What ISO 28000 Certification Actually Means

ISO 28000 certification is a third-party assessment that an organization has established and applies a security management system suitable for its operations. The applicable standard is ISO 28000:2019, Security and resilience — Security management systems — Requirements, although organizations should also check whether a documented amendment or national adoption affects their program. Certification is normally issued to the legal entity and the physical location assessed; it does not automatically cover every subsidiary, warehouse, product, or country. The system covers the deliberate and unintentional risks associated with security and resilience, including supply-chain threats, fraud, site disruption, and breaches of confidentiality. It is not an information-security standard in the ISO/IEC 27000 series, nor is it a guarantee that every attack will be prevented. Certification also does not mean that the organization has become insurer-certified, received government approval, or proved that its controls are perfect. Instead, it indicates that an independent certification body found documented controls, responsibilities, risk processes, internal audits, management review, and continual improvement that satisfy the audited ISO 28000 requirements. For an AI Insurance Broker, the value is primarily in structuring operational risk decisions, client due diligence, and evidence that security controls are reviewed rather than merely purchased.

Also worth reading: How Should You Prepare for ISO 28000 Certification in 2026? · How Does ISO 28000:2022 Certification Work for Supply Chain Security in 2026? · Illinois SR-22 Insurance Requirements: What Drivers Need to Know in 2026?

ISO 28000, ISO 27001, and Related Standards Compared

Choosing the wrong standard can create months of duplicated work because management-system standards share a common structure but examine different risks. ISO 27001 is designed specifically for information security and is recognized widely in cybersecurity procurement and tender processes. ISO 28000 addresses a broader set of security and resilience concerns within an organization’s operating environment. ISO 28004-1 gives guidance for implementing ISO 28000, but it is not a substitute for the requirements standard and is normally not independently certified. ISO 28001 concerns the security and resilience of management systems and may be relevant where a particular sector requires it, but ISO 28000 remains the central general requirements standard discussed in most ISO 28000 certification guides.

FeatureISO 28000 certificationISO/IEC 27001 certificationISO 31000 risk-management system
Primary focusSecurity and resilience across operationsProtection of information assetsRisk-management processes
Typical scopeWhole organization, site, or business unitInformation security management systemEnterprise or activity risk system
Supply-chain securityStrongly relevantRelevant where information or systems are affectedRelevant but not security-specific
CertificationYes, through independent assessmentYes, through independent certificationThe ISO 31000 framework itself is not certification criteria
Common buyerLogistics, manufacturing, ports, logistics services, and security-conscious businessesTechnology, finance, professional services, and data-intensive organizationsOrganizations needing a structured risk process
Main limitationBroad scope requires well-evidenced operational controlsDoes not cover every physical or business-continuity riskRisk criteria and treatments remain organization-specific
A company may use both ISO 28000 and ISO 27001 when it wants an enterprise-wide security-resilience system supported by a specialist information-security system. A shared governance model, common audit program, and linked risk register can reduce duplication. However, combining them does not make either certification automatic, and separate audits or statements of applicability may still be required. For an insurance broker, the decision should depend on client requirements and the risks being priced, not on the assumption that one certification is universally superior.

Requirements That an Auditor Will Examine

An ISO 28000 management system must be appropriate to the organization’s context and affected interested parties. The organization defines its scope, establishes security objectives, identifies and evaluates risks, determines controls, and maintains documented information needed to operate the system. Threats and vulnerabilities may include unauthorized access, loss of cargo, fraud, workplace violence, cyber incidents, supplier failure, natural hazards, and disruption of essential services. Unlike a generic checklist, ISO 28000 requires risk-based decisions tied to the organization’s operations and the level of security and resilience it needs to achieve.

The management structure should identify responsibilities and authorities, while competent personnel must have the knowledge and skills needed to perform assigned functions. Awareness matters because employees and contractors can affect control effectiveness even when they do not design security systems. The organization should establish processes for operational control, incident management, business continuity or continuity of activity, and continual improvement. Documented information is not prescribed as one rigid manual; it can include policies, procedures, risk registers, plans, records, internal audit reports, management-review minutes, and performance data. The evidence must demonstrate implementation rather than merely show that a template document exists. Internal audits must be planned at suitable intervals, conducted objectively, and reported to management. Management review should occur at planned intervals and consider audit results, changes affecting the system, performance against objectives, resource adequacy, risks, opportunities, and improvement actions.

The Certification Process From Gap Review to Audit

The first stage is usually a readiness or gap review against ISO 28000:2019. This should be performed against the organization’s actual scope, locations, activities, personnel, suppliers, and applicable legal or customer requirements. If certification is not yet necessary, the organization can still use ISO 28004-1 as implementation guidance. During preparation, management approves the scope and objectives, maps responsibilities, documents risk evaluation and control selection, trains relevant personnel, tests incident and continuity arrangements, and conducts an internal audit and management review. Evidence should be dated and traceable. A useful rule is to ask whether an auditor could follow the record from an identified risk to the selected control, assigned owner, monitoring method, incident response, and management decision.

A certification body then conducts the planned audit process defined by applicable ISO certification principles, including stage 1 and stage 2 activities. Stage 1 generally checks scope, context, readiness, and major gaps; stage 2 evaluates implementation and effectiveness. The exact sequence depends on the body, certification scheme, and organizational readiness. Nonconformities are classified according to the scheme and must be addressed through the defined corrective-action process. A major nonconformity can prevent certification until the issue is corrected and verified; a minor nonconformity may be accepted with a documented correction and later verification. The certificate is normally issued after successful completion of the certification decision process, not merely after the final audit visit. Organizations should use certification for operational improvement and evidence, but should not represent it as a promise of uninterrupted service or complete cyber protection.

Practical Timeline, Team, and Operational Preparation

A first-time organization often needs approximately four to nine months for meaningful preparation before the final certification audit, although three to twelve months is possible when the scope is complex. A simpler site with existing quality, safety, or risk systems may move faster. A fragmented business, multiple warehouses, major IT migration, or weak incident records usually takes longer. The organization does not need to replace every other management system. ISO 14001, ISO 45001, ISO 9001, ISO 27001, or a strong internal control environment can provide a foundation for shared governance, document control, audits, and management review. The key is to integrate security and resilience into existing processes rather than create a security department that operates apart from the business.

A practical core team normally includes an executive sponsor, security or resilience manager, operations representative, risk or compliance representative, information-security input, human-resources support, and site or facility representatives. Suppliers and contractors should be included when their conduct can materially affect the organization’s objectives. The team should set measurable objectives, such as completing annual training, closing critical corrective actions within defined periods, exercising continuity plans twice per year, or reviewing high-risk suppliers quarterly. Those numbers are examples, not ISO requirements; actual targets should reflect risk, legal duties, and operational capacity. Management must allocate time and resources for evidence collection, not only policy writing. Small organizations can use a lean team, but they still need enough independence and expertise to conduct meaningful internal audits.

Cost and Pricing: What Determines the Budget

There is no universal ISO 28000 certification fee because the price depends on employee count, number of sites, audit days, legal entities, geographic spread, risk, and whether the organization needs extensive preparation. A small organization with one straightforward site may see total consulting, audit, and internal preparation costs in the low five-figure range, while a multi-site or highly regulated enterprise may spend tens of thousands or more. Certification-body fees are only one component. Organizations may pay separately for gap analysis, consultant support, documentation, training, software, travel, corrective actions, surveillance audits, and management time. In some markets, certification costs are quoted per site or per employee band, so a written quotation based on a defined scope is more useful than a headline price.

The business case should be tested carefully. Certification can support customer confidence, tender qualification, supply-chain governance, incident response, and insurance discussions, but it does not automatically reduce premiums or eliminate losses. An AI Insurance Broker can use it as one control when comparing carriers, exclusions, limits, deductibles, wording, and security assumptions. The broker should ask for the certificate, issuing body, scope, expiry date, covered locations, and relevant nonconformity status, then verify claims through the accreditation route where applicable. ISO certification bodies should be assessed by an accreditation body recognized for the relevant certification scheme; ISO itself does not directly certify organizations. Buyers should be wary of certificates purchased without an audit, certificates that cover an undefined “global company,” or claims that certification guarantees compliance with every legal or customer requirement.

Common Mistakes That Delay Certification

One common mistake is treating ISO 28000 as a paperwork exercise. Downloading policies and naming a security officer do not demonstrate that risks are assessed or controls work. Another is copying a generic risk register that contains hundreds of theoretical risks but provides no ownership, treatment, residual-risk decision, or evidence of review. Organizations sometimes confuse ISO 28000 with ISO 28004-1, even though the latter is guidance rather than the requirements standard used for certification. Scope is another frequent problem: the certificate may state one site while the application, training, supplier controls, and management review are undocumented elsewhere.

A further error is waiting until shortly before an audit to conduct internal audits or management reviews. Those processes must operate as part of normal management, not as activities created only for the auditor. Weak corrective-action records are also problematic, particularly where findings remain open without root-cause analysis or effectiveness checks. Certification bodies should maintain independence and should not be offered gifts or participation in management decisions. Conversely, consultants must avoid guaranteeing certification or promising a particular outcome, since the decision belongs to the certification body. The organization should correct evidence gaps early, disclose significant changes to the auditor, and avoid treating the surveillance audit as the first serious review of the system.

When to Act and How an AI Insurance Broker Fits In

An organization should consider ISO 28000 when customers, contracts, regulators, insurers, or business partners require a formal security-resilience system, or when repeated disruption, fraud, cargo loss, vendor incidents, or site-security events reveal that informal controls are insufficient. It is also reasonable for a growing organization to prepare before a major tender, new warehouse rollout, acquisition, or insurance renewal. Conversely, a very small business with limited physical assets, few personnel, and modest contractual obligations may get more immediate value from proportionate risk controls, vendor screening, access management, backup testing, and incident procedures. ISO 28000 is not automatically justified for every organization, and a full certification program can consume resources that might be better spent on specific hazards or controls.

An AI Insurance Broker can help clients decide whether certification is relevant to the insurance program. The broker can compare quote assumptions about cyber controls, supply-chain resilience, business interruption, data exposure, and physical security against the client’s actual risk profile. Automated analysis can flag documents, claims, or inconsistencies, but it should not be presented as an independent conformity assessment. Certification evidence should inform—not replace—questions about loss history, controls, recovery time objectives, subcontractors, incident notification, exclusions, limits, and claims cooperation. This approach keeps the broker from hard-selling a certificate as a universal solution. It also helps clients understand that ISO 28000 can be one useful layer in risk management while insurer underwriting, contractual requirements, and tested recovery performance remain separate matters.

Final Decision Guidance and Verification Questions

Before committing, management should answer several questions in writing. Which legal entity and sites need certification? What events could seriously disrupt the business? Who owns each high-risk control? How will risk treatment and residual risk be approved? What records will prove that controls were implemented? How will incidents, continuity, audits, corrective actions, and management reviews connect? If the answers depend mainly on an auditor template, the organization is not ready. If the organization has a functioning system but lacks formal documentation, preparation may be straightforward. If there is no incident history, resilience testing, supplier review, or management commitment, certification should be treated as a multi-year improvement program rather than a quick certificate purchase.

After certification, the organization should monitor the certificate and surveillance schedule, maintain open communication with the certification body, and track changes to scope, ownership, locations, suppliers, products, threats, and applicable requirements. Renewal is not automatic; it depends on the certification process and successful surveillance and review. A certificate should be verified directly with the certification body or relevant accreditation records, not solely from a PDF on a supplier’s website. The most defensible position is that ISO 28000 provides an externally assessed framework for managing security and resilience. It can strengthen governance, customer confidence, and insurance discussions, but its business value comes from what the organization does with the system after the audit, not from displaying the certificate.