Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 28000 vs C-TPAT explained

ISO 28000 vs C-TPAT: 4 Clear Differences Explained (2026)

ISO 28000 vs C-TPAT is a comparison between two things that are usually mistaken for alternatives and are in fact different kinds of instrument. ISO 28000:2022 is a certifiable management system standard — “Security and resilience — Security management systems — Requirements” — that any organisation can implement and have audited by an accredited certification body anywhere in the world. C-TPAT (CBP now writes CTPAT, the Customs Trade Partnership Against Terrorism) is a voluntary U.S.

Customs and Border Protection partnership programme, open only to eligible categories of the trade community — importers, carriers, brokers, consolidators, port and terminal operators, and Mexican and Canadian manufacturers — that validates a member’s supply chain security profile against CBP’s Minimum Security Criteria in exchange for border benefits. One is a standard with a certificate; the other is a customs programme with a membership. This guide sets out the four differences that decide which you need, compares the two documents clause by criterion, explains where they overlap and reinforce each other, and shows how a logistics operator uses ISO 28000 as the system that produces the C-TPAT evidence.

ISO 28000 vs C-TPAT: a standard and a customs programme
ISO 28000:2022 — certifiable security management system, any organisation, accredited audit · C-TPAT — CBP partnership, eligible U.S. trade categories, Minimum Security Criteria, validation, border benefits.

ISO 28000 vs C-TPAT at a glance

Dimension ISO 28000:2022 C-TPAT (CTPAT)
What it is International management system standard; second edition March 2022; ISO/TC 292; Amd 1:2024 (climate change) Voluntary CBP supply chain security partnership, launched November 2001
Who can use it Any organisation, any sector, any country — the abstract calls it “a holistic and common approach”, “not industry or sector specific” Eligible categories: U.S. importers and exporters, U.S./Canada and U.S./Mexico highway carriers, rail and sea carriers, licensed customs brokers, marine port and terminal operators, consolidators, NVOCCs, Mexican and Canadian manufacturers
What you are measured against Clauses 4–10 of the standard; controls determined by your own risk assessment (8.3, 8.4) CBP’s Minimum Security Criteria (MSC) for your category — for U.S. importers, the October 2021 MSC: 12 categories in three focus areas, criteria marked Must or Should
Who checks An accredited certification body: stage 1, stage 2, annual surveillance, three-year cycle CBP Supply Chain Security Specialists: security profile review, then validation visits
What you get A certificate Membership and tiered benefits: fewer examinations, front-of-line inspections, FAST lanes, an assigned specialist, mutual recognition with partner customs administrations
Cost Certification body fees plus implementation No fee to join; implementation and validation preparation
Scope of security Any security risk the organisation faces — the 2022 edition widened it beyond the supply chain Supply chain security against terrorism and criminal exploitation of cargo

The four differences that decide ISO 28000 vs C-TPAT

  1. Eligibility. ISO 28000 is open to everyone. C-TPAT is open to defined trade categories with a U.S. nexus — an importer must be an active U.S. importer or non-resident Canadian importer with a valid continuous import bond. A European warehouse operator with no U.S. trade cannot join C-TPAT; it can certify to ISO 28000. Our guide to the Authorised Economic Operator covers the customs programme that plays C-TPAT’s role in the EU and elsewhere.
  2. Prescription. ISO 28000 prescribes a system, not controls: clause 8.3 requires risk assessment and treatment, 8.4 requires controls to be determined from it, 8.6 requires security plans. C-TPAT prescribes criteria — seals, conveyance inspection, access control, personnel screening, cybersecurity — each marked Must (required) or Should (expected practice). ISO 28000 lets you argue a control is unnecessary; a C-TPAT Must does not.
  3. Assurance model. ISO 28000 uses third-party accredited certification; the certificate is recognised through the accreditation system. C-TPAT uses CBP’s own validation; recognition abroad comes through mutual recognition arrangements between CBP and partner customs administrations.
  4. What the customer is buying. A shipper asking for ISO 28000 wants assurance that security is managed as a system. A customs administration granting C-TPAT benefits wants assurance that this supply chain is low-risk at the border. Both can be true of the same operation; the paperwork proving each is different.

ISO 28000 vs C-TPAT: where they overlap

Topic ISO 28000:2022 clause C-TPAT importer MSC category Shared evidence
Management commitment and policy 5.1 Leadership; 5.2 Security policy 1 Security Vision & Responsibility Signed policy or statement of support; named security owner
Risk assessment 8.3 Risk assessment and treatment 2 Risk Assessment Documented risk assessment of the supply chain, reviewed annually and on change
Business partners and suppliers 4.2 Interested parties; 8.1 outsourced processes 3 Business Partners Partner screening, security requirements in contracts, monitoring
Cybersecurity 8.4 Controls (as determined) 4 Cybersecurity Policies, access, patching, incident response — 13 importer criteria
Conveyance, seals and cargo handling 8.4 Controls; 8.5 procedures; 8.6 plans 5 Conveyance and IIT Security; 6 Seal Security; 7 Procedural Security Inspection checklists, seal procedures (ISO 17712 high-security seals), documentation controls
Physical security and access 8.4 Controls 9 Physical Security; 10 Physical Access Controls Perimeter, lighting, alarms, visitor and badge controls
People 7.2 Competence; 7.3 Awareness 11 Personnel Security; 12 Education, Training and Awareness Screening, training records, awareness programme
Performance and improvement 9.1–9.3; 10 Annual security profile review; validation findings Audit results, corrective actions, management review

The overlap is the practical answer to ISO 28000 vs C-TPAT, and it settles most ISO 28000 vs C-TPAT debates inside a logistics business: an ISO 28000 system whose risk assessment takes the MSC as an input produces the C-TPAT security profile as an output, and a C-TPAT member that wants a certificate for non-U.S. customers has most of clause 8 already evidenced. ISO 28001:2007, still published, was written to align a security management system with customs programmes of exactly this kind. Our guide to ISO 28000:2022 covers the clauses; our C-TPAT guide covers the criteria.

Choosing ISO 28000 vs C-TPAT

Situation Choose Why
U.S. importer with inbound ocean freight; customers do not ask for a certificate C-TPAT Border benefits pay for the work; no fee to join
Freight forwarder or 3PL in Europe, Asia or the Middle East serving multinationals ISO 28000 Certifiable anywhere; recognised through accreditation; tender requirement
Mexican or Canadian manufacturer shipping to the U.S. C-TPAT, with ISO 28000 where non-U.S. customers require it Eligible category; FAST lanes and reduced examinations
Port or terminal operator with U.S. and international customers Both, on one system ISO 28000 clause 8 produces the MSC evidence; one risk assessment serves both
Organisation with security risks beyond cargo — sites, people, operations ISO 28000 The 2022 edition is a general security management system standard
EU-based operator asked about C-TPAT AEO, then mutual recognition C-TPAT is not open to it; AEO is recognised by CBP under the EU–U.S. arrangement

Frequently asked questions

Is C-TPAT the same as ISO 28000?
No. ISO 28000:2022 is a certifiable international management system standard for security management; C-TPAT is a voluntary U.S. Customs and Border Protection partnership programme for eligible trade categories, validated against CBP’s Minimum Security Criteria. One produces a certificate, the other a membership with border benefits.

Can an ISO 28000 certificate replace C-TPAT membership?
No. C-TPAT benefits — reduced examinations, FAST lanes, front-of-line inspections — come only with membership. An ISO 28000 system makes the C-TPAT security profile far easier to complete and validate.

Does C-TPAT accept ISO 28000 as evidence?
The security profile is written against the MSC, and ISO 28000 records — risk assessment, controls, procedures, training — are the evidence behind many criteria. CBP validates against its criteria, not against the certificate.

Which is cheaper?
C-TPAT has no membership fee; ISO 28000 carries certification body fees across a three-year cycle. Implementation cost is similar because the controls overlap; our ISO 28000 certification cost guide gives ranges.

What about AEO?
The Authorised Economic Operator programme is the World Customs Organization SAFE Framework’s equivalent of C-TPAT in the EU and other jurisdictions. CBP and the EU recognise each other’s programmes, which is how a European AEO obtains C-TPAT-equivalent treatment.

Where this leaves you

Settle ISO 28000 vs C-TPAT by asking who wants the assurance. A customs administration wants C-TPAT or AEO; a customer or tender wants ISO 28000; a port, carrier or manufacturer serving both wants one security management system whose risk assessment takes the Minimum Security Criteria as input, so that the certificate and the membership are two outputs of the same work.

References

More on supply chain security

The Security Management System Manual and Policy, the supply chain security risk assessment, the access, cargo and seal control procedures and the C-TPAT/AEO cross-mapping are in the ISO 28000 Supply Chain Security Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.