How to read a standards requirement
Whatever sector you are in, a requirement reaches you in one of three shapes, and the first thing to settle is which one you are holding. A standard is a document you meet because a contract, a tender or a customer's quality clause names it; ISO 9001, AQAP 2110 and ISO/IEC 27001 are standards, and the most useful of them are certifiable, meaning an accredited body audits you and issues a certificate. A regulation is a law that binds you because of what you are and what you sell, whether or not a contract mentions it; the MDR, EU GMP, NIS2 and DORA are regulations, and an authority, an inspector or a notified body enforces them. Guidance is what a regulator or an industry body publishes on how it expects a rule to be met; the GMP annexes, the ICH guidelines and the MDCG documents are guidance, not binding in themselves and read as if they were. The explorer below labels every entry as one of the three.
Most of it starts with ISO 9001
For most companies the first standard a customer asks about is ISO 9001, the quality management system standard, and almost everything else builds on it. Defence adds the AQAPs on top of it. A medical device quality system, ISO 13485, is ISO 9001 in shape with what a regulator expects added. A pharmaceutical quality system under ICH Q10 is built on the same concepts. ISO/IEC 27001 uses the same management-system structure for information security, so a company that holds one is halfway to holding the other. A certified ISO 9001 system is the usual place to start, and the ISO management-system standards page explains the family.
Four sectors, one map
The cards below take you to the sector pages. Defence covers NATO's STANAGs and Allied Publications, the AQAP quality standards and EN 9100. Cybersecurity covers the ISO/IEC 27000 family, the NIST and CIS frameworks, IEC 62443, and the EU laws from NIS2 to the Cyber Resilience Act. Pharma and medical devices covers EU GMP and its annexes, the ICH guidelines, 21 CFR, the MDR and IVDR, and the ISO and IEC standards for devices and for software as a medical device. Risk management covers ISO 31000 and the techniques and sector standards that all describe the same process. Every page has its own explorer, scoped to its sector; the one on this page holds all of it.
Who decides what applies to you
Not this page, and not us. The contract names the standard, the law names its own scope, and the authority or the notified body decides what evidence it expects. What the explorer can do is show you the whole map: search it by number or name, browse it by family, or answer four questions and see which areas companies like you are commonly asked about. Each entry links to its source, to its ComplyTrain page where one exists, and otherwise to a request. ComplyTrain holds a standard as a requirement tree with the evidence against each requirement. The certificate stays yours to earn.