Skip to content
← Resources

ISO 14025:2026 is not the hard part. The transition is.

Anni Oviir 8 min read
Waves rolling onto a beach one after another — a metaphor for the ISO 14025:2026 transition reaching EPD programmes in waves

In June, ISO 14025:2026 replaced a standard that had governed EPDs for twenty years. The industry commentary has mostly treated this as a milestone to applaud. Modernised terminology, stronger impartiality requirements, digital EPDs formally recognised, better harmonisation, and for the first time, formal requirements for EPD tools, including their independent verification. All true, all welcome.

I think the applause may be a little premature. Not because anything is wrong with the standard, but because publication was probably the easy part.

Here is what happens next. Every EPD programme operator in the world now has to align its own rulebook: General Programme Instructions, PCR procedures, verification arrangements, and now also how they handle EPD tools. The obvious question is: by when?

Look closely and the answer is genuinely complicated. As far as I can tell, there is no global deadline. ISO 14025 is not a certifiable management system standard like ISO 14001, where the International Accreditation Forum sets a transition period, typically three years, and every accredited certificate worldwide moves to the new edition on the same clock. For EPD programmes, no equivalent mechanism seems to exist.

In Europe, there is a coordination layer: ECO Platform. And it is, in my view, one of the most valuable things this industry has. Once ECO Platform releases a new version of its Standards, member programmes implement it within six months, new EPDs comply within twelve, and members are audited on it. That is a real synchronisation mechanism, and European construction EPDs are better off for having it.

But look at what ECO Platform is dealing with right now, because it says something about the scale of change in this space. The ECO Platform Standards, the vehicle through which new rules reach member programmes, are in the middle of a broad, multi-chapter revision. That revision drew such a high volume of detailed, substantive comments from the community that the planned December publication was pushed back to give the feedback proper diligence. That seems like the right call. It is also a telling one: even the organisation whose entire purpose is keeping European programmes aligned, with real expertise and real processes, needs more time to work through everything that is changing at once. ISO 14025:2026 alignment will likely travel through that same channel, joining a pipeline that is already full. I don’t read that as a weakness of ECO Platform. I read it as a measure of how much is genuinely moving.

And the coordination, by design, only reaches so far. ECO Platform covers its member programmes, largely European and construction-focused. Plenty of programme operators worldwide sit outside it. Meanwhile some operators are already ahead: EPD International states its General Programme Instructions are already closely aligned with the new edition.

So this is what the transition looks likely to become. Not one change, but waves. Some programmes effectively aligned before the ink dried. European members preparing for coordinated transition whose start date is still being worked out. Programmes outside any framework, moving on their own schedules. If you develop EPDs across three programmes, you may well spend the next couple of years under three rulebooks, each on its own clock.

We have some idea how this goes, because something similar already happened on a smaller scale. During the EN 15804 A1 to A2 transition, programme operators ran mixed PCR portfolios for years. Many who worked through it will remember the recurring conversation: which version applies to this project, are you sure, who checked.

That was one amendment, largely one region. This is every programme, everywhere. And the stakes have changed since 2022. Under the revised Construction Products Regulation (CPR), environmental data moves into legally binding Declaration of Performance and Conformity (DoPC), and from January 2027 Member States can penalise faulty environmental declarations. Following an outdated version used to cost you rework. Increasingly, it may cost liability.

Some programme operators will reasonably say that for them, the changes are modest. That their instructions are largely aligned already. For some, that is true, and it is to their credit. But notice what it does not necessarily do: it does not make the transition safe. It may just make it quiet. Sweeping changes announce themselves; everyone stops, retrains, rebuilds. Modest changes are often the ones that slip past: a definition retired here, a new tool verification requirement there, a tightened PCR governance clause that only matters the day it matters. And “modest” means something different at every programme, which is part of the problem for anyone working across several.

An uncomfortable opinion

Now the part where I find myself disagreeing with how our industry tends to handle this.

We often treat standards compliance as a knowledge problem. Read the standard, understand it, hire people who know it well. Under that logic, the teams that fail during a transition must be the ones who did not do their homework.

In my experience, that is rarely the whole story. The teams that get caught are often experienced practitioners whose knowledge quietly expired. Their checklist was correct when it was written. Their template was compliant when it was built. Then a standard revised, a PCR versioned, a transition timeline shifted, and nothing in their workflow forced anyone to notice. Nobody chose to follow outdated rules. The rules moved and the workflow did not.

Compliance knowledge expires silently. I believe that is a bigger failure mode than we usually admit. And this transition makes the point at every level: if a dedicated coordination body with deep expertise needs extra time to work through the changes, then an individual practitioner tracking all of it through memory and newsletters, across several programmes at once, faces long odds of catching everything. Not through carelessness. Simply through arithmetic.

I think the more durable fix is structural: the rules live in one maintained place, and every review runs against the current state of that place, automatically. Standards-currency, in this view, becomes infrastructure - much the way few people manually track security patches anymore.

What that looks like in practice

This is the design premise of Lodestellar, and I want to be concrete about it, because “we stay on top of the standards” is a claim anyone can type.

In our system, a standard is not a PDF someone read once. Every requirement is encoded as a discrete, individually maintained check, traceable to the clause it comes from. Those requirements compose into rulesets that mirror how the rules actually stack in the real world: core standard, plus PCR version, plus programme-specific instructions. Submit an EPD and it is reviewed against the stack that applies to that document, that programme, that date, rather than against a generic checklist.

The payoff shows up most clearly during a transition like this one. When ISO 14025:2026 changes a requirement, we update it once, version the ruleset, and every review from that moment runs against the new state. When ECO Platform publishes its revised Standards, its six and twelve month implementation windows become dates in the ruleset, and the coordinated European transition it has built gets reflected as designed. When a programme outside that framework announces its own path, that becomes its own ruleset version. The waves that make this period demanding for practitioners are, to the system, data arriving at different times.

One honest caveat: software does not read standards. A domain expert maintains those requirements and encodes every change the programmes announce. What the system does is help stop that expertise from expiring. Keeping it current is our entire job. We are not building an EPD generator, not becoming a programme operator, not replacing verifiers. We see ourselves as a layer that helps the work of programme operators, verifiers, and coordination bodies land in practice, and that only works if staying current is the only thing we do.

The level above: who checks the PCRs?

There is one more implication here, and it deserves its own section, because it is a part of this transition that seems to get very little attention.

Every EPD stands on a PCR. The product category rules decide the functional unit, the system boundary, the scenarios, the data requirements. If the PCR is flawed, every EPD built on it inherits the flaw, no matter how carefully the LCA was done or how diligently the EPD was verified. The PCR is the foundation layer of the system.

And here is the uncomfortable part: as an industry, we systematically verify EPDs, but as far as I can see, we do not systematically re-check PCRs. A PCR gets reviewed once, at creation, by a review panel and an open consultation. After that, it typically lives for years while the standards underneath it move. Rarely does anyone go back and ask, requirement by requirement, whether the PCR still conforms to the rules it was supposed to be developed under, or whether it ever fully did. With hundreds of PCRs across dozens of programmes, in different versions, developed under different editions of the standards, that looks less like a gap and more like a missing layer of quality assurance.

ISO 14025:2026 makes this harder to ignore. It tightens how PCRs are developed and governed, integrates ISO/TS 14027 as a normative reference, and brings EPD tools under formal verification requirements for the first time. The rulebook for making rulebooks just got stricter. Which raises a fair question: who checks conformance against it?

Structurally, this looks like the same problem we already work on. A PCR is a document that must conform to a rulebook, which means it can in principle be checked the same way an EPD can: requirement by requirement, against the applicable edition. We are actively building in that direction. Not as a policing exercise, but as the same kind of support layer: helping PCR committees, programme operators, and EPD developers see whether a PCR holds up against the current rules before hundreds of EPDs get built on top of it. Under the CPR, with environmental data becoming legally binding, a defect inherited from a PCR could get expensive. Catching it at the foundation is likely cheaper than catching it in a hundred declarations.

The standard changed once. The transition will arrive in waves, and even with good coordination, those waves probably will not land everywhere at once. Tracking it by hand is possible. We think there is a strong case for making it infrastructure.


Related reading