Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 13485 vs ISO 9001 — ISO 13485:2016 medical device quality management

ISO 13485 vs ISO 9001: The Differences That Matter

ISO 13485 vs ISO 9001 is a question with a short answer and a long one. The short
answer: if you make, design or distribute medical devices, ISO 13485 is the one that counts. The
long answer is about structure, intent and documentation — and it explains why the two standards
no longer look alike.

ISO 13485 vs ISO 9001: the structural split

ISO 9001:2015 adopted the harmonized structure from Annex SL: the ten-clause
framework shared by ISO 14001, ISO 45001, ISO 27001 and most modern management system standards.
ISO 13485:2016 deliberately did not. Its technical committee kept the older clause 4
to 8 layout to stay aligned with medical device regulation rather than with other management
standards.

That has a practical consequence people discover the hard way: the clause numbers do not
map between the two
. If you run an integrated system, you cannot cross-reference ISO 13485
clause 8 to ISO 9001 clause 8 and expect them to mean the same thing. Our
Annex SL clause guides apply to ISO 9001
and its siblings — not to ISO 13485.

ISO 13485 vs ISO 9001 compared clause by clause

ISO 9001:2015 ISO 13485:2016
Structure Annex SL, clauses 4–10 Own structure, clauses 4–8
Quality manual Not required Required (4.2.2)
Medical device file Required (4.2.3)
Preventive action Absorbed into risk-based thinking Retained as its own clause (8.5.3)
Continual improvement Central objective Maintain suitability and effectiveness; improvement is regulatory-driven
Customer satisfaction Must be monitored (9.1.2) Replaced by feedback, complaints and regulatory reporting (8.2)
Risk Risk-based thinking, no method prescribed Risk management across product realization, ISO 14971 in practice
Regulatory requirements Referenced generally Woven throughout; the subtitle is “requirements for regulatory purposes”
Design controls Clause 8.3, can be excluded Clause 7.3, extensive, with a design and development file

The philosophical difference

ISO 9001 exists to improve customer satisfaction and drive continual improvement. ISO 13485 exists
to produce devices that are consistently safe and meet regulatory requirements. That is why 13485
speaks of maintaining effectiveness rather than continually improving: in a regulated
environment, an uncontrolled change is a risk, not a benefit.

It is also why 13485 says almost nothing about customer satisfaction and a great deal about
complaints, adverse event reporting and advisory notices. The “customer” whose expectations dominate
is the regulator and, ultimately, the patient.

Certifying to ISO 13485?

The ISO 13485 Toolkit covers the clause 4 to 8 structure as the standard actually sets it out — quality manual, medical device file, design controls and the full CAPA set, editable and audit-ready.

Explore the ISO 13485 Toolkit →

ISO 13485 vs ISO 9001: do you need both?

Usually not. ISO 13485 covers the quality management ground a device manufacturer needs, and
certification bodies audit it in its own right. Organisations that hold both are typically those
with a mixed portfolio — a medical division alongside industrial products — or those whose
non-medical customers specifically ask for ISO 9001.

Holding both means maintaining two structures rather than one, because the clause numbering does
not align. Weigh that cost against the commercial reason for the second certificate.

If you already hold ISO 9001

An existing ISO 9001 system is a genuine head start, but less of one than people expect, and the
gap is not where they look.

What transfers largely intact: document and record control, internal audit
mechanics, management review discipline, competence and training records, and supplier evaluation
as a habit. The governance muscle is the same.

What has to be built from scratch: the medical device file, risk management
across the product lifecycle to ISO 14971, design controls at ISO 13485’s depth including the design
and development file, complaint handling as distinct from general feedback, regulatory reporting,
advisory notices, traceability at device level, and preventive action as its own evidenced process.

What has to be unlearned: the continual improvement reflex. In ISO 9001, change
that improves performance is good. Under ISO 13485, an unvalidated change to a validated process is
a nonconformity regardless of how much better it makes things. Teams migrating across find the
change-control discipline the hardest adjustment — harder than any documentation gap.

Budget the migration around design controls and risk management. Those two consume most of the
effort, and neither has an ISO 9001 equivalent you can adapt.

What changed for US manufacturers in 2026

The FDA’s Quality Management System Regulation, enforced from 2 February 2026,
incorporates ISO 13485:2016 by reference into 21 CFR Part 820. For anyone selling into the United
States that settles the question: ISO 13485 is now the substance of the federal quality regulation,
and ISO 9001 has no equivalent standing.

References

More on ISO 13485

All of these are covered by the ISO 13485 Toolkit, or try the free ISO 13485 templates first.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.