Suite of ISO standards defining how medicinal products are identified, classified, and exchanged across regulatory submissions globally.
Why it mattersEMA and FDA increasingly require IDMP-aligned product master data. Future regulatory submissions (eCTD v5+) will require IDMP.
Life Sciences (Pharma & MedTech)
Includes substance, strength, dose form, presentation, manufacturer, regulatory status, and regional authorization details — all with managed identifiers.
Why it mattersEMA SPOR (Substance, Product, Organisation, Referential) compliance is now expected. FDA following with similar identifier requirements.
Life Sciences (Pharma & MedTech)
International standard for substation automation and protection. Defines logical nodes, GOOSE messaging, sampled values, and substation configuration language (SCL).
Why it mattersDe-facto standard for modern substation automation. Required by most utility customers for new substation equipment.
Energy & Utilities
Defines semantic objects for grid topology (substations, lines, transformers), customers, measurements, and operations. Foundational for utility information sharing.
Why it mattersRequired for EMS/DMS interoperability and ISO/RTO market participation. De-facto utility semantic standard.
Energy & Utilities
Standard data exchange model for electric utility operations. Defines XML/RDF schemas for grid topology, assets, customers, measurements, and operations.
Why it mattersDe-facto standard for grid data integration. Required for modern EMS/DMS interoperability and ISO/RTO market participation.
Energy & Utilities
Security extensions for power system protocols including IEC 61850, ICCP, IEC 60870-5. Specifies authentication, encryption, intrusion detection.
Why it mattersIncreasingly required for new deployments. Foundation for trusted grid operations.
Energy & Utilities
Multi-part standard covering security for industrial control systems. Defines security levels (SL1-SL4), security zones, and conduits between zones.
Why it mattersDe-facto standard for OT/IT security in manufacturing. Required by some industrial customers and increasingly by regulators.
Industrial Manufacturing
Identification and authentication, use control, system integrity per IEC 62443 security levels (SL1-SL4). Required for ICS/SCADA environments.
Why it mattersDe-facto standard for OT security. Increasingly required by regulators and enterprise customers.
Industrial Manufacturing
Identification, authentication, use control aligned with security levels. Includes MFA for critical functions.
Why it mattersDe-facto standard for OT security in utilities. Required by enterprise customers and increasingly regulators.
Energy & Utilities
Logical and physical segmentation of OT networks into security zones based on Purdue Reference Model (Levels 0-5) with controlled conduits between zones.
Why it mattersRequired for IEC 62443 certification. Reduces blast radius of security incidents. Standard requirement for Critical Infrastructure operators.
Industrial Manufacturing
Multi-part standard defining models and terminology for integration between enterprise (ERP) and control systems (MES, SCADA). Defines hierarchy levels (L0 sensors → L4 ERP) and B2MML XML schemas.
Why it mattersDe-facto standard for OT/IT integration. Required for serious manufacturing data architectures. Foundation for ISA-95 software products.
Industrial Manufacturing
XML schemas for ISA-95 information models, used for ERP-MES integration. Defines product, equipment, material, personnel, and process segment hierarchies.
Why it mattersDe-facto semantic standard for OT/IT integration. Required for interoperability across vendors.
Industrial Manufacturing
ISO standard for exchanging 3D CAD data with PMI (Product Manufacturing Information) between A&D enterprises. Replaces older AP203 and AP214.
Why it mattersRequired for OEM-supplier 3D data exchange in modern A&D programs. Reduces integration cost and prevents proprietary lock-in.
Aerospace & Defense
International standard for BCMS. Provides systematic framework for resilience.
Why it mattersIncreasingly required by enterprise customers and major retailers. Provides demonstrable resilience evidence.
Food & Beverage
International standard specifying requirements for an Information Security Management System (ISMS). Covers 93 controls across organizational, people, physical, and technological domains.
Why it mattersFrequently required by enterprise customers in B2B procurement. Foundation for many other compliance programs (TISAX, IATF security extensions).
Industrial Manufacturing
Identity management, access provisioning/de-provisioning, privileged access, MFA — applied to manufacturing IT environments.
Why it mattersFrequently required by enterprise customers in B2B procurement.
Industrial ManufacturingTechnology, Media & Telecom
International standard for ISMS. Updated 2022 with new control structure (4 themes, 93 controls).
Why it mattersRequired by enterprise customers and partners. Standard certification for tech/SaaS/telecom companies.
Technology, Media & Telecom
ISO 27017 for cloud security; ISO 27018 for protection of PII in public cloud. Particularly relevant for TMT.
Why it mattersIncreasingly required by enterprise customers of cloud services. Differentiator in cloud SaaS market.
Technology, Media & Telecom
International standard for supply chain security management. Increasingly required by major retailers from suppliers.
Why it mattersStandard for supply chain security. Increasingly required by enterprise customers.
Consumer Products & Retail
International standard for energy management. Defines energy performance indicators (EnPIs), energy review, baseline, and continuous improvement.
Why it mattersIncreasingly required by enterprise customers and regulators. Foundation for industrial energy efficiency programs.
Energy & Utilities
International standard for managing cybersecurity in road vehicles throughout development, production, and post-production. Aligned with UN R155 regulation requiring CSMS (Cybersecurity Management System).
Why it mattersRequired for vehicle type approval in EU since July 2022. UNECE WP.29 regulation R155 mandates CSMS certification for new vehicle types.
Automotive & Mobility
Access controls aligned with vehicle cybersecurity management — least privilege, MFA for security-critical changes, tiered access by clearance.
Why it mattersRequired for UN R155 Type Approval. Vehicles connected to the internet need defense-in-depth from the development environment outward.
Automotive & Mobility
Technical data subject to ITAR must be physically and logically restricted to US persons. Cloud storage must be in US-only regions with screened US-persons-only operations staff.
Why it mattersStrict liability — even accidental access by foreign person is a violation. AWS GovCloud / Azure Government / Google Gov are designed for this.
Aerospace & Defense
Access to ITAR-restricted technical data is restricted to US persons (citizens, lawful permanent residents, certain protected individuals). Requires screening, training, and ongoing monitoring.
Why it mattersITAR violations can result in $1M+ per violation, debarment, and individual criminal prosecution. Common audit area.
Aerospace & Defense
Every data ingestion must screen for ITAR/EAR-controlled content (technical data, specifications, drawings) before processing or storage. Includes automated content classification and access restriction.
Why it mattersITAR violations are strict liability — intent doesn't matter. Penalties include $1M+ per violation, debarment, and individual criminal liability.
Aerospace & Defense