Quality Management System

ISO 9001 vs ISO 27001: Differences, Overlap and Which to Choose

ISO 9001 and ISO 27001 answer two different questions. ISO 9001 asks: can you consistently deliver what your customers expect? ISO 27001 asks: can you protect the information you hold while doing it?

One is a quality management standard; the other, an information security standard. Although they share the same underlying structure, they certify very different things.

Last Updated: 19 July 2026

Written By: Alan Parker (ISO 27001) and Fiona Parker (ISO 9001). Between us, we practise both standards: Alan has spent a decade helping SMEs implement ISO 27001, and Fiona is a BSI-qualified Lead Auditor in ISO 9001 and ISO 14001. Most comparisons of these standards are written by firms that practise one but not both. We run both, often for the same clients, which is exactly the position many readers of this page are in.

Key Takeaways

This guide compares the two ISO standards: what they share, where they genuinely differ, what each costs a typical small business, and, because it is the question behind most searches for this comparison, which one you should pursue first.

  • ISO 9001 certifies quality; ISO 27001 certifies information security. Same clause structure (4-10) between the standards, but completely different purposes.
  • Neither is a prerequisite for the other. Choose based on what your customers and tenders are actually demanding.
  • Tech, SaaS, and data businesses usually need 27001 first; manufacturers and public-sector suppliers usually need 9001 first.
  • Holding one gives you roughly a third of the other for free. Document control, internal audit, management review and corrective action all transfer; the standard-specific substance does not.
  • Doing both together is cheaper than doing them in sequence. One integrated system, combined audits, and typically 30-40% less effort than two separate implementations.
  • ISO 9001:2026 is due this autumn, but it is no reason to wait. The changes are evolutionary, and a system built now transitions through updates rather than a rebuild.


The two standards at a glance

The standards are structurally siblings but substantively different. If you’ve already done one, then it does give you a genuine head start on the other, but not a shortcut through its subject matter.

AreaISO 9001ISO 27001
What it certifiesQuality management system (QMS)Information security management system (ISMS)
Core questionDo you consistently meet customer requirements?Do you protect the confidentiality, integrity and availability of information?
First published19872005
Current editionISO 9001:2015 (a 2026 edition is expected this autumn. See below)ISO 27001:2022
StructureClauses 4-10 (Annex SL harmonised structure)Clauses 4-10 (same structure) plus Annex A
Controls annexNoneAnnex A: 93 controls across 4 themes
Key artefactsQuality policy, quality objectives, process documentationRisk assessment, Statement of Applicability, Annex A controls
Certification auditStage 1 + Stage 2, then annual surveillanceStage 1 + Stage 2, then annual surveillance
Typical SME implementation timeline3-4 Months3-6 Months
Typical SME cost (implementation support)From £2,950 (coached)From £3,500 (coached)
Typical UK certification body fees (10-50 staff)Roughly £2,500-£5,000 initial, then annual surveillanceRoughly £3,500-£6,500 initial, then annual surveillance
Who mandates itManufacturing supply chains, public sector tenders, engineering and construction frameworksEnterprise customers of tech and services firms, financial services supply chains, public sector data handling

What they share

If you look at both standards, you’ll immediately recognise that they are built on the same structural skeleton, which is, of course, intentional from ISO, and is based on ten key clauses / requirements.

Clause 4 – context of the organisation, interested parties, and scope
Clause 5 – leadership, policy, roles and responsibilities
Clause 6 – planning, risks and opportunities, objectives
Clause 7 – resources, competence, awareness, communication, documented information
Clause 8 – operational planning and control
Clause 9 – monitoring, measurement, internal audit, management review
Clause 10 – nonconformity, corrective action, continual improvement

Both follow the Plan-Do-Check-Act cycle. Both require top management to own the system rather than delegate it to shelfware (the cardinal sin we see when auditing organisations). Both are audited the same way: a Stage 1 review of your documentation and readiness, a Stage 2 assessment of the system in operation, then annual surveillance visits and recertification every three years.

So, the bones are the same, but the detail in some of those clauses differs substantially. However, someone familiar with 9001 will pick up 27001 very quickly and vice versa. We’ll cover the differences in a moment, so hold with us.

In practice, this means a well-run management system has a set of shared requirements that serve as standard practices: a document control approach, an internal audit programme, a management review cadence, a corrective action process, and a way to set and track objectives. Build that machinery once, and it carries both certificates.

What ISO 9001 and ISO 27001 share A shared management system core of Clauses 4 to 10 feeds two standard-specific blocks: ISO 9001 quality substance and ISO 27001 security substance, each leading to its own certificate. Shared machinery (Clauses 4-10) Leadership and policy Document control Internal audit programme Management review built once, serving both ISO 9001 substance Delivery process control (Clause 8) Customer satisfaction measurement ISO 27001 substance Risk assessment and SoA 93 Annex A controls Quality certificate Information security certificate

There are genuine overlaps between the two:

  • Supplier management
  • Non-conformity processes
  • Internal audits
  • An overarching policy
  • Documentation controls

So you can reuse, or rather lean on, the same processes between standards.


Where they differ

The overlap ends at the subject matter, and the differences are bigger than most comparison articles will admit.

Risk is handled very differently.

While ISO 9001 asks you to consider risks and opportunities in a broad, proportionate way related to the quality of products and services, it does not mandate a specific methodology.

We usually tell clients that if you lift the bonnet (or hood, to my US friends) on ISO 27001, the engine beneath it all is ‘risk’. 27001 requires a formal information security risk assessment with defined criteria, an owner for every risk, and a documented treatment plan. This is usually the single largest piece of new work for a 9001-certified organisation moving to 27001. So, you must have an established risk methodology and have evaluated and decided on your response to a host of information security risks.

Annex A has no equivalent in ISO 9001.

ISO 27001 includes a reference set of 93 security controls (you can think of them as safeguards that need to be addressed) grouped into four themes: organisational, people, physical and technological. You do not have to implement all 93, but you must assess each one and justify inclusions and exclusions in a Statement of Applicability.

This is a big piece of work, and arguably the majority of what you need to attend to under ISO 27001. There’s no direct comparison in 9001.

Clause 8 diverges completely.

If you flick quickly through the standards, you’ll immediately see how much Clause 8 differs between the two. In 27001 it’s short and sharp, effectively telling you to keep on top of risks and operations. In all honesty, it took me quite a while to realise that in 27001, Clause 8 says ‘keep the thing running‘ and duplicates the wording on risk from Clause 6. We tell clients who have just emerged from wrestling with Clause 6 that they’ll address Clause 8 by doing everything else in the standard well, much to their relief.

In ISO 9001, Clause 8 is the operational heart of the standard: seven subclauses that cover everything from design and development to the control of nonconforming outputs. You won’t find anything similar in 27001, where it focuses on Clause 6 Planning.

This reflects each standard’s centre of gravity: 9001 lives in your delivery processes; 27001 lives in your risk decisions.

Customer satisfaction is a 9001 concept.

ISO 9001 requires you to monitor customer perceptions and explicitly includes customer focus in its leadership requirements. ISO 27001 has no equivalent; its interested parties are broader, and its concern is the information, wherever it sits.

The evidence burden differs.

A 27001 auditor wants to see controls in operation: access reviews completed, incidents logged and classified, suppliers assessed.

A 9001 auditor wants to see processes producing consistent outcomes: nonconformities trending down, customer complaints handled, objectives measured.

Neither is harder in the abstract, but they exercise different muscles in the business.


Even auditors get it wrong.

Not too long ago, I (Alan) was sitting in a 27001 (information security) audit when the auditor asked to see the ‘preferred supplier list’ and some other artefacts that had no bearing at all upon running an ISMS. I pushed back gently, asking where these were required in the standard (fully well knowing that he was starting to confuse 27001 and 9001). They grudgingly had to admit they weren’t, but wouldn’t admit the truth, which we both knew; they’d confused the standards.

The mandatory paperwork differs too.

People often ask what documents each standard actually requires. Here is the honest list of what is explicitly mandated, side by side. Anything else you produce should exist because it helps you run the business, not because you think an auditor wants it.

Documented informationISO 9001ISO 27001
Scope of the management systemRequiredRequired
Policy (quality / information security)RequiredRequired
Objectives and plans to achieve themRequiredRequired
Evidence of competenceRequiredRequired
Internal audit programme and resultsRequiredRequired
Management review resultsRequiredRequired
Nonconformities and corrective actionsRequiredRequired
Risk assessment process and resultsNot mandatedRequired
Risk treatment plan and resultsNot mandatedRequired
Statement of ApplicabilityNo equivalentRequired
Process documentation to support operationsRequired (as determined necessary)Required (as determined necessary)
Calibration and measurement traceability recordsRequired (where relevant)No equivalent
Design and development recordsRequired (where relevant)No equivalent
Supplier evaluation recordsRequiredDriven by Annex A controls
Customer requirement review recordsRequiredNo equivalent
Control of nonconforming outputs recordsRequiredNo equivalent

Two things stand out from this table. First, the seven shared rows at the top are the integrated core in document form: produce each of those once, covering both standards, and you have the backbone of a combined system. Second, each standard’s unique rows point at its centre of gravity again: 27001’s extras are all about risk, while 9001’s are all about controlling what you deliver.


Which should you do first?

This is the real question, and the honest answer is likely to be ‘follow the money’. We almost always see the drive to certification as a response to buyer pressure, so look at what your contracts and tenders actually demand. Addressing that is what will get you the most support from the leadership around you.

However, if you need some additional help in deciding, then

Choose ISO 27001 first if you are a software, SaaS, IT services or data-handling business.
Your enterprise customers’ security questionnaires already ask for it, and in many procurement processes, it has shifted from a differentiator to an entry requirement. Quality matters to these buyers too, but security is what usually blocks the deal.

Choose ISO 9001 first if you manufacture, build, engineer or deliver physical or process-heavy services.
Supply chain and public sector procurement in these sectors have asked for 9001 for decades, and it is often a scored or mandatory tender requirement. It is also the gentler introduction to management systems if you have never run one.

Consider both together if you sell into buyers who ask for both.
Increasingly includes government frameworks, defence supply chains and larger enterprise procurement. Doing them together is meaningfully cheaper and faster than doing them sequentially, for reasons explained below.

One caution from experience: do not choose a standard because a competitor has it or because it feels like the respectable thing to do. A management system you did not need is a maintenance cost with no return. Anchor the decision in what your customers and prospective customers are actually asking for.

Which standard should you pursue first? A decision flow starting from what customers and tenders are asking for, branching to ISO 9001 first, both standards together, or ISO 27001 first, with typical business profiles under each. What are your customers and tenders asking for? quality both security ISO 9001 first Manufacturing, engineering Public sector tenders Supply chain quality asks Both, together Buyers ask for both Government frameworks One integrated build ISO 27001 first SaaS, IT and data services Enterprise security reviews Deals blocked on security No buyer pressure at all? Question whether you need certification yet.

Already hold one? Here’s your head start…

From ISO 9001 to ISO 27001.
You already have document control, an internal audit programme, management review, corrective action handling, and leadership that understands what an external auditor expects. That machinery transfers directly.

The genuinely new work is the information security risk assessment and methodology, the Statement of Applicability, the Annex A controls themselves, and building security awareness across the team. In our experience, the shared machinery represents perhaps a third of the total 27001 effort; a working QMS makes the ISMS faster, but the security substance still has to be built.

From ISO 27001 to ISO 9001.
The same machinery transfers in the other direction, and 27001 holders tend to arrive with a stronger risk habit than 9001 requires. The new work concentrates in Clause 8: defining and controlling your delivery processes, handling customer requirements and design activity, and managing nonconforming outputs. You will also need to start measuring customer satisfaction deliberately, which many security-first firms have never formalised.

Either direction, the trap to avoid is running two parallel systems. Two document sets, two audit programmes and two management reviews doubles your maintenance burden for no benefit. The whole point of the harmonised structure is that you should not have to.


Running both as one integrated system

We get asked frequently if you can mix your ISMS and QMS, and the answer is ‘yes, but…’

An integrated management system means one set of shared machinery serving both certificates: a single document control approach, one internal audit programme covering both standards, one management review with both on the agenda, one corrective action log. The standard-specific substance (the risk assessment and controls for 27001, the process and quality management for 9001) plugs into that shared core.

So the savings are real and there to be made. We certainly wouldn’t recommend duplicating processes where you already have one established. For example, we would immediately suggest that if you have a noncompliance handling process and database, then there’s an obvious overlap between the two standards, but you’ll need to tag 27001 noncompliances as ‘security’ or something to separate them out from the ISO 9001 ‘quality’ issues. That’s so you can maintain a clean list for both and provide auditors with a way to filter one system from the other. So entirely possible, but just be careful and able to separate the two when necessary.

Certification bodies can audit both standards in combined visits, which reduces audit days against two separate cycles. Internally, you attend one management review instead of two and maintain one system instead of two. For an SME, the integrated route typically saves 30-40% of the effort of sequential, separate implementations.

It also changes the economics of getting consultancy help from someone like ourselves. Implemented separately with coaching support, the two standards would cost £3,500 and £2,950 respectively. We offer a combined programme covering both standards for £5,500: eight coaching sessions, booked as you choose, typically spread across 90 days. The saving exists because the shared machinery genuinely is shared; we build it once, with both certificates in mind from the first session.

One integrated management system, two certificates ISO 9001 and ISO 27001 substance both plug into one shared core of document control, internal audit, management review and corrective action, leading to combined certification audits and two certificates. ISO 9001 substance Process control Customer satisfaction ISO 27001 substance Risk assessment, SoA Annex A controls One shared core Single document set One internal audit programme One management review One corrective action log Combined certification audits ISO 9001 certificate ISO 27001 certificate

What about ISO 9001:2026?

ISO 9001 is in the final stage of its first revision since 2015. The Final Draft International Standard has been issued and publication is expected in autumn 2026, followed by a transition period expected to run to 2029 for organisations already certified.

The changes are evolutionary: a stronger emphasis on a culture of quality and ethical behaviour, clearer treatment of risks and opportunities, and the formal integration of the 2024 climate change amendment. Nothing in the draft alters the analysis on this page, and nothing in the revision warrants delay. An ISO 9001:2015 system built now transitions to the 2026 edition as an update, not a rebuild, and certification bodies will assess against 2015 until the new edition and its transition arrangements are in force. If anything, the revision strengthens the integration case, since the harmonised structure that makes 9001 and 27001 fit together is retained.

We will update this page when the final standard is published.


Where does ISO 42001 for Artificial Intelligence fit in?

We are getting asked about ISO 42001 a lot. Published in late 2023, it does for artificial intelligence what 9001 does for quality, and 27001 does for information security: it certifies an AI management system (AIMS) that covers the responsible development and use of AI.

Structurally, it is another sibling. It follows the same Clauses 4-10 approach, so the shared machinery described on this page (document control, internal audit, management review, corrective action) serves it too, and like 27001 it comes with its own annex of AI-specific controls (34 of them) and a Statement of Applicability – so there’s a lot of similarity with the 27001 structure.

For most businesses, it is not yet a buyer-driven requirement as with 9001 and 27001, but that is changing quickly for firms building or embedding AI into their products. If your customers have started asking about AI governance in their due diligence questionnaires, the practical point is the same one this whole page makes: whichever standards you adopt, build one integrated system, not parallel ones.


ISO 9001 vs ISO 27001 Frequently asked questions

Is ISO 27001 harder than ISO 9001?

It usually involves more new work for a first-time implementer, primarily due to the risk assessment and the 93 Annex A controls. But difficulty depends on your starting point: a chaotic delivery operation will find 9001 harder than a well-run IT firm finds 27001.

Can ISO 9001 and ISO 27001 be certified together?

Yes. Certification bodies routinely run combined audits covering both standards, and an integrated management system is specifically designed for this. You receive two certificates from one programme of audits.

Do I need ISO 9001 before ISO 27001?

No. Neither standard is a prerequisite for the other. Choose based on what your customers are asking for.

Do the standards expire or change?

Both are periodically revised. ISO 27001 was last revised in 2022; organisations certified to the 2013 edition had until late 2025 to transition. ISO 9001:2026 is expected this autumn with a multi-year transition period.

Is certification mandatory?

No standard is legally mandatory in itself, but contracts and tenders frequently make certification a condition of doing business, which for practical purposes amounts to the same thing.