GAO Report on CTPAT: Key Findings and Implications for the Program and Participants

According to CBP data, CTPAT participants were involved in 1% of the total security incidents in the cargo supply chain from Fiscal Year 2020 through 2024.

  • 480 CTPAT participants were involved in  approximately 2,200 security incidents.
  • Of the 480 participants involved:
    • 160 were involved in multiple incidents
    • 166 were suspended or removed
    • 59% were licensed U.S. customs brokers or highway carriers
  • Of the 2,200 security incidents:
    • Air carriers accounted for 35%
    • Sea carriers accounted for 26%
  • The most common types of incidents involving CTPAT participants were:
    • Drug-related: 49%
    • “Other” (ammunition, weapons parts, consumer safety violations): 20%
    • Intellectual property rights violations: 16%

However, the GAO identified data limitations, inconsistent enforcement practices, outdated guidance, and statutory compliance gaps in the CTPAT program.

  •  CBP does not collect complete data on security incidents involving program participants, such as on incidents self-reported by participants.
  • CBP investigations and enforcement actions related to the security incidents were not consistent.
  • CBP is not fully meeting the statutory requirements related to the CTPAT program set out in the Security and Accountability for Every Port (SAFE) Port Act of 2006, specifically regarding annual Minimum Security Criteria (MSC) reviews, annual workload planning, and development of 5-year strategic plans.

The GAO made six recommendations to CBP to address these findings:

  1. Improve completeness and consistency of incident data.
  2. Update operating guidance for investigations and enforcement using risk-based decision criteria.
  3. Improve accuracy of enforcement data in the CTPAT Portal.
  4. Develop a formal mechanism for annual MSC review.
  5. Create documented annual work plans aligned with projected workloads.
  6. Develop a 5-year strategic plan with measurable outcomes.

On one hand, CTPAT participants account for a very small percentage of total supply chain security incidents, supporting the program’s risk-based certification model. However, there clearly remain areas for improvement, and by strengthening data governance, clarifying enforcement standards, and modernizing program management, CBP will ensure its supply chain risk management remains effective while also increasing consistency and transparency for CTPAT participants.

Additionally, having more information about the security incidents among CTPAT participants can help members identify and monitor risks for current supply chain threats. The data presented in the report, while helpful, may require more detailed information such as:

  • Drug-related incidents: Although 49% of the total number of security incidents reported were drug related and could be alarming, this may not paint a total picture of what was reported. It would be valuable to know what was seized. As  the report notes, between FY23 and FY24, the CTPAT program began capturing data on security incidents involving fentanyl precursor chemicals and seizures with small trademark violations, leading to the increase in recorded security incidents.
  • “Involved” versus “associated”: A CTPAT participant being “involved” may not necessarily mean direct knowledge of an incident and that the company was implicated in the seizure. The company may have just been a part of the shipping process.
1. Stronger documentation and data controls
  • CBP is expected to improve data completeness and consistency in the CTPAT Portal. This likely means increased follow-up on incomplete or inconsistent data moving forward and/or reconciliation of historical data. CTPAT participants should make sure they have strong documentation protocols in place to help ensure the data CTPAT has is complete and consistent with company records.
2. Updated investigation and enforcement guidance
3. More frequent updates to the MSC and/or the program as a whole
  • The MSC updated implemented in 2020 was the first major change to the MSC since the original criteria were established in 2001. While significant changes are unlikely in the immediate future, annual MSC reviews and more detailed strategic plans could mean e more frequent changes to the MSC. Additionally, CBP is already taking steps to make broader updates to the program, such as piloting the participation of additional 3PL entities, which are currently not eligible to join the program.
  • CTPAT participants should make sure they are informed of upcoming changes to the program. A basic step is to ensure the Points of Contact (POCs) for your company listed in your CTPAT Portal are up-to-date and have elected to receive email notifications from the CTPAT Portal, so that the appropriate personnel are receiving notifications from the program.

The report, titled Supply Chain Security: Actions Needed to Improve CBP Management of the Customs Trade Partnership Against Terrorism Program, was commissioned as part of the CTPAT Pilot Act of 2023 and was developed from October 2024 to January 2026. It examines:

  1. What CBP data shows about the number and types of security incidents that occurred in the cargo supply chain from fiscal years 2020 through 2024 and the extent to which CTPAT participants were involved.
  2. What CBP data shows about program actions taken to suspend, remove, or maintain the status of those CTPAT participants, if any, involved in security incidents during this timeframe.
  3. The extent to which CBP meets certain statutory requirements in the SAFE Port Act in its management of the CTPAT program.

For this report, GAO follows CBP’s definition of “security incident”, which may include the introduction of restricted, prohibited, or otherwise harmful cargo or individuals into the supply chain, which are in violation of laws and regulations enforced by CBP, or the laws and regulations enforced by other domestic or foreign government agencies.

The report finds that, from FY20 – FY24, there were a total of 215,000 security incidents in the cargo supply chain. Of these incidents, 81% involved express consignment carriers and 10% involved commercial air carriers.

Most of these security incidents involved counterfeit goods and drugs, with counterfeit goods accounting for 39% of security incidents and drugs accounting for 27%.

The report found that, of the total security incidents in the cargo supply chain, 1% involved CTPAT participants. Of the approximately 11,000 CTPAT program participants, 480 (4%) were involved in an estimated 2,200 security incidents between FY20-FY24.

  • 320 were involved in one security incident; the other 160 participants were involved in more than one security incident during this timeframe
  • Licensed U.S. customs brokers and highway carriers accounted for the largest number of participants involved, totalling 59%.
  • Despite making up the lowest proportion of CTPAT participants, air carriers and sea carriers were involved in the highest proportion of incidents, with air carriers involved in 35% of security incidents linked to CTPAT participants and sea carriers involved in 26%.
  • The most common type of security incident involving CTPAT participants were:
    • Drug-related: 49%
    • “Other” (ammunition, weapons parts, consumer safety violations): 20%
    • Intellectual property rights vioaltions:16%
  • Of the 480 participants involved in incidents, 166 (35%) were suspended or removed from the program.

The GAO identified gaps and inconsistencies in the data quality, enforcement actions, and statutory compliance in the CTPAT program.

Data Quality

The report found potential issues in CBP data around security incidents involving CTPAT participants:

  • inconsistent or incomplete data
  • only included security incidents identified by CTPAT program personnel located at the headquarters office, with no information from field offices or self-reported from participants
  • the method of recording security incidents creates a risk of duplicate entries depending on how the information was entered

Enforcement

While CBP guidance states that personnel are to conduct post-incident analyses for all security incidents involving CTPAT participants, CBP officials explained to the GAO that, in practice, CTPAT personnel determine whether a post-incident analysis is necessary after reviewing additional information. This is why post-incident analyses were conducted on less than 2% of the 2,200 incidents involving CTPAT participants.

In April 2025, CBP began internal discussions to update the outdated guidance to reflect the current, discretionary approach.

Statutory Compliance

Beyond incident management, GAO examined whether CBP is meeting statutory requirements under the SAFE Port Act. It found gaps in:

  • Mininmum Security Criteria (MSC) Reviews: The SAFE Port Act requires annual reviews and, if necessary, updates to the MSC, but an annual review has not been conducted since 2020.
  • Annual Workload Planning: CBP is required to develop annual workload projections aligned with available resources. While plans exist for validation activities, they do not reflect the program’s full workload, particularly incident-related oversight.
  • Five-Year Stratic Plan: While the CTPAT Program was included in the CBP Office of Field Operations’ strategic plan, the SAFE Port Act requires a program-specific  plan with outcome-based goals and performance measures.

GAO issued six recommendations to strengthen oversight, data integrity, enforcement consistency, and strategic planning. DHS concurred with the recommendations and have set target completion dates between February 2026 and January 2027

Recommendation 1: Develop a plan and assign responsibility for overseeing the completeness and consistency of its security incident data involving CTPAT participants.

DHS Response: CTPAT’s Technology & Innovation Branch will develop a plan and assign responsibility. Estimated complation date: February 27, 2026.

Recommendation 2: Update the operating guidance for investigating and taking enforcement action against CTPAT participants involved in security incidents.

DHS Response: CTPAT’s Field & Operational Support Branch will update operating guidance. Est. completion date: February 27, 2026.

Recommendation 3: Improve the completeness and accuracy of the CTPAT program’s enforcement actions data in the CTPAT Portal.

DHS Response: Updates were created in FY25 to the CTPAT Portal to improve accuracy and assist with eliminating potential duplicate entries. CBP will ensure the updates were developed and deployed, and provide training for complete, accurate, and consistent data entry. Est. completion date: February 27, 2026.

Recommendation 4: Develop a formal mechanism to ensure it annually reviews and updates as necessary the CTPAT program’s minimum security requirements.

DHS Response: CTPAT will develop a formal mechanism to perform annual reviews of the MSC. Est. completion date: February 27, 2026.

Recommendation 5: Develop an annual plan for each fiscal year to match available resources to the projected workload of the CTPAT program.

DHS Response: CBP will develop a comprehensive annual work plan that includes not only validation work, but also other activities under the CTPAT program. Est. completion date: January 29, 2027.

Recommendation 6: Develop a 5-year plan with outcome-based goals and performance measures of the CTPAT program.

DHS Response: CTPAT’s Field & Operational Support Branch is currently in the process of developing a 5-year strategic plan, which will modernize benefits and explore partnership tiers, allowing CBP to better manage risk by labeling Partnership companies in tiers based on the likelihood of risk of contraband. Est. completion date: February 27, 2026.

This website uses cookies to ensure you get the best experience on our website.