ISO 9001:2015 vs ISO 13485:2016
The general QMS standard vs the medical-device one built on top of it.
What a comparison is not
A comparison is SPEQ’s reading of how two published documents differ. Neither is the right answer, it is not a determination of which applies to you, and neither is summarised in a way that replaces reading it.
ISO 9001 is the generic quality-management-system standard used across every industry, built around customer satisfaction and continual improvement. ISO 13485 is the medical-device QMS standard: it shares ISO 9001’s structure and history but reorients the system toward regulatory compliance, risk, and patient safety. They look similar on the surface and are routinely confused, but a device firm cannot substitute one for the other.
| ASPECT | ISO 9001:2015 | ISO 13485:2016 |
|---|---|---|
| Scope | Any organisation, any sector | Organisations in the medical-device lifecycle |
| Guiding aim | Customer satisfaction + continual improvement | Meeting regulatory requirements + device safety/efficacy |
| Continual improvement | A central, explicit requirement | Emphasis is on maintaining effectiveness and meeting regulation, not improvement for its own sake |
| Risk | Risk-based thinking, broadly applied | Risk management embedded throughout, tied to ISO 14971 |
| Documentation | Leaner; “documented information” at the org’s discretion | More prescriptive documented procedures and records |
| Regulatory linkage | None inherent | Written to support device regulations (EU MDR, FDA QMSR) |
| Management review / design | Required, general | Design & development controls are detailed and mandatory |
Use ISO 9001 when you need a recognised, general-purpose quality system — a supplier, a service org, or a component maker that is not itself placing a medical device on the market.
Use ISO 13485 if you design, manufacture, or service medical devices: it is the QMS regulators expect, and the FDA QMSR now incorporates ISO 13485:2016 by reference.
ISO 13485 is not “ISO 9001 for devices” — it deliberately drops the continual-improvement and customer-satisfaction emphasis and swaps in regulatory compliance, risk, and traceability. A device company builds to 13485; holding only ISO 9001 does not make you device-compliant. If you supply into device makers, 9001 may be enough, but read your customer’s flow-down before assuming it.
ISO 9001:2015 vs ISO 13485:2016: frequently asked questions
Common questions on how ISO 9001:2015 and ISO 13485:2016 differ and when each applies.
Is ISO 13485 based on ISO 9001?
Historically yes — ISO 13485 grew from the ISO 9001 structure — but the 2016 edition is deliberately de-coupled and does not follow ISO 9001:2015’s high-level structure. It reorients the system toward regulatory compliance and device safety rather than continual improvement.
Can ISO 9001 certification cover a medical-device company?
Not for device-specific regulatory purposes. Regulators and notified bodies expect ISO 13485, which the FDA QMSR now incorporates by reference. ISO 9001 may satisfy some upstream suppliers, but it is not a substitute for a device QMS.
Why doesn’t ISO 13485 stress continual improvement?
Because in a regulated device context, uncontrolled change is a risk. ISO 13485 emphasises establishing, maintaining, and demonstrating the effectiveness of the QMS and meeting regulatory requirements, rather than continual improvement as an end in itself.
Do I need both?
Rarely. Most device firms certify to ISO 13485 alone. Some corporate groups hold ISO 9001 for non-device operations and ISO 13485 for device operations, but there is no requirement to hold both for the device business.