Skip to main content
Category: Regulatory Frameworks

ISO 28000

Also known as: ISO 28000:2022, ISO 28000:2007, Security and resilience — Security management systems
Simply put

ISO 28000 is an international standard that helps organizations set up a management system for handling security concerns related to their supply chains. It provides a structured framework for identifying and managing security risks, but it focuses on security rather than covering every type of supply chain risk. An organization can build its practices around this standard, and in some cases seek certification against it.

Formal definition

ISO 28000 is a high-level, requirements-based management system standard that specifies criteria for establishing, implementing, and maintaining a security management system, including aspects critical to the security assurance of the supply chain. The current edition, ISO 28000:2022 (published under the "Security and resilience" family and superseding ISO 28000:2007), is intended to be applicable to organizations of varying types and sizes. Its scope centers on security management as it relates to supply chain operations; it does not by itself address the full spectrum of supply chain risk domains such as financial, operational, geopolitical, or ESG risk except where these intersect with security assurance. As a management system standard, conformity may be independently certified, but certification attests to conformity with the standard's requirements at a point in time and does not by itself guarantee the absence of security incidents or extend visibility across all tiers of a supply chain.

Why it matters

Supply chain security spans a wide range of threats, from physical tampering and cargo theft to unauthorized access and disruption of logistical flows, that individual, ad hoc controls often address inconsistently. ISO 28000 matters because it gives organizations a structured, requirements-based management system for security assurance across supply chain operations, allowing them to move from fragmented practices to a repeatable framework for identifying, managing, and reviewing security risks. As a high-level management system standard, it is designed to be applicable to organizations of varying types and sizes, which makes it a common reference point when parties across a supply chain need a shared vocabulary for security expectations.

It is important to be clear about what ISO 28000 is and is not. Its scope centers on security management as it relates to the supply chain; it does not by itself cover the full spectrum of supply chain risk domains such as financial, operational, geopolitical, or ESG risk, except where those intersect with security assurance. Organizations that treat conformity with ISO 28000 as evidence of broad supply chain resilience or risk coverage may overstate what the standard delivers.

Equally important, certification against ISO 28000 attests to conformity with the standard's requirements at a point in time. It does not guarantee the absence of security incidents, nor does it by itself extend visibility across all tiers of a supply chain. Risk professionals relying on a supplier's certification should treat it as one input into due diligence rather than as independent assurance that security controls remain effective over time or that deeper tiers of the supply chain are equally governed.

Who it's relevant to

Supply chain security and resilience managers
Professionals responsible for securing supply chain operations can use ISO 28000 as a structured framework to establish and maintain a security management system, giving fragmented controls a repeatable, requirements-based foundation. They should recognize that the standard centers on security assurance and does not, by itself, address financial, operational, geopolitical, or ESG risk except where those intersect with security.
Procurement and third-party risk teams
Teams assessing suppliers may treat a supplier's ISO 28000 certification as one input into due diligence. It is useful evidence of a documented security management system, but because certification reflects conformity at a point in time and does not extend visibility across all tiers, it should complement rather than replace ongoing monitoring and independent verification.
Compliance and audit functions
Compliance and internal audit staff can reference ISO 28000 when evaluating whether an organization's supply chain security management system aligns with a recognized standard. They should be careful to distinguish conformity with the standard's requirements from a guarantee of incident-free operation, and to note which risk domains fall outside the standard's security scope.
Logistics and operations leaders
Those managing the physical and logistical flow of goods can apply the standard's framework to embed security considerations into supply chain operations. Because ISO 28000 is designed to be applicable to organizations of varying types and sizes, it can be scaled to different operational contexts, though it prescribes a management system rather than specific technical safeguards.

Inside ISO 28000

Security management system scope
ISO 28000 specifies requirements for a management system focused on security within the supply chain, framing security as one dimension of risk to be managed through a structured, auditable process rather than addressing all supply chain risk categories at once.
Risk assessment and treatment approach
The standard directs organizations to identify security-related threats and vulnerabilities, assess their significance, and apply treatment measures proportionate to the assessed risk, typically informed by the organization's own risk tolerance and operating context.
Plan-Do-Check-Act structure
Like other ISO management system standards, it is generally organized around a continual improvement cycle, covering policy, planning, implementation, performance evaluation, and management review rather than prescribing specific technical controls.
Leadership and policy requirements
It calls for management commitment, a defined security management policy, assigned roles and responsibilities, and objectives against which performance can be monitored.
Operational and continual improvement elements
The standard addresses operational planning and control, monitoring and measurement, internal audit, and corrective action, so that the security management system is maintained and adjusted over time rather than treated as a one-time exercise.

Common questions

Answers to the questions practitioners most commonly ask about ISO 28000.

Does ISO 28000 certification confirm that a supplier's supply chain is secure?
No. ISO 28000 specifies requirements for a security management system, and certification (where obtained) indicates that an organization has established and maintains such a management system that conforms to the standard's requirements. It does not attest that the supply chain itself is secure, that specific threats have been eliminated, or that outcomes are guaranteed. A certificate reflects conformity of the management system, assessed at a point in time by a certification body, and should not be read as independent verification of the security state of any particular shipment, facility, or relationship.
Is ISO 28000 the same as an information security standard like ISO 27036?
No. ISO 28000 addresses security management for supply chain operations, oriented toward the physical and logistical movement of goods and related security threats, whereas ISO 27036 addresses information security in supplier relationships. They occupy different scopes and are not interchangeable. An organization may reference one, both, or neither depending on the risks it is managing. Treating an ISO 28000 management system as covering information security risks in supplier relationships would overstate its scope.
How does ISO 28000 typically fit alongside our existing TPRM or SCRM program?
In many programs, ISO 28000 is used as a framework for the supply chain security management system component rather than as the whole of third-party or supply chain risk management. It can complement broader TPRM activities that also cover financial, operational, geopolitical, or ESG risk dimensions the standard does not primarily address. Whether it is adopted internally as guidance or pursued as a certifiable requirement for suppliers depends on the program's risk appetite, sector, and the tiers of the supply chain in scope.
Can we require ISO 28000 certification from our suppliers as a contractual control?
Depending on the risk tier and sector, some organizations do specify ISO 28000 certification or conformance as a supplier requirement. If used this way, it is worth clarifying in the contract what the certification covers, what scope of the supplier's operations it applies to, and what evidence beyond the certificate is expected. A certificate applies to the certified scope only, so a supplier's certification may not extend to every facility, business unit, or relationship relevant to your engagement.
Does an ISO 28000 management system replace ongoing monitoring of a supplier?
Not on its own. A management system standard supports structured, repeatable processes, but conformity is typically assessed periodically, and the state it reflects can become stale between assessments. Programs generally treat certification or conformance as one input alongside ongoing monitoring, since a point-in-time evaluation does not capture changes in a supplier's operations, ownership, threat environment, or risk posture that may occur afterward.
What does ISO 28000 not cover that we may need to address separately?
Because the standard centers on security management for supply chain operations, organizations often find that financial risk, information security in supplier relationships, ESG and labor considerations, and multi-tier or Nth-party visibility fall outside or only partially within its scope. Regulatory expectations also vary across regions and sectors, so conformance with the standard does not by itself establish compliance with any particular jurisdiction's requirements. These areas typically need to be addressed through complementary frameworks, controls, or due diligence.

Common misconceptions

ISO 28000 certification guarantees that an organization's supply chain is secure.
Certification, where obtained, indicates that a security management system meeting the standard's requirements is in place and has been assessed; it does not eliminate security risk, verify the security posture of every supplier tier, or guarantee against incidents. It reflects process conformance, not an outcome guarantee.
ISO 28000 covers all forms of supply chain risk, including financial, operational, geopolitical, and ESG risk.
The standard is focused on security within the supply chain. It does not, by itself, address financial stability, quality, business continuity, ESG, or other risk categories, which are typically managed through separate frameworks or complementary standards.
Adopting ISO 28000 is the same as implementing supply chain risk management (SCRM).
ISO 28000 provides a security management system that can support SCRM, but SCRM is broader, extending across multiple tiers and the physical and logistical flows of goods and services. ISO 28000 addresses one component and does not substitute for a full multi-tier SCRM program.

Best practices

Scope the ISO 28000 security management system explicitly, documenting which security risks and which parts of the supply chain it covers and which risk categories (financial, ESG, continuity, quality) are handled elsewhere.
Integrate the standard's security controls with adjacent frameworks and programs so that non-security risks are not assumed to be covered by ISO 28000 conformance.
Treat security risk assessments as recurring rather than point-in-time, refreshing them as threats, suppliers, and operating context change to avoid stale results.
Distinguish self-attested conformance from independently verified conformance when relying on a supplier's ISO 28000 status, and confirm the certification scope and issuing body rather than assuming full coverage.
Extend security expectations beyond the first tier where feasible, recognizing that a management system at the direct supplier does not by itself provide visibility into fourth-party or Nth-party security practices.
Use internal audit, management review, and corrective action mechanisms to drive continual improvement, rather than treating certification as a completed, static achievement.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide