ISO 9001
Quality management systems — Requirements. Updated: September 29, 2026.
ISO 9001 is the most widely held certificate in the world, and the one most likely to appear as a hard requirement in a public tender. It is not about product quality in the sense of excellence. It is about consistency: doing what you said you would do, finding out when you did not, and fixing the reason.
What It Requires
The structure will look familiar if you have read ISO 27001, because they share the same high-level clause structure deliberately — context, leadership, planning, support, operation, performance evaluation, improvement. The content differs:
- Understand your customers' requirements, and confirm you can meet them before you agree to.
- Define your processes, their inputs and outputs, and who owns them.
- Control your suppliers, because their output becomes yours.
- Handle nonconforming work — what happens when something is wrong, and how you stop it recurring.
- Measure customer satisfaction, and act on what it says.
- Risk-based thinking throughout, rather than a separate risk register.
Why an IT Business Would Bother
Usually because a customer requires it. In public procurement across much of Europe it is a scoring criterion or a qualification threshold, and no amount of demonstrated competence substitutes for the certificate number on the form.
The secondary reason is more interesting: it is the cheapest management system to run first. The clause structure is shared with 27001, 22301 and 20000-1, so the internal audit process, the management review, the document control and the corrective action process are built once and reused. An organisation that already holds 9001 finds 27001 substantially cheaper than one starting cold.
The Honest Criticism
ISO 9001 has a reputation for producing documentation rather than quality, and the reputation is partly earned. A system built to satisfy an auditor, describing processes nobody follows, passes audits and improves nothing. The standard does not require that outcome — it is what happens when the certificate is the goal rather than the by-product. Worth saying plainly before anyone starts.
Getting Certified
The process is the same eight steps as 27001: gap analysis, define scope and processes, implement, operate long enough to produce records, internal audit and management review, Stage 1, Stage 2, certificate for three years with annual surveillance. Three to nine months is typical for a first certification, and less for a small organisation with well-understood processes. Check the current edition and any transition deadline before you begin.
Written from an infrastructure perspective. We are not a certification body, an audit firm or a legal adviser, and this is not legal advice. Standards are revised on a cycle — confirm the current edition before you commit.