03

Technology and Data

On the software and data side, what decides is not the sector but which data you process, whether you provide a defined service to customers, and your role in the AI chain. For most technology companies several standards become candidates at once.

Candidate ISO standards
11
Non-ISO programmes common in this field
2
Country requirements verified to relate to this sector
8
Last verified

Most commonly confused in Technology and Data

ISO/IEC 27017 and 27018 are not standalone certificates

They are cloud security and personal data controls, not standalone Type A management system standards, although they are frequently marketed as separate certificates.

ISO 27001 does not mean data protection compliance

An information security management system does not substitute for KVKK or GDPR compliance or legal advice. ISO/IEC 27701 strengthens this side but is still not a legal compliance certificate.

Using AI is not a trigger on its own

A team using a chat tool does not create ISO/IEC 42001 candidacy. The developer, provider or high-impact user role is questioned.

Candidate ISO standards11

Non-ISO programmes common in this field

These are not ISO standards; each has its own scheme owner, issuing body and rules. Whether they are candidates is decided by activity and buyer requirement.

  • Cloud and data centre customer audit programmes
  • Sector cyber security frameworks

Country requirements verified to relate to this sector

Frameworks & audits for this sector

ADISA Standard 8.0Certification
ADISA ICT Asset Recovery Standard 8.0

ADISA ICT Asset Recovery Standard 8.0 certifies processors that handle IT asset disposal; ADISA Certification owns and audits the scheme.

EUCCCertification
European Common Criteria-based Cybersecurity Certification Scheme

EUCC is the EU's first Cybersecurity Act certification scheme for ICT products, based on Common Criteria and applied from 27 February 2025.

ISMS-PCertification
Personal Information & Information Security Management System

ISMS-P is South Korea's integrated certification for information security and personal-data management, statutory for defined ICT operators.

Kantara InitiativeCertification
Kantara Initiative

Kantara Initiative runs global identity-assurance certification programs, assessing services against standards including NIST SP 800-63 and the UK's DIATF.

MTCSCertification
Multi-Tiered Cloud Computing Security (SS 584)

MTCS (Singapore Standard SS 584:2020) is a three-level cloud security certification, published under the Information Technology Standards Committee.

NAID AAACertification
NAID AAA Certification

NAID AAA Certification is i-SIGMA's voluntary program for member companies providing secure information destruction. Membership comes first.

O-TTPSCertification
Open Trusted Technology Provider Standard

O-TTPS is The Open Group's certification standard against maliciously tainted and counterfeit ICT products, with a live public certification register.

SCS 9001Certification
SCS 9001

SCS 9001 is TIA's certifiable cyber and supply chain security standard for the ICT industry, with optional benchmarking across supply chains.

TL 9000Certification
TL 9000

TL 9000 is TIA QuEST Forum's ICT-industry certification, extending ISO 9001:2015 with telecom-specific requirements for certified organizations.

C5Attestation
Cloud Computing Compliance Criteria Catalogue

C5 is the BSI's cloud security criteria catalogue for Germany — auditors examine against it and the output is an attestation (Testat), not a certificate.

Secure Software Development Attestation FormAttestation
Secure Software Development Attestation Form

A U.S. government-wide software attestation form: the OMB memoranda requiring its collection were rescinded by OMB M-26-05 on 23 January 2026.

ACN Cloud Qualification SchemeAuthorization program
ACN Cloud Qualification Scheme

ACN's Regolamento sets three qualification tracks — AI, AC and QC — for Italian public bodies and their cloud providers to move data to the cloud.

FedRAMPAuthorization program
Federal Risk and Authorization Management Program

FedRAMP is the U.S. federal cloud authorization program run by GSA under the FedRAMP Authorization Act — agencies grant authorizations, not certificates.

GovRAMPAuthorization program
GovRAMP

GovRAMP is a nonprofit cloud security verification program serving U.S. state, local, tribal and educational government — StateRAMP's dba name since 2025.

SecNumCloudAuthorization program
SecNumCloud

SecNumCloud is a French state qualification for cloud service providers, granted by ANSSI, covering SaaS, PaaS, CaaS and IaaS activities.

TX-RAMPAuthorization program
Texas Risk and Authorization Management Program

TX-RAMP is Texas's state-government cloud security authorization program: Texas Cyber Command evaluates vendors and DIR issues the certification.

CCCS Cloud Security Assessment ProgramFramework
Cloud Service Provider (CSP) Information Technology Security (ITS) Assessment Program

The Cyber Centre's CSP ITS Assessment Program assesses cloud services for GC procurement up to Protected B — the output is a report, not a certificate.

CCMFramework
Cloud Controls Matrix

The CSA Cloud Controls Matrix is a cybersecurity control framework for cloud computing, structured in 17 domains, maintained by the Cloud Security Alliance.

ISO/IEC 27017Framework
ISO/IEC 27017

ISO/IEC 27017 gives cloud-specific security controls on top of ISO/IEC 27002; the current edition is 27017:2026 — the 2015 text is withdrawn.

ISO/IEC 27018Framework
ISO/IEC 27018

ISO/IEC 27018 guides protection of PII in public clouds where the provider acts as PII processor; the current edition is 27018:2025 (third edition).

RBA VAPAudit methodology
RBA Validated Assessment Program

The RBA Validated Assessment Program is an on-site audit methodology for RBA Code compliance, carried out by independent third-party firms, not RBA itself.

CSA STARPrequalification register
Security, Trust, Assurance and Risk (STAR)

CSA STAR is the Cloud Security Alliance's cloud assurance program, built around a publicly accessible registry of provider security submissions.

EU Cloud CoCTrust mark
EU Cloud Code of Conduct

The EU Cloud Code of Conduct is a voluntary GDPR Article 40 code; cloud providers declare adherence and SCOPE Europe verifies compliance annually.

FTRTrust mark
AWS Foundational Technical Review

The AWS Foundational Technical Review (FTR) is a self-service review of AWS Partner solutions; AWS calls the outcome an approval and a badge, not a certificate.

Requirements Finder results by country

Last verified:

This page is for information only; it is not legal advice. A record appearing here does not mean it is required for your business. This library does not issue certificates.

Cite this page

Attributing this record helps other researchers verify it independently.

"Technology and Data." Certifidex, FutureTechnologies. Last verified 4 August 2026. https://certifidex.com/sectors/technology-and-data

All industry guides →