Third-Party ISO Certification Body in UK, Europe, UAE, MENA & Globally. (MENA HO: UAE)
SCS KNOWLEDGE CENTRE

ISO 18788 Certification Malaysia | Cost & ICoCA | SCS

ISO 18788 certification in Malaysia covering requirements, cost, process, ICoCA, KDN, industries and locations. Get certified with SCS.

  1. Home
  2. Knowledge Centre
  3. ISO 18788 Certification Malaysia | Cost & ICoCA | SCS

ISO 18788 Certification in Malaysia – Requirements, Cost, Process & ICoCA | Get Certified with SCS

ISO 18788 Certification in Malaysia – Requirements, Cost, Process & ICoCA | Get Certified with SCS
ISO 18788 certification in Malaysia for private security companies, contractors and security operations, covering Malaysian requirements, KDN considerations, ICoCA, cost, process, industries and business locations.

ISO 18788 Certification in Malaysia – Requirements, Cost, Process & ICoCA | Get Certified with SCS

SCS Certification – Malaysia Office

SCS Certification
Jalan Pinang
50450 Kuala Lumpur
Malaysia

Phone: +60 11 6263 6611
Enquiry: Contact SCS Certification

http://www.scscertification.com/contactus.php

ISO 18788 certification in Malaysia provides a structured Security Operations Management System (SOMS) for organizations that conduct, manage or contract private security operations.

For Malaysian security companies, certification can become an important commercial qualification when customers, multinational organizations, industrial companies, infrastructure projects, international clients or tenders require an internationally recognized framework for managing security operations.

Malaysia-specific certification planning also needs to consider the country's private-security regulatory environment. The Private Agencies Act 1971 (Act 27) is part of Malaysia's private-agency regulatory framework administered by the Ministry of Home Affairs (Kementerian Dalam Negeri – KDN). KDN's systems also provide information relating to registered private security companies.

For businesses, three requirements should be kept separate:

  • ISO 18788 management-system requirements
  • Malaysian legal and regulatory requirements
  • Customer, contract and tender requirements

Where an international customer additionally requires ICoCA certification, the Certification Body route becomes important because ICoCA recognizes ISO 18788 but does not accept certification from every Certification Body.

What Is ISO 18788 Certification in Malaysia?

ISO 18788:2015 is the international standard for Management System for Private Security Operations – Requirements with Guidance for Use.

ISO states that ISO 18788 provides a framework for establishing, implementing, operating, monitoring, reviewing, maintaining and improving security operations. It provides principles and requirements for a Security Operations Management System and a business and risk-management framework for organizations conducting or contracting security operations.

The standard can be relevant to Malaysian organizations providing or managing activities such as:

  • Manned guarding
  • Security supervision
  • Access control
  • Security patrols
  • Site protection
  • Asset protection
  • Security monitoring
  • Security escort services
  • Contract security management
  • Industrial security
  • Logistics security
  • Infrastructure security
  • Other private security operations

The certification scope should reflect the organization's actual activities rather than simply listing every possible security service.

ISO 18788:2015 and Current Standard Status

The current published standard is ISO 18788:2015.

ISO confirms that the 2015 edition remains the current published standard. ISO also lists ISO 18788:2015/Amd 1:2024 – Climate action changes, which applies to ISO 18788:2015.

Organizations should therefore avoid referring to "ISO 18788:2026" as though it were the current published edition.

When preparing a Malaysian certification programme, the organization should determine the applicable requirements, amendments and customer expectations relevant to its certification scope.

ISO 18788 and Malaysia's Private Security Regulatory Requirements

ISO 18788 certification and Malaysian private-security licensing are different matters.

The Private Agencies Act 1971 forms part of Malaysia's regulatory framework for private agencies. KDN's public systems provide information on security companies registered under the Act.

This creates an important distinction:

KDN licensing is a regulatory matter.

ISO 18788 certification is a management-system conformity assessment.

Customer and tender requirements are contractual or procurement matters.

One should not be represented as automatically replacing the others.

ISO 18788 and KDN-Licensed Security Companies

A Malaysian security company should establish the legal and regulatory requirements applicable to its activities before finalizing its ISO 18788 certification scope.

For an ISO 18788 project, relevant information can include:

  • Company legal status
  • Private-security activities
  • Applicable KDN licensing
  • Operating locations
  • Security personnel
  • Customer sites
  • Contractual obligations
  • Applicable legal requirements
  • Customer specifications
  • Tender conditions

The objective is not to claim that ISO 18788 grants a Malaysian security licence. Instead, the management system should identify and manage the legal and contractual requirements applicable to the organization's operations.

What Are the Main ISO 18788 Requirements for Malaysian Security Companies?

A Malaysian Security Operations Management System should be built around the organization's actual security activities.

Important areas include:

  • Understanding the security-operational environment
  • Identifying interested parties and customer requirements
  • Defining the SOMS scope
  • Establishing security policy and objectives
  • Assessing security risks
  • Identifying applicable legal and contractual requirements
  • Defining responsibilities and authority
  • Ensuring competent personnel
  • Controlling security operations
  • Managing incidents and emergencies
  • Monitoring operational performance
  • Conducting internal audits
  • Performing management review
  • Managing nonconformities and corrective action
  • Continually improving the system

The implementation should be appropriate to the organization's scope, risks, services, customers and operating environment.

ISO 18788 Security Risk Management in Malaysia

Security risks should be assessed according to the actual Malaysian operating environment.

For example, a security contractor supporting a manufacturing plant may need to consider:

  • Unauthorized access
  • Theft
  • Perimeter breaches
  • Contractor access
  • Employee access
  • Vehicle movement
  • Security personnel shortages
  • Communication failure
  • Emergency incidents
  • Security-control failures

A logistics-security operation may have a different risk profile involving:

  • Warehouse access
  • Cargo protection
  • Vehicle entry
  • Driver verification
  • Loading areas
  • Remote facilities
  • Loss or theft
  • Incident escalation

The risk assessment should therefore be operationally specific rather than copied from a generic security template.

ISO 18788 Legal and Compliance Requirements in Malaysia

The organization should identify legal and other requirements relevant to its security operations.

Depending on its scope, this can include:

  • Private Agencies Act 1971
  • Applicable KDN requirements
  • Licensing conditions
  • Security personnel requirements
  • Customer contractual requirements
  • Site-specific requirements
  • Tender conditions
  • Other Malaysian laws relevant to the organization's activities

KDN's official systems provide information concerning security companies registered under the Private Agencies Act 1971.

ISO 18788 should therefore be implemented with a clear understanding of which obligations are legal, which are contractual and which arise from the management-system standard.

ISO 18788 Customer Requirements for Malaysian Security Companies

A major commercial reason for obtaining ISO 18788 may come from the customer rather than from Malaysian legislation.

A Malaysian customer, multinational company or international contractor may specify:

  • ISO 18788 certification
  • Accredited certification
  • A defined certification scope
  • Specific security sites
  • Specific security services
  • Customer security procedures
  • Incident-reporting requirements
  • Personnel competence requirements
  • ICoCA certification
  • An accepted Certification Body

Before beginning certification, the security company should obtain the customer's written requirement wherever possible.

Questions to Ask a Customer Before ISO 18788 Certification

  1. Is ISO 18788 mandatory or preferred?
  2. Which security activities must be covered?
  3. Which Malaysian locations must be included?
  4. Does the customer require accredited certification?
  5. Is a particular Certification Body specified?
  6. Is ICoCA certification required?
  7. Must the certificate cover a particular customer site?
  8. Is certification required before tender submission?
  9. Is certification required before contract award?
  10. Are subcontracted security activities included?

These questions can prevent the organization from obtaining a certificate that does not meet the customer's actual procurement requirement.

ISO 18788 and ICoCA Requirements for Malaysian Security Companies

ICoCA currently recognizes ISO 18788 as one of the standards that can be used for ICoCA certification. ICoCA also recognizes PSC.1 and ISO 28007 within its certification framework.

However:

ISO 18788 certification does not automatically equal ICoCA certification.

ICoCA requires certification to a recognized standard and certification by an accepted Certification Body. ICoCA states that accepted Certification Bodies can qualify through specified accreditation routes, including accreditation to a recognized standard by an applicable Global ACI MRA signatory or accreditation to ISO 17021 with the required ICoCA competency checks.

This is particularly important for Malaysian security companies targeting international contracts.

Before selecting a Certification Body, a company whose customer requires ICoCA should verify the current ICoCA acceptance requirements.

ISO 18788 and ICoCA: Why the Certification Body Matters

A company should not assume that every ISO 18788 certificate will automatically satisfy an ICoCA requirement.

ICoCA expressly states that it does not accept certifications from all Certification Bodies. Its current information identifies specific routes through which a Certification Body can be accepted.

Therefore, Malaysian companies targeting ICoCA certification should check:

  • The applicable ICoCA standard
  • Certification Body acceptance
  • Accreditation status
  • Applicable ICoCA competency requirements
  • Customer requirements
  • Certificate scope
  • Certification validity

This should be confirmed before the certification programme begins.

ISO 18788 for Malaysian Private Security Agencies

Private security agencies are a direct application of ISO 18788.

Potential operations include:

  • Manned guarding
  • Gate control
  • Access control
  • Patrols
  • Security supervision
  • Visitor management
  • Vehicle control
  • Site protection
  • Incident reporting
  • Emergency response
  • Customer reporting

The SOMS should connect these activities to risk assessment, competence, operational controls, performance monitoring and continual improvement.

ISO 18788 for Manufacturing Security in Malaysia

Malaysia's manufacturing sector can create significant demand for structured security operations.

Potential applications include:

  • Factory access control
  • Employee entry
  • Contractor access
  • Visitor management
  • Vehicle checks
  • Warehouse security
  • Perimeter patrols
  • Material protection
  • Incident reporting

Relevant business markets include:

  • Selangor
  • Shah Alam
  • Klang
  • Penang
  • Bayan Lepas
  • Johor
  • Pasir Gudang
  • Melaka
  • Kulim

ISO 18788 for Semiconductor and Electronics Security

Malaysia's semiconductor and electronics ecosystem presents security requirements that can differ from conventional commercial guarding.

Security operations may involve:

  • Restricted production areas
  • Controlled access
  • Contractor entry
  • Visitor control
  • Sensitive facilities
  • Warehouse protection
  • Perimeter security
  • Incident escalation

Potential business locations include:

  • Penang
  • Bayan Lepas
  • Kulim
  • Selangor
  • Johor
  • Kuala Lumpur

For these organizations, customer requirements can be an important driver for ISO 18788 certification.

ISO 18788 for Oil, Gas, Energy and Petrochemical Security

Security providers serving energy-related operations may manage environments with significant operational and asset risks.

Potential applications include:

  • Industrial facilities
  • Storage areas
  • Restricted zones
  • Energy infrastructure
  • Port-related facilities
  • Contractor access
  • Perimeter protection
  • Emergency escalation

Potential Malaysian locations include:

  • Kerteh
  • Pengerang
  • Johor
  • Terengganu
  • Bintulu
  • Miri
  • Sarawak
  • Labuan

The scope should be aligned with the services actually contracted.

ISO 18788 for Port, Maritime and Logistics Security

Malaysia's logistics and port environment creates applications for structured security operations.

Potential controls include:

  • Port access
  • Gate security
  • Cargo-area protection
  • Warehouse access
  • Vehicle movement
  • Restricted-area control
  • Visitor management
  • Patrols
  • Incident reporting

Relevant locations include:

  • Port Klang
  • Johor
  • Tanjung Pelepas
  • Penang
  • Kuantan
  • Bintulu
  • Kuching

ISO 18788 for Aviation Security Contractors

Security contractors operating in aviation environments may manage:

  • Restricted-area access
  • Personnel entry
  • Vehicle access
  • Perimeter security
  • Visitor management
  • Incident response
  • Security patrols

Potential business markets include:

  • Kuala Lumpur / Sepang
  • Penang
  • Johor
  • Kota Kinabalu
  • Kuching

The certification scope should clearly distinguish the organization's contractual security responsibilities from aviation-security functions outside its control.

ISO 18788 for Banking and Financial Security

Security providers serving financial institutions may support:

  • Branch security
  • Corporate-office security
  • Access control
  • Visitor management
  • Asset protection
  • Security patrols
  • Incident response

Kuala Lumpur and the Klang Valley can be important commercial markets for these services.

ISO 18788 for Construction and Infrastructure Security

Large construction and infrastructure projects can require structured control over:

  • Site access
  • Contractor entry
  • Worker access
  • Vehicle movement
  • Equipment protection
  • Material protection
  • Perimeter patrols
  • Incident management

ISO 18788 can be considered where the customer specifically requires a formal private-security operations management system.

ISO 18788 for Hospitality and Tourism Security

Security contractors serving hotels, resorts and tourism businesses may manage:

  • Guest-area security
  • Access control
  • Parking
  • Visitor management
  • Emergency response
  • Perimeter protection
  • Incident reporting

Potential markets include:

  • Kuala Lumpur
  • Penang
  • Langkawi
  • Melaka
  • Johor
  • Sabah
  • Sarawak

ISO 18788 for Plantation and Remote-Site Security

Security operations in plantations and remote facilities may require controls for:

  • Remote-site access
  • Patrols
  • Asset protection
  • Equipment protection
  • Vehicle movement
  • Contractor access
  • Incident communication

Potential markets include:

  • Sabah
  • Sarawak
  • Johor
  • Pahang
  • Perak

The risk profile should be developed from actual site conditions.

ISO 18788 Certification Locations in Malaysia

The Malaysia certification page should remain a single national authority page rather than creating multiple near-identical city pages.

The following locations can be addressed as long-tail commercial markets.

ISO 18788 Certification in Kuala Lumpur

Relevant sectors include:

  • Corporate security
  • Banking
  • Financial services
  • Commercial buildings
  • Hotels
  • Technology companies
  • Headquarters operations

ISO 18788 Certification in Selangor

Potential sectors include:

  • Manufacturing
  • Logistics
  • Warehousing
  • Industrial facilities
  • Data centres
  • Commercial properties

Key areas include Shah Alam, Klang, Petaling Jaya, Subang Jaya, Cyberjaya and Port Klang.

ISO 18788 Certification in Penang

Potential sectors include:

  • Electronics
  • Semiconductor
  • Manufacturing
  • Logistics
  • Industrial facilities
  • Commercial security

ISO 18788 Certification in Bayan Lepas

The location is particularly relevant to:

  • Electronics
  • Semiconductor
  • Technology
  • Manufacturing
  • Industrial facilities

ISO 18788 Certification in Johor Bahru

Potential sectors include:

  • Manufacturing
  • Logistics
  • Warehousing
  • Construction
  • Industrial facilities
  • Commercial properties

ISO 18788 Certification in Pasir Gudang

Potential applications include:

  • Port security
  • Petrochemical facilities
  • Manufacturing
  • Logistics
  • Warehousing
  • Industrial operations

ISO 18788 Certification in Iskandar Malaysia

Potential applications include:

  • Manufacturing
  • Logistics
  • Construction
  • Commercial developments
  • Industrial facilities
  • Data centres
  • Hospitality

ISO 18788 Certification in Melaka

Potential sectors include:

  • Manufacturing
  • Automotive
  • Electronics
  • Logistics
  • Hospitality
  • Industrial operations

ISO 18788 Certification in Ipoh

Potential applications include:

  • Manufacturing
  • Logistics
  • Commercial facilities
  • Industrial security

ISO 18788 Certification in Kuantan

Potential applications include:

  • Port-related security
  • Manufacturing
  • Logistics
  • Industrial facilities

ISO 18788 Certification in Kerteh and Pengerang

These locations can be relevant to:

  • Oil and gas
  • Petrochemical
  • Energy
  • Industrial facilities
  • Storage
  • Port-related operations

ISO 18788 Certification in Kota Kinabalu

Potential applications include:

  • Hospitality
  • Logistics
  • Commercial facilities
  • Infrastructure
  • Industrial operations

ISO 18788 Certification in Kuching

Potential applications include:

  • Energy
  • Manufacturing
  • Logistics
  • Infrastructure
  • Commercial security

ISO 18788 Certification in Bintulu and Miri

Potential sectors include:

  • Energy
  • Oil and gas
  • Industrial operations
  • Ports
  • Logistics
  • Construction

ISO 18788 Certification in Labuan

Potential applications include:

  • Oil and gas
  • Maritime services
  • Offshore support
  • Logistics
  • Financial services
  • Commercial security

ISO 18788 Certification Process in Malaysia

A practical certification programme can follow these stages.

1. Identify the Customer or Business Requirement

Determine whether ISO 18788 is being requested by:

  • A Malaysian customer
  • Multinational organization
  • Main contractor
  • Tender
  • International customer
  • Security contract
  • ICoCA-related requirement

2. Review Applicable Malaysian Requirements

Identify relevant:

  • Private Agencies Act 1971 requirements
  • KDN requirements
  • Licensing requirements
  • Security-personnel requirements
  • Customer requirements
  • Contract requirements
  • Site requirements

3. Define the ISO 18788 Scope

Identify:

  • Security services
  • Locations
  • Branches
  • Personnel
  • Customer sites
  • Supporting functions
  • Outsourced activities

4. Conduct a Gap Assessment

Assess the organization's existing Security Operations Management System against the applicable ISO 18788 requirements.

5. Implement the Required Controls

Develop and implement appropriate:

  • Security policy
  • Security objectives
  • Risk assessments
  • Legal requirements
  • Customer requirements
  • Operational controls
  • Competence arrangements
  • Incident processes
  • Emergency arrangements
  • Monitoring processes
  • Corrective-action controls

6. Conduct Internal Audit

The organization should assess whether the system is implemented and functioning as planned.

7. Conduct Management Review

Management should review relevant system and security-performance information.

8. Certification Audit

An independent Certification Body conducts the certification assessment against the agreed scope.

9. Address Applicable Findings

Where findings are raised, the organization addresses them through the applicable corrective-action process.

10. Certification Decision

Certification is completed according to the Certification Body's applicable procedures and decision process.

11. Maintain and Improve the System

The organization continues to monitor, evaluate and improve its Security Operations Management System.

ISO 18788 Certification Cost in Malaysia

There is no single fixed ISO 18788 certification cost in Malaysia.

The cost can depend on:

  • Number of employees
  • Number of security personnel
  • Number of locations
  • Number of customer sites
  • Security activities
  • Operational complexity
  • Certification scope
  • Multi-site arrangements
  • Existing management-system maturity
  • Audit requirements

A single-location security contractor and a national security company with multiple branches will have very different certification requirements.

For a meaningful quotation, the proposed scope and organization profile should be reviewed first.

How Long Does ISO 18788 Certification Take in Malaysia?

The certification timeline depends on:

  • Organization size
  • Security personnel
  • Locations
  • Certification scope
  • Existing system maturity
  • Documentation readiness
  • Internal audit
  • Management review
  • Certification scheduling
  • Customer deadline

Companies facing a tender or contract deadline should communicate that deadline during the initial certification discussion.

Documents and Evidence for ISO 18788 Certification in Malaysia

Depending on the certification scope, evidence may include:

  • SOMS scope
  • Security policy
  • Security objectives
  • Organizational responsibilities
  • Security risk assessments
  • Legal and regulatory requirements
  • KDN-related requirements where applicable
  • Customer requirements
  • Contract requirements
  • Operational procedures
  • Site instructions
  • Competence requirements
  • Training records
  • Incident records
  • Emergency arrangements
  • Monitoring records
  • Internal audit records
  • Management review records
  • Corrective-action records

The documentation should describe the organization's actual Malaysian security operations.

ISO 18788 for Malaysian Companies Seeking International Contracts

A Malaysian security company pursuing international business should first establish exactly what its customer requires.

The customer may request:

  • ISO 18788
  • Accredited ISO 18788 certification
  • ICoCA certification
  • An accepted Certification Body
  • A particular accreditation route
  • Additional responsible-security requirements

ICoCA identifies ISO 18788 as a recognized standard for its certification framework and specifies requirements concerning accepted Certification Bodies.

Therefore, the certification route should be checked before the company commits to a Certification Body.

ISO 18788 vs KDN Licensing in Malaysia

These requirements should not be confused.

KDN / private-agency licensing:
Applicable regulatory authorization for private-security activities.

ISO 18788:
An international management-system standard for private security operations.

Customer requirements:
Contractual expectations imposed by the customer.

Tender requirements:
Procurement conditions established by the tendering organization.

ICoCA certification:
A separate international certification framework involving recognized standards and accepted Certification Bodies.

A Malaysian security organization may need to address several of these simultaneously.

Who Should Consider ISO 18788 Certification in Malaysia?

ISO 18788 may be relevant to:

  • Private security agencies
  • Contract security companies
  • Security guarding companies
  • Industrial security contractors
  • Manufacturing security providers
  • Semiconductor security providers
  • Logistics security companies
  • Port security contractors
  • Aviation security contractors
  • Energy-sector security providers
  • Oil and gas security contractors
  • Infrastructure security companies
  • Construction security contractors
  • Corporate security providers
  • International security contractors

The suitability of certification depends on the organization's activities and intended scope.

Why Malaysian Customers May Ask for ISO 18788

A customer may seek evidence that a security provider has a structured approach to:

  • Security risk management
  • Operational planning
  • Customer requirements
  • Applicable legal requirements
  • Personnel competence
  • Incident management
  • Security performance
  • Internal auditing
  • Management review
  • Continual improvement

ISO 18788 can therefore become a commercial qualification tool when it is specifically required or recognized by the customer.

Get ISO 18788 Certified in Malaysia with SCS

If your Malaysian security organization has received an ISO 18788 requirement from a customer, tender, multinational company, main contractor or international business partner, the certification project should begin by defining the exact requirement.

For an initial discussion, prepare:

  • Company activity
  • Security services
  • Number of employees
  • Security personnel
  • Malaysian locations
  • Number of customer sites
  • Applicable KDN licensing status
  • Customer requirement
  • Tender requirement
  • ICoCA requirement, where applicable
  • Existing management systems
  • Desired certification timeline

SCS can discuss the proposed ISO 18788 certification scope according to the organization's actual security operations and commercial requirements.

Get Certified with SCS for ISO 18788 Certification in Malaysia

If your organization is looking for ISO 18788 certification in Malaysia, the certification strategy should start with the actual business requirement.

SCS can discuss:

  • ISO 18788 certification requirements
  • Malaysian private-security regulatory considerations
  • KDN-related requirements
  • Customer requirements
  • Tender requirements
  • ICoCA requirements
  • Certification scope
  • Malaysian business locations
  • Audit arrangements
  • Certification timeline
  • Cost considerations

Whether your organization operates in Kuala Lumpur, Selangor, Shah Alam, Klang, Port Klang, Cyberjaya, Penang, Bayan Lepas, Johor Bahru, Pasir Gudang, Iskandar Malaysia, Melaka, Ipoh, Kuantan, Kerteh, Pengerang, Kota Kinabalu, Kuching, Bintulu, Miri, Labuan or another Malaysian business location, the certification scope should be based on the actual security operations.

Get Certified with SCS for ISO 18788 Certification in Malaysia.

http://www.scscertification.com/contactus.php

Get Certified with SCS for ISO 18788 Certification in Malaysia.

http://www.scscertification.com/contactus.php

SCS Certification – Malaysia Office

SCS Certification
Jalan Pinang
50450 Kuala Lumpur
Malaysia

Phone: +60 11 6263 6611
Enquiry: Contact SCS Certification

Share this article

Need ISO Certification for Your Business?

Speak with our certification specialists to understand certification requirements, audit process, implementation timelines and accredited certification services.

Frequently Asked Questions

ISO 18788 certification is independent certification of a defined Security Operations Management System against the applicable requirements of ISO 18788.
ISO 18788:2015 is the international standard for a management system for private security operations. ISO describes it as a framework for organizations conducting or contracting security operations.
No. ISO 18788 should not be described as a universal Malaysian statutory licence. It may instead become a customer, tender, contractual or international qualification requirement.
The Private Agencies Act 1971 is a key part of Malaysia's private-agency regulatory framework. KDN provides information concerning registered security companies under the Act.
No. The Act and ISO 18788 serve different purposes. The Act establishes legal requirements, while ISO 18788 provides a management-system framework for private security operations.
No. ISO 18788 certification does not itself provide a KDN private-agency licence.
KDN is Malaysia's Ministry of Home Affairs, which administers relevant private-agency regulatory and licensing functions.
KDN's eSIMS provides public information concerning registered private security companies.
Yes, where their activities fall within an appropriate ISO 18788 certification scope.
It provides a structured framework for establishing, operating, monitoring, reviewing, maintaining and improving security operations.
No. Its application can extend to organizations conducting or contracting different types of private security operations, depending on scope.
Depending on the organization, scope can include guarding, patrols, access control, site protection, security supervision, monitoring, escort and other private-security operations.
A SOMS is the management framework used to plan, control, monitor, evaluate and improve an organization's security operations.
There is no universal fixed price. Cost depends on employees, security personnel, locations, operational complexity, scope and audit requirements.
The timeframe depends on organizational size, scope, locations, system readiness, audit arrangements and certification scheduling.
Depending on scope, evidence may include policies, objectives, risk assessments, legal requirements, customer requirements, operational controls, training records, incident records, audits and management reviews.
It can support qualification when the tender specifically requires or recognizes ISO 18788 certification.
No. Tender awards depend on the complete set of technical, commercial, regulatory and eligibility requirements.
Yes. A customer can specify ISO 18788 as a contractual or supplier-qualification requirement.
Yes. International customers may request ISO 18788 as part of security-provider qualification.
Yes. ICoCA currently recognizes ISO 18788 as one of its standards for certification.
No. ICoCA certification has additional requirements, including requirements concerning the Certification Body.
ICoCA does not accept certifications from every Certification Body. It specifies accreditation and competency routes for accepted Certification Bodies.
Yes. The current ICoCA acceptance requirements should be verified before selecting the certification route.
No. ISO currently identifies ISO 18788:2015 as the published standard, with Amendment 1:2024.
It is an amendment to ISO 18788:2015 concerning climate-action changes.
Yes, where manufacturing facilities use contracted security operations or customers require a structured security-management framework.
Yes. Security providers serving semiconductor and electronics facilities may use ISO 18788 where it matches customer and operational requirements.
Yes. Penang has potential applications across electronics, semiconductor, manufacturing, logistics and industrial security.
Yes. Security providers supporting electronics, semiconductor and manufacturing facilities may encounter customer requirements for structured security management.
Yes. Manufacturing, logistics, industrial and commercial security providers in Johor Bahru may encounter ISO 18788 requirements.
Yes. The location can be relevant to port, petrochemical, manufacturing, logistics and industrial security operations.
Yes. Corporate, financial, commercial, technology and hospitality security providers may encounter ISO 18788 requirements.
Yes. Manufacturing, logistics, warehousing, industrial and commercial security activities create potential applications.
Yes. Port, cargo, logistics and warehouse security operations can be suitable applications where the customer requires ISO 18788.
Yes. Manufacturing, automotive, electronics, logistics and hospitality security operations can create applications.
It can be relevant to oil, gas, petrochemical and industrial security operations.
It can be relevant to energy, petrochemical, refining, storage and industrial security operations.
It can be relevant to hospitality, logistics, commercial, infrastructure and industrial security.
It can be relevant to energy, manufacturing, logistics, infrastructure and commercial security.
It can be relevant to energy, oil and gas, industrial, port and logistics security operations.
It can be relevant to oil and gas, maritime, offshore-support, logistics and financial-sector security operations.
Potentially yes, depending on the organizational structure, certification scope and applicable audit arrangements.
Potentially yes, where the branches fall within the defined certification scope and applicable certification arrangements.
Yes. Common processes such as internal audit, corrective action and management review can often be coordinated.
Yes. Appropriate common management processes can be coordinated while maintaining the requirements of each standard.
Yes. Integration may be useful where security operations also involve significant information-security risks.
ISO 18788 focuses on private security operations management, while ISO 9001 focuses on quality management.
ISO 18788 addresses private security operations, while ISO 45001 addresses occupational health and safety.
ISO 18788 focuses on security operations management, while ISO 27001 focuses on information-security management.
Relevant customer and contractual requirements should be identified and translated into appropriate operational controls.
Applicable KDN and Malaysian regulatory requirements should be identified and managed within the organization's compliance arrangements.
It can provide a structured framework for planning, controlling, monitoring and improving security operations.
It can provide independent evidence of a structured security-management system where the customer recognizes or requires the standard.
Yes, where ISO 18788 is required or recognized by the international customer.
It should verify the current ICoCA recognized-standard and Certification Body requirements before selecting the certification route.
Not necessarily. ICoCA certification involves requirements beyond simply holding an ISO 18788 certificate.
Provide the company activity, security services, number of employees and security personnel, locations, customer sites, proposed scope, customer or tender requirement and any ICoCA requirement.
Yes. SCS can discuss the proposed certification scope according to the organization's activities, locations and customer requirements.
Yes. Malaysian organizations can discuss their security activities, locations and certification requirements with SCS.
Yes. Security organizations in Penang, Bayan Lepas, Johor Bahru, Pasir Gudang and other Malaysian locations can discuss their certification requirements with SCS.
Yes. Organizations in Kota Kinabalu, Kuching, Bintulu, Miri and other Malaysian locations can discuss their certification requirements with SCS.
Identify the security activities, Malaysian locations, applicable regulatory requirements, customer requirements, tender conditions and intended certification scope.
You can contact SCS through http://www.scscertification.com/contactus.php to discuss your Malaysian security operations, certification scope and customer requirements.