OOaegis UK
All insights

C-TPAT's 11 Minimum Security Criteria: A Plain-English Breakdown

Where AEO organises its requirements around five broad criteria, C-TPAT's Minimum Security Criteria (MSC) are organised into eleven more granular, entirely security-focused categories. Here's what each one actually covers.

The eleven categories

  1. Business Partner Requirements: screening and qualifying your own supply chain partners.
  2. Cybersecurity: protecting the IT systems that manage cargo and customs data.
  3. Conveyance and Instruments of International Traffic Security: securing the vehicles, containers, and equipment that move goods.
  4. Seal Security: high-security seals, applied and verified correctly, every time.
  5. Procedural Security: controls over documentation, manifesting, and cargo discrepancy reporting.
  6. Agricultural Security: preventing pest contamination in containers and conveyances.
  7. Physical Security: fencing, lighting, locking devices, and facility structure.
  8. Physical Access Controls: identifying and challenging employees, visitors, and vehicles.
  9. Personnel Security: screening, vetting, and offboarding staff.
  10. Education, Training and Awareness: keeping staff alert to security and terrorism-related risks.
  11. Risk Assessment: a documented, regularly reviewed assessment of your international supply chain.

Proportionality by partner type

CBP does not expect identical evidence from every applicant. A highway carrier is assessed heavily on conveyance security, seal security, and personnel security; an importer is assessed across all eleven categories, including the security posture of its own business partners. The emphasis shifts by role, but every applicant is expected to have a documented answer for each of the eleven.

How this maps to AEO's five criteria

If you're already familiar with AEO, the mapping is instructive, and reveals a structural difference worth knowing about before you assume the two are equivalent:

AEO criterionClosest C-TPAT MSC categories
Compliance recordNo direct MSC equivalent; assessed separately during CBP's risk review
Accounting and logistics systemsProcedural Security
Financial solvencyNot part of the MSC; C-TPAT does not assess financial solvency at all
Practical standards of competenceEducation, Training and Awareness
Security and safety (AEO(S))Physical Security, Access Controls, Personnel Security, Cybersecurity, Seal Security, Conveyance Security

Notice what's missing: C-TPAT has no equivalent to AEO(C)'s customs-simplification tier, and doesn't assess financial solvency at all. Every C-TPAT applicant is, in effect, being assessed on something closer to AEO(S) alone; just broken into more, and more granular, categories. That's a genuinely different shape of assessment, not just a different name for the same one.

Go further

This is covered in full, with evidence templates, worked examples, and a knowledge check, in the C-TPAT Certified Practitioner Programme, now discounted to £450.