ISO 9001:2026 Is Here – What the New Quality Standard Means for Certified Organizations
On 16 September 2026, ISO published the sixth edition of ISO 9001. After eleven years, it replaces the 2015 version and integrates the 2024 climate change amendment.
The good news first: the proven Harmonized Structure, the process approach and the seven quality management principles remain in place. Nevertheless, ISO 9001:2026 is a genuine technical revision – with new priorities that should not be overlooked in your next audit. Quality becomes more clearly a matter of leadership and culture, risks and opportunities are separated, and change management becomes much more concrete.
Five ISO 9001:2026 Takeaways From Our Advisory Practice
Quality Culture and Ethical Behaviour – Leadership
Top management must now explicitly promote quality culture and ethical behaviour, and everyone working under the organization’s control must be aware of the quality culture and the expectations regarding ethical behaviour. Quality is visibly a leadership task.
Risks and Opportunities – Risk Management
Risks and opportunities are determined, analysed and evaluated in separate clauses. Actions to address risks must be proportionate, including risks from disruptions to delivery. A formal risk management system is still not required.
Planning of Changes – Change Management
Seven aspects now have to be considered instead of four. New items include communicating the change and defining how its effectiveness will be monitored and its results reviewed.
Compliance Obligations – Legal Compliance
Organizations must determine which requirements of their interested parties they address through the QMS – including possible climate-related requirements. If you have managed legal and customer-specific requirements only implicitly so far, now is the time to make this allocation transparent.
Documented Information – Document Management
Requirements remain largely stable. However, the significantly expanded Annex A clarifies that evidence must be protected from unintended or unauthorized alteration and deletion – a point that gains weight with digital systems.
Three years – but plan early: Global ACI has set a three-year transition period. ISO 9001:2015 certificates remain valid until 30 September 2029; from 31 March 2028, initial certifications will only be issued to the new edition. If you plan to align the transition with a regular surveillance or recertification audit, schedule a gap analysis early. Austria: According to Akkreditierung Austria, all audits – including surveillance and recertification audits – must be conducted against the new standard no later than 18 months after publication, i.e. probably from spring 2028. Further Austria-specific requirements are possible.
Organizations also certified to ISO 14001:2026 can combine both transitions. For internal audits against the new standard, the revised ISO 19011:2026 provides the matching guideline.
Whether – and to what extent – your organization needs to act depends on your individual system. Sennefer Consulting is happy to help you assess the new requirements and prepare for the transition.
This article was created with AI assistance.