Regulations / Enterprise procurement
Regulations by jurisdiction
Enterprise procurement: what binds a connected product
When the buyer is a corporation rather than a consumer or a regulator, the questions are organisational. ISO 27001 alignment is the usual gate, and it is about the supplier, not the product.
| Framework | Applies when | Who demands it | In force | Penalties |
|---|---|---|---|---|
| ISO 27001 / 27002 | Enterprise buyers that require ISMS alignment from suppliers | Procurement and tenders | 2022 edition current | None; losing the tender |
ISO 27001 / 27002
Not a product standard. Organisational risk treatment, asset ownership, supplier agreements, internal audit. A product can pass every ETSI provision and still fail procurement if nobody owns the ISMS.
Check your own product
The IoT security scorecard and the requirements generator resolve these frameworks for your product archetype and markets. Educational reference, not legal advice.
← All jurisdictions