# How Should You Prepare for ISO 28000 Certification in 2026?

Amelia Palmer · September 30, 2026

> What ISO 28000 Certification Actually Means ISO 28000 certification is a third-party assessment of an organization’s security management system for...

## What ISO 28000 Certification Actually Means

ISO 28000 certification is a third-party assessment of an organization’s security management system for the supply chain. The current applicable edition for certification purposes is ISO 28000:2013, which replaced ISO 28000:2006; organizations should therefore ask their certification body to confirm the exact standard and edition covered by its quotation and certificate. The standard is designed for organizations that may need to demonstrate controlled and repeatable processes for preventing or reducing supply-chain security incidents. Certification does not mean that every shipment is risk-free, that government authorities have approved the organization, or that cyberattacks and disruptions cannot occur. It provides external assurance that defined requirements have been implemented, evidence has been reviewed, and the management system operates as documented. The certification scope matters because a certificate may cover only one legal entity, site, warehouse, distribution center, or function. As of 1 October 2026, an organization should be preparing against the current ISO 28000 edition rather than assuming that the 2006 version is acceptable simply because it appeared in older software or consultancy material. A certificate issued by an accredited conformity-assessment body is generally more useful than an unaccredited supplier’s statement of conformity.

**Also worth reading:** [How Do You Prepare D4212 Gingivectomy Appeal Documentation After a Denial?](https://in-surely.com/knowledge/how_do_you_prepare_d4212_gingivectomy_appeal_documentation_after_a_denial.php) · [How Do I Prepare for the 2027 Medicare Enrollment and Open Enrollment?](https://in-surely.com/knowledge/how_do_i_prepare_for_the_2027_medicare_enrollment_and_open_enrollment.php) · [How Do You Prepare for a Strata Insurance Renewal Without Getting Stuck With Underinsurance?](https://in-surely.com/knowledge/how_do_you_prepare_for_a_strata_insurance_renewal_without_getting_stuck_with_underinsurance.php)

## Why Certification May Be Required and What It Does Not Prove

Customers often request ISO 28000 when they need a consistent way to evaluate how a supplier protects goods, information, buildings, transport operations, and other supply-chain assets. Tender documents, logistics contracts, security questionnaires, and supplier onboarding systems may refer to it as a screening, qualification, or assurance requirement. The business case is strongest when certification replaces repeated questionnaires, supports participation in customer-controlled supply chains, or reduces uncertainty about a supplier’s controls. However, certification should not be treated as a marketing guarantee. A buyer may still conduct risk assessments, inspect facilities, test business-continuity arrangements, review subcontracting, or demand additional controls based on the product and threat environment. The standard is not a cybersecurity framework, customs-compliance standard, transport-safety standard, or general insurance policy. It does not certify the security quality of an individual pallet, validate a supplier’s financial stability, or guarantee immediate recovery from a major disruption. For an insurance broker, this distinction is important: ISO 28000 can support a discussion about operational risk and control maturity, but it is only one input into underwriting and does not automatically determine premiums, limits, deductibles, or coverage availability.

## How the Certification Process Works

Preparation normally starts with a gap analysis against the applicable ISO 28000 requirements and the organization’s intended scope. The organization then documents its security-management system, assigns responsibilities, trains personnel, controls records, assesses risks, and implements the selected measures. An internal audit and management review provide evidence that the system is being used, not merely created to obtain a certificate. Stage 1 audit typically examines readiness, scope, documentation, and the main processes; stage 2 audit evaluates implementation and effectiveness at the sites within the certified scope. If nonconformities are identified, the organization must investigate their causes, correct the issues, and provide evidence that the corrective actions were completed. The certification body then makes its certification decision, after which surveillance audits normally occur under the applicable ISO/IEC and accreditation rules. A three-year certification cycle is common, with surveillance and recertification requirements set by the certification and accreditation framework rather than by ISO 28000 alone. Exact stage timing depends on site size, number of employees, process complexity, documentation maturity, audit findings, and the certification body’s schedule. Certification bodies should be able to explain the applicable audit method, accreditation status, sampling rules, nonconformity process, and appeal process before accepting an engagement.

## A Practical Preparation Method

Begin by defining the assets, processes, locations, legal entities, suppliers, contractors, and interfaces that belong within scope. Scope creep can be costly, while an artificially narrow scope may not satisfy customers whose stated requirement covers warehousing, distribution, manufacturing, or procurement operations. A cross-functional team should then identify applicable risks and existing controls, preferably drawing on incident records, customer requirements, threat assessments, asset registers, access controls, route information, and continuity plans. The team must translate those findings into documented procedures rather than copying generic templates; generic policies may pass a superficial review but fail an effectiveness audit. Implementation records should demonstrate that responsibilities are assigned, approvals occur, training reaches relevant personnel, access is reviewed, deviations are handled, and corrective actions close identified gaps. An internal audit should occur early enough to reveal weaknesses and leave time for improvement, while management review should include measurable evidence such as incident trends, audit results, objective achievement, supplier performance, and resource decisions. Many organizations benefit from using both management-system and cyber-security frameworks, but overlapping documentation should be simplified. ISO 28000 addresses supply-chain security, so a separate ISO/IEC 27001 certification is an option only when the organization independently needs auditable information-security controls; it is not a replacement for ISO 28000.

## Certification Routes and Alternative Approaches

There is no single “ISO certificate” that all providers issue equally. Organizations should distinguish certification by an accredited certification body from consultancy, training, software templates, pre-assessment, and informal endorsements. ISO/IEC 17021-1 provides the general requirements for bodies providing audit and certification of management systems, while IAF or regional accreditation arrangements determine whether a provider’s competence is formally recognized. The accreditation status of a certificate can be checked with the certification body and the relevant national accreditation database, not merely from a logo on a proposal. Other approaches may be more proportionate depending on the transaction. A customer-defined security questionnaire can address a specific procurement relationship, while a recognized security-management certification may be more useful when the organization needs broad, repeatable assurance across customers and sites. ISO 28000-1:2022 provides guidance on implementing a security management system for the supply chain, but guidance is not itself a certifiable requirements standard.

| Feature | ISO 28000 certification | Customer questionnaire or self-assessment | Alternative management-system certification |
| --- | --- | --- | --- |
| Assurance | Independent audit by a certification body | Mainly internal or customer review | Independent audit under another standard |
| Supply-chain focus | Central to the standard | Depends on the customer | May only partly address supply-chain security |
| Cost and effort | Usually higher due to audit and system work | Usually lower for one transaction | Varies by scope, sites, and standard |
| Customer recognition | Often useful where ISO certification is specified | Useful for tailored requirements | Valuable where another framework is mandated |
| Main limitation | Does not eliminate security risk | No independent certificate | May not satisfy an ISO 28000 requirement |

The organization should not choose ISO 28000 solely because it sounds prestigious. If the real need is stronger governance, measurable risk reduction, or better operational performance, an internally managed system with targeted external validation may deliver more value than certification. Conversely, if a tender requires a valid certificate, supplier portal record, or approved scope, informal alternatives may not meet the requirement. The decision should identify the requesting customer, contractual deadline, required issuing body, site coverage, version, accreditation expectation, and consequences of non-compliance before the budget is approved.

## Common Mistakes That Delay Certification

A frequent error is purchasing a document package before understanding the organization’s actual operations. Templates cannot establish ownership, resolve contradictory procedures, train warehouse staff, control privileged access, or demonstrate corrective action. Another common mistake is treating ISO 28000 as a technical IT-security specification and focusing almost entirely on firewalls and passwords, while neglecting physical security, route or transport risks, supplier controls, personnel screening where lawful, incident response, and business continuity. Scope misstatements also cause difficulty: the certificate may exclude a warehouse, third-party logistics provider, or manufacturing line that the customer considers essential. Organizations sometimes select a certification body using price alone, fail to verify accreditation, or accept a proposal that does not identify excluded or outsourced processes. Other weak points include incomplete records, an internal audit performed immediately before the external audit, management review lacking real decisions, training evidence that proves attendance but not competence, and corrective actions that close paperwork without addressing causes. Finally, teams may wait until the customer deadline before beginning, leaving insufficient time to resolve major nonconformities and complete the certification decision.

## Timeframes, Costs, and Certification-Body Selection

A well-run, relatively mature organization may need roughly 3 to 9 months for preparation and certification, while a multi-site or operationally complex organization may require 9 to 18 months or longer. These are planning ranges, not ISO-set deadlines. The readiness stage can be shorter where documented systems, internal audits, trained personnel, and prior management-system certification already exist. Cost likewise cannot be quoted responsibly without knowing the number of sites, employees, shifts, countries, outsourced processes, travel requirements, risk complexity, and desired schedule. Certification-body fees are often presented only after a scope review, and implementation support from consultants is separate from the audit and certification fees. Illustrative project budgets can range from approximately USD 10,000 for a small, simple scope to USD 100,000 or more for a broad or multi-site program, but these figures are not official ISO prices and may be far below or above actual local quotations. The organization should request a written proposal separating consultancy, documentation, training, translation, internal audit preparation, stage 1 audit, stage 2 audit, travel, certificate fees, surveillance, and recertification costs. Cheap certification that cannot be supported by the relevant accreditation framework may create a false procurement advantage and a later replacement problem.

## When to Act and How an Insurance Broker Can Help

An organization should start preparation when a current customer, tender, contract, or insurer makes ISO 28000 a condition of participation, when a material security incident has exposed weak governance, or when the business plans significant supplier, site, or logistics expansion. If a certification deadline is fixed, work backward from that date and allow time for the two audit stages, nonconformity responses, management review, certification decision, and customer upload or verification. Even without an immediate external requirement, a readiness project can be useful if it identifies vulnerabilities that affect interruption losses, cargo exposure, contractual penalties, or insurance terms. An insurance broker should not represent a certificate as a promise of lower premiums. Instead, the broker can compare its scope and validity with the organization’s actual exposures, identify gaps that remain, and ask underwriters what evidence they accept. Brokers can also connect the organization with qualified implementation specialists and certification bodies, while keeping compliance advice distinct from underwriting advice. The sensible objective is controlled, evidence-based risk management supported by credible assurance—not possession of a certificate that the organization has not earned and cannot sustain.

As of 1 October 2026, organizations should confirm the current status of ISO 28000, the applicable certification rules, and the accreditation of their chosen provider before committing to a deadline. The strongest preparation strategy is to use the standard to improve real security decisions, then test those decisions through internal audit and an independent assessment. If a customer requires ISO 28000, obtain the requirement in writing and define the exact certificate scope. If no customer requires it, compare the expected commercial return with the cost and management attention involved, and consider a proportionate internal program first. Either way, document residual risks, incident response, supplier governance, and continuity measures so that certification remains a reflection of operating discipline rather than a one-time administrative achievement.

## Quick answers

### Is ISO 28000:2026 a new certification standard?

As of 1 October 2026, organizations should verify the current ISO publication and certification status before beginning a project. The widely referenced current requirements edition is ISO 28000:2013, while ISO 28000-1:2022 is guidance for implementation. A certification body should state precisely which edition and standard type it will audit.

### Does ISO 28000 certification guarantee lower insurance premiums?

No. Certification may help an insurer understand that security-management processes exist, but underwriters still assess the organization’s controls, loss history, business continuity, cargo exposure, locations, suppliers, and coverage requested. Premiums and terms therefore depend on the insurer and the full underwriting picture.

### How long does ISO 28000 certification take?

A small or mature organization may complete preparation and certification in about 3 to 9 months, while complex or multi-site programs may take 9 to 18 months or longer. Timing depends on documentation, risk complexity, audit findings, management reviews, corrective actions, and the certification body’s schedule.

### Can one certificate cover several warehouses?

It can if they are within the organization’s defined and auditable certification scope and the certification body applies the relevant multi-site rules. A certificate that covers only the headquarters, while omitting a customer-critical warehouse, may not satisfy the customer’s requirement.

### Is ISO 28000 the same as ISO 27001?

No. ISO 28000 concerns security management across the supply chain, while ISO/IEC 27001 concerns information-security management systems. Some controls may overlap, but ISO 27001 does not automatically establish ISO 28000 certification or cover every physical and logistical security risk.

Canonical: https://in-surely.com/knowledge/how_should_you_prepare_for_iso_28000_certification_in_2026.php
Markdown: https://in-surely.com/knowledge/how_should_you_prepare_for_iso_28000_certification_in_2026.php/index.md
