←  Back to the Hall
C-TPAT · U.S. Customs & Border Protection

Five steps stand between your suppliers and the border. Can you run them?

As of the Strengthening Customs Enforcement executive order signed June 3, 2026, C-TPAT — directly or through a CTPAT-validated broker — is now a practical requirement to import. And C-TPAT isn't about your security, it's about your suppliers'. We run the five steps CBP requires, on every supplier, so your team doesn't have to.

Show me my gaps
8 suppliers · 15 days · no credit card
Certification deadline
Nov 30, 2026
00
Days
00
Hrs
00
Min
Under the June 3, 2026 executive order, foreign importers of record have ~180 days to be CTPAT-validated or file entries through a CTPAT-validated and licensed broker — roughly Nov 30, 2026.
0
Doing this by hand
0
Organizations assessed
0
Assessments completed
0
C-TPAT · PIP · AEO success
Trusted across three decades of supply chains

Has keeping your supply chain compliant become a full-time job on top of your full-time job?

Your suppliers are exhausted. Questionnaire fatigue is real. And every time they push back, it lands on you.

It's not about us. It's about you.

C-TPAT looks like a security checklist. It's a behavioral audit. A validator rarely fails you on a missing fence, they fail you on the distance between what a supplier wrote on a form and what actually happens on the floor: at the end of a double shift, on the load that's already late, when the trained manager is away.

That distance has a name: the human factor. Not negligence, but people doing their best in moments no procedure prepared them for. It hides in the three places almost no assessment looks:

01
The sub-supplier you never mapped.
02
The process that works on paper but not under pressure.
03
The new hire onboarded after the busy season, not before.

A form can't see a moment like that. A person under pressure can't be audited by a questionnaire. That's where every breach actually begins, and it's exactly what we built XFACTOR to walk into, supplier by supplier, and close before it reaches your border.

The C-TPAT 5-Step Risk Assessment

Here's exactly what CBP requires.

Flip each step. Tick the boxes your team can honestly do today, for every supplier. Watch your exposure.

Your live exposure
15
of 15 checks still unmet

You can complete 0 of 15.
A validator will find the other 15.

These five steps were written for a customs officer, not a procurement team with a day job. Run your 8 highest-risk suppliers and we'll surface every gap they'd find, in days, and hand you the report.

Show me my real gaps

And the gap is already moving.

One supplier who won't be assessed. One validation that lands before you're ready. One client who asks for your C-TPAT status and doesn't wait for the answer.

When budgets tighten, security is the first thing companies cut, the one thing protecting the revenue.

more likely to be pulled for security inspection without C-TPAT (U.S. CBP)
$200M
exposure for an uncertified importer: 20,000 shipments at $10K a day
Waiting is the most expensive thing you can do.
WHERE C-TPAT ACTUALLY HURTS

Five places C-TPAT puts you on the hook.
Five parts of XFACTOR that close them.

C-TPAT does not ask whether you are secure. It makes you answer for every supplier that touches your freight. Here is what that exposes, and exactly how we handle each one.

You cannot see your real cargo flow.
Cargo MappingAssessing your suppliers maps every route, carrier, and sub-supplier you never knew was there. That data is leverage: a full view of your chain to protect profitability, and the power to pivot, amalgamate, or reform supply chains by seeing what the numbers actually mean to you.
A questionnaire cannot catch the moment a breach begins.
The live assessmentEach supplier walks cinematic scenarios with Morpheus, scored on how they actually respond, not on a form they fill in to look good.
You do not know which suppliers actually expose your border.
Risk IntelligenceEvery supplier geo-pinned by risk on one live map, with concentration risk and the gaps a spreadsheet would never show, surfaced for you.
When CBP asks how you know, a score will not answer.
The 5-Step Master ReportEvery supplier assessed against all 11 MSC areas and pulled into one validator-ready evidence package. The exact thing CBP asks to see.
A gap with no owner never closes.
The Plan of ActionEvery finding becomes a corrective action with an owner, a deadline, and a supplier signature. The gap gets closed, and proven closed.

Everyone else hands you a map.
We hand you a closed gap.

The other platforms
-
The rating platforms score your supplier and walk away. A medal, not a fix.
-
The mapping tools show you where the risk sits. Knowing where the leak is doesn't stop the water.
-
A static PDF, filed once a year, that a validator has already seen a hundred times.
XFACTOR VERIFIED
We run the actual CBP 5-step, then assess, find, correct, and get your supplier to SIGN.
The gap doesn't get catalogued. It gets closed, and proven closed.
A living Master Risk Assessment Report, the exact evidence package validation asks for.
Built by the assessor who has run this by hand for 30 years. Not a logo wall.

Not a dashboard. A verdict.

This is what your suppliers walk and what your board sees, every supplier scored, every gap tracked to a signature.

app.xfactorverified.com / intelligenceLIVE
XFACTOR VERIFIED cargo mapping: every supplier geo-pinned by risk on a live globe
Every supplier, geo-pinned by risk
Scored live, not surveyed
Intelligence map
Your whole chain, scored on one screen.
A glimpse, not a blueprint. The full system is what your suppliers walk, not what your competitors copy.

What if one assessment handled all of it, without spending a fortune, without the manual work, and without chasing a single supplier?

From your exposure to verified.

01
Drop in your supplier list. Morpheus maps it, no spreadsheet wrangling.STEP 1
02
Each supplier runs the assessment as cinematic scenarios, in their own language, scored against all 11 MSC areas.STEPS 2 & 3
03
Every gap becomes a finding; every finding a corrective action plan with an owner and a deadline.STEP 4
04
The whole process documented, refreshed annually, validator-ready.STEP 5
05
Your supplier earns a verified CF score and designation. You get the Master Risk Assessment Report.DONE
VERIFIED
5 steps · closed
Found. Corrected. Signed.
Questions you would ask on a sales call

There is no sales call. So here are the answers, straight.

8 questions across two themes: the 15-day free trial, and C-TPAT itself. Straight answers, no hedging.

The free trial

Yes. Your first 8 suppliers are completely free for 15 days. No credit card, no sales call, no contract required. We assess them with the same methodology a CBP validation uses. If we do not surface a gap worth more than the ten minutes it takes to start, you have lost nothing. We run it free because once you see what the platform finds in 15 days, the conversation about the rest of your chain is easy.

Because the result is the sales pitch. We have done this work 500,000 times by hand. We already know there is a gap in your chain. Running 8 of your suppliers free for 15 days lets the platform prove it to you directly, faster than any demo ever could. You get real findings on real suppliers. We get a client who has already seen the value.

No card, no contract, no commitment. You drag your supplier list in, Morpheus maps it, and the assessments run. The 15-day trial clock starts the moment your first supplier receives their invite. If you decide to assess the rest of your chain after the trial, that is when pricing comes in, and it is published on the site. No sales call required.

Every supplier in the 15-day trial goes through the full intake: email verification, address validation, and watchlist screening against the US Consolidated Screening List (OFAC, BIS, DDTC). Then each supplier receives the cinematic scenario assessment, narrated by Morpheus, behaviourally scored. You get findings, gap analysis, and a Corrective Action Plan for every gap found. The only thing gated behind a paid plan is assessing more than 8 suppliers and accessing the full Master Risk Assessment Report for your entire chain.

For you, setup is minutes. You upload your supplier list and Morpheus handles the intake: email verification, address check, watchlist screening, and tier assignment. Suppliers typically complete their scenario assessment in 20 to 40 minutes. The trial window is 15 days, and most teams see findings well before the midpoint. You do not reformat a spreadsheet and you do not chase anything manually.

No. The platform handles outreach automatically. Once you upload your list, Morpheus sends each supplier their assessment invitation, follows up with a Day 3 nudge and a Day 7 nudge if they have not responded, and tracks completion status in your dashboard in real time. You see who has finished, who is in progress, and who has not opened it yet, without sending a single email yourself.

About C-TPAT

C-TPAT is a trusted-trader certification. Importers and the partners in their international supply chain pursue it to earn expedited border processing and fewer inspections, and increasingly because their own customers now require it. To become certified, you complete and document the 5-step risk assessment, then pass CBP's validation. If your suppliers move goods across the US border on your behalf, their security is part of what your certification stands on.

Under the Strengthening Customs Enforcement executive order signed June 3, 2026, foreign importers of record have roughly 180 days — about November 30, 2026 — to be CTPAT-validated or to file entries through a CTPAT-validated and licensed broker, alongside a new good-standing requirement and a 50% minimum penalty floor for violations. Validation is not a form you file. You complete the 5-step risk assessment, document it, and pass CBP's review. The clock is already moving, and if each supplier takes about two weeks to assess, most of your runway is gone before the date.

The platform is built on CBP's own published 5-Step Risk Assessment methodology, the same framework a C-TPAT validation auditor walks through. The 5 assessment steps, the Minimum Security Criteria coverage, the corrective action documentation, the signed evidence package: every piece is designed to survive a real CBP review, not just produce a good-looking PDF. The founder has a 20-year, zero-failure record on C-TPAT and PIP validations. The F.F. Soucy 2009 CBP Tier-II validation letter is in the reference archive.

That is the signal. A supplier who refuses a documented security assessment is not a supplier you want crossing the border on your behalf. The platform flags non-responders, documents the outreach attempts, and surfaces them as a high-risk gap in your Master Report. For C-TPAT validation purposes, documented refusal and your response plan is evidence that you identified the risk. Refusing to assess is a finding in itself.

8 suppliers · 15 days · free

Run your 8 highest-risk suppliers through the full C-TPAT 5-step. Free for 15 days.

See every gap within your 15-day trial window, not the months a consultant takes.
No sales call. No credit card. No contract. Trial starts when your first supplier gets their invite.
Drag your list in. Morpheus does the mapping. You reformat nothing.

If we don't surface a gap worth more than the ten minutes it takes to start, you've lost nothing.

Show me my gaps
Founder
30 YEARS · 44,000 ORGANIZATIONS · 500,000 ASSESSMENTS · 100% SUCCESS ON C-TPAT, PIP & AEO.
Built by the expert who has spent a career inside these programs, for the teams who live them.
The XFACTOR family · zero to hero on C-TPAT

One program. Four products walking you there.

Every product below works on its own — or as a section inside your CommandCenter. Same service, two homes. This is the road from zero to hero on C-TPAT.

Command

Command the program

Run C-TPAT end to end inside XFACTOR COMMANDCENTER: your security profile answered once in your own voice, department-specific training with real testing, the security committee rhythm, procedures and forms kept current against the regulators, monthly self-audits, and the annual internal assessment — through six department cockpits and one calendar. Carry more than one program, and one answer publishes to every program that asks the same question.

See XFACTOR COMMANDCENTER →
Assess

Assess your suppliers

XFACTOR VERIFIED runs the 5-Step risk assessment on every supplier you answer for under C-TPAT — regulatory certificates tracked, whole supply chains mapped, and a 300-to-600-page master report that turns supplier risk into signed, audit-ready proof. Never a per-supplier fee.

See XFACTOR VERIFIED →
Be ready

Be ready for your government review

When your officer review comes, XFACTOR VALIDATED has already made you ready: a mock officer visit per department from a question bank built on real reviews, a prep playbook, and — after the visit — a response engine that turns the officer’s actual findings report into corrective actions and drafted responses in your own approved language. Live inside CommandCenter today, standalone in August.

See XFACTOR VALIDATED →
See further

See further

XFACTOR VANTAGE is the intelligence layer over everything the family sees — ESG recommendations, automation recommendations, and the stats flywheel. Coming soon; no promises before it’s real.

A first look at VANTAGE →
Supply chain security · Built by a 30-year expert

Your supply chain has a gap
you haven't seen yet.

8 suppliers. 15 days. No credit card. Run the real CBP 5-step on your highest-risk suppliers and see exactly what a validator would find first.

30
Years
44,000
Organizations
300,000
Trained

Mandy-Lynn Aitken · 30 years · C-TPAT · PIP · Bill S-211 · 44,000+ organizations assessed

The XFACTOR Risk Brief

Weekly C-TPAT, Bill S-211, and ESG regulatory intelligence for importers.

Show me my gaps →