# ISO 28000 Certification Guide: Requirements, Costs, and Certification Steps in 2026?

Amelia Palmer · October 1, 2026

> What ISO 28000 Certification Actually Means ISO 28000 certification is a third-party assessment that an organization has established and applies a...

## What ISO 28000 Certification Actually Means

ISO 28000 certification is a third-party assessment that an organization has established and applies a security management system suitable for its operations. The applicable standard is ISO 28000:2019, Security and resilience — Security management systems — Requirements, although organizations should also check whether a documented amendment or national adoption affects their program. Certification is normally issued to the legal entity and the physical location assessed; it does not automatically cover every subsidiary, warehouse, product, or country. The system covers the deliberate and unintentional risks associated with security and resilience, including supply-chain threats, fraud, site disruption, and breaches of confidentiality. It is not an information-security standard in the ISO/IEC 27000 series, nor is it a guarantee that every attack will be prevented. Certification also does not mean that the organization has become insurer-certified, received government approval, or proved that its controls are perfect. Instead, it indicates that an independent certification body found documented controls, responsibilities, risk processes, internal audits, management review, and continual improvement that satisfy the audited ISO 28000 requirements. For an AI Insurance Broker, the value is primarily in structuring operational risk decisions, client due diligence, and evidence that security controls are reviewed rather than merely purchased.

**Also worth reading:** [How Should You Prepare for ISO 28000 Certification in 2026?](https://in-surely.com/knowledge/how_should_you_prepare_for_iso_28000_certification_in_2026.php) · [How Does ISO 28000:2022 Certification Work for Supply Chain Security in 2026?](https://in-surely.com/knowledge/how_does_iso_280002022_certification_work_for_supply_chain_security_in_2026.php) · [Illinois SR-22 Insurance Requirements: What Drivers Need to Know in 2026?](https://in-surely.com/knowledge/illinois_sr-22_insurance_requirements_what_drivers_need_to_know_in_2026.php)

## ISO 28000, ISO 27001, and Related Standards Compared

Choosing the wrong standard can create months of duplicated work because management-system standards share a common structure but examine different risks. ISO 27001 is designed specifically for information security and is recognized widely in cybersecurity procurement and tender processes. ISO 28000 addresses a broader set of security and resilience concerns within an organization’s operating environment. ISO 28004-1 gives guidance for implementing ISO 28000, but it is not a substitute for the requirements standard and is normally not independently certified. ISO 28001 concerns the security and resilience of management systems and may be relevant where a particular sector requires it, but ISO 28000 remains the central general requirements standard discussed in most ISO 28000 certification guides.

| Feature | ISO 28000 certification | ISO/IEC 27001 certification | ISO 31000 risk-management system |
| --- | --- | --- | --- |
| Primary focus | Security and resilience across operations | Protection of information assets | Risk-management processes |
| Typical scope | Whole organization, site, or business unit | Information security management system | Enterprise or activity risk system |
| Supply-chain security | Strongly relevant | Relevant where information or systems are affected | Relevant but not security-specific |
| Certification | Yes, through independent assessment | Yes, through independent certification | The ISO 31000 framework itself is not certification criteria |
| Common buyer | Logistics, manufacturing, ports, logistics services, and security-conscious businesses | Technology, finance, professional services, and data-intensive organizations | Organizations needing a structured risk process |
| Main limitation | Broad scope requires well-evidenced operational controls | Does not cover every physical or business-continuity risk | Risk criteria and treatments remain organization-specific |

A company may use both ISO 28000 and ISO 27001 when it wants an enterprise-wide security-resilience system supported by a specialist information-security system. A shared governance model, common audit program, and linked risk register can reduce duplication. However, combining them does not make either certification automatic, and separate audits or statements of applicability may still be required. For an insurance broker, the decision should depend on client requirements and the risks being priced, not on the assumption that one certification is universally superior.

## Requirements That an Auditor Will Examine

An ISO 28000 management system must be appropriate to the organization’s context and affected interested parties. The organization defines its scope, establishes security objectives, identifies and evaluates risks, determines controls, and maintains documented information needed to operate the system. Threats and vulnerabilities may include unauthorized access, loss of cargo, fraud, workplace violence, cyber incidents, supplier failure, natural hazards, and disruption of essential services. Unlike a generic checklist, ISO 28000 requires risk-based decisions tied to the organization’s operations and the level of security and resilience it needs to achieve.

The management structure should identify responsibilities and authorities, while competent personnel must have the knowledge and skills needed to perform assigned functions. Awareness matters because employees and contractors can affect control effectiveness even when they do not design security systems. The organization should establish processes for operational control, incident management, business continuity or continuity of activity, and continual improvement. Documented information is not prescribed as one rigid manual; it can include policies, procedures, risk registers, plans, records, internal audit reports, management-review minutes, and performance data. The evidence must demonstrate implementation rather than merely show that a template document exists. Internal audits must be planned at suitable intervals, conducted objectively, and reported to management. Management review should occur at planned intervals and consider audit results, changes affecting the system, performance against objectives, resource adequacy, risks, opportunities, and improvement actions.

## The Certification Process From Gap Review to Audit

The first stage is usually a readiness or gap review against ISO 28000:2019. This should be performed against the organization’s actual scope, locations, activities, personnel, suppliers, and applicable legal or customer requirements. If certification is not yet necessary, the organization can still use ISO 28004-1 as implementation guidance. During preparation, management approves the scope and objectives, maps responsibilities, documents risk evaluation and control selection, trains relevant personnel, tests incident and continuity arrangements, and conducts an internal audit and management review. Evidence should be dated and traceable. A useful rule is to ask whether an auditor could follow the record from an identified risk to the selected control, assigned owner, monitoring method, incident response, and management decision.

A certification body then conducts the planned audit process defined by applicable ISO certification principles, including stage 1 and stage 2 activities. Stage 1 generally checks scope, context, readiness, and major gaps; stage 2 evaluates implementation and effectiveness. The exact sequence depends on the body, certification scheme, and organizational readiness. Nonconformities are classified according to the scheme and must be addressed through the defined corrective-action process. A major nonconformity can prevent certification until the issue is corrected and verified; a minor nonconformity may be accepted with a documented correction and later verification. The certificate is normally issued after successful completion of the certification decision process, not merely after the final audit visit. Organizations should use certification for operational improvement and evidence, but should not represent it as a promise of uninterrupted service or complete cyber protection.

## Practical Timeline, Team, and Operational Preparation

A first-time organization often needs approximately four to nine months for meaningful preparation before the final certification audit, although three to twelve months is possible when the scope is complex. A simpler site with existing quality, safety, or risk systems may move faster. A fragmented business, multiple warehouses, major IT migration, or weak incident records usually takes longer. The organization does not need to replace every other management system. ISO 14001, ISO 45001, ISO 9001, ISO 27001, or a strong internal control environment can provide a foundation for shared governance, document control, audits, and management review. The key is to integrate security and resilience into existing processes rather than create a security department that operates apart from the business.

A practical core team normally includes an executive sponsor, security or resilience manager, operations representative, risk or compliance representative, information-security input, human-resources support, and site or facility representatives. Suppliers and contractors should be included when their conduct can materially affect the organization’s objectives. The team should set measurable objectives, such as completing annual training, closing critical corrective actions within defined periods, exercising continuity plans twice per year, or reviewing high-risk suppliers quarterly. Those numbers are examples, not ISO requirements; actual targets should reflect risk, legal duties, and operational capacity. Management must allocate time and resources for evidence collection, not only policy writing. Small organizations can use a lean team, but they still need enough independence and expertise to conduct meaningful internal audits.

## Cost and Pricing: What Determines the Budget

There is no universal ISO 28000 certification fee because the price depends on employee count, number of sites, audit days, legal entities, geographic spread, risk, and whether the organization needs extensive preparation. A small organization with one straightforward site may see total consulting, audit, and internal preparation costs in the low five-figure range, while a multi-site or highly regulated enterprise may spend tens of thousands or more. Certification-body fees are only one component. Organizations may pay separately for gap analysis, consultant support, documentation, training, software, travel, corrective actions, surveillance audits, and management time. In some markets, certification costs are quoted per site or per employee band, so a written quotation based on a defined scope is more useful than a headline price.

The business case should be tested carefully. Certification can support customer confidence, tender qualification, supply-chain governance, incident response, and insurance discussions, but it does not automatically reduce premiums or eliminate losses. An AI Insurance Broker can use it as one control when comparing carriers, exclusions, limits, deductibles, wording, and security assumptions. The broker should ask for the certificate, issuing body, scope, expiry date, covered locations, and relevant nonconformity status, then verify claims through the accreditation route where applicable. ISO certification bodies should be assessed by an accreditation body recognized for the relevant certification scheme; ISO itself does not directly certify organizations. Buyers should be wary of certificates purchased without an audit, certificates that cover an undefined “global company,” or claims that certification guarantees compliance with every legal or customer requirement.

## Common Mistakes That Delay Certification

One common mistake is treating ISO 28000 as a paperwork exercise. Downloading policies and naming a security officer do not demonstrate that risks are assessed or controls work. Another is copying a generic risk register that contains hundreds of theoretical risks but provides no ownership, treatment, residual-risk decision, or evidence of review. Organizations sometimes confuse ISO 28000 with ISO 28004-1, even though the latter is guidance rather than the requirements standard used for certification. Scope is another frequent problem: the certificate may state one site while the application, training, supplier controls, and management review are undocumented elsewhere.

A further error is waiting until shortly before an audit to conduct internal audits or management reviews. Those processes must operate as part of normal management, not as activities created only for the auditor. Weak corrective-action records are also problematic, particularly where findings remain open without root-cause analysis or effectiveness checks. Certification bodies should maintain independence and should not be offered gifts or participation in management decisions. Conversely, consultants must avoid guaranteeing certification or promising a particular outcome, since the decision belongs to the certification body. The organization should correct evidence gaps early, disclose significant changes to the auditor, and avoid treating the surveillance audit as the first serious review of the system.

## When to Act and How an AI Insurance Broker Fits In

An organization should consider ISO 28000 when customers, contracts, regulators, insurers, or business partners require a formal security-resilience system, or when repeated disruption, fraud, cargo loss, vendor incidents, or site-security events reveal that informal controls are insufficient. It is also reasonable for a growing organization to prepare before a major tender, new warehouse rollout, acquisition, or insurance renewal. Conversely, a very small business with limited physical assets, few personnel, and modest contractual obligations may get more immediate value from proportionate risk controls, vendor screening, access management, backup testing, and incident procedures. ISO 28000 is not automatically justified for every organization, and a full certification program can consume resources that might be better spent on specific hazards or controls.

An AI Insurance Broker can help clients decide whether certification is relevant to the insurance program. The broker can compare quote assumptions about cyber controls, supply-chain resilience, business interruption, data exposure, and physical security against the client’s actual risk profile. Automated analysis can flag documents, claims, or inconsistencies, but it should not be presented as an independent conformity assessment. Certification evidence should inform—not replace—questions about loss history, controls, recovery time objectives, subcontractors, incident notification, exclusions, limits, and claims cooperation. This approach keeps the broker from hard-selling a certificate as a universal solution. It also helps clients understand that ISO 28000 can be one useful layer in risk management while insurer underwriting, contractual requirements, and tested recovery performance remain separate matters.

## Final Decision Guidance and Verification Questions

Before committing, management should answer several questions in writing. Which legal entity and sites need certification? What events could seriously disrupt the business? Who owns each high-risk control? How will risk treatment and residual risk be approved? What records will prove that controls were implemented? How will incidents, continuity, audits, corrective actions, and management reviews connect? If the answers depend mainly on an auditor template, the organization is not ready. If the organization has a functioning system but lacks formal documentation, preparation may be straightforward. If there is no incident history, resilience testing, supplier review, or management commitment, certification should be treated as a multi-year improvement program rather than a quick certificate purchase.

After certification, the organization should monitor the certificate and surveillance schedule, maintain open communication with the certification body, and track changes to scope, ownership, locations, suppliers, products, threats, and applicable requirements. Renewal is not automatic; it depends on the certification process and successful surveillance and review. A certificate should be verified directly with the certification body or relevant accreditation records, not solely from a PDF on a supplier’s website. The most defensible position is that ISO 28000 provides an externally assessed framework for managing security and resilience. It can strengthen governance, customer confidence, and insurance discussions, but its business value comes from what the organization does with the system after the audit, not from displaying the certificate.

## Quick answers

### Is ISO 28000 the same as ISO 27001?

No. ISO 28000 addresses security and resilience across organizational operations, while ISO 27001 focuses on information security management. An organization may use both when it needs broader operational security supported by a specialized information-security system.

### How long does ISO 28000 certification take?

Many organizations need roughly four to nine months of preparation, although complex or multi-site organizations may require twelve months or more. The final timetable depends on scope, existing systems, audit findings, corrective actions, and the certification body’s schedule.

### Can an organization be certified to ISO 28000 without an external audit?

A credible ISO 28000 certification requires evaluation by an independent certification body under an applicable certification scheme. Internal audits and management review support readiness, but they do not replace the external certification audit.

### Does ISO 28000 certification guarantee lower insurance premiums?

No. It may help an insurer understand the organization’s security and resilience arrangements, but pricing also depends on exposure, loss history, limits, deductibles, wording, exclusions, recovery capability, and the carrier’s underwriting view. Certification is evidence, not a premium guarantee.

### Is ISO 28004-1 a certifiable replacement for ISO 28000?

ISO 28004-1 provides guidance for implementing ISO 28000, but it is not the general requirements standard used to certify an ISO 28000 management system. Organizations should verify the intended certification standard with the selected certification body before buying services.

Canonical: https://in-surely.com/knowledge/iso_28000_certification_guide_requirements_costs_and_certification_steps_in_2026.php
Markdown: https://in-surely.com/knowledge/iso_28000_certification_guide_requirements_costs_and_certification_steps_in_2026.php/index.md
