BlackLeafwatch the watchmen
CTPAT trusted-trader security enforcement

CBP hasn't published a strategic plan for CTPAT since 2004.

Summary

The Customs Trade Partnership Against Terrorism lets vetted importers and carriers move goods with fewer inspections in exchange for meeting security standards. The premise only holds if CBP actually tracks who breaks that bargain and keeps the program's own planning current. Two GAO reports, almost nine years apart, found CBP has struggled with both: a 2017 report found the tool CBP used to measure whether members were actually getting the benefits it advertised couldn't be relied on, and a 2026 report found CBP still doesn't consistently investigate or act on security incidents involving participants -- and hasn't published the 5-year strategic plan the SAFE Port Act requires for the program since November 2004.

By Marcus Aurelius · July 12, 2026

The Customs Trade Partnership Against Terrorism, or CTPAT, lets importers, carriers, and other supply-chain firms trade security commitments for faster, lighter-touch treatment at the U.S. border. The bargain rests on two things has to do: verify that members are actually meeting the security standards, and keep planning the program the way federal law requires. In February 2017, found couldn't reliably measure whether members were getting the benefits it publicized, because the data behind its own benefits-tracking tool didn't hold up. In January 2026 -- almost nine years later -- found still doesn't consistently investigate or enforce against participants involved in security incidents, and has missed three separate statutory planning requirements, including a 5-year strategic plan not published since November 2004.

2017: a tool CBP couldn't trust

CTPAT members are supposed to get concrete benefits for their security commitments -- lower cargo-examination and hold rates, faster processing. built a tool called the Dashboard in 2012 to track whether that was actually happening. 's review found the Dashboard's data could not be relied on for accurately measuring those benefits -- meaning had likely been working off questionable data for the tool's entire life up to that point, with no way to assure members they were consistently getting what the program promised. also found CTPAT's field offices, lacking standardized headquarters guidance, had each developed their own procedures for tracking required security validations. recommended standardize that field-office guidance and fix the Dashboard's data problems. concurred with both and, rather than repair the existing tool, decided to scrap it and build a replacement by the end of June 2017.

2026: the enforcement side, and a planning requirement CBP wasn't tracking

By August 2025, CTPAT had grown to almost 11,000 participants -- 30% importers, 18% U.S./Canada highway carriers, 18% foreign manufacturers, the rest other entity types. Over fiscal years 2020 through 2024, about 480 of them (4%) were involved in roughly 2,200 security incidents in the cargo supply chain -- about 1% of all 215,000 security incidents recorded in that period, just under half of them drug-related. The share is small. What found troubling was what happened after: did not consistently investigate those incidents or take enforcement action, sometimes documenting a decision to do neither without explaining why. In one case, took no action against a participant involved in a 2021 incident -- that same participant went on to rack up dozens more incidents before it was finally suspended two years later.

A small share of participants, an even smaller share of incidents
CTPAT participants and security incidents, fiscal years 2020-2024
CTPAT participants involved in a security incident
4.4%
Those incidents' share of all CBP-recorded incidents
1%
Source: GAO-26-107893
View data as table
Share of CTPAT participants involved in one or more security incidents (480 of almost 11,000), and those incidents' share of all roughly 215,000 security incidents CBP recorded in the cargo supply chain, fiscal years 2020-2024
CTPAT participants involved in a security incident4.4%
Those incidents' share of all CBP-recorded incidents1%

then checked CTPAT against three planning requirements Congress wrote into the SAFE Port Act. had not annually reviewed and updated minimum security requirements for every industry type -- its 2020 update, the program's first since the original 2001 standup, hadn't touched rail-carrier requirements since, and couldn't document reviews for other industry types despite officials' claims that they occurred. had no annual workload plan matching its resources to projected caseload; officials told they weren't even aware this specific requirement existed, confusing it with a different revalidation-planning rule. And had not published the 5-year strategic plan, with outcome-based goals, that the law requires for the program -- not since November 2004. told in May 2025 that senior officials had directed CTPAT staff not to produce one, on the theory it would be folded into a broader field-operations plan instead.

Years overdue for the SAFE Port Act's required 5-year strategic plan
Required plan-refresh cycle versus time elapsed since CTPAT's last strategic plan (Nov. 2004)
SAFE Port Act's required update cycle (years)
5
Years elapsed since the last strategic plan
21.2
Source: GAO-26-107893
View data as table
The SAFE Port Act's required 5-year plan-refresh cycle compared with the years elapsed since CTPAT's last published strategic plan, November 2004
SAFE Port Act's required update cycle (years)5
Years elapsed since the last strategic plan21.2

made six recommendations: build a plan and assign responsibility for the completeness of security-incident data; rewrite enforcement guidance with documented, risk-based decision criteria; fix the accuracy of enforcement-action data in the CTPAT Portal; create a formal mechanism for the annual security-requirement reviews the law requires; write internal policy for the annual workload plan; and produce the overdue 5-year strategic plan. concurred with all six. On the workload-plan recommendation, 's first draft response cited the wrong statutory requirement as already satisfied; after clarified which SAFE Port Act provision it meant, concurred with the corrected recommendation and committed to a comprehensive annual work plan.

Years since CBP published a strategic plan for CTPAT
21
roughly 4.2 times the SAFE Port Act's own required 5-year plan-refresh cycle -- last published November 2004
Share of CTPAT participants involved in a security incident, FY2020-2024
4%
480 of almost 11,000 participants -- yet CBP did not consistently investigate or act on those incidents
SAFE Port Act statutory requirements GAO found CBP had not met
3
annual security-requirement reviews, an annual workload plan, and the 5-year strategic plan -- all missed

The takeaway

  • CTPAT's central promise -- that vetted status is checked and enforced -- has a documented enforcement gap. found does not consistently investigate or act on security incidents involving participants, including one case where a participant already involved in a 2021 incident went unpunished through dozens more before a suspension two years later.
  • The program's own required planning has lapsed for two full decades. has not published the SAFE Port Act's mandatory 5-year strategic plan since November 2004 -- 21 years, or roughly 4.2 of the plan's own required cycles, and counting.
  • This isn't a one-time lapse -- found data-reliability problems in this program nearly a decade earlier, too. In 2017, found couldn't verify whether members were actually receiving the benefits the program advertised, because the tracking tool's own data couldn't be trusted.

Findings on the 2017 data-reliability gap are from -17-84, 'Supply Chain Security: Providing Guidance and Resolving Data Problems Could Improve Management of the Customs-Trade Partnership Against Terrorism Program' (February 8, 2017), read in full via an archived copy after the current gao.gov asset URL blocked direct access. Findings on the 2026 enforcement and planning gaps are from -26-107893, 'Supply Chain Security: Actions Needed to Improve Management of the Customs Trade Partnership Against Terrorism Program' (January 27, 2026), read directly in full. The two reports are part of the same recurring audit series on CTPAT, about 8.97 years apart, examining different facets of the same program -- member-benefits data reliability in 2017, incident-enforcement consistency and statutory planning compliance in 2026 -- and are not presented here as tracking the same finding over time.

Sources(2) ▾
  • U.S. Government Accountability Office, Supply Chain Security: Providing Guidance and Resolving Data Problems Could Improve Management of the Customs-Trade Partnership Against Terrorism Program (2017-02-08)-17-84, part of a recurring audit series on the Customs Trade Partnership Against Terrorism (CTPAT) program -- the member-benefits-data facet, finding couldn't reliably measure whether members received the benefits the program promised. Distinct from doc-gao26-107893 (the security-incident-enforcement facet, about 9 years later). Direct gao.gov fetch returned HTTP 403; fetched via an existing Wayback capture. gao.gov · original document
  • U.S. Government Accountability Office, Supply Chain Security: Actions Needed to Improve CBP Management of the Customs Trade Partnership Against Terrorism Program (2026-01-27)-26-107893, the next report in the same recurring CTPAT audit series -- the security-incident-data and enforcement-consistency facet, plus SAFE Port Act statutory-planning compliance, about 9 years after doc-gao17-84. Fetched directly from files.gao.gov (HTTP 200); a Wayback capture was found to already exist at read time. gao.gov · original document
Weekly digest: the most-read systems, in brief. Mondays.

Comments

Always open. Logged-in readers can annotate paragraphs in place.

Loading comments…
or log in to comment under your account