4 min read
Cybersecurity requirements are not a checkbox anymore
For most of the CTPAT program's history, CTPAT cybersecurity requirements were a written policy. You documented your security posture, you put the...
The U.S. Customs and Border Protection’s (CBP) minimum security criteria (MSC) are imperative to your success, whether you’re new to CTPAT certification or prepping for validation or recertification. You can learn more about MSC and corporate security from Veroot. In today’s post, we’re diving into risk assessment to satisfy MSC.
Since CTPAT certification was created to mitigate the threat of terrorist groups and criminal organizations, having an MSC risk assessment that identifies these vulnerabilities is an obvious part of minimum security requirements. Understanding exactly how to document this assessment and mitigate/eliminate necessary risks may not be as obvious to foreign manufacturers. Veroot is here to support you on your quest to pass the MSC risk assessment.
Multiple steps must be taken to prepare a successful MSC risk assessment. First is a self-assessment of your supply chain practices, procedures, and policies.
The purpose of the MSC self-assessment is to:
To document this, you might conduct an internal MSC self-assessment, send MSC security questionnaires to business partners, and conduct facility and management reviews. The goal of the MSC self-assessment is to take an objective look at your organization and gain confidence that you’re meeting the requirements or that you’ve identified areas of risk and have plans in motion to improve them.
The next step is to conduct an MSC international risk assessment. There are 3 parts to this.
During the MSC international threat assessment, you’ll need to identify threats that exist within a country or region based on your business model and various roles in your supply chain. The MSC threat assessment is meant to identify threats that are outside of your control. Examples include terrorist activity, drug smuggling, hijacking, corruption levels, and human smuggling.
When assessing risk, a simple way to label each threat is:
Once the threats are assessed, you can dedicate more time and resources to the “high” areas of risk to mitigate them.
The international risk assessment also needs to contain cargo mapping to meet MSC, determining how your cargo moves from the point of origin to the importer’s distribution center. The MSC cargo mapping needs to include all parties that are involved with moving cargo, whether directly or indirectly. This includes:
In addition, you’ll need to look at all transportation legs, especially when cargo is “at rest,” where it is likely more vulnerable. Read more from Veroot about cargo maps if you’re interested in an example.

If threats have been identified in your supply chain, an MSC risk assessment action plan needs to be put in place to improve them. It’s very important that you have a risk assessment plan available to create change.
Examples of action plans for MSC include security questionnaire reviews or site visits to address vulnerabilities. Veroot’s CTPAT compliance software allows you to:
Having a central location to store your action plan, security questionnaires, SOPs, management reviews, and more will put you at ease knowing you have all your compliance documentation on hand.
The work doesn’t end after you’ve compiled your initial MSC risk assessment; it needs to be completed annually. If a CTPAT member has several “high” risk factors, assessments for MSC may need to be completed more often. Examples of when this would be necessary include an increased threat level from a specific country, periods of heightened alert, changes in business partners, and/or changes in corporate structure/ownership.
The most important piece of advice when seeking MSC alignment is to document everything. According to the CBP, to meet the MSC for risk assessment, you must have written procedures in place that address:
Not only is this a good practice as a company, but cataloging and writing everything down gives you the evidence you need to successfully answer the CBP when they ask about your risk assessment for minimum security criteria.
As you can see, conducting, documenting, and monitoring your MSC risk assessment is no small feat. Many organizations that are seeking CTPAT compliance have dedicated internal resources to accomplish these tasks, but many do not. That’s where Veroot comes in.
Our CTPAT compliance software simplifies the process for you. With an automated process, our customers save an average of 85% – 90% of the time they used to spend managing their CTPAT membership the old-fashioned way. Let’s get you ready for the MSC risk assessment. Get in touch with us today to get started.
4 min read
For most of the CTPAT program's history, CTPAT cybersecurity requirements were a written policy. You documented your security posture, you put the...
When companies think about the primary goal of CTPAT (Customs Trade Partnership Against Terrorism), which is to strengthen international supply...