Latest News

Latest News

Regulations vs. Standards Compliance: Why ASTM, ASME & ITAR Belong in Your Stack

Regulations vs. Standards Compliance: Why ASTM, ASME & ITAR Belong in Your Stack

Regulations vs. Standards Compliance: Why ASTM, ASME & ITAR Belong in Your Stack

Vasanth

Vasanth

Vasanth

Vasanth

Calendar

Regulations vs. Standards Compliance: Why ASTM, ASME & ITAR Belong in Your Stack
Regulations vs. Standards Compliance: Why ASTM, ASME & ITAR Belong in Your Stack

Every manufacturer's compliance program rests on two different kinds of obligation that are often treated as one. Regulations are legally binding rules issued by governments. Standards are voluntary technical documents published by standards bodies. Understanding regulations vs standards compliance is not an academic exercise. It determines which obligations carry legal penalties, which are enforced through customer contracts, and which most compliance software silently leaves out of scope.

ASTM specifications, ASME codes, ISO standards, and the ITAR export-control regime sit in exactly this blind spot. Mainstream product-compliance tools are built around substance regulations such as RoHS, REACH, and PFAS. They rarely track engineering standards or export controls, which leaves those obligations in spreadsheets and in individual engineers' heads. This guide explains the distinction, why it matters to enterprise manufacturers, and how to bring standards and regulations into a single compliance system of record.

New to consolidating obligations across frameworks? Start with the complete guide to product compliance management for global manufacturers, then use this guide to close the standards and export-control gap.

Key Takeaways

๐Ÿ“Œ Regulations are mandatory by law. Standards are voluntary until a law, contract, or market requirement makes them binding.

โš ๏ธ ITAR is a federal export-control regulation (22 CFR 120-130), not a standard. Treating it as an engineering standard is a common and costly misclassification.

๐Ÿ“„ A voluntary standard becomes enforceable through three routes: incorporation by reference, customer contract, or market-access requirement.

๐Ÿญ The ASME Boiler and Pressure Vessel Code is adopted into law by most US states, making a "voluntary" standard legally mandatory for pressure equipment.

๐Ÿ“Š Most compliance platforms model substance regulations, not design standards or export classification, so those obligations fall outside the system of record.

๐Ÿ”— Standards conformance, customer requirements, and export-control documentation are supply-chain and evidence problems, not just engineering ones.

๐Ÿค– A unified compliance stack, supported by AI-driven regulatory intelligence, keeps standards and regulations under continuous monitoring instead of periodic manual review.

Regulations vs. Standards: The Distinction That Defines Your Compliance Stack

The words "regulation" and "standard" are used interchangeably in most compliance conversations. For an enterprise manufacturer, the difference is operational and legal. It changes who enforces the obligation, what penalty attaches to a failure, and where the evidence has to live. A clear taxonomy is the foundation of any credible compliance management program.

What Is a Regulation?

A regulation is a legally binding rule issued by a government or regulatory authority. Non-compliance can result in fines, import or sales bans, and in some cases criminal liability. REACH, RoHS, TSCA, and California Proposition 65 are regulations. So are the US export-control regimes. Regulations are enforced by the state, and compliance is not optional for products in scope.

What Is a Standard?

A standard is a technical document developed by a standards development organization (SDO) to define materials, test methods, design rules, or management systems. Standards from ASTM International, ASME, and ISO are voluntary consensus documents. On their own they carry no legal force. They become binding only when a separate mechanism, such as a law or a contract, makes them so. This is the single most misunderstood point in managing standards and regulations together.

Where ITAR Fits (It Is a Regulation, Not a Standard)

ITAR is frequently grouped with engineering standards in casual usage, and that grouping is wrong. The International Traffic in Arms Regulations are a federal regulation codified at 22 CFR Parts 120-130 and administered by the US Department of State's Directorate of Defense Trade Controls (DDTC) under the Arms Export Control Act. ITAR controls the export of defense articles, technical data, and defense services listed on the US Munitions List. It is mandatory federal law with substantial penalties, and it belongs in the regulation column, not the standards column.

Dimension

Regulation

Standard

Source

Government or regulatory authority

Standards development organization (SDO)

Examples

REACH, RoHS, TSCA, ITAR, EAR

ASTM, ASME BPVC, ISO 9001, IEC

Legal status

Mandatory by law

Voluntary until made binding

Enforced by

Government penalties and inspections

Contract, certification, incorporation by reference

Failure exposure

Fines, bans, criminal liability

Lost contracts, failed audits, market denial

Regulations vs standards compliance comparison for manufacturers showing legal and enforcement differences

Click on image to view full

When a Voluntary Standard Becomes Mandatory

A standard is voluntary in principle and mandatory in practice far more often than teams expect. Three mechanisms convert a consensus document into an enforceable obligation. Recognizing which mechanism applies tells you whether the obligation is a legal exposure, a contractual exposure, or a market-access exposure.

Mechanism

How it works

Example

Incorporation by reference

A law or regulation cites the standard, giving it legal force

ASME BPVC adopted into US state boiler and pressure-vessel laws

Contractual requirement

A customer or OEM mandates the standard in the contract

IATF 16949, AS9100, and ISO 9001 in supplier agreements

Market access or certification

The standard is required to sell or to obtain a mark

CE marking harmonized standards; product safety certification

The ASME Boiler and Pressure Vessel Code is the clearest example. The 2025 edition of the ASME BPVC is a voluntary consensus standard, yet most US states and many international jurisdictions incorporate it by reference into public safety law. For pressure equipment, a "voluntary" standard is effectively mandatory. ASTM standards follow a similar path, with many incorporated into US federal regulations for materials, consumer products, and transportation.

ISO management system standards usually become binding through contract. The sixth edition, ISO 9001:2026, was published on 16 September 2026 and replaces ISO 9001:2015, with a three-year transition period for certified organizations. Automotive suppliers layer IATF 16949 on top, and aerospace suppliers apply AS9100. These are rarely legal requirements, but they are gatekeepers for customer and industry requirements and are enforced through customer RFQ and audit processes.

ASTM, ASME, ISO and ITAR: What Each One Actually Governs

Precision here signals competence to engineering and quality teams. Each body or regime governs a different domain and becomes binding through a different route. Grouping them by name alone hides those differences.

ASTM International Standards

ASTM International publishes voluntary consensus standards for materials, products, systems, and test methods. Metal specifications, plastics test methods, and material property standards are the ones manufacturers meet most often. Many are referenced in customer drawings and purchase specifications, and a significant number are incorporated by reference into federal regulations.

ASME Codes and Standards

ASME publishes engineering codes and standards, most notably the Boiler and Pressure Vessel Code and the B31 piping codes. Because these are incorporated into jurisdictional law, ASME conformance is a legal requirement in the majority of US states for equipment in scope, alongside the design, inspection, and documentation evidence that goes with it.

ISO Standards

ISO publishes management system standards, including ISO 9001 for quality and ISO 14001 for environmental management. They are certified against by accredited bodies and are usually enforced through customer contracts. Maintaining certification is an ongoing evidence exercise best handled inside a quality management system rather than a static document folder.

ITAR and EAR Export Controls

ITAR and the Export Administration Regulations (EAR) are the two primary US export-control regimes. ITAR (22 CFR 120-130, DDTC) governs defense articles on the US Munitions List. The EAR (15 CFR 730-774), administered by the Commerce Department's Bureau of Industry and Security, governs dual-use items on the Commerce Control List. Both are regulations, both require jurisdiction and classification decisions, and both generate documentation obligations that belong in your trade and customs compliance and aerospace and defense workflows.

Body or regime

Type

Administered or published by

Binding through

ASTM International

Standards (materials, test methods)

ASTM International

Contract; incorporation by reference

ASME (BPVC, B31)

Codes and standards (pressure equipment)

ASME

State and jurisdictional law

ISO (9001, 14001)

Management system standards

ISO

Customer contract; certification

ITAR

Regulation (defense export control)

US State Dept / DDTC, 22 CFR 120-130

Federal law (mandatory)

EAR

Regulation (dual-use export control)

US Commerce / BIS, 15 CFR 730-774

Federal law (mandatory)

Why Most Compliance Tools Ignore Standards and Export Controls

Mainstream product-compliance software was designed around one model: the restricted-substance list. It screens a bill of materials against substance thresholds for RoHS, REACH, and PFAS, then produces a pass or fail. That model is valuable, and Certivo supports it through materials and environmental compliance. It also explains the gap.

Engineering standards and export controls do not fit a substance-list model. ASME conformance is a design, testing, and documentation question. ITAR is a classification and licensing question. Neither maps to a CAS number and a threshold, so most tools leave them out. The obligations then default to spreadsheets, shared drives, and the knowledge of a few experienced engineers. When those people move on, the evidence trail moves with them.

The result is a compliance stack that looks complete but is not. Substance regulations are automated, while standards conformance and export-control documentation remain manual and siloed. That is the exact gap that creates surprises during customer audits and export reviews, and it is why replacing spreadsheets with a scalable system matters as much for standards as it does for chemicals.

Compliance stack coverage gap where standards and export controls fall outside automated regulatory tracking

Click on image to view full

The Business Risk of Treating Standards as an Afterthought

The distinction between regulations and standards is not just a compliance-team concern. It shapes exposure at the executive level, and the failure modes differ by obligation type.

CEO and board: Export-control and safety-code failures create strategic and legal exposure, not only fines. ITAR violations can lead to debarment from exporting and to civil and criminal penalties under the Arms Export Control Act.

CFO: Standards and export obligations drive audit-preparation cost, testing spend, and the risk of shipment holds when documentation cannot be produced on demand.

Quality and compliance: A failed certification audit or a customer audit finding on ISO 9001, IATF 16949, or AS9100 can suspend a supplier's approved status and stop orders.

Supply chain and procurement: Standards conformance and export classification cascade to suppliers. Without multi-tier supplier evidence, a manufacturer cannot prove that purchased parts meet the referenced ASTM or ASME specification.

Audit readiness across all of these is an evidence problem. It depends on time-stamped declarations, historic state tracking, and the ability to answer a point-in-time question about what a product conformed to when it shipped. That is a data capability, not a filing habit, and it is central to staying audit-ready across frameworks.

Building a Compliance Stack That Covers Standards and Regulations Together

The fix is not another point tool for each obligation. It is a single system of record that treats regulations, standards, and export controls as tracked obligations against the same products and bills of materials. A centralized compliance data backbone removes the divide between "automated" substance compliance and "manual" everything else.

In practice, that means mapping each obligation to the products and parts it applies to, then attaching the evidence that proves conformance. Certivo is built to hold regulatory frameworks, customer and industry requirements, quality standards, and export and trade obligations such as DFARS and ITAR-adjacent controls in one place, linked to compliance tracked at the BOM level. This is where BOM-level compliance intelligence and automated supplier evidence collection replace the spreadsheet.

Check coverage for your standards list. If ASTM, ASME, ISO, or export-control obligations live outside your compliance platform, request a compliance review to see where the gaps are.

For multi-plant and multi-region manufacturers, the same backbone supports standardized compliance across plants and regions, so a standard referenced in one facility's specification is not re-tracked from scratch in another. The goal is continuous compliance monitoring and audit-ready documentation, not a periodic scramble before each audit.

How AI Supports Standards and Regulatory Change Management

Standards and regulations both change, and they change on different clocks. The ASME BPVC revises every two years. ISO 9001 moved to its 2026 edition. Export-control lists are amended through the Federal Register. Tracking all of this manually across a global portfolio is where teams fall behind.

CORA-driven regulatory intelligence supports horizon scanning across regulatory frameworks and referenced standards, flagging changes before they reach an audit rather than after. AI document parsing helps validate supplier certificates and material declarations against the applicable specification, and it turns a folder of test reports into retrievable, structured evidence. Combined with Certivo's platform capabilities, this shifts compliance from reactive to continuous.

None of this eliminates compliance risk or makes a company "audit-proof." What AI-native compliance automation does is reduce surprises, shorten evidence-retrieval time, and give compliance, quality, and export teams a shared, current view. That is the practical difference between managing standards and regulations as one connected program and managing them as disconnected silos.

Compliance Stack Coverage Checklist

Use this checklist to test whether your current stack actually covers standards and export controls, not just substances.

โœ… Every ASTM and ASME specification referenced in customer drawings is recorded as a tracked obligation, not just a drawing note.

โœ… ASME BPVC conformance is linked to the jurisdictions that incorporate it by reference for your equipment.

โœ… ISO 9001, IATF 16949, and AS9100 requirements are mapped to the products and processes they govern, with certification status and dates.

โœ… ITAR and EAR classification decisions and licensing documentation are stored in the system of record, not in email.

โœ… Standards and export obligations are linked to the BOM, so an engineering change triggers a compliance review.

โœ… Supplier evidence for referenced standards is collected and validated, not assumed.

โœ… Historic, time-stamped conformance states can be produced for any product at any past ship date.

โœ… Regulatory and standards changes are monitored continuously, with owners assigned to act on them.

Conclusion

Regulations vs standards compliance is the distinction that decides which obligations carry legal penalties, which are enforced by customers, and which your software quietly ignores. Regulations like ITAR and REACH are mandatory by law. Standards like ASTM, ASME, and ISO are voluntary until a law, a contract, or a market makes them binding, which happens more often than most programs assume. The manufacturers who manage well are the ones who stop treating these as separate worlds.

A single compliance system of record, supported by AI-driven regulatory intelligence, brings substance regulations, engineering standards, quality certifications, and export controls under one continuously monitored program. That is how a global manufacturer moves from reactive audit preparation to durable, audit-ready confidence.

To see whether your standards, regulations, and export-control obligations are fully covered, speak with a Certivo compliance specialist and check coverage for your standards list.

FAQs

FAQs

What is the difference between a regulation and a standard in compliance?

A regulation is a legally binding rule issued by a government, with penalties for non-compliance. A standard is a voluntary technical document from a standards body that becomes binding only through law, contract, or market requirement. Certivo tracks both as obligations against the same products, so neither is left out of scope.

Is ITAR a standard or a regulation?

ITAR is a federal regulation, not a standard. It is codified at 22 CFR 120-130 and administered by the US State Department's DDTC under the Arms Export Control Act, controlling defense articles on the US Munitions List. It carries civil and criminal penalties and should be managed alongside regulatory frameworks, not engineering standards.

When do ASTM and ASME standards become legally mandatory?

They become mandatory when a law incorporates them by reference, when a customer contract requires them, or when a market or certification demands them. The ASME BPVC, for example, is adopted into law by most US states, making conformance a legal requirement for pressure equipment despite being a voluntary consensus standard.

Why do most compliance software tools not track standards or export controls?

Most tools are built around restricted-substance screening against a BOM, which fits RoHS, REACH, and PFAS but not design standards or export classification. Those obligations then default to spreadsheets. Certivo's centralized data backbone holds standards, customer requirements, and export documentation together with substance regulations.

How can manufacturers manage standards and regulations in one system?

By mapping every obligation, regulatory or standard, to the products and BOMs it applies to, then attaching conformance evidence and supplier documentation. CORA-driven regulatory intelligence adds horizon scanning for changes across referenced standards and frameworks, supporting continuous, audit-ready compliance rather than periodic manual review.

What is the difference between a regulation and a standard in compliance?

A regulation is a legally binding rule issued by a government, with penalties for non-compliance. A standard is a voluntary technical document from a standards body that becomes binding only through law, contract, or market requirement. Certivo tracks both as obligations against the same products, so neither is left out of scope.

Is ITAR a standard or a regulation?

ITAR is a federal regulation, not a standard. It is codified at 22 CFR 120-130 and administered by the US State Department's DDTC under the Arms Export Control Act, controlling defense articles on the US Munitions List. It carries civil and criminal penalties and should be managed alongside regulatory frameworks, not engineering standards.

When do ASTM and ASME standards become legally mandatory?

They become mandatory when a law incorporates them by reference, when a customer contract requires them, or when a market or certification demands them. The ASME BPVC, for example, is adopted into law by most US states, making conformance a legal requirement for pressure equipment despite being a voluntary consensus standard.

Why do most compliance software tools not track standards or export controls?

Most tools are built around restricted-substance screening against a BOM, which fits RoHS, REACH, and PFAS but not design standards or export classification. Those obligations then default to spreadsheets. Certivo's centralized data backbone holds standards, customer requirements, and export documentation together with substance regulations.

How can manufacturers manage standards and regulations in one system?

By mapping every obligation, regulatory or standard, to the products and BOMs it applies to, then attaching conformance evidence and supplier documentation. CORA-driven regulatory intelligence adds horizon scanning for changes across referenced standards and frameworks, supporting continuous, audit-ready compliance rather than periodic manual review.

Table of Contents
No headings found on page
Table of Contents
No headings found on page

See how Certivo can automate compliance for your business.

See how Certivo can automate compliance for your business.

See how Certivo can automate compliance for your business.

Book a demo

Book a demo

Vasanth

Vasanth is a skilled Compliance Engineer with over five years of experience specializing in global environmental regulations, including REACH, RoHS, Proposition 65, POPs, TSCA, PFAS, CMRT, EMRT, FMD, and IMDS. With a strong academic foundation in Chemical Engineering from Anna University, he brings a deep technical understanding to compliance processes across complex product lines.

Vasanth excels in analyzing Bills of Materials (BOMs), evaluating supplier declarations, and ensuring regulatory conformity through meticulous review and risk assessment. He is highly proficient in supplier engagement, adept at interpreting material disclosures, and experienced in preparing customer-ready compliance documentation tailored to diverse global standards.

Known for his attention to detail, up-to-date regulatory knowledge, and proactive communication style, Vasanth plays a critical role in maintaining product compliance and advancing sustainability goals within fast-paced, globally integrated manufacturing environments.