ISO Certifications

ISO 28000:2022 — Supply Chain Security Management

Implementation and certification-readiness support for a security management system for the supply chain — managing security risks across logistics, transport and the movement of goods.

Book a consultation
ISO 28000 supply chain security management implementation
12-16 weeks Indicative timeline — varies with scope, size, sites and shifts
ISO Governing body / standard owner
Advisory Consulting, training & audit readiness
What this covers
ISO 28000Supply Chain SecurityLogisticsResilience

What ISO 28000 covers

ISO 28000 is the international standard for a security management system for the supply chain. It gives organisations a structured way to identify and manage security risks across the movement and storage of goods — from theft, tampering and smuggling to wider disruption. The 2022 revision aligned the standard with the common ISO management-system structure, making it easier to integrate with quality, environmental and continuity systems.

It applies to any organisation in the supply chain that wants to demonstrate it manages security deliberately: logistics and transport operators, ports and terminals, warehousing and customs businesses among them.

What certification involves

Certification is a two-stage assessment that examines how supply chain security is managed in practice, typically including:

  • A security risk assessment across the relevant parts of the supply chain
  • Security controls and procedures for facilities, transport and goods handling
  • Roles, responsibilities and training for security
  • Incident management and continuity of secure operations

Surveillance audits across the three-year cycle confirm the system is maintained. It is part of the broader ISO Certifications portfolio ABS supports, and pairs naturally with continuity certification like ISO 22301.

Climate change: since ISO’s February 2024 climate action amendment (ISO 28000:2022/Amd 1:2024), the standard requires you to determine whether climate change is a relevant issue for your organisation, and notes that interested parties can have climate-related requirements. Certification audits include it.

How ABS helps

We prepare you for the certification audit in five steps, tailored to ISO 28000:

  • Scope and gap assessment — we agree the scope of your supply chain security management system and assess what you already have against the standard, so you know exactly what to close.
  • Implementation — we help you assess security risks across your part of the supply chain, set up security controls for facilities, transport and goods handling, define roles and training, and plan incident management.
  • Internal audit and management review — we help you run the internal audit and management review the standard requires, so the system has a record of operating before the audit.
  • Readiness check — a pre-assessment, approached the way an auditor would approach it, highlights anything still to close.
  • Audit support — we support you through the certification body’s Stage 1 and Stage 2 audits and help you close any findings.

Timeline & process

For most organisations, ISO 28000 certification takes around 12–16 weeks, depending on the number of sites and the complexity of the supply chain in scope. Each engagement begins with a fixed-price scoping call, and we send a proposal within 24 hours.

Common questions

Who needs ISO 28000?

Organisations involved in moving, storing or handling goods — logistics and transport operators, ports and terminals, warehousing, customs and freight businesses — where security through the supply chain is a customer or regulatory expectation.

How does ISO 28000 relate to other security standards?

ISO 28000 focuses on physical and operational security across the supply chain, while ISO 27001 covers information security. Many organisations that move both goods and data hold both, and ISO 28000 also complements ISO 22301.

How long does ISO 28000 certification take?

For most organisations, ISO 28000 certification takes around 12–16 weeks, depending on the number of sites and the complexity of the supply chain in scope.

What does ABS do, and what does the certification body do?

ABS prepares you for certification: we agree the scope of your supply chain security management system, assess the gaps, help you implement it, support your internal audit and management review, check readiness and support you through the audits. The certification body, an independent, accredited organisation you choose, carries out the Stage 1, Stage 2 and surveillance audits, makes the certification decision and issues the certificate.

How long is an ISO 28000 certificate valid?

Three years. The certification body carries out surveillance audits in the first and second years, and a recertification audit before the three-year cycle ends.

Which edition of ISO 28000 is current, and is there a transition?

The current edition is ISO 28000:2022, with the climate change amendment added in 2024. There is no transition under way.

More services

Related services

ISO Certifications / 01 ISO 9001 quality management system documentation review

ISO 9001 — Quality Management

The world's most widely adopted standard for quality management systems.

ISO 9001QMSQuality Management
Get a quote
ISO Certifications / 02 ISO 27001 information security management implementation

ISO 27001 — Information Security Management

Globally recognised certification for information security management systems (ISMS).

ISO 27001ISMSInformation Security
Get a quote
ISO Certifications / 03 Industrial facility managing environmental impact under ISO 14001

ISO 14001 — Environmental Management

The international standard for environmental management systems and measurable sustainability.

ISO 14001EMSEnvironmental Management
Get a quote

Get started

Ready to get certified?

Get a free, fixed-price quote within one business day. No obligation, no sales pressure, no follow-up spam — just a clear path to certification.

Book a 30-min consultation
24-hour response time Fixed price, multi-currency Consulting & audit readiness Remote & on-site delivery
Call us