CTPAT Resources

CTPAT Physical Security Requirements: Where They Collide With Your Cybersecurity Criteria

Written by Admin | Jul 20, 2026 3:25:16 PM

CTPAT's Minimum Security Criteria treat Physical Security, Physical Access Controls, and Cybersecurity as separate categories. In practice they run on the same infrastructure. Badge readers, CCTVs, alarm panels, and gate systems are all networked computers, which means every physical control in your program is also an IT asset. When those two categories are owned by different teams, the evidence gap between them is where validation findings come from.

The CTPAT Minimum Security Criteria lists Cybersecurity as one category. It lists Physical Security and Physical Access Controls as others. Different sections, different pages, different owners inside your company.

Your validator doesn't see it that way.

When a Supply Chain Security Specialist walks your facility, they're looking at one system. The badge reader at the dock door is a networked device. The CCTV recording your container yard is a computer. The alarm panel talks to a monitoring service over an IP connection. Every one of those is a physical control running on digital infrastructure. And every one of them tends to fall into the seam between your IT team and your facilities team.

That seam is where findings come from.

 

Why does CTPAT separate cyber and physical security?

The categories are split because the disciplines developed separately, not because the risks are separate.

CBP's 2020 MSC update didn't add cybersecurity as a checkbox. It reframed it as an operational discipline, with control implementation, evidence of testing, an incident response capability, and real integration between IT operations and your compliance program. We broke the full list down in CTPAT Cybersecurity Requirements Under the New MSC.

At the same time, the physical criteria got sharper. Cameras have to cover critical areas and be checked for focus and coverage. Alarms have to be tested on a schedule and again after any repair. Footage has to be retained and reviewed periodically, not only after something goes wrong.

Read those two lists next to each other and the overlap is obvious. Camera footage is your physical security evidence. It lives on a networked recorder. If that recorder is unpatched, running a default password, and sitting flat on the corporate network, you have a cybersecurity gap that produces a physical security failure.

Most compliance officers have never been shown that connection. It isn't their fault. Nobody handed them an asset list that includes the DVR.

 

Where do CTPAT cyber and physical security requirements overlap?

Six places, and these aren't hypotheticals. They're the questions that get asked during a validation.

1. Offboarding runs on two lists. The MSC expects prompt removal of IT system access when someone leaves. It also expects prompt collection of badges and IDs. Those are usually two separate processes owned by two separate people. IT kills the email account on day one. Facilities collect the badge whenever HR gets around to telling them. You can prove one and not the other, and a validator will ask for both.

2. Your camera system is a networked computer. The NVR has firmware. It has an admin account. It probably has a remote support tunnel so the installer can troubleshoot without driving out. That's third-party network access to a device holding your compliance evidence. Ask who owns patching it. In most companies, the honest answer is nobody.

3. Access control systems store credentials. A badge database is an authentication system. It has user accounts, permission levels, and an audit log. Your cybersecurity criteria covers exactly that kind of system. Your IT team has never touched it.

4. Testing evidence lives in a binder. The MSC wants proof that alarms and cameras are tested on a schedule and that facility inspections happen regularly. That evidence usually sits in a facilities spreadsheet or a paper log in a drawer at the site. Your compliance evidence for a whole MSC category is in a building you don't work in.

5. Incident response plans stop at ransomware. Most IR plans cover encrypted servers and phishing. Very few cover a cloned badge, a wiped CCTV, or an alarm panel that stopped reporting three weeks ago. If your plan doesn't name a physical scenario, it isn't a supply chain security plan.

6. Storage failures are silent. A recorder that silently stops recording to the disk provides no alert and captures no footage. You find out during an incident, or during a validation, when you go looking for retained footage you're supposed to have. That's a monitoring problem, and monitoring is an IT function.

 

Why does the gap survive?

It isn't a technology problem. It's an ownership problem.

Physical security reports to operations or facilities. Cybersecurity reports to IT. Compliance reports to legal or trade. Three functions, three sets of records, three definitions of what "done" looks like. Nobody is wrong. Nobody is talking to each other either.

Then a validation date lands. The compliance officer becomes the person who has to assemble evidence from all three, by email, in six weeks, from people who have other jobs. Half the evidence is stale. Some of it doesn't exist. The parts that do exist are screenshots with no timestamp and no owner.

That's the grind. It's also why gaps stay open for years without anyone noticing. When evidence collection is a fire drill, nobody has the bandwidth to ask whether the controls are actually working between drills.

 

How do you close the gap between CTPAT physical and cyber controls?

You don't need a security overhaul. You need the two sides to share one view.

Build one asset inventory that includes physical security systems. Cameras, recorders, badge controllers, alarm panels, gate systems. Record IP address, firmware version, admin account owner, patch status, and vendor remote access. Map each one back to the 13 cybersecurity requirements CTPAT expects you to meet. If IT has never seen this list, that's the finding you just prevented.

Give offboarding one trigger. When HR marks a departure, IT access removal and badge deactivation should fire from the same event. Log both. A single record showing both actions on the same date is far stronger evidence than two systems that mostly agree.

Put physical scenarios into your incident response plan. Add tampered access control, camera outage, and unauthorized facility entry. Name the responder. Set the escalation path. Test it once.

Run one testing calendar. Alarm tests, camera coverage checks, firmware updates, and access log reviews belong on the same schedule with the same evidence format. Different technicians can execute them. The record should look identical.

Collect the evidence continuously, not annually. Timestamped, attributed, and stored in one place your team can pull from on any day. If you can only produce evidence during the audit season, you don't have a control. You have a project.

The same logic runs through the broader CTPAT minimum security requirements for importers. Every category assumes an owner. Most companies have never named one.

 

What this actually buys you

Closing this gap is defensive on the surface. It's commercial underneath.

Trusted trader status is a sales asset. It shortens conversations with customers who move regulated freight. It's a differentiator in RFPs where your competitor is still promising to "look into" their security program. And it holds up under the scrutiny that comes when a partner audits you, not just when CBP does.

A validator who asks for your camera testing log and gets it in four minutes forms an opinion about the rest of your program. So does a prospect. Audit readiness compounds.

The companies that stay ahead here aren't the ones with the biggest security budgets. They're the ones who stopped treating cyber and facility controls as two separate binders and started running them as one system of record.

 

FAQ

Does CTPAT require cybersecurity controls on camera and badge systems? CTPAT's cybersecurity criteria apply to IT systems used in the company's operations. Networked video recorders, access control servers, and alarm panels are IT systems by any working definition, which means the same expectations around patching, password policy, access management, and monitoring apply to them. Most companies have never included them in an IT asset inventory.

Who should own CTPAT physical security evidence? One person, with input from three. The failure mode is shared ownership with no single accountable name. Whoever assembles evidence for the validator should own the calendar, the format, and the storage location for physical and cyber evidence alike.

How long does CTPAT require security footage to be retained? CBP publishes CCTV footage retention guidance within the Minimum Security Criteria (MSC) for each applicable CTPAT business entity. The guidance recommends retaining footage for at least 14 days after a shipment reaches its first point of distribution, the location where the container is first opened after clearing Customs. Check the MSC document for your specific role, because retention expectations differ by category.

What happens if physical security evidence is missing during a validation? A missing testing log or an unretained recording is a finding. It also shapes the specialist's read on the rest of your program. Validators generalize from what they can and can't see quickly.