Supply chain security risk assessment across your end-to-end operations, from sourcing through final delivery

Supply Chain Security Management
ISO 28000 Certification
Supply Chain Security Management
ISO 28000 Certification
Manage Supply Chain Security as a System, Not a Series of One-Off Fixes
ISO 28000 certification proves your organization manages supply chain security through a structured, risk-based management system, covering everything from cargo integrity to partner vetting to crisis response, rather than reacting to each incident as it happens. We build that management system around your operations, close the gaps a certification auditor would flag, and get you certified without disrupting the flow of goods it's meant to protect.
The challenge
The Problem We're Usually Called In For
Most supply chain security problems trace back to fragmentation, security is handled well within one function, like warehouse access control, but disconnected from how transport partners, customs processes, and crisis response actually get managed. A theft or diversion incident exposes that nobody owned end-to-end accountability for supply chain security risk. A new trade lane opens without anyone formally assessing the security risk it introduces.
We work with Supply Chain Directors, Heads of Security, COOs, and Trade Compliance leads at manufacturers, distributors, and logistics providers with complex, multi-partner supply chains. Some of you are formalizing security management for the first time. Some are consolidating fragmented, function-specific security practices into one system. Others need certification to satisfy a customer, insurer, or trade program requirement.
Scope
What the Certification Process Covers
Gap analysis against ISO 28000, benchmarked against your current security governance, policies, and controls
Security management structure and accountability review, ensuring clear ownership of supply chain security risk
Partner, supplier, and logistics provider security review, including how third-party security posture is assessed and monitored
Physical, cargo, and information security control review across your supply chain touchpoints
Crisis management and business continuity planning specific to supply chain disruption scenarios
Performance measurement and continual improvement process design, so the system gets stronger over time
Internal audit support and management review ahead of certification
Engagement
How the Engagement Works
Step 01
Discovery & Scoping
Step 02
Risk Assessment & Gap Analysis
Step 03
Build & Remediation
Step 04
Internal Audit & Management Review
Step 05
Certification Support
A short call to map your supply chain structure, current security practices, and what's driving certification. We agree on scope before assessment begins.
We assess supply chain security risk across your operations and benchmark current practice against ISO 28000's requirements.
We help close the gaps, from governance structure to partner assessment processes, working across the functions that touch your supply chain rather than treating security as one team's job.
We run the internal audit ISO 28000 requires and support the management review that certification depends on.
We prepare your team for the certification body's audits and help resolve any findings quickly.
Outcomes
Proof, Not Promises
Distributor with security responsibilities split across warehouse, logistics, and IT teams:
the gap assessment found no single function owned end-to-end supply chain security risk, so a cargo theft incident had taken weeks to fully investigate because information sat in three different systems. A unified governance structure closed the gap and cut incident response time significantly on the next test.
Manufacturer opening a new international trade lane:
the risk assessment identified a transshipment risk that hadn't been part of any prior security review, since the existing program had never been extended to cover new lanes systematically. Building that assessment into the standard onboarding process for new lanes closed a recurring blind spot.
FAQ
Questions We Get Asked Before Signing
ISO 28000 is the overarching supply chain security management system standard, covering governance, risk assessment, and continual improvement. ISO 28001 focuses specifically on developing and implementing the security plan and assessment process within that system. Many organizations pursue both together.
Typically four to seven months depending on the complexity and geographic spread of your supply chain.
No, it builds a management structure around them, ensuring existing controls are risk-assessed, coordinated, and continually improved rather than operating in isolation.
Yes, and it often makes sense to, since the management system structures share a common framework and audits can be coordinated to reduce duplicated effort.
Often, yes. Insurers and customers increasingly ask for evidence of structured supply chain security management, and certification provides exactly that kind of independently verified evidence.
Certification runs on a three-year cycle with annual surveillance audits. We can support those ongoing or transition the system fully to your internal security and supply chain teams.

Ready to Manage Supply Chain Security as One System, Not Five Disconnected Efforts?
Fragmented security practices leave gaps exactly where responsibility is unclear. ISO 28000 certification proves those gaps have been found and closed, before a theft, diversion, or disruption finds them instead.
Schedule a 30-minute supply chain security readiness call and find out where your gaps are. When you reach out, we'll ask for your name, work email, company, role, and a brief note on what's driving the certification. That's enough for us to come prepared.
