09

Public Sector and Education

Some records under this heading are aimed at public and community bodies rather than businesses. They are therefore not shown as automatic candidates in a business search.

Candidate ISO standards
21
Non-ISO programmes common in this field
2
Country requirements verified to relate to this sector
1
Last verified

Most commonly confused in Public Sector and Education

ISO 21001 is not a licence or accreditation

It is an educational organisations management system and does not substitute for ministry or university licensing and accreditation, or for a personal training certificate.

ISO 37101 and ISO/TS 54001 are not business records

Their audience is community and electoral bodies. ISO/TS 54001 is additionally a Technical Specification and an ISO 9001 application.

ISO 30301 does not substitute for archival legislation

It is a management system for records; it does not remove statutory retention periods and archival obligations.

Candidate ISO standards21

ISO 90012015
Quality Management System

For organisations in any sector seeking to standardise processes and manage customer expectations systematically.

ISO/IEC 19770-12017
IT Asset Management System

For organisations with substantial IT estates and for IT service providers.

ISO 223012019
Business Continuity Management System

For organisations where service interruption is critical, or that are multi-site or critical suppliers.

ISO/IEC 270012022
Information Security Management System

For organisations that process data, access customer systems or provide cloud services.

ISO 280002022
Security Management System

For organisations of any type and size establishing security management, including supply chain aspects.

ISO 302012026
Human Resource Management System

For people-intensive organisations seeking corporate assurance over HR processes.

ISO 303012019
Management System for Records

For organisations and groups of organisations establishing corporate governance over records.

ISO 304012018
Knowledge Management System

For organisations seeking to manage institutional knowledge systematically.

ISO 370012025
Anti-Bribery Management System

For organisations in public procurement, using agents or intermediaries, or selling across multiple countries.

ISO 373012021
Compliance Management System

For organisations carrying a broad inventory of regulatory obligations.

ISO 390012012
Road Traffic Safety Management System

For organisations operating vehicle fleets or with heavy work-related road use.

ISO 410012018
Facility Management System

For organisations providing facility services or managing large property portfolios.

ISO 440012017
Collaborative Business Relationship Management System

For organisations running joint ventures, consortia, alliances or long-term supply relationships.

ISO 460012019
Water Efficiency Management System

For businesses with high water consumption or treatment costs.

ISO 550012024
Asset Management System

For organisations managing critical physical assets across their lifecycle.

ISO 560012024
Innovation Management System

For R&D and technology organisations establishing systematic innovation management.

ISO 16000-402019
Indoor Air Quality Management System

For organisations managing air quality in building and facility interiors.

ISO 187882015
Private Security Operations Management System

For organisations providing private security operations.

ISO 210012025
Educational Organisations Management System

For organisations delivering educational services.

ISO 371012016
Sustainable Development in Communities Management System

For public bodies designated by cities and communities.

ISO/TS 540012019
Quality Management for Electoral Organisations

For electoral organisations at all levels of government.

ISO 9001 sector application

Non-ISO programmes common in this field

These are not ISO standards; each has its own scheme owner, issuing body and rules. Whether they are candidates is decided by activity and buyer requirement.

  • Public procurement legislation obligations
  • Institutional accreditation programmes

Country requirements verified to relate to this sector

Frameworks & audits for this sector

ENSCertification
Esquema Nacional de Seguridad

Esquema Nacional de Seguridad is Spain's statutory security framework for public-sector information systems, set by Real Decreto 311/2022.

Secure Software Development Attestation FormAttestation
Secure Software Development Attestation Form

A U.S. government-wide software attestation form: the OMB memoranda requiring its collection were rescinded by OMB M-26-05 on 23 January 2026.

ACN Cloud Qualification SchemeAuthorization program
ACN Cloud Qualification Scheme

ACN's Regolamento sets three qualification tracks — AI, AC and QC — for Italian public bodies and their cloud providers to move data to the cloud.

FedRAMPAuthorization program
Federal Risk and Authorization Management Program

FedRAMP is the U.S. federal cloud authorization program run by GSA under the FedRAMP Authorization Act — agencies grant authorizations, not certificates.

GovRAMPAuthorization program
GovRAMP

GovRAMP is a nonprofit cloud security verification program serving U.S. state, local, tribal and educational government — StateRAMP's dba name since 2025.

IRS Pub 1075Authorization program
Tax Information Security Guidelines for Federal, State and Local Agencies

IRS Publication 1075 sets the controls agencies, agents, contractors and sub-contractors must meet as a condition of receiving Federal Tax Information.

MARS-EAuthorization program
Minimum Acceptable Risk Standards for Exchanges

MARS-E is CMS's security and privacy standard for ACA Administering Entities, built on the CMS Acceptable Risk Safeguards and NIST SP 800-53 Rev 4.

PSN CoCoAuthorization program
PSN Code of Connection

PSN Code of Connection is the application process and yearly certificate required to connect to the UK's Public Services Network.

TX-RAMPAuthorization program
Texas Risk and Authorization Management Program

TX-RAMP is Texas's state-government cloud security authorization program: Texas Cyber Command evaluates vendors and DIR issues the certification.

BIO2Framework
BIO2 (Baseline Informatiebeveiliging Overheid 2)

BIO2 is the Dutch government's baseline information-security framework, now legally anchored for organisations within the Cyberbeveiligingswet's scope.

CAFFramework
Cyber Assessment Framework

The Cyber Assessment Framework is the NCSC's outcome-based framework for assessing cyber resilience, structured around 4 objectives and 41 assessments.

CCCS Cloud Security Assessment ProgramFramework
Cloud Service Provider (CSP) Information Technology Security (ITS) Assessment Program

The Cyber Centre's CSP ITS Assessment Program assesses cloud services for GC procurement up to Protected B — the output is a report, not a certificate.

CJIS Security PolicyFramework
FBI CJIS Security Policy

The FBI CJIS Security Policy sets security rules for Criminal Justice Information; compliance runs through a signed Security Addendum, not a certificate.

DESC ISRFramework
Information Security Regulation

DESC's Information Security Regulation sets minimum security controls for all Dubai Government Entities, formalized under Resolution No. 13 of 2012.

NIST SP 800-37 Rev. 2 / RMFFramework
Risk Management Framework for Information Systems and Organizations

NIST's Risk Management Framework (SP 800-37) is a 7-step lifecycle process ending in an Authorization to Operate, not a control checklist.

NIST SP 800-53 Rev. 5Framework
Security and Privacy Controls for Information Systems and Organizations

NIST SP 800-53 is a catalog of security and privacy controls; FIPS 200 requires U.S. federal agencies to meet minimum requirements using it.

UAE IA RegulationFramework
UAE Information Assurance Regulation

The UAE IA Regulation sets minimum information-security controls that TDRA-designated critical entities must implement and demonstrate compliance with.

DigiD ICT-beveiligingsassessment (DigiD ICT Security Assessment)Audit methodology
DigiD ICT-beveiligingsassessment (DigiD ICT Security Assessment)

Organisations using DigiD must complete an annual ICT security assessment, overseen by Logius under the Dutch Ministry of the Interior.

GovAssureAudit methodology
GovAssure

GovAssure is the UK government's scheme for assessing government critical systems against the NCSC Cyber Assessment Framework.

HECVATAudit methodology
Higher Education Community Vendor Assessment Toolkit

HECVAT is a self-assessment questionnaire created by leaders in higher education with EDUCAUSE, Internet2 and REN-ISAC, hosted at no cost.

Requirements Finder results by country

Last verified:

This page is for information only; it is not legal advice. A record appearing here does not mean it is required for your business. This library does not issue certificates.

Cite this page

Attributing this record helps other researchers verify it independently.

"Public Sector and Education." Certifidex, FutureTechnologies. Last verified 4 August 2026. https://certifidex.com/sectors/public-sector-and-education

All industry guides →