ISO 9001 · From the Auditor's Desk

ISO 9001:2026 publishes on 16 September. Here's what happens to your 2015 certificate.

The short answer is: nothing, on the day. The longer answer is a deadline you have to work out for yourself — and for most UK organisations it lands well before 2029.

Jason Misters · IRCA® Registered Principal Auditor · 29 August 2026

On 16 September 2026, ISO 9001:2026 is published. In the weeks since the FDIS was approved in July, the question I have been asked most often by certified clients is some version of the same worry: “does my certificate stop being valid?”

It does not. Nothing happens to your ISO 9001:2015 certificate on publication day. You do not need to do anything that week, and any consultant telling you otherwise is selling urgency rather than advice.

But a clock does start. The transition window opens on publication and is expected to run for around three years. And here is the part that catches people out: the deadline that applies to you is not the end of that window. It is the last audit in your own certification cycle that lands with enough room before it. For a lot of organisations that is 2028, not 2029 — and for some it is earlier still.

A note on certainty

The publication date is settled — the FDIS was approved on 15 July 2026 and publication is confirmed for 16 September 2026. The transition arrangements are a separate matter: the length of the window and what counts as a valid transition audit are set by the International Accreditation Forum (IAF), applied by accreditation bodies such as UKAS, and implemented by your certification body. Three years is the well-established norm and the sensible planning assumption. Confirm your own dates with your certification body rather than with a blog — including this one.

What actually happens on 16 September

Four things, none of which require you to move that day:

  • Your certificate stays valid. Unchanged, on its existing expiry date, with your existing audit schedule.
  • The transition window opens. Expected to run roughly three years, to around September 2029.
  • Certification bodies cannot certify to the new edition immediately. Each one needs its own accreditation scope extended before it can issue 2026-edition certificates. That typically takes some months after publication — so the practical start of transitions is later than the formal one.
  • The 2015 edition is withdrawn at the end of the window. Certificates to it cease to be valid at that point.

That third point matters more than it looks. It compresses a three-year window into something closer to two and a half years of usable capacity, and it does so at the front end — where the queue is shortest.

Your real deadline is your last audit before the window closes

ISO certification runs on a three-year cycle: a recertification audit, then two annual surveillance audits, then recertification again. You do not book a special appointment to transition. You transition at one of the audits you were already having, usually with some extra audit time added.

So work backwards. You need to hold a 2026-edition certificate before the window closes — not merely to have started the process. That means the transition audit, the closure of any nonconformities raised at it, and the re-issue of the certificate all have to complete inside the window. Realistically that is a few months of margin, not a few days.

Here is how that maps onto a typical UK certification cycle:

If your ISO 9001:2015 certificate expires… Your recertification audit lands… What that means in practice
During 2027 Around mid-2027 Your certification body may not be accredited for the 2026 edition yet. Expect to recertify to 2015, then transition at a surveillance audit in 2028. Ask them now which it will be.
During 2028 Around mid-2028 This is your natural transition audit, and the most comfortable position to be in. Prepare through 2027 and it is a routine update.
During 2029 Around mid-2029 Tight, and squarely in the crush. Book the slot early and treat your 2028 surveillance audit as the dry run.
During 2030 or later After the window has closed You cannot wait for it. You must transition at a surveillance audit in 2028 or 2029 regardless of what your certificate says.

That last row is the one that bites. A certificate with a 2030 expiry date printed on it feels like permission to ignore all of this until 2029. It is not. The transition deadline is set by the window, not by your certificate.

Why “we'll do it at the 2029 recert” is a trap

It is a reasonable-sounding plan, and it is the plan almost everyone defaults to. That is precisely the problem.

Transitions cluster hard at the end of the window. Certification body capacity is finite — there is a fixed number of accredited auditors and a fixed number of audit days in a year. When the majority of certified organisations all want their transition audit in the final twelve months, slots book out, dates slip, and the flexibility you are relying on quietly disappears. I watched this happen through the 2015 transition, and the organisations that struggled were not the unprepared ones. They were the ones who had left themselves no room to reschedule.

And the downside is asymmetric. If you miss the window, you do not get a transition audit — you get a new initial certification: Stage 1, Stage 2, the full sequence. More cost, more time, and a gap in your certified status.

That gap is the real damage. It is not the audit fee. It is the PQQ that lands in the middle of it and asks for your current certificate number.

What your certification body will want to see

A transition audit is not a re-run of your whole system. The auditor is looking for evidence that you have understood what changed and acted on it. In practice:

  • Context of the organisation, revisited. Clauses 4.1 and 4.2, including the climate change amendment issued in 2024. If you have not closed that off, do it now — see the note below.
  • Evidence that leadership has actually engaged. Management review minutes are the natural home for this, and the easiest thing to produce if you started early.
  • An internal audit programme that has covered the changed requirements at least once before your transition audit. Auditors notice when the internal audit schedule has not caught up with the standard.
  • Updated documented information where the changes actually bite — not a rewritten manual for its own sake.
  • Awareness and competence. Evidence that the people running the processes have been briefed on what changed.

The one thing to do this month

If you have not yet addressed the 2024 climate change amendment to clauses 4.1 and 4.2, close it now. This is not a 2026 requirement waiting in the wings — it has been mandatory since February 2024, it applies to your current certificate, and it is one of the most commonly raised findings I see. Going into a transition audit with it still open is an avoidable own goal.

What to do in the next 90 days

None of this requires the published standard in your hands. All of it is worth doing before the end of the year:

  1. Find your certificate expiry date and write it down. It is on the certificate PDF or in your certification body's client portal. Surprisingly few people know it from memory.
  2. Map your audit cycle. List every surveillance and recertification audit due before the window closes.
  3. Choose your transition audit from that list — and tell your certification body that is your intention. Getting into their planning early is most of the battle.
  4. Confirm the 2024 climate amendment is closed in your context analysis and risk register.
  5. Add “ISO 9001:2026 transition” as a standing management review input so leadership engagement is evidenced as it happens, rather than reconstructed afterwards.
  6. Buy the standard when it publishes and run a proportionate gap assessment. Read it before you change anything.
  7. Do not rewrite your manual. Change what the standard requires you to change. Auditors are not impressed by volume, and a rewrite introduces errors into a system that currently passes.

How PICMS helps

The slow part of any transition is not understanding the standard. It is proving, clause by clause, what your existing system already satisfies — and finding the handful of places where it genuinely does not.

PICMS maps your live documents and records against every ISO 9001 clause, so the gap assessment stops being a fortnight of manual cross-referencing and starts being a report you read. When the 2026 clause set lands, the same mapping shows you what moved. And because the evidence is already linked to clauses, the management review minutes and internal audit records your certification body will ask for are a by-product of running the system rather than a separate exercise before the audit.

If you want the wider picture of what is changing in the standard itself, the companion piece is here: ISO 9001:2026 transition guide — what's changing and how to prepare.

Frequently asked questions

Does my ISO 9001:2015 certificate expire on 16 September 2026?

No. Publication of ISO 9001:2026 does not invalidate any existing certificate. Your ISO 9001:2015 certificate remains valid through the transition window, which is expected to run for three years from publication. What changes on 16 September 2026 is that the clock starts — not your certification status.

When can I actually be certified to ISO 9001:2026?

Not necessarily on publication day. Your certification body must first have its own accreditation scope extended by its accreditation body — UKAS in the UK — to certify against the new edition, and that typically takes some months after publication. Ask your certification body directly when they expect to be able to offer transition audits, because it shapes your whole plan.

My ISO 9001 certificate runs to 2030 — am I safe until then?

No, and this is the most common misconception I encounter. The transition deadline is set by the end of the transition window, not by your certificate expiry date. If your certificate runs past the end of the window, you must still transition at an audit before the window closes — normally a surveillance audit — or the certificate ceases to be valid.

What happens if I miss the ISO 9001:2026 transition deadline?

Your certification to the 2015 edition ceases to be valid when the window closes. Regaining certification is normally treated as a new initial certification — a full Stage 1 and Stage 2 audit rather than a transition audit — which costs more, takes longer, and leaves a visible gap in your certified status that tender and PQQ questionnaires will ask about.

Can I transition at a surveillance audit or does it have to be recertification?

Transition is commonly carried out at either a surveillance audit or a recertification audit, usually with additional audit time added to cover the changed requirements. The exact arrangement is set by your certification body under the applicable IAF transition rules — confirm the option and the extra duration with them before you plan around it.

Does transitioning cost extra?

Normally yes, in the form of additional audit time on top of your scheduled surveillance or recertification audit. The amount varies with the size and complexity of your system. Ask your certification body for an indication early — it is a budget line for next year, not a surprise for 2029.

How do I work out my own transition deadline?

Start from your certificate expiry date, map the surveillance and recertification audits that fall before the window closes, and pick the last one that still leaves room to close nonconformities and have the certificate re-issued inside the window. That margin should be measured in months. The table above covers the common cycles.

Know your transition date before your competitors know theirs.

PICMS maps your existing documents and records against every ISO 9001 clause — so your gap assessment is a report you read, not a fortnight of cross-referencing, and the evidence your certification body wants is already linked and ready.

Start a Free Trial Book a Demo