You are currently viewing Difference Between ISO 28000 & ISO 28001 Certification

Difference Between ISO 28000 & ISO 28001 Certification

A modern supply chain can involve manufacturers, suppliers, warehouses, transport companies, freight forwarders, ports, customs authorities and distributors across several countries. Every additional connection can introduce another security risk.

Cargo may be stolen or tampered with. Unauthorised individuals may gain access to facilities. A supplier may have weak security controls. A transport partner may not adequately protect goods in transit. Even a disruption that begins with one organisation can eventually affect customers and business operations across the wider supply chain. For Singapore businesses involved in logistics, manufacturing, warehousing, transportation, import and export activities, supply chain security has therefore become an important part of operational risk management.

This is where ISO 28000 and ISO 28001 are often considered. The two standards have similar names, and both address supply chain security, but they are not the same standard and should not automatically be treated as two alternative certifications. Understanding the difference is important before deciding which framework is appropriate for your organisation.

ISO 28000 vs ISO 28001: What Is the Main Difference?

The simplest way to understand the difference is to look at their purpose.

ISO 28000:2022 is a security management system standard. It specifies requirements for establishing, implementing, maintaining and continually improving a security management system. The standard has a broad security and resilience focus and can be applied by organisations of different sizes and types. ISO describes ISO 28000:2022 as a standard for security management systems and their requirements.

ISO 28001:2007 has a more specific focus on supply chain security. It provides best practices, requirements and guidance for implementing supply chain security processes, conducting assessments and developing security plans. ISO also explains that it can support applicable Authorised Economic Operator requirements and national supply chain security programmes. ISO’s official page for ISO 28001 provides the current status and scope of the document.

In simple terms:

ISO 28000 focuses on the security management system. ISO 28001 focuses more specifically on supply chain security assessments, processes and security plans.

This distinction becomes particularly important when a customer, tender or business partner asks for “ISO 28001 certification”. The organisation should first clarify exactly what evidence is required rather than assuming that ISO 28000 and ISO 28001 certification are interchangeable.

difference between 28000 and 28001 certification

What Is ISO 28000 Certification?

ISO 28000:2022 is titled Security and resilience — Security management systems — Requirements. It is the current edition of the standard and replaced ISO 28000:2007. ISO also published Amendment 1:2024, which introduces climate action changes to the standard. The current ISO 28000:2022 information provides the official scope and publication details.

The purpose of ISO 28000 is to give an organisation a structured way to manage security risks. Instead of treating security as a collection of separate activities, an organisation establishes a management system through which relevant security risks can be identified, assessed, controlled, monitored and improved. Imagine a Singapore manufacturer importing high-value components from overseas. Its security exposure does not begin when the goods arrive at its warehouse. Risks may exist at the supplier’s facility, during loading, while the goods are being transported, at ports, during customs clearance and when the shipment is finally delivered.

Once the goods reach the organisation’s own premises, additional risks can arise through access control, storage, personnel, documentation, technology and internal processes. A security management system helps the organisation look at this wider picture. GQS provides more information about the scope, requirements, certification process and benefits on its ISO 28000 Certification in Singapore page.

What Is ISO 28001?

ISO 28001:2007 is titled Security management systems for the supply chain — Best practices for implementing supply chain security, assessments and plans — Requirements and guidance.

Its purpose is more specifically connected with supply chain security. ISO explains that ISO 28001 helps organisations develop and implement supply chain security processes, establish and document a minimum level of security within a supply chain or part of one, conduct security assessments and develop supply chain security plans. It can also support organisations seeking to meet applicable AEO criteria and national supply chain security programmes. The ISO 28001 standard provides the official description.

For example, a logistics company could use the principles in ISO 28001 to assess the security risks associated with the part of the supply chain it manages and determine appropriate security measures.

This could involve considering the security of cargo, premises, personnel, transport arrangements, business partners and other relevant activities.

However, businesses should be careful with the phrase “ISO 28001 certification”. ISO 28001 is not simply a certification alternative to ISO 28000. Its purpose and structure differ, so the organisation should establish what a customer, regulator, customs programme, or contractual requirement actually expects.

Why Do Businesses Confuse ISO 28000 and ISO 28001?

The confusion is understandable. Both standards belong to the same general family of supply chain security standards. Both involve security risks. Both can involve assessments, documented controls, security planning and operational measures. However, the level at which they operate is different. ISO 28000 provides a management-system framework through which an organisation can systematically manage security. ISO 28001 provides specific guidance and requirements for supply chain security practices, assessments, and plans. One does not simply replace the other. In some circumstances, the two can even complement one another.

difference between 28000 and 28001 certification

ISO 28000 vs ISO 28001: Purpose and Scope

The first major difference is purpose. ISO 28000 is designed to establish a security management system. It provides requirements that an organisation can use to structure its security processes and demonstrate conformity through an appropriate certification process.

ISO 28001 focuses on establishing security practices within the supply chain, assessing vulnerabilities and determining appropriate security controls and plans. The second difference is scope.

ISO 28000 can be applied to organisations of different types and sizes and is not limited to freight or logistics companies. ISO’s description of ISO 28000 explains its applicability across different organisations and activities. ISO 28001 places greater emphasis on international supply chains and on the specific portion of the supply chain an organisation is responsible for securing.

This means a manufacturer, warehouse operator, or logistics provider may need to consider both the organisation-wide security management perspective and the specific security requirements associated with its supply chain.

ISO 28000 vs ISO 28001: Certification Difference

This is perhaps the most important distinction for businesses. ISO 28000 is a management-system requirements standard. Organisations can establish a security management system aligned with their requirements and undergo an appropriate third-party certification audit. ISO 28001 should not automatically be described as an equivalent certification standard. Therefore, if a tender document states that a supplier must have “ISO 28001 certification”, it is worth asking the customer exactly what is required.

  • Does the customer want evidence of supply chain security controls?
  • Does it require a security assessment?
  • Does it require a documented security plan?
  • Is the requirement actually referring to ISO 28000 certification?
  • Could it instead relate to an AEO or national customs security programme?

Clarifying the requirement before beginning a certification project can prevent an organisation from investing time and money in the wrong framework.

Why Supply Chain Security Matters in Singapore

This subject is especially relevant in Singapore because the country is a major international trading and logistics hub.

Singapore Customs operates the Secure Trade Partnership (STP) programme, which encourages companies to strengthen supply chain security and adopt robust security practices. The programme is aligned with the World Customs Organisation’s SAFE Framework of Standards. Singapore Customs has also introduced STP-Plus recognition for companies that meet enhanced security requirements. The programme reflects the wider importance of protecting cargo and supply chain processes from security threats.

Supply chain security can involve much more than physical cargo protection. It can include premises security, cargo security, conveyance security, personnel security, trading partner security, crisis management and incident recovery. This is why simply installing cameras or controlling warehouse access is not enough to create a mature supply chain security system. Security needs to be considered across the wider network.

What Does ISO 28000 Cover?

An ISO 28000 management system can help an organisation establish a structured approach to identifying and managing relevant security risks.

  • For a logistics company, this could involve assessing risks associated with cargo handling, transportation, warehouses, employees, contractors and third-party service providers.
  • For a manufacturer, it could include security risks affecting suppliers, incoming materials, production locations, finished goods, transportation and distribution.
  • For a warehouse operator, the focus could include access controls, cargo integrity, personnel security, storage processes and incident response.
  • The exact scope depends on the organisation and its operational risks.

The objective is not to apply every possible security control. Instead, the organisation should understand its context and risks and establish appropriate controls.

What Does ISO 28001 Focus On?

ISO 28001 has a more direct supply chain security orientation.

  • It provides a structured approach for conducting supply chain security assessments and developing security plans.
  • This can help an organisation understand where vulnerabilities exist within its defined supply chain activities and determine what measures are necessary to address them.
  • For example, a company may discover that its own warehouse has strong physical security but one of its external transport partners does not have comparable controls.
  • That creates a supply chain vulnerability even though the company’s own facility is secure.
  • The organisation therefore needs to consider security beyond its own premises.

This broader perspective is one of the reasons ISO 28001 can be useful when developing supply chain security processes.

Which Is Better for Logistics Companies?

There is no universal answer. A logistics company looking for a formal, certifiable security management system may consider ISO 28000. An organisation looking to strengthen supply chain security assessments and develop appropriate security plans may find ISO 28001 useful.

A company may also use the two standards together as part of a broader supply chain security strategy. The correct choice depends on the company’s objectives, supply chain structure, contractual requirements and the expectations of customers or relevant programmes.

For businesses that also need to manage disruption and recovery, an integrated approach can be useful. For example, GQS’s ISO 22301 Business Continuity Management System services can complement supply chain security planning by addressing how an organisation prepares for and responds to disruptive events.

Which Is Better for Manufacturers?

Manufacturers often have complicated supply networks.

  • A single production facility may depend on hundreds of suppliers, international shipping routes, third-party warehouses and logistics companies.
  • A security incident involving one critical component can therefore have consequences far beyond the immediate loss.
  • ISO 28000 can help manufacturers establish a structured security management system.
  • ISO 28001 can support the assessment of supply chain security risks and the development of security plans.
  • For manufacturers, the important question is not simply whether a supplier has been approved by procurement.
  • It is whether the security risks associated with that supplier and the movement of materials have been understood and controlled.

This approach can also complement ISO 9001 quality management systems, particularly where supplier controls, operational processes and business risks overlap.

Can ISO 28000 Work With ISO 27001?

Yes. Modern supply chains are increasingly digital. Shipping documentation, customer information, inventory systems, warehouse management systems and transport platforms all depend on information technology. That creates another layer of risk. A company may have excellent physical cargo security while its logistics data is poorly protected. This is why organisations with significant information-security exposure may consider combining supply chain security with ISO 27001 Information Security Management. ISO 27001 focuses on information security, while ISO 28000 focuses on security management within its defined scope. Together, they can help organisations address both information-related and supply-chain security risks.

ISO 28000 and Business Continuity

Security incidents do not always result in the permanent loss of goods. Sometimes the biggest impact is disruption. A shipment may be delayed. A facility may become inaccessible. A transport route may be interrupted. A critical supplier may become unavailable. This is where supply chain security and business continuity intersect. ISO 28000 can help organisations manage relevant security risks, while ISO 22301 provides a framework for business continuity management. The two therefore address different but connected questions:

  • How can we reduce security risks?
  • How will we continue critical operations if disruption occurs?

For organisations heavily dependent on international supply chains, considering both questions can provide a more complete resilience strategy.

Which Standard Should Your Business Choose?

Before choosing ISO 28000 or ISO 28001, start with the business requirement. If your organisation wants to establish a formal security management system and pursue certification, ISO 28000 is generally the more relevant standard to investigate.

If your organisation needs a framework for supply chain security assessments, security planning and best practices, ISO 28001 may be relevant. If a customer or tender specifically requests ISO 28001, clarify the requirement before assuming that ISO 28000 certification will satisfy it. Similarly, if the requirement comes from a customs or trade-security programme, check the programme’s own requirements rather than assuming that an ISO certificate automatically provides recognition. This distinction is particularly important in Singapore, where organisations may encounter requirements connected with the Singapore Customs Secure Trade Partnership and other international trade security expectations.

Why ISO 28000 Can Be Valuable for Singapore Businesses

For Singapore companies, supply chain security is closely connected with business resilience. A security incident can result in lost cargo, delayed shipments, production interruptions, contractual problems, customer dissatisfaction and reputational damage. A structured management system can help an organisation move away from reactive security. Instead of asking what went wrong after an incident, management can ask beforehand:

  • Where are our most important supply chain vulnerabilities?
  • Which assets and processes are most critical?
  • Which suppliers and logistics partners present the greatest risk?
  • How would we detect a security incident?
  • Who would respond?
  • How would we recover?
  • How do we know that our security controls continue to work?

These questions turn supply chain security into an ongoing management responsibility rather than an isolated compliance exercise.

The Bottom Line: ISO 28000 or ISO 28001?

The difference between ISO 28000 and ISO 28001 becomes much clearer once their intended roles are understood. ISO 28000:2022 is a security management system standard that provides requirements organisations can use as the basis for certification. ISO 28001:2007 focuses specifically on supply chain security practices, assessments and security plans.

Neither should simply be treated as a newer or older version of the other. For an organisation seeking formal management-system certification, ISO 28000 is usually the starting point. For organisations developing detailed supply chain security assessments and plans, ISO 28001 can provide relevant guidance. The right choice ultimately depends on your organisation’s supply chain, risk exposure, customer requirements and business objectives.

At Global Quality Services, organisations can obtain support in understanding applicable ISO requirements, assessing their current systems and preparing for certification. Our ISO 28000 certification services are designed for organisations that need a structured approach to supply chain security. The goal should not simply be to obtain a certificate. The goal should be to create a supply chain security system that works in the real world — protecting cargo, people, information, facilities and business operations while helping the organisation respond more effectively when risks change.

Frequently Asked Questions

Is ISO 28000 the same as ISO 28001?

No. ISO 28000:2022 specifies requirements for a security management system, while ISO 28001:2007 focuses on supply chain security practices, assessments and security plans. They are related but have different purposes.

Can ISO 28000 be certified?

Yes. ISO 28000 is a management system requirements standard and can serve as the basis for third-party certification by an appropriate certification body.

Is ISO 28001 still valid?

Yes. ISO currently lists ISO 28001:2007 as a current published standard. It was confirmed following its 2021 review. Organisations should nevertheless verify the exact requirements of the customer, programme, or tender that requests ISO 28001-related evidence.

Is ISO 28000 mandatory in Singapore?

ISO 28000 certification is not generally mandatory for all Singapore businesses. However, particular customers, contracts, tenders or supply chain programmes may have their own security requirements. Organisations should check the specific requirement applicable to their business.

Which standard is better for a logistics company?

It depends on the objective. If the organisation wants a formal, certified security management system, ISO 28000 is generally the more relevant option. If the organisation needs guidance for supply chain security assessments and security plans, ISO 28001 may be useful.