EN 1090 vs ISO 28000
EN 1090
European standard for structural steel/aluminium execution and CE marking
ISO 28000
International standard for supply chain security management systems.
Quick Verdict
EN 1090 mandates CE marking for structural steel/aluminium via FPC and execution classes for EU construction market access. ISO 28000 provides voluntary security management for global supply chains. Fabricators choose EN 1090 for legal compliance; logistics firms adopt ISO 28000 for resilience.
EN 1090
Execution of steel and aluminium structures
Key Features
- Risk-based Execution Classes (EXC1-EXC4) scaling requirements
- Mandatory Factory Production Control (FPC) certification
- Enables CE marking for EU market access
- Comprehensive welding quality via ISO 3834 alignment
- Full material traceability and NDT inspection regimes
ISO 28000
ISO 28000:2022 Security Management Systems Requirements
Key Features
- Risk-based supply chain security management framework
- PDCA cycle for continual improvement and resilience
- Scalable to all organization sizes and industries
- Integrates with ISO 9001, 22301, 27001 standards
- Supplier and third-party security governance controls
Detailed Analysis
A comprehensive look at the specific requirements, scope, and impact of each standard.
EN 1090 Details
What It Is
EN 1090 is a harmonized European standard family (EN 1090-1/2/3) for execution of steel and aluminium structural components. It provides a risk-based framework under the Construction Products Regulation (CPR) enabling CE marking for load-bearing components in construction works. Primary scope covers fabrication, assembly, and conformity assessment.
Key Components
- **EN 1090-1Conformity assessment, Factory Production Control (FPC), Declaration of Performance (DoP).
- **EN 1090-2/3Technical rules for steel/aluminium (welding, tolerances, corrosion protection, NDT).
- Execution Classes (EXC1-4) based on consequence, service, production categories.
- Certification via Notified Body audits and ongoing surveillance.
Why Organizations Use It
- Mandatory for EU market access and CE marking.
- Reduces liability, ensures traceability, minimizes rework.
- Builds trust with clients, enables high-risk projects.
Implementation Overview
Phased approach: gap analysis, FPC development, welding qualification, NB certification. Applies to fabricators globally targeting EEA; 3-12 months typical, high complexity for EXC3/4.
ISO 28000 Details
What It Is
ISO 28000:2022 is an international management system standard specifying requirements for establishing, implementing, maintaining, and improving a security management system (SMS) focused on supply chain security and resilience. It uses a risk-based, PDCA (Plan-Do-Check-Act) approach to protect people, assets, goods, infrastructure, and information.
Key Components
- Core clauses: context, leadership, planning, support, operation, performance evaluation, improvement.
- Emphasizes risk assessment, security strategies, incident response, supplier controls.
- Aligned with ISO High Level Structure for integration with ISO 9001, 22301, 27001.
- Optional certification via accredited bodies per ISO 28003.
Why Organizations Use It
- Reduces supply chain disruptions, theft, sabotage risks.
- Meets contractual, regulatory drivers (e.g., C-TPAT equivalents).
- Lowers insurance costs, enables trade facilitation.
- Builds stakeholder trust, competitive edge in logistics, manufacturing.
Implementation Overview
- Phased: scoping, gap analysis, risk treatment, deployment, audit, certification.
- Scalable for SMEs to multinationals across industries.
- Involves mapping, training, KPIs, continual improvement.
Key Differences
| Aspect | EN 1090 | ISO 28000 |
|---|---|---|
| Scope | Execution and conformity of steel/aluminium structures | Supply chain security management system |
| Industry | Construction, steel/aluminium fabrication (EU/EEA) | Logistics, manufacturing, all supply chains (global) |
| Nature | Harmonized standard, mandatory CE marking (CPR) | Voluntary management system standard |
| Testing | FPC certification, ITT/ITC, notified body surveillance | Internal audits, management review, optional certification |
| Penalties | Market exclusion, legal liability without CE mark | No legal penalties, loss of certification/trust |
Scope
Industry
Nature
Testing
Penalties
Frequently Asked Questions
Common questions about EN 1090 and ISO 28000
EN 1090 FAQ
ISO 28000 FAQ
You Might also be Interested in These Articles...

Your Compliance Command Center: How Modern Tools Orchestrate Cross-Departmental Adherence
Unlock your compliance command center with modern tools for real-time monitoring, automation & integrations across IT, HR, Legal & Finance. Slash non-compliance

SOC 2 Audit Survival Guide: First 5 Steps to Ace Your Type 2 Audit with Infographic
Ace your SOC 2 Type 2 audit with the first 5 essential steps: evidence collection, auditor tips, red flags from SignWell's experience. Get checklists & infograp

What is DORA and which Requirements does the Standard define?
Discover DORA requirements for info security, strict authority monitoring, and steps to achieve compliance. Build a resilient organization with our detailed gui
Run Maturity Assessments with GRADUM
Transform your compliance journey with our AI-powered assessment platform
Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.
Explore More Comparisons
See how EN 1090 and ISO 28000 compare against other standards