Guide

Can ISO 9001 and ISO 27001 be combined? Integrated management systems explained

What ISO 9001 and ISO/IEC 27001 have in common, which processes an integrated management system (IMS) can share, and what remains specific to each standard.

Summary

Yes. ISO 9001 and ISO/IEC 27001 share the same high-level structure (Harmonized Structure). Context, leadership, document control, internal audit, management review, corrective actions and improvement can be handled once in an integrated management system. Specific to ISO 27001 are mainly the information security risk assessment, the Annex A controls and the Statement of Applicability.

If you already run a quality management system according to ISO 9001, you have more of an ISMS than you might think.

One structure, several standards

ISO management system standards use a common high-level structure, now called the Harmonized Structure: the same clause numbers, many identical core terms and the same Plan-Do-Check-Act logic. ISO 9001, ISO/IEC 27001 and ISO/IEC 42001 all follow it.

What can be shared

Element Shared in an IMS?
Context of the organization, interested parties Yes, with topic-specific additions
Leadership, policy, roles Yes — one role model, topic-specific policies where needed
Objectives and KPIs Yes, as one set of connected objectives
Competence and awareness Yes
Document control Yes — one process for all documents
Internal audit Yes — one combined audit program
Management review Yes — one review covering all topics
Nonconformities and corrective actions Yes — one process
Continual improvement Yes

What stays specific

  • ISO/IEC 27001: information security risk assessment and treatment, the Annex A controls, the Statement of Applicability.
  • ISO 9001: customer focus, product and service requirements, design and development, control of externally provided processes, customer satisfaction.

Typical path: from ISO 9001 to ISO 27001

  1. Map the existing QMS: which processes, documents and roles exist?
  2. Identify what can be extended (document control, audits, reviews, corrective actions).
  3. Add the information security risk assessment and the Annex A controls.
  4. Extend the audit program and management review.
  5. Prepare a combined or coordinated certification with your certification body.

A note on ISO 9001:2026

The new edition ISO 9001:2026 was published in September 2026, with a transition period for certified organizations. If you are planning ISO/IEC 27001 at the same time, it can make sense to align both changes in one integrated step.

Frequently asked questions

What is a QMS?

A quality management system (QMS) is how an organization plans, controls and improves its processes so that products and services reliably meet customer and regulatory requirements. ISO 9001 is the most widely used standard for it.

What is an integrated management system?

An integrated management system (IMS) combines several management system standards — for example ISO 9001, ISO/IEC 27001 and ISO/IEC 42001 — into one coherent system with shared processes and standard-specific modules.

Talk to us

Want to tackle this in your organization? We help — together with your team.

contact@feldmanncyber.com · +49 (0)151 6275 6121