Ga naar inhoud

ISO 27001 ·

ISO 9001:2026 when you already run an ISO 27001 ISMS

ISO plans publication for 16 September 2026; checked on 8 September 2026. A definitive transition deadline was not confirmed.

Map shared workflows without merging the scopes

Create a comparison register with one row per relevant requirement, its quality-management objective, any related ISMS process, available evidence and remaining work. A shared review meeting can discuss both systems, but its decisions must still address each system’s objectives. Do not label a security risk register as a complete quality-management analysis without checking what is missing.

ISO schedules the sixth edition of ISO 9001 for 16 September 2026. Checked on 8 September 2026: the official standard page lists it as under publication. At this check date, the new edition is therefore still a planned publication.

Publication is not a transition deadline

The official ISO page supports the planned publication date. This review did not confirm a final, universally applicable transition deadline. The previous categorical claim of a three-year transition ending in September 2029 has been removed. Confirm the transition arrangements and your certificate’s validity with your certification body.

Prepare a controlled comparison

Identify which edition your policies, contracts and audit programme reference. Assign an owner to compare the final requirements with your existing system once published. Record affected processes, available evidence, required changes and approval decisions. Do not treat a summary of a draft as the complete final standard.

Working alongside ISO 27001

Context analysis, document control, internal audits and management review can share an organisational workflow. Quality management and information security still have distinct objectives and scopes. An established ISMS can support the method of working, but does not demonstrate conformity with every quality management requirement.

Practical preparation checklist

  1. Verify final publication with ISO.
  2. Confirm applicable transition arrangements with the certification body.
  3. Compare the full new standard with current practices.
  4. Plan targeted changes, training and internal checks.
  5. Keep the source versions and recorded decisions.

The publication date, transition deadline and expiry date of an individual certificate are different facts. This page verifies the current publication plan, not an unconfirmed transition rule.

Primary sources for this topic

Frequently asked questions

Can an existing ISMS supply all quality-management evidence?
No. Shared workflows such as document control and review meetings can support implementation, but quality management and information security have different objectives and scopes. Map each relevant requirement to the actual process and evidence. Record remaining gaps rather than assuming that an existing security risk register or audit automatically covers the quality-management question.

Deep dive in the knowledge base

Continue in ISO Ready

Manage actions, risks and evidence in one line of sight toward certification.

Visit ISO Ready

← Back to overview

isocertificering.org is operated by Oosterwal Consultancy (oosterwal.com). ISO Ready (iso-ready.nl) has the same owner. Links to ISO Ready refer to our own commercial offering. About us (Dutch)

AI reading guide (llms.txt)