The Government Accountability Office (GAO) recently released a report analyzing U.S. Customs and Border Protection (CBP) data on security incidents in the cargo supply chain and the extent to which CTPAT-certified companies were involved. The report included recommendations for CBP to improve the completeness, consistency, and accuracy of CTPAT program data, as well as to update guidance for determining enforcement actions involving CTPAT members.
One key takeaway: according to CBP data, between FY2020 and FY2024, only 1% of security incidents involved CTPAT members. This reinforces the objective of the program – to enable CBP to classify CTPAT members as lower-risk entities.
However, lower risk does not mean zero risks. No supply chain can eliminate all threats entirely so security incident involving CTPAT members do occur. What distinguishes strong programs from weak ones is whether they are identified, managed, documented, and reported before the cargo arrives at a US port of entry.
Part of the aim of the CTPAT Program is to enable private sector partners to proactively detect and respond to supply chain threats. In many cases, CTPAT members themselves identify potential violations or security breaches.
To help clarify expectations, we asked our CTPAT experts what members should know about responding to and reporting security incidents.
1. What are common security incidents that CTPAT members may encounter in their supply chains?
Members may encounter various types of security incidents; however, some of the most common include missing seals, seal discrepancies, and pilferage. Regardless of the type of incident, companies are expected to exercise due diligence by conducting a thorough investigation to determine the root cause.
In cases involving missing seals or seal discrepancies on arriving containers, any unexplained irregularities must be promptly reported to CBP at the port of entry, as well as to CTPAT. Incidents of pilferage should be investigated in coordination with all relevant parties to identify the breakdown in security. A comprehensive Corrective Action Plan (CAP) should then be developed and implemented to address the root cause and prevent recurrence.
2. What steps should a CTPAT member take after experiencing a security incident or breach?
If a CTPAT member experiences a security incident or breach, the incident must be reported promptly to their assigned Supply Chain Security Specialist (SCSS). The member should be prepared to provide detailed information and respond to initial inquiries regarding the incident.
The member is expected to initiate an immediate internal investigation to gather all relevant facts, determine the root cause of the breakdown, and assess any associated responsibility. Existing internal procedures and security policies should be thoroughly reviewed to confirm compliance and to identify any gaps or deficiencies that may have contributed to the incident. Following the investigation, a comprehensive Corrective Action Plan (CAP) should be developed. The CAP should clearly outline identified weaknesses, define corrective measures, and establish preventive actions designed to mitigate risk and reduce the likelihood of future incidents.
3. What information should CTPAT members provide to their SCSS and when?
The information to report will vary depending on the nature of the incident and should be provided in a timely manner upon request. Members should be prepared to address the five fundamental questions: Who, What, When, Where, and Why. While the “Why” may not be immediately known when initially reported, additional details may emerge as the investigation progresses. Follow-up inquiries will likely focus on newly discovered information that helps determine the underlying cause.
CTPAT members should be prepared to provide comprehensive information not only about their own operations, but also about the operations of any business partners involved in the incident.
4. Can self-reporting to their SCSS impact the company’s CTPAT status?
Failure to report a security incident can have a significant impact on a company’s CTPAT status. While self-reporting does not preclude CTPAT from taking appropriate action, it demonstrates transparency and a commitment to supply chain security. The nature and severity of the incident, along with the findings of the subsequent investigation, will be key factors in determining the company’s status moving forward; however, timely reporting will be viewed favorably. When uncertainty exists, it is always advisable to report the incident rather than risk non-disclosure.
Incidents that must be reported include, but are not limited to, unexplained missing, tampered, or discrepant seals; unauthorized modifications to conveyances; the discovery of contraband or evidence of smuggling; unauthorized entry into conveyances; and the presence of stowaways.
5. What happens if CBP discovers a security incident (i.e. there’s a seizure) and can this impact the company’s CTPAT status?
Yes, if CBP makes a seizure on a CTPAT member’s shipment, it may impact the company’s CTPAT status. CTPAT will conduct a comprehensive review of the incident to assess the circumstances and determine any level of culpability. Accordingly, the member must be prepared to undertake a thorough internal investigation and provide detailed findings and supporting documentation to CTPAT.
In evaluating the matter and determining whether action is warranted, CTPAT will consider several factors, including whether the incident was self-reported, the nature and severity of the incident, and whether the CTPAT Minimum-Security Criteria (MSC) were effectively implemented and followed. Additional considerations may include evidence of company knowledge or involvement versus the actions of a rogue employee, as well as the company’s level of cooperation and willingness to provide relevant information and implement an appropriate CAP.
6. How can CTPAT members better prevent security incidents from occurring?
One of the most effective ways a CTPAT member can mitigate security incidents is by implementing a robust business partner screening process. Comprehensive due diligence should be conducted to ensure partners are reputable, financially sound, and aligned with supply chain security expectations. This may include background checks, security assessments conducted through questionnaires, contractual requirements, and on-site visits to confirm that appropriate security measures are in place and consistently followed.
In addition, strong internal audit practices are essential. Members should periodically review and assess their own policies and procedures to ensure they remain effective, relevant, and fully implemented. Employees must be clearly informed of their security responsibilities and held accountable for compliance to minimize vulnerabilities. Any identified deficiencies should be promptly addressed through corrective measures to strengthen controls and prevent future incidents.
Read our summary of the GAO report here, including key takeaways and implications for the CTPAT Program and participants.



