ISO 9001:2026 is published. Sixth edition, dated 2026-09, and its foreword leaves no room for interpretation: “This sixth edition cancels and replaces the fifth edition (ISO 9001:2015), which has been technically revised. It also incorporates the Amendment ISO 9001:2015/Amd 1:2024.” In other words, the 2015 edition is superseded and the 2024 climate amendment is absorbed into the body of the text.
What follows is read in the published edition, clause by clause, and compared with the official French edition of 2015. One point of method, because it governs what can be asserted: we read the 2026 edition in English and the 2015 edition in French. Structure compares without risk, since the number of sub-points in a list or the existence of a clause does not depend on the language. The shade of meaning carried by a verb does not compare from one language to the other: a difference may come from the translation rather than from the revision. You will therefore find no assertion here of the kind “the standard replaced this verb with that one”.
The six changes the standard declares itself
There is no need to guess: the foreword carries its own list of the main changes, and that list has six points. It is the only authoritative list, and it is the one a certification body will read.
- Terms and definitions enter clause 3. Clause 3 now carries a limited number of terms and definitions, ISO 9000 remaining the normative reference for the whole vocabulary of quality.
- Quality culture and ethical behaviour enter the requirements, particularly around leadership, awareness and the environment in which processes are operated.
- Risks and opportunities are separated, with actions considered distinctly for each of them.
- The management of changes is reinforced.
- Annex A is expanded, to clarify the structure, the terminology and the intent of the requirements, as informative text and without creating any additional requirement.
- Annex B is removed. It listed the other standards of ISO/TC 176; those cross-references now live in Annex A and on the committee's website.
What this list does not say, and what costs the most in an audit, is the renumbering. It does not appear among the six points because it is not a change of substance; it is nonetheless what breaks the documents already in place.
Clause 10 loses a sub-clause, and that is the costliest trap
In 2015, clause 10 had three sub-clauses: 10.1 General, 10.2 Nonconformity and corrective action, 10.3 Continual improvement. In 2026 it has two: 10.1 Continual improvement and 10.2 Nonconformity and corrective action. Clause 10.3 no longer exists.
The detail that makes the difference: the number 10.1 is kept and it designates something else. In 2015, clause 10.1 opened on “The organization shall determine and select opportunities for improvement” (our translation of the official French edition). In 2026, clause 10.1 opens on what used to be the first sentence of 10.3: “The organization shall continually improve the suitability, adequacy and effectiveness of the quality management system.” A number that is kept while designating other content is the worst possible case, because nothing on the screen signals it.
The list of actions has moved as well. Where 2015 called for the improvement of products and services, the correction of undesired effects and the improvement of the performance of the system, 2026 calls for “improving processes, products and services”, then “addressing future needs and expectations” as a point in its own right, then “correcting, preventing or reducing undesired effects”. Processes enter the scope of improvement explicitly.
The practical consequences are immediate. A gap analysis calibrated on the 2015 numbering no longer lines up. An audit finding written as a nonconformity with clause 10.3 targets a clause that does not exist, which is the first reflex of an auditor used to 2015. And a correspondence matrix between standards, the most fragile document in an integrated system, is corrected cell by cell: ISO 45001:2018 does keep its clause 10.3, so a global substitution would break the column where it remains correct.
Quality culture: two requirements, and one note not to confuse with them
This is the most commented change, and the one where confusion will cost the most. The published text places it in three locations, and one of those three cannot be held against anyone.
Two requirements. Clause 5.1.1 requires top management to demonstrate leadership, and its sub-point i) is new: “promoting quality culture and ethical behaviour”. That list grows in passing from ten sub-points in 2015 to twelve in 2026, and the count is exact: quality culture adds one, and the single 2015 sub-point that required promoting “the use of the process approach and of the risk-based approach” (our translation of the official French edition) splits in two, opportunity-based thinking joining risk-based thinking along the way. Clause 7.3, on awareness, adds a sub-point e) of its own: persons are to be made aware of “the organizational quality culture and ethical behaviour”.
One note. At clause 7.1.4, on the environment for the operation of processes, the requirement is unchanged: determine, provide and maintain the environment that is needed. Quality culture appears only in the NOTE, whose last sentence says that some factors can be influenced by the organization's quality culture and ethical behaviour. A note is not a requirement. An auditor who raises a nonconformity at 7.1.4 for want of a quality culture is citing a note, and the finding does not stand.
That leaves the question everyone asks: how does one audit a culture? The standard gives an indication, and it is also a note. NOTE 2 to clause 5.1.1 says that the quality culture and ethical behaviour of an organization “are reflected in its shared values, attitudes, practices and actions”. Observable practices and acts are therefore what carries the evidence, not a poster or a signed charter. Annex A points here to ISO 10010, devoted to the evaluation and the improvement of quality culture.
Risks and opportunities: one clause becomes three, and the yardstick changes
In 2015, clause 6.1 had two sub-clauses and dealt with risks and opportunities together: clause 6.1.2 planned “the actions to address risks and opportunities” (our translation of the official French edition) in a single movement. In 2026 there are three of them: 6.1.1 determines risks and opportunities, 6.1.2 addresses risks, 6.1.3 addresses opportunities. Annex A puts it plainly: “Risks and opportunities are distinct; they can be determined and addressed through separate processes.”
The separation is not cosmetic, because the two clauses do not carry the same yardstick of proportionality. This is the point the summaries leave out, and it is established by comparing the two texts.
- In 2015, the actions had to be “proportionate to the potential impact on the conformity of products and services” (our translation of the official French edition).
- In 2026, the actions addressing risks are to be “proportionate to the potential impact of the risks on the intended results of the quality management system”. The yardstick is no longer the conformity of the product but the intended results of the system, which is broader.
- In 2026, the actions addressing opportunities are to be “appropriate to the organization's context and support the achievement of desired results”. Another yardstick, which the 2015 edition did not set apart.
Two details are useful in an audit. NOTE 1 to 6.1.2 now mentions the risks attached to the ability to supply conforming products “during and after a disruption”: business continuity enters the field of quality risks. And Annex A defines a new notion, “disruptive occurrences”, as the incidents that adversely affect the planned provision of products and services.
Above all, Annex A carries the sentence that spares many organizations pointless work: “The application of risk-based thinking does not imply the use of formal risk management approaches or a documented risk management process.” No documented risk management process is required, and an auditor who demands one has left the text. The annex points to ISO 31000 for anyone who wants to go further, and that pointer remains a pointer.
Planning of changes goes from four points to seven
Clause 6.3 already existed in 2015, with four points to be taken into account: the purpose of the changes and their potential consequences, the integrity of the system, the availability of resources, the allocation of responsibilities and authorities. In 2026 it has seven. The three new ones all bear on what comes afterwards:
- the communication of the changes;
- how the effectiveness of the changes will be monitored and evaluated;
- how the results of the changes will be reviewed.
That is the sense of the fourth point of the foreword, the reinforced management of changes. The clause still requires no documented process; Annex A merely observes that the planning approach can vary with the reason for the change, its complexity and the significance of its effects, and it points to ISO/TS 10020 for organizational change management.
One point of vocabulary counts here, and Annex A settles it itself: the verb of clause 6.3 is “consider”, which the annex explicitly distinguishes from “take into account”. To consider is to think about the subject in order to determine whether it will enter the decisions; to take into account is to think about it and include it. The seven points are therefore to be considered, and an auditor cannot require that all seven be implemented.
Annex A: the part nobody reads, and the one that settles disputes
It is informative, and the annex says so itself: this information “does not add to, subtract from or in any way modify” the requirements. It creates nothing, then. What it does is explain what the words mean, and it is precisely on those words that audit disagreements have turned for ten years. Six clarifications are worth the detour.
- “Appropriate” and “applicable” are not interchangeable. Appropriate means suitable for the context of the organization and implies judgement; applicable means that where the requirement is judged relevant or possible, it applies.
- “Consider” is not “take into account”. See clause 6.3 above: the difference separates an act of reflection from an obligation to include.
- “Continual” is not “continuous”. The annex states that the word “continuous” does not appear in the document and that this confusion is a common source of error. Improvement is continual, therefore in periods with interruptions, and not continuous.
- “Ensure” designates a responsibility for the result, not an obligation to carry out every related activity oneself. The actions can be delegated to persons under the control of the organization. Enough to close many discussions about outsourcing.
- Two documentation formulas that look alike and do not say the same thing. “Shall be available as documented information” bears on the availability of the information; “documented information shall be available as evidence of” bears on the retention of objective evidence. The annex adds that “as evidence of” implies no requirement for proof in the legal sense.
- The order of the sub-points means nothing. This is the most useful paragraph of the annex: the numbering of lists serves only for identification and citation, the order indicates neither sequence, nor priority, nor relative importance unless expressly stated, and all the points apply as written whatever their position. In other words, an auditor who reads a) b) c) as a chronological sequence is mistaken. And the reorganization of the sub-points of clause 6.1.1 between 2015 and 2026 therefore carries no message at all.
A last contribution from the annex, often useful at the first certification audit: clause A.3 frames the not applicable. A requirement can be declared not applicable only where doing so affects neither the ability to ensure the conformity of products and services, nor the enhancement of customer satisfaction, nor compliance with legal and regulatory obligations. And that status means the organization has examined the requirement and determined, with justification, that it does not apply. A box ticked NA with no written reason is therefore not enough.
Three changes of wording that change the audit
Organizational knowledge (7.1.6) is now to be applied and shared. The 2015 edition required this knowledge to be “maintained and made available to the extent necessary” (our translation of the official French edition). The 2026 edition requires it to be “retained, applied and shared to the extent necessary”. Holding it and making it available no longer suffices on the letter of the text: knowledge deposited in a shared space that nobody opens ticks the first condition and not the other two. The NOTE also lists the forms this knowledge takes, among them the knowledge held by persons and the knowledge embedded in methods, processes and products.
Customer satisfaction (9.1.2) is monitored directly. In 2015, the organization had to monitor “the perception of customers of the degree to which their needs and expectations have been fulfilled” (our translation of the official French edition). In 2026, the clause opens on “The organization shall monitor customer satisfaction”. The object of the monitoring is no longer the perception but satisfaction itself. What does not change, and what remains the nonconformity most often raised in error: no survey is required. The organization determines the methods, and the NOTE lists the possible sources, which now include social media alongside warranty claims and dealer reports.
The management review clause is now titled “Management review results” (9.3.3). The title changes, the 2015 list of three points becomes a single sentence, and the documentation formula moves from “retain documented information as evidence” (our translation of the official French edition) to “documented information shall be available as evidence of”. Yet Annex A has just told us that this second formula designates retention. The obligation is therefore the same; only the wording has changed. Saying so avoids reopening a documentation project for nothing.
What the standard says about technologies, and it is entirely new
No requirement mentions artificial intelligence or automation. Annex A, on the other hand, speaks of technologies in four places, and that is where the intent of the committee for the years ahead can be read.
- On roles and responsibilities, where technologies support the management of the system, confidence in its integrity rests on two things: the availability of reliable information on which the decisions are based, and the clarity of responsibilities and authorities for those decisions.
- On persons, where technologies assist them in relevant roles, this can create risks and opportunities for the system. The annex points here to ISO 30201, the human resources management system standard, which we have presented separately.
- On communication, it can take place between persons or “through automated interactions between devices”.
- On infrastructure, hybrid working, remote working and emerging technologies can introduce risks and opportunities.
None of this can be held against anyone, since the annex is informative. But it indicates where an auditor trained on the 2026 edition will put the questions, and what the next revision is liable to turn into a requirement.
What is not yet known, and must not be invented
The question that comes immediately after “the standard is published” is “how long do we have to move to it”. The honest answer is that no transition period has been published to date. The period is a matter for the accreditation body, and the timetable is confirmed with one's certification body, not with an article. Be wary in particular of the 2029 deadlines in circulation: they come from a draft put out for consultation, and a draft is not a decision. We keep the point up to date in our watch on the revisions under way.
A second reservation, which comes from our sources. The passages quoted from the 2026 edition are verbatim, because we read that edition in English. The 2015 passages are another matter: we read the 2015 edition in French, in the official ISO 9001:2015(F) version, and every quotation attributed to it here is our own translation, flagged as such at each occurrence. For the wording of a finding written against the 2015 text, the official English edition remains the reference.
Finally, for anyone wondering how an edition comes to be published with a different numbering, we have set out elsewhere the mechanics by which an ISO standard is revised, its two ballots and their thresholds.
Where to start, in practice
Three steps, in this order, and none of them calls for waiting on a transition date.
- Take the numbering before the content. Every document that cites a clause by its number is to be reread: procedures, audit grids, correspondence matrices, report templates. It is mechanical, it is quick, and it is what produces the most false findings when it is forgotten.
- Deal with the four genuine changes of substance: quality culture at 5.1.1 and 7.3, the separation of risks and opportunities at 6.1.1 to 6.1.3 with their two yardsticks, the three points added at 6.3, and knowledge applied and shared at 7.1.6.
- Check on the ground before the auditor does. A mock audit run on the 2026 numbering reveals in a day the documents still set on 2015. One finding comes back almost every time and is prepared on its own: the control of measuring equipment, which Annex A of the 2026 edition points to ISO 10012 for, and which our ISO 10012 grid covers.
The self-assessment grid below has already been rebuilt on the 2026 edition: 33 requirements, clause 6.1 cut in three, knowledge set apart, and clause 10 brought down to two requirements since clause 10.3 no longer exists.
Sources
- ISO 9001:2026, Quality management systems, Requirements. Sixth edition, 2026-09. Foreword, clauses 4 to 10 and Annex A (informative). See the ISO 9001:2026 catalogue page on iso.org.
- ISO 9001:2015(F), fifth edition, corrected version 2015-09-15, the official French edition, for all the comparisons with the superseded edition.
This article quotes the published text and does not replace it. The classification of a gap as a minor or a major nonconformity is a matter for ISO/IEC 17021 and for the certification body. HEMC prepares and attests; the certification audit is conducted by an accredited body.
