The wait is over. On 16 September 2026, the responsible committee ISO/TC 176/SC 2 published the revised ISO 9001 — the sixth edition since 1987 and the first substantive revision since 2015. For every company holding a 9001 certificate, the transition starts now.
First, the assessment I always give at the start of client conversations: this is not a revolution. Anyone running a system that is actually used is in a good position. But it is not merely a linguistic tidy-up either. Two or three requirements call for genuine work, and one of them cannot be settled with a new document.
“The new version asks less whether you have a procedure and more whether it works. That is exactly what good auditors check anyway — now it is written into the standard.” – Nadeesh Lötscher, Sales Partner Switzerland and ECA auditor ISO 9001 and 27001
What has actually changed
The revision does not add any new main clauses. It sharpens the text in several places, and the relevant points can be named. According to the analysis of the revision, these are essentially the following:
- Quality culture and ethical behaviour become a requirement. In clause 5.1.1, top management must actively promote a quality culture and ethical behaviour. For the first time this appears not in an introduction, but in the requirements section.
- Awareness among all employees. Clause 7.3 is extended accordingly: employees must be familiar with the quality culture and the ethical principles — not just the quality policy as a piece of text.
- Risks and opportunities are separated. Clause 6.1 is split into actions to address risks and actions to address opportunities. In practice, the previous blending of the two meant that opportunities were barely addressed at all.
- Strategic direction in the quality policy. Clause 5.2.1 adds a reference to context and strategic direction. The quality policy should fit the long-term strategy rather than sit alongside it.
- Climate change and sustainability in the context. These topics are anchored more firmly in the clause on the context of the organisation, as external issues whose relevance you must assess.
- Annex A has been fundamentally revised. It explains the relationships between the requirements more clearly — and expressly does not create any additional obligations. It is a reading aid, not a workload.
- Full alignment with the Harmonized Structure. This brings the standard even closer to ISO 14001, ISO 27001 and ISO 42001, which makes integrated systems easier.
One point matters more than all the additions combined, and it is a deletion of expectations: the new version deliberately remains technology-neutral. There are no separate requirements on AI or automation. Anyone who hoped — or feared — that ISO 9001:2026 would become the AI standard can put that aside; for that there is ISO 42001.
How long your existing certificate remains valid
Here I have to distinguish between the rule and the formality, because online the two get mixed up.
The rule is clear: for a revision, a transition period of three years from publication normally applies. With publication in September 2026, that period therefore runs until September 2029. By then, all certificates based on the 2015 version must have been transitioned to the new edition; after that they lose their validity.
The formality: the binding transition rules are set by the accreditation umbrella body Global ACI, which emerged from the International Accreditation Forum in early 2026. Its transition requirements for ISO 9001:2026 are available: three years from publication of the standard, i.e. until September 2029.
For your planning, however, that does not mean “time until 2029”. What matters is your own cycle. With us, certificates are valid for three years from the audit date. Anyone whose recertification audit falls in 2027 or 2028 makes the switch exactly then — that is the most cost-effective moment, because the assessment is taking place anyway. Anyone not due until 2029 has to bring it forward.
Which points mean real work in practice
From an audit perspective, two of the seven points mean genuine work; the rest is document maintenance.
Quality culture is the hard one, because it cannot be satisfied with a document. In future, an auditor will talk to employees and check whether management actually promotes the culture. A mission statement on the wall is not enough. What counts are visible actions: how mistakes are handled, whether improvement suggestions receive a response, whether quality wins or always loses when it conflicts with deadlines. This is also exactly what ISO 19011:2026 is aimed at — the revised guideline for audits, which places greater emphasis on evidence of effectiveness.
Separating risks and opportunities is the second point with substance. In many systems, opportunities have so far existed only rhetorically. In future they form a separate section, and something has to be written in it — something that has to do with your business.
Climate change and strategic direction, by contrast, are manageable. In both cases it is about a reasoned assessment as part of the context, not about a sustainability report. If climate topics are not relevant to your business, document that assessment — with reasons.
The approach I recommend
Do without a migration project with its own project structure. Most small and medium-sized companies do not need one. Four steps are enough.
- Carry out a gap analysis against the new version. As a rule, you will find three to five places needing adjustment, not thirty.
- Work on culture and opportunities first, because these two points need time to take hold in the organisation.
- Update the documents afterwards, in one pass. The order matters: anyone who starts with the documents is describing a state that does not yet exist.
- Check against the new version in the internal audit before the external audit takes place.
On our platform, this path runs via guided templates and a gap display that shows which clause still has no evidence. If your system is running and the documentation is complete, assessment, decision and issuance are possible within 48 hours — whether that is realistic in your case is something we tell you in advance, free of charge. The details on the standard at our end are on the ISO 9001 page, the terms on the pricing page: 179 euros per month for the first standard, 149 euros for each additional one, a term of 36 months, fixed price up to 30 employees.
A side effect that pays off right now: because the standard is even closer to the common basic structure, the moment of migration is the most favourable time to add a second standard. You are working on context, risks and documentation anyway.
Conclusion
ISO 9001:2026 does not require a new system. It requires a system that visibly works — and it checks this at the point that is hardest to fake: with the people who work with it every day.
Anyone who takes this seriously during the migration, instead of merely re-dating documents, will come out with a better management system. Anyone who waits until 2029 will do the same work under time pressure.
Your next step: Work out your migration in the cost calculator, or find out via express certification how quickly the transition is possible in your case.
Further reading:




