EN 1090 vs ISO 28000
EN 1090
European standard for structural steel/aluminium execution and CE marking
ISO 28000
International standard for supply chain security management systems.
Quick Verdict
EN 1090 mandates CE marking for structural steel/aluminium via FPC and execution classes for EU construction market access. ISO 28000 provides voluntary security management for global supply chains. Fabricators choose EN 1090 for legal compliance; logistics firms adopt ISO 28000 for resilience.
EN 1090
Execution of steel and aluminium structures
Key Features
- Risk-based Execution Classes (EXC1-EXC4) scaling requirements
- Mandatory Factory Production Control (FPC) certification
- Enables CE marking for EU market access
- Comprehensive welding quality via ISO 3834 alignment
- Full material traceability and NDT inspection regimes
ISO 28000
ISO 28000:2022 Security Management Systems Requirements
Key Features
- Risk-based supply chain security management framework
- PDCA cycle for continual improvement and resilience
- Scalable to all organization sizes and industries
- Integrates with ISO 9001, 22301, 27001 standards
- Supplier and third-party security governance controls
Detailed Analysis
A comprehensive look at the specific requirements, scope, and impact of each standard.
EN 1090 Details
What It Is
EN 1090 is a harmonized European standard family (EN 1090-1/2/3) for execution of steel and aluminium structural components. It provides a risk-based framework under the Construction Products Regulation (CPR) enabling CE marking for load-bearing components in construction works. Primary scope covers fabrication, assembly, and conformity assessment.
Key Components
- **EN 1090-1Conformity assessment, Factory Production Control (FPC), Declaration of Performance (DoP).
- **EN 1090-2/3Technical rules for steel/aluminium (welding, tolerances, corrosion protection, NDT).
- Execution Classes (EXC1-4) based on consequence, service, production categories.
- Certification via Notified Body audits and ongoing surveillance.
Why Organizations Use It
- Mandatory for EU market access and CE marking.
- Reduces liability, ensures traceability, minimizes rework.
- Builds trust with clients, enables high-risk projects.
Implementation Overview
Phased approach: gap analysis, FPC development, welding qualification, NB certification. Applies to fabricators globally targeting EEA; 3-12 months typical, high complexity for EXC3/4.
ISO 28000 Details
What It Is
ISO 28000:2022 is an international management system standard specifying requirements for establishing, implementing, maintaining, and improving a security management system (SMS) focused on supply chain security and resilience. It uses a risk-based, PDCA (Plan-Do-Check-Act) approach to protect people, assets, goods, infrastructure, and information.
Key Components
- Core clauses: context, leadership, planning, support, operation, performance evaluation, improvement.
- Emphasizes risk assessment, security strategies, incident response, supplier controls.
- Aligned with ISO High Level Structure for integration with ISO 9001, 22301, 27001.
- Optional certification via accredited bodies per ISO/IEC TS 17021-8.
Why Organizations Use It
- Reduces supply chain disruptions, theft, sabotage risks.
- Meets contractual, regulatory drivers (e.g., C-TPAT equivalents).
- Lowers insurance costs, enables trade facilitation.
- Builds stakeholder trust, competitive edge in logistics, manufacturing.
Implementation Overview
- Phased: scoping, gap analysis, risk treatment, deployment, audit, certification.
- Scalable for SMEs to multinationals across industries.
- Involves mapping, training, KPIs, continual improvement.
Key Differences
| Aspect | EN 1090 | ISO 28000 |
|---|---|---|
| Scope | Execution and conformity of steel/aluminium structures | Supply chain security management system |
| Industry | Construction, steel/aluminium fabrication (EU/EEA) | Logistics, manufacturing, all supply chains (global) |
| Nature | Harmonized standard, mandatory CE marking (CPR) | Voluntary management system standard |
| Testing | FPC certification, ITT/ITC, notified body surveillance | Internal audits, management review, optional certification |
| Penalties | Market exclusion, legal liability without CE mark | No legal penalties, loss of certification/trust |
Scope
Industry
Nature
Testing
Penalties
Frequently Asked Questions
Common questions about EN 1090 and ISO 28000
EN 1090 FAQ
ISO 28000 FAQ
You Might also be Interested in These Articles...

The Tool Landscape for Reaching and Maintaining ISO 27701 Compliance
Discover the top tools for ISO 27701 compliance. Compare functionality, complexity, costs, and benefits to choose the best solution for your privacy program. Ac

Decoding Tomorrow's Regulations: How Advanced Compliance Tools Predict and Prepare for Future Shifts
Advanced compliance tools use AI, analytics & real-time monitoring to predict regulatory shifts, cut non-compliance costs 3x, and ensure audit readiness. Stay p

Practical Implementation Blueprint for Regulation S-K Item 106: Cybersecurity Governance and Risk Management Disclosures in 10-Ks
Step-by-step guide for Item 106 cybersecurity disclosures in 10-Ks: risk management, board oversight, Inline XBRL templates (Dec 2024 compliance). Templates for
Run Maturity Assessments with GRADUM
Transform your compliance journey with our AI-powered assessment platform
Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.
Explore More Comparisons
See how EN 1090 and ISO 28000 compare against other standards