After a three-year revision project, ISO 9001:2026 has been published, replacing the 2015 edition that quality teams have worked to for over a decade.
If you have spent the past year reading speculative previews, here is the headline. This is an evolution, not a rebuild. The clause structure is largely unchanged. The process approach, the Plan-Do-Check-Act cycle and risk-based thinking all remain central. Most of the minor title and subclause changes exist to align ISO 9001 with the harmonized structure shared across ISO management system standards, which is designed to give all of them common clause titles, core text and definitions so that organisations running multiple standards can integrate them more easily.
But three areas have moved in ways that will show up in your next audit, and they are worth understanding properly.
1. Quality culture and ethical behaviour are now in the requirements
This is the most significant addition. A new requirement and a clarifying note were added to subclause 5.1.1, placing quality culture and ethical behaviour within top management's leadership commitment. The change aligns ISO 9001 with the ISO 9000 leadership principle and its definition of quality culture.
It does not stop at leadership. Because culture and behaviour influence the working environment, they were also added to subclause 7.1.4, and clause 7.3 was updated so that awareness of culture and behaviour extends to everyone working under the organisation's control.
The practical challenge is evidential. Culture is not a procedure you can point an auditor at. Demonstrating it means showing patterns over time: that people raise issues without fear of consequence, that reported problems get investigated and closed, that improvement suggestions come from the floor as well as the management review, and that leadership visibly acts on what it hears.
2. Risks and opportunities are now handled separately
In the 2015 edition, "risks and opportunities" travelled together as a single phrase, which encouraged organisations to treat opportunity as an afterthought in a risk register. The 2026 edition pulls them apart in clause 6.1 to clarify the distinction, with the same separation applied in subclause 9.1.3 (analysis and evaluation) and subclause 9.3.2 (management review inputs).
Requirements to analyse and evaluate risks and opportunities now sit in subclauses 6.1.2 and 6.1.3 respectively. Importantly, Annex A clarifies that this does not imply a formal or documented approach is required. Subclause 5.1.1 also now references opportunity-based thinking alongside the process approach and risk-based thinking, which were themselves separated.
Where this bites is management review. Because risks and opportunities are separated at 9.3.2, the effectiveness of the actions taken against each can now be reviewed independently. A single combined register makes that harder to evidence than it needs to be.
3. Climate change is formalised in the standard text
Clause 4.1 now requires organisations to determine whether climate change is a relevant issue for their context, and a note has been added at clause 4.2 recognising that interested parties may have climate-related requirements. This formalises the amendment published in February 2024, so for most certified organisations it is not new work. What it does mean is that the assessment now sits within the standard rather than alongside it, and auditors will expect to see that you considered it, including where you concluded it was not relevant.
Changes that are easy to miss
- Management review inputs are now mandatory. At subclause 9.3.2, the framing shifted from taking inputs into consideration to a requirement that the review shall include them. A further input has been added: reviewing changes in the needs and expectations of interested parties relevant to the QMS. If your management review agenda has drifted over the years, this is the clause to check first.
- Quality policy is more closely tied to strategy. Clause 5.2 strengthens the connection between the quality policy, the organization's context and its strategic direction, reinforcing the QMS as a business management tool rather than a standalone compliance exercise.
- Planning of changes has been expanded. Clause 6.3 gained considerations covering how changes are communicated, how their effectiveness is monitored and evaluated, and how results are reviewed. These remain considerations rather than new requirements, but they signal what good change control now looks like.
- Documented information language has changed. References to maintaining documented information have become requirements for information to be available as documented information, and retaining documented information as evidence has been reworded accordingly. The revision deliberately avoided adding new documentation requirements, so this is terminology alignment rather than extra burden.
- Clause 10 has been consolidated. The general and specific continual improvement requirements were combined to remove redundancy, and the clause 10.1 title changed to continual improvement. At clause 10.2, the reference to complaints moved into a note, on the basis that not every complaint is a nonconformity.
- Annex A has grown, Annex B has gone. Annex A was expanded to clarify clause structure, terminology and the requirements in clauses 4 to 10. It remains informative and is not auditable. Annex B was removed, with its references to other ISO standards folded into Annex A.
- New definitions were added at clause 3. A set of common ISO 9000 terms was brought into the standard to align with the harmonized structure, covering terms such as organisation, interested party, top management, risk, competence and corrective action. ISO 9000 remains the normative reference for QMS terms and definitions.
What this means for your transition
ISO has confirmed a three-year transition period for organizations certified to ISO 9001:2015. Certification bodies will advise organizations on timing and transition requirements, and existing certificates will remain valid throughout the transition window.
There is no reason to panic and good reason not to wait. Certification bodies hold a fixed pool of accredited auditors, and every certified organisation in the world needs a transition audit inside the same window. The 2015 transition saw exactly that bottleneck in its final year.
Five steps worth taking this quarter
- Obtain copies of ISO 9001:2026 and ISO 9000:2026, and get them into the hands of the people who own the clauses.
- Talk to your certification body about its transition timetable and when accredited audits will be available.
- Run a gap analysis against the 2015 edition to identify what genuinely needs to change, particularly around leadership, culture and the separation of risk and opportunity.
- Identify training needs, especially for top management and internal auditors, who will be auditing against changed expectations.
- Build an action plan with dates, owners and a scheduled internal audit against the new edition.
Where a purpose-built QMS earns its place
The 2026 revision rewards organisations that can evidence how their quality management system actually operates, not just that documents exist. That is uncomfortable for teams running quality from shared drives and spreadsheets, where the audit trail has to be reconstructed rather than simply produced.
Ideagen Quality Management brings document control, CAPA, audit, risk and training and competence into one connected system, so the evidence the 2026 edition asks for becomes a by-product of day-to-day work. A controlled change record shows how a change was communicated and reviewed. Risk and opportunity are handled as distinct records. Competence and awareness are tracked against role. Management review inputs are assembled from live data rather than rebuilt by hand each quarter.
If your gap analysis is showing that the constraint is your system rather than your processes, that is a conversation worth having early in the transition, not late.
Explore quality management solutions
Automate and streamline your quality processes, identify opportunities for excellence and achieve compliance with regulations and standards.