Services / ISO 28000 certification
ISO 28000 supply chain security certification, from $800
For logistics providers, warehouses, ports, carriers and exporters that need to show customers and authorities how they manage security risks in the supply chain.
From $800Certified by EUROTECH

- Accredited by IAB and INTAQS
- Issuing certificates since 2004
- Online or on-site audits worldwide
- Verify any EUROTECH certificate
What ISO 28000 certification covers
ISO 28000 sets the requirements for a security management system. It was written with supply chains in mind and is used most by organizations that move, store or handle goods: freight forwarders, carriers, warehouses, port and terminal operators, packers and exporters. The current edition, ISO 28000:2022, broadened the standard so any organization can use it to manage security risks, inside or outside a supply chain.
The audit looks at how you identify security threats and vulnerabilities, assess the risks, and choose and run controls. Typical risks are theft, tampering with cargo, smuggling, unauthorized access to sites and systems, fraud in documentation and disruption by criminal or hostile acts.
Security controls in a supply chain are both physical and procedural. Fences, gates, lighting, cameras and seals matter, but so do personnel screening, access control, document checks, partner requirements and incident reporting.
- Stage 1 review of scope, security risk assessment and documented system
- Stage 2 on-site audit of physical, procedural and personnel controls
- Certification decision and three-year certificate
- Listing on verify.eurotechcertification.com
- Yearly surveillance audits and recertification
The certificate scope lists the sites and activities covered, for example warehousing and distribution of consumer electronics, or freight forwarding and customs brokerage services. Customers compare that scope with the services they buy from you.
On-site audit and how ISO 28000 relates to customs programmes
Because so many security controls are physical, ISO 28000 Stage 2 audits are carried out on site. The auditor needs to walk the perimeter, see how gates and loading docks are controlled, watch a container or trailer being sealed and check how visitors and drivers are handled.
Customs authorities run their own trusted trader programmes, such as the Authorised Economic Operator status in the European Union and the Customs Trade Partnership Against Terrorism in the USA. These are separate from ISO 28000 and are granted by the authorities, not by a certification body. A working ISO 28000 system does, however, cover many of the same security criteria and makes those applications easier to support with evidence.
ISO 28000 shares the high-level structure of other ISO management system standards. Logistics companies often combine it with ISO 9001 and ISO 14001, or with ISO 22301 for continuity, in an integrated system.
Information security is part of supply chain security. Shipment data, routes and schedules are valuable to criminals, so the auditor also checks who can see and change that data in your systems, and how access is removed when people leave.
What drives the price
ISO 28000 certification with EUROTECH starts at $800. Audit time depends on the size and spread of your operations.
- Number of people in scope, including security staff and drivers
- Number of sites: warehouses, terminals, depots and offices
- Activities: storage, transport, handling of high-value or dangerous goods
- Outsourced security services and subcontracted carriers
- Travel for on-site audits
We confirm audit days, travel and all fees in a written quote. A current risk assessment for each site and clear records of security incidents keep the audit efficient.
Sites that handle high-value goods or operate around the clock usually need more audit time, because the auditor must sample controls across shifts and check the higher level of protection those goods require.
How ISO 28000 certification works with us

Step 1
Scope and quote
We agree the sites, activities and routes in scope and quote the ISO 28000 audit in writing.

Step 2
Stage 1 review
We review your security risk assessment, procedures and partner requirements.

Step 3
Stage 2 site audit
The auditor walks the site and tests access, seals, screening and incident records.

Step 4
Certificate and surveillance
After the decision you receive the ISO 28000 certificate, with yearly surveillance audits.
Security risks and rules by region
We certify ISO 28000 for organizations in the USA, Europe, Asia and Africa. Threats differ by route and region: cargo theft hotspots, piracy on some sea lanes, smuggling routes, or political instability around certain ports. Your risk assessment should reflect the routes, sites and partners you actually use.
Legal requirements also differ, from customs security filing rules to aviation and maritime security regulations that apply at airports and ports. ISO 28000 requires you to identify these and to evaluate compliance, and the auditor samples that evaluation.
Customers in high-value sectors, such as electronics, pharmaceuticals and luxury goods, often set their own security requirements for carriers and warehouses. Bring those to the audit too, since the standard expects you to meet them.
If your customers or authorities ask for security declarations or partner questionnaires, the evidence gathered for ISO 28000, such as site risk assessments and partner checks, can be reused to answer them consistently.
What to expect on audit day
Expect a site walk early in the audit. The auditor will look at the perimeter and lighting, gate procedures, visitor and driver registration, key and card control, camera coverage and recording, and segregation of high-value or sensitive goods.
Procedures are then tested against records: seal logs and seal verification on arrival and departure, personnel screening files, training records, security incident reports and how they were investigated, and checks on business partners and subcontracted carriers.
The auditor may also review how shipping documents are protected against fraud and how IT systems that hold shipment data are secured.
Personnel security is checked as well: how new employees and temporary staff are screened where the law allows, how access rights are matched to roles, and how security awareness training is given to drivers, warehouse staff and office staff who handle shipping documents.
Findings are graded as major or minor, and the certification decision rests on the evidence. You receive a written report explaining each finding.
The closing meeting summarizes what was seen at each site and agrees dates for corrective actions on any minor findings.
Keeping the certificate
Security risks change with your routes, customers and partners. Review the risk assessment when you add a site, change a major route or take on a customer with high-value goods. Keep security training current, test alarms and emergency procedures and record every security incident, even minor ones.
Surveillance audits sample these records, the actions taken after incidents and any changes to sites or partners. Tell us about new sites in good time so they can be included in the audit plan.
Exercises help. A periodic drill, such as a simulated seal breach or an unauthorized vehicle at the gate, shows whether staff follow the procedure, and gives you evidence of effectiveness for the surveillance audit.
Questions buyers ask
How much does ISO 28000 certification cost?
With EUROTECH it starts at $800. People, sites, activities, outsourced security and travel set the final price.
Is ISO 28000 the same as AEO or C-TPAT?
No. AEO and C-TPAT are customs programmes granted by authorities. ISO 28000 is a certifiable standard that covers many of the same security criteria.
Which edition of ISO 28000 is current?
ISO 28000:2022, which extended the standard so any organization can use it to manage security risks.
Can the audit be done online?
Document reviews can, but Stage 2 is carried out on site because physical security controls must be seen.
Who uses ISO 28000?
Freight forwarders, carriers, warehouses, ports, terminals, packers and exporters, and any organization managing security risks.
Can ISO 28000 be combined with ISO 9001?
Yes. They share structure, and logistics companies often run them as one integrated system.
Related services
- ISO 22301 certification
From $800
- ISO 18788 certification
From $800
- Pre-shipment inspection
From $1,500
Get a quote for ISO 28000 certification
Tell us your company, sites and the standard you need. We reply with a written quote and the audit plan.
Prefer to talk? Call +1 307 205 1833
Monday to Friday, 09:00 to 18:00 (US Mountain Time)
