DEV Community

Rajiv Iyer
Rajiv Iyer

Posted on

DEKRA's first ISO 9001:2026 gap is "assumed readiness" — and most transition plans are built on it

DEKRA's ISO 9001:2026 readiness checklist opens with the gap they are calling "assumed readiness based on existing certification" — organisations assuming their 2015 system will carry them across. When I read it I thought, adi paaru ("look at that") — I have watched this exact pattern burn a Q3 at a previous employer, and seeing DEKRA name it as gap #1 is a small vindication for anyone who has lived through a transition like that.

Why "we already have 9001:2015" is a starting line, not a finish line

The 2026 revision is not a typo. ISO 9001 last had a major update in 2015, and a decade between revisions means the changes are not cosmetic. Committee communications and the published drafts point at expanded expectations on climate, broader contextual understanding, and a more explicit treatment of organisational knowledge and risk. None of these were absent from 9001:2015, but they were lighter. A 2015 system that documented context and risk in a paragraph and moved on is not automatically a 2026 system that demonstrates them.

In a CMO, the gap is wider than most OEM-side templates suggest, because we sit on top of multiple customer expectations. I run supplier quality at a contract manufacturer — three OEM customers, forty-plus upstream suppliers, and our own ISO 9001 and ISO 13485 certifications running in parallel. The QMS has to bridge two worlds. When DEKRA lists "assumed readiness" as the top gap, what I see in my own stack is the assumption that the 2015 manual is essentially correct, plus a few line items.

That is not a gap analysis. That is hope.

What a real transition gap analysis looks like, from a CMO seat

Here is the discipline I run every quarter for both 9001 and 13485:

  • Clause-by-clause mapping. Take the new standard text directly, not a consultant's summary. For each clause, write down: what evidence do we already have? What is missing? Which existing evidence does not satisfy the new wording?
  • Evidence pull, not policy pull. A real gap analysis does not start from your quality manual. It starts from the records — audit reports, management reviews, CAPA logs, training records, calibration records — and asks whether the records answer the new clauses.
  • Distinguish "documented" from "demonstrated". Your 2015 quality policy probably mentions context. That is not the same as a documented analysis of climate-related risks affecting your product, supply continuity, or facility exposure.
  • Owner's name on every gap. A gap analysis that ends in a Gantt chart with one QA lead's name on every line is hope wearing a project plan costume.
  • Customer-overlay check. At a CMO, the new standard does not land in a vacuum. I check each OEM customer's quality agreement to see what they require from the new revision and when.

The climate clause is where "assumed readiness" usually breaks

ISO 9001:2026's expanded treatment of climate is the part most 2015 manuals fudge. I have seen three flavours of fudge:

  1. A one-line statement that "we consider climate as part of context" with no supporting evidence.
  2. A risk register that lists "climate change" as a single line item with a generic mitigation.
  3. An annual management review slide that mentions ESG once and moves on.

None of these will satisfy a 2026 auditor looking for a documented understanding of how climate-related issues affect the QMS — supply continuity, infrastructure exposure, product realisation, even workforce continuity in extreme heat zones. In Bangalore, where two of my facilities sit, this is not abstract. Monsoon disruption to incoming inspection, heat-related deviation spikes in summer, grid instability affecting calibrated equipment — these are operational realities, and the QMS should be able to point at how we have considered them.

What a CMO's transition plan should explicitly call out

If you are a contract manufacturer with a multi-customer quality system, the transition plan is a different shape than an OEM's plan. A few items I have learned to make explicit:

  • Which customers require which revision, and when. OEMs do not adopt standards in unison. Your transition deadline may be earlier than ISO's, depending on contracts.
  • Which clauses hit the CMO-supplier interface hardest. Context, risk, and organisational knowledge tend to interact with supplier qualification in ways the standard does not call out directly.
  • How integrated management systems are handled. If you run 9001 and 13485 together — most medtech CMOs do — the transition plan must specify the integration points and where the new revision creates asymmetric traceability requirements across the two standards.
  • What tooling supports this, and what it does not. I use a mix of homegrown Python + Postgres automation and a vendor eQMS. The vendor tool I rely on is positioned for medtech — ISO 13485, FDA 21 CFR Part 820, ISO 14971 — not specifically for ISO 9001:2026 transition work. That is not a criticism of the tool, just an honest read: if your transition plan leans entirely on a tool that does not position itself around the standard you are transitioning to, you have a tooling gap as well as a process gap.

A short pre-transition checklist I run

Before I commit any Q4 hours to a 9001:2026 transition, I check:

  • Current 9001:2015 internal audit findings — are any of them the kind of finding that will be amplified under the new revision?
  • The last two management reviews — does the input already include the new clause topics, even informally?
  • CAPA backlog — anything open that touches the new clause topics, and is the closure-evidence language compatible with the new wording?
  • Customer quality agreements — what does each OEM require, and is the transition deadline contractually pinned?

If four of those line up, the transition is a project. If only one lines up, the transition is hope, and DEKRA's gap list is correct.

I work on qmsWrapper. The honest read above is mine; qmsWrapper is positioned for medtech device makers and SaMD teams, and my CMO-side ISO 9001:2026 transition work does not fit that scope.

So — CMOs and OEMs alike — what is the first gap on your own 9001:2026 transition list, and is it "assumed readiness" or something your team has already named with more precision?

Top comments (0)