My product falls under the CRA.
- Reporting duty
- live
- Technical file
Every framework, one subscription
A few questions, one button, and it stays compliant.
€249/mo flat, excl. VAT · no card to start · cancel in-app anytime
Frameworks
8 frameworks
For ISO 27001, ISO 42001 and ISO 9001
Support is included and answered within one business day by the people who build the product, before the certificate and through every surveillance year after it.
You do not need to be an expert.
€249/moevery feature14 days freeno card
This is the product's actual scoping engine, running in your browser. Your answers stay on this page. Nothing is sent anywhere.
Question 1 of 7
The obligations are written, the dates are fixed, and the documentation each one wants is what StandardOS drafts.
Article 14 makes reporting a duty for anyone placing a product with digital elements on the EU market. Two destinations, three deadlines, one clock that starts when you become aware.
The reporting deadlinesRegulation (EU) 2023/1230 replaces the Machinery Directive. A manufacturer needs the file, the declaration and the essential health and safety requirements assessed.
What the file containsFrom December 2027 a product needs its Annex I assessment, its vulnerability handling, and a technical file an authority can ask for. 11 controlled documents.
The CRA technical fileEverything an auditor will ask about lives in one place, versioned and connected, and the product always knows what your next step is. Below are the two artefacts they read first, at the size they are read.
Readiness at a glance, the road to certification as an ordered checklist, and the operational numbers that slip (overdue tasks, expiring evidence, open corrective actions) before they become audit findings.
Access Control Policy
sha256
9f2a1c77d0b4e83a5f6c2d19b7e4a08c3d5f91b2e7c46a80d1f3b5927ce4a061
Chain intact, anchored2026-09-07
A worked example, not a customer's record.
All 93 controls with applicability, implementation status, and drafted justifications, reviewed control by control, exported as a hash-stamped PDF the moment your auditor asks.
Use of cryptography
Applicable
Justification
Customer data is encrypted at rest and in transit. TLS 1.2 and above is enforced at the edge, and database encryption is managed by the provider under the agreement in our supplier register.
Drafted by StandardOS from your scoping answers, edited by you on 3 August 2026.
A worked example, not a customer's record.
A template pack tells you what to do. This connects to the 12 systems you already run and re-verifies 125 controls against them, on your own tenants, with read-only credentials you grant and can revoke.
125
checks re-run every day, against your own systems
Amazon Web Services · Microsoft Azure · Google Cloud
Microsoft Entra ID · Okta · Google Workspace
Kandji · Jamf Pro · Microsoft Intune
GitHub
Snyk
Personio
Evidence collected this way carries the date it was read and the account it was read from, so it does not go stale between audits. When a check that was passing starts failing, the owners and admins hear about it the same day rather than the week before the audit.
Every check, and the scopes each connection asks for01
Answer seven questions and get a drafted Statement of Applicability (the master list of which of the 93 ISO 27001 controls apply to you and why) with a rationale against every one, ready to tailor.
02
Generated policies, a starter risk register, and a compliance calendar, all editable, versioned and approved. Then it keeps going: evidence carries an expiry date, connected systems refresh it on their own, and anything about to lapse reaches you before it does.
03
Hash-stamped, tamper-evident PDFs and a one-click export your auditor understands instantly.
04Your certification auditBooked with an accredited body, which reads the four documents and checks they describe one organisation. That is the whole of Stage 1.
Why auditors relax when they see it
Every change to your ISMS records is appended to a hash chain, each entry sealed with the fingerprint of the one before it and with who made it.
append-only · sha-256 chained · anchored daily to your inbox · verifiable without us
You are buying an information-security tool, so it goes through the same vendor review as everything else. Those answers were already published. They were not on this page.
And the part most vendor pages leave out: of the ISO 9001 clauses, 21 are covered in full, 11 in part, and 4 not at all. We publish the register clause by clause, including the gaps, because a coverage claim you cannot check is not worth making.
The register, clause by clause€249/mo · excl. VAT
Flat, per organization. Every feature. Unlimited people.
Your certification body's audit fee is separate and paid to them. see what that costs.
No card required to start · reminder email before any charge · cancellation policy
Sold to businesses and organizations only.
No. The 14-day trial starts without payment details, and there is no auto-charge when it ends. A subscription begins only when you go through checkout yourself. We email you three days before the trial ends so the date is never a surprise. If you do nothing, the workspace becomes read-only when the trial ends: nothing is deleted, and you can still sign in, read everything and export it all.
It is software rather than consulting: the management system itself, with drafts generated for you to confirm. That does not mean you are on your own with it. Every screen explains what the clause behind it actually asks for, in plain language, and support is email, answered within one business day by the people who build the product. There is no sales team, and nobody will call you.
It depends where your customers are, and it is worth checking rather than assuming. In EU public procurement it is not close: over the last 365 days ISO 27001 appears in 3,405 tender notices on TED, the EU's own procurement portal, against 104 for SOC 2, about 32.7 times more often. Counting every spelling of both, on 12 September 2026, and TED's search API is public so you can run it yourself. Those are mentions rather than requirements, and the ratio compares like with like. If you sell mainly to US companies the argument runs the other way: SOC 2 is the shape their procurement expects, and we do not do SOC 2.
See the TED numbers →Our €249/mo, plus an accredited certification body's audit fee, which is a separate company you pay directly. Nobody in this market publishes that fee, but it is auditor days × day rate and the days are fixed by ISO/IEC 27006, so you can work it out in advance. For a 25-person company it is roughly €8,000–€13,000 for initial certification and about a third of that annually after.
Work out your number →Email us, and a person who built the product answers within one business day. That is included in the price, not an add-on. Every screen also explains what the clause behind it actually asks for, in plain language, so most questions answer themselves before they reach us.
Four to seven months is realistic for a small software company. About three months is the floor no tool can beat: your internal audit and management review have to have actually happened before Stage 2, because the auditor samples those records. What software removes is the two-to-six months of building the system beforehand.
See the full timeline →No, and the reason is not a missing feature. All 93 Annex A controls get a Statement of Applicability entry with a justification, and every one of the 26 management-system clauses in 4 to 10 has a place in the product. What no software can do is be the evidence: clause 5.1 is leadership demonstrating commitment, and every record still has to be something you actually wrote and meant. We print the clause-by-clause list before you pay, which most tools in this market do not.
See it clause by clause →ISO/IEC 27001:2022 and ISO/IEC 42001:2023, the AI management system standard, with all 38 of its Annex A controls. Clauses 4 to 10 are the identical harmonised structure in every modern ISO standard: the same documents, risks, audits, reviews and corrective actions. So the machinery that runs one runs the other, and a record you keep for one counts towards both. We publish the clause-by-clause coverage for both before you pay.
See ISO 42001 →You write to us and we look at it with you, within one business day. The product shows you what an auditor will sample before they arrive: overdue reviews, expired evidence, controls with nothing behind them. If the record is wrong, you fix the record; if the product is wrong, we fix the product. What we cannot do is sit in the audit for you or promise its outcome: certification is the auditor's judgment of how you actually operate.
In the European Union (Ireland), whichever country you are in. StandardOS is operated by a Danish company under the GDPR, so EU privacy law protects your records by default rather than by contract, wherever you are. Our Article 28 data processing agreement is published in full at /legal/dpa for every customer, with no signature and no sales call, and the Trust page lists every subprocessor and where each one processes data.
Yes. ISO/IEC 27001 and ISO/IEC 42001 are international standards, audited to the same requirements by accredited bodies in every country, and the management system StandardOS builds is the standard's own, not a regional interpretation of it. The EU material you will see around this site is included on top: GDPR Article 30 processing records, Cyber Resilience Act Article 14 incident reporting, NIS2, and the EU AI Act position in the ISO 42001 templates. If those reach you, they are already there; if they do not, you can ignore them and nothing about the certification changes. Your certification body is local to you, and subscriptions are billed in euros.
Export everything, in open formats, with one click, during the trial, while subscribed, and for 90 days after cancelling. Cancellation itself is one click in Billing, effective end of the period.
No tool can. Certification is an accredited auditor's judgment of how your organization actually operates. What StandardOS does is make the system you'll be audited on: complete, consistent, and backed by records your auditor can verify.
Your auditor will ask for twelve months of records.
The time to start collecting them is not the month before the audit.