Third-Party ISO Certification Body in UK, Europe, UAE, MENA & Globally. (MENA HO: UAE)
SCS KNOWLEDGE CENTRE

ISO 18788 Oman: Cost, Requirements & Certification Process

Get ISO 18788 certification in Oman with guidance on security requirements, Omani regulations, cost, certification process, ICoCA and locations.

  1. Home
  2. Knowledge Centre
  3. ISO 18788 Oman: Cost, Requirements & Certification Process

ISO 18788 Certification in Oman – Requirements, Cost & Process | Get Certified with SCS

ISO 18788 Certification in Oman – Requirements, Cost & Process | Get Certified with SCS
ISO 18788 certification in Oman for private security companies covering Omani requirements, customer demands, ICoCA, certification costs, process, industries and locations.

ISO 18788 Certification in Oman – Requirements, Cost & Process | Get Certified with SCS

http://www.scscertification.com/contactus.php

Private security companies in Oman are increasingly expected to show more than simply having trained guards and operational procedures. Customers want to know how security risks are assessed, how personnel are selected and trained, how incidents are handled, and whether the company can consistently deliver the level of service promised in the contract.

ISO 18788 certification in Oman gives security-service providers a structured way to manage these areas through a Security Operations Management System.

The standard can be relevant to companies providing security services to oil and gas facilities, industrial sites, logistics operations, construction projects, commercial properties, hotels, healthcare facilities and other customers.

For companies also considering ICoCA Certification, the certification route needs additional attention. ISO 18788 certification and ICoCA Certification are not the same thing, and the Certification Body's accreditation and acceptance status should be checked before the certification process begins.


What Is ISO 18788 Certification in Oman?

ISO 18788 is an international management-system standard developed for organizations involved in security operations.

In practical terms, it gives a security company a way to bring its operational controls into one organized system. Instead of treating risk assessments, staff competence, incident reporting, customer instructions and internal audits as separate activities, the company manages them as connected parts of its security operation.

For an Oman-based security company, the system may cover areas such as:

  • Security-risk assessment
  • Customer and contractual requirements
  • Legal and regulatory obligations
  • Security personnel competence
  • Training and awareness
  • Operational instructions
  • Incident management
  • Emergency arrangements
  • Monitoring and performance
  • Internal auditing
  • Management review
  • Corrective action
  • Continual improvement

The exact scope depends on what the company actually does.


Why ISO 18788 Matters to Security Companies in Oman

A security company may come across ISO 18788 as a direct customer requirement rather than as a voluntary improvement project.

For example, an international customer may ask a security contractor to demonstrate that it has a recognized management system. A major industrial project may request certification as part of its supplier qualification process. A tender may specify ISO 18788 or another recognized security standard.

In these situations, the company needs to look beyond the certificate itself.

The customer may also want evidence of:

  • Trained and competent security personnel
  • Security-risk assessments
  • Site-specific instructions
  • Incident reporting
  • Emergency response
  • Supervisory controls
  • Contractor management
  • Internal audits
  • Corrective-action records
  • Management involvement

This is why it is sensible to obtain the customer's specification or tender requirement before deciding on the certification route.


ISO 18788 and Omani Private Security Requirements

ISO 18788 certification does not give a company permission to provide private security services in Oman.

Applicable Omani licences, approvals and regulatory requirements remain separate.

Royal Decree 24/99 regulates specified additional security services in Oman. The decree addresses services including centralized monitoring, security guard services, cash and jewellery transport and security-guard training. (decree.om)

Royal Decree 39/2004 subsequently amended the provision relating to security guards, including guards trained or not trained to carry and use weapons. (decree.om)

For a security company preparing for ISO 18788 certification, the practical approach is therefore to identify the laws, licences, approvals and contractual requirements that actually apply to its activities.


What Does an Oman Security Company Need for ISO 18788?

There is no sensible “one-size-fits-all” checklist for every security company.

A company guarding a commercial building in Muscat will not necessarily have the same controls as a company providing security services at an industrial facility in Sohar or a large project in Duqm.

The certification system should reflect the organization's real operations.

Organization and Operating Environment

The company should understand the circumstances that affect its security operations.

These may include:

  • Types of customers
  • Locations served
  • Security threats
  • Workforce requirements
  • Contractor arrangements
  • Site conditions
  • Legal obligations
  • Technology used for security operations
  • Emergency situations
  • Customer-specific instructions

Customer Requirements

Customer requirements deserve particular attention.

A contract may specify:

  • Minimum qualifications
  • Training requirements
  • Number of guards
  • Shift arrangements
  • Reporting requirements
  • Access-control procedures
  • Incident notification
  • Emergency response
  • Supervisory arrangements
  • Performance indicators

These requirements should be understood before the organization finalizes its ISO 18788 scope.

Security Risk Assessment

Security risks should be assessed according to the company's actual work.

Depending on the operation, risks may include:

  • Unauthorized access
  • Theft
  • Intrusion
  • Violence
  • Loss of assets
  • Security personnel misconduct
  • Communication failures
  • Contractor-related risks
  • Emergency situations
  • Equipment or technology failures

The important point is that the risk assessment should describe the organization's real security environment rather than being a generic document prepared only for an audit.

Personnel Competence

A security management system is only useful when the people operating it understand their responsibilities.

The company should establish appropriate arrangements for:

  • Recruitment
  • Competence
  • Job responsibilities
  • Training
  • Awareness
  • Refresher training
  • Evaluation of competence
  • Training records

Customer-specific competence requirements should also be incorporated where applicable.

Operational Controls

Day-to-day security activities should be controlled through suitable procedures and instructions.

Depending on the scope, this could involve:

  • Access control
  • Visitor management
  • Patrols
  • Site instructions
  • Security monitoring
  • Shift handover
  • Contractor control
  • Communication
  • Incident response
  • Asset protection

The controls should be practical enough for security personnel to use during normal operations.

Incident Management

When something goes wrong, the company needs to know what happens next.

Incident-management arrangements may cover:

  • Initial reporting
  • Immediate response
  • Escalation
  • Customer notification
  • Investigation
  • Root-cause review where appropriate
  • Corrective action
  • Follow-up
  • Lessons learned

The resulting records can also provide useful evidence during certification audits.


Customer and Tender Requirements for ISO 18788 in Oman

For many security companies, the business reason for obtaining ISO 18788 comes from a customer or tender.

A customer may ask for:

  • ISO 18788 certification
  • Accredited certification
  • Certification from an accepted Certification Body
  • ICoCA Certification
  • Evidence of security-risk management
  • Staff competence records
  • Security procedures
  • Incident-management arrangements
  • Emergency procedures
  • Security performance information

The wording in the tender matters.

For example, a requirement for “ISO 18788 certification” is not necessarily identical to a requirement for “ICoCA Certification.”

Before spending money on certification, the security company should confirm exactly what the customer expects.


ICoCA and ISO 18788 Certification in Oman

ICoCA is particularly relevant to private security companies that work with international customers or want to demonstrate responsible security practices.

ICoCA identifies ISO 18788 as one of the standards that can be used within its certification framework. (icoca.ch)

This creates an important opportunity for Oman-based security companies, but it also creates a point that should not be overlooked:

ISO 18788 certification is not automatically the same as ICoCA Certification.

A company planning to pursue both should establish the complete route before choosing its Certification Body.


Does ISO 18788 Certification Automatically Give ICoCA Certification?

No.

An ISO 18788 certificate by itself does not make an organization an ICoCA-certified company.

ICoCA has its own certification requirements and specifies conditions relating to Certification Bodies whose certification can be used within its framework. (icoca.ch)

This is particularly important when a customer has specifically requested ICoCA Certification.


ICoCA Certification Body Requirements

A security company should check the Certification Body before beginning the ISO 18788 audit if ICoCA is part of its business objective.

ICoCA provides requirements concerning accepted Certification Bodies and their accreditation arrangements. Its published information includes routes involving accreditation to recognized standards and applicable accreditation arrangements. (icoca.ch)

The practical lesson for a security company is simple:

Do not assume that every ISO 18788 certificate will satisfy an ICoCA-related customer requirement.

Check the current requirements and Certification Body status before signing the certification agreement.


ISO 18788 Certification Process in Oman

The certification process is easier to manage when the organization starts with its actual business requirement.

Step 1 – Confirm Why Certification Is Required

First establish whether ISO 18788 is being requested for:

  • A customer contract
  • A tender
  • Supplier qualification
  • International business
  • Internal improvement
  • An ICoCA certification objective

The answer can influence the certification scope and Certification Body selection.

Step 2 – Define the Scope

The organization should identify:

  • Security services
  • Locations
  • Sites
  • Personnel
  • Supporting activities
  • Outsourced processes
  • Customer operations

The scope should describe what the company really provides.

Step 3 – Review Legal and Contractual Requirements

Identify the Omani legal requirements applicable to the company's activities together with customer and contractual obligations.

Where the organization provides regulated additional security services, applicable licensing and approval requirements should be considered. (decree.om)

Step 4 – Assess Security Risks

Security risks should be assessed for the sites, people, assets, customers and operations covered by the system.

Step 5 – Develop the Management System

The organization then establishes the policies, responsibilities, procedures and controls required for its scope.

Step 6 – Put the System into Practice

This is where documentation becomes actual operational evidence.

Examples include:

  • Training records
  • Site instructions
  • Patrol records
  • Incident reports
  • Risk assessments
  • Inspections
  • Customer communications
  • Corrective-action records

Step 7 – Internal Audit

The company checks whether its system is being followed and whether it is working as intended.

Step 8 – Management Review

Management reviews the system's performance, including issues such as incidents, customer feedback, audit results, risks and improvement opportunities.

Step 9 – Certification Audit

The Certification Body carries out the applicable certification audit.

Step 10 – Corrective Action

If nonconformities are identified, the organization addresses them within the applicable certification process.

Step 11 – Certification Decision

The Certification Body completes its review and makes the certification decision in accordance with its certification procedures.

Step 12 – Maintain the System

Certification is not the end of the process. The company continues with audits, reviews, risk assessments, training, performance monitoring and improvement activities.


ISO 18788 Certification Cost in Oman

There is no standard price that applies to every Oman security company.

The cost can change considerably depending on:

  • Number of employees
  • Number of security personnel
  • Number of sites
  • Geographic coverage
  • Security activities
  • Operational complexity
  • Existing management systems
  • Audit duration
  • Multi-site arrangements
  • Customer requirements

A small security operation in Muscat may have a very different audit requirement from a company managing security contracts across Muscat, Sohar, Salalah and Duqm.

If the organization also needs ICoCA Certification, it should consider that requirement separately rather than assuming it is included automatically within the ISO 18788 certification cost.


ISO 18788 Certification in Muscat

Muscat contains a wide range of commercial, construction, healthcare, hospitality, corporate and infrastructure activities.

Security providers may be responsible for:

  • Corporate facilities
  • Commercial buildings
  • Hotels
  • Hospitals
  • Construction sites
  • Warehouses
  • Residential developments
  • Infrastructure facilities

For these operations, ISO 18788 can provide a structured approach to security-risk assessment, personnel competence, site instructions, incident reporting and customer requirements.


ISO 18788 Certification in Sohar

Sohar has a significant industrial and logistics presence. The Oman Logistics Center identifies Sohar Port and Sohar Free Zone among Oman's major logistics and industrial facilities. (mtcit.gov.om)

Security providers working in this environment may support:

  • Industrial facilities
  • Logistics companies
  • Warehouses
  • Manufacturing sites
  • Petrochemical operations
  • Port-related facilities
  • Free-zone businesses

For these companies, the ISO 18788 scope should reflect the security services actually provided.


ISO 18788 Certification in Salalah

Salalah has an important combination of logistics, port, industrial, manufacturing and tourism activities.

The Oman Logistics Center identifies the Port of Salalah and Salalah Free Zone as significant parts of Oman's logistics and industrial infrastructure. (mtcit.gov.om)

Security companies serving these customers may require controls for:

  • Access management
  • Site protection
  • Patrols
  • Incident response
  • Contractor access
  • Asset protection

ISO 18788 Certification in Duqm

Duqm has developed into an important industrial, logistics and economic zone.

The Oman Logistics Center identifies the Special Economic Zone at Duqm as a major location for industry, logistics and tourism, while the Port of Duqm supports the wider industrial and logistics environment. (mtcit.gov.om)

Security companies working on projects in Duqm may provide services for:

  • Construction projects
  • Industrial facilities
  • Port-related operations
  • Logistics
  • Contractor access
  • Perimeter security
  • Asset protection

ISO 18788 in Nizwa, Sur, Barka and Other Oman Locations

ISO 18788 is not limited to Muscat, Sohar, Salalah or Duqm.

Security providers operating in Nizwa, Sur, Barka, Al Buraimi, Rustaq, Ibri and other locations can consider certification where their customer or business requirements call for a structured security-management system.

The important issue is the company's actual scope, not simply the number of cities printed in its marketing material.


ISO 18788 for Oil and Gas Security Companies in Oman

Oil and gas facilities can present demanding security conditions because of the value of the assets, restricted areas, contractor activity and emergency considerations.

A security provider may need controls for:

  • Access control
  • Perimeter protection
  • Patrols
  • Contractor access
  • Incident response
  • Emergency communication
  • Asset protection
  • Customer reporting

Where the oil and gas customer specifies ISO 18788, those contractual requirements should be incorporated into the organization's management system.


ISO 18788 for Petrochemical and Industrial Security

Industrial and petrochemical locations can have restricted areas, multiple contractors, shift-based operations and valuable equipment.

A security provider can use ISO 18788 to bring these activities under a consistent management framework covering risk assessment, personnel competence, operational controls, incident handling and performance monitoring.


ISO 18788 for Port and Logistics Security

Sohar, Salalah and Duqm are important locations within Oman's logistics infrastructure. (mtcit.gov.om)

Security companies supporting port-related and logistics customers may deal with:

  • Vehicle access
  • Visitor control
  • Perimeter security
  • Contractor management
  • Cargo and asset protection
  • Incident reporting

The exact certification scope should be based on the land-based security activities performed by the organization and the requirements of its customer.


ISO 18788 for Hotels and Tourism Security

Hotel security has its own practical challenges.

Depending on the contract, security personnel may be responsible for:

  • Guest and visitor access
  • Employee entrances
  • Restricted areas
  • Parking areas
  • Events
  • Emergency response
  • Incident reporting

The organization's controls should reflect the hotel's actual security arrangements.


ISO 18788 for Healthcare Security

Hospitals and healthcare facilities can require controlled access, visitor management, emergency response and protection of restricted areas.

A security provider working for a healthcare customer should establish its procedures according to the customer's requirements and applicable legal obligations.


ISO 18788 for Banks and Financial Facilities

Financial facilities can require controlled access, monitoring, guarding, incident reporting and emergency procedures.

A security company's ISO 18788 system can incorporate these requirements when they fall within its contracted services.


ISO 18788 for Construction and Infrastructure Projects

Construction sites often change as the project progresses.

There may be:

  • Multiple contractors
  • Temporary access points
  • Valuable equipment
  • Large workforces
  • Vehicle movements
  • Remote locations
  • Changing site conditions

Security companies working on such projects need procedures that can adapt as the project changes.


Records Commonly Used During ISO 18788 Certification

The exact evidence depends on the scope, but a security organization may maintain:

  • Security policy
  • Security objectives
  • Scope statement
  • Security-risk assessments
  • Legal and regulatory requirements
  • Customer requirements
  • Site instructions
  • Training records
  • Competence records
  • Incident reports
  • Patrol records
  • Inspection records
  • Emergency procedures
  • Contractor records
  • Monitoring results
  • Internal audit reports
  • Management-review records
  • Corrective-action records

The objective is not to create paperwork simply for an auditor. The records should demonstrate how the company actually manages its security operations.


Choosing an ISO 18788 Certification Body in Oman

Price should not be the only consideration when selecting a Certification Body.

A security company should check:

  • Accreditation
  • ISO 18788 scope
  • ISO/IEC 17021 accreditation where applicable
  • Auditor competence
  • Security-sector experience
  • Customer acceptance
  • Tender requirements
  • Certification scope
  • ICoCA requirements where relevant

For an organization pursuing an ICoCA-related objective, checking the Certification Body's current ICoCA acceptance status is particularly important. ICoCA publishes information on Certification Bodies accepted within its certification framework. (icoca.ch)


How to Get ISO 18788 Certification in Oman with SCS

The first step is to understand the organization's actual requirement.

SCS can discuss the proposed:

  • Security services
  • Certification scope
  • Operating locations
  • Number of personnel
  • Customer requirements
  • Tender conditions
  • Applicable legal requirements
  • ICoCA-related requirements

This allows the certification route to be considered around the organization's actual business rather than around a generic checklist.


Get ISO 18788 Certified in Oman with SCS

If your company has received a customer or tender requirement for ISO 18788 certification in Oman, it is worth checking the requirement carefully before starting the certification process.

This is particularly important for security providers serving oil and gas, petrochemical, industrial, logistics, port, construction, infrastructure, healthcare, hospitality and international customers.

Where ICoCA Certification is also required, verify the applicable ICoCA requirements and Certification Body route before proceeding.

For ISO 18788 certification enquiries with SCS:

http://www.scscertification.com/contactus.php

UAE

Saudi Arabia

UK

Canada

India

SCS Certification6th Floor Salaam Bldg, Office 9 Al Marakib St, Al Danah, Zone 1,Abu Dhabi, UAE.

SCS Certification (Partners)7713, King Abdulaziz Street, Al Dawasir, Dammam, 32416Kingdom of Saudi Arabia

SCS CERTIFICATION EUROPE LIMITED Office 6996,58 Peregrine Road, Hainault, Ilford, Essex, United Kingdom IG6 3SZ.

SCS Certification (E) Limited Oaklea Blvd, Brampton, ONL6Y 5A2, Canada.

Chennai: Building bearing No.19/35, V 270,Situated on First Floor, Mount Road, Little Mount, Chennai – 600015, India.

Bangalore: Bangalore, Karnataka, India.

Share this article

Need ISO Certification for Your Business?

Speak with our certification specialists to understand certification requirements, audit process, implementation timelines and accredited certification services.

Frequently Asked Questions

It is certification of a security organization's management system against ISO 18788 within the agreed scope of its security operations.
Not necessarily. A company may need ISO 18788 because of a customer, tender, contract or international business requirement.
No. ISO certification and Omani licensing or regulatory approval are separate matters.
Royal Decree 24/99 addresses specified additional security services and associated approval and licensing requirements. (decree.om)
Yes. Royal Decree 39/2004 amended the security-guard provision. (decree.om)
Yes, when the customer recognizes or specifically requests ISO 18788.
It can support tender qualification where ISO 18788 is specified or accepted by the contracting organization.
ISO 18788 is an international security-management standard, while ICoCA operates a separate certification framework involving recognized standards and specific Certification Body requirements.
No. ICoCA Certification has additional requirements.
Yes. ISO 18788 is listed by ICoCA among the standards recognized within its certification framework. (icoca.ch)
No. The applicable Certification Body requirements should be checked against ICoCA's current published criteria. (icoca.ch)
It should check accreditation, ISO 18788 scope, auditor competence, customer requirements and, where relevant, the Certification Body's suitability for the intended ICoCA route.
Cost depends on the number of employees, security personnel, sites, locations, scope, complexity and audit requirements.
Yes. The certification scope and audit arrangements should reflect the size and complexity of the actual operation.
Yes, subject to the applicable certification arrangements and the organization's ability to demonstrate control across the included locations.
Typical evidence may include risk assessments, customer requirements, procedures, training records, incident reports, audits, management reviews and corrective-action records.
Security risks should be identified and evaluated as part of the organization's management-system approach.
Yes. Competence and training evidence can be important parts of demonstrating that personnel are capable of carrying out assigned security duties.
Incident handling and the organization's response arrangements are important parts of managing security operations.
Yes, where the security company's activities fall within the standard's scope and the customer requires or recognizes ISO 18788.
Yes. The management system can be applied to suitable security operations supporting petrochemical and industrial customers.
Yes. It can be relevant to security providers serving industrial, logistics and other customers in Sohar.
Yes. It can be relevant to security providers working with logistics, industrial, hospitality and commercial customers.
Yes. Security providers serving industrial, construction and logistics activities in Duqm can consider ISO 18788 where appropriate.
Yes. It can be applied to suitable commercial, corporate, construction, healthcare, hospitality and infrastructure security operations.
Yes. The applicability depends on the company's security services and customer requirements.
Yes. Construction security can involve access control, contractor management, asset protection and incident response.
Yes. The system can cover suitable hotel-security activities within the agreed scope.
Yes. Security providers supporting healthcare facilities can establish controls appropriate to their contracted activities.
Yes. Access control, perimeter security, visitor management and asset protection can fall within the security provider's scope.
Begin by identifying the customer requirement, defining the security-services scope, reviewing applicable requirements and assessing the organization's readiness.
Yes. Organizations can contact SCS to discuss their certification scope and requirements.
Contact SCS through http://www.scscertification.com/contactus.php