I have clients who have just finished their ISO 9001:2015 certification. The first question once the certificate is in hand: “Do we have to redo everything in two years?”

My short answer: no. The revision is not a complete revolution.

ISO 9001:2015 is the world’s most widely used quality management standard. It has not been revised in depth for eleven years. The new version, ISO 9001:2026, is at the FDIS stage (Final Draft International Standard), the last formal step before publication.

The Draft International Standard (DIS) was released on 27 August 2025 and approved by ISO member bodies in December 2025. Official publication is expected in September 2026, though some sources point to October or November instead.

At this stage, ISO rules allow only an approve-or-reject vote on the text, with no further substantive changes. The technical content is therefore locked.

The transition timeline

Once the standard is published, you will have a transition period of about three years to comply, which pushes the deadline toward September 2029 (subject to confirmation by the International Accreditation Forum, the IAF). On the other hand, the first ISO 9001:2026 certificates will probably not be issued before late 2027 — the time it takes for certification bodies themselves to be accredited to the new version.

So if you are certifying or recertifying to the 2015 version this year, do not delay waiting for the new edition. You would have three years ahead of you either way.

The six changes

1. Climate change enters clause 4

The 2024 climate amendment (ISO 9001:2015/Amd 1:2024) is now integrated into the body of the standard, in clauses 4.1 and 4.2, with knock-on effects on clauses 4.3 and 6.1. You must determine whether climate change is a relevant external issue for your quality management system and, if so, factor it into your planning.

2. Quality culture and ethical behaviour (clause 5.1.1)

This is the most discussed addition. Top management must now explicitly promote a quality culture and ethical behaviour.

I will be frank: this clause is not practically verifiable. The responsible technical committee (TC 176) added no supporting requirements. “Strategic direction” is still undefined in the standard. It is a statement of intent, not a measurable obligation. An auditor will not be able to check much beyond whether the words appear somewhere in your documents.

3. Risks and opportunities, each in their own clause (6.1)

Clause 6.1 is now split into three: 6.1.1 (determine risks and opportunities), 6.1.2 (act on risks) and 6.1.3 (act on opportunities). In 2015, both were handled together, with the risk that one of the two would be neglected.

That said, the new clause 6.1.3 is almost word-for-word the text of 6.1.2 with “risk” replaced by “opportunity”. There is little real new content. And the word “opportunity” remains undefined, nearly a decade after it arrived in the standard in 2015.

4. Change management is strengthened (6.3)

Change planning requirements are expanded, with knock-on effects on clauses 5.3, 8.1, 8.2.1, 8.2.4 and 9.3. The focus is on communication, monitoring and evaluation of changes.

Wording often remains conditional (“should consider”), without a clear documentary obligation. That leaves ample room for interpretation by the auditor — and by you.

5. Awareness is broadened (7.2 and 7.3)

Your employees must now understand the organization’s quality culture and ethical behaviour, in addition to the usual quality management system processes. In practice, that means reviewing your onboarding and ongoing training programmes to add these notions — not just mentioning them in a procedure that gathers dust.

6. A much fuller Annex A

The new Annex A is about 15 pages and clarifies structure, terminology and the intent of the clauses.

This annex contains no binding requirements. You can ignore it entirely without changing anything about your certification. A large share of the technical committee’s work went here rather than into long-known gaps in clause 8 (Operations).

What does NOT change

Plenty of rumours circulate about this revision. Here is what the FDIS text confirms is false:

There is no new technical requirement on artificial intelligence, cybersecurity or cloud computing. The standard does not become a sustainability standard — only the 2024 climate amendment is integrated. There is no specific clause on supply-chain resilience. And the Annex SL structure, with the usual clause numbering, is largely preserved. One real deletion: clause 10.3 on continual improvement disappears, judged redundant with 10.1. The requirements remain; they are simply regrouped.

Two opposing readings: I lean one way

Certification bodies present this revision as an important strategic change, framed around organisational resilience and quality culture.

On the other side, an independent and highly critical technical analysis (Oxebridge) calls most of the changes cosmetic. According to that analysis, nearly all substantive content sits in non-normative text (introduction, Annex A) rather than in the actual requirements of clauses 4 to 10.

Updating a system already certified to ISO 9001:2015 would take about an hour of real work. Historical weaknesses of the standard — such as the lack of a clear delivery clause or the confusion between “documents” and “records” — remain unfixed.

After reading both camps, I lean toward the critics. Certification bodies have an obvious commercial interest in presenting every revision as a major change: it justifies the transition engagements they will bill you for.

The reality of the text is that operational clauses move little. What moves a lot is the intent text. Useful for understanding the philosophy of the standard, but it does not change much of what an auditor will check at your site.

In practice

Here is what I recommend to my clients, wherever they are in their certification cycle:

  • Run a gap analysis between your current system and the revised clauses, prioritizing 4.1/4.2 (climate), 5.1.1/5.2 (culture and quality policy), 6.1 (risks/opportunities) and 7.3 (awareness).
  • Revise your quality policy so it explicitly mentions the organization’s context and strategic direction.
  • Update your training programmes to cover quality culture and ethical behaviour, even if the requirement remains fuzzy. Better to be able to discuss it with an auditor than to be caught off guard.
  • Do not delay an ongoing certification or recertification to wait for 2026. The transition gives you three years, and the first certificates on the new version will not appear before 2027.
  • If you already have ISO 14001, look at the transition in an integrated way. Both 2026 revisions share common terminology and climate requirements.

In short, this revision deserves your attention, but not your panic. The foundations of your quality management system stay the same. What will really take work is quality culture and change management — two areas where the standard remains deliberately vague about what an auditor will require as evidence.

I am curious to see how certification bodies will interpret the quality-culture clause in practice once the standard is published. It could vary widely from one auditor to another.

An audit or recertification is coming up and you are not sure what this revision changes for you? Write to me.