Quality Management System
For organisations in any sector seeking to standardise processes and manage customer expectations systematically.
Read this record →"ISO certified," "accredited," "compliant" — words thrown around loosely. Certifidex is a source-backed library that traces each one back to what it actually requires, who it applies to, and who is authorised to issue it.
Certifidex covers 48 ISO management system standards, 42 certification schemes, 21 industry guides, 173 assurance frameworks and 10 binding regulations, each dated to when its facts were last checked against the primary source. It does not issue certificates or sell advisory or consultancy services — certification decisions are always made by an independent, accredited body.
Selling to the EU or UK? Check which marking your product needs
Requirements Finder
Pick a country and a sector — legal obligations, regulations, buyer-driven schemes and voluntary standards, each traced to a verified, dated source.
Country
Sector
Pick a country and a sector to see what applies.
Pick a country and a sector to see what applies.
48 ISO management system standards
42 Certification schemes
173 Frameworks & audits
10 Regulations
21 Industry guides
23 Country guides
ISO Standards
What each standard is for, who it applies to and how it is certified — in plain language, with the official source on the page.
For organisations in any sector seeking to standardise processes and manage customer expectations systematically.
Read this record →For businesses seeking to measure and manage environmental impacts and tie them to corporate objectives.
Read this record →For organisations that process data, access customer systems or provide cloud services.
Read this record →For businesses seeking to address employee, site and operational risks systematically.
Read this record →Certification
Programmes with their own scheme owners, their own rules and their own types of issuing body — none of them ISO standards. One word covers very different things, so every record is shown with its class.
A good agricultural practice programme requested by exporters and retailers at primary production.
Requested by retailers and buyers across the food chain — built on ISO 22000 but a separate scheme from it.
A voluntary environmental label for defined product and service groups placed on the EU market — licensed by a public authority.
A points-based rating for building and interior projects — it certifies the project, not the company.
SMETA is not a certificate — it is an audit methodology. In Sedex's own words: 'Sedex owns and evolves the SMETA methodology.' 2024 saw 115,000 site visits.
IMPORTANT: this is NOT a certification scheme — it is a voluntary government partnership/status programme run by US Customs and Border Protection (CBP). More than 11,400 certified partners, covering over 52 percent (by value) of cargo imported into the US.
Frameworks & Audits
Attestations, authorization programs, certifiable frameworks and audit schemes that sit outside the ISO management-system catalog. Every record names its class honestly — an attestation is a report, not a certificate — and links to the owner's own pages.
SOC 2 is an AICPA attestation: the output is an examination report, not a certificate, examining a service organization's system and controls.
FedRAMP is the U.S. federal cloud authorization program run by GSA under the FedRAMP Authorization Act — agencies grant authorizations, not certificates.
The NIST Cybersecurity Framework 2.0 is guidance a business aligns with, not a certification — published by NIST as CSWP 29 on 26 February 2024.
Regulations
Binding legal instruments whose scope, dates and penalty ceilings are quoted verbatim from the official text, article numbers and source links included. Whether one applies to your organisation is a question this library never answers for you.
GDPR is Regulation (EU) 2016/679, applicable from 25 May 2018 — its territorial scope and fine ceilings are reproduced verbatim on this page.
Directive (EU) 2022/2555 (NIS2): Article 2 sets out which entities are in scope; Member States had to transpose it by 17 October 2024.
Regulation (EU) 2022/2554 (DORA) applies from 17 January 2025; Article 2 lists the financial entities and ICT third-party providers in scope.
HIPAA is Public Law 104-191 (1996); the applicability rule in 45 CFR 160.102 and the civil penalty tiers are reproduced verbatim on this page.
The CCPA is Cal. Civ. Code §§ 1798.100–1798.199.100; the "business" thresholds and the administrative fine ceiling are reproduced verbatim here.
The UK GDPR is Regulation (EU) 2016/679 as it applies in UK law; Article 3 scope and the Article 83 fine ceilings are reproduced verbatim here.
The Data Protection Act 2018 (2018 c. 12) sits alongside the UK GDPR; s.207 scope and the s.157 penalty maximums are reproduced verbatim here.
The Texas Data Privacy and Security Act applies by business-size test rather than a revenue threshold; its scope and $7,500 penalty cap are reproduced here.
Virginia's Consumer Data Protection Act has no revenue threshold: scope turns on consumer counts, and the statute's own exemption list is reproduced here.
PECR's cookie rule and penalty regime were rewritten on 5 February 2026; this record carries the wording now in force, not the superseded text.
Accreditation Bodies
The accreditation body is the organisation that accredits a country's certification bodies and runs the official register where a certificate can be checked. One record per body, linking to that register.
Industry guides
Which records can become candidates in a given field, and which questions actually decide. A sector name alone does not produce a result.
Countries
A full guide opens for a country once its data is verified — every other country is reachable through its national accreditation body.
Entry points
The same records, indexed six ways.
How this library works
A certificate is a claim about a document, a body and a scope. This library keeps those three things separate, shows where each one comes from, and dates the check.
Search the libraryScope of this library
Stated plainly, so you know what you are reading and what you still have to do elsewhere.