What ISO 28000 covers
ISO 28000 is the international standard for a security management system for the supply chain. It gives organisations a structured way to identify and manage security risks across the movement and storage of goods — from theft, tampering and smuggling to wider disruption. The 2022 revision aligned the standard with the common ISO management-system structure, making it easier to integrate with quality, environmental and continuity systems.
It applies to any organisation in the supply chain that wants to demonstrate it manages security deliberately: logistics and transport operators, ports and terminals, warehousing and customs businesses among them.
What certification involves
Certification is a two-stage assessment that examines how supply chain security is managed in practice, typically including:
- A security risk assessment across the relevant parts of the supply chain
- Security controls and procedures for facilities, transport and goods handling
- Roles, responsibilities and training for security
- Incident management and continuity of secure operations
Surveillance audits across the three-year cycle confirm the system is maintained. It is part of the broader ISO Certifications portfolio ABS issues under IAS accreditation, and pairs naturally with continuity certification like ISO 22301.
Timeline & process
For most organisations, ISO 28000 certification takes around 12–16 weeks, depending on the number of sites and the complexity of the supply chain in scope. Each engagement begins with a fixed-price scoping call, and we send a proposal within 24 hours.
Common questions
Who needs ISO 28000?
Organisations involved in moving, storing or handling goods — logistics and transport operators, ports and terminals, warehousing, customs and freight businesses — where security through the supply chain is a customer or regulatory expectation.
How does ISO 28000 relate to other security standards?
ISO 28000 focuses on physical and operational security across the supply chain, while ISO 27001 covers information security. Many organisations that move both goods and data hold both, and ISO 28000 also complements ISO 22301.