iso27001partnersUK certification, costed Get a cost estimate

ISO 27001 vs ISO 9001: what each certifies, and what changed in ISO 9001:2026

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 9 min read
6 primary sources cited on this page. How we check what is on this site
New this month ISO 9001:2026 is published

“This sixth edition cancels and replaces the fifth edition (ISO 9001:2015), which has been technically revised. It also incorporates the Amendment ISO 9001:2015/Amd 1:2024.” — ISO 9001:2026, foreword. ISO/IEC 27001 remains at the 2022 edition.

ISO 9001 and ISO 27001 can sit side by side in the same supplier questionnaire. They look alike because they share a skeleton, and they certify completely different things. This page compares them from the text of each standard, with the audit-day figures the certification body starts from.

ISO 27001 and ISO 9001, side by side

ISO/IEC 27001:2022 and ISO 9001:2026 compared
ISO/IEC 27001ISO 9001
Current editionISO/IEC 27001:2022ISO 9001:2026 (sixth edition, 2026-09)
What it managesInformation security — confidentiality, integrity and availability of information in scopeQuality — consistently meeting customer and applicable statutory and regulatory requirements
Scope, in its own words“The requirements set out in this document are generic and are intended to be applicable to all organizations, regardless of type, size or nature.”“All the requirements of this document are generic. This document is applicable to any organization, regardless of its type or size, or the products and services it provides.”
StructureAnnex SL high-level structure, clauses 4–10The harmonized approach, clauses 4–10
Annex A93 controls you compare your risk treatment againstExplanatory only — “It does not contain any additional requirements.”
Signature documentThe Statement of Applicability (6.1.3 d)None equivalent
RiskA defined information security risk assessment and risk treatment process (6.1.2, 6.1.3)Risks and opportunities, now considered separately (6.1.2, 6.1.3 in the 2026 edition)
Initial audit at 25 people7 days3 days
Audit-time rulesISO/IEC 27006IAF MD 5
Certified byAn accredited certification body, under ISO/IEC 17021-1An accredited certification body, under ISO/IEC 17021-1

The shared structure is deliberate. ISO/IEC 27001:2022 says: “This document applies the high-level structure, identical sub-clause titles, identical text, common terms, and core definitions defined in Annex SL of ISO/IEC Directives, Part 1, Consolidated ISO Supplement, and therefore maintains compatibility with other management system standards that have adopted the Annex SL.” ISO 9001:2026 says it applies the same harmonized approach, whose “intention is to support alignment and facilitate the integration” of more than one standard.

What ISO 9001 is for

ISO 9001:2026 specifies requirements for a quality management system when an organisation:

ISO 9001:2026, clause 1 (verbatim)
When an organisation
aneeds to demonstrate its ability to consistently provide products and services that meet customer and applicable statutory and regulatory requirements
baims to enhance customer satisfaction through the effective application of the system, including processes for improvement of the system and the assurance of conformity to customer and applicable statutory and regulatory requirements

It is built on seven quality management principles, which the standard lists as:

  • customer focus
  • leadership
  • engagement of people
  • process approach
  • improvement
  • evidence-based decision-making
  • relationship management

What ISO 9001 does not cover

“This document does not include requirements specific to other management systems, such as those for environmental management, occupational health and safety management, or asset management.” A quality certificate says nothing about how you protect information. When a customer's security questionnaire asks for ISO 27001, an ISO 9001 certificate does not answer it.

What ISO 27001 adds that ISO 9001 does not have

A defined risk process

ISO 9001 asks for risks and opportunities to be addressed. ISO 27001 specifies an information security risk assessment process in detail — risk criteria, identification against confidentiality, integrity and availability, risk owners, analysis, evaluation — and a risk treatment process that ends in a treatment plan approved by the risk owners.

Annex A and the Statement of Applicability

ISO 27001's Annex A lists 93 controls, and clause 6.1.3 requires you to compare your own controls against it and record the result in a Statement of Applicability. ISO 9001's Annex A is different in kind: “Annex A provides information and clarifications that can support understanding of the structure, terms and clauses of this document. It does not contain any additional requirements.”

Audit days, side by side

Each standard has its own published table for the initial certification audit (Stage 1 plus Stage 2), starting from the number of people in scope. For ISO 9001 that is IAF MD 5, Table QMS 1; for ISO 27001, the ISMS audit-time table used by certification bodies.

Initial audit days by headcount (table starting figures, single site)
People in scopeISO 27001ISO 9001
551.5
1052
2573
458.54
65105
125127
275149
62516.511

ISO 27001 starts higher at every size in the table. Both are then adjusted: ISO 9001 audit time may be reduced, but “The reduction of audit time of management systems shall not exceed 30% of the times established from Tables QMS 1, EMS 1, or OH&SMS 1.” And in both regimes surveillance runs at about a third of the initial audit each year, and recertification at about two thirds. The ISO 9001 table also comes with a note: “The numbers of personnel in Table QMS 1 should be seen as a continuum rather than a stepped change.”

For ISO 27001 at your size, the calculator applies the published adjustments for sites and complexity.

What changed in ISO 9001:2026

For an organisation that holds ISO 9001 and is adding ISO 27001, the new edition arrives at the same time. Its foreword lists the main changes:

ISO 9001:2026, main changes (foreword, verbatim)
ChangeWhat the foreword says
Inclusion of core ISO management system terms and definitionsClause 3 of the document now includes a limited number of terms and definitions. ISO 9000 remains the normative reference for all quality management terms and definitions.
Introduction of quality culture and ethical behaviourQuality culture and ethical behaviour are now addressed within the requirements, particularly in relation to leadership, awareness and the environment for the operation of processes.
Separation of risks and opportunitiesRisks and opportunities are more clearly distinguished, with separate consideration of actions to address each.
Strengthened management of changeRequirements related to changes to the quality management system have been reinforced to support the achievement of intended results.
Enhanced explanatory content in Annex AIt has been revised to provide enhanced clarification of the structure, terminology and intent of the requirements as informative text, without introducing additional requirements.
Removal of Annex BIt previously provided information on other ISO/TC 176 standards. References to these standards are now included in Annex A and on the ISO/TC 176 website.

Two of those matter to an ISO 27001 holder

The separation of risks and opportunities moves ISO 9001 a little closer to the way ISO 27001 already treats risk as its own process. And the strengthened management of change sits alongside ISO 27001 clause 6.3, which requires changes to the ISMS to be “carried out in a planned manner”. That is our reading of the two texts side by side, not a statement either standard makes.

The transition

How and by when ISO 9001:2015 certificates move to the new edition is decided by the accreditation system rather than by the standard, and we have not found the published arrangements for this edition — so we do not give a date. Ask your certification body.

Holding both? Audit them together

An integrated audit starts from the sum of both audit times and may be reduced by at most 20%. The rules, and worked figures, are on the integrated management system page.

We do not audit, certify or consult, and are paid the same fixed fee per enquiry whichever certification body or consultancy you use. Every figure above is a published starting point.

Where this fits

Common questions

What is the difference between ISO 27001 and ISO 9001?

ISO 27001 is the requirements standard for an information security management system; ISO 9001 is the requirements standard for a quality management system. They share the same clause structure, but ISO 27001 adds a defined risk assessment, risk treatment and an Annex A of 93 controls, while ISO 9001 adds requirements about customers, products and services.

Is ISO 27001 harder than ISO 9001?

On audit time, yes: at 25 people in scope the published starting figure is 7 days for ISO 27001 against 3 for ISO 9001. Whether it is harder to implement depends on the organisation; the standards do not say, and we have no data to answer it.

Do I need ISO 9001 before ISO 27001?

No. Neither standard requires the other. Both can be certified on their own, and both are designed so that they can be run as one integrated management system if you hold both.

What is new in ISO 9001:2026?

Its foreword lists six main changes: core management system terms in clause 3, quality culture and ethical behaviour, risks and opportunities handled separately, strengthened management of change, expanded explanatory Annex A, and the removal of Annex B.

How long do we have to move to ISO 9001:2026?

The transition period is set by the accreditation bodies, not by the standard. We have not found the published arrangements for this edition, so we do not state a date. Your certification body will tell you.

Can one audit cover ISO 27001 and ISO 9001?

Yes. The certification body adds the two audit times together and, for an integrated system, may reduce the total by at most 20%. See integrated management systems.

Does ISO 9001 cover information security?

Not as such. ISO 9001:2026 is explicit that “This document does not include requirements specific to other management systems, such as those for environmental management, occupational health and safety management, or asset management.” Information security is not in that list, but it is not in ISO 9001's requirements either — that is what ISO 27001 is for.

Sources cited on this page

  1. ISO 9001:2026, Quality management systems — Requirements, official preview (foreword, introduction, clauses 1–3), read first-hand
  2. ISO/IEC 27001:2022, official preview (clauses 1 to 6.3 and contents), read first-hand
  3. IAF MD 5:2023, Determination of Audit Time of Quality, Environmental, and Occupational Health & Safety Management Systems (Issue 4, Version 3)
  4. ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)
  5. IAF MD 11:2023, Application of ISO/IEC 17021-1 for Audits of Integrated Management Systems (Issue 3)
  6. ISO/IEC Harmonized structure for MSS with guidance for use (formerly Annex SL Appendix 2 of the ISO/IEC Directives, Part 1), approved 30 July 2025

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Already ISO 9001, adding ISO 27001?

Say how many people are in scope and when the next ISO 9001 audit is. Aligning the two saves audit days.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — that is a useful answer too.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to contact@iso27001partners.co.uk. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now