Supply chain security threat and risk assessment across your specific transport modes, routes, and transshipment points

Supply Chain Security
ISO 28001 Certification
Supply Chain Security
ISO 28001 Certification
Prove Your Supply Chain Security Plan Works, Not Just That One Exists
ISO 28001 certification confirms your organization has assessed its supply chain security risks and put a real, workable security plan in place, the kind of evidence customs authorities, trade partners, and programs like AEO or C-TPAT actually recognize. We build that plan around your specific supply chain, close the gaps a certification auditor would flag, and get you certified without slowing down the shipments that plan is meant to protect.
The challenge
The Problem We're Usually Called In For
Most supply chain security gaps aren’t dramatic, they’re a threat assessment that was done once at onboarding and never revisited as routes, ports, or partners changed. A cargo security plan exists but was written generically and doesn’t reflect your actual transport modes or transshipment points. A logistics partner with access to shipment data or physical cargo was never formally assessed against the same standard you hold yourself to.
We work with Supply Chain Directors, Logistics Managers, Trade Compliance leads, and Heads of Security at manufacturers, freight forwarders, and logistics providers moving goods across borders. Some of you need ISO 28001 to support an AEO or C-TPAT application. Some are responding to a customer or partner requirement. Others had a security incident, theft, tampering, a documentation breach, that exposed how thin the existing plan really was.
Scope
What the Certification Process Covers
Gap analysis against ISO 28001, benchmarked against your current security plan and physical and procedural controls
Cargo and asset security review, including seals, tracking, and chain-of-custody controls at each handoff point
Partner and subcontractor security assessment, since ISO 28001 expects you to verify the security posture of the parties handling your cargo
Personnel security review, including background screening and access control for staff handling sensitive shipments
Security incident and crisis management process review, tested against realistic disruption scenarios
Documentation aligned to support AEO, C-TPAT, or equivalent trade partnership program applications where relevant
Internal audit support and management review ahead of certification
Engagement
How the Engagement Works
Step 01
Discovery & Scoping
Step 02
Threat & Risk Assessment
Step 03
Gap Assessment & Plan Development
Step 04
Internal Audit & Management Review
Step 05
Certification Support
A short call to map your supply chain, transport modes, and what's driving certification, whether it's a trade program application, a customer requirement, or a security incident. We agree on scope before assessment begins.
We assess the specific security threats relevant to your supply chain, from the routes you use to the partners handling your cargo.
We benchmark current practice against ISO 28001 and build or refine your security plan around what your supply chain actually looks like, not a generic template.
We run the internal audit ISO 28001 requires and support the management review that certification depends on.
We prepare your team for the certification body's audits and help resolve any findings quickly.
Outcomes
Proof, Not Promises
Manufacturer applying for AEO status:
the threat assessment found a transshipment point in the route hadn't been formally risk-assessed since a change in freight partner two years earlier. Updating the assessment and tightening chain-of-custody controls at that point closed the gap and directly supported the AEO application.
Freight forwarder responding to a cargo tampering incident:
the partner assessment found a subcontracted trucking company had never been evaluated against any formal security standard. Bringing that partner under a documented assessment process closed the gap and became the strongest evidence point in the resulting certification audit.
FAQ
Questions We Get Asked Before Signing
ISO 28000 sets the requirements for a supply chain security management system as a whole. ISO 28001 provides specific guidance and requirements for the security plan and assessment process within that system, and is what most organizations pursuing trade partnership program recognition are specifically assessed against.
Yes, ISO 28001's security plan and assessment structure closely aligns with what those programs expect as evidence, and we build the documentation with that alignment in mind from the start.
Typically three to five months depending on the complexity of your supply chain and how many transport modes and partners are in scope.
No, but ISO 28001 expects you to assess the security posture of the partners handling your cargo, even if they hold no certification of their own.
We schedule around your operational commitments, and most of the assessment work happens through documentation review, interviews, and site or route walkthroughs rather than halting shipments.
Certification runs on a three-year cycle with periodic surveillance audits. We can support those ongoing or transition the program fully to your internal team.

Ready for a Security Plan That Actually Holds Up in Transit?
A security plan that was accurate at onboarding and never revisited isn't protecting anything anymore. ISO 28001 certification proves your plan reflects your supply chain as it actually operates today.
Schedule a 30-minute supply chain security readiness call and find out where your gaps are. When you reach out, we'll ask for your name, work email, company, role, and a brief note on what's driving the certification. That's enough for us to come prepared.
