
As the sector prepares for the new ISO 9001:2026, the most practical question returns: is it really worth it? A reflection on the true cost — and value — of compliance.
There's a question that comes up every time a standard is updated, and it comes up now too, as the sector prepares for the new ISO 9001:2026: is it really worth it? It's not a rhetorical question: it's the most concrete one an organization can ask.
According to ACCREDIA 2024 data, Italy has 138,810 ISO 9001-certified sites — almost triple the second-ranked standard and more than all the others combined:
Italy ranks first in Europe and second in the world for the number of certified sites. ISO 9001 is the most widespread in the country, and all the other standards integrate with it.
The technical changes are limited: not a rewrite but an update with a precise direction — more governance, more attention to ESG and digital. The changes with real impact concern three areas: leadership, which must be demonstrable in behaviour and not just in documents; risk management, which becomes a continuous process instead of a static register; and digital, with the need to ensure the reliability of the data used in processes. The direction is clear: less formal box-ticking, more verifiable substance.
When a revision arrives, costs are the first thing to materialise: internal ones (Quality Manager hours, documentation, training) and external ones (consultants, certification bodies, courses). But the heaviest cost is often the least visible: producing documentation no one will read, procedures written for the auditor and not for the people doing the work. That's not compliance, it's theatre. And theatre costs without giving anything back.
On the other side are the benefits: a stronger organizational culture, less waste, less rework. Real, but hard to quantify and built over time. The return of a well-made system shows when processes hold under pressure, when people know how to act without waiting for instructions, when an external change doesn't put everything back into question. It's an investment with a long horizon.
Faced with a revision, there have always been two paths: the documentary one (updating procedures and records) and the more demanding one (training people, changing behaviour, embedding the standard in the way work is done). ISO 9001:2026 narrows the space for the first: when the standard requires the quality culture to be demonstrably lived, updating documents is no longer enough.
ISO 9001:2026 won't be the last change. Each time the cycle starts over: gap analysis, consultants, documentation, costs. Not because standards change too often, but because many organizations have built their system around the standard rather than independently of it. Moreover, many requirements are already present, in a different form, in other standards: the overlap is huge and often ignored. What's needed is a system built not around a specific standard but one that evolves with the organization.
Compliance doesn't spread through well-organised document archives but when the right information reaches the right people at the moment they need it. The key shift is not training itself but the awareness it produces: training transfers content, awareness changes how decisions are made and how a problem is spotted before it becomes a non-conformity. It's the difference between a system designed to pass an audit and one designed to make an organization work better. The first costs every time; the second, over time, gives back.
With Complify, ISO 9001 costs less: documentation, audits and deadlines in one platform.