Industry

ISO 13485 vs ISO 9001: Clause Correspondence Table

Equip IgeraSolutions
September 25, 2026
9 min read
ISO 13485 vs ISO 9001: Clause Correspondence Table
🎧 Listen with AI Voice

2-minute executive summary

⚡ Quick Answer in 30s

ISO 13485 is standalone, not an ISO 9001 add-on. See the real structural links, where the official cross-reference table lives, and where gap analysis concentrates.

✓ Citing current regulationsSee detailed guide below ↓

ISO 13485 vs ISO 9001: clause correspondence table

ISO 13485:2016 is a standalone, independently certifiable quality management standard for medical devices — not a mere add-on to ISO 9001. It shares ISO 9001's broad structural logic (context, leadership, planning, support, operation, evaluation, improvement) but is markedly more prescriptive on documentation, design controls and regulatory risk. The official ISO 13485:2016 standard itself publishes, in its own annex, the authoritative clause-by-clause correspondence table against ISO 9001:2015 — and that annex, not a third-party summary, is where the precise mapping should always be checked.

Quick answer

ISO 13485 and ISO 9001 are related but separate standards. ISO 13485 does not require an organisation to hold ISO 9001 certification, and it can be implemented and audited entirely on its own. The two standards do, however, follow a comparable overall shape, which is exactly why ISO 13485:2016 includes an official annex cross-referencing its clauses against ISO 9001:2015 — a resource every organisation working across both standards should consult directly rather than rely on a paraphrase.

Two standards, one shared ancestry

ISO 13485:2016, "Medical devices — Quality management systems — Requirements for regulatory purposes," was originally developed using ISO 9001 as its structural template. That shared ancestry is visible in the clause numbering and general flow of both documents: organisational context and QMS scope, management responsibility, resource management, product or service realisation, and measurement/analysis/improvement all appear in some form in each standard.

But ISO 13485 diverged deliberately. Its purpose is not general quality management — it is demonstrating that an organisation can consistently design, manufacture, and support medical devices that meet applicable regulatory requirements. That purpose reshapes entire sections of the standard, which is why treating it as "ISO 9001 plus a few medical clauses" understates how differently the two documents are applied in practice.

A common misconception: that ISO 13485 certification requires ISO 9001 certification first, or that it is somehow a "module" bolted onto ISO 9001. Neither is true. ISO 13485 is independently certifiable, and an organisation with no ISO 9001 history at all can pursue it directly.

Why we're not publishing an invented clause-by-clause table

A precise, numbered mapping — "ISO 13485 clause 7.3 corresponds to ISO 9001 clause 8.3," and so on through every sub-clause — is genuinely useful information. It also already exists, published by ISO itself, inside ISO 13485:2016 as a normative or informative annex dedicated exactly to this cross-reference.

Reproducing that level of detail from memory, without the standard open in front of you, risks getting a sub-clause number wrong in a document that quality and regulatory teams may rely on for audit preparation. For a YMYL topic like regulatory compliance, an approximate table that looks authoritative is worse than no table at all. So rather than presenting an invented numeric mapping as fact, this article describes the relationship at the structural level below and points you to the correct source.

Where to get the authoritative table

The clause-by-clause correspondence between ISO 13485:2016 and ISO 9001:2015 is published as an annex within the official ISO 13485:2016 standard text. Obtain it through ISO directly (iso.org) or through your national standards body (such as BSI in the UK, ANSI/ASQ in the US, or the equivalent in your country) when you purchase or license the standard. That annex, read alongside the full clause text, is the only source you should treat as authoritative for a formal gap analysis or audit.

The structural relationship, in general terms

Without claiming sub-clause precision, it is fair and verifiable to describe the relationship at a broader level. ISO 13485's core clauses 4 through 8 broadly correspond to the structure running through ISO 9001's clauses 4 through 10 — both standards move from quality management system fundamentals, through management and resource responsibilities, into operational/product realisation requirements, and on to measurement and improvement activity. The clause numbering itself isn't identical between the two standards (ISO 13485 wasn't rewritten to the newer ISO High Level Structure that ISO 9001:2015 uses), which is exactly why the official annex exists — to translate between the two numbering schemes.

Area ISO 9001:2015 approach ISO 13485:2016 approach
Overall aim General QMS effectiveness and customer satisfaction, applicable to any sector QMS effectiveness specifically in service of meeting medical device regulatory requirements
Documentation Flexible — organisation decides what documented information is necessary Far more prescriptive: device master/technical files, defined retention obligations, tighter document and record control
Design and development General design and development planning and controls Detailed design control requirements — design inputs/outputs, verification, validation, transfer, and a design/development file per device
Risk management Risk-based thinking woven through the QMS generally Explicit, formal risk management expectations tied to the product across its lifecycle, referencing dedicated risk management practice
Continual improvement Explicit requirement to demonstrate continual improvement of the QMS Focuses on maintaining QMS effectiveness and regulatory conformity rather than mandating the same explicit continual-improvement demonstration

This table summarises well-established conceptual differences between the two standards at a general level. It is not a substitute for the clause-by-clause annex published in ISO 13485:2016.

The practical business case: why an ISO 9001 organisation has a head start

If your organisation already holds ISO 9001 certification, you are not starting from zero when you approach ISO 13485. The two standards share enough structural DNA that a mature ISO 9001 system typically already covers, at least in outline:

  • A functioning management review cycle and internal audit programme
  • Document and record control processes, even if they need tightening
  • Supplier evaluation and purchasing controls
  • Corrective and preventive action (CAPA) discipline
  • A quality policy and defined quality objectives cascaded through the organisation
  • A working culture of process-based thinking and internal audit readiness

That foundation is real value. Auditors and consultants alike generally observe that organisations moving from ISO 9001 to ISO 13485 need to build on top of an existing management system rather than construct one from scratch — which typically shortens implementation timelines and reduces the change-management burden on staff who are already used to a QMS.

Where the gap-analysis effort actually concentrates

Based on the conceptual differences established above, the bulk of transition effort for an ISO 9001-certified organisation typically concentrates in three areas:

1

Design controls

If your ISO 9001 scope didn't include formal design and development activity, this is usually the largest build: design input/output records, verification and validation protocols, design history/technical files, and a defined design transfer process into manufacturing.

2

Documentation rigor

ISO 13485 expects tighter, more traceable document and record control than many ISO 9001 implementations maintain in practice — device-specific files, more disciplined change control, and clearer linkage between records and specific products or batches.

3

Risk management and regulatory requirements

Formal, product-lifecycle risk management and explicit regulatory-conformity obligations are more deeply embedded in ISO 13485 than in a typical ISO 9001 system, and usually need dedicated process build-out rather than a light adaptation of existing procedures.

Outside these three areas, an experienced ISO 9001 organisation will often find that management commitment, internal audit, CAPA, and supplier management processes need adaptation and tightening for the medical device context, but not rebuilding from the ground up.

Practical impact for quality and regulatory teams

For a quality manager scoping a transition project, the practical takeaway is to run a structured gap analysis against the official ISO 13485:2016 text and its ISO 9001 correspondence annex — clause by clause, using the real document — rather than assuming coverage based on general familiarity with ISO 9001. Treat design controls, documentation depth, and risk management as the three workstreams likely to need dedicated resourcing, and budget internal audit and management review time accordingly before a certification audit is booked.

One of the recurring frictions in this kind of gap analysis is simply locating the right evidence fast: which procedure covers design verification, which record shows the last risk assessment review, which document defines retention for a given file type. This is precisely the kind of question IgeraIndustria is built to answer — it lets a quality or regulatory team query their own QMS documents directly in natural language and get an answer that cites the exact source document and section, rather than relying on institutional memory of where something was last filed.

Common mistakes when comparing the two standards

Assuming ISO 9001 certification is a prerequisite. It isn't. Organisations frequently pursue ISO 13485 directly, especially medical device start-ups with no prior QMS certification at all.

Treating an unverified online "mapping table" as authoritative. Only the official annex published within ISO 13485:2016 itself, alongside the full clause text, should be used for formal gap-analysis or audit-preparation purposes.

Underestimating design controls because "we already do design and development." ISO 13485's design control expectations are considerably more detailed than a general ISO 9001 clause, and light-touch design processes rarely transfer without substantial rework.

Assuming continual improvement obligations are identical. ISO 13485 does not require the same explicit demonstration of continual improvement that ISO 9001 does; conflating the two can lead to either over-building unnecessary improvement documentation or, worse, under-building the regulatory-conformity evidence ISO 13485 actually does require.

Is your QMS documentation spread across folders, versions, and email threads?

IgeraIndustria indexes your procedures, design files, and risk records, and answers your team's questions by citing the exact document and section — no guessing where the latest version lives.

Try free for 14 days

Frequently asked questions

Is ISO 13485 just an extension of ISO 9001?

No. ISO 13485 is a standalone, independently certifiable standard with its own scope, requirements, and audit process. It shares a broadly similar structure with ISO 9001 and was originally developed from it, but it is not a supplement or add-on module — an organisation can be certified to ISO 13485 without ever holding ISO 9001 certification.

Do I need ISO 9001 before I can get ISO 13485?

No, ISO 9001 certification is not a prerequisite for ISO 13485. Many medical device organisations, particularly newer ones, go directly for ISO 13485 without ever pursuing ISO 9001.

Where can I find the exact clause-by-clause correspondence between the two standards?

The authoritative source is the annex published within the official ISO 13485:2016 standard document itself, which cross-references its clauses against ISO 9001:2015. Obtain this through ISO (iso.org) or your national standards body rather than relying on third-party summaries for formal compliance work.

What is the biggest gap an ISO 9001 company usually faces moving to ISO 13485?

Design controls are typically the largest gap, followed by the additional documentation rigor and the more formal, product-lifecycle risk management ISO 13485 expects. Organisations with limited or informal design and development processes under ISO 9001 should expect this to be the most resource-intensive area to build out.

Does ISO 13485 require the same continual improvement demonstration as ISO 9001?

No. ISO 13485 focuses on maintaining the effectiveness of the QMS and ongoing regulatory conformity, rather than mandating the same explicit continual-improvement demonstration that ISO 9001 requires. This is one of the clearer conceptual differences between the two standards.

Can I keep both certifications at once?

Yes. Many medical device manufacturers maintain both ISO 9001 and ISO 13485 certification concurrently, often through an integrated management system, since the shared structural elements make dual maintenance more efficient than running two entirely separate systems.

Is this article a substitute for a formal gap analysis?

No. It explains the general, verifiable relationship between the two standards to help you scope a transition project. A formal gap analysis should be carried out against the current, official text of ISO 13485:2016 and ISO 9001:2015, ideally with support from a qualified quality consultant or notified body familiar with your product category and market.

Disclaimer

This article is for general information purposes only and does not constitute certification, legal, or regulatory advice. It does not reproduce or replace the official clause-by-clause correspondence annex published within ISO 13485:2016. For a formal gap analysis, certification planning, or regulatory submission, consult a qualified quality management consultant or an accredited notified body, and always refer to the current official text of ISO 13485:2016 and ISO 9001:2015.

#ISO 13485 vs ISO 9001#ISO 13485 ISO 9001 correspondence#medical device QMS standard#ISO 13485 clause mapping#ISO 13485 gap analysis#ISO 13485 design controls#ISO 13485 certification#medical device quality management

Ask this article

IA 2026

Igera's AI answers questions citing the facts and regulations in this article

2 of 2 free queries

Suggested questions (click to test):

Diagnóstico Interactivo 60s

Technical Compliance & Industrial Operations Diagnostic

Analyze speed of access to regulations (CTE, OSH, CE) in your plant or jobsite

Pregunta 1 de 3

How do technicians and operators access safety protocols and manuals?

Was this article helpful?

⚙️IgeraIndustriaOperations Template
GUÍA DESCARGABLE (TXT)

Preventive Maintenance & ISO 9001/45001 Industrial Checklist

Floor inspection template for machine operations, failure tracking and unplanned downtime reduction.

  • Shift inspection standardization for plant operators
  • Up to 40% faster anomaly response times
  • Full traceability for ISO audits and HSE compliance

Instant download · No card · 100% spam-free

Share this article

Help spread knowledge by sharing this content with your network