|
For Certification Body Professionals & ISO Auditors
Monthly News on ISO Standards, Events & Tech
Issue No. 3 · August 2026
|
|
|
|
Lead Story
DAkkS Opens Accreditation for the EU Cyber Resilience Act
On 28 July 2026, Germany's national accreditation body, DAkkS, began accepting applications from conformity assessment bodies seeking accreditation under the EU Cyber Resilience Act, opening one of the first national routes to notification under Regulation (EU) 2024/2847. The CRA sets binding cybersecurity requirements for products with digital elements placed on the EU market, and accreditation is the prerequisite for any body seeking official notification to assess them. Bodies can now apply against two schemes: DIN EN ISO/IEC 17065 for product type-examination under the regulation's Module B, and DIN EN ISO/IEC 17021-1 for management-system assessment under Module H, spanning quality assurance across development and manufacturing.
Before filing, applicants must complete an information session with the Federal Office for Information Security (BSI) to fix their intended scope of accreditation, a step DAkkS has formalized through an updated administrative agreement with BSI that extends the cooperation model already used under the Cybersecurity Act. For certification bodies, this is a first-mover opportunity: CRA obligations phase in ahead of full application in December 2027, and demand for accredited conformity assessment is likely to concentrate quickly around the bodies that secure scope early. CBs weighing entry should open scoping discussions with BSI now, map competence against both the 17065 and 17021-1 modules, and line up internal audit capacity before the application window grows congested. |
|
|
News
UPDATE ISO 45001 DIS ballot runs to 8 September ahead of 2027 publication The Draft International Standard for the first ISO 45001 revision since 2018 opened for formal ballot on 16 June 2026, with national member bodies able to vote and comment until 8 September 2026 and publication expected around mid-2027. The draft extends occupational health and safety beyond physical hazards, treating psychosocial risks such as stress, burnout and workplace behaviour as hazards to be identified and controlled, and adds expectations around hybrid and digital working, workforce diversity, return-to-work arrangements, and oversight of externally provided products and services. With a three-year transition anticipated in line with ISO 9001 and ISO 14001, CBs should route comments through their national mirror committees now and begin mapping OH&S auditor competence against psychosocial risk assessment, an area few existing auditor qualification schemes cover in depth.
NEW ISO 19011:2026 formalizes remote and hybrid audit methods At the end of May 2026, the fourth edition of EN ISO 19011 was published, redefining the guidelines for conducting management system audits and fully replacing the 2018 edition. The revision officially defines a "remote auditing method" and expands guidance on hybrid approaches, digital evidence handling, and auditor competence for technology-enabled engagements. CBs should refresh audit programmes, sampling justifications, and auditor training records to reflect the new guidance, since accreditation bodies will expect alignment during upcoming witness assessments.
UPDATE ISO/IEC 27000:2026 sixth edition streamlines the ISMS family overview In July 2026, ISO and IEC published the sixth edition of ISO/IEC 27000, replacing the 2018 edition. This is a substantial revision with a new title, new structure, and new purpose. The sixth edition was revised to emphasize its role as an overview document for ISMS standards, now focusing on concepts, principles and relationships rather than acting primarily as a terminology document. ISMS auditors should note that many definitions previously anchored in 27000 have migrated to individual 27xxx standards, which affects citation practices and audit references but does not alter ISO/IEC 27001:2022 requirements.
ALERT EU AI Act GPAI enforcement begins 2 August 2026, elevating ISO/IEC 42001 audits Providers of general-purpose AI models must comply with obligations effective August 2, 2025, with enforcement by the European Commission beginning on August 2, 2026, and models already on the market before August 2, 2025 required to comply by August 2, 2027. As of 2026, ISO 42001 is not a harmonized standard under the EU AI Act, so certification does not by itself grant a presumption of conformity. CBs delivering AIMS certification should clarify this scope boundary in client communications while positioning ISO/IEC 42001 audits as evidence of governance maturity ahead of the forthcoming prEN 18286 harmonized standard.
UPDATE ISO 37001:2025 transition milestones under IAF MD 30 continue through 2028 IAF MD 30 sets a three-year transition for anti-bribery management systems, with accreditation body transitions of CABs to be completed by 28 February 2026, one year from publication of the standard, and initial and recertification audits conducted only against ISO 37001:2025 thereafter. Certificates to ISO 37001:2016 are no longer valid after the transition end date, and assessments will be conducted against the published version of the standard aligned with final IAF transition requirements. CBs should confirm auditor qualifications against the 2025 edition and schedule client transition audits well before the closing deadline to avoid capacity bottlenecks in the final quarter.
|
|
|
Market Intelligence
First-half 2026 results from the two largest players show that certification volume and certification margin have decoupled. SGS reported H1 revenue of CHF 3,683 million, up 7.6% with 5.6% organic growth, and a Business Assurance division delivering 7.3% organic growth at an 18.9% adjusted operating margin, with Certification posting high single-digit organic growth led by medical devices and food, Digital Trust growing double digits on information security and cybersecurity demand, and Sustainability growing double digits on greenhouse gas verification, forestry and circularity work source. Bureau Veritas grew H1 revenue to EUR 3,258.4 million at 5.0% organic, accelerating to 5.5% in Q2 at a 15.5% group adjusted operating margin, but its Certification division managed only 1.9% organic growth and saw margin contract 253 basis points to 15.4%, even as its sustainability-related and digital cyber certification activities delivered high single-digit organic growth source. Against a broader TIC market growing at a modest 3.8% CAGR from USD 254.41 billion in 2026 source, the signal for smaller CBs is that scope mix now drives profitability more than certificate count: mature QMS and EMS work funds the base, while cyber, carbon and AI-adjacent scopes carry the growth.
The Cyber Resilience Act has created a conformity assessment capacity gap that is currently unfilled. The CRA's Chapter IV provisions on notification of conformity assessment bodies took effect on 11 June 2026, reporting obligations for actively exploited vulnerabilities and severe incidents begin on 11 September 2026, and the regulation applies in full from 11 December 2027 source. Article 35(2) asks Member States to strive to ensure a sufficient number of notified bodies by 11 December 2026 specifically to avoid bottlenecks that hinder market entry, yet as of 26 June 2026 not a single notified body had been designated for the CRA in the Commission's NANDO database, leaving roughly an 18-month window in which demand will rise sharply while capacity remains finite source. For bodies with product certification competence, this is the clearest scarcity-priced opportunity on the 2026 board, and the accreditation routes now opening at national level are the practical on-ramp. Bodies without 17065 infrastructure should decide early whether to build, partner, or refer this work rather than lose the client relationship entirely.
Sustainability assurance has become a smaller but firmer market, with the accreditation architecture still being assembled. The Omnibus package narrowed mandatory CSRD reporting to undertakings above 1,000 employees and EUR 450 million net turnover, delayed the remaining waves by two years, and removed the planned move to reasonable assurance, confirming limited assurance as the permanent requirement, with EU limited assurance standards due for adoption by July 2027 source. In parallel, ISO published the ISO 14019 series in February 2026, with Part 1 separating validation of forward-looking claims from verification of historical sustainability information and Part 4 specifying competence, operational and impartiality requirements for the bodies performing that work source. Practitioners are warning of a verification body capacity shortfall and calling for accelerated accreditation pathways with clearer scope boundaries between GHG-specific verification under ISO 14065 and ISO/IEC 17029 and broader sustainability assurance source. CBs should treat the window before the 2027 assurance standards as the time to secure 14019 scope, since fewer in-scope clients means each mandate is larger and harder to win late.
Consolidation continues to set the valuation benchmark for independent certification bodies. The TIC and compliance sector recorded 66 transactions in Q1 2026 against 56 in Q1 2025, following more than 280 announced deals across 2025 compared with 270 in 2024 source. Mid-market pricing is visible: Certania acquired construction inspection and compliance platform Ica Group in February 2026 at a GBP 30.5 million enterprise value, roughly 10x 2025 adjusted EBITDA, while sponsor-backed platform deals cluster in the 10x to 20x range, with dispersion driven by regulatory embeddedness, recurring revenue visibility and integration capability rather than sector label alone source. European consolidators including Normec, Phenna Group and Celnor have also begun buying into the United States, extending competition for both clients and accredited auditor capacity. For owner-managed CBs, the practical takeaway is that accredited scope breadth and contracted surveillance revenue are what move a multiple, and both are built years before any conversation with a buyer.
|
|
|
Upcoming Events
August 5–7, 2026 | ISO 9001:2015 Internal Auditor (3-Day) — Virtual, Intertek Academy This three-day course equips participants with the knowledge and practical skills needed to conduct internal audits of quality management systems in accordance with ISO 19011, covering the full audit process from planning and preparation through to follow-up. Certification body personnel and internal auditors will benefit from a structured refresh of QMS audit methodology ahead of the pending ISO 9001 revision.
August 10, 2026 | ISO 14001:2026 Transition Essentials — Virtual, Intertek Academy This interactive, eight-hour instructor-led workshop is designed specifically for EMS practitioners and certified site teams preparing for a confident and successful transition to ISO 14001:2026. The session is directly relevant for EMS auditors and CB scheme managers who need early alignment with the revised environmental management standard before transition audits begin.
August 16–21, 2026 | IAAC 35th General Assembly — Lima, Peru The Inter-American Accreditation Cooperation convenes its regional accreditation bodies, evaluators, and stakeholders for governance decisions, MLA/MRA committee work, and technical exchanges under the new Global ACI framework. Certification bodies operating across the Americas should follow outcomes closely, as decisions here shape peer-evaluation practices and accreditation recognition arrangements in the region.
August 17, 2026 | Certified ISO/IEC 27001 Lead Auditor Training — United States, Bilginç IT Academy This four-day accredited course prepares participants to plan, conduct, and report third-party audits of information security management systems against ISO/IEC 27001. With ISMS certification demand continuing to accelerate, the program is a practical route for auditors seeking to expand competence scopes and for CBs staffing new 27001 audit teams.
|
|
|
TIC Operating System Changelogs
NEW Client Portal replaces open-link flow A secure self-service Client Portal is now live, offering magic-link login, audit status visibility, contract signing, team access, and Mongolian and Portuguese language support. This gives CBs a controlled environment for client interactions, replacing the previous open-link approach and reducing risk around sensitive audit communications.
NEW Auditor App with onboarding flow A dedicated Auditor App is now available, allowing CBs to invite auditors who then sign up and complete detailed profiles. Direct audit access from the Cockpit is currently in secure-access testing, streamlining how CBs manage auditor participation across engagements.
UPDATE Cockpit improvements for audit operations The Cockpit now supports custom application numbering, bulk document upload in audits, a new Resources & Help section, and more flexible pricing and currency setup, with existing setups unaffected. These changes reduce administrative friction for CBs handling high audit volumes and varied client configurations.
|
|
|
|
|