ISO 9001:2026 Changes and What Your Company Should Review

Two quality professionals review process documents beside a manufacturing facility.

ISO 9001:2026 was published on September 16, 2026. If your company already uses ISO 9001:2015, the next step is to understand which changes affect the way your quality management system works. ISO’s publication announcement confirms that the new edition builds on the familiar framework.

In reviewing the final edition against 2015, I focused on what your company may need to do differently. Some changes introduce requirements. Others strengthen existing expectations, move requirements to another location, or explain them in more detail. Recognizing the difference will help you focus your effort.

The process approach, customer focus, controlled operations, and continual improvement remain central. A working system gives you a foundation for this review. Below are the changes I recommend examining first, with examples of how to apply them. The examples are practical suggestions, not additional ISO requirements.

Quality culture and ethical behavior become specific expectations

The 2015 edition already required leadership commitment, support for people, and awareness of how individuals contribute to an effective quality management system. The 2026 edition adds a specific leadership duty to promote quality culture and ethical behavior in 5.1.1.i. Clause 7.3.e adds awareness of those topics for people working under the organization’s control. A note in 7.1.4 also connects culture and ethical behavior with the work environment.

For your company, this reaches beyond adding a sentence to an orientation presentation. Consider how leaders respond when an employee reports an inspection failure or questions a release decision under delivery pressure. Those responses show people which behaviors the company supports.

I recommend checking whether employees understand expectations for accurate records, reporting problems, and raising quality concerns. Look at leadership actions alongside training and communications. These clauses do not prescribe a separate ethics procedure.

Risks and opportunities need separate consideration

ISO 9001:2015 already required your company to address risks and opportunities, integrate actions into its processes, and evaluate whether those actions worked. Opportunities are not a new concept in 2026.

What changes is the treatment of each. Clause 6.1.2 addresses risks, and 6.1.3 addresses opportunities, basically each has its own house. Both now specifically require determining, analyzing, and evaluating them. Risk actions must be proportionate to their potential impact on intended QMS results. Opportunity actions must fit your company’s context and support desired results.

For example, reliance on one qualified supplier may be a risk. An opportunity could be a different inspection method that shortens turnaround while maintaining reliable results. Your review should explain the opportunity, the action you select, and how you will assess its effectiveness.

Check whether your current planning gives opportunities meaningful attention. If every entry describes something that could go wrong (a typical exercise to identify risks), then your process may need more work. You can use a combined tool if it supports both types of analysis. Also keep in mind that having separate requirements does not automatically require separate registers or a prescribed scoring method.

Change planning extends through communication and review of results

Clause 6.3 in the 2015 edition already addressed the purpose and consequences of QMS changes, system integrity, resources, and responsibilities, but it was short (trying not to use the word “weak”). The 2026 edition adds available information, communication of changes, how effectiveness will be monitored and evaluated, and how results will be reviewed to the matters your company must consider.

Suppose you replace your order-entry system. Assigning a project owner and a launch date covers only part of the work. You also need to consider the information required for the change, who needs to know about it, how you will determine whether it works, and how you will review the results.

A practical approach could include checking whether customer requirements transfer correctly and reviewing order errors after launch. These are examples you can adapt to your own company and the resources you have. The requirement is to consider the added planning matters, not to adopt a particular change form or software (although Web QMS has the most amazing MOC app ever!).

Organizational knowledge must be retained, applied, and shared

Under 2015, your company had to determine the knowledge needed to operate its processes and achieve product and service conformity, maintain that knowledge, and make it available as needed.

Clause 7.1.6 in 2026 connects necessary knowledge to the intended results of the QMS and specifically requires retaining, applying, and sharing it to the extent necessary. The focus reaches beyond whether information exists in a folder.

Think about an experienced employee who knows why a particular setup prevents recurring defects. If that knowledge never reaches a replacement or another shift, the company may lose an important part of its process capability.

I recommend tracing one useful lesson from a problem or successful project. Has it changed the way people work? Can the people who need it find and use it? Coaching, revised work instructions, and shared lessons may help, depending on the knowledge involved.

Interested-party requirements connect more directly to decisions and communication

The 2015 edition already required identifying relevant interested parties and their relevant requirements. Clause 4.2.c now adds determining which of those requirements will be addressed through the QMS. Clause 9.3.2.c makes changes in relevant interested-party needs and expectations a specific management-review input.

Related operational wording also changes. Clause 8.2.4 addresses updating relevant documented information and communicating it to relevant interested parties when product or service requirements change. Clause 8.4.3.d includes supplier interactions with customers and other relevant interested parties, as applicable.

For example, a changed customer specification may affect purchasing, a subcontractor, and the people performing final inspection. Review how the change reaches each relevant party and how the controlled information is updated.

Start with the interested parties you have already identified. Check whether your review leads to decisions about what the QMS will address, and whether significant changes reach management review and the affected processes.

Disruptions receive more direct attention

The 2015 edition already included risk planning and customer communication about contingency actions when relevant, but most people gave contingency little to no prime time. In 2026, a note in 6.1.2 specifically recognizes risks to conformity during and after a disruption. Clause 8.2.1.e addresses providing customers with relevant contingency information, including information related to disruptions in supplying products or services. Those of you who work with API Q1 or Q2 will recognize the attention to contingency planning, although the requirements are not identical. In my view, contingency arrangements are especially useful when you decide to tolerate a risk. If you control or treat the risk and reassessment shows that it has decreased, review what contingency arrangements are still needed. Lower residual risk does not automatically mean you can do without them; the remaining risk and potential consequences matter.

Consider a potential supplier shutdown or equipment failure. The review should cover how you will continue to meet requirements, including after operations resume, and what customers need to know if the supplier or equipment does shut down.

Check whether your existing risk and communication arrangements cover the disruptions relevant to your operations. The risk note is guidance, and these changes do not impose a universal requirement for a standalone contingency plan.

Internal audits and management review need targeted updates

Under 2015, each internal audit needed defined criteria and scope. Clause 9.2.2.a now also requires defined audit objectives. An objective explains what the audit is intended to accomplish; criteria identify the requirements used to assess the process, and scope establishes its boundaries. I imagine scope, criteria and objectives may be extrapolated in some cases, but having a defined objective will be valuable so Auditors understand why a certain audit matters.

For an audit of a changed order-entry process, an objective might be to determine whether the change was implemented effectively and preserves customer requirements. Check whether your audit planning already makes that purpose evident.

The separate treatment of risk and opportunity actions also carries through to analysis and evaluation in 9.1.3 and management review in 9.3.2. Review the effectiveness of both, along with the added input on changing interested-party needs and expectations. Several existing management-review inputs have simply moved within the list; retain them in your review.

Wording changes do not automatically remove existing duties

As you work through the standard, keep these distinctions in mind:

  • Documentation and records: Much of the maintain and retain wording becomes wording about documented information being available, including as evidence. Annex A explains the relationship. Required evidence and the controls in 7.5 still matter. This is a great change in my view, and makes the standard more relevant in our current times.
  • Climate change: The climate-relevance requirement in 4.1 and the interested-party note in 4.2 carry forward the 2024 amendment. If you already addressed that amendment, check continued applicability rather than treating it as an entirely new 2026 task.
  • Continual improvement: The former 10.1 and 10.3 are consolidated in 10.1. Continual improvement remains required even though the old 10.3 heading disappears and so does the unnecessary redundancy.
  • Design and development: New notes recognize iterative design and evolving inputs. They provide guidance while leaving design controls in place.

Start with your existing processes

I recommend reviewing these changes with the people who own the affected processes. Identify what your company already does, where the new edition adds an expectation, and what evidence will show that your approach works. Then assign the necessary actions and review their results.

For certification timing, confirm transition arrangements with your certification body. ISO’s guidance for certified organizations directs organizations to their certification body for further information. Use the published final standard as your authoritative reference when planning updates.

Get the clause by clause comparison

To help you examine the details, Mireaux’s ISO 9001:2026 Comparison Analysis brings the 2015 and final 2026 wording together with highlighted changes and practical observations.

When you sign up, Part 1 covers the overview, Foreword, Introduction, and Clauses 1 through 3. Seven weekly emails follow with Parts 2 through 8, covering Clauses 4 through 10 individually.

Get the ISO 9001:2026 Comparison Analysis.

Build your skills with Mireaux University

If you want help turning the requirements into practical actions, Mireaux University offers options for learning on your own schedule or working directly with an instructor:

  • Self-paced: Introduction to ISO 9001 gives you a starting point for ISO 9001:2026 and how a quality management system supports reliable results.
  • Instructor-led: ISO 9001 Implementation helps you build or upgrade your QMS. The next live-stream class is October 6 through 7, 2026.
  • Instructor-led: ISO 9001 Internal Auditor helps you strengthen your understanding of ISO 9001:2026 and evaluate your system through internal audits. The next live-stream class is October 6 through 8, 2026.

View available ISO 9001 courses and upcoming classes to choose the option that fits your role and schedule.

Advance Your Knowledge with API and ISO Training from Mireaux

Whether you’re preparing for certification or want to enhance your team’s expertise, our training programs cover everything from foundational knowledge to advanced best practices. With expert-led courses and real-world insights, Mireaux helps you build the skills needed for success.

ABOUT THE AUTHOR

Picture of Miriam Boudreaux, CEO

Miriam Boudreaux, CEO

Miriam Boudreaux is the founder of Mireaux Management Solutions, a leading ISO and API consulting, auditing, and training firm.
With over 30 years of experience and as the creator of Web QMS software, she is passionate about helping organizations build practical, sustainable management systems that truly work.
Beyond leading Mireaux, Miriam enjoys connecting with audiences through her YouTube channel ISO & API Mastery with Miriam, where she shares practical ISO and API insights.

Free Essential Guide

The Essential Steps to Jumpstart your ISO/API Certification Journey!

These are the same steps our own Consultants use to successfully guide our clients to achieve ISO/API certification

DRAFT STANDARD ANALYSIS

ISO 9001:2026 DIS Draft Analysis

ISO 9001:2026 DIS Comparison Analysis

We are actively reviewing the ISO 9001:2026 Draft International Standard and documenting key observations, wording and interpretation  changes.

Sign up to receive one section of our analysis per week:

Want to receive all sections at once? Click here