Verified against primary sources as of 15 August 2026. Laws and figures change — confirm current requirements before relying on this page.
United States: 6 verified country-layer records — legal permit (2), mandatory scheme (2), conditional requirement (2). 7 accreditation bodies are listed for this jurisdiction. Each record below carries its legal instrument, who it binds, and the date it was last verified against its primary source.
- Records
- 6
- Accreditation bodies
- 7
National accreditation
- A2LA — American Association for Laboratory Accreditation
- AIHA LAP — AIHA Laboratory Accreditation Programs, LLC
- ANAB — ANSI National Accreditation Board
- IAS — International Accreditation Service, Inc
- NAC — NAC National Accreditation Center LLC
- NVLAP — National Voluntary Laboratory Accreditation Program (NIST)
- PJLA — Perry Johnson Laboratory Accreditation, Inc
Mandatory and regulatory records
Verified from primary sources, grouped by how binding each one is. None of these is a certificate; each carries the instrument it comes from and the date it was last checked.
Conditional requirement
How this jurisdiction is structured
No single national accreditation authority
Accreditation in the United States is run by multiple private-sector bodies, not one national authority.
Official source ↗Last verified:
Find a US accreditation body
ANAB (ANSI National Accreditation Board) is one of the United States' private-sector accreditation bodies.
Official source ↗Last verified:
General duty to provide a safe workplace
The OSH Act's General Duty Clause, §5(a)(1), requires "employment and a place of employment which are free from recognized hazards that are causing or are likely to cause death or serious physical harm." §5(a)(2) binds the employer to OSHA's own standards; §5(b) binds the employee to standards applicable to their own conduct. OSHA is a legal duty enforced by a federal agency; ISO 45001 is a voluntary management-system standard — one does not substitute for the other.
Official source ↗Last verified:
Incentive and support programs
No centralized federal program was found that pays certification costs directly; NIST MEP provides advisory and training support to manufacturers.
Manufacturing Extension Partnership (MEP)
- Funder
- NIST, U.S. Department of Commerce
- What it provides
- Advisory and training services for small and medium manufacturers, delivered through 450+ service locations and ~1,400 advisors nationwide.
- Eligibility
- Small and medium-sized manufacturers in the United States and Puerto Rico.
Official source ↗Last verified:
Trade & market access
14 agreements
| Agreement | Parties | Date | Note |
|---|---|---|---|
| CAFTA-DR | Dominican Republic, Central American countries | In force 2006-03-01 | |
| KORUS (South Korea-US) | South Korea | In force 2012-03-15 | |
| US-Australia | Australia | In force 2005-01-01 | |
| US-Bahrain | Bahrain | In force 2006-08-01 | |
| US-Chile | Chile | In force 2004-01-01 | |
| US-Colombia | Colombia | In force 2012-05-15 | |
| US-Israel | Israel | In force 1985-08-19 | |
| US-Jordan | Jordan | In force 2001-12-17 | |
| US-Morocco | Morocco | In force 2006-01-01 | |
| US-Oman | Oman | In force 2009-01-01 | |
| US-Panama | Panama | In force 2012-10-31 | |
| US-Peru | Peru | In force 2009-02-01 | |
| US-Singapore | Singapore | In force 2004-01-01 | |
| USMCA / CUSMA / T-MEC | Canada, Mexico | In force 2020-07-01 | date cross-verified from Canada's and Mexico's own sources |
WTO Regional Trade Agreements Information System (RTAIS) · retrieved
Frameworks & audits in United States
A U.S. government-wide software attestation form: the OMB memoranda requiring its collection were rescinded by OMB M-26-05 on 23 January 2026.
SOX §404 requires covered U.S. issuers to assess internal control over financial reporting, with an independent auditor's attestation for accelerated filers.
FedRAMP is the U.S. federal cloud authorization program run by GSA under the FedRAMP Authorization Act — agencies grant authorizations, not certificates.
GovRAMP is a nonprofit cloud security verification program serving U.S. state, local, tribal and educational government — StateRAMP's dba name since 2025.
IRS Publication 1075 sets the controls agencies, agents, contractors and sub-contractors must meet as a condition of receiving Federal Tax Information.
MARS-E is CMS's security and privacy standard for ACA Administering Entities, built on the CMS Acceptable Risk Safeguards and NIST SP 800-53 Rev 4.
TX-RAMP is Texas's state-government cloud security authorization program: Texas Cyber Command evaluates vendors and DIR issues the certification.
The FBI CJIS Security Policy sets security rules for Criminal Justice Information; compliance runs through a signed Security Addendum, not a certificate.
CRI Profile is named in FFIEC's own sunset statement as one industry resource institutions may consider — not a designated successor to the CAT.
The FFIEC sunset its Cybersecurity Assessment Tool (CAT) on August 31, 2025; it was a voluntary self-assessment, not an examination requirement.
NERC CIP is the mandatory cybersecurity reliability standard family for the U.S. bulk-power system, developed by NERC and approved by FERC.
NIST SP 800-171 is NIST's framework for protecting Controlled Unclassified Information in nonfederal systems; DoD contracts bind it through DFARS clauses.
EPCS is the DEA rule under 21 CFR 1311.300: providers of electronic prescription or pharmacy applications must obtain a third-party audit.
HECVAT is a self-assessment questionnaire created by leaders in higher education with EDUCAUSE, Internet2 and REN-ISAC, hosted at no cost.
The AICPA & CIMA Peer Review Program requires firms performing accounting or auditing work to undergo a peer review of their engagements or quality control.