HomeResources › Consulting
Guide · Medical Devices

ISO 13485 vs ISO 9001: what's the difference?

Both are quality management system standards — but they are built for different purposes. Here's how they differ and which one a medical-device company actually needs.

By Continuum Improvement · Updated 2026-07-03

ISO 9001 and ISO 13485 are both quality management system (QMS) standards, and they share a lot of DNA. But they are written for different worlds. ISO 9001 is a general-purpose standard used across nearly every industry, with a strong emphasis on customer satisfaction and continual improvement. ISO 13485 is purpose-built for medical devices, where the priority is patient safety and regulatory compliance. Understanding the difference tells you which one your company needs.

Same roots, different priorities

ISO 13485 is based on the structure of ISO 9001, so if you know one, the other will feel familiar. The key shift is in emphasis:

  • ISO 9001 centers on customer satisfaction and continual improvement.
  • ISO 13485 centers on consistently meeting customer and regulatory requirements, with safety and risk front and center.

Notably, ISO 13485 deliberately does not adopt some of ISO 9001's newer language around continual improvement as a headline goal — for a medical device, predictability and control matter more than constant change.

Where ISO 13485 goes further

ISO 13485 adds requirements that ISO 9001 does not emphasize, because they matter specifically for medical devices:

  • Risk management woven throughout the product lifecycle (aligned with ISO 14971)
  • Design and development controls, including a design history file
  • Stronger documentation and record-keeping, including a medical device file
  • Traceability requirements, especially for implantable devices
  • Regulatory alignment — the system is expected to map to requirements like FDA 21 CFR 820 and EU MDR/IVDR
  • Process validation where output can't be fully verified by later inspection

Which one do you need?

Here is the short version:

  • If you make or design medical devices or in-vitro diagnostics, you almost certainly need ISO 13485. Many markets and customers effectively require it, and it aligns with the regulations you must meet.
  • If you are a general manufacturer or service provider outside the medical space, ISO 9001 is the right target.
  • Some suppliers to the medical industry carry both — ISO 9001 for their broader business and ISO 13485 for their device-related work.

You don't have to choose blind

Because the two standards share a structure, a well-designed QMS can be built to satisfy ISO 13485 while remaining compatible with ISO 9001 thinking. For device companies, we generally recommend building to ISO 13485 and mapping in the applicable FDA and EU requirements from the start — it is far cheaper than retrofitting a general QMS later.

This is an overview, not regulatory advice. Your specific pathway depends on your device classification and target markets — which is exactly what a scoping conversation sorts out.
FAQ

Frequently asked

Is ISO 13485 harder than ISO 9001?

Not harder so much as stricter in specific areas — risk management, design controls, documentation, and traceability. If you already run an ISO 9001 system, moving to ISO 13485 is an extension rather than a restart.

Can one QMS cover both ISO 9001 and ISO 13485?

Yes. Because they share a common structure, a single well-designed quality system can be built to meet both, which some suppliers to the medical industry do.

Does ISO 13485 make us FDA compliant?

Not automatically, but it overlaps heavily with FDA 21 CFR 820. A system built to ISO 13485 can be structured to satisfy FDA and EU requirements together, which is how we recommend building it.

Want a hand with this?

We help teams turn a checklist into a passing audit — practical, right-sized, and led by a Six Sigma Black Belt with 15+ years in regulated industries.

Ask us which standard fits