What ISO 28000:2022 Certification Requires in 2026

ISO 28000:2022 certification confirms that an organization has established and can operate a security management system for its supply chains. The assessment considers documented processes, assigned responsibilities, control implementation, internal review, corrective action and evidence that the system produces intended results. It does not merely test whether policies exist, and completing training or purchasing security software is not sufficient by itself. In 2026, organizations should also account for the transition from ISO 28000:2013, identify the intended certification scheme, and confirm that the certification body is accredited for the applicable scope. From an insurance perspective, a valid certificate can support underwriting discussions, but it is evidence of risk governance rather than a guarantee that disruption, cyberattack, cargo loss or business-interruption losses cannot occur.

Also worth reading: How Is the AI Cyber Policy Review Changing Business Insurance Requirements in 2026? · Will Insurance Cover Meniscus Surgery in 2026, and What Requirements Apply? · California rideshare insurance requirements and what Uber or Lyft drivers need after an accident?

The applicable requirements come from ISO 28000:2022, titled Security and resilience — Security management systems — Requirements, together with the rules of the certification body, accreditation requirements and any customer-specific criteria. ISO 28000 is designed for organizations of any type or size, including manufacturers, logistics providers, freight forwarders, ports, airports, customs operators, distributors and service companies. It is structured around the Plan-Do-Check-Act model used by modern ISO management-system standards. Organizations should not assume that every requirement in the standard is separately auditable as a universal control; the accredited assessment evaluates the management system and samples relevant security practices within the agreed scope.

The Management-System Clauses That Must Be Demonstrated

ISO 28000:2022 follows the seven-clause structure of ISO management-system standards. Clauses 4 through 10 address the organization’s context, leadership, planning, support, operation, performance evaluation and improvement, while Clause 1 contains the scope and Clause 2 the normative references and Clause 3 the terms and definitions. This structure means the organization must understand how supply-chain security relates to its business, affected parties and operating environment. It must also establish governance, objectives, competence, communication, documented information, operational controls, incident response, monitoring, audits and improvement processes.

The clauses should be understood as a connected system rather than as isolated documents. A risk assessment that is never connected to purchasing, shipment release, supplier approval or incident escalation is unlikely to demonstrate effective operation. Similarly, an incident procedure that produces no lessons, corrective action or management review does not satisfy the full logic of the standard. Certification auditors normally seek objective evidence across the system: approved procedures, dated records, system access logs, supplier files, training completion, investigation reports, internal-audit findings, management-review minutes and evidence that identified problems were resolved. The certificate is consequently an assessment conclusion, not a list of guarantees about every individual security control.

Security Planning, Risk Assessment and Control Implementation

Clause 6 requires the organization to address risks and opportunities associated with its supply chain and establish appropriate security objectives. Planning should consider threats such as counterfeit goods, unauthorized access, theft, sabotage, terrorism, smuggling, cyber intrusion, data manipulation, compromised suppliers, natural hazards and regulatory disruption. The organization should define risk-appetite and acceptance criteria at an authorized management level, assess the likelihood and potential impact of relevant scenarios, and determine whether existing controls are adequate. It then needs to select and implement controls proportionate to those risks and assign accountable persons, resources, deadlines and evidence requirements.

ISO 28000 addresses security objectives and the management system, while ISO 28001 provides more detailed guidance on implementing a security-control framework. An organization may therefore use ISO 28001 concepts, control domains or a recognized security framework to support its planning, but it should not describe an ISO 28001 certificate as the same thing as an ISO 28000 certificate. Effective planning also includes continuity, recovery and alternative-supply arrangements where a serious disruption could affect the organization’s ability to provide products or services. Measures may include dual sourcing, safety stock, route diversification, access controls, shipment-security technology, supplier screening, secure transport, information-security safeguards and tested response arrangements. The precise controls are not fixed by ISO 28000:2022; they depend on the organization’s scope, risk profile, products, geography, legal obligations and contractual expectations.

Leadership, Competence, Communication and Documented Evidence

Top management must demonstrate active ownership of the supply-chain security system. That normally means approving policy, establishing objectives, allocating resources, reviewing performance and making decisions when significant risks or failures arise. A written statement signed once by an executive is not enough if operational leaders do not understand their responsibilities. Management should also consider the needs of customers, regulators, employees, suppliers, carriers, law-enforcement bodies and other interested parties. Where security issues affect multiple functions or business units, the system should explain how authority, escalation and accountability work.

Competence requirements are practical. The organization must determine what knowledge and skills are necessary for security roles, provide appropriate training and retain evidence of competence. This includes technical staff, procurement personnel, warehouse employees, quality teams, security officers, crisis managers and internal auditors. Communication procedures should specify who receives what information, when escalation is required, how incidents are reported and how confidentiality is protected. Documented information must be controlled sufficiently to ensure that current versions are available, obsolete material is prevented from accidental use, and changes are traceable. Nevertheless, ISO management-system standards are intentionally flexible about documentation: organizations do not need to create a large manual for its own sake, but they need enough records to show that decisions, controls and reviews actually occur.

Operational Control of Goods, Facilities, Suppliers and Information

Clause 8 concerns operation, including processes that control the supply chain and the organization’s own security activities. Depending on the scope, evidence may include procedures for supplier approval, purchasing controls, access authorization, visitor management, cargo handling, packaging, storage, transportation, customs processing, returns, subcontracting and disposal. Controls should address both physical security and information security because contemporary supply chains connect shipment data, identity systems, IoT devices, warehouse platforms, customs records and business applications. If the organization uses a cloud-based track-and-trace platform or shares documents with logistics partners, responsibilities for access, data integrity, availability, change management and supplier assurance should be addressed.

The scope must be defined accurately. A certificate may cover a particular legal entity, site, warehouse, transport operation, product line or business activity, and a multi-site organization may need group-wide arrangements. The scope should not imply that an unassessed subsidiary, outsourced provider or geographic location has been certified. Certification bodies commonly examine the control environment, sampling of transactions and records, interview evidence and follow-up through an audit conducted at relevant locations. A supplier’s security controls cannot simply be transferred to the certified organization: outsourcing may reduce direct control, but the customer still needs supplier-selection, contract, monitoring and contingency arrangements. In insurance terms, this distinction matters because the certificate can cover the certified organization’s management system without transferring the supplier’s physical assets or liabilities to the certificate holder.

Internal Audit, Management Review, Incidents and Corrective Action

The organization must conduct internal audits at planned intervals and use an impartial, evidence-based process. The audit program should cover all applicable processes, sites, risk areas and clauses over a defined cycle, with auditors who are competent and independent enough to avoid auditing their own work. Findings must identify conformity, nonconformity, opportunities and risks, and the resulting reports should be retained. The audit is not a ceremonial inspection; it is part of the organization’s own evaluation of whether the system remains suitable, adequate and implemented as intended.

Management review should occur at planned intervals and consider changes in internal and external conditions, performance against objectives, audit results, nonconformities, corrective actions, supplier performance, incidents, resource needs and opportunities for improvement. An organization with a major incident should be able to show how information moved from the event to top management and how lessons affected policies, objectives, contracts, training or resources. Corrective action must address the underlying cause rather than only recording that a person was retrained. If repeated cargo discrepancies arise from weak supplier controls, for example, retraining a warehouse employee would not correct the purchasing or oversight failure. The standard does not prescribe that every incident result in certification nonconformity, but a serious pattern of uncontrolled or concealed failures may have a material effect on the certification recommendation.

Certification Audit, Accreditation and the 2013-to-2022 Transition

The first stage of certification is normally a readiness or documentation review, followed by an on-site certification audit. The organization must agree with the certification body on the applicable standard, scope, sites, audit duration, sampling plan and any supplementary criteria. Stage 1 is intended to identify gaps and confirm that the planned audit can be completed; it is not a substitute for the Stage 2 assessment of implementation. The certification body then evaluates the management system and selected operating evidence, issues findings, and recommends certification only if the applicable requirements have been met. Major nonconformities may prevent immediate certification, while minor nonconformities generally require correction and evidence of effectiveness within an agreed period, subject to the certification body’s rules.

Assessment elementWhat the organization should expectCommon misleading interpretation
ISO 28000:2022 requirementsDemonstrated supply-chain security management system within the agreed scopeA generic security policy with no implementation evidence
ISO 28001 guidanceSupport for defining and managing security-control objectivesAn ISO 28001 certificate automatically proving ISO 28000 certification
Stage 1 auditPreparation, scope and readiness reviewFinal certification approval
Stage 2 auditImplementation, effectiveness and objective evidenceA desk review of documents alone
AccreditationIndependent recognition of certification-body competenceA guarantee that every insured risk is low
Transition from 2013Mapping of changed requirements, implementation and evidenceTreating the old certificate as permanently equivalent
Accreditation status must be checked rather than inferred from a logo. ISO/IEC 17065 addresses the competence and operation of certification bodies, and accreditation is normally provided by a national accreditation body or an arrangement recognized in the relevant market. The accreditation body, certification body and applicable accreditation symbol should be confirmed for the country in which the certificate will be relied upon. ISO 28000:2022 superseded ISO 28000:2013, so organizations should establish whether the certification body is conducting a transition audit, using a defined transition period or accepting a new audit under the current requirements. A certificate number, customer portal entry or supplier questionnaire is not enough on its own; the original certificate, scope, issuing body, issue date, expiry date and accreditation details should be verified.

How Organizations Should Prepare in Practice

Preparation should begin with a clear decision about why certification is needed. If the driver is a tender, customer audit, port requirement, insurer questionnaire or regulatory expectation, the exact wording may determine whether ISO 28000 is sufficient, whether ISO 28001 is expected, or whether a separate scheme such as an AEO, ISRS, C-TPAT, security or quality certification is involved. An organization should then define the legal entities, sites, functions, products, transport modes and suppliers included in scope. It should perform a gap analysis against ISO 28000:2022, assign owners and completion dates, and establish the policy, objectives, risk methodology, control matrix and governance arrangements needed to operate the system.

After implementation, the organization should run internal audits and a management review before the external assessment. It should collect evidence from representative transactions rather than relying only on centrally selected samples. For example, an auditor may request records for several suppliers, shipments, access events, nonconformities and corrective actions to determine whether the same process works across teams. The organization should also test the response to a plausible disruption, such as a compromised carrier, unavailable warehouse, cyber incident affecting shipment data or sudden border restriction. This exercise can expose missing escalation contacts, unclear decision authority and dependencies that were absent from the original risk register. An insurance broker can use this process to identify operational weaknesses, but should not represent readiness exercises as certification or coverage advice.

Common Mistakes, Limitations and When to Act Before Certification

A frequent mistake is treating ISO 28000:2022 as a fixed catalog of security technologies. The standard is a management-system requirement, so the controls should respond to the organization’s actual risks and objectives. Another mistake is assuming that certification automatically covers every affiliate, supplier, cargo movement or country; the certificate scope and exclusions must be read carefully. Organizations also make the error of copying the old ISO 28000:2013 structure without examining the revised edition, or of selecting a certification body without checking whether it is accredited for the intended standard and market. Finally, a rushed application can produce a certificate without a functioning system, which may create customer disputes, reputational concerns and questions during an insurance renewal.

Organizations should act well before a customer deadline. A reasonable planning period often requires at least 6 to 12 months for a first certification, while multi-site, high-complexity or heavily regulated operations may need longer; these are planning estimates, not requirements in the standard. Certification is usually voluntary unless a contract, regulation, tender or industry scheme expressly requires it, although indirect commercial pressure can make it effectively necessary. A current certificate may help an insurer understand governance and loss-prevention maturity, but insurers will still evaluate revenue concentration, cargo values, accumulation exposure, cyber dependencies, business interruption, claims history, contractual limits and recovery capability. In 2026, the safest approach is to obtain the current standard and certification-body rules, define the scope precisely, verify accreditation, and treat certification as one component of broader supply-chain risk management rather than as a shield against every possible loss.