ISO 21001 is not a licence or accreditation
It is an educational organisations management system and does not substitute for ministry or university licensing and accreditation, or for a personal training certificate.
09
Some records under this heading are aimed at public and community bodies rather than businesses. They are therefore not shown as automatic candidates in a business search.
It is an educational organisations management system and does not substitute for ministry or university licensing and accreditation, or for a personal training certificate.
Their audience is community and electoral bodies. ISO/TS 54001 is additionally a Technical Specification and an ISO 9001 application.
It is a management system for records; it does not remove statutory retention periods and archival obligations.
For organisations in any sector seeking to standardise processes and manage customer expectations systematically.
For organisations with substantial IT estates and for IT service providers.
For organisations where service interruption is critical, or that are multi-site or critical suppliers.
For organisations that process data, access customer systems or provide cloud services.
For organisations of any type and size establishing security management, including supply chain aspects.
For people-intensive organisations seeking corporate assurance over HR processes.
For organisations and groups of organisations establishing corporate governance over records.
For organisations seeking to manage institutional knowledge systematically.
For organisations in public procurement, using agents or intermediaries, or selling across multiple countries.
For organisations carrying a broad inventory of regulatory obligations.
For organisations operating vehicle fleets or with heavy work-related road use.
For organisations providing facility services or managing large property portfolios.
For organisations running joint ventures, consortia, alliances or long-term supply relationships.
For businesses with high water consumption or treatment costs.
For organisations managing critical physical assets across their lifecycle.
For R&D and technology organisations establishing systematic innovation management.
For organisations managing air quality in building and facility interiors.
For organisations providing private security operations.
For organisations delivering educational services.
For public bodies designated by cities and communities.
For electoral organisations at all levels of government.
These are not ISO standards; each has its own scheme owner, issuing body and rules. Whether they are candidates is decided by activity and buyer requirement.
Esquema Nacional de Seguridad is Spain's statutory security framework for public-sector information systems, set by Real Decreto 311/2022.
A U.S. government-wide software attestation form: the OMB memoranda requiring its collection were rescinded by OMB M-26-05 on 23 January 2026.
ACN's Regolamento sets three qualification tracks — AI, AC and QC — for Italian public bodies and their cloud providers to move data to the cloud.
FedRAMP is the U.S. federal cloud authorization program run by GSA under the FedRAMP Authorization Act — agencies grant authorizations, not certificates.
GovRAMP is a nonprofit cloud security verification program serving U.S. state, local, tribal and educational government — StateRAMP's dba name since 2025.
IRS Publication 1075 sets the controls agencies, agents, contractors and sub-contractors must meet as a condition of receiving Federal Tax Information.
MARS-E is CMS's security and privacy standard for ACA Administering Entities, built on the CMS Acceptable Risk Safeguards and NIST SP 800-53 Rev 4.
PSN Code of Connection is the application process and yearly certificate required to connect to the UK's Public Services Network.
TX-RAMP is Texas's state-government cloud security authorization program: Texas Cyber Command evaluates vendors and DIR issues the certification.
BIO2 is the Dutch government's baseline information-security framework, now legally anchored for organisations within the Cyberbeveiligingswet's scope.
The Cyber Assessment Framework is the NCSC's outcome-based framework for assessing cyber resilience, structured around 4 objectives and 41 assessments.
The Cyber Centre's CSP ITS Assessment Program assesses cloud services for GC procurement up to Protected B — the output is a report, not a certificate.
The FBI CJIS Security Policy sets security rules for Criminal Justice Information; compliance runs through a signed Security Addendum, not a certificate.
DESC's Information Security Regulation sets minimum security controls for all Dubai Government Entities, formalized under Resolution No. 13 of 2012.
NIST's Risk Management Framework (SP 800-37) is a 7-step lifecycle process ending in an Authorization to Operate, not a control checklist.
NIST SP 800-53 is a catalog of security and privacy controls; FIPS 200 requires U.S. federal agencies to meet minimum requirements using it.
The UAE IA Regulation sets minimum information-security controls that TDRA-designated critical entities must implement and demonstrate compliance with.
Organisations using DigiD must complete an annual ICT security assessment, overseen by Logius under the Dutch Ministry of the Interior.
GovAssure is the UK government's scheme for assessing government critical systems against the NCSC Cyber Assessment Framework.
HECVAT is a self-assessment questionnaire created by leaders in higher education with EDUCAUSE, Internet2 and REN-ISAC, hosted at no cost.
Last verified:
This page is for information only; it is not legal advice. A record appearing here does not mean it is required for your business. This library does not issue certificates.
Attributing this record helps other researchers verify it independently.
"Public Sector and Education." Certifidex, FutureTechnologies. Last verified 4 August 2026. https://certifidex.com/sectors/public-sector-and-education