C-TPAT Security Profile
Produces a CBP-ready C-TPAT Security Profile grounded in documented, verifiable practices aligned with CBP Minimum Security Criteria.
Gather Inputs
- Corporate identifiers — legal name, EIN, DUNS, HQ, facility list, C-TPAT account/tier if enrolled
- Supply chain map — roles (importer/broker/forwarder), trade lanes, origin countries, products, volume
- Security governance — org chart, C-TPAT coordinator, reporting lines, authority
- Policies & SOPs — physical, personnel, procedural, conveyance, IT security procedures
- Risk assessment artifacts — methodology, frequency, recent assessments, mitigation plans
- Training records — onboarding, refresher, role-based, attendance logs
- Business partner vetting — questionnaires, audits, certifications, corrective actions
- Incident logs — security events, seal discrepancies, investigations, remediation
- Validation history — prior CBP validations, findings, corrective actions
Profile Sections
Draft each section using only verifiable, current practices. Never use future-tense promises.
1. Document Control
Version, date, preparer, approver, confidentiality marking.
2. Company Overview & Eligibility
Legal name, EIN, DUNS, HQ, facilities, C-TPAT account/tier, supply chain role, import volume, primary origins, product categories.
3. Governance & Organization
- C-TPAT coordinator — name, title, authority, reporting line
- Security team roles — physical, IT, compliance, operations
- Executive sponsor and review cadence
4. Risk Assessment Method
Framework, frequency, trigger events, scope, risk scoring, documentation approach.
5. Physical Security
6. Personnel Security
7. Procedural Security & Supply Chain Integrity
8. Conveyance Security
Seven-point inspection for containers/trailers: front wall, left side, right side, floor, ceiling/roof, inside/outside doors, outside/undercarriage. Document with logs and photos. Apply equivalent protocols for rail/other modes.
9. Seal Control
10. IT Security
Cover access control (MFA/RBAC), network security (firewalls/IDS/segmentation), data protection (encryption/backup/DR), patch management, and incident response.
11. Compliance & Continuous Improvement
12. Recordkeeping & Validation Readiness
13. Statement of Commitment
Include signature block: "[Company] affirms its commitment to maintaining C-TPAT security standards, continuous improvement, and full cooperation with CBP validation activities." With signature, title, and date lines.
14. Appendices
Org chart, facility diagrams, sample inspection/seal logs, training records, risk assessment summary.
Pitfalls
- Unverifiable claims — never assert certifications or tier status without supporting documentation
- Omitted facilities/lanes — profile must cover all facilities and trade lanes; gaps trigger CBP scrutiny
- Inconsistency — cross-check facts across sections; contradictions undermine credibility
- Uncertain citations — mark any unverified regulatory references with
[VERIFY]
- Confidentiality — align markings with company policy and CBP submission expectations
1---2name: c-tpat-security-profile3description: Drafts a U.S. C-TPAT Security Profile for CBP submission covering physical, personnel, procedural, conveyance, and IT security domains. Use when preparing C-TPAT enrollment, certification, validation, or recertification profiles, or assembling a CBP-ready security narrative. Trigger: C-TPAT, CBP security profile, supply chain security, trusted trader, customs validation.4---5
6# C-TPAT Security Profile
7
8Produces a CBP-ready C-TPAT Security Profile grounded in documented, verifiable practices aligned with CBP Minimum Security Criteria.
9
10## Gather Inputs
11
121. **Corporate identifiers** — legal name, EIN, DUNS, HQ, facility list, C-TPAT account/tier if enrolled
132. **Supply chain map** — roles (importer/broker/forwarder), trade lanes, origin countries, products, volume
143. **Security governance** — org chart, C-TPAT coordinator, reporting lines, authority
154. **Policies & SOPs** — physical, personnel, procedural, conveyance, IT security procedures
165. **Risk assessment artifacts** — methodology, frequency, recent assessments, mitigation plans
176. **Training records** — onboarding, refresher, role-based, attendance logs
187. **Business partner vetting** — questionnaires, audits, certifications, corrective actions
198. **Incident logs** — security events, seal discrepancies, investigations, remediation
209. **Validation history** — prior CBP validations, findings, corrective actions
21
22## Profile Sections
23
24Draft each section using only verifiable, current practices. Never use future-tense promises.
25
26### 1. Document Control
27
28Version, date, preparer, approver, confidentiality marking.
29
30### 2. Company Overview & Eligibility
31
32Legal name, EIN, DUNS, HQ, facilities, C-TPAT account/tier, supply chain role, import volume, primary origins, product categories.
33
34### 3. Governance & Organization
35
36- C-TPAT coordinator — name, title, authority, reporting line
37- Security team roles — physical, IT, compliance, operations
38- Executive sponsor and review cadence
39
40### 4. Risk Assessment Method
41
42Framework, frequency, trigger events, scope, risk scoring, documentation approach.
43
44### 5. Physical Security
45
46- [ ] Perimeter controls (fencing, barriers, lighting)
47- [ ] CCTV coverage map and retention
48- [ ] Access controls for all zones
49- [ ] Visitor management
50- [ ] Loading dock controls
51- [ ] Alarm/monitoring response
52- [ ] Guard force staffing and training
53
54### 6. Personnel Security
55
56- [ ] Pre-employment screening scope
57- [ ] Enhanced checks for sensitive roles
58- [ ] Contractor/temp worker controls
59- [ ] Security awareness training
60- [ ] Termination and access revocation procedures
61- [ ] Re-screening policy
62
63### 7. Procedural Security & Supply Chain Integrity
64
65- [ ] Business partner vetting and re-assessment
66- [ ] Receiving procedures and discrepancy handling
67- [ ] Cargo storage access controls
68- [ ] Shipping documentation accuracy checks
69- [ ] Recordkeeping controls
70
71### 8. Conveyance Security
72
73Seven-point inspection for containers/trailers: front wall, left side, right side, floor, ceiling/roof, inside/outside doors, outside/undercarriage. Document with logs and photos. Apply equivalent protocols for rail/other modes.
74
75### 9. Seal Control
76
77- [ ] High-security seals meet ISO 17712
78- [ ] Seal inventory control
79- [ ] Authorized applicators identified
80- [ ] Seal number logging
81- [ ] Verification at transfer points
82- [ ] Discrepancy escalation procedure
83
84### 10. IT Security
85
86Cover access control (MFA/RBAC), network security (firewalls/IDS/segmentation), data protection (encryption/backup/DR), patch management, and incident response.
87
88### 11. Compliance & Continuous Improvement
89
90- [ ] Annual self-assessments
91- [ ] Corrective actions tracked with owners/dates
92- [ ] CBP updates monitoring
93- [ ] Training refresh cadence
94
95### 12. Recordkeeping & Validation Readiness
96
97- [ ] Evidence repository organized and indexed
98- [ ] Retention periods documented
99- [ ] Validation visit readiness plan
100
101### 13. Statement of Commitment
102
103Include signature block: "[Company] affirms its commitment to maintaining C-TPAT security standards, continuous improvement, and full cooperation with CBP validation activities." With signature, title, and date lines.
104
105### 14. Appendices
106
107Org chart, facility diagrams, sample inspection/seal logs, training records, risk assessment summary.
108
109## Pitfalls
110
111- **Unverifiable claims** — never assert certifications or tier status without supporting documentation
112- **Omitted facilities/lanes** — profile must cover all facilities and trade lanes; gaps trigger CBP scrutiny
113- **Inconsistency** — cross-check facts across sections; contradictions undermine credibility
114- **Uncertain citations** — mark any unverified regulatory references with `[VERIFY]`
115- **Confidentiality** — align markings with company policy and CBP submission expectations
116
117---