At Sungrow, we maintain a robust global compliance framework that aligns with international standards and regional regulatory requirements across key markets.
Comprehensive compliance framework covering major markets including the EU, North America, and Asia-Pacific
ISO/IEC 27001:2022
International standard for information security management systems
ISO/IEC 27017:2015
International standard for cloud security controls
CSA STAR
A certification program that provides security and transparency for cloud services
ISO/IEC 27701:2019
International standard for protection of personally identifiable information privacy information management systems
ISO/IEC 27018:2019
International standard for personal privacy protection specifically for public cloud service providers
ISO/IEC 27019:2024
Information security standard for process control systems used in the energy utility industry
IEC 62443-4-1:2018
Standard for security development process management system for industrial control vendors
ISO/IEC 29147 & 30111
International standards for product security vulnerability management and disclosure
MLPS
The Multi-Level Protection Scheme (MLPS), also referred to as Classified Protection of Cybersecurity.
CRA
The Cyber Resilience Act (Regulation (EU) 2024/2847) is the EU's horizontal cybersecurity regulation for products with digital elements.
GDPR
The General Data Protection Regulation (GDPR) is a comprehensive data protection law of the European Union
RED
An EU directive establishing essential requirements for the safety, electromagnetic compatibility, and efficient use of the radio spectrum for radio equipment
NIS2 Directive
A legally binding cybersecurity directive
enacted by the European Union for critical infrastructure.
PSTI Act
Product Security and Telecommunications Infrastructure Act
ETSI EN 303 645
The first global cybersecurity standard for consumer IoT products
UL 2941
Cybersecurity of Distributed Energy and Inverter-based Resources