Call Today! (800) 244-5409

September 2026

ISO 13485: A Practical Guide for Medical Device Companies

If you manufacture, supply, or distribute medical devices, ISO 13485 is not optional in any market that matters. It is the quality management system standard regulators, notified bodies, and customers expect you to run your business on. And as of 2026, understanding it is more urgent than ever, because the U.S. Food and Drug Administration has rewritten its own device quality regulation to incorporate ISO 13485 by reference.

This guide walks through what ISO 13485 requirements actually ask of you, how the standard relates to the more familiar ISO 9001, where design controls and risk management fit, and who in the device supply chain needs to be certified. The goal is to give operations and quality leaders a clear, practical picture before you commit budget and calendar to an implementation.


What ISO 13485 Is — and How It Differs from ISO 9001

ISO 13485 is a stand-alone quality management system standard written specifically for organizations involved in the medical device life cycle. Although it shares DNA with ISO 9001 and follows a similar clause structure, it is not a sector supplement or an add-on. You certify to ISO 13485 in its own right, and a device company generally does not need to hold ISO 9001 as well.

The most important distinction is philosophical. ISO 9001 is built around risk-based thinking and gives organizations broad latitude to decide how much process and documentation their context requires. ISO 13485 deliberately narrows that flexibility. Where ISO 9001 lets you judge whether a documented procedure is necessary, ISO 13485 frequently tells you outright that one is required. Records, controls, and documented procedures are mandated across design, production, sterilization, complaint handling, and post-market activity.

That prescriptiveness reflects the stakes. A defective consumer product is a return; a defective medical device can injure a patient. So ISO 13485 trades ISO 9001’s adaptability for regulatory rigor. It expects traceability, formal document control, validated processes, and evidence that your system stays effective over the life of every product. If your team knows ISO 9001, the transition is real work rather than a simple relabeling.

If you are weighing the two standards for a mixed product portfolio, our ISO 9001 consulting and ISO 13485 consulting teams can help you decide what to certify and in what sequence.


Design Controls: Proving the Device Was Designed Right

For most device makers, design and development controls are the heart of ISO 13485 and the area auditors probe hardest. The standard requires a disciplined, documented flow from design inputs through outputs, verification, validation, transfer to production, and formal control of design changes.

In practice that means capturing user needs and regulatory requirements as measurable design inputs, translating them into design outputs that can be verified, and holding design reviews at planned stages with the right people in the room. Verification confirms the device meets its specifications. Validation confirms it meets the user’s actual needs under real conditions of use. Every one of these steps produces records, and those records must live in a coherent design history file that tells the full story of how the device came to be.

Design controls are also where ISO 13485 aligns most closely with FDA expectations, which makes getting them right a dual investment. Clean, well-structured design documentation satisfies your certification audit and puts you in far better shape for regulatory submissions and inspections. Weak documentation here is the single most common reason device QMS implementations stall.


Risk Management and ISO 14971

ISO 13485 requires you to apply risk management across the product realization process, but it does not spell out the method in detail. That is by design. The recognized companion standard, ISO 14971, defines how to identify hazards, estimate and evaluate risk, implement controls, and monitor residual risk throughout the device life cycle.

Treat the two standards as partners. ISO 13485 tells you that risk management must be woven into design, purchasing, production, and post-market surveillance. ISO 14971 gives you the framework to do it defensibly. Auditors will look for a living risk management file that traces each identified hazard to a control and to evidence that the control works, not a one-time document written to pass an audit and then shelved.

This is a genuine departure from ISO 9001’s lighter, more discretionary approach to risk. Under ISO 13485, risk management is a continuous, documented discipline that follows the product from concept through obsolescence, and post-market data is expected to feed back into your risk assessments.


Why FDA’s QMSR Now Incorporates ISO 13485

For decades, U.S. device manufacturers followed the FDA Quality System Regulation, known as the QSR, under 21 CFR Part 820. That regulation ran on a separate but parallel track to ISO 13485, forcing companies selling internationally to satisfy two overlapping systems.

The FDA has closed that gap. Under the Quality Management System Regulation (QMSR), the agency has amended Part 820 to incorporate ISO 13485 by reference, harmonizing U.S. requirements with the international standard. The final rule was published in early 2024 with a transition period, and it takes effect in 2026. When it does, conformance to ISO 13485 becomes the backbone of FDA quality expectations rather than a separate voluntary standard.

The practical takeaway is straightforward. A well-run ISO 13485 system is no longer just a passport to global markets; it increasingly maps to what the FDA itself now requires of device firms. Companies that build to ISO 13485 today are positioning themselves for the QMSR rather than facing a scramble later. If you sell into the U.S., treat ISO 13485 alignment as regulatory readiness, not merely a certificate.


Who Actually Needs ISO 13485

The standard reaches further up and down the supply chain than many companies assume. ISO 13485 applies to any organization involved in one or more stages of the medical device life cycle, which in practice includes:

  • Manufacturers — the most obvious case, covering firms that design, produce, and place finished devices on the market.
  • Component and material suppliers — organizations providing parts, subassemblies, sterilization, or contract manufacturing to device makers. Manufacturers increasingly require certified suppliers, so certification becomes a condition of doing business.
  • Distributors and importers — companies that store, handle, or move devices and must show they protect product integrity and maintain traceability.
  • Providers of associated services — including calibration, installation, and servicing organizations whose work affects device safety or performance.

If your customers are certified device manufacturers, the question is usually not whether you need ISO 13485 but when a customer will make it a purchase requirement. Getting ahead of that demand protects existing accounts and opens doors to new ones.


The EU MDR Context

Selling devices in Europe adds another layer. The EU Medical Device Regulation, or MDR, governs market access across the European Union and sets its own conformity assessment requirements. ISO 13485 is not the MDR, and certification to the standard does not by itself grant a CE mark.

That said, the two are deeply complementary. A quality management system conforming to ISO 13485 is the foundation most manufacturers use to demonstrate the QMS obligations the MDR imposes, and notified bodies will expect to see one. Think of ISO 13485 as necessary groundwork for EU market access rather than the whole staircase. If Europe is on your roadmap, build your ISO 13485 system with MDR expectations in mind so the two efforts reinforce each other instead of duplicating work.


Getting Implementation Right

An ISO 13485 implementation is more demanding than a typical ISO 9001 project, largely because of the mandatory documentation, design controls, and risk management the standard requires. A structured gap analysis at the outset shows exactly where your current practices fall short of ISO 13485 requirements, which is far cheaper than discovering those gaps during a registrar audit.

From there, the work is methodical: build or refine the QMS documentation, stand up compliant design controls, integrate ISO 14971 risk management, train your team, and run internal audits before the certification body arrives. At QRC we pair veteran ISO consultants with AI tooling that accelerates gap analysis, documentation drafting, and audit preparation — with our consultants accountable for every deliverable. You move faster without cutting the corners regulators care about. Explore how that works on our AI-powered ISO consulting page, and browse the full range of ISO consulting services if you support multiple standards.


Ready to map your path to ISO 13485 and QMSR readiness? Contact QRC or call (800) 244-5409 to talk through a gap analysis built for your device business.

AS9100 vs ISO 9001, AS9110 and AS9120: What Aerospace Suppliers Need to Know

If you supply parts, assemblies, or services to the aerospace and defense industry, sooner or later a customer will tell you that ISO 9001 alone is not enough. They want AS9100 — or, depending on what your business does to the product, AS9110 or AS9120. And if you have spent any time reading the two standards side by side, you have probably noticed something: they look almost identical for the first several pages, then AS9100 keeps going.

That is the whole story in one sentence. AS9100 is ISO 9001 with an aerospace layer bolted on top. Understanding exactly what that layer contains — and why it exists — is the difference between walking into your first registrar audit prepared and walking in hoping the auditor does not ask the wrong question. This article breaks down what AS9100 adds, how AS9100 compares with AS9110 and AS9120, who actually requires each one, and the realistic path from a general quality system to an aerospace-grade one.


The Short Version: AS9100 Contains ISO 9001

AS9100 is published by the SAE and maintained through the International Aerospace Quality Group (IAQG). It incorporates the full text of ISO 9001 verbatim, then adds requirements specific to aviation, space, and defense. When you read the standard, the aerospace additions are usually printed in a different format so you can see exactly where ISO 9001 ends and the aerospace content begins.

That means an AS9100-certified company is, by definition, also meeting every ISO 9001 requirement. The reverse is not true. A company certified to ISO 9001 has a solid quality management system, but it has not demonstrated the additional controls that aerospace customers consider non-negotiable — controls built up over decades of hard lessons about what happens when a single non-conforming part reaches a flying aircraft.

There is also a family of related standards worth knowing. AS9100 covers organizations that design and manufacture aviation, space, and defense products. AS9110 covers maintenance, repair, and overhaul (MRO) operations. AS9120 covers distributors and stockists — companies that buy, hold, and resell aerospace parts without manufacturing them. All three share the same ISO 9001 foundation and the same aerospace philosophy; they differ in which additional requirements apply to your role in the supply chain. Our AS9100, AS9110, and AS9120 implementation services cover all three.


AS9100 vs AS9110 vs AS9120: Which Applies to You

Suppliers comparing AS9100 vs AS9120 — or AS9100 vs AS9110 — are almost always asking one practical question: which certificate does my customer expect from a business like mine? The answer follows what your organization does to the product, not how big you are.

AS9100 applies if you design and/or manufacture aviation, space, and defense products. It is the broadest of the three and carries the full aerospace layer: configuration management, first article inspection, critical items and key characteristics, product safety.

AS9110 applies to maintenance, repair, and overhaul organizations. It keeps the ISO 9001 core and the aerospace philosophy, then adds the requirements that matter when you are returning an article to service rather than building it new — maintenance planning, human factors in maintenance error, technical data control, and airworthiness responsibilities.

AS9120 applies to distributors and stockists that buy, hold, split, and resell aerospace parts without manufacturing them. Its additions concentrate on the risks of a pass-through business: traceability back to the original manufacturer, control of records that travel with the part, counterfeit-part prevention, and correct handling, storage, and splitting of lots.

Because all three share the same ISO 9001 foundation, the comparison is less about which standard is harder and more about scope. Organizations that do more than one thing — a distributor that also performs light assembly, or a manufacturer with an in-house repair station — sometimes certify to more than one, or scope a single certificate carefully. If that is your situation, get the scope decided before you build the system, because rescoping after documentation is written is expensive.

QRC implements and maintains systems for all three: see AS9100, AS9110 & AS9120 consulting if you need the system built, or AS9100 training, including 16-hour internal auditor training and certification, if you need your own people able to run and audit it.


What AS9100 Adds That ISO 9001 Does Not Require

The aerospace layer is not a vague set of good intentions. It is a specific list of disciplines. These are the ones that most often catch suppliers off guard.

Risk Management

ISO 9001 asks you to think about risk in general terms — the well-known “risk-based thinking” language. AS9100 goes further and requires a defined, documented process for operational risk management: identifying risks in your products and processes, assigning them, mitigating them, and tracking them through the life of the program. Auditors expect to see evidence that risk is managed as an ongoing activity, not a box checked once during planning.

Configuration Management

This is one of the biggest additions and one of the most misunderstood. Configuration management means you can prove, at any point, exactly which revision of a design, drawing, or specification a given part was built to — and that changes were controlled, approved, and communicated. In an industry where a part might be manufactured years after it was designed and installed years after that, knowing the precise configuration is not paperwork for its own sake. It is traceability that can be reconstructed on demand.

Counterfeit-Part Prevention

AS9100 requires a documented process to prevent the use of counterfeit or suspect parts, particularly for purchased components and electronics. Counterfeit parts have caused real failures in defense and aerospace systems, so the standard expects controls around sourcing, verification, and handling of suspect material — a concern that ISO 9001 does not address at all.

First Article Inspection (FAI)

Before a production run, AS9100 requires a first article inspection: a complete, documented verification that the first manufactured part meets every drawing and specification requirement. The FAI is recorded on standardized forms (the AS9102 format) and becomes objective evidence that your process is capable of producing conforming parts before you build hundreds or thousands of them.

Special Requirements and Critical Items

AS9100 introduces defined terminology for critical items (features whose variation significantly affects safety, performance, or fit) and key characteristics (attributes that must be controlled because their variation affects the product). You are expected to identify these, flow them down to suppliers, and apply appropriate controls. This is where quality planning gets genuinely aerospace-specific.

Product Safety and Human Factors

Recent revisions of AS9100 added explicit requirements around product safety and awareness of human factors in non-conformances — recognizing that human error is a root cause worth managing directly rather than treating every defect as a purely mechanical problem.

The OASIS Database

This one is administrative but unavoidable. AS9100 certifications are registered in OASIS — the Online Aerospace Supplier Information System maintained by the IAQG. Your certification, your certification body, and your audit status are visible in OASIS to customers who want to verify you. Your registrar reports audit results there, and prime contractors routinely check it before awarding work. An ISO 9001 certificate lives in your filing cabinet; an AS9100 certificate lives in a database the whole industry can see.


Who Actually Requires AS9100

AS9100 is rarely something a company pursues purely for internal improvement. It is almost always driven by customer demand, and the demand flows downhill through the supply chain.

Prime contractors — the major airframe and engine manufacturers and their tier-one suppliers — require AS9100 of the companies they buy from. When a prime holds AS9100, the standard obligates them to flow aerospace quality requirements down to their own suppliers. So even if you are a small machine shop three tiers removed from the final aircraft, the requirement reaches you through your immediate customer.

The Department of Defense and its contractors frequently require AS9100 for aerospace and defense work, either by direct specification or through the prime contractors executing defense programs. If you are pursuing defense work, AS9100 often travels alongside other requirements — cybersecurity maturity chief among them. Suppliers heading in that direction should look at CMMC readiness in parallel, since the same customers tend to ask for both.

The practical test is simple: if your customers are in aviation, space, or defense, ask them directly what they require. Many suppliers discover they need AS9100 not because a regulation compels it, but because they cannot win or keep contracts without it. Certification becomes the price of admission to the aerospace supply chain.


The Path From ISO 9001 to AS9100

The good news for a company that already holds ISO 9001 is that you are not starting from zero. You have the foundation. The work is closing the gap between a general quality system and an aerospace one.

Start with a gap analysis. Map your existing ISO 9001 system against the AS9100 requirements and identify exactly which aerospace additions you are missing — risk management processes, configuration management, FAI procedures, counterfeit-part controls, and so on. A structured ISO gap analysis turns “we need AS9100” into a concrete, prioritized list of what to build.

Build the missing processes and documentation. Most of the effort is in the aerospace-specific disciplines above. This is where the documentation load is heaviest, and where AI-assisted drafting can genuinely accelerate the work without cutting corners. At QRC we use AI tooling to speed up gap analysis and generate first-draft procedures, while our veteran aerospace consultants stay accountable for every deliverable — because an auditor will hold a human accountable, and so do we. Proper documentation services keep the manual readable rather than bloated.

Implement, then verify with internal audits. New processes need to run long enough to produce records before your certification audit. Internal audits and a management review confirm the system is working as designed and surface problems while you still have time to fix them. If your team needs the skills, auditor training builds internal capability that pays off long after certification.

Choose an accredited registrar and complete the certification audit. AS9100 certification must come from a certification body accredited for the aerospace scheme, and the results are recorded in OASIS. Companies on our full-service program consistently pass their first registrar audit — a track record that matters most when a contract is riding on the outcome.

For companies already holding ISO 9001, the upgrade is typically faster than a first-time implementation because the management-system backbone is already in place. A full ISO 9001 implementation generally runs five to seven months; an AS9100 upgrade focuses that effort on the aerospace layer. If you are still building the ISO 9001 foundation itself, our ISO 9001 consulting and broader ISO consulting services cover the whole journey.


Making the Right Call

If you are weighing AS9100 vs ISO 9001, the decision usually is not really yours to make — your customers make it for you. What is in your control is how prepared you are when the requirement lands. Treat AS9100 as ISO 9001 plus a well-defined aerospace discipline, close the gap deliberately rather than scrambling, and the certification becomes a durable competitive advantage instead of a fire drill.

The suppliers who struggle are the ones who underestimate the aerospace layer — who assume their ISO 9001 system is “basically AS9100” and find out otherwise at the audit. The ones who succeed treat configuration management, risk, FAI, and counterfeit prevention as real capabilities worth building, because in aerospace, they are.

Ready to move from ISO 9001 to AS9100, or to certify from scratch? Contact QRC or call (800) 244-5409 to talk through your aerospace certification path with a consultant who has done it before.