ISO 28000:2022 CertificationSupply Chain Security Management

Protect people, goods and infrastructure across your supply chain with ISO 28000 security management certification.

Stage 1 & Stage 2 auditsSurveillance auditsOnline verification
ISOCertified
management system
About the Standard

What is ISO 28000:2022?

ISO 28000 specifies requirements for a security management system, including aspects critical to security assurance of the supply chain such as theft, tampering, smuggling and disruption.

Who is it for?

  • Ports, terminals and freight forwarders
  • Logistics and warehousing companies
  • Manufacturers and exporters
  • Oil, gas and critical infrastructure
Start Your Certification
Structure of the Standard

Key Requirements (Clauses 4–10)

ISO 28000:2022 follows the common high‑level structure shared by ISO management system standards, making it easy to integrate with other standards.

4

Context of the organisation

Understand internal and external issues and interested parties.

5

Leadership

Top management commitment, policy and responsibilities.

6

Planning

Risks, opportunities and measurable objectives.

7

Support

Resources, competence, awareness and documented information.

8

Operation

Planning and control of the processes that deliver results.

9

Performance evaluation

Monitoring, internal audit and management review.

10

Improvement

Corrective action and continual improvement.

Certification Process

How to Get ISO 28000:2022 Certified

1

Application

Submit an application with details of your organisation, sites, scope and standard(s).

2

Quotation & agreement

We review the application, confirm audit duration and send a quotation and certification agreement.

3

Stage 1 audit

Review of your documentation and readiness for the Stage 2 audit.

4

Stage 2 audit

On‑site audit to evaluate the implementation and effectiveness of your management system.

5

Certification decision

Independent review of audit results and, once any non‑conformities are closed, certificate issue.

6

Surveillance audits

Periodic audits to confirm your system continues to meet the standard while you are certified.

7

Recertification

A recertification audit before your certificate expires to renew your certification.

Training for Your Team

Awareness, internal auditor and lead auditor courses for ISO 28000 and other standards.

View ISO courses

Verify a Certificate

Check whether a certificate issued by SRA is valid.

Verify now

Rules & Regulations

Read the conditions that apply to certified clients.

Read the rules
FAQ

Frequently Asked Questions

It depends on your organisation’s size, complexity and readiness. After reviewing your application we will give you a clear timeline.

Certificate validity depends on the type of certification and the scheme requirements. The validity period is confirmed in your certification agreement and shown on your certificate, and certification is maintained through surveillance audits.

Yes. It can be audited together with other ISO management system standards in an integrated audit.