ISO 9001:2015 vs. ISO 9001:2026 – Main differences

The most common mistake organizations make with ISO 9001 revisions is assuming nothing will really change. Then, the new version arrives, and auditors start asking questions. Companies scramble to retrofit their systems, usually under pressure, with wasted effort, and sometimes with findings that could have been avoided.

ISO 9001:2026 is now available and introduces targeted changes in leadership, quality culture, ethical behavior, risks and opportunities, change planning, organizational knowledge, and operational control. Organizations should determine which revised requirements affect their existing QMS and prepare proportionate updates.

Main differences in ISO 9001:2026:
  • Stronger focus on risk and opportunity management (Clause 6.1)
  • Quality culture and ethical behavior elevated (Clauses 5.1.1 & 7.3)
  • Change management requirements expanded (Clause 6.3)
  • Continual improvement reframed and strengthened (Clause 10.1)

This article examines the key clause-by-clause differences between ISO 9001:2015 and the new ISO 9001:2026, highlighting what these shifts mean for organizations, quality managers, auditors, and consultants preparing for the transition.

Overview of the revision

This comparison is based on ISO 9001:2026. The revision retains the existing framework and most requirements. It also incorporates the climate-related provisions introduced through the 2024 amendment to ISO 9001:2015, so these should not be regarded as entirely new requirements introduced by the 2026 revision.

Clause 3 now includes core management system and quality management terms and definitions, with ISO 9000:2026 as the normative reference. Annex A has been substantially expanded to clarify the structure, terminology, and intent of the requirements across the standard. It does not add requirements. Annex B has been removed, with relevant references relocated to Annex A and the ISO/TC 176 website.

Summary of the changes

Degree of change Clause number Clause name
Major 5.1.1 Leadership and commitment — General
6.1.2 Actions to address risks
6.1.3 Actions to address opportunities
6.3 Planning of changes
7.3 Awareness
10.1 Continual Improvement
Moderate 4.2 Understanding the needs and expectations of interested parties
7.1.6 Organizational knowledge
8.2.1 Customer communication
8.2.3 Review of requirements related to products and services
8.2.4 Changes to requirements for products and services
8.3 (Moderate for 8.3.2 and 8.3.5) Design and development of products and services
8.4.3 Information for external providers
8.5.3 Property belonging to customers or external providers
9.1.2 Customer satisfaction
9.2.2 Internal audit program
9.3.2 Management review inputs
9.3.3 Management review results
Small (editorial) 4.1 (Incorporation of the 2024 amendment) Understanding the organization and its context
4.3 Determining the scope of the quality management system
4.4 Quality management system and its processes
5.2 Quality policy
5.3 (Clarification of responsibilities for QMS integrity) Organizational roles, responsibilities and authorities
6.1.1 Determining risks and opportunities
6.2 Quality objectives and planning to achieve them
7.1.3 Infrastructure
7.1.4 (Small explanatory note) Environment for the operation of processes
7.1.5 Monitoring and measuring resources
7.2 Competence
7.5 Documented information
8.1 Operational planning and control
8.5.1 (clarification and restructuring) Control of production and service provision
8.5.2 Identification and traceability
8.5.3 (documented information wording) Property belonging to customers or external providers
9.1.1 (clarification and restructuring) General (Monitoring, measurement, analysis and evaluation)
9.1.3 (clarification and restructuring) Analysis and evaluation
10.2 Nonconformity and corrective action
No change 5.1.2 Customer focus
7.1.1 General (Resources)
7.1.2 People
7.4 Communication
8.2.2 Determining requirements related to products and services
8.2.3 Review of requirements related to products and services
8.2.4 Changes to requirements for products and services
8.4.1 General (Control of externally provided processes, products and services)
8.4.2 Type and extent of control
8.5.4 Preservation
8.5.5 Post-delivery activities
8.5.6 Control of changes
8.6 Release of products and services
8.7 Control of nonconforming outputs
9.1.3 Analysis and evaluation
9.1.1 General (Monitoring, measurement, analysis and evaluation)
9.2.1 General (Internal audit)
9.3.1 General (Management review)

Overview of Changes in ISO 9001:2026

Clause 4 – Context of the Organization

4.1 Understanding the organization and its context – The requirement to determine whether climate change is a relevant issue is incorporated into the revised edition. The 2024 amendment to ISO 9001:2015 already introduced it. The note in clause 4.2 also retains the reminder that relevant interested parties can have climate-related requirements.

4.2 Understanding the needs and expectations of interested parties – A new requirement was added: Organizations determine which of the relevant requirements of interested parties will be addressed through the QMS. This does not permit them to disregard applicable statutory or regulatory requirements or accepted customer commitments.

Clause 5 – Leadership

5.1.1 Leadership and commitment (General) – A new leadership responsibility was introduced: Top management must actively promote a culture of quality and ethical conduct.

5.3 Roles, responsibilities and authorities – Responsibility for maintaining QMS integrity is clarified as applying generally, including when changes are planned and implemented.

Clause 6 – Planning

6.1.2 / 6.1.3 Risks and opportunities – The previous clause 6.1.2 was split into two:

  • 6.1.2 now focuses only on actions to address risks.
  • 6.1.3 is dedicated to actions to address opportunities, making their treatment explicit and distinct from actions addressing risks.
  • ISO 9001:2026 requires organizations to determine, analyze, and evaluate relevant risks and opportunities. Risk actions must be proportionate to their potential impact on the intended results of the QMS. Opportunity actions must be appropriate to the organization’s context and support desired results. A note highlights risks affecting the ability to provide conforming products and services during and after a disruption.

6.3 Planning of changes The list of factors to consider has expanded from four to seven, now including:

  • How the effectiveness of changes will be monitored and evaluated
  • Communicating changes
  • How the results of changes will be reviewed

The revised wording clarifies that organizations must consider the potential impact of changes on QMS integrity and explicitly adds information alongside resources when considering availability.

Clause 7 – Support

7.1.4 Environment for the operation of processes – The requirement remains substantively unchanged. The revised note explains that some work-environment factors can be influenced by organizational quality culture and ethical behavior

7.1.6 Organizational knowledge – The focus broadens from operating processes and achieving product/service conformity to achieving the intended results of the QMS as a whole. Knowledge must be retained, applied, and shared to the extent necessary, not just “made available.”

7.3 Awareness – People working under the organization’s control must now also be aware of the organization’s quality culture and ethical behavior. This adds to awareness of the quality policy, relevant quality objectives, their contribution to QMS effectiveness, and the implications of not conforming to QMS requirements.

7.5 Documented information – Across the standard, revised wording distinguishes information that must be available to support activities from documented information available as evidence. The latter still entails retaining objective evidence. Organizations do not need to rename their documents and records, and existing documentation controls remain applicable.

Clause 8 – Operation

8.2.1 Customer communication – Organizations must now provide customers with relevant information about contingency actions, including those related to disruptions to the provision of products or services. Examples of communication channels (social media, websites, FAQs) are provided in a note.

8.2.3.2 Review of requirements for products and services – Documented information must be available, as applicable, as evidence of review results and any new or changed requirements. The explicit addition of changed requirements extends the previous reference to new requirements.

8.2.4 Changes to requirements for products and services – Relevant documented information must be updated and communicated to the relevant interested parties when requirements change.

8.3.2 Design and development planning – The considerations concerning involvement in the process and the expected level of control now refer to customers and other relevant interested parties, broadening the previous references to customers and users.

8.3.5 Design and development outputs – Outputs must specify not only the essential product and service characteristics, but also the information about those products and services needed for their intended purpose, including safe and proper provision.

8.4.3 Information for external providers – External providers must, where relevant, be informed of requirements related to their interactions with the organization’s customers and relevant interested parties, in addition to interactions with the organization itself.

8.5.1 Control of production and service provision – The revised wording explicitly refers to the availability and use of documented information and separates three elements: characteristics, activities, and results. This clarifies and reorganizes existing controls. Validation and periodic revalidation remain required where the resulting output cannot be verified by subsequent monitoring or measurement.

Clause 9 – Performance Evaluation

9.1.2 Customer satisfaction – Simplified wording: Organizations must “monitor customer satisfaction.” The note provides examples of information sources, including complaints and social media.

9.1.3 Analysis and evaluation – The evaluation of the effectiveness of actions addressing risks and opportunities is now presented as two separate items, consistent with the revised structure of clause 6.1.

9.2.2 Internal audit program – Each internal audit must now have defined objectives, in addition to scope and criteria.

9.3.2 Management review inputs – Management reviews must explicitly consider changes in the needs and expectations of interested parties relevant to the QMS. The effectiveness of actions addressing risks and opportunities is also presented as separate inputs.

9.3.3 Management review results – The revised clause refers to results rather than outputs and explicitly mentions continual improvement opportunities. Results must include decisions concerning these opportunities, any need for QMS changes, and resource needs. This does not make decision-making a new requirement.

Clause 10 – Improvement

10.1 Continual improvement (combining content from former clauses 10.1 and 10.3) – Improving the suitability, adequacy, and effectiveness of the QMS was already required in ISO 9001:2015. The revised clause explicitly includes monitoring and measurement, alongside analysis, evaluation, and management review results, as inputs for determining improvement opportunities. Actions cover improving processes, products, and services; addressing future needs and expectations; and correcting, preventing, or reducing undesired effects.

How much has changed?

To summarize, the current revision of ISO 9001 introduces a series of targeted but meaningful updates. Most of the structural framework of ISO 9001:2015 remains intact; organizations familiar with the process approach, risk-based thinking, and continual improvement will not face a radical overhaul.

The main body of the standard underwent moderate adjustments, including more precise requirements for risk evaluation, a dedicated sub-clause for opportunities, expanded expectations for change management, a broader treatment of organizational knowledge, and an explicit emphasis on quality culture and ethical behavior.

Other targeted changes concern evidence of new or changed customer requirements, communication of requirement changes, design planning and outputs, and external providers’ interactions with customers and other relevant interested parties.

For most companies, these changes will not require a full redesign of their QMS. Instead, they will need to refine existing processes, strengthen how they justify decisions (including risks, opportunities, and the needs of interested parties), and expand awareness and leadership practices to encompass culture and ethics.

The new version is evolutionary, not revolutionary. Organizations already certified against ISO 9001:2015 will face adjustments, sometimes subtle, sometimes requiring more discipline, but the overall transition effort should be manageable rather than disruptive. A focused transition review should distinguish genuine gaps from arrangements that already work. Implement necessary updates through the relevant processes and evaluate their effectiveness.

Order the ISO 9001 Premium Documentation Toolkit today and receive a free upgrade to the 2026 revision when released.

Advisera Carlos Pereira da Cruz

Carlos Pereira da Cruz

Carlos Pereira da Cruz has over 30 years of experience working as a consultant, trainer, and auditor with ISO 9001 and ISO 14001. He is a university teacher and author of several books on strategic management, ISO 9001, and ISO 14001, as well as an ISO 9001 author.
Read more articles by Carlos Pereira da Cruz