Skip to main content
Standards

Standards-aware policy and compliance guidance

Browse active standards and frameworks that inform how Quick Policy baselines policy drafting and review.

Mapped standards (ISO, SOC 2, UK GDPR, and more)
Source-linked summaries
Policy-family guidance

Active public standards

Each page explains what the standard is, why it matters, and how Quick Policy helps teams draft and govern policies against it.

404 standards

Browsing all 404 standards. Search by name, code or plain-English purpose.

ICAEW_AAF_01_20

ICAEW AAF 01/20 — Assurance Reports on Internal Controls

AAF 01/20 is the ICAEW assurance framework for reporting on the description, design and operating effectiveness of a service organisation’s internal controls (the UK analogue to ISAE 3402 / SOC 1). Used by accountancy and outsourcing firms to give user auditors assurance over controls relevant to user entities’ financial reporting.

Jurisdiction: UK

Lifecycle: Active

AAT_CODE_OF_ETHICS

AAT Code of Professional Ethics

The AAT Code of Professional Ethics applies to AAT members and licensed members in practice. It mirrors the IESBA fundamental principles and conceptual framework and adds AAT-specific requirements on continuing professional development (CPD), professional indemnity insurance, client money, and complaints handling for AAT-licensed bookkeepers and accountants.

Jurisdiction: UK

Lifecycle: Active

ACCA_CODE_OF_ETHICS

ACCA Code of Ethics and Conduct

The ACCA Code of Ethics and Conduct binds ACCA members, affiliates and students worldwide. Like the ICAEW Code it adopts the IESBA five fundamental principles and the threats-and-safeguards conceptual framework, with specific provisions on professional appointments, conflicts of interest, fees, inducements, custody of client assets, and independence for assurance engagements.

Jurisdiction: UK

Lifecycle: Active

AEO_TRUSTED_TRADER

AEO + Trusted Trader Programs (EU + US C-TPAT + UK)

Authorized Economic Operator (AEO) is a globally-recognised customs trusted-trader status (WCO SAFE Framework). EU AEO certification (AEOC customs + AEOS security + AEOF full) under UCC Art 38. US Customs-Trade Partnership Against Terrorism (C-TPAT) + UK AEO (post-Brexit) provide similar benefits including reduced inspections, simplified procedures + mutual recognition with partner countries. Annual self-assessment + customs audit verification. Voluntary but increasingly contractually required by major customers.

Jurisdiction: GLOBAL

Lifecycle: Active

AICPA_SSAE_21

AICPA SSAE 21 — Statements on Standards for Attestation Engagements

AICPA Statements on Standards for Attestation Engagements (SSAE) are the standards for US attestation engagements (examinations, reviews + agreed-upon procedures) other than audits of historical financial statements. SSAE 21 consolidated + revised the framework. The most well-known SSAE-based engagements are SOC 1 (ICFR reports), SOC 2 (Trust Services Criteria), SOC 3 (general use SOC 2 summary). Audit firms applying SSAEs operate ISQM 1-aligned quality management.

Jurisdiction: US

Lifecycle: Active

AIFMD_2011_61

EU Alternative Investment Fund Managers Directive (AIFMD)

AIFMD regulates managers of alternative investment funds (AIFs) marketed in the EU — hedge funds, private equity, real estate, infrastructure, venture capital. Imposes authorisation + ongoing requirements on AIFMs including organisational requirements, capital, conduct of business, delegation, valuation, depositary, leverage limits, transparency + reporting (Annex IV). AIFMD II (Dir 2024/927) amends the regime with substance + delegation requirements, liquidity-management tools for open-ended AIFs + new loan-origination AIF rules. Transposition deadline April 2026.

Jurisdiction: EU

Lifecycle: Active

ANSI_ASSP_A10

ANSI/ASSP A10 — Construction + Demolition Safety

The ANSI/ASSP A10 series of voluntary consensus standards is the US construction industry's detailed companion to OSHA 29 CFR 1926 — covering pre-project + pre-task safety + health planning (A10.1), demolition (A10.6), tube + coupler scaffolding (A10.10), fall protection (A10.32), excavation (A10.12), steel erection (A10.13), explosives (A10.7) + many others. Voluntary but increasingly contractually required by owners + integrated into safety management systems. Frequently cited as recognised good practice in OSHA citations + enforcement.

Jurisdiction: US

Lifecycle: Active

AS9100D

AS9100D / EN 9100 — Aerospace QMS

AS9100D is the global aerospace industry QMS standard, built on ISO 9001 with aerospace-specific requirements covering configuration management, risk-based product safety, counterfeit parts prevention, FAI (First Article Inspection) + supplier control. Required across aerospace + defence supply chains globally. EN 9100 + JISQ 9100 are the European + Japanese equivalents. Certification via IAQG-accredited bodies under the OASIS database.

Jurisdiction: GLOBAL

Lifecycle: Active

ASC_AQUACULTURE_STANDARDS

ASC Aquaculture Standards

Aquaculture Stewardship Council certification for responsibly farmed seafood. Species standards (salmon, shrimp, tilapia, pangasius, bivalves, seabass/seabream, etc.) cover environmental + social criteria. Joint ASC-MSC Seaweed Standard covers cultivated seaweeds.

Jurisdiction: GLOBAL

Lifecycle: Active

BASEL_III_IV

Basel III / Endgame "Basel IV"

Basel III is the Basel Committee on Banking Supervision's comprehensive set of reform measures developed in response to the 2007-09 financial crisis. The post-crisis reforms finalised in December 2017 (often called "Basel IV" or the Basel III Endgame) introduced revised credit + operational + market risk frameworks + an aggregate output floor. Implementation is phased through 2025-2028 across jurisdictions. Transposed into EU law via CRR / CRD (CRR3 + CRD VI), into UK rules via PRA Rulebook Implementation Phase 1 (effective 1 January 2026 in UK), into US via OCC/Fed/FDIC capital rules. Mandatory for all internationally-active banks; broad applicability to other licensed banks through national implementation.

Jurisdiction: GLOBAL

Lifecycle: Active

BRCGS_FOOD_V9

BRCGS Global Standard for Food Safety Issue 9

BRCGS Global Standard for Food Safety Issue 9 is a GFSI-benchmarked food safety + quality scheme widely required by UK + EU retailers + global brand owners. Covers senior management commitment, food safety plan (HACCP), food safety + quality management system, site standards, product control, process control, personnel + food fraud + defence. Audited by accredited certification bodies on a tiered grade system (AA+/AA/A/B/C/D).

Jurisdiction: GLOBAL

Lifecycle: Active

BREEAM_CURRENT

BREEAM — Building Research Establishment Environmental Assessment Method

BREEAM is the UK + international sustainability assessment method for buildings, administered by BRE. Rates buildings across 9 categories with ratings Pass / Good / Very Good / Excellent / Outstanding. Used widely in UK + Europe (mandatory in some public sector procurement) + frequently in pre-let / leasing requirements for grade-A commercial space. Companion schemes for refurbishment, in-use + communities.

Jurisdiction: UK

Lifecycle: Active

BSA_FINCEN

US Bank Secrecy Act + FinCEN Regulations

The US Bank Secrecy Act (BSA) is the principal federal anti-money-laundering law, administered by FinCEN. Requires US financial institutions (including banks, broker-dealers, money services businesses, casinos, mutual funds + certain non-bank residential mortgage lenders) to operate AML programmes, file Suspicious Activity Reports (SARs) + Currency Transaction Reports (CTRs), conduct customer due diligence (CDD/EDD) + identify beneficial ownership. The AML Act of 2020 significantly modernised the regime; the Corporate Transparency Act 2021 introduced beneficial-ownership reporting to FinCEN.

Jurisdiction: US

Lifecycle: Active

BSI_C5_2020

BSI Cloud Computing Compliance Criteria Catalogue (C5)

BSI C5 is the German Federal Office for Information Security (BSI) catalogue of minimum cloud-security requirements. Required by German federal procurement, increasingly required by German enterprise. The 2020 revision added 17 criteria reflecting cloud-specific evolution. Assessed via ISAE 3000 attestation that maps closely to SOC 2 reporting structure — many cloud providers obtain C5 + SOC 2 together.

Jurisdiction: DE

Lifecycle: Active

CCPA_CPRA_PROFILE_2023

CCPA/CPRA Obligations Profile

The California Consumer Privacy Act, expanded by the CPRA, gives California residents specific rights over their personal information — including access, deletion, correction, and the right to limit use of sensitive personal information. The California Privacy Protection Agency (CPPA) now enforces directly, in addition to the state Attorney General, and has signalled aggressive action against businesses that fail to honour opt-outs, ignore Global Privacy Control signals, or mishandle sensitive personal information. Statutory damages of $100–$750 per consumer per breach add up fast in class actions. Even non-California companies above the size thresholds are typically in scope.

Jurisdiction: US_CA

Lifecycle: Active

CFR_42_PART_2

42 CFR Part 2 — SUD Patient Records

42 CFR Part 2 governs the confidentiality of substance use disorder (SUD) patient records held by federally-assisted Part 2 programs. Stricter than HIPAA — historically required patient consent for nearly every disclosure (including treatment, payment + operations), with severe penalties for re-disclosure. The 2024 Final Rule (effective Feb 2026) harmonised Part 2 more closely with HIPAA — single patient consent for TPO is now permitted, breach notification aligned with HIPAA, civil + criminal penalties strengthened. Continues to require segregation of Part 2 records in EHRs, special handling for legal process, and the iconic re-disclosure prohibition notice.

Jurisdiction: US

Lifecycle: Active

CIS_CONTROLS_V8_1

CIS Controls v8.1

CIS Controls v8.1 (2024) consolidates 18 prioritised cybersecurity safeguards spanning identity, asset, vulnerability, account, data, and incident response domains. Maintained by the Center for Internet Security as a free, prescriptive baseline used by SMBs and as a procurement filter by enterprise + public-sector buyers. Implementation Group (IG) 1 covers essential hygiene; IG2 and IG3 add depth for higher-impact environments.

Jurisdiction: GLOBAL

Lifecycle: Active

CMMC_2_0_2024

Cybersecurity Maturity Model Certification 2.0

CMMC 2.0 is the US Department of Defense's tiered cybersecurity certification programme for contractors and subcontractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). Level 1 (self-assessment) covers basic FCI safeguards; Level 2 (NIST SP 800-171-aligned) is required for CUI; Level 3 (NIST SP 800-172) for the most sensitive contracts. Final rule effective 2024; phased flow-down to contracts began 2025.

Jurisdiction: US

Lifecycle: Active

CMS_HOSPITAL_COP

CMS Hospital Conditions of Participation

CMS Conditions of Participation (CoP, 42 CFR Part 482) are the federal health + safety regulations hospitals must meet to participate in Medicare + Medicaid. Cover governing body, patients' rights, QAPI, medical staff, nursing services, medical records, pharmaceutical services, infection prevention, EMTALA + discharge planning. Enforced through CMS surveys + deemed-status accreditation (Joint Commission, DNV, AAAHC). Failure to meet a Condition can result in termination of provider agreement.

Jurisdiction: US

Lifecycle: Active

COBIT_2019

COBIT 2019

COBIT 2019 (ISACA) is an IT governance + management framework providing 40 governance + management objectives across 5 domains. Used by enterprise IT governance functions and audit teams to structure IT governance, risk + control activities. Often paired with ITIL 4 (service management) and ISO 27001 (security management) for integrated IT governance.

Jurisdiction: GLOBAL

Lifecycle: Active

CODEX_ALIMENTARIUS_HACCP

Codex Alimentarius General Principles of Food Hygiene + HACCP

FAO/WHO Codex Alimentarius General Principles of Food Hygiene (CXC 1-1969) including the HACCP annex. The foundation for most national food safety regulations + industry standards globally.

Jurisdiction: GLOBAL

Lifecycle: Active

CODEX_HACCP

Codex HACCP — Hazard Analysis + Critical Control Points

Codex Alimentarius HACCP (CXC 1-1969) is the global reference for food-safety management. Seven principles: conduct hazard analysis, determine CCPs, establish critical limits, monitoring, corrective actions, verification + record-keeping. The foundational framework underlying virtually every national food-safety regime — including FSMA in the US, FSA in the UK + EU regulations.

Jurisdiction: GLOBAL

Lifecycle: Active

ICD10_SNOMED_LOINC

ICD-10-CM / SNOMED CT / LOINC — Clinical Coding Standards

The three core clinical-coding standards used in modern healthcare: ICD-10-CM (US morbidity classification, annually updated by CMS + NCHS), SNOMED CT (comprehensive clinical terminology, distributed under SNOMED International / NHS), LOINC (laboratory + clinical observations, distributed by Regenstrief Institute). Together they enable problem lists, diagnoses, lab results + procedure coding for billing, public health reporting, clinical decision support + research. USCDI v4 + FHIR Implementation Guides specify which terminology is required per data class.

Jurisdiction: GLOBAL

Lifecycle: Active

COSO_ERM_2017

COSO Enterprise Risk Management — Integrating with Strategy + Performance

COSO ERM 2017 is the enterprise risk management reference framework used by US public companies, financial-services firms, and increasingly enterprise CFO + CRO offices globally. Integrates risk management with strategy and performance through 20 principles across 5 components. Heavily referenced by SOX + SEC risk-management commentary; the de-facto framework for ERM committee structure.

Jurisdiction: US

Lifecycle: Active

CQC_FUNDAMENTAL_STANDARDS

CQC Fundamental Standards

The Care Quality Commission (CQC) Fundamental Standards are the regulations all CQC-registered providers in England must meet — covering person-centred care, dignity + respect, consent, safe care + treatment, safeguarding, nutrition + hydration, premises + equipment, complaints, good governance, staffing, fit + proper persons, and duty of candour. Breach can result in registration conditions, prosecution + closure. The single assessment framework (effective from 2023) replaces previous KLOEs with quality statements + ratings: Outstanding / Good / Requires Improvement / Inadequate.

Jurisdiction: UK

Lifecycle: Active

CRR_CRD_V_VI

EU Capital Requirements Regulation + Directive (CRR + CRD)

The EU's transposition of Basel III into binding regulation (CRR) + member-state-transposed directive (CRD). CRR3 + CRD VI were adopted in 2024 to complete Basel III + add the 2017 Basel "Endgame" reforms — revised credit risk standardised approach, operational risk + output floor. Applies to EU credit institutions + investment firms (with separate prudential regime IFR/IFD for smaller investment firms). Enforcement: ECB (Single Supervisory Mechanism) for significant institutions + national competent authorities for others. Key obligations: capital ratios + buffers, LCR, NSFR, leverage ratio, large exposures, governance + remuneration, public disclosure (Pillar 3).

Jurisdiction: EU

Lifecycle: Active

CSA_CCM_V4_2024

CSA Cloud Controls Matrix v4

CSA Cloud Controls Matrix v4 is the Cloud Security Alliance's cloud-specific control framework — 197 controls across 17 domains, mapped to ISO 27001, ISO 27017, NIST 800-53, PCI DSS, and others. Forms the assessment criteria for CSA STAR Level 1 (self-assessment) + Level 2 (third-party certification) and is increasingly required by enterprise cloud procurement.

Jurisdiction: GLOBAL

Lifecycle: Active

CYBER_ESSENTIALS_2023

Cyber Essentials

Cyber Essentials and Cyber Essentials Plus are the UK government-backed cybersecurity certifications administered by the IASME consortium and required for many public-sector contracts. Cyber Essentials is self-assessed across five technical control areas (firewalls, secure configuration, user access control, malware protection, security update management); Cyber Essentials Plus adds independent technical testing. The 2023 update tightened expectations around cloud services, MFA on internet-facing services, and bring-your-own-device. Certification is annual and is the fastest credible signal to UK buyers that baseline cyber hygiene is in place.

Jurisdiction: UK

Lifecycle: Active

DICOM_CURRENT

DICOM — Digital Imaging and Communications in Medicine

DICOM is the international standard for medical imaging + related metadata, used in nearly all radiology, cardiology + oncology imaging worldwide. Covers data structure (Information Object Definitions), services (Storage, Query/Retrieve, Modality Worklist, Print), network protocol (DICOM upper layer over TCP/IP) + media exchange. DICOMweb (RESTful DICOM) modernises access. Tightly integrated with HL7 + IHE Profiles (XDS-I, Scheduled Workflow, etc.). Compliance is operational rather than certified, but interoperability with PACS / VNA / RIS is the practical test.

Jurisdiction: GLOBAL

Lifecycle: Active

DORA_PROFILE_2025

DORA Obligations Profile

The EU Digital Operational Resilience Act (DORA) is the binding ICT resilience regime for banks, insurers, investment firms, payment institutions, crypto-asset providers, and a long list of critical ICT third parties from 17 January 2025. National competent authorities (NCAs) and the ESAs can fine, issue enforcement actions, and require corrective action plans. Defensible compliance proves an ICT risk-management framework, a current third-party register at contract-level, structured incident reporting on regulator timelines, threat-led penetration testing for critical entities, and resilience testing across important business services — not just the IT estate.

Jurisdiction: EU

Lifecycle: Active

EU_EECC_5G_TOOLBOX

EU 5G Security Toolbox

The EU 5G Security Toolbox is a coordinated EU approach to securing 5G networks. Recommends strategic + technical risk-mitigation measures including supplier risk assessment, multi-vendor strategies, restricting high-risk vendors from core + sensitive parts of networks + mitigating dependencies. Implemented through national + sector regulations. Pairs with UK Telecommunications Security Act + national equivalents.

Jurisdiction: EU

Lifecycle: Active

EU_ADR_DANGEROUS_GOODS

ADR — European Agreement on Dangerous Goods by Road

ADR (Accord européen relatif au transport international des marchandises Dangereuses par Route) is the European agreement on the international carriage of dangerous goods by road. Classifies hazardous substances + sets requirements for packaging, marking + labelling, vehicles, tank construction, training (DGSA), documentation + security. Updated biennially. Implemented across 50+ countries including UK + EU. Companion modes: RID (rail), ADN (inland waterways), IMDG Code (sea), ICAO TI / IATA DGR (air). DGSA appointment required for in-scope companies.

Jurisdiction: EU

Lifecycle: Active

EU_AI_ACT_2024_1689

EU AI Act

EU Regulation 2024/1689 (the AI Act) is the first comprehensive AI law — a risk-tiered regulation reaching anyone who places an AI system on the EU market, puts one into service in the EU, or whose output is used in the EU. Penalties reach €35 million or 7% of global turnover for prohibited-practice violations; €15 million or 3% for high-risk non-compliance. Obligations land in waves: prohibited practices and AI literacy from February 2025; general-purpose AI model rules from August 2025; full high-risk system obligations from August 2026. High-risk systems (Annex III: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice, democratic processes) require a registered AI system, risk-management process, data-governance evidence, technical documentation, logging, human oversight, accuracy/robustness/cybersecurity testing, and a quality-management system. Quick Policy seeds the AI governance, AI risk, transparency, and human-oversight policies the Act requires and links them to ISO 42001 + 42005 for a defensible audit trail.

Jurisdiction: EU

Lifecycle: Active

EU_ATEX_2014_34

EU ATEX 2014/34/EU — Equipment for Explosive Atmospheres

The ATEX Equipment Directive 2014/34/EU sets requirements for equipment + protective systems intended for use in potentially explosive atmospheres placed on the EU market. Companion to ATEX Workplace Directive 1999/92/EC. Equipment categorised by Group (I mining, II surface) + Category (1/2/3 reflecting protection level). CE marking + Ex marking + DoC required. Notified body involvement increases with category. Aligned with IEC 60079 series.

Jurisdiction: EU

Lifecycle: Active

EU_AVMSD

EU Audiovisual Media Services Directive

The EU Audiovisual Media Services Directive (AVMSD) regulates television broadcasting + on-demand audiovisual media services (VOD) + video-sharing platforms (VSPs) across EU Member States. Covers protection of minors, commercial communications, European works promotion (30% quota for VOD), accessibility + advertising restrictions. National regulatory authorities (e.g. Ofcom (formerly), CNIL, AGCOM) implement nationally. Implemented in UK as Audiovisual Media Services Regulations (retained post-Brexit).

Jurisdiction: EU

Lifecycle: Active

EU_BATTERY_REG_2023

EU Battery Regulation 2023/1542

The EU Battery Regulation 2023/1542 replaced the Battery Directive 2006/66/EC. Covers all battery categories — portable, EV, industrial, LMT (light means of transport), SLI. Imposes carbon footprint, recycled content, due diligence, performance + durability, removability + replaceability + labelling requirements. Phased implementation 2024-2030+. Strong supply-chain due-diligence requirements for cobalt, lithium, nickel + natural graphite.

Jurisdiction: EU

Lifecycle: Active

EU_CPR_305_2011

EU CPR — Construction Products Regulation (EU) 305/2011

The EU Construction Products Regulation 305/2011 (CPR) establishes harmonised conditions for the marketing of construction products in the EU. Requires the CE marking of products covered by a harmonised European standard (hEN) or European Assessment Document (EAD), based on a manufacturer's Declaration of Performance (DoP). Sets out 7 basic requirements for construction works. UK has implemented a UKCA-marking parallel regime post-Brexit. 2024 CPR reform — Regulation (EU) 2024/3110 — modernises the framework.

Jurisdiction: EU

Lifecycle: Active

EU_CSDDD_2024

EU Corporate Sustainability Due Diligence Directive

The EU CSDDD obliges large EU + non-EU companies to identify, prevent + mitigate adverse human rights + environmental impacts in their operations + value chains. In-scope: EU companies >1,000 employees + €450m turnover; non-EU companies with €450m EU turnover. Phased implementation 2027-2029. Civil liability + Member State enforcement; transition plans for climate. Companion to CSRD reporting.

Jurisdiction: EU

Lifecycle: Active

EU_CSRD_REPORTING

EU CSRD + ESRS — Corporate Sustainability Reporting

The EU Corporate Sustainability Reporting Directive (CSRD) Directive (EU) 2022/2464 + the European Sustainability Reporting Standards (ESRS) adopted by EFRAG significantly expand sustainability reporting for in-scope EU companies + non-EU companies with EU activities. Phased application from 2024 for large public companies + extending to large + listed SMEs by 2027. Mandatory double-materiality assessment + assurance by auditor / independent assurance provider. Companion: SFDR for financial market participants.

Jurisdiction: EU

Lifecycle: Active

EU_DMA_DIGITAL_MARKETS

EU Digital Markets Act (DMA)

The EU Digital Markets Act (Regulation (EU) 2022/1925) sets rules for "gatekeepers" — large digital platforms providing core platform services. Imposes obligations + prohibitions to ensure contestable + fair digital markets including interoperability, data portability, anti-self-preferencing + transparent app stores. Enforced by EU Commission. Fines up to 10% global turnover (20% for repeats). Indirectly affects retail through marketplace + advertising rules.

Jurisdiction: EU

Lifecycle: Active

EU_DSA_DIGITAL_SERVICES

EU Digital Services Act (DSA)

The EU Digital Services Act (Regulation (EU) 2022/2065) regulates online intermediaries + platforms. Imposes obligations including transparent content moderation, transparent advertising, recommender system transparency, risk assessments (for Very Large Online Platforms (VLOPs) + Very Large Online Search Engines (VLOSEs)) + Trusted Flaggers. Online marketplaces face additional KYC of business users. Enforced by Member State Digital Services Coordinators + EU Commission. Fines up to 6% global turnover.

Jurisdiction: EU

Lifecycle: Active

EU_EASA_PART_M_145

EU EASA Aircrew + Air Operations + Maintenance

The European Union Aviation Safety Agency oversees civil aviation safety across EU Member States + EASA-participating states. Implementing Regulations cover Aircrew (Part-FCL), Air Operations (Part-ORO, Part-CAT, Part-SPO), Continuing Airworthiness (Part-M, Part-145), Initial Airworthiness (Part-21) + Aerodromes (Part-ADR). National Aviation Authorities (NAAs) implement EASA regulations. AOC (Air Operator Certificate) + Continuing Airworthiness Management Organisation (CAMO) approvals. UK post-Brexit operates a parallel CAA regime largely aligned with EASA.

Jurisdiction: EU

Lifecycle: Active

EU_EECC_TELECOMS

EU European Electronic Communications Code

The European Electronic Communications Code (EECC) is the foundational EU regulatory framework for electronic communications networks + services + associated facilities. Covers market regulation, spectrum, end-user rights (transparency, contract information, switching, fault repair), universal service + security of networks + services. National Regulatory Authorities (NRAs e.g. ComReg, BNetzA) implement. UK retained pre-Brexit equivalent via Communications Act 2003 + General Conditions.

Jurisdiction: EU

Lifecycle: Active

EU_EMC_2014_30

EU EMC 2014/30/EU — Electromagnetic Compatibility

The Electromagnetic Compatibility Directive 2014/30/EU sets essential requirements for equipment to not generate excessive electromagnetic disturbance + to function in its intended electromagnetic environment. Applies to most electrical + electronic equipment placed on the EU market alongside LVD. Self-certification via technical file + DoC supporting CE marking. Harmonised standards EN 55032, EN 61000 series, EN 55035.

Jurisdiction: EU

Lifecycle: Active

EU_ESPR_2024

EU Ecodesign for Sustainable Products Regulation

The Ecodesign for Sustainable Products Regulation (ESPR) (EU) 2024/1781 expands the Ecodesign Directive 2009/125/EC. Sets a framework to apply ecodesign + circular requirements to virtually all physical products placed on the EU market (initial focus: textiles, iron + steel, furniture, tyres, chemicals, paint). Introduces the Digital Product Passport (DPP), prohibits destruction of unsold consumer goods + sets ecodesign requirements through delegated acts. Phased implementation.

Jurisdiction: EU

Lifecycle: Active

EU_F_GAS_517_2014

EU F-Gas Regulation 517/2014

EU Regulation 517/2014 (F-Gas Regulation) controls fluorinated greenhouse gases used in refrigeration, air conditioning, heat pumps + fire protection. Imposes a phase-down quota system on HFC placement on the EU market, leak-check obligations, record-keeping, recovery + destruction obligations + training + certification of technicians + companies. Revised by Regulation (EU) 2024/573 — accelerated HFC phase-down to net-zero by 2050. UK retained equivalent regime post-Brexit.

Jurisdiction: EU

Lifecycle: Active

EU_ALLERGEN_FIC_1169_2011

EU Food Information to Consumers Regulation 1169/2011

EU FIC Regulation 1169/2011 sets mandatory food information rules for the EU — covering allergen declaration (14 listed allergens), nutrition labelling, country of origin, durability date + readability. UK Natasha's Law (Food Information Amendment 2019) extends allergen labelling to prepacked-for-direct-sale (PPDS) food + is widely referenced as a model elsewhere.

Jurisdiction: EU

Lifecycle: Active

EU_852_2004_HYGIENE

EU Regulation (EC) 852/2004 on the Hygiene of Foodstuffs

EU regulation setting general hygiene requirements for all food business operators, including HACCP principles, food premises + equipment, water, waste, personal hygiene + training. Annex I covers primary production; Annex II covers processing.

Jurisdiction: EU

Lifecycle: Active

EU_FOOD_LAW_178_2002

EU General Food Law Regulation (EC) 178/2002

Foundation EU food regulation establishing general principles + requirements of food law, the European Food Safety Authority + procedures in matters of food safety. Imposes traceability (Article 18), the precautionary principle, withdrawal/recall (Article 19) + responsibility of food + feed business operators.

Jurisdiction: EU

Lifecycle: Active

EU_GENERAL_FOOD_LAW_178_2002

EU General Food Law Regulation 178/2002

EU Regulation 178/2002 is the foundational EU food law — establishing food safety principles, the European Food Safety Authority (EFSA), the Rapid Alert System for Food + Feed (RASFF) + the precautionary principle. Imposes traceability + withdrawal / recall obligations on all food businesses. Companion regulations cover hygiene (852/2004), official controls (625/2017) + food information to consumers (1169/2011).

Jurisdiction: EU

Lifecycle: Active

EU_GPSR_2023

EU General Product Safety Regulation 2023/988

EU Regulation 2023/988 (General Product Safety Regulation — GPSR) replaces the General Product Safety Directive 2001/95/EC from December 2024. Imposes safety + traceability + recall obligations on producers, importers, distributors + online marketplaces. Internal Production Control + risk assessment required. Mandatory online product safety information + corrective action public notifications. Companion: Market Surveillance Regulation 2019/1020 + product-specific safety laws.

Jurisdiction: EU

Lifecycle: Active

EU_IVDR_2017_746

EU IVDR — Regulation (EU) 2017/746

The EU In Vitro Diagnostic Regulation (IVDR) replaced the IVDD, applying since 26 May 2022. Risk-based classification (Class A / B / C / D) drives notified-body involvement for the vast majority of IVDs (vs ~10% under IVDD). Sets requirements on clinical evidence (scientific validity, analytical + clinical performance), performance evaluation reports, EUDAMED registration, UDI, and Person Responsible for Regulatory Compliance. Transitional provisions extended in 2024 (IVDR Amendment 2024/1860) for legacy IVDD devices.

Jurisdiction: EU

Lifecycle: Active

EU_LVD_2014_35

EU LVD 2014/35/EU — Low Voltage Directive

The Low Voltage Directive 2014/35/EU sets essential safety requirements for electrical equipment operating between 50-1000V AC + 75-1500V DC placed on the EU market. Self-certification via technical file + DoC supporting CE marking. Aligned with harmonised standards (EN IEC 62368 + others). One of the foundational CE-marking directives. Enforced by Member State market surveillance.

Jurisdiction: EU

Lifecycle: Active

EU_MACHINERY_REGULATION_2023

EU Machinery Regulation 2023/1230

The EU Machinery Regulation 2023/1230 (effective 2027) replaces the Machinery Directive 2006/42/EC. Sets essential health + safety requirements for the design + construction of machinery placed on the EU market, plus requirements for CE marking, Technical File, Declaration of Conformity + (for Annex I "high-risk" machinery including AI-enabled) third-party assessment. AI-enabled machinery + cybersecurity addressed for the first time. Companion to LVD + EMC + RED.

Jurisdiction: EU

Lifecycle: Active

EU_MCD_2014_17

EU Mortgage Credit Directive 2014/17/EU

EU Directive regulating credit agreements for consumers relating to residential immovable property. Establishes harmonised pre-contractual information (ESIS), creditworthiness assessment, conduct of business rules + cooling-off / reflection period.

Jurisdiction: EU

Lifecycle: Active

EU_MDR_2017_745

EU MDR — Regulation (EU) 2017/745

The EU Medical Device Regulation (MDR) replaced the MDD + AIMDD, applying since 26 May 2021. Sets requirements for the placing on the market + putting into service of medical devices + their accessories in the EU. Drives notified-body conformity assessment, technical documentation (Annex II + III), clinical evaluation (Annex XIV), post-market surveillance (Annex III) + post-market clinical follow-up. EUDAMED registration + UDI assignment + Person Responsible for Regulatory Compliance (PRRC) required. Transitional provisions extended in 2023 (MDR Amendment 2023/607) for legacy MDD devices.

Jurisdiction: EU

Lifecycle: Active

EU_NITRATES_91_676

EU Nitrates Directive 91/676/EEC

EU Directive protecting waters against pollution caused by nitrates from agricultural sources. Member States designate Nitrate Vulnerable Zones (NVZs) + adopt action programmes with manure storage + spreading limits.

Jurisdiction: EU

Lifecycle: Active

EU_ORGANIC_2018_848

EU Organic Regulation (EU) 2018/848

EU regulation on organic production + labelling of organic products. Replaces 834/2007 from 2022. Covers crops, livestock, aquaculture, processed food, wine, yeast + seaweed. Mandates certification by control bodies + organic logo on labelled products.

Jurisdiction: EU

Lifecycle: Active

EU_PED_2014_68

EU PED — Pressure Equipment Directive 2014/68/EU

The Pressure Equipment Directive 2014/68/EU establishes essential safety requirements for the design + manufacture of pressure equipment + assemblies placed on the EU market. Classifies equipment by category (I-IV) based on pressure, volume + fluid type with corresponding conformity assessment modules. Notified body involvement increases with category. CE marking + DoC required. Companion: SPVD 2014/29/EU for simple pressure vessels.

Jurisdiction: EU

Lifecycle: Active

EU_PESTICIDES_1107_2009

EU Regulation (EC) 1107/2009 — Plant Protection Products

EU regulation on the placing of plant protection products (pesticides) on the market. Companion: Sustainable Use Directive 2009/128/EC + Maximum Residue Levels Regulation 396/2005. Establishes active substance approval + product authorisation.

Jurisdiction: EU

Lifecycle: Active

Review industries served

See how standards context shows up in sector-specific rollout and drafting guidance.

Read supporting articles

Explore long-form explainers, buyer guides, and roadmap content that supports these standards pages.

Validate platform fit

Compare the workflow, trust material, and rollout path before starting a free guided preview.

Need help baselining against specific standards?

Use Quick Policy to turn standards context into practical drafting, review, and evidence workflows.