How to Evaluate a Secure Printing Factory for National ID and Passport Tenders

You have a tender deadline, a shortlist of bidders, and a folder of glossy capability decks that all say the same thing: “world-class security printing.” Somewhere in that folder is a factory that can actually produce your national ID cards or e-passport booklets under audit-grade controls — and at least one that cannot. Getting that judgement wrong is not a procurement inconvenience; it is a sovereign risk event. This guide gives buyers a practical, evidence-based method for evaluating a secure printing factory before a national ID or passport award, including the certification tiers that genuinely differentiate suppliers, the site-audit controls worth verifying in person, and the red flags that should end a conversation.

Secure printing factory production floor for national ID cards and passport booklets
Evaluating a secure printing factory is about verifiable controls, not capability decks.

Why a Secure Printing Factory Audit Decides the Tender, Not the Price Sheet

In most government identity programmes, the printed document is the cheapest line item and the most expensive failure. A national ID card may cost a few dollars to produce, but a security breach at the production stage — blank stock leaving the plant, a personalisation database exposed, an unaccounted overrun of security foil — triggers costs that dwarf the contract value: emergency re-issuance, border-control mistrust, parliamentary inquiry, and years of reputational damage to the issuing authority.

This is why experienced buyers treat supplier evaluation as a risk-transfer exercise rather than a price comparison. The question is not “who is cheapest per card” but “whose control environment can I put in front of an auditor, a minister, or a court”. A factory that cannot produce reconciliation records for every sheet of security substrate it consumed last quarter is not a cheaper supplier — it is an unpriced liability sitting on your balance sheet.

Three practical consequences follow for your tender design:

  • Make evidence mandatory, not optional. Ask for certificate numbers, audit scopes and validity dates in the bid response itself, so that unqualified bidders self-select out before evaluation begins.
  • Score the control environment separately from price. Blended scoring lets a weak-security, low-price bid survive to the final round.
  • Reserve the right to audit on site. Reserve it contractually, and use it — including unannounced surveillance visits during production.
Government procurement team reviewing security printing tender documents and audit evidence
Score the control environment separately from price — blended scoring hides weak security.

Certification Tiers: What ISO 14298 and INTERGRAF 15374 Actually Tell You

Almost every bidder will claim to be “ISO certified”. The useful question is which standard, at which level, for which scope, and whether you can verify it independently. For security printing there is one internationally recognised management-system standard: ISO 14298:2021, Graphic technology — Management of security printing processes, now in its second edition (published August 2021, with Amendment 1 issued in 2024). The earlier 2013 edition has been withdrawn, so a certificate still referencing ISO 14298:2013 is a signal that the supplier’s audit cycle has lapsed.

What most buyers miss is that ISO 14298 certification is not a single pass/fail badge. Under the Intergraf certification scheme — the programme run by the European printing federation since 2003 — certificates are issued at distinct levels that correspond to the sensitivity of the documents a plant is cleared to produce. On Intergraf’s public register you will see certificates labelled:

  • ISO 14298 – Central Bank level — the highest tier, associated with banknote and central-bank work.
  • ISO 14298 – Governmental level — the tier relevant to passports, national ID cards, driving licences, visas and civil-registry documents.
  • ISO 14298 – Fundamental level — a baseline tier suitable for lower-risk security print.
  • INTERGRAF 15374 – Secure Supplier — for upstream suppliers of security paper, inks, foils, inlays, laminates and related components rather than for the printer itself.

The practical implication is blunt: a bidder holding a Fundamental-level certificate is not certified for the class of work a passport or national ID tender represents, even though its marketing may simply say “ISO 14298 certified”. Intergraf reports that more than 180 production sites across 58 countries and six continents currently hold its certifications, and every certificate — with its number, issuing audit body, scope wording and expiry date — is published on the Intergraf list of certified companies. Verification therefore takes about two minutes and costs nothing: look the bidder up by name, confirm the level, and confirm that the certificate scope explicitly covers your document type.

Two cautions are worth keeping in mind. First, scope wording matters more than the headline. A certificate scoped to “tax stamps and holographic labels” does not cover passport booklet manufacture, however impressive the level. Second, certification is a floor, not a ceiling — it evidences that a security management system exists and was audited, not that this particular plant, this particular line, and this particular shift will perform on your job. That is what the site audit is for.

ISO 14298 and INTERGRAF certification documents for a security printing supplier
Certificate level and scope wording decide eligibility — not the phrase “ISO certified”.

The Site Audit: Physical and Logical Controls Worth Verifying in Person

A document review tells you what a factory claims. A site visit tells you what it does at 2 a.m. on a Saturday during a peak run. Walk the plant in the direction the material flows — from goods-in through pre-press, printing, personalisation, finishing, packing and dispatch — and test the following controls with your own eyes rather than accepting a slide.

  • Security zoning and access control. Are high-security areas physically separated with controlled interlocks, and are access rights role-based and logged? Ask to see an access log export for a random date and check for shared or generic credentials.
  • Material accountability. Every sheet of security substrate, every metre of holographic foil and every chip inlay should be serialised or batch-controlled, with an unbroken reconciliation from receipt to finished good or destruction. Ask for last quarter’s reconciliation and look at the variance line.
  • Waste and spoilage destruction. Setup waste and rejected personalised documents are the classic leakage path. Require witnessed destruction with signed logs, and verify that the destruction records reconcile against production counts.
  • CCTV coverage and retention. Confirm camera coverage of every high-security zone including waste handling, and confirm the retention period in writing — a system that overwrites in seven days cannot support an investigation.
  • Personnel vetting. Background screening, clearance renewal cycles, contractor and cleaner management, and a documented leaver process that revokes access the same day.
  • Data and personalisation security. Citizen data is the highest-value asset in the building. Look for a certified information-security management system under ISO/IEC 27001:2022, encrypted data transfer, segregated personalisation networks, and defined data-retention and secure-deletion rules.
  • Secure storage and dispatch. Vault or strong-room specification, dual control for stock movements, tamper-evident packing, and a chain-of-custody record that survives the handover to your logistics provider.
  • Business continuity. A documented, tested continuity plan with a named alternate site — not an aspiration in a policy document.

The single most revealing question on any site audit is: “show me the numbers for the last job that went wrong.” A mature security printer will produce the non-conformance record, the root-cause analysis and the corrective action within minutes, because its system is built to surface exceptions. A weak one will tell you nothing has ever gone wrong — which is, in this industry, the least credible sentence a supplier can say.

Auditor inspecting access control, material reconciliation and secure storage inside a security printing plant
Walk the plant in the direction the material flows, and test each control yourself.

Technical Capability: Matching the Factory to Your Document Specification

Certification and security controls establish trust. Technical capability establishes whether the plant can actually build the document you specified. For travel documents this begins with ICAO Doc 9303, the specification set for machine readable travel documents, which is published free of charge by ICAO and governs booklet and card form factors (TD1, TD2, TD3), the machine readable zone, and the logical data structure and public key infrastructure for electronic documents. For card-format credentials, the physical characteristics baseline is ISO/IEC 7810. If a bidder cannot discuss these documents fluently and map each clause to a production step, that is diagnostic in itself.

Beyond the standards, establish precisely which steps happen inside the audited perimeter and which are subcontracted. Outsourcing is not automatically disqualifying, but every outsourced step is a new security boundary, a new chain-of-custody handover and a new party whose certification you must also verify. Map the following against the bidder’s own facilities:

  • Substrate and body material — security paper manufacture or sourcing; card body material selection between polycarbonate, PVC and PETG, which drives document lifetime and laser-engraving capability. Our comparison of polycarbonate vs PVC vs PETG for government ID sets out the trade-offs.
  • Security feature origination — in-house design of guilloche, microtext, UV and IR features, and holographic origination versus bought-in stock designs. Stock holograms offer far weaker protection than an originated, customer-exclusive design.
  • Chip and inlay integration — antenna production, inlay lamination, chip initialisation and key management, and whether the chip platform holds an independent security evaluation.
  • Personalisation — laser engraving, retransfer or inkjet personalisation, biometric image handling, and quality-control sampling rates.
  • Inspection and test — durability and environmental testing, bending and torsion, delamination resistance, and the sample retention policy for dispute resolution.

If your programme also involves EMV or contactless card credentials, the applicable compliance stack widens further; our ICAO, ISO 7810 and EMV compliance checklist maps the standards to procurement questions you can paste directly into a tender document.

Polycarbonate ID card and e-passport booklet with chip inlay, laser engraving and holographic overlay
Map every production step — substrate, origination, inlay, personalisation, test — to the audited perimeter.

Capacity, Continuity and Delivery Risk

National programmes fail on schedule far more often than on specification. A plant that comfortably produces 200,000 cards a month may still collapse under a first-year enrolment surge of two million, and an issuing authority that has already announced a rollout date has very little room to absorb a slipped delivery.

Interrogate capacity with numbers rather than adjectives:

  • Demonstrated versus theoretical throughput. Ask for the highest monthly volume actually shipped in the last 24 months for a comparable document, not the nameplate rating of the machinery.
  • Machine redundancy. How many independent lines can run your job? A single personalisation line is a single point of failure for an entire national rollout.
  • Input lead times. Chip and inlay allocation, security substrate and originated foil often carry the longest lead times in the bill of materials, and they are the items that silently push a launch date.
  • Secure logistics. Who takes custody at the factory gate, under what insurance, with what tracking, and what is the escalation path if a consignment is delayed at customs?
  • Contractual teeth. Service levels with defined turnaround times, escalation paths, liquidated damages for late delivery and explicit financial consequences for a security or data breach.

Timeline realism is a supplier quality in its own right. A bidder who quotes a schedule noticeably shorter than every competitor is not more efficient; they are usually excluding origination, approval cycles or pilot testing. Our overview of a typical smart card manufacturing project timeline is a useful sanity check when you compare bid schedules side by side.

High volume card personalisation lines and secure dispatch packing in an ID document factory
Ask for demonstrated shipped volume and line redundancy, not nameplate capacity.

A Scoring Framework and the Red Flags That Should End a Conversation

To keep evaluation defensible, convert the above into a scored matrix where each claim must be backed by a named artefact. The table below is a starting point you can adapt to your tender’s weighting.

Evaluation areaEvidence to requestDisqualifying finding
CertificationISO 14298 certificate number, level, scope and expiry; entry on Intergraf public registerFundamental level only, expired certificate, or scope excluding your document type
Physical securityZoning plan, access log sample, CCTV retention policyShared credentials, no zoning, retention under 30 days
Material accountabilityQuarterly reconciliation with variance analysis; witnessed destruction logsNo serialisation of security stock; unexplained variance
Data securityISO/IEC 27001 certificate; personalisation network architecture; data-retention policyCitizen data handled on general office network
Technical fitClause-by-clause mapping to ICAO Doc 9303 / ISO 7810; sample documentsCannot discuss the specification without the sales engineer
Capacity24-month shipped volume records; line redundancy; BOM lead timesSingle personalisation line; no evidence of comparable volume
ContinuityTested continuity plan with named alternate sitePlan exists on paper only, never exercised

Alongside the scorecard, treat the following as hard stops rather than negotiating points:

  • Refusal of a site visit, or a visit restricted to the meeting room and a showroom.
  • Vagueness about subcontracting. If a bidder cannot name every third party that will touch your document or your data, it does not control its own supply chain.
  • Reference customers that cannot be contacted, or case studies with no verifiable counterparty. Confidentiality is normal in this sector, but a credible supplier can always arrange a reference call under NDA.
  • Certificates presented as images with no register entry. Public verification exists precisely because certificates are easy to fabricate.
  • Prices materially below the market for the specified feature set. In security printing, an outlier low price almost always signals a substituted substrate, a stock hologram in place of an originated one, or an uncertified subcontractor.

For a broader view of how institutional buyers structure these programmes, see our guides on how professional security printing protects institutions and on high-security ID card procurement.

Supplier evaluation scorecard and sample security documents laid out on a procurement desk
Convert every claim into a named artefact — that is what makes an award defensible.

Frequently Asked Questions

Is ISO 9001 enough for a security printing tender?

No. ISO 9001 addresses quality management and says nothing about material accountability, personnel vetting, secure destruction or chain of custody. For document-of-value work it should be treated as a baseline hygiene factor that sits alongside ISO 14298 and, where citizen data is processed, ISO/IEC 27001.

How do I verify a supplier’s ISO 14298 certificate independently?

Search the supplier’s legal entity name on Intergraf’s public list of certified companies. Each entry shows the certification level, the certificate number, the auditing body, the validity dates and the scope of work covered. Confirm all five fields, and confirm that the certified entity name matches the legal entity signing your contract — not a parent, affiliate or trading name.

Should we require production in a single country or allow multi-site manufacture?

Multi-site manufacture can improve continuity, but each site must be separately certified and separately audited, and the chain of custody between sites must be documented. Never accept a single certificate as covering an unnamed network of plants; certification is granted per production site.

What should a pre-award sample run actually test?

Specify a run that exercises the full process rather than the pretty parts: originated security features, chip encoding and read verification, personalisation legibility, durability and environmental testing, and — critically — the accountability paperwork. Request the reconciliation and destruction records for the sample run itself; how a supplier documents 500 samples predicts how it will document five million documents.

How far in advance should we start supplier evaluation?

For a national programme, begin market engagement and site auditing well before the tender closes. Origination of exclusive security features, chip allocation and pilot testing routinely consume months before the first production document exists, and compressing that phase is the most common cause of a missed launch date.

Next Step: Put a Factory Under Audit Before You Put It Under Contract

GENUINE has manufactured security paper, holographic overlays, smart cards, RFID credentials and certificate documents for institutional and government-adjacent programmes since 2005. If you are preparing a national ID, e-passport, driving licence or civil-registry tender, we can support your evaluation in three concrete ways: a documented capability pack mapped clause by clause to your specification, physical samples produced to your feature set for durability and encoding testing, and a factory audit visit arranged at your convenience.

Send us your draft specification or tender schedule and we will return a technical response and a sample plan. If you are still shaping requirements, start with our guide to passport printing for the document-side considerations that most often get written into a specification too late to change.

Table of Contents

This is the heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

More Posts

*By submitting this form, you agree to our Privacy Policy. We respect yourprivacy and will not share your information.

Scroll to Top
Request A Qute