wa-img

ISO 28000 Certification in UAE

ISO 28000 certification in UAE for supply-chain security management

ISO 28000 certification in UAE is independent confirmation that an organization’s security management system has been assessed against ISO 28000:2022. ISO publishes the standard but does not certify organizations. For businesses seeking ISO 28000 consultancy in UAE, Qdot can assess gaps, support implementation, train employees, conduct internal audits and prepare the organization for the external audit. The certificate and certification decision remain the responsibility of an independent certification body.

What is ISO 28000:2022?

ISO 28000:2022, is an international standard for security and resilience. It specifies requirements for establishing, implementing, maintaining and continually improving a security management system. It includes security aspects relevant to the supply chain but is not limited to one industry or sector.

The current edition was published in March 2022 and replaced ISO 28000:2007. It applies to organizations of different types and sizes, including commercial businesses, public bodies and non-profit organizations.

In practical terms, the standard helps an organization:

  • Understand its security environment and supply-chain dependencies.
  • Identify security threats, vulnerabilities, risks and opportunities.
  • Select and operate controls that match its risks.
  • Define security responsibilities, objectives and response arrangements.
  • Monitor performance, investigate problems and improve the system.

ISO 28000 helps organizations manage risk systematically. It does not eliminate every security incident or guarantee uninterrupted operations.

What changed through the 2024 climate amendment?

ISO 28000:2022/Amd 1:2024, titled Amendment 1: Climate action changes, applies to ISO 28000:2022; it does not replace the 2022 standard.

The amendment adds climate-change consideration to the organization’s context and interested-party analysis. An organization should determine whether climate change is relevant to its security management system and consider whether interested parties have related requirements.

Who can benefit from ISO 28000 certification in the UAE?

The UAE’s port, airport, free-zone, industrial and cross-border trade activity creates complex links between suppliers, manufacturers, warehouses, transport operators and customers. ISO 28000 may be useful where theft, tampering, unauthorized access, information loss, cargo disruption or weak partner controls could affect operations.

Organizations that may benefit include:

  • Logistics and third-party logistics providers
  • Freight forwarders and customs-related service providers
  • Warehouses, fulfilment centres and distribution operations
  • Importers, exporters and businesses involved in wholesale and retail trade
  • Manufacturers with inbound or outbound supply chains
  • Port, airport, shipping, road-transport and cargo-handling operations
  • Organizations handling sensitive, hazardous or high-value goods
  • Multi-site businesses that need consistent security controls

These use cases are relevant across Dubai, Abu Dhabi, Sharjah and the Northern Emirates, including businesses connected with ports, airports, industrial areas and free zones. This geographic relevance does not mean every organization in these locations must obtain certification.

Is ISO 28000 certification mandatory in the UAE?

ISO 28000 certification is generally voluntary in the UAE. There is no blanket requirement for every UAE organization or every logistics company to hold it.

Certification may nevertheless become necessary when:

  • A customer requires it from approved suppliers.
  • A public- or private-sector tender includes it as a qualification condition.
  • A contract requires the organization to obtain or maintain certification.
  • A regulator, authority or sector-specific rule applies to the organization’s activity.

Before treating ISO 28000 as mandatory, check the exact tender, customer contract, licence condition or regulatory source. Certification also does not replace compliance with UAE laws, customs rules, free-zone requirements or sector obligations.

What are the main ISO 28000 requirements?

The auditable requirements of ISO 28000:2022 are organized in clauses 4 to 10. The following is a plain-language overview, not a reproduction of the standard.

Clause Area What the organization needs to address
4 Context of the organization Understand internal and external issues, relevant interested parties, system boundaries and the scope of the security management system.
5 Leadership Demonstrate top-management commitment, establish a security policy and assign responsibilities and authorities.
6 Planning Address risks and opportunities, set security objectives and plan how to achieve them.
7 Support Provide resources, competence, awareness, communication and controlled documented information.
8 Operation Plan, implement and control the processes needed to manage security risks and respond to security events.
9 Performance evaluation Monitor and evaluate performance, conduct internal audits and complete management reviews.
10 Improvement Manage nonconformities, take corrective action and continually improve the system.

Organizations should use an authorized copy of the standard when designing or auditing their system.

What benefits can ISO 28000 certification provide?

When the system is implemented and maintained effectively, certification can help an organization:

  • Apply a structured, risk-based approach to security.
  • Improve control over cargo, facilities, information, people and supply-chain interfaces.
  • Give customers and partners independent assurance about the management system.
  • Support tenders or contracts that value or require ISO 28000 certification.
  • Clarify security roles, escalation routes and incident-response arrangements.
  • Use audit findings and performance data to drive continual improvement.
  • Align security management with other ISO management systems.

Results depend on the quality of implementation. Certification does not guarantee tender success, regulatory compliance, incident prevention or risk elimination.

How does the ISO 28000 certification process work in the UAE?

A typical certification journey includes the following steps:

  1. Define the certification scope. Confirm the legal entity, sites, activities, services and supply-chain interfaces that the security management system will cover.
  2. Conduct a gap analysis. Compare existing practices and evidence with ISO 28000:2022 to identify gaps.
  3. Implement the system. Establish the required policies, responsibilities, risk controls, objectives, operational arrangements and records.
  4. Complete internal assurance. Conduct an internal audit and management review, then address identified weaknesses.
  5. Choose a certification body. Evaluate its competence, independence, market acceptance and, where required, accreditation status and scope.
  6. Complete the Stage 1 audit. The certification body reviews the system’s documented information, scope and readiness for the main audit.
  7. Complete the Stage 2 audit. Auditors evaluate implementation and effectiveness across the agreed scope.
  8. Address nonconformities. Provide corrections, root-cause analysis and corrective-action evidence where required.
  9. Receive the certification decision. The certification body reviews the audit outcome and decides whether certification can be granted.
  10. Maintain certification. Continue operating and improving the system through surveillance and later recertification.

Qdot may support readiness and implementation, but it does not control the auditor’s findings or the certification decision.

What happens during Stage 1 and Stage 2 audits?

Audit stage Main purpose Typical focus Typical result
Stage 1 Evaluate readiness for the main audit Scope, documented system, organizational context, key processes, internal audit and management-review status Confirmation of readiness or areas to address before Stage 2
Stage 2 Evaluate implementation and effectiveness Operational controls, employee awareness, records, monitoring, risk treatment and corrective action across the certified scope Findings used by the certification body when making its decision

Stage 1 is not the certification decision. Stage 2 also does not guarantee immediate certificate issuance: any required nonconformities must be handled to the certification body’s satisfaction.

Which documents and evidence may be required?

The standard does not require every organization to use an identical document set. The appropriate evidence depends on scope, risks, complexity and operating model. Common examples include:

  • Security management system scope
  • Security policy and objectives
  • Security risk and opportunity assessment
  • Risk-treatment or control plans
  • Defined roles, responsibilities and authorities
  • Competence, training and awareness records
  • Operational procedures and control records
  • Security-event, incident and response records
  • Monitoring and measurement results
  • Internal audit reports
  • Management-review records
  • Nonconformity and corrective-action records

Auditors look for evidence that the system is understood and operating in practice, not merely a collection of templates.

How long does ISO 28000 certification take?

There is no universal or guaranteed duration. The timeline depends on:

  • Organization size and employee numbers
  • Number and location of sites
  • Certification scope
  • Operational and supply-chain complexity
  • Existing security controls and management-system maturity
  • Availability of competent internal personnel
  • Time needed to implement controls and generate evidence
  • Certification-body audit availability
  • Number and seriousness of nonconformities

A mature, single-site organization with a clear scope may progress faster than a complex multi-site operation starting without a formal system. Obtain the certification body’s audit schedule separately from Qdot’s implementation plan.

What affects ISO 28000 certification cost in the UAE?

There is no single fixed price. The total budget may contain separate cost categories:

Cost category Usually paid to Main cost drivers
Readiness or consultancy support Qdot, if engaged Current gaps, scope, sites, complexity, training and implementation support required
Certification audits Independent certification body Employee numbers, audit duration, sites, scope, complexity and travel
Internal implementation Internal team and selected providers Staff time, security controls, technology, facilities and documentation
Training Qdot or another training provider, if required Audience, course type, delivery method and number of participants
Corrective action Internal team and selected providers Nature and severity of gaps or audit findings
Surveillance and recertification Certification body Certification cycle, sites, scope and audit programme

Ask for separate proposals for consultancy and certification. This makes the roles, deliverables and fees easier to compare and preserves the independence of the certification process.

How should a UAE business choose a certification body?

ISO advises organizations to evaluate several certification bodies. Accreditation is not legally compulsory in every situation, but it provides independent confirmation of a certification body’s competence and may be required by a customer, tender or regulator.

Before signing an agreement:

  1. Check independence. The organization conducting certification should be separate from Qdot or any consultant that designed the system.
  2. Confirm market acceptance. Ask the customer, tendering authority or regulator what recognition it expects.
  3. Verify accreditation where required. In the UAE, official accreditation resources include the Emirates National Accreditation System (ENAS) under the Ministry of Industry and Advanced Technology and the Emirates International Accreditation Centre (EIAC).
  4. Check the detailed accreditation scope. Do not assume that approval for one management-system standard automatically includes ISO 28000.
  5. Check international recognition where relevant. Review the applicable accreditation arrangement and, where useful, the IAF CertSearch database.
  6. Review audit competence and coverage. Confirm that the proposed team can assess the organization’s activities, sites and security risks.

Do not rely only on a certification body’s logo or marketing statement. Verify credentials with the named accreditation body and confirm that they meet the intended use of the certificate.

How is ISO 28000 certification maintained?

Certification is not a one-time audit. After certification, the organization must continue to:

  • Operate and monitor the security management system.
  • Maintain current risk assessments, controls and records.
  • Complete internal audits and management reviews.
  • Correct nonconformities and respond to change.
  • Participate in surveillance audits.
  • Complete recertification at the end of the applicable certification cycle.

The certification body defines the audit programme and certificate-cycle arrangements. Confirm the exact schedule and conditions in its proposal.

Can ISO 28000 integrate with other ISO management systems?

Yes. ISO 28000:2022 follows the common structure used by many ISO management-system standards. Shared subjects such as context, leadership, planning, support, internal audit, management review and improvement can be coordinated with existing systems.

For example:

  • ISO 9001 can align quality and process controls with security objectives.
  • ISO 22301 certification can connect supply-chain security with business continuity and recovery.
  • ISO/IEC 27001 can help align information-security controls with physical and operational security risks.

Integration can reduce duplicated processes and records, but ISO 28000 may also be implemented and certified as a standalone system.

What Does ISO 28000 Consultancy in UAE Include?

Qdot provides ISO consultancy support in the UAE for organizations that need to build and implement a practical security management system before independent ISO 28000 certification. The exact scope depends on the organization’s sites, activities, supply-chain interfaces, outsourced providers and existing controls. Support can include:

  • Gap assessment against ISO 28000:2022
  • Scope definition and implementation planning
  • Security risk-assessment support
  • Development or improvement of relevant documented information
  • Employee and management awareness
  • Implementation support across the agreed sites and functions
  • Internal audit and corrective-action support
  • Management-review preparation
  • Stage 1 and Stage 2 audit-readiness checks

An ISO 28000 consultancy project should move beyond document preparation. A typical approach progresses from current-state review and scope definition to security risk assessment, system development, employee awareness, implementation evidence, internal audit, management review, corrective action and external-audit readiness.

Qdot does not issue ISO 28000 certificates, select findings on behalf of the auditor or guarantee certification. The external certification body retains responsibility for assessment and the final decision.

We can assess your current security management practices, identify implementation gaps and help your team prepare for independent Stage 1 and Stage 2 audits.

Reach out to our experts for quick assistance.

  info@qdot.ae   |     /   +971 800 QDOT9 (73689)

Frequently asked questions

It is third-party confirmation that an organization’s security management system has been audited against ISO 28000:2022 within a defined scope.

No. ISO develops and publishes the standard. Independent certification bodies audit organizations and issue certificates.

No. Qdot provides consultancy and readiness support. An independent certification body must conduct the certification audit and make the certification decision.

It is generally voluntary. A customer, tender, contract, licence condition or applicable sector requirement may make it necessary for a particular organization.

Not in every situation. ISO states that accreditation is not compulsory, although it provides independent confirmation of competence. Check what the relevant customer, tender or regulator requires and verify the certification body’s accreditation scope where accredited certification is expected.

The organization must address the finding in line with the certification body’s process. This may include correction, root-cause analysis, corrective action and evidence that the issue has been resolved before certification can proceed.

The duration depends on scope, size, sites, operational complexity, current readiness, implementation progress, audit availability and the time required to close findings.

The main factors are employee numbers, sites, scope, audit duration, operational complexity, current gaps, training needs and the separate fees for consultancy, certification, surveillance and recertification.

Potentially, if the sites fall within an agreed certification scope and the certification body’s audit programme covers them appropriately. The organization should confirm eligibility and sampling arrangements directly with the certification body.

Yes. Their common management-system structure allows shared governance, audits, reviews and improvement processes, while each standard’s specific requirements must still be addressed.

The scope can include gap assessment, scope definition, security risk assessment, documented information, employee awareness, implementation support, internal audit, management review and preparation for independent Stage 1 and Stage 2 audits.