ISO 28000:2022
Security and resilience — Security management systems — Requirements
The international standard for security management systems. ISO 28000:2022 helps organisations manage security risks across their operations and supply chains — protecting people, cargo, assets, and continuity of business.
Why Certify
Benefits of ISO 28000:2022 Certification
ISO 28000:2022 provides the structure to secure your supply chain from end to end.
Protect Supply Chain Integrity
Systematically identify and control security threats across your entire supply chain — from sourcing to delivery.
Evidence for Customs & Trade
A certified security management system gives documented evidence of your security controls when customs authorities or trading partners ask for it.
Facilitate International Trade
Demonstrate supply chain security credentials to customs authorities, clients, and international trading partners.
Reduce Cargo Loss & Theft
Structured security controls reduce the risk of cargo theft, tampering, and counterfeiting throughout your supply chain.
Build Partner Confidence
Show logistics partners, clients, and regulators that your supply chain operates to internationally recognised security standards.
Structured Incident Response
Defined reporting, investigation, and emergency response procedures so security incidents are handled consistently rather than ad hoc.
What It Covers
Key Requirements of ISO 28000:2022
ISO 28000:2022 uses the High Level Structure (HLS) for compatibility with ISO 9001:2015, ISO 14001:2026, ISO 45001:2018, and other management system standards.
Industries
Who Needs ISO 28000:2022?
ISO 28000:2022 is particularly relevant for organisations that manage complex supply chains or where cargo security is critical, including:
Simple & Clear
Our ISO 28000:2022 Certification Process
Application
Submit your application to initiate the certification process.
Certification Agreement
A formal agreement will be shared for your review and signature prior to commencement.
Stage 1 Audit
A thorough review of your documentation, processes, and overall readiness against the applicable standard.
Stage 1 Audit Report
A detailed report outlining findings, observations, and recommended actions will be shared with you.
Stage 2 Audit
An on-site or remote assessment evaluating the implementation, effectiveness, and conformity of your management system.
Final Report & Certification
Upon completion of the Stage 2 audit, a comprehensive report will be issued. Any identified nonconformities must be addressed before certification is formally granted.
Detailed Guide
Everything You Need to Know
Many organisations in the UAE rely on global trade and logistics networks that connect suppliers, manufacturers, transport providers, and distributors. Modern supply chains involve multiple organisations, transportation routes, and logistics partners working together to move goods from origin to destination. A product might be designed in one country, manufactured in another, and delivered through several logistics partners before reaching the customer.
This interconnected structure supports global trade and improves operational efficiency. However, the complexity of these supply chains also introduces security risks that organisations must carefully manage.
Cargo theft, cyber incidents, counterfeit goods, and disruptions in logistics networks are becoming more common. Even political instability, natural disasters, or operational failures can interrupt supply chains. Because of this, organisations need a clear and structured way to manage security risks.
ISO 28000:2022 is an international standard that defines the requirements for a Security Management System (SMS) to identify, assess, and manage security risks across supply chain operations.
By implementing ISO 28000:2022, organisations in the UAE can strengthen supply chain security, reduce vulnerabilities, and ensure that goods and services move safely and reliably across global markets.
Need ISO 28000:2022 certification in the UAE? Universal Certification and Services is an accredited certification body — we audit and certify security management systems against ISO 28000:2022.
Contact us for a quotation.
What ISO 28000:2022 Actually Does
At its core, ISO 28000:2022 focuses on managing security risks within supply chain activities in a systematic way.
Rather than relying on scattered security procedures, the standard encourages organisations to establish a structured management system that connects policies, responsibilities, operational controls, and monitoring activities.
An organisation implementing ISO 28000:2022 typically works through several steps:
- identifying potential security threats
- assessing vulnerabilities
- implementing preventive controls
- monitoring security performance
- improving the system continually over time
This approach helps organisations protect people, assets, and supply chain infrastructure while maintaining secure and reliable operations.
Why Supply Chain Security Matters
Many businesses in the UAE depend on reliable supply chain operations to maintain production, delivery schedules, and customer commitments. When security risks are not properly managed, disruptions at any stage of the supply chain can impact operations, cause financial losses, and damage business reputation.
Some common supply chain risks include:
- cargo theft during transport
- counterfeit goods entering the supply chain
- cyber-attacks on logistics systems
- smuggling or illegal activity within transport networks
- disruption caused by geopolitical events
ISO 28000:2022 helps organisations manage these risks by establishing structured procedures for identifying and managing them before they escalate.
Who Should Consider ISO 28000:2022
The standard is flexible and can be applied to organisations of different sizes and sectors. It is especially relevant for industries that depend on secure logistics and supply chains.
Examples include:
- logistics and freight companies
- shipping and maritime organisations
- manufacturing companies
- warehousing and distribution centres
- aviation cargo operators
- oil and gas supply chains
- retail distribution networks
Organisations outside traditional logistics environments may also benefit if their operations depend on secure movement of goods or the protection of critical infrastructure.
How ISO 28000:2022 Fits with Other ISO Standards
One reason the 2022 version of ISO 28000:2022 is easier to adopt is that it follows the High-Level Structure (HLS) used by modern ISO management system standards.
This means organisations that have already implemented standards such as ISO 9001:2015 Quality Management Systems, ISO 14001:2026 Environmental Management Systems, or ISO/IEC 27001:2022 Information Security Management Systems can often easily integrate ISO 28000:2022 into their existing management system.
The ISO 28000:2022 structure includes:
- understanding the organisation, its context, and security risks
- leadership commitment and a defined security policy
- planning and risk assessment
- support processes such as resources, competence, and documentation
- operational controls to manage supply chain security risks
- monitoring, measurement, and performance evaluation
- continual improvement
This structure keeps the system practical and aligned with other ISO standards.
If you are looking for ISO certification services in Australia, visit our Australia website. In the UAE, our team certifies security management systems against ISO 28000:2022 — contact us for details.
ISO 28000:2022 Compared to the Older Version
The first edition, ISO 28000:2007, was published in 2007 to provide organisations with a structure for managing security risks within supply chain operations.
The 2022 revision aligned the standard with the High-Level Structure (HLS) used by other ISO standards and strengthened the emphasis on organisational context, risk-based thinking, leadership involvement, and continual improvement.
| Requirements | ISO 28000:2007 | ISO 28000:2022 |
| Structure | Earlier ISO management system structure specific to ISO 28000:2022 | High-Level Structure (HLS) |
| Integration | More difficult to integrate with other ISO standards | Easier integration with other ISO standards |
| Risk management | Security risks identified through periodic risk assessments | Security risks managed through a structured approach integrated into planning, operations, and continual improvement |
| Performance evaluation | Basic monitoring of security controls and risk management activities | Structured performance evaluation with stronger focus on monitoring, analysis, and continual improvement |
The updated version reflects the evolving nature of supply chain security, where risks now include physical threats, digital vulnerabilities, and operational disruptions that may affect the movement of goods and the reliability of supply chain activities.
Have questions about ISO 28000:2022 certification or the certification process?
Contact us to request more information and a free quotation.
Benefits of ISO 28000:2022 Certification
Organisations that implement ISO 28000:2022 often see several practical benefits.
| Benefits | Explanation |
| Better security risk management | Risks are identified, assessed, and managed in a structured way. |
| Stronger supply chain stability | Disruptions can be reduced or managed more effectively. |
| Increased confidence from partners | Customers and partners trust organisations that manage their security risks properly. |
| Improved compliance | Helps meet regulatory and international trade security expectations. |
| Stronger reputation | Demonstrates commitment to responsible operations. |
While certification does not eliminate all supply chain risks, it can help organisations manage them in a more controlled and structured way.
Why Work with Universal Certification and Services
Universal Certification and Services operates under internationally recognised accreditation and follows ISO/IEC 17021-1, the standard for bodies providing audit and certification of management systems.
Clients often choose UCS because we focus on a clear and practical certification process. Our auditors have experience across multiple management system standards, which makes integration easier for organisations that already operate certified systems.
We aim to keep the certification process straightforward while maintaining the integrity of the audit.
What is ISO 28000:2022?
Who benefits most from ISO 28000:2022 certification?
What is the main goal of ISO 28000:2022?
Can ISO 28000:2022 be integrated with other ISO standards?
Often Certified Together
Related Certifications
Many businesses pair this standard with one of the certifications below.
Ready to Get ISO 28000:2022 Certification?
Contact our team today for a free assessment and tailored quote. Most eligible businesses can achieve certification within 7–10 working days.