Rättskällor med officiella primärkällor

Utskrivet ·

Skip to main content
Skip to the answer

Swedish standards: designation, edition and scope

18 Swedish standards with designation, edition, scope and a link to SIS. The standards are copyright protected and sold by the publisher: this page carries metadata only, never the standard text.

Share this page

Register

Standards in the register
18
Publisher
Svenska institutet för standarder (SIS)
Read date
2026-09-09
Version
se-standards-v1.0.0

Standards are not statute. They are purchased documents from SIS that parties agree to, or that regulations refer to. We carry the designation, edition and scope, never the text.

Management systems

Certifiable management systems for quality, environment, occupational health and safety and energy. Certification is voluntary, but buyers and public purchasers often require it in tender documents.

  • Quality management systems, requirements

    SS-EN ISO 9001:2015Svenska institutet för standarder (SIS)

    The requirements for a quality management system: management responsibility, processes, non-conformities, corrective action and continual improvement. The certificate is regularly requested as a qualification requirement in public procurement.

  • Environmental management systems, requirements

    SS-EN ISO 14001:2015Svenska institutet för standarder (SIS)

    The requirements for an environmental management system: environmental aspects, binding obligations, objectives, monitoring and management review. It is used to show customers and purchasers that the business is in control of its environmental obligations.

  • Occupational health and safety management systems, requirements

    SS-EN ISO 45001:2018Svenska institutet för standarder (SIS)

    The requirements for systematic work on the working environment: risk assessment, worker participation, incident investigation, preparedness and follow-up. It serves as a method for the systematic work environment management the Work Environment Act requires.

  • Energy management systems, requirements

    SS-EN ISO 50001:2018Svenska institutet för standarder (SIS)

    The requirements for governing energy use: energy review, performance indicators, objectives and follow-up. It is used by organisations that must show energy performance in reporting or in procurement.

Information security and privacy

The framework for governing information security and the processing of personal data. These standards serve as method where the law only requires appropriate technical and organisational measures.

  • Information security management systems, requirements

    SS-EN ISO/IEC 27001:2022Svenska institutet för standarder (SIS)

    The requirements for an information security management system: scope, risk assessment, risk treatment, statement of applicability and management review. It is the most common basis when a business must show appropriate technical and organisational measures.

  • Guidance on information security controls

    SS-EN ISO/IEC 27002:2022Svenska institutet för standarder (SIS)

    The catalogue of security controls that belongs with the management system: organisational, people, physical and technological controls, with the purpose and application of each.

  • Guidance on managing information security risks

    SS-ISO/IEC 27005:2022Svenska institutet för standarder (SIS)

    The method for identifying, analysing, evaluating and treating information security risks, and how that work connects to the management system and to decisions on acceptable risk.

  • Extension to the management system for privacy information management

    SS-EN ISO/IEC 27701:2021Svenska institutet för standarder (SIS)

    The extension that turns the information security management system into a privacy information management system, with roles for controller and processor and controls tied to data subject rights.

  • Artificial intelligence management systems, requirements

    SS-ISO/IEC 42001:2023Svenska institutet för standarder (SIS)

    The requirements for governing AI systems: accountability, impact assessment, data, life cycle, logging and monitoring. It serves as a method when an organisation must show AI governance to customers and supervisors.

Risk, compliance and continuity

Methods for risk management, compliance, anti-bribery, continuity and management system auditing. They give a documentable way of working where the law only requires the business to be in control.

  • Guidelines for auditing management systems

    SS-EN ISO 19011:2018Svenska institutet för standarder (SIS)

    Guidance on how internal and external audits of management systems are planned, performed, reported and followed up, and what competence the auditor needs. Used to make internal control auditable.

  • Risk management, principles and guidelines

    SS-ISO 31000:2018Svenska institutet för standarder (SIS)

    The principles, framework and process for managing risk in an organisation: context, risk identification, analysis, evaluation, treatment, communication and monitoring.

  • Business continuity management systems, requirements

    SS-EN ISO 22301:2019Svenska institutet för standarder (SIS)

    The requirements for continuity management: impact analysis, recovery times, continuity plans, exercises and review. Financial undertakings and public sector suppliers meet the same requirements again in supervisory rules on operations and outsourcing.

  • Anti-bribery management systems, requirements

    SS-ISO 37001:2016Svenska institutet för standarder (SIS)

    The requirements for work against bribery and corruption: risk assessment, control of gifts and hospitality, due diligence on business partners, a reporting channel and investigation.

  • Compliance management systems, requirements

    SS-ISO 37301:2021Svenska institutet för standarder (SIS)

    The requirements for a compliance management system: identification of obligations, accountability, routines, training, reporting and follow-up of deviations. Used to make compliance documentable in supervision and procurement.

  • Information security incident management, principles

    SS-EN ISO/IEC 27035-1:2023Svenska institutet för standarder (SIS)

    The principles of incident management: preparation, detection, assessment, response and lessons learned. Used alongside the duty to report personal data breaches and incidents in essential services.

Product, accessibility and medical devices

Standards that meet product regulation: quality management for medical devices, risk management for medical devices and accessibility requirements for digital products and services.

  • Medical devices, quality management systems

    SS-EN ISO 13485:2016Svenska institutet för standarder (SIS)

    The quality management requirements for manufacturers and suppliers of medical devices: design, traceability, production, sterility and post-market action.

  • Medical devices, application of risk management

    SS-EN ISO 14971:2019Svenska institutet för standarder (SIS)

    The method for risk management across the whole life cycle of a medical device: risk analysis, evaluation, reduction and follow-up of residual risk in clinical use.

  • Accessibility requirements for ICT products and services

    SS-EN 301 549Svenska institutet för standarder (SIS)

    The European accessibility requirements for websites, apps, documents and digital equipment. It is the harmonised basis for public sector accessibility obligations and accessibility statements.

Swedish law

Next step

Three ways to put the register to work in your own practice.

Start with your task