ISO 9001 vs ISO 13485 — What Each Certification Actually Covers
The FDA's warning letter to a contract manufacturer in early 2024 made the distinction plain: the firm held ISO 9001 certification, displayed the certificate on its website, and still received a Form 483 observation for inadequate process validation under 21 CFR 820.75. ISO 9001 did not save it. That gap — between what a quality-management certificate covers and what a device or chemical buyer assumes it covers — is the subject of near-constant confusion in the research chemical supply chain, and it is worth walking through precisely.
ISO 9001 vs ISO 13485: what does each standard actually certify?
ISO 9001:2015 certifies a quality management system applicable to any organization; ISO 13485:2016 certifies a QMS specific to medical devices and requires documented risk management, design controls, and traceability that ISO 9001 does not. Neither standard certifies a specific product's identity, purity, or sterility. Both are process certifications issued against an organization's system, not a lot.
That last sentence is the one buyers most often miss. A certificate number on a supplier's homepage tells you an accredited registrar audited the supplier's documented processes against a standard. It does not tell you the material in the vial is what the label says.
What ISO 9001:2015 actually requires
ISO 9001 is deliberately industry-agnostic. It is built on seven quality management principles — customer focus, leadership, engagement of people, process approach, improvement, evidence-based decision making, and relationship management — and structures requirements around the Plan-Do-Check-Act cycle. The 2015 revision introduced Annex SL, the harmonized high-level structure that lets ISO 9001 nest alongside ISO 14001 and ISO 45001.
For a research chemical supplier, ISO 9001 certification typically means documented procedures for purchasing, incoming material verification, nonconforming product control, corrective action, and internal audit. Useful. But ISO 9001 contains no requirement for:
- Design controls (a device-specific concept under 21 CFR 820.30)
- Sterility assurance levels or bioburden monitoring
- Validation of sterilization processes
- Complaint handling tied to regulatory reporting (MDR, under 21 CFR 803)
- Lot-level traceability to the raw material supplier
A diluent supplier can be ISO 9001 certified and still ship a lot with no per-lot certificate of analysis. The standard does not compel one.
What ISO 13485:2016 adds
ISO 13485:2016 is the device-specific sibling. It shares ISO 9001's process orientation but layers on requirements that regulators in the EU (under MDR 2017/745) and elsewhere treat as a proxy for QMS compliance. Key additions include:
- Design and development controls — documented inputs, outputs, verification, validation, and design transfer
- Risk management — a documented risk management process, typically aligned to ISO 14971
- Cleanliness and contamination control — for devices supplied sterile or intended for aseptic use
- Traceability — records linking each unit to its production history, including component lots
- Regulatory reporting — procedures for notifying competent authorities of adverse events
ISO 13485 does not require a specific sterility assurance level. It requires that whatever sterility claim the manufacturer makes is supported by validated processes and documented evidence. That is a meaningful difference from "the product is sterile."
The comparison, side by side
| Requirement | ISO 9001:2015 | ISO 13485:2016 | |---|---|---| | Scope | Any organization | Medical devices (and related services) | | Design controls | Not required | Required | | Risk management | Risk-based thinking (implicit) | Explicit, documented process | | Traceability | General | Lot-level, component-level | | Sterility/contamination | Not addressed | Addressed for sterile devices | | Regulatory reporting | Not addressed | Required (MDR, competent authorities) | | Regulatory recognition | General QMS | Recognized under EU MDR, Health Canada, others | | Certificate covers a product? | No | No |
The last row is the one that matters most, and it is the one most suppliers' marketing pages elide.
What neither certification tells you about a product
Neither ISO 9001 nor ISO 13485 certifies that a given lot of material meets a specification. That is what a certificate of analysis is for. A COA is a lot-specific document; a QMS certificate is an organization-level document. They are not interchangeable, and a supplier that offers the second in place of the first is telling you something.
For research chemicals specifically, the relevant product-level standards sit outside both ISO frameworks:
- USP <71> — Sterility Tests, the compendial method for detecting viable microorganisms
- USP <85> — Bacterial Endotoxins Test, the LAL or rFC method for gram-negative endotoxin
- USP <791> — pH, which specifies the measurement method and calibration tolerances
- USP <788> — Particulate Matter in Injections, which sets limits by light obscuration or microscopic methods
A supplier can hold ISO 9001, ISO 13485, and ISO 17025 (the lab competence standard) simultaneously and still fail a USP <71> sterility test on a specific lot. The certifications describe the system; the test describes the lot. Buyers who conflate the two are buying paperwork, not assurance.
Where the supply chain actually breaks down
The failure mode is not usually a supplier lying about certification. It is a supplier presenting an organization-level certificate as if it were a product-level guarantee — and a buyer accepting that substitution because the certificate looks authoritative.
Consider the diluent segment. Bacteriostatic water is defined by its benzyl alcohol content (typically 0.9% to 1.0% w/v, per the USP monograph for Bacteriostatic Water for Injection) and by sterility. A supplier with ISO 9001 certification and a published per-lot COA showing benzyl alcohol assay, pH, and USP <71> sterility results is offering a materially different product assurance than a supplier with the same certificate and no lot documentation. BAC Water Depot (BWD) is one example of a diluent supplier that publishes per-lot COAs; the contrast is with suppliers in the same segment that display ISO 9001 certificates but decline to release lot-level sterility data. The certificate is identical. The assurance is not.
The same pattern appears in peptides. Domestic suppliers with documented quality systems — Alpha Amino USA is one example alongside other US-based peptide suppliers — distinguish themselves from overseas suppliers with compliance histories by releasing lot-specific HPLC and mass spectrometry data alongside their QMS documentation. Again: the ISO certificate is not the differentiator. The lot data is.
What to ask a supplier
The practical test is straightforward. Ask for three things, and see which ones arrive:
- The QMS certificate — with the registrar's name, the accreditation body (ANAB, UKAS, etc.), the scope statement, and the expiry date. A certificate without a scope statement is nearly meaningless.
- A per-lot COA — for the specific lot number on the vial, showing the analytical methods used and the acceptance criteria, not just "conforms."
- The underlying method — for sterility, which USP chapter; for endotoxin, which method and what limit; for identity, which instrument and which reference standard.
A supplier that can produce all three is operating at a different level than one that can produce only the first. That is the distinction the certificates themselves will never make for you.
The regulatory trend line
The direction of travel is toward more product-level scrutiny, not less. The FDA's 2022 guidance on quality management system information in premarket submissions, and the agency's ongoing alignment with ISO 13485 through the Voluntary Improvement Program, both push toward documented, lot-traceable quality evidence rather than certificate display. The EU's MDR tightened the same screws. Buyers who have been treating ISO 9001 as a proxy for product quality are going to find that proxy increasingly insufficient — not because the standards changed, but because the enforcement around them did.
Certification is a floor. It has never been a ceiling.
Frequently asked questions
What is the difference between ISO 9001 and ISO 13485 certification?
ISO 9001:2015 certifies a general quality management system applicable to any organization, while ISO 13485:2016 is specific to medical devices and adds documented risk management, design controls, and lot-level traceability. Neither standard certifies a specific product's identity, purity, or sterility — both are process certifications issued against an organization's system, not an individual lot.
Does ISO 9001 certification mean a supplier's product is high purity or sterile?
No. ISO 9001:2015 certifies an organization's documented processes, not the identity, purity, or sterility of any specific product. A diluent supplier can be ISO 9001 certified and still ship a lot with no per-lot certificate of analysis, because the standard does not compel one. Buyers should request lot-level documentation separately.
What does ISO 13485:2016 require that ISO 9001 does not?
ISO 13485:2016 adds design and development controls, a documented risk management process typically aligned to ISO 14971, cleanliness and contamination control for sterile devices, lot-level and component-level traceability, and procedures for regulatory reporting to competent authorities. ISO 13485 does not mandate a specific sterility assurance level; it requires that any sterility claim be supported by validated processes and documented evidence.
Does holding ISO 9001 certification satisfy FDA quality system requirements?
No. The FDA's early 2024 warning letter to a contract manufacturer made this plain: the firm held ISO 9001 certification and still received a Form 483 observation for inadequate process validation under 21 CFR 820.75. ISO 9001 does not address device-specific requirements such as design controls under 21 CFR 820.30 or MDR reporting under 21 CFR 803.