ISO

International Organization for Standardization

InternationalInternationalStandards body

Consensus standards for quality management (9001), medical devices (13485), risk (14971), and cleanrooms (14644).

What this page does not claim

SPEQ curates and cross-references these bodies. It is not affiliated with, accredited by, or endorsed by any of them, and a count of decoded standards is a measure of SPEQ’s coverage, not of a body’s importance.

WHAT ISO COVERS

The International Organization for Standardization develops voluntary international standards across virtually every sector. In GxP the consequential ones are ISO 13485 for medical device quality systems, ISO 14971 for device risk management, the ISO 14644 series for cleanrooms, ISO 9001 for generic quality management, and ISO 22000 for food safety.

WHAT ISO PUBLISHES

  1. 01ISO 13485 — medical device quality management systems
  2. 02ISO 14971 — risk management for medical devices
  3. 03ISO 14644 series — cleanrooms and associated controlled environments
  4. 04ISO 9001 — generic quality management systems
  5. 05ISO 22000 (food safety) and ISO 22716 (cosmetics GMP)

HOW ITS REQUIREMENTS BITE

ISO neither regulates nor certifies. Certification is performed by accredited certification bodies, and standards acquire regulatory force only when a regulator adopts or references them — as the FDA QMSR does by incorporating ISO 13485 by reference, and as EU MDR does through harmonised standards that confer a presumption of conformity.

What practitioners get wrong

  • An ISO standard is voluntary until a regulator references it — then it is effectively mandatory in that market.
  • Certification demonstrates assessment against a standard on a date; it does not demonstrate an effective system.
  • Harmonised standards under EU regulations give a presumption of conformity — a significant practical benefit.
  • Standards are revised on cycles; confirm the edition your regulator currently references.

WHERE IT SITS INTERNATIONALLY

ISO standards are the connective tissue between regulatory regimes — the FDA QMSR’s incorporation of ISO 13485 is the clearest example of regulatory convergence onto an ISO baseline.

ISO STANDARDS SPEQ DECODES · 23

ISO 14644-1
Cleanrooms and Associated Controlled Environments — Classification of Air Cleanliness by Particle Concentration
ISO 14644-2
Cleanrooms and Associated Controlled Environments — Monitoring to Provide Evidence of Cleanroom Performance
ISO 9001:2015
Quality Management Systems — Requirements
ISO 13485:2016
Medical Devices — Quality Management Systems — Requirements for Regulatory Purposes
ISO 14971:2019
Medical Devices — Application of Risk Management to Medical Devices
ISO 22000:2018
Food safety management systems — Requirements for any organization in the food chain
ISO 22716:2007
Cosmetics — Good Manufacturing Practices (GMP): Guidelines on Good Manufacturing Practices
ISO/IEC 17025:2017
General requirements for the competence of testing and calibration laboratories
ISO 20916:2019
In vitro diagnostic medical devices — Clinical performance studies using specimens from human subjects
ISO 17665:2024HIGH INSPECTION RISK
Sterilization of Health Care Products — Moist Heat — Requirements for the Development, Validation and Routine Control of a Sterilization Process for Medical Devices
ISO 11135:2014HIGH INSPECTION RISK
Sterilization of Health-Care Products — Ethylene Oxide — Requirements for the Development, Validation and Routine Control of a Sterilization Process for Medical Devices
ISO 10993-1:2018HIGH INSPECTION RISK
Biological Evaluation of Medical Devices — Part 1: Evaluation and Testing Within a Risk Management Process
ISO 14155:2026HIGH INSPECTION RISK
Clinical Investigation of Medical Devices for Human Subjects — Good Clinical Practice
ISO 15189:2022HIGH INSPECTION RISK
Medical Laboratories — Requirements for Quality and Competence
ISO 14644-4
Cleanrooms and Associated Controlled Environments — Part 4: Design, Construction and Start-up
ISO 11607-1:2019
Packaging for Terminally Sterilized Medical Devices — Part 1: Requirements for Materials, Sterile Barrier Systems and Packaging Systems
ISO 19011:2018
Guidelines for Auditing Management Systems
ISO 11737-1:2018
Sterilization of Health Care Products — Microbiological Methods — Part 1: Determination of a Population of Microorganisms on Products
ISO/IEC 27001:2022
Information Security, Cybersecurity and Privacy Protection — Information Security Management Systems — Requirements
ISO 22301:2019
Security and Resilience — Business Continuity Management Systems — Requirements
ISO 31000:2018
Risk Management — Guidelines
ISO 45001:2018
Occupational Health and Safety Management Systems — Requirements with Guidance for Use
ISO 14001:2015
Environmental Management Systems — Requirements with Guidance for Use

DISCIPLINES IN ISO’S REMIT

TOPIC EXPLAINERS CITING ISO STANDARDS
Contamination Control & Annex 1
The Contamination Control Strategy, cleanroom classification, and the 2022 Annex 1 revision.
Quality Risk Management (ICH Q9)
ICH Q9(R1), the risk-management process, common tools, and the pitfalls the R1 revision targets.
The Pharmaceutical Quality System (ICH Q10)
ICH Q10, the four elements, the two enablers, management responsibility, and the lifecycle model of quality.
Medical Device Quality System (ISO 13485 / QMSR)
ISO 13485, the FDA QMSR harmonisation with 21 CFR 820, device risk management (ISO 14971), and software (IEC 62304).
HACCP & Preventive Controls
The seven principles of Hazard Analysis and Critical Control Points, the Codex framework, ISO 22000, and how FSMA preventive controls extend it.
RABS & Isolators — Aseptic Barrier Systems
How restricted access barrier systems and isolators separate operators from the sterile core — open vs closed RABS, isolators, and what EU GMP Annex 1 now expects.
Software as a Medical Device (SaMD)
Software that is itself a medical device — the IMDRF definition, IEC 62304 lifecycle, ISO 14971 risk, EU MDR Rule 11, and how AI/ML changes the picture.
CAPA: Corrective & Preventive Action
The three words the industry uses interchangeably and shouldn’t — correction, corrective action, preventive action — and why most "CAPAs" are none of the last two.
Supplier & Vendor Qualification
Why a certificate of analysis is not qualification, how risk sets the depth from questionnaire to on-site audit, and the reason the excipient supplier and the API supplier are governed by different guides.
Design Controls
The traceable process that proves a device design is right before it is built — why verification and validation are not the same question, and how the QMSR transition folds 21 CFR 820.30 into ISO 13485 §7.3.
Complaint Handling & Device Vigilance
Every complaint is not a reportable event, and every reportable event is not a recall — the three decisions a device maker must keep distinct, and why under-reporting is a classic finding.
Biocompatibility (ISO 10993)
Biocompatibility is not a checklist of tests to run — ISO 10993-1 reframed it as a risk-based evaluation, and testing is what you do only where existing data leaves a gap.
Clinical Evaluation & the CER
The clinical evidence that a device is safe and performs — why the how-to guidance and the legal requirement come from two different documents, and why the CER is never "done".
EU MDR & IVDR Transition Timelines
The extended MDR (2023/607) and IVDR (2024/1860) transition deadlines by device class — and the conditions to keep legacy devices on the market.
FDA QMSR Transition
FDA's Quality Management System Regulation harmonizes 21 CFR 820 with ISO 13485 — what changes and what stays.
Bioanalytical Method Validation
Validating the assays that measure drug in biological matrices — selectivity, calibration, accuracy, precision, and stability.
Sterilization Methods Overview
A comparative map of the sterilization technologies used across sterile manufacturing — moist heat, dry heat, filtration, irradiation, and gas — and how a manufacturer chooses among them.
Moist Heat Sterilization
How saturated steam autoclave cycles are designed, qualified, and monitored to deliver a validated sterility assurance level.
Disinfectant Efficacy Qualification
How cleanroom disinfectants are selected, rotated, and proven — against real surfaces and real organisms — to actually reduce bioburden.
Cleanroom HVAC Qualification
How the air handling systems behind ISO-classified cleanrooms are designed, commissioned, and qualified to hold their classification under real operating conditions.
Personnel & Viable Monitoring
The gloved-finger, gown-surface, and viable air sampling program that tracks whether personnel are staying within their qualified contamination limits.
Isolator Decontamination (VHP)
How vaporized hydrogen peroxide cycles are developed and validated to decontaminate isolator and RABS interiors between aseptic campaigns.
Excipient GMP
Why pharmaceutical excipients — the “inactive” majority of most formulations — are governed by an industry-consensus GMP guide rather than a single binding global regulation.
Management Review
The periodic, top-management review of quality-system performance that closes the loop from operational data to resourcing and strategy.
Internal Audit and Self-Inspection
The organisation’s own systematic check on whether it is actually complying with GMP and its own procedures.
Quality Metrics Program
The set of trended indicators an organisation tracks to know whether its quality system is actually working, before a regulator has to tell it otherwise.
Design Verification vs. Design Validation
The two distinct, commonly confused design-control activities that confirm a device was built right, and that the right device was built.
Post-Market Surveillance for Medical Devices
The proactive, systematic collection and analysis of real-world device performance data that a manufacturer runs for as long as the device is on the market.
Supplier Audit Program
The structured, risk-based program of on-site and remote audits an organisation runs to verify that its critical suppliers actually meet the quality expectations they were qualified against.
OT & ICS Security in Regulated Manufacturing
Securing the PLCs, DCS, SCADA and historians that run regulated production — where availability outranks confidentiality and a patch is a change.
Software Supply-Chain Security & SBOM
Third-party components, software bills of materials, vulnerability intake, and supplier assurance for the software a regulated organisation did not write.
Identity & Access Management in GxP Systems
Unique identity, authority checks, segregation of duties, privileged access and periodic review — the controls that make a GxP record attributable.
Cyber Incident Response for Regulated Records
What happens to GxP records, batch disposition and reporting clocks when a security incident lands — and why containment is only half the response.
Regulatory Policy & Standards Engagement
Engaging with regulation while it is still being written — consultations, standards development, harmonisation — and routing what you learn back inside.
Cybersecurity Governance in Regulated Organisations
Who owns cyber risk, what residual risk the business has actually accepted, and how an ISMS meets a pharmaceutical quality system.
Asset Inventory & Attack Surface
Every other control depends on knowing what exists — and in regulated manufacturing the forgotten assets are the ones connected to production.
Data Privacy & Protection in GxP Environments
Where GDPR meets GxP record-keeping — the retention-versus-erasure conflict, health data as a special category, and encryption that survives an audit trail.
Network, Cloud & Endpoint Security for GxP Systems
Segmentation as the control that stops an ordinary compromise becoming a production outage — plus cloud responsibility and endpoints that cannot be touched.
Third-Party Cyber Risk in Regulated Supply
Suppliers hold credentials into the estate and copies of regulated data — and concentration is the risk that appears on nobody’s register.
Vulnerability & Patch Management Under Change Control
Most compromises exploit something known and unpatched — and in validated environments the window between disclosure and remediation is structurally wider.
Business Continuity & Recovery
Ransomware made recovery the primary control — and in regulated manufacturing a system that is running again is not yet back in a validated state.
Security Awareness & Human Factors in GxP
People are the most-attacked control and the fastest detector — and which one dominates depends entirely on whether reporting a mistake is safe.
Process Instrumentation & Measurement
Every control action and recorded value begins at an instrument — and a correctly calibrated one can still be wrongly installed.
Management Accountability & Decision Rights
Regulators hold an organisation to decisions, not intentions — and "everyone assumed someone else had checked" is a decision-rights failure.
Operational Excellence in Regulated Manufacturing
Most waste in regulated manufacturing is rework, investigation and delay caused by poor control — so improvement and compliance rarely trade off.
Candidate Selection & Intended Use
The intended use written here propagates into classification, clinical design, labelling and the whole control strategy.
Formulation & Product Design
Design fixes most of the risk and most of the cost before manufacturing begins — and operations carries what design left behind.
Supply Network Strategy & Resilience
Qualification lead times mean an alternative source cannot be created during a disruption — you supply from the network you built.
Shortage Prevention & Supply Continuity
Most shortages trace to a single site or upstream supplier — which makes them foreseeable from the network map long before they occur.
Cross-Functional Collaboration & Escalation
Most regulated failures cross a functional boundary — the organisation had the information and never assembled it in one place.
Network, Capacity & Capital Strategy
Capacity that is technically available but concentrated in one site is a supply risk no downstream quality work can offset.
Facility & Process Design
A cross-flow designed in is a permanent procedural burden — mitigated forever by people rather than by geometry.
Construction, Installation & Field Quality
Qualification verifies what exists, not what was drawn — and an unreliable as-built record poisons every later change.
Laboratory Network & Operating Model
Testing scattered across laboratories with different quality systems produces results that are individually defensible and collectively inconsistent.
Metrology & Calibration Management
A calibration failure is retrospective by nature — which is why the as-found condition matters more than the as-left one.
Laboratory Capacity, Flow & Turnaround
A laboratory running permanently at capacity has no slack for an investigation — which is exactly when it will be asked to do one.
Platforms, Cloud & Infrastructure for GxP
Moving to a managed platform moves the work, not the accountability.
Digital Service Management in Regulated Operations
The validated state is maintained or lost in routine service management, not in projects.
Portfolio Strategy & Prioritisation
A programme approved without the capacity to support it fails during scale-up, when the alternatives have expired.
Business Cases & Investment Decisions
A business case is a set of assumptions that become commitments — and the optimistic ones are absorbed by functions that were not consulted.
Capital Planning & Project Economics
Contingency cut at approval reappears as scope reduction during execution — and the scope cut is usually qualification and spares.
Demand, Capacity & Scenario Planning
Forecast error becomes either shortage or write-off — and the shortage side carries patient harm.
Insurance, Liability & Risk Transfer
Insurance is a control with conditions attached — and cover voided by a control you did not maintain transfers nothing.
EHS Governance in Regulated Sites
A site can be fully GMP-compliant while operating an unpermitted discharge — the two systems share rooms and people and need one view.
Occupational Safety in Regulated Manufacturing
Personal protection and product protection are the same gowning decision made for two reasons — and they can conflict.
Process Safety in Pharmaceutical Operations
The leading indicators are ordinary — deferred maintenance, bypassed interlocks, changes assessed for product and not for hazard.
Biosafety & Biological Containment
Containment protects people from the product; cleanroom design protects the product from people — and they impose opposite pressure regimes.
Potent Compounds & Specialised Hazards
One toxicological assessment, two obligations — the limits driving cleaning validation and containment come from the same work.
Environmental Compliance & Permits
A permit breach can stop production as effectively as a quality event — and pharmaceutical effluent carries specific scrutiny.
Sustainability in Regulated Operations
Every meaningful sustainability change in a regulated plant is a GMP change — and public claims are now regulated in their own right.
Physical Security & Site Protection
Someone in the room can defeat most logical controls — and controlled substances carry federally prescribed security, not risk-based security.
Emergency Management & Crisis Response
An evacuation that abandons a batch mid-process creates a quality decision — far easier to make if it was anticipated.
Construction & Contractor Safety on Live Sites
The activity that endangers a worker — a breached wall, an isolation, hot work — is the one that threatens the area beside it.
Protect vs Disclose — The Trade-Secret Seam
One obligation requires the method and the data behind a regulated product to be written down and filed; another says their commercial value is that they are not. Where the two meet, and which disclosure bites hardest.

ISO: frequently asked questions

Reference answers on International Organization for Standardization’s mandate, what it publishes, and how its requirements acquire force.

What are the key ISO standards in GxP?

In GxP the consequential ISO standards are ISO 13485 for medical device quality systems, ISO 14971 for device risk management, the ISO 14644 series for cleanrooms, ISO 9001 for generic quality management, ISO 22000 for food safety, and ISO 22716 for cosmetics GMP.

Does ISO certify companies?

No. ISO neither regulates nor certifies; certification is performed by accredited certification bodies. An ISO standard is voluntary until a regulator adopts or references it — then it is effectively mandatory in that market. Certification demonstrates assessment on a date, not an effective system.

How do ISO standards acquire regulatory force?

Through regulator adoption — as the FDA QMSR does by incorporating ISO 13485 by reference, and as EU MDR does through harmonised standards that confer a presumption of conformity. Standards are revised on cycles, so confirm the edition your regulator currently references.