Standards that govern the radio layer.
GS1 EPC & EPCglobal
Electronic Product Code identifiers, Gen2v2 air interface (ISO/IEC 18000-63), and the GS1 Tag Data Standard 2.x for traceability across supply chains.
Passive RFID Alliance
The industry body for passive UHF RFID. Certified interoperability, deployment best practice, and the ecosystem map of compliant readers and tags.
FiRa Consortium
UWB interoperability standards (IEEE 802.15.4z), MAC / PHY profiles, and secure ranging. The basis of cross-vendor UWB deployments.
Bluetooth SIG
BLE 5.x core spec, AoA / AoD direction finding, Mesh 1.1 networking, and Channel Sounding for next-gen BLE precision ranging.
LoRa Alliance
LoRaWAN 1.0.4 / 1.1 specifications, Class A / B / C device profiles, and the certified-device programme for LPWAN deployments.
ISO 18000-6/7
Passive UHF (-6) and active 433 MHz (-7) RFID air interface standards, with regional regulatory frequency allocations (ETSI EN 302 208, FCC Part 15).
Standards that govern OT/IT convergence.
IEC 62443
Industrial-automation cybersecurity. We design to -2-1 (security programmes), -2-4 (service provider requirements), -3-3 (system requirements), and -4-1 (secure development).
ISA-95 / Purdue Model
The reference architecture for OT/IT integration. Level 0–5 segmentation drives our network and middleware design for industrial deployments.
NIST CSF · ISO 27001 · SOC 2
The information-security frameworks enterprise buyers expect. Mapped to your IoT and RTLS programme from day one.
Zero Trust / SPIFFE
Device identity, service-to-service authentication, and the move away from network-perimeter trust toward per-message authorisation.
GDPR · UK DPA
Privacy by design for location data — lawful basis, data minimisation, DPIA, and the technical controls (pseudonymisation, retention) that survive audit.
NIS2 · DORA
EU directives for critical-infrastructure and financial-services cybersecurity — relevant wherever IoT crosses into regulated territory.
Vertical standards we build for.
Healthcare
HIPAA, HITECH, HL7 v2 / FHIR R4, Joint Commission tracer methodology, AAMI EQ56 for equipment management, Care Coordination Performance Measures.
Aerospace
AS9100D, AS9120, ATA Spec 2000 Chapter 9 (electronic identification), MIL-STD-129R, MIL-STD-130N for item marking and traceability.
Automotive
IATF 16949, VDA 6.3 process audit, JIS / JIT conformance, VDA 5050 for AGV/AMR multi-vendor fleet management.
Pharma & Life Sciences
21 CFR Part 11 (electronic records), DSCSA serialisation, EU FMD, Good Distribution Practice (GDP), GAMP 5 for computer system validation.
Logistics & supply chain
GS1 SSCC / GLN / GTIN, ASN messaging (EDI 856), C-TPAT, AEO, Maritime Anti-Drug Smuggling Act (MADSA) for high-risk freight.
Mining, oil & gas
ATEX / IECEx for hazardous-area electronics, MSHA and OSHA compliance, ISO 45001 occupational safety management, ANSI/API RP 754.
How standards should steer architecture — not slide decks
Radio standards (UWB, BLE, RAIN RFID, LoRaWAN), OT security (IEC 62443), quality regimes (IATF, AS9100), privacy (GDPR/HIPAA), hazardous area (ATEX/IECEx) and pharma traceability (DSCSA/GS1, Part 11) interact. A design that maximises one and ignores another fails at the first serious audit or works-council review.
Use this hub to navigate which framework applies, then read the deep compliance notes for obligations and vendor claims to challenge. Standards are constraints and enablers — they are not a reason to buy a particular brand that 'supports' a logo farm.
Competitive advisory angle: many platforms claim compliance features; fewer ship secure defaults, exportable EPCIS, Ex certificate schedules, or role models that survive a DPO. Score the evidence pack, not the logo strip.
Practical sequencing for multi-framework sites
Chemical pharma campuses may need ATEX people tags, GDPR staff controls, IEC 62443 segmentation and GMP data integrity simultaneously. Sequence safety certification and network zoning before analytics ambitions. Automotive plants combine IATF traceability with VDA 5050 fleet contexts and works-council limits on people location.
Document the governing frameworks in gate 1. If procurement later adds a framework mid-RFP, expect redesign — budget contingency or freeze scope earlier.
Where TRACIO helps
We translate framework obligations into locating architecture choices, RFP language and gate criteria. We do not sell certified hardware ourselves; we make sure what you buy and how you integrate it will stand scrutiny.
Standards watchlist for locating programmes
Watch GS1/EPCIS evolutions for pharma, IEC 62443 interpretations in your sector schemes, national privacy enforcement themes on workplace monitoring, and Ex certificate special conditions on wearable radios.
When standards conflict in time (e.g. rush RFID for inventory vs unfinished DPIA), stop and re-sequence. Shipping tags into a legal gap is not agility.
Use linked compliance articles for operator-level obligations and vendor challenge lists; this hub remains the map.
Extended standards advisory for multi-overlay sites
Multi-overlay sites (for example pharma with GMP + DSCSA + GDPR + IEC 62443, or chemicals with ATEX + GDPR + OT security) need a governing framework list in gate 1 with an owner per overlay. Orphan overlays resurface as go-live blockers.
Radio standards ensure interoperability of air interfaces; they do not ensure your process is compliant. Do not confuse ISO/IEC air interface conformance with IATF genealogy adequacy or HIPAA minimum necessary.
When auditors visit, they ask for evidence artefacts — DPIAs, BAAs, certificate schedules, zone diagrams, IQ/OQ/PQ, traceability plans — not a slide of logo soup. Design programmes to emit those artefacts as stage outputs.
Vendor scoring should include standards evidence quality. A platform can implement optional encryption yet ship with it off; a tag can be 'Ex available' in a different SKU than the one quoted. Read the schedule.
Use this hub as the map; use compliance child pages for operator-level depth; use templates for procurement mechanics; use method pages for gates. Together they replace brochure compliance.
How standards should steer architecture — not slide decks
Radio standards (UWB, BLE, RAIN RFID, LoRaWAN), OT security (IEC 62443), quality regimes (IATF, AS9100), privacy (GDPR/HIPAA), hazardous area (ATEX/IECEx) and pharma traceability (DSCSA/GS1, Part 11) interact. A design that maximises one and ignores another fails at the first serious audit or works-council review.
Use this hub to navigate which framework applies, then read the deep compliance notes for obligations and vendor claims to challenge. Standards are constraints and enablers — they are not a reason to buy a particular brand that 'supports' a logo farm.
Competitive advisory angle: many platforms claim compliance features; fewer ship secure defaults, exportable EPCIS, Ex certificate schedules, or role models that survive a DPO. Score the evidence pack, not the logo strip.
Practical sequencing for multi-framework sites
Chemical pharma campuses may need ATEX people tags, GDPR staff controls, IEC 62443 segmentation and GMP data integrity simultaneously. Sequence safety certification and network zoning before analytics ambitions. Automotive plants combine IATF traceability with VDA 5050 fleet contexts and works-council limits on people location.
Document the governing frameworks in gate 1. If procurement later adds a framework mid-RFP, expect redesign — budget contingency or freeze scope earlier.
Standards watchlist for locating programmes
Watch GS1/EPCIS evolutions for pharma, IEC 62443 interpretations in your sector schemes, national privacy enforcement themes on workplace monitoring, and Ex certificate special conditions on wearable radios.
When standards conflict in time (e.g. rush RFID for inventory vs unfinished DPIA), stop and re-sequence. Shipping tags into a legal gap is not agility.
Use linked compliance articles for operator-level obligations and vendor challenge lists; this hub remains the map.
Extended standards advisory for multi-overlay sites
Multi-overlay sites (for example pharma with GMP + DSCSA + GDPR + IEC 62443, or chemicals with ATEX + GDPR + OT security) need a governing framework list in gate 1 with an owner per overlay. Orphan overlays resurface as go-live blockers.
Radio standards ensure interoperability of air interfaces; they do not ensure your process is compliant. Do not confuse ISO/IEC air interface conformance with IATF genealogy adequacy or HIPAA minimum necessary.
When auditors visit, they ask for evidence artefacts — DPIAs, BAAs, certificate schedules, zone diagrams, IQ/OQ/PQ, traceability plans — not a slide of logo soup. Design programmes to emit those artefacts as stage outputs.
Vendor scoring should include standards evidence quality. A platform can implement optional encryption yet ship with it off; a tag can be 'Ex available' in a different SKU than the one quoted. Read the schedule.
Use this hub as the map; use compliance child pages for operator-level depth; use templates for procurement mechanics; use method pages for gates. Together they replace brochure compliance.
Last updated: 13 September 2026