RoHS
EU regulation restricting hazardous substances in EEE
ISO 28000
International standard for supply chain security management systems
Quick Verdict
RoHS restricts hazardous substances in EEE for EU market access, while ISO 28000 builds security management systems for supply chains. Companies adopt RoHS for legal compliance and recyclability; ISO 28000 for resilience, risk reduction, and stakeholder trust.
RoHS
Directive 2011/65/EU (RoHS 2)
Key Features
- Restricts 10 hazardous substances in homogeneous materials
- Open-scope applies to all EEE unless excluded
- Time-limited exemptions via delegated directives
- Requires technical documentation and EU DoC
- Tiered verification using IEC 62321 testing methods
ISO 28000
ISO 28000:2022 Security management systems — Requirements
Key Features
- Risk-based supply chain security management framework
- PDCA cycle for continual improvement and evaluation
- Scalable to all organization sizes and industries
- Integrates with ISO 9001, 27001, 22301 standards
- Supplier governance and third-party risk controls
Detailed Analysis
A comprehensive look at the specific requirements, scope, and impact of each standard.
RoHS Details
What It Is
RoHS (Directive 2011/65/EU, recast as RoHS 2, amended by 2015/863) is an EU regulation restricting hazardous substances in electrical and electronic equipment (EEE) to protect health and environment during waste management. It uses an open-scope approach applying to all EEE unless excluded, with restrictions at homogeneous material level (0.1% w/w default, 0.01% for Cd).
Key Components
- **10 restricted substancesPb, Hg, Cd, Cr(VI), PBB, PBDE, DEHP, BBP, DBP, DIBP.
- **Annexes III/IV exemptionsTime-limited, application-specific allowances.
- **Compliance modelTechnical documentation per EN IEC 63000, EU Declaration of Conformity (DoC), CE marking where applicable; tiered verification via IEC 62321 methods.
Why Organizations Use It
Ensures EU market access, reduces e-waste hazards alongside WEEE Directive, mitigates enforcement risks (fines, recalls). Drives supply chain governance, substitution innovation, ESG credibility, and recyclability for competitive edge.
Implementation Overview
Risk-based: Scope analysis, BoM mapping, supplier declarations, targeted testing (XRF screening, ICP-MS/GC-MS confirmation), technical files (10-year retention). Applies to manufacturers/importers of EEE globally selling to EU; no certification but audit-ready evidence for surveillance.
ISO 28000 Details
What It Is
ISO 28000:2022 is an international management system standard titled Security and resilience — Security management systems — Requirements. It provides a risk-based framework for establishing, implementing, maintaining, and improving a security management system (SMS) focused on supply chain protection, covering people, assets, goods, infrastructure, and information.
Key Components
- Core clauses: Context, Leadership, Planning, Support, Operation, Performance Evaluation, Improvement (aligned with ISO High Level Structure and PDCA cycle).
- Emphasizes risk assessment, controls (physical, personnel, procedural), incident response, supplier governance.
- No fixed controls; proportionate to risks.
- Supports third-party certification via accredited bodies per ISO 28003.
Why Organizations Use It
- Reduces disruptions, theft, sabotage; lowers insurance costs.
- Meets contractual/regulatory demands (e.g., C-TPAT equivalents).
- Enhances resilience, market access, trade facilitation.
- Builds stakeholder trust, competitive edge in logistics, manufacturing.
Implementation Overview
- Phased: Gap analysis, risk assessment, controls deployment, audits.
- Scalable for SMEs to multinationals across industries.
- 6-36 months typical; requires training, documentation, continual improvement.
Key Differences
| Aspect | RoHS | ISO 28000 |
|---|---|---|
| Scope | Hazardous substances in EEE materials | Supply chain security management system |
| Industry | Electrical/electronic equipment manufacturers | Logistics, manufacturing, all supply chains |
| Nature | EU directive, mandatory market access | Voluntary ISO management standard |
| Testing | Material analysis (XRF, ICP-MS, GC-MS) | Internal/external audits, risk assessments |
| Penalties | Fines, recalls, market bans by states | Loss of certification, no legal penalties |
Scope
Industry
Nature
Testing
Penalties
Frequently Asked Questions
Common questions about RoHS and ISO 28000
RoHS FAQ
ISO 28000 FAQ
You Might also be Interested in These Articles...

NIST CSF 2.0: Key Enhancements and How They Address Evolving Cyber Threats
Explore NIST CSF 2.0 updates: Govern function, supply chain security, SME playbooks for ransomware & AI threats. Boost your cyber defenses now!

Real-World ISO 27701 Success: Synthesized Case Studies, Metrics, and Lessons for Privacy Resilience
Real-world ISO 27701 success from Tribeca, Kocho: DSAR efficiency gains, risk score reductions, certification ROI. Synthesized metrics prove privacy resilience

CIS Controls v8.1 for Cloud & Kubernetes: A Practical Implementation Playbook (AWS/Azure/GCP + IaC)
Translate CIS Controls v8.1 to cloud-native: Kubernetes patterns for IAM, logging, vuln mgmt, hardening on AWS, Azure, GCP + IaC. Practical playbook for teams.
Run Maturity Assessments with GRADUM
Transform your compliance journey with our AI-powered assessment platform
Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.
Check out these other Gradum.io Standards Comparison Pages
BRC vs GRI
Compare BRC vs GRI: BRCGS ensures food safety via HACCP, audits & grading; GRI drives ESG impact reporting thru materiality & disclosures. Master compliance—read now!
CSA vs IATF 16949
Discover CSA vs IATF 16949: Compare OHS standards (Z1000/Z1002) with automotive QMS. Key gaps in risk, leadership & compliance. Boost your strategy now!
C-TPAT vs AS9110C
Compare C-TPAT vs AS9110C: CBP's trusted trader security for supply chains vs aerospace QMS for aviation maintenance. Key differences, benefits & strategies inside!