If you have a CTPAT validation coming up, now’s the time to take a close look at your Security Profile!
Even if it’s already approved in the CTPAT Portal, don’t assume you’re in the clear. The validation is CBP’s way of confirming that what’s in your Profile matches what’s actually happening in your operations. Just because it looks good in the Portal, doesn’t mean issues won’t come up during the validation.
Here are a few key areas to focus on:
- Make sure the responses and EOI are up-to-date.
- Policies and procedures don’t necessarily need to change every year, but they should show that they’ve been reviewed. Adding “last reviewed” dates to your Evidence of Implementation (EOI) is a simple way to demonstrate ongoing oversight.
- Make sure the Security Profile accurately reflects your company’s operations.
- One of the biggest mistakes that companies make is including policies and procedures in the Security Profile that aren’t actually in practice. Remember: the CTPAT Minimum Security Criteria (MSC) are not meant to be a prescriptive list of procedures. Often company’s procedures meet the MSC, and the Profile is to explain how.
- Coordinate with relevant departments.
- Connect with key department personnel on relevant sections of the Security Profile. A few coordination meetings or working sessions helps ensure accuracy and that the right people are prepared to participate during the validation.
- Review previous validation reports.
- If this is a revalidation, revisit your previous CTPAT validation report and any corrective actions. CBP often uses this as an opportunity to check in on how those were addressed. But keep in mind, that’s just one part of the revalidation!
Taking the time to do a thorough review now can help prevent issues later and make your CTPAT validation go much more smoothly.
This is the third post in our series on Preparing for CTPAT Validations in 2026. Check out previous posts about validation scheduling & communication with your SCSS and getting your team ready for the validation.



