Compliance6 clauses11 min read

What ISO 9001:2026 changes for maintenanceand what it doesn't

The sixth edition was published on 16 September 2026. Everyone is commenting on the new material. For a maintenance department, the clauses that decide the audit did not move.

MM
Melek Mehrez · September 19, 2026 · 11 min

Every quality newsletter published the same week is about what is new in the 2026 edition. If you run maintenance, the honest summary is shorter: nothing in it lands on a work order.

ISO 9001:2026 was published on 16 September 2026. It is the sixth edition and it replaces ISO 9001:2015, the edition that roughly 1.47 million certified organisations worldwide have been running against for the last decade. The revision is real, and some of it matters a great deal — to top management, to the people who write the quality policy, to whoever owns the risk register.

It matters much less to the maintenance department than the volume of commentary suggests. The clauses that cause maintenance-related findings are the same clauses that caused them in 2015, asking for the same evidence, in the same shape. The requirement that trips teams up has not changed since the last revision, and the teams it trips up were already failing it.

This article covers what actually changed, why the transition deadline you have read elsewhere is not yet an official date, which clauses touch equipment and what each one asks for, what an auditor does on the floor, and why the failure mode is almost never the software.

1

What actually changed in 2026

The harmonised structure survives intact: ten clauses, same numbering, same order. Anyone who knows their way around the 2015 edition will not get lost. Inside that frame, the substantive additions cluster in three places.

  • Leadership (5.1.1). Promoting a quality culture and ethical behaviour is now something top management is expected to demonstrate, not merely believe in. The list of leadership commitments grew from ten items to twelve. Clause 7.3 extends the same theme to awareness across the workforce.
  • Risks and opportunities (6.1). They are now handled separately, in new subclauses 6.1.2 and 6.1.3. In 2015 they shared one paragraph and, in practice, one register in which opportunities were a polite afterthought.
  • Context and change (4.1, 4.2, 6.3). Climate change moves from the 2024 amendment into the main text as something you must consider when determining context. Clause 4.2 adds an expectation to record which interested-party requirements the system actually addresses. Clause 6.3 expands the factors to weigh when planning a change.

Two structural notes worth knowing: clause 10 was reorganised from three subclauses into two, and the standard gains Annex A — around fifteen pages of guidance, the first annex in the history of ISO 9001. It is informative, not normative. It explains intent; it does not add requirements. The old Annex B was dropped.

Where this lands for maintenance

Read that list again with a maintenance planner's eyes. Quality culture, ethics, climate, opportunity registers, change planning — every one of them is a management-system obligation discharged in a document, a review or a policy. Not one of them changes what has to be written down when a technician finishes a job. That is the whole point of this article, and it is good news: your preparation work is the same work it was in 2015.

2

The transition deadline that does not exist yet

Search for the deadline and you will find September 2029, stated with confidence, in a dozen places. It is a reasonable guess. It is not, at the time of writing, a published date — and the reason why is more interesting than the date itself.

Publishing a standard and setting the transition rules are two separate acts by two separate organisations. ISO publishes the standard. The accreditation world decides how long certificates issued against the old edition stay valid. That second job belonged to the International Accreditation Forum — and the IAF ceased operations on 1 January 2026, merging with ILAC into a single body, Global Accreditation Cooperation Incorporated, which took over both mandates.

The state of play, as of late September 2026

The transition requirements document for ISO 9001 is listed among the work the new body inherited and is still developing. It had not been published when the standard came out. So there is currently no confirmed global deadline for ISO 9001:2026 — not September 2029, not any other date. Individual accreditation bodies may move first, as they have before.

The nearest precedent is the sister standard. ISO 14001:2026 was published on 15 April 2026, and UKAS issued a technical bulletin in May setting two dates: certification bodies had to transition their own accreditation by 30 April 2027, and all their certified clients by 30 April 2029. Three years, counted from publication. If ISO 9001 follows the same shape, late 2029 is where it lands — which is why everyone is writing September 2029.

What this means practically is unglamorous and reassuring. Your existing certificate stays valid. Nothing expires because a new edition exists. You are not late. The one concrete action worth taking now is to ask your certification body, in writing, what their transition schedule is and at which audit in your cycle they intend to assess you against the new edition — because they will schedule it around your surveillance and recertification visits, not around a press release.

That cycle is also the reason the rest of this article matters. An ISO 9001 certificate runs on a three-year cycle: an initial audit, two surveillance visits, then recertification. When an auditor pulls equipment history, the cycle is the natural depth of the question — which means the records you are keeping this month are the ones that will be sampled long after you have forgotten the job.

3

The equipment clauses, one number at a time

There is no "maintenance clause" in ISO 9001. There never was. Maintenance obligations are distributed across six or seven places, which is precisely why they are easy to half-satisfy: each one looks small on its own. Here is each of them, what it asks of a maintenance function, and whether the 2026 edition moved it.

ClauseWhat it asks of maintenanceChanged in 2026?
7.1.3InfrastructureDetermine, provide and maintain the infrastructure your processes need. This is where general equipment upkeep lives.Unchanged in substance
7.1.4Environment for the operation of processesProvide and maintain suitable operating conditions around the process — physical, and human.Linked to quality culture; no new equipment obligation
7.1.5.1Monitoring and measuring resourcesProvide resources fit for the measurement being made, keep them fit, and keep evidence that they are.Unchanged
7.1.5.2Measurement traceabilityCalibrate or verify at defined intervals against recognised measurement standards, and keep the record.Unchanged
7.5Documented informationThe evidence has to exist, be identifiable, and be retrievable when asked for.Wording unified; obligation identical
8.5.1Control of production and service provisionRun production under controlled conditions, which includes suitable infrastructure and environment.Unchanged
10.2Nonconformity and corrective actionReact when an equipment failure produces a nonconformity, and deal with the cause.Unchanged (clause 10 restructured from three subclauses to two)

The one wording change that looks bigger than it is

The 2015 edition used two verbs for documented information: you maintained documents, which describe what should happen and can be revised, and you retained records, which describe what did happen and must not be. The 2026 edition replaces both with a single unified phrasing across roughly a dozen clauses, and Annex A supplies the key for telling which sense is meant.

If you keep maintenance records, this changes your vocabulary and nothing else. A completed job still has to leave evidence behind; that evidence still has to be findable; an auditor still has to be able to take your word for none of it. Anyone telling you that the documentation burden has shifted is reading a verb change as a policy change.

The distinction that produces real findings

The trap in this list is not novelty, it is 7.1.3 versus 7.1.5. A pump and a pressure gauge are both equipment, and a maintenance system that treats them identically will satisfy one clause and fail the other.

7.1.3 — the pump
  • • A maintenance schedule, followed
  • • Evidence the planned work happened
  • • Reasonable judgement about intervals
  • • No external certificate required
7.1.5 — the gauge
  • • A calibration interval, defined and met
  • • Traceability to recognised standards
  • • Identification of calibration status
  • • A documented decision when it drifts

Incomplete or missing calibration records are consistently among the most common ISO 9001 findings, and the shape is almost always the same: an interval that lapsed, an instrument bought last year that nobody added to the programme, or a certificate that does not establish traceability. None of that is hard. It is simply the part that does not announce itself until an auditor asks.

4

What the auditor actually asks for

There is a persistent fantasy about the audit day in which someone evaluates your maintenance strategy — your criticality analysis, your preventive-to-corrective ratio, the sophistication of your planning. That is a reliability consultant. It is not an ISO 9001 auditor.

What an auditor does, according to auditors themselves, is far more physical. They walk the floor. They notice equipment while they are walking — and what draws the eye is the machine that looks worst: the visible leak, the temporary fix that outlived its temporariness, the unit that is clearly older than its neighbours. Then they ask for its maintenance plan, and then they ask for proof that the plan was followed.

The classic question put to an operator holding an instrument is not about the standard at all. It is: how do you know this thing is accurate?

An auditor cannot read everything and does not try to. They sample. The logic of sampling is what makes the worst-looking machine the natural pick: if the records hold up for the asset you have most plausibly neglected, the auditor can reasonably extend that confidence to the rest. If they do not, the sample has told them something about the system, not about one pump.

And the request, when it comes, is almost disappointingly small. Show me this asset's history. Five fields answer it completely: the equipment, a real date, who intervened, what was done, and whether it was planned work or a breakdown. Nothing about MTBF. Nothing about strategy. Five fields, across the certification cycle.

Here is the uncomfortable part

Every CMMS on the market produces those five fields. All of them. It is the minimum viable data model of the category — a work order that did not record what equipment, when, by whom and what kind would not be a work order. The capability has never been the constraint.

5

Why teams still fail, with the software right there

If the requirement is five fields and every tool emits five fields, the failures should not happen. They happen constantly. The reason is not capability and it is not discipline. It is arithmetic.

Most maintenance software is priced per named user. That is a perfectly defensible commercial model, and this is not an argument about whether vendors deserve to be paid. It is an argument about what that model does to an audit trail, because the effect is mechanical and nobody chooses it deliberately.

Run the numbers the way a maintenance manager runs them. A budget clears for a handful of seats — say three to five. Who gets them? Obviously the manager, the planner, the supervisors: the people who schedule work, pull reports and answer to management. That is the correct allocation. Every one of those seats is justified.

Now count the people who are not on that list. The twenty technicians who open the cabinet, replace the bearing, top up the oil and close the job. They keep working the way they always have: a notebook, a printed sheet on a clipboard, a message to the supervisor at the end of the shift. Somebody transcribes it later. Sometimes.

What transcription does to the five fields

  • The date becomes the date of transcription, not of the work.
  • Who intervened becomes whoever typed it in — the supervisor, not the technician.
  • What was done becomes a summary of a summary, written by someone who was not there.
  • Planned or breakdown gets assigned from memory, days later.
  • • And some jobs never get transcribed at all, because nothing in the process fails when they do not.

Four of the five fields degrade, and the fifth goes missing entirely on the jobs nobody wrote up. The system still contains records. They still look like records. They simply cannot survive the one question an auditor asks when a date looks suspiciously tidy: who wrote this, and when?

Notice that nothing in this story is negligent. Every decision was rational. The budget was finite, the seats went to the people with the strongest claim on them, the supervisors did extra work to keep the system populated. A sound budgeting decision made the majority of the workforce untraceable — and the audit trail broke on the exact machine an auditor was always going to walk up to, because the worst-looking asset is also the one that gets the most unplanned attention from the people who are not in the system.

This is worth saying plainly to whoever owns the budget: the coverage question and the licence question are the same question. A tool that ten percent of the maintenance workforce can log into produces an audit trail with ninety percent of the work missing, no matter how good the tool is.

6

The five fields to start keeping now

Whatever your transition date turns out to be, the history that will be sampled at it is being created this week. These five fields, captured by the person doing the work, at the time they do it, are the whole requirement.

Equipmentasset tagDateof the workWhonamed personWhatone written linePlanned?PM or breakdownBreak any one link and the chain stops being evidence.
1The equipment

A unique identifier that appears the same way every time — the asset tag or the nameplate reference. Not "the pump in bay B".

2A real date

The date the work happened, not the date someone typed it up. These diverge the moment recording is deferred, and the gap is what an auditor notices.

3Who did it

A named person. "Maintenance" is not an answer, because the follow-up question is always whether that person was competent for the task.

4What was done

One written line is enough. It has to be written, though — an auditor cannot sample a memory.

5Planned or breakdown

Preventive or corrective. This single flag is what lets anyone judge whether the maintenance plan is being followed or quietly abandoned.

Two practical additions that cost nothing and save the follow-up question. Keep instruments on a separate list from machines, with intervals rather than schedules — that is the 7.1.3 / 7.1.5 line, drawn once. And make sure whatever holds these records can tell you who entered a line and when, because the difference between a record and an assertion is that a record knows its own provenance. You can read more about how we treat that in the audit log documentation.

If you want the wider compliance picture — LOTO, permits and inspection evidence, which follow exactly the same logic under a different standard — we covered it in HSE compliance that exists only on paper, and the reporting side in the maintenance KPIs that lie.

7

What to do with all this

The 2026 edition is a genuine revision and your quality manager has real work ahead — the culture and ethics expectations under 5.1.1 and 7.3, the split registers under 6.1, climate in the context analysis. Help them where you can. That work is theirs.

Maintenance has a shorter list. Write to your certification body and ask when they will audit you against the new edition, since no global deadline has been published. Check that your instruments sit on a calibration programme with live intervals and traceable certificates, because that is where findings actually come from. Then look honestly at how many of the people who touch your equipment can record what they did, at the moment they did it.

That last one is the only question on the list where the answer is likely to be uncomfortable — and it is the only one that was already true in 2015.

In the same series

If the constraint is seats, not software

FreeMaint has a free Core tier with unlimited users, and the paid tiers are priced per company rather than per seat — so the number of technicians who can record their own work is never a budget decision. Today it runs across more than 5,600 organisations in 141 countries, tracking over 114,000 assets.

Frequently asked questions

Does ISO 9001:2026 require maintenance software?

No. ISO 9001 has never named a tool, and the 2026 edition does not either. It is technology-neutral: it requires that evidence exist and be retrievable when an auditor asks. A paper logbook satisfies the requirement in principle. What software changes is not compliance but coverage — whether the people who actually touch the equipment can record what they did at the moment they did it.

What is the ISO 9001:2026 transition deadline?

As of late September 2026 there is no published global deadline. Publication of the standard and the accreditation-side transition rules are two separate acts. The body that used to publish those rules, the IAF, ceased operations on 1 January 2026 and merged with ILAC into Global Accreditation Cooperation Incorporated, which had not released the ISO 9001 transition requirements document at publication. A three-year window is widely expected, by analogy with ISO 14001:2026 where UKAS set April 2029 for certified clients, but no authority has confirmed a date for ISO 9001. Ask your certification body in writing rather than trusting a date you read in an article.

Which ISO 9001 clauses cover equipment maintenance?

Maintenance is not confined to one clause. Clause 7.1.3 covers infrastructure, which is where general equipment upkeep sits. Clause 7.1.4 covers the environment in which processes run. Clause 7.1.5 covers monitoring and measuring resources, with 7.1.5.2 on measurement traceability — that is calibration, and it is audited far more strictly than general maintenance. Clause 8.5.1 requires production to run under controlled conditions, including suitable infrastructure. Clause 7.5 governs the documented information you keep as evidence, and clause 10.2 governs what you do when equipment failure causes a nonconformity. None of these changed in substance in the 2026 edition.

Is an Excel spreadsheet enough as maintenance evidence for ISO 9001?

Formally yes — the standard does not prescribe a format, and plenty of certified sites pass with spreadsheets. The practical limits show up under questioning, not in the clause. A spreadsheet cell does not record when it was written or by whom, and it can be edited afterwards without leaving a trace. So the auditor cannot distinguish a record written on the day of the work from one reconstructed the week before the audit, and neither can you. That is not a compliance failure by itself, but it is why spreadsheet-based evidence tends to generate follow-up questions that well-kept records do not.

What are the most common maintenance-related ISO 9001 nonconformities?

Calibration records under clause 7.1.5 are the classic finding: intervals that have lapsed, a new instrument that was never added to the calibration programme, or a certificate with no traceability to recognised measurement standards. A close second is the confusion between clause 7.1.3, which covers general equipment maintenance, and clause 7.1.5, which covers measuring devices — treating a gauge like a pump means it gets a maintenance schedule instead of a calibration interval.

Article by Melek Mehrez, founder of FreeMaint. See all articles.