What is ISO 28000?
ISO 28000 is an international standard that specifies the requirements for supply chain and security management systems. This standard was developed by the International Organization for Standardization (ISO) and is designed to help organizations ensure the security of their supply chain.
ISO 28000 considers various aspects of supply chain security, including physical security, information security, and other aspects that may affect the reliability and efficiency of the supply chain. The standard provides a framework for implementing management systems that help organizations identify, assess, and manage risks associated with supply chain security.
Organizations that choose to implement a supply chain and security management system in accordance with ISO 28000 can increase their ability to effectively respond to potential threats and ensure the stability and reliability of their supply chain.
Who is ISO 28000 certification suitable for?
Certification according to the ISO 28000 standard is suitable for various types of organizations, especially those that have a significant supply chain and want to ensure its security and reliability. This standard can be useful for:
- Manufacturers and suppliers:
– Organizations that manufacture goods or provide services and have a wide supply chain.
- Transport companies:
– Companies that transport goods and materials, especially those with complex logistics chains.
- Logistics companies:
– Organizations that specialize in managing logistics and supply for other companies.
- Organizations with a large amount of information:
– Those who process large amounts of confidential information about the supply chain can benefit from the implementation of information security measures.
- Organizations wishing to reduce risks:
– Organizations that understand the importance of identifying and managing risks in their supply chain.
- Organizations working with critical infrastructure:
– Sectors such as energy, transport, telecommunications, which have critical infrastructure, may find this standard particularly useful.
Certification according to ISO 28000 can improve customer confidence, provide competitive advantages, and contribute to overall risk and security management in the organization.
How is the ISO 28000 standard useful for my organization?
The ISO 28000 standard can have several useful aspects for your organization:
- Improving supply chain security:
– ISO 28000 helps to identify and manage security risks in the supply chain, providing effective protection against possible threats.
- Increasing customer confidence:
– Certification according to ISO 28000 can serve as confirmation of your ability to effectively manage security and risks in the supply chain, which will increase the confidence of customers and partners.
- Reducing risks and losses:
– The implementation of the standard allows the organization to identify potential risks and take measures to reduce the likelihood of problems and losses.
- Improving efficiency and productivity:
– Managing risks and security can improve efficiency and productivity in the supply chain, allowing for a more effective response to unforeseen circumstances.
- Compliance with legislation and standards:
– The ISO 28000 standard helps your organization comply with legal and safety standards, which can be especially important in high-risk industries.
- Competitive advantages:
– Having an ISO 28000 certificate, your organization can use it as a competitive advantage, showing your ability to ensure a high level of security and risk management.
- Raising staff awareness:
– The implementation of the standard can contribute to raising the level of awareness and skills of personnel on supply chain security issues.
The overall goal is to create a sustainable and reliable supply chain that can effectively resist potential threats and risks.
Who has the right to conduct certification according to ISO 28000?
Currently, certification in Ukraine is voluntary, but this process allows you to reduce the risks of legal issues. Conducting voluntary certification allows you to actively comply with all legal requirements and avoid possible sanctions. It will increase consumer confidence, increase competitiveness, improve internal management, and open up new opportunities in the market
Certification by an accredited body is a key step to confirm the compliance of your management system with international standards.
This process provides important benefits for your business, namely:
- Recognition by the global market: Certification by an accredited body indicates a high degree of confidence in your management system. This makes your business more attractive to international partners and customers.
- Reducing the risks of legal issues: Conducting voluntary certification allows you to actively comply with all legal requirements and avoid possible sanctions.
- Improving efficiency: The certification process forces you to evaluate and optimize processes in the company, which can lead to increased efficiency and reduced risks.
- Attracting new customers: Many companies require certification as a condition of cooperation. This opens up new opportunities for attracting customers and markets.
- Strengthening reputation: Certification is evidence of your commitment to high standards and helps to confirm your reputation as a reliable partner or supplier.
By choosing an accredited body for certification, you ensure the highest level of recognition and trust in your industry.

What can you expect from us?
Our specialists have innovative thinking, which allows us to solve non-standard tasks with maximum speed and convenience.
Factum operates in accordance with the requirements of the following standards: DSTU EN ISO/IEC 17021-1:2017 "Conformity assessment. Requirements for bodies providing audit and certification of management systems. Part 1. Requirements" (EN ISO/IEC 17021-1:2015, IDT; ISO/IEC 17021-1:2015, IDT) Accreditation certificate No. 8О095. And DSTU EN ISO/IEC 17065:2019 "Conformity assessment. Requirements for bodies certifying products, processes and services" (EN ISO/IEC 17065:2012, IDT; ISO/IEC 17065:2012, IDT). Accreditation certificate No. 1О237
Discussion of the specifics of your organization and your ISO certification goals.
Application submission
Based on the outcome of the discussion, you will receive a detailed and transparent proposal that takes into account your individual needs.
Application analysis
Agreeing with you on the timeframes for conducting audits for the full certification cycle of your Enterprise.
Creating an audit program
Agreeing with you on the timeframes for conducting the initial certification audit.
Audit planning
Stage 1 - assessment of your management system, objectives, results of your management review and internal audit. Stage 2 - assessment of all management processes at your Enterprise.
Conducting the audit
Within a month, you will receive an audit report documenting all audit evidence.
Preparation of the audit report
If all the requirements of the standard are met, a decision is made regarding the possibility of certifying your management system.
Certification decision
The certificate is issued for 3 years. The terms of use and details of the annual confirmation of the management system's compliance with the requirements of the standard will be specified in the License Agreement.
Issuance of certificate and license agreement