Skip to content

Business Compliance & Sustainability faster, easier, and smarter.

Helping businesses navigate global and local comliance & sustainability frameworks with confidence.

Explore the Blog About Sustalium


What We Write About


The Challenge We're Solving

The Problem

72% of SMEs struggle with sustainability certification due to complex processes, high costs, and limited resources. The many existing and upcoming requirements are affecting millions of products across Europe, North America, Asia, Latam, Africa and the rest of the world.

Our Approach

Sustalium provides a unified platform that makes compliance & sustainability documents faster to obtain, easier to manage, and smarter through automation and AI-powered compliance tools.


Stay Connected

Follow us on social media to stay up-to-date with our latest content and announcements.

LinkedIn Twitter

FSC Chain of Custody Certification Software

If you buy or sell FSC-certified materials, you know the administrative burden of collecting, verifying, and sharing certificates. Buyers demand proof before every transaction, suppliers scramble to find the latest PDF, and someone on your team manually checks expiry dates and scope codes. This process breaks down as soon as you handle more than a handful of certifications — and a single lapse can cost you a sale or put your own chain of custody at risk.

ISO 27001 Certification: ISMS & Buyer Sharing

As of the ISO Survey 2023, there were 71,549 valid ISO 27001 certificates across 175 countries — making it the second most adopted ISO management system standard after ISO 9001. In a 2024 Vanta survey, 78% of companies reported that ISO 27001 certification directly helped them close deals faster. The transition from ISO 27001:2013 to ISO 27001:2022 completed in October 2025, and any organization still holding a certificate against the 2013 version must now recertify against the updated standard. The market message is unambiguous: in B2B procurement, ISO 27001 has become less a security posture indicator and more a market access prerequisite.

ISO 27001 is the international standard for Information Security Management Systems (ISMS). For B2B companies — SaaS platforms, IT service providers, cloud infrastructure companies, and any organization handling client data — it is the single most requested compliance credential in vendor assessments. On the Sustalium platform, we see the real bottleneck is rarely the technical controls themselves — it is the inability to produce the certificate, Statement of Applicability, and audit reports in a single verifiable package when procurement asks for them.

US Toys: CPC, ASTM F963 & State Requirements

Toys are the most heavily regulated consumer product category in the United States — and the compliance path is fundamentally different from general consumer goods. The key difference is that toys require a Children's Product Certificate (CPC) , not the General Certificate of Conformity (GCC) that covers adult products. The CPC demands third-party testing at a CPSC-accepted laboratory, additional chemical restrictions beyond what applies to general consumer goods, and specific labeling requirements — including a tracking label on every product.

This guide covers every compliance requirement for toys sold in the US, from federal testing standards to state-level chemical warnings, and compares the US framework to the EU Toy Safety Directive for brands selling in both markets.

Canada Bill S-211 Compliance Software

Canada Bill S-211 — the Fighting Against Forced Labour and Child Labour in Supply Chains Act — came into force on January 1, 2024. It requires many businesses and government institutions to file an annual report with the Minister of Public Safety detailing the steps they have taken to prevent and reduce the risk of forced labour and child labour in their supply chains. For procurement, legal, and sustainability teams, the reporting burden is real — and the penalties for non-compliance can be severe. Sustalium's Canada Bill S-211 compliance software turns this annual headache into a guided, automated workflow that maps directly to Public Safety Canada's expectations.

EU MDR Class I Device Compliance Guide

In 2024, the European Commission acknowledged that only 45 Notified Bodies had been designated under the MDR — down from roughly 80 under the previous Medical Device Directive. The resulting bottleneck has delayed recertification across all device classes, and several EU Member States have reported that up to 20% of Class I manufacturers had not fully transitioned their technical documentation from MDD to MDR format during spot checks. A non-sterile Class I device may not need a Notified Body, but that self-declaration must still be built on the new regulation's structure — and outdated documentation is treated the same as no documentation during a competent authority audit.

Under the EU Medical Device Regulation (MDR — Regulation [EU] 2017/745), all medical devices placed on the European market require a Declaration of Conformity. Class I devices are the lowest-risk category but the documentation burden is far from trivial. On the Sustalium platform, the area where we see Class I manufacturers submit incomplete documentation most frequently is the new clinical evaluation and post-market surveillance requirements — obligations that simply did not exist under MDD.

Selling Cosmetics in the US and EU: MoCRA vs. CPSR

A cosmetic brand selling in both the United States and the European Union must comply with two regulatory frameworks that are structurally similar but operationally distinct — and neither framework accepts the other's documentation. The US system, modernized in 2022 by MoCRA, emphasizes manufacturer self-declaration of safety. The EU system, established under the Cosmetic Products Regulation (EC) 1223/2009, requires a qualified safety assessor to prepare a formal Cosmetic Product Safety Report (CPSR) and mandates notification to the EU's Cosmetic Product Notification Portal (CPNP) before the product reaches the market.

For brands selling in both markets, the compliance cost is additive — you need both a MoCRA safety substantiation and an EU CPSR. But the ingredient data and toxicological assessments that support one can inform the other, and building both in parallel from the same product data is significantly more efficient than treating them as separate compliance projects.

SOC 2 Type II Report Software

The average SOC 2 audit costs between $30,000 and $100,000 and consumes months of engineering time. Without dedicated software, security teams drown in spreadsheets, screen captures, and manual log collection — and still face costly audit failures when evidence falls short. A SOC 2 Type II report demands twelve months of continuous, defensible evidence — and most teams realise too late that their manual processes cannot deliver it.

Importing US Furniture: Complete Compliance Checklist

Furniture is the rare product category that triggers nearly every major US import compliance framework at once. A single wooden dresser imported into the United States requires a Lacey Act plant declaration for the wood, a CPSC General Certificate of Conformity for the safety standards, a TSCA Title VI certification for formaldehyde emissions from composite wood panels, and packaging that complies with California TPPA heavy metal limits. If the dresser has upholstery, add a flammability standard. If it contains stain-resistant treatments, add PFAS state-law considerations.

This guide maps every US compliance requirement for imported furniture into a single checklist — so you know exactly what you need before your container reaches the port.

US GCC Guide: CPSC Certificate of Conformity

In 2023, the US Consumer Product Safety Commission levied over $45 million in civil penalties across multiple enforcement actions — and a recurring finding in compliance investigations is that the General Certificate of Conformity either did not exist, was incomplete, or cited the wrong safety standard. When a GCC is missing or inaccurate, the product is legally non-compliant regardless of how safe it actually is. Amazon has increasingly codified this into its own enforcement: in categories like children's furniture, apparel, and electronics, sellers must upload a valid GCC directly to Seller Central or face listing suppression.

The US General Certificate of Conformity (GCC) is a mandatory document under the Consumer Product Safety Improvement Act (CPSIA) Section 14. It certifies that your consumer product has been tested and complies with all applicable CPSC safety rules. On the Sustalium platform, the most common GCC error we see is not a missing certificate — it's a certificate that lists one or two applicable standards while omitting others that apply to the same product.

OEKO-TEX Certification Software

Managing OEKO-TEX Standard 100 compliance across a textile supply chain is slow, error-prone, and paper-heavy. Every garment, fabric, and accessory must meet strict chemical limits, and proving that compliance to buyers requires collecting, verifying, and sharing certificates — often hundreds at a time. Without software, teams drown in spreadsheets, expired PDFs, and manual audits.