
Certificación
ISO 28000 Certification Security and Resilience Management System
ISO 28000 is the international standard that establishes the requirements for implementing, maintaining, and improving a Security Management System. Its current edition, ISO 28000:2022, expanded the original scope—focused on supply chain security—to apply to any type of organization, covering risks such as theft, sabotage, terrorism, cyberattacks, operational disruptions, and natural disasters.
¿Qué es ISO 28000 Certification?
What is the ISO 28000 standard?
ISO 28000 provides a comprehensive approach to managing security: identifying risks and threats, defining a security policy and objectives, implementing controls and mitigation plans, and continually improving the organization's responsiveness and resilience. It covers aspects such as physical security, information security, the protection of people and property, and business continuity in the face of incidents.
Although initially focused on the supply chain, the 2022 version transformed it into a general-purpose standard: it is useful for logistics and transportation companies as well as any organization that needs to manage security risks in a structured way. By following the High-Level Structure (Annex SL), it integrates easily with other certified management systems, such as ISO 9001, ISO 14001, ISO 22301, or ISO 27001.

The conceptual basis
The pillars of ISO 28000
Security and resilience as a comprehensive approach
The standard is not limited to physical protection: it covers people, property, infrastructure, information and operational continuity against any type of threat.
Risk and threat assessment
It requires systematically identifying and assessing the security risks relevant to the organization, in order to prioritize and mitigate the most critical ones.
Application beyond the supply chain
Since the 2022 revision, ISO 28000 is no longer exclusive to logistics and transport, and applies to organizations in any sector that need to manage security in a structured way.
High-Level Structure (Annex SL)
ISO 28000 shares the same structure as ISO 9001, ISO 14001 or ISO 22301, which makes it easier to integrate security management with other already certified systems.
The structure of the standard
The 10 chapters of ISO 28000
Scope
Define the scope of the standard and which organizations it is directed to.
Regulatory references
Indicate the reference documents necessary for the application of the standard.
Terms and definitions
It brings together the specific terms and definitions on safety and resilience used in the standard.
Organizational context
It requires identifying internal and external factors, and the needs of stakeholders, that influence security management.
Leadership
It establishes senior management's commitment to the security policy and the integration of security management into the organization's processes.
Planning
Define security objectives, risk and threat assessment, and actions to address them.
Support
It covers the resources, skills, training, communication, and documentation necessary to sustain the system.
Operation
It establishes the operational planning and control of security, including incident response and crisis management.
Performance evaluation
It requires monitoring, measuring, analyzing, and auditing the performance of the security management system.
Improvement
Establish the continuous improvement cycle based on non-conformities, security incidents, and lessons learned.

The value of the LSQA seal
We turn technical backing into trust
The LSQA seal is not just a document: it is visible proof that an organization went through a rigorous, objective audit process. When a client, business partner, or regulator sees it, they know it reflects years of certification experience across Latin America, strict technical criteria, and ongoing monitoring — not a self-assessment. That's why the seal becomes a business tool: it reduces the uncertainty of whoever chooses you and communicates, at a glance, a real commitment to quality.
Why certify
Benefits of ISO 28000 certification
Reduces risks of theft, sabotage, terrorism and other security threats
It improves the capacity to respond to and recover from incidents and crises.
It facilitates compliance with the security requirements of customers, partners, and regulators.
It increases the confidence of business partners who require security-certified suppliers.
It integrates easily with other certified management systems (ISO 9001, ISO 22301, ISO 27001, etc.)
It strengthens reputation and reduces the financial impact of disruptions due to security incidents.

Your journey with LSQA
Certification Process

Preguntas frecuentes
What is ISO 28000 certification?
ISO 28000 certification verifies that an organization has a Security Management System implemented in accordance with the requirements of the international standard ISO 28000:2022, aimed at protecting people, property, infrastructure and information against security risks.
What type of organizations does ISO 28000 apply to?
ISO 28000 applies to any organization, regardless of its size or sector. Although it originally focused on logistics and supply chain companies, the 2022 revision broadened its scope to include all types of organizations.
What is the difference between ISO 28000 and the ISO 28001 to ISO 28004 standards?
ISO 28000 is the certifiable standard that establishes the requirements for a security management system. ISO 28001, 28002, 28003, and 28004 are supplementary documents that provide specific guidance on implementation, best practices, and auditing, but they are not certifiable on their own.
Can ISO 28000 be integrated with other already certified standards?
Yes. By following the High-Level Structure (Annex SL), ISO 28000 integrates easily with existing management systems, such as ISO 9001 for quality, ISO 22301 for business continuity, or ISO 27001 for information security.
How long does the ISO 28000 certification process with LSQA take?
The ISO 28000 certification process with LSQA, from application to certificate issuance, typically takes between two and four months, depending on the size and complexity of the organization. This timeframe includes service coordination, Stage 1 and Stage 2 audits, report preparation (up to 15 days after the audit), and, if applicable, the time for the organization to present and demonstrate the effectiveness of corrective actions for any nonconformities.
What is the validity period of the ISO 28000 certificate?
The ISO 28000 certificate is valid for three years. During this period, LSQA conducts annual follow-up audits to verify that the Safety Management System remains compliant with the standard's requirements. At the end of the three-year period, a recertification audit is performed to renew the certificate for another three-year term.
Certify your Safety Management System with LSQA
Contact us and start your journey towards ISO 28000 certification