Auditing and Management Systems
ISO 9001: General Quality Management Systems
ISO 9001 is one of the most widely used quality management standards, written for any organization in any sector. Many device suppliers and parent companies hold ISO 9001 certificates, but device regulators look for a quality system built on ISO 13485 and the applicable regulations.
At a Glance
- Standard
- ISO 9001
- Subject
- General Quality Management Systems
- Group
- Auditing and Management Systems
- Industries
- 1 industry guides reference it
A plain-language summary of scope, not the standard itself. Buy the current edition from the publisher and check which edition your auditor or market expects.
What It Covers
ISO 9001 sets requirements for a QMS that consistently delivers products and services meeting customer and applicable statutory and regulatory requirements, and that aims to improve customer satisfaction. It follows the common structure ISO uses for its management system standards, which makes it straightforward to combine with environmental, information security and other systems. Context of the organization, interested parties, leadership, risk-based thinking and continual improvement sit at its center.
ISO 13485 grew from an earlier ISO 9001 text but went its own way. Where ISO 9001 stresses customer satisfaction and continual improvement, ISO 13485 stresses meeting regulatory requirements and maintaining an effective system. It also adds device-specific expectations that ISO 9001 doesn't have: more documented procedures, design and development files, process validation, sterile product controls, traceability, complaint handling and regulatory reporting. ISO 9001 leaves organizations more freedom in how much they document.
For a device manufacturer, ISO 9001 on its own is not sufficient for device regulators. FDA's QMSR incorporates ISO 13485, not ISO 9001, and MDSAP and EU notified body audits are built around ISO 13485 and the device regulations. ISO 9001 still matters in the supply chain: component and service suppliers often hold it, and some groups run both systems for different business units.
Who It Applies To
- Component and service suppliers to device makers that don't make finished devices
- Parent companies or divisions outside the regulated device business
- Device firms running one system across regulated and non-regulated product lines
- Device makers qualifying suppliers whose quality system is built on ISO 9001
What Auditors Check
Context and Interested Parties
A documented understanding of internal and external issues and the needs of interested parties, and how they shape the QMS scope.
Risks and Opportunities
Evidence that risks and opportunities were identified and that actions to address them were planned and their effect evaluated.
Quality Objectives
Measurable objectives, plans for achieving them and records showing progress is reviewed by management.
Customer Focus
How customer requirements are captured, and how customer satisfaction is monitored and acted on.
Continual Improvement
Nonconformity and corrective action records, internal audit results and management review outputs that lead to real improvement.
Fit for Device Supply
When a device maker audits an ISO 9001 supplier, whether the quality agreement covers what the device maker needs, such as change notification, traceability and process validation.
Related Services
ISO 13485 Certification Readiness
Prepare your QMS, records and people for a certification body's Stage 1 and Stage 2 audits.
Supplier Audits and Supplier Controls
Risk-based supplier selection, quality agreements, monitoring and supplier audits that hold up under QMSR.
QMS Build for Startups (Phased)
A QMS built in phases for a device startup: design controls and risk first, the rest before you need it.
Industry Guides That Reference ISO 9001
Questions
Is ISO 9001 certification enough to sell a medical device in the US?
No. FDA's QMSR incorporates ISO 13485, not ISO 9001, and adds FDA-specific requirements on top. An ISO 9001 certificate shows a working quality system, but you'd still need to close the gaps to ISO 13485 and the QMSR.
Can we hold both ISO 9001 and ISO 13485 certificates?
Yes, and some organizations do, often when they have regulated and non-regulated product lines. The two systems can share procedures, but the device side has to meet ISO 13485's added requirements, and the certification body audits each against its own standard.
We're moving from ISO 9001 to ISO 13485. Where are the biggest gaps?
Usually in design and development documentation, process validation, documented procedures and records, complaint handling and regulatory reporting, and risk management tied to the device. A gap assessment shows which existing ISO 9001 procedures can be extended and where new ones are needed.
Should our suppliers hold ISO 13485 rather than ISO 9001?
Not necessarily. What matters is whether a supplier's controls match the risk of what it supplies, and your supplier controls should define that. For critical components or processes you may need more than either certificate tells you, such as a quality agreement, audits and change notification.
ISO 9001
Check Your Quality System Against ISO 9001
An AI-assisted first pass maps your existing documents against the requirements in scope, and an advisor reviews every result. Please don't send confidential documents yet: secure upload is set up after onboarding.


