How does ISO 13485 differ from ISO 9001?

ISO 13485:2016 vs ISO 9001:2015 · Key divergences for medical device manufacturers

Quick answer

ISO 13485 is stricter, regulation-focused and cannot be replaced by ISO 9001 for medical devices. While both share a process approach and PDCA cycle, ISO 13485 adds mandatory regulatory compliance throughout, more rigorous design controls, device-specific documentation, and a formal vigilance system — none of which are required by ISO 9001.

Common foundation

Both standards share a common heritage — ISO 13485 was originally aligned to ISO 9001:2000 and retains many structural similarities. Both require a process approach to quality management, the Plan-Do-Check-Act (PDCA) cycle, customer focus, leadership commitment, and a documented QMS with internal audit and management review. Both aim to demonstrate the ability to consistently provide product and services that meet requirements.

However, the similarities end at the structural level. ISO 13485 deliberately diverges from ISO 9001:2015 in areas critical to medical device safety and regulatory compliance.

Key differences

TopicISO 9001:2015ISO 13485:2016Practical impact
Primary focusCustomer satisfaction and continual improvementCompliance with regulatory requirements, product safetyLegal obligation — not just customer preference
Continual improvementExplicitly required throughoutMaintain effectiveness (not explicitly continual improvement)QMS stability and compliance take priority over optimisation
Risk managementRisk-based thinking (general, no specific method required)Risk management throughout, with ISO 14971 as primary referenceA formal Risk Management File per product is required
Design controlsAddresses product/service design in general termsDetailed clause 7.3 with eight sub-clauses specific to medical devicesDesign History File (DHF) or equivalent is mandatory
Record retentionNot specified precisely — organisation-definedProduct lifetime + 2 years minimum; at least 5 years absolute minimumLonger, defined retention periods for all device records
Sterile productsNot addressedSpecific requirements for sterile device production and contamination controlCleanroom validation, sterilisation validation, personnel health monitoring
Complaints and MDRCustomer complaints handled as general nonconformanceFormal complaint handling procedure + regulatory reporting (vigilance) requiredMandatory adverse event reporting to competent authorities
Statistical techniquesRequired where appropriate — no further specificationMore prescriptive application to product inspection and process controlSampling plans and process capability studies required for production

Can you hold both certifications?

Yes — it is possible to be certified to both ISO 9001 and ISO 13485 simultaneously. Some organisations operating across both medical and non-medical markets maintain dual certification. However, ISO 9001 alone is never sufficient for medical device activities. Regulatory authorities worldwide require ISO 13485 (or its equivalent) — ISO 9001 is not accepted as a substitute for QMS compliance under EU MDR, MDSAP, or Health Canada requirements.

If your QMS already meets ISO 13485:2016, you effectively satisfy most ISO 9001 requirements as well, since ISO 13485 is generally more demanding. A gap analysis from ISO 9001 to ISO 13485 typically reveals the additional medical device-specific requirements as the primary work items.

Why regulators require ISO 13485 and not ISO 9001

The fundamental reason is that ISO 9001 is designed for any industry and optimises for customer satisfaction. Medical devices are regulated products where patient safety and regulatory compliance take legal precedence over customer satisfaction. Key regulatory needs not met by ISO 9001 include:

  • Traceability to patients: The ability to trace a device to the patient who received it — required for field safety corrective actions (recalls)
  • Vigilance system: Mandatory adverse event reporting to regulators within defined timelines (30, 15, or 2 days depending on event type in the EU)
  • Technical documentation: The Medical Device File (MDF) or Design History File (DHF) demonstrating device safety and performance
  • Regulatory-specific design controls: Clinical evaluation, usability engineering, software validation, and biocompatibility — all required by regulators but not addressed by ISO 9001

Transitioning from ISO 9001 to ISO 13485

Organisations moving from ISO 9001 to ISO 13485 typically need to address five main areas:

  1. Create a Medical Device File structure for each product
  2. Implement a formal design and development procedure (clause 7.3)
  3. Establish a complaint handling and vigilance reporting system (clause 8.2.1 / 8.2.3)
  4. Integrate ISO 14971 risk management into product development and post-market activities
  5. Extend record retention periods to meet the product lifetime + 2 years minimum

Check your ISO 13485 gaps

Self-assess your QMS against all key clauses — free tool.

Try free →