Quality Management System
ISO 9001 vs ISO 27001: Differences, Overlap and Which to Choose
ISO 9001 and ISO 27001 answer two different questions. ISO 9001 asks: can you consistently deliver what your customers expect? ISO 27001 asks: can you protect the information you hold while doing it?
One is a quality management standard; the other, an information security standard. Although they share the same underlying structure, they certify very different things.
Last Updated: 19 July 2026
Written By: Alan Parker (ISO 27001) and Fiona Parker (ISO 9001). Between us, we practise both standards: Alan has spent a decade helping SMEs implement ISO 27001, and Fiona is a BSI-qualified Lead Auditor in ISO 9001 and ISO 14001. Most comparisons of these standards are written by firms that practise one but not both. We run both, often for the same clients, which is exactly the position many readers of this page are in.
Table of Contents
Key Takeaways
This guide compares the two ISO standards: what they share, where they genuinely differ, what each costs a typical small business, and, because it is the question behind most searches for this comparison, which one you should pursue first.
- ISO 9001 certifies quality; ISO 27001 certifies information security. Same clause structure (4-10) between the standards, but completely different purposes.
- Neither is a prerequisite for the other. Choose based on what your customers and tenders are actually demanding.
- Tech, SaaS, and data businesses usually need 27001 first; manufacturers and public-sector suppliers usually need 9001 first.
- Holding one gives you roughly a third of the other for free. Document control, internal audit, management review and corrective action all transfer; the standard-specific substance does not.
- Doing both together is cheaper than doing them in sequence. One integrated system, combined audits, and typically 30-40% less effort than two separate implementations.
- ISO 9001:2026 is due this autumn, but it is no reason to wait. The changes are evolutionary, and a system built now transitions through updates rather than a rebuild.
The two standards at a glance
The standards are structurally siblings but substantively different. If you’ve already done one, then it does give you a genuine head start on the other, but not a shortcut through its subject matter.
| Area | ISO 9001 | ISO 27001 |
|---|---|---|
| What it certifies | Quality management system (QMS) | Information security management system (ISMS) |
| Core question | Do you consistently meet customer requirements? | Do you protect the confidentiality, integrity and availability of information? |
| First published | 1987 | 2005 |
| Current edition | ISO 9001:2015 (a 2026 edition is expected this autumn. See below) | ISO 27001:2022 |
| Structure | Clauses 4-10 (Annex SL harmonised structure) | Clauses 4-10 (same structure) plus Annex A |
| Controls annex | None | Annex A: 93 controls across 4 themes |
| Key artefacts | Quality policy, quality objectives, process documentation | Risk assessment, Statement of Applicability, Annex A controls |
| Certification audit | Stage 1 + Stage 2, then annual surveillance | Stage 1 + Stage 2, then annual surveillance |
| Typical SME implementation timeline | 3-4 Months | 3-6 Months |
| Typical SME cost (implementation support) | From £2,950 (coached) | From £3,500 (coached) |
| Typical UK certification body fees (10-50 staff) | Roughly £2,500-£5,000 initial, then annual surveillance | Roughly £3,500-£6,500 initial, then annual surveillance |
| Who mandates it | Manufacturing supply chains, public sector tenders, engineering and construction frameworks | Enterprise customers of tech and services firms, financial services supply chains, public sector data handling |
What they share
If you look at both standards, you’ll immediately recognise that they are built on the same structural skeleton, which is, of course, intentional from ISO, and is based on ten key clauses / requirements.
– Clause 4 – context of the organisation, interested parties, and scope
– Clause 5 – leadership, policy, roles and responsibilities
– Clause 6 – planning, risks and opportunities, objectives
– Clause 7 – resources, competence, awareness, communication, documented information
– Clause 8 – operational planning and control
– Clause 9 – monitoring, measurement, internal audit, management review
– Clause 10 – nonconformity, corrective action, continual improvement
Both follow the Plan-Do-Check-Act cycle. Both require top management to own the system rather than delegate it to shelfware (the cardinal sin we see when auditing organisations). Both are audited the same way: a Stage 1 review of your documentation and readiness, a Stage 2 assessment of the system in operation, then annual surveillance visits and recertification every three years.
So, the bones are the same, but the detail in some of those clauses differs substantially. However, someone familiar with 9001 will pick up 27001 very quickly and vice versa. We’ll cover the differences in a moment, so hold with us.
In practice, this means a well-run management system has a set of shared requirements that serve as standard practices: a document control approach, an internal audit programme, a management review cadence, a corrective action process, and a way to set and track objectives. Build that machinery once, and it carries both certificates.
There are genuine overlaps between the two:
- Supplier management
- Non-conformity processes
- Internal audits
- An overarching policy
- Documentation controls
So you can reuse, or rather lean on, the same processes between standards.
Where they differ
The overlap ends at the subject matter, and the differences are bigger than most comparison articles will admit.
Risk is handled very differently.
While ISO 9001 asks you to consider risks and opportunities in a broad, proportionate way related to the quality of products and services, it does not mandate a specific methodology.
We usually tell clients that if you lift the bonnet (or hood, to my US friends) on ISO 27001, the engine beneath it all is ‘risk’. 27001 requires a formal information security risk assessment with defined criteria, an owner for every risk, and a documented treatment plan. This is usually the single largest piece of new work for a 9001-certified organisation moving to 27001. So, you must have an established risk methodology and have evaluated and decided on your response to a host of information security risks.
Annex A has no equivalent in ISO 9001.
ISO 27001 includes a reference set of 93 security controls (you can think of them as safeguards that need to be addressed) grouped into four themes: organisational, people, physical and technological. You do not have to implement all 93, but you must assess each one and justify inclusions and exclusions in a Statement of Applicability.
This is a big piece of work, and arguably the majority of what you need to attend to under ISO 27001. There’s no direct comparison in 9001.
Clause 8 diverges completely.
If you flick quickly through the standards, you’ll immediately see how much Clause 8 differs between the two. In 27001 it’s short and sharp, effectively telling you to keep on top of risks and operations. In all honesty, it took me quite a while to realise that in 27001, Clause 8 says ‘keep the thing running‘ and duplicates the wording on risk from Clause 6. We tell clients who have just emerged from wrestling with Clause 6 that they’ll address Clause 8 by doing everything else in the standard well, much to their relief.
In ISO 9001, Clause 8 is the operational heart of the standard: seven subclauses that cover everything from design and development to the control of nonconforming outputs. You won’t find anything similar in 27001, where it focuses on Clause 6 Planning.
This reflects each standard’s centre of gravity: 9001 lives in your delivery processes; 27001 lives in your risk decisions.
Customer satisfaction is a 9001 concept.
ISO 9001 requires you to monitor customer perceptions and explicitly includes customer focus in its leadership requirements. ISO 27001 has no equivalent; its interested parties are broader, and its concern is the information, wherever it sits.
The evidence burden differs.
A 27001 auditor wants to see controls in operation: access reviews completed, incidents logged and classified, suppliers assessed.
A 9001 auditor wants to see processes producing consistent outcomes: nonconformities trending down, customer complaints handled, objectives measured.
Neither is harder in the abstract, but they exercise different muscles in the business.
Even auditors get it wrong.
Not too long ago, I (Alan) was sitting in a 27001 (information security) audit when the auditor asked to see the ‘preferred supplier list’ and some other artefacts that had no bearing at all upon running an ISMS. I pushed back gently, asking where these were required in the standard (fully well knowing that he was starting to confuse 27001 and 9001). They grudgingly had to admit they weren’t, but wouldn’t admit the truth, which we both knew; they’d confused the standards.
The mandatory paperwork differs too.
People often ask what documents each standard actually requires. Here is the honest list of what is explicitly mandated, side by side. Anything else you produce should exist because it helps you run the business, not because you think an auditor wants it.
| Documented information | ISO 9001 | ISO 27001 |
|---|---|---|
| Scope of the management system | Required | Required |
| Policy (quality / information security) | Required | Required |
| Objectives and plans to achieve them | Required | Required |
| Evidence of competence | Required | Required |
| Internal audit programme and results | Required | Required |
| Management review results | Required | Required |
| Nonconformities and corrective actions | Required | Required |
| Risk assessment process and results | Not mandated | Required |
| Risk treatment plan and results | Not mandated | Required |
| Statement of Applicability | No equivalent | Required |
| Process documentation to support operations | Required (as determined necessary) | Required (as determined necessary) |
| Calibration and measurement traceability records | Required (where relevant) | No equivalent |
| Design and development records | Required (where relevant) | No equivalent |
| Supplier evaluation records | Required | Driven by Annex A controls |
| Customer requirement review records | Required | No equivalent |
| Control of nonconforming outputs records | Required | No equivalent |
Two things stand out from this table. First, the seven shared rows at the top are the integrated core in document form: produce each of those once, covering both standards, and you have the backbone of a combined system. Second, each standard’s unique rows point at its centre of gravity again: 27001’s extras are all about risk, while 9001’s are all about controlling what you deliver.
Which should you do first?
This is the real question, and the honest answer is likely to be ‘follow the money’. We almost always see the drive to certification as a response to buyer pressure, so look at what your contracts and tenders actually demand. Addressing that is what will get you the most support from the leadership around you.
However, if you need some additional help in deciding, then
Choose ISO 27001 first if you are a software, SaaS, IT services or data-handling business.
Your enterprise customers’ security questionnaires already ask for it, and in many procurement processes, it has shifted from a differentiator to an entry requirement. Quality matters to these buyers too, but security is what usually blocks the deal.
Choose ISO 9001 first if you manufacture, build, engineer or deliver physical or process-heavy services.
Supply chain and public sector procurement in these sectors have asked for 9001 for decades, and it is often a scored or mandatory tender requirement. It is also the gentler introduction to management systems if you have never run one.
Consider both together if you sell into buyers who ask for both.
Increasingly includes government frameworks, defence supply chains and larger enterprise procurement. Doing them together is meaningfully cheaper and faster than doing them sequentially, for reasons explained below.
One caution from experience: do not choose a standard because a competitor has it or because it feels like the respectable thing to do. A management system you did not need is a maintenance cost with no return. Anchor the decision in what your customers and prospective customers are actually asking for.
Already hold one? Here’s your head start…
From ISO 9001 to ISO 27001.
You already have document control, an internal audit programme, management review, corrective action handling, and leadership that understands what an external auditor expects. That machinery transfers directly.
The genuinely new work is the information security risk assessment and methodology, the Statement of Applicability, the Annex A controls themselves, and building security awareness across the team. In our experience, the shared machinery represents perhaps a third of the total 27001 effort; a working QMS makes the ISMS faster, but the security substance still has to be built.
From ISO 27001 to ISO 9001.
The same machinery transfers in the other direction, and 27001 holders tend to arrive with a stronger risk habit than 9001 requires. The new work concentrates in Clause 8: defining and controlling your delivery processes, handling customer requirements and design activity, and managing nonconforming outputs. You will also need to start measuring customer satisfaction deliberately, which many security-first firms have never formalised.
Either direction, the trap to avoid is running two parallel systems. Two document sets, two audit programmes and two management reviews doubles your maintenance burden for no benefit. The whole point of the harmonised structure is that you should not have to.
Running both as one integrated system
We get asked frequently if you can mix your ISMS and QMS, and the answer is ‘yes, but…’
An integrated management system means one set of shared machinery serving both certificates: a single document control approach, one internal audit programme covering both standards, one management review with both on the agenda, one corrective action log. The standard-specific substance (the risk assessment and controls for 27001, the process and quality management for 9001) plugs into that shared core.
So the savings are real and there to be made. We certainly wouldn’t recommend duplicating processes where you already have one established. For example, we would immediately suggest that if you have a noncompliance handling process and database, then there’s an obvious overlap between the two standards, but you’ll need to tag 27001 noncompliances as ‘security’ or something to separate them out from the ISO 9001 ‘quality’ issues. That’s so you can maintain a clean list for both and provide auditors with a way to filter one system from the other. So entirely possible, but just be careful and able to separate the two when necessary.
Certification bodies can audit both standards in combined visits, which reduces audit days against two separate cycles. Internally, you attend one management review instead of two and maintain one system instead of two. For an SME, the integrated route typically saves 30-40% of the effort of sequential, separate implementations.
It also changes the economics of getting consultancy help from someone like ourselves. Implemented separately with coaching support, the two standards would cost £3,500 and £2,950 respectively. We offer a combined programme covering both standards for £5,500: eight coaching sessions, booked as you choose, typically spread across 90 days. The saving exists because the shared machinery genuinely is shared; we build it once, with both certificates in mind from the first session.
What about ISO 9001:2026?
ISO 9001 is in the final stage of its first revision since 2015. The Final Draft International Standard has been issued and publication is expected in autumn 2026, followed by a transition period expected to run to 2029 for organisations already certified.
The changes are evolutionary: a stronger emphasis on a culture of quality and ethical behaviour, clearer treatment of risks and opportunities, and the formal integration of the 2024 climate change amendment. Nothing in the draft alters the analysis on this page, and nothing in the revision warrants delay. An ISO 9001:2015 system built now transitions to the 2026 edition as an update, not a rebuild, and certification bodies will assess against 2015 until the new edition and its transition arrangements are in force. If anything, the revision strengthens the integration case, since the harmonised structure that makes 9001 and 27001 fit together is retained.
We will update this page when the final standard is published.
Where does ISO 42001 for Artificial Intelligence fit in?
We are getting asked about ISO 42001 a lot. Published in late 2023, it does for artificial intelligence what 9001 does for quality, and 27001 does for information security: it certifies an AI management system (AIMS) that covers the responsible development and use of AI.
Structurally, it is another sibling. It follows the same Clauses 4-10 approach, so the shared machinery described on this page (document control, internal audit, management review, corrective action) serves it too, and like 27001 it comes with its own annex of AI-specific controls (34 of them) and a Statement of Applicability – so there’s a lot of similarity with the 27001 structure.
For most businesses, it is not yet a buyer-driven requirement as with 9001 and 27001, but that is changing quickly for firms building or embedding AI into their products. If your customers have started asking about AI governance in their due diligence questionnaires, the practical point is the same one this whole page makes: whichever standards you adopt, build one integrated system, not parallel ones.
ISO 9001 vs ISO 27001 Frequently asked questions
Is ISO 27001 harder than ISO 9001?
It usually involves more new work for a first-time implementer, primarily due to the risk assessment and the 93 Annex A controls. But difficulty depends on your starting point: a chaotic delivery operation will find 9001 harder than a well-run IT firm finds 27001.
Can ISO 9001 and ISO 27001 be certified together?
Yes. Certification bodies routinely run combined audits covering both standards, and an integrated management system is specifically designed for this. You receive two certificates from one programme of audits.
Do I need ISO 9001 before ISO 27001?
No. Neither standard is a prerequisite for the other. Choose based on what your customers are asking for.
Do the standards expire or change?
Both are periodically revised. ISO 27001 was last revised in 2022; organisations certified to the 2013 edition had until late 2025 to transition. ISO 9001:2026 is expected this autumn with a multi-year transition period.
Is certification mandatory?
No standard is legally mandatory in itself, but contracts and tenders frequently make certification a condition of doing business, which for practical purposes amounts to the same thing.