ISO 9001:2026 is here: what actually changes, and what to do about it
ISO 9001, the world's most widely adopted management system standard, has received its first major revision in over a decade. ISO published the sixth edition on 16 September 2026, after the FDIS was approved in August with overwhelming international support.
If you hold ISO 9001, the clock on your transition has started. And if you hold ISO 27001, ISO 27701 or ISO 42001, the changes tell you where all of them are heading, because every other ISO management standard borrows ISO 9001's skeleton.
What stays the same
The core is untouched: the process approach, risk-based thinking and the Plan-Do-Check-Act cycle. If your QMS works today, it did not stop working on publication day. This is a sharpening, not a rebuild.
What actually changes
Five areas are strengthened in the 2026 edition. First, quality culture: leadership must now visibly foster it rather than assume it exists. Second, ethical behaviour is named explicitly for the first time. Third, the treatment of risks and opportunities is clearer and less ambiguous. Fourth, organisations must consider whether climate change is relevant to the QMS. Fifth, the standard is finally drafted for digital-first operations.
The transition window
Certified organisations have a three-year transition period, running to roughly September 2029. Certification bodies are publishing their arrangements over the coming months.
Our advice, from both sides of the audit table
Do not rush a transition audit in year one, but do run a gap review early. The culture and ethics elements need real evidence, and evidence takes time to accumulate. A fixed-scope gap review now gives you a prioritised plan and two full years to build the record your auditor will want to see.
There is a wider opportunity here too. ISO 9001 shares its harmonised structure with ISO 27001 (information security), ISO 27701 (privacy) and ISO 42001 (AI governance). Organisations that treat the 2026 transition as the moment to integrate their management systems, with one set of evidence and one audit programme, come out the other side with lower compliance costs, not higher ones.
Cybercontrols implements and audits ISO 9001 alongside ISO 27001, ISO 27701 and ISO 42001, and we hold ISO 27001 and ISO 42001 certification ourselves. If you would like a transition gap review, or simply a candid conversation about what the 2026 edition means for your organisation, get in touch.
