# ISO 9001

> ISO 9001 is the internationally recognised standard for quality management systems, voluntary, but often contractually required in manufacturing and supply chains as well as in public tenders. It is built on the PDCA cycle (Plan-Do-Check-Act) and is audited by accredited certification bodies, with a validity of three years and annual surveillance audits. ISO published the new ISO 9001:2026 version on 16 September 2026; existing certificates to ISO 9001:2015 remain valid until 30 September 2029 at the latest.

- Type: Standard, Market-driven
- Scope: Switzerland, EU, Germany
- As of: 24 September 2026
- Page: https://sacosi.ch/en/norms/iso9001
- Regulatory Check: https://sacosi.ch/en/regulation#normencheck

## When does ISO 9001 apply to you?

- Industry: Manufacturing (Likely applies): In manufacturing and supply chains, a certified quality management system is a common precondition for even being listed as a supplier.
- Industry: MedTech (Likely applies): In medical technology, ISO 9001 is the basis that the sector-specific ISO 13485 builds on; without a functioning quality management system, 13485 certification is not achievable.
- Activity: Public-sector clients (Recommend individual review): Public tenders in manufacturing and services frequently require a certified quality management system as an eligibility criterion.
- Role towards customers: Supplier (only together with industry or activity) (Likely applies): Large customers in supply chains regularly check suppliers for a certified quality management system before awarding contracts.
- Activity: Supplier to the automotive industry (Recommend individual review): Automotive manufacturers and their suppliers require a quality management system to ISO 9001 as the basis on which sector-specific requirements such as IATF 16949 build.

## Exceptions

- No legal obligation to be certified.
- For micro-enterprises without a specific customer requirement, there is generally no trigger.
- Medical technology companies generally need the sector-specific ISO 13485 in addition to ISO 9001; this is only mentioned here, with detail covered in a separate file (iso13485).

## Obligations

- Establish a quality management system following the PDCA cycle (Plan-Do-Check-Act)
- Documented processes, responsibilities and evidence (control of documents and records)
- Internal audits and management review
- Measures for continual improvement and for managing risks and opportunities

## Evidence

- Certificate from an accredited certification body following a Stage 1 audit (document review) and Stage 2 audit (implementation review)
- Annual surveillance audits
- Recertification every three years
- For existing ISO 9001:2015 certificates: validity ends 30 September 2029 at the latest, after which certification to ISO 9001:2026 is required

## Deadlines

- 16 September 2026: Publication of ISO 9001:2026 by ISO (supersedes ISO 9001:2015)
- 30 September 2029: Existing certificates to ISO 9001:2015 lose validity at the latest on this date (three-year transition period)

## Penalties

No fine, since voluntary; in practice: without a valid certificate, exclusion from tenders and supplier lists is a risk, particularly in manufacturing and supply chains.

## Frequently asked questions

**Is ISO 9001 legally required?**
No. The standard is voluntary, but is often contractually required in manufacturing and supply chains as well as in public tenders.

**What changes with ISO 9001:2026?**
ISO published the new version on 16 September 2026; it replaces ISO 9001:2015 and, per certification bodies, brings among other things stronger requirements on resilience, supply chain management, sustainability, leadership responsibility, and managing risks and opportunities. Existing certificates to the old version remain valid until 30 September 2029 at the latest.

**Is ISO 9001 sufficient for medical technology?**
Generally not on its own. Medical technology companies also need the sector-specific ISO 13485, which builds on the same principles but imposes additional regulatory requirements.

## Open points of the research

- iso.org responded to direct retrieval in this session with HTTP 403 (bot block); the facts on the 2026 revision come from the secondary sources TÜV and DNV, which agree on the publication date (16.09.2026) and the transition period (until 30.09.2029), but were not checked against the ISO original text.
- The exact substantive scope of the changes from 2015 to 2026 (resilience, supply chain management, sustainability, leadership responsibility) is evidenced only via a secondary source (TÜV), not checked against the ISO original text.
- Whether and how the PDCA cycle remains explicitly named in the 2026 version was not examined in this session.
- An earlier note in the architecture document ('ISO 9001 revision not checked') is resolved by this research step: the revision is published (16.09.2026), evidenced via two consistent secondary sources, not via the ISO original text.

## Sources

- [ISO 9001:2015 — Quality management systems — Requirements](https://www.iso.org/standard/62085.html), ISO, retrieved 24 September 2026
- [ISO 9001:2026 — Quality management systems — Requirements](https://www.iso.org/standard/9001), ISO, retrieved 24 September 2026
- [Overview & schedule: Revision of ISO 9001 coming in 2026](https://www.tuv.com/world/en/revision-iso-9001-2026.html), TÜV (TÜV Rheinland-Gruppe), retrieved 24 September 2026
- [ISO 9001:2026 Revision: Changes & Transition](https://www.dnv.us/assurance/Management-Systems/new-iso/transition/iso-9001-revision/), DNV, retrieved 24 September 2026

---
A professional assessment based on publicly available sources, not legal advice. Whether a given rule applies in your specific case depends on circumstances that are not fully captured here.
Source: SACOSI, Situational Awareness Consulting by Ivo Schönberner (https://sacosi.ch).
