ISO 9001 — Quality Management

The quality management standard, and a frequent hard gate on government and corporate tenders. ISO 9001:2026, the sixth and current edition, was published on 16 September 2026.

ISO, through technical committee ISO/TC 176/SC 2. Certification is issued by accredited certification bodies.

What it is

ISO 9001 is the international standard for a Quality Management System. It governs how an organisation consistently delivers what it promised: how work is planned, who owns each process, how problems are captured and corrected, and how the organisation demonstrates it improves rather than merely intends to.

It applies to any organisation delivering anything — product, software, professional services, construction, logistics. The requirements are deliberately process-agnostic, which is why it is the most widely held management system certificate in the world.

ISO 9001:2026 is now published

ISO 9001:2026 was published on 16 September 2026 as the sixth edition of the quality management standard. ISO describes it as a targeted update that improves clarity and usability while keeping ISO 9001 relevant to current organisations and stakeholder expectations.

ISO's published summary highlights clearer attention to quality culture and leadership, separate treatment of risks and opportunities, and better alignment with other ISO management system standards. Organisations should assess the issued standard against their current quality management system rather than rely on earlier draft summaries.

Existing ISO 9001:2015 certificates need to move through a formal transition. The applicable timing, audit route and availability of ISO 9001:2026 certification should be confirmed with the appointed certification body. A universal transition deadline has not yet been confirmed.

What that means for you now

If you are starting a programme now, use ISO 9001:2026 as the current requirements baseline and confirm with your selected certification body when it can audit against the new edition. If that body is still completing its own transition, Soveriq can sequence the implementation so the management-system work remains usable across the changeover.

Who it's for

Almost always a procurement requirement rather than an internal ambition.

Organisations bidding for government work

ISO 9001 is a frequent hard gate on federal, state and local tenders — the box you tick to be allowed to bid at all. This is the most common driver we see.

Suppliers into large corporate supply chains

Construction, defence, mining, manufacturing and infrastructure primes routinely flow quality requirements down to subcontractors.

Managed service providers and IT vendors

Usually alongside ISO/IEC 20000-1 and ISO 27001, to evidence disciplined and repeatable delivery across a panel application.

Organisations outgrowing informal process

Where the founders can no longer personally hold the standard of delivery in their heads, and rework has started to cost real money.

Why implement it

  • Tender eligibility. The dominant reason Australian organisations certify. It is pass/fail, and without it a submission is frequently not scored at all.
  • It reduces the cost of rework. A functioning nonconformance and corrective action process is the difference between fixing a problem once and fixing it every quarter.
  • It survives staff turnover. Documented process means capability sits in the organisation rather than in the head of whoever has been there longest.
  • It makes the complaint loop visible. Complaints get logged, analysed and closed rather than absorbed informally by whoever happened to take the call.
  • Start with the current requirements. ISO 9001:2026 is now published, so new implementation work can be mapped to the issued standard. Audit timing still depends on the selected certification body's readiness and transition arrangements.
  • It shares the spine. Under Annex SL it reuses the same context, leadership, internal audit and management review as ISO 27001, so certifying both is far cheaper than two separate programmes.

How implementation works

Four to seven months is typical — often the fastest of the ISO management system standards, because most organisations already run the underlying processes informally.

1. Gap assessment

Review existing documentation, records and actual practice against the standard. Many organisations already do most of what is required and have simply never evidenced it.

2. Scope and process mapping

Identify the processes making up the QMS, their sequence and interaction, and assign an owner to each. Process ownership is where first attempts are usually weakest — a process everyone contributes to and nobody owns will not survive an audit.

3. Risk, opportunity and quality objectives

Determine what could stop the organisation meeting requirements, and set measurable objectives that mean something operationally rather than a poster in reception.

4. Build the controls and records

Quality policy, documented process descriptions, nonconformance and corrective action, supplier and purchasing control, competence records, customer feedback and complaint handling, change control.

5. Operate the system

Two to three months. The QMS must generate records — closed corrective actions, completed reviews, handled complaints. An auditor tests the process by following real cases through it end to end.

6. Internal audit and management review

Both mandatory before Stage 2.

7. Stage 1 and Stage 2 certification audit

How Soveriq helps

Soveriq builds the quality management system inside the tools you already run, so process documentation and records sit where the work happens rather than in a parallel compliance system nobody opens between audits.

Where an ISO 9001:2015 certificate is transitioning, Soveriq maps the issued 2026 requirements against the existing management system, closes the evidence gaps and prepares the organisation for the route confirmed by its certification body.

On internal audit. Where Soveriq has built your management system, we do not then audit it and present that as an independent internal audit. What we provide is readiness validation, labelled as such. Where an independent internal audit is needed after a Soveriq build, it is performed by someone independent of that build and disclosed to you in writing.

Clear roles through certification. Soveriq prepares the quality management system, evidence and organisation for certification. The certificate and final certification decision come from an independent certification body, keeping implementation and certification roles clear. Soveriq supports your team through Stage 1 and Stage 2 without pre-empting that independent decision.

What the engagement looks like

  • Module 01 — Gap analysis. Review of existing process documentation and records against the standard.
  • Module 02 — Build. Process mapping and ownership, quality policy and objectives, nonconformance and corrective action, supplier control, complaint handling.
  • Module 03 — Internal audit, subject to the impartiality position above.
  • Module 04 — Audit representation through Stage 1 and Stage 2.
  • Module 05 — Continuous compliance, including ISO 9001:2026 transition support aligned with the appointed certification body's requirements.

Price floors are published on the pricing page. Certification body fees are separate and paid directly to that body.

Common questions

Should we wait for ISO 9001:2026?

No. ISO 9001:2026 was published on 16 September 2026 and is now the current edition. If certification is time-critical, ask your selected certification body when it can audit against the new edition and what route applies during its changeover. Do not assume every certification body is ready on the same date.

What if we are starting from scratch right now?

Build against the published ISO 9001:2026 requirements. Before setting the certification timetable, confirm when your selected certification body will accept an application and audit against the new edition. If there is a short readiness gap, the implementation can still proceed while the audit sequence is agreed.

What actually changes in the 2026 edition?

ISO describes the sixth edition as a targeted update that improves clarity and usability. Its published summary highlights stronger attention to quality culture and leadership, separate treatment of risks and opportunities, and better alignment with other ISO management system standards. A proper gap assessment should use the issued standard, not an earlier draft or summary.

Can we certify ISO 9001 and ISO 27001 together?

Yes, and it is considerably cheaper than two separate programmes. They share Clauses 4 to 10 under Annex SL, so context, leadership, internal audit and management review are built once and serve both.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope