Third-Party ISO Certification Body in UK, Europe, UAE, MENA & Globally. (MENA HO: UAE)
SCS KNOWLEDGE CENTRE

ISO 18788 Certification in India | Get Certified with SCS

Get ISO 18788 certification in India with SCS. Learn requirements, PSARA, ICoCA, cost, process, Indian industries, locations and customer requirements.

  1. Home
  2. Knowledge Centre
  3. ISO 18788 Certification in India | Get Certified with SCS

ISO 18788 Certification in India – Requirements, Cost, Process & ICoCA | Get Certified with SCS

ISO 18788 Certification in India – Requirements, Cost, Process & ICoCA | Get Certified with SCS
ISO 18788 certification in India helps security companies establish a structured Security Operations Management System while addressing customer, tender, PSARA and applicable Indian requirements.

ISO 18788 Certification in India – Requirements, Cost, Process & ICoCA | Get Certified with SCS

http://www.scscertification.com/contactus.php

ISO 18788 certification in India provides a structured management-system framework for organizations that conduct or contract security operations. It can be particularly relevant to private security agencies, security contractors, industrial security providers, logistics security companies, infrastructure projects and organizations whose customers require an internationally recognized security-operations management system.

ISO 18788:2015 is the published standard for a Security Operations Management System (SOMS). It provides a framework for establishing, implementing, operating, monitoring, reviewing, maintaining and improving security operations.

For an Indian organization, however, ISO 18788 should not be treated as a replacement for Indian statutory requirements. A security company may need to manage several different requirements at the same time:

  • Indian legal and regulatory requirements
  • PSARA requirements where applicable
  • State and Union Territory requirements
  • Customer and contractual requirements
  • Tender and procurement requirements
  • ISO 18788 requirements
  • International customer requirements
  • ICoCA requirements where specifically applicable

The Ministry of Home Affairs lists the Private Security Agencies (Regulation) Act, 2005, the Private Security Agencies (Private Security to Cash Transportation Activities) Rules, 2018 and the Private Security Agencies Central Model Rules, 2020. The 2020 Model Rules superseded the earlier 2006 Model Rules.

For Indian security companies, the most important commercial question is therefore not simply "How do I get ISO 18788?" but:

What certification scope, legal requirements, customer requirements, tender conditions and certification-body requirements must my organization satisfy?

What Is ISO 18788 Certification in India?

ISO 18788 certification is an independent assessment of an organization's defined Security Operations Management System against the applicable requirements of ISO 18788.

The certification scope should correspond to the organization's actual activities.

Depending on the organization, this may include:

  • Manned guarding
  • Security supervision
  • Access control
  • Security patrols
  • Site protection
  • Security monitoring
  • Asset protection
  • Security escort services
  • Industrial security
  • Logistics security
  • Infrastructure security
  • Event security
  • Contract security management

A security company should avoid using a generic certification scope that does not accurately represent its activities.

The scope should consider the services being provided, locations covered, operational personnel, customers, contractual obligations, security risks and applicable requirements.

ISO 18788:2015 and Current Standard Status

The applicable published standard is ISO 18788:2015 – Management system for private security operations – Requirements with guidance for use.

Organizations preparing for certification should use the applicable current edition and amendments rather than describing ISO 18788 as an incorrectly numbered future edition.

The certification scope should also take account of applicable current requirements and the organization's actual operating environment.

ISO 18788 Certification Is Not a Replacement for Indian Law

This distinction is particularly important for Indian security companies.

ISO 18788 is an international management-system standard.

Indian laws and regulations establish statutory obligations.

Customer contracts establish contractual obligations.

Tender documents establish procurement requirements.

ICoCA establishes its own certification-programme requirements.

These may interact, but they are not interchangeable.

Therefore:

PSARA is not ISO 18788.

ISO 18788 is not a PSARA licence.

ISO 18788 certification is not automatically ICoCA certification.

An ISO 18788 certificate does not automatically satisfy every customer or tender requirement.

This distinction should be established before certification begins.

ISO 18788 and PSARA Requirements in India

The Private Security Agencies (Regulation) Act, 2005 is an important part of India's regulatory framework for private security agencies.

The Ministry of Home Affairs lists the PSARA Act together with the Private Security Agencies Central Model Rules and the specific rules relating to private security to cash transportation activities.

A security organization should determine which statutory requirements apply to its activities and operating jurisdictions.

ISO 18788 can then be used as the management-system framework for managing security operations.

The relationship can be understood as:

PSARA and applicable law: statutory requirements.

ISO 18788: Security Operations Management System requirements.

Customer requirements: contractual expectations.

Tender requirements: procurement conditions.

ICoCA: additional international certification requirements where applicable.

Private Security Agencies Central Model Rules, 2020

The Private Security Agencies Central Model Rules, 2020 were notified by the Ministry of Home Affairs in supersession of the earlier 2006 Model Rules. The MHA has stated that State Governments and Union Territory Administrations are to adopt the new Rules through their respective notifications.

This is particularly relevant for security companies operating in several Indian States.

A multi-State organization should identify the requirements applicable to each jurisdiction in which it operates.

Depending on the business, the compliance framework may need to address areas such as:

  • Licensing
  • Security personnel
  • Training
  • Verification
  • Deployment
  • Supervisory arrangements
  • Operational controls
  • Records
  • Customer requirements
  • Applicable State or UT requirements

ISO 18788 and State & Union Territory Requirements

A security organization operating only in one State may have a different compliance profile from a security company providing services throughout India.

Organizations should identify requirements relevant to their actual operating locations.

This is particularly important for companies with operations across:

  • Tamil Nadu
  • Karnataka
  • Kerala
  • Maharashtra
  • Telangana
  • Andhra Pradesh
  • Goa
  • Delhi
  • Haryana
  • Gujarat
  • Rajasthan
  • Uttar Pradesh
  • West Bengal
  • Other States and Union Territories

The ISO 18788 management system should provide a controlled method for identifying and managing applicable requirements.

ISO 18788 Requirements for Indian Security Companies

An effective SOMS should be connected to the organization's actual security operations rather than existing only as a collection of documents.

Important implementation areas include:

Security Operations Planning

Security activities should be planned according to:

  • Customer requirements
  • Site conditions
  • Security risks
  • Personnel requirements
  • Contractual obligations
  • Applicable legal requirements
  • Operational objectives

Security Risk Assessment

Risks may include:

  • Unauthorized access
  • Theft
  • Intrusion
  • Violence
  • Property damage
  • Personnel misconduct
  • Security-control failure
  • Communication failure
  • Emergency situations
  • Inadequate staffing
  • Contractor risks
  • Client-site risks
  • Operational disruption

Controls should be proportionate to the organization's activities and responsibilities.

Legal and Regulatory Compliance

The organization should identify applicable legal and regulatory requirements and establish processes for keeping that information current.

For an Indian private security organization, this can include:

  • PSARA requirements
  • Central Model Rules
  • Applicable State or UT requirements
  • Sector-specific requirements
  • Customer requirements
  • Contract requirements
  • Tender conditions

Personnel Competence

Security personnel should have competence appropriate to their assigned duties.

Evidence may include:

  • Qualification records
  • Training records
  • Site induction
  • Role-specific training
  • Supervisor competence
  • Refresher training
  • Performance evaluation

Incident Management

The organization should have an appropriate method for handling security incidents.

Depending on the scope, this can include:

  1. Incident identification
  2. Immediate response
  3. Escalation
  4. Customer communication
  5. Investigation
  6. Evidence and records
  7. Corrective action
  8. Follow-up
  9. Management review

Emergency Preparedness

Emergency arrangements should correspond to the organization's actual security responsibilities.

Potential situations include:

  • Fire
  • Violence
  • Intrusion
  • Medical emergency
  • Natural disaster
  • Industrial emergency
  • Security-system failure
  • Communication failure
  • Evacuation

ISO 18788 and Customer Requirements in India

For many Indian security companies, ISO 18788 certification may arise from a customer requirement rather than a general statutory requirement.

A customer may request:

  • ISO 18788 certification
  • Accredited certification
  • Internationally recognized certification
  • A particular certification scope
  • Certification covering specific sites
  • Certification before contract award
  • ICoCA certification
  • A certification body meeting specified criteria

Before starting certification, the security company should obtain the customer's actual requirement in writing wherever possible.

Questions to Ask the Customer

  1. Is ISO 18788 mandatory?
  2. What activities must the certificate cover?
  3. Which sites must be included?
  4. Does the customer require accredited certification?
  5. Is a particular Certification Body specified?
  6. Is ICoCA certification required?
  7. Is there a tender closing date?
  8. Must certification exist before contract award?
  9. Are subcontractors included?
  10. Are additional security qualifications required?

This prevents the organization from obtaining a certificate that does not satisfy the customer's commercial requirement.

ISO 18788 and Indian Security Tenders

ISO 18788 can become commercially relevant when a tender or procurement process requests a security-management certification.

However, a certificate should not automatically be assumed to satisfy every tender.

The organization should compare the tender wording against:

  • Required standard
  • Required scope
  • Accreditation requirement
  • Certificate validity
  • Sites covered
  • Security services covered
  • Personnel requirements
  • Experience requirements
  • Regulatory licences
  • Insurance
  • Reporting requirements
  • Training requirements

Certification can support supplier qualification where it is requested or accepted, but tender award depends on the complete tender evaluation.

ISO 18788 and ICoCA Requirements

ICoCA is particularly important for security companies targeting international customers.

ICoCA identifies ISO 18788 as one of the standards recognized within its certification framework. ICoCA also specifies requirements concerning Certification Bodies accepted within its certification programme.

Therefore, an Indian security company should distinguish between:

ISO 18788 certification

and

ICoCA certification.

Obtaining ISO 18788 certification does not automatically mean that the company is ICoCA certified.

Where a customer specifically requests ICoCA certification, the organization should verify the current ICoCA requirements and the acceptance status of the proposed Certification Body.

ICoCA Certification Body Requirement for Indian Security Companies

The Certification Body is particularly important where ISO 18788 certification is intended to support an ICoCA requirement.

ICoCA states that a Certification Body can be accepted through specified mechanisms, including accreditation to an ICoCA-recognized standard by an appropriate Global ACI MRA signatory or accreditation to ISO 17021 together with ICoCA competency checks.

ICoCA specifically identifies ISO 18788 within its recognized certification framework.

An Indian security company should therefore verify the current requirements before selecting a Certification Body where ICoCA acceptance is part of the customer's requirement.

ISO 18788 for Oil & Gas Security in India

Security contractors serving energy and industrial customers may require structured security controls for:

  • Refineries
  • Petrochemical facilities
  • Storage facilities
  • Industrial terminals
  • Energy infrastructure
  • Pipeline-related sites
  • Large industrial premises

Potential security activities include:

  • Gate security
  • Access control
  • Restricted-area protection
  • Vehicle control
  • Contractor verification
  • Perimeter patrols
  • Incident reporting
  • Emergency response

The exact scope should be based on contracted activities.

ISO 18788 for Manufacturing Security

India's manufacturing sector provides substantial potential application for ISO 18788.

Security operations can include:

  • Factory gate security
  • Employee access
  • Visitor control
  • Contractor control
  • Vehicle checks
  • Warehouse security
  • Perimeter patrols
  • Restricted-area control
  • Incident reporting

This is particularly relevant where large manufacturers require formal qualification of their security contractors.

ISO 18788 for Automotive Security

Automotive and component-manufacturing locations may require security services covering:

  • Production facilities
  • Vehicle gates
  • Warehouses
  • Employee entrances
  • Contractor entrances
  • Material movement
  • Parking
  • Perimeter protection

Important automotive markets include Pune, Chennai, Hosur, Bengaluru and other industrial locations.

ISO 18788 for Logistics and Warehousing

Logistics-security contractors may provide:

  • Warehouse security
  • Gate control
  • Vehicle access
  • Driver verification
  • Cargo-area protection
  • Perimeter patrol
  • Incident reporting
  • Visitor management

ISO 18788 may become relevant where logistics customers require structured security-management certification.

ISO 18788 for Banking and Cash Transportation

Organizations involved in cash transportation should separately consider the applicable Indian statutory requirements.

The Ministry of Home Affairs lists the Private Security Agencies (Private Security to Cash Transportation Activities) Rules, 2018.

ISO 18788 should therefore be treated as a management-system requirement rather than a replacement for the applicable statutory rules.

ISO 18788 for IT and Technology Companies

Security contractors supporting technology organizations may provide:

  • Corporate campus security
  • Access control
  • Visitor management
  • Restricted-area security
  • Data-centre access
  • Patrols
  • Incident response
  • Emergency support

Major technology markets include Bengaluru, Hyderabad, Chennai, Pune and Mumbai.

ISO 18788 for Healthcare Security

Security contractors serving hospitals and healthcare campuses may manage:

  • Main entrance security
  • Emergency-area security
  • Visitor control
  • Restricted-area access
  • Parking security
  • Staff-area protection
  • Incident response

The certification scope should cover only the security activities actually managed by the organization.

ISO 18788 for Construction and Infrastructure

Large construction and infrastructure projects may require:

  • Site access control
  • Worker verification
  • Contractor control
  • Vehicle management
  • Equipment protection
  • Material protection
  • Perimeter security
  • Security patrols
  • Incident management

Security risks should be reviewed as the project develops.

ISO 18788 Certification Locations in India

ISO 18788 certification can be relevant across India's major industrial, commercial, technology, logistics and infrastructure markets.

The location itself does not automatically create an ISO 18788 requirement. The relevant question is whether the security organization operates there and whether customers, contracts, tenders or other requirements call for certification.

ISO 18788 Certification in Mumbai

Mumbai is relevant to security providers serving:

  • Banking and financial services
  • Corporate offices
  • Ports
  • Logistics
  • Warehouses
  • Manufacturing
  • Hotels
  • Commercial facilities
  • Infrastructure

Security companies serving international or multinational customers may encounter ISO 18788 requirements through supplier qualification.

ISO 18788 Certification in Pune

Pune is relevant to:

  • Automotive
  • Engineering
  • Manufacturing
  • IT
  • Electronics
  • Industrial facilities
  • Warehousing

Security companies serving Pune's industrial and business markets can consider ISO 18788 where customers require a structured security-management system.

ISO 18788 Certification in Bengaluru

Bengaluru is relevant to:

  • IT
  • Technology
  • Aerospace
  • Electronics
  • Manufacturing
  • Corporate campuses
  • Data-sensitive operations
  • Logistics

Security providers can define certification around their actual contracted services.

ISO 18788 Certification in Chennai

Chennai provides applications across:

  • Automotive
  • Manufacturing
  • Ports
  • Logistics
  • Electronics
  • IT
  • Healthcare
  • Industrial facilities

The certification scope should reflect the actual security operations performed.

ISO 18788 Certification in Coimbatore

Coimbatore can be targeted for security companies serving:

  • Manufacturing
  • Engineering
  • Textile facilities
  • Automotive components
  • Warehouses
  • Logistics
  • Industrial facilities
  • Corporate campuses

The city should remain part of the main India page rather than being treated as a separate near-duplicate landing page.

ISO 18788 Certification in Hosur

Hosur is particularly relevant to:

  • Automotive
  • Engineering
  • Electronics
  • Manufacturing
  • Logistics
  • Industrial facilities

Security services may include:

  • Factory security
  • Gate control
  • Vehicle movement
  • Warehouse protection
  • Contractor management
  • Perimeter security
  • Incident reporting

ISO 18788 Certification in Mysuru

Mysuru can be targeted for:

  • Manufacturing
  • Engineering
  • IT
  • Healthcare
  • Hospitality
  • Commercial facilities
  • Industrial security

ISO 18788 Certification in Hyderabad

Hyderabad has potential applications across:

  • Pharmaceuticals
  • Biotechnology
  • IT
  • Healthcare
  • Aerospace
  • Manufacturing
  • Data centres
  • Logistics

Security contractors supporting these sectors may encounter customer-specific certification requirements.

ISO 18788 Certification in Visakhapatnam

Visakhapatnam is relevant to:

  • Ports
  • Logistics
  • Heavy industry
  • Manufacturing
  • Infrastructure
  • Warehousing
  • Energy-related facilities

ISO 18788 Certification in Goa

Goa can be targeted for security organizations serving:

  • Hotels and resorts
  • Tourism infrastructure
  • Pharmaceuticals
  • Industrial facilities
  • Ports
  • Logistics
  • Commercial properties
  • Construction projects

ISO 18788 Certification in Thiruvananthapuram

Thiruvananthapuram can be relevant to:

  • IT
  • Aerospace
  • Healthcare
  • Technology
  • Commercial facilities
  • Hospitality
  • Infrastructure

ISO 18788 Certification in Kochi

Kochi provides applications across:

  • Ports
  • Shipping
  • Logistics
  • Industrial facilities
  • IT
  • Healthcare
  • Hospitality
  • Commercial buildings

ISO 18788 Certification in Trichy

Trichy can be targeted for security companies serving:

  • Engineering
  • Manufacturing
  • Heavy industry
  • Infrastructure
  • Construction
  • Industrial projects
  • Institutional facilities

ISO 18788 Certification in Madurai

Madurai provides potential applications across:

  • Manufacturing
  • Textiles
  • Healthcare
  • Hospitality
  • Logistics
  • Commercial facilities
  • Construction
  • Industrial premises

Other South India Locations for ISO 18788 Certification

Tamil Nadu

Potential business locations include:

  • Chennai
  • Coimbatore
  • Hosur
  • Madurai
  • Trichy
  • Salem
  • Tiruppur
  • Erode
  • Sriperumbudur
  • Oragadam
  • Ambattur
  • Thoothukudi
  • Tirunelveli

Relevant industries include automotive, engineering, manufacturing, textiles, logistics, ports, warehouses and infrastructure.

Karnataka

Potential locations include:

  • Bengaluru
  • Mysuru
  • Mangaluru
  • Hubballi
  • Belagavi
  • Tumakuru

Potential sectors include technology, aerospace, automotive, manufacturing, logistics, healthcare and commercial facilities.

Kerala

Potential locations include:

  • Kochi
  • Thiruvananthapuram
  • Kozhikode
  • Thrissur
  • Palakkad
  • Alappuzha

Potential sectors include ports, logistics, hospitality, healthcare, IT and manufacturing.

Andhra Pradesh

Potential locations include:

  • Visakhapatnam
  • Vijayawada
  • Tirupati
  • Nellore
  • Kakinada

Potential sectors include ports, logistics, manufacturing, infrastructure and industrial operations.

Telangana

Potential locations include:

  • Hyderabad
  • Warangal
  • Karimnagar
  • Nizamabad

Potential sectors include pharmaceuticals, technology, manufacturing, logistics and infrastructure.

Puducherry

Potential applications include:

  • Manufacturing
  • Pharmaceuticals
  • Healthcare
  • Hospitality
  • Warehousing
  • Commercial facilities

ISO 18788 Certification Process in India

The certification process should be built around the organization's actual requirements.

1. Confirm the Customer or Tender Requirement

First establish whether certification is being requested by:

  • Customer
  • Tender
  • Main contractor
  • International client
  • Industrial customer
  • Infrastructure project
  • Security programme
  • ICoCA-related requirement

2. Review Indian Legal Requirements

Identify:

  • PSARA requirements
  • Central Model Rules
  • State and UT requirements
  • Sector-specific requirements
  • Contractual requirements
  • Customer requirements

3. Define the Certification Scope

Establish:

  • Security services
  • Locations
  • Personnel
  • Customers
  • Operational activities
  • Supporting functions
  • Applicable outsourced activities

4. Conduct a Gap Assessment

Review existing arrangements against the applicable ISO 18788 requirements.

The assessment should identify practical gaps rather than simply generate documentation.

5. Implement the Security Operations Management System

The organization may establish or improve:

  • Security policy
  • Security objectives
  • Risk assessments
  • Legal compliance processes
  • Customer requirements
  • Operational controls
  • Training
  • Competence
  • Incident management
  • Emergency arrangements
  • Monitoring
  • Corrective action

6. Conduct Internal Audit

The internal audit should evaluate whether the management system has been implemented and is operating as intended.

7. Conduct Management Review

Management should consider relevant information such as:

  • Security performance
  • Customer feedback
  • Incidents
  • Audit results
  • Corrective actions
  • Risks
  • Opportunities
  • Improvement needs

8. Certification Audit

An independent Certification Body assesses the organization against the agreed ISO 18788 certification scope.

9. Address Applicable Findings

Where findings are identified, the organization should respond through the applicable corrective-action process.

10. Certification Decision

Following completion of the applicable certification process, the Certification Body makes the certification decision in accordance with its procedures.

ISO 18788 Certification Cost in India

There is no single fixed ISO 18788 certification cost for every Indian organization.

Cost can depend on:

  • Number of employees
  • Number of security personnel
  • Number of locations
  • Number of States
  • Certification scope
  • Security activities
  • Operational complexity
  • Existing management systems
  • Audit requirements
  • Multi-site arrangements
  • Certification Body arrangements

A single-location security provider and a pan-India security company may have very different certification requirements.

For a meaningful quotation, the organization should provide its actual scope and operating information.

How Long Does ISO 18788 Certification Take in India?

The timeline depends on:

  • Existing management-system maturity
  • Number of employees
  • Security personnel
  • Number of locations
  • Operational complexity
  • Documentation readiness
  • Internal audit readiness
  • Management review
  • Customer deadline
  • Certification audit scheduling

A tender deadline should be discussed at the beginning of the certification process rather than after implementation has started.

Documents Required for ISO 18788 Certification in India

Depending on the certification scope, evidence may include:

  • SOMS scope
  • Security policy
  • Security objectives
  • Organizational responsibilities
  • Security risk assessments
  • Legal and regulatory information
  • Customer requirements
  • Contract requirements
  • Security procedures
  • Site instructions
  • Operational plans
  • Competence requirements
  • Training records
  • Personnel records
  • Incident reports
  • Emergency procedures
  • Performance records
  • Supplier records
  • Internal audit records
  • Management review records
  • Corrective-action records

The documentation should reflect actual operations and should not simply be copied from another organization.

ISO 18788 Benefits for Indian Security Companies

ISO 18788 can help an organization demonstrate a structured approach to:

  • Security risk management
  • Operational control
  • Customer requirements
  • Applicable compliance obligations
  • Personnel competence
  • Training
  • Incident management
  • Performance monitoring
  • Internal audit
  • Management review
  • Continual improvement

For companies targeting larger industrial, infrastructure, multinational or international customers, these capabilities may support supplier qualification where ISO 18788 is requested.

ISO 18788 for Indian Companies Seeking International Contracts

An Indian security company seeking international contracts should check the customer's exact certification requirement.

The customer may request:

  • ISO 18788
  • Accredited ISO 18788 certification
  • ICoCA certification
  • A specified Certification Body
  • A recognized accreditation route
  • Additional responsible-security requirements

Where ICoCA certification is specifically requested, the company should verify current ICoCA requirements and Certification Body acceptance rather than assuming that every ISO 18788 certificate meets the requirement.

Who Should Consider ISO 18788 Certification in India?

ISO 18788 may be relevant to:

  • Private security agencies
  • Security guarding companies
  • Security contractors
  • Industrial security providers
  • Oil and gas security contractors
  • Petrochemical security providers
  • Logistics security providers
  • Cash transportation organizations
  • Corporate security contractors
  • Infrastructure security providers
  • Construction security companies
  • Facility-management organizations providing security
  • Event-security providers
  • Security monitoring organizations
  • International security contractors

Applicability should be determined from the organization's actual activities and customer requirements.

ISO 18788 vs PSARA – What Indian Businesses Should Know

PSARA: Indian statutory framework applicable to private security agencies.

ISO 18788: International management-system standard for private security operations.

Customer requirements: Requirements established by the customer or contract.

Tender requirements: Procurement conditions established by the purchaser.

ICoCA: International certification programme with its own requirements.

These should not be treated as interchangeable.

Get ISO 18788 Certified in India with SCS

If your Indian security company has received an ISO 18788 requirement from a customer, tender, main contractor or international business partner, the first step is to establish exactly what certification and accreditation route is expected.

Useful information for the initial discussion includes:

  • Company activity
  • Security services
  • Number of employees
  • Security personnel
  • Number of locations
  • States covered
  • Customer requirement
  • Tender requirement
  • Existing management systems
  • Applicable regulatory requirements
  • ICoCA requirement, where applicable
  • Desired certification timeline

SCS can discuss the proposed certification scope based on the organization's actual security operations and commercial requirements.

Get Certified with SCS for ISO 18788 Certification in India.

http://www.scscertification.com/contactus.php

UAE

Saudi Arabia

UK

Canada

India

SCS Certification6th Floor Salaam Bldg, Office 9 Al Marakib St, Al Danah, Zone 1,Abu Dhabi, UAE.

SCS Certification (Partners)7713, King Abdulaziz Street, Al Dawasir, Dammam, 32416Kingdom of Saudi Arabia

SCS CERTIFICATION EUROPE LIMITED Office 6996,58 Peregrine Road, Hainault, Ilford, Essex, United Kingdom IG6 3SZ.

SCS Certification (E) Limited Oaklea Blvd, Brampton, ONL6Y 5A2, Canada.

Chennai: Building bearing No.19/35, V 270,Situated on First Floor, Mount Road, Little Mount, Chennai – 600015, India.

Bangalore: Bangalore, Karnataka, India.

 

Share this article

Need ISO Certification for Your Business?

Speak with our certification specialists to understand certification requirements, audit process, implementation timelines and accredited certification services.

Frequently Asked Questions

It is independent certification of a defined Security Operations Management System against the applicable requirements of ISO 18788.
No. ISO 18788 should not be presented as a universal statutory licence. Applicable Indian legal and regulatory requirements are separate from voluntary or customer-driven ISO certification.
PSARA refers to the Private Security Agencies (Regulation) Act, 2005, which forms part of India's statutory framework for private security agencies.
No. ISO 18788 certification and PSARA requirements serve different purposes.
Yes. An organization can maintain applicable statutory requirements while establishing an ISO 18788 Security Operations Management System.
They are Central Model Rules under the PSARA framework that superseded the earlier 2006 Model Rules.
Yes. A security company should identify requirements applicable to its actual operating jurisdictions.
Potentially yes, subject to the certification scope and applicable multi-site certification arrangements.
Yes, where a tender specifically requires or accepts ISO 18788 certification.
No. Tender award depends on all applicable eligibility, technical, commercial and evaluation criteria.
Yes. A customer can establish certification as a contractual or supplier-qualification requirement.
Yes. International customers may specify ISO 18788 as part of supplier qualification.
It should confirm the required standard, scope, locations, accreditation expectations, Certification Body requirements, deadline and whether ICoCA certification is also required.
No. ICoCA has its own certification requirements and requirements concerning accepted Certification Bodies.
Yes. ICoCA identifies ISO 18788 as an ICoCA-recognized standard within its certification framework.
ICoCA specifies conditions under which Certification Bodies are accepted, so the company should verify the current requirements before selecting its certification route.
Yes, where prospective customers recognize or require the standard.
Yes. Industrial security operations can be included when they fall within the organization's defined certification scope.
Yes. Manufacturing sites may use contracted security operations covering access, visitors, vehicles, warehouses, perimeter security and incident management.
Yes. Automotive factories and component facilities may require structured security operations.
Yes. Logistics and warehouse security operations can fall within an appropriate certification scope.
It may apply to their security-management system, but applicable Indian cash-transportation rules must also be considered. The MHA lists the relevant 2018 Rules.
Yes, where their contracted security activities fall within the certification scope.
Yes. Construction and infrastructure-site security can be included where applicable.
Yes. Security contractors serving healthcare facilities can consider ISO 18788 where customers require it.
Yes. Corporate and technology-campus security operations can fall within the standard's scope.
Yes. Hospitality security operations can be covered where appropriate.
Potential sectors include manufacturing, automotive, oil and gas, logistics, infrastructure, construction, healthcare, hospitality, technology, corporate facilities and industrial operations.
Potentially yes, depending on the organization's structure, scope and applicable certification arrangements.
Potentially yes, subject to the defined scope and applicable multi-site arrangements.
Potentially yes, where the organization's certification arrangements support those locations.
Potentially yes, subject to the organization's actual operations and certification scope.
It can be relevant to security companies serving manufacturing, engineering, textile, automotive-component and logistics customers.
It can be relevant to automotive, engineering, electronics, manufacturing and logistics security operations.
It can be relevant to manufacturing, engineering, technology, healthcare and commercial security.
It can be relevant to port, logistics, heavy-industry, manufacturing and infrastructure security.
It can be relevant to pharmaceutical, biotechnology, technology, healthcare, aerospace and manufacturing security.
It can be relevant to hospitality, tourism, pharmaceuticals, industrial, port and commercial security.
It can be relevant to automotive, engineering, manufacturing, IT and industrial security.
It can be relevant to financial, corporate, port, logistics, commercial and industrial security.
It can be relevant to technology, aerospace, healthcare, hospitality and commercial security.
It can be relevant to port, shipping, logistics, industrial, healthcare and hospitality security.
It can be relevant to engineering, manufacturing, infrastructure and industrial security.
It can be relevant to manufacturing, textiles, healthcare, logistics, hospitality and commercial security.
Yes. Security companies in Tamil Nadu, Karnataka, Kerala, Andhra Pradesh, Telangana, Goa and other locations can pursue certification according to their activities and requirements.
It normally involves confirming the requirement, defining scope, reviewing applicable requirements, implementing the management system, conducting internal audit and management review, undergoing certification assessment and addressing applicable findings.
Cost depends on scope, employee strength, security personnel, locations, operational complexity, existing systems and audit requirements.
No. A meaningful quotation requires information about the organization's actual certification scope and operating conditions.
The timeline depends on organizational readiness, scope, locations, documentation, internal audit, management review and certification scheduling.
The process can be planned around a tender deadline, but the required implementation and independent assessment should not be bypassed.
Depending on scope, evidence may include the SOMS scope, security policy, risk assessments, legal requirements, customer requirements, procedures, training records, incident records, internal audits and management reviews.
No. The certificate demonstrates conformity of the defined management system with ISO 18788; applicable statutory obligations must be managed separately.
Yes. Compatible processes such as internal audit, corrective action and management review can be integrated.
Yes. Organizations can coordinate security-management and occupational-health-and-safety processes where appropriate.
Yes. This may be useful where security operations also involve significant information-security risks.
ISO 18788 focuses on security operations management, while ISO 9001 focuses on quality management.
ISO 18788 addresses security operations, while ISO 45001 addresses occupational health and safety.
ISO 18788 addresses security operations, while ISO 27001 addresses information security.
Yes. Relevant customer and contractual requirements should be identified and incorporated into appropriate operational controls.
Yes. This can prevent a mismatch between the certification scope and the tender's actual requirement.
Yes, the certification scope can be defined around applicable activities, provided the scope accurately reflects what is managed and assessed.
Potentially yes, subject to the organization's structure and applicable certification arrangements.
Relevant externally provided activities should be addressed according to their significance and the organization's responsibilities.
It involves identifying and managing security-related risks associated with the organization's operations, customers, locations and responsibilities.
It should identify applicable legal and regulatory requirements relevant to its actual activities and operating locations.
The scope determines which security activities, locations and organizational functions are assessed and represented by the certificate.
A generic manual may not adequately demonstrate an effective system. Documentation should reflect actual security operations, risks, customers and responsibilities.
Depending on scope, an audit may examine risk management, legal requirements, customer requirements, operational controls, competence, incidents, monitoring, internal audit, management review and improvement.
No. Customers may impose additional technical, regulatory, experience, accreditation or contractual requirements.
No. Tender eligibility and award depend on the complete tender requirements and evaluation process.
No. ICoCA has separate certification requirements and conditions concerning accepted Certification Bodies.
It should verify the current ICoCA acceptance requirements and confirm that the proposed certification arrangement satisfies the customer's stated requirement.
Yes. The organization can provide its customer specification, tender wording, scope and operating details for discussion.
Yes. Where ICoCA is part of the customer's requirement, the organization should clearly identify that requirement before selecting the certification route.
Provide the organization name, activities, security services, employee and security-personnel numbers, locations, customer requirement, tender requirement and intended scope.
Organizations in South Indian business locations can discuss their certification requirements and scope with SCS.
Organizations operating in Coimbatore can discuss their security activities, scope and certification requirements with SCS.
Organizations operating in Hosur can discuss their automotive, manufacturing, engineering or logistics security requirements with SCS.
Organizations operating in Kochi can discuss port, logistics, industrial, healthcare, hospitality or other security operations with SCS.
Organizations operating in Hyderabad can discuss pharmaceutical, technology, healthcare, aerospace, manufacturing or other security operations with SCS.
Organizations operating in Pune can discuss automotive, engineering, manufacturing, technology and industrial security requirements with SCS.
Organizations operating in Mumbai can discuss corporate, financial, port, logistics, industrial and commercial security requirements with SCS.
Define the security activities, operating locations, customer requirements, applicable Indian legal requirements and intended certification scope.
Because the customer may specify the scope, accreditation expectations, Certification Body, locations, deadline or ICoCA requirement.
Where customers require or recognize it, ISO 18788 can demonstrate a structured approach to security operations, risk management, customer requirements, competence and continual improvement.
You can contact SCS through http://www.scscertification.com/contactus.php to discuss your organization, certification scope and customer requirements.