
Update, August 2026: publication confirmed for 16 September 2026
ISO 9001 has moved past the draft stage. The Final Draft International Standard (FDIS) went to ballot, and the ballot has now closed. At FDIS the content is no longer open to technical change. National bodies voted on whether it proceeds as written, not on what it says. Publication is now confirmed for 16 September 2026, with a three-year transition expected to follow, subject to formal confirmation by Global ACI, which took over the IAF’s role on 1 January 2026. In practical terms: what you see now is what you will be audited against.
If your organisation is already certified to ISO 9001, the clock on your transition is about to start. I have watched a few of these cycles up close, and the pattern rarely changes: the organisations that engage early stay calm, and the ones that wait until their certification body sends the reminder end up doing the work twice. Once badly, in a hurry, and again properly after the audit finding.
The timeline, and what it means for you
- Now: FDIS ballot closed. The technical content is locked. This is the moment early movers start, because there is no longer any risk of preparing against wording that changes.
- 16 September 2026: ISO 9001:2026 published, superseding ISO 9001:2015.
- Then, a three-year transition (expected to run to roughly September 2029, pending confirmation by Global ACI). Your certificate to the 2015 version does not survive past the end of that window.
Three years sounds generous. It is not, and here is the trap I watch organisations fall into every transition cycle: you do not get three years, you get however many surveillance audits fall inside three years. Your transition realistically has to be done in time for a scheduled audit, with evidence that has been running long enough to demonstrate the system works. Work back from your recertification date and the runway shortens considerably.
The other trap is a quiet one. Certification bodies get busy at the end of a transition window. If everyone leaves it late, availability tightens exactly when you need it.
What’s changing
The structure will feel familiar. This is not a ground-up rewrite. But several themes become considerably more explicit.
Quality culture and leadership
Leadership requirements are sharpened beyond policy approval and procedural compliance, toward genuinely fostering a culture of quality, embedded in behaviours, decisions and ethical conduct.
As an auditor, the tell on a leadership clause has never been the signed policy on the wall. It is whether quality showed up in the decisions people actually made: a supplier kept or dropped, a shipment held, a deadline missed on purpose because the product was not right. That is the hardest thing in the entire standard to retrofit the week before an audit. If the revision leans harder here, and it does, then start collecting that evidence now, because you cannot manufacture a year of decisions retrospectively.
Digital systems and data integrity
As organisations lean on cloud platforms and data-driven decisions, the standard now expects stronger control of the digital records and software your QMS actually runs on: data integrity, system reliability, appropriate control of software.
If your quality system still treats IT as “out of scope”, that position is getting harder to defend. It also dovetails with ISO 27001, and, for anyone whose team has quietly started drafting procedures with AI, with ISO 42001.
Climate and sustainability move into context
Rather than being parked in a separate ESG framework, sustainability and climate considerations are woven into the organisation’s context and risk-based thinking. If you are also facing ISO 14001 or climate-reporting pressure from customers, these are converging rather than multiplying.
Risk, opportunity and resilience
Risk-based thinking remains central, but with a sharper distinction between managing threats and actively pursuing opportunities, and more emphasis on resilience and aligning quality objectives with strategic direction.
Want to know how far you actually are?
Now the text is locked, a gap analysis against ISO 9001:2026 gives you a real answer rather than a guess, and lets you spread the work across the transition instead of compressing it into the month before an audit.
Book an ISO 9001:2026 gap analysis →What it means if you’re already certified
The good news: this is not a rebuild. Organisations with a mature QMS, real leadership engagement, digital recordkeeping, meaningful risk management and some consideration of sustainability will find the transition mostly a matter of refining language, strengthening evidence and tightening a few processes.
The bad news, and I will be blunt because it is kinder than the alternative: a transition is a very unforgiving x-ray of a system that was never really implemented. If your QMS has been a folder that gets dusted off before surveillance audits, the revision will not be the problem. It will simply be the moment the underlying problem becomes visible. If that is you, the transition is an opportunity, not a threat. It is a legitimate reason to fix the thing properly, with a deadline attached.
ISO’s own transition cheatsheet, and what it leaves out
In August 2026 ISO published a one-page ISO 9001:2026 transition and readiness cheatsheet. It is worth reading, and the shape of it is sound: learn the changes early, work out who needs to know, look honestly at your current system, integrate where you run more than one standard, keep it proportionate if you are small, follow your certification body on timing, and write a transition plan.
What it does not do is attach a date to anything, or say what a good answer looks like. Those two omissions are the difference between a calm transition and a scramble. Here is the same list with the missing half filled in.
- “Familiarise yourself with the key changes.” Put a date on it. Publication is 16 September 2026 and the transition runs three years from there. Work backwards from the audits your certification body has already scheduled, not forwards from today.
- “Determine who needs awareness.” Naming the groups is the easy part. Clause 7.3 asks you to demonstrate awareness, so record what each group was told and when. A list of names with dates is evidence. An intention is not.
- “Reflect on your current QMS.” The questions are the right questions, but reflection is not an output. Turn each one into a decision recorded where an auditor can find it: context reviewed on this date, these issues added, these interested parties changed, these objectives revised.
- “Integrate if you run several standards.” Worth saying plainly: ISO 14001 has been revised too. If you hold both, transition them together. Running the same gap analysis, management review and internal audit twice is the most common avoidable cost of a transition year.
- “If you are a small business, keep it proportionate.” Agreed, and here is the test. If a change to your system does not alter a decision someone makes or a record someone keeps, it is documentation for its own sake. Leave it out.
- “Follow guidance from your certification body.” They need something from you first. Bodies get busy at the end of a transition window, and they cannot fit you in against a plan they have never seen.
- “Develop a high-level transition plan.” This is the item that carries all the others, and it is the one the cheatsheet says least about. The plan should name who owns each change, when the gap analysis, internal audit and management review happen, and which audit is the transition audit. Then send it to your certification body, so they can schedule Stage 1 and Stage 2 around it rather than you hoping a slot exists.
None of that is difficult. It is the difference between a document that describes a transition and a plan that produces one.
What I would do now
- Find your recertification date and work backwards. That, not September 2029, is your real deadline.
- Run a gap analysis against the new requirements. The text is settled, so the answer will not move under you.
- Start the leadership evidence trail immediately. It is the one thing you cannot create retrospectively, and it is where the revision bites hardest.
- Bring IT inside the tent. Decide how you control the digital systems your QMS depends on before an auditor asks.
- Ask your certification body for their transition timetable, and book early, before the queue forms.
Frequently asked questions
Can we still get certified to ISO 9001:2015?
Until publication, yes. The 2015 version remains the current standard and a certificate issued against it is valid. But if you are starting a system now, build it with the 2026 requirements in view. There is no sense constructing something you will have to revisit within the year.
Is three years really enough time?
Comfortably, if you start. The organisations that struggle are not the ones with complex systems; they are the ones that treated three years as permission to do nothing for two and a half.
Do we need a consultant to transition?
Not necessarily. If you have a capable quality manager, ISO mentoring is usually the better value: your team does the work and keeps the knowledge, and we make sure it will pass. A transition is a particularly good fit for mentoring, because the system already exists. It needs judgement applied to it, not rebuilding.
What about ISO 14001 and ISO 45001?
ISO 14001 has also been revised. If you run an integrated system, plan the transitions together rather than sequentially. Doing them as one piece of work is materially cheaper than doing them twice.
Running a council? ISO 18091, the guidance standard written for local government, is built on ISO 9001:2015 and is not being revised alongside the 2026 edition. See local government quality management systems and the 2026 revision for what that means in practice.
Talk to us about ISO 9001:2026
Whether you want us to run the transition, mentor your team through it, or simply give you an honest gap analysis so you know where you stand, you will deal directly with an experienced ISO auditor who has been through these cycles before.
Email hello@streamline.business, use our contact form, or call Brisbane 07 3667 8280, Sydney 02 8315 7780, or Melbourne 03 9034 3990.
Status as at 24 August 2026: ISO 9001 is at FDIS stage, ballot closed; publication is confirmed for 16 September 2026; three-year transition expected, subject to confirmation by Global ACI. We will update this page when the standard is published.
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











