Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 28000 certification cost explained

ISO 28000 Certification Cost in 2026: The Complete Breakdown

ISO 28000 certification cost is built from the same four invoices as any management system certification — the certification body’s audit fees over a three-year cycle, the cost of building the security management system, optional consultancy, and internal staff time — plus a fifth line that other standards do not carry: the physical and technical controls a security risk assessment tends to find missing.

Fences, lighting, CCTV, access control, seal programmes and cyber measures are not certification costs in the strict sense, but a system certified to ISO 28000:2022 has to have implemented the controls its clause 8.3 risk assessment determined, so the budget that ignores them is the one that overruns. This guide builds the ISO 28000 certification cost line by line with labelled typical ranges for three sizes of operation, explains what drives the audit-day count, shows the three-year total, separates the controls spend from the certification spend, and names the decisions that move the figure most.

ISO 28000 certification cost: four invoices plus the controls the risk assessment finds
Certification body (3-year cycle) · SMS build · consultancy · internal time · plus physical, procedural and cyber controls determined under clause 8.3–8.4.

What ISO 28000 certification cost is made of

Cost line Who is paid What decides it Typical 2026 range (USD)
The standard ISO or national body Fixed ISO 28000:2022 from the ISO Store; ISO 28001:2007 optional for supply chain best practice
Certification body: stage 1 + stage 2 Accredited certification body Effective personnel, sites, complexity, day rate $5,000 to $20,000
Certification body: surveillance × 2 Same About one-third of initial audit time per year $1,500 to $7,000 per year
Certification body: recertification Same About two-thirds of a fresh initial audit $3,500 to $14,000
SMS documentation Template supplier or consultant Build, adapt a template pack ($99), or commission $99 to $15,000
Consultancy (optional) Consultant Risk assessment facilitation, gap analysis, internal audit $0 to $30,000
Training Provider Security awareness; internal auditor course $500 to $6,000
Internal staff time Opportunity cost Process identification (8.2), risk assessment (8.3), procedures and plans (8.5, 8.6), audit and review $10,000 to $90,000 equivalent
Controls the risk assessment determines Contractors and vendors Site condition; findings of 8.3; customer and customs requirements $0 to $250,000+ — separate budget

Planning ranges, not quotes. Certification bodies quote per organisation; audit time for a security management system is commonly scaled from the Global ACI audit-time tables (Global ACI-TECH-3-004, formerly IAF MD 5), which set surveillance at about one-third and recertification at about two-thirds of the initial audit. Our guide to ISO 22301 certification cost covers the sister standard ISO 28000 is most often integrated with.

ISO 28000 certification cost by size of operation

Line Single warehouse or forwarder (≤30 staff) Regional logistics operator (100–300 staff, 2–5 sites) Port, terminal or national 3PL (500+ staff, multi-site)
Stage 1 + stage 2 $5,000 to $8,000 $9,000 to $16,000 $16,000 to $35,000+
Surveillance × 2 $3,500 to $6,000 $6,000 to $11,000 $11,000 to $24,000
Recertification $3,500 to $6,000 $6,500 to $11,000 $11,000 to $25,000
Documentation and training $600 to $6,000 $2,000 to $15,000 $5,000 to $25,000
Consultancy $0 to $8,000 $5,000 to $20,000 $10,000 to $40,000
Internal time $10,000 to $25,000 $25,000 to $60,000 $60,000 to $150,000
Three-year cash cost (excluding internal time and controls) $13,000 to $34,000 $29,000 to $73,000 $53,000 to $149,000+
Three-year total (excluding controls) $23,000 to $59,000 $54,000 to $133,000 $113,000 to $299,000+

What drives the audit days behind ISO 28000 certification cost

Driver Effect How to manage it
Effective personnel The base band; drivers, warehouse staff and security guards count Count accurately, including contracted security
Sites and yards Each site in scope adds time unless multi-site sampling applies (Global ACI-TECH-3-001, ex-IAF MD 1) Central control and common procedures make sampling defensible
Scope of security The 2022 edition covers any security risk; a scope limited to the supply chain is smaller than one covering all sites and operations Scope to what customers and customs require; extend later
Integration Reduction for integrated audits with ISO 9001, ISO 22301 or ISO 27001 under Global ACI-TECH-3-008 (ex-IAF MD 11) Share clauses 4–7, 9, 10
Night and shift operations Auditors sample the operation as it runs, including nights Plan audit days around shifts; expect some out-of-hours time

The controls line: why ISO 28000 certification cost is two budgets

Clause 8.3 requires the security risks to be assessed and treated; 8.4 requires the controls determined by that treatment to be implemented; 8.6 requires security plans. An organisation cannot certify a system whose risk assessment says the yard needs CCTV and lighting and whose yard has neither — the auditor will raise it under 8.4.

The controls budget therefore has to be estimated before the certification date is set, and it is the widest line of all: a warehouse with fencing, lighting, alarms and access control in place spends little; a greenfield yard or a site inheriting a customer’s C-TPAT-driven requirements can spend six figures. Keep it as a separate budget with its own approvals, sequence it before stage 2, and use the risk assessment to justify each item. Our guide to the supply chain security risk assessment covers the assessment that sizes it.

Four decisions that move ISO 28000 certification cost

  1. Integrate with a system you already certify. ISO 28000:2022 is on the harmonized structure and its foreword records changes made “for better consistency with ISO 22301”; a BCMS or QMS already carries clauses 4–7, 9 and 10.
  2. Run the risk assessment before booking the audit. Its output sizes the controls budget and the timeline; booking first and assessing second is how stage 2 is postponed.
  3. Adapt template documentation. The auditor tests whether procedures describe the operation, not who wrote them.
  4. Get the three-year quote with days shown. Stage 1, stage 2, two surveillance visits and recertification in one figure.

Frequently asked questions

How much does ISO 28000 certification cost?
As a planning range, $13,000 to $34,000 in cash over three years for a single-site forwarder or warehouse, $29,000 to $73,000 for a regional operator and $53,000 to $149,000 or more for a port, terminal or national 3PL — before internal time and before the physical, procedural and cyber controls the risk assessment determines.

Why is the controls budget separate?
Because it depends on the site and the risk assessment, not the standard. Clause 8.4 requires the controls determined under 8.3 to be implemented, so a system cannot certify with them missing, but a site that already has fencing, lighting, alarms and access control spends little.

Is C-TPAT cheaper than ISO 28000?
C-TPAT has no membership fee, so its cost is implementation and validation preparation only. The controls overlap heavily, which is why an operation doing both should run one system; see our ISO 28000 vs C-TPAT guide.

How long does it take?
Four to nine months for an operator with existing security procedures; longer where controls have to be installed, because the audit tests the controls as implemented.

Can we integrate ISO 28000 with ISO 22301 or ISO 9001?
Yes. The 2022 edition uses the harmonized structure and was aligned with ISO 22301 deliberately; integrated audits reduce audit time under Global ACI-TECH-3-008.

Where this leaves you

Budget ISO 28000 certification cost as two budgets: the certification and system budget over a three-year cycle, and the controls budget the risk assessment produces. Run the assessment first, integrate with whatever you already certify, adapt documentation rather than commissioning it, and get the full-cycle quote with the day count shown from at least two accredited bodies.

References

More on supply chain security

The 29 templates that cover the documentation line — SMS manual and policy, process and activity register, security risk assessment and treatment workbook, control procedures, security plans and the audit set — are in the ISO 28000 Supply Chain Security Toolkit for $99, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.