Cross-Framework Mapping

ISO 28001:2007 Supply Chain Security ManagementvsCustoms-Trade Partnership Against Terrorism (C-TPAT)

See exactly how ISO 28001:2007 Supply Chain Security Management controls map to Customs-Trade Partnership Against Terrorism (C-TPAT). Pre-computed mappings, identified gaps, and coverage analysis.

26
Controls Mapped
0
Gaps Found
52%
Coverage

According to the TheArtOfService Compliance Knowledge Graph:

ISO 28001:2007 Supply Chain Security Management maps to Customs-Trade Partnership Against Terrorism (C-TPAT) with 52% coverage across 11 directly mapped controls. Analysis of 21 ISO 28001:2007 Supply Chain Security Management controls identifies 10 compliance gaps — primarily concentrated in Monitoring and Continuous Improvement.

Source: TheArtOfService Knowledge Graph | 21 controls analysed | 693 frameworks | 819K+ cross-framework mappings

Control Mappings

Showing 20 of 26 mapped controls across 5 domains. Sign up to explore all 819K+ mappings across 693 frameworks.

Monitoring and Continuous Improvement(10 mappings)

DMF-6.4Incident Response and Learning
CTPAT-CC-01Cybersecurity
ISO28001-MI-02Internal Security Audits3 targets
AEO-SC-4Trading Partner Security
NRF-4Supply Chain Risk Identification
NRF-5Third-Party Partner Standards
ISO28001-MI-03Management Review of Security Program3 targets
AEO-SC-4Trading Partner Security
NRF-4Supply Chain Risk Identification
NRF-5Third-Party Partner Standards
ISO28001-MI-04Corrective and Preventive Actions3 targets
AEO-SC-4Trading Partner Security
NRF-4Supply Chain Risk Identification
NRF-5Third-Party Partner Standards

Process and Procedural Controls(8 mappings)

ISO28001-PC-01Customs and Trade Compliance
CTPAT-CC-03Trade Compliance
ISO28001-PC-03Supply Chain Incident Reporting3 targets
AEO-SC-4Trading Partner Security
NRF-4Supply Chain Risk Identification
NRF-5Third-Party Partner Standards
ISO28001-PC-04Supply Chain Continuity Planning4 targets
AEO-SC-4Trading Partner Security
CTPAT-CC-01Cybersecurity
NRF-4Supply Chain Risk Identification
NRF-5Third-Party Partner Standards

Personnel and Information Security(2 mappings)

ISO28001-PI-01Personnel Security Screening
CTPAT-SCS-02Personnel Security
ISO28001-PI-02Security Awareness and Training
CTPAT-SCS-02Personnel Security

+6 more mappings

Plus AI-powered gap analysis, compliance advisory, PDF exports, and cross-mapping for all 693 frameworks.

Create Free Account →

Free forever — no credit card required

Related Comparisons

Other ISO 28001:2007 Supply Chain Security Management comparisons

Other Customs-Trade Partnership Against Terrorism (C-TPAT) comparisons

Stop Paying Consultants to Read Spreadsheets

AI-powered compliance intelligence across 693 frameworks — at a fraction of consulting costs.

$0/forever

Free

  • 693 framework browser
  • Cross-framework mappings (819K+)
  • 824 compliance assessments
  • 3 AI queries & searches per day
Get Started Free
Recommended
$49/month

Professional

  • Unlimited AI Compliance Advisory
  • Unlimited full-text search
  • Framework self-assessment
  • PDF, Excel & CSV exports
Start 7-Day Free Trial →

What are the key differences between ISO 28001:2007 Supply Chain Security Management and Customs-Trade Partnership Against Terrorism (C-TPAT)?

ISO 28001:2007 Supply Chain Security Management has 21 controls across its framework, while Customs-Trade Partnership Against Terrorism (C-TPAT) covers 28 controls. Direct mapping analysis identifies 11 overlapping controls (52% coverage). The frameworks diverge most significantly in Monitoring and Continuous Improvement, where 4 ISO 28001:2007 Supply Chain Security Management controls have no direct Customs-Trade Partnership Against Terrorism (C-TPAT) equivalent.

How many controls map between ISO 28001:2007 Supply Chain Security Management and Customs-Trade Partnership Against Terrorism (C-TPAT)?

Of 21 total ISO 28001:2007 Supply Chain Security Management controls, 11 map directly to Customs-Trade Partnership Against Terrorism (C-TPAT) controls — representing 52% coverage. The remaining 10 controls represent compliance gaps requiring additional documentation or compensating controls to satisfy both frameworks simultaneously.

What are the compliance gaps when mapping ISO 28001:2007 Supply Chain Security Management to Customs-Trade Partnership Against Terrorism (C-TPAT)?

10 ISO 28001:2007 Supply Chain Security Management controls have no direct equivalent in Customs-Trade Partnership Against Terrorism (C-TPAT). The highest concentration of gaps is in Monitoring and Continuous Improvement with 4 unmapped controls. These gaps represent areas where additional controls, policies, or documentation must be created to achieve compliance with both frameworks.

Which control domains have the most gaps between ISO 28001:2007 Supply Chain Security Management and Customs-Trade Partnership Against Terrorism (C-TPAT)?

The domain with the highest gap count is Monitoring and Continuous Improvement (4 gaps). Export the full domain-by-domain gap breakdown via the Professional tier to generate a prioritised remediation roadmap.

This platform provides educational compliance tools, not legal, regulatory, or professional compliance advice. Cross-framework mappings are AI-assisted interpretations and do not reproduce or replace official standards. Framework names and trademarks belong to their respective owners. Consult qualified professionals for your specific compliance requirements. See our Terms of Service.