Framework Trade, Ethics & Franchise
C-TPAT
The Customs Trade Partnership Against Terrorism (CTPAT) is a voluntary supply chain security program run by US Customs and Border Protection.
Companies in the international trade chain (importers, exporters, carriers, brokers, consolidators, foreign manufacturers, and others) apply, document how they meet CBP's Minimum Security Criteria, and are then validated by a CBP Supply Chain Security Specialist.
In return, members get reduced examination rates, front-of-line processing, access to the FAST lanes, and other trade benefits.
The Minimum Security Criteria were substantially rewritten in 2019 and 2020 and are organized under corporate security, transportation security, and people and physical security, adding cybersecurity, agricultural security, and security vision and responsibility as newer areas.
CTPAT is a paperwork-heavy program. Members must complete and keep current a security profile in the CTPAT Portal that explains, criterion by criterion, how the requirement is met, and must back it with written procedures: a supply chain security risk assessment refreshed at least annually, a written cybersecurity policy, container and trailer inspection procedures, seal control procedures, personnel screening and termination procedures, visitor and access control, business partner screening and monitoring, and training records.
Validators check that the written procedures match what happens at the sites they visit.
Who has to comply
Voluntary. Open to US importers and exporters, US and Canadian highway carriers, rail, sea, and air carriers, licensed customs brokers, consolidators and NVOCCs, marine port authorities and terminal operators, foreign manufacturers in specified countries, and certain third-party logistics providers, each with its own eligibility rules.
Many large importers require their suppliers to join or to meet the criteria contractually.
What you have to write
Documents on this site that C-TPAT requires or expects, each with who must have it, the review cycle and the obligations that cite it.
What the assessor asks to see
Security profile in the CTPAT Portal; supply chain security risk assessment with threat and vulnerability analysis by route and partner; written procedures for each criterion (business partner screening, cybersecurity, conveyance and container inspection, seal control, procedural security, physical security, access controls, personnel security, education and training, agricultural security); business partner questionnaires and monitoring records; training attendance and materials; audit and self-assessment records; corrective action records from prior validations.
Where the requirement sits: CTPAT Minimum Security Criteria (2020): security vision and responsibility, risk assessment, business partners, procedural security, personnel security, education/training and awareness
Tiers
For importers, Tier I is certified but not yet validated; Tier II is validated as meeting the Minimum Security Criteria; Tier III is validated as exceeding the criteria and adopting recognized best practices. Higher tiers receive larger risk score reductions and fewer security examinations.
What AllyMatter does here
Controls the written security procedures and proves staff training acknowledgment.
AllyMatter publishes this site.
Assessors
Who assesses C-TPAT
CBP Supply Chain Security Specialists (government officers) perform validations and revalidations. There are no private third-party certifiers for CTPAT; consultants can prepare a member but cannot validate it. Validation is performed by the government agency that runs the program.
No firm has claimed a C-TPAT assessor listing yet. Claim yours →
Consultants
Who helps with C-TPAT
A well-developed consultant market helps companies write the security profile, run the risk assessment, draft procedures, train staff, and prepare for validation visits. Typical engagement is a readiness project of one to three months before application, plus periodic help before revalidation.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a C-TPAT consultant listing yet. Claim yours →
Software
Tools for C-TPAT
Tools that name this framework in their own material.
Related reading
- Understanding the CTPAT minimum security criteriaBreaks the twelve criteria categories into musts and shoulds and shows which of them require written procedures.Thomson Reuters
- CTPAT validation and minimum security criteriaPractitioner walkthrough of how a CBP validation actually runs: document review, staff interviews and site inspection.Diaz Trade Law
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for C-TPAT
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of C-TPAT in AllyMatter
Approve the policies C-TPAT asks for, keep every version, and record a named acknowledgment from each person who has to read them.