HomePoliciesQualityCTPAT Security Profile and Written Security Procedures

Policy  required document  Quality

CTPAT Security Profile and Written Security Procedures

The Customs Trade Partnership Against Terrorism is a voluntary CBP program. Once a company applies, it must complete a security profile in the CTPAT Portal that addresses every Minimum Security Criteria item for its business type, and it must be able to produce written procedures behind most of them.

The MSC is organized into three focus areas and twelve categories: corporate security (security vision and responsibility, risk assessment, business partners, cybersecurity), transportation security (conveyance and instruments of international traffic, seal security, procedural security, agricultural security), and people and physical security (physical security, physical access controls, personnel security, education and training and awareness).

Each criterion is marked must or should, and the implementation guidance states where CBP expects a written procedure.

CBP validates the profile within a year of certification and revalidates at least every four years, visiting sites to compare the written procedures with what happens on the dock. The profile must be reviewed and updated in the portal annually.

Members of the CTPAT Trade Compliance track also carry forced labor requirements, including a documented social compliance program, since August 2023.

Also called: C-TPAT security profile, Supply chain security manual, CTPAT written procedures, Minimum Security Criteria documentation
AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedSecurity procedures v5by name, on record
MSC 4 Handledwith AllyMatter
Seal It the Modern WayYour security profile, acknowledged at every dock and gate
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every warehouse and driver on record
Who read which version, and when
03
Hand the CBP validator the trail
From $29/mo, 20 editors, unlimited staff (published)

Obligation ledger

Who requires it, and what each one says.

SourceApplies whenWhat it requiresStatus
CTPAT Minimum Security Criteria
CTPAT MSC by entity type, 2019 to 2021 versions with implementation guidance
CTPAT member or applicantMeet every must criterion and address should criteria based on risk; written procedures where the MSC or its guidance states, including risk assessment, business partner screening, cybersecurity policies, seal control, procedural security for cargo and documents, personnel screening, and training. Program requirement; voluntary to join, mandatory to keep the certification.Implied
CTPAT security profile annual review
CTPAT Portal requirement; MSC 1.x security vision and responsibility
Every memberUpdate and confirm the security profile in the portal each year; document an annual review of security procedures and the risk assessment. Program requirement.Attestation
CTPAT validation and revalidation
CBP validation process
Within one year of certification, then at least every four yearsSite visits by supply chain security specialists comparing the profile and written procedures with observed practice; a validation report with required actions. Program requirement.Attestation
CTPAT MSC, business partners and forced labor
MSC 3.9 (importers); CTPAT Trade Compliance forced labor requirements (Aug 2022, compliance Aug 1, 2023)
Importers; mandatory for Trade Compliance membersA documented social compliance program addressing forced labor in the supply chain, with evidence of implementation such as supplier contracts, audits and training. Should criterion for security-only members; must for Trade Compliance members. Verify the November 2025 FAQ.Implied
Customer supply chain security requirements
Retailer and manufacturer vendor manuals
You supply a CTPAT member that flows down the criteriaWritten security procedures and periodic self-assessment questionnaires. Contractual.Market

Required sections

  • Security vision and responsibility: management commitment statement, designated security point of contact, review process and audit of security procedures (MSC category 1)
  • Risk assessment: documented process covering the international supply chain, threat and vulnerability analysis, and annual review or on trigger (category 2)
  • Business partner requirements: written screening and selection procedures, verification of partners' CTPAT or equivalent status, periodic reviews, and the social compliance program for forced labor (category 3)
  • Cybersecurity: written policies covering access, passwords or MFA, patching, backup, removable media, incident reporting, and personal device use (category 4)
  • Conveyance and instruments of international traffic security: inspection procedures (the seven and seventeen point inspections), tracking and monitoring, and inspection records (category 5)
  • Seal security: written high-security seal policy covering purchase, issuance, application, verification, discrepancy reporting and ISO 17712 compliance (category 6)
  • Procedural security: cargo handling and documentation controls, manifest accuracy, shipping and receiving, discrepancy and incident reporting to CBP and law enforcement, brokers and agents (category 7)
  • Agricultural security: written procedures to prevent pest contamination, wood packaging compliance, and visible pest contamination reporting (category 8)
  • Physical security: perimeter, lighting, locking devices, alarms and surveillance, and periodic checks (category 9)
  • Physical access controls: employee, visitor and vendor identification, badge issuance and removal, challenge and removal of unauthorized persons, mail and package screening (category 10)
  • Personnel security: pre-employment verification, background checks consistent with local law, periodic re-checks for sensitive positions, termination procedures (category 11)
  • Education, training and awareness: security awareness program for all employees, specialized training for sensitive roles, training records, and a means for employees to report anonymously (category 12)
  • Document retention and evidence of implementation for each written procedure (validation expectation)

What the examiner asks for

Written planThe security profile as submitted and updated annually, plus the written procedures behind each criterion with revision dates. Customs and trade compliance consultants and law firms; supply chain security consultants; policy tools hold versions
AttestationSecurity awareness training records per employee; specialized training for seal handlers, drivers and shipping staff; acknowledgment of the cybersecurity policy and code of conduct. Policy tools, LMS, training vendors
Operational recordsRisk assessment with annual review date, business partner screening files, conveyance inspection checklists, seal logs, visitor logs, incident reports, internal audit results, background check records. The company; customs brokers; supply chain security consultants who run mock validations
Technical controlsAccess control and camera systems with retention, GPS tracking, IT controls named in the cybersecurity policy. Physical security integrators, MSPs

What changed

Change log.

2025-11CBP updated the CTPAT Trade Compliance forced labor requirements FAQ. Verify content.
2023-08-01Deadline for existing CTPAT Trade Compliance members to implement the six forced labor requirements announced August 1, 2022. Verify.
2021-10Revised MSC for U.S. importers published (October 2021 508 version). Verify.
2020-01Validations against the 2019 MSC began; new criteria added cybersecurity and agricultural security categories and the must or should designation. Verify.
2019-05CBP announced the first major MSC revision since 2001. Verify.

Frameworks

Where this document is required.

Who looks at it

Where this document gets checked.

No one certifies a document like this on its own. It is read during the audits and inspections below, and by the agency behind each rule.

Where it is looked atWho looks at it
C-TPATCBP Supply Chain Security Specialists (government officers) perform validations and revalidations. There are no private third-party certifiers for CTPAT; consultants can prepare a member but cannot validate it

Who helps write it

Consultants.

Firms that name these standards in their own material.

No firm has claimed a listing for this document yet. Claim yours →

Where it lives

Software.

Tools that hold documents like this one and record who has read them.

Need a hand implementing it?

Find a Consultant for CTPAT Security Profile and Written Security Procedures

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Manage This Document in AllyMatter

Route it for approval, keep every version, and record a named acknowledgment from everyone who has to read it.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

Questions

What people ask.

Is CTPAT membership required?

No. It is voluntary and gives benefits such as fewer examinations and front-of-line processing. Once you join, meeting the MSC and keeping the profile current is a condition of staying in.

How many written procedures does CBP expect?

The MSC uses the word written in a defined set of criteria and the implementation guidance says procedures should be written where consistency over time matters. Most importers end up with twelve to twenty procedures mapped to the twelve categories. Length depends on business model.

What happens at validation?

A CBP supply chain security specialist visits your facility and often a foreign supplier or carrier, walks through each criterion, compares your written procedure with what staff do, and issues a report with required actions and a due date.

Do the forced labor requirements apply to us?

The documented social compliance program is a should criterion for security-only importer members and a must for CTPAT Trade Compliance members. Check the November 2025 FAQ and your membership type.

Who owns this site?

AllyMatter, a policy management tool that may appear in listings on this page. It is labeled every time, excluded from picks, and receives nothing from the matching form unless you name it.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.