| name | c-tpat-security-profile |
| title | C-TPAT Security Profile |
| description | Drafts a U.S. C-TPAT Security Profile for CBP submission covering physical, personnel, procedural, conveyance, and IT security domains. Use when preparing C-TPAT enrollment, certification, validation, or recertification profiles, or assembling a CBP-ready security narrative. Trigger: C-TPAT, CBP security profile, supply chain security, trusted trader, customs validation. |
| author | CaseMark |
| author_url | https://github.com/CaseMark/skills/tree/main/skills/legal/c-tpat-security-profile |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | us |
| practice | trade |
| language | en |
C-TPAT Security Profile
Produces a CBP-ready C-TPAT Security Profile grounded in documented, verifiable practices aligned with CBP Minimum Security Criteria.
Gather Inputs
- Corporate identifiers — legal name, EIN, DUNS, HQ, facility list, C-TPAT account/tier if enrolled
- Supply chain map — roles (importer/broker/forwarder), trade lanes, origin countries, products, volume
- Security governance — org chart, C-TPAT coordinator, reporting lines, authority
- Policies & SOPs — physical, personnel, procedural, conveyance, IT security procedures
- Risk assessment artifacts — methodology, frequency, recent assessments, mitigation plans
- Training records — onboarding, refresher, role-based, attendance logs
- Business partner vetting — questionnaires, audits, certifications, corrective actions
- Incident logs — security events, seal discrepancies, investigations, remediation
- Validation history — prior CBP validations, findings, corrective actions
Profile Sections
Draft each section using only verifiable, current practices. Never use future-tense promises.
1. Document Control
Version, date, preparer, approver, confidentiality marking.
2. Company Overview & Eligibility
Legal name, EIN, DUNS, HQ, facilities, C-TPAT account/tier, supply chain role, import volume, primary origins, product categories.
3. Governance & Organization
- C-TPAT coordinator — name, title, authority, reporting line
- Security team roles — physical, IT, compliance, operations
- Executive sponsor and review cadence
4. Risk Assessment Method
Framework, frequency, trigger events, scope, risk scoring, documentation approach.
5. Physical Security