ISAO — International Standards Accreditation Organization home pageVerify a certificate

Menu

Health, safety and security

ISO 28000:2022

Security management systems

ISO 28000 sets out requirements for a security management system.

Key facts

Edition
Current edition (2022)

A certified organisation assesses the security threats and risks to its people, assets, operations and information, including those that arise in its supply chain, and puts strategies, plans and controls in place to deal with them. Since the 2022 edition the standard applies to security management in any organisation, not only to supply chains.

Who it suits

Logistics, freight forwarding, warehousing and port operators; manufacturers and shippers that move high-value or sensitive goods; security service providers; and any organisation whose customers or insurers ask for evidence that security risks are managed.

What certification involves

ISAO, or a certification body accredited for ISO 28000, audits the system in two stages: first the scope, the security risk assessment and readiness; then how security plans, procedures and controls work in practice, for example physical security, access control, the handling of goods and information, and incident response. The scope states the activities, sites and parts of the supply chain covered. Certificates are normally valid for three years, with surveillance audits at least once a year and a recertification audit before expiry. ISAO carries out this certification itself, and also accredits certification bodies to do it. Every certificate ISAO issues, and every certificate issued under ISAO accreditation, is recorded on the public register.

Key themes

  • Understanding security threats and the organisation's exposure, including through suppliers and partners
  • A security risk assessment that shapes security strategies, plans and procedures
  • Protecting people, premises, goods, information and transport
  • Working with authorities, partners and service providers
  • Preparing for, responding to and recovering from security incidents
  • Testing plans, monitoring performance and improving

Edition

Current edition
ISO 28000:2022

ISO 28000:2022, the second edition, was published in March 2022. It replaced ISO 28000:2007, a specification for security management in the supply chain. The 2022 edition carries the earlier requirements forward, widens the standard to security management in any organisation, and adds recommendations that align it with ISO 31000 on risk management and ISO 22301 on business continuity. An amendment published in February 2024 asks the organisation to consider whether climate change matters to it when it reviews its context, and adds a note that interested parties may have expectations about climate change.

Check a certificate for ISO 28000:2022

  • Enter the certificate number or verification code at Verify a certificate, or scan the QR code on the certificate. The record shows the certificate's status today, for example valid, suspended, withdrawn or expired.
  • Compare the organisation name, scope and sites on the record with the copy you were given. Check that the activities, sites and stages of the supply chain you rely on are within the stated scope.
  • Check who issued the certificate, as named on the record. Where a certification body accredited by ISAO issued it, the record shows the status of that accreditation and its accreditation number, and says so if the accreditation did not cover ISO 28000:2022 when the certificate was issued.
  • If the certificate is not on the register, ISAO cannot confirm it: it may have been issued under another accreditation, or a detail may be wrong. Ask the issuing body, and report a concern if something does not look right.

This is ISAO’s own summary, not the text of the standard. Copies of ISO 28000:2022 can be bought from ISO or from national standards bodies.