Spec Registries & Catalogs
Where specs live before you pick an individual RFC or file format. SDOs publish normative documents; registries allocate code points; meta-indexes catalog the organizations themselves.
SDO vs Registry vs Meta-index
Standards body — publishes normative protocol and format specs (RFC Editor, W3C, ISO).
Code-point registry — allocates numbers and enums (IANA ports, MIME types, RTP PTs).
Catalog of catalogs — find which org owns a spec (ConsortiumInfo, ISO ICS, ANSI SDOs).
ConsortiumInfo Standards Setting Organizations List
When you don't know which body owns a spec, start here. It's the phone book of standards organizations.
ISO National Standards Bodies
ISO specs are often mirrored or sold through your national body. This is how you find the US, UK, or EU entry point.
ISO International Classification for Standards (ICS)
Browse ISO's catalog by subject when you know the domain (file formats, healthcare, vehicles) but not the standard number.
ANSI Accredited Standards Developers
Many 'international' specs are developed by US SDOs (INCITS, IEEE, ASTM) and transposed to ISO. ANSI is the US hub.
RFC Editor
Every internet protocol spec (HTTP, TLS, DNS, SMTP, OAuth) eventually lands here as an RFC.
IETF Datatracker
See what's being standardized now — WG charters, draft revisions, and adoption status before it becomes an RFC.
IANA Protocol Registries
Specs define behavior; IANA registries define the allowed code points. Wrong port or MIME type? Check here.
Internet Corporation for Assigned Names and Numbers
Domain registration policy, WHOIS/RDAP deployment context, and new TLD programs live here — distinct from IETF DNS protocol specs.
W3C Technical Reports
CSS, CSP, WebAuthn (with FIDO), SVG, and accessibility specs are W3C Recommendations even when WHATWG owns HTML.
Ecma International Standards
JavaScript language semantics and JSON syntax have Ecma normative specs — implemented by all engines.
Unicode Consortium
Every string, domain name (IDNA), and emoji behavior traces back to Unicode specs and the character database.
NIST Computer Security Resource Center
FIPS 140 (crypto modules), AES/SHA standards, and NIST post-quantum algorithms — the US government's normative crypto baseline.
CA/Browser Forum
Every Let's Encrypt, DigiCert, or ACM certificate must comply with CA/B Baseline Requirements — not just PKIX RFCs.
OpenID Foundation Specifications
OIDC Core, Discovery, and Session Management are published here — separate from IETF OAuth RFCs.
OWASP Foundation
When someone says 'follow OWASP' they mean ASVS or Top 10 — the canonical security baseline for web apps, separate from NIST and IETF crypto specs.
MITRE ATT&CK, CWE & CVE Program
Security teams map threats to ATT&CK, classify bugs with CWE, and track vulns by CVE — three vocabularies that interlink across the industry.
CISA Known Exploited Vulnerabilities Catalog
If a CVE appears in KEV, patch priority jumps — widely used as a de-facto industry triage list beyond raw CVSS scores.
PCI Security Standards Council
Any system touching cardholder data must map controls to PCI DSS — a policy spec parallel to (and stricter than) generic app security baselines.
Cloud Security Alliance
CSA CCM is the cross-cloud control framework — maps to ISO 27001, NIST, and PCI for cloud service assessments.
ENISA Publications & Threat Landscape
EU regulatory context (NIS2, CRA, eIDAS2) and ENISA threat intel feed European compliance and product security programs.
CIS Critical Security Controls
CIS Benchmarks are the practical hardening checklists (AWS, K8s, Windows) that complement OWASP app guidance and NIST frameworks.
Trusted Computing Group
Secure Boot, TPM attestation, and BitLocker-style key sealing trace to TCG specs — the hardware root of trust below UEFI.
Common Criteria Portal
Government procurement and high-assurance products reference CC EAL levels and Protection Profiles — the global product security certification framework.
Kantara Initiative
Enterprise federation trust frameworks and eIDAS-adjacent identity assurance certification live here — complementary to OpenID and SAML.
ITU-T Recommendations
E.164 phone numbers, G.711/G.722 audio codecs, and H.323 all live in ITU-T series — foundational for telephony.
3GPP Specification Series
VoLTE, 5G NR, SMS PDU format, and SIM/USIM specs all come from 3GPP TS/TR documents indexed by series and release.
ETSI Standards
European mobile standards transposition, NFV/MEC for telco cloud, and many 3GPP specs publish through ETSI.
GSMA Specifications & Resources
RCS Universal Profile and eSIM remote provisioning specs are GSMA — not 3GPP — and drive consumer messaging and SIM policy.
ISO Standards Catalogue
Most binary file formats on the web (JPEG, PDF, MP4) are ISO/IEC standards — browse by ICS or search by number.
International Electrotechnical Commission
ISO/IEC joint specs (14496 MPEG, 10918 JPEG) publish through both ISO and IEC — IEC webstore for electrical/embedded.
Khronos Registry
WebGL and Vulkan specs plus extension enums are maintained in the Khronos registry — structured like a formal spec tree per API.
FileFormat.info
Upload validation and forensic identification start with magic bytes. This is the best practical lookup when you don't have the full spec.
IEEE Standards Association
Every Ethernet frame and Wi-Fi packet conforms to IEEE 802 specs — the physical/link layer foundation.
OASIS Open Standards
MQTT (IoT), SAML (enterprise SSO), and OpenDocument (ODF) are all OASIS standards with formal catalog entries.
OpenConfig YANG Models
Modern network automation (Google, Meta, Apple operators) standardizes on OpenConfig models over vendor SNMP/MIBs.
UEFI Forum Specifications
Secure Boot, ACPI power management, and firmware-to-OS handoff are all UEFI Forum specs.
PCI-SIG Specifications
Every GPU and NVMe SSD connects via PCIe — the spec tree and ECN index live at PCI-SIG (membership for latest revs).
USB-IF Specifications
USB HID (keyboards/mice), mass storage, and Type-C PD all have USB-IF class specs — separate from the base transport spec.
Ethereum Improvement Proposals
ERC-20, ERC-721, EIP-1559, EIP-4337 (account abstraction) — all indexed by type and number at eips.ethereum.org.
Bitcoin Improvement Proposals
HD wallets, mnemonic seeds, and Bitcoin URI schemes are BIPs — the index is the authoritative catalog.
IPFS Specifications
Content-addressed web infrastructure — each primitive (CID, gateway, IPNS) has its own spec page in a structured index.
Linux Foundation Projects
When a protocol is 'under the Linux Foundation' (OpenAPI, GraphQL, OCI, Node.js) this is the parent org catalog — broader than CNCF alone.
Open Container Initiative
Every container image and runtime (containerd, CRI-O, Podman) implements OCI specs — not Docker proprietary format.
SPIFFE / SPIRE
mTLS between microservices at scale uses SPIFFE IDs instead of per-service certificates — CNCF graduated identity standard.
YAML Specification
YAML 1.2 is the normative spec for config syntax — distinct from JSON Schema validation layered on top.
Schema.org Vocabulary
Rich snippets, SEO structured data, and knowledge graph markup use Schema.org types — the de-facto web semantics catalog.
XMPP Standards Foundation
Federated chat (Movim, Snikket, commercial XMPP) implements XEPs — the IETF core RFC plus hundreds of XEP extensions indexed here.
Authenticated Transfer Protocol (AT Protocol)
ActivityPub isn't the only federated social model — AT Protocol's lexicon catalog and repo sync spec are indexed at atproto.com.
RIPE NCC Technical Documents
BGP routing policy, ASN allocation, and RIPE DB inetnum/inet6num objects are governed by RIPE community policies and docs.
ARIN Policy & Resource Management
North American IP and ASN resources are allocated under ARIN policy — distinct from RIPE/APNIC regional rules.
APNIC Policies & Resources
APAC IP allocation and routing registry (whois.apnic.net) follows APNIC-specific policies — third leg of the RIR system.
NVM Express
Every NVMe SSD and cloud block volume speaks NVMe — spec revisions and command set registry at nvmexpress.org.
JEDEC Solid State Technology Standards
RAM timing, flash endurance ratings, and memory module specs are JEDEC — the hardware layer below NVMe and PCIe.
VESA Standards & DisplayPort
Monitor connectors, HDR certification, and desk mount hole patterns are VESA specs — ubiquitous but rarely cited by name.
HDMI Forum Specifications
HDMI 2.1 features (4K120, VRR, eARC) are HDMI Forum specs — parallel to VESA DisplayPort for display transport.
RISC-V International Specifications
Every RISC-V CPU implements ratified ISA modules from riscv.org/specifications — the open alternative to ARM/x86 ISAs.
DWARF Debugging Information Format
gdb, lldb, and perf rely on DWARF — the spec is maintained independently from ELF (gABI) and LLVM debug info.
LLVM Documentation & LangRef
Rust, Swift, Clang, and Julia target LLVM IR — LangRef is the practical spec for compiler and toolchain interoperability.
SMPTE Standards
Broadcast IP video (ST 2110) and professional timecode (ST 12) are SMPTE — the production pipeline layer above consumer codecs.
DVB Specifications
European and global broadcast receivers implement DVB spec families — parallel ecosystem to ATSC (US) and ISDB (Japan).
TM Forum Open APIs & Frameworx
Telco BSS/OSS digital transformation standardizes on TM Forum Open APIs — the REST catalog for operator IT integration.
MEF Standards
Enterprise WAN and carrier Ethernet SLAs reference MEF service definitions — parallel to IETF protocol specs for operator services.
SIP Forum Technical Recommendations
Enterprise SIP trunking (SIPconnect) and robocall mitigation (STIR/SHAKEN) deployment guides are SIP Forum — atop IETF SIP RFCs.
OPC Foundation Specifications
Factory floor, SCADA, and Industry 4.0 integrations standardize on OPC UA — the industrial protocol catalog beyond MQTT.
Object Management Group
UML/BPMN diagrams and DDS real-time pub/sub middleware trace to OMG — common in aerospace, defense, and enterprise architecture.
FIX Trading Community
Equity and FX trading integrations speak FIX — the tag/value message dictionary is versioned and indexed by the FIX Trading Community.
GS1 Standards
Every UPC/EAN barcode and warehouse scan event maps to GS1 identifiers — the physical-world naming layer for logistics and retail.
DICOM Standard (NEMA)
Hospital PACS, CT/MRI exports, and radiology workflows use DICOM — a massive tagged data dictionary indexed by PS number.
HL7 International Standards
Legacy hospital HL7v2 ADT/ORU feeds and CDA clinical documents remain ubiquitous — FHIR is one branch of the HL7 catalog.
Apache Software Foundation Projects
Data infrastructure specs (Parquet, Avro, Arrow) live under Apache — broader than the Parquet/Arrow entry alone.
Eclipse Foundation Specifications
Sparkplug B industrial MQTT and Jakarta REST/JMS specs are Eclipse — major specs outside Apache and CNCF.
Python Enhancement Proposals
Python packaging (pyproject.toml), type hints, and stdlib behavior are specified as PEPs — the language's RFC equivalent.
SPDX Specification
SBOM mandates (US EO 14028, EU CRA) reference SPDX — the license ID list and SBOM tag-value/JSON format spec.
CycloneDX Specification
Many SCA tools default to CycloneDX JSON/XML alongside SPDX — ECMA-424 normative spec with VEX and attestations.
OpenSSF Best Practices & Scorecards
SLSA provenance levels and OpenSSF Scorecards are the practical OSS security maturity frameworks — under Linux Foundation.
Wikipedia List of File Formats
Not normative, but the fastest way to discover what a format is called and find the real spec link — referenced throughout Rundown file format entries.
JSON Schema
API request/response validation and OpenAPI schemas trace to JSON Schema drafts — indexed by version at json-schema.org.
GraphQL Foundation
GraphQL spec versions are published at spec.graphql.org with a clear edition index (June 2018, October 2021…).
Protocol Buffers
Proto3 syntax, wire encoding, and language guides are indexed at protobuf.dev — separate from gRPC transport specs.
Apache Parquet & Arrow
Data lake and analytics pipelines standardize on Parquet file layout and Arrow IPC — specs at apache.org project sites.
Connectivity Standards Alliance
Matter device spec and certification requirements are CSA — the index spans Matter core, clusters, and device types.
LoRa Alliance Specifications
LoRaWAN spec versions and regional frequency parameters are published and versioned by the LoRa Alliance.
Matrix Specification
Matrix spec versions are published at spec.matrix.org with a structured API index — the federated messaging alternative to XMPP.
HL7 FHIR
Healthcare API integrations (EHR, payers, apps) use FHIR resource catalog and REST spec at hl7.org/fhir.
INCITS Technical Committees
US participation in ISO/IEC IT standards flows through INCITS committees — find the US entry point for POSIX, C, SQL, etc.
The Open Group Standards
POSIX.1 is the portable Unix API — published and indexed by The Open Group, co-maintained with IEEE.
Bluetooth SIG Specifications
Web Bluetooth, BLE devices, and audio accessories all implement Bluetooth SIG specs — indexed by core version and profile.
CNCF Cloud Native Landscape
Cloud-native infrastructure projects live here — useful for finding which foundation owns a protocol vs a product.