The ISO 9001 Gap Nobody’s Talking About
ISO 9001 is getting an update, and if you’re a manufacturer, you’ve heard the buzz. The next revision is bringing stronger requirements around risk-based thinking, supply chain accountability, and operational resilience. Quality management teams are scheduling gap assessments, prepping for transition audits, and bookmarking webinars.
Most of those conversations are missing something: cybersecurity.
Why ISO 9001 exists
ISO 9001 isn’t a bureaucratic checkbox exercise. It’s a framework for making sure you consistently deliver products and services that meet customer and regulatory requirements, with a disciplined approach to identifying anything that could get in the way of that.
The risk-based thinking requirements embedded in ISO 9001 ask you to look at your processes, your people, your suppliers, and your environment, and honestly assess what could go wrong. Decade by decade, that list has gotten longer. Supply chains stretched globally, regulatory requirements multiplied, and somewhere along the way, the biggest operational risk most manufacturers face became a compromised computer.
A cyberattack is a quality event
A ransomware attack locks your production systems. Orders can’t be fulfilled, shipments are delayed, and customers get a call they weren’t expecting. Depending on your manufacturing sector, that can be a contractual failure, a regulatory event, or both.
A phishing email tricks someone in engineering into opening a malicious file. Design specs are corrupted, or worse, exfiltrated by a competitor. The product that ships six weeks later may or may not be the product your customer ordered.
And those phishing emails are getting harder to spot. AI-generated attacks are more targeted, more convincing, and arriving at scale. Or a supplier’s systems are breached, and the compromise travels up the chain to you, or further to your customers. The threat landscape your QMS was designed around five years ago looks nothing like the one you’re operating in today.
Every one of these scenarios is a quality management failure. ISO 9001 has always required manufacturers to think about risks to product conformity, customer satisfaction, and process integrity. Cyber threats have become the most direct and fastest-moving source of those risks — and yet most quality management systems treat it as a different department’s problem. It isn’t.
The new revision makes this harder to ignore
The final language of ISO 9001:2026 isn’t fully public yet, and we’re not going to pretend otherwise. What’s been signaled from the standard’s development process points toward stronger requirements around risk, resilience, and organizational context. Auditors will likely ask harder questions about business continuity, supplier risk management, and recovery capabilities.
“We don’t have a formal cyber program” won’t age well as an answer.
If you’re preparing for the transition, your readiness assessment should include your cybersecurity posture. The two are more connected than most QMS plans acknowledge.
AS9100 figured this out years ago
If you’re in aerospace or defense manufacturing, you may already know this firsthand. AS9100 — the quality management standard built on ISO 9001 for that sector — has embedded information security and operational security controls as explicit requirements. The aerospace and defense supply chain recognized years ago that a compromised QMS is a national security risk.
For defense contractors specifically, CMMC (the Cybersecurity Maturity Model Certification) takes it further. Cybersecurity isn’t a quality consideration there — it’s a condition of doing business with the Department of Defense.
The broader manufacturing industry is catching up to what aerospace already knows. Regulators, customers, and quality auditors increasingly expect manufacturers to treat cybersecurity as a core operational discipline.
What this actually means for your business
Questions to consider as you’re going through the process:
Take stock of what you’re protecting — and where it lives. What systems touch your production environment? What data moves between you and your suppliers? Where does a breach create a quality impact? Map it the same way you’d map any other process risk.
Assess your current controls. Do you have documented Incident Response procedures? Are your employees trained to recognize Phishing? Are the systems running your production equipment separated from your general business network?
Include cybersecurity in your FMEA and risk register. If you maintain a formal risk register as part of your QMS, cyber threats belong there. A ransomware attack has a severity, a likelihood, and a detection method. Treat it the same way you’d treat any other process failure.
Know your Third Party risk Management Strategy. ISO 9001 has always required you to manage supplier quality. The same logic extends to supplier security. A breach that enters your environment through a vendor is your problem too.
Have a plan for when something happens. Not if, but when. How quickly can you recover? Who gets called? What’s your communication protocol with customers? A mature cybersecurity program includes Incident Response, not just prevention.
This doesn’t have to be complicated
Most of what protects smaller manufacturers isn’t exotic. It’s consistent, well-implemented fundamentals recommended by people who understand your environment, your industry, and cybersecurity.
ISO 9001 has always been about building systems that work reliably under real-world conditions. A sound cybersecurity program does the same thing. The manufacturers who navigate the ISO 9001:2026 transition most smoothly won’t be waiting for an auditor to surface the gap. They’ll have already closed it.
Want to learn more? We work closely with local MEPs across New York State and can help talk about how we can build a cybersecurity strategy that fits your business mission, and ISO 9001 or AS9100 strategy.
Frequently asked questions
Is cybersecurity actually required by ISO 9001? Not explicitly — ISO 9001 doesn’t call out cybersecurity by name. But it does require organizations to identify and manage risks that could affect product quality, customer satisfaction, and operational continuity. A ransomware attack that shuts down your production line or corrupts your design specs qualifies. The standard gives you the framework; cyber risk fills in a gap most QMS plans don’t account for.
What’s the difference between ISO 9001 and AS9100? AS9100 is built on ISO 9001 but adds requirements specific to the aerospace and defense industry — including information security controls. If you’re supplying to the aerospace or defense supply chain, AS9100 is likely the standard you’re working toward, and it already assumes cybersecurity is part of your quality program.
What is CMMC, and do I need it? CMMC (Cybersecurity Maturity Model Certification) is a Department of Defense requirement for companies in the defense supply chain. If you sell to or contract with the DoD — directly or as a subcontractor — CMMC certification is becoming a condition of doing business. It’s separate from ISO 9001 but addresses similar themes: risk management, operational controls, and supply chain security.
Where do I start if I’ve never thought about cyber risk in the context of my QMS? Start with your risk register. If you maintain one as part of your ISO 9001 program, add a cyber risk row and think through severity, likelihood, and what controls you have in place. If you don’t have a risk register, that’s worth addressing regardless of cybersecurity. From there, a basic cybersecurity assessment will tell you where the biggest gaps are.
Do I need to hire a cybersecurity company to comply with ISO 9001? ISO 9001 doesn’t mandate any specific vendor or solution. What it requires is that you’ve identified your risks and have reasonable controls in place. For most smaller manufacturers, that means working with a cybersecurity partner who understands your environment and can build a program proportionate to your size and risk profile.



