Skip to content
itmad

Capabilities / Certification

ISO 28000 Supply Chain Security Management System Certification

ISO 28000 supply chain security management certification in Oslo, Bergen and Norway. Security risk controls, cargo and freight resilience. Accredited body.

Transport & InfrastructureOil & GasMarineIndustrial & ManufacturingRetail & TradeConsumer ProductsAviationGovernment & Public

ISO 28000 specifies requirements for a security management system across the supply chain — the risk assessment, controls and resilience arrangements that protect goods, people and information as they move through logistics, storage and transport. Certification is independent confirmation that security is managed deliberately rather than assumed, which carries weight in a country built around the movement of goods.

Why Norwegian organisations certify

The UAE is one of the world's major logistics and re-export hubs, and the security expectations on that trade — from customs regimes, from port and free-zone authorities, and from international clients — have risen accordingly. ISO 28000 gives freight forwarders, logistics operators, port service providers and manufacturers a recognised way to demonstrate that cargo, facilities and the wider supply chain are protected against theft, tampering, smuggling and disruption. For many, certification is what qualifies them to handle sensitive or high-value consignments at all.

What the standard requires

  • Security risk assessmentIdentifying threats to the supply chain and the vulnerabilities they could exploit, and treating them proportionately.
  • Security policy and objectivesA stated organisational position on supply chain security, with measurable targets.
  • Physical and procedural controlsControls over facilities, cargo, access and handling appropriate to the assessed risk.
  • Personnel securityScreening, competence and awareness for people in security-critical roles.
  • Information and data securityProtecting the information that moves with and about the goods.
  • Business continuity and resilienceArrangements to withstand and recover from disruption to the supply chain.
  • Supplier and partner controlExtending security requirements to the third parties the supply chain depends on.
  • Incident managementDetecting, responding to and learning from security incidents.

Who needs it

Logistics and freight companies, warehouse and port operators, manufacturers with exposed supply chains, and any organisation whose clients or regulators require demonstrable supply chain security. The standard applies at any point in the chain — a single warehouse, a forwarding operation, or an end-to-end logistics network — and complements customs-driven schemes such as Authorised Economic Operator status.

The certification process

Stage 1 reviews your security management documentation, confirms the scope of operations and locations covered, and establishes readiness, raising gaps early enough to close them. Stage 2 assesses implementation: whether the security risk assessment is real and current, whether the physical and procedural controls operate as documented, whether personnel understand their security responsibilities, and whether incidents are managed and learned from. The certificate is valid three years, with surveillance audits in each intervening year and full recertification before expiry.

Working with other standards

ISO 28000 shares its high-level structure with ISO 9001, ISO 22301 and ISO/IEC 27001, and organisations concerned with supply chain security are frequently concerned with business continuity and information security too. Integrated auditing covers the common clauses once rather than repeatedly, and the security risk assessment at the heart of ISO 28000 often draws on the same analysis that feeds the continuity and information-security systems.

What you receive

  • Stage 1 report identifying readiness gaps before the main audit
  • Stage 2 audit report with findings supported by objective evidence
  • Non-conformities classified by severity with defined response timescales
  • Certificate of registration stating your certified scope and locations
  • Certification mark for use under our mark and seal policy
  • Annual surveillance audits and reports through the cycle