ISO 9001

ISO 9001:2026 Gap Analysis: How to Identify What Needs to Change in Your QMS

A gap analysis for ISO 9001:2026 applies the same general gap-assessment method used for any QMS readiness check, narrowed specifically to the standard's confirmed changes. Rather than reviewing every clause, the assessment works through each of those items individually, asking what currently exists, what's missing, and what evidence would confirm it.

A full QMS gap analysis, the kind organizations run before a first certification audit, makes sense when the entire system needs assessing from the ground up. A standard revision is a different situation — the QMS already exists and mostly already conforms, so the useful work is narrower and more targeted. This guide walks through assessing your current QMS against each of ISO 9001:2026's confirmed changes specifically, rather than repeating a full-system review — written by Maria Falbo, a Lead Auditor with decades of ISO 9001 experience.

Maria Falbo|Lead Trainer, Logix ISO|August 2026|6 min read

Why This Gap Analysis Is Narrower Than a Full QMS Review

A general ISO 9001 gap analysis compares an entire QMS against the full standard, useful when the system is being built or assessed for the first time. For that broader method, see our ISO 9001 Gap Analysis guide. A 2026-specific gap analysis works differently — it assumes the underlying QMS is already sound and focuses exclusively on the standard's eight confirmed changes, since that's genuinely the only content that's moved. For the full detail on what each of those changes actually involves, see our ISO 9001:2026 Key Changes guide.

This narrower scope means the assessment can be considerably faster than a full QMS review, provided it's applied rigorously to each of the items rather than treated as a quick skim.

Assessing Each of the Eight Changes

For each item below, the same three questions apply: does this currently exist in some form, is it documented, and would the current evidence hold up if an auditor asked to see it? For the full clause-by-clause reference behind each item, see our ISO 9001 Requirements Explained guide.

Risk and opportunity planning. Does your current risk register treat risks and opportunities as one combined list, or are they already genuinely distinct exercises? If combined, this is very likely a gap requiring restructuring.

Interested party requirement filtering. Does your documentation include a decision about which interested party requirements actually fall within the QMS's scope — or does it stop at simply listing who those parties are and what their needs and expectations are?

Planning for changes. When your organization plans a change, does anyone check afterward whether it actually delivered what was intended, and is there a real communication step built into the process, not just an approval signature?

Quality culture and ethical behavior. Is this addressed anywhere in current awareness training, even informally — or would staff have no framework for discussing it if asked directly?

Externally provided processes, products, and services. Does your current documentation use the narrower "outsourced processes" language, or does it already reflect the broader scope this update requires?

Audit program objectives. Do your current audit plans state a specific objective for each audit, or only scope and criteria?

Management review inputs. Does anyone at management review ask whether interested parties' needs have changed since the last review — or does that question never come up?

Improvement clause structure. This one is document-only — check whether any internal procedure references the old Clause 10 structure by number, since that's the only thing this specific change actually affects.

In Practice

The items that consistently surface as genuine gaps, not just documentation updates, are the risk and opportunity restructuring and the interested party filtering step. Both require an organization to make a decision that often wasn't being made explicitly before — not just to add a new line to an existing document. Everything else on this list tends to be a smaller change once you know exactly what to look for.

Get an expert 2026 gap analysis before you build your transition plan

Our ISO 9001 consulting services identify exactly where your QMS stands against each of the eight changes.

View Consulting Services

Common Findings from This Type of Assessment

Across organizations running this specific assessment, a few patterns are most likely. Risk registers built years ago and not restructured are the most common substantive gap. Audit program templates rarely have an objective field built in, since it simply wasn't a requirement before. Change management processes frequently stop at approval, with no documented step for reviewing whether a change actually achieved what it was meant to.

Documentation referencing old clause numbers is the most common purely administrative finding — not a genuine conformance issue, but something that needs updating regardless to keep internal references accurate.

In Practice

The gap I find gets rationalized away most often is the management review question. Teams frequently tell me "we probably talk about that informally," which isn't the same as it being an identifiable agenda item an auditor could actually verify happened. If nobody can point to when it was last specifically discussed, it's a gap, regardless of how confident the informal answer sounds.

Turning Results Into Your Transition Plan

Once the assessment identifies which of the changes require work, that list becomes the actual scope for your transition project. For the full sequence of turning these findings into a timeline, updated documentation, and team training, see our how to transition to ISO 9001:2026 guide.

FAQ

Frequently asked questions

Do we need to reassess our entire QMS, or just the specific changes?

Just the changes, provided your existing QMS is already functioning well under the 2015 edition. A revision-specific gap analysis intentionally doesn't revisit content that hasn't been modified.

How long does this type of assessment typically take?

Considerably less time than a full QMS gap analysis — most organizations can complete a focused assessment against these items within a day to a few days since the scope is narrow and well defined.

Should the same person who conducts our regular internal audits run this assessment?

That's often practical, since they already understand the QMS well, but it's worth pairing that familiarity with a deliberate focus on the specific changes rather than a general audit mindset, so new gaps aren't missed simply because they weren't relevant to check before.

What if we find gaps beyond the confirmed changes?

That's worth investigating separately — it likely reflects an existing QMS issue unrelated to the 2026 revision, and addressing it is good practice regardless of the standard transition, even though it falls outside this specific assessment's intended scope.

About the Author
Maria Falbo — Lead Trainer, Logix ISO
Maria Falbo
Founder & Lead Trainer, Logix ISO · 25+ Years Global Experience

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.

Learn more about Maria →
ISO 9001 Consulting Services
Ready for an expert 2026 gap analysis of your QMS?

Change-by-change readiness assessment

View Consulting Services