The next few years will bring a major convergence in quality and compliance standards. ISO 9001, the foundational global quality management system (QMS) standard, is being revised for 2026. In aerospace and defense, AS9100 is transitioning into IA9100 to align with ISO’s revisions and to embed tighter supply-chain and digital-assurance practices. At the same time, the automotive sector’s IATF 16949 standard is going through its own modernization, and U.S. defense suppliers are preparing for CMMC cybersecurity certification, which is derived from NIST SP 800-171 requirements.
This simultaneous wave of revisions is no coincidence — it reflects an industry-wide effort to harmonize quality, risk, and cybersecurity expectations across manufacturing sectors. The result is a new generation of management systems built around digital supply chains, resilience, and data integrity.
The Headline Updates in ISO 9001:2026
ISO Technical Committee 176 is moving the revision forward: the Draft International Standard (DIS) was issued in August 2025, the FDIS stage is expected in early 2026, and final publication is anticipated around September 2026.
The core Annex SL structure will stay the same, but expect refinements in areas such as:
- Leadership accountability and ethical conduct
- Quality culture and employee engagement
- Integration of risk and opportunity into business planning
- Organizational knowledge management
- Supplier and lifecycle assurance language
In addition, the ISO 9001:2015/Amd 1:2024 “Climate Change” amendment, which took effect in February 2024, already added two important references requiring organizations to factor climate change into their contextual analysis and stakeholder expectations.
Recommended preparation steps:
- Reassess your context, risk, and leadership clauses in light of climate and sustainability considerations
- Strengthen change-management and knowledge-retention processes
- Audit supplier qualification and performance data for resilience and sustainability readiness
From AS9100 to IA9100: What’s Changing and When
The aerospace and defense sector will see AS9100 rebranded as IA9100, reflecting the International Aerospace Quality Group’s (IAQG) push for global alignment. IAQG plans to keep pace with ISO 9001:2026 through two stages:
- A limited update addressing near-term needs and rebranding (2025–2026)
- A comprehensive update once ISO 9001:2026 is officially published (2027)
The IA9100 revision is expected to preserve hallmark aerospace requirements — product safety, configuration management, counterfeit-parts prevention — while modernizing supplier management and digital assurance.
Action items for aerospace organizations:
- Map your existing AS9100D controls against the ISO 9001:2026 drafts
- Plan for two transition audits rather than one
- Start updating supplier quality agreements to anticipate new cybersecurity and export-control clauses
IATF 16949: What’s Coming for Automotive
The International Automotive Task Force (IATF), which governs IATF 16949, has confirmed a revision cycle is underway, expected to follow ISO 9001:2026’s publication by 12–18 months. The next release is tentatively being referred to as IATF 16949:2027, though this is not yet finalized.
Like IA9100, the updated standard will remain structurally tied to ISO 9001 while preserving automotive-specific requirements, including:
- Core tools (APQP, PPAP, FMEA, SPC, MSA)
- Traceability and product safety
- Embedded software quality and cybersecurity for vehicle systems
- Customer-specific requirements (CSRs) and supplier performance metrics
Focus Areas of the Upcoming Revision
Based on IATF and AIAG working-group discussions from 2024–2025, several enhancements are under consideration:
- Cybersecurity and software assurance — closer integration with ISO/SAE 21434 and UNECE R155 frameworks
- Sustainability and ESG requirements — alignment with ISO 9001:2026’s climate-action amendment
- Data integrity and digital manufacturing — explicit controls for AI-assisted inspection, digital twins, and MES/ERP data traceability
- Remote audits and AI-assisted quality monitoring — formal recognition of digital audit methods that emerged during the COVID era
- Enhanced supplier risk management — more detailed supplier scorecarding, early-warning systems, and escalation protocols
How IATF and ISO Are Linked
IATF’s internal communications emphasize that IATF 16949 will not be reissued independently of ISO 9001:2026 — meaning the next version is expected to reference ISO 9001:2026 clauses directly, with automotive-specific requirements layered on top.
For multi-sector suppliers working across automotive, aerospace, and defense, this timing matters:
- A single harmonized QMS foundation can underpin IATF, IA9100, and CMMC controls simultaneously
- Shared processes for risk, change control, supplier management, and data assurance will simplify cross-certification
Where NIST and CMMC Fit In
CMMC and NIST SP 800-171 continue to mature as cybersecurity baselines for defense and aerospace, and they relate closely to data-protection policies that may already exist within a manufacturer’s ISO/AS9100 QMS.
Integrating NIST/CMMC into ISO/IA9100 QMS processes typically involves:
- A gap assessment mapping current cybersecurity compliance
- Treating DFARS and CMMC obligations as customer-specific requirements under Clause 8
- Applying risk-based thinking to data protection, supplier cyber readiness, and system access control
Both the IA9100 and IATF 16949 committees are exploring references to information security management systems (ISMS) to better align with ISO/IEC 27001 and the broader industry push toward secure supply chains.
A Unified Transition Timeline
| Year | Expected Standard | Key Actions |
|---|---|---|
| 2025 | ISO 9001 DIS published | Conduct early gap analysis; adopt the climate-change clause |
| 2026 | ISO 9001:2026 finalized; IA9100 limited update | Begin transition planning; train leadership; audit supplier flow-down |
| 2027 | IA9100 major revision; IATF 16949 revision | Align documentation; unify audit cycles; integrate CMMC/NIST |
| 2028 | Industry-wide transition deadline | Achieve full cross-sector certification alignment |
The Strategic Payoff
Organizations that integrate updates across ISO 9001, IA9100, IATF 16949, and NIST/CMMC can:
- Build a single governance framework covering quality, risk, and cybersecurity
- Leverage data-driven performance metrics across sectors
- Simplify supplier assurance and auditing across automotive, aerospace, and defense supply chains
- Strengthen resilience and trust with regulators, OEMs, and customers
- Expand into new markets, including defense and aerospace, more easily
Conclusion: Preparation Starts Now
ISO 9001:2026 is shifting the emphasis toward leadership, knowledge management, sustainability, and risk. IA9100 (formerly AS9100) is being rebranded to align fully with ISO’s 2026 structure. IATF 16949:2027 will bring cyber, digital, and ESG requirements into the automotive supply chain. And NIST and CMMC requirements now need to be operationalized directly within QMS processes rather than treated as a separate compliance track.
For multi-sector suppliers, this alignment period is an opportunity to build a unified, future-proof management system. Given the scale of the changes ahead, starting early — from gap analysis to updating supplier agreements — is the single most important step organizations can take to navigate the 2027–2028 transition smoothly.
Source: Iafrate, D. (2026). ISO 9001 in 2026: What’s Changing—and How AS9100 (IA9100), IATF 16949, NIST & CMMC Fit Together. Quality Magazine, January 2026. qualitymag.com/articles/99324







