C-TPAT's 11 Minimum Security Criteria: A Plain-English Breakdown
Where AEO organises its requirements around five broad criteria, C-TPAT's Minimum Security Criteria (MSC) are organised into eleven more granular, entirely security-focused categories. Here's what each one actually covers.
The eleven categories
- Business Partner Requirements: screening and qualifying your own supply chain partners.
- Cybersecurity: protecting the IT systems that manage cargo and customs data.
- Conveyance and Instruments of International Traffic Security: securing the vehicles, containers, and equipment that move goods.
- Seal Security: high-security seals, applied and verified correctly, every time.
- Procedural Security: controls over documentation, manifesting, and cargo discrepancy reporting.
- Agricultural Security: preventing pest contamination in containers and conveyances.
- Physical Security: fencing, lighting, locking devices, and facility structure.
- Physical Access Controls: identifying and challenging employees, visitors, and vehicles.
- Personnel Security: screening, vetting, and offboarding staff.
- Education, Training and Awareness: keeping staff alert to security and terrorism-related risks.
- Risk Assessment: a documented, regularly reviewed assessment of your international supply chain.
Proportionality by partner type
CBP does not expect identical evidence from every applicant. A highway carrier is assessed heavily on conveyance security, seal security, and personnel security; an importer is assessed across all eleven categories, including the security posture of its own business partners. The emphasis shifts by role, but every applicant is expected to have a documented answer for each of the eleven.
How this maps to AEO's five criteria
If you're already familiar with AEO, the mapping is instructive, and reveals a structural difference worth knowing about before you assume the two are equivalent:
| AEO criterion | Closest C-TPAT MSC categories |
|---|---|
| Compliance record | No direct MSC equivalent; assessed separately during CBP's risk review |
| Accounting and logistics systems | Procedural Security |
| Financial solvency | Not part of the MSC; C-TPAT does not assess financial solvency at all |
| Practical standards of competence | Education, Training and Awareness |
| Security and safety (AEO(S)) | Physical Security, Access Controls, Personnel Security, Cybersecurity, Seal Security, Conveyance Security |
Notice what's missing: C-TPAT has no equivalent to AEO(C)'s customs-simplification tier, and doesn't assess financial solvency at all. Every C-TPAT applicant is, in effect, being assessed on something closer to AEO(S) alone; just broken into more, and more granular, categories. That's a genuinely different shape of assessment, not just a different name for the same one.
Go further
This is covered in full, with evidence templates, worked examples, and a knowledge check, in the C-TPAT Certified Practitioner Programme, now discounted to £450.