DEV Community

Priya Nair
Priya Nair

Posted on

ISO 13485 does most of the work. The 2026 ISO 9001 revision shifts where the rest lives

The audit prep spreadsheet for our dual-cert surveillance has six rows for ISO 13485 and two for ISO 9001. That ratio has been roughly stable for the four years I have been at my current role, and it reflects a reality most medical device QMS people know: 13485 carries the load, 9001 is the standard we run alongside it for other reasons.

Which is why the upcoming revision of ISO 9001 deserves a careful look rather than a shrug. The easy answer is "13485 already covers everything that matters, so who cares." The honest answer is more interesting.

Why medical device companies hold ISO 9001 at all

Article 10(9) of the EU MDR requires a QMS. ISO 13485:2016 is the harmonised standard under MDR, so for CE marking that is — operationally — the standard you have to satisfy. ISO 9001 is held for other reasons: a parent company requirement, a non-medical customer asking for "ISO certified" on a tender, some third-country registrations, or occasionally a board that wants the badge.

For a pure EU meddev SME selling only CE-marked product, ISO 9001 is sometimes optional. In practice it stays on the certificate because pulling it triggers internal conversations nobody wants to have.

What the two standards actually disagree on

The widely held belief is that ISO 13485 is "ISO 9001 with extra medical device stuff." That is not quite right.

ISO 13485 is more prescriptive on the things medical device regulators care about: document control (4.2.4), records control (4.2.5), design and development (7.3), purchasing and supplier control (7.4), production and service provision (7.5), CAPA (8.5.2 and 8.5.3), and complaint handling. ISO 9001 covers some of the same ground but at a higher level, and pulls in different themes: context of the organisation, leadership, customer satisfaction, and a broader definition of "interested parties."

13485 also has a few explicit exclusions and modifications relative to 9001 — post-delivery activities in 7.5.5, for instance, are narrower. So the two standards do not align clause for clause, even though Annex SL keeps the structure compatible.

The practical upshot: when we map our QMS to both, the 13485 clauses generate real procedure work. The 9001 clauses mostly need a sentence in the manual and a paragraph in a management review.

What the 2026 revision actually changes

Without going clause-by-clause into FDIS territory, the themes that show up across the draft material are:

  • Climate change and sustainability considerations inside "context of the organisation"
  • Risk-based thinking made more explicit at strategic and operational levels
  • Broader stakeholder and interested-party framing beyond customers
  • Digital transformation as something the QMS is expected to address
  • A continued relaxation of prescriptive documentation requirements — less "you shall maintain documented information for X"

For a 13485 shop, the risk-based thinking theme is old news — 13485 has been risk-obsessed since long before MDR made it fashionable. The digital transformation theme is mostly already covered by your design controls and your change control. The documentation relaxation mostly aligns 9001 with how most of us were running it anyway.

The genuinely new content is climate and sustainability in the context-of-the-organisation analysis.

Where it actually bites for a meddev QMS

Here is the honest list:

  • Context of the organisation: you will need to address climate change as an external issue. Not as a product requirement — your 13485 risk file is not suddenly expected to manage emissions — but as a strategic QMS consideration. To be fair, this is one paragraph in a context document. It is still work.
  • Interested parties: the broadening of who counts as a "stakeholder" beyond customers and regulators might surface people you have not formally documented. Usually a tweak.
  • Leadership and commitment: usually already addressed; unlikely to require new procedure.
  • Documentation requirements: the relaxation is real and welcome, but be careful not to throw out records your 13485 system or your notified body still expects.

The 2026 revision does not require a 13485 rebuild. It requires a 9001 refresh with one new strategic content area and a general tightening of the context and stakeholder sections.

What I would do differently this time

Granted, my first reaction to the FDIS was to file it under "noted." A more useful reaction would have been:

  • Pull the current 9001 quality manual and do a clause-by-clause gap against the new revision before anyone else on the team touches it. The context and stakeholder sections are where your bespoke text lives; that is where the new content lands.
  • Decide how you are going to address climate in your QMS — paragraph in the context document, reference to your ESG reporting, or a real operational control? The standard gives latitude. Auditors will not.
  • Do not assume 13485 automatically satisfies the new 9001 expectations. The overlap is large but not complete, and the new themes sit mostly outside 13485's scope.
  • Watch your transition timeline. Most notified bodies will want your 9001 transition plan bundled into your next 13485 surveillance.

The honest answer

For a medical device company running ISO 13485 well, the 2026 ISO 9001 revision is mostly paperwork. It is paperwork with one genuinely new content area (climate and sustainability), a tightening of the context analysis, and a more flexible stance on documentation that most of us were already taking.

It is not the upheaval some of the FDIS commentary suggested. But it is not a no-op either, and the audit prep spreadsheet will probably grow from two rows for ISO 9001 to three.

For those of you holding both — how are you treating the climate and sustainability content? Reference to existing ESG reporting, or genuinely new content inside the QMS itself?

Top comments (0)