Industries
The rules for your kind of company, with your deadlines on them.
One page per kind of company: the frameworks that reach it, the dates they apply from, and two ways to start.
Machine makers
The Machinery Regulation, the Cyber Resilience Act and NIS2 each want something different from a machine maker. StandardOS tells you which apply, drafts the technical files and keeps the evidence current.
- CRA reporting ·
- Machinery Regulation ·
- The CRA in full ·
Software and SaaS
ISO 27001 for the security questionnaires, the Cyber Resilience Act for software you place on the market, and ISO 42001 if you build with AI. One system runs them together, with the evidence read from your tools every day.
- CRA reporting ·
- The CRA in full ·
IT service providers
Managed service and managed security service providers are listed in Annex I of NIS2, whatever sector their clients are in. StandardOS works out your status, prepares the registration and keeps the ISO 27001 evidence current from your own tools.
- NIS2 applies ·
- NIS2 registration ·
Finance and ICT suppliers
DORA has applied to financial entities since 17 January 2025, and Article 30 sets what their contracts with ICT suppliers must contain. StandardOS keeps the clause answers, the register-of-information fields and the due-diligence answers your customers ask for in one place.
- DORA applies ·