ISO 9001
The quality standard, and the one with no Statement of Applicability.
ISO 9001 has no Annex A and no Statement of Applicability; a customer or a tender makes it required, and the first number to know is what the audit takes for a company of your size.
For 25 people the certification audit is 3 auditor days under IAF MD 5 Table QMS 1, against 7 for ISO 27001 at the same headcount: €3,600 to €5,400 for the initial audit and €6,000 to €9,000 for the three-year cycle, at the day rates accredited bodies in Europe charge, audit fees only.
Read the arithmetic, from IAF MD 5TED, the EU's procurement portal, carried 17,076 notices naming ISO 9001 in the last 365 days against 3,405 naming ISO 27001, 5 times as many, read on 12 September 2026. Where, by country, and how often a buyer asks for both
What we hold, clause by clause
21
covered
11
partly covered
4
not covered
Of 36 clauses. The 4 we do not hold records for:
- 7.1.4The environment in which processes are operated
- 8.2Customer requirements: communication, determination, review and change
- 8.3Design and development, from planning through to changes
- 8.5Production and service provision, identification, traceability, preservation
Two of those are a scoping decision and two are a backlog; the section above says which is which. Every other clause carries a note inside the product explaining exactly what is covered and what is not. This list is meant to shrink: clause 7.1.5 was on it until we built the calibration register.
Most of it you have already built
Clauses 4 to 7, 9 and 10 are the Harmonized Structure, the same skeleton as ISO 27001 and ISO 42001: context, interested parties, leadership, competence, documented information, internal audit, management review, corrective action. If you run one of those standards you have most of ISO 9001's management system already, and StandardOS keeps those records once for every standard you hold rather than once per standard.
Clause 8: two of these are not ours, two are not built yet
ISO 9001 clause 8 is Operation: customer requirements and their review, design and development, production control, traceability, and release. Two of its sub-clauses are genuinely somebody else's job. Design history (8.3) and unit-level production traceability (8.5) belong in a PLM or MES built for them, and always will. The other two are ours: reviewing customer requirements before you commit (8.2), and recording release against acceptance criteria (8.6). Those are not built yet. All four are named below rather than hidden.
Honest about what it does not do
You get the clause register, the recurring calendar of obligations, starting policies, a risk register and the clause 4 to 6 records. You do not get a Statement of Applicability, because the standard does not have one.
Of the four above, design history and unit-level production traceability belong in systems purpose-built for them. Reviewing customer requirements before committing, and recording release against acceptance criteria, are ours to build and are not built yet. If your quality system lives mostly in the first two, we are not the answer for that part, and the list above is how you tell before you pay.
Four tools, free, no account
Write the quality policy
Clause 5.2 from ten answers: what the company delivers, why quality matters to it, the commitments, the objectives it will measure, who is accountable, and how the policy is communicated and reviewed.
Write the internal audit programme
Clause 9.2 from five answers and the names of your processes: the criteria, the frequency, the auditors and their independence, the methods, a schedule that spreads the seven clause sections and your processes over the year's audits, the reporting and the records.
Write the management review minutes
Clause 9.3 as an agenda: the six inputs in the clause's order, the seven performance trends with their counts, the conclusion on the system, the decisions on improvement, changes and resources, the actions with owner and date, and the minutes an auditor reads.
Write a corrective action record
Clause 10.2 for one finding: the nonconformity, the correction and its consequences, the cause, whether it exists elsewhere, the action with owner and date, the effectiveness check, the risks and opportunities updated, and the change to the system, as the record an auditor reads.
Every free template on one page
Read next
Does ISO 9001:2015 require a quality manual? What clause 7.5 asks for instead, the 21 places the standard names documented information, and what a manual is for today
ISO 9001:2008 required a quality manual; ISO 9001:2015 does not, and says so in its Annex A. What it requires is documented information: five things to maintain (the scope, the process information, the quality policy, the objectives, the operational planning) and sixteen kinds of record to retain, each named by clause. What clause 7.5 asks of every document, why a manual is still the right place for the map of the system, and what to put in it. With the count of EU tender notices that asked for ISO 9001 in the last year, 17,076, five times ISO 27001.
The ISO 9001 management review: the 13 inputs and 3 outputs of clause 9.3 as an agenda, where each input comes from, and what the minutes have to show
Clause 9.3 of ISO 9001:2015 is the one meeting the standard writes the agenda for. Top management reviews the quality management system at planned intervals for suitability, adequacy, effectiveness and alignment with strategy (9.3.1); considers thirteen inputs, from the status of last time's actions to the performance of external providers (9.3.2); and decides on improvement, changes to the system and resources (9.3.3), with the results retained as documented information. The agenda, the record behind each input, what the minutes must show, and how the same meeting serves ISO 27001 and, for NIS2 entities, the annual policy review the Implementing Regulation requires.
The ISO 9001 quality policy: the four things clause 5.2 says it must contain, the three things that must happen to it, and a one-page example
Clause 5.2 of ISO 9001:2015 is short and precise. Top management establishes a quality policy that fits the organisation's purpose and context and supports its strategy, gives a framework for the quality objectives, and commits to meeting applicable requirements and to continual improvement (5.2.1). The policy is then maintained as documented information, communicated, understood and applied inside the organisation, and available to interested parties (5.2.2). What each of the seven requirements means for a page of text, the mistakes auditors write up, how the same policy serves ISO 27001, and a one-page example in our own words.
Which EU countries name ISO 9001 in public tenders: 4,897 German notices, 4,743 Romanian, and one in ten Romanian notices names it
Over 365 days, ISO 9001 appears in 16,356 TED notices from EU-27 buyers, 1.87% of everything they published and five times the 3,361 that name ISO 27001. Germany and Romania account for 59% of the mentions; Romania names it in 10.48% of its notices, Bulgaria in 7.34%, Hungary in 7.02%; France, Spain and Italy barely name it. And 1,475 notices name both standards, 44% of every ISO 27001 mention. The table by country, the overlap, and the query to re-run them.
How to check an ISO 9001 certificate is real: what a certificate must show, three checks that take ten minutes, and the 27 accreditation registers
ISO does not certify companies and keeps no register of them, so a certificate is only as good as the body that issued it and the accreditation behind that body. What ISO/IEC 17021-1 makes a certificate show, the three checks (the certifier is accredited for ISO 9001, the certificate is current, the scope covers what you are buying), the 27 national accreditation registers with links, why a certifier in another EU state is as good as one in yours, and why the cheap unaccredited certificate costs more in the end.
ISO 9001 for a software company: what clause 8 means when the product is code, sub-clause by sub-clause
Clauses 4 to 7, 9 and 10 of ISO 9001:2015 are the management-system skeleton an ISO 27001 company already runs. Clause 8, Operation, is the one written for factories and service desks, and the one a software company has to translate. What each sub-clause is when the product is software: requirements review before you commit (8.2), the development life cycle as design and development (8.3), cloud providers and dependencies as external providers (8.4), deployment, traceability, customer data and support as production and service provision (8.5), the release gate (8.6), and bugs and incidents as nonconforming outputs (8.7). With where the Cyber Resilience Act asks for the same records.
What ISO 9001 certification costs: the audit days IAF MD 5 fixes by headcount, the day rate, the three-year total, and why it is a third of ISO 27001
Certification bodies do not publish prices, but the audit days are not their opinion: IAF MD 5 sets them by the number of people in scope, 1.5 days for up to five people, 3 for 16 to 25, 7 for 86 to 125, and the accreditation body holds the certifier to the table. Multiply by a day rate of 1,200 to 1,800 euros, add two surveillance audits at about a third each, and you have your number before anyone quotes you. Worked for six company sizes, with the ISO 27001 days beside them, what moves the number up or down, and what else you pay.