Implementing ISO standards? Don't overlook GDPR. Try Cookiebot free →

ISO 28001

Supply Chain Security - Best Practices, Assessments and Plans

Management Systems Published: 2007

ISO 28001:2007 at a glance

Current edition
ISO 28001:2007 - Security management systems for the supply chain — Best practices for implementing supply chain security, assessments and plans — Requirements and guidance
Published
2007
Status
Published
Type of standard
Requirements
Certifiable
No — used for reference and implementation, not certification
Previous edition
ISO/PAS 28001:2006
Official ISO page
View ISO 28001:2007 on iso.org
Last verified

Overview

Requirements and guidance for organizations in international supply chains to develop and implement supply chain security processes and establish a documented minimum level of security, supporting Authorized Economic Operator programmes.

ISO 28001:2007 provides requirements and guidance for organizations in international supply chains to develop and implement supply chain security processes, and to establish and document a minimum level of security within their supply chains. It replaced ISO/PAS 28001:2006, upgrading the earlier Publicly Available Specification to a full International Standard. The publication was last reviewed and confirmed in 2021, so this version remains current.

Customs and AEO context. The standard's most practical role is in customs compliance. It is written to help organizations meet the applicable Authorized Economic Operator (AEO) criteria set out in the World Customs Organization SAFE Framework of Standards and in conforming national supply chain security programmes. The best practices in ISO 28001 help an organization establish and document security levels within an international supply chain and facilitate validation within national AEO programmes — which in turn can bring benefits such as simplified customs procedures and reduced inspection rates, depending on the national programme concerned.

Method. ISO 28001 works through a security assessment of the supply chain: identifying the scope of the international supply chain the organization controls or influences, conducting a security assessment that considers threat scenarios against the organization's assets and processes, determining the consequences and likelihood of those scenarios, developing a supply chain security plan with countermeasures proportionate to the assessed risk, implementing and exercising the plan, and documenting the whole so that it can be presented to customs authorities or trading partners. It also addresses the declaration of security in the supply chain and the handling of information relating to it.

Relationship to ISO 28000. ISO 28000 is the management system standard for security in the supply chain and is the certifiable document; it was revised in 2022 and now specifies requirements for a security management system aligned to the ISO harmonized structure. ISO 28001 is the best-practice and assessment companion. ISO 28003 sets requirements for bodies providing audit and certification of supply chain security management systems, and the ISO 28004 parts give implementation guidance for ISO 28000 — including ISO 28004-4, which gives specific guidance where conformity with ISO 28001 is a management objective.

Certification. Organizations are certified to ISO 28000, not to ISO 28001. Conformity with ISO 28001 is typically demonstrated through the documented security assessment and security plan, and through validation by customs authorities under an AEO programme, rather than through an ISO certificate. Organizations often integrate supply chain security with ISO/IEC 27001 for information security and ISO 22301 for business continuity.

Purpose

To help organizations in international supply chains assess security threats, develop and implement supply chain security plans, and document a minimum level of security consistent with Authorized Economic Operator and WCO SAFE Framework criteria.

Key Benefits

  • Supports validation under national Authorized Economic Operator programmes
  • Aligned with the World Customs Organization SAFE Framework of Standards
  • Structured security assessment method for international supply chains
  • Documented security plan usable in dealings with customs and trading partners
  • Complements the certifiable ISO 28000 security management system
  • Applicable across manufacturing, logistics, transport and retail supply chains

Key Requirements

  • Define the scope of the international supply chain covered
  • Conduct a security assessment identifying threat scenarios and affected assets
  • Evaluate consequences and likelihood of identified security scenarios
  • Develop a supply chain security plan with proportionate countermeasures
  • Assign responsibilities for supply chain security, including a security officer role
  • Implement, exercise and maintain the security plan
  • Document security measures to support AEO validation and partner assurance
  • Communicate security expectations to supply chain partners
  • Review and update the assessment and plan as threats and operations change

Who Needs This Standard?

Exporters and importers seeking AEO status, freight forwarders, customs brokers, port and terminal operators, logistics and transport providers, manufacturers with international supply chains, and supply chain security and customs compliance managers.

Where to get ISO 28001

The full text of ISO 28001 is copyrighted and is sold by ISO and its national member bodies — buy the official edition on iso.org, or order the same document from your national standards body, often at a member price. Sites offering a free PDF of the complete standard are not authorised to distribute it, and the files circulating there are frequently superseded editions, partial scans or altered copies, with no way to tell which. What is legitimately free is the standard's page on iso.org: the abstract, the current edition and status, the table of contents, and a preview of the opening sections. This page summarises the scope and requirements of ISO 28001 in our own words; it does not reproduce the standard's text and is not a substitute for the published document.

Get our free implementation resources

Send me the implementation checklist for ISO 28001, plus an alert when this standard is revised, withdrawn or replaced. Free, no account needed.

We'll only email you about this standard. Unsubscribe anytime.

Looking to get certified?

You cannot be certified to ISO 28001 — it is guidance, and no accredited scheme exists for it. The closest standards you can certify against are ISO 28000 (Supply Chain Security Management Systems), ISO 27001 (Information Security Management Systems) and ISO 22301 (Business Continuity Management Systems).

If that is the direction you are heading, tell us what stage you are at and we will put you in touch with people who work with them. Free and no obligation.

Get help with certification

In a hurry? You can also compare quotes from verified providers on CertBetter (affiliate link — we earn a commission, and it stays free for you).

Related Standards