DEV Community

James Whitfield
James Whitfield

Posted on

ISO 9001:2026 and the medical device shop — does it change anything, or is it a footnote to 13485?

We hold both. ISO 13485 was the audit we prepped for weeks in advance. ISO 9001 was the one we prepped for the morning of, because the 13485 evidence covered most of it already.

That's been the pattern for our Class II setup, and from what I can tell talking to peers at other 200-ish person manufacturers, it's not unusual. ISO 13485 is the one with teeth: the prescriptive document control, the design history file, the traceability records, the CAPA loop that auditors will actually dig into. ISO 9001 tends to ride along. The clauses line up, the risk-based thinking is already baked in by 13485 Section 8, and nobody on the QA team loses sleep over it.

So when I started reading the ISO 9001:2026 revision drafts and committee outputs, my first question wasn't "what's changing" — it was whether the things it's adding were things we were already doing anyway because of 13485.

What's reportedly new in the 2026 revision

I won't pretend to have a final DIS in hand, but the published committee direction and industry briefings point to a few areas:

  • Climate change as a context-of-organization consideration (Clause 4.1)
  • More explicit treatment of AI and emerging tech in operational planning
  • Strengthened leadership accountability language
  • Continued emphasis on risk-based thinking, with possible refinements to how "risks and opportunities" are documented
  • Some structural alignment pressure with ISO 13485's own revision cycle

For a generic manufacturer, several of those would be real work. For a medical device shop already running 13485, my read is that most of it is already addressed — not always by name, but by evidence.

Why 13485 has done most of the heavy lifting for us

In practice, when our notified body audits us against 13485, they're effectively auditing the system an ISO 9001 auditor would look at, with more scrutiny:

  • Document control and records — 13485 §7.5 is stricter than 9001 §7.5. If 13485 passes, 9001's document requirements are met.
  • CAPA and nonconforming product — 13485 §8.5.2 and §8.5.3 demand verification of effectiveness and explicit disposition. 9001 §10.2 is satisfied.
  • Design and development — most of us aren't even required to do this under 9001, but 13485 §7.3 (or the FDA's 21 CFR 820.30 for the US market) forces it.
  • Management review — 13485 §5.6 has more required inputs than 9001 §9.3.
  • Risk management — 13485 points to ISO 14971 throughout. 9001's risk language is comparatively hand-wavy.

So when an ISO 9001 surveillance audit comes around, the binder is already thick. We do a gap-check, not a rebuild.

What I'd actually want from 2026

If I'm honest about what would make my job easier in the revision:

  • A clearer statement that AI used in the QMS itself (CAPA clustering, document classification, automated routing) is in scope for risk management — not just AI used in the product. Right now it falls in a gray zone, and reviewers ask about it more every cycle.
  • Climate change considerations that don't duplicate what we're already doing for ISO 14001 or supplier sustainability asks. We've had customers send Scope-3 questionnaires that overlap heavily with this.
  • Something concrete on knowledge management (§7.1.6 in the 2015 version). The current text is thin. Our institutional knowledge walks out the door every time a senior engineer retires, and I'd take a more prescriptive clause on knowledge preservation over another row in the management review minutes.

None of those are deal-breakers. All of them are addressable inside a system already running 13485.

The audit-readiness test

The way I tell whether 9001 is going to bite us for real in 2026 is simple: pick three clauses where the 13485 evidence is weakest, and ask whether the new 9001 text adds anything to our obligations there. For us right now:

  1. Context of the organization (Clause 4) — our 13485 statement of applicability is light. 9001:2026's climate language probably pushes us to actually write down what we're doing, not just intend to.
  2. Knowledge (Clause 7.1.6) — see above.
  3. Documented information retention periods — 9001 has historically been flexible; 13485 prescribes by record type. Where 13485 doesn't specify (training records, certain supplier records), 9001 audit findings can still land.

For those three, the 2026 revision probably means real work, not paperwork.

So is it mostly paperwork?

For a mature 13485 shop, mostly yes — with one or two clauses that will earn a real look. For a startup that only held 9001 and is now chasing 13485 to access the EU or US market, the equation is reversed: 13485 is the work, 9001 follows.

The thing I'd caution against is treating the 2026 revision as a marketing exercise for the QMS. If your existing 13485 evidence is solid, the gap is probably a few SOP edits and a management review input — not a project.

For anyone holding both, how are you sizing the 2026 revision internally — a standalone project, or something you're folding into your next 13485 surveillance cycle?

Top comments (0)