CRAIG WILLETTS ISO & BUSINESS CONSULTANT
  • Meet Craig Willetts
    • Change The Game
    • Give Back
    • Go Paperless With ISO
    • Compliance Master
  • Business Articles
    • New Business Tips >
      • Cash Flow Planning
      • Cybersecurity Basics for SMEs
      • From Startup to Scale-Up
      • Train Your Brain
      • Organise Your Workspace
      • Colour use in Business
      • Writing a Business Plan
      • Setting KPI's
      • Website Building Instructions
      • Business Insurance
    • Business Development >
      • Building Strategic Partnerships
      • Social Media Essentials
      • Strategic Growth Planning
      • SEO Tips
      • Sell your product or service
    • General Business Tips >
      • How to price your services
      • IR35 Rules Explained
      • Meeting Tips
      • GDPR changes 2026
      • Health & Safety Law Updates
      • Making Tax Digital (MTD):
      • Problem Solving
      • Ensure Compliance
      • Health & Safety Tips
      • Cost-Effective Technology Solutions
      • Anti-Money Laundering Regulations
      • Customer Service Sector
      • Prevent burnout in your team
  • Sector specific articles
    • Security Sector
    • Construction Sector
    • Cleaning & FM Sector
    • Manufacturing Sector
    • Training Sector
    • Warehouse Sector
    • Project Management Sector
    • Healthcare Sector: Navigating CQC Compliance
  • Understanding People
    • How to Tell If Your Team Is Using AI
    • Onboarding New Employees: First 90 Days Checklist
    • Be A Great Employee
    • Understand Customers
    • Talent Management
    • How To Get The Most From Your Team
    • Stress at Work
    • Managing Remote and Hybrid Teams Effectively
    • Made it Mindset
  • ISO Standards Tips
    • Top 20 ISO Standards
    • ISO 9001 Tips
    • ISO 14001 Tips
    • ISO 45001 Tips
    • ISO 45003 Tips
    • ISO 31000 Tips
    • ISO 22301 Tips
    • ISO 27001 Tips
    • ISO 42001 Tips
    • ISO 17025 Tips
    • ISO 13485 Tips
    • ISO 18788 Tips
    • ISO 28000 Tips
    • ISO 28007 Tips
    • ISO 50001 Tips
    • ISO 17021 Tips
    • ISO 10015 Tips
    • ISO 37001 Tips
    • ISO 22000 Tips
    • ISO 37301 Tips
    • ISO 27701 Tips
    • ISO 20000 Tips
    • ISO 26000 Tips
    • ISO 15189 Tips
    • ISO 20121 Tips
    • Internal audits in plain English
    • Corrective Actions that work
    • Management Review Meeting
    • Integrating ISO Standards

How to tackle the ISO 28000

​Supply chain Security Management Systems 

Picture
In plain English, it is a structured way to protect your supply chain from theft, tampering, fraud, and disruption. That includes your goods in transit, your storage facilities, your suppliers, your distribution network, and anyone who handles your products or materials between you and your customer.
ISO 28000 is not just about locks and cameras. It is a business management system that covers people, processes, technology, and risk management across your entire supply chain.
What ISO 28000 actually helps you controlMost supply chain security problems are preventable with the right processes in place.
ISO 28000 helps you control:
  1. Who has access to your goods and storage areas
  2. How you track and verify products in transit
  3. How you prevent theft, tampering, and counterfeiting
  4. How you manage suppliers and third parties in your chain
  5. How you respond to security incidents and breaches
  6. How you maintain continuity if disruption happens
  7. How you prove to customers and regulators that your chain is secure

Who ISO 28000 is forISO 28000 is a strong fit if you:
  1. Manufacture or distribute physical products
  2. Handle high-value goods, pharmaceuticals, or food
  3. Import or export internationally
  4. Work with customs or regulated borders
  5. Supply to retailers, government, or defence contracts
  6. Want to reduce shrinkage and win higher value contracts
  7. Need to prove supply chain integrity to customers
If you move goods from point A to point B, you are already managing supply chain security. ISO 28000 just makes it controlled, consistent, and auditable.

ISO 28000 and ISO 28007: what is the differenceISO 28000 is the management system for supply chain security.
ISO 28007 is the standard for private security personnel in supply chain environments.
They overlap, but they are not the same thing.
A simple way to think about it:
  1. ISO 28000 covers your entire supply chain security system
  2. ISO 28007 covers the training and competence of security staff who work in that system
Many businesses get both, but ISO 28000 is the foundation.

What auditors look for in ISO 28000Auditors are not looking for perfection. They are looking for control and consistency.
In practice, they want to see that you:
  1. Know your supply chain and the risks in it
  2. Have assessed threats and vulnerabilities
  3. Have controls in place that match your risk level
  4. Apply those controls consistently, not just on paper
  5. Train staff and manage access properly
  6. Monitor, review, and improve the system
  7. Can prove continuity if something goes wrong

The core building blocks of ISO 28000You do not need to memorise clause numbers. You need to understand the structure.
ISO 28000 is built around:
  1. Context: what you do, what you move, and what matters to your customers
  2. Leadership: roles, responsibilities, and commitment
  3. Planning: risk assessment and threat identification
  4. Support: competence, awareness, documentation
  5. Operation: how you run security day to day
  6. Performance evaluation: internal audits, monitoring, management review
  7. Improvement: corrective actions and continual improvement

Supply chain mapping, explained simplySupply chain mapping is one of the most important steps in ISO 28000.
In plain English, it is your security roadmap.
It shows:
  1. Every step from raw material to customer delivery
  2. Who handles your goods at each step
  3. Where the biggest risks are
  4. What controls you need at each point
  5. How you monitor and verify each stage
If your supply chain map is weak, your ISO 28000 system will be weak. If your map is clear and detailed, auditors can follow your logic and see where your controls matter most.

Common ISO 28000 nonconformities we seeThese are the issues that regularly cause trouble in audits:
  1. Supply chain map that does not match reality
  2. Risk assessment that is generic or outdated
  3. Supplier security checks missing or incomplete
  4. No evidence of staff training on security procedures
  5. Access control not reviewed or updated regularly
  6. Incident reporting process exists but is not used
  7. No continuity plan or testing of backup procedures
  8. Documentation that does not reflect actual operations

How long ISO 28000 takesWith the right approach, ISO 28000 does not need to drag on for months.
Typical timelines:
  1. Simple supply chain with low complexity: a few weeks
  2. More complex or international chains: 6 to 12 weeks depending on scope and readiness
The key is scoping it properly and building a system that fits how you actually operate.

What you need to get startedTo start ISO 28000 properly, you need:
  1. A clear scope: which parts of your supply chain you are covering
  2. A supply chain map: every step, every handler, every location
  3. A risk assessment: what can go wrong and how likely it is
  4. A control plan: what you will do to prevent or respond to risks
  5. Evidence: training records, access reviews, supplier checks, incident logs

The plain-English ISO 28000 certification processMost certification bodies follow the same structure:
  1. Gap analysis and system build
  2. Implementation period: you start using the controls and collecting evidence
  3. Internal audit
  4. Management review
  5. Stage 1 audit: readiness review
  6. Stage 2 audit: full certification audit
  7. Annual surveillance audits
  8. Recertification every three years

How we make ISO 28000 simple at CAW ConsultancyWe keep it practical and fast.
What you get with us:
  1. A bespoke supply chain security system built around how you actually operate
  2. Plain-English policies and procedures, not generic templates
  3. Supply chain mapping and risk assessment that auditors can follow
  4. Staff training so the system works in real life
  5. Support through the audit, including fixes if anything is flagged
We are known for speed, value, and results.

If you want ISO 28000 without the jargon, send me a message and I will tell you exactly what you need, what you do not need, and how fast we can get you through it.
​

Email: [email protected]Phone: 01257 824481
Picture

If you need any advice or have any questions, then please get in touch - [email protected]

Don't forget to share this blog to help others with get great free advice

Picture
  • Meet Craig Willetts
    • Change The Game
    • Give Back
    • Go Paperless With ISO
    • Compliance Master
  • Business Articles
    • New Business Tips >
      • Cash Flow Planning
      • Cybersecurity Basics for SMEs
      • From Startup to Scale-Up
      • Train Your Brain
      • Organise Your Workspace
      • Colour use in Business
      • Writing a Business Plan
      • Setting KPI's
      • Website Building Instructions
      • Business Insurance
    • Business Development >
      • Building Strategic Partnerships
      • Social Media Essentials
      • Strategic Growth Planning
      • SEO Tips
      • Sell your product or service
    • General Business Tips >
      • How to price your services
      • IR35 Rules Explained
      • Meeting Tips
      • GDPR changes 2026
      • Health & Safety Law Updates
      • Making Tax Digital (MTD):
      • Problem Solving
      • Ensure Compliance
      • Health & Safety Tips
      • Cost-Effective Technology Solutions
      • Anti-Money Laundering Regulations
      • Customer Service Sector
      • Prevent burnout in your team
  • Sector specific articles
    • Security Sector
    • Construction Sector
    • Cleaning & FM Sector
    • Manufacturing Sector
    • Training Sector
    • Warehouse Sector
    • Project Management Sector
    • Healthcare Sector: Navigating CQC Compliance
  • Understanding People
    • How to Tell If Your Team Is Using AI
    • Onboarding New Employees: First 90 Days Checklist
    • Be A Great Employee
    • Understand Customers
    • Talent Management
    • How To Get The Most From Your Team
    • Stress at Work
    • Managing Remote and Hybrid Teams Effectively
    • Made it Mindset
  • ISO Standards Tips
    • Top 20 ISO Standards
    • ISO 9001 Tips
    • ISO 14001 Tips
    • ISO 45001 Tips
    • ISO 45003 Tips
    • ISO 31000 Tips
    • ISO 22301 Tips
    • ISO 27001 Tips
    • ISO 42001 Tips
    • ISO 17025 Tips
    • ISO 13485 Tips
    • ISO 18788 Tips
    • ISO 28000 Tips
    • ISO 28007 Tips
    • ISO 50001 Tips
    • ISO 17021 Tips
    • ISO 10015 Tips
    • ISO 37001 Tips
    • ISO 22000 Tips
    • ISO 37301 Tips
    • ISO 27701 Tips
    • ISO 20000 Tips
    • ISO 26000 Tips
    • ISO 15189 Tips
    • ISO 20121 Tips
    • Internal audits in plain English
    • Corrective Actions that work
    • Management Review Meeting
    • Integrating ISO Standards