ISO 28000 certification cost is built from the same four invoices as any management system certification — the certification body’s audit fees over a three-year cycle, the cost of building the security management system, optional consultancy, and internal staff time — plus a fifth line that other standards do not carry: the physical and technical controls a security risk assessment tends to find missing.
Fences, lighting, CCTV, access control, seal programmes and cyber measures are not certification costs in the strict sense, but a system certified to ISO 28000:2022 has to have implemented the controls its clause 8.3 risk assessment determined, so the budget that ignores them is the one that overruns. This guide builds the ISO 28000 certification cost line by line with labelled typical ranges for three sizes of operation, explains what drives the audit-day count, shows the three-year total, separates the controls spend from the certification spend, and names the decisions that move the figure most.

What ISO 28000 certification cost is made of
| Cost line | Who is paid | What decides it | Typical 2026 range (USD) |
|---|---|---|---|
| The standard | ISO or national body | Fixed | ISO 28000:2022 from the ISO Store; ISO 28001:2007 optional for supply chain best practice |
| Certification body: stage 1 + stage 2 | Accredited certification body | Effective personnel, sites, complexity, day rate | $5,000 to $20,000 |
| Certification body: surveillance × 2 | Same | About one-third of initial audit time per year | $1,500 to $7,000 per year |
| Certification body: recertification | Same | About two-thirds of a fresh initial audit | $3,500 to $14,000 |
| SMS documentation | Template supplier or consultant | Build, adapt a template pack ($99), or commission | $99 to $15,000 |
| Consultancy (optional) | Consultant | Risk assessment facilitation, gap analysis, internal audit | $0 to $30,000 |
| Training | Provider | Security awareness; internal auditor course | $500 to $6,000 |
| Internal staff time | Opportunity cost | Process identification (8.2), risk assessment (8.3), procedures and plans (8.5, 8.6), audit and review | $10,000 to $90,000 equivalent |
| Controls the risk assessment determines | Contractors and vendors | Site condition; findings of 8.3; customer and customs requirements | $0 to $250,000+ — separate budget |
Planning ranges, not quotes. Certification bodies quote per organisation; audit time for a security management system is commonly scaled from the Global ACI audit-time tables (Global ACI-TECH-3-004, formerly IAF MD 5), which set surveillance at about one-third and recertification at about two-thirds of the initial audit. Our guide to ISO 22301 certification cost covers the sister standard ISO 28000 is most often integrated with.
ISO 28000 certification cost by size of operation
| Line | Single warehouse or forwarder (≤30 staff) | Regional logistics operator (100–300 staff, 2–5 sites) | Port, terminal or national 3PL (500+ staff, multi-site) |
|---|---|---|---|
| Stage 1 + stage 2 | $5,000 to $8,000 | $9,000 to $16,000 | $16,000 to $35,000+ |
| Surveillance × 2 | $3,500 to $6,000 | $6,000 to $11,000 | $11,000 to $24,000 |
| Recertification | $3,500 to $6,000 | $6,500 to $11,000 | $11,000 to $25,000 |
| Documentation and training | $600 to $6,000 | $2,000 to $15,000 | $5,000 to $25,000 |
| Consultancy | $0 to $8,000 | $5,000 to $20,000 | $10,000 to $40,000 |
| Internal time | $10,000 to $25,000 | $25,000 to $60,000 | $60,000 to $150,000 |
| Three-year cash cost (excluding internal time and controls) | $13,000 to $34,000 | $29,000 to $73,000 | $53,000 to $149,000+ |
| Three-year total (excluding controls) | $23,000 to $59,000 | $54,000 to $133,000 | $113,000 to $299,000+ |
What drives the audit days behind ISO 28000 certification cost
| Driver | Effect | How to manage it |
|---|---|---|
| Effective personnel | The base band; drivers, warehouse staff and security guards count | Count accurately, including contracted security |
| Sites and yards | Each site in scope adds time unless multi-site sampling applies (Global ACI-TECH-3-001, ex-IAF MD 1) | Central control and common procedures make sampling defensible |
| Scope of security | The 2022 edition covers any security risk; a scope limited to the supply chain is smaller than one covering all sites and operations | Scope to what customers and customs require; extend later |
| Integration | Reduction for integrated audits with ISO 9001, ISO 22301 or ISO 27001 under Global ACI-TECH-3-008 (ex-IAF MD 11) | Share clauses 4–7, 9, 10 |
| Night and shift operations | Auditors sample the operation as it runs, including nights | Plan audit days around shifts; expect some out-of-hours time |
The controls line: why ISO 28000 certification cost is two budgets
Clause 8.3 requires the security risks to be assessed and treated; 8.4 requires the controls determined by that treatment to be implemented; 8.6 requires security plans. An organisation cannot certify a system whose risk assessment says the yard needs CCTV and lighting and whose yard has neither — the auditor will raise it under 8.4.
The controls budget therefore has to be estimated before the certification date is set, and it is the widest line of all: a warehouse with fencing, lighting, alarms and access control in place spends little; a greenfield yard or a site inheriting a customer’s C-TPAT-driven requirements can spend six figures. Keep it as a separate budget with its own approvals, sequence it before stage 2, and use the risk assessment to justify each item. Our guide to the supply chain security risk assessment covers the assessment that sizes it.
Four decisions that move ISO 28000 certification cost
- Integrate with a system you already certify. ISO 28000:2022 is on the harmonized structure and its foreword records changes made “for better consistency with ISO 22301”; a BCMS or QMS already carries clauses 4–7, 9 and 10.
- Run the risk assessment before booking the audit. Its output sizes the controls budget and the timeline; booking first and assessing second is how stage 2 is postponed.
- Adapt template documentation. The auditor tests whether procedures describe the operation, not who wrote them.
- Get the three-year quote with days shown. Stage 1, stage 2, two surveillance visits and recertification in one figure.
Frequently asked questions
How much does ISO 28000 certification cost?
As a planning range, $13,000 to $34,000 in cash over three years for a single-site forwarder or warehouse, $29,000 to $73,000 for a regional operator and $53,000 to $149,000 or more for a port, terminal or national 3PL — before internal time and before the physical, procedural and cyber controls the risk assessment determines.
Why is the controls budget separate?
Because it depends on the site and the risk assessment, not the standard. Clause 8.4 requires the controls determined under 8.3 to be implemented, so a system cannot certify with them missing, but a site that already has fencing, lighting, alarms and access control spends little.
Is C-TPAT cheaper than ISO 28000?
C-TPAT has no membership fee, so its cost is implementation and validation preparation only. The controls overlap heavily, which is why an operation doing both should run one system; see our ISO 28000 vs C-TPAT guide.
How long does it take?
Four to nine months for an operator with existing security procedures; longer where controls have to be installed, because the audit tests the controls as implemented.
Can we integrate ISO 28000 with ISO 22301 or ISO 9001?
Yes. The 2022 edition uses the harmonized structure and was aligned with ISO 22301 deliberately; integrated audits reduce audit time under Global ACI-TECH-3-008.
Where this leaves you
Budget ISO 28000 certification cost as two budgets: the certification and system budget over a three-year cycle, and the controls budget the risk assessment produces. Run the assessment first, integrate with whatever you already certify, adapt documentation rather than commissioning it, and get the full-cycle quote with the day count shown from at least two accredited bodies.
References
- ISO 28000:2022 — Security and resilience — Security management systems — Requirements — Second edition, March 2022, with Amd 1:2024.
- Global ACI-TECH-3-004 (M) — Determination of Audit Time — Formerly IAF MD 5; the audit-time tables and the 1/3 surveillance, 2/3 recertification rules.
- Global ACI-TECH-3-008 (M) — Audits of Integrated Management Systems — Formerly IAF MD 11.
More on supply chain security
- ISO 28000 certification cost — you are here
- ISO 28000:2022 explained
- ISO 28000 vs C-TPAT
- ISO 28000 mandatory documents
- Supply chain security risk assessment
- ISO 22301 certification cost
The 29 templates that cover the documentation line — SMS manual and policy, process and activity register, security risk assessment and treatment workbook, control procedures, security plans and the audit set — are in the ISO 28000 Supply Chain Security Toolkit for $99, or start with the free templates.