Quality Management Systems
An ISO 9001 gap analysis run today is not the same exercise it was two years ago, and the organizations still running it the old way are quietly losing the one thing the transition does not give back: time. ISO has moved the sixth edition of the world's most-used quality standard into publication. The requirements you will be audited against in 2028 are already written. The distance between your quality management system and those requirements is already real — whether or not anyone has measured it.
This guide covers what an ISO 9001 gap analysis has to score in 2026, why a 2015-era checklist will now under-report your exposure, which clauses generate the most findings, how to score honestly when the person scoring works for the organization being scored, and how to turn the result into sequenced work rather than a list of complaints. It is written for quality managers who already hold a certificate and now have a second standard bearing down on them.
Definition and Scope
What Is an ISO 9001 Gap Analysis in 2026?
Measure. Score. Sequence.
The mechanics are simple enough to describe in a sentence and difficult enough to get wrong in a dozen ways. You take the standard, clause by clause, and you ask two separate questions of each requirement. Does a documented arrangement exist that satisfies this? And is that arrangement actually operating, generating records, and known to the people who are supposed to be following it?
Those two questions are separate on purpose, and an ISO 9001 gap analysis that asks only the first one is measuring paperwork. Organizations fail audits in the space between them far more often than they fail for missing documents. A procedure that exists but nobody follows scores worse in practice than a gap everybody knows about, because the first one creates a false sense of coverage while the second at least generates urgency. Any ISO 9001 gap analysis that collapses documentation and implementation into a single yes-or-no column is producing a number that flatters you.
The scope question follows immediately. A gap analysis covering only the clauses you think changed is not a gap analysis; it is a spot check. ISO 9001 requirements interact. A weakness in competence records at Clause 7.2 surfaces as a nonconformity in production controls at 8.5. A vague quality policy at 5.2 produces objectives at 6.2 that nobody can measure. The findings that cost the most are the ones that trace back through three clauses to a root nobody scored, which is exactly why the same architecture applies whether you are working in quality, environment, or medical devices — as MSI's parallel guides to the ISO 14001 gap analysis and the ISO 13485 gap analysis both demonstrate.
One structural note matters before going further. ISO 9001, ISO 14001, and ISO 45001 all share the Harmonized Structure — the ten-clause backbone formerly published as Annex SL. ISO 13485 does not; it predates the harmonized architecture and retains an earlier structure suited to regulatory needs. That distinction determines whether your ISO 9001 gap analysis findings map cleanly onto a second standard or have to be re-scored from scratch. MSI's overview of how an ISO audit works across standards covers the shared spine in more detail.
The 2026 Timeline
Why Has the ISO 9001 Gap Analysis Clock Already Started?
Published. Counting. Closing.
Most organizations are waiting for a publication date before they start work. That instinct is understandable and it is costing them the cheapest part of the transition.
ISO's own catalogue entry for the sixth edition now lists the project at stage 60.00 — under publication — with a publication date of September 2026 and ISO/TC 176/SC 2 named as the responsible committee. The Final Draft International Standard completed its ballot in July 2026. At the FDIS stage only editorial adjustments are permitted, which means the technical substance of what you will be audited against is settled. The text is not yet public and should not be quoted, but its direction has been documented by the committee in ISO/TC 176/SC 2's published revision updates and confirmed on ISO's official development page for the standard.
That is the arithmetic almost nobody runs. Assume publication in September 2026 and a three-year transition to roughly September 2029, consistent with the pattern MSI has mapped across both 2026 transition deadlines. Now work backwards. Your registrar cannot issue a transition certificate until it has itself been re-accredited to the new edition, and accreditation bodies work through that sequence after publication, not before. Certification bodies will spend late 2026 into mid-2027 training auditors. Realistically your transition audit lands in 2028.
To pass it, your revised arrangements need at least one full internal audit cycle and one management review under the new clauses before the auditor arrives. Back that out and the documentation work has to be substantially finished in 2027. Back that out again and the ISO 9001 gap analysis that tells you what to change needs to exist well before then. The window that looks like three years is closer to twelve months of real project time, and an ISO 9001 gap analysis is the first item in it.
There is a second reason to move now, and it is commercial rather than procedural. Transition timelines are overseen by Global Accreditation Cooperation Incorporated, which unified the former International Accreditation Forum and International Laboratory Accreditation Cooperation on 1 January 2026. Below it sit accreditation bodies such as ANAB, and below those, your certification body. When roughly 1.5 million valid ISO 9001 certificates worldwide — a figure drawn from the ISO Survey — all need transitioning inside the same window, auditor availability becomes the scarce resource. Organizations that scored early book the calendar slots. Organizations that waited take what is left.
Scoring Architecture
What Must an ISO 9001 Gap Analysis Score?
Every clause. Both axes. No exemptions.
Clauses 4 through 10 carry the auditable requirements. Clauses 1 through 3 are scope, references, and terms. A complete ISO 9001 gap analysis walks all seven auditable clauses and does not skip the ones that feel settled.
An ISO 9001 gap analysis should also score numerically and consistently. A four-point scale works well: zero for absent, one for documented but not implemented, two for implemented but not effective, three for conforming and demonstrable. What matters is not the scale you choose but that the same scale is applied by the same criteria across every clause, so the resulting ISO 9001 gap analysis produces a comparable picture rather than a mood.
The 2026 Delta
What Does the 2026 Revision Add to an ISO 9001 Gap Analysis?
Culture. Ethics. Evidence.
The structural answer is that the ten-clause backbone survives. Organizations bracing for a rebuild can stop bracing. The revision is an evolution of the 2015 text, not a replacement of its architecture, and the committee has been consistent on that point throughout the cycle.
The substantive answer is that Clause 5.1 acquires a quality-culture expectation with no predecessor anywhere in the standard's history. Top management is asked to promote a quality culture and demonstrate ethical behavior, and a corresponding awareness requirement asks that people in the organization actually understand it. This is genuinely new. There is no 2008 or 2015 equivalent to fall back on, which means every certified organization on earth has a gap here by default — the question is only how large.
The practical difficulty is that culture resists the evidence-gathering habits quality professionals have spent careers building. An auditor cannot grade a feeling, so the requirement will be examined through artifacts: management review decisions that show quality weighed against schedule and cost, speak-up and escalation data, competence and awareness records, culture-survey trends with actions attached, and documented instances where leadership chose the quality-protective option when it was expensive. MSI's detailed treatment of auditing quality culture under ISO 9001:2026 works through the specific evidence types auditors are expected to accept, and the companion piece on what ISO 9001:2026 means for boardrooms covers the governance side of the same requirement.
Alongside culture, committee reporting has pointed consistently toward sharpened treatment of resilience, supply chain management, change management, organizational knowledge, and the risks-and-opportunities distinction. None of these are new concepts in the standard. All of them are places where a 2015-era ISO 9001 gap analysis scored a system as conforming that a 2026 auditor will look at more closely. The broader shift in what quality leadership is expected to look like is covered in MSI's work on the modern quality management mindset.
Note also that ISO 9000, the fundamentals and vocabulary companion, has been revised in the same cycle. Definitions carry weight in audits. An ISO 9001 gap analysis scored against 2015 vocabulary can reach a defensible conclusion using terms the revised standard has since refined.
Where Findings Concentrate
Which Clauses Generate the Most Findings?
Predictable. Repeated. Avoidable.
Across 200+ audits attended, MSI client experience suggests findings cluster in a small number of predictable places. Knowing where they cluster lets you weight the ISO 9001 gap analysis toward the areas most likely to produce work, rather than spreading effort evenly across clauses that rarely fail.
Quality objectives at Clause 6.2. The requirement asks for objectives that are measurable, monitored, communicated, resourced, and assigned. Most systems produce objectives that satisfy the first and fail the rest. “Improve customer satisfaction” is an aspiration. An objective states the measure, the target, the owner, the resources, and the review point.
Corrective action at Clause 10.2. The standard requires evaluating whether similar nonconformities exist or could occur elsewhere. That sentence is skipped constantly. A corrective action that repairs one instance and never asks where else the same cause is live is incomplete on the face of the clause.
Internal audit at Clause 9.2. Programs that audit the same processes on the same rotation regardless of risk, performed by auditors who lack independence from what they are auditing, generating findings that recur year after year. MSI's guide to internal audit planning covers the scope-and-criteria discipline, and the internal audit risk matrix shows how to weight a program so depth follows risk. Note that ISO 19011:2026 published in May 2026 and immediately withdrew the 2018 edition with no transition period — any internal audit procedure still citing ISO 19011:2018 is citing a withdrawn document, a point covered in MSI's breakdown of the six edits ISO 19011:2026 requires.
Management review at Clause 9.3. The clause specifies inputs and requires outputs in the form of decisions and actions. Reviews that present data and adjourn without decisions fail the output half of the requirement, regardless of how complete the input half was.
External providers at Clause 8.4. Criteria for evaluation and selection that exist on paper but were never applied to the suppliers actually in use, and re-evaluation that has not happened on any defined cycle. MSI's risk management procedure template guidance covers how supplier risk feeds the wider register.
Competence and awareness at Clauses 7.2 and 7.3. Competence is usually documented. Awareness usually is not, because awareness is only demonstrable by asking people. Under the 2026 revision this clause carries the culture requirement, which raises the stakes considerably.
Objectivity
How Do You Score an ISO 9001 Gap Analysis Honestly?
Evidence. Not memory.
The hardest problem in any internal ISO 9001 gap analysis is not technical. It is that the person scoring the system usually built the system, and nobody grades their own work harshly.
Four disciplines make the difference. First, name the evidence. Every score above zero cites a specific document, record, or observation — a document number, a meeting date, a record range. A score with no citation is an opinion. Second, score implementation on the floor. Documentation scores from the document; implementation scores from watching the work and asking the person doing it. Those are different activities and merging them is how systems come to be described as conforming when they are merely papered.
Third, apply a hostile reading. For each requirement, ask what a registrar looking for a nonconformity would say. That reframing catches more than any checklist refinement, and it is the single most valuable thing a consultant who sits in certification audits brings to the exercise. Fourth, get a second set of eyes on the clean scores. The gaps you found are not the risk. The requirements you scored as fully conforming without much thought are the risk, because nobody will look at them again until an auditor does.
This is also where independence has practical value. Sitting in 200+ audits produces a specific kind of knowledge: not what the clause says, but what registrars actually write findings against, which varies from the plain text of the standard in ways no checklist captures. Organizations working with an ISO consulting partner most often cite that calibration as the reason, rather than any shortage of internal capability.
From Findings to Work
How Do You Prioritize What the ISO 9001 Gap Analysis Finds?
Sort. Sequence. Ship.
A finished ISO 9001 gap analysis that lands as a forty-page list of everything wrong will be read once and shelved. The deliverable that gets acted on sorts findings into three buckets and gives each a sequence.
Tier one: housekeeping. Outdated references, procedures naming roles that no longer exist, forms superseded but not withdrawn, a withdrawn standard cited in a reference list. Real findings, cheap fixes. Clear them first: they are the cheapest yield an ISO 9001 gap analysis produces, and they are the ones that make a system look neglected to an auditor who has just walked in.
Tier two: structural. A requirement with no arrangement behind it at all, or an arrangement that does not function. These need scoping, ownership, and a date. They are the substance of the transition project.
Tier three: evidence over time. This is the tier that governs your calendar. Where the gap is that a process has not yet run under revised arrangements, no amount of resourcing accelerates it. Culture evidence is the clearest example — you cannot generate a trend line retroactively. Every tier-three finding has to start early enough that the records exist before the audit, which is the whole reason scoring cannot wait for publication.
One efficiency worth capturing: if your organization holds both ISO 9001 and ISO 14001, run the two transitions as a single project rather than two. The shared Harmonized Structure means one documentation update, one integrated internal audit program, and one restructured management review can serve both certificates. MSI's guide to running the ISO 9001 and 14001 transition as one plan sequences the work, and organizations moving on the environmental side should note that ISO 14001:2026 published in April 2026 with a hard deadline already running.
Your Gap List Is the Easy Part. The Documents Are the Work.
Every structural finding in an ISO 9001 gap analysis ends in the same place: a procedure that has to be written, reviewed, approved, and rolled out. MSI's ISO procedure templates are built by consultants who sit in certification audits — pre-written, editable, and structured the way registrars expect to read them. Start from a working document instead of a blank page.
Internal or External
Who Should Run Your ISO 9001 Gap Analysis?
Capability. Calibration. Candor.
Most organizations can run their own ISO 9001 gap analysis. The question is not capability — quality managers know their standard. The question is calibration and candor.
Run it internally when your team includes someone who did not build the system, when you have recent certification audit experience to calibrate against, and when leadership has genuinely signalled that unwelcome findings are wanted. Bring in outside help when the same person owns and would score the system, when your last transition produced surprises at the certification audit, when the 2026 culture requirement leaves you unsure what evidence would even satisfy it, or when the schedule is tight enough that a wrong prioritization call costs a cycle.
MSI has supported 80+ certifications and attended 200+ audits over 28 years, and has trained 600+ professionals in the disciplines this article describes. Organizations working toward first certification typically run SurePath; those maintaining an established system year-round use SureResults. To talk through your own scoring approach, plan a session at 760-434-9141 and bring your current clause scores to the call.
For leadership teams still deciding how much of the 2026 transition to resource, MSI's ISO Executive Decision Briefs are worth watching before the budget cycle closes — they are built for the people who approve the project rather than the people who run it.
Common Questions
ISO 9001 Gap Analysis: Frequently Asked Questions
Asked. Answered. Sourced.
How long does an ISO 9001 gap analysis take?
Should we wait for ISO 9001:2026 to publish before scoring?
Is an ISO 9001 gap analysis the same as an internal audit?
Does the 2026 revision change the ten-clause structure?
Can one gap analysis cover ISO 9001 and ISO 14001 together?
What evidence satisfies the new quality culture requirement?
How often should we repeat the exercise?
Keep Reading
Related Reading From MSI
ISO 9001 and 14001 Transition: Why One Plan Wins
Auditing Quality Culture: Proven Evidence Auditors Accept
ISO 14001 Gap Analysis: Why the 2026 Transition Wins
ISO 13485 Gap Analysis: The Proven Path to QMSR Ready
Internal Audit Planning: Why Proven Methods Always Win
ISO Procedure Templates and Guides
References and Authoritative Sources
International Organization for Standardization — ISO 9001 and quality management
ISO/TC 176/SC 2 — Committee news and revision updates
ISO/TC 176/SC 2 — Committee home
International Organization for Standardization — ISO 19011, Guidelines for auditing management systems
International Organization for Standardization — ISO 14001 and environmental management
International Organization for Standardization — The ISO Survey of certifications
International Organization for Standardization — Certification and conformity
Global Accreditation Cooperation Incorporated — Global ACI (successor to IAF and ILAC, operational 1 January 2026)
ANSI National Accreditation Board — ANAB
American Society for Quality — ASQ ISO 9001 resources
National Institute of Standards and Technology — Baldrige Performance Excellence Program
National Archives — Electronic Code of Federal Regulations
About Management Systems International (MSI)
Management Systems International (MSI) is a veteran-owned, female-owned ISO consulting firm founded in 1998. With 28 years of experience including extensive AS9100 work in MSI's early years, MSI's track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries.
Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.
msi-international.com · 760-434-9141