Skip to content
DEEN
Book a call

Standard Market-driven · Switzerland, EU, Germany

ISO 9001.

Short answer

ISO 9001 is the internationally recognised standard for quality management systems, voluntary, but often contractually required in manufacturing and supply chains as well as in public tenders. It is built on the PDCA cycle (Plan-Do-Check-Act) and is audited by accredited certification bodies, with a validity of three years and annual surveillance audits. ISO published the new ISO 9001:2026 version on 16 September 2026; existing certificates to ISO 9001:2015 remain valid until 30 September 2029 at the latest.

01 Triggers

When does ISO 9001 apply to you?

ISO 9001 may apply to you if one of these triggers applies. The Regulatory Check tests them against your details. Triggers marked “only together with industry or activity” only count if a trigger on industry or activity applies at the same time.

  • Industry: Manufacturing (Likely applies): In manufacturing and supply chains, a certified quality management system is a common precondition for even being listed as a supplier.
  • Industry: MedTech (Likely applies): In medical technology, ISO 9001 is the basis that the sector-specific ISO 13485 builds on; without a functioning quality management system, 13485 certification is not achievable.
  • Activity: Public-sector clients (Recommend individual review): Public tenders in manufacturing and services frequently require a certified quality management system as an eligibility criterion.
  • Role towards customers: Supplier (only together with industry or activity) (Likely applies): Large customers in supply chains regularly check suppliers for a certified quality management system before awarding contracts.
  • Activity: Supplier to the automotive industry (Recommend individual review): Automotive manufacturers and their suppliers require a quality management system to ISO 9001 as the basis on which sector-specific requirements such as IATF 16949 build.

Exceptions

  • No legal obligation to be certified.
  • For micro-enterprises without a specific customer requirement, there is generally no trigger.
  • Medical technology companies generally need the sector-specific ISO 13485 in addition to ISO 9001; this is only mentioned here, with detail covered in a separate file (iso13485).

02 Obligations

What does ISO 9001 require?

  • Establish a quality management system following the PDCA cycle (Plan-Do-Check-Act)
  • Documented processes, responsibilities and evidence (control of documents and records)
  • Internal audits and management review
  • Measures for continual improvement and for managing risks and opportunities

03 Evidence

What evidence is needed?

  • Certificate from an accredited certification body following a Stage 1 audit (document review) and Stage 2 audit (implementation review)
  • Annual surveillance audits
  • Recertification every three years
  • For existing ISO 9001:2015 certificates: validity ends 30 September 2029 at the latest, after which certification to ISO 9001:2026 is required

04 Deadlines

Which deadlines apply?

  1. Publication of ISO 9001:2026 by ISO (supersedes ISO 9001:2015)
  2. Existing certificates to ISO 9001:2015 lose validity at the latest on this date (three-year transition period)

Information as of: 24 September 2026. Past dates are grey, upcoming ones highlighted (as of when the page was built).

05 Penalties

What are the consequences of violations?

No fine, since voluntary; in practice: without a valid certificate, exclusion from tenders and supplier lists is a risk, particularly in manufacturing and supply chains.

06 Related

What is connected with it?

07 Open

What is still uncertain?

  • iso.org responded to direct retrieval in this session with HTTP 403 (bot block); the facts on the 2026 revision come from the secondary sources TÜV and DNV, which agree on the publication date (16.09.2026) and the transition period (until 30.09.2029), but were not checked against the ISO original text.
  • The exact substantive scope of the changes from 2015 to 2026 (resilience, supply chain management, sustainability, leadership responsibility) is evidenced only via a secondary source (TÜV), not checked against the ISO original text.
  • Whether and how the PDCA cycle remains explicitly named in the 2026 version was not examined in this session.
  • An earlier note in the architecture document ('ISO 9001 revision not checked') is resolved by this research step: the revision is published (16.09.2026), evidenced via two consistent secondary sources, not via the ISO original text.

08 Sources

Sources

Information as of: 24 September 2026.

A professional assessment based on publicly available sources, not legal advice. Whether a given rule applies in your specific case depends on circumstances that are not fully captured here.

FAQ Answers

Questions about ISO 9001.

Is ISO 9001 legally required?

No. The standard is voluntary, but is often contractually required in manufacturing and supply chains as well as in public tenders.

What changes with ISO 9001:2026?

ISO published the new version on 16 September 2026; it replaces ISO 9001:2015 and, per certification bodies, brings among other things stronger requirements on resilience, supply chain management, sustainability, leadership responsibility, and managing risks and opportunities. Existing certificates to the old version remain valid until 30 September 2029 at the latest.

Is ISO 9001 sufficient for medical technology?

Generally not on its own. Medical technology companies also need the sector-specific ISO 13485, which builds on the same principles but imposes additional regulatory requirements.

Does ISO 9001 apply to you?

The Regulatory Check gives an initial assessment. In a conversation, we clarify what really applies in your situation and in which order you address it.

Ivo Schönberner on a lakeside promenade in the morning light