Four major quality standards are moving at once — and if you’re responsible for certification, transition planning, or supplier compliance, you need a clear read on what’s real, what’s still a draft, and what’s simply anticipated.
ISO 9001 is in the middle of a revision. IATF 16949 is expected to follow it. The regional AS9100/EN9100 aerospace standards are being unified into one global standard. And in medical devices, the FDA has already finalized a real, dated change — while ISO 13485 itself stays put.
This article is built directly from Omnex’s October 2025 webinar on these updates, the third in a series (the first covered ISO 9001, 14001, 45001, and ISO 19011; the second covered ISO 26262, ISO 21434, and Automotive SPICE). The presenters were Bill Kovacic — 38 years with Caterpillar, a 2021 ISO Excellence Award and 2023 US TAG Award for Distinction winner, and a US representative to ISO TC 176 (quality) and TC 207 (environmental) — and Frankie Breedlove, who represents Omnex on ISO Technical Committee 207 and leads Omnex’s medical-device standards work. Because standards timelines shift as drafts move through balloting, every date and milestone below is presented exactly as it was framed in that October 2025 session: as an estimate, not a certainty. We’ve flagged where that matters most, and we’d encourage you to verify current status before locking in a transition plan.
ISO 9001:2026: What’s Actually Changing
As of this webinar, ISO 9001 was at the Draft International Standard (DIS) stage, with the comment period closing the following month. A final DIS was anticipated for the following spring or summer, with ISO 9001:2026 itself expected to publish around September 2026 and sector-specific standards built on it following a few months after. Compared to the 2008-to-2015 transition, this is a much lighter lift: most of the visible change is text reorganized to match the harmonized structure ISO now requires across every management system standard, plus a handful of genuinely new requirements.
Here’s what’s substantively different, not just reordered:
- Risk and opportunity get separated. What’s currently one combined clause splits into 6.1.2 (risks) and 6.1.3 (opportunities), worded almost identically aside from swapping “risk/undesirable” for “opportunity/desirable.” The reasoning: in practice, “risk” tends to get treated as only negative, so organizations overinvest in avoiding downside and underinvest in exploiting upside. The new clauses also require you to determine, analyze, and evaluate risks and opportunities, not just plan actions against them.
- “Maintained” and “retained” are gone. Documented information that used to be “maintained” is now “available”; what used to be a record is now “documented information to be available as evidence of.” The change exists because “maintained” versus “retained” doesn’t translate cleanly into every language the standard is published in.
- Quality culture and ethical behavior show up explicitly. Ethical behavior is newly referenced in the leadership, environment, and awareness clauses (a related document, ISO 10018 on quality culture, is worth knowing about too). This mirrors a broader shift toward treating culture as an auditable input, not just a poster on the wall.
- Clause 3 now spells out 23 definitions pulled directly from ISO 9000, instead of just pointing you to that document. Only one — “process” — actually changed in substance (it now includes “or transforms inputs to deliver a result”); the other 22 are unchanged.
- Planning a change now means planning three more things (clause 6.3): how you’ll monitor and evaluate whether the change worked, how you’ll communicate it, and how you’ll review its results.
- Internal audits get sharper (clause 9.2.2): you now have to define audit objectives, not just criteria and scope, and results go to “relevant managers” instead of a generic “management.”
- Management review inputs get more mandatory (clause 9.3.2): “shall take into consideration” becomes “shall include,” and a new required topic is added — changes in the needs and expectations of interested parties relevant to the QMS. (Note: some US TAG members have submitted comments on a related wording change to the review outputs — from “actions and decisions” to just “decisions” — so that specific point may still shift before final release.)
Smaller but practical changes round it out: calibration language in 7.1.5.2 now says “calibration or verification status”; clause 7.1.6 replaces “made available” with the more active “applied and shared”; clause 8.4.3 adds “customers and other relevant interested parties” for cases where a supplier ships directly to your customer; and clauses 10.1 and 10.3 merge into a single continual-improvement clause that now references monitoring and measuring the relevant data, not just analyzing it.
If you want the detail behind any of this, three resources are worth tracking: Annex A of the new standard itself (about 15 pages of clause-by-clause clarification — notes, not new requirements); ISO 9002, the companion guidance document for applying ISO 9001 (running roughly 6–7 months behind, with a DIS anticipated around February–April 2026, an FDIS around October, and publication anticipated around April the following year); and the separate “ISO 9001 for Small Enterprises” success-package guidance.
Tracking audit findings against a moving set of clauses gets harder without a system built for it. See how Audit Pro handles it →
IATF 16949: What Automotive Suppliers Should Watch For
IATF 16949 will incorporate everything ISO 9001 changes, plus its own automotive-specific updates. As of this webinar, the IATF and IAOB hadn’t formally started drafting sessions — but priority-topic review was already underway, informed by 26 sanctioned interpretations (SIs) already issued against the current standard. Reviewing those SIs for patterns points to where the next edition is likely to focus:
- Supplier relationships (4 SIs) and supplier quality management system development — a long-standing IATF goal, with growing attention specifically on sub-tier suppliers.
- Cybersecurity (3 SIs) — likely to reference frameworks like TISAX and ISO 27001, which European OEMs already require, and which Stellantis and PACCAR also require.
- External labs (3 SIs) and process controls and measures (3 SIs).
- Competence (2 SIs) and management review inputs (2 SIs), plus themes around preventing recurrence of nonconformities and control-plan execution.
Industry input adds more color. The IAOB’s own “wishlist,” presented at a recent Quality Summit, calls for: more prescriptive sub-tier supplier development requirements; provisions for highly automated manufacturing; strengthened software requirements (an estimated 40–50% of warranty costs now trace back to software); provisions for small and lower-tier manufacturing enterprises; requirements tied to program management; clarity on calibration; and consolidation of common customer-specific requirements (CSRs) to reduce the CSR burden suppliers currently carry.
Why this matters practically: warranty cost tied to software is now a bigger line item than many quality teams are staffed to handle, and CSR fragmentation is a real tax on every supplier serving more than one OEM. Both are squarely on the IAOB’s list — which is a strong signal they’ll show up in the next edition in some form.
Anticipated release: based on the ISO 9001 timeline, IATF’s next edition is anticipated sometime between roughly March and July 2027, since IATF has to wait for ISO 9001’s final text before running its own balloting.
A few related automotive-standards updates worth tracking alongside this: updated APQP and Control Plan reference manuals released around February 2024 became mandatory for GM and Stellantis around September 2024, and for Ford in December 2024. A new SPC “core tools” reference manual and a new MSA (Measurement Systems Analysis) reference manual are both anticipated in 2026. And CQI-34 (software PPAP guidance) is being revised around four focus areas — aligning it with other standards, enhancing common submission/warrant documentation, addressing off-the-shelf components, and change-management updates — with indications that software PPAP is headed toward becoming a GM customer-specific requirement, and possibly a Ford one in its next CSR revision.
AS9100/EN9100: Unifying Into “IA 9100”
Aerospace has run three regionally-branded near-duplicates of the same standard for years — AS9100 in the Americas, EN9100 in Europe, and an Asian equivalent. That’s being harmonized under one common name, IA 9100 (International Aerospace 9100), so every region works from the same document.
The timeline here is tied to ISO 9001’s own delays: in April 2024, the ISO 9001 revision was sent back for independent review with feedback, which pushed IA 9100 back too. As of this webinar, an incremental version of IA 9100 informed by that review was anticipated around November 2025 (190 comments had been dispositioned as of a recent IAQG meeting), with a further-updated version expected once ISO 9001:2026 itself is finalized — anticipated around early 2027.
Anticipated changes in the next edition: stronger information-security requirements against cyber threats; stronger counterfeit-parts provisions; more APQP concepts, including measurement systems analysis; more risk-based thinking paired with QMS maturity assessments; a clarification that statutory and regulatory requirements take precedence over customer requirements; more rigorous oversight of tier-1 and tier-2 sub-tier suppliers, with an emphasis on showing that IA 9100 implementation actually correlates with better product quality, not compliance for its own sake; an elevated, more deeply integrated product-safety section; quality culture (mirroring the ISO 9001 change); a greater sustainability/environmental focus; and an expanded FOD definition that covers both foreign object damage and foreign object debris.
Related standards to keep on your radar: AS9110 (aviation maintenance), AS9120 (aviation, space, and defense distribution), AS9115 (deliverable software, tied to ISO 9001, so it changes alongside it), and a newer, separate standard covering non-deliverable software that isn’t tied to ISO 9001 and won’t change with it.
The One Date That’s Already Locked
The FDA’s new Quality Management System Regulation (QMSR) takes effect February 2, 2026. Unlike everything above, this isn’t a draft or a projection — it’s a finalized regulatory change with a real compliance date.
ISO 13485 and the FDA’s New QMSR
ISO 13485 itself just went through a review cycle with no changes — it remains stable, and continues to be the standard the US market relies on for FDA clearance. What is changing is how the FDA references it. Effective February 2, 2026, the FDA has incorporated ISO 13485:2016 by reference directly into 21 CFR Part 820, retiring the old “Quality System Regulation” (QSR) in favor of a new “Quality Management System Regulation” (QMSR). The FDA’s reasoning: international markets are converging on ISO 13485 as the common reference standard, so harmonizing keeps the US aligned with how the rest of the world already works.
Practically, Part 820 has shrunk from roughly 46 sections to about 6, with section 820.10 doing the heavy lifting — it defines “device” per the FDA and incorporates ISO 13485 by reference. Around that core, the FDA added provisions clarifying where its own terminology differs from ISO 13485’s, made conforming edits to Part 4 for combination products (e.g., a device with both a device component and a drug component — if the drug-manufacturing process meets current Good Manufacturing Practice, certain device-constituent-part requirements streamline), and updated definitions across Parts 4 and 820.
A few specifics worth knowing before you assume ISO 13485’s definitions carry straight over:
- FDA’s own definitions don’t always match ISO 13485’s — for terms like components/parts, blood and blood components, and HCT/Ps (human cells, tissues, and cellular/tissue-based products), you need to use the FDA’s specific definition in the QMSR context, not assume ISO 13485’s meaning applies.
- “Finished device” is clarified: if a device could be used as-is before packaging, labeling, or sterilization, it’s already a “finished device” once building is complete — even before those three steps happen. That affects anything sitting on a shelf mid-process.
- “Remanufactured” is further defined, and third-party repair facilities that significantly change a device’s performance, safety, or specifications now more clearly fall under compliance obligations.
- Where ISO 13485 says “safety and performance,” the QMSR treats that as equivalent to “safety and effectiveness” under 21 CFR 820.
The QMSR also still leans on several existing CFR sections by reference even though many old QSR sections were removed: 21 CFR 803 (medical device reporting), 806 (corrections/removals), 821 (device tracking), 830 (Unique Device Identification/UDI), and section 501(h) of the Food, Drug & Cosmetic Act (adulteration/misbranding tied to QMSR non-compliance). Traceability requirements are more prescriptive under FDA rules than under ISO 13485 alone — for devices that “sustain or support life,” the QMSR requires more prescriptive UDI/traceability compliance aligned to 21 CFR 821, layered on top of ISO 13485’s more general language.
Interestingly, ISO 13485 still follows the older 8-clause structure aligned with ISO 9001:2008, not the 10-clause harmonized structure ISO 9001:2015 introduced — the medical-device sector never fully restructured around it, though it did informally absorb some 2015-era concepts like elements of process-approach thinking. One consequence: ISO 9001’s 2026 changes are expected to have very limited direct impact on ISO 13485 itself, at least until ISO 13485 undergoes its own future revision. There’s also a related nuance on the FDA side: the FDA has adopted ISO 9000’s clause 3 (terms and definitions) by reference for interpreting QMSR terms, but not ISO 9001 itself — so ISO 9001’s 2026 revision doesn’t automatically change how the QMSR works, though a future ISO 9000 revision could. Until the FDA issues a formal amendment, manufacturers should keep following the current dated editions (ISO 9000:2015 and ISO 13485:2016) rather than assuming any future edition passes through automatically.
A new guidance document, ISO/TS 23485, is also in progress — the first-ever guidance document written specifically for ISO 13485. It’s at draft stage, recently approved by committee to move to public commentary, with no release date yet anticipated (likely not before 2027).
Juggling ISO 13485, IATF 16949, and AS9100 requirements under one QMS? See how QHSE.AI brings it together →
Two broader threads are worth watching alongside all of this. First, the EU is updating its own medical-device regulation, with compliance deadlines for legacy devices around December 31, 2027 (high-risk devices) and December 31, 2028 (medium/low-risk devices), plus a phased rollout of the EU’s EUDAMED device database. Second, both the FDA and EU are paying growing attention to AI/ML lifecycle management specifically as it applies to software in medical devices and “software as a medical device” (SaMD) — an area where cybersecurity training is increasingly treated as close to mandatory for organizations that need to comply. One thing that is not changing: software development for medical devices continues to rely on the existing IEC 62304 standard, rather than being folded into ISO 13485 itself.
What to do about it now: (1) run a gap analysis comparing your current QMS against the new QMSR requirements, not the old QSR; (2) train your team on where FDA-specific terminology differs from ISO 13485/ISO 9000; (3) watch for ISO/TS 23485 guidance as it becomes available; and (4) mark February 2, 2026 on your compliance calendar — that date is not moving.
Planning Your Next 12–18 Months
Put side by side, here’s the honest state of play: ISO 13485/QMSR has one hard, dated, already-final requirement. Everything else — ISO 9001:2026, IATF 16949, and IA 9100 — is still in draft, review, or pre-drafting stages, with anticipated (not confirmed) release windows stretching from late 2025 through mid-2027.
- 1
Start now on culture and risk/opportunity thinking — these changes don’t require the final text to start preparing your team’s mindset and management-review agenda.
- 2
Watch the SI patterns, not just the standard — IATF’s sanctioned interpretations are a real early signal of what’s coming, even before drafting starts.
- 3
Budget for software and cybersecurity requirements — both IATF and IA 9100 are trending the same direction here, and it’s not a surprise if it lands.
- 4
Treat February 2, 2026 as fixed — unlike everything else in this article, the QMSR date is not an estimate.
A note on timing: every date in this article reflects Omnex’s October 2025 webinar and the standards-development status at that time. Draft standards move through balloting, comment periods, and revision cycles that can shift release dates in either direction. Before you commit resources to a transition plan, verify the current status of any standard discussed here.
Plan Your Standards Transition With Omnex
Whether you’re preparing for ISO 9001:2026, anticipating IATF 16949’s next edition, tracking IA 9100’s harmonization, or getting ahead of the QMSR’s February 2026 deadline, Omnex’s standards experts can help you build a realistic transition plan.
Frequently Asked Questions
What’s the anticipated IATF 16949 update timeline?
Based on projected ISO 9001 timing, IATF 16949’s next edition is anticipated roughly between March and July 2027, since IATF needs to wait for the final ISO 9001 text before running its own balloting process.
How would sector-specific requirements, like for other industries, be handled?
Any sector standard built on ISO 9001 — whether it’s IATF 16949 for automotive, IA 9100 for aerospace, or a standard for another industry like textiles — would need to incorporate all of ISO 9001’s changes into its own structure.
Is ISO 13485 still based on the 2008 (8-clause) version of ISO 9001, not 2015?
Yes, confirmed. ISO 13485 still uses the 8-clause structure aligned to ISO 9001:2008, though it did informally incorporate some individual 2015-era concepts without a full restructuring around the newer 10-clause format.
Can we integrate an aerospace standard like AS9100 and a medical-device standard like ISO 13485 under one quality management system?
Yes. Omnex has worked with a real client to successfully integrate AS9100 and ISO 13485 under the same quality management system.
Do all management system standards need to follow the same 10-clause structure?
Yes. ISO directives require all management system standards to follow the harmonized 10-clause structure and use the same clause numbering, which is why ISO 9001, ISO 14001, ISO 45001, and their sector-specific derivatives are converging on a common shape.
Now that the FDA is more involved, will ISO 13485 certification bodies start issuing “non-compliances” instead of “non-conformances”?
No. ISO certification bodies continue issuing findings as nonconformances through ISO audits, and the FDA continues its own separate regulatory enforcement — the two don’t merge into one reporting mechanism. However, under the new harmonization, the FDA does gain visibility into management review and audit records during FDA inspections, something it previously had access to but didn’t typically review. Organizations can mark such information as confidential, and the FDA then decides whether it stays private or becomes subject to Freedom of Information Act disclosure.
How can I get a copy of the ISO 9001:2026 draft?
DIS and FDIS drafts are typically available for purchase through a national standards body — ASQ, in the US. Once the FDIS is available, Omnex plans to have transition training ready for auditors and understanding-level training ready for implementers.
