Direct Answer to the Question

The ISO 28000 certification process is a structured route to demonstrating that an organization has established, implemented, maintained, and continually improved a security management system. The applicable current edition is ISO 28000:2022, titled “Security and resilience — Security management systems — Requirements.” Certification is normally completed by an independent, accredited certification body after the organization has prepared its system, conducted an internal audit and management review, addressed findings, and passed a multi-stage external audit. The process is not merely a document review: auditors examine evidence that security risks are understood, controls are operational, responsibilities are assigned, incidents are managed, and improvement occurs over time.

Also worth reading: How Do Property Owners Navigate the Short-Term Rental Insurance Claim Process Successfully? · How Does an AI Insurance Broker Work, and What Should You Compare in 2026? · How Much Does Medigap Plan G Cost in 2026, and Is It Worth It?

Certification applies only to the organization and activities identified in the certification scope. An accredited body should state that scope on the certificate, and an organization cannot imply that the entire company or every shipment is covered unless those activities are genuinely included. The usual sequence is gap analysis, design and implementation, evidence-building, internal audit, management review, stage 1 audit, stage 2 audit, nonconformity closure, certification decision, surveillance audits, and recertification. A typical first-time project takes about 6 to 12 months, although larger, multi-site, or highly regulated organizations may need 12 to 18 months. The standard itself does not prescribe a fixed certification duration, audit frequency, or price.

What ISO 28000 Certification Actually Proves

ISO 28000 provides requirements for a security management system, which means it asks the organization to manage security systematically rather than relying entirely on individual habits. Its central concepts include organizational context, leadership, planning, risk assessment, security objectives, competence, awareness, documented information, operational control, incident management, emergency preparedness and response, performance evaluation, internal audit, management review, and improvement. Supply-chain security is especially prominent, but the standard is broader than cargo theft prevention alone. It may also address information, personnel, physical assets, business continuity, contractor risk, and other security concerns within the declared scope.

A certificate is evidence that a defined system met the standard at the time of audit. It does not prove that every shipment will be secure, that every crime has been prevented, or that cybersecurity has been perfected. Nor does it guarantee compliance with every legal requirement applicable to freight forwarding, warehousing, manufacturing, e-commerce, or insurance. Its practical value is that it gives customers, insurers, regulators, and trading partners a common description of how risk is managed, supported by a certification body’s independent sampling and findings. A mature certificate, active surveillance, and credible performance data are more informative than the mere possession of a PDF document.

The 2022 edition replaced the previous edition’s high-level structure with requirements aligned to the structure used by contemporary ISO management-system standards. This can make integration with ISO 9001 quality management or ISO 14001 environmental management easier, because common elements such as context, leadership, planning, performance evaluation, and improvement use familiar language. Integration still requires more than putting two manuals beside each other. Shared governance, compatible objectives, coordinated audits, coherent risk processes, and consistent documented information remain necessary.

How the Certification Process Works

Preparation normally begins with confirming why certification is needed and defining the intended scope. The scope should identify the legal entity, locations, functions, and security-relevant activities being assessed. An organization then compares its current arrangements against ISO 28000:2022 and performs a gap analysis. The gap should be treated as a management issue, not simply a backlog of missing forms. For example, if third-party screening data is required but quality is inconsistent, purchasing controls, service-level terms, training, monitoring, and escalation procedures may all need attention.

The organization establishes a security management system that fits its operations. This usually includes a documented scope, policies, risk methodology, inventories of assets and interested parties, security objectives, treatment plans, competence arrangements, communication rules, operational controls, incident procedures, business continuity arrangements, and performance indicators. The standard requires documented information, but excessive manuals can create false confidence. Evidence should reflect decisions and work actually performed: approved risk assessments, access records, training completion, screening outcomes, incident reports, audits, corrective actions, and management-review records are generally more useful than decorative policy text.

After the organization believes implementation is effective, it conducts an internal audit covering the full declared scope. A competent, objective internal auditor then performs a management review with the level of participation and information expected of top management. The external audit usually has two stages. Stage 1 checks readiness, scope, documentation, internal preparation, and the overall design of the system. Stage 2 evaluates implementation and effectiveness through interviews, observations, records sampling, and verification. If major nonconformities are found, the client must correct them and submit acceptable evidence. The certification body then makes an independent certification decision; passing the audit alone does not always equal immediate issuance.

FeatureInitial certificationRecertification and surveillance
Main purposeConfirm the system is established and effectiveConfirm it continues operating and improving
Typical timing6–12 months after substantial preparationRecertification commonly at the end of a 3-year cycle
Audit patternStage 1 followed by stage 2Periodic surveillance, with at least one audit per surveillance year under the usual 3-year model
Key evidenceScope, risk process, controls, internal audit, management reviewOperational records, incident trends, objectives, audits, corrective actions, management review
Main riskRushing implementation before the auditTreating surveillance as a paperwork exercise
## How Long Does Certification Take?

A realistic preparation period for a small or medium-sized organization is usually 6 to 9 months, while a 9- to 12-month plan is safer when multiple sites, complex contractor networks, significant IT systems, or several legal entities are involved. Very large organizations may require 12 to 18 months, particularly if they must redesign procurement, physical-access, employee-screening, or incident-escalation processes. These ranges measure readiness, not simply the duration of auditor attendance. External certification itself may involve only several audit days, but a short audit is possible only when evidence already exists.

Compressing the timeline can work when management ownership is clear, the scope is tightly defined, existing controls are mature, and internal evidence is readily available. It is risky when certification is demanded for a tender, event, or insurance transaction only weeks before the required date. Audit-day count is not a reliable measure of the project; one qualified full-time security professional may not be enough for a global organization, while a smaller operation may need only part-time support. Organizations should also allow time to resolve nonconformities because evidence of effectiveness may need to be demonstrated over time.

After certification, the body must remain within its surveillance and recertification rules. ISO 28000 does not itself establish a universal three-year certificate cycle, but three years is a common ISO certification-cycle structure, with surveillance activities conducted over that period. Exact intervals, audit hours, and rules should be confirmed with the selected certification body. A material change in scope, site, ownership, or system operation should be communicated to that body rather than waiting for the next scheduled visit.

What Does ISO 28000 Certification Cost?

There is no official ISO fee and no single market price. Certification costs include readiness work, internal auditing, management review, consultant support if used, external audit fees, travel, corrective actions, surveillance, and recertification. A small organization pursuing straightforward certification may encounter total project costs of roughly US$10,000 to US$30,000, while a larger or multi-site program may range from US$30,000 to US$100,000 or more. External audit quotations can vary substantially with employee count, number of sites, risk, scope complexity, travel, required languages, and the market in which the certification body operates.

These are planning ranges, not ISO tariffs, and quotations should be requested from more than one accredited provider. The cheapest offer may exclude travel, application or certificate fees, stage 1 and stage 2 audits, surveillance, recertification, taxes, or corrective-action verification. A consultant may charge a separate professional-services fee, and that expense should not be confused with certification itself. ISO does not certify organizations directly; an external certification organization does so. A valid certificate should identify an accredited certification body, and buyers or brokers should verify the certificate and accreditation status rather than relying on the logo alone.

Insurance can affect the commercial value of certification. An AI insurance broker can compare how different carriers interpret the standard, whether particular controls are required, and which documents will be requested during underwriting or claims preparation. Certification alone may not determine the premium, premium reduction, coverage terms, or eligibility for a particular product. The stronger result usually comes from pairing credible certification with loss-control information, claims history, security-control tests, continuity plans, and a clear explanation of the certified scope.

Comparison with Other Security Standards and Choices

ISO 28000 is a broad security management-system standard. Other standards may be more appropriate depending on the organization’s main exposure. ISO 27001 focuses on information security, ISO 27002 provides implementation guidance, ISO 22301 addresses business continuity, ISO 31000 concerns risk-management principles, and ISO 9001 concerns quality management. Some supply-chain organizations use ISO 28000 together with one or more of these standards. Selecting a narrower alternative does not automatically reduce total risk; it may simply match the question being asked more closely.

FeatureISO 28000:2022ISO 27001ISO 22301Internal control program
Primary focusSecurity management, including supply-chain risksInformation security managementBusiness continuity managementOrganization-specific operational controls
Certification availableYes, through a certification bodyYes, through a certification bodyYes, through a certification bodyNo formal third-party system certificate
Best fitLogistics, trade, manufacturing, warehousing, related supply chainsOrganizations managing information-security riskOrganizations needing continuity and recovery capabilityA business that does not yet need certification
Main limitationBroad and not proof of zero incidentsDoes not cover every physical or supply-chain issueDoes not comprehensively cover security managementOffers no independent certification evidence
A declaration of conformity is not equivalent to third-party certification. A supplier questionnaire or security plan is also not a management system, although either can be a useful first step. Certification is usually most defensible when it answers a defined business need, such as tender qualification, customer assurance, insurer due diligence, or internal governance. Organizations that face limited security risks may achieve better control by investing in operational measures first and using ISO 28000 later. Conversely, a regulated or customer-mandated program may justify earlier implementation because external deadlines and audit expectations are the real constraint.

Common Mistakes That Delay or Weaken Certification

The most frequent mistake is choosing the certificate before defining the business problem and scope. A scope that includes an entire global group when only one warehouse or process is ready can create major nonconformities. Another common error is purchasing templates without establishing ownership. Policies copied from another company will not satisfy the system if employees, contractors, and managers do not understand how the requirements apply to actual work. Certification bodies evaluate evidence and implementation, not document appearance alone.

Organizations also make the error of treating security as a compliance exercise controlled by one manager. Supply-chain security usually depends on purchasing, human resources, operations, IT, legal, quality, finance, and senior leadership. Weakly controlled service providers, inconsistent access rules, and unclear incident escalation can undermine the system. The design should identify how these functions interact, how risk decisions are made, and who has authority to act when controls fail.

Audit rushing is another frequent problem. Internal audits and corrective actions cannot be genuine if performed immediately before the external visit, and a stage 1 audit is not a substitute for operational history. Some organizations overreact to minor findings by creating excessive documentation, while others close them without checking effectiveness. A useful nonconformity response states the evidence of noncompliance, identifies the cause, implements action, evaluates results, and prevents recurrence where relevant. Management review should likewise consider changes, performance, incidents, audit results, risks, resources, and opportunities rather than merely signing a recurring agenda.

When to Act and How to Choose a Certification Partner

Certification is worth considering when security failures could disrupt contractual commitments, create material losses, trigger legal obligations, or damage confidence in the organization. It is especially relevant where customers require supplier assurance, insurers request structured risk evidence, or multiple logistics and contractor interfaces make consistent controls difficult. It may be less urgent where a business already has mature systems, no external requirement, and a small operating scope, although this should be tested rather than assumed. A useful trigger is not a date alone but a documented decision about the problem certification is intended to solve.

The first practical step is to identify the applicable obligations and obtain quotations from accredited certification bodies. The organization should ask about the proposed scope, methodology, days, total lifecycle fees, surveillance arrangements, auditor competence, travel, and treatment of multiple sites. It should also confirm whether the provider can demonstrate relevant accreditation for the standard and explain how independence is maintained. Marketing claims about guaranteed insurance savings, guaranteed regulatory acceptance, or automatic tender eligibility should be treated skeptically.

By October 2026, the relevant baseline is ISO 28000:2022, not an obsolete edition. A sound program begins with a limited but accurate readiness assessment, then builds controls into normal operations. In parallel, an insurance broker can assess carriers’ requirements, coverage gaps, and the evidence that can be reused. The best outcome is not simply a certificate: it is a defensible security system, honest scope, documented effectiveness, and continued improvement supported by surveillance and recertification.