DEV Community

James Whitfield
James Whitfield

Posted on

DEKRA's "assumed readiness" warning hits close to home — most transition plans I see are extrapolation, not gap analysis

DEKRA recently published a readiness piece on ISO 9001:2026, and the opening line landed: too many organizations are treating "existing 9001:2015 certification" as evidence of readiness for the 2026 revision. Reading it, I had the uncomfortable thought that the document I'm sitting on at work isn't much different.

What "assumed readiness" actually looks like

It's not malicious. It's the natural mental shortcut. You have a certified QMS, an auditor visited recently, and the cert body hasn't flagged anything catastrophic. So when 2026 lands, you assume the delta is small — maybe a clause or two, maybe a new term in the glossary. You write a one-pager, name a sponsor, set a deadline, and move on.

The problem is that 9001:2026 isn't a copy-edit. It's a structural revision. The big themes — climate change, digitalization, AI governance, organizational context as a moving target — are not bolt-ons to clause 4. They change how you scope context, how you define interested parties, and what counts as "documented information" for risks that didn't exist when 2015 was drafted.

If your transition plan is "we'll update the quality manual and retrain," you don't have a gap analysis. You have a calendar event.

The uncomfortable bit: climate change is already in the standard

This is the part I think a lot of teams are missing. ISO added climate change considerations to clause 4.1 and 4.2 via Amendment 1 in 2024. It's not a "wait for 2026" item — it's already in force for any surveillance audit you walk into today.

In practice, that means:

  • Context of the organization needs to account for climate-related risks and opportunities as a QMS driver, not a CSR sidebar.
  • Interested parties include regulators, supply chain partners, and investors who care about climate disclosure.
  • Leadership has to demonstrate that climate considerations are part of how the QMS is planned and resourced, not deferred to a sustainability report that lives somewhere else.

If your last internal audit didn't touch climate, your 2015 system is no longer 2015-compliant. It just hasn't been tested yet.

What a real gap analysis looks like (for me, this week)

I'm running this exercise now, in a Class II setup where I also have to keep ISO 13485 and 21 CFR 820 in view. The framework I've been using:

  • Clause-by-clause read of DIS/FDIS drafts. Not the summary blog posts — the actual draft text. The Annex SL changes in particular rewires how clauses connect, and that's where most teams miss the real impact.
  • Process ownership map. For every process in the QMS, who owns it, what inputs/outputs cross the boundary, and where the new wording would force a change. Most of my hits land in design control, supplier control, and post-market surveillance.
  • Evidence audit on what's already in place. Pulling the last two cycles of internal audits, management reviews, and CAPAs. If we already discuss climate risk in management review, that's evidence. If we don't, that's the gap.
  • Third-party preview. Talking to the certification body about how they intend to audit the new clauses. CBs are publishing transition guidance — use it, but treat it as their interpretation, not gospel.

The output isn't a checklist. It's a matrix: clause → current state → required state → evidence already in hand → evidence to build → owner → date. Anything less is a wish list.

Where I expect to get stuck

Two places, honestly:

  1. AI and automation governance. If 9001:2026 lands with explicit language on AI oversight (the drafts suggest it will), I'll need to decide whether AI-assisted processes in the QMS itself — automated CAPA triage, document classification, that kind of thing — are in scope. In medical devices that's already a thorny question under 13485 and Part 11. In 9001 it's new ground for most teams I talk to.
  2. Climate disclosure overlap. Sustainability reporting and QMS documentation want the same facts in different shapes. I'm not excited about maintaining two views of the same data.

What I'd tell a colleague starting from scratch

Skip the transition template. Read the standard yourself, end to end. Then read your current quality manual side by side. Anything you find yourself writing "this is implicit" next to — that's a gap. Implicit doesn't survive an audit; documented information does.

For climate specifically: if you can't point to a management review minute where it was discussed as a QMS input and not a CSR input, you're not there. Same logic applies to AI governance — if there's no record of who decided what the AI is allowed to do in your process, you don't have governance, you have an experiment running in production.

The question I'm wrestling with

Is anyone else doing this as a structured gap analysis with traceability from each new clause back to existing evidence, or are most of you (like me, six weeks ago) working from a list of changes someone summarized at a conference?

Top comments (0)