Integrated Management Systems
ISO 9001 + ISO 13485,
built as one system.
If you know ISO 9001, you already know most of ISO 13485. The medical device standard was built on the ISO 9001:2008 bones — the DNA is shared. MSI builds one system on the ISO 9001 outline and inserts what 13485 requires: regulatory roles, device risk, design controls, and traceability. One document set. One audit program. One management review.
Or call 888-914-9141
The Foundation
ISO 13485 is ISO 9001 with a regulatory spine
Define. Design. Deliver.
ISO 13485:2016 was built on the structure and content of ISO 9001:2008. It is not a foreign management system — it is a close relative of the one you already know, hardened for an industry where a defect can injure a patient.
That single fact is the most useful thing an organization entering medical devices can understand. You are not learning a new discipline from scratch. Process approach, document control, competence, internal audit, corrective action, management review — all of it carries over. The QMS content overlaps enormously.
What ISO 13485 adds is a regulatory spine: your role under device regulation, risk management aimed at patient safety rather than business performance, design controls with a documented file per device, traceability that can follow an implant to a patient, and an obligation to report to regulatory authorities when something goes wrong. Those are the inserts. Everything underneath them is the ISO 9001 system you already run.
ISO 9001 · Quality
The outline
The process approach, context, leadership, competence, internal audit, and management review. MSI builds every integrated system on this structure — and ISO 9001:2015 does not require you to follow its clause order, which is exactly what makes it a workable outline for a standard organized differently.
ISO 13485 · Medical Devices
The inserts
Regulatory roles, ISO 14971 risk management, design and development files, sterile and contamination controls, traceability, complaint handling, and regulatory reporting. Written into the sections of the outline that already govern that work.
The Method
ISO 9001 is the outline. ISO 13485 gets inserted.
Outline. Insert. Integrate.
This is the technical approach behind every integrated system MSI builds — and it is the decision that separates a genuinely integrated system from two binders sharing a shelf.
You write one documented system using the ISO 9001 structure as the outline. Then, section by section, you insert what ISO 13485 requires that ISO 9001 does not. Many sections need no insert at all — the requirement is already met by what the quality system does. Where an insert is needed, it goes into the section that already governs that activity. The device and regulatory content lives inside the process, not beside it.
The most expensive mistake in medical device quality is treating ISO 13485 as a separate system bolted onto the QMS. It is not a separate system. It is your quality system, with the regulatory requirements written into the sections where the work actually happens.
Where the ISO 13485 inserts go
| Section of the ISO 9001 outline | What it already does | ISO 13485 insert |
|---|---|---|
| 4 · Context | Organization, issues, interested parties, scope, and the QMS processes | Document the regulatory role(s) you undertake — manufacturer, importer, distributor, authorized representative. Identify applicable regulatory requirements. Add the Quality Manual and a Medical Device File per device type or family. Validate any software used in the QMS. |
| 5 · Leadership | Policy, roles, responsibilities, authorities, and customer focus | Appoint a named Management Representative. Customer focus extends to meeting applicable regulatory requirements, not just customer requirements. |
| 6 · Planning | Risks and opportunities; quality objectives and the plans to reach them | Risk management to ISO 14971, across the entire product realization lifecycle. This is patient-safety risk — a heavier, more formal discipline than 9001's business risk, and the single biggest conceptual insert on this list. |
| 7 · Support | Resources, competence, awareness, communication, documented information | Work environment and contamination control — cleanliness of product, and the health, cleanliness, and clothing of personnel where these affect the device. Record retention tied to device lifetime and regulatory retention periods. |
| 8 · Operation | Operational planning and control, design and development, external providers, production, release, nonconforming output | The heaviest section by far. Design and development file per device; design transfer. Validation of production processes, including software. Sterile device and sterilization validation requirements. Identification and traceability, including implantable device records. Installation and servicing activities. Supplier controls proportionate to device risk. |
| 9 · Performance evaluation | Monitoring, measurement, internal audit, management review | Feedback from production and post-production, feeding back into risk management. Complaint handling. Reporting to regulatory authorities — adverse events and vigilance. Management review inputs and outputs are prescriptively listed. |
| 10 · Improvement | Nonconformity, corrective action, continual improvement | Preventive action — which ISO 9001:2015 removed and 13485 kept. Advisory notices and recall. Rework controls. Corrective and preventive actions must be verified not to adversely affect the device. |
Read Clause 8 twice. Design and development is where most medical device projects are won or lost — and whether design controls even apply to your scope is one of the most misjudged decisions in the whole certification. Companies exclude design to simplify scope and fail the audit; others include it needlessly and drown in documentation. MSI assesses design applicability at the start of every engagement, and there's a full breakdown in our guide to what ISO certification actually costs.
The Thing Nobody Warns You About
13485 kept what ISO 9001:2015 threw away
Know it. Plan it. Avoid it.
Here is the wrinkle that catches almost every ISO 9001-certified company moving into medical devices — and it follows directly from the fact that 13485 descends from ISO 9001:2008.
When ISO 9001 moved to the 2015 revision, it deliberately retired several requirements. Many organizations celebrated, deleted the associated documents, and moved on. But ISO 13485:2016 branched off the earlier version and kept every one of them. Which means a 9001:2015-certified company doesn't just add device content — it has to reinstate things it was told it no longer needed.
What you have to put back
Four requirements ISO 9001:2015 removed that ISO 13485 still demands:
- The Quality Manual. ISO 9001:2015 dropped the requirement. ISO 13485 still requires a documented quality manual, including the scope, the procedures, and a description of the interaction between processes.
- The Management Representative. ISO 9001:2015 removed the named role in favor of distributed leadership responsibility. ISO 13485 still requires a specific member of management to be appointed, with defined responsibility and authority.
- Preventive action. ISO 9001:2015 folded preventive action into risk-based thinking and removed the clause. ISO 13485 retains it as a distinct requirement with its own documented procedure.
- Documented procedures. ISO 9001:2015 relaxed to the flexible language of "documented information." ISO 13485 explicitly mandates documented procedures for a defined set of activities — you don't get to decide.
None of this is difficult. It is only expensive when it's discovered late — typically during a gap assessment three months before an audit, when a team that spent 2016 deleting the quality manual now has to rebuild it. Knowing it on day one costs nothing.
It also cuts the other way, and this is the part worth saying out loud: ISO 13485 does not require continual improvement, customer satisfaction measurement, or the context and interested-parties analysis that ISO 9001:2015 does. So a device company certified only to 13485 is missing genuine business machinery. That is precisely why building on the 9001 outline is the right call — you get the regulatory rigor and the improvement engine, rather than choosing between them.
Where You're Starting
Three ways in — all end in one system
Assess. Align. Advance.
ISO 9001 certified, entering medtech
The most common path, and the strongest position to start from. You already own the outline. Extending into 13485 means writing the regulatory inserts into sections that already exist — plus reinstating the quality manual, management representative, and preventive action.
Medtech, starting from nothing
A clean slate is an advantage. You write the ISO 9001 outline once, knowing from day one where every device and regulatory insert lands — and you never pay to untangle a system that was designed for one standard and later asked to carry two.
13485 certified, now needing 9001
Usually driven by a non-device customer or a diversifying product line. The good news: you already exceed most of 9001's operational bar. What you're adding is the business machinery 13485 never asked for — context, interested parties, customer satisfaction, and continual improvement.
Not sure what shape your system is in? Start with a free ISO gap analysis tool — self-scoring workbooks for ISO 9001 and ISO 13485 that show you where you actually stand before you commit to anything.
The Roadmap
How MSI builds it
Plan. Build. Verify. Certify.
Each phase depends on the one before it. Writing procedures before the design-applicability decision is made — or auditing before the system is real — is the most common cause of wasted effort in a medical device build.
Leadership, scope & regulatory role
Define the scope, name the system owner, and establish which regulatory role you actually undertake — manufacturer, importer, distributor, authorized representative. That determination drives which 13485 requirements apply to you at all, and getting it wrong reshapes the entire project.
Design applicability assessment
Does design and development apply to your scope? This is the highest-leverage decision in the build and the one most often misjudged in both directions. MSI settles it at the start, not as a mid-project surprise.
Planning — including ISO 14971 risk management
Analyze context and interested parties once. Establish device risk management across the product realization lifecycle in the same planning activity that handles business risk and objectives. Patient-safety risk is planning work — it is not a side project owned by one engineer.
Documentation — outline first, then inserts
Map the processes once and build the ISO 9001 document outline. Then insert the 13485 requirements section by section — quality manual, medical device file, design controls, traceability, complaint handling — into the procedures that already govern that work. MSI writes the actual procedures with you.
Implementation, validation & training
Deploy the system, validate the processes that require it, and train the workforce to the competence requirements. Let it run long enough to generate real records. Evidence is built as the work happens — not reconstructed the week before an audit.
Integrated audit, review & certification
One audit program evaluates each process against both standards in a single pass. Results feed one management review, the loop closes, and you enter certification with a coherent, traceable system. MSI attends the audit with you — we've been present at more than 200 of them.
Certification is not regulatory approval. An ISO 13485 certificate demonstrates a conforming quality system. It is not the same thing as market authorization — FDA, EU MDR, and other regimes have their own pathways, and 13485 supports them without replacing them. MSI builds and maintains the system; an accredited independent registrar audits it and issues the certificate. Keeping those roles distinct is what protects the integrity of your certification.
Build the Competence
The integrated 9001 + 13485 training track
Build. Train. Transform.
Both standards require demonstrable competence, and an auditor will ask for the evidence. Unlike most pairings, MSI has purpose-built integrated 9001 + 13485 courses — your team learns the combined system as one discipline, not two subjects they have to reconcile themselves.
Built for the integrated system
ISO 9001 + 13485 · Integrated
Executive ISO Launch Quality & MedDevice ProgramThe implementation roadmap for leadership teams building quality and medical device management together — resource planning, buy-in, and the milestone plan for a combined launch.
ISO 9001 + 13485 · Integrated
ISO 9001 & 13485 2-Day Internal Auditor TrainingAudit planning, checksheet development, interviewing strategies, opening and closing meetings, report writing, and the audit program — taught across both standards at once, so one auditor covers both in a single pass. Certificate of completion.
ISO 9001 + 13485 · Integrated
Inspired Leadership iaw ISO 9001 and 13485 WorkshopThe leadership clause of both standards, made practical — for the managers whose commitment the system actually depends on.
ISO 9001 + 13485 · Integrated
Customer Focus ISO 9001 and 13485 WorkshopWhere the two standards diverge most sharply — 9001 wants customer satisfaction, 13485 wants feedback, complaint handling, and regulatory reporting. This workshop covers both obligations together.
Standard by standard
ISO 9001
ISO 9001 OverviewCore QMS principles, objectives and KPIs, and the steps to certification. Then QMS 9001 Launch Mastery and ISO 9001 2-Day Internal Auditing.
ISO 13485
ISO 13485 OverviewThe medical device QMS from documentation to performance metrics. Then ISO 13485 Launch Mastery and ISO 13485 2-Day Internal Auditor Training.
The two that matter most for devices
Design Controls
Design and Development Training Video SeriesClause 8 is where medical device certifications are won or lost. If design applies to your scope — and for most device companies it does — this is not optional knowledge.
Corrective Action
Catch. Correct. Continually Improve.Both standards run on the same corrective-action engine — and 13485 adds preventive action back on top of it. This is the course that builds both.
New to auditing entirely? The ISO Internal Auditor Online Workshop is the short starting point before the 2-day intensive.
Corporate Training License
Training a whole organization?
LearningPaths™ — MSI's Corporate Training License — gives your team seat-based access to the full course library, organized into role-based PDCA learning paths. The 9001 + 13485 path can be assigned as a single integrated track rather than two separate standards.
And Everything After
A device system has to be maintained — or it decays
Maintain. Optimize. Excel.
The certificate is a milestone, not a finish line. Surveillance audits arrive on a schedule, standards revise, people leave — and in a regulated industry, a quality system that nobody tends doesn't just drift. It becomes a liability, because the records you failed to keep are the records a regulator will ask for.
SureResults® is MSI's maintenance program for certified organizations: internal audit support, management review facilitation, surveillance-audit preparation, and continuous improvement, year-round. 85% of MSI-implemented systems continue with SureResults — the clients who build with us generally keep us.
Measurable Authority
Why MSI for a medical device build
Proven. Present. Practical.
We settle design applicability first
The single most misjudged decision in medical device certification — excluded when it applies, or included when it doesn't. MSI assesses it at the start of every engagement, not as a mid-project surprise.
We write the actual procedures
Most consultants hand over templates. In a regulated industry, a template that doesn't match how you actually build a device is worse than no template. MSI drafts the real documentation with your team.
We're in the audit room
MSI has attended 200+ certification, surveillance, and recertification audits. We've watched what registrars actually probe in a device system — and we build toward that evidence standard from day one.
MSI is a veteran-owned, female-owned ISO consulting firm founded in 1998. We consult on ISO 9001, ISO 13485, ISO 14001, ISO 45001, ISO 7101, and integrated combinations of them. If you're still weighing whether to pursue certification at all, the free ISO Executive Decision Briefs walk leadership through that decision before a single procedure is written.
Questions Answered
Integrated ISO 9001 + 13485 FAQ
Is ISO 13485 really just ISO 9001 for medical devices?
Close, but not quite. ISO 13485:2016 was built on ISO 9001:2008 — so the structure and most of the QMS content are shared with the quality standard you know. What it adds is a regulatory spine: your role under device regulation, ISO 14971 risk management, design controls, traceability, complaint handling, and regulatory reporting. The system underneath is familiar. The obligations layered on top are not.
We're ISO 9001:2015 certified. What do we have to add?
The device and regulatory inserts — and, surprisingly, several things you were told you could delete in 2015. Because 13485 branched off the 2008 edition, it kept the quality manual, the management representative, preventive action, and mandatory documented procedures, all of which ISO 9001:2015 dropped. Most companies discover this late. Knowing it on day one costs nothing.
How do you actually combine two standards into one system?
ISO 9001 becomes the outline. You write one documented system on the ISO 9001 structure and insert what ISO 13485 requires into the section where it belongs — regulatory roles into context, ISO 14971 risk into planning, design controls and traceability into operation, complaint handling and regulatory reporting into performance evaluation. ISO 9001:2015 explicitly does not require you to follow its clause order, which is what makes this work.
Does design and development apply to us?
It's the most consequential scoping question in the whole project, and it's misjudged in both directions. If you design products, develop new formulations, create custom solutions, or modify existing products to customer specification, design controls almost certainly apply. Excluding design to simplify scope can produce a failed audit, a certificate that doesn't cover what you actually do, or real regulatory exposure. MSI assesses this at the start of every engagement.
Can we certify both standards in one audit?
Yes. Certification bodies routinely run combined audits for organizations holding multiple management-system certifications, and an integrated system is what makes that possible — the auditor evaluates each process against both standards in a single pass, which reduces total audit days compared with running two separate programs.
Does ISO 13485 certification mean we can sell our device?
No. An ISO 13485 certificate demonstrates a conforming quality management system — it is not market authorization. FDA, EU MDR, and other regulatory regimes have their own pathways, and 13485 supports them without replacing them. Any consultant who blurs that line is one to be careful with.
We're 13485 certified. Is there any point adding ISO 9001?
Often, yes — and usually for reasons that have nothing to do with devices. ISO 13485 does not require continual improvement, customer satisfaction measurement, or the context and interested-parties analysis that ISO 9001 does. A 13485-only company is missing genuine business machinery, and non-device customers frequently ask for the 9001 certificate specifically. You're already past most of the operational bar.
Does MSI issue the certificate?
No — and no consultant does. Certification is granted by an accredited independent registrar. MSI builds the system that earns it and stands alongside you at the audit. Keeping those two roles separate is what protects the integrity of your certification.
Go Deeper
Related guides
- The ISO 13485 Standard — the requirements, in full.
- What ISO Certification Actually Costs — including why design applicability is the biggest cost driver nobody talks about.
- ISO Consulting: The Decoder Ring for 5 Standards — how the standards fit together, and where 13485 breaks the pattern.
- Integrated Management System Implementation Done Right — the clean-slate case, phase by phase.
- ISO 9001 + ISO 14001 Integrated System — the other most common pairing, and why it behaves differently.
Ready to Build
One system. One truth. One team.
The first step in a medical device build is a leadership decision, not a document. A planning session settles your regulatory role, whether design controls apply, and where the inserts go — before anyone writes a procedure.
Schedule Your Planning Session →
Or call 888-914-9141 · Send us a message