ISO 9001

ISO 9001

ISO 9001 is the international standard for a quality management system (QMS) that any organization can adopt, regardless of sector or size. Published by the International Organization for Standardization (ISO), it sets requirements for consistent processes, customer focus, risk-based thinking, and continual improvement. In medical devices, it is the generic foundation that the sector-specific ISO 13485 standard extends.


What is ISO 9001?

ISO 9001 is the world’s most widely used quality management system standard. The current edition, ISO 9001:2015, defines what an organization must do to consistently deliver products and services that meet customer and regulatory requirements. It is generic by design, so a software firm, a food producer, and a device contract manufacturer can all certify to it.

For a medical device company, ISO 9001 is rarely the end goal. The industry uses ISO 13485, a standard built on the same QMS logic but rewritten for the regulatory demands of medical devices. ISO 9001 still matters because it explains the quality concepts ISO 13485 inherits and because many suppliers in a device supply chain hold ISO 9001 rather than ISO 13485.


Why ISO 9001 matters in medical device development

A device maker depends on process control, and ISO 9001 codifies the discipline that makes process control auditable. Regulators such as the FDA and EU notified bodies look for ISO 13485 and 21 CFR Part 820, but the quality thinking underneath is the same: documented procedures, records, corrective action, and management review.

The practical stakes show up in the supply chain. When you qualify a supplier that is ISO 9001-certified but not ISO 13485-certified, you have to assess the gap yourself. ISO 9001 ensures general process discipline, but it does not require device-specific controls such as sterilization validation, biocompatibility records, or a design history file. Treating an ISO 9001 certificate as if it were ISO 13485 is a mistake that surfaces during an unannounced audit, usually at the worst time.


How ISO 9001 works

ISO 9001:2015 is built on the Plan-Do-Check-Act (PDCA) cycle and seven quality management principles, including customer focus, leadership, the process approach, and improvement. The requirements are set out in clauses 4 through 10, which an organization implements and an auditor checks.

The core building blocks are:

Context and scope (Clause 4)

Define what the QMS covers, identify interested parties, and map your processes.

Leadership (Clause 5)

Top management owns the quality policy. Accountability cannot sit only with the quality department.

Planning (Clause 6)

Address risks and opportunities and set quality objectives. This is where risk-based thinking enters, aligning with ISO 14971 risk management for devices.

Support (Clause 7)

Resources, competence, documented information, and control of records.

Operation (Clause 8)

The work itself: requirements, design and development, supplier control, production, and release.

Performance evaluation (Clause 9)

Monitoring, internal audits, and management review.

Improvement (Clause 10)

Nonconformity, corrective action, and continual improvement.

An accredited third-party body grants certification after a two-stage audit, then maintains it through annual surveillance audits and recertification every three years. ISO 13485 follows the same clause structure but trades the continual-improvement emphasis for an emphasis on maintaining effectiveness, and adds device-specific requirements that map to FDA 21 CFR Part 820 and EU MDR 2017/745.


Common challenges and best practices

The most common failure is a QMS that satisfies the auditor but is not used by anyone. Procedures get written, filed, and ignored. A good system reflects how work actually happens, so the documented process and the floor match during an audit.

Teams also over-document. ISO 9001:2015 reduced the mandatory number of documented procedures and lets you decide which documentation your processes need. Writing a procedure for every task creates a maintenance burden and more ways to drift out of compliance. Keep documentation proportionate to risk.

For device organizations, the better move is to design the QMS to ISO 13485 from the start rather than certifying to ISO 9001 first and retrofitting later. When you rely on ISO 9001 suppliers, write a supplier quality agreement that includes the device-specific controls ISO 9001 omits, and verify them through audits rather than trusting the certificate alone.


Frequently asked questions

Is ISO 9001 required for medical devices?

No. ISO 9001 is voluntary and generic. Medical device manufacturers are expected to use ISO 13485, the sector-specific QMS standard recognized by the FDA, EU MDR, and MDSAP. ISO 9001 still appears in device supply chains, where general suppliers hold it instead of ISO 13485, so manufacturers must assess the gap during supplier qualification.

What is the difference between ISO 9001 and ISO 13485?

ISO 9001 is the generic quality standard for any industry, with a strong emphasis on customer satisfaction and continual improvement. ISO 13485 retains the same structure but is written for medical devices, prioritizing regulatory compliance, risk management, and consistent safety. ISO 13485 adds requirements such as design controls, sterilization records, and device traceability that ISO 9001 does not mandate.

Can a company hold both ISO 9001 and ISO 13485?

Yes, and many contract manufacturers do. Holding both allows an organization to serve medical and non-medical customers under a single integrated quality system. Because ISO 13485 shares the process foundation of ISO 9001, the two work well together, though ISO 13485 governs device-specific work and is the certificate regulators and notified bodies expect to see.

What is the current version of ISO 9001?

The current edition is ISO 9001:2015. It introduced risk-based thinking, the high-level structure shared across ISO management standards, and reduced mandatory documentation. A revision is in development, but ISO 9001:2015 remains the version organizations certify to today.

Related terms

ISO 13485 · Quality Management System (QMS) · FDA 21 CFR Part 820 · ISO 14971 · Supplier Qualification


Table of Contents

Free EU MDR Technical Documentation Compliance Checklist

Understand documentation gaps and use our single-window worksheet to prepare for Notified Body review.

Related Glossaries

```html ```