Supply Chain & Logistics
Vendor risk management and chain of custody
WCO Online AEO Compendium (aeo.wcoomd.org), which also records 7 programmes under development and, separately, 126 bilateral and 6 plurilateral mutual recognition arrangements.
Supply chain security extends beyond IT to encompass physical logistics, vendor management, and chain of custody for goods. Thalorin provides comprehensive supply chain compliance covering vendor risk, logistics security, and the documentation required to demonstrate supply chain integrity.
The World Customs Organization published the 2025 edition of the SAFE Framework of Standards, and national programmes take their validation criteria from it. The 2025 edition adds a Code of Conduct for Authorised Economic Operators, education on internal conspirators and insider threats, provisions bringing micro, small and medium enterprises into AEO programmes, and cooperation with environmental authorities. None of that amends a statute. It changes what a validator asks about at the next site visit, which is the form regulatory change usually takes in trade security: no notice, new questions.
Two regimes govern the same supplier list and do not speak to each other. On the customs side, CTPAT is a voluntary government-private sector programme established at 6 U.S.C. 961, with Tier 1, Tier 2 and Tier 3 participants and minimum security requirements the Commissioner must review at least once every year. Internationally, the WCO records 92 operational AEO programmes and 126 bilateral mutual recognition arrangements. On the cyber side sits NIST SP 800-161 Revision 1, updated on 1 November 2024. One regime asks who touched the container. The other asks what shipped inside the software.
The seal rule everyone cites is thinner than they think. 6 U.S.C. 944 ordered a rulemaking on container security standards, and its interim provision applies ISO PAS 17712 sealing to containers in transit to the United States only because that rule did not issue — it took effect on 15 October 2008 and lapses when the rule arrives. Most organisations can produce a seal number. Far fewer can show the number applied at stuffing is the number verified at the port of loading, at deconsolidation and at the door.
Rather than keeping a file per programme, each supplier and each site is held once and projected into the CTPAT criteria, the AEO criteria of whichever administration is asking, and the NIST SP 800-161 control set. Custody evidence binds to the shipment rather than to the vendor record, so a seal discrepancy resolves to a container, a leg and a carrier. Defense supply chain obligations such as Section 889 prohibited sources and criticality analysis are a different problem, treated on the supply chain risk capability rather than here.
Manufacturing faces evolving cyber risks
A seal number nobody reconciles
The ISO PAS 17712 requirement at 6 U.S.C. 944 is an interim default that holds only until the rulemaking it names takes effect. Recording a number at stuffing is straightforward; proving it survived every handoff to arrival is what quietly fails.
Minimum security requirements reviewed yearly
6 U.S.C. 961 obliges the Commissioner to review CTPAT minimum security requirements at least once every year and update them as necessary, and tier status depends on validation against the current set. A programme built once against an earlier edition drifts out of qualification.
Mutual recognition does not travel by itself
The WCO records 126 bilateral and 6 plurilateral arrangements. Benefit under any of them depends on the partner administration receiving and matching your operator identifier on the declaration, which is a data quality problem before it is a security one.
Two assessments of the same supplier
A customs validator inspects the perimeter, the seal log and the hiring process. A cyber assessor working from NIST SP 800-161 asks about build systems and component provenance. One vendor, two evidence sets, two owners who never compare notes.
How Thalorin helps
Vendor security assessment
One assessment record per supplier site, projected into the CTPAT criteria a validator works from and into the NIST SP 800-161 Revision 1 control set, instead of two questionnaires asking overlapping questions in different vocabulary.
Logistics system security
Transport and warehouse management systems, carrier portals and messaging interfaces are treated as in-scope systems with named owners, because booking, routing and release instructions can be altered there without anyone approaching a container.
Chain of custody documentation
Seal numbers under the ISO PAS 17712 specification named at 6 U.S.C. 944 are recorded at stuffing and reconciled at every handoff, so a discrepancy resolves to a leg and a carrier rather than to a whole shipment.
Supplier qualification workflows
Qualification carries programme status alongside security evidence: CTPAT tier, AEO authorisation, and which mutual recognition arrangements actually reach the destination administration, so sourcing sees both at the point of decision.
Third-party risk management
Scoped deliberately to the logistics chain: forwarders, brokers, drayage and deconsolidation, including the subcontractors your contracted parties appoint. Enterprise-wide third-party programmes are run through the vendor risk capability instead.
Supply chain visibility
Advance cargo information, booking records and status messages are held against the shipment, so a question from a customs administration about one container is answered from records rather than from a forwarder's inbox.
Supply Chain & Logistics: common questions
Does our supplier's CTPAT membership cover our shipments?
No. CTPAT status attaches to the member and to the sites and processes validated during its assessment, not to any particular container. If a supplier is a member and the drayage firm it nominates is not, the leg between the plant and the port sits outside every validated programme in the chain. Membership is meaningful evidence about the supplier's own facility, but it does not answer who held custody of a specific box on a specific day.
How many countries recognise our AEO authorisation?
Only those covered by an arrangement your own administration has concluded. The WCO Online AEO Compendium records 92 operational AEO programmes, 7 more under development, 126 bilateral mutual recognition arrangements and 6 plurilateral ones. Recognition is not a global status; it is a list of pairs. The benefit also only lands if your operator identifier is transmitted on the declaration in the form the partner administration expects to read it in.
What seal standard applies to containers bound for the United States?
ISO PAS 17712, but by default rather than by rule. 6 U.S.C. 944 directed a rulemaking on container security standards and provided that, absent the interim final rule, containers in transit to the United States would have to meet that specification from 15 October 2008 — a requirement that ceases once the rule takes effect. What validation examines beyond the seal is procedure: who may apply one, where numbers are recorded, and whether anyone reconciles the record at opening.
Is CTPAT mandatory for importers?
No. 6 U.S.C. 961 establishes it as a voluntary government-private sector programme with Tier 1, Tier 2 and Tier 3 participants and benefits that scale with validation. In practice it behaves as a commercial requirement rather than a legal one, because customers flow it down and the examination treatment applied outside the programme shows up as landed cost. The statute also obliges annual review of the minimum security requirements, which makes membership a recurring obligation rather than an achievement.
We already run CTPAT. Do we still need NIST 800-161?
They catch different failures. CTPAT and AEO validation address physical custody, facility access, personnel screening and business partner vetting. NIST SP 800-161 Revision 1, updated on 1 November 2024, addresses cybersecurity risk in what you acquire: counterfeit or tampered components, compromised development environments, inherited vulnerabilities in software you did not write. A container can arrive with an intact seal and a defective device inside it, and neither programme detects what the other is looking for.
Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.
Talk to us about Supply Chain & Logistics.
See how one evidence artifact satisfies Supply Chain & Logistics requirements alongside every other framework you carry.