Skip to main content

ISO 9001:2026 Is Out. Here Is What Actually Changed.

The sixth edition of ISO 9001 was published on 16 September 2026. Quality culture becomes a requirement, risks and opportunities finally split, and the documented information wording shifts. A practitioner's read, clause by clause, with the transition dates.

Christophe MazzolaChristophe Mazzola· Practicing CISO · Founder of Cyber Academy8 min read
The new ISO 9001:2026 standard beside a worn 2015 binder, with a checklist of what changed: culture, risks, opportunities, change and documented information

ISO published the sixth edition of ISO 9001 on 16 September 2026. It cancels ISO 9001:2015 and absorbs the climate change amendment from 2024. At European level, EN ISO 9001:2026 was approved by CEN on 10 August 2026, and national bodies have until March 2027 to adopt it and withdraw anything that conflicts with it.

I bought both standards on day one, ISO 9001 and ISO 9000, and read them side by side. The structure looks familiar. Ten clauses, same order, same headings, and most of the text you already know. That familiarity is a trap. Four things changed in a way that will show up in your next audit, and one of them is not a requirement you can write a procedure for.

Here is the honest read.

Clause 3 stops pointing elsewhere

In 2015, the terms and definitions clause was one line long. It sent you to ISO 9000 and that was that. In 2026, Clause 3 carries its own set of core definitions, from 3.1 organization to 3.20 monitoring, including risk, process, competence, documented information, conformity, nonconformity, corrective action and audit.

ISO 9000 stays the normative reference for the full vocabulary. Nothing was taken away from it. What changed is that the terms an auditor argues about most often are now inside the requirements document, so nobody can claim they never saw them.

Small detail with teeth: "conformance" is now explicitly deprecated. Use conformity.

Quality culture and ethical behaviour are requirements now

This is the one people will underestimate.

Clause 5.1.1 lists what top management has to demonstrate. Item i) is promoting quality culture and ethical behaviour. Not considering it, not encouraging it where practical. Promoting it. And a note tells you where to look for it: shared values, attitudes, practices and actions.

It doesn't stop at leadership. Clause 7.3 on awareness adds a new item e), the organizational quality culture and ethical behaviour, which means people doing work under your control have to be aware of it. Awareness is auditable. Auditors have been sampling awareness for ten years by walking up to someone on the floor and asking three questions.

Clause 7.1.4, the environment for the operation of processes, keeps the social, psychological and physical factors that were already there in 2015. Non-discriminatory, calm, non-confrontational. Stress-reducing, burnout prevention, emotionally protective. What's new is the closing line: some of those factors can be influenced by the organizational quality culture and ethical behaviour. The link is now written down.

If you want the reference material, Annex A points to ISO 10010 for guidance on quality culture. ISO 9000:2026 defines it properly in 4.3.9, as shared values, beliefs, history, attitudes and observed behaviours, reinforced by how people at every level behave.

Be clear-eyed about what this does to audits. Culture is not a procedure. It will be assessed through interviews, through how your people talk about defects, through whether anyone hesitates before reporting bad news. Some auditors will do this well. Some will turn it into an opinion contest. Your defence is evidence of what management actually does, not a policy page that says you value quality.

Risks and opportunities get their own clauses

In 2015, 6.1 treated risks and opportunities as one lump, and the requirement was vague enough that most organisations produced a table, reviewed it once a year and moved on.

2026 splits it. Clause 6.1.1 determines both. Clause 6.1.2 handles risks, 6.1.3 handles opportunities, and the verb is the same on both sides: determine, analyse and evaluate. Then plan actions, integrate them into your QMS processes, and evaluate the effectiveness of what you did.

Two more constraints. Actions on risks must be proportionate to the potential impact on intended results. Actions on opportunities must fit your context and support desired results.

The split runs all the way through the standard. Clause 9.1.3 now asks you to evaluate the effectiveness of actions taken on risks and on opportunities as separate items, e) and f). Management review inputs do the same, in 9.3.2 g) and h). So you can't merge them back together in your reporting and hope nobody notices.

Alongside risk-based thinking, the standard introduces opportunity-based thinking, and top management has to promote both under 5.1.1 k).

Now the part nobody is quoting. Annex A.6.1.2 says the application of risk-based thinking does not imply the use of formal risk management approaches or a documented risk management process. No mandatory register, no mandatory methodology, no ISO 31000 by the back door. If a consultant tells you the new version forces a formal risk management system, they're selling something.

Change management stops being a footnote

Clause 6.3 in 2015 gave you four things to consider when changing the QMS. 2026 gives you seven, and the three new ones are where the work is:

  • the communication of the changes
  • how the effectiveness of the changes will be monitored and evaluated
  • how the results of the changes will be reviewed

Combined with 5.3 f), which puts responsibility for maintaining the integrity of the system during change squarely on an assigned role, this closes a gap auditors have complained about for years. Organisations restructure, move sites, swap ERPs, and the QMS silently drifts out of date until the next surveillance visit finds it.

ISO 9000:2026 backs this with a full concept on change management in 4.4.7, and Annex A points to ISO/TS 10020 for guidance.

Documented information: available, not retained

Read this one carefully because it looks cosmetic and isn't.

2015 alternated between "maintain documented information" and "retain documented information". 2026 mostly says "Documented information shall be available" or "shall be available as documented information". Competence evidence, fitness for purpose of monitoring resources, evidence of design inputs, all reworded.

Annex A.2 e) explains the intent. "Shall be available as documented information" refers to information you obtained, use or provide. "Documented information shall be available as evidence of" refers to retaining objective evidence, and the annex adds that this does not imply legal evidential requirements.

In practice, the emphasis moves to the information being usable at the point of use, in any medium, rather than to a retention ritual. It also gives you room to argue against the auditor who wants a signed PDF for everything. Bring the argument with the clause reference.

Two other wording changes worth noting. Organizational knowledge in 7.1.6 must now be retained, applied and shared, not simply maintained and made available. And 9.1.2 now says monitor customer satisfaction, and determine the methods for obtaining, monitoring and reviewing that information, which is more direct than the 2015 formulation about perceptions.

Climate change stays, and Annex B is gone

The two lines added by Amendment 1 in 2024 are in the body of the standard. Clause 4.1 requires you to determine whether climate change is a relevant issue. Clause 4.2 carries a note that interested parties can have requirements related to climate change. Nothing new if you already dealt with the amendment. If you ignored it, it's no longer an amendment you can pretend you missed.

Annex A was rewritten and expanded, and it's genuinely more useful than the 2015 version, including the clarifications on appropriate versus applicable, consider versus take into account, continual versus continuous, and what "ensure" means. Annex B, the old list of other ISO/TC 176 standards, was removed.

ISO 9000:2026 did the conceptual work

Published earlier in 2026, the fifth edition of ISO 9000 dropped "systems" from its title. It is now Quality management, fundamentals and vocabulary, and the fundamentals moved from Clause 2 to Clause 4.

The eight quality management principles are untouched. What's new sits in two groups. Fundamental quality management concepts now include process management, risk-based thinking and organizational quality culture. Additional concepts bring in circular economy, emerging technologies, innovation, change management, customer experience, knowledge management, information management, people aspects and business continuity.

Read that list again. It maps almost exactly onto what ISO 9001:2026 asks of you, and onto where the next revision cycle will go. If you want to know what the auditors' training material will be built on for the next decade, it's in that clause.

The transition clock

The dates come from Global ACI, the accreditation cooperation that took over from IAF at the start of 2026, in its transition requirements document for ISO 9001:2026:

  • 31 March 2027: accreditation bodies ready to assess against ISO 9001:2026
  • 30 June 2027: certification bodies submit their transition declarations
  • 30 September 2027: accreditation decisions completed
  • 31 March 2028: new and initial accredited certificates may only be issued to ISO 9001:2026
  • 30 September 2029: end of the transition, ISO 9001:2015 certificates expire

Three years sounds comfortable. It isn't, for one reason. Most organisations will transition during a scheduled surveillance or recertification audit rather than paying for a separate transition audit, and those slots fill from the certification body's side, not yours. Count backwards from your own certification cycle and you'll usually find you have one realistic window, not three years of them.

What to do in the next six months

Don't rewrite your manual. Do four things.

Run a gap review against 6.1.2 and 6.1.3 and see whether your current risk work survives the word "analyse". Most single-column risk tables won't.

Extend your change process to cover communication, monitoring of effectiveness, and review of results, then test it on a change you're making anyway.

Decide what evidence you'll put in front of an auditor when they ask how top management promotes quality culture and ethical behaviour. Board minutes, decisions where quality beat schedule, what happened to the last person who escalated a problem. Collect it now, because you can't reconstruct it later.

Brief your internal auditors before they run the next cycle. If they audit the 2026 text against 2015 habits, you'll find out about the gaps from your certification body instead.

The structure didn't change. The expectations did.

Training with Cyber Academy

We run PECB and ISACA certification courses in small cohorts, taught by a practitioner who audits and implements these systems for a living. If your team needs to be fluent in the 2026 requirements before the transition audit, browse the programmes or book a 20-minute call.

Want the next field note in your inbox?

The GRC Brief newsletter. Five links and one short take, every Monday at 8am CET. Three-minute read.

ISO 9001:2026 Is Out. Here Is What Actually Changed. · Cyber Academy