Blog cover

Perry Johnson Registrars

Blog

ISO 9001:2026: What’s Changed (Not Much), and What Has Stayed the Same (A Lot)

8/3/2026
Group of businesspeople holding jigsaw puzzles, team solving and planning together

ISO 9001:2026: What’s Changed (Not Much), and What Has Stayed the Same (A Lot) A plain-language guide to the upcoming revision, from Perry Johnson Registrars, Inc. If you hold, or are pursuing, an ISO 9001 certification, you’ve likely heard about…

Read more

ISO 9001:2026: What’s Changed (Not Much), and What Has Stayed the Same (A Lot)

A plain-language guide to the upcoming revision, from Perry Johnson Registrars, Inc.

If you hold, or are pursuing, an ISO 9001 certification, you’ve likely heard about the upcoming 2026 revision. Perry Johnson Registrars, Inc. (PJR) recently hosted a webinar breaking down what’s on the horizon. The short version: change is coming, but it’s evolutionary, not revolutionary.

A Quick Refresher: Where ISO 9001 Comes From

ISO standards are developed by dedicated Technical Committees. For ISO 9001, that’s Technical Committee 176 (TC 176), which draws members from major industrialized nations, including the American National Standards Institute (ANSI).

A significant portion of the standard’s content is mandatory boilerplate defined by Annex SL, the shared structure that allows ISO 9001 to align with other management system standards.

Where Things Stand: Timeline Update

ISO/FDIS 9001 (Final Draft International Standard) was issued for review and approval voting in May 2026, the last formal step before publication. Earlier milestones:

  • Committee Draft released in April 2024
  • Draft International Standard (DIS) released in June 2025

Publication is expected in September or October 2026. Once published, existing ISO 9001:2015 certifications remain valid for three years.

What’s Staying the Same

The most reassuring takeaway from PJR’s analysis is how much is not changing. Specifically, ISO 9001:2026:

  • Maintains the familiar 10-section auditable structure and section titles used in ISO 9001:2015.
  • Keeps the same minimal documentation requirements; no procedures are mandated.
  • Preserves the process approach that has anchored ISO 9001 since the 2000 revision.
  • Retains the Plan-Do-Check-Act (PDCA) methodology.
  • Introduces no new substantive terminology or definitions beyond what already exists in the 2015 version.
  • Keeps every concept introduced in 2015 fully intact: Risk, Interested Parties, Internal/External Issues, Organizational Knowledge, and Manageent Accountability all remain.

What’s Actually Changing

PJR’s review of the FDIS found few substantive changes, but they’re worth understanding.

Climate Change Language

This isn’t new. A February 2024 amendment added climate change considerations to sections 4.1 and 4.2, and that language carries forward unchanged. Organizations must consider whether climate change is a relevant issue to their quality management system and be able to show the reasoning, even if the answer is “it isn’t relevant to us.”

The Rise of “Quality Culture”

The phrase “Quality Culture” now appears throughout the standard. The idea is straightforward: quality shouldn’t be a checklist exercise; it should be woven into how a company operates day to day. It surfaces in several auditable clauses:

  • Clause 4.1 ties “culture” to the existing concept of organizational “context.”
  • Clause 5.1.1 assigns Top Management responsibility for promoting and empowering a quality culture.
  • Clause 7.1.4 links quality culture to an organization’s environmental factors (social, physical, etc.).
  • Clause 7.3 requires organizations to ensure employees are aware of the quality culture.

“Quality Culture” appears in nine additional places within the FDIS, and final wording may shift before publication.

A Possible Tweak to Your Quality Policy

Clause 5.2.1(e) now requires that an organization’s quality policy “take into account the context of the organization and support its strategic direction.” Most companies already meet this, but it’s a good opportunity to revisit your policy and confirm it still fits.

Risk Triggers Get a Clearer Definition

Clause 6.1.2 now states that organizations must determine, analyze, and evaluate risks affecting their ability to consistently deliver conforming products and services. This clarifies original intent rather than introducing something new.

“Opportunities” Gets Its Own Clause

Previously bundled with Risk, “Opportunities” now has its own clause 6.1.3. The wording mirrors 6.1.2, but the message is clear: risks and opportunities are distinct, and organizations should be ready to explain how each is addressed.

Documented Information Language Shifts Again

ISO 9001:2015 replaced the plain terms “document” and “record” with “documented information,” distinguished only by the verbs “maintain” and “retain.” The 2026 revision doesn’t simplify this; it introduces new phrasing instead:

  • “…shall be available as documented information” implies a document requirement.
  • “Appropriate documented information shall be available as evidence of…” implies a record requirement.

The key word to watch for going forward is “evidence,” which is now the separator between the two.

Customer Communication Adds Contingency Planning

Clause 8.2.1 now requires organizations to communicate with customers about agreed-upon responsibilities for contingency actions, where relevant. Specific guidance is expected after publication.

Social Media as a Customer Satisfaction Input

A new note to clause 9.1.2 recognizes social media as a legitimate source for gauging customer perception. How organizations monitor and act on this will vary by industry and company size.

Other Notable Smaller Changes

  • Clause 5.3: Top Management must now assign responsibility for reporting on opportunities for improvement.
  • Clause 6.3 adds non-binding guidance on planning and executing changes effectively.
  • Clause 8.4.3 adds an “as appropriate” qualifier to purchase order information requirements.
  • Clause 10.2.1 clarifies (via a note) that customer complaints remain a potential, not mandatory, input to Corrective Action.

Annex A Guidance Expands Significantly

Annex A, the non-enforceable guidance portion of the standard, grows from roughly two pages to eleven and has been renumbered to align with the main clause numbers. Nothing in Annex A is auditable, but it now offers expanded guidance on structure and terminology, leadership and commitment, risks and opportunities, and management review intervals.

The Bottom Line: Minimal Disruption Expected

PJR’s conclusion is simple: the substantive changes are minimal, and organizations certified to ISO 9001:2015 should find the shift manageable. PJR does not anticipate changes to its audit process, including the Leadership Interview. A handful of new prompts may be added to audit documentation, but core auditing practices will remain consistent.

How Will the Transition Work?

A three-year transition period will begin once ISO 9001:2026 is formally published. In practical terms:

  • Any organization certified to ISO 9001:2015 after the 2026 standard publishes will receive a certificate valid for less than three years. If the standard publishes October 2, 2026, a company certified December 2, 2026 would receive a certificate expiring October 1, 2029.
  • PJR intends to offer ISO 9001:2026 audits within weeks of publication, prioritizing organizations whose certificates expire between October 2026 and January 2027.
  • Organizations with certificates expiring in 2027 will need to decide how to proceed; recertifying to ISO 9001:2015 first means the transition occurs during a surveillance audit.

PJR has not set a date for when it will stop offering ISO 9001:2015 certifications; that decision likely won’t be finalized until mid-2027.

Will Staff and Internal Auditors Need Training?

In most cases, yes, though the scope depends on how much your quality management system actually changes. At a minimum, PJR recommends awareness training plus an assessment of the standard’s impact on your processes and personnel. Many employees will notice little change day to day.

For internal auditors, the expectation is the same as with any required competency: your organization determines what’s needed. A seasoned team may be able to transition through self-study alone.

Looking Ahead

ISO 9001:2026 continues a standard with nearly 40 years of history. The publication date is still a few months away, but the direction is clear: organizations already doing quality management well won’t need to reinvent their systems. A thoughtful review of your quality policy, risk and opportunity processes, and documentation language will go a long way toward a smooth transition.

PJR will continue to share updates, articles, and webinars as ISO 9001:2026 moves toward publication, and we’re committed to making the transition as smooth as possible.

Contact Perry Johnson Registrars, Inc.
Website: www.pjr.com • Phone: (248) 358-3388 • Email: pjr@pjr.com

CMMC Phase 2 Is Paused. Your Cybersecurity Obligations Are Not.

7/31/2026
Data security on a tablet with touchscreen technology and a hand with a finger pointing at it

CMMC Phase 2 Is Paused. Your Cybersecurity Obligations Are Not. What the Department of Defense review means for contractors handling Controlled Unclassified Information (CUI) and why this is the wrong moment to slow down. The Department of Defense has temporarily…

Read more

CMMC Phase 2 Is Paused. Your Cybersecurity Obligations Are Not.

What the Department of Defense review means for contractors handling Controlled Unclassified Information (CUI) and why this is the wrong moment to slow down.

The Department of Defense has temporarily suspended implementation of CMMC Phase 2 while conducting a 60-day review of the program. Understandably, the announcement has raised questions across the Defense Industrial Base: What happens to our certification timeline? Do we still need to invest in compliance right now?

The timeline may be changing. The underlying requirements are not.

What Has Not Changed

Organizations that handle CUI are still required to meet NIST SP 800-171 and comply with applicable DFARS 252.204-7012 requirements. Self-assessments, accurate SPRS reporting where required, and strong day-to-day cybersecurity practices all remain essential to supporting government contracts.

– A pause in the certification process is not a pause in the obligation to protect sensitive information.

Check Your Contracts Before You Change Your Plans

It is also worth remembering that the Department of Defense is not the only party setting expectations. Some prime contractors continue to require third-party CMMC certification or assessments as a condition of doing business, and those contractual requirements may remain in effect regardless of the Phase 2 pause.

Before adjusting any compliance plan, review your active contracts and confirm your customers’ current expectations directly. A program-level pause does not automatically release you from a commitment you have already signed.

Use The Pause As An Opportunity

We encourage organizations to treat this review period as time gained rather than time off. Improving policies, implementing technical controls, training employees, and documenting processes will continue to deliver value regardless of how the CMMC program ultimately evolves, and every one of those efforts reduces real risk in the meantime.

Self-attestation Carries Real Weight

As certification timelines shift, many organizations may need to self-attest to their compliance with NIST SP 800-171. Because these attestations carry significant responsibility for company leadership, they should be supported by objective evidence and, wherever possible, an independent evaluation.

That is why we continue to recommend:

  • Readiness Assessments – to measure overall preparedness.
  • Mock Audits – to simulate a formal CMMC assessment.
  • NIST SP 800-171 Gap Assessments – to identify and address compliance gaps.

How PJR Can Help

For organizations preparing to meet third-party certification obligations, Perry Johnson Registrars (PJR) is here to help. While PJR is not yet an authorized C3PAO and does not currently perform CMMC certification assessments, we can help with readiness and pre-assessment checks that are led by Lead CMMC Certified Assessors (LCCAs) using a structured, audit-based approach.

An independent assessment provides confidence that your compliance claims are accurate, well documented, and ready to withstand scrutiny. Whether you are preparing for future CMMC certification, supporting a self-attestation, or meeting a prime contractor’s third-party assessment requirement.

Moving Forward With Confidence

Our team will continue monitoring developments and sharing updates as they become available. Whether you are preparing for future certification or strengthening your cybersecurity program today, PJR is here to help you move forward with confidence.

To discuss a Readiness Assessment, Mock Audit, or NIST SP 800-171 Gap Assessment, contact Perry Johnson Registrars, Inc.

Client Spotlight: BruckEdwards, Inc.

7/16/2026
BruckEdwards, Inc. logo

BruckEdwards, Inc. – Delivering Secure Solutions That Go Beyond Expectations For more than two decades, BruckEdwards has been helping federal and commercial organizations secure, modernize, and optimize their operations through innovative technology and consulting services. Headquartered in Reston, Virginia, the…

Read more

BruckEdwards, Inc. – Delivering Secure Solutions That Go Beyond Expectations

For more than two decades, BruckEdwards has been helping federal and commercial organizations secure, modernize, and optimize their operations through innovative technology and consulting services. Headquartered in Reston, Virginia, the company specializes in mission-focused solutions that empower clients to meet today’s evolving security and operational challenges.

BruckEdwards provides solution engineering and operational support for Identity, Credential, and Access Management (ICAM) programs, secure physical and logical access control solutions, cybersecurity, IT service management, and program management support. Their experienced team works closely with clients to implement, operate, and sustain solutions that strengthen security while improving operational performance.

The Value of Certification

Two people sitting at a table looking at a laptopISO certification has played an important role in BruckEdwards’ continued growth and success. Together, certification to ISO/IEC 20000-1:2018, ISO/IEC 27001:2022, and ISO 9001:2015 has strengthened operational maturity, enhanced quality management practices, and reinforced a culture centered on continuous process improvement.

By standardizing business processes and focusing on risk management, performance measurement, and ongoing improvement, BruckEdwards continues to deliver exceptional project outcomes for its clients. Certification has also positioned the company to pursue additional federal contract opportunities where ISO certification is often a key requirement.

A Decade of Partnership with PJR

BruckEdwards has partnered with Perry Johnson Registrars for the past 10 years and values the collaborative relationship that has developed throughout that time.

The team describes their experience with PJR as a true partnership, highlighting the professionalism, knowledge, and positive approach demonstrated throughout every audit. Beyond maintaining a thorough audit process, PJR’s auditors provide valuable insights that help support continual improvement across the organization.

What Sets BruckEdwards Apart

BruckEdwards believes its greatest strength is its people. Rather than simply designing solutions, their team actively implements, operates, and sustains them for clients across the United States.

With employees supporting projects nationwide from its headquarters in Reston, Virginia, the company has built a reputation for solving complex challenges through collaboration, technical expertise, and a commitment to customer success.

Their culture is driven by accountability, employee empowerment, and a “yes we can” mindset that encourages every team member to go beyond expectations while creating lasting value for clients and the communities they serve.

Looking Ahead

As technology and cybersecurity continue to evolve, BruckEdwards is focused on expanding its capabilities in cybersecurity, Identity, Credential, and Access Management (ICAM), Zero Trust solutions, program management, and data analytics.

By strengthening strategic partnerships, expanding contract vehicles, and continuing to invest in innovation, BruckEdwards remains committed to delivering high-quality solutions that help clients confidently meet the challenges of tomorrow.


BruckEdwards, Inc. logo

Company Information

BruckEdwards, Inc.
12355 Sunrise Valley Drive, Suite 340, Reston, Virginia 20191
Phone: (703) 286-5311

PJR and First Defense CMMC – What You Need To Know About CMMC

7/2/2026

What You Need To Know About CMMC In this video, Terry Boboige, President of Perry Johnson Registrars, discusses CMMC readiness with Shannon Craddock, PJR Programs and Accreditation Manager Steve Jurovic, First Defense CMMC Mark Debry, First Defense CMMC The conversation…

Read more

What You Need To Know About CMMC

In this video, Terry Boboige, President of Perry Johnson Registrars, discusses CMMC readiness with

  • Shannon Craddock, PJR Programs and Accreditation Manager
  • Steve Jurovic, First Defense CMMC
  • Mark Debry, First Defense CMMC

The conversation focuses on what defense primary contractors and subcontractors should know before beginning the assessment process.

Viewers will learn

  • Why CMMC matters for organizations that handle Controlled Unclassified Information (CUI)
  • The role CMMC 3rd-Party Assessment Organizations (C3PAOs) play in the process
  • Why many small and mid-sized contractors need to start preparing early

For companies working with the Department of Defense, this conversation gives a clear overview of what to expect and how to avoid costly delays.

Key Topics Covered

  • CMMC requirements for DoD contractors
  • CUI and cybersecurity readiness
  • C3PAO third-party assessments
  • Mock assessments and scoping
  • Documentation and evidence
  • Common assessment pitfalls

Ready for CMMC? Learn more and get your process started!

Perry Johnson Registrars, Inc. Achieves ANAB Accreditation for ISO/IEC 42001 Certification

6/23/2026
Close up of hand using tablet with AI showing an outline of a brain with chart and gear images

Perry Johnson Registrars, Inc. Achieves ANAB Accreditation for ISO/IEC 42001 Certification Perry Johnson Registrars, Inc. (PJR), a leading accredited certification body, is pleased to announce that it has been granted accreditation by the ANSI National Accreditation Board (ANAB) to provide…

Read more

Perry Johnson Registrars, Inc. Achieves ANAB Accreditation for ISO/IEC 42001 Certification

Perry Johnson Registrars, Inc. (PJR), a leading accredited certification body, is pleased to announce that it has been granted accreditation by the ANSI National Accreditation Board (ANAB) to provide accredited certification to ISO/IEC 42001, the international standard for Artificial Intelligence Management Systems (AIMS).

ISO/IEC 42001 is the world’s first certifiable management system standard specifically designed for organizations that develop, provide, or use artificial intelligence systems. The standard establishes a structured framework for the responsible governance of AI, helping organizations address risks, improve transparency, support regulatory compliance, and promote the ethical development and deployment of AI technologies.

With ANAB accreditation, PJR is now authorized to perform accredited ISO/IEC 42001 certification audits, providing organizations with confidence that their AI management systems have been evaluated by a globally recognized and impartial certification body.

“Earning ANAB accreditation for ISO/IEC 42001 is a milestone we are very proud of. AI governance is becoming increasingly important for organizations around the world, and we are excited to offer accredited certification services that help clients demonstrate responsible and trustworthy AI practices. This accreditation required a great deal of preparation, collaboration, and attention to detail. Proof that while AI may be able to automate many things, it still can’t replace a dedicated accreditation team and knowledgeable auditors.”

— Shannon Craddock, PJR Programs & Accreditations Manager

Achieving ANAB accreditation for ISO/IEC 42001 reflects PJR’s continued commitment to providing accredited certification services that help organizations build trust, demonstrate accountability, and strengthen AI governance. As artificial intelligence continues to reshape industries around the world, ISO/IEC 42001 provides organizations with a recognized framework for managing AI responsibly while supporting continual improvement and stakeholder confidence.
Organizations pursuing ISO/IEC 42001 certification can benefit from:

  • Demonstrating responsible AI governance
  • Strengthening risk management and oversight of AI systems
  • Increasing stakeholder confidence through accredited certification
  • Supporting compliance with emerging AI regulations and customer expectations
  • Integrating AI governance into existing management systems

PJR has decades of experience providing accredited management system certification services across a broad range of international standards. The addition of ISO/IEC 42001 further expands PJR’s ability to support organizations navigating rapidly evolving technologies and regulatory expectations.

Learn more about ISO/IEC 42001 certification or request a quote.

Printer-friendly version of this press release.