Transition guide
ISO 9001:2026: what changes, and what to do about it
The revision publishes on 16 September 2026. If you hold a certificate, nothing happens to it that day. If you are certifying for the first time, the decision is slightly more interesting. Here is the whole picture, without the consultancy upsell.
The short version
- The structure does not change. Clauses 4 to 10 stay exactly where they are. Nothing is renumbered except clause 6.1, which gains sub-clauses.
- Your certificate stays valid. You transition at a normal surveillance or recertification audit, not on publication day.
- The climate change requirement already applies to you today. It arrived with Amendment 1:2024 in February 2024, not with the 2026 revision. This is the one most small companies have missed.
- The real work is small but specific: a handful of additions around culture, ethics, opportunities and digital controls.
The thing to deal with first, and it isn’t 2026
ISO 9001:2015/Amd 1:2024 was published in February 2024 and added climate change to clauses 4.1 and 4.2. It is in force now. It needed no transition programme, it did not affect anyone’s certificate, and precisely because it arrived so quietly, a large number of small companies have never addressed it.
What it asks is modest: determine whether climate change is a relevant issue for your organization, and consider whether the people with a stake in your quality have climate-related requirements of you. Concluding that it is not relevant is a legitimate answer. Having never asked the question is not.
For a machine shop this might be as simple as recording that two customers now ask about emissions in their supplier questionnaires, that summer heat affects the measuring room, and that neither currently threatens conforming output. That is a defensible determination. A blank page is a finding.
The timeline, and how much of it is actually known
Only the publication date is confirmed. Everything after it is set by the International Accreditation Forum, which has not yet issued its resolution for this revision. What follows is the 2015 transition’s timetable projected forward, which is the best evidence available — and better than the round numbers most guidance quotes.
- 16 September 2026ISO 9001:2026 published. Nothing happens to existing certificates.Confirmed
- Around September 2027Most certification bodies accredited to audit the new edition. Before this, certifying to 2015 is usually the only option available.Projected
- Around September 2028Expected cut-off for new certifications against ISO 9001:2015, based on the two-year point in the 2015 revision.Projected
- Around March 2029Expected point at which all audits must be conducted against the 2026 edition.Projected
- Around September 2029Expected expiry of remaining ISO 9001:2015 certificates.Projected
What happened with the 2015 revision
The 2008-to-2015 transition is the only hard evidence for how this one will run. It went like this:
- 15 September 2015 — ISO 9001:2015 published.
- 15 September 2017 — Certification bodies stopped accepting new applications against ISO 9001:2008 — two years after publication.
- 15 March 2018 — All initial, surveillance and recertification audits had to be conducted against the 2015 edition — two and a half years after publication.
- 15 September 2018 — All remaining ISO 9001:2008 certificates expired — three years after publication.
Certification bodies have to be accredited to audit against the new edition before they can issue a certificate to it, which typically takes 9 to 12 months after publication. For roughly the first year, most bodies will still be training auditors — so certifying to ISO 9001:2015 remains the normal path well into 2027.
What actually changes in 2026
Clause by clause, in plain language, with what an already-certified company should do about each one.
Understanding the organization and its context
expandedThe climate-change consideration added by Amendment 1:2024 is written into the body of the 2026 text, and sits alongside a broader expectation that sustainability forms part of your context.
What to do: Nothing new if you already handled Amendment 1:2024 — this is the same requirement in a tidier place. If you have not yet recorded a climate-relevance determination, do that now; it is already auditable under the 2015 edition.
Needs and expectations of interested parties
clarifiedThe 2026 text carries the Amendment 1:2024 note about interested parties having climate-related requirements directly in the clause.
What to do: No practical change where Amendment 1:2024 has already been addressed.
Leadership and commitment
expandedLeaders are explicitly required to promote and demonstrate a quality culture and ethical behaviour — setting an example rather than only allocating resources. Auditors will look for evidence of how leadership behaves when quality and commercial pressure pull in opposite directions.
What to do: Think about what you could show an auditor: a decision where you took the quality-led option at a cost, how concerns get raised without blame, how that expectation is communicated. Most well-run companies already do this and simply do not record it.
Establishing the quality policy
expandedThe policy is expected to sit alongside your strategic direction, not just your purpose and context — a tighter link between what you tell customers about quality and where the business is actually going.
What to do: Re-read your policy next to your business plan. If it could belong to any company in your sector, it needs work.
Actions to address risks and opportunities
restructuredIn the 2026 edition this single clause becomes three: 6.1.1 general, 6.1.2 actions to address risks, and 6.1.3 actions to pursue opportunities. Risks and opportunities stop being treated as one exercise.
What to do: If your register lumps risks and opportunities into one list, split it. Most companies find they have plenty of risks recorded and almost no opportunities, which is exactly what the change is aimed at.
Environment for the operation of processes
expandedThe social and psychological side of the working environment is given more weight, sitting alongside the physical conditions rather than trailing behind them.
What to do: Be able to explain how you would know if pressure or workload were driving mistakes, and what you would do about it. Rushed jobs bypassing checks is the classic example an auditor will probe.
Organizational knowledge
expandedMore emphasis on actively maintaining and checking that knowledge is still correct, rather than collecting it once — with the reality of part-remote teams and increasing automation in mind.
What to do: Check whether your captured know-how still matches how the job is done. Setup sheets that describe a machine you replaced two years ago are worse than none.
Awareness
expandedAwareness now extends to the organization's quality culture and expected ethical behaviour — people should understand what is expected of them when they spot a problem, including that they can stop work or escalate rather than push it through.
What to do: Add it to your induction and toolbox talks, and make sure the message is genuine. An auditor asking an operator 'what happens here if you find a defect on a Friday afternoon with a shipment due?' is testing exactly this.
Control of documented information
expandedThe clause is written with digital document control in mind — change history, access control and the resilience of the systems holding your records.
What to do: If your documents live on a shared drive, be able to show how you know which version is current and who changed what. A folder called 'Quality FINAL v3 (2)' is the failure mode this is aimed at.
Control of production and service provision
expandedWhere automated or algorithmic tools make quality-critical decisions — automated inspection, pass/fail vision systems, predictive tooling — those tools themselves are expected to be controlled: validated before use, and re-checked when the software or model behind them changes.
What to do: Only relevant if software decides whether something passes. If it does, treat an update to that software the way you would treat a change to a gauge: record it, and confirm the results are still right afterwards.
Analysis and evaluation
clarifiedMore emphasis on actually using the data to spot trends and drive decisions, rather than reporting numbers that nobody acts on.
What to do: Show a decision you made because of what the numbers said. That is what the clause has always been for.
Continual improvement
expandedLeadership's role in driving improvement is made explicit — improvement is expected to be led, not left to emerge from corrective actions.
What to do: Make sure improvement appears as its own item at management review, with named owners, rather than only showing up as a list of closed CAPAs.
Genuinely new sub-clauses
Risks and opportunities — general
Using your context and interested-parties work, determine both the risks that could stop the quality system achieving its intended results and the opportunities that could improve it. Plan proportionate actions for each, integrate those actions into how your processes actually run, and evaluate afterwards whether they worked.
Actions to address risks
Deal with the things that could go wrong. For each significant risk, decide and record how you are handling it — avoiding it, removing the source, changing how likely it is or how bad it would be, sharing it (for example by insurance or contract), or consciously accepting it. Consciously accepting a risk is a legitimate answer; not having thought about it is not. A formal risk methodology such as ISO 31000 is not required, and for a small company should not be assumed necessary.
Actions to pursue opportunities
Actively look for ways the quality system could make the business better, and act on them — new practices, new products or services, new customers or markets, new partnerships, better technology. Opportunities are now expected to be tracked in their own right, connected to your objectives and picked up at management review when resources are allocated, rather than being an afterthought bolted onto the risk register.
What stays exactly the same
Worth stating plainly, because revision anxiety sells a lot of unnecessary consultancy. Every one of these sections keeps its number and its intent:
Clause 4 Context of the organization
Understand the business you are actually in, who depends on your quality, and what your quality system covers.
Clause 5 Leadership
Top management has to visibly own the quality system — not delegate it entirely to one quality person.
Clause 6 Planning
Think ahead about what could go wrong, set concrete quality goals, and plan changes rather than improvising them.
Clause 7 Support
The resources, people, skills, communication and paperwork control that let the system actually run.
Clause 8 Operation
How you actually take an order, plan the work, buy what you need, make and check the product, and handle it when something is wrong.
Clause 9 Performance evaluation
Measure whether the system is working, audit yourself honestly, and have management formally review the results.
Clause 10 Improvement
Fix problems at the root so they don't come back, and keep making the system better over time.
The order to do it in
- 1
Record your climate-change determination
This is already auditable. Half a page at your next management review covers it.
- 2
Split risks and opportunities
If they live in one list, separate them. You will probably find the opportunities column is empty — that is exactly what the revision is aimed at.
- 3
Write down what you already believe about quality culture
Who can stop a job, what happens when a deadline and a defect collide, how someone raises a concern. Most small companies have a clear culture and no record of it.
- 4
Add culture and ethics to your induction
One paragraph and one toolbox talk. Clause 7.3 awareness is tested by asking your staff, not by reading your file.
- 5
Check anything where software decides pass or fail
If it does, treat a software update the way you treat a gauge going out of calibration: record it and confirm results are still right.
- 6
Book the transition into a normal audit
Talk to your certification body about which surveillance visit will cover it. There is no benefit in doing it as a standalone exercise.
Questions people actually ask
When does ISO 9001:2026 come out?+
16 September 2026. The Final Draft International Standard ballot is complete and the technical content is settled, so work you do against the FDIS now stays valid at publication.
Does my ISO 9001:2015 certificate become invalid in September 2026?+
No. Certification to ISO 9001:2015 remains valid throughout the transition period. Existing certificates do not become invalid on the publication date. You transition at a normal surveillance or recertification audit during the transition period rather than doing anything special on publication day.
How long do I have to transition?+
Three years is what certification bodies currently anticipate, which would put the deadline at September 2029. The three-year transition period is the length ISO has used for recent management-system revisions and is what certification bodies currently anticipate. The binding rules — when new certifications to the old edition stop, when audits must switch over, and when old certificates expire — are set by the International Accreditation Forum, and no IAF resolution for the 2026 edition has been published yet. Treat every date after publication as expected rather than fixed, and confirm with your own certification body.
Is this a big change or a small one?+
Small, structurally. The clause structure — 4 through 10 — is unchanged, there is no renumbering of the familiar sections, and the process approach works exactly as before. Certification bodies are describing it as evolutionary rather than revolutionary. The work is in a handful of specific additions, not in rebuilding your system.
We are getting certified for the first time in the next few months. Should we go for 2015 or 2026?+
Almost certainly 2015, and not because it is the safe choice — because it is likely the only one on offer. Certification bodies have to be accredited to audit against the new edition before they can issue a certificate to it, which typically takes 9 to 12 months after publication. For roughly the first year, most bodies will still be training auditors — so certifying to ISO 9001:2015 remains the normal path well into 2027. Certify to 2015 now, build the 2026 additions in as you go (they are small), and transition at a later surveillance audit. Ask your certification body what they can actually offer and when; it varies between bodies.
Can I still get certified to ISO 9001:2015 after September 2026?+
Yes, for a while. Last time round, the equivalent cut-off came two years after publication: ISO 9001:2015 published in September 2015, and certification bodies stopped accepting new applications against ISO 9001:2008 in September 2017. If the same pattern holds, new certifications against the 2015 edition would run until around September 2028. That is a projection from precedent, not a published rule — the IAF has not issued the 2026 resolution yet.
When do audits have to switch to the new edition?+
In the 2015 transition, all initial, surveillance and recertification audits had to be conducted against the new edition from March 2018 — two and a half years after publication, six months before old certificates expired. The equivalent point for this revision would be around March 2029. Again: precedent, not a published rule.
Should we just skip 2015 and go straight to 2026?+
Only if your certification body can actually audit you to it, which for most bodies will not be true until well into 2027. Certification bodies have to be accredited against the new edition before they can issue a certificate to it, and that accreditation typically takes 9 to 12 months after publication. Waiting for that means waiting a year to get certified — which is usually a worse outcome than certifying now and transitioning later at a routine audit.
Do I need to buy the new standard?+
If you are maintaining the system yourself, yes — eventually. You cannot audit yourself properly against a document you have not read, and the text is only available from ISO or your national standards body. Note that ISO's licence is single-user: you cannot put the PDF on a shared drive for the team, which catches out a lot of small companies.
What is the climate change requirement, and does it apply already?+
It applies already — this is the most commonly missed point. ISO 9001:2015/Amd 1:2024 (climate action) was published on 23 February 2024 and applies now. The IAF confirmed no separate transition programme is needed for it, and it does not affect the validity of an existing certificate. It adds one sentence to clause 4.1 requiring the organization to determine whether climate change is a relevant issue, and a note to 4.2 that interested parties can have climate-related requirements. Clause 4.1 requires you to determine whether climate change is a relevant issue for your organization, and 4.2 asks whether interested parties have climate-related requirements of you. Deciding it is not relevant is a perfectly acceptable answer, but you need a recorded reason for that decision. Silence is the finding, not the conclusion.
What does 'quality culture and ethical behaviour' actually mean in practice?+
It means an auditor can ask your staff what happens when quality and a deadline conflict, and expects a consistent answer. In a small company this is usually already true in practice and simply not written down anywhere. The practical work is making the expectation explicit — in your induction, your toolbox talks, and in how leadership demonstrably behaves when it costs something.
Why are risks and opportunities being split up?+
Because in practice almost everyone filled in the risk half and left the opportunity half blank. Splitting 6.1 into 6.1.2 for risks and 6.1.3 for opportunities forces opportunities to be identified, resourced or consciously declined, and reviewed — rather than being a column nobody completes.
Does ISO 9001 require a management representative?+
No — and it has not since the 2015 edition, which removed the requirement that was in clause 5.5.2 of ISO 9001:2008. What clause 5.3 requires is that specific responsibilities and authorities are assigned to named people and communicated. Many companies still use the job title, and some customers still ask for one by name, but the standard itself does not require the role to exist.
Can we use AI to write our quality documents?+
Yes, as a drafting tool. The consensus among practising auditors is that AI-drafted documentation is acceptable where a competent person reviews, edits and formally approves it — and that AI as the final author with no human review would be a serious finding. Clause 7.5.2 still requires review and approval before use, regardless of how the draft was produced. Keep the records that show the review happened, and expect to be asked about it: AI use is becoming a routine audit question.
What is Annex A?+
A new informative annex — around fifteen pages of guidance on how to interpret the requirements, including risk-based and opportunity-based thinking and how much formality is proportionate for your size. Informative means it is guidance, not requirements you are audited against. It is genuinely useful if you have ever wondered whether you are over-engineering your system.
See where you stand against both editions
Cornerstone9 assesses your business clause by clause against ISO 9001:2015 and flags the 2026 additions alongside, so you can see your position today and what the revision will ask of you. The readiness report is free.
Check where you standThis guide describes the revision in our own words. It does not reproduce the text of ISO 9001, which is copyrighted and available from ISO or your national standards body. Transition arrangements are confirmed by the International Accreditation Forum and the accreditation bodies at or around publication — check with your own certification body before planning around a specific date.
Cornerstone9 helps you prepare for certification but cannot guarantee an audit outcome, which is determined by an independent certification body auditor.