Policy required document Quality
CTPAT Security Profile and Written Security Procedures
The Customs Trade Partnership Against Terrorism is a voluntary CBP program. Once a company applies, it must complete a security profile in the CTPAT Portal that addresses every Minimum Security Criteria item for its business type, and it must be able to produce written procedures behind most of them.
The MSC is organized into three focus areas and twelve categories: corporate security (security vision and responsibility, risk assessment, business partners, cybersecurity), transportation security (conveyance and instruments of international traffic, seal security, procedural security, agricultural security), and people and physical security (physical security, physical access controls, personnel security, education and training and awareness).
Each criterion is marked must or should, and the implementation guidance states where CBP expects a written procedure.
CBP validates the profile within a year of certification and revalidates at least every four years, visiting sites to compare the written procedures with what happens on the dock. The profile must be reviewed and updated in the portal annually.
Members of the CTPAT Trade Compliance track also carry forced labor requirements, including a documented social compliance program, since August 2023.
Obligation ledger
Who requires it, and what each one says.
| Source | Applies when | What it requires | Status |
|---|---|---|---|
| CTPAT Minimum Security Criteria CTPAT MSC by entity type, 2019 to 2021 versions with implementation guidance | CTPAT member or applicant | Meet every must criterion and address should criteria based on risk; written procedures where the MSC or its guidance states, including risk assessment, business partner screening, cybersecurity policies, seal control, procedural security for cargo and documents, personnel screening, and training. Program requirement; voluntary to join, mandatory to keep the certification. | Implied |
| CTPAT security profile annual review CTPAT Portal requirement; MSC 1.x security vision and responsibility | Every member | Update and confirm the security profile in the portal each year; document an annual review of security procedures and the risk assessment. Program requirement. | Attestation |
| CTPAT validation and revalidation CBP validation process | Within one year of certification, then at least every four years | Site visits by supply chain security specialists comparing the profile and written procedures with observed practice; a validation report with required actions. Program requirement. | Attestation |
| CTPAT MSC, business partners and forced labor MSC 3.9 (importers); CTPAT Trade Compliance forced labor requirements (Aug 2022, compliance Aug 1, 2023) | Importers; mandatory for Trade Compliance members | A documented social compliance program addressing forced labor in the supply chain, with evidence of implementation such as supplier contracts, audits and training. Should criterion for security-only members; must for Trade Compliance members. Verify the November 2025 FAQ. | Implied |
| Customer supply chain security requirements Retailer and manufacturer vendor manuals | You supply a CTPAT member that flows down the criteria | Written security procedures and periodic self-assessment questionnaires. Contractual. | Market |
Required sections
- Security vision and responsibility: management commitment statement, designated security point of contact, review process and audit of security procedures (MSC category 1)
- Risk assessment: documented process covering the international supply chain, threat and vulnerability analysis, and annual review or on trigger (category 2)
- Business partner requirements: written screening and selection procedures, verification of partners' CTPAT or equivalent status, periodic reviews, and the social compliance program for forced labor (category 3)
- Cybersecurity: written policies covering access, passwords or MFA, patching, backup, removable media, incident reporting, and personal device use (category 4)
- Conveyance and instruments of international traffic security: inspection procedures (the seven and seventeen point inspections), tracking and monitoring, and inspection records (category 5)
- Seal security: written high-security seal policy covering purchase, issuance, application, verification, discrepancy reporting and ISO 17712 compliance (category 6)
- Procedural security: cargo handling and documentation controls, manifest accuracy, shipping and receiving, discrepancy and incident reporting to CBP and law enforcement, brokers and agents (category 7)
- Agricultural security: written procedures to prevent pest contamination, wood packaging compliance, and visible pest contamination reporting (category 8)
- Physical security: perimeter, lighting, locking devices, alarms and surveillance, and periodic checks (category 9)
- Physical access controls: employee, visitor and vendor identification, badge issuance and removal, challenge and removal of unauthorized persons, mail and package screening (category 10)
- Personnel security: pre-employment verification, background checks consistent with local law, periodic re-checks for sensitive positions, termination procedures (category 11)
- Education, training and awareness: security awareness program for all employees, specialized training for sensitive roles, training records, and a means for employees to report anonymously (category 12)
- Document retention and evidence of implementation for each written procedure (validation expectation)
What the examiner asks for
What changed
Change log.
Frameworks
Where this document is required.
Who looks at it
Where this document gets checked.
No one certifies a document like this on its own. It is read during the audits and inspections below, and by the agency behind each rule.
| Where it is looked at | Who looks at it |
|---|---|
| C-TPAT | CBP Supply Chain Security Specialists (government officers) perform validations and revalidations. There are no private third-party certifiers for CTPAT; consultants can prepare a member but cannot validate it |
Who helps write it
Consultants.
Firms that name these standards in their own material.
No firm has claimed a listing for this document yet. Claim yours →
Where it lives
Software.
Tools that hold documents like this one and record who has read them.
Need a hand implementing it?
Find a Consultant for CTPAT Security Profile and Written Security Procedures
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Manage This Document in AllyMatter
Route it for approval, keep every version, and record a named acknowledgment from everyone who has to read it.
Questions
What people ask.
Is CTPAT membership required?
No. It is voluntary and gives benefits such as fewer examinations and front-of-line processing. Once you join, meeting the MSC and keeping the profile current is a condition of staying in.
How many written procedures does CBP expect?
The MSC uses the word written in a defined set of criteria and the implementation guidance says procedures should be written where consistency over time matters. Most importers end up with twelve to twenty procedures mapped to the twelve categories. Length depends on business model.
What happens at validation?
A CBP supply chain security specialist visits your facility and often a foreign supplier or carrier, walks through each criterion, compares your written procedure with what staff do, and issues a report with required actions and a due date.
Do the forced labor requirements apply to us?
The documented social compliance program is a should criterion for security-only importer members and a must for CTPAT Trade Compliance members. Check the November 2025 FAQ and your membership type.
Who owns this site?
AllyMatter, a policy management tool that may appear in listings on this page. It is labeled every time, excluded from picks, and receives nothing from the matching form unless you name it.