June 2026: Key Developments in ISO

June 2026 shows a clear shift toward trusted digital ecosystems, verifiable information, and stronger management-system governance.

Across cybersecurity, data quality, supply chains, sustainability, human resources, resilience, and project management, ISO work is increasingly addressing a common challenge: how organizations can operate with confidence when information, responsibilities, technologies, and decisions extend beyond their own boundaries.

This is particularly visible in the start of a new revision of ISO/IEC 27002, one of the most important references for information-security controls, and in new work on trusted data usage, dataspace trust frameworks, privacy-by-design audits, and social-engineering threats. At the same time, a major family of standards for supply-chain interoperability is approaching publication, including verification of trading entities, supply-chain data, certificates, and sourcing information.

Sustainability is moving in the same direction. New editions of ISO 14021 and ISO 14025 strengthen the framework for environmental product information, while ISO/DIS 14060 takes the concept of net-zero alignment toward a structured organizational standard.

Three themes dominate June:

Digital trust moves from individual controls toward connected trust frameworks — with activity around ISO/IEC 27002, security measurement, trusted data usage, privacy audits, dataspaces, and social-engineering threats.

Supply-chain interoperability increasingly requires verification — with standards approaching publication for verifying trading-entity identity, supply-chain data, certificates, sourcing information, and purchasing data.

Management systems continue expanding into strategic organizational capabilities — through developments in occupational health and safety, human resources, knowledge management, records, net zero, project management, resilience, and asset management.

For top management, June delivers a clear message: interoperability alone is no longer enough. Organizations increasingly need to demonstrate that the people, organizations, data, controls, certificates, and claims participating in digital ecosystems can be trusted and verified.

Newly published standards

ISO 30201:2026 – Human resources management systems — Requirements
A significant development in the continued expansion of management-system thinking into human resources. The standard introduces formal requirements for an HR management system, creating a more structured connection between people management, organizational objectives, capability, and governance.

ISO 14025:2026 – Environmental statements and programmes for products — Environmental product declarations (EPDs)
Updates a central standard for structured environmental product information. As environmental data becomes increasingly important for procurement, sustainability reporting, value-chain decisions, and product transparency, EPDs provide an established framework for communicating quantified environmental information.

ISO 14021:2026 – Environmental statements and programmes for products — Self-declared environmental claims
Strengthens the framework for environmental claims made directly by organizations. Together with ISO 14024:2026 on ecolabels and ISO 14025:2026 on EPDs, the new edition contributes to a more structured architecture for environmental product communication and the evidence behind environmental claims.

ISO/IEC 9837:2026 – Systems and software engineering — Systems resilience concepts
Provides a common conceptual foundation for systems resilience. As organizations depend on increasingly interconnected digital infrastructure, resilience must be considered not only at the organizational level but also within the systems and architectures on which operations depend.

ISO 42503:2026 – Sharing economy — Framework for implementation
Provides an implementation framework for sharing-economy models, supporting more structured approaches to responsibilities, relationships, and governance across platform-based ecosystems.

ISO 41002:2026 – Facility management — Development of the facility management organization
Provides guidance for developing facility-management organizations and strengthens the connection between facility management, organizational structure, responsibilities, and performance.

ISO/TS 44005:2026 – Collaborative business relationship management system — Guidance on leadership for collaborative working
Places leadership at the centre of collaborative business relationships. This is increasingly relevant as organizations depend on partnerships, ecosystems, suppliers, and cross-organizational collaboration to create value.

ISO/PAS 25171:2026 – Educational organizations — Management systems — Guidance for auditing ISO 21001
Strengthens the assurance framework around management systems for educational organizations by providing more specific guidance for auditing ISO 21001.

Final Draft International Standards (FDIS): Editorials before publication

ISO/FDIS 30440 – Human resource management — Strategic and ethical integration of technology
Addresses a highly relevant management challenge: how organizations integrate technology into work in a way that is both strategic and ethically considered. As AI and automation become increasingly embedded in organizational processes, technology adoption is becoming as much a people and governance question as a technical one.

ISO/IEC FDIS 27028 – Information security, cybersecurity and privacy protection — Guidance on using information security control attributes
Supports a more structured approach to understanding and organizing information-security controls. The work complements the wider ISO/IEC 27000 family and becomes particularly relevant as organizations need to select and manage controls across increasingly complex digital environments.

ISO/IEC/IEEE FDIS 21841 – Systems and software engineering — Taxonomy of systems of systems
Provides a shared framework for understanding systems of systems, an increasingly important area as organizations depend on interconnected digital, physical, and organizational systems rather than isolated technologies.

ISO/IEC FDIS 33063 – Information technology — Process assessment — Process assessment model for software testing
Strengthens the ability to assess software-testing processes systematically and provides another element of assurance in increasingly software-dependent organizations.

ISO/IEC FDIS 17067 – Conformity assessment — Fundamentals of and guidelines for conformity assessment schemes
An important development for the wider assurance infrastructure. Conformity-assessment schemes determine how requirements are translated into assessment and certification, making consistent scheme design increasingly important as markets become more regulated and evidence-driven.

ISO/FDIS 28022 – Security and resilience — Security management systems — Guidelines on security management system processes
Provides more detailed guidance for security-management processes and reinforces the connection between security governance and systematic implementation.

Draft International Standards (DIS): Nearing publication

June brings particularly strong activity around management systems, digital trust, sustainability, and data.

ISO/DIS 45001 – Occupational health and safety management systems — Requirements with guidance for use
The revision of one of ISO’s most important management-system standards has reached Draft International Standard stage. Occupational health and safety remains a fundamental leadership responsibility, and the revision continues the evolution of ISO management systems toward stronger integration with governance, context, risk, and organizational performance.

ISO/DIS 14060 – Net zero aligned organizations
One of the most strategically important sustainability projects currently progressing through ISO. The standard moves net-zero alignment toward a structured organizational framework, potentially strengthening how organizations connect climate ambition with governance, objectives, transition planning, measurement, and credible claims.

ISO/IEC DIS 27004 – Information security management — Monitoring, measurement, analysis and evaluation
Strengthens the evidence-based side of information-security management. Organizations need not only controls, but also mechanisms for understanding whether those controls work and whether information-security objectives are actually being achieved.

ISO/DIS 30401 – Knowledge management systems — Requirements
The revision of ISO 30401 reinforces knowledge management as a strategic organizational capability. This becomes increasingly relevant as organizational knowledge is distributed between people, digital systems, AI tools, partners, and external networks.

ISO/DIS 30301 – Information and documentation — Management systems for records — Requirements
Strengthens records management as a formal management discipline. Reliable records increasingly underpin accountability, compliance, organizational memory, traceability, and evidence.

ISO/DIS 9002 – Quality management systems — Guidelines for the application of ISO 9001
Progresses alongside the wider revision of the ISO 9000 family. ISO 9002 provides practical guidance for applying ISO 9001 and will therefore become important as organizations prepare for the next generation of quality-management requirements.

ISO/DIS 8000-2 – Data quality — Part 2: Vocabulary
Updates the common language around data quality. Shared terminology becomes increasingly important as organizational data is exchanged across systems and used for analytics, automation, AI, and cross-organizational collaboration.

ISO/DIS 50012 – Energy management systems — Energy data collection plan
Moves energy management deeper into systematic data governance. Credible energy performance depends on reliable underlying information, making data collection an increasingly important part of environmental and energy management.

ISO/DIS 22333 – Security and resilience — Business continuity management systems — Guidelines on BCMS processes
Strengthens the process architecture behind business continuity management and complements the wider revision work taking place around ISO 22301.

ISO/DIS 42501 – Sharing economy — General trustworthiness and safety requirements for digital platforms
Moves platform governance toward formal requirements for trustworthiness and safety. The project reflects the growing importance of managing responsibility and trust in environments where organizations, service providers, and users interact through digital platforms.

ISO/IEC DIS 25029 – Artificial intelligence — AI-enhanced nudging
Extends AI standardization into the relationship between AI systems and human behaviour. As AI increasingly influences recommendations, interfaces, and decisions, the way systems shape user behaviour becomes an important governance issue.

ISO/DIS 21511 – Project, programme and portfolio management — Work breakdown structures
Strengthens project governance by providing a more systematic framework for structuring and communicating work across projects, programmes, and portfolios.

Committee Drafts (CD): Key Standards in Progress

June shows important work around trusted information, asset management, and digital-system governance.

ISO/IEC CD 25985 – Information technology — Data usage — Trusted data usage
One of the most interesting data-governance developments of the month. The project addresses a growing challenge: organizations need not only access to data but confidence that data is used according to agreed rules, responsibilities, and expectations.

This becomes particularly important when information is shared across organizational boundaries and through digital ecosystems.

ISO/CD 55002 – Asset management — Management systems — Guidelines for the application of ISO 55001
Continues the development of the ISO 55000 family and supports organizations in translating asset-management requirements into practical implementation.

ISO/IEC/IEEE CD 26511 – Systems and software engineering — Management of information for users of systems, software, and services
Addresses the information users require when interacting with increasingly complex systems and services. Reliable, understandable, and accessible user information remains an important part of system quality and trust.

New work items and early-stage developments

June’s earliest projects reveal an increasingly connected agenda around cybersecurity, data, verification, management systems, and digital ecosystems.

1. Information-security controls enter a new revision cycle

ISO/IEC PWI 27002 – Information security, cybersecurity and privacy protection — Information security controls

One of the most significant developments of June is the start of work toward a new edition of ISO/IEC 27002.

ISO/IEC 27002 is one of the foundational standards for information-security controls and is closely connected with the implementation of ISO/IEC 27001. A new revision therefore has implications far beyond information-security specialists.

The environment surrounding information security is changing rapidly. Cloud platforms, AI, connected products, software supply chains, remote working, and shared-data environments are creating risks and dependencies that security-control frameworks need to continue addressing.

The project is still at a very early stage, but organizations relying on ISO/IEC 27001 should monitor its development closely.

2. Cybersecurity increasingly addresses human manipulation

ISO/IEC NP 25857 – Cybersecurity — Guidance for addressing social engineering threats within the digital environment

The project reflects an important reality: many cybersecurity incidents exploit people and organizational processes rather than technical vulnerabilities alone.

Social engineering therefore needs to be considered as part of systematic cybersecurity governance, connecting awareness, communication, identity, processes, and technical controls.

3. Privacy by design becomes auditable

ISO/IEC AWI 31700-3 – Consumer protection — Privacy by design for consumer goods and services — Part 3: Audits of privacy by design for consumer products and services

An important evolution in privacy governance.

Privacy by design has traditionally focused on principles and implementation. Developing an audit framework moves the concept toward assurance — providing a more structured mechanism for evaluating whether privacy considerations have genuinely been integrated into products and services.

This follows a broader pattern across standardization: principles increasingly need to be supported by evidence.

4. Dataspaces require formal trust frameworks

ISO/IEC AWI 20151-2 – Cloud computing and distributed platforms — Dataspaces — Part 2: Trust frameworks

Dataspaces depend on organizations being able to share data while maintaining confidence in identities, access, rules, responsibilities, and permitted usage.

The development of formal trust frameworks therefore represents an important step from technical data exchange toward governable data ecosystems.

Together with ISO/IEC 25985 on trusted data usage, this points toward an emerging ISO architecture for trusted cross-organizational data sharing.

5. Supply chains move from data exchange to verification

A particularly notable development in June is the group of ISO 25500 projects approaching publication on supply-chain interoperability and integration.

ISO/PRF 25500-1 – Overview and principles of the industrial internet

ISO/PRF 25500-2 – Vocabulary

These provide the basic framework and common terminology.

More importantly, the series then moves directly into verification:

ISO/PRF 25500-3 – Verification of trading entity identity

ISO/PRF 25500-100 – Verification of supply chain data

ISO/PRF 25500-110 – Verification of certificates in the supply chain

ISO/PRF 25500-120 – Verification of data in support of local purchasing

ISO/PRF 25500-240 – Strategic sourcing concepts, principles, and data requirements

Together, these standards suggest a significant evolution in supply-chain standardization.

The challenge is no longer simply whether systems can exchange data. Increasingly, organizations need to determine who they are interacting with, whether information can be trusted, whether certificates are valid, and whether the evidence supporting commercial and regulatory claims can be verified.

This makes identity and data verification increasingly important components of supply-chain interoperability.

6. Project management moves toward formal requirements

ISO/WD 21514.2 – Project, programme and portfolio management — Requirements

An important development within the ISO 21500 family.

Much of ISO’s project-management work has historically been guidance-oriented. The development of requirements points toward a more formalized approach to the governance of projects, programmes, and portfolios.

Together with ISO/DIS 21511 on work breakdown structures, this signals increasing maturity in how ISO approaches project and portfolio governance.

7. Data quality becomes a management discipline

ISO/AWI TS 8000-60 – Data quality — Part 60: Data quality management: Overview

Data quality is increasingly moving from a technical concern toward a management issue.

Organizations depend on data for transactions, reporting, automation, analytics, AI, digital twins, and regulatory compliance. Poor-quality data therefore creates operational and governance risks across the organization.

Combined with ISO/DIS 8000-2 on data-quality vocabulary, the project reinforces the idea that organizations need systematic approaches to managing data quality — not simply technical corrections after problems appear.

8. Innovation management reaches startups and SMEs

ISO/NP 26849 – Innovation Management for Startups and SMEs — Guidance

Extends innovation-management thinking toward smaller organizations.

The project recognizes that structured approaches to innovation are not relevant only to large enterprises. Startups and SMEs also need ways to connect innovation with strategy, resources, learning, and organizational capability without creating unnecessary complexity.

9. Service excellence becomes measurable

ISO/AWI 23686 – Service excellence — Measuring service excellence performance

Continues the move from general service-excellence principles toward measurable outcomes.

As services become increasingly digital, automated, and delivered across multiple channels, structured approaches to measuring the customer experience and service performance become more important.

Looking Ahead

June 2026 shows an increasingly clear direction across the ISO standards landscape: trust is becoming something that needs to be designed, measured, and verified. Information-security controls are entering a new revision cycle, privacy by design is becoming auditable, data usage is being connected to formal trust frameworks, and supply-chain interoperability is expanding into verification of identities, certificates, and data. Sustainability follows the same direction through environmental product information and the development of a standard for net-zero aligned organizations. Across these areas, simply exchanging information or making commitments is no longer enough — organizations increasingly need evidence that the information, identities, controls, and claims involved can be relied upon.

This also represents a broader evolution in management systems. Traditional management systems largely focused on activities within organizational boundaries. The emerging standards landscape increasingly addresses ecosystems where organizations depend on suppliers, platforms, cloud services, data spaces, digital identities, certificates, and external information. Governance therefore needs to work across organizational and technical boundaries. Identity, data quality, interoperability, monitoring, measurement, audit, and verification are becoming parts of the same organizational trust infrastructure.

For top management, the implication is significant. The next generation of governance will increasingly depend on whether an organization can establish trust not only internally, but across the networks in which it operates. Organizations that can verify who they interact with, understand where information comes from, measure whether controls work, demonstrate credible claims, and manage shared data responsibly will be better positioned for increasingly digital and regulated markets. At StandardsHero, we will continue translating these developments into actionable leadership guidance — helping organizations understand how standards are evolving from frameworks for internal management into infrastructure for trusted collaboration across entire ecosystems.