ISO 9001:2026 is here.
What you need to know (and what you don’t).
On 16 September 2026, the ISO published the sixth edition of ISO 9001, retiring the 2015 version and officially launching the 2026 version.
There’s been a tonne of noise and speculation about this new version for the last 18 months. However, it was all based on draft notes and assumptions, not the final standard.
The thing is, drafts change on their way through the committee process. Some expected changes didn’t make it through; others did.
This blog covers the changes to ISO 9001 and their impact on Australian IT Service Providers, or MSPs as they’re often referred to.
The good news is that, for you, the changes are relatively minor. If you’re ISO/IEC 27001:2022 certified (which most of you reading this are), you’re already on strong ground.
We've read the published edition of ISO 9001:2026 in full and compared it against 2015 clause by clause. This is what you do (and don’t) need to know or care about.
What needs your attention
There were a bunch of changes, lots of them minor. Most are wording, terminology, and definitions. But four of them will change or enhance something you do.
1. Risks now must be analysed and evaluated.
The 2015 edition asked organisations to determine their risks. The new version goes further: risks must be determined, analysed, and evaluated. We think this reflects what MSPs already expect of themselves as a matter of course, whether for cyber insurance or compliance with ISO/IEC 27001:2022. Our view is that structured risk analysis is becoming a baseline expectation across all compliance frameworks, not just ISO.
A list of things that might go wrong is no longer enough. There must be some judgement applied to each risk item, covering how likely it is to happen and the potential consequences. You need a basis for deciding which risks to act on and which you're prepared to live with.
This won't be unfamiliar territory for anyone holding ISO/IEC 27001:2022, where this kind of risk assessment has always been required. What's changed is that the same expectation now applies to quality risks under ISO 9001.
The standard is deliberately vague on how to do it. Its guidance states plainly that no formal risk management framework is needed. A simple approach is perfectly acceptable if it's applied consistently and you can show how you arrived at your conclusions.
2. Opportunities are now a requirement in their own right.
Under the 2015 edition, risks and opportunities were dealt with in a single requirement. In most organisations, that meant opportunities were an afterthought, or a column on the risk register that nobody filled in properly.
The new edition separates them.
Under ISO 9001:2026, a risk is something that could hurt your ability to deliver your core services. An opportunity is something that could improve it, make it better. Both can now be identified and addressed through entirely separate processes.
You must now identify, analyse, and evaluate opportunities independently. You need to decide what to do about the ones worth pursuing, build those actions into how the business runs, and then look back at whether they achieved anything. This also changes what goes into your management review. Opportunity actions and risk actions are now assessed separately, not as a single item. Take note of this one, because auditors will.
3. Quality culture and ethical behaviour.
This is genuinely new language in the standard, and its inclusion was widely (and rightly) guessed at.
Leadership teams must promote quality culture and ethical behaviour, and people doing work under the organisation's control must be aware of it.
The standard connects quality culture to how decisions are made and how people are expected to behave day to day. Awareness, specifically, means people can recognise whether their work meets requirements and know what to do when it doesn't.
The awareness half requires preparation, because auditors usually test awareness by interviewing your people rather than by reading documents. Whatever position an organisation takes on this needs to be clear enough that the people doing the work can describe it in their own words. If you don’t have company values that your team lives and breathes, it’s time to bring some in.
What didn’t make it in:
Three things that were widely reported as ‘likely to change’ in the 2026 version, but didn’t eventuate are:
- Artificial intelligence. The expectation was that the new edition would bring AI, automation and digitalisation into quality management. It doesn't.
- Sustainability. Some coverage suggested quality management would be aligned with ESG expectations. But no. Sustainable development rates a single mention as one of the things a quality management system can support. No requirement anywhere in the standard asks you to measure, report on, or manage environmental or social performance.
- Resilience. Disruption appears in the new edition, but not to the extent suggested by early conjecture. There's a note acknowledging that the risks you consider can include your ability to keep delivering when something goes wrong, and a change to the customer communication clause so that it covers telling customers about contingency arrangements, including those relating to interruptions to service. Neither requires a business continuity programme, though.
There are more changes, but they're minor.
The rest of the changes to the standard are real but smaller, and most can be handled during your transition, either internally or with the help of a consultant.
When do you need to act on these changes?
Not immediately. Based on transition guidelines set for other standards in the past, you will likely have three years to plan and finalise your transition to ISO 9001:2026.
As of the date of this blog, certification bodies can’t issue certificates against the new edition until they've been trained and accredited against it themselves. During the last transition, that process took the best part of a year. Until all that is complete, audits carry on against the 2015 edition as normal.
More guidance is also on the way. ISO 9002, which covers how to apply the requirements, and a handbook aimed at small enterprises are both in development.
If you're partway through implementing ISO 9001, continue with the 2015 edition. It remains the version you can certify to, and the work you're doing now carries across.
What do you need to know if you’re an ISO365 client?
The uplift to ISO 9001:2026 rolls out as part of your managed service.
We'll update your management system, registers and policies centrally, and bring the changes into your regular monthly meetings. Rest assured, we’ve got you covered.
Not an ISO365 client? Get in touch, and we'll walk you through what the transition involves. [Contact link]