ISO's Directives publish, for free, the clause skeleton that ISO 9001:2015 and ISO/IEC 27001:2022 both derive from; here it is clause by clause, with the line between a shared worklist and a shared audit.
Hold an ISO 9001 certificate and adopt ISO/IEC 27001, or the reverse, and the usual answer to "how much of this is new work" is that the two standards share a structure. True, and it settles nothing about how much of the second programme is work the organisation already does. ISO publishes that answer at no cost. The ISO/IEC Directives, Part 1, Consolidated ISO Supplement states in Annex SL, clause SL.8.2, that "Type A MSS shall apply the harmonized structure detailed in Appendix 2." That structure is clauses 4 to 10 of a management-system standard, and ISO 9001:2015 and ISO/IEC 27001:2022 both derive their management-system clauses from it. What the two do not share is where the audit happens.
The supplement online today is Edition 2024 (V01/2024). Annex SL clause SL.8.1 says who the harmonized structure is for: "It will be particularly useful for those organizations that choose to operate a single (sometimes called “integrated”) management system that can meet the requirements of two or more MSS simultaneously." Then SL.8.2:
Type A MSS shall apply the harmonized structure detailed in Appendix 2.
Type A is defined in SL.2.5:
Type A MSS — MSS (SL.2.2) providing requirements. EXAMPLE Management system requirements standards (specifications); management system sector-specific requirements standards.
Nothing in the Directives calls either ISO 9001 or ISO/IEC 27001 a Type A management system standard, so the step to them is an inference. ISO's catalogue lists ISO 9001:2015 as Quality management systems — Requirements (fifth edition, September 2015) and ISO/IEC 27001:2022 as Information security, cybersecurity and privacy protection — Information security management systems — Requirements (third edition, October 2022). Both are requirements standards; the Directives define a Type A standard as one providing requirements; Type A standards shall apply the harmonized structure.
Both texts are paywalled; the catalogue pages serve titles and edition years only, and nothing here quotes either standard. "Derive from" is as far as I take it, because the Directives let a committee add discipline-specific text and, in exceptional cases, deviate, so "identical" is a claim I cannot check. ISO's catalogue lists a revised ISO 9001 as expected in September 2026; everything here cites the 2015 edition.
Appendix 2 of Annex SL is a link to a separate document, ISO/IEC Harmonized structure for MSS with guidance for use, approved on 2025-07-30 under TMB Resolution 74/2025.
The discipline is a placeholder, defined on page 1: "XXX = a Management System Standard (MSS) discipline specific qualifier (e.g. energy, road traffic safety, IT security, food safety, environment, quality) that needs to be inserted". The top-level clauses are 4 Context of the organization, 5 Leadership, 6 Planning, 7 Support, 8 Operation, 9 Performance evaluation and 10 Improvement (numbering normalised).
The sub-clauses that require an artefact to exist use one of two formulas, and the document's informative guidance column keys them at general guidance g): "… shall be available …" means "the documented information is available for use"; "… shall be available as evidence of …" means it "is to provide evidence of conformity". Over the normative text, "shall be available as documented information" occurs three times and "shall be available as evidence of" five times. Here they are, with 8.1 kept apart because it is the first kind.
| Clause | Title (as printed) | Duty (verbatim fragment) |
|---|---|---|
| 4.3 | Determining the scope of the XXX management system | "The scope shall be available as documented information." |
| 5.2 | XXX Policy | "The XXX policy shall: — be available as documented information; …" |
| 6.2 | XXX objectives and planning to achieve them | "The XXX objectives shall: … g) be available as documented information." |
| 7.2 | Competence | "Appropriate documented information shall be available as evidence of competence." |
| 8.1 | Operational planning and control | "Documented information shall be available to the extent necessary to have confidence that the processes have been carried out as planned." |
| 9.1 | Monitoring, measurement, analysis, and evaluation | "Documented information shall be available as evidence of the results." |
| 9.2.2 | Internal audit programme | "… shall be available as evidence of the implementation of the audit programme(s) and the audit results." |
| 9.3.3 | Management review results | "… shall be available as evidence of the results of management reviews." |
| 10.2 | Nonconformity and corrective action | "… shall be available as evidence of: — the nature of the nonconformities and any subsequent actions taken; — the results of any corrective action." |
Source: HS normative column, pages 14 to 29; bullet glyphs rendered as dashes.
The HS names each of those artefacts once, and the placeholder is the only thing that changes when the qualifier is quality or IT security. Whether the rows in that table exist once or twice in an organisation is that organisation's choice, and nothing in the text asks for twice.
The Directives reserve the room for divergence themselves. SL.8.3(e):
A committee may add or insert discipline-specific text within Appendix 2. Examples of additions include: … 4) additional text that enhances the existing requirements in Appendix 2.
And SL.8.3(i):
If, due to exceptional discipline-specific circumstances, text from the harmonized structure cannot be applied in the management system standard, then the committee may amend the text and introduce a deviation.
Where the additions go is visible in the HS. Clause 8 there is one sub-clause, 8.1 Operational planning and control. The guidance column, addressed to standards writers, says beside it: "Clause 8 is typically the area of the HS where MSS writers add the most discipline-specific requirements. For this reason, in many MSS, Clause 8 is often longer than other clauses." ISO 9001, per that guidance, "includes requirements for determining customer requirements, design and development, externally provided processes, products, and services, control of production and service provision, release of product and service delivery, and control of nonconforming output". ISO/IEC 27001 "includes operational requirements for information security risk assessment and treatment". ISO/IEC 27001 also carries an annex of controls, Annex A, which no free source here names; I state it as a structural fact and quote nothing from it.
What each standard puts under clause 8, and what 27001 adds in its annex, is discipline-specific by the Directives' own arrangement, and it is what an auditor for that discipline comes to test. "We did the management-system work" is a true sentence about clauses 4 to 7, 9 and 10, and says nothing yet about the rest.
The next thing a second programme reaches for is a mapping: this 9001 clause corresponds to that 27001 clause. The vocabulary for what a mapping can claim already exists, in NIST SP 1347, the August 2026 quick-start guide to informative references for the US Cybersecurity Framework 2.0, used here for its definitions and not as a framework to adopt. Its opening sentence on the subject: "Informative references identify relationships between elements of different source documents". The glossary then distinguishes kinds. A crosswalk "indicates relationships between pairs of elements without additional characterization of those relationships". Derived relationship mappings "are non-authoritative and represent a starting point when comparing reference documents". NIST also says it "does not conduct correctness testing on non-NIST submitted mappings".
The guide also quotes, from NIST IR 8278r1, a scenario I read as the reader's own: "The organization needs to comply with a new standard, so it is necessary to determine which of its requirements are already met, which are not currently met, and which potentially conflict with other requirements." The guide never mentions ISO 9001; the fit is my reading.
The rule I would apply, with any tool, is this. The shared clauses are one worklist read through two lenses: one management review, one internal-audit programme, one competence record, one documented-information discipline, each satisfying both qualifiers. A link between a 9001 clause and a 27001 clause is recorded as a relationship of a stated kind, a bare crosswalk at minimum, and never as an equivalence: it says where to look, and it never says a requirement has been met twice. The discipline-specific requirements, 9001's clause 8 and 27001's risk treatment and controls, are tested on their own terms, so "done" on the shared clauses leaves them open.
devguard's catalogue holds both standards, so here is what its number means. ISO 9001:2015 is in the catalogue with clauses 4 to 10 and their sub-clauses, and with a twenty-step guided journey in six phases; each step carries instructions on what the clause asks, how to complete it, and what evidence to keep. Its management-system clauses are mapped to their ISO/IEC 27001:2022 counterparts and its external-provider clauses to the supplier controls of ISO/IEC 27002:2022. Every match is recorded as a partial correspondence, none as full, and the targets are 27001's clauses, not its annex. Of 9001's clause 8, only the external-provider sub-clauses carry a match; the operational clause is where the mapping stops.
Where a control is matched to a control in another framework you already run, and that other control reads Full or Partial, the first counts as covered too, but only if it had nothing of its own: a control covered in its own right is never counted twice, and a match never lifts a control above Partial. Coverage is calculated when you look at it, from the tasks, links and matches behind each control; it is never stored and cannot be set by hand. All non-cancelled tasks done reads Full; any task in progress, in review or done reads Partial; open tasks only reads None. With no tasks, any linked policy, asset, risk, vendor or evidence item reads Partial, and nothing behind it reads Unknown; Not relevant leaves both numerator and denominator. The percentage is covered over relevant, and covered counts Full, Partial and indirectly covered controls alike. Seeding, role ownership and re-planning are in the July post on the worklist.
First, the seeded journeys for ISO 27001 and ISO 9001 link to no control: across the eighteen guided journeys, twenty-one of 318 steps carry a control link, all of them in the SOC 1 and SOC 2 journeys. So finishing either ISO journey moves the roadmap's "tasks done" counter and never the coverage percentage. Second, "covered" includes partial progress and is not a conformity claim: one linked evidence item, never reviewed, already makes a control read Partial and count as covered, and nothing checks that evidence exists, is current or was approved. Third, a control can be marked not relevant with an optional note; the change is audit-logged with who and when, and the control leaves both numerator and denominator. The action is available through the API; the app itself has no button for it. The Statement of Applicability report lists linked policies, assets and risks beside each control and never prints the note.
The shared clauses are one worklist read through two qualifiers, and a mapping between them tells you where to look. The clause-8 requirements and the 27001 controls are tested on their own terms by an auditor who came for that discipline, and no coverage number stands in for the visit.
The coverage, mapping and journey behaviour described above lives in devguard's Tasks module: devguard.ch/platform/tasks.
Vadim leads engineering, the architecture, automation, and integrations that let compliance live. He's set on making a serious, audit-grade system genuinely easy to run.
Start free, bring your frameworks, and keep the evidence attached as the work ships — no setup friction, no audit-week fire drill.
Start free, bring your frameworks, and keep the evidence attached as the work ships — no setup friction, no audit-week fire drill.