For years, “innovative” was a brochure word in Spanish companies: every one of them said it about itself and nobody could check. ISO 56001 changes that. Published in September 2024, it is the first certifiable international standard to set the requirements for an innovation management system, from the same family and with the same structure as ISO 9001 for quality or ISO 27001 for security. CEDESA was one of the first software companies in Spain to obtain this certification, so in this guide we explain from the inside what the standard requires, how it differs from UNE 166002 (the Spanish standard that many companies already held), who should get certified and what it delivers in practice.
What is ISO 56001?
ISO 56001:2024 (in Spain, UNE-EN ISO 56001:2024, published on 11 December 2024) sets out the requirements for an innovation management system: the set of policies, processes, roles and resources with which an organisation generates, evaluates, develops and exploits ideas systematically, rather than depending on the talent or luck of a few individuals. It is part of the ISO 56000 family, which includes the vocabulary and fundamentals (ISO 56000), the implementation guidance (ISO 56002) and standards on innovation partnerships, intellectual property management, strategic intelligence, idea management and measurement.
Unlike those guidance documents, ISO 56001 is certifiable: an accredited body audits the system and issues a certificate, just as with ISO 9001. It follows the harmonised structure of all ISO management system standards, with clauses on context, leadership, planning, support, operation, performance evaluation and improvement, which means it can be integrated into a system already certified for quality or security without duplicating documentation.
What sets it apart from ISO 9001 is its subject matter. Quality manages the repetition of what is known; innovation manages uncertainty. That is why ISO 56001 asks for things that seem alien to a quality system: tolerating controlled failure, exploring opportunities with no guaranteed outcome, measuring the idea funnel, and protecting and exploiting what is created.
ISO 56001 compared with UNE 166002
UNE 166002, the national standard for R&D&I management systems, had existed in Spain since 2006 and was revised in 2021. Many companies held it, among other reasons because it was one of the routes to the Pyme Innovadora seal (the official “innovative SME” seal awarded by Spain’s Ministry of Science). The relationship between the two is direct:
- UNE-EN ISO 56001:2024 replaces UNE 166002:2021 and shares more than ninety per cent of its requirements. Anyone with a well-implemented UNE 166002 system has migrated with adjustments, not with a new project.
- ENAC (Spain’s national accreditation body) set a migration period from 1 January 2025 to 1 June 2026, during which certificates under both standards coexisted. As at the date of this article that period has ended and the reference standard in Spain is ISO 56001.
- ISO 56001 is international: it carries the same weight with a client in Portugal, Germany or Latin America, something UNE 166002 did not offer.
What the standard requires
Without going into the detail of each clause, an innovation management system that conforms to ISO 56001 has to demonstrate:
- Context and strategy. An understanding of the environment (technology, market, regulation, competitors) and of the needs of interested parties, and, derived from that, an innovation intent and an innovation strategy aligned with the company’s strategy.
- Leadership and culture. Senior management commitment, an approved innovation policy, defined roles and a culture that tolerates uncertainty and learns from failure. The standard asks for evidence of that culture, not statements.
- Planning. Measurable innovation objectives, a portfolio of initiatives balanced between the short and the long term, and the management of risks and opportunities.
- Support. People with innovation competences, allocated time and budget, tools, knowledge management, strategic intelligence and intellectual property management.
- Operation: the innovation process. Identifying opportunities, creating concepts, validating them through experiments, developing solutions and deploying them. This is the heart of the standard and where the audit tests whether the company does what it says: how an idea comes in, who decides, on what criteria, and what happens to the ones that are discarded.
- Performance evaluation. Funnel indicators (ideas, concepts, projects, results), internal audit and management review.
- Improvement. Nonconformities, corrective actions and improvement of the system itself.
Which companies should obtain it
No one is required by law to have it. It makes sense, and third parties increasingly require it or give credit for it, in the following cases:
- Suppliers to the public sector and to large companies. Tender specifications and supplier approval processes ask for evidence of innovation capability, and a third-party certificate carries more weight than a chapter in the bid. In technology and software development contracts it is a differentiator against competitors that offer only ISO 9001, as we explain in our comparison of large integrator or mid-sized company.
- Companies that finance their R&D&I with public funds. Funding calls from the CDTI (Spain’s public agency for business R&D&I funding), from the autonomous communities (regions) or under the Next Generation EU funds give credit for a certified management system, and the system helps to document projects with the traceability that reporting and justification later demand. We cover this in the guide to Next Generation EU for digitalisation projects.
- SMEs that want the Pyme Innovadora seal. Royal Decree 475/2014 (Real Decreto 475/2014) set several routes to obtaining it, among them having a certified innovation management system, which used to be UNE 166002 and is now ISO 56001. The seal gives access to reductions in social security contributions for research staff and to other advantages.
- Companies that claim R&D&I tax deductions. The deduction under Article 35 of Spain’s Corporate Income Tax Law (Ley del Impuesto sobre Sociedades) does not require the standard, but a certified system brings order to the documentation for each project and makes it easier to obtain reasoned reports (informes motivados, the official reports that classify a project as R&D&I for tax purposes).
- Organisations that genuinely innovate, but haphazardly. This is the most common case: companies with good ideas that depend on two people, with no portfolio, no decision criteria and no measurement of anything. The standard gives them a method before it gives them a badge.
How ISO 56001 is implemented
The route is the same as for any management system, with two particular features: a process that is informal in many companies has to be made visible, and something that was not previously measured has to be measured.
- Diagnosis. What innovation takes place today, who decides, with what resources and with what results. If UNE 166002 is already in place, the diagnosis is a gap analysis, and the gaps will be few.
- Scope, policy and leadership. Defining which units and which types of innovation the system covers (product, process, business model), and having senior management approve the policy and allocate resources.
- Design of the innovation process. How opportunities come in, how they are turned into concepts, how they are validated with cheap experiments before any investment is made, how they are developed and deployed, and what is done with whatever does not succeed. With written decision criteria at every gate.
- Portfolio and indicators. A balanced portfolio of initiatives and a dashboard of funnel and results indicators.
- Support. Competences, protected time for innovation, intellectual property and knowledge management, and strategic intelligence on technology and the market.
- A full cycle before certification. An internal audit and a management review backed by evidence, as with any ISO standard.
- Certification. A body accredited by ENAC for ISO 56001, a two-stage audit, and a three-year certificate with annual surveillance audits.
If the company already holds ISO 9001 or ISO 27001, it makes sense to integrate ISO 56001 into the same system: it shares the structure, the internal audit, the management review and the handling of nonconformities, and avoids having to maintain three parallel systems. Our guide on how to implement ISO 27001 step by step describes that common cycle.
What it delivers in practice: CEDESA’s experience
At CEDESA the certification attests to something we were already doing: conversational artificial intelligence projects for rural municipalities, predictive models for water networks, NFC smart labelling for agri-food traceability, IoT sensing. What the system brought was order: a visible portfolio, criteria for deciding where we invest our R&D&I time, indicators and a systematic way of turning what we learn on one project into the next. You can see those projects on the innovation and artificial intelligence page and our four current certifications under certifications.
For a client, public or private, the value can be verified: an accredited third party checks every year that the supplier manages innovation methodically, and does not merely advertise it.
Frequently asked questions about ISO 56001
Does ISO 56001 replace UNE 166002?
Yes. UNE-EN ISO 56001:2024 replaces UNE 166002:2021, with which it shares more than ninety per cent of its requirements. ENAC set a migration period between 1 January 2025 and 1 June 2026; now that the period has ended, the reference standard in Spain for certifying an innovation management system is ISO 56001.
Is ISO 56001 mandatory?
No. It is a voluntary standard. Companies get certified because clients, tender specifications and public funding calls ask for it or give credit for it, because it is one of the routes to the Pyme Innovadora seal and because it brings order to the company’s own R&D&I management.
What is the difference between ISO 56001 and ISO 56002?
ISO 56002 is a guidance document for implementing an innovation management system and is not certifiable. ISO 56001 is the requirements standard and can be certified. The two share structure and concepts; ISO 56002 helps to interpret what ISO 56001 requires.
How long does it take to get certified to ISO 56001?
It depends on the starting point. A company with UNE 166002 migrates with a gap analysis and some adjustments. A company starting from scratch needs to design the innovation process, define indicators and complete a cycle of internal audit and management review before the certification audit, which usually takes several months.
Does ISO 56001 count towards the Pyme Innovadora seal?
Having a certified innovation management system is one of the routes provided for in Royal Decree 475/2014 for obtaining the seal; that certification used to be UNE 166002 and, since its replacement, is ISO 56001. The other routes are having received public R&D&I funding, holding patents that are being exploited or having certain official recognitions.
Conclusion
ISO 56001 turns innovation into something that is managed and audited, with the same structure as the quality and security standards many companies already hold. It should be obtained by suppliers competing for technology contracts with public authorities and large clients, by companies that finance their R&D&I with public funds or want the Pyme Innovadora seal, and by any organisation that genuinely innovates but without a method. CEDESA was among the first software companies in Spain to be certified; if you are looking for a supplier that can back this up with a certificate and with real projects, write to us via our contact page.