Published: 23 September 2026  |  Reviewed: 23 September 2026

Direct answer: ISO 9001:2026 is now a published International Standard, released by ISO on 16 September 2026. It is therefore not a draft, project or proposed “2026 update”. For security buyers and ISO-certified organisations, the immediate task is to understand the final edition, confirm transition arrangements with the certification body and prepare evidence that operational controls work in practice.

The decision: treat ISO 9001:2026 as published, not as a proposal

As at 23 September 2026, ISO lists ISO 9001:2026 as the sixth and current edition of the quality-management standard, with status “Published” and a publication date of September 2026. ISO also records ISO 9001:2015 and its 2024 amendment as withdrawn. This corrects a common but now outdated framing: the revision was a project while the committee was developing drafts, but that development stage has ended.

It is also not quite right to call this the first change since 2015. ISO published ISO 9001:2015/Amd 1:2024, a one-page climate-action amendment, in February 2024. ISO 9001:2026 is the first full new edition since the fifth edition in 2015. That distinction matters in procurement documents, audit planning and supplier conversations: quote the edition and certificate scope rather than relying on a broad claim that a provider is simply “ISO 9001 certified”.

What has ISO verified about the new edition?

Buyers should avoid building requirements around commentary on earlier drafts. ISO’s published overview describes targeted changes intended to improve clarity and usability across organisations of different sizes, maturity and purpose. It identifies a greater emphasis on quality culture and leadership, separate treatment of risks and opportunities, and improved alignment with other ISO management-system standards. These are the published directions on which a conversation can be based; the detailed requirements remain in the standard itself.

For a security operation, the useful question is not whether a supplier can recite new terminology. It is whether its quality-management system connects the client’s requirements to controlled delivery: a defined scope, assignment instructions, competent people, records, review of issues and corrective action where something has not worked as intended. ISO says the standard covers, among other areas, organisational context, leadership, planning, support, operation, performance evaluation and improvement. The practical relevance will differ between a fixed corporate site, an event, door supervision or a close-protection engagement.

Do not assume a transition deadline

ISO states that certified organisations will need to transition within the timeframe set by their certification cycle and advises them to contact their certification body. It does not set a universal transition date on its public ISO 9001:2026 page. A security company should therefore obtain its own written transition plan from its certification body, including when its certificate reference must change, what will be sampled at surveillance or reassessment, and what evidence is expected. A buyer should ask the same question of a material security supplier, rather than treating a web claim or an old certificate as confirmation.

This is also the point to separate standards, certification and accreditation. ISO develops the standard; ISO does not certify organisations. An independent certification body issues a certificate, and accreditation concerns the competence of that certification body. Where UKAS-accredited management-system certification is material to a tender or supplier assurance process, UKAS CertCheck provides a public route to search and verify claims of UKAS-accredited certification. The certificate still needs to match the service and scope being bought.

A practical next-inspection checklist

Use the period before the next internal audit, surveillance visit or reassessment to test the working system rather than create a last-minute file set.

Prepare and test What good evidence looks like
Certificate, scope and transition plan Current certificate, the services/sites it covers, certification-body instructions and ownership of each transition action.
Client and site requirements Agreed scope, assignment instructions, roles, escalation routes and controlled changes to them.
People and competence Role-appropriate licence checks where required, vetting, training and briefing records, with expiry or refresh actions managed.
Service delivery records Attendance, patrol or activity records where applicable, incident reports, handovers and evidence that exceptions were reviewed.
Performance and improvement Internal-audit findings, client feedback, complaints or incidents, root-cause analysis where appropriate, corrective actions and follow-up.
Supplier control and continuity Due diligence for subcontractors or labour providers, responsibility for licensing and vetting, and records of approved changes.

Keep the review proportionate. A small, stable guarding contract will not generate the same records as a multi-location programme, but both should be able to show how requirements are understood, delivered, checked and improved. For licensable private-security work, buyers and providers should also verify that the individual holds the correct SIA licence for the role. The SIA register of licence holders can be searched using a licence number or relevant personal details. The role performed, rather than the job title alone, is important.

What to prepare before speaking to a security provider

Bring the operating question, not just a request for a number of officers. Set out the site or event, hours, expected activities, access points, client responsibilities, known vulnerabilities, reporting needs and the decisions that require escalation. Identify any roles that may be licensable, and ask how licences, vetting, training, insurance and any subcontracted supply will be checked. The SIA’s guidance for buyers of security recommends due diligence on insurance, relevant experience, assignment instructions, staff lists, screening and vetting, licensing, subcontracting and training; although written for events, these are useful questions to tailor to the service being procured.

For quality assurance, ask for the certificate reference, issuing certification body, current scope and transition approach to ISO 9001:2026. If a contract requires an SIA Approved Contractor, check the SIA register rather than assuming that all licensed providers hold that voluntary status. Agreement on records and access is equally valuable: decide in advance what the client needs to see, how incidents will be reported and how service changes will be authorised.

How SSS can support a controlled security service

SSS Official is certified to ISO 9001:2015 for its stated scope. As with other certified organisations, transition timing should be confirmed with the relevant certification body. For relevant engagements, the SSS Application can support agreed operational administration, including attendance, assignment instructions, patrol records, lone-worker capability, training and compliance records, incident reporting and client access to agreed rotas and records. It helps organise agreed information for review; it does not replace a client’s due diligence or create a legal determination.

To discuss a guarding, door supervision, event or protective-security requirement and the evidence that matters to your organisation, contact SSS Official. We can begin with the site context, service scope and assurance information you need.

Sources and further reading

This article is general information, not legal, certification, procurement or compliance advice. Requirements depend on the service, contract, certification scope and facts of the particular operation. Seek appropriate professional advice where needed.