CBP held the 2026 Trade and Cargo Security Summit in Dallas on September 8-10, moved from its original April dates. The message to certified partners was to stop waiting. Evidence of Implementation is being judged harder than the Security Profile, Annual Reviews are being read rather than filed, Executive Order 14411 is pushing accountability onto importers of record by name, and 2027 brings digital validations and AI-assisted targeting.
Veroot's CTPAT compliance team spent three days in Dallas at CBP's 2026 Trade and Cargo Security Summit. We sat in the general sessions and the breakouts, and one line keeps coming back to us.
CBP told the room not to take a wait-and-see approach.
That isn't throwaway conference language. An agency doesn't stand in front of a room of certified partners and tell them to stop waiting unless it already knows what's coming. Between Executive Order 14411, the changes queued up for 2027, and the direction validations are heading, plenty is coming.
Here's what stood out to us, and what we'd be doing about it if we were in your chair.
If you take one thing from this post, take this. Your Security Profile describes what your company says it does. Evidence of Implementation shows that you actually do it. Those are two different things, and CBP spent real time at the Summit on the gap between them.
Blank forms don't count. Templates don't count. Neither does a folder of material someone assembled the week before a validation, which is a pattern they recognize instantly. What counts is the ordinary paper your operation generates on a normal Tuesday. Completed inspection checklists. Seal logs with real dates and real signatures. Training records. Audit reports. Management review minutes. Corrective action records with the correction actually documented.
There's a second half to this that companies miss. Evidence has to be legible, current, dated, signed where a signature is required, and associated directly with the applicable Minimum Security Criterion in the portal. A specialist shouldn't have to guess what a file is meant to demonstrate. If your uploads are named things like "scan_047.pdf" and floating unassociated, you're making someone do detective work on your behalf. That rarely goes your way.
We've written before about what audit-ready actually looks like on the day, including the three-criteria test that tells you in ten minutes whether your evidence holds up. Everything CBP said at the Summit pointed in the same direction. If you haven't run that test on your own program this year, run it this quarter.
A theme ran through the Summit sessions about how partners treat the Annual Review. Too many companies change the dates, keep the same language, and submit. CBP sees that. Repetitive statements with no meaningful update signal that no real review happened.
A few practical things came out of those sessions.
Keep your Company Officer and points of contact current. CBP sometimes learns a listed contact left the company when an email bounces, which is a bad way for that conversation to start. Set a reminder for the day your 90-day review window opens, and don't let it drift to the final week. Late submissions draw extra scrutiny and get rejected more often. If you genuinely need more time, ask your assigned Supply Chain Security Specialist in writing before the due date, not after.
Pull in the people who own each section. IT should answer the IT questions. HR should answer the HR questions. Warehouse management should answer the physical security questions. Larger companies can divide the profile across subject matter experts, but the Company Officer still has to consolidate it, read all of it, and be ready to defend all of it.
That last point matters more than it sounds. Consultants can help with the profile. We do this work every day. But during a validation, your Company Officer and your contacts are the ones answering questions about every response and every attachment. If they can't explain it, it doesn't hold up.
Summit discussion kept circling back to visibility, and specifically to how often risk assessments stop at the parties companies interact with directly.
The commonly overlooked ones came up by name. Foreign factories. Foreign ports of lading. The transportation leg from the factory to the port. Subcontracted cargo handling facilities. Highway carriers sourced off a load board, where a lot of companies quietly assume their responsibility ends the moment cargo gets assigned. Consolidators and forwarders have their own version of this, because the overseas agents and warehouses touching that freight are often invisible in the mapping.
Useful mapping captures partner name and address, manufacturing location, container stuffing location, transportation provider, routing, cargo handling points, port of lading, and who holds security responsibility at each step. Building that isn't a compliance department project. It takes purchasing, logistics, security, quality control, IT, your broker, and your forwarder in the same conversation, because those groups usually hold conflicting pieces of the same picture.
While you're in there, look at your business partner questionnaires. One broad questionnaire sent to every entity type produces thin answers. Questionnaires tailored to what each partner actually does produce answers you can use. Run them annually, and again whenever something material changes or risk goes up. Then have a company officer review and sign off on the process.
Executive Order 14411 came up across multiple sessions. The framing CBP used was that importing is a privilege and the trade system works as an extension of the physical border.
The practical effect for partners is more scrutiny on importers of record identity and legitimacy. CBP is asking more questions about who's behind an IOR, and ACE functionality is being used to find inactive IORs and take them out of circulation. CBP has since published a notice on the accuracy of importer of record data. If your CBP Form 5106 and related records aren't complete, accurate, and current, fix that before someone else notices.
One line from those sessions is worth repeating to your leadership team verbatim. Responsibility cannot continually be shifted among importers, brokers, forwarders, carriers, and manufacturers. Everyone in that chain has been pointing at the party upstream for years. CBP signaled it intends to hold IORs and their business partners accountable, with due process, but with actual consequences.
Brokers got a direct version of the same message. CBP described compliant brokers as force multipliers and made clear it expects them to know their customers, exercise responsible supervision and control, and question information that looks wrong. A broker acting as a pure data transmitter when the facts suggest undervaluation, false origin, or identity misuse is a problem CBP is prepared to move on quickly, including through filer code suspensions.
CBP outlined enhancements anticipated for 2027: digitizing CTPAT processes including validations, sharper focus on high-risk areas, and expanded use of AI and automated tools.
Read that through a compliance lens and it means something specific. Digital validation is easier for partners whose evidence is already organized, named, and associated in the portal. It's harder for partners whose evidence lives in a shared drive, three inboxes, and one person's memory, which is exactly the problem a CTPAT system of record solves. Better targeting means the companies with visible gaps get looked at more closely, and the companies that are clearly in order get looked at less. The gap between those two groups is about to widen.
CBP was also clear that AI assists while humans stay responsible for final decisions. That's the right posture, and it's the one we'd hold internally too. Use technology to find the gaps. Keep a person accountable for closing them.
It's easy to read all of this as more work landing on a team that's already stretched. Some of it is. But there's a side of this that doesn't get said enough at compliance conferences.
CBP made the economic security argument repeatedly at this Summit. Legitimate companies can't compete fairly against forced labor, fraudulent origin claims, and undervalued entries. Every enforcement action against that behavior is a point in your favor. Strong enforcement makes trade easier for compliant companies, and that was stated plainly.
Being genuinely audit-ready is a commercial asset. It shortens validations. It survives customer due diligence questionnaires without a scramble. It's the reason a large shipper picks you over a competitor who can't produce the same paper. Trusted trade status is worth something precisely because it's hard to hold.
If your team needs a short list, start here. Audit your Evidence of Implementation against your Security Profile and find the criteria where you have nothing current. Verify your 5106, IOR data, and portal contacts. Extend your supply chain map past the parties you talk to directly, especially foreign ports of lading and any carrier sourced off a load board. Put a calendar reminder on the day your 90-day annual review window opens.
None of that requires waiting for a final rule. That's the point CBP was making.
Not sure where you stand? The CTPAT maturity assessment takes about ten minutes and shows you which of the seven domains are thin.
If you want a second set of eyes on where your evidence is weak, that's the work we do. We sit inside this every day with roughly 500 CTPAT certified operators, and we can usually tell you in one conversation which criteria are going to give you trouble. Talk to a specialist.
The companies that move now will spend 2027 answering questions. The ones that wait will spend it building evidence under a deadline.
When was the 2026 Trade and Cargo Security Summit?
CBP held the 2026 Trade and Cargo Security Summit September 8-10, 2026 at the Hyatt Regency Dallas. It was postponed from its original April 28-30 dates. Attendance was available in person and by virtual webcast.
What did CBP say about Evidence of Implementation at the Summit?
CBP emphasized the gap between what a Security Profile claims and what a partner can prove. Blank forms and templates do not count. Evidence must be routine operational records, legible, current, dated, signed where required, and associated with the applicable Minimum Security Criterion in the CTPAT Portal.
How does Executive Order 14411 affect CTPAT partners?
It drives more scrutiny on importer of record identity and legitimacy. CBP is using ACE to identify inactive IORs, is asking more questions about who stands behind an IOR, and has signaled it will hold IORs and their business partners accountable rather than allowing responsibility to shift along the chain. Complete and current CBP Form 5106 data is the immediate action item.
What is changing for CTPAT in 2027?
CBP outlined digitized CTPAT processes including validations, sharper targeting of high-risk areas, and expanded use of AI and automated tools. Humans remain responsible for final decisions. Partners whose evidence is already organized and associated in the portal will find digital validation easier than partners whose evidence is scattered.