ISO 28000:2022 — Securing the Supply Chain from End to End
Supply chains are the arteries of the global economy, and they are also one of its softest targets. Goods in transit, warehouses full of stock, and the information that coordinates it all are exposed to theft, tampering, smuggling and worse. ISO 28000:2022 is the international standard that helps organizations manage these threats systematically. This guide explains what ISO 28000 covers, who it is for, and how a security management system is built and certified. It is written for security managers, logistics and operations personnel, risk professionals and senior leaders who depend on goods moving safely and predictably.
What is ISO 28000?
ISO 28000:2022 specifies requirements for a security management system, including the aspects relevant to the security of the supply chain. It enables organizations to establish, implement, maintain and improve controls that safeguard people, goods, infrastructure, information and operations against security threats.
The standard's purpose is to help organizations assess security risks across their own activities and their supply chains, and then implement proportionate measures to prevent, detect, respond to and recover from security-related incidents. Those incidents span a broad spectrum — theft, smuggling, tampering, terrorism, sabotage and other malicious acts.
The 2022 revision brought the standard into line with the ISO harmonized high-level structure, so it now follows the familiar sequence of context, leadership, planning, support, operation, performance evaluation and improvement, driven by the Plan-Do-Check-Act cycle and a strong risk-based approach consistent with ISO 31000.
Who needs it and who it applies to
ISO 28000 is deliberately broad in scope. It applies to organizations of any size and sector that are involved in — or rely upon — manufacturing, service provision, storage, transportation or the movement of goods. That includes manufacturers, logistics and freight operators, warehousing providers, ports, distributors and the many businesses whose operations depend on a secure flow of materials.
Within those organizations, it speaks to:
- Security managers designing and running protective controls.
- Logistics and operations personnel who handle goods and movements daily.
- Risk professionals assessing threats across the chain.
- Senior leadership accountable for resilience and continuity.
Key benefits of certification
A security management system built on ISO 28000 turns security from a patchwork of reactive measures into a coherent, auditable discipline. The benefits reach across operations, finance and reputation.
They include:
- Enhanced resilience and continuity of supply, so disruptions are contained.
- Reduced losses and liabilities from theft, damage and interruption.
- Improved regulatory and customer confidence in the organization's controls.
- A systematic, auditable approach to security governance rather than ad-hoc responses.
What's inside the management system
At its core, ISO 28000 asks the organization to understand its threats and then design controls proportionate to them. Key components include:
- Understanding the internal and external context and the needs of interested parties.
- A security policy and objectives endorsed by leadership.
- Security risk assessment and treatment to identify threats and decide how to address them.
- Operational planning and control covering the day-to-day security of activities and goods.
- Resources and competence, ensuring people are equipped and trained.
- Preparedness and response for disruptive and security events.
- Performance evaluation, internal audit and management review to measure effectiveness.
- Continual improvement as threats evolve.
The structure of the standard
Following Annex SL, the standard's clauses move logically from context and leadership through planning, support and operation to evaluation and improvement. The risk-based approach runs through all of it: rather than prescribing a fixed set of security measures, ISO 28000 requires the organization to assess its own risks and apply controls that fit. This makes it equally usable by a small freight forwarder and a multinational manufacturer.
Because it shares the harmonized structure, ISO 28000 integrates readily with other management system standards — ISO 9001 for quality, ISO 22301 for business continuity and ISO 27001 for information security. It also complements broader supply-chain security programs, including customs and trade initiatives, giving organizations a single internal framework that supports multiple external expectations.
The road to certification
ISO 28000 is a certifiable standard, so organizations can pursue accredited third-party certification to demonstrate the effectiveness of their supply-chain security management. The journey typically runs as follows:
- Gap analysis — assess current security arrangements against the standard's requirements.
- Implementation — establish the security policy, conduct risk assessment and treatment, and put operational controls in place.
- Operation — run the system, train staff, and generate records showing controls are working.
- Internal audit and management review — verify readiness and correct weaknesses.
- Stage 1 audit — a certification body reviews documentation and overall readiness.
- Stage 2 audit — the auditor evaluates the system in operation and confirms conformity.
- Surveillance and recertification — periodic audits maintain the certificate and confirm continual improvement.
Certification provides independent assurance to partners and authorities that supply-chain security is established, effective and improving — increasingly a differentiator in competitive tenders.
How AGS can help
Designing a security management system that satisfies ISO 28000 across a complex supply chain is demanding work. The AGS ISO 28000:2022 Management System toolkit, part of our Standard tier, gives you a structured, professional foundation. It provides editable manuals, procedures, security risk assessment templates, response plans, forms and compliance matrices mapped directly to the clauses of the standard.
Instead of building security documentation from nothing, your team tailors proven templates to your operations, routes and threats. The kit streamlines implementation, brings consistency to how security risks are assessed and controlled, and accelerates your path to audit-readiness. Contact the AGS Compliance Team to secure your supply chain with confidence.