How to tackle the ISO 28000
In plain English, it is a structured way to protect your supply chain from theft, tampering, fraud, and disruption. That includes your goods in transit, your storage facilities, your suppliers, your distribution network, and anyone who handles your products or materials between you and your customer.
ISO 28000 is not just about locks and cameras. It is a business management system that covers people, processes, technology, and risk management across your entire supply chain.
What ISO 28000 actually helps you controlMost supply chain security problems are preventable with the right processes in place.
ISO 28000 helps you control:
Who ISO 28000 is forISO 28000 is a strong fit if you:
ISO 28000 and ISO 28007: what is the differenceISO 28000 is the management system for supply chain security.
ISO 28007 is the standard for private security personnel in supply chain environments.
They overlap, but they are not the same thing.
A simple way to think about it:
What auditors look for in ISO 28000Auditors are not looking for perfection. They are looking for control and consistency.
In practice, they want to see that you:
The core building blocks of ISO 28000You do not need to memorise clause numbers. You need to understand the structure.
ISO 28000 is built around:
Supply chain mapping, explained simplySupply chain mapping is one of the most important steps in ISO 28000.
In plain English, it is your security roadmap.
It shows:
Common ISO 28000 nonconformities we seeThese are the issues that regularly cause trouble in audits:
How long ISO 28000 takesWith the right approach, ISO 28000 does not need to drag on for months.
Typical timelines:
What you need to get startedTo start ISO 28000 properly, you need:
The plain-English ISO 28000 certification processMost certification bodies follow the same structure:
How we make ISO 28000 simple at CAW ConsultancyWe keep it practical and fast.
What you get with us:
If you want ISO 28000 without the jargon, send me a message and I will tell you exactly what you need, what you do not need, and how fast we can get you through it.
Email: [email protected]Phone: 01257 824481
ISO 28000 is not just about locks and cameras. It is a business management system that covers people, processes, technology, and risk management across your entire supply chain.
What ISO 28000 actually helps you controlMost supply chain security problems are preventable with the right processes in place.
ISO 28000 helps you control:
- Who has access to your goods and storage areas
- How you track and verify products in transit
- How you prevent theft, tampering, and counterfeiting
- How you manage suppliers and third parties in your chain
- How you respond to security incidents and breaches
- How you maintain continuity if disruption happens
- How you prove to customers and regulators that your chain is secure
Who ISO 28000 is forISO 28000 is a strong fit if you:
- Manufacture or distribute physical products
- Handle high-value goods, pharmaceuticals, or food
- Import or export internationally
- Work with customs or regulated borders
- Supply to retailers, government, or defence contracts
- Want to reduce shrinkage and win higher value contracts
- Need to prove supply chain integrity to customers
ISO 28000 and ISO 28007: what is the differenceISO 28000 is the management system for supply chain security.
ISO 28007 is the standard for private security personnel in supply chain environments.
They overlap, but they are not the same thing.
A simple way to think about it:
- ISO 28000 covers your entire supply chain security system
- ISO 28007 covers the training and competence of security staff who work in that system
What auditors look for in ISO 28000Auditors are not looking for perfection. They are looking for control and consistency.
In practice, they want to see that you:
- Know your supply chain and the risks in it
- Have assessed threats and vulnerabilities
- Have controls in place that match your risk level
- Apply those controls consistently, not just on paper
- Train staff and manage access properly
- Monitor, review, and improve the system
- Can prove continuity if something goes wrong
The core building blocks of ISO 28000You do not need to memorise clause numbers. You need to understand the structure.
ISO 28000 is built around:
- Context: what you do, what you move, and what matters to your customers
- Leadership: roles, responsibilities, and commitment
- Planning: risk assessment and threat identification
- Support: competence, awareness, documentation
- Operation: how you run security day to day
- Performance evaluation: internal audits, monitoring, management review
- Improvement: corrective actions and continual improvement
Supply chain mapping, explained simplySupply chain mapping is one of the most important steps in ISO 28000.
In plain English, it is your security roadmap.
It shows:
- Every step from raw material to customer delivery
- Who handles your goods at each step
- Where the biggest risks are
- What controls you need at each point
- How you monitor and verify each stage
Common ISO 28000 nonconformities we seeThese are the issues that regularly cause trouble in audits:
- Supply chain map that does not match reality
- Risk assessment that is generic or outdated
- Supplier security checks missing or incomplete
- No evidence of staff training on security procedures
- Access control not reviewed or updated regularly
- Incident reporting process exists but is not used
- No continuity plan or testing of backup procedures
- Documentation that does not reflect actual operations
How long ISO 28000 takesWith the right approach, ISO 28000 does not need to drag on for months.
Typical timelines:
- Simple supply chain with low complexity: a few weeks
- More complex or international chains: 6 to 12 weeks depending on scope and readiness
What you need to get startedTo start ISO 28000 properly, you need:
- A clear scope: which parts of your supply chain you are covering
- A supply chain map: every step, every handler, every location
- A risk assessment: what can go wrong and how likely it is
- A control plan: what you will do to prevent or respond to risks
- Evidence: training records, access reviews, supplier checks, incident logs
The plain-English ISO 28000 certification processMost certification bodies follow the same structure:
- Gap analysis and system build
- Implementation period: you start using the controls and collecting evidence
- Internal audit
- Management review
- Stage 1 audit: readiness review
- Stage 2 audit: full certification audit
- Annual surveillance audits
- Recertification every three years
How we make ISO 28000 simple at CAW ConsultancyWe keep it practical and fast.
What you get with us:
- A bespoke supply chain security system built around how you actually operate
- Plain-English policies and procedures, not generic templates
- Supply chain mapping and risk assessment that auditors can follow
- Staff training so the system works in real life
- Support through the audit, including fixes if anything is flagged
If you want ISO 28000 without the jargon, send me a message and I will tell you exactly what you need, what you do not need, and how fast we can get you through it.
Email: [email protected]Phone: 01257 824481