HomeFrameworksTrade, Ethics & FranchiseC-TPAT

Framework  Trade, Ethics & Franchise

C-TPAT

The Customs Trade Partnership Against Terrorism (CTPAT) is a voluntary supply chain security program run by US Customs and Border Protection.

Companies in the international trade chain (importers, exporters, carriers, brokers, consolidators, foreign manufacturers, and others) apply, document how they meet CBP's Minimum Security Criteria, and are then validated by a CBP Supply Chain Security Specialist.

In return, members get reduced examination rates, front-of-line processing, access to the FAST lanes, and other trade benefits.

The Minimum Security Criteria were substantially rewritten in 2019 and 2020 and are organized under corporate security, transportation security, and people and physical security, adding cybersecurity, agricultural security, and security vision and responsibility as newer areas.

CTPAT is a paperwork-heavy program. Members must complete and keep current a security profile in the CTPAT Portal that explains, criterion by criterion, how the requirement is met, and must back it with written procedures: a supply chain security risk assessment refreshed at least annually, a written cybersecurity policy, container and trailer inspection procedures, seal control procedures, personnel screening and termination procedures, visitor and access control, business partner screening and monitoring, and training records.

Validators check that the written procedures match what happens at the sites they visit.

AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedSecurity procedures v5by name, on record
MSC 4 Handledwith AllyMatter
Clear Customs the Modern WayYour written security procedures, acknowledged by every dock hand
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every warehouse and driver on record
Who read which version, and when
03
Hand the CBP validator the trail
From $29/mo, 20 editors, unlimited staff (published)

Who has to comply

Voluntary. Open to US importers and exporters, US and Canadian highway carriers, rail, sea, and air carriers, licensed customs brokers, consolidators and NVOCCs, marine port authorities and terminal operators, foreign manufacturers in specified countries, and certain third-party logistics providers, each with its own eligibility rules.

Many large importers require their suppliers to join or to meet the criteria contractually.

What you have to write

Documents on this site that C-TPAT requires or expects, each with who must have it, the review cycle and the obligations that cite it.

What the assessor asks to see

Security profile in the CTPAT Portal; supply chain security risk assessment with threat and vulnerability analysis by route and partner; written procedures for each criterion (business partner screening, cybersecurity, conveyance and container inspection, seal control, procedural security, physical security, access controls, personnel security, education and training, agricultural security); business partner questionnaires and monitoring records; training attendance and materials; audit and self-assessment records; corrective action records from prior validations.

Where the requirement sits: CTPAT Minimum Security Criteria (2020): security vision and responsibility, risk assessment, business partners, procedural security, personnel security, education/training and awareness

Tiers

For importers, Tier I is certified but not yet validated; Tier II is validated as meeting the Minimum Security Criteria; Tier III is validated as exceeding the criteria and adopting recognized best practices. Higher tiers receive larger risk score reductions and fewer security examinations.

What AllyMatter does here

Controls the written security procedures and proves staff training acknowledgment.

AllyMatter publishes this site.

Assessors

Who assesses C-TPAT

CBP Supply Chain Security Specialists (government officers) perform validations and revalidations. There are no private third-party certifiers for CTPAT; consultants can prepare a member but cannot validate it. Validation is performed by the government agency that runs the program.

No firm has claimed a C-TPAT assessor listing yet. Claim yours →

Consultants

Who helps with C-TPAT

A well-developed consultant market helps companies write the security profile, run the risk assessment, draft procedures, train staff, and prepare for validation visits. Typical engagement is a readiness project of one to three months before application, plus periodic help before revalidation.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a C-TPAT consultant listing yet. Claim yours →

Software

Tools for C-TPAT

Tools that name this framework in their own material.

Related reading

  1. Understanding the CTPAT minimum security criteriaBreaks the twelve criteria categories into musts and shoulds and shows which of them require written procedures.Thomson Reuters
  2. CTPAT validation and minimum security criteriaPractitioner walkthrough of how a CBP validation actually runs: document review, staff interviews and site inspection.Diaz Trade Law

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for C-TPAT

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Run the Policy Side of C-TPAT in AllyMatter

Approve the policies C-TPAT asks for, keep every version, and record a named acknowledgment from each person who has to read them.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.