If you are shipping your products to the USA, your buyer or freight forwarder may have asked whether you comply with the C-TPAT security criteria. C-TPAT compliance is not something for which you receive a certificate. Rather, it is a list of security criteria used by CBP to assess supply-chain security and determine which shipments may need more inspection and which may receive fewer inspections.
Below is a complete C-TPAT Security Criteria Checklist divided into the key areas used by CBP and commonly assessed through supplier security questionnaires.
Read more :- c-tpat full form
What C-TPAT Actually Is and Isn’t
Customs Trade Partnership Against Terrorism, or C-TPAT, is a voluntary program by US Customs and Border Protection (CBP) to secure international supply chains, from the country of origin to US ports of entry, against terrorism.
Now here’s what Indian factories tend to misunderstand about C-TPAT. C-TPAT participation is generally available to eligible US-based importers, carriers, brokers, and other qualifying business partners. An Indian factory in Ludhiana, Tirupur, or another manufacturing hub should not assume that it can simply obtain a standalone C-TPAT certificate through the CBP website.
What Indian exporters generally do is demonstrate that their security practices meet applicable C-TPAT expectations as business partners of eligible US companies. The C-TPAT status and supply-chain security of a buyer can depend on the security practices of its partners, including overseas suppliers. This is why a buyer may give you a security questionnaire and make C-TPAT compliance a sourcing requirement in its RFQ.
The C-TPAT Security Criteria Checklist: 11 Core Areas
The C-TPAT requirements for supply-chain security cover 11 major areas. For Indian exporters, these areas provide a practical framework for preparing internal controls, buyer questionnaires, and security assessments.
1. Business Partner Requirements
You need to know who you’re doing business with. This means:
- Checking suppliers, vendors, and service providers against applicable denied-party and sanctions lists
- Maintaining written agreements or contracts that include security requirements
- Conducting periodic reviews of business partners and their security practices
- Maintaining proper documentation of the screening and review process, not just evidence that the activity took place
2. Cybersecurity
CBP places significant importance on protecting information and systems used within the supply chain. Expect to show:
- Data protection and access-control policies in writing
- Password policies and defined password-management procedures
- Network firewalls, intrusion detection or prevention systems, and updated antivirus or endpoint protection
- An incident-response plan in case of data breaches or other cybersecurity incidents
- Controls covering warehouse systems, handheld scanners, tablets, and other connected devices
3. Conveyance and Instruments of International Traffic Security
This covers containers, trailers, and other equipment used to move goods internationally.
- Pre-stuffing container or trailer checks using the applicable seven-point inspection process
- Procedures for reporting unauthorized access, tampering, or suspicious conditions
- Empty container storage in a safe and controlled environment
- Documentation showing that required inspections were completed
4. Seal Security
Every loaded container should use a high-security seal meeting applicable ISO/PAS 17712 requirements.
- Only authorized personnel should be provided with seals
- Maintain a documented Seal Control Log showing seal numbers, the seal applicator’s name, and date
- Use the VVTT verification process at applicable handover points
- VVTT stands for View the seal, Verify the seal number against shipping documents, Tug the seal, and Twist the seal
- Cross-check seal numbers against shipping documentation before dispatch
5. Procedural Security
This is where documented procedures are tested in practice.
- Procedures for identifying, questioning, and responding to unauthorized or unknown individuals in shipping and receiving departments
- Procedures for checking that seal numbers correspond with documentation before the container leaves
- A defined process for reporting shortages, surpluses, damage, tampering, and other cargo irregularities
- Escalation procedures for reporting issues to management or relevant authorities when applicable
6. Agricultural Security
This area is particularly relevant to food, spice, agricultural, and other exporters whose shipments may create contamination or biosecurity concerns.
- Measures to prevent contamination by prohibited soil, plants, animals, or other materials
- Training to ensure employees can detect signs of pest infestation
- Inspection of containers and cargo areas before loading
- Documentation demonstrating that containers are clean and dry before stuffing
Read more :- c-tpat audit
7. Physical Security
The facility itself needs controlled boundaries.
- Fencing of cargo handling and storage areas, with damage checked and rectified promptly
- Good lighting inside and outside the building, including parking lots and entrances
- Security locks or suitable controls on exterior and interior doors, windows, gates, and fences
- Alarms and video surveillance monitoring key locations
- Defined procedures for retaining and reviewing security footage
8. Physical Access Controls
Access control is about who gets into the facility and sensitive areas.
- Positive identification of employees, vendors, contractors, and visitors upon entering the facility
- Logging of vendors and visitors and requiring escorts in sensitive areas where applicable
- Procedures for issuing, tracking, and revoking employee access devices such as ID cards, keys, and access cards
- Prompt removal of facility and system access when an employee leaves the organization
9. Personnel Security
Security starts with who you hire and who has access to sensitive operations.
- Background checks or verification before employment, in accordance with local laws
- Procedures for immediate de-provisioning of access to facilities and systems after termination
- Periodic review of sensitive personnel positions such as shipping, receiving, warehouse operations, and IT
- Procedures for reporting suspicious employee activity or security concerns
10. Education, Training, and Awareness
CBP wants proof that security policy translates into staff behaviour, not just a binder on a shelf.
- A documented security-awareness training programme that is reviewed and updated at least annually
- Specific training on detecting internal conspiracies, product integrity, suspicious behaviour, access control, and reporting procedures
- Documentation of training participants, dates, and training content
- Refresher training when procedures, responsibilities, or security risks change
11. Trade Compliance
This ties supply-chain security back to accurate customs documentation.
- Written procedures to ensure information used for tariff classification, valuation, and country-of-origin determination is correct
- A documented process for identifying and correcting compliance issues
- Assignment of responsible personnel to oversee trade-compliance activities
- Records supporting customs-related decisions, corrections, and declarations
C-TPAT Security Criteria Checklist for Exporters: What’s Different
For an Indian exporter, the C-TPAT security criteria checklist for exporters is generally used as an internal readiness framework and to demonstrate compliance to a US buyer or other supply-chain partner.
The compliance department of your buyer will generally provide you with a supplier security questionnaire based on the applicable security categories.
It is possible that the importer, its customs broker, or an independent auditor appointed by the importer may conduct a site visit at your premises.
Paperwork is just as important as physical controls because buyers and auditors need to see evidence that security procedures are actually implemented. If you sell to several buyers in the US, it is beneficial to design one internal security programme covering the relevant security areas instead of preparing separately for every questionnaire.
C-TPAT Minimum Security Requirements at a Glance
| Category | Core Requirement | Common Gap Found in Audits |
|---|---|---|
| Business Partner Requirements | Screen and document partner due diligence | No written screening record |
| Cybersecurity | Written IT security policy, access controls, and incident plan | No documented breach response plan |
| Conveyance/IIT Security | Seven-point container inspection before stuffing | Inspection completed but not logged |
| Seal Security | ISO/PAS 17712 seals and documented verification | Seal numbers not cross-checked against documents |
| Procedural Security | Challenge unidentified persons and verify seals before departure | No formal discrepancy-reporting process |
| Agricultural Security | Prevent contamination and train staff on pest awareness | Container cleanliness or dryness not documented |
| Physical Security | Fencing, lighting, locks, alarms, and CCTV | Camera coverage or retention is inadequate |
| Physical Access Controls | ID checks, visitor logs, and access-device management | Access is not revoked promptly |
| Personnel Security | Background verification and termination protocols | Sensitive roles are not periodically reviewed |
| Education & Training | Annual security training and records | Training occurs but is not documented |
| Trade Compliance | Accurate classification, valuation, and origin controls | No named compliance owner |
Preparing for a C-TPAT Validation Visit
If your buyer’s supply chain includes a validation step, the C-TPAT Validation Visit is where CBP or the importer’s team may physically confirm what’s documented and how those controls operate at the facility.
A few things make this process smoother:
- Take the tour yourself first using the 11 applicable security areas as a checklist
- Have training logs, seal logs, visitor logs, background-verification records, access records, and relevant policies ready for review
- Train gate, warehouse, shipping, receiving, and security personnel on the questions they may be asked
- Correct physical security vulnerabilities before the assessment rather than during it
- Check that employees understand the procedures they are expected to follow
- Verify that documentation matches actual practices on the shop floor and in warehouse operations
Common Mistakes That Fail a C-TPAT Compliance Checklist Review
A few patterns show up repeatedly in facilities that are not adequately prepared:
- Security policies exist on paper, but employees cannot explain what they mean or how they apply to daily work
- Seal logging is maintained, but seal numbers are not verified against shipping documents
- CCTV cameras are installed, but footage is not retained for the required or defined period
- Background checks are performed during hiring, but sensitive roles are not periodically reviewed
- Cybersecurity policies cover office computers but overlook handheld scanners, tablets, warehouse systems, or other connected devices
- Visitor and contractor records are incomplete
- Corrective actions are discussed verbally but are not documented
- Physical security controls exist but are not regularly inspected for damage or failure
When to Bring in CTPAT Certification Services
It can be difficult to build and maintain a security programme covering all applicable areas while operating a manufacturing facility at the same time. CTPAT Certification Services can help an exporter review existing processes, identify gaps, prepare documentation, train employees, and organise evidence before a buyer or third-party assessment.
Legal4Sure works with Indian food, textile, and general manufacturing exporters to review existing processes against the C-TPAT compliance checklist and help align security documentation with buyer expectations.
Key Takeaways
- The C-TPAT Security Criteria Checklist covers business partners, cybersecurity, containers and conveyances, seals, procedures, agricultural security, physical security, access controls, personnel, training, and trade compliance.
- Indian exporters generally demonstrate compliance through their relationship with eligible US supply-chain partners rather than treating C-TPAT as a standalone factory certificate.
- Seal verification, documentation, access management, training records, and cybersecurity controls are common areas that require strong evidence.
- Early preparation for a validation or buyer assessment is more effective than making physical and documentary corrections at the last minute.
- A single internal security programme can help an exporter respond consistently to questionnaires from multiple US buyers.
Conclusion
Compliance with C-TPAT security standards is not an issue of passing an inspection on one particular day. It is an ongoing process of maintaining a business environment where security controls are documented, implemented, reviewed, and understood by employees.A structured security programme makes it easier to identify gaps before they become buyer audit findings. It also helps exporters maintain consistent controls as customers, products, employees, and logistics arrangements change.
ETHICAL COMPLIANCE SERVICES
C-TPAT Security Criteria
Avoid certificate expiry, maintain buyer confidence, and restore compliance quickly. Our experts help with audit planning, corrective actions, documentation, and C-TPAT Security Criteria
Need Help with C-TPAT Security Criteria
Our C-TPAT Security Criteria help you manage certificate expiry, recertification audits, corrective actions, compliance documentation, and fast reinstatement to minimize business disruption.
FAQs
What are the C-TPAT security criteria?
The C-TPAT security criteria cover business partner controls, cybersecurity, conveyance and container security, seals, procedures, agricultural security, physical security, access controls, personnel security, training, and trade compliance.
Is there a C-TPAT security criteria checklist for exporters specifically?
Yes. Exporters can use the applicable security areas as a readiness framework and then demonstrate compliance with the specific requirements communicated by their US buyer or supply-chain partner.
What are the C-TPAT minimum security requirements for containers?
Key controls include the applicable seven-point inspection before stuffing, secure handling and storage, documentation of inspections, and high-security seals that meet the applicable ISO/PAS 17712 requirements.
Can an Indian manufacturer enroll directly in C-TPAT?
Eligibility depends on the C-TPAT entity type and CBP participation rules. Indian manufacturers should not assume that they can obtain a standalone C-TPAT certificate simply because they export to the United States.
How often does C-TPAT security training need to happen?
Security-awareness training should be conducted at least annually where the applicable C-TPAT requirements call for annual training, with completion and participation documented.
What happens during a C-TPAT Validation Visit?
A validation or security assessment may review the facility, employees, procedures, records, access controls, cargo handling, seal management, and other applicable controls to confirm that security measures are implemented.
Do CTPAT Certification Services help with buyer audits too?
Yes. A consultant can help prepare an export facility for buyer security questionnaires, site assessments, and applicable C-TPAT-related reviews.

