Obtaining AEOS (Authorized Economic Operator – Security) certification requires more than just technical measures: it demands structured security governance, led by a competent individual recognized by customs authorities. Many companies find themselves unprepared for this requirement, lacking the internal expertise needed to coordinate risk assessments, operational procedures, and regulatory compliance.
The Union Customs Code (UCC) precisely defines who must handle security and what responsibilities they must assume. Understanding these obligations and choosing the most suitable organizational solution can make the difference between obtaining authorization quickly and facing a long, complex process.
Who must handle security according to the Customs Code
Article 28, paragraph 1, letter h) of the Implementing Regulation (IR) establishes that every applicant for AEOS authorization must designate a contact person competent in supply chain security matters. This figure acts as the official interface between the company and customs authorities.
It is important to clarify that this role concerns exclusively customs and IT security; it does not coincide with the workplace safety manager required by Legislative Decree 81/08, which operates in a completely different regulatory framework.
The regulations allow for flexibility: the manager can be an internal employee or a formally appointed external professional, provided they demonstrate full knowledge of company procedures and adequate technical competence.
What the Self-Assessment Questionnaire (SAQ) requires
Section 6 of the SAQ, dedicated to security requirements, asks to document who protects company systems and how defense measures are coordinated. Customs authorities verify that this person is capable of:
- Conducting and updating the Risk Assessment: preparing a documented assessment of specific threats to the supply chain and IT systems.
- Defining and monitoring security procedures: managing physical and logical access controls, data protection, and the security of sensitive areas.
- Managing security incidents: coordinating investigations, communications, and corrective actions in the event of breaches or intrusions, following structured monitoring and incident response procedures.
- Verifying business partners: ensuring that suppliers and subcontractors comply with the security standards required by AEOS.
These responsibilities require skills that go beyond ordinary IT management: knowledge of Risk Assessment, regulatory compliance, and security management according to international standards such as ISO/IEC 27001 is necessary.
The Virtual CISO as a solution for AEOS governance
For many companies, hiring a full-time Chief Information Security Officer represents an investment disproportionate to their size or organizational complexity. The Virtual CISO model offers a strategic alternative that fully meets regulatory requirements:
- Certified competence: the Virtual CISO brings consolidated experience in Risk Management, compliance, and security management, satisfying the competence requirement demanded by Customs.
- Multi-site coordination: in the presence of multiple facilities or offices, it ensures consistency in security measures and simplifies the customs audit process.
- Economic efficiency: provides high-level governance without the costs of an internal executive, while keeping full operational control with the company.
- Operational flexibility: intervenes with the necessary frequency, adapting to the specific needs of the certification path and the maintenance of the authorization.
The Virtual CISO can prepare all documentation required by the SAQ, coordinate the implementation of security measures, and act as a technical point of contact during inspection visits by customs authorities. Furthermore, they can supervise specialized technical activities such as network infrastructure penetration tests required to demonstrate the resilience of critical systems.
Frequently asked questions about AEOS security governance
- Is it mandatory to appoint a security manager to obtain AEOS?
- Yes. Article 28, paragraph 1, letter h) of the Implementing Regulation expressly requires the designation of a contact person competent in security, who acts as an interface with the customs administration.
- Must the security manager necessarily be an internal employee?
- No. The regulations allow the function to be performed by an external entity, provided they are formally appointed and demonstrate full knowledge of the company’s security procedures. This flexibility makes the use of a Virtual CISO possible.
- How can a Virtual CISO concretely support AEOS requirements?
- The Virtual CISO defines the security framework, coordinates risk analysis, prepares the documentation necessary for the Self-Assessment Questionnaire (Section 6), and acts as a technical point of contact during inspection visits by customs authorities.
- What documents must the security manager produce or supervise?
- The manager must supervise the production of the documented Risk Assessment, security plans for each site, access management procedures, incident logs, and security training plans for personnel.
- Does outsourcing security relieve the company of responsibilities toward Customs?
- No. Even when entrusting technical activity to a Virtual CISO or external consultants, the economic operator always remains responsible for compliance with AEOS criteria before customs authorities. Outsourcing concerns execution, not final responsibility.
- What technical skills must the AEOS security manager possess?
- They must know Risk Assessment methodologies, IT and physical security management, customs regulations, and international standards such as ISO/IEC 27001. They must also be able to coordinate external suppliers and manage communication with authorities.
Security governance represents a fundamental pillar for obtaining and maintaining AEOS certification. The Virtual CISO model offers specialized competence and operational flexibility, but the final responsibility for compliance with the criteria always remains with the economic operator requesting the authorization.
Related insights
- AEO certification and cybersecurity: requirements and compliance path
- System and application security for AEOS certification
- Vulnerability management for AEOS certification
- AEOS and business partner security in the supply chain
- Cybersecurity training for Authorized Economic Operators
Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.
Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.
Already know what you need? Explore our services:
- Vulnerability Assessment
- Network Penetration Testing
- Web Application Penetration Testing
- Mobile Application Security Testing
- Ethical Hacking
- Training
And much more. Protect your company with the best cybersecurity experts!
