ISO 9001:2026: How to Implement the Changes, Not Just Read Them
ISO 9001:2026 is not a revolution, and that is exactly what makes it risky. The changes look small, and if you implement them poorly they will be written up in your transition audit.
Almost everything published about this update walks you through the list of changes, clause by clause. You end up knowing what changed and with no idea how to land it. This article does the opposite: the changes that genuinely cost work, and for the two hardest ones, the methodology I use to implement them.
Not all changes are equal
When I went through the published version I sorted the changes into three groups, and that sorting is what saves you time:
- General changes. Wording adjustments that make the standard easier to read. They do not touch your quality management system and they are not worth your time.
- Small changes. Low impact, but worth knowing about. I left them for the end of this article.
- Big changes. Here you will implement something new, or change your approach to something you already have.
There are three big ones, and in my experience they rank like this in difficulty: the quality culture requirement in 5.1.1, risks and opportunities in 6.1, and the new interested parties filter in 4.2.
1. Interested parties: clause 4.2 c)
The note about climate change is not the interesting part of this clause: that had already been a requirement since the 2024 amendment. The interesting part is item c).
The standard now asks you to determine, out of every requirement from your interested parties, which ones you will address through the quality management system. That is a requirement, not a recommendation.
Watch out for what this is not, because this is where most people get confused: the standard does not ask you for a new procedure or a new form. It asks you for a criterion, and the criterion is yours to set. A couple of extra columns in the table where you already manage interested parties will cover the record; what is missing is the logic behind the decision.
I use a five-node decision tree. You walk it once per requirement, and the moment a node takes you out of the path you already know what to record and why.
Three things worth pointing out about the path:
- Node 1 drops the most rows. A requirement existing does not mean you are the one who has to meet it. If the discharge permit is in the name of the industrial park, the park is the obligated party. If neighbors expect the access road to be paved, that falls to the local authority. Outsourcing, on the other hand, does not transfer responsibility: if a food safety regulation requires pest control and you contract it out, the requirement is still yours under clause 8.4.
- Node 2 is decisive. If the requirement is mandatory, whether by law, by contract, or because the product does not conform without it, you skip straight to node 5. There is nothing to decide.
- Node 4 is the one almost nobody records. An expectation becomes a requirement the moment your top management adopts it, not before. If your retail customer wants recyclable packaging and it is not in the contract, it is an expectation. Once management decides to adopt it because that is your main account, it is your requirement, and from that date on.
If you want the background on why this clause exists, I wrote about it a while ago in interested parties in ISO 9001.
2. Quality culture: clause 5.1.1 i)
To me this is the change with the largest impact in the whole update, and it is a single item: top management must now promote a quality culture and ethical behavior.
Let me put my opinion up front, because it is opinion and not requirement. I have always believed culture was one of the great gaps in the ISO standards, and I have been saying so since 2019. As a consultant I walk into companies that only ever wanted the certificate and that are chaos on the inside. A system can be perfectly documented, certified, and still be a facade. This requirement goes straight at that, and at the consultants who sell a folder of procedures with the logo swapped out and call it a management system.
Now the requirement itself. Four things worth getting straight before you implement anything:
- Ethical behavior is part of the quality culture, not a separate program. The standard is not asking you for two things. It is asking for one.
- The note refers to shared values, attitudes, practices and actions. With those last two words in there, declaring values is not enough: you have to evaluate that they are applied.
- Shared means shared. It is not enough for top management to have a quality culture, and the scope reaches employees, suppliers, customers and any other interested party.
- It does not require documents, but it does require evidence. A code of ethics, a whistleblowing line, a culture survey, an ISO 37001 implementation: none of these are mandatory. They help, but a small company can comply without any of them by demonstrating real actions.
And the working definition I use so I do not lose the thread: quality culture is how your people behave when complying costs time, costs money or costs a telling-off, and nobody is watching.
Since this does not get solved with a policy and a couple of forms, I designed a six-phase method. Each phase produces a deliverable, and those deliverables together are the only evidence you can use to hold the requirement up.
Three notes on the method:
- Start with phase 1, and run it with your top management in the room. A critical behavior point is a real situation where doing the right thing hurts: the out-of-spec lot when the truck leaves in an hour, the mistake nobody else saw, the measuring equipment that fails mid-shift. For each one you declare the expected behavior. That is customized by definition, and it is why nobody can sell you the finished procedure.
- Phase 3 is the most uncomfortable and the one that changes the most. This is where you check whether your own system pushes people against what management declares. A bonus based on output that ignores rejects, or a zero-complaints target that rewards not logging them, contradicts this requirement even if nobody planned it that way.
- The full cycle is plan, do, check, act. It is not a layer on top of the system. It is the system.
And a warning that will save you the project: reported nonconformities will go up at first. That is normal, and it is the signal that it is working, because people stopped hiding them. If top management reacts by punishing, you destroy in one meeting what you built across six phases.
If you want the short version of why culture decides whether your processes are followed, I covered it here.
The two methodologies in this article, the decision tree and the six phases, are my own work and I am giving them away. Use them as they are if they fit, or adapt them to your organization, which is what they are for. The diagrams reproduce the logic exactly as I use it.
3. Risks and opportunities: clause 6.1
The simple way to explain this change is that the standard finally gave opportunities a place of their own. Up to the 2015 version it mentioned them as the positive effect of a risk. Now it separates them.
And it is not asking you to separate the concept. It is asking you to separate the methodology, because a risk and an opportunity are neither evaluated nor treated the same way:
| Risks | Opportunities | |
|---|---|---|
| How you evaluate it | Likelihood or frequency, against impact or severity | Feasibility, against benefit |
| Action strategies | Terminate, treat, transfer, tolerate | Exploit, enhance, share, observe |
| Which way you push | Down: less likelihood, less impact | Up: more likelihood, more benefit |
If your matrix uses the same likelihood-and-impact scale for both, there is your first job. Open it and split the rows: negative effects on one side, positive ones on the other. In most of the matrices I get to review one of two things happens: either no opportunity survives, or the ones that do are the same risks written backwards.
And a clarification I end up making often on the plant floor, because the confusion is real:
| When it happens | What you do | |
|---|---|---|
| Risk | In the future, it might happen | You prevent it |
| Problem | In the present, it is happening | You solve it |
| Nonconformity | In the past, it already happened | You correct it and learn from it |
Corrective action has not disappeared, it is still in clause 10. What it no longer is, is the primary improvement mechanism, and the reason is simple: by the time you apply it, the cost, the complaint or the lost customer already happened.
The small changes, one by one
None of these force you to redesign anything, but it is worth knowing they are there:
| Clause | What changed | What you have to do |
|---|---|---|
| 6.3 Planning of changes | The full plan-do-check-act cycle is made explicit, and the criterion is now that the change achieves its intended objectives | Planning the change used to be enough. Now the criterion is the result |
| 7.1.3 Infrastructure | A note adds on-site, remote or combined work | If you have remote or hybrid staff, provide their infrastructure too |
| 7.1.4 Environment | Recognizes that some factors depend on the quality culture and ethical behavior | Nothing extra. It follows from 5.1.1 and is resolved there |
| 7.1.6 Organizational knowledge | A note clarifies where knowledge lives: people, methods, processes, products and documented information | Nothing extra, but the clarification is useful |
| 7.3 Awareness | Brings in the quality culture and ethical behavior | Phase 5 of the method above covers it |
| 8.2.1 e) Customer communication | New item: provide information on contingency actions, including disruptions to supply | The focus moved from the document to the actual communication. Review your contingency plans and include supply interruptions, not only fires and equipment failures |
| 8.4.3 d) External providers | Provider interactions with your customers and interested parties | If your provider deals directly with your customer, set the rules in writing |
| 9.1.3 and 9.3.2 Analysis and management review | Risks and opportunities appear separately, and changes in interested party expectations come in as an input | New inputs for your management review. No rethinking needed |
| 10.1 and 10.2 Improvement | Continual improvement becomes 10.1 and corrective action moves to the end. A note clarifies that improvement can be incremental or disruptive, through innovation or reorganization | A change of form, with a clear message: corrective action is the last resort in improvement, not the first |
How long do you have to transition?
The short answer is three years. That is what has historically been granted to move from one version to the next, it is what happened in the transition from the 2008 version to 2015, and it would give you until September 2029 to complete it.
One thing to be clear about: your certification body is the one that confirms the official deadline, so keep an eye on the announcements they will issue. And do not worry, because throughout that whole period your ISO 9001:2015 certificate remains completely valid. In fact, if you are only now pursuing certification, you will be certified to the 2015 version, because certification bodies also need time to prepare for the new one.
Once the transition period ends, the 2026 version will be the only one you can certify to.
Do not leave it until the end
Three years sounds like plenty of time, and that is the trap.
The quality culture requirement in 5.1.1 is not something you implement in a month, because it does not depend on writing a document: it depends on real things happening in your company and being recorded. If you start generating that evidence in the year of your transition audit, you will show up with a freshly signed policy and not one logbook proving anyone lives by it. That is exactly the paper system this requirement came to expose.
The other two big changes cost less, but they share the same underlying problem. The 4.2 c) filter and the separation of risks and opportunities move documents that later feed your management review. The later you touch them, the more you will have to redo.
Start this year, even if it is with a single clause. Pick the one that hurts most in your operation, and work it through end to end.
With AdminISO you keep your Quality Management System aligned with the ISO 9001 changes, with risks and opportunities already separated into two distinct methodologies. See how AdminISO helps you.
