+359 887 407 840 office@escert.com Stara Zagora · Sofia · Plovdiv
BGEN
New editionISO 28000:2022 has superseded the 2007 edition

ISO 28000 certification for supply chain security

We certify security management systems to ISO 28000 in Bulgaria under the established certification procedures of CERTIND S.A. The standard is aimed primarily at transport, courier, postal and logistics companies and at everyone involved in the delivery of products and services. The audit is conducted in Bulgarian, and you will receive a tailored quote within two hours.

  • Certification bodyCERTIND S.A.
  • Who it is fortransport, logistics, couriers
  • Quotewithin 2 hours during business hours
Warehouse staff checking the documents for a loaded pallet

The standard at a glance

What is ISO 28000?

ISO 28000 is the international standard that sets out the requirements for a security management system. It is built on risk management: the organization identifies the threats, assesses the risk they pose and introduces measures to manage that risk. It is applied primarily in the supply chain and is aimed at reducing the consequences of incidents.

The system is applicable mainly to transport, courier, postal, logistics and other companies involved in the supply chain for products and services. The standard does not prescribe specific technical measures — it requires them to be selected according to the real threats to the specific activity, and to be checked.

The current edition is ISO 28000:2022 “Security and resilience — Security management systems — Requirements”. It cancels and replaces ISO 28000:2007, which was written only for the supply chain. The new edition retains the requirements of the old one to ensure continuity for organizations that are already certified, but it is now applicable to any organization and activity. What changed.

The standard follows the common structure of ISO management system standards, so it combines easily with ISO 9001 and ISO/IEC 27001. With an integrated system, the combined audit is usually shorter than separate audits.

Who ISO 28000 is for

  • Transport and freight forwarding Carriage of goods by land, sea and air, freight forwarding and customs services.
  • Warehousing and logistics Warehouses, distribution centres, shipment handling and order picking.
  • Couriers and postal services Courier and postal operators — the entire route of a shipment to the recipient.
  • Manufacturing and trade Manufacturers and traders for whom a disruption or substitution in supply is a serious risk.

ISO 28000 · scope

What the standard covers along the chain

The standard covers five areas that go hand in hand — from risk assessment to continuity of supply.

  1. Risk assessment

    Identifying the threats to supply, and assessing, treating and managing the related risks.

  2. Operational control

    Control measures for all operations related to the delivery of the product.

  3. Monitoring

    Proactive monitoring of how regulatory and customer requirements for the supply are being met.

  4. Emergency response

    Plans, procedures, organization and arrangements for responding to emergencies affecting the supply.

  5. Continuity

    A framework that keeps supplies moving even when something goes wrong.

The five areas come from the requirements of the standard — the audit checks how they work in your organization, not whether they are described on paper.

ISO 28000 · risk assessment

How supply risk is ranked

The standard does not require specific measures; it requires the measures to match the real risk. That is why every threat is ranked by likelihood and impact.

Low impact
Noticeable
Severe
Frequent
Monitoredmeasure and record
Prioritymeasure + plan
Urgentmeasure, plan, check
Occasional
Acceptedrecord
Monitoredmeasure and record
Prioritymeasure + plan
Rare
Acceptedrecord
Acceptedrecord
Monitoredresponse plan

The ranking is not a paper exercise — it decides where the money and people go. The auditor checks whether your measures match the assessment and whether the assessment is reviewed when your activities change.

  1. 1Describe the threats

    Theft, substitution, damage, delay, access to the cargo, dependence on a single supplier or route.

  2. 2Assess likelihood and impact

    For each threat — how often it could happen and what it would cost if it did.

  3. 3Choose the measures

    Access control, seals, tracking, checks on receipt, a backup supplier or route.

  4. 4Keep checking

    Monitoring, internal audit in accordance with ISO 19011, management review, corrective actions.

How ISO 28000 certification works

The process is the same for every organization and follows ISO/IEC 17021-1, the international standard for certification bodies. Only the audit duration differs — it depends on the number of employees, the sites and the complexity of the activity.

The process in detail
  1. 01 Enquiry and quoteYou describe your activity, number of employees and sites. You receive a quote with the scope, audit duration and price.within 2 hours during business hours
  2. 02 Contract and audit planOnce the contract is signed, we agree the dates, the scope and the audit team.dates that suit you
  3. 03 Stage 1 — readiness reviewThe auditor reviews the scope, the supply risk assessment, the selected measures and the emergency plans, and assesses whether the system is ready.documents, scope, readiness
  4. 04 Stage 2 — on-site auditThe work is checked on site — control of access to the cargo, receipt and handover, seals and records, incident response, and interviews with people at the sites.in Bulgarian, at your premises
  5. 05 Corrective actionsIf nonconformities are found, you are given a deadline to correct them and submit evidence.only if needed
  6. 06 Decision and certificateAn independent certification decision and issue of the certificate by CERTIND S.A.under CERTIND S.A. procedures

NewThe 2022 edition

What changed in ISO 28000:2022

The second edition cancels and replaces ISO 28000:2007. It retains the existing requirements to ensure continuity for organizations already working to the standard, but broadens its field of application.

The standard applies the “Plan — Do — Check — Act” model to planning, implementing, operating, monitoring, reviewing and improving the security management system.

The four differences at a glance

  • The title

    Security and resilience

    The new title is “Security and resilience — Security management systems — Requirements”. The old one referred only to a specification for the supply chain.

  • The scope

    Any organization

    It applies to organizations of all types and sizes — commercial companies, state and municipal authorities, and non-profit organizations. It is not tied to any sector.

  • The link with risk

    Aligned with ISO 31000

    Recommendations on principles have been added that align the standard with ISO 31000 — the international document on risk management.

  • The link with continuity

    Aligned with ISO 22301

    Recommendations have been added for better alignment with ISO 22301 — the business continuity standard.

What the price of ISO 28000 certification depends on

The price of the certificate is not fixed, because it is calculated from several factors, including the audit days your organization requires, which are determined under the mandatory document IAF MD 5.

ISO certification pricing
  • 01Complexity and sectorTransport, warehousing, shipment handling or manufacturing — different activities require different amounts of audit time.
  • 02Number of sitesWarehouses, terminals and offices. Each site is audited or checked on a sample basis.
  • 03Number of employeesFull-time and part-time staff.
  • 04Number and type of standardsIn an integrated system with ISO 9001 or ISO/IEC 27001, the combined audit is usually shorter.
What is not included in the certification price

A consultant to implement the system is a separate cost. A certification body cannot provide consultancy to the organizations it certifies — this is an impartiality requirement under ISO/IEC 17021-1.

A tailored quote for your organization

Describe your activity, number of employees and sites — within two hours during business hours you will receive a quote with scope and price.

Exact quote within 2 hours

Questions and answers

Frequently asked questions about ISO 28000

Answers to the questions our clients ask most often before certification.

Didn’t find an answer? Call us — we will answer right away. +359 887 407 840 office@escert.com

Is ISO 28000 certification accredited?

No. ISO 28000 certification is outside the scope of CERTIND S.A.’s RENAR accreditation. The certificate is issued under the body’s established procedures after an actual audit. If you need an accredited certificate in the field of security, the appropriate standard is ISO/IEC 27001.

Who is ISO 28000 suitable for?

Primarily for transport, courier, postal and logistics companies and for all organizations involved in the supply chain for products and services. Since the 2022 revision, the standard has been applicable to organizations of any type and size.

What is the difference between ISO 28000 and ISO/IEC 27001?

ISO 28000 manages the security of the physical supply — cargo, sites, routes, access. ISO/IEC 27001 manages information security. The two standards complement each other and are often implemented together.

Do we need ISO 9001 first?

Not necessarily. ISO 28000 is certified on its own. If you already have a system in place to ISO 9001, however, much of the common requirements are already covered and the audit is usually shorter.

How long is the certificate valid?

Three years. Surveillance audits are carried out in the second and third years, and after the end of the cycle comes recertification, which keeps the certificate valid.

ISO 28000 · Free quote

ISO 28000 certification

Describe your activity, the organization’s locations, number of employees and types of standards — within two hours during business hours you will receive a quote with the scope, audit duration and an all-inclusive price.

Get a quote for ISO 28000 +359 887 407 840 Reply within two hours during business hours
  • Certification bodyCERTIND S.A.
  • Auditin Bulgarian, at your premises
  • Quotewithin 2 hours during business hours