Customs-Trade Partnership Against Terrorism (CTPAT) revalidation is tougher than it used to be. Since the updated Minimum Security Criteria (MSC) took effect, US Customs and Border Protection (CBP) has returned to routine reviews with a sharper eye on how organizations provide evidence of supply chain security. Those who earned Tier II or Tier III status years ago now find revalidation requires more visibility, documentation, and proof of continuous improvement.
The impact spans security, supply chain, trade compliance, responsible sourcing, procurement, and operations teams. Across recent validations, CBP is pressing on three priorities.
1. Greater emphasis on supply chain mapping
CBP is prioritizing supply chain mapping, with a focus on the final stages before cargo enters the United States (US). Importers must now identify every party handling that last movement before freight is loaded to enter the US, not just primary service providers. For many importers, that means mapping transportation and logistics partners in greater detail than before.
To get ahead of it:
- Revisit Automated Commercial Environment (ACE) data to identify who handles the final movement into the US.
- Confirm that transportation partners are either CTPAT certified or meet CTPAT requirements.
- Collaborate with logistics, supply chain, and inbound transportation teams to close the gaps, especially in transportation from factory to port.
Tony Pelli, Global Practice Director, Security & Resilience, BSI Consulting states that, "It's always worth it to go into slightly more detail than you think you may need to for that supply chain mapping piece."
2. Increased scrutiny of transportation at origin
Importers can no longer focus due diligence solely on direct suppliers and tier-one carriers. CBP is scrutinizing origin transport from the overseas factory to the port, even when the supplier handles local logistics. In major export hubs like Vietnam, Supply Chain Security Specialists look for detailed information about local trucking providers, including how they were selected, monitored, and managed.
In recent revalidations, organizations have faced detailed questions about:
- How overseas transportation providers are selected and vetted.
- The oversight factories have over the local trucking companies they use.
- Whether cargo is tracked and monitored from origin to port.
- If shipments run directly to the port or make intermediate stops.
To prepare, engage suppliers and manufacturing partners on how they manage transportation risk before cargo reaches the port. Confirm that origin providers follow baseline security guidelines to mitigate risk long before a shipment reaches the US border. Tony Pelli emphasizes that this "has come up in multiple different revalidations with a much higher level of detail expected than in previous years."
3. CBP expects evidence of continuous improvement
Organizations that joined CTPAT 10 to 15 years ago may hold strong security foundations, but CBP wants to understand how security programs have evolved since the last validation and whether organizations are investing in stronger practices over time.
Tier III organizations should be prepared to demonstrate recent progress across their programs, including:
- Improvements made over the past year.
- More detailed supply chain mapping.
- A more sophisticated risk assessment.
- Stronger supplier oversight or a more consistent seal integrity program rolled out across the business.
Point to tangible improvements rather than routine maintenance. Ongoing governance makes a strong case. Quarterly steering committees, regular stakeholder reviews, internal working groups, and mandatory security training all show that CTPAT is embedded in daily operations.
For Tier II organizations, emphasis shifts to proof of implementation. Work through each of your CTPAT profile requirements, ensuring every control is backed by records, training logs, and documented supplier engagement. Regular internal audits before your next review prove controls are actively managed. As Tony Pelli puts it, "You say you have this process in place. What logs do you have that can show that?"
Revalidation now rewards evolution. Map the deeper legs of your supply chain, keep clear records for every control, and treat CTPAT as the year-round effort CBP now expects. The organizations that stay certified are the ones treating security as a living program, not a box to check before an audit.