Skip to content

Maintained reference

What changed in ISO 9001:2026, ranked by how well it is sourced.

The standard is not published yet, so nobody outside the committee process has read it — including us. What exists is a large volume of published commentary, some of it precise and some of it apparently invented. This page separates the two.

Last verified 27 August 2026

Start here: we have not read the standard

As of 27 August 2026, ISO 9001 sits at stage 60.00 — under publication. It is scheduled for release on 16 September 2026. The Final Draft International Standard can be purchased from some national standards bodies, but it cannot be republished, and it carries an explicit warning that content may still change before publication.

So a page promising you a definitive clause-by-clause comparison of ISO 9001:2015 against ISO 9001:2026 is doing one of two things: working from a paid draft it is not permitted to reproduce, or filling in the gaps. Several of the pages currently ranking for that query are visibly doing the second.

What we can do honestly is assess the claims. When three certification bodies independently cite the same subclause number for the same change, that is meaningful evidence. When one publisher asserts that the revision adds artificial intelligence requirements, and cites no clause and no source, and no other publisher mentions it, and ISO's own page does not mention it — that is meaningfully different. The entire value of this page is the distinction.

The primary source, which nobody links

The 16 September 2026 date is repeated across dozens of commercial pages. In our review, not one of them linked to where it comes from.

It comes from ISO/TC 176/SC 2 — the subcommittee that actually writes ISO 9001 — in a news item dated 7 August 2026, which states that the FDIS “has been approved with overwhelming international support” and that the sixth edition “is scheduled for publication on 16 September 2026.” That item is still the most recent update the subcommittee has published.

Read it yourself. It takes thirty seconds, and it is worth doing with any claim on any page, including this one.

One caveat worth carrying: ISO's own project record still shows only “2026-09” with no day, and the standard has slipped once already — the first committee draft was referred back as not mature enough. A committee schedule is not an accomplished fact.

Tier 1 — corroborated. Plan around these.

Cited with the same subclause number by three or more organisations publishing independently. Where ISO's own material uses similar language, we have said so.

ClauseClaimed changeWho says so
5.1.1 Quality culture and ethical behaviour become explicit expectations on top managementThe most-corroborated change in the whole revision, and the only one ISO's own page names in similar language. Also the hardest to evidence, because culture is demonstrated by a track record rather than a document. DNV, DQS, TÜV SÜD, BSI, SGS — and thematically by ISO itself
6.1.2 / 6.1.3 Risks and opportunities separated into distinct subclausesPractically the most disruptive change for a working system. Most organisations run a single combined risk-and-opportunity register; that needs restructuring into distinct treatments. DNV, DQS, TÜV SÜD — with the same numbering, independently
7.3 Awareness requirements extended to quality culture and ethical conductTouches onboarding and training records, which is cheap to fix and easy for an auditor to sample. DQS, TÜV SÜD, BSI, ANSI's blog
Clause 3 QMS terms carried in the standard itself, reducing reliance on ISO 9000Mostly a usability change. Worth knowing if your documented information cites ISO 9000 definitions by reference. DNV, BSI, SGS, ANSI's blog
Annex A Annex A expanded; Annex B removed and its references folded inAnnex A is informative, not auditable — but it is the context an auditor uses to interpret intent, so it is worth reading first rather than last. ISO's own page, ANSI's blog, TÜV NORD
4.1 / 4.2 Climate change considerations embedded rather than appendedSee the correction below. This is integration of text that has already been in force since the 2024 amendment — not a new requirement arriving in 2026. DNV, DQS, BSI, SGS, and ISO's guidance brochure

Tier 2 — thinly sourced. Watch, do not budget.

Claimed by one or two organisations, or corroborated only loosely. Plausible, not established.

ClauseClaimed changeWho says so
6.3 Change management reinforcedPlausible — ISO 14001:2026 added a change management clause at 6.3 — but the parallel is suggestive rather than evidence. DNV, with a looser echo from SGS and ANSI's blog
5.2.1 e) Quality policy must reflect organisational context and strategic directionSmall if true. A one-paragraph policy revision rather than a project. DQS and SGS
10.1 Continual improvement consolidated from the old 10.1 and 10.3Single-sourced. We are listing it because DNV is among the most accurate publishers on this revision, not because it is confirmed. DNV only, at this level of specificity

Tier 3 — circulating widely, supported by nothing

Each of the following is asserted on at least one published page, sometimes by a large and reputable organisation. None of them carries a clause number anywhere we could find. None appears in any of the clause-level accounts. None appears on ISO's own ISO 9001:2026 page or in its guidance brochure.

  • New requirements on artificial intelligence, digital transformation or “digital systems”
  • Cybersecurity or data-integrity requirements, including in internal audit scope
  • Supply chain resilience or supply chain oversight requirements
  • ESG or sustainability requirements beyond the existing climate amendment
  • Organisational resilience as a new requirement
  • Expanded stakeholder engagement requirements

We think we know where these came from. ISO 9001 went through its committee draft stage in 2023 and 2024, when a great deal of speculative commentary was written about what the revision might contain. Much of that commentary was never revisited after the draft matured. It is still ranking.

The practical risk is not that you will be surprised at your audit. It is that you will spend money now on requirements that do not exist. A cybersecurity workstream added to your quality management system because a blog said ISO 9001:2026 would require one is a real cost incurred against an imaginary obligation.

Two specific errors worth knowing about

Both of these appear on the page of a major certification body. We are naming the claims rather than making a general complaint, because a claim you can check is more useful than a warning you cannot.

Claim: the 2026 edition gives ISO 9001 an annex of supplementary guidance for the first time.

Checkable, and incorrect. ISO 9001:2015 already contains an Annex A, clarifying the new structure, terminology and concepts, and an Annex B listing other ISO standards on quality management. What is reported for 2026 is that Annex A is expanded and Annex B is removed, with its references folded into Annex A and onto the TC 176 website. That is a real change. It is not a first annex.

Claim: climate change and sustainability are now explicitly part of ISO 9001, as of the 2026 edition.

Misleading on timing. Climate change considerations entered ISO 9001 through the 2024 amendment, which added text at clauses 4.1 and 4.2 and has been in force since February 2024. If your management system is current, you have already dealt with this. What the 2026 edition reportedly does is embed that text rather than carry it as an amendment. Presenting it as a new 2026 requirement invites organisations to redo work they finished two years ago.

To be fair to the bodies concerned: both publish a great deal of accurate material, and both are doing something genuinely difficult — writing about a standard before it exists. We have made and published our own corrections on this site, including retracting a change list we had wrongly attributed to ISO. The point is not that anyone is careless. It is that on this topic, right now, you should check.

The deadline claim, and why we will not repeat it

Across the certification body pages we reviewed, most state or imply a three-year transition ending around September 2029. The wording varies — “expected,” “anticipated,” “likely,” “typically” — and in several cases no source is offered at all. One body, DNV, is explicit that its source is a draft Global ACI document and that no final official source exists. That is the honest version, and it is rare.

Here is what is actually published. Global ACI, which replaced IAF and ILAC on 1 January 2026 and is the body that sets transition periods for accredited certification, lists in its own General Assembly resolutions the inherited documents it will continue to develop. One entry reads:

IAF MD XX Transition Requirements for ISO 9001

The XX is unallocated. The document has not been issued. We checked the 2026 resolutions and the 2026 news feed as well, in case a number had been assigned since — it has not.

Three years is a reasonable expectation, because three years is the pattern. It is not a published date, and we are not going to print it as one. Our transition tracker carries the full evidence chain and will change the day that changes.

What to do with this before 16 September

Two things, and neither of them depends on the final text saying what anyone expects.

Start the slow work. The two most-corroborated changes — leadership and quality culture evidence, and separating risks from opportunities — are also the two that cannot be done quickly. Culture is demonstrated by a record of decisions over time: what got recorded when quality and schedule conflicted, how a concern raised on the floor was closed out, what leadership actually did rather than what the policy says. You cannot generate twelve months of that in the month before an audit. Splitting a combined risk-and-opportunity register is a smaller job, but it is far easier done calmly than in a queue behind everyone else.

Ignore Tier 3 until something supports it. If a proposal on your desk adds an artificial intelligence or cybersecurity workstream to your quality management system on the strength of the ISO 9001 revision, ask which clause. If nobody can name one, the answer is not yet.

That is the whole of our advice, and you will notice it does not require hiring anyone. If you do want help with the transition itself, that is a separate page — deliberately, so this one can stay a reference.

Common questions

Have you read ISO 9001:2026?

No, and neither has almost anyone publishing about it. The standard is not published — as of 27 August 2026 it sits at ISO stage 60.00, under publication. The Final Draft International Standard can be bought from some national standards bodies, but it cannot be republished, and it carries the warning that content may still change before publication. So this page does not tell you what the standard says. It tells you what the organisations publishing about it claim, and how well each claim is supported. That is a different thing, and right now it is the more useful one.

Why does the tiering matter? Aren't certification bodies reliable?

The good ones are, and DNV, DQS and TÜV SÜD have published carefully here — real subclause numbers, correct attribution, honest hedging. But across the wider set of published pages there is a second group of claims with no clause number attached and no corroboration anywhere: artificial intelligence requirements, cybersecurity in internal audit scope, supply chain resilience, ESG. None of that appears in any clause-level account, and none of it appears on ISO's own page. It reads like commentary written at the committee-draft stage in 2023 and never revisited. If you build a transition plan around it you will spend money on requirements that may not exist.

So what should we actually plan around?

The Tier 1 list. Quality culture and ethical behaviour as leadership expectations, the separation of risks from opportunities, extended awareness requirements, and the climate text being embedded rather than appended. Those are cited by three or more bodies independently, with matching clause numbers, and the two that matter most — leadership evidence and the risk register split — are also the two that take longest to do properly. Neither can be produced in the month before an audit.

When is the transition deadline?

There isn't one, and this is the claim where the gap between what is published and what is repeated is widest. Nearly every certification body page states or implies a three-year window ending around September 2029. Not one of them cites a source that exists — DNV is the only body honest enough to say its source is a draft. Global ACI, which is the body that actually sets transition periods, still lists the relevant document in its own resolutions as “IAF MD XX.” The XX is unallocated. We track this in detail on our transition tracker.

How long after publication will the deadline appear?

The best available evidence is the sister standard. ISO 14001:2026 published on 15 April 2026. Six weeks later, in a technical bulletin dated 22 May 2026, UKAS was still referring to the “anticipated” publication of the Global ACI mandatory document for that transition — while setting its own deadline for certification bodies. So even for a standard already on the shelf, the accreditation-level document had not appeared after six weeks. Expect the same pattern for ISO 9001: publication on 16 September, and a wait after that.

Should we wait for publication before starting?

It depends what you would be starting. If you are not yet certified, no — you certify to ISO 9001:2015 now and transition later, because certification bodies cannot issue accredited certificates to a new edition until their own accreditation is extended. If you already hold a certificate, the work worth doing now is the work that is slow regardless of what the final text says: building demonstrable leadership and quality culture evidence, and separating your risk and opportunity treatments. Both appear in the corroborated tier, and both need a track record rather than a document.

Will you update this page when the standard publishes?

Yes, and the changelog at the bottom will record what changed and when. Publication is scheduled for 16 September 2026. When the text is available we will move claims between tiers based on what it actually says, including — quite possibly — recording that something we listed as corroborated turned out to be wrong. We have published corrections on this site before and dated them.

Changelog

  • 2026-08-27 Page published. Based on a review of the public ISO 9001:2026 pages of nine certification bodies, ISO's own iso.org/9001-2026 page and guidance brochure, ISO/TC 176/SC 2 news, Global ACI resolutions, and ANAB and UKAS bulletins, all read on 27 August 2026. ISO 9001 confirmed still at stage 60.00 — not published.

We maintain this page. When ISO 9001:2026 publishes we will move claims between tiers based on what the text actually says — including recording anything we got wrong. If you spot an error before we do, tell us and we will correct it and date it.

Sources