ISO 9001:2026 transition key changes and FAQs
2026.09.22
ISO 9001:2026 has been officially published. Is your organization ready for the transition?
To suport organizations understand the new requirements and transition arrangements, SGS technical experts have compiled answers to the most frequently asked questions from clients, providing practical guidance and insights for a successful transition.
Q1. What are the key differences between ISO 9001:2026 and ISO 9001:2015?
ISO 9001:2026 does not replace or fundamentally change the existing Quality Management System (QMS) requirements. Instead, it builds upon ISO 9001:2015 by introducing several important enhancements to help organizations address evolving business challenges and improve overall management effectiveness.
Key updates include:
- A clearer separation of risks and opportunities
- A stronger emphasis on quality culture and ethical behaviour
- Enhanced clarity and reduced ambiguity through a new Annex A
- Closer alignment with other ISO management system standards
These updates are designed to help organizations build more effective, transparent and future-ready quality management systems.
Q2. My company is already certified to ISO 9001:2015. Do we need to rebuild our entire Quality Management System?
In most cases, no.
ISO 9001:2026 continues to adopt the ISO Harmonized Structure (formerly known as Annex SL), meaning that:
- Quality policy
- Quality objectives
- Risk and opportunity management
- Control of documented information
- Internal audit
- Management review
will continue to be key elements of the standard.
For most organizations, the transition to ISO 9001:2026 will primarily involve:
- Conducting a Gap Analysis to identify differences between the current management system and the new requirements.
- Reviewing and updating affected processes, procedures, and documented information.
- Providing transition training to relevant personnel and internal auditors.
- Verifying effective implementation through internal audits and management reviews.
Therefore, for most organizations, the transition is expected to be a process of improvement and updating rather than rebuilding the management system.
Q3. What are the key areas that auditors are likely to focus on during an ISO 9001:2026 transition audit?
Building upon ISO 9001:2015, ISO 9001:2026 places greater emphasis on risk and opportunity management, quality culture, ethical behaviour, and management system integration. Therefore, in addition to verifying the continued conformity of the existing Quality Management System (QMS), auditors are expected to focus on how well an organization has embedded these concepts into its day-to-day operations and decision-making processes.
The main areas of focus are likely to include:
- Identification and evaluation of internal and external issues: Organizations are expected to reassess internal and external factors that may affect the effectiveness of their QMS, taking into account changes in the market, technology, regulations, and supply chains. Auditors will look for evidence that the organization has identified and evaluated both risks and opportunities arising from these changes.
- Management of risks and opportunities: Organizations should be able to clearly distinguish between risks and opportunities and demonstrate how they are identified, assessed, addressed, and monitored. Auditors will seek evidence that risk- and opportunity-based thinking is effectively applied to support decision-making and drive continual improvement.
- Development of a quality culture: Auditors may assess whether employees understand the organization's quality policy and quality objectives, and whether they actively participate in reporting issues, improvement initiatives, and continual improvement activities. The focus will be on whether quality is embedded in the organization's culture rather than being solely the responsibility of the quality function.
- Ethical behaviour and data integrity: Organizations are expected to ensure that quality-related data is accurate, reliable, and trustworthy. Auditors may also evaluate whether the organization promotes a culture of integrity, transparency, accountability, and responsible business conduct throughout its operations.
- Management of external providers and the supply chain: Auditors are likely to pay increased attention to how organizations monitor and control suppliers, outsourced processes, and external service providers. This includes assessing the effectiveness of supplier oversight, risk controls, and contingency plans to address potential supply chain disruptions.
In summary, an ISO 9001:2026 transition audit will go beyond verifying compliance with documented procedures and records. Auditors are expected to place greater emphasis on how top management promotes a quality culture, applies risk- and opportunity-based thinking, and drives continual improvement to enhance the overall effectiveness of the management system.
Q4. Does the scope of emerging technologies include the maintenance of implemented systems? If not, can the related certification requirements be excluded from applicability?
Regarding “Emerging Technologies”, it generally refers to newly introduced or rapidly evolving technologies, such as Artificial Intelligence (AI), big data analytics, automation technologies, the Internet of Things (IoT), and cloud-based platforms, which may create new risks, opportunities, or impacts on an organization's products, services, processes, or management systems.
For systems that have already been implemented and are operating in a stable manner, routine maintenance, bug fixes, and periodic updates would not normally be classified as emerging technologies simply because they are IT-related activities. However, if the maintenance activities involve the introduction of new technological features, major system upgrades, architectural changes, or new digital capabilities, they may need to be assessed and managed as technology-related changes.
Therefore, even if such activities do not fall within the scope of emerging technologies, this does not automatically mean that the relevant requirements of ISO 9001:2026 can be excluded. Organizations should still evaluate, based on the nature of the activities, whether they involve (e.g.,):
- Planning and control of changes (Clause 6.3);
- Risk and opportunity management (Clause 6.1);
- Organizational knowledge management (Clause 7.1.6);
- Operational control and change management (Clauses 8.1 and 8.5.6);
- Design and development changes, where applicable (Clause 8.3.6).
Q5. My company is planning to undergo a recertification audit in June 2027. Should the audit be conducted against ISO 9001:2015 or ISO 9001:2026? By when must organizations complete the transition?
If your organization is scheduled for a recertification audit in June 2027, the applicable audit criteria will depend on the certification body's transition arrangements and accreditation requirements in place at that time.
During the transition period following the publication of ISO 9001:2026, organizations will generally have the option to be audited against either ISO 9001:2015 or ISO 9001:2026, subject to the certification body's transition policies. However, all certified organizations will be required to complete the transition to ISO 9001:2026 before the end of the transition period.
According to the current UKAS Transition Plan, ISO 9001:2015 certificates are expected to remain valid until 30 September 2029. Organizations should therefore ensure that their management systems are fully transitioned and certified to ISO 9001:2026 before this date.
To facilitate a smooth and effective transition, organizations are encouraged to adopt a phased approach:
Phase 1: Understand the new requirements
Following the publication of ISO 9001:2026:
- Review and understand the new and revised requirements.
- Attend ISO 9001:2026 transition training.
- Conduct a Gap Analysis to identify areas requiring updates.
Phase 2: Implement necessary changes
- Update relevant procedures, processes, and documented information.
- Implement any required operational changes.
- Conduct internal audits against ISO 9001:2026 requirements.
- Complete a management review to evaluate readiness for transition.
Phase 3: Complete the transition audit
- Complete the transition audit.
- Obtain ISO 9001:2026 certification.
- Continue to monitor and maintain effective implementation of the new requirements.
Please note that the transition audit will normally require additional audit man-days (MDs) to evaluate the organization's transition planning, implementation activities, and conformity with the new ISO 9001:2026 requirements. Organizations are therefore encouraged to discuss and confirm the transition arrangements with their certification body at an early stage and, where possible, combine the transition audit with a Surveillance Audit or Recertification Audit to improve efficiency and minimize additional time, cost, and resource requirements.