---
title: "Solutions by Industry"
description: "Regulated-industry ERP and B2B systems: healthcare, finance, manufacturing, aerospace and more — each built to the controls that sector is audited against."
canonical: https://erpstack.io/industries
markdown_url: https://erpstack.io/industries.md
publisher: ERPStack
---

# Solutions by Industry

> **In short:** ERPStack builds one architecture and changes the compliance surface per industry. The stack is the same in every sector — Next.js, TypeScript, PostgreSQL, Drizzle ORM, RBAC, SSO, REST and GraphQL APIs on AWS or Microsoft Azure — while healthcare answers to HIPAA, finance to PCI DSS, government to NIST SP 800-53, aerospace to ITAR and biotech to FDA 21 CFR Part 11 compliance. You own the source code and pay no per-seat licence.

## One architecture, twenty compliance surfaces

### The core does not change with the sector

Every ERPStack build starts from the same core: Next.js and TypeScript, a PostgreSQL primary behind Drizzle ORM, RBAC and SSO, JWT sessions, an Immutable Audit Trail, Terraform and GitHub Actions, Sentry instrumentation, deployed to AWS or Microsoft Azure in your own account. What differs by sector is the evidence that core has to produce: HIPAA and SOC 2 in healthcare, PCI DSS in retail and finance, ISO 27001 across regulated work, GDPR wherever EU data lands, and FedRAMP Security Controls for government work.

### Where the industry actually changes the schema

The sector decides the ledger, not the login. In manufacturing and construction the PostgreSQL schema is a bill of materials and a WIP schedule; in insurance and finance it is a double-posted ledger; in healthcare and biotech it is a validated record whose audit trail cannot be edited; in logistics and agriculture it is an Event-Driven Architecture carrying lot-level traceability; in media and telecom it is a rated usage ledger; in legaltech it is a trust account that can never go negative. Same PostgreSQL, same RBAC, different invariants.

### Package or custom build

Most sectors have a credible package: SAP S/4HANA and Epicor ERP in manufacturing, Oracle NetSuite in retail, Salesforce in telecom and insurance, Odoo, Sage X3, Zoho Creator and Microsoft Dynamics 365 in the mid-market. A custom ERP on Next.js and PostgreSQL wins when the package cannot hold the sector's invariant — an aerospace heat-lot trace, a legaltech trust ledger, a mining assay lineage — or when per-seat licensing prices out the partner portals the business actually needs. Where both are true we run a Strangler Fig Migration Pattern instead of a cutover.

## Industries

- [Life Sciences & Healthcare](https://erpstack.io/industries/healthcare) — Custom healthcare ERP engineered to the HIPAA Security Rule and HITRUST CSF controls: FHIR v4 and HL7 v2 integration, immutable audit trails, AES-256 ePHI encryption. Standards: HIPAA, HITRUST, GDPR, SOC 2 Type II, FDA 21 CFR Part 11.
- [FinTech & Financial Services](https://erpstack.io/industries/finance) — Custom FinTech ERP on a cryptographically chained PostgreSQL ledger: PCI DSS v4.0 tokenisation, SEC Rule 17a-4 retention, SOC 2 and ISO 27001 evidence from the schema. Standards: PCI-DSS v4.0, SOC 2 Type II, ISO 27001, SEC Rule 17a-4.
- [Retail & D2C E-commerce](https://erpstack.io/industries/retail) — Custom retail and D2C e-commerce ERP: one stock ledger behind Shopify, Amazon and the store, supplier PO automation, PCI DSS scope reduction, CCPA and GDPR deletion. Standards: PCI DSS v4.0.1, CCPA / CPRA — Civ. Code §§ 1798.100–1798.199.100, Civ. Code § 1798.82 — 30-day breach notice, GDPR — 72-hour breach notification, SOC 2 Type II, ISO 27001.
- [Advanced Manufacturing](https://erpstack.io/industries/manufacturing) — Custom manufacturing ERP on the ISA-95 Level 3/4 boundary: multi-level BOM with ECO effectivity, EDI 850/856/862, IATF 16949 PPAP evidence and CBAM data. Standards: IATF 16949:2016, ISO 9001:2015, ANSI/ISA-95.00.01-2025, ANSI/ISA-62443-3-3-2013, CBAM Regulation (EU) 2023/956, SOC 2 Type II.
- [Supply Chain & Logistics](https://erpstack.io/industries/logistics) — Custom logistics ERP on EDI X12 204/990/214/210 and GS1 EPCIS 2.0, with ISF 10+2 timing under 19 CFR 149 and 46 CFR 541 demurrage invoicing. Standards: 19 CFR 149 ISF 10+2, UFLPA rebuttable presumption, 46 CFR 541 demurrage, 49 CFR 395 ELD, EU ICS2 ENS, ISO 14083 emissions.
- [Public Sector & Government](https://erpstack.io/industries/government) — Custom government ERP on GASB fund accounting with encumbrances: NIST SP 800-53 Rev. 5 controls, WCAG 2.1 AA by 26 April 2027, NARA records, FOIA workflows. Standards: NIST SP 800-53 Rev. 5, NIST SP 800-37 Rev. 2 RMF, NIST SP 800-171 Rev. 3, CJIS Security Policy v6.0, Section 508 / 36 CFR 1194, ADA Title II / 28 CFR 35.200, 2 CFR 200 Uniform Guidance.
- [NGO & Nonprofit](https://erpstack.io/industries/ngo) — Custom NGO and nonprofit ERP on FASB ASC 958: donor-restricted net assets, functional expense allocation, Form 990 Part IX, 2 CFR 200 subawards, IATI 2.03. Standards: FASB ASC 958 / ASU 2016-14, 2 CFR 200 Uniform Guidance, IRS Form 990 & Schedules, Core Humanitarian Standard 2024, IATI Standard 2.03, UK GDPR & PECR, OFAC SDN screening.
- [Education Technology (EdTech)](https://erpstack.io/industries/edtech) — Custom edtech ERP on LTI 1.3, OneRoster 1.2 and Ed-Fi: the FERPA school-official boundary, the COPPA Rule's 22 April 2026 date, and NDPA district data maps. Standards: FERPA (34 CFR Part 99), COPPA Rule (16 CFR Part 312), PPRA (20 U.S.C. 1232h), NY Education Law 2-d, SOPIPA (Cal. B&P Code 22584), WCAG 2.2 AA / Section 508, GDPR Article 8, SOC 2.
- [Insurance & InsurTech](https://erpstack.io/industries/insurance) — Custom insurance ERP on ACORD AL3 and ACORD XML: statutory and IFRS 17 ledgers from one Postgres stream, NAIC Model #668 72-hour evidence, SERFF and X12 837/835. Standards: NAIC Insurance Data Security Model Law #668, NAIC Annual Financial Reporting Model Regulation #205, IFRS 17 Insurance Contracts, Solvency II Directive 2009/138/EC, DORA Regulation (EU) 2022/2554, HIPAA 45 CFR Part 162, SOC 2 Type II.
- [Legal Technology (LegalTech)](https://erpstack.io/industries/legaltech) — Custom legaltech ERP where a client matter cannot go negative: per-matter IOLTA ledger in PostgreSQL, LEDES 1998B and UTBMS validation, FRCP 37(e) holds and load files. Standards: ABA Model Rule 1.15 / IOLTA, ABA Model Rule 1.6(c), FRCP 37(e), FRE 502(d), EU-US Data Privacy Framework, SOC 2 Type II, ISO 27001.
- [Real Estate & PropTech](https://erpstack.io/industries/realestate) — Custom real estate ERP on RESO Web API Core 2.0.0 and MISMO 3.6: CAM reconciliation with base years and gross-ups, ASC 842 rent, FinCEN Real Estate Reports. Standards: 31 CFR 1031.320 FinCEN Real Estate Report, 24 CFR 100.500 Fair Housing effects, ASC 842 and IFRS 16, RESO Data Dictionary 2.0, MISMO Reference Model 3.6, NYC Local Law 97 emissions reporting, GDPR, SOC 2 Type II.
- [Energy & Utilities](https://erpstack.io/industries/energy) — Custom energy ERP on the FERC Uniform System of Accounts: CIP-013 vendor evidence, IEC 61850 and CIM telemetry into TimescaleDB, and versioned AMI meter data. Standards: NERC CIP-013-3, NERC CIP-010-5, FERC 18 CFR Part 101, IEC 62443-3-3, IEC 61850, PHMSA 49 CFR 191, SOC 2 Type II.
- [Telecom Operators](https://erpstack.io/industries/telecom) — Custom telecom OSS/BSS on TM Forum Open APIs — TMF620 catalogue, TMF622 ordering, TMF678 billing — with 3GPP CDR mediation and FCC CPNI recordkeeping. Standards: FCC CPNI 47 CFR 64.2009, FCC 47 CFR 8.1 Broadband Labels, STIR/SHAKEN 47 CFR 64.6305, CALEA 47 CFR 1.20000, TM Forum ODA, 3GPP TS 32.290, SOC 2 Type II.
- [Construction & Contracting](https://erpstack.io/industries/construction) — Construction ERP built on cost-to-cost ASC 606 revenue, WIP over- and under-billings, AIA G702/G703 billing, retainage, lien waivers and WH-347 payroll. Standards: ASC 606 cost-to-cost, AIA G702 / G703, 29 CFR 5.5 payroll, 29 CFR 1904.41 OSHA, ISO 19650 / IFC 4.3.
- [Food Supply Chain & Agriculture](https://erpstack.io/industries/agriculture) — Agriculture ERP built on 21 CFR Part 1 Subpart S Critical Tracking Events, EUDR six-decimal plot polygons, and grain settlement posted to the ledger. Standards: FSMA 204 — 21 CFR Part 1 Subpart S, EUDR — Regulation (EU) 2023/1115, EPA Worker Protection Standard 40 CFR 170, Veterinary Feed Directive 21 CFR 558.6, FSMA Sanitary Transportation 21 CFR 1 Subpart O, USDA NOP Strengthening Organic Enforcement, GLOBALG.A.P. IFA v6 GFS.
- [Media & Entertainment](https://erpstack.io/industries/media) — Custom media ERP for rights windowing, avails and residuals: DDEX ERN 4.3.2 and DSR, EIDR and ISRC identifiers, VAST 4.3 and ads.txt reconciliation. Standards: EU AI Act Art. 50 (Reg. 2024/1689), European Accessibility Act (Dir. 2019/882), FCC 47 CFR 79.4 captioning, C2PA 2.4 Content Credentials, EU VAT One Stop Shop, Digital Services Act (Reg. 2022/2065), GDPR, PCI DSS, SOC 2, ISO 27001.
- [Hospitality & Travel](https://erpstack.io/industries/hospitality) — Custom hospitality ERP wired to PMS, CRS, RMS and POS: night audit as code, USALI 12th Revised Edition accounts, PCI DSS 4.0.1 scope cuts, occupancy tax. Standards: PCI DSS 4.0.1, USALI 12th Revised Edition, GDPR, Regulation EU 2024/1028, PSD2 SCA — Regulation 2018/389, 29 CFR 531.54 tip pooling, SOC 2 Type II.
- [Mining & Metals](https://erpstack.io/industries/mining) — Custom mining ERP built on resource and reserve lineage: assay-to-JORC/S-K 1300 audit trail, GISTM tailings telemetry, offline shift capture, MSHA Part 50. Standards: JORC Code 2012, NI 43-101, SAMREC 2016, SEC S-K 1300, GISTM 2020, MSHA 30 CFR Part 50, SOC 2 Type II.
- [Aerospace & Defense](https://erpstack.io/industries/aerospace) — Custom aerospace and defense ERP: AS9102C First Article Forms 1-3, heat-lot traceability to the mill certificate, ITAR deemed-export RBAC and CMMC Level 2. Standards: AS9100D, AS9102C, AS5553E, RTCA DO-178C, ITAR 22 CFR 120-130, CMMC Level 2 (32 CFR 170), NIST SP 800-171.
- [Pharma & Biotech](https://erpstack.io/industries/biotech) — Custom biotech and pharma ERP built to 21 CFR Part 11 and EU GMP Annex 11: ALCOA+ audit trails, GAMP 5 risk tiers, and FDA's 2025 final CSA guidance. Standards: FDA 21 CFR Part 11, EU GMP Annex 11, GAMP 5 Second Edition, 21 CFR Part 58 (GLP), ICH E6(R3) GCP, 21 CFR Part 820 (QMSR), GDPR Article 9.

## Frequently asked questions

### Which industries does ERPStack build for?

Twenty sectors have a page here: healthcare, finance, retail, manufacturing, logistics, government, NGO and nonprofit, edtech, insurance, legaltech, real estate, energy, telecom, construction, agriculture, media, hospitality, mining, aerospace and biotech. Each industry page states the standards that build is engineered against, the systems it has to integrate with — SAP S/4HANA, Oracle NetSuite, Salesforce, Apache Kafka — and the questions buyers in that sector actually ask. If your industry is not listed the architecture still applies; the compliance surface is what we would research first.

### Does ERPStack hold industry certifications such as SOC 2 or HIPAA?

No. ERPStack holds no SOC 2 attestation, no ISO 27001 certificate, no HITRUST or FedRAMP authorisation of its own. What it does is build systems that pass yours: RBAC, an Immutable Audit Trail, encryption and evidence exports generated from the PostgreSQL schema, and Zero-Trust Security defaults, so your auditor tests the system rather than trusting a vendor badge. Every industry page names the standards that sector's build is engineered against, and says plainly where the certification belongs to you and not to us.

### What is the same in every industry solution you build?

The core. Next.js and TypeScript, a PostgreSQL primary behind Drizzle ORM, RBAC and SSO, JWT sessions, an Immutable Audit Trail, Terraform and GitHub Actions, Sentry instrumentation, deployed to AWS or Microsoft Azure in your own account. Multi-tenant architecture where it helps, single-tenant where the industry demands isolation, and serverless only where it earns its keep. You own the source code, there is no per-seat licence, and the same solutions run for ten users or ten thousand.

### Do you replace SAP or NetSuite, or build alongside them?

Usually alongside. In most industry engagements the package keeps the statutory books — SAP S/4HANA, Oracle NetSuite, Microsoft Dynamics 365 or Odoo — while the custom ERP takes the part the package cannot model, joined over a REST or GraphQL API boundary. That is a Strangler Fig Migration Pattern, not a big-bang cutover. Full replacement is the right call only when licence and change-request costs over three years exceed the cost of a rebuild.

### Which industry pages carry the most regulatory detail?

The heavily regulated ones: biotech and healthcare on 21 CFR Part 11, HIPAA and SOC 2, aerospace on ITAR and CMMC Level 2, government on NIST SP 800-53 Rev. 5, energy on NERC CIP, insurance on NAIC Model #668 and IFRS 17, telecom on FCC CPNI, retail on PCI DSS, and finance on SEC Rule 17a-4. Each industry page names the instrument, the date it bites, and what it forces into the PostgreSQL schema and the RBAC model — not a badge wall.

### Which systems do these industry builds integrate with?

The sector decides that too. SAP S/4HANA appears in manufacturing, aerospace, insurance, mining and biotech; Oracle NetSuite and Salesforce where a package is already the system of record; Apache Kafka and TimescaleDB wherever the industry streams telemetry — energy, logistics, mining, agriculture and telecom; a ClickHouse analytics database for telecom mediation; AWS S3 Object Lock where a record has to be immutable; AWS KMS for finance and biotech key custody. Each industry page lists its own integration surface rather than a generic connector count.

### What does one industry page actually contain?

Four things a generic vendor page does not: the standards that sector is audited against with the dates they bite, the integration surface the build has to speak, the metrics the system is designed toward, and the questions buyers in that industry actually ask, answered in full. The engineering is the shared core — Next.js, TypeScript, PostgreSQL, Drizzle ORM, RBAC, SSO on AWS or Microsoft Azure — so the page can spend its length on what is specific to the sector rather than repeating that the ERP runs on Vercel, Redis and Terraform like every other ERPStack build.
