time-bound route from first call to certificate in hand.
Application & Proposal
We scope on the goods, transport modes, number of facilities, countries crossed and how much movement is subcontracted. Subcontracted legs usually drive most of the audit effort.
1–2 daysGap Review & Readiness
Site security is usually the strong part. The exposure starts at the gate, where a subcontracted driver signs for a load and no one verifies the seal against the paperwork.
1–2 weeksStage 1 + Stage 2 Audit
Stage 1 examines scope, threat assessment and policy. Stage 2 follows a consignment through loading, sealing, transit records, storage and delivery, and tests the partner verification files.
Scheduled around operationsCertificate Issued
The certificate names the operations and locations covered. Surveillance then goes back to the routes and the third parties, because a haulier added mid-contract is where controls erode first.
Valid 3 yearsIndustries That Need ISO 28000
Commonly taken alongside
Not Sure Which Certification You Need?
Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.
Which sector best describes your organisation?
Scope the audit around who actually moves your freight
We do not quote supply chain security from a form. Owning the trucks or hiring them changes the audit more than tonnage does, and that needs a conversation.
Get My Free Quote →What ISO 28000 Changes for Your Business
Certification is not a certificate on the wall. It is a working system that pays for itself.
Loss and shrinkage down
Sealed and verified handovers make theft visible at the point it happens instead of at the delivery gate, where blame turns into an insurance argument.
Customs facilitation supported
Trusted trader programmes assess much the same controls, so a certified system provides most of the evidence and reduces the questions raised during an application.
Security clauses answered with evidence
Chain-of-custody and anti-counterfeit clauses can be answered with an accredited certificate rather than a policy document and a promise about subcontractors.
Counterfeits kept out
Supplier verification and controlled receipt make it far harder for a substituted component to enter production and reach a customer’s safety-critical assembly.
Subcontractors under control
Security requirements written into haulier and warehouse contracts, and then verified, close the gap where most cargo actually goes missing.
Evidence at insurance renewal
Documented controls and honest incident records give underwriters something to price against, which usually helps at renewal on high-value cargo.
Knowledge Base - Downloads
Practical documents prepared by our auditors. Fill the short form once and every download on the page unlocks.
Cargo security threat assessment checklist
Handover points, dwell locations and transport legs, with the questions to ask about each before writing any controls into the plan.
Transporter security requirements clause set
Contract language covering seals, parking, route deviation, driver vetting and the right to audit a subcontracted haulier without notice.
ISO 28000 and trusted trader alignment
Where certified controls map onto authorised operator criteria, and what customs will still want to inspect and see separately.
Where consignments actually go missing
Patterns behind theft and diversion at transhipment, unplanned stops and third-party storage, and the controls that interrupt them.
Frequently Asked Questions
Straight answers to what buyers ask before they commit to ISO 28000.
Does ISO 28000 give us trusted trader or AEO status?
What changed in the 2022 edition?
Do our hauliers need to be certified?
How does this differ from ISO/IEC 27001?
How long does certification take?
Will SIS advise on our security controls?
Secure the chain, certify the system
Chain-of-custody clauses get written by people who will never see your yard. The audit is where the wording meets the reality. Ask what that looks like for your operation.
Get My Free Quote → WhatsApp Us