Accredited certification evidences your organization’s achievement. ISO 13485 and ISO 9001 are quality management standards and certified compliance gives customers assurance in the reliability of your business and quality of your products. So which standard do you choose and what are the benefits of each program?

 

Key differences between ISO 13485 vs. 9001


1. Industry Focus


•    ISO 9001: This standard is versatile and applies to any organization, regardless of the industries. Its goal is to help businesses to enhance customer satisfaction by establishing a well-structured QMS.
•    ISO 13485: Specifically for the medical device industry, ISO 13485 focuses on ensuring safety and efficacy of medical devices, whilst also meeting applicable regulatory and organizational requirements.


2. Risk Management Requirements


•    ISO 9001: Risk-based thinking is an important element, though it is balanced with opportunities for improvement for process improvement. Risk is evaluated in terms of the impact on customer satisfaction and process efficiency.
•    ISO 13485: Risk management plays a central role in this standard, with a strong emphasis on risk identification, control, and mitigation throughout the lifecycle of medical devices. Detailed documentation is required to ensure risks are managed effectively.


3. Regulatory Compliance


•    ISO 9001: Whilst ISO 9001 encourage organization to comply with applicable regulations, it does not mandate specific industry-regulations. The standard is broad and does not provide detailed frameworks for compliance.
•    ISO 13485: The standard places a significant emphasis on complying with medical device regulations. Organizations must meet both local and international regulatory requirements (e.g., FDA, EU MDR) and maintain rigorous documentation and audits to ensure compliance.


4. Focus on Continual Improvement vs. Compliance


•    ISO 9001: Continual improvement is a key focus of ISO 9001. Organizations are expected to regularly assess and enhance their processes to boost customer satisfaction and operational efficiency.
•    ISO 13485: While continual improvement is still important, particularly for processes, ISO 13485 prioritizes maintaining compliance with regulatory standards and ensuring the safety and efficacy of medical devices over broader process optimization.


5. Documentation Requirements


•    ISO 9001: Documentation requirements are relatively flexible and generally focus on internal processes, customer satisfaction, and ongoing improvement.
•    ISO 13485: Documentation requirements are much more detailed and prescriptive, requiring records on risk management, product traceability, and compliance with safety and performance standards. This documentation is crucial for passing regulatory audits.

CriteriaISO 9001ISO 13485
ScopeAll industriesMedical devices only
Continual improvementRequiredNot explicitly required
Risk managementRisk-based thinkingFull lifecycle risk management
DocumentationFlexiblePrescriptive and auditable
Regulatory focusGeneralFDA, EU MDR, IVDR specific
Customer satisfactionCentral focusSecondary to patient safety
Design controlsGeneralDetailed and mandatory
Post-market surveillanceNot requiredRequired
Sterile productsNot addressedSpecific requirements
MDSAP compatibilityNoYes

What the Differences Look Like From the Other Side of the Audit Table

As a Notified Body conducting MDR conformity assessments, DQS assessors see the practical consequences of these differences every day. The gap between ISO 9001 and ISO 13485 is most visible in three areas:

Design controls: ISO 9001 requires organizations to plan and control product development, but leaves significant flexibility in how. ISO 13485 is explicit: design inputs, outputs, reviews, verification, validation, and transfer must each be documented separately, and the design history file must support the entire technical documentation under MDR. Assessors follow this chain from intended purpose through to the final device, gaps in the design history are among the most common findings in technical documentation reviews.

Risk management integration: In ISO 9001, risk is managed at the process and business level. In ISO 13485, risk management per ISO 14971 is a thread that runs through every element of the QMS — from design controls and supplier management to production validation, usability engineering, and post-market surveillance. Assessors expect risk controls to be traceable across the entire technical file, not contained in a standalone risk management document.

Post-market surveillance: ISO 9001 monitors customer satisfaction. ISO 13485 requires manufacturers to systematically gather and evaluate post-market data as evidence that devices continue to meet safety and performance requirements throughout their lifecycle. Under MDR, this PMS obligation is further defined, PSUR reporting, PMCF plans, and EUDAMED registration of surveillance data are now formal regulatory requirements, not internal quality activities.

For manufacturers preparing for MDR conformity assessment, the practical implication is clear: an ISO 9001-based QMS is not a sufficient foundation. ISO 13485 is the required baseline and what is assessed is not just whether the standard is implemented, but whether it is producing the evidence quality that a conformity assessment depends on.

Learn Post-Market Surveillance in Practice

DQS Academy covers PMS planning, PMCF strategy, PSUR reporting and vigilance obligations under EU MDR, led by auditors who assess these requirements as part of conformity assessment.

Explore the training

What ISO 9001 and ISO 13485 Have in Common

Before comparing the differences, it helps to understand why these two standards are so frequently discussed together. ISO 13485 was originally derived from ISO 9001 and shares its Plan-Do-Check-Act (PDCA) structure, its emphasis on process-based thinking, and its core commitment to consistent product quality.

Both standards require organizations to:

- Establish, implement, and maintain a documented QMS
- Define roles, responsibilities, and authorities
- Manage resources, infrastructure, and work environment
- Control nonconforming outputs and implement corrective actions
- Conduct internal audits and management reviews
- Manage external providers through documented processes

For organizations producing both medical devices and non-medical products, this shared structure makes an integrated audit programme possible: one audit team, one calendar, common-clause testing across both standards. DQS delivers integrated ISO 9001 + ISO 13485 audits where both are in scope.

The differences, however, are significant and for medical device manufacturers, they are not optional.

Can an Organization be Certified for Both ISO 9001 and ISO 13485?

Yes, organizations can be certified for both standards. Manufactures of medical devices, for example, may choose to implement both ISO 9001 and ISO 13485 to ensure a comprehensive approach to quality management across all business areas. However, ISO 13485 certification is often mandatory for regulatory approval of medical devices.

How Do ISO 9001 and ISO 13485 Differ with Respect to Product Development?

ISO 9001 covers product development with a broad focus to meet the needs of multiple industries. In contrats, ISO 13485 is much more prescriptive, placing a heavier emphasis on the design and development stages of medical devices and requiring manufacturers to establish robust controls and maintain comprehensive documentation throughout the product lifecycle. This includes risk management, validation, and verification processes that assure medical devices safety and performance. 

Which Certification is Best for My Organization?


•    ISO 9001: Ideal for businesses across all industries that seek to improve quality management, efficiency, and customer satisfaction. This standard offers flexibility and provides a framework for continuous improvement in a variety of sectors. The standard includes key business strategies including contextualisation, evidence-based decision making, proportionate risk management, and compliance with legal and regulatory requirements.
The business focus of ISO 9001 is valuable for top management in designing, developing and maintaining a robust business in all sectors. It is an indicator of a commitment to quality and is required by some purchasers.
 

ISO 13485: Essential for organizations that design, manufacture, or service medical devices, and beneficial for organisations in the MedTech sector. ISO 13485 is focused on regulatory compliance and risk management, making it a key certification for accessing global markets in the medical device sector.
ISO 13485 is more product-focused, demonstrating a deep understanding of the documentation and quality requirements for components, services, and final products within the MedTech sector. In some regulatory jurisdictions, it is a mandatory requirement for legal manufacturers of medical devices. Since ISO 13485 certification also takes into account critical suppliers—potentially including them in the audit program—it provides an added layer of assurance in building supply chains. This can help reduce audit costs, making suppliers with ISO 13485 certification more likely to be selected over those without it.
 

The Certification Cycle


Both ISO 9001 and ISO 13485 certifications follow the requirements of ISO 17021-1, including an 2-stage initial audit. Whereas the ISO 9001 stage 1 audit is often remote, the ISO 13845 Stage 1 audit is preferably on site, and must be on-site for high-risk devices. To maintain certification both schemes require periodic surveillance audits and recertification every three years. The renewal process involves a comprehensive review of the QMS and adherence to the specific requirements of each standard.

Conclusion: ISO 13485 vs. 9001 - Choosing the Right Standard


In summary, both ISO 9001 and ISO 13485 are focused on quality management but serve different needs. ISO 9001 is generic, with more content on business development and less prescriptive requirements for the products and documentation. ISO 13485 is specifically tailored for the MedTech industry, with a stronger emphasis on safety, risk management, and regulatory compliance. For companies in the medical device sector, ISO 13485 is crucial for regulatory approval and market access. However, ISO 9001 can complement ISO 13485 to offer a more comprehensive quality strategy, encompassing the business elements. Indeed, even if your strategy is only to have ISO 13485 certification, it is worth considering adoption of some of the ISO 9001 tools to support business resilience. Selecting the right certification ensures both compliance and success, depending on your organization’s goals and industry.

Frequently Asked Questions

Is ISO 13485 replacing ISO 9001 for medical device manufacturers?

No. ISO 13485 and ISO 9001 are separate standards with different scopes. ISO 13485 is specifically designed for medical device quality management systems and is the required QMS standard for regulatory compliance in most major medical device markets. ISO 9001 remains a general quality management standard applicable to all industries. Many medical device organizations hold both certifications: ISO 13485 for their regulated medical device operations and ISO 9001 for broader business functions or non-medical product lines. They can be audited in an integrated programme.

Do I need ISO 13485 if I already have ISO 9001?

For medical device manufacturers, yes, in most cases. ISO 9001 certification does not satisfy the regulatory requirements for medical device market access in the EU, Canada, Australia, Brazil, Japan, or increasingly the US. These markets require ISO 13485 as the QMS foundation for regulatory approvals, licence applications, and conformity assessment. ISO 9001 can complement ISO 13485 but cannot replace it for medical device regulatory purposes. If your devices require Notified Body involvement under MDR, your QMS must be certified to ISO 13485.

What is the biggest practical difference between ISO 13485 and ISO 9001?

The most significant practical difference is what happens to documented evidence. ISO 9001 gives organizations flexibility in determining what to document and how. ISO 13485 is prescriptive: specific records are mandated, including the design history file, risk management records, validation documentation, and post-market surveillance data, and these records must be structured and traceable in a way that supports regulatory audit and Notified Body assessment. For many manufacturers transitioning from ISO 9001 to ISO 13485, the documentation rebuild is the most resource-intensive part of implementation.

Does ISO 13485 require continual improvement like ISO 9001?

This is one of the most important and least understood differences. ISO 9001 explicitly requires continual improvement of the QMS as a core principle. ISO 13485 does not, it requires organizations to demonstrate that the QMS is effectively implemented and maintained. The focus shifts from improvement-driven to compliance-driven: maintaining the effectiveness of established processes takes priority over optimizing them. This reflects the regulatory reality of medical devices, where change control requirements mean that process modifications must be carefully managed and documented rather than continuously iterated.

Can a supplier be certified to ISO 13485 even if it doesn't manufacture medical devices?

Yes, and it is increasingly common. ISO 13485 applies to any organization involved in one or more stages of the medical device lifecycle, including design, production, storage, distribution, installation, servicing, and final decommissioning. Suppliers of components, contract manufacturers, sterilization service providers, and software developers supplying to medical device manufacturers can all be certified to ISO 13485. Certification demonstrates to their customers (and to the Notified Bodies auditing those customers) that the supplier's QMS meets the standard required for inclusion in the medical device audit scope.

How long does it take to get ISO 13485 certified compared to ISO 9001?

Both follow a two-stage initial audit process. However, ISO 13485 typically takes longer for two reasons. First, the documentation requirements are more extensive, the QMS must be fully implemented and generating controlled records before the Stage 2 audit can proceed. Second, for high-risk devices, the Stage 1 audit must be conducted on-site (rather than remotely, as is common for ISO 9001), which adds planning time. As a planning benchmark, most organizations need six to twelve months of QMS implementation before they are ready for the Stage 2 audit, depending on the maturity of existing processes and the complexity of their device portfolio.

What is the connection between ISO 13485 and EU MDR conformity assessment?

ISO 13485 is the QMS standard that forms the foundation of MDR Notified Body conformity assessment. Under MDR Annex IX — the most common conformity assessment route — DQS audits the manufacturer's quality management system against ISO 13485 requirements as part of the overall conformity assessment procedure. A manufacturer cannot achieve MDR CE marking through Notified Body assessment without a conforming ISO 13485-based QMS. The two are not separate processes: ISO 13485 certification and MDR conformity assessment are typically delivered as an integrated programme by DQS, covering QMS audit, technical documentation review, and certificate issuance under a single coordinated plan.

ISO 13485 Certification

Don’t know where to start for your ISO 13485 compliance or certification? Contact us for more whitepapers and guidance documents to support your quality management system implementation or an obligation free quote for compliance assessment and certification services. 

Contact us now!
Author

Claire Dyson

has a doctorate in rational drug design and over 10 years of experience in medical devices that interact with or deliver medicines or biological responses. Most of her career has been spent in industry, mainly in Switzerland. She moved into certification bodies in 2018 and has been involved in several transformative change projects, including new accreditations and designations.

Loading...

You Might Also Enjoy These Reads

Discover more articles that dive deep into related themes and ideas.
Blog
Loading...

From MDR Compliance to IEC 81001-5-1 Software Lifecycle Management

Blog
Loading...

Improving MDR Technical Documentation: Practical Lessons from the New Team-NB Guidance Revision

Blog
Loading...

Akila Limited Achieves ISO 13485:2016 Certification for Medical Device PCBA Manufacturing in Hong Kong