Skip to main content

ISO Standards 8 min read

ISO 9001 vs ISO 13485: Which Standard Does Your Company Actually Need?

Summayah (Maya) Summayah (Maya) Lead Regulatory & Quality Consultant, CerturaCo

Companies entering the medical device sector often already hold ISO 9001 and want to know how much of it transfers. Others are starting fresh and want to know whether to do 9001 first. Both questions have clear answers once you understand what actually separates the two standards.

The common ground

ISO 13485 was derived from ISO 9001 and retains much of its architecture. If you hold ISO 9001:2015, you already have working versions of a substantial amount of what ISO 13485 requires:

  • Management commitment and quality policy
  • Document and record control
  • Internal audit programme
  • Corrective action process
  • Management review cycle
  • Competence, training and awareness
  • Purchasing and supplier control
  • Control of nonconforming output

That is a real head start — typically the difference between a six-month project and a twelve-month one.

The differences that actually matter

1. Risk management is structural, not optional

ISO 9001 asks you to consider risks and opportunities at a business level. ISO 13485 requires risk management applied to the product across its entire lifecycle, in the manner set out in ISO 14971. That means a risk management file, hazard identification, risk estimation and evaluation, risk control measures with verification that they work, evaluation of residual risk, and a feedback loop from production and post-production information back into the analysis.

This is the single largest addition, and it cannot be retrofitted with a spreadsheet the week before the audit.

2. Design and development controls

If you design devices, ISO 13485 requires controlled design planning, defined inputs and outputs, review, verification, validation, transfer to production, change control, and a maintained design file. ISO 9001's design clause is considerably lighter and is frequently excluded altogether by organisations that do not design.

3. Regulatory requirements run through everything

ISO 13485 repeatedly ties obligations to "applicable regulatory requirements". The QMS must demonstrably account for the regulations of the markets you serve — in Malaysia, the Medical Device Act 2012 and MDA guidance. ISO 9001 has no equivalent thread.

4. Post-market surveillance and vigilance

ISO 13485 requires defined processes for complaint handling, deciding whether an event is reportable, reporting to authorities within required timeframes, and executing advisory notices or recalls. ISO 9001 addresses customer feedback and satisfaction, which is a much lighter obligation.

5. Traceability and record retention

ISO 13485 imposes specific traceability requirements — heightened for implantable devices — and requires records to be retained for defined periods tied to device lifetime. ISO 9001 leaves retention to your discretion.

6. Improvement versus effectiveness

This difference is philosophical but auditors probe it. ISO 9001 emphasises continual improvement of the management system. ISO 13485 emphasises maintaining the effectiveness of the system and meeting regulatory requirements. The reasoning is deliberate: in a regulated safety context, uncontrolled change is itself a risk. Consistency and validated change are valued over constant iteration.

So which do you need?

Your situationRecommendation
You manufacture medical devicesISO 13485. Go directly — doing ISO 9001 first is usually a detour.
You import or distribute devices in MalaysiaGDPMD is generally the applicable system. ISO 9001 is optional and commercially useful.
You supply components to device manufacturersISO 9001, unless a customer specifically requires ISO 13485 in your quality agreement.
You are a broader business with a device divisionBoth, integrated as one system with 13485 requirements layered where they apply.
You plan to enter devices laterISO 9001 now, structured deliberately so the 13485 upgrade is an extension rather than a rebuild.

Running both as one system

Where both apply, do not build two systems. Parallel systems duplicate document control, internal audit and management review, double your maintenance burden and — in our experience — drift apart within eighteen months, at which point one of them is quietly abandoned.

An integrated system has one document hierarchy, one internal audit programme covering both standards, one management review addressing both, and a single set of processes with the ISO 13485 requirements applied where relevant. Certification bodies audit integrated systems routinely and it usually reduces total audit time.

If you are transitioning from 9001 to 13485

  1. Gap analysis first. Establish precisely what carries across and what must be built. Most organisations find they are further along than they feared.
  2. Build the risk management system early. It is the longest lead item and everything else references it.
  3. Rework document control for retention rules before you generate records under the new system.
  4. Add the regulatory thread — map which processes carry which regulatory obligations.
  5. Run the system long enough to generate evidence. Certification bodies want a system in operation, not a system on paper. Budget several months of live running before the certification audit.

If you are weighing which route fits your business, our ISO 13485 and ISO 9001 service pages set out what each engagement covers — or ask Maya directly and we will tell you plainly which one your situation calls for.

Frequently asked

01

Is ISO 13485 harder to achieve than ISO 9001?

It is more prescriptive rather than harder in the abstract. ISO 13485 tells you more specifically what must exist — risk management files, design controls, defined retention periods, vigilance processes — which removes some interpretive freedom but also removes guesswork. Organisations with disciplined operations often find the prescriptiveness helpful.

02

Can we hold ISO 13485 without ISO 9001?

Yes. ISO 13485 is a standalone standard and certification to it does not require or imply ISO 9001 certification. Many certified medical device manufacturers hold only ISO 13485.

03

Does ISO 13485 certification satisfy Malaysian regulatory requirements on its own?

No. ISO 13485 certification is an important element of demonstrating conformity, but it does not by itself constitute registration or licensing. You still need the applicable Establishment Licence and device registrations from the Medical Device Authority. Certification supports those applications rather than replacing them.

Disclaimer: This article is general information, not regulatory or legal advice. Requirements, fees and validity periods are set by the Medical Device Authority and may change. Verify current requirements against applicable MDA guidance documents, or engage us for a formal assessment of your specific case.

Continue reading