QM Standards

ISO 9001 Explained: Structure, Requirements and Certification

Updated 27 August 2026. This article describes ISO 9001:2015, the edition currently in force. ISO 9001:2026 is due on 16 September 2026 as the sixth edition and will replace it. What changes is set out on the ISO 9001:2026 overview page; the clause-by-clause comparison is in ISO 9001:2026: every change in detail.

Few standards attract as many half-truths as ISO 9001 — and most of them live in beginner articles, which is exactly where least gets checked. Over a million organizations are certified. An annual management review is mandatory. The standard requires the PDCA cycle. None of those three statements survives a look at the text.

This article explains ISO 9001:2015 [1] as it is actually written: with clause references, with the limits of the available figures, and with the points where the common account is demonstrably wrong.

What ISO 9001 Is — and What It Does Not Certify

ISO 9001 sets minimum requirements for a quality management system and is deliberately sector-neutral: no product characteristic, no test method, no calibration interval. What it asks for is evidence that the organization consistently meets customer requirements and applicable statutory requirements, and continually improves its system.

The distinction matters in practice. A certificate does not attest that your incoming inspection catches every defect. It attests that there is a defined, controlled and evidenced way of doing it, that deviations from it are detected and handled, and that somebody evaluates whether the handling worked. What gets certified is the system, not the product.

A second point is stated wrongly almost everywhere. ISO certifies nobody. On its own certification page the organization writes that it does not perform certification or issue certificates, and does not permit anyone to use the ISO logo in connection with certification; certification is performed by external certification bodies, so a company cannot be certified by ISO [2]. The marketing phrase “ISO certified” is therefore strictly wrong: you are certified to ISO 9001, by a certification body.

How Widespread It Actually Is

The only defensible source on uptake is the ISO Survey, and it does not count organizations — it counts certificates and sites.

According to the ISO Survey 2023, there were 837,978 valid ISO 9001 certificates worldwide, covering 1,250,243 sites [3]. ISO defines both units itself: a certificate is the document issued by a certification body once the client has demonstrated conformity, and a site is a permanent location where an organization carries out work or provides a service [3].

Between those numbers and the question “how many companies are certified” sit two conversions nobody can perform. A group can hold three separate certificates for a plant, a sales company and a service subsidiary; a single multi-site certificate can cover thirty locations. No ISO figure for certified organizations exists — and the widespread claim of “over a million organizations” is wrong twice over: wrong unit, and the certificate count is below a million.

Then there is the robustness of the survey itself, which ISO flags: it is not a database; the data comes from certification bodies accredited by IAF members participating on a voluntary basis, and the level of participation fluctuates between editions, which can affect country-level results in particular [3]. For 2023 there is a concrete gap on top of that: China’s accreditation body did not participate, and ISO describes the impact as significant [3]. The 837,978 are a known undercount.

This article deliberately does not cite newer figures. Since 2025 the survey has been compiled from anonymized, aggregated CertSearch data and sits behind a login; the 2024 values in circulation cannot be verified at the publisher. They would not be comparable anyway: the move from voluntary reporting to bulk extraction is a methodology break, not growth.

Assessment: the honest answer to “how many are certified” is: well under a million certificates, collected with known gaps. Anyone giving you an exact, current number cannot evidence it.

The Structure: Ten Clauses

ISO 9001:2015 follows the High Level Structure, the common outline of modern ISO management system standards. That makes integrated systems with ISO 14001 or ISO 27001 easier, because clauses 4 to 10 carry the same headings there.

Clause What it covers Auditable?
1 Scope What the standard applies to and what it is meant to achieve no — contains no requirements
2 Normative references Refers to ISO 9000 as the accompanying document no
3 Terms and definitions Adopts the terms from ISO 9000 no — but decisive for interpretation
4 Context of the organization External and internal issues, interested parties, scope, processes (4.4) yes
5 Leadership Top management commitment, quality policy, roles and authorities (5.3) yes
6 Planning Risks and opportunities (6.1), quality objectives, planning of changes yes
7 Support Resources, competence, awareness, communication, documented information (7.5) yes
8 Operation From requirements determination through design and purchasing to control of nonconforming outputs (8.7) yes — the largest part
9 Performance evaluation Monitoring and measurement, internal audit (9.2), management review (9.3) yes
10 Improvement Nonconformity and corrective action (10.2), continual improvement yes

One detail separates carefully written texts from copied ones: not every subclause has a printed heading. 9.3 splits into 9.3.1 General, 9.3.2 Management review inputs and 9.3.3 Management review outputs, while 9.2.1 and 9.2.2 carry no heading at all — and neither do 10.2.1, 10.2.2, 8.7.1 and 8.7.2. Anyone citing “9.2.1 General” or “10.2.1 Reacting to nonconformity” is citing something the standard does not print. It is a reliable tell.

After clause 10 come the informative Annex A with sections A.1 to A.8, the informative Annex B, and the bibliography. Informative means explanatory, not auditable — a distinction that carries the rest of this article.

The Process Approach, Risk-Based Thinking — and Where PDCA Actually Sits

The process approach is the substantive backbone of the standard. It becomes normative in 4.4.1, items a) to h): determine the processes needed and their interactions, determine required inputs and expected outputs, sequence and criteria, resources, responsibilities, risks and opportunities, evaluation and improvement. Anyone who draws a process map but cannot name criteria and an owner per process does not meet 4.4.1, however handsome the map.

And here is the correction most introductory articles lack: PDCA is not a requirement of ISO 9001. The cycle appears only in the Introduction — in 0.3.2 and in Figure 2, which maps clauses 4 to 10 onto Plan, Do, Check and Act. In the normative part, clauses 1 to 10, PDCA does not occur once. Stated correctly: the standard presents its structure within the PDCA cycle; it does not require it. The difference is real in an audit — nobody can write a nonconformity for “PDCA not lived”.

The same applies to the seven quality management principles: customer focus, leadership, engagement of people, process approach, improvement, evidence-based decision making and relationship management. They are named in clause 0.2 of the Introduction but authoritatively described in ISO 9000, the standard for fundamentals and vocabulary — now in its 2026 edition, published in May 2026 [4].

Risk-based thinking, finally, sits in 6.1, in exactly two subclauses: 6.1.1 and 6.1.2. Risks and opportunities are treated together there; the 2015 edition has no separate clause for opportunities. 6.1.2 closes with a proportionality rule: actions shall be proportionate to the potential impact on the conformity of products and services. A supplier evaluation for a safety-relevant bought-in part may therefore look different from one for office supplies — as long as you can justify the gradation. This is precisely where the 2026 revision starts, by separating risks from opportunities.

“At Planned Intervals”: Who Sets the Interval

The second widespread misstatement concerns frequency. The word annual does not appear in ISO 9001:2015 even once. The phrase “at planned intervals” occurs exactly twice: in 9.2.1 for internal audits and in 9.3.1 for the management review. In both cases the organization determines the interval. What clause 9.3 requires beyond that — and why the review need not be a meeting — is covered in management review under ISO 9001 clause 9.3.

What the standard requires instead is planning with a rationale. 9.2.2 a) requires one or more audit programmes to be planned, established, implemented and maintained — including frequency, methods, responsibilities, planning requirements and reporting. Exactly three factors must be taken into account: the importance of the processes concerned, changes affecting the organization, and the results of previous audits. “Risks” is expressly not on that list, however many templates insert it there. How to build a defensible annual plan from this is covered in the guide to audit programme planning; the content to test per clause is in the internal audit checklist for ISO 9001.

Assessment: the annual rhythm is common practice and sensible in most organizations, not least because the management review hangs on financial-year figures. But it does not come from ISO 9001. It comes from the outside relationship: the certification body works to ISO/IEC 17021-1:2015, which requires a surveillance audit per calendar year [5]. The external cadence has been inherited into internal planning. A six-month cycle for critical processes and a two-year cycle for stable secondary processes would be equally permissible.

Part of the same pattern is what the standard expressly does not require, despite persistent claims: no quality manual, no quality plan, no documented procedure for internal audit or corrective action — Annex A.6 says so explicitly — and no management representative; clause 5.3 distributes those responsibilities across top management.

Documented Information: Maintain or Retain

When an experienced auditor wants to know whether someone has read the standard, they ask about this distinction. ISO 9001:2015 uses two different verbs for documented information, and they mean two entirely different things:

  • maintain — the live, currently valid specification. This is what earlier editions called a “document” or a “procedure”. There is one valid version; superseded versions are withdrawn.
  • retain — the historical record. This is what used to be called a “record”. It is frozen, and under 7.5.3.2 it must be protected against unintended alteration.

Annex A.6 states this distinction explicitly. It is cleanest to see in 4.4.2, where both verbs stand side by side in a single subclause: a) maintain documented information to support the operation of processes, b) retain documented information to have confidence that the processes are being carried out as planned. Process description and process evidence, in two consecutive letters.

In practice this decides which tool you need. A process description needs versioning, approval and a single valid state — requirements from 7.5.2 and 7.5.3.2. An audit record needs the opposite: immutability, attributability, a defined retention period. A filing system that treats both as “documents” will necessarily serve one of them badly.

The retention obligations are also more specific than usually quoted. 9.2.2 f) requires evidence of the implementation of the audit programme and of the audit results — two things in one letter; audit reports alone cover only the second half. 10.2.2 requires evidence of a) the nature of the nonconformities and any subsequent actions taken and b) the results of any corrective action. And 8.7.2 is a separate, standalone obligation for the control of nonconforming outputs. A single event can trigger all three. How to run that chain without gaps is covered in the article on handling findings and corrective action.

The Route to Certification, Briefly

Certification is not governed by ISO 9001 but by ISO/IEC 17021-1:2015, the standard for certification bodies [5]. In short: a two-stage initial audit, then a three-year certification cycle that begins with the certification decision, with two on-site surveillance audits and a recertification in the third year.

Two points belong here already, because they are regularly misstated. First, ISO does not certify [2]. Second, accreditation is not compulsory — ISO notes on the same page that a lack of accreditation does not necessarily mean a certification body is not reputable [2]. In practice customers and supplier approvals demand it almost always anyway. The full mechanism with clause references is described in The External Audit: Process and Certification Cycle.

What Changes with ISO 9001:2026

ISO 9001 is close to publication as the sixth edition, dated September 2026 [6]. The substantive focus: risks and opportunities split into separate subclauses, quality culture and ethical behaviour enter the leadership requirements, climate change moves out of Amendment 1:2024 and into clause 4 permanently, and for the first time the standard gains an informative Annex A. The detail is in the clause comparison for ISO 9001:2026, and the consequences for question catalogs in the article on the impact on internal audits.

One figure is still missing, and it is the most important one: the transition period. It is not set by ISO but by the accreditation side — since 1 January 2026 the Global Accreditation Cooperation Incorporated, into which the IAF and ILAC merged. In its published resolutions the relevant document still appears without a number [7]. The circulating “three years, deadline September 2029” is an expectation extrapolated from earlier revisions, not a published rule.

From the Standard to Audit Practice

The jump from the standard into daily work rarely fails on understanding the clauses. It fails on traceability. When a finding exists only as free text instead of being tied to a specific requirement such as 8.5.1 or 9.3.1, what is missing later is exactly the link the auditor and the management review need. qportal therefore models the clause structure as a hierarchical catalog of audit criteria — clauses up to three levels deep, linked to question catalogs and findings. An overview of the standard is on the ISO 9001 standards page.

Conclusion

ISO 9001 is considerably leaner than its reputation suggests — and considerably more precise than the introductory literature reports. It requires no manual, no management representative, no annual rhythm and no PDCA cycle. It requires you to know your processes, justify your intervals, distinguish the valid specification from the historical record, and evidence effectiveness.

Anyone who does not separate the normative text from the common interpretation builds effort nobody asked for — and overlooks the requirements that are genuinely in the text. Reading the standard costs an afternoon. Taking it second-hand costs more, permanently.

Sources

  1. ISO 9001:2015, Quality management systems — Requirements, published as DIN EN ISO 9001:2015-11, Beuth Verlag, Berlin. Adopted by CEN on 14 September 2015. Clauses cited here: 0.2, 0.3.2, 4.4.1, 4.4.2, 5.3, 6.1, 7.5, 8.7, 9.2, 9.3, 10.2 and Annex A.6. Normative wording is protected by copyright and is not reproduced.
  2. ISO: Certification. Official information page. https://www.iso.org/certification.html (accessed 2026-08-27)
  3. ISO (CASCO): The ISO Survey of Management System Standard Certifications – 2023 – Explanatory Note. September 2024. PDF, retrievable directly from the ISO document server: https://www.iso.org/sd/fetch/Fa2-37vSwgP8VQOJeyE081DlsqaYuxi47ADwUc8eHr4tFr-YPHMBPT8xK4Wu2u7s (accessed 2026-08-28). The overview page that linked to it was lost in ISO’s 2025 site restructuring and is reachable only in the archive: http://web.archive.org/web/20250604121021/https://www.iso.org/the-iso-survey.html (accessed 2026-08-27)
  4. ISO: ISO 9000:2026 — Quality management. Fundamentals and vocabulary. Edition 5, published 2026-05. https://www.iso.org/standard/9000 (accessed 2026-08-27)
  5. ISO/IEC: ISO/IEC 17021-1:2015 — Conformity assessment. Requirements for bodies providing audit and certification of management systems. Part 1: Requirements. Edition 1, published 2015-06, stage 90.60 (confirmed 2020). https://www.iso.org/standard/61651.html (accessed 2026-08-27)
  6. ISO: ISO 9001 — Quality management systems. Requirements. Edition 6, stage 60.00 (International Standard under publication), publication date 2026-09, ISO/TC 176/SC 2. https://www.iso.org/standard/88464.html (accessed 2026-08-27)
  7. Global Accreditation Cooperation Incorporated: Resolutions — including 2025-25 and 2025-29 on the continued force of the IAF Mandatory Documents, and 2025-18, which lists the relevant document as “IAF MD XX Transition Requirements for ISO 9001”, without a number. https://global-aci.org/en/global_aci-documents/resolutions/ (accessed 2026-08-27)

Certification-body, consultancy and content-marketing pages are not cited. ISO Survey figures are limited to the last edition ISO itself published; subsequent editions have sat behind a login since 2025, cannot be verified at the publisher, and are therefore not reproduced. Where this text goes beyond the documented evidence, it is marked as an assessment.

Frequently asked questions

How many organizations are certified to ISO 9001?
That figure does not exist. The ISO Survey counts certificates and sites, never organizations. As of 31 December 2023, ISO records 837,978 valid ISO 9001 certificates covering 1,250,243 sites — so certificates are below one million. One organization can hold several certificates, and one certificate can cover many sites. The common claim of "over a million organizations" confuses the unit.
Does ISO 9001 require an annual management review?
No. The word annual does not appear once in ISO 9001:2015. Clause 9.3.1 requires top management to review the quality management system "at planned intervals"; which intervals those are is the organization's decision, and it must be able to justify them. The same applies to internal audits under 9.2.1. An annual rhythm is common practice, not a requirement.
Does ISO 9001 require the PDCA cycle?
Not as a requirement. PDCA appears only in the Introduction — in 0.3.2 and in Figure 2, which maps clauses 4 to 10 onto the cycle. In clauses 1 to 10, the normative part, PDCA does not occur at all. The standard presents its structure within the PDCA cycle; it does not prescribe it as a method.
What is the difference between maintaining and retaining documented information?
Maintaining refers to the live, currently valid specification — what earlier editions called a document or a procedure. Retaining refers to the historical record, which stays frozen — what used to be called a record. Annex A.6 of ISO 9001:2015 states this distinction explicitly, and 4.4.2 places both verbs side by side in a single subclause: a) maintain, b) retain.
Do you need a quality manual for ISO 9001?
No. Annex A.6 states that ISO 9001:2015 requires neither a quality manual nor a quality plan nor documented procedures for internal audit or corrective action. The standard does not require a management representative either; clause 5.3 distributes those responsibilities across top management. A manual is permitted and often useful — it has not been mandatory since 2015.