Resources · Quality management

ISO 9001:2026 explained

ISO 9001:2026 is the sixth edition of the international standard for quality management systems, published on 16 September 2026. It replaces ISO 9001:2015 and its 2024 climate amendment, both now withdrawn. ISO describes the revision as clearer, with a stronger emphasis on quality culture and leadership, and risk separated from opportunity.

Last verified: 16 September 2026.

The fact almost nobody is leading with is the withdrawal. ISO’s catalogue entry for the standard records the 2026 edition as published, edition 6, 36 pages, at stage 60.60, developed by ISO/TC 176/SC 2. The same life cycle panel lists ISO 9001:2015 and ISO 9001:2015/Amd 1:2024 as withdrawn. Most commentary this week is framed as “what is changing”. The register says the previous edition has already stopped being the current one.

Withdrawal is not the same as expiry. Your certificate against the 2015 edition remains valid through a transition period that your certification body administers, and we cover that machinery in detail on the ISO 9001:2026 transition page. But the reference copy of the old edition is now a historical document, and anything in your management system that cites it is citing something ISO no longer maintains.

This page does something the certification bodies mostly do not. They describe what changed in the words of the standard, which they are well placed to do. We describe what a working quality management system leaves behind: the records that show it ran. Throughout, we keep three things apart. The requirement is what ISO or a named certification body says the standard asks for. Practical evidence is what an auditor may reasonably expect to see, which is not the same thing. Optional good practice is what mature organisations tend to do anyway. Blurring those three is how a summary turns into a sales pitch.

What changed in ISO 9001:2026?

ISO answers this itself, and the answer is free to read. The Foreword to the standard carries a numbered list of the main changes, and ISO publishes the Foreword, the whole Introduction, the Scope and all of Clause 3 on its Online Browsing Platform with no sign-in and no payment. The paywall falls between the vocabulary and the requirements. That makes the Foreword the only authoritative account of this revision available to anyone, and it is shorter than almost every summary written about it.

ISO lists six changes. Quoted from the Foreword:

  • Inclusion of core ISO management system terms and definitions. “Clause 3 of the document now includes a limited number of terms and definitions. ISO 9000 remains the normative reference for all quality management terms and definitions.”
  • Introduction of quality culture and ethical behaviour. These are “now addressed within the requirements, particularly in relation to leadership, awareness and the environment for the operation of processes.”
  • Separation of risks and opportunities. They are “more clearly distinguished, with separate consideration of actions to address each.”
  • Strengthened management of change. “Requirements related to changes to the quality management system have been reinforced to support the achievement of intended results.”
  • Enhanced explanatory content in Annex A. “It has been revised to provide enhanced clarification of the structure, terminology and intent of the requirements as informative text, without introducing additional requirements.”
  • Removal of Annex B. It previously listed other ISO/TC 176 standards, and those references now sit in Annex A and on the committee website.

Read that list against any transition guide you have been sent. ISO names no artificial intelligence, no digital transformation, no cybersecurity, no sustainability requirement and no resilience requirement. Climate change is not listed as a change either: the Foreword records that the sixth edition “incorporates the Amendment ISO 9001:2015/Amd 1:2024”, which absorbs something that already applied to you rather than adding something that did not. Anyone telling you the 2026 edition introduces an AI requirement can be checked against ISO’s own change list in about a minute, for nothing. We have written separately on how much of the standard you can read for free.

Certification bodies who have read the full text fill in the clause numbers ISO does not give. DNV reports quality culture and ethical behaviour added under clause 5.1, clause 6.1 restructured into new subclauses, reinforced requirements for managing changes to the QMS under clause 6.3, and Annex A significantly expanded. BSI puts the 2026 annex at roughly fifteen pages. DQS names clauses 6.1.2 and 6.1.3 as the split between actions on risks and actions on opportunities. That last one is corroborated inside the free text: the Introduction cross-refers to “risk-based thinking (see A.6.1.2)” and “opportunity-based thinking (see A.6.1.3)”, so the subclauses exist and ISO has a name for the second kind of thinking.

Is ISO 9001:2026 a major rewrite?

No, and treating it as one is the most expensive mistake available to you this year.

The ten clause harmonised structure survives. Clause numbers you have cross-referenced across procedures, audit checklists and job descriptions for a decade largely survive with them, with additions inside clause 6.1 rather than a renumbering of the whole. That single fact sets the scale of the work, because a renumbering would have forced every cross-reference in your system to be rewritten by hand.

What changed is emphasis and precision, not architecture. ISO says the edition “focuses on improving clarity”. A clarification is harder to prepare for than a new requirement, because there is no new box to tick. Instead, things you were already doing loosely are now expected to be done recognisably.

A standard that asks you to be clearer is asking to see your records, not your intentions.

There is one structural change of substance: Annex A, which the 2015 edition already carried, is substantially expanded. It is informative guidance, not requirements. Nobody will be audited against Annex A. It will, however, shape how auditors interpret the clauses it explains, which makes it the most useful fifteen pages in the document and the most frequently misrepresented.

What does ISO 9001:2026 say about quality culture and ethical behaviour?

This is the headline change, and it is also the one most likely to be answered with a poster.

The requirement. ISO states that the edition “emphasizes the importance of quality culture and leadership”. DNV reports promoting quality culture and ethical behaviour added as a new entry under clause 5.1 on leadership and commitment, with the theme picked up again in the awareness clause. DQS reports that top management must “actively promote a quality culture and ethical behaviour”, and that clause 7.3 extends to making employees aware of that culture and its underlying ethical principles. ISO does not, as far as we can verify, require a document called a quality culture policy or an ethics policy. Nobody should tell you it does.

Practical evidence. Culture is difficult to evidence with a statement and straightforward to see in behaviour under pressure. What happens when somebody on the shop floor reports a defect at four in the afternoon on the last day of the month? What happens when an inspector questions a release that the schedule needs? Those two moments leave records, and the records are the evidence. A non-conformance raised by an operator rather than by an auditor, an escalation logged and answered, a release held and the holding decision recorded with a name against it: these are unglamorous and they are far more persuasive than a framed value statement.

An auditor cannot inspect your culture, but they can count how many non-conformances were raised by the people doing the work.

Optional good practice. Some organisations track who raises findings, by role and by site, and treat a sudden fall in reporting as a warning rather than an improvement. That is not required by anything. It is a useful habit, and it is the sort of thing a dashboard can surface without anyone filling in an extra form.

How are risks and opportunities different in the 2026 edition?

The requirement. ISO states that the edition “separates risk and opportunities to ensure organizations proactively take actions to pursue beneficial results”. DQS reports clause 6.1 restructured so that actions to address risks and actions to address opportunities sit in separate subclauses, noting that previously “the risk-based approach was formulated relatively openly”. BSI says the edition “separates risk from opportunity and introduces stronger ‘opportunity-based thinking’”.

The 2015 edition let organisations bundle the two into one register and call the job done. Many did. The practical effect of separation is that an opportunity can no longer be evidenced by being listed next to a risk in the same spreadsheet column.

Practical evidence. The standard does not require a risk register, an opportunity register, or any named software. We can find no basis for saying it does. What an auditor can reasonably ask is what you identified, what you decided to do, and whether it worked. That trail exists whether you keep it in a register, a project record or a management review minute. Where structured analysis is already part of the process, FMEA is a natural place for risk identification to live, because it already captures cause, effect and control in a form somebody else can follow.

Optional good practice. Recording opportunities with the same discipline as risks, including an owner and a date by which the decision was reviewed, is not mandated. It is the cheapest way to stop the opportunity column becoming a wish list.

What changed in planning changes to the QMS?

Clause 6.3 covered planning of changes in the 2015 edition and was frequently the thinnest part of an otherwise sound system.

The requirement. DNV reports “reinforced requirements related to management of changes to the quality management system” under clause 6.3. DNV gives the aim as supporting achievement of intended results, which puts the weight on reviewing whether a change worked. That element is the one that bites. Planning a change is common. Going back afterwards to establish whether it worked is not.

Practical evidence. A change record that can answer four questions: what changed, when it took effect, who authorised it, and what the review afterwards concluded. A system that stores only the current version of a procedure answers the first question and none of the others.

Half of all change control is the part that happens after the change.

This is also the clause that makes your transition itself auditable, since moving between editions is a change to the QMS. The sequencing of that is covered on the transition page.

The change matrix

Confidence is stated honestly, and it is checkable. CONFIRMED means ISO states it in the Foreword or the Introduction, both of which you can read free and verify against this page in a couple of minutes. HIGH means certification bodies who hold the full text agree, and ISO has not said it directly. Nothing reported only in draft era commentary appears in this table at all: those rows were written and then cut, and what happened to them is set out below the table.

Area2015 position2026 change or clarificationPractical evidenceConfidence
Overall structureTen clause harmonised structureRetained. The Foreword records a technical revision of the fifth edition, prepared with CEN under the Vienna AgreementA cross-reference map only if you keep one; nothing new is requiredCONFIRMED
Clause 3, terms and definitionsTerms held in ISO 9000Twenty numbered terms now carried in the standard itself, twenty three counting the quality specific subentries, with ISO 9000 still the normative referenceYour own glossary pointed at the edition you are certified againstCONFIRMED
Clause 4, context, and climateClimate added by Amd 1:2024Not listed by ISO as a main change. The Foreword records the amendment as incorporated, so climate is absorbed rather than newA context review that records whether climate change is relevant, and the reasoning either wayCONFIRMED
Quality culture and ethical behaviourNo culture wordingAddressed within the requirements “particularly in relation to leadership, awareness and the environment for the operation of processes”. DNV reads the first at 5.1, DQS at 5.1.1Findings raised by the people doing the work, escalations answered, releases held and recorded with a decision maker namedCONFIRMED
Clause 6.1, risks and opportunitiesAddressed together, loosely framedSeparated, with “separate consideration of actions to address each”. Annex A is numbered A.6.1.2 and A.6.1.3, confirming the subclause splitAn identification, decision, action and review trail for both, in whatever record you already keepCONFIRMED
Clause 6.3, planning of changesChanges to be carried out in a planned manner“Reinforced to support the achievement of intended results”Change records carrying what changed, when, who authorised it, and what the post change review concludedCONFIRMED
Clause 7.1.4, environment for the operation of processesEnvironment clause with no culture wordingNamed by ISO as one of the three places culture and ethics landThe conditions you actually provide, evidenced however you already evidence themCONFIRMED
Clause 7.3, awarenessAwareness of policy, objectives and contributionNamed by ISO as one of the three places culture and ethics land. DNV and DQS report awareness extending to the culture and its ethical principlesInduction and refresher records naming what people were made aware ofCONFIRMED
Clause 10, improvement10.1 improvement and 10.3 continual improvement separateNew 10.1 mainly consolidates the 2015 clauses 10.1 and 10.3, per DNV. Not named in ISO’s change listClosed corrective actions carrying evidence that the action workedHIGH
Annex AAnnex A present, informative“Revised to provide enhanced clarification of the structure, terminology and intent of the requirements as informative text, without introducing additional requirements”. BSI puts it at around fifteen pagesNone. Annex A is guidance and is not auditable as a requirementCONFIRMED
Annex BListed other ISO/TC 176 standardsRemoved. Those references now sit in Annex A and on the ISO/TC 176 websiteNoneCONFIRMED

What is deliberately not in that table. Draft era commentary written against ISO/DIS 9001:2025, chiefly Advisera, reported changes at clauses 7.1.6, 7.5, 8.2.1, 9.1.2, 9.2 and 9.3. We had rows for all six and cut them. No certification body corroborates any of them against the published text, and BSI, having read the final draft, says the opposite on two: that clause 8 sees “only minor adjustments, primarily focused on terminology updates”, and that “the core performance evaluation requirements in ISO/FDIS 9001 remain unchanged”, which covers monitoring, internal audit and management review. A draft is not a standard, and the clauses that move between the two are exactly the ones a draft cannot tell you about. If you have been told clause 9 changed, ask which published source says so.

What documented information and evidence should an organisation have?

Nothing in the 2026 edition, as far as anyone credible has reported, adds a new mandatory document. The pressure is on quality of evidence rather than quantity of paperwork.

Take the single most examined object in any quality system. A non-conformance report is not a number on a dashboard. Somebody saw something, recorded it, investigated it, reached a decision, assigned an action, and then established whether the action actually worked. Six steps, six points at which the trail can go cold, and the last one is the one that fails most often. A corrective and preventive action marked closed with no evidence of effectiveness is an administrative event, not an improvement.

A closed action with no effectiveness check proves that somebody stopped working on it, not that the problem went away.

For anything serious enough to warrant structured problem solving, an 8D report carries the evidence in its own shape: containment, root cause, escape point, verification before rollout, and confirmation afterwards. That is not required by ISO 9001. It is one of several formats that happens to answer the questions an auditor will ask anyway.

Your internal quality audits need one extra field this year that they probably do not have: which edition the audit was performed against. During the transition window you will run audits against both, and a finding raised under one edition and closed under the other is perfectly legitimate and completely indefensible if the record does not say so.

Optional good practice. Capturing evidence at the point of work rather than reconstructing it afterwards. A timestamped photograph attached at the moment of the finding beats a paragraph written the following week. That is a tooling choice, not a requirement.

Does ISO 9001:2026 require AI, digital transformation or social media monitoring?

No. This section exists because a great deal of what was published this month implies otherwise.

ISO 9001:2026 does not require artificial intelligence. It does not require a digital transformation programme. It does not require a cybersecurity control set, and it is not a Quality 4.0 mandate. You do not have to take our word for that, and you do not have to buy the standard to settle it. ISO’s Foreword lists the main changes in six numbered items, it is free to read, and none of the six is any of these things. The Introduction is blunter still: the document “does not include requirements specific to other management systems, such as those for environmental management, occupational health and safety management, or asset management”.

That is the whole method, and it takes about a minute. Open the Foreword, read the six items, and compare them with whatever you have been sent. If a claimed requirement is not in ISO’s list and the person making the claim cannot give you a clause number, it is their reading, not the standard.

One honest caveat, because someone will raise it. ISO’s own media release for the launch does talk about helping organisations “strengthen resilience” and serve “increasingly interconnected global supply chains”. That is a press office describing why the edition matters, not the standard describing what it asks of you. The two live in different documents and only one of them is auditable. When the marketing and the Foreword diverge, the Foreword is the one your certification body will be working from.

Social media deserves a specific correction. Accessible draft era material on clause 9.1.2 lists online reviews and social media among possible sources of information about customer perception. That is an example, and the wording reported is conditional. Monitoring social media is not a duty created by ISO 9001, and any consultant telling you that your certificate now depends on it is selling something.

An example in a standard is permission, not instruction.

The same caution applies to organisational knowledge under clause 7.1.6. Commentary linking it to emerging technologies is commentary. How you manage it remains your decision.

What happens to ISO 9001:2015 certification?

Your certificate does not become invalid on publication day. ISO’s own catalogue now lists the 2015 edition and its 2024 amendment as withdrawn, but withdrawal of a document and expiry of a certificate are different events with different owners.

ISO directs certified organisations to follow the timeframe set through their certification body. We are deliberately not printing a fixed three year deadline or a September 2029 date on this page, because no accreditation communique fixing one had been published when we last verified. A three year window is widely expected and repeated confidently across the internet. It is a forecast. The sibling page on the ISO 9001:2026 transition sets out why the deadline is genuinely unfixed, including which body now issues it.

There is a second timing fact that matters more to your plan than the end date. A newly published standard is not immediately certifiable, because certification bodies must first be accredited against the new edition. Quality consultancies estimate that lag at nine to twelve months, and we have found no accreditation body statement confirming a figure. The mechanism is the reliable part: it takes months rather than weeks, so the first accredited transition audits will not happen this year. You almost certainly have more runway than the headlines suggest, and it is the only period in which you can change your system without an auditor watching.

How should organisations prepare?

Buy the standard before you rewrite anything. ISO offers a free official preview labelled “Read sample” on the catalogue page, the list price is CHF 196, and UK buyers are directed to BSI. Every summary you read, this one included, is someone’s reading of a document you can hold yourself for the price of an afternoon.

Then do four things in order. Fix a dated baseline of what your system looked like under the 2015 edition, because a transition is a set of changes and you need something to be changing from. Run a gap assessment against the text rather than against a blog. Check whether your records can answer the four questions of change control for any item on any past date. Ask your certification body in writing which visit it proposes to use as your transition audit, and keep the reply.

Notice that three of those four are about records rather than requirements. That is the honest shape of this revision for a mature system. If your QMS genuinely runs, the 2026 edition asks you to prove it more legibly. If it does not, no amount of redrafting the quality manual will produce the evidence, because the evidence is created at the moment work happens or it is not created at all.

The organisations that will find this transition easy are the ones whose records were already a by-product of doing the work.

A note on what we have read

We have not read the requirements. Clauses 4 to 10 and Annex A sit behind ISO’s paywall, we hold no licensed copy, and we will not reproduce clause text or state requirement wording we have not seen. What we have read, in full and at the source, is everything ISO publishes openly: the Foreword with its list of the main changes, the Introduction, the Scope, and the whole of Clause 3. That is where every CONFIRMED row above comes from, and you can check each one yourself without paying anything.

Everything on this page is therefore one of two things, and we have tried to keep them visibly separate. Statements marked CONFIRMED come from ISO’s own Foreword or Introduction. Clause numbers, which ISO does not give in the Foreword, are attributed by name to BSI, DNV or DQS, who hold the full text. Nothing here rests on draft era commentary: the rows that did were cut before publication, and the cut is described under the matrix.

If you find something here that the published text contradicts, we would rather correct it than defend it.

Frequently asked questions

What changed in ISO 9001:2026?

ISO answers this itself, and the answer is free to read. The Foreword to the standard carries a numbered list of the main changes, and ISO publishes the Foreword, the whole Introduction, the Scope and all of Clause 3 on its Online Browsing Platform with no sign-in and no payment.

Is ISO 9001:2026 a major rewrite?

No, and treating it as one is the most expensive mistake available to you this year. The ten clause harmonised structure survives.

What does ISO 9001:2026 say about quality culture and ethical behaviour?

This is the headline change, and it is also the one most likely to be answered with a poster. The requirement. ISO states that the edition “emphasizes the importance of quality culture and leadership”.

How are risks and opportunities different in the 2026 edition?

The requirement. ISO states that the edition “separates risk and opportunities to ensure organizations proactively take actions to pursue beneficial results”.

What changed in planning changes to the QMS?

Clause 6.3 covered planning of changes in the 2015 edition and was frequently the thinnest part of an otherwise sound system. The requirement.

What documented information and evidence should an organisation have?

Nothing in the 2026 edition, as far as anyone credible has reported, adds a new mandatory document. The pressure is on quality of evidence rather than quantity of paperwork.

Does ISO 9001:2026 require AI, digital transformation or social media monitoring?

No. This section exists because a great deal of what was published this month implies otherwise. ISO 9001:2026 does not require artificial intelligence.

Sources

Related terms

Last verified: 16 September 2026

About Logincident. Logincident is a data and software company whose configurable platform captures structured evidence at the point of work and presents it in dashboards and reports, including the live quality platform we run with a heavy equipment dealer group. We are not a law firm or a claims handler, and nothing on this page is legal advice.