Standardization as law ISO and IEEE explained

Standardization as law: ISO and IEEE explained

ISO and IEEE standards are voluntary, yet regulatory citation, contracts, and liability law quietly turn them into rules with the force of legislation.

The concept of "standardization as law" describes a contemporary regulatory phenomenon where technical standards, despite not being formal statutes, effectively operate with the force of legal requirements. Organizations such as the International Organization for Standardization (ISO) and the Institute of Electrical and Electronics Engineers (IEEE) are central to this dynamic. Their voluntary guidelines transform into mandates through a series of mechanisms, blurring the lines between what is legally enacted and what is practically enforced within industries and governmental frameworks.

This transition from soft law to hard law signifies a fundamental shift in governance, particularly in sectors requiring intricate technical specifications and interoperability. Nobody voted for ISO 9001. Yet in construction, food safety, and medical devices, ignoring it can be just as costly as breaking a statute.

The spectrum of legal authority: Soft law versus hard law

Understanding how standards acquire legal weight requires a clear distinction between "soft law" and "hard law."

Hard law encompasses traditional, legally binding instruments - statutes, governmental regulations, international treaties. These are enforceable through formal legal processes, and non-compliance typically brings penalties or legal repercussions.

Soft law is different. It comprises non-binding guidelines, principles, declarations, and recommendations. It lacks direct legal enforceability, yet it exerts considerable influence over industry practices, ethical norms, and stakeholder expectations. International standards, in their initial form, often reside within this soft law domain - frameworks for best practice rather than strict commands.

There's a second distinction worth holding onto: de jure versus de facto.

  • De jure refers to what is established by law - formally recognized, legally binding.
  • De facto describes what exists in practice, irrespective of formal legal sanction.

Many ISO and IEEE standards begin as de facto guidelines, emerging from industry consensus or technological prevalence. Over time, through the integration mechanisms described below, these de facto standards can acquire de jure legal force - and that shift fundamentally alters compliance requirements for everyone operating within their scope.

Mechanisms transforming standards into mandates

ISO and IEEE standards are generally conceived as voluntary frameworks. In practice, several distinct - and often overlapping - mechanisms routinely turn them into something closer to obligation.

Regulatory incorporation

The most direct route is regulatory incorporation. Governments and national regulatory bodies frequently reference or directly integrate ISO and IEEE standards into domestic laws and regulations. Once a standard is explicitly cited in legislation, adherence becomes a legal requirement for the industries or products in scope.

A few concrete examples make this less abstract:

  • ISO 22000, covering food safety management systems, is a mandatory requirement for food industry exports into certain global regions.
  • ISO 9001, the quality management standard, is frequently stipulated in government construction tenders, including in India.
  • ISO 13485 is a legal requirement for medical device manufacturers in numerous jurisdictions, governing quality from design through post-market surveillance.
  • ISO 14001, the environmental management standard, becomes practically mandatory for industries with heavy environmental footprints, or for suppliers whose customers impose strict ESG requirements down the chain.

In the European Union this incorporation takes a particularly formal shape. When a "harmonised standard" is cited in the EU's Official Journal under a piece of harmonisation legislation - the Machinery Regulation or the Toy Safety Directive, for instance - compliance with that standard creates a presumption of conformity with the underlying legal requirements. Meeting the standard is the easiest way to prove you've met the law; departing from it means proving compliance some other, harder way.

National regulators lean on ISO and IEEE standards as ready-made benchmarks for good practice, letting private technical expertise do work that would otherwise require drafting bespoke regulatory text from scratch. It's a shortcut, and a fairly elegant one - though, as the final section of this piece shows, not one without cost.

Technical guidelines are quietly rewriting the legal code, blurring the lines between engineering consensus and governmental mandate

Contractual obligation

Standards also become obligatory the old-fashioned way: through contracts.

Businesses routinely write specific ISO or IEEE standards into commercial agreements with clients, suppliers, and partners. A major automotive manufacturer, for example, might require every component supplier to hold IATF 16949 certification (the standard that superseded ISO/TS 16949) to keep quality consistent across a sprawling supply chain.

Fail to comply, and the consequences run through ordinary contract law - breach of contract claims, financial penalties, termination of the relationship. This is how commercial leverage quietly converts a voluntary guideline into a legally binding stipulation, enforceable in exactly the way any other contractual term would be.

True regulatory power no longer rests solely in parliaments; it emerges from the technical consensus of industry experts worldwide

Industry-specific mandates and market access

Many industries set their own bar for entry, and certification to a given standard often sits right at that threshold. ISO certification frequently acts as a gatekeeper - determining whether a company is even eligible to bid for certain contracts or serve certain customers.

For a company eyeing international expansion, holding the relevant ISO certification tends to stop being "nice to have" and starts being a precondition. This is especially visible in sectors with complex supply chains, high-stakes safety requirements, or dense technical interoperability needs - aerospace, medical devices, semiconductors.

Global supply chains are governed by private contracts; without the right certification, entire international markets remain impenetrable

Due diligence and liability mitigation

Here the standard functions less as a rulebook and more as a shield.

Adherence to established industry standards is a strong demonstration of due diligence in quality control, product safety, and environmental stewardship. When something goes wrong - product failure, environmental damage, an injury - courts and regulators typically ask whether the parties involved exercised reasonable care. Non-compliance with a widely accepted standard can be read as negligence; compliance, conversely, becomes a strong defense, evidence that the organization followed recognized best practice and took reasonable steps to prevent harm.

This dynamic matters most in tort law and product liability litigation, where a standard offers a clear, externally validated benchmark for what "acceptable conduct" actually looks like.

Compliance with an ISO or IEEE standard rarely settles a case outright. But it shifts the burden - and in litigation, that shift is often worth more than any single clause in the contract.

In the courtroom, compliance is the ultimate defense. Failing to adopt a voluntary standard is increasingly interpreted as legal negligence

De facto standardization through widespread adoption

Sometimes no government, court, or contract is needed at all. A technology, protocol, or practice simply becomes so pervasive within an industry that conforming to it is the only way to function within the ecosystem - a de facto standard.

Specific communication protocols developed under IEEE's auspices are a good illustration. Once a protocol becomes embedded across networking equipment, any new product entering that market effectively has to conform to it, whether or not any law says so. Market forces and technological momentum do the enforcing here, not legislation.

Sometimes, a technology becomes universally adopted, and no formal law is needed - the ecosystem itself demands absolute conformity

The architects of standards: ISO and IEEE

International Organization for Standardization (ISO)

ISO is a non-governmental organization, founded in the aftermath of the Second World War, responsible for developing and publishing international standards across nearly every corner of technology and manufacturing. It has published more than 25,000 international standards to date, covering everything from quality management to date formats to country codes.

Its membership is built around national standards bodies - one per country, currently numbering 175 members. The development process itself runs through more than 800 technical committees and subcommittees, drawing experts from industry, government, academia, and consumer organizations to build genuine consensus around technical requirements, rather than simply rubber-stamping whatever the largest player in a market happens to prefer.

ISO's own authority stops at persuasion. It has no legal power to compel anyone to implement its standards. What it has instead is scale: widespread acceptance, regulatory incorporation by governments around the world, and sheer market demand from companies that need the credibility a certification confers.

IEEE Standards Association (IEEE SA)

The IEEE Standards Association is a unit within the broader IEEE organization, focused on developing global technical standards. Where ISO's footprint is famously wide, IEEE SA's is deep in a specific set of domains - electric power systems, artificial intelligence, the Internet of Things, consumer technology, telecommunications. It maintains a substantial portfolio of over 1,400 standards and projects under active development at any given time.

The approval process is built around consensus rather than simple majority. A draft standard needs an affirmative vote from at least 75% of voting members present, alongside a minimum 75% response rate from balloting members overall. IEEE is explicit that its standards are not meant to obstruct international or domestic trade, nor to target specific products or companies - and it retains copyright over the standards it develops, a detail that becomes considerably more consequential later in this piece.

While lacking formal legislative authority, these private bodies draft the blueprints that governments and markets ultimately enforce

Collaboration, contention, and legal ramifications

Synergies and disputes in standards development

ISO and IEEE aren't strangers. The two organizations signed a partner standards development organization (PSDO) cooperation agreement in 2008, aiming to reduce duplicated effort and speed up the arrival of shared standards in areas like information technology, intelligent transport systems, and health informatics. For genuinely global interoperability to work, this kind of coordination is close to essential - fragmentation between competing technical specifications helps nobody.

But the relationship hasn't been free of friction. The clearest example traces back to IEEE's 2015 update to its patent policy, which changed the terms governing licensing of Standard-Essential Patents (SEPs) - the patents a company effectively cannot avoid infringing if it wants to implement a given standard.

The 2015 changes made it considerably harder for SEP holders to seek injunctions and tightened the definition of a "reasonable" royalty rate. Major patent holders, including several large telecom and technology firms, responded by submitting so-called "negative letters of assurance" - signaling that they were unwilling to license their patents under the revised terms. Within a few years, negative assurances came to dominate the letters submitted for certain standards, notably amendments to the Wi-Fi standard, IEEE 802.11.

The fallout reached beyond IEEE itself. ANSI and other national and international standards bodies grew reluctant to accredit IEEE standards carrying these negative assurances, and in March 2023 the ISO/IEC JTC-1 Plenary approved resolutions preventing IEEE standards accompanied by negative letters of assurance from flowing into ISO standards - an effort to keep IP terms considered inconsistent with F/RAND principles from "contaminating" the ISO catalogue.

The dispute didn't stay frozen at that point, though. IEEE revised its patent policy again, adjusting the letter-of-assurance form and accompanying guidance effective January 2023, moving the framework back closer to conventional FRAND practice elsewhere in the standards world. That revision eased much of the tension that had built up with ANSI and, by extension, with ISO. The episode is worth remembering less as a settled precedent and more as a case study in how quickly a patent policy tweak inside one standards body can ripple outward into the legitimacy of standards everywhere else.

Notably, the U.S. Department of Justice reviewed IEEE's original 2015 patent policy update and declined to challenge it, concluding it had the potential to facilitate mutually beneficial licensing agreements and support pro-competitive standards development.

The metamorphosis from optional to obligatory relies on an inescapable web of market pressures, contractual locks, and liability fears

Academic and legal perspectives on standards' authority

Legal scholars have paid increasing attention to how international standards feed into national legislation. The consensus view is that standards contribute meaningfully to the harmonization of legal norms across jurisdictions - a country adopting an ISO standard wholesale gets a shortcut to regulatory consistency with its trading partners. In practice, though, implementation isn't always smooth; legislative conflicts with existing domestic law and administrative friction can slow adoption considerably.

This soft-law-to-hard-law pathway is particularly attractive for emerging technologies, where the traditional treaty-based approach to international governance - slow, resource-intensive, politically fraught - simply moves too slowly to keep pace. Soft law offers something more nimble: a framework that can harden into a legal mandate once incorporated into a statute, regulation, or treaty, without requiring years of multilateral negotiation to get there.

Governments have their own reasons to lean on this mechanism. Referencing an international standard can help create a level playing field with trading partners, support competitive neutrality, or lend outside credibility to a domestic regulation that might otherwise struggle for political support on its own merits. Seen this way, a technical standard becomes an instrument of policy as much as engineering.

For readers interested in how a comparable dynamic plays out in a very different area of international law - where written assurances also fell short of binding legal guarantees - the Budapest Memorandum's assurances to Ukraine offers a striking parallel: soft commitments that carried real diplomatic weight without ever converting into enforceable hard law.

When governments cite a standard, they outsource regulation, instantly transforming industry best practices into enforceable national statutes

The Malamud case and copyright implications

The clearest recent test of how far "standardization as law" actually extends came from the European Court of Justice, in what's become known as the Malamud case (formally, Case C-588/21 P).

Two non-profit organizations, Public.Resource.Org and Right to Know, had asked the European Commission for free access to several harmonised technical standards - specifically, EU toy safety standards referenced in the Official Journal. The Commission refused, citing the standard-setters' copyright. The General Court initially sided with the Commission in 2021. On appeal, though, the ECJ reversed course: in its March 2024 ruling, the Court held that because these harmonised standards had been given legal effect through publication in the Official Journal, they formed part of EU law - and documents that are part of EU law must be accessible to any citizen who requests them.

The ruling didn't abolish copyright in standards outright, but it did force a reckoning. National standards organizations - including Germany's DIN and others - responded by building read-only "readability platforms" where the specific standards covered by the ruling can be viewed, though not downloaded or redistributed; copyright formally remains with the standards bodies.

ISO and the International Electrotechnical Commission (IEC), both of which co-author many EU harmonised standards and rely heavily on licensing revenue from selling access to them, pushed back hard. In December 2024, they filed suit against the European Commission, arguing that extending the Malamud logic to their internationally co-authored standards infringed their copyright. That case remains before the General Court. In the meantime, a genuine bottleneck emerged: European standardisation bodies have been unable to propose new EN ISO or EN IEC standards for publication in the EU Official Journal while the copyright question stays unresolved - a pause with real consequences for any regulation that depends on referencing an up-to-date harmonised standard.

It's a genuinely awkward position for the standard-setters to be in. Their entire business model depends on selling access to documents that, once cited by a government, arguably stop being fully private property. The dispute is still working its way through the EU courts, and how it resolves will shape not just ISO and IEC's finances, but the basic question of how governments can lean on private technical expertise without eventually being forced to give that expertise away for free.

If a standard becomes public law, can it remain private property? The demand for free legal access threatens standard-setters' revenue model

Why this matters beyond compliance departments

It's tempting to treat all this as a niche concern for compliance officers and in-house counsel. It isn't. A handful of technical committees, most of whose deliberations never make the news, quietly set terms that shape:

  • which products can legally enter a market
  • which suppliers a manufacturer is permitted to use
  • how a court assesses negligence after an accident
  • how fast (or slowly) a government can regulate an emerging technology like AI or autonomous vehicles

None of that requires a single vote in a parliament. It requires a technical committee, a regulatory citation, and enough market pressure to make deviation impractical. That's the quiet trade at the center of standardization as law: efficiency and technical rigor, purchased at the cost of democratic visibility. Whether that trade is worth it probably depends on which side of the standard you're standing on.

The future of global regulation is technical: engineering specifications increasingly carry the practical weight of parliamentary decrees

Conclusion

The transformation of voluntary technical standards from ISO and IEEE into de facto and sometimes de jure legal requirements marks a genuine shift in global governance. Regulatory incorporation, contractual mandates, industry-specific prerequisites, and the quiet pull of due diligence all push in the same direction: what starts as a suggestion ends up functioning as a rule.

These standards were designed to deliver efficiency, interoperability, and quality - and by most measures, they do. But their growing reach also raises questions that are still very much unresolved: who owns a rule once a government cites it, who gets to access it, and where the line between private standard-setting and public legal authority should actually sit. The Malamud dispute makes clear that the EU courts are still working that line out in real time - and the answer they land on will ripple far beyond Brussels.

Key takeaways

  • ISO and IEEE standards can function like legal requirements even without ever being formally enacted as statutes.
  • Soft law (non-binding guidelines) can "harden" into hard law through regulatory incorporation, contracts, and market pressure.
  • ISO 22000 (food safety), ISO 9001 (quality management), ISO 13485 (medical devices), and ISO 14001 (environmental management) are all examples of voluntary standards that become practically mandatory in specific sectors or jurisdictions.
  • In the EU, standards cited in the Official Journal create a presumption of conformity with legal requirements - meeting the standard is the easiest path to proving compliance with the law.
  • Businesses routinely write ISO or IEEE standards into commercial contracts, turning voluntary guidelines into legally enforceable obligations under contract law.
  • Compliance with recognized standards can serve as a strong legal defense, demonstrating due diligence in tort and product liability cases.
  • ISO has published more than 25,000 international standards and counts 175 national member bodies, developed through over 800 technical committees.
  • IEEE SA maintains more than 1,400 standards and projects under development, with approval requiring a 75% affirmative vote from participating members.
  • IEEE's 2015 patent policy update triggered a wave of "negative letters of assurance" from major patent holders, prompting ISO/IEC to restrict affected Wi-Fi standards in 2023 - a dispute later eased by IEEE's own 2023 policy revision.
  • The 2024 "Malamud" ruling by the European Court of Justice found that harmonised standards cited in EU law must be freely accessible to the public.
  • Following Malamud, ISO and IEC sued the European Commission in December 2024 over copyright, and new EN ISO/EN IEC standards have been stalled from EU Official Journal publication while the case remains unresolved.
  • The 2008 ISO-IEEE cooperation agreement was designed to reduce duplicated standards work and speed up development in shared technical domains like IT and health informatics.
 avatar
@wiktoria
  • Redaction badge
    Redaction
Wiktoria Wysocka
Digital Rights & Policy Analyst
Wiktoria Wysocka is a legal consultant who navigates the rapidly evolving terrain where digital technology collides with civil rights, data privacy, and corporate accountability. With a sharp instinct for regulatory complexity, she deciphers the dense legal frameworks governing AI liability, platform regulation, and surveillance capitalism, translating them into practical knowledge for developers, businesses, and everyday users. She believes most people are not confused by technology - they are confused by the law that governs it - and she writes to close that gap with precision and clarity.
No posts yet