
Summary: ISO published 9001:2026 on September 16, 2026, replacing ISO 9001:2015. The changes are an evolution, not a rebuild, but three carry real audit weight: quality culture and ethical behavior, the split between risks and opportunities, and stronger change planning. The transition deadline is not yet confirmed. Plan for roughly three years and work backward from your next recertification date.
ISO 9001:2026 is published. Here is what changed and when you need to move
The International Organization for Standardization (ISO) published the sixth edition of ISO 9001 in September 2026. It replaces ISO 9001:2015 over a transition period and folds in the 2024 climate action amendment.
If you hold an ISO 9001:2015 certificate, you have one decision to make now: when to schedule your ISO 9001:2026 transition audit.
Transition periods for revisions of this kind have historically run three years from publication, which would put the deadline around September 2029. The International Accreditation Forum (IAF) has not yet issued the formal transition requirements for ISO 9001:2026, so that date is an expectation rather than a published deadline. Plan for three years and watch for the IAF announcement to confirm it.
Do nothing and your 2015 certificate lapses at the end of the transition period. At that point you are not renewing. You are starting over with an initial certification, which costs more, takes longer, and puts any contract or tender that requires current certification at risk in the meantime.
What changed in ISO 9001:2026?
The revision is an evolution, not a rebuild. The 10-clause harmonized structure is intact. The process approach, the Plan-Do-Check-Act cycle, and risk-based thinking all remain central.
Six changes carry the most weight.
1. Quality culture and ethical behavior are now in the requirements
Clause 5.1.1 requires top management to promote both. Clause 7.3 requires people doing work under your control to be aware of them. Clause 7.1.4 acknowledges that the environment for operating your processes can be shaped by them. This is the change with the least documentation to point at and the most audit exposure. You cannot build the evidence trail retroactively.
2. Risks and opportunities are separated
Clause 6.1 now splits into three subclauses: determining risks and opportunities, actions to address risks, and actions to address opportunities. Each requires you to determine, analyze, and evaluate, then plan actions and evaluate their effectiveness. “Opportunity-based thinking” now sits alongside risk-based thinking throughout the standard. A single combined risk-and-opportunity register may no longer demonstrate what the auditor is looking for.
3. Management of change is stronger
Clause 6.3 grew from four considerations to seven. New additions cover communicating the change, how you will monitor and evaluate its effectiveness, and how you will review the results. Change planning now has a closed loop.
4. Climate change is built in
Clause 4.1 requires you to determine whether climate change is a relevant issue, and Clause 4.2 notes that interested parties can have climate-related requirements. If you adopted the February 2024 amendment, this is already done.
5. Clause 3 now carries its own definitions
The standard includes roughly 20 core management system terms directly. ISO 9000 remains the normative reference for quality management terms.
6. Annex B is gone and Annex A is expanded
Annex A now clarifies structure, terminology, and intent, including the distinction between “appropriate” and “applicable,” between “consider” and “take into account,” and what “ensure” means for accountability. Read it. It tells you how an auditor is meant to interpret the requirements.

Which ISO 9001 clauses changed in the 2026 revision?
| CLAUSE | WHAT TO LOOK AT |
|---|---|
| 4.2 | New requirement to determine which interested party requirements will be addressed through the QMS |
| 4.3 | Scope must be available as documented information and state the products and services covered, with justification for anything determined not applicable |
| 4.4 | Retitled and reordered; process improvement is now an explicit item |
| 5.1.1 | Reordered; adds promotion of quality culture, ethical behavior, and opportunity-based thinking |
| 5.2 | Quality policy must be implemented, understood, and applied, not only communicated |
| 5.3 | New assigned responsibilities for reporting QMS performance and improvement opportunities to top management, and for maintaining system integrity through change |
| 6.1 | Split into 6.1.1, 6.1.2, and 6.1.3; risk actions proportionate to impact on QMS intended results, with a new note on disruption |
| 6.3 | Expanded change planning requirements |
| 7.1.3 | Infrastructure now covers on-site, remote, and hybrid work |
| 7.1.6 | Organizational knowledge must be retained, applied, and shared |
| 7.3 | Awareness extends to quality culture and ethical behavior |
| 8.1 | Restructured; control now applies to externally provided processes, products, and services relevant to the QMS |
| 8.2.1 | Customer communication covers contingency actions including service disruption |
| 8.3.3 | New note recognizing that design inputs can evolve iteratively |
| 9.1.3 | Risk effectiveness and opportunity effectiveness evaluated separately; adds effectiveness of planning implementation |
| 9.2 | Split into general and audit program; audit objectives now defined per audit |
| 9.3.2 | Adds changes in interested party needs and expectations; separates risk and opportunity effectiveness |
| 10 | Old 10.1 General folded into continual improvement; clause count reduced from three to two |
One change runs through the whole document and is easy to miss. The 2015 language of “maintain documented information” and “retain documented information” is replaced with “documented information shall be available” and “documented information shall be available as evidence of.”
Annex A explains the distinction. Your document control procedure and your records retention language will likely need rewording even where the underlying practice does not change.
How do you prepare for the ISO 9001:2026 transition?
1. Run your own documented gap analysis
This step belongs to your team, and it cannot come from your certification body. Accredited certification bodies must remain independent of your management system, which rules out telling you how your QMS should change or how to close a gap we might later audit. The practical reason points the same direction: the comparison depends on how your processes run day-to-day rather than on what your procedures say, and you are the one who determines applicability and scope under Clause 4.3. You know your environment better than any auditor will.
Compare the 2026 requirements against your QMS as it operates today, clause-by-clause. The output you want is a list of specific updates with owners and dates, not a summary. Expect the work to concentrate in four areas:
- Leadership evidence for quality culture and ethical behavior
- The separation of your risk and opportunity processes
- Your change management procedure
- Your documented information wording
Keep the gap analysis itself as a record. Auditors ask how you determined the scope of your transition, and a documented analysis answers that in one document.
2. Update the QMS and run it
Revised procedures are not enough on their own. Clause 5.1 and Clause 7.3 require demonstrated behavior, and your management review and internal audit cycles need to have covered the new requirements before your transition audit. Give yourself at least one internal audit and one management review under the updated system. That sequencing, not the 2029 deadline, is what determines your real start date.
3. Schedule the transition audit
A transition audit is usually added to a scheduled surveillance or recertification visit rather than run as a separate engagement. For a straightforward single-site system, it often runs about half a day. Multi-site operations, wider scopes, and systems with open gaps take longer. Audit duration is set under IAF audit-time rules, so ask for the specific figure for your scope when you book.
The auditor is looking at the delta. Expect questions on:
- How leadership promotes quality culture and ethical behavior
- How you separated risks from opportunities and evaluated the effectiveness of each
- How your change planning now closes the loop
- Whether your internal audit and management review have covered the revised requirements
Your gap analysis is usually the first document requested, because it shows how you determined the scope of the transition.
Two scheduling realities are worth planning around. Certification bodies must be accredited to the new edition before they can issue certificates against it, so confirm when transition audits open for booking. And every certified organization needs an audit inside the same window. Slots in the final year of a transition period are the hardest to get and the least forgiving if corrective action is raised.
Final thoughts: finding your real ISO 9001:2026 transition deadline
Work backward from your next recertification date, not from the expected 2029 deadline. Add time for the gap analysis, the QMS updates, one internal audit cycle, one management review, and any corrective action raised at audit. That analysis usually shows that the comfortable start date is sooner than it feels.
In a transition, the high cost of unknowns is rarely the standard itself. It is discovering in the final months that your leadership evidence does not exist, that your risk register does not separate opportunities, and that audit slots are gone.
How does Aprio fit into your ISO 9001:2026 transition?
As an accredited ISO certification body, we conduct the transition audit and issue the revised certificate against the new standard.
That role comes with a boundary, and the boundary is not specific to us. Every auditor at every accredited certification body works independently of the client’s management system. We do not perform your gap analysis, write your procedures, or advise on how to close a finding, because that independence is what makes the certificate worth holding. You prepare the system. We audit it and certify it.
One certification body across your ISO portfolio
We certify against ISO 9001 alongside ISO/IEC 27001 for information security, ISO/IEC 27701 for privacy, ISO 22301 for business continuity, and ISO/IEC 42001 for AI management systems.
That matters during a transition, because the harmonized structure means these standards share the same Clause 4 through Clause 10 skeleton. Context, leadership, planning, support, performance evaluation, and improvement are asking closely related questions in each one. This overlap can help to implement a test once, certify many approach when more than one standard is in scope.
The 2026 revision increases the overlap. Planning of changes, the separation of risks from opportunities, and the shift in documented information language all move ISO 9001 closer to how the newer standards are already written. If you certified to ISO/IEC 27001:2022 or ISO/IEC 42001, some of the thinking your team did there transfers directly into this transition.
Auditors who know your stack
We focus on technology companies. Our auditors spend their working lives in cloud-native architectures, continuous integration and continuous deliver (CI/CD) pipelines, infrastructure as code, containerized workloads, and multi-tenant SaaS.
The practical effect is where your audit time goes. You spend it on whether your controls work rather than on explaining how AWS works or why the hard gates in GitHub are effective for segregation of duties.
Start with the gap analysis. Everything after it follows from what it finds, including how much audit time you will need.