ISO 28000 Certification: Security Management System

Address potential security issues across activities, functions and operations at all stages of the supply chain.

Journey continues on Veracity, DNV's trusted digital platform.

ISO 28000 Certification: Security Management System

Certification of your security management system to ISO 28000 demonstrates that you are working to manage and reduce security risks across all functions that influence the safe and reliable flow of goods, services, information and resources. Its helps manage potential issues such as theft, tampering, sabotage, counterfeiting, cyber incidents or operational disruptions. A security management system contributes to stronger resilience, more stable operations, improved business continuity and reputation, and ticket-to-trade where certification may be required.

The ISO 28000 standard provides specific requirements for a security management system that enhances your ability to prevent, manage, mitigate and recover from security related disruptions. It supports a structured, organization wide approach to identifying threats, implementing effective controls and ensuring secure and efficient performance across your operations and supply chain.

What is the ISO 28000 standard?

ISO 28000 is applicable to organizations of any size and sector that need to establish, maintain or improve a security management system. The standard covers all activities that influence the security of an organization, from procurement and information management to transportation, warehousing and the movement of goods. It provides a structured, risk based approach to identifying threats, implementing effective controls and continually improving the organization’s ability to prevent, detect and respond to security related disruptions. In essence, it ensures that organizations understand their security context, manage risks systematically and strengthen the resilience of their operations and supply chains over time.

ISO 28000 helps you achieve:

  • Strengthened enterprise resilience and operational continuity
  • More systematic identification and management of security risks
  • Aligned terminology and practices across global operations
  • Improved supply chain performance and fewer disruptions
  • Clear benchmarking against internationally recognized security criteria
  • More robust governance and compliance processes
  • Demonstrated commitment to protecting people, assets and goods

ISO 28000 is built on ISO’s Harmonized Structure (HS), which provides a consistent set of high level clauses shared across all modern ISO management system standards. This common structure makes ISO 28000 straightforward to integrate with existing systems such as ISO 9001, enabling organizations to embed security considerations into broader management frameworks and operate with greater coherence and efficiency.

Value of ISO 28000 certification

Certification to ISO 28000 by an independent third-party like DNV demonstrates that your security management system meets the requirements of the standard.

The certification also shows that you can effectively manage security risks across all activities that influence the safe and reliable flow of goods, information and resources. In addition, it confirms that you have a structured and internationally recognized approach to preventing, detecting and responding to security related disruptions, both within your organization and throughout the supply chain.

As a result, you get:

  • Enhanced credibility and trust with customers, partners and regulators 
  • A stronger competitive position in security sensitive markets
  • Reduced exposure to security related disruptions and operational losses 
  • More reliable and efficient supply chain performance
  • Clear assurance that security expectations from customers and partners are met
  • Smoother cross border movement of goods and fewer trade delays
  • A visible demonstration of commitment to protecting people, assets and critical operations.

Why partner with DNV?

DNV is one of the world’s leading certification bodies. Through management system certification, supply chain assurance and training services, we help companies manage risks, assure compliance and build competence in organizations, supply chains and people.

Trusted

A global partner locally before, during and after the audit

Knowledge

Solid auditor competence and industry experience

Innovation

Value adding services, solutions and digital tools

Experience

Commitment to a superior customer experience

80000

Customers

90000

Certificates

20000

People trained annually

180 +

Countries

How to get ISO 28000 certified

The first step towards third party certification is to implement an effective management system complying with the standard’s requirements. DNV can help you throughout the journey from initial training to gap-analysis and certification.

As a DNV customer, you also get access to a suite of digital tools that can help you ensure compliance, continually improve and manage your entire certification journey with us.

Learn how to get started and be certified

    • Obtain the standard:

    Get a licensed copy of the relevant standard and familiarize yourself with the requirements to decide if certification/registration to this standard makes good sense for your organization.

    • Review available literature and apply digital tools

    Explore available literature, guidelines from the standard owners (e.g. ISO/TS 9002 for ISO 9001, ISO 14004 for ISO 14001)   and digital sources and tools that can assist with implementation. Note that as a DNV customer you get access to tailored tools that can assist you.

    • Assemble a team and define strategy:

    To implement a management system should be a strategic decision for the entire organization. Senior management must be involved in the decision, committed and involved in shaping the system. They decide the business strategy the management system should support. In addition, you need a dedicated team to develop and implement your management system.

    • Determine competence needs:

    First, your team implementing and maintaining the management system needs a thorough understanding of the chosen standards. Later on, the wider organization needs awareness training. DNV offers a variety of public and in-house courses worldwide that meets your competence training needs at all levels within your organization.

    • Review consultant options:

    Independent consultants can advise on a workable, realistic, and cost-effective strategy plan for implementation if you do not have this competence or capacity already.

    • Develop management system documentation: 

    Decide on an appropriate platform for your documented information (e.g. software, process map- or SharePoint-based). The right platform is important to ensure effective management, communication and implementation.

    • Determine, manage and document processes:

    First identify key processes – what they are, how they work, and how they interact. Each process should have a clear purpose, defined responsibilities, and expected outputs. The level of documented information needed depends on the organization’s size, complexity, and the importance of each process, but must include relevant processes and other documented information needed to deliver on intended outcomes and comply with the chosen standard’s requirements.

    • Implement management system:

    Clear communication and necessary competence training are essential elements. During the implementation phase, you will work to ensure that your organization is working according to defined and documented processes. Once successful, you can prove system’s compliance and effectiveness.

    • Select a certification body/registrar:

    Selecting the right certification body/registrar can make a difference throughout your certification journey. DNV offers a trusted partnership approach, a risk-based approach and range of free digital tools that help you manage your certification journey before, during and after the audit.

    • Consider a pre-audit gap analysis:

    Consider a preliminary evaluation by your certification body/registrar to identify and correct nonconformities before starting the official certification process. The purpose is to identify areas of non-conformance or weaknesses, allowing you to correct these before you begin the official certification process.

ISO 28000 - FAQ

  • A security management system is a structured framework an organization uses to identify, assess, manage and continually improve security risks at all levels of the supply chain. It ensures that people, assets, information, infrastructure and supply chain activities are protected against threats such as theft, tampering, sabotage, counterfeiting cyber incidents or operational disruptions. A security management system defines processes to evaluate security risks, assign responsibilities, implement controls and monitor performance over time.

  • ISO 28000 is the international standard for security management systems, with a strong focus on all levels of the supply chain. It provides a comprehensive, risk based framework for managing security across all activities that influence the movement of goods, services, people and information. The standard helps organizations identify and manage security risks systematically, strengthen resilience, improve supply chain performance and demonstrate a clear commitment to protecting assets and meeting customer expectations. ISO 28000 follows the ISO High Level Structure, which makes it easy to integrate with other management system standards such as ISO 9001.

  • ISO 28000 covers all requirements needed to establish, implement, operate, monitor, review and improve a security management system. It includes security risk assessment and treatment, leadership and responsibilities, operational planning and control, incident preparedness and response, and performance evaluation. The scope extends across the entire supply chain and all supporting activities, including procurement, financing, information management, transportation, warehousing, distribution and supplier relationships. Organizations can apply ISO 28000 to internal operations, external partners or the full end to end supply chain.

  • To achieve ISO 28000 certification, an organization must implement a security management system that meets the requirements of ISO 28000 and then complete an independent audit by an accredited certification body. The process begins with understanding the standard and defining the scope, understanding the context of its organization and then developing a management system with the necessary processes and controls in place. Internal audits should confirm compliance with the ISO 28000 standard before the audit by the selected certification body which results in the certificate when found compliant.

More information

Training

Relevant insight in an active learning environment.

Interested in how this service can support your organization?

Contact us