also, it's completely okay if no code had to be changed
also there are quality assurance and process related standards, that are about documentation...
and let's not forget that a government can usually require that the vendor sign paperwork, which makes sure the officers of the vendor are criminally liable
... I'm not in favor of them, nor in favor of spending millions on legal and documentation fees, but without knowing more it's yet another "public procurement bad" story (which is completely believable! I mean 1M EUR compliance cost nowadays is not that unusual)
At some point some lawmakers (under the influence of some company such as Cap Gemini or Atos) passed a law to force notaries to use only software with that particular stamp.
The problem is that it's typically the sort of standard that should be applied to a particular organisation and workflow, through an auditing process, instead of a global, upfront stamp that is really a way to do gatekeeping, not actually enforcing data safety and security.
Nobody on this thread said a word against standardization. It's really important. You are replying for some comment that isn't there.
Physical Engineering standards serve a different purpose than software standards. Engineering standards are a social contract we all buy into because of the incredibly cost and complexity of designing physical infrastructure.
Software is not constrained by the same standards. It's alright if the firmware of a coffee machine and a cell phone run on a different standard, but it's going to cause problems if each of my sockets has a different grounding.