21

Retail and E-commerce

Today, the only verified, global certification scheme in retail applies to the food retail supply chain (sourcing, purchase, importation, distribution, preparation and retailing). No global certification scheme was found in this round for general/non-food retail or online-only sales — that does not mean your business is unregulated, only that you need to look at your own country's consumer/distance-selling law.

Candidate ISO standards
0
Non-ISO programmes common in this field
3
Country requirements verified to relate to this sector
1
Last verified

Most commonly confused in Retail and E-commerce

BRCGS Retail is not the same scheme as BRCGS Food Safety/Storage & Distribution

BRCGS's "Retail" standard covers companies sourcing, purchasing, importing, distributing, preparing and retailing food products (including physical stores) — its own scope sentence states verbatim "food retail supply chain". This is a SEPARATE certificate from "BRCGS Food Safety, Storage & Distribution", already listed under Food and Agriculture: that standard covers the producer/processor/warehouse, this one covers the retailer's own role. The two should not be confused.

See the Food and Agriculture sector guide

No global certification scheme was found in this round for general/non-food retail or e-commerce

An "e-commerce certification" search returns mostly personal/professional training certificates, not an organisational compliance scheme. No verified global scheme exists for non-food retail businesses in this round — this is not a gap in coverage, it is an honest finding; your business remains subject to your country's consumer/distance-selling law, which is jurisdiction-specific.

PCI DSS is not a certificate — it is a compliance attestation system

The Payment Card Industry Data Security Standard (PCI DSS) is a regime imposed by contract by the card brands (Visa/Mastercard etc.) — it is not government legislation. Compliance is achieved via self-assessment (SAQ) or an independent Qualified Security Assessor (QSA) audit, and the output is not a "certificate" but an Attestation of Compliance (AOC). It covers any business processing, storing or transmitting card data, not only retail.

Candidate ISO standards

No verified candidate standards are mapped to this sector yet.

Non-ISO programmes common in this field

These are not ISO standards; each has its own scheme owner, issuing body and rules. Whether they are candidates is decided by activity and buyer requirement.

  • BRCGS Retail (food retail supply chain)
  • PCI DSS (card data security, compliance attestation)
  • Consumer/distance-selling law (jurisdiction-specific)

Country requirements verified to relate to this sector

Frameworks & audits for this sector

Requirements Finder results by country

Last verified:

This page is for information only; it is not legal advice. A record appearing here does not mean it is required for your business. This library does not issue certificates.

Cite this page

Attributing this record helps other researchers verify it independently.

"Retail and E-commerce." Certifidex, FutureTechnologies. Last verified 23 August 2026. https://certifidex.com/sectors/retail-and-e-commerce

All industry guides →