ISO 9001:2026, expected by September 2026, introduces a harmonized structure with clarifications on documented information, now termed “available as evidence of” compliance, alongside a split between risk-based and opportunity-based thinking. Sector standards like IATF 16949 (second edition by March-July 2026), AS9100, ISO 13485, and emerging ISO 23485 will align closely, incorporating these changes plus industry-specific rules on cybersecurity, software processes, and supplier development. Organizations must prepare for enhanced requirements on quality culture, ethical behavior, and active knowledge sharing to ensure seamless transitions.
ISO 9001:2026 Core Revisions
The standard adds 23 definitions from ISO 9000 into Clause 3 for consistency across management systems, with Clause 6 now separating risk actions (6.1.2) from opportunities (6.1.3), mandating determination, analysis, and evaluation of both undesirable and desirable effects. Clause 6.3 expands planning to include resource availability, change effectiveness monitoring, and communication strategies, while Clause 7.1.6 shifts to “applied and shared” knowledge. Annex A offers 15 pages of clause-specific guidance, supported by upcoming ISO 9002 and SME packages for implementation.
- Leadership clauses emphasize quality culture and ethics.
- Audits require defined objectives (Clause 9.2.2); reviews must cover interested parties’ changing needs (Clause 9.3.2).
- Clause 10 merges continual improvement, adding monitoring for future needs.
Automotive: IATF 16949 and Core Tools Evolution
IATF 16949’s update mandates ISO 9001 alignment, plus interpretations on contingency plans, sub-tier suppliers, AI provisions, and external labs, addressing 40-50% software-related warranties. Updated APQP/Control Plan manuals are required for GM/Stellantis (September 2024) and Ford (December 2024), with SPC/MSA manuals and CQI-34 for embedded software PPAP following in 2026. Compliance teams should integrate these into digital QMS for EV/AV supply chain resilience.
Aerospace and Medical Devices Alignment
AS9100 follows ISO 9001 timelines, prioritizing AS9115 for legacy compliance (2027-2028) and TISAX cybersecurity enhancements. ISO 13485/23485 updates target AI/ML lifecycles, FDA software scrutiny, and EU MDR high-risk device deadlines (December 2027), demanding robust process controls.
Actionable Steps for Compliance Teams
Audit current systems against risk/opportunity splits and quality culture gaps using Annex A checklists. Leverage EWQIMS platforms for automated tracking of changes like supplier interactions and knowledge sharing. Schedule training now to meet 2026 deadlines—contact Omnex for tailored transition support.