Is ANSI Webstore Legit? A Buyer’s Guide (2026)

Before paying $150–$400 for a standard, buyers want to know if ANSI Webstore is legitimate. This guide covers who runs it, how it compares to resellers and free PDFs, and — the part most buyers miss — how to confirm you’re buying the correct edition.

What to know before you enter your card number for an ISO, ASTM, or ANSI standard

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


You Searched “Is ANSI Webstore Legit” for a Reason

You’re not being paranoid. You found a webpage that wants $150–$400 for a PDF, the checkout page looks a little dated, and you’ve probably seen at least one sketchy standards-reseller site pop up in the same search results. Before you hand over a company card for a document your auditor is going to check line by line, you want to know exactly who you’re paying.

Here’s the short answer: ANSI Webstore is legit — it’s the official online store operated by the American National Standards Institute, the U.S. nonprofit that has coordinated the voluntary standards and conformity assessment system for more than a century.

Is ANSI Webstore Legit? Yes. The ANSI Webstore is ANSI’s official online standards ordering platform, selling standards from more than 150 publishers with individual purchases, discounted packages, and multi-user access options.

But here’s the distinction that actually matters: a legitimate source doesn’t automatically mean the correct edition for your application. ANSI sells historical and superseded editions right alongside current ones — so “legit” and “the exact document your certification requires” are two different questions, and this guide covers both.

From the Floor: I’ve seen an operations team walk into a surveillance audit with a printed copy of a standard that was two editions behind — pulled from a PDF a supplier had forwarded around years earlier. The auditor caught it in the first ten minutes, and the finding wasn’t about the process. It was about the document. That’s the actual risk with standards purchases: not getting scammed out of your money, but building your QMS around the wrong edition — a risk that exists even when you buy from the right source.

Before you buy anything, make sure you know exactly which clauses and documentation your certification actually requires — not just which standard number to search for.

👉 Get the free ISO 9001 Roadmap — a step-by-step breakdown of what your QMS needs before you spend a dollar on documents or consultants.

In This Guide:

  • What the ANSI Webstore actually is, and who’s behind it
  • Official store vs. resellers vs. “free” PDFs — what changes at each level
  • Payment, delivery, and what you get for your money
  • Why “legitimate source” and “correct edition” aren’t the same thing
  • A pre-purchase checklist so you buy the right edition the first time


👉 Start Here (Top Resources)

If you’re ready to buy, these are the fastest paths:


What Is the ANSI Webstore, Actually?

The ANSI Webstore (webstore.ansi.org) is the official electronic ordering platform run by the American National Standards Institute, a private nonprofit founded in 1918. ANSI doesn’t write most of the standards it sells — it accredits the procedures of the organizations that do, and it’s the official U.S. representative to the International Organization for Standardization.

That’s an important distinction, not just a technicality. When you purchase ISO 9001, ISO 14001, or a SAE aerospace standard through the webstore, you’re buying an authorized, officially published edition sold with the standards developer’s authorization — not a scanned copy, not a summary, and not a document of unknown origin. What it doesn’t automatically tell you is whether the specific edition you selected is the one currently required by your certification, contract, or customer — more on that below.

The platform itself covers a lot of ground: standards from more than 150 publishers, delivered mostly as PDF, with a handful still available in print. If you’re comparing document costs before you commit, Why Are ISO Standards So Expensive? breaks down where that price actually goes.


Is ANSI Webstore Legit, or Is There a Catch?

ANSI Webstore legit comparison showing official standards source, third-party reseller, and unverified free PDF copy
ANSI Webstore legit? Compare an official standards source with third-party resellers and unverified free PDF copies before buying.

There’s no catch — but there is a pattern worth understanding. “Legit” gets confused with “cheap” a lot in this space, and the two aren’t related.

The stronger evidence is simpler than any third-party rating tool: webstore.ansi.org is operated by ANSI itself. ANSI identifies the Webstore as its own electronic standards ordering and delivery system, listing standards from more than 150 publishers. That doesn’t mean every document on the Webstore is automatically the right document for your application — it means you’re dealing with the official ANSI storefront rather than an anonymous third-party reseller.

Where things get murkier is one step removed from ANSI itself:

  • Reseller sites that mark up standards and sometimes sell outdated editions without disclosing it
  • “Free download” sites that host pirated copies, often years out of date, with no guarantee the text matches what your registrar will audit against
  • Marketplace listings on general e-commerce platforms, where you genuinely cannot verify which edition you’re getting until it arrives

None of those are “ANSI Webstore” problems. They’re what happens when buyers go looking for a shortcut around the official source. For a deeper look at what’s legal and what isn’t when it comes to standards distribution, see Legal Download ANSI Standards.

Official Source vs. Reseller vs. “Free” PDF

SourceEdition GuaranteeLegal StandingTypical Price
ANSI WebstoreAuthorized edition selected at checkout — confirm year/status yourselfFully licensedFull retail (packages/coupon reduce cost)
Third-party resellerNot guaranteed — often outdatedVaries; some unauthorized resaleUsually similar or higher
“Free” PDF / forwarded copyFrequently outdated or alteredCopyright infringement$0 — but audit risk

If you’re weighing digital against a printed copy once you’ve settled on the official source, Digital vs. Printed ISO Standards walks through that decision.


Is It Safe to Enter Your Payment Info?

The ANSI Webstore accepts major credit cards and deposit accounts, and ANSI’s own FAQ confirms that completed orders generate an email confirmation with order details. As with any online purchase, use the official webstore.ansi.org domain and verify the checkout page before entering payment information.

On invoicing: ANSI does not send invoices for Webstore orders. After checkout, you receive an email confirmation containing your order details — save that confirmation for your procurement records. If your accounting team needs a deposit account set up for repeat purchases, that’s a standard request the webstore supports for organizations that buy standards regularly.

If you’re under time pressure before an audit → don’t wait on a mailed print copy. Buy the digital PDF edition and confirm it’s the current one before your surveillance or certification audit date, not after.


What You Actually Get When You Buy

ANSI Webstore legit guide showing what to do after buying a standards PDF, including download, license verification, and record retention
ANSI Webstore legit buying guide showing the steps after checkout: save the confirmation, download the PDF, verify licensing, and retain procurement records.

Most purchases are delivered as a downloadable PDF, licensed for the number of users specified at checkout — usually single-user unless you buy a multi-user or site license. That licensing detail matters more than people expect: sharing a single-user PDF across a whole quality team generally isn’t permitted under the license, not just a courtesy the vendor overlooks.

One detail worth knowing before you buy: for individual standards, the download link is active for seven days after purchase. Download and save your copy promptly rather than planning to come back for it later — a link you let lapse means contacting customer service to reissue it.

For standards you’ll reference constantly — ISO 9001, your industry-specific standard, anything your team pulls up during internal audits — compare the package price against buying each one individually before you check out. ANSI offers discounted standards packages for many collections, and if you’re building out a management system that touches more than one standard, that comparison is worth ten minutes of your time.

👉 Not sure your team is even buying against current requirements? Grab the Manufacturing Compliance Checklist before you spend another dollar on documentation you might not need yet.


Common Objection: “Why Not Just Find It Free?”

This is the honest objection, so let’s address it directly. Standards are expensive, and it’s tempting to search around for a copy someone else already paid for.

The problem isn’t getting caught — it’s getting it wrong. Standards get revised. ISO 14001 moved from the 2015 edition to a 2026 edition. AS9100 has moved through multiple revisions. A “free” copy circulating online has no mechanism to tell you it’s stale, and your registrar’s auditor isn’t going to accept “I didn’t know there was a newer edition” as an answer during a nonconformance discussion.

Buying through the ANSI Webstore gives you an authorized source for the standard you select — but it doesn’t automatically hand you the edition your certification or contract requires. That’s why checking the standard number, edition year, and revision status before checkout still matters, even when you’re buying from the official source.

ANSI Webstore legit guide showing how to verify the correct ISO standard edition, year, status, and certification requirements
ANSI Webstore legit? Verify the standard number, edition year, status, and applicable certification or contract requirements before purchasing.

Buyer’s Checklist Before You Purchase

✅ Confirm you’re on webstore.ansi.org — not a similarly-named domain
✅ Search by the exact standard number and confirm the edition year before adding to cart
✅ Filter for “Most Recent” rather than “Historical” unless you specifically need a superseded edition
✅ Check whether a package covers multiple standards you need — compare package price to individual pricing
✅ Apply code CC2026 at checkout for 5% off (valid through December 31, 2026)
✅ Confirm single-user vs. multi-user licensing matches how many people need access
✅ Download your file within 7 days of purchase and save it to your records
✅ Save your email order confirmation for procurement or audit records

⚠️ If a price looks unusually low, verify the seller before buying — it’s likely a reseller or an outdated copy, not the official source


FAQ

Is the ANSI Webstore operated by ANSI?

Yes. The ANSI Webstore is ANSI’s official online standards ordering platform, rather than a licensed third-party reseller.

Is webstore.ansi.org safe to use?

It’s ANSI’s own official ordering platform, not a third-party site. The domain is operated directly by the American National Standards Institute.

Does ANSI Webstore sell outdated or superseded standards?

Yes — historical and withdrawn editions remain available alongside current ones, since some states and contracts still reference older versions. Always check whether a listing is marked “Most Recent” or “Historical” before buying, and confirm the edition your certification or contract actually requires.

Can I legally get ISO or ANSI standards for free?

Some standards referenced in public regulations are available for free reading (not download) through official reading-room programs. Outside of that narrow case, standards are copyrighted works, and free downloads circulating online are typically unauthorized copies of uncertain edition.

Why does the ANSI Webstore cost more than some other sites I’ve found?

Other sites are usually reselling at a markup or distributing outdated copies without disclosing it. The webstore price reflects an authorized, officially published edition — not a discount copy of unknown accuracy.

Does ANSI Webstore ship or sell internationally?

Yes. The webstore serves international buyers and lists standards from ISO, IEC, and other international bodies alongside U.S. standards, which is useful if your operation buys against both domestic and international requirements.

What file format will I receive, and how long do I have to download it?

Most purchases are delivered as a licensed PDF, downloadable immediately after checkout. The download link stays active for seven days, so download and save your copy promptly.

Is there a discount code for ANSI Webstore?

Yes — code CC2026 takes 5% off qualifying purchases through December 31, 2026.

I need the same standard for multiple team members. What do I buy?

Check the licensing option at checkout. Single-user licenses are for one person; if more than one person on your team needs direct access to the document, you’ll need a multi-user or site license rather than sharing a single-user PDF.


📥 Free Resources

  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system, so you know what you’re actually buying documents for.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.

Not Sure What to Do Next?

🔹 Still researching? Read Where to Buy ISO Standards for the full landscape of official sources before you commit to a purchase.

🔹 Ready to buy your standard? Head to the ANSI Webstore and search by standard number and edition year — apply code CC2026 at checkout for 5% off.

🔹 Buying more than one standard? Compare individual pricing against the ANSI Webstore package option before you check out — for related standards, packages are often the better value, but check the numbers for your specific documents.

Buying the right document, from the right source, in the right edition, is the least glamorous part of getting certified — and the part that quietly causes the most audit headaches when it’s skipped. The Standards Navigator exists to make that decision boring and correct, not expensive and uncertain.


Before You Go

Buying the wrong edition, or buying from the wrong source, doesn’t usually surface until an auditor is standing in front of you asking why your documented procedure doesn’t match current clause numbers. Manufacturers who get this right treat the standard itself as step one — not an afterthought after the QMS is already built. Manufacturers who get it wrong find out during a nonconformance write-up, when it’s expensive to fix.

The Standards Navigator covers where to legally and confidently source every standard your certification actually requires — not just ISO 9001, but the full range of clusters manufacturers deal with.

👉 Get updates on standards purchasing and document sourcing
👉 Be first to access new compliance checklists and gap assessment tools

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

ISO 14001:2026 Clauses Explained: A Complete Clause-by-Clause Breakdown

ISO 14001:2026 replaces the 2015 edition, but most of the standard is unchanged. This guide breaks down every clause — the five named environmental conditions in 4.1, the strengthened scope requirements in 4.3, the new Clause 6.3 on change management, the restructured audit and management-review requirements in Clause 9, and the 10.1/10.3 merge — so manufacturers know exactly what needs updating before their certification body’s April 30, 2029 transition deadline.

What Changed in Every Clause — And What Your EMS Actually Needs to Do About It

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Your EMS Isn’t Broken. But Several Clauses Just Changed Underneath It.

This ISO 14001:2026 clauses explained guide breaks down every clause so you know exactly what changed and what to leave alone.

If you’re certified to ISO 14001:2015, here’s the uncomfortable truth: your certificate has an expiration date now, and it’s not the one on the wall.

ISO 14001:2026 was published April 15, 2026. It cancels and replaces the 2015 edition. Every organization holding an ISO 14001:2015 certificate now has until April 30, 2029 — confirmed directly in UKAS’s published technical bulletin for accredited certification bodies — to move to the new edition or lose certified status entirely.

The good news: this is not a rebuild. The Plan-Do-Check-Act structure is untouched. The ten-clause Harmonized Structure you already know from ISO 9001 and ISO 45001 is still there. What changed is narrower and more specific than most transition guides make it sound — and that’s exactly why a clause-by-clause read matters more than a high-level summary. You need to know which clauses to touch and which ones to leave alone.

I’ve spent 25+ years in heavy industrial operations, and I hold ISO 9001 Internal Auditor certification and a Six Sigma Green Belt — which means I’ve been the one standing in front of an auditor when a clause got reinterpreted mid-cycle. When ISO 9001:2015 rolled out its own risk-based thinking language, I watched two “equivalent” fabrication shops get very different audit outcomes — one had mapped the new requirement into an existing procedure six months ahead, the other tried to bolt it on during the transition audit itself. The shops that treat a standard revision as a documentation exercise get surprised. The ones that treat it as a system update don’t.

EMS teams generally fall into one of two postures over the transition window: reactive gap-closing right before a transition audit, or a planned, clause-mapped update that folds into a normal surveillance cycle. Before your next audit window closes, run a structured gap check against the 2026 requirements

→ Get the Manufacturing Compliance Checklist — a practical reference for closing gaps before an auditor finds them for you.


In This Guide

  • What actually changed between ISO 14001:2015 and ISO 14001:2026, clause by clause
  • The one genuinely new clause (6.3) and why it exists
  • Which requirements are genuinely new, which are reorganized, and which are primarily clarified
  • How the 2024 Climate Change Amendment folds into the 2026 edition
  • Transition timeline and what your certification body will expect
  • Where to buy the standard and where to get training
  • A quick-reference audit checklist for your next internal audit


ISO 14001:2026 Clauses Explained: Quick Answer

ClauseWhat ChangedAction Needed
4.1Five named environmental conditions: climate change, biodiversity, pollution, resource availability, ecosystem healthUpdate context analysis
4.3Life-cycle perspective now required at the EMS scoping stageExtend scope justification upstream/downstream
6.1.4New sub-clause dedicated to risks and opportunitiesMake risks/opportunities traceable — register optional
6.3Entirely new clause — Planning of ChangesBuild or extend a change-management procedure
8.1“Externally provided processes, products and services” replaces “outsourced processes”Broaden supplier and flow-down controls
9.2.2Audit objectives now required for every internal auditAdd defined objectives to your audit programme
9.3Restructured into 9.3.1 / 9.3.2 / 9.3.3Update management review agenda and minutes template
10.1Merged with former 10.3 (Continual improvement)Update internal cross-references

👉 Start Here (Top Resources)


Why This Revision Happened

ISO doesn’t revise a management system standard every few years for the sake of it. ISO 14001:2015 has been in place over a decade, and in that time three things happened that the standard didn’t fully account for: climate reporting became a business expectation rather than a voluntary add-on, supply chain environmental accountability moved from “nice to have” to contractual requirement in many industries, and the 2024 Climate Change Amendment (Amendment 1) was issued as a stopgap that needed to be formally folded into the core text rather than living as a bolt-on.

ISO.org confirms the core structure of ISO 14001 remains the internationally recognized environmental management system framework it has always been — this revision sharpens the requirements, it doesn’t replace the model.

If you are already ISO 9001 or ISO 45001 certified → you’ll recognize most of what changed here immediately, because the 2026 revision closes gaps that made ISO 14001 feel slightly out of step with its Harmonized Structure siblings. Clause 6.3 is the clearest example — ISO 9001 has had it since 2015.


Clause 4: Context of the Organization

This is where the most-cited substantive change sits, spread across three sub-clauses.

Clause 4.1 (Understanding the organization and its context) now names five specific environmental conditions that organizations must explicitly consider: climate change, biodiversity, pollution levels, natural resource availability, and ecosystem health. Under the 2015 edition, these lived as Annex A examples rather than requirement text. The 2026 edition writes them into the “shall” statement itself — auditors will expect to see these named factors addressed in your context analysis, not filed under a generic catch-all.

Clause 4.2 (Understanding the needs and expectations of interested parties) carries the same tightening, with a new note clarifying the types of interested parties in language that aligns more closely with ISO 9001. If your organization already addressed the 2024 Climate Change Amendment, you’re largely ahead of this change — it’s been formally absorbed into the core text rather than treated as a standalone add-on.

Clause 4.3 (Determining the scope of the EMS) picks up a genuine substantive change of its own: the life-cycle perspective is now explicitly required at the scoping stage, not just when identifying environmental aspects later in Clause 6. In practice, this means your scope statement needs to reflect where you have control or influence across upstream and downstream activities — not just what happens inside your fence line. A manufacturing site that already controls emissions and waste on-site may still need to account for supplier and product-use impacts when justifying its scope boundary.

⚠️ A gap worth closing before an audit tests it: a documented statement that a factor (say, biodiversity) was considered and found not material is defensible. Silence on it is not. Auditors are trained to look for evidence of consideration, not necessarily a full formal assessment for every factor.

If you are updating your context analysis for the first time under 2026 → don’t treat this as a rewrite. Add the five named factors to your existing context documentation, extend your scope justification to address life-cycle control and influence under 4.3, and note your rationale where a factor doesn’t apply to your operation.


Clause 5: Leadership

No new sub-clauses were added to Clause 5, and the changes here are clarifications and strengthened emphasis rather than a wholesale redesign — but it isn’t purely a matter of tone, either. The policy note under 5.2 has been expanded to explicitly reference commitment to the preservation or conservation of natural resources, and the documented-information language shifts from “fulfil” to “meet” for compliance obligations. If your environmental policy is due for review during the transition window, this is a natural point to incorporate the expanded commitment language.

Beyond that wording update, certification bodies are signaling that auditors will expect more visible evidence of personal top-management engagement — not just a signed environmental policy and calendar attendance at the annual management review. Accountability, integration of environmental objectives into business planning, and alignment with strategic direction were always required; the 2026 revision keeps the pressure on without adding new formal sub-clause requirements.

A common finding going into transition audits: leadership commitment that exists on paper (signed policy, meeting minutes) but isn’t traceable to an actual business decision — a capital allocation, a supplier contract clause, a product design change. That traceability is what auditors are being trained to probe for.


Clause 6: Planning

Clause 6 sees the most structural change of any section in the revised standard, split across three areas.

6.1 Actions to Address Risks and Opportunities

The core planning clause — environmental aspects, compliance obligations, risk-based thinking — isn’t redesigned, but it’s restructured for clarity. Most of the general content that lived in 2015’s Clause 6.1.1 has been moved into a new dedicated sub-clause, and the former “planning actions” content is renumbered to 6.1.5.

New Clause 6.1.4 (Risks and opportunities) gives risks and opportunities their own dedicated sub-clause for the first time. It requires the organization to determine which risks and opportunities — arising from its 4.1 context, 4.2 interested-party needs, and 4.3 scope — need to be addressed, and to make that determination available as documented information. Important nuance: the standard does not prescribe a specific document format called a “risks-and-opportunities register.” If your current system scatters this information across aspect registers, compliance logs, and planning documents, 6.1.4 is a good opportunity to make the connection more explicit and traceable — but a register isn’t a mandatory artifact, just a common and defensible way to demonstrate it.

6.1.2 (Environmental aspects) strengthens the life-cycle perspective that already existed in 2015, with a new note clarifying that environmental risk planning — including identification, assessment, and emergency-situation determination — must consider the life-cycle perspective. This is the clause connecting most directly to Clause 8.1 below — if your supplier flow-down documentation is thin, both clauses will surface it.

6.3 Planning of Changes — The One Genuinely New Clause

ISO 14001:2026 clauses explained with a practical Clause 6.3 planning of changes workflow for an environmental management system
ISO 14001:2026 clauses explained through a practical Clause 6.3 workflow for identifying, planning, implementing, and verifying EMS changes.

This is the headline change in the entire revision. Clause 6.3 did not exist in ISO 14001:2015. It requires organizations to determine, plan, and manage changes that affect — or could affect — the intended outcomes of the EMS, and to carry those changes out in a planned, controlled manner.

If you’re also certified to ISO 9001, this will look immediately familiar — ISO 9001:2015 has had a change management clause since its last revision. ISO 14001 is catching up, and for integrated management systems this closes one of the more persistent structural mismatches between the two standards. In the 2015 edition, environmental change management lived piecemeal across multiple clauses with no single anchor point. The 2026 edition gives it one.

If you are running an integrated management system (ISO 9001 + ISO 14001) → extend your existing ISO 9001 clause 6.3 change-management procedure rather than building a parallel one from scratch. Keep the risks-and-opportunities information clearly identifiable and traceable under 6.1.4, even if the underlying process is shared.


Clause 7: Support

Structurally unchanged. The documented-information terminology is refreshed to match the vocabulary used across the rest of the 2026 edition, but the substantive requirements — competence, awareness, communication, control of documented information — carry over from 2015 without new “shall” statements.

Objection worth naming here: “Do we need to rebuild our entire document control system for this?” No. If your EMS documentation was compliant under 2015, the structure doesn’t need rebuilding. What needs review is whether the terminology and cross-references in your procedures still match the clause numbering and vocabulary used in the 2026 text — a find-and-replace exercise, not a redesign.


Clause 8: Operation

Clause 8.1 (Operational planning and control) is broadened, and this is the second most consequential change in the revision after Clause 6.3. The 2026 edition replaces the 2015 term “outsourced processes” with “externally provided processes, products and services” — a deliberately wider scope that extends environmental accountability further into your supply chain, not just the processes you’ve formally outsourced.

This connects directly back to Clause 6.1.2’s strengthened life-cycle perspective and Clause 4.3’s scope requirements. Together, these clauses are where auditors will spend more time in a transition audit than anywhere else in the standard.

ISO 14001:2026 clauses explained through the life-cycle perspective connecting Clause 6.1.2 environmental aspects with Clause 8.1 external controls
ISO 14001:2026 clauses explained through the life-cycle perspective from raw materials and suppliers through manufacturing, distribution, product use, and end of life.

If you are under customer pressure to demonstrate supply chain environmental controls → this is the clause pairing to get ahead of first. Supplier questionnaires, flow-down clauses in purchase orders, and documented supplier evaluation criteria all become more defensible evidence under the 2026 text than a general “we expect suppliers to comply” statement.


Clause 9: Performance Evaluation

This clause carries two real structural changes and deserves the same depth as Clause 7.

Clause 9.2.2 (Internal audit programme) now explicitly requires audit objectives, alongside the existing scope and criteria elements, as part of every internal audit. This is a small addition in word count but a real one in practice: “verify we’re ready for the certification audit” doesn’t meet the intent. A defensible objective looks more like “verify conformance of the updated EMS to the 2026 requirements, with particular focus on Clauses 4.1, 6.1.4, 6.3, and 8.1” — specific, testable, and tied to what actually changed.

Clause 9.3 (Management review) is restructured from a single clause into three sub-clauses: 9.3.1 General, 9.3.2 Management review inputs, and 9.3.3 Management review results. The required inputs and results are substantially preserved from 2015 — this is a structural reorganization more than a content rewrite — but your management review agenda and meeting-minutes template should be updated to reflect the new sub-clause structure so your documented information maps cleanly to what an auditor will be checking against.

Monitoring, measurement, analysis, and evaluation requirements outside these two areas carry over largely intact. What auditors are being trained to check more closely is whether performance evaluation data actually feeds into the Clause 6.3 change-planning process — in other words, whether your monitoring results are driving documented EMS changes, not just sitting in a report.


Clause 10: Improvement

The 2015 and 2026 structures line up like this:

2015 Edition2026 Edition
10.1 General10.1 Continual improvement
10.2 Nonconformity and corrective action10.2 Nonconformity and corrective action
10.3 Continual improvement—

Clause 10.1 and 10.3 from the 2015 edition are merged into a single renumbered Clause 10.1, “Continual improvement.” This is a structural consolidation with two accompanying wording updates rather than a new requirement — nonconformity and corrective action content stays at 10.2 and is unaffected in substance, only in how the surrounding clauses are numbered and referenced.

If your procedures cross-reference clause numbers directly (a common practice in older EMS documentation) → this is the one place a pure numbering change can create a real nonconformity if your document control doesn’t catch it. Update cross-references before your transition audit, not during it.


Transition Timeline: What Happens and By When

MilestoneDateWhat It Means
ISO 14001:2026 publishedApril 15, 2026The 2015 edition is formally superseded
New certifications to 2015 edition stopOctober 31, 2027Certification bodies stop issuing fresh 2015 certificates — 18 months after publication
Recertification audits incorporate transition activitiesOctober 1, 2027Under published certification-body schedules (e.g., Amtivo) — not a universal UKAS date; confirm with your own registrar
Final transition deadlineApril 30, 2029ISO 14001:2015 certificates are no longer valid after this date
ISO 14001:2026 clauses explained with a transition timeline from publication through the 2029 certification deadline
ISO 14001:2026 clauses explained with key publication, certification transition, and final deadline milestones.

A three-year transition window is standard practice for a major ISO management system revision under IAF rules — it mirrors the timelines used for ISO 9001:2015 and ISO 45001:2018. UKAS’s published technical bulletin confirms both dates directly: certification bodies must transition their certified customers by April 30, 2029, and stop issuing new ISO 14001:2015 certificates after 18 months from publication. Many organizations fold the transition into a scheduled surveillance or recertification audit rather than scheduling a standalone transition audit, which reduces duplicated audit activity — though additional audit time, training, or documentation work should still be budgeted for depending on your certification body’s approach.

⚠️ Certification bodies are still finalizing their own auditor training and accreditation updates for the 2026 edition. If you’re scheduling a transition audit in the next few months, confirm directly with your certification body which clauses their auditors are currently trained to assess — you can verify a certification body’s accredited scope through ANAB if you want independent confirmation beyond what the registrar tells you — since availability and readiness vary by registrar.

A common transition failure isn’t that the work is hard — it’s assuming a scheduled recertification audit will automatically cover the new edition. Confirm with your registrar now whether your next audit is scoped for the 2026 transition →

Get the ISO 9001 Roadmap — a step-by-step framework for sequencing management system implementation and updates without missing a deadline.


Where to Buy ISO 14001:2026 and Get Trained

The ANSI Webstore remains the preferred source for the official current edition — it serves international buyers and offers standards in multiple languages, which matters if you’re managing EMS documentation across more than one country. ISO 14001:2026 — ANSI Webstore. Use code CC2026 for 5% off any standard purchase through December 31, 2026.

If you’re building out a broader environmental documentation set, the ISO 14001 Collection bundles related standards at a lower combined cost than buying individually.

For internal auditor training on the revised clauses, both ISOQAR and BSI Group offer current courses covering the 2026 changes — worth comparing both since training format and pacing differ between the two providers. For a fuller side-by-side, see our BSI vs ISOQAR comparison.

If you are ready to buy the standard today → go with ANSI Webstore for the official edition. If you are still evaluating training providers → compare ISOQAR and BSI directly before committing budget. If you are building documentation from scratch → start with the ISO Documentation Kits for Manufacturers page rather than a generic template search.


Quick Audit Checklist

Use this as a fast pre-transition scan — not a substitute for a full gap assessment.

  • ✅ Context analysis (4.1/4.2) explicitly names all five environmental conditions: climate change, biodiversity, pollution, resource availability, and ecosystem health
  • ✅ A documented rationale exists for any named factor deemed not material
  • ✅ EMS scope statement (4.3) addresses control and influence across upstream and downstream life-cycle stages
  • ✅ Risks and opportunities (6.1.4) are identified, traceable, and available as documented information — register format optional
  • ✅ Life-cycle perspective (6.1.2) documentation addresses upstream supplier and downstream product impact
  • ✅ A change-management procedure exists and is mapped to Clause 6.3 — shared with ISO 9001 if integrated
  • ✅ Supplier and externally-provided-process flow-down and evaluation criteria (8.1) go beyond a general compliance statement
  • ✅ Internal audit programme documentation includes defined audit objectives (9.2.2)
  • ✅ Management review agenda and minutes template reflect the 9.3.1/9.3.2/9.3.3 structure
  • ✅ Internal procedures cross-referencing old clause numbers (especially 10.1–10.3) have been updated

FAQ

Is ISO 14001:2026 a completely new standard?

No. The revision keeps the ten-clause Harmonized Structure and PDCA model, but reorganizes several sub-clauses, clarifies requirements, and adds the new 6.3 Planning of Changes.

What is the actual deadline to transition my certificate?

April 30, 2029, per UKAS’s published technical bulletin for accredited certification bodies. Certification bodies must also stop issuing new ISO 14001:2015 certificates by October 31, 2027. Confirm both dates with your own certification body, since national accreditation bodies outside the UK may communicate on slightly different timelines.

Do I need to rebuild my entire EMS documentation?

Generally, no. Organizations with a mature, well-run EMS under the 2015 edition should not need to start from scratch. The clarified expectations concentrate in specific clauses — primarily 4.1, 4.2, 4.3, 6.1.4, 6.3, 8.1, 9.2.2, and 9.3 — not the full documentation set.

What is the one genuinely new requirement in ISO 14001:2026?

Clause 6.3, Planning of Changes. It requires a formal, planned approach to managing changes affecting the EMS. It did not exist in any form in the 2015 edition.

Does the 2024 Climate Change Amendment still apply separately?

No. Amendment 1:2024, which introduced climate change considerations into clauses 4.1 and 4.2, has been formally integrated into the 2026 edition. If you already addressed the amendment, you’re ahead of most of this revision.

Will my certification body’s auditors already know the new requirements?

Not universally yet. Certification bodies are still completing their own auditor training and accreditation updates for the 2026 edition. Confirm directly with your registrar which clauses their auditors are currently trained and accredited to assess before scheduling a transition audit.

Does this revision affect integration with ISO 9001 or ISO 45001?

It improves it. Clause 6.3 closes a structural gap that previously existed between ISO 14001 and its Harmonized Structure siblings — ISO 9001 has had a change-management clause since 2015. Integrated management systems should find alignment easier, not harder, under the 2026 edition.

Should I certify directly to ISO 14001:2026 if I’m not yet certified to any edition?

If you’re implementing an EMS for the first time, there’s little reason to build to the 2015 edition and then transition. Go directly to the 2026 requirements.


📥 Free Resources

  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts

Not Sure What to Do Next?

🔹 Still researching what changed? Start with our ISO 14001:2026 vs 2015: What’s New at a Glance for the condensed version, then bookmark this clause-by-clause breakdown as your reference.

🔹 Ready to start closing gaps? Run the Manufacturing Compliance Checklist against Clauses 4.1, 4.3, 6.1.4, 6.3, 8.1, and 9.2–9.3 first — that’s where the substantive changes concentrate.

🔹 Need to buy the standard or get your team trained? ISO 14001:2026 — ANSI Webstore for the standard itself, or compare ISOQAR and BSI Group for internal auditor training on the revised clauses.

The revision cycle rewards the organizations that mapped their EMS to the new clauses early — not the ones that waited for the deadline to force the issue. That’s the difference between a transition audit that folds into your normal surveillance cycle and one that turns into a scramble.

The Standards Navigator will keep tracking this transition as certification bodies finalize their auditor guidance.


Every Revision Cycle Produces the Same Split

Some EMS teams treat a standard revision as a scramble that starts the month before their transition audit. Others map the changed clauses the week the new edition publishes and fold the update into their next scheduled surveillance visit. The difference isn’t resources — it’s whether someone read the clause-by-clause changes before the deadline was the only thing driving the timeline.

The Standards Navigator covers ISO 14001, ISO 9001, and ISO 45001 clause-by-clause — not just certification overviews — because the clause level is where audit findings actually happen.

👉 Get updates on ISO 14001:2026 transition guidance as certification bodies finalize their timelines
👉 Be first to access new EMS gap-assessment resources as they’re built

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

ISO 13485 Clauses Explained: A Complete Clause-by-Clause Breakdown (2026)

ISO 13485:2016 has eight clauses, but only five carry auditable requirements. This ISO 13485 clauses explained guide breaks down Clauses 4 through 8 in practical terms, corrects the common DHF-to-Medical-Device-File mapping error, and explains how FDA’s Compliance Program 7382.850 — which replaced QSIT on February 2, 2026 — reorganizes inspections around six QMS Areas and four Other Applicable FDA Requirements.

What every section of ISO 13485:2016 actually requires — and where auditors dig deepest

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Standard Reads Like a Checklist. It Isn’t One.

ISO 13485:2016 has eight clauses. Five of them carry actual requirements. That structure looks simple on the page — and it’s exactly why so many quality teams underestimate how much interpretation each clause demands once an auditor starts asking “show me.” This ISO 13485 clauses explained guide breaks down what each section requires, where the requirements overlap, and what auditors and FDA investigators may look for.

The FDA’s Quality Management System Regulation (QMSR) took effect February 2, 2026, incorporating ISO 13485:2016 by reference into 21 CFR Part 820. That changes what this clause structure means in practice. FDA also replaced its inspection methodology the same day — the Quality System Inspection Technique (QSIT) is gone, replaced by Compliance Program 7382.850. Getting the clause boundaries right now has a direct line to how an FDA investigator scopes an inspection, not just how a certification body audits.

Regulatory affairs and quality professionals reading this already know ISO 13485 exists. What’s harder to find is a breakdown that goes past the clause titles and into what each section demands in practice — where the audit findings cluster, where risk management threads through clauses that don’t mention risk in their title, and where the standard’s lack of an Annex SL high-level structure changes how it should be read compared to ISO 9001.

My perspective on this comes from 25+ years in operations leadership, an ISO 9001 Internal Auditor certification, and a Six Sigma Green Belt — a lot of that time spent on both sides of the table, building QMS documentation and sitting in CAPA reviews when a gap in that documentation turned into a finding. The pattern holds across every regulated QMS I’ve worked with: teams don’t fail because they misread a clause. They fail because they treated clause boundaries as more rigid than the standard actually intends, and missed how much cross-referencing an auditor expects between clauses 4 through 8.

If you haven’t run a structured gap check against the current clause set, that’s the place to start — not a full documentation rewrite.

👉 Run the ISO 13485 Gap Assessment Checklist before you touch your quality manual — a free, structured way to see exactly which clauses your QMS already satisfies and which ones need real work before an auditor finds the gap for you.


In This Guide

  • How ISO 13485:2016 is structured, and why it doesn’t follow ISO’s Annex SL format
  • A clause-by-clause breakdown of Clauses 4 through 8
  • How FDA’s current inspection program, Compliance Program 7382.850, reorganizes inspections around six QMS Areas
  • The most common audit findings tied to specific sub-clauses
  • Where risk management actually appears throughout the standard
  • How ISO 13485 clause numbering compares to ISO 9001
  • FAQs on structure, exclusions, and transition timing


👉 Start Here (Top Resources)


ISO 13485 Clauses Explained: How the Standard Is Structured

ISO 13485 clauses explained with an eight-clause map covering the standard’s foundational and QMS requirement clauses
ISO 13485 clauses explained through an eight-clause map showing the foundational clauses and the five clauses containing QMS requirements.

ISO 13485:2016 is built around eight clauses. The first three are introductory — they define scope, point to normative references, and set terminology. They carry no auditable requirements on their own, but skipping them is a mistake most teams make once and then correct the hard way.

Clauses 4 through 8 are where the requirements live. This is the part of the standard your certification body actually audits against, clause by clause, sub-clause by sub-clause.

Here’s something worth knowing before you go further: ISO 13485 does not follow the Annex SL high-level structure that ISO 9001:2015, ISO 14001, and ISO 45001 all share. Those three standards align clause-for-clause at the top level, which is why integrated management systems work so cleanly across them. ISO 13485 kept its own structure when it was revised in 2016, specifically so it could stay independent of ISO 9001 revision cycles — a deliberate choice by the technical committee to protect regulatory stability for device manufacturers. If you’re coming from an ISO 9001 background, this is the first adjustment to make: don’t assume clause 7 means the same thing in both standards. It doesn’t.


Clauses 1 Through 3: No Requirements, But Don’t Skip Them

Clause 1 (Scope) defines what the standard covers and, critically, how exclusion and non-application work. ISO 13485 doesn’t let an organization simply skip a requirement that seems inconvenient — where a clause is excluded or considered non-applicable (say, you don’t perform installation), the scope and justification have to be documented in the quality manual under Clause 4.2.2, and be prepared to defend that justification during an audit.

Clause 2 (Normative References) points to ISO 9000:2015 for terms and definitions. You don’t need to buy ISO 9000 to comply, but auditors do expect your team to be using its vocabulary consistently — “nonconformity,” “corrective action,” and “verification” all carry specific meanings your documentation should match.

Clause 3 (Terms and Definitions) establishes the vocabulary used throughout the standard, including specific definitions for concepts like medical device, complaint, risk, and post-market surveillance. Getting comfortable with this terminology matters more than it looks like it should — auditors expect your documentation to use these terms precisely, not colloquially.

📥 Before diving into clauses 4-8: if your QMS documentation predates 2020, run it against the current ISO 13485 Documentation Requirements breakdown first. Most gaps trace back to documentation structure, not missing procedures.


Clause 4: Quality Management System

Clause 4 sets the general requirements for the QMS itself — and it’s where most audit programs start, because everything downstream depends on it.

4.1 General Requirements requires you to identify your QMS processes, map their sequence and interaction, and — this is the part that trips up contract manufacturers — maintain control over any process you outsource. Most common finding: outsourced processes (contract sterilization, contract testing, third-party calibration) that exist operationally but were never formally brought into QMS scope. If a supplier touches your product or your data, your QMS has to account for it.

4.2 Documentation Requirements covers the quality manual, the Medical Device File (Clause 4.2.3), document control, and record control. This requirement is specific to this standard — it’s not something ISO 9001 asks for. It’s a defined set of documents and references demonstrating a device meets its requirements throughout its lifecycle, and auditors will ask to see it assembled, not scattered across a dozen disconnected folders.

If your documentation still uses FDA’s old terminology, this is worth getting precise about. As of February 2, 2026, the terms Device Master Record, Device History Record, and Design History File no longer appear in 21 CFR Part 820. Those legacy record concepts weren’t simply eliminated; their applicable requirements are now addressed through the QMSR framework and ISO 13485’s own structure. Most of what a Device Master Record covered lives in the Medical Device File at Clause 4.2.3, while the Design History File corresponds to the Design and Development File at Clause 7.3.10. These aren’t simple one-for-one renamings: the Medical Device File in particular is a broader requirement than the DMR it replaced, so a straight terminology swap in your documentation will likely leave gaps a crosswalk exercise would catch.

Sub-clause 4.2.4 (control of documentation) and 4.2.5 (control of records) get their own scrutiny. Auditors typically check three things here: are documents reviewed and approved before use, is there a mechanism to prevent use of outdated versions, and are records retained for a defined, justified period. If you’re preparing for your first audit under this clause → build your document control procedure before you build anything else. Everything else in the QMS references it.


Clause 5: Management Responsibility

Clause 5 puts specific, named accountability on top management — not “the quality department,” but leadership itself.

This clause requires a documented quality policy, measurable quality objectives, evidence of planning for QMS changes, and a sub-clause I’ve seen come up repeatedly in audit findings — management review. Clause 5.6.2 is unusually prescriptive for an ISO standard: it names twelve required inputs, and a compliant management review record has to address all of them or document why one doesn’t apply — feedback, complaint handling, reporting to regulatory authorities, audits, monitoring and measurement of processes, monitoring and measurement of product, corrective action, preventive action, follow-up actions from previous reviews, changes that could affect the QMS, recommendations for improvement, and applicable new or revised regulatory requirements. A management review that skips several of these, or that doesn’t produce documented outputs and action items, is a finding waiting to happen — and under the current FDA inspection framework, it’s no longer just a certification-audit concern (more on that below).

If you are already ISO 9001 certified, this clause will feel familiar structurally — but ISO 13485 expects a tighter link between management review and regulatory requirements specifically, not just general business objectives.


Clause 6: Resource Management

Clause 6 covers human resources, infrastructure, and work environment — including contamination-control requirements under 6.4.2 that go considerably further than ISO 9001’s general treatment of work environment.

6.2 Human Resources requires documented competence for anyone whose work affects product quality — not just “trained,” but competence tied to education, skills, and experience, with evidence. 6.3 Infrastructure requires maintenance records for equipment critical to product conformity. 6.4 Work Environment and Contamination Control is where device manufacturers doing anything sterile, implantable, or otherwise contamination-sensitive get the most detailed scrutiny — cleanroom classifications, gowning procedures, and environmental monitoring data all trace back here.


Clause 7: Product Realization

Clause 7 is the largest clause in the standard, and it’s where design controls, purchasing, production, and servicing all live.

7.1 Planning of Product Realization is where ISO 13485 explicitly requires documented risk management processes within product realization, with records maintained throughout. The clause’s note points readers to ISO 14971 for further guidance on structuring that risk management activity — it’s a reference, not a formal incorporation, though in practice most organizations end up using ISO 14971’s framework to satisfy this requirement.

7.3 Design and Development is one of the sub-clauses most commonly identified as non-applicable by contract manufacturers who don’t design product — but where it applies, it can’t be excluded lightly, and the justification has to hold up to the same Clause 4.2.2 scrutiny as any other exclusion. If it applies to you, this is the densest technical section of the standard: design inputs, outputs, review, verification, validation, transfer, and change control, each with its own documented evidence trail. Most common finding: design changes made without running them back through the full verification/validation cycle, especially late in development when schedule pressure is highest.

7.4 Purchasing requires supplier evaluation criteria proportionate to risk, and re-evaluation triggers when supplier performance changes. 7.5 Production and Service Provision covers process validation for anything that can’t be fully verified by downstream inspection — sterilization is the textbook example, which is why it gets its own dedicated body of standards. 7.6 Control of Monitoring and Measuring Equipment ties directly into your calibration program.

If you are under customer or FDA pressure to show design control maturity quickly → prioritize closing out 7.3 documentation gaps before anything else in this clause. In my experience, it’s one of the first sections a regulatory reviewer or auditor asks to see in depth.


Clause 8: Measurement, Analysis and Improvement

Clause 8 is where the QMS proves it’s actually working — and where CAPA lives.

8.2 Monitoring and Measurement covers feedback, complaint handling, and internal audit. Complaint handling under this clause has to interface with FDA’s separate adverse-event reporting requirements — a complaint that may represent a reportable event under Medical Device Reporting (21 CFR Part 803) can’t remain solely an internal QMS record; it has to be evaluated independently against those reporting obligations.

8.3 Control of Nonconforming Product requires documented procedures for identifying, segregating, and dispositioning nonconforming product, including for product discovered nonconforming after delivery — which is where recall-adjacent procedures connect back into the standard.

8.5 Improvement is where corrective and preventive action requirements sit. CAPA under ISO 13485 requires root cause investigation, verification that the action taken was effective, and — a detail I’ve seen auditors check for specifically — evidence that you evaluated whether the same nonconformity could exist elsewhere in the organization before closing the CAPA. A CAPA record that fixes one instance without documenting that broader check is incomplete by this clause’s own standard, regardless of whether the immediate fix worked.

For a deeper breakdown of this clause specifically, see our full guide to CAPA requirements in ISO 13485.


Where ISO 13485 and FDA’s QMSR Overlap by Clause

FDA’s Quality Management System Regulation took effect February 2, 2026, incorporating ISO 13485:2016 by reference into 21 CFR Part 820. That’s the headline most coverage stopped at. What matters more for how you prepare is what happened on the inspection side the same day: FDA retired the Quality System Inspection Technique (QSIT), the inspection methodology it had used since 1999, and replaced it with a new compliance program manual — CP 7382.850, Inspection of Medical Device Manufacturers.

ISO 13485 clauses explained through the 2026 FDA QMSR inspection framework, including six QMS Areas and four OAFRs
ISO 13485 clauses explained in the context of the FDA QMSR and CP 7382.850 inspection framework effective February 2, 2026.

QSIT organized inspections around four subsystems. CP 7382.850 reorganizes them around six QMS Areas, each mapped to ISO 13485 clauses with FDA-specific requirements layered in:

  • Management Oversight — the QMS itself, management review, the medical device file, and product realization planning
  • Design and Development — design inputs, outputs, review, verification, validation, software validation, and transfer
  • Production and Service Provision — production planning, process validation, and servicing
  • Measurement, Analysis, and Improvement — complaint handling, feedback, internal audits, corrective and preventive action, and control of nonconforming product
  • Outsourcing and Purchasing — supplier evaluation and control
  • Change Control — how changes to product or process are managed and documented

Alongside the six QMS Areas, inspections also evaluate four Other Applicable FDA Requirements (OAFRs) that sit outside ISO 13485’s text entirely: Medical Device Reporting (21 CFR Part 803), Corrections and Removals reporting (21 CFR Part 806), Medical Device Tracking (21 CFR Part 821), and Unique Device Identification (21 CFR Part 830). This is where the clause structure above stops covering everything — these four areas are FDA-specific regulatory obligations, not ISO 13485 requirements. They’re evaluated during routine surveillance, compliance follow-up, and PMA postmarket inspections; a narrow exception can apply to certain PMA preapproval inspections when the manufacturer hasn’t yet introduced the device to the U.S. market.

The change that affects Clause 5 most directly: under the prior QSR, management review records were categorically exempt from FDA review under §820.180(c). Under CP 7382.850, that exemption is gone. Management review now sits squarely inside the Management Oversight QMS Area, and an investigator can ask to see it — which means the twelve required Clause 5.6.2 inputs covered above aren’t just a certification-audit concern anymore.

One caution worth stating plainly: ISO 13485 certification and FDA QMSR compliance are related but not identical. A QMS built cleanly against Clauses 4 through 8 covers the ISO 13485 core that QMSR incorporates, but it doesn’t automatically satisfy the four OAFRs — those require their own documented processes regardless of how strong your clause-by-clause QMS is.

If you’re not sure whether your current documentation satisfies both frameworks → our FDA QSR vs ISO 13485 comparison and MDSAP vs ISO 13485 breakdown both walk through this in more detail than fits here.

ISO 13485 vs ISO 9001: Same Numbers, Different Weight

ElementISO 13485:2016ISO 9001:2015
Structure8 clauses, own structure (not Annex SL)10 clauses, Annex SL high-level structure
Risk managementDocumented risk management required in product realization (7.1); note references ISO 14971Risk-based thinking, less prescriptive
Customer satisfaction monitoringNo direct ISO 9001-style requirement; feedback/complaints addressed via Clause 8.2Explicit requirement (Clause 9.1.2)
DocumentationMedical device file required (Clause 4.2)No equivalent requirement
Design controlsDetailed, mandatory unless justified exclusionLess detailed by comparison
Regulatory linkDirectly referenced in FDA QMSR (21 CFR 820)Not tied to a specific regulation

The clause numbers look similar enough to cause real confusion — both standards use “Clause 7” for a large operational section, but the content underneath diverges substantially. If your organization holds both certifications, don’t assume a clause 7 audit finding under one standard tells you anything about your standing under the other. For the full comparison, see ISO 9001 vs ISO 13485.

The objection I hear most on this topic: “We’re already ISO 9001 certified — how much of this is actually new work?” Realistically, expect Clauses 5 and 6 to require the least rework, since management responsibility and resource management overlap heavily in intent. Clauses 4, 7, and 8 are where the medical device-specific requirements add real documentation and process work — the medical device file, design control rigor, and CAPA’s broader-impact evaluation aren’t things a general ISO 9001 QMS already has built in.


Most teams don’t fail an ISO 13485 audit because they misunderstood a clause. They fail because they assumed a documented procedure was enough without checking whether it actually produces the evidence an auditor will ask to see.

👉 Run a structured check before that assumption gets tested in front of an auditor → ISO 13485 Gap Assessment Checklist


Quick Clause Reference Checklist

A clause tells you what’s required. It doesn’t tell you what to hand an auditor when they ask for proof. Below is a quick translation — clause by clause, requirement to evidence.

ISO 13485 clauses explained through an audit evidence checklist showing objective evidence for Clauses 4, 5, 7, and 8
ISO 13485 clauses explained through the objective evidence auditors may review for Clauses 4, 5, 7, and 8.

✅ Clause 4 — QMS scope defined, outsourced processes controlled, medical device file assembled
✅ Clause 5 — Quality policy documented, management review covering all required inputs
✅ Clause 6 — Competence records current, contamination controls documented where applicable
✅ Clause 7 — Risk management documented within product realization; ISO 14971 provides further guidance; design control records complete, supplier evaluation criteria defined
✅ Clause 8 — Complaint handling tied to regulatory reporting, CAPA records show broader-impact evaluation

⚠️ Clauses 1–3 — Exclusions and non-applicability justified in the quality manual, not just left blank

For implementation sequencing beyond the checklist above, our ISO 13485 Implementation Roadmap and ISO 13485 Gap Assessment: Step-by-Step Guide walk through the order to tackle these in.


FAQ

How many clauses does ISO 13485:2016 have?

Eight. Clauses 1 through 3 are introductory and carry no auditable requirements. Clauses 4 through 8 contain the substantive quality management system requirements that certification bodies audit against — and since February 2026, FDA investigators evaluate the same core requirements under Compliance Program 7382.850.

Does ISO 13485 follow the same structure as ISO 9001?

No. ISO 13485 does not use ISO’s Annex SL high-level structure, which ISO 9001, ISO 14001, and ISO 45001 all share. The technical committee kept ISO 13485 independent specifically to protect regulatory stability for device manufacturers, so clause numbers that look similar between the two standards often cover different scope.

Can I exclude clauses from ISO 13485?

Only with documented justification. Under Clause 4.2.2, the scope and justification for any exclusion or non-application have to be recorded in the quality manual, and you need to be prepared to defend that justification during an audit.

Which ISO 13485 clause covers risk management?

Clause 7.1 (Planning of Product Realization) is where documented risk management is explicitly required, and its note points to ISO 14971 for further guidance. But risk-related requirements aren’t confined to one clause — they surface throughout Clauses 4 through 8 rather than sitting in a single isolated section.

What’s the difference between ISO 13485 and the FDA’s QMSR?

As of February 2, 2026, FDA’s QMSR incorporates ISO 13485:2016 by reference into 21 CFR Part 820, and FDA’s inspection methodology changed to match — Compliance Program 7382.850 replaced QSIT the same day. The two frameworks are far more tightly aligned than before, but they’re not identical: four Other Applicable FDA Requirements (Medical Device Reporting, Corrections and Removals, Medical Device Tracking, and UDI) sit outside ISO 13485’s text and are evaluated in applicable inspection types, with a limited exception for certain PMA preapproval inspections when the device has not yet been introduced to the U.S. market.

What is CP 7382.850?

CP 7382.850 (Inspection of Medical Device Manufacturers) is FDA’s current compliance program manual for device inspections, effective February 2, 2026 alongside the QMSR. It replaced the Quality System Inspection Technique (QSIT) and reorganizes inspections around six QMS Areas — Management Oversight, Design and Development, Production and Service Provision, Measurement/Analysis/Improvement, Outsourcing and Purchasing, and Change Control — plus four Other Applicable FDA Requirements evaluated in most inspection types.

Do I need to buy ISO 9001 to understand ISO 13485’s terminology?

You don’t need to purchase it, but ISO 13485 does reference ISO 9000:2015 for its terms and definitions, and auditors expect consistent use of that vocabulary in your documentation.

Which clauses deserve the closest audit preparation?

In practice, Clause 4.2 (documentation control), Clause 7.3 where applicable (design and development), and Clause 8.5 (CAPA effectiveness) tend to draw sustained attention, largely because each requires ongoing documented evidence rather than a one-time procedure. The exact focus varies by organization, device type, and regulatory scope — under the current FDA inspection framework, Management Oversight and Measurement, Analysis, and Improvement are evaluated on every inspection regardless of device type.

Is a documentation kit enough to get ISO 13485 clause requirements right?

A kit gives you a starting structure, but clause-by-clause compliance depends on evidence specific to your processes — training records, design and development records, CAPA effectiveness checks. Our ISO Documentation Kits for Manufacturers page breaks down what a kit does and doesn’t cover.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching how the clauses fit together? Start with What Is ISO 13485? for the foundational overview before working through this clause breakdown a second time.

🔹 Ready to assess where your QMS actually stands? Run the ISO 13485 Gap Assessment Checklist against the clause list above — it’s built to map directly to Clauses 4 through 8.

🔹 Need the official standard text to cite exact clause language? Purchase ISO 13485:2016 through ANSI Webstore — use code CC2026 for 5% off through December 31, 2026. International-language editions are available for teams managing documentation across multiple regulatory regions.

🔹 Need your internal auditors trained on this clause structure before your next surveillance audit? ISO 13485 training through BSI Group covers the structure clause by clause with a certification body’s own instructors.

The Standards Navigator breaks down what these clauses actually demand — not just what they’re titled — so your team can walk into an audit knowing which sub-clause the finding will land on before it does.


Stay Ahead of Clause-Level Changes

Most QMS documentation doesn’t fail because a team ignored ISO 13485. It fails because someone mapped a procedure to the wrong clause once, early on, and every review since has confirmed the wrong thing.

Organizations that treat the clause structure above as a living reference — checked against actual audit findings, updated as FDA’s QMSR enforcement approach becomes clearer — walk into surveillance audits with far fewer surprises than organizations treating their quality manual as a document they wrote once and filed away.

The Standards Navigator tracks ISO 13485, QMSR, and the surrounding medical device standards landscape as they develop, not just at certification time.

👉 Get updates on ISO 13485 and medical device QMS requirements
👉 Be first to access new gap assessment tools and clause-mapping resources

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

ISOQAR Academy Training Review: Is It Worth It for Manufacturers in 2026?

ISOQAR Academy is the training division of certification body ISOQAR, offering CQI/IRCA-certified courses across ISO 9001, 14001, and 45001. This review breaks down course levels from foundation through lead auditor, distinguishes the IMS route from the auditor-conversion route, and covers what training costs and how to decide which level actually fits a given shop.

ISOQAR doesn’t just certify manufacturers — it trains them through ISOQAR Academy. Here’s what the courses actually cover, what they cost, and whether formal training is worth the investment for your shop

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you. The Standards Navigator is an authorized affiliate of ISOQAR.


Your Auditors Don’t Need a Certificate. They Need to Actually Be Competent.

Every ISO standard requires competent internal auditors. None of them requires you to buy a specific training course to get there.

That distinction matters, because training providers — ISOQAR included — will always make the case that their course is the fastest path to that competence. Sometimes it is. Sometimes your shop already has the in-house experience to get there a cheaper way. The question worth answering before you book anything is which path actually fits where your operation stands right now.

ISOQAR Academy is the training arm of ISOQAR, the UKAS-accredited certification body. It offers CQI/IRCA-certified auditor training alongside foundation and other ISO courses across ISO 9001, ISO 14001, ISO 45001, and ISO 27001, delivered both in person at UK training venues and through live virtual classrooms. This review breaks down what ISOQAR Academy training actually covers, what it costs, and how to decide whether it’s the most efficient way to build your team’s competence.

From the Floor: I’ve watched auditors who were genuinely sharp on ISO 9001 fundamentals still miss things once the audit crossed into AS9100-only territory — a configuration management record that didn’t tie back cleanly, a counterfeit-parts control that existed on paper but nobody on the floor could actually explain. That’s not a competence gap in the general sense. It’s a knowledge gap in the aerospace-specific clauses that ISO 9001 experience alone doesn’t cover. Training earns its cost closing that specific gap — it doesn’t replace the auditing fundamentals your team should already have walking in.

Before you book a course, know where your QMS actually stands. A gap assessment tells you which clauses need work before you decide who needs training and at what level.

📥 Download the ISO 9001 Roadmap — a step-by-step implementation guide that walks you from gap assessment through Stage 2 audit clearance, so you know exactly what training gap you’re actually closing.


In This Guide

  • What ISOQAR Academy is and how it fits alongside ISOQAR’s certification business
  • What each course level actually covers — foundation, internal auditor, integrated auditor, and lead auditor
  • The honest pros and cons of training through ISOQAR Academy
  • What it costs, and how the pricing model works
  • A decision framework: which course level fits your shop right now
  • How ISOQAR Academy compares to BSI Group’s training catalog
  • FAQ: CQI/IRCA accreditation, in-house delivery, and what training does and doesn’t guarantee


👉 Start Here: Where to Look Into ISOQAR Academy Training

If your shop is evaluating formal ISO training, ISOQAR Academy’s course catalog spans foundation, internal auditor, and lead auditor levels across ISO 9001, ISO 14001, and ISO 45001. Review ISOQAR Academy’s current ISO 9001 training courses.

If you haven’t purchased a current copy of the standard yet, budget for it separately — course fees don’t always include it. Buy the current standard through the ANSI Webstore — use code CC2026 for 5% off through December 31, 2026.


What Is ISOQAR Academy?

ISOQAR Academy is the training division of ISOQAR, part of the Alcumus Group. While ISOQAR’s certification arm audits organizations against ISO standards, the Academy is a separate function that teaches teams how to understand and audit against those same standards — ISOQAR reports delivering over 8,000 hours of training to 10,000 participants each year.

Courses run through two delivery formats: classroom-based training at UK venues, and live virtual classroom sessions for teams who want to avoid travel cost and time away from the floor. In-house delivery is also available for shops training multiple employees at once, built around your own facility’s documentation rather than a generic case study.

A meaningful share of ISOQAR Academy’s auditor-level courses are CQI/IRCA-certified — accredited through the Chartered Quality Institute’s International Register of Certificated Auditors. That certification provides a formally recognized training credential, which can be useful when an individual’s training record needs to be demonstrated beyond their current employer, not just a course completion certificate.

A 2026 note on ISO 14001: ISOQAR Academy’s catalog is already transitioning ISO 14001 courses to the 2026 edition of the standard. If you’re booking ISO 14001 training, confirm which edition the specific course covers before enrolling — you don’t want your team trained against a superseded version while your certification body is auditing against the current one.


What ISOQAR Academy Courses Actually Cover

ISOQAR Academy training course levels for ISO auditors
ISOQAR Academy training ranges from foundation and internal auditor courses to IMS, CQI/IRCA conversion, and lead auditor training.

ISOQAR Academy’s course catalog isn’t one course — it’s a track, and most manufacturers only need the first one or two levels.

Course LevelWhat It CoversTypical LengthBest For
Foundation (single standard)Standard requirements clause by clause1 dayTeams new to a standard needing working familiarity before anything else
IMS FoundationIntroduces ISO 9001, ISO 14001, and ISO 45001 together, focused on the synergies between them1 dayTeams building familiarity across multiple standards from scratch
Internal Auditor (single standard)Planning, conducting, and reporting internal audits against one standard1 day (standard track) or 2 days (CQI/IRCA-certified)Teams ready to run their own audit program for a single standard
IMS Internal AuditorAuditing across ISO 9001, ISO 14001, and ISO 45001 in one course2 daysTeams already familiar with quality, environmental, or safety systems who need to audit all three together
Auditor Conversion (CQI/IRCA)Extends an existing single-standard auditor’s skills to add ISO 14001 and ISO 450013 daysAuditors already qualified in one standard who need to add EMS/OHS scope
Lead AuditorFull auditor competence for leading external or supplier audits5 daysDeveloping a professional auditing credential, not typical for a single shop’s internal program

A note on terminology: ISOQAR Academy doesn’t sell one generic “integrated auditor” course — it separates a from-scratch IMS Internal Auditor course (for teams building multi-standard audit capability together) from a CQI/IRCA conversion course (for auditors who already hold a single-standard credential and want to extend it). Confirm which one actually fits your team’s starting point before booking, since they assume different prior knowledge.

Most common finding: manufacturers default to booking internal auditor training as the first step, even when their team has never worked through the standard’s requirements in a structured setting. The foundation course exists for a reason — you can’t audit effectively against clauses your team doesn’t understand yet.

If you are new to a standard and still building your QMS → start with the foundation course, not internal auditor training.

If your team already understands the standard and just needs to run audits → the internal auditor course is the right entry point. CQI/IRCA-certified tracks provide a formally recognized training credential, which is useful if the individual’s training record ever needs to be demonstrated beyond this employer — a generic in-house version doesn’t carry that same portability.

If you’re pursuing certification across ISO 9001, 14001, and 45001 together and your team is starting from scratch → the IMS Internal Auditor course is built specifically for that, rather than sending your team through three separate single-standard courses.

If someone on your team is already a qualified auditor for one standard and you’re adding scope → the CQI/IRCA conversion course extends that existing credential to ISO 14001 and 45001, rather than starting them over with a from-scratch integrated course.


Pros and Cons of ISOQAR Academy Training

What ISOQAR Academy Does Well

  • CQI/IRCA-certified course tracks for internal and integrated auditor levels, providing a formally recognized training credential rather than just a generic completion certificate
  • Full course ladder from foundation through lead auditor, so you’re not stuck choosing between “too basic” and “too advanced”
  • Both classroom and live virtual delivery, with in-house options for training multiple employees at once
  • Courses cover ISO 9001, ISO 14001, ISO 45001, and ISO 27001 under one training provider
  • High course volume — ISOQAR reports delivering over 8,000 hours of training to 10,000 participants annually across course levels

Where ISOQAR Academy May Fall Short

  • Course pricing isn’t fully published for every format — in-house and group quotes typically require a direct request
  • Course value depends heavily on where your team already stands: a foundation course won’t add much for an experienced auditor, and an internal auditor course won’t help a team with no prior standard familiarity
  • Classroom locations are UK-based (Manchester, London, Bristol, Leamington Spa, and similar venues) — manufacturers outside the UK should confirm live virtual availability and time zone fit before booking
  • As with any training provider, actual instructor quality varies by who’s assigned to your specific session — a strong course catalog doesn’t guarantee every individual instructor is an equally strong fit for your industry

What ISOQAR Academy Training Costs

ISOQAR Academy doesn’t publish fixed pricing on its course pages — every course listing directs you to request details and book directly rather than showing a price upfront. That’s a call-for-quote model, not hidden pricing, but it does mean you can’t budget from the website alone. What’s generally true:

  • Individual seats on public courses are typically the standard entry point for one or two employees.
  • In-house delivery for multiple employees is worth comparing directly against per-seat pricing once you’re training several people — don’t assume one option is cheaper without requesting both quotes.
  • The standard itself usually isn’t included in the course fee. Budget separately for a current copy before class starts.
  • Live virtual delivery can meaningfully reduce total cost for smaller shops by cutting travel and time away from the floor, particularly for foundation-level courses that don’t require the same hands-on format as auditor training.

Because pricing isn’t published, request a written quote for your specific course, format, and group size before committing a budget — and get it in writing rather than relying on a verbal figure from an initial call.

If you haven’t priced out the full path to certification — training, documentation, gap assessment, and audit fees together — see the complete breakdown of ISO certification costs before committing to training in isolation.


Which Course Level Fits Your Shop?

Where you land depends on what competence already exists on your team — not on whether training is generically “a good idea.”

No prior experience with the standard and no internal audit experience on staff → Start with the foundation course. Booking internal auditor training before your team understands the standard’s requirements means teaching people to audit against clauses they haven’t learned yet.

Team already understands the standard but has never formally audited against it → The internal auditor course is the right level. A CQI/IRCA-certified track is worth the modest premium over a generic version if anyone might use the credential beyond this one employer.

Pursuing certification across multiple standards at once → The IMS Internal Auditor course (or the CQI/IRCA conversion course, if someone’s already qualified in one standard) is built for exactly this and avoids sending your team through three separate single-standard courses.

One experienced auditor already on staff → That person may be able to mentor others through the standard’s requirements without sending the whole team through a full course — formal training becomes most valuable for newer team members who don’t have that internal resource.

Multiple employees need the same training → Compare in-house group quotes against per-seat public course pricing before booking. In-house sessions built around your own documentation are usually the more efficient option past two or three people.

⚠️ Common mistake: booking lead auditor training as a first step before your shop has working documentation in place. That course assumes real familiarity with the standard already — it’s the wrong entry point for a team still building its QMS.


How ISOQAR Academy Compares to BSI Group Training

BSI Group runs a parallel training catalog and is the other name that comes up constantly in this conversation. Both providers offer foundation, internal auditor, and lead auditor courses across the major ISO standards, and both run CQI/IRCA-certified tracks at the auditor level.

FactorISOQAR AcademyBSI Group
Foundation courseYesYes
Internal auditor courseYesYes
Lead auditor courseYesYes
CQI/IRCA-certified tracksYesYes
Live virtual deliveryYesYes
In-house deliveryYesYes
UK classroom networkSmaller, regional venuesBroader national footprint

Neither provider wins universally — the practical differences tend to come down to course availability for your specific standard and format, instructor pool in your region, and quoted price for your group size, not a meaningful difference in the underlying accreditation of the courses themselves. Compare BSI Group’s ISO training courses alongside ISOQAR Academy before booking, particularly if you’re training multiple people and requesting in-house quotes from both.

For U.S. manufacturers specifically: both providers’ classroom networks are UK-based, so live virtual delivery is likely to be the practical default for a single-employee booking — reserve in-person or in-house formats for cases where you’re training several people at once and travel makes more sense.

If you’re already working with ISOQAR as your certification body → training through ISOQAR Academy keeps your documentation and terminology consistent with the language your certification auditor will use, though it isn’t required — you can train with one provider and certify with another.

If brand or provider isn’t a factor → request quotes from both and let course content, instructor experience, and price for your group size make the decision.


A Note on Certification vs. Training

ISOQAR Academy training vs certification for ISO management systems
ISOQAR Academy training builds auditor competence, while ISO certification independently evaluates whether a management system meets the applicable standard.

Worth being direct about this distinction: ISOQAR Academy trains your team. ISOQAR’s certification division audits your organization and issues your certificate. These are related but separate parts of the same company, and it’s a common point of confusion.

Completing an ISOQAR Academy course does not guarantee a smoother certification audit, whether that audit is conducted by ISOQAR or a different certification body entirely. Training builds competence — it doesn’t buy leniency, and the certification decision itself is a separate engagement with its own scope, quote, and timeline.

If you’re also evaluating which certification body to use — ISOQAR, BSI, or another UKAS-accredited provider — that’s a distinct decision from which training to book, and one worth researching separately. See the full breakdown of ISO certification bodies for that comparison.


ISOQAR Academy training readiness checklist for manufacturers
Use this ISOQAR Academy training checklist to match the right course to your team’s competence, audit experience, QMS readiness, and delivery needs.

Quick Checklist: Is Your Shop Ready to Book Training?

  • ✅ You’ve identified whether your team needs foundation-level or auditor-level training — not defaulted to auditor training by habit
  • ✅ You know whether you’re pursuing a single standard or an integrated audit across multiple standards
  • ✅ You’ve compared in-house group pricing against individual seat pricing for your team size
  • ✅ You’ve budgeted separately for the standard itself, since course fees typically don’t include it
  • ✅ You’ve confirmed live virtual availability if your shop is outside the UK or wants to avoid travel cost
  • ⚠️ If your QMS documentation isn’t far enough along to give auditors real processes and records to work with, reconsider the timing of internal auditor training — there’s little to practice against otherwise

FAQ

Does ISOQAR Academy training count toward certification?

No single training course is required for certification. What matters is that your internal auditors are genuinely competent to plan, conduct, and report an effective audit — training is one path to building that competence, not a certification requirement in itself. Your certification body will assess whether your organization has established and maintained personnel competent to carry out its management system and audit activities, not which specific course they attended.

Is ISOQAR Academy training CQI/IRCA accredited?

A meaningful portion of ISOQAR Academy’s internal auditor, IMS internal auditor, and conversion courses are CQI/IRCA-certified, accredited through the Chartered Quality Institute’s International Register of Certificated Auditors. Confirm accreditation status for the specific course you’re booking, since not every course level carries this certification.

Can I train with ISOQAR Academy and certify with a different body?

Yes. Training and certification are separate engagements, even when both are available through ISOQAR. You can complete ISOQAR Academy training and pursue certification with BSI, another UKAS-accredited body, or ISOQAR’s own certification division — whichever fits your shop’s needs.

How much does ISOQAR Academy training cost?

Pricing isn’t published on ISOQAR Academy’s course pages — course listings direct you to request details and book directly. Individual public-course seats are generally the entry point for one or two employees; in-house delivery is quoted separately and worth comparing directly once you’re training several people. Request a written quote for your specific course, format, and group size before budgeting.

Does the course include a copy of the standard?

Course inclusions vary by course and format. Confirm directly with ISOQAR Academy whether the applicable standard is included before enrolling — if not, budget separately for a current copy.

Is virtual training as effective as classroom training?

For foundation-level courses, live virtual formats generally work well. For auditor-level courses with hands-on practical exercises, in-person classroom formats offer more natural opportunities for group exercises, though live virtual delivery remains a reasonable option if travel cost or time away from the floor is the deciding factor.

Can one course cover ISO 9001, ISO 14001, and ISO 45001 together?

Yes — the IMS Internal Auditor course covers all three standards together for teams starting from scratch, and the CQI/IRCA conversion course extends an existing single-standard auditor’s skills to add the other two. Either route is typically more efficient than three separate single-standard courses for shops pursuing or maintaining an integrated management system — which one fits depends on whether your team already holds a single-standard auditor qualification.

Is ISOQAR Academy the same as ISOQAR certification?

No. ISOQAR Academy is the training division; ISOQAR’s certification division conducts the third-party audits that result in your certificate. They’re related parts of the same company but function as separate engagements with separate scopes and pricing.


📥 Free Resources

  • ISO 9001 Roadmap — Step-by-step implementation guide for manufacturers building or improving a quality management system
  • Manufacturing Compliance Checklist — Practical compliance reference covering key ISO, OSHA, and quality requirements for production environments
  • Supplier Quality Checklist — Evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts

Not Sure What to Do Next?

🔹 Still researching whether formal training makes sense for your shop? Start with the ISO 9001 Roadmap to see exactly where your QMS stands before you commit a training budget.

🔹 Ready to look at course options? Review ISOQAR Academy’s current ISO 9001, 14001, and 45001 training courses and request a quote for your team size.

🔹 Want to compare against another training provider first? Compare BSI Group’s ISO training courses.

🔹 Still deciding on a certification body altogether? See how the major players stack up in Best ISO Certification Bodies — Ranked & Reviewed.


Training is one line item in a bigger certification budget, and it earns its cost once the rest of your QMS groundwork is in place — not before. Get the sequence right, and ISOQAR Academy training becomes the thing that builds real auditor competence on your team, not just a certificate on the wall.

The Standards Navigator covers ISO training, certification, and provider selection in plain, practitioner-level language — no sales pitch, just what actually moves the needle toward a compliant, audit-ready QMS.


Stay Ahead of Training and Certification Decisions

Most manufacturers who end up frustrated with a training investment aren’t dealing with a bad course — they’re dealing with a mismatch between the course level they booked and where their team actually stood.

Organizations that build their QMS, develop competence, and conduct meaningful internal audits before certification tend to walk into the certification process with fewer surprises than shops that bolt on training as an afterthought once a customer starts asking questions.

The Standards Navigator covers ISO training providers, certification body selection, and QMS implementation for manufacturers building a compliant, audit-ready quality system.

👉 Get updates on training provider comparisons and certification body reviews

👉 Be first to access new gap assessment tools and implementation resources

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

ISO 13485 Gap Assessment: A Step-by-Step Guide for Medical Device Manufacturers (2026)

Learn how to run an ISO 13485 gap assessment step by step — from scoping and clause mapping to grading findings and building a remediation timeline before your certification audit.

How to run an ISO 13485 gap assessment before your certification body ever sees your QMS.

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Gap Assessment Is the Step Most Manufacturers Skip

Many manufacturers don’t discover their biggest ISO 13485 gaps until they systematically compare their QMS against the standard.

An ISO 13485 gap assessment gives you a structured way to find those gaps before your certification body does. It’s a clause-by-clause comparison of your current quality management system against what ISO 13485:2016 actually requires — and it’s one of the highest-leverage steps between “we think we’re ready” and “we’re ready for Stage 1.”

This guide walks through the gap assessment process step by step: how to scope it, how to run it, how to grade what you find, and how to turn the results into a remediation plan your team can actually execute before your audit window opens.

From the Floor: As a certified ISO 9001 Internal Auditor, the pattern I see most often in gap assessments — regardless of which standard is on the cover — is a QMS that has real documentation but no clause map. Procedures exist. Records exist. But nobody has walked the standard clause by clause and confirmed each requirement actually has evidence behind it. That’s exactly what a gap assessment is designed to expose, and finding it internally gives your team more control over the remediation timeline than discovering it during certification.

Before you build a remediation plan, you need to know where the gaps actually are. Run the free ISO 13485 Gap Assessment Checklist and get a clause-by-clause starting point for your own QMS.


In This Guide

  • What an ISO 13485 gap assessment actually is, and how it differs from an internal audit
  • The eight-step process, from scoping to remediation
  • How to grade findings so your team knows what to fix first
  • A readiness checklist for what “gap-assessed” should actually mean
  • Answers to the questions manufacturers ask most before their first assessment


👉 Start Here (Top Resources)

  • Own the standard you’re assessing against: ISO 13485:2016 — ANSI Webstore — you can’t run an accurate gap assessment without the current clause text in front of you. Use code CC2026 for 5% off through December 31, 2026.
  • Close the gaps once you find them: 9001Simplified — documentation kits built for manufacturers who need to build or rebuild QMS documentation without hiring a full-time consultant.
  • Get your team trained on the requirements before they run the assessment: ISO 13485 Training — BSI Group — a team that understands the clause structure finds gaps faster and more accurately than one working from intuition.

What an ISO 13485 Gap Assessment Actually Is

A gap assessment is not an audit. It’s not a certification activity, and no external party has to be involved. It’s an internal, structured comparison: for every requirement in ISO 13485:2016, does your QMS have documented evidence that requirement is met — and if not, how far off is it?

That distinction matters because it changes the tone of the exercise. An internal audit (covered in our guide on how to audit a medical device QMS) assumes a QMS is largely built and tests whether it’s being followed. A gap assessment assumes nothing — it’s asking “does this exist at all, and if it does, is it complete.”

Gap Assessment vs. Internal Audit

Gap AssessmentInternal Audit
Primary questionDoes the requirement and supporting evidence exist?Is the QMS being followed and operating effectively?
Typical timingOften performed during QMS development or transitionPerformed as part of the established audit program
Main outputGap list and remediation planAudit findings and corrective action
Evidence examinedDocuments, records, and implementation evidenceProcess implementation, records, and objective evidence
PurposeIdentify what needs to be built, changed, or strengthenedEvaluate conformity and implementation of the established QMS

Quick Answer

QuestionQuick Answer
Is a gap assessment required for ISO 13485 certification?No. It’s not a formal requirement of the standard, but it’s a practical risk-reduction step manufacturers can use to identify gaps before a certification audit.
How long does a gap assessment take?As a planning estimate, a single-site manufacturer with an existing QMS might spread the assessment across roughly 2–4 weeks of part-time effort. Actual duration varies significantly with QMS maturity, scope, number of sites, product lines, and team availability.
Can I do a gap assessment myself, or do I need a consultant?You can do it yourself with a structured checklist and a working knowledge of the standard. Consultants add value for complex or first-time QMS builds, but the assessment itself doesn’t require outside certification.
What’s the difference between a gap assessment and an internal audit?A gap assessment checks whether documentation and evidence exist against each clause. An internal audit checks whether an existing, documented QMS is actually being followed in practice.

The Eight-Step Gap Assessment Process

Step 1: Define Scope and Assemble Your Team

Before you open the standard, decide what’s actually in scope. Which sites? Which product lines? Which regulatory markets — because that determines which country-specific requirements layer on top of the ISO 13485 baseline. If you’re weighing whether MDSAP applies to your assessment scope, our MDSAP vs ISO 13485 guide walks through that decision separately.

Assemble a small cross-functional team — quality, at minimum, plus whoever owns design, production, and supplier management. A gap assessment run entirely by one person in the quality department tends to miss operational gaps that only show up on the floor.

Step 2: Gather Current QMS Documentation

Pull everything: your quality manual, procedures, work instructions, forms, records, and any prior audit findings — internal or external. If your document control system is disorganized, this step alone often reveals your first gap. See our guide on ISO 13485 documentation requirements for what a complete document set should include.

Step 3: Build Your Clause Map

At a high level, ISO 13485:2016 organizes its requirements across five main clause groups: Quality Management System (Clause 4), Management Responsibility (Clause 5), Resource Management (Clause 6), Product Realization (Clause 7), and Measurement, Analysis and Improvement (Clause 8). Build a simple matrix — clause number down one side, your corresponding procedure or record down the other. Anywhere that cell is blank is your first visible gap, before you’ve even started evaluating quality.

ISO 13485 gap assessment clause map connecting requirements to procedures, records, and objective evidence
An ISO 13485 gap assessment clause map connects each requirement to the corresponding QMS procedure, work instruction, records, and objective evidence.

Step 4: Walk Each Clause Against the Evidence

This is the core of the assessment. For each clause, ask three questions: Does a documented procedure exist? Does it match what the standard actually requires — not just what sounds similar? And is there objective evidence (records, forms, logs) that the procedure is being followed, not just written?

CAPA is worth flagging specifically here because it requires the team to connect nonconformance, root cause, corrective action, and effectiveness verification across the QMS. Our breakdown of CAPA requirements under ISO 13485 covers what auditors expect to see connected — traceable within the QMS rather than reconciled manually across separate systems.

This is often where gap assessments slow down because the work is tedious, not because it’s conceptually difficult. If your team needs a structured starting point instead of building the clause matrix from scratch → Run the free ISO 13485 Gap Assessment Checklist.

ISO 13485 gap assessment showing how procedures, records, and objective evidence demonstrate QMS conformity
An ISO 13485 gap assessment should verify not only that procedures exist, but that records provide objective evidence the QMS is being followed.

Step 5: Grade Each Finding

Not every gap carries the same weight. A missing signature on a training record is not the same category of problem as a design control process that doesn’t exist. Grade findings on a simple scale:

  • Critical — the requirement is effectively absent. No procedure, no evidence, no compensating control.
  • Major — a procedure exists but has a significant gap against the clause requirement, or evidence of following it is inconsistent.
  • Minor — the procedure and evidence both exist, but execution has small, correctable inconsistencies.

Grading matters because it drives sequencing. These labels are an internal prioritization framework, not ISO 13485-defined finding classifications — the exact grading terminology and criteria used by a certification body or regulatory program can vary. For an internal assessment, the important thing is to apply your criteria consistently so the team knows which gaps require immediate attention.

Step 6: Prioritize Remediation

Start with the gaps that present the greatest risk to QMS conformity or product and regulatory compliance. In most cases, that means addressing foundational gaps such as a missing design-control process or nonexistent CAPA system before working through lower-risk administrative issues. Major findings come next, typically grouped by clause area so one person or team can work through related gaps together rather than jumping between unrelated processes.

If you are rebuilding documentation from a critical or major finding → start with the clause itself, not a generic template. A procedure written to satisfy a checklist item without matching your actual process creates a new gap the moment an auditor asks a follow-up question.

If you are working through a backlog of minor findings → batch them by owner and set a single close-out date rather than tracking dozens of individual deadlines. Minor findings left open individually tend to get lost; batched with a deadline, they get closed.

Step 7: Build a Remediation Timeline

Attach real dates to every finding, not target quarters. Critical findings should have the shortest timeline your team can realistically execute — these are the gaps most likely to create significant problems during a certification assessment if they remain unresolved. Build in a buffer before your target certification audit date; remediation almost always takes longer than the first estimate, especially where a new procedure requires training staff to actually follow it.

Step 8: Re-Assess Before You Schedule Your Audit

A gap assessment isn’t a one-time snapshot. Once remediation work closes out your critical and major findings, re-walk those specific clauses to confirm the fix actually holds — not just that a document was updated, but that the evidence trail behind it exists. This is also the point where many manufacturers benefit from a full internal audit as a final check before scheduling Stage 1.


Common Mistakes That Undermine a Gap Assessment

Treating the assessment as a documentation review only. Confirming a procedure exists isn’t the same as confirming it’s followed. A gap assessment that never looks at records — training logs, CAPA files, supplier evaluations — will miss exactly the kind of gap an auditor finds first, because auditors ask for objective evidence, not just the procedure. Our guide on common mistakes in ISO 13485 QMS implementation covers this pattern in more depth.

Assessing against an old edition of the standard. ISO 13485:2016 is the current edition, but manufacturers working from a QMS built years ago sometimes have procedures written against superseded clause numbering. Confirm you’re assessing against the current published text before you start building your clause matrix.

Skipping the connection to FDA’s QMSR. If you sell into the United States, consider whether your gap assessment also needs to address FDA’s QMSR requirements and inspection expectations — FDA’s QMSR, effective February 2, 2026 and incorporating ISO 13485:2016 by reference, expanded what FDA can review during an inspection. Records that were previously exempt from routine inspection under the legacy QSR — management review, internal quality audit, and supplier audit records — are not exempt under QMSR. That’s worth building into your assessment scope rather than assuming an ISO 13485-only assessment automatically covers it.


Gap Assessment Readiness Checklist

✅ Scope defined — sites, product lines, and regulatory markets confirmed
✅ Cross-functional team assembled, not just quality department staff
✅ Full current QMS documentation set gathered and organized
✅ Clause matrix built against ISO 13485:2016, Clauses 4 through 8
✅ Each clause walked against both procedure and objective evidence, not procedure alone
✅ Findings graded — critical, major, minor — using consistent criteria
✅ Remediation timeline built with real dates, prioritized by severity
✅ Critical and major findings re-assessed after remediation, before scheduling your audit

ISO 13485 gap assessment process showing how manufacturers find, prioritize, remediate, and re-assess QMS gaps before certification
An ISO 13485 gap assessment turns identified QMS gaps into a prioritized remediation plan, followed by verification and re-assessment before the certification audit.

Frequently Asked Questions

Is a gap assessment required before ISO 13485 certification?

No. It’s not a formal requirement in the standard itself. It’s a risk-reduction step manufacturers use to avoid discovering major or critical nonconformities for the first time during an actual certification audit, where findings can delay certification.

How is a gap assessment different from an internal audit?

A gap assessment asks whether documentation and evidence exist at all against each clause — it’s typically run once, early, often before a QMS is fully built out. An internal audit assumes a documented QMS exists and tests whether it’s actually being followed in day-to-day operation. A common approach is to run the gap assessment first, then use internal audits on a recurring schedule once the QMS is established.

Who should be involved in a gap assessment?

At minimum, someone from quality who knows the standard well enough to interpret clause intent, plus representation from any function the clauses touch directly — design, production, supplier management. A single-person assessment tends to miss operational gaps that only surface when someone from outside quality reviews the finding.

How long does a gap assessment typically take?

As a planning estimate, a manufacturer with an existing QMS and a single site in scope might spread the assessment across roughly 2–4 weeks of part-time effort. Actual duration varies significantly with QMS maturity, scope, number of sites, product lines, and team availability — manufacturers building a QMS from scratch, or with multiple sites in scope, should expect it to take longer.

Can I use the same gap assessment for MDSAP readiness?

Largely, yes — MDSAP audits use ISO 13485:2016 requirements alongside applicable regulatory requirements from participating authorities, so a thorough ISO 13485 gap assessment covers most of the same ground. MDSAP layers those country-specific regulatory requirements on top of the ISO 13485 baseline, so if MDSAP is in scope, your assessment should also map those additional requirements. See our MDSAP vs ISO 13485 guide for how the two relate.

What happens if I find a critical gap close to my planned audit date?

Push the audit date. Scheduling a certification audit around a known critical gap doesn’t make the gap disappear — it moves the risk of discovering that gap into the certification audit, where the certification body will determine whether the issue constitutes a nonconformity and how it should be classified, instead of remaining an internal finding you controlled the timeline on.

Do I need a consultant to run a gap assessment?

Not necessarily. A structured checklist and a working knowledge of the standard’s clause structure is enough for most single-site manufacturers with an existing QMS. Consultants add the most value for first-time QMS builds, multi-site assessments, or situations where the internal team lacks bandwidth to run the assessment alongside daily operations.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still figuring out where your QMS stands? Start with the ISO 13485 Gap Assessment Checklist — it’s the fastest way to see your clause-by-clause starting point before you build a full remediation plan.

🔹 Ready to close documentation gaps you’ve already identified? 9001Simplified’s documentation kits are built for manufacturers assembling or rebuilding QMS documentation without a full-time consultant.

🔹 Need to confirm your clause matrix against the current standard? Get ISO 13485:2016 from ANSI Webstore — code CC2026 takes 5% off through December 31, 2026.

🔹 Want your team trained before they run the assessment? BSI Group’s ISO 13485 training builds the clause knowledge that makes a gap assessment faster and more accurate.

Treating a gap assessment as a formality can leave significant gaps undiscovered until the certification audit. A properly executed assessment gives your team an opportunity to find those gaps internally, assign ownership, and control the remediation timeline before the certification audit begins. The Standards Navigator will keep this guide current as ISO 13485 and its related regulatory frameworks continue to evolve.


Stay Ahead of Your Next Audit Cycle

Skipping the gap assessment step doesn’t remove the risk of undiscovered gaps — it increases the chance that a gap will first be identified during the certification process, in front of an auditor, where the certification body determines whether it constitutes a nonconformity. Running it properly moves that discovery earlier, onto your own timeline, with your team in control of the fix.

The Standards Navigator tracks how ISO 13485, MDSAP, and FDA’s QMSR continue to shift so your QMS doesn’t fall behind a requirement you didn’t know had changed.

👉 Get updates on ISO 13485 requirements and medical device compliance as they happen
👉 Be first to access new gap assessment tools and documentation resources as we build them

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

MDSAP vs ISO 13485: What’s the Difference and Do You Need Both in 2026?

MDSAP and ISO 13485 are often confused, but they answer different questions. This guide breaks down how the MDSAP audit program relates to the ISO 13485:2016 standard, what changed with FDA’s 2026 QMSR, and which manufacturers actually need MDSAP registration.

Whether the MDSAP consolidated audit program adds real value to your QMS — or scope you don’t need yet.

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Two Audits, One QMS Standard — and a Decision Most Manufacturers Get Wrong

MDSAP vs ISO 13485 is a distinction worth getting right before you scope an audit program: these are not competing options, and they are not two paths to the same certificate. Treating them as interchangeable is exactly how manufacturers end up either over-auditing themselves or discovering — mid-application — that a market they assumed was covered isn’t.

If you sell into more than one of the five MDSAP countries, this decision affects your audit calendar, your registrar spend, and your regulatory submission timeline for years. If you sell only into the EU or UK, most of what follows doesn’t apply to you at all — and that’s worth knowing before you spend a quarter evaluating a program you don’t need.

This guide breaks down exactly what MDSAP is, how it relates to ISO 13485:2016, and — now that the FDA’s Quality Management System Regulation has replaced the legacy 21 CFR Part 820 — what changed for US-market manufacturers in 2026.

From the Floor: With 25+ years in heavy industrial manufacturing and a certified ISO 9001 Internal Auditor credential, I’ve seen the same regulated-QMS failure pattern show up regardless of which standard is on the cover — 9001 or 13485. It’s not missing documentation. It’s documentation that exists but doesn’t connect: a CAPA log that references a nonconformance report that was never actually closed out in the corrective action file. Stack five regulatory authorities’ expectations on top of each other instead of one, and that gap can become a nonconformity that appears in the MDSAP audit record used by the participating Regulatory Authorities.

Before you evaluate MDSAP, confirm your QMS actually conforms to ISO 13485:2016 first — MDSAP audits against it, it doesn’t substitute for it. Run the free ISO 13485 Gap Assessment Checklist and see exactly where your documentation stands before you add audit scope on top of it.

In This Guide

  • What MDSAP actually is, and how it relates to ISO 13485:2016
  • A side-by-side comparison of both frameworks
  • What changed in 2026 with the FDA’s QMSR and the revised MDSAP Audit Approach
  • Decision-stage signals for whether MDSAP applies to your business
  • What MDSAP costs — and what it saves — compared to separate country audits
  • Documentation issues that can create problems in MDSAP-scope audits
  • A readiness checklist and answers to the questions manufacturers ask most


👉 Start Here (Top Resources)

  • Own the standard MDSAP is built on: ISO 13485:2016 — ANSI Webstore — the foundation document every MDSAP audit is measured against. Use code CC2026 for 5% off through December 31, 2026.
  • Close documentation gaps before you’re audited on them: 9001Simplified — documentation kits built for manufacturers assembling or tightening a QMS without hiring a full-time consultant.
  • Get your team trained on the underlying requirements: ISO 13485 Training — BSI Group — BSI is one of the Auditing Organizations recognized under MDSAP, and their training builds the ISO 13485 foundation your audit is scored against.

What Is ISO 13485, and What Is MDSAP Built on Top Of It?

ISO 13485:2016 is the quality management system standard for medical device manufacturers. It’s a standalone document you can certify to on its own — covered in detail in our What Is ISO 13485 guide.

MDSAP (Medical Device Single Audit Program) is not a standard. It’s a regulatory audit program. Five participating Regulatory Authorities — Australia’s TGA, Brazil’s ANVISA, Health Canada, Japan’s MHLW/PMDA, and the U.S. FDA — use a single consolidated audit, conducted by an MDSAP-recognized Auditing Organization, to assess the applicable QMS and regulatory requirements across participating markets, rather than requiring separate audits from each regulator. That audit is scored against ISO 13485:2016 as the baseline, with country-specific regulatory requirements layered on top for each market a manufacturer participates in.

Standalone ISO 13485 certification, by contrast, is issued by certification bodies accredited through national accreditation bodies — in the US, that’s typically ANAB. MDSAP Auditing Organizations go through a separate recognition process run directly by the participating Regulatory Authorities, not through the standard accreditation pathway.

In plain terms: ISO 13485 is what you’re audited against. MDSAP is who accepts that audit, and how many regulators it satisfies at once.


Quick Answer

QuestionQuick Answer
Is MDSAP the same as ISO 13485?No. MDSAP is a multi-country regulatory audit program built on top of ISO 13485:2016 — it doesn’t replace the standard, it audits against it plus country-specific requirements.
Do I need ISO 13485 certification before MDSAP?No. Your QMS must conform to ISO 13485:2016, but you don’t necessarily need a separate ISO 13485 certificate before undergoing an MDSAP audit — the MDSAP audit itself assesses that conformance.
Is MDSAP required?Only for Class II–IV Canadian market access. In the other participating MDSAP markets, participation is generally voluntary, although it can consolidate applicable regulatory assessments across multiple markets.
Does MDSAP replace FDA inspections entirely?No. MDSAP audit results can be used by FDA within its regulatory program, but FDA retains its authority to conduct inspections, including for-cause inspections.

MDSAP vs ISO 13485: Side-by-Side

CategoryISO 13485:2016MDSAP
What it isA quality management system standardA multi-jurisdiction regulatory audit program
BasisStandalone documentBuilt on ISO 13485:2016 plus country-specific regulatory requirements
Who administers itCertification bodies accredited by ANAB or an equivalent accreditation bodyAuditing Organizations recognized by the five participating Regulatory Authorities
Countries coveredGlobal — recognized wherever ISO 13485 certification is acceptedAustralia, Brazil, Canada, Japan, United States
Can you buy it?Yes — it’s a purchasable standard documentNo — it’s an audit program, not a document
Mandatory?Often required by customers, notified bodies, or regulators (EU MDR, for example)Mandatory only for Class II–IV Canadian market access; voluntary elsewhere
Audit frequencyPer your certification body’s surveillance schedule — typically annualInitial audit followed by annual surveillance audits within the certification cycle
What you getAn ISO 13485 certificateAn MDSAP certification document and audit report each participating Regulatory Authority can use within its own regulatory program

For the broader question of how ISO 13485 stacks up against the standard most manufacturers compare it to first, see ISO 9001 vs ISO 13485.


The 2026 Regulatory Shift: QMSR and the Revised MDSAP Audit Approach

MDSAP vs ISO 13485 infographic showing the 2026 FDA QMSR transition and changes to medical device quality records
MDSAP vs ISO 13485: The 2026 FDA QMSR aligns U.S. medical device quality requirements with ISO 13485:2016 and changes FDA access to management review, internal audit, and supplier audit records.

Two changes landed in 2026 that directly affect this comparison.

On February 2, 2026, the FDA’s Quality Management System Regulation (QMSR) officially took effect, replacing the legacy 21 CFR Part 820 Quality System Regulation and incorporating ISO 13485:2016 by reference. That doesn’t make US manufacturers MDSAP-compliant automatically — it means the US regulatory baseline now speaks the same structural language as ISO 13485, closing a gap that used to require manufacturers to maintain two separate documentation logics. We cover the mechanics of that shift in FDA QSR vs ISO 13485.

The QMSR also removed a long-standing FDA inspection exemption. Under the prior QSR, §820.180(c) shielded management review records, internal quality audit reports, and supplier audit reports from routine FDA inspection. The QMSR eliminates that exemption entirely — FDA’s own QMSR FAQ confirms investigators now have authority to review management review, quality audit, and supplier audit records as part of a standard inspection. For manufacturers who treated those records as internal-only, that’s a meaningful shift in what “audit-ready” documentation needs to look like.

Around the same window, the MDSAP Regulatory Authority Council released a revised Audit Approach document (MDSAP AU P0002.010), updating the audit sequence and process guidance auditors use during MDSAP assessments. If your last MDSAP audit was conducted under the prior version, don’t assume your documentation package is still current against the revised approach — verify against the current edition before your next audit window.

It can be tempting to assume that QMSR compliance automatically covers MDSAP scope. It doesn’t — QMSR alignment closes the gap between the US baseline and ISO 13485, but MDSAP still layers the applicable regulatory requirements of each participating jurisdiction on top of that baseline. Check where your QMS actually stands before you assume you’re covered → Run the ISO 13485 Gap Assessment Checklist.


Do You Need MDSAP? Decision-Stage Signals

  • If you are selling only into the EU or UK → you still need to meet the applicable medical-device QMS and conformity-assessment requirements for those markets, but MDSAP is not generally required there.
  • If you are selling into Canada at Class II, III, or IV → MDSAP is mandatory. Health Canada requires an MDSAP certificate, issued by a recognized MDSAP Auditing Organization, as part of the device license application.
  • If you sell into several of the five MDSAP countries → compare the cost and disruption of MDSAP against the separate regulatory assessments that would otherwise apply. Three or more can be a useful practical threshold for comparison, but the right number depends on your specific audit costs, inspection history, device scope, and market plans.
  • If you are already ISO 13485 certified and sell only into the US → weigh MDSAP against your actual FDA inspection frequency and any near-term expansion plans before adding audit scope you may not need yet.
MDSAP decision flowchart showing when medical device manufacturers need MDSAP for Canada and when it is generally voluntary in other markets
A practical MDSAP decision guide showing when certification is required for Canadian Class II–IV devices and when manufacturers should evaluate MDSAP based on market scope, audit costs, and regulatory strategy.

What MDSAP Actually Costs You — And What It Saves

The most common objection we hear is straightforward: MDSAP audits cost more than a standard ISO 13485 surveillance audit, so why add the expense?

That’s true in isolation — an MDSAP audit typically runs longer and costs more per audit day than a single-standard ISO 13485 surveillance visit, because the auditor is assessing conformance to multiple regulatory frameworks in one visit. But the comparison that matters isn’t MDSAP audit cost versus ISO 13485 audit cost. It’s MDSAP audit cost versus the combined cost of separate inspections from Health Canada, ANVISA, TGA, and PMDA, run independently, on different schedules, each requiring separate audit prep. For manufacturers selling across several MDSAP markets, the consolidation can make the overall audit program less costly and less disruptive than managing multiple separate regulatory assessments — but the business case depends on device classification, facility count, audit scope, your Auditing Organization, and your existing inspection cadence, so get a scoped quote rather than budgeting off a generic number.

Manufacturers building out documentation to support a broader audit scope shouldn’t be doing it from scratch. If your QMS documentation isn’t structured to hold up under multiple regulatory frameworks at once, that’s the gap to close first → 9001Simplified’s documentation kits are built for exactly this kind of consolidation work.


Documentation Issues That Can Create Problems in MDSAP Readiness

One area worth checking closely is CAPA traceability. CAPA records should connect clearly to the underlying nonconformance, investigation, corrective action, and effectiveness evidence, rather than leaving the auditor to reconcile separate systems manually — see our breakdown of common mistakes in ISO 13485 QMS implementation and the full CAPA requirements under ISO 13485 for what auditors expect to see connected.

Another area to review is how regulatory requirements are mapped into the QMS. MDSAP audits ISO 13485 alongside applicable jurisdiction-specific requirements, so documentation that only reflects one regulator’s language may need additional mapping before an MDSAP audit. Our guide on ISO 13485 documentation requirements covers how to structure it correctly the first time.


MDSAP vs ISO 13485 readiness infographic showing CAPA traceability, document control, regulatory mapping, internal audits, and audit evidence
MDSAP vs ISO 13485: MDSAP readiness depends on connected evidence across CAPA, document control, regulatory mapping, internal audits, and market scope.

MDSAP Readiness Checklist

✅ QMS is currently certified — or verified compliant — to ISO 13485:2016
✅ CAPA records cross-reference nonconformance reports within the QMS itself, not a separate tracking tool
✅ Document control system is organized by ISO 13485 clause structure, not by individual regulator language
✅ You’ve confirmed which of the five MDSAP countries you actually sell into or plan to
✅ You’ve reviewed your documentation against the revised MDSAP Audit Approach (AU P0002.010)
✅ You’ve scoped audit cost and timeline with an MDSAP-recognized Auditing Organization
✅ Internal audit process already traces process interactions, not just individual clause compliance — see how to audit a medical device QMS


Frequently Asked Questions

Is MDSAP the same thing as ISO 13485?

No. ISO 13485:2016 is the quality management system standard. MDSAP is a regulatory audit program that assesses conformance to that standard, plus country-specific requirements from five participating Regulatory Authorities, in a single consolidated audit.

Do I need to be ISO 13485 certified before I can apply for MDSAP?

Your QMS needs to conform to ISO 13485:2016 — MDSAP auditors assess that conformance directly as part of the MDSAP audit itself. In practice, most manufacturers already hold or are pursuing ISO 13485 certification before entering the MDSAP process.

Which countries does MDSAP cover?

Five participating Regulatory Authorities: Australia (TGA), Brazil (ANVISA), Canada (Health Canada), Japan (MHLW/PMDA), and the United States (FDA). A number of other regulators participate as observers or affiliate members without full recognition of MDSAP audit results.

Is MDSAP required to sell medical devices in the United States?

No. The FDA accepts MDSAP audit results as part of its compliance program, and the 2026 QMSR incorporates ISO 13485:2016 by reference, but MDSAP participation itself remains voluntary for US-only manufacturers.

How did the FDA’s 2026 QMSR change affect MDSAP?

The QMSR, effective February 2, 2026, replaced 21 CFR Part 820 and incorporated ISO 13485:2016 by reference — narrowing the gap between US regulatory expectations and the ISO 13485 baseline that MDSAP already audits against. It doesn’t grant automatic MDSAP compliance; it changes what the US regulatory floor requires your documentation to look like.

How much does an MDSAP audit cost compared to a standard ISO 13485 audit?

MDSAP audits generally run longer and cost more per audit than a single-standard ISO 13485 surveillance audit, since the scope covers multiple regulatory frameworks in one visit. Pricing varies significantly by Auditing Organization, facility count, and audit scope — get a quote scoped to your specific situation rather than relying on a general figure.

Can a small manufacturer participate in MDSAP?

Yes. Any manufacturer with a product that falls under the scope of at least one participating Regulatory Authority may apply. It tends to make the most financial sense for manufacturers selling into several of the five MDSAP countries, where consolidating audits can produce clearer savings — though the exact threshold depends on your specific cost structure.

Does an MDSAP certificate replace my ISO 13485 certificate?

Not automatically, and it depends on the market. In Canada, the MDSAP certificate has replaced the standalone ISO 13485 certificate in the device license application process for Class II–IV devices. In most other participating markets, manufacturers typically maintain both, since ISO 13485 certification is often required independently by customers or notified bodies.


📥 Free Resources

  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements before pursuing MDSAP or standalone certification.
  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.
  • AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification.

Not Sure What to Do Next?

🔹 Still researching whether MDSAP applies to you? Start with the ISO 13485 Gap Assessment Checklist — confirm your QMS conforms to ISO 13485:2016 before you evaluate adding MDSAP scope on top of it.

🔹 Ready to close documentation gaps before your next audit? 9001Simplified’s documentation kits are built for manufacturers structuring a QMS to hold up under more than one regulatory framework at once.

🔹 Need to buy the ISO 13485:2016 standard itself? Get it directly from ANSI Webstore — code CC2026 takes 5% off through December 31, 2026.

🔹 Want your team trained on the requirements before your MDSAP audit? BSI Group’s ISO 13485 training builds the foundation MDSAP auditors score against.

MDSAP isn’t a bigger version of ISO 13485 certification — it’s a different question entirely: not “is your QMS compliant,” but “how many regulators can rely on the same answer.” Get that distinction right before you scope an audit program you may not need, or miss one you do. The Standards Navigator will keep tracking how MDSAP and the 2026 QMSR shift continue to interact as more guidance comes out.


Stay Ahead of the Next Regulatory Shift

Manufacturers who treat MDSAP as “extra paperwork” usually find out the hard way — mid-application, with a Canadian import deadline already on the calendar. Manufacturers who map their audit scope to their actual markets first spend less on audits and never scramble for a certificate they didn’t know they’d need.

The Standards Navigator tracks how ISO 13485, MDSAP, and FDA’s QMSR continue to shift against each other so you don’t have to monitor five regulators’ guidance pages yourself.

👉 Get updates on medical device compliance and regulatory changes as they happen
👉 Be first to access new gap assessment tools and documentation resources as we build them

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

BSI AS9100 Training Review: Is It Worth It for Small Manufacturers in 2026?

AS9100 doesn’t require a specific training course — it requires competent auditors. This review breaks down what BSI’s AS9100 training actually covers, its pros and cons against other providers, realistic cost ranges, and a five-scenario framework for deciding whether formal training is the most efficient path for your shop.

AS9100 doesn’t require you to buy a training course — it requires competent people. Here’s how to figure out the most efficient path to get there

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


AS9100 Doesn’t Require a Training Course. It Requires Competent People.

Nearly every training provider will tell you their course is essential. Here’s what the standard itself actually requires: it doesn’t name BSI, ISOQAR, or anyone else. It requires that your internal auditors be competent — genuinely capable of planning, conducting, and reporting an effective audit against AS9100.

That leaves you with a real question, not a marketing one: is formal BSI AS9100 training the most efficient way for your shop to establish that competence, or is there a faster, cheaper path that gets you there just as well?

This isn’t a promotional writeup for BSI’s course catalog. It’s a decision framework for figuring out which path fits where your shop actually stands — and what that path costs.

From the Floor: I’ve sat in on the decision more than once — which employees get sent to formal standards training and which get handed the standard and told to figure it out. The pattern I’ve seen holds regardless of which standard is involved: the people who come back and actually change how audits get run aren’t the ones who sat through the most polished course. They’re the ones who used the class time to work through their own facility’s real nonconformances instead of generic case studies. That’s the filter I’d apply before signing off on any training spend — including this one.

If you haven’t run a gap assessment against AS9100 Rev D yet, that’s the decision that should come before a training decision — not after. Operations managers who evaluate training before understanding their QMS gaps may be solving the wrong problem first.

👉 Before you spend a dime on training, find out exactly where your QMS stands. Run the AS9100 Rev D Gap Assessment Checklist — a 74-item, 12-section clause-by-clause tool that shows you precisely which sections need work before you decide who needs training and in what format.

In This Guide:

  • What BSI’s AS9100 training actually covers, course by course
  • The honest pros and cons of BSI’s training — and how it compares to other providers
  • What it costs — and how BSI’s pricing model actually works
  • A decision framework: which competence-building path fits your shop
  • A cost comparison: formal training vs. experience-based routes vs. skipping it
  • What training actually establishes, and where it doesn’t help
  • FAQ: certificates, recertification, and whether training is technically required


👉 Start Here: Where to Look Into AS9100 Training

If your shop is evaluating formal AS9100 training, BSI Group is one of the established providers worth comparing against — its AS9100 training portfolio covers requirements training, internal auditor training, and lead auditor training. Review BSI’s AS9100 training course options.

If you haven’t bought a current copy of the standard yet, check whether the current course fee includes a copy of the applicable standard. If it doesn’t, budget separately for your copy before class starts. Purchase the current AS9100/SAE standard through ANSI Webstore.


What BSI’s AS9100 Training Actually Covers

BSI’s AS9100 training isn’t a single course — it’s a track, and small manufacturers tend to only need the first one or two levels of it.

The entry-level course covers the AS9100 Rev D requirements themselves: what each clause demands, how the aerospace-specific additions build on the ISO 9001 foundation, and how the standard maps to your existing documentation. This is the right starting point if your team understands ISO 9001 already but has never worked with the aerospace-specific clauses — configuration management, first article inspection, counterfeit parts controls, and the rest.

The internal auditor course goes a step further. It’s built around conducting audits against AS9100 and AS9101, and it typically runs as a multi-day, instructor-led format — in person or live online — with practical audit exercises rather than lecture alone. This is the course that matters most if you’re planning to run your own internal audit program instead of outsourcing every internal audit to a consultant.

Beyond that sits lead auditor training, which is usually more than a small shop needs unless someone is being developed to lead aerospace audits or pursue auditing professionally.

If you are new to AS9100 and still building your quality management system → start with the requirements-level course, not internal auditor training. You can’t audit effectively against clauses your team doesn’t understand yet.

BSI AS9100 training path showing requirements, internal auditor, and lead auditor training levels
BSI AS9100 training offers different levels of learning, from understanding AS9100 requirements to developing internal and lead auditor skills.

Pros and Cons of BSI AS9100 Training

What BSI Does Well

  • Established global training and certification organization with a broad aerospace training portfolio
  • Full AS9100 course catalog spanning requirements, internal auditor, and lead auditor levels
  • Both live online and in-person delivery formats available
  • Course completion certificates from an established training provider
  • In-house delivery available for training multiple employees at once

Potential Drawbacks

  • Pricing isn’t published upfront for most course types — expect to go through a quote request
  • May run higher than some smaller or regional training providers, depending on format and group size
  • Course value depends heavily on where your team already stands — a requirements-level course won’t add much for an already-experienced auditor, and an internal auditor course won’t help a team with no prior standard familiarity
  • Small shops adding AS9100 to an existing ISO 9001 program may only need the requirements-level course, not BSI’s full auditor track

How BSI Compares to Other AS9100 Training Providers

BSI isn’t the only organization offering AS9100 training. Smaller, regional, and boutique training providers also run AS9100 requirements and internal auditor courses, and sometimes at a lower per-seat cost than a multi-national provider like BSI. A provider with an established aerospace training portfolio may offer a familiarity advantage, but don’t assume the provider’s name substitutes for demonstrated auditor competence.

If you’re comparing multiple providers, weigh course content and instructor experience against price alone. An aerospace-specific internal auditor course taught by an instructor with real AS9100 audit experience is worth more than a generic quality-auditing course relabeled for aerospace. Ask any provider — BSI included — how their course specifically addresses the AS9100-unique clauses (configuration management, counterfeit parts, first article inspection) rather than treating AS9100 as ISO 9001 with an extra chapter.


What It Costs — and How BSI’s Pricing Model Works

This is the part that frustrates small manufacturers the most: BSI’s course pages typically direct buyers toward public-course enrollment for individual seats and a separate quote process for private or in-house training, so pricing can vary by course, delivery format, and group size rather than sitting on a single published price list.

That’s not unusual for the industry, and it also means published cost figures age fast. A rough, non-exhaustive comparison across a few established AS9100 training providers suggests 2-day internal auditor courses can run anywhere from roughly $1,000 to $1,600+ per seat depending on provider, country, and delivery format — treat this as an illustrative snapshot rather than a sourced market rate, and confirm current pricing directly with the provider before budgeting.

A practical consideration: shops training more than one or two people are generally better served requesting an in-house quote for the whole quality team rather than booking individual seats one at a time — it’s worth comparing against per-seat pricing, and it often means the session gets built around your actual facility’s documentation instead of a generic case study.

Two things push the real cost higher than the course fee alone:

  • Check whether the standard itself is included. Course fees don’t always cover it — if it isn’t, budget separately for your copy.
  • Travel and time away from the floor add up fast for in-person formats — live online delivery can be a practical choice for smaller shops trying to control the total cost.

If your facility hasn’t priced out the full certification path yet — training, gap assessment, documentation, audit fees — that’s worth doing before training in isolation. See the full breakdown of what AS9100 certification actually costs.


Formal Training vs. Alternatives: A Straight Comparison

ApproachWhat You GetBest ForTypical Cost Range
BSI formal training (requirements or internal auditor course)Structured instruction, practical audit exercises, recognized course certificateShops building an internal audit program from scratch or preparing for first-time AS9100 certificationVaries by provider, format, country, and group size — confirm current pricing directly before budgeting
Experience-based route (auditor learns on the job, under an existing certified internal auditor)Practical familiarity, no course feeShops that already have at least one AS9100-experienced auditor on staff to mentor othersTime cost only — no direct training fee
Documentation kit + self-study (no formal course)Templates and structure, but does not by itself establish internal-auditor competenceShops still in the early documentation-build phase, not yet auditingCost of the documentation kit only

If you are preparing for your first AS9100 certification and have no one on staff with prior aerospace QMS audit experience → formal training is one of the strongest ways to build and demonstrate the required auditor competence. Self-study can contribute to that competence, but you’ll need a defensible way to show your internal auditor is capable of planning and conducting effective audits.

If you are already ISO 9001 certified and simply adding the AS9100-specific clauses → your existing internal auditors may only need requirements-level training rather than repeating a full internal auditor course.


The Real Question: What’s the Most Efficient Path to Auditor Competence?

Not every shop needs the same answer. Where you land depends on what competence you already have on staff — not on whether training is generically “a good idea.”

No aerospace experience and no internal audit experience on staff → Formal training is highly valuable here. This is the shop with the least existing competence to draw on, and a structured course is one of the more direct and defensible ways to build it.

Strong QMS experience and already-trained internal auditors, but new to aerospace → Requirements-level training is often the better starting point, not a full internal auditor course. Your team already knows how to audit — they need the aerospace-specific clause knowledge, not a repeat of general auditing fundamentals.

An experienced aerospace auditor already on staff → You may not need to send everyone through the same course. That person can mentor others through the aerospace-specific requirements, and only newer team members may need formal training.

Multiple employees need the same training → Compare public-seat pricing against in-house delivery before booking. In-house sessions built around your own facility’s documentation are often the more efficient option once you’re training more than one or two people.

No mature QMS yet → A gap assessment and requirements-level understanding should come before loading anyone into auditor training. Sending a team through internal auditor training before the documentation exists may mean teaching them to audit against requirements you haven’t fully built out yet.

⚠️ Common mistake: sending a single employee to lead auditor training as a first step, before the shop has even completed its documentation. That course assumes working familiarity with the standard already in place — it’s the wrong entry point for a shop still building its QMS.


The ROI Question: What Training Actually Establishes

BSI AS9100 training and auditor competence comparison showing training knowledge, audit methods, experience, and demonstrated ability
BSI AS9100 training can help build auditor competence, but completing a course does not replace demonstrated auditing ability.

Training helps establish auditor competence — it doesn’t replace the underlying requirement to actually demonstrate that competence. That distinction matters more than the sales pitch usually lets on: an internal auditor doesn’t need a specific course, they need to be genuinely capable of planning and conducting an effective audit, however they got there.

Where training earns its cost is in areas like configuration management, counterfeit parts controls, and first article inspection — areas where generic ISO 9001 knowledge may not transfer cleanly to aerospace-specific requirements. An internal auditor who’s never been walked through these clauses in a structured setting is more likely to miss a gap during their own internal audit, which means the external auditor finds it first.

That said, training doesn’t fix a documentation problem. If your procedures don’t exist yet, sending someone to auditor training won’t create them — it just teaches someone how to audit against requirements you haven’t built out. For many first-time shops, the practical sequence is gap assessment, initial QMS documentation development, targeted training, then internal audits. Requirements-level training can make sense earlier; internal auditor training becomes more valuable once there’s an actual system to audit.

👉 Not sure if your documentation is even ready for an internal auditor to work against? Run the AS9100 Rev D Gap Assessment Checklist first — it takes less than an hour and tells you exactly which of the 12 major sections still need work.


✅ Quick Checklist: Is Your Shop Ready to Book Training?

  • ✅ Your AS9100-specific documentation is drafted, even if not finalized
  • ✅ You’ve identified who will actually conduct internal audits going forward
  • ✅ You know whether you need requirements-level training, internal auditor training, or both
  • ✅ You’ve priced in-house/group rates against individual seat pricing for your team size
  • ✅ You’ve budgeted separately for the standard itself, since course fees typically don’t include it
  • ⚠️ If you can’t check the first two boxes, reconsider booking internal auditor training yet — the timing may be premature
BSI AS9100 training roadmap showing gap assessment, QMS development, targeted training, internal audit, and certification readiness
A practical AS9100 training sequence connects QMS development, targeted training, internal auditing, and certification readiness.

FAQ

Is AS9100 training legally required for certification?

No. AS9100 does not prescribe a specific training provider or course for internal auditors. The organization is responsible for ensuring its auditors are competent to perform effective audits, and IAQG does not specify a particular 9100-series training course as mandatory. Formal training is one common way small shops establish and document that competence, but it isn’t the only path if you already have qualified aerospace audit experience in-house.

How long does BSI’s AS9100 internal auditor course take?

Multi-day formats are standard across the industry for this course level, typically delivered across two to three consecutive days, whether in person or through live online instruction. Confirm current course length and format directly with BSI, since schedules and formats are updated periodically.

Does the training include a copy of the AS9100 standard?

Course inclusions vary by provider and delivery format. Confirm directly with BSI whether the applicable standard is included before enrolling — if not, budget separately for a current copy.

Can one person get trained and cover the whole shop’s internal audit needs?

For a very small operation, one competent internal auditor may be enough, provided the audit program can maintain appropriate objectivity and coverage — auditors generally shouldn’t audit their own work or processes they’re directly responsible for. Larger shops or those with multiple product lines often train two or more people so audits aren’t bottlenecked by one person’s schedule or independence limits.

Is virtual training as effective as in-person for AS9100?

For the requirements-level course, virtual formats work well. For internal auditor training, in-person formats offer more natural opportunities for hands-on practice exercises, though live online formats with interactive workshops are a reasonable substitute if travel cost or time away from the floor is the deciding factor.

Does BSI training count toward recertification of an existing auditor?

Course-to-course requirements vary by prior certification and course provider. If your auditor already holds a credential from a different accredited provider, confirm directly with BSI whether their program requires a re-sit or a full course before enrolling.

What’s the difference between BSI’s requirements course and internal auditor course?

The requirements course teaches what the standard demands, clause by clause. The internal auditor course teaches how to plan, conduct, and report an audit against those requirements — it assumes the requirements-level knowledge already exists.

Is ISOQAR an alternative for AS9100 training?

No — as of publication, ISOQAR does not offer AS9100-specific training courses. For AS9100 training specifically, BSI is the option covered in this review; confirm current course catalogs directly with any provider before enrolling, since offerings can change over time.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching whether formal training makes sense for your shop? Start with the AS9100 Rev D Gap Assessment Checklist to see exactly where your QMS stands before you commit a training budget.

🔹 Ready to move forward with a specific course? Compare BSI’s current AS9100 training course options and request an in-house quote if you’re training more than one person.

🔹 Need the standard itself before class starts? Buy the current AS9100/SAE standard through ANSI Webstore.

🔹 Still deciding on a certification body altogether? See how the major players stack up in AS9100 Certification Bodies — Ranked & Reviewed.

Training is one line item in a much bigger certification budget, and it’s only worth spending on once the rest of your QMS groundwork is in place. Get the sequence right, and training becomes the thing that keeps an auditor from finding a gap your own team should have caught first. At The Standards Navigator, that’s the entire point — clear, practitioner-level guidance on what actually moves the needle toward certification, without the sales pitch.


Stay Ahead of Aerospace Audit Requirements

A common Stage 1 problem isn’t simply misunderstanding AS9100 — it’s discovering that training, documentation, or internal audit readiness isn’t as mature as the organization assumed.

Shops that treat certification as a sequence — documentation, then training, then internal audits — walk into Stage 1 with far fewer surprises than shops that bolt on training as an afterthought once a customer starts asking questions.

The Standards Navigator covers AS9100 certification, training decisions, and aerospace supplier compliance in plain, practitioner-level language — no fluff, no sales pitch.

👉 Get updates on AS9100 certification and aerospace supplier compliance
👉 Be first to access new gap assessment tools and aerospace QMS resources

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

AS9100 Documentation Requirements: What Auditors Actually Check (2026)

This guide breaks down what AS9100 Rev D actually requires in documented information — from first article inspection and traceability records to counterfeit parts prevention and configuration management. It explains which records auditors pull first, where most aerospace suppliers fall short, and how AS9100 documentation differs from a standard ISO 9001 system.

A clause-by-clause breakdown of what your aerospace QMS documentation needs — and where most suppliers fall short

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Documentation Gap That Fails Aerospace Audits

AS9100 documentation requirements cover the documented information needed to operate and demonstrate an aerospace QMS, along with aerospace-specific records and controls in areas such as configuration management, traceability, counterfeit parts prevention, first article inspection, and FOD control. The exact documents and records an organization maintains depend on its processes, applicable requirements, and customer flow-downs.

AS9100 documentation isn’t ISO 9001 paperwork with an aerospace label stuck on it. Traceability records, first article inspection (FAI) data, and configuration management records aren’t background paperwork — auditors use them as objective evidence that aerospace parts were manufactured and controlled according to applicable requirements.

Most suppliers assume a quality manual and a stack of procedures covers it. Then an auditor selects a part number, asks for the traceability record behind its FAI, and finds the two don’t connect — what looked like a minor gap becomes a major nonconformance.

Whether you’re mapping documentation before your first Stage 1 audit or checking an existing system against Rev D, this breaks down exactly what auditors pull first — and where the gaps usually are.

FROM THE SHOP FLOOR: I’ve sat across the table from an AS9100 auditor who skipped the quality manual entirely and went straight for first article inspection records on a part we’d shipped eight months earlier. We had the FAI — what we didn’t have was the linked traceability record showing which material heat lot went into it. That gap alone became a major finding. Auditors aren’t grading your paperwork; they’re testing whether your records actually trace back to the part in front of them.

👉 Most AS9100 documentation gaps don’t surface until an auditor asks for a specific record — by then it’s too late to fix quietly. Run the AS9100 Rev D Gap Assessment Checklist before your next audit and find out exactly where your documentation stands.

In this guide:

  • What AS9100 documented information actually requires — and where it goes beyond ISO 9001
  • Whether you still need a quality manual under Rev D
  • The core records auditors pull first: FAI, traceability, counterfeit parts, FOD
  • Two documentation areas most suppliers underbuild
  • Common findings and how to close them before your audit
  • Where to buy the standard and find training if you’re building this from scratch


👉 Start Here


What “Documented Information” Actually Means Under AS9100

AS9100 Rev D uses the same “documented information” language as ISO 9001 — but the aerospace-specific clauses layer on requirements that don’t exist in a standard ISO 9001 system at all.

AS9100 Rev D does not explicitly require a document called a quality manual. The practical takeaway is that eliminating a document called a “quality manual” does not eliminate the need to document and communicate how your QMS is structured.

Many aerospace organizations continue to use a quality manual because it provides a practical way to describe the QMS and its relationship to the applicable requirements — and it’s the document reviewers commonly use to navigate everything else.

Where AS9100 genuinely goes further than ISO 9001 is in the aerospace-specific documented information requirements: first article inspection, more extensive material and process traceability, counterfeit parts prevention, foreign object debris (FOD) control, and configuration management. None of these have a real equivalent in a baseline ISO 9001 system — see What Is AS9100? for the full standard overview if you’re still mapping out scope.

If you’re building this documentation structure from scratch rather than adapting an existing ISO 9001 system, the ISO Documentation Kits for Manufacturers page is a reasonable starting point for the underlying procedures and forms — just plan to adapt anything generic to AS9100’s aerospace-specific requirements before relying on it for certification.


AS9100 documentation requirements showing an aerospace auditor reviewing FAI, traceability, counterfeit parts prevention, FOD control, and process records
AS9100 documentation requirements include objective evidence showing that aerospace parts and processes were controlled as required.

The Core Records Auditors Pull First

First Article Inspection Records

A common audit approach is to select a specific part number and request the FAI record supporting it, along with the traceability behind it. FAI reporting itself is governed by AS9102, published by SAE International. Full requirements — including what counts as a valid FAI and when a re-FAI is triggered — are covered in First Article Inspection Requirements.

Traceability Records

Traceability records should allow applicable material, batch/lot, and process information to be traced through the product lifecycle to the shipped part, based on the organization’s processes and applicable requirements — not just exist as separate records. See AS9100 Traceability Requirements for what Clause 8.5.2 actually demands.

Counterfeit Parts Prevention Records

Documented controls for counterfeit parts prevention are required under Clause 8.1.4 — and auditors check whether they’re actually followed, not just written. Full breakdown in AS9100 Counterfeit Parts Standards.

FOD Control Records

AS9100 expects documented controls and evidence appropriate to the organization’s processes for preventing foreign object debris — the specific form that takes varies by operation. See FOD Control Standards for what Clause 8.5.4 requires.

A recurring pattern I’ve seen: these four record types exist independently but aren’t cross-referenced. An auditor pulls an FAI, asks for the traceability record behind it, and finds no clear link between the two documents — even though both technically exist. In practice, that kind of disconnect often draws more scrutiny than a missing document, because it suggests the system isn’t actually being used to trace parts, just to generate paperwork.

The Audit Trail: Part Number → Revision → Material Lot → Process Route → FAI → Final Record

An auditor doesn’t just want to see that each record in that chain exists individually. They want to see how the records relate to each other and to the specific part in front of them. (This makes a strong visual for the published page — worth building as a simple graphic rather than just text.)

👉 If your traceability records and FAI paperwork don’t reference each other by part number and revision, that’s a gap worth closing before an audit tests it. Download the Manufacturing Compliance Checklist and confirm your records connect.

AS9100 documentation requirements audit trail showing part number, drawing revision, material heat lot, process routing, FAI, and shipped product
AS9100 documentation requirements connect the part number, revision, material, process, inspection, and final shipment into a traceable audit trail.

Two Documentation Areas Most Suppliers Underbuild

Configuration Management Documentation (Clause 8.1.2)

Configuration management — tracking exactly which design revision, engineering change, and customer-approved deviation applies to a given part — gets far less attention than FAI or traceability, but auditors increasingly check it as a standalone item. If your documentation doesn’t clearly show which configuration was in effect at the time of manufacture, that’s a gap worth closing before it becomes a finding. This is dense enough to deserve its own dedicated breakdown — flagging it here as a topic to watch.

Risk-Based Documentation for Special Processes

Special processes — such as welding, heat treating, and nondestructive testing — carry their own documented risk requirements under AS9100’s risk-based thinking clauses. Nadcap accreditation may apply separately when required by a customer or applicable supply-chain requirements; that accreditation question is covered in NADCAP vs AS9100. The documentation angle specifically — how you document special-process risk decisions, distinct from whether you’re Nadcap-accredited — is underserved content-wise and worth a dedicated piece.


How AS9100 Documentation Differs from ISO 9001

CategoryISO 9001AS9100
Quality ManualNot explicitly mandatedNot explicitly mandated, but commonly used in practice
First Article InspectionNo aerospace-specific FAI requirementIncorporated through AS9100 and applicable customer requirements; AS9102 (SAE) governs FAI reporting
TraceabilityGeneral requirement, scope flexibleMore extensive material/process traceability, including customer- and product-specific requirements where applicable
Counterfeit Parts PreventionNo equivalent requirementDocumented controls required (Clause 8.1.4)
Configuration ManagementNo equivalent requirementRequired (Clause 8.1.2)
FOD ControlNo equivalent requirementDocumented controls and evidence appropriate to the organization’s processes and applicable requirements

For the full standard-by-standard comparison beyond documentation specifically, see AS9100 vs ISO 9001.

👉 Building this documentation structure without a consultant is realistic — but only if you’re working from the current edition. Buy the AS9100 Rev D standard through ANSI Webstore and use code CC2026 for 5% off.


What Happens When Documentation Doesn’t Hold Up

A documentation gap doesn’t automatically fail an audit — but an auditor who finds one disconnected record set often digs deeper, and what started as a single finding turns into a pattern of findings across the whole system. That’s the real cost: not the first gap, but what it triggers.

The cost objection: it’s fair to wonder whether this level of documentation rigor is overkill for a small shop with a handful of part numbers. When FAI and traceability requirements apply, a five-person shop and a five-hundred-person supplier may need to maintain the same core record types for a given part number; the difference is the complexity of the system used to manage them.

If you’re deciding whether your existing system is ready, AS9100 Internal Audit Process walks through running that check yourself before a registrar does it for you. And if you haven’t picked a certification body yet, AS9100 Certification Bodies — Ranked & Reviewed is a good next stop — worth confirming the body you choose is itself accredited by a recognized accreditor such as ANAB.

In practice, traceability is a significant part of aerospace QMS auditing because auditors need objective evidence that product and process records can be connected to the requirements they support.


Quick Documentation Checklist

✅ Quality manual (or equivalent scope document) references all applicable Rev D clauses

✅ FAI records exist and cross-reference traceability records by part number and revision

✅ Traceability records identify applicable material heat/lot/batch information for shipped parts, based on customer, product, and process requirements

✅ Documented controls for counterfeit parts prevention are in place and actively followed, not just written

✅ FOD controls are documented and supported by evidence appropriate to the organization’s processes and applicable requirements

✅ Configuration management records show which design revision applied at time of manufacture

✅ Special process records (welding, heat treat, NDT, etc.) are retained per customer and registrar requirements


AS9100 documentation requirements showing the difference between controlled documents and records used as objective audit evidence
AS9100 documentation requirements distinguish controlled information from records that provide objective evidence processes were performed.

FAQ

Is a quality manual required under AS9100 Rev D?

Not explicitly by the standard’s own wording — but many aerospace organizations continue to use one because it provides a practical way to describe the QMS and map it to the standard’s structure. Skipping it entirely can create more audit friction than it saves in paperwork, since certification bodies commonly expect some document that fills that role.

What documents does an AS9100 auditor ask for first?

A common audit approach is to select a specific part number and request the first article inspection record supporting it, followed by the traceability record behind that FAI. Auditors use this pairing to test whether your documentation system actually connects, not just exists.

What’s the difference between documented information and records under AS9100?

Documented information is the broader AS9100 term covering anything required to be created, maintained, and controlled — procedures, work instructions, and forms all count. Records are a specific type of documented information that provide evidence of results, like a completed FAI or a calibration record. Every record is documented information, but not everything documented is a record.

How long do AS9100 records need to be retained?

Retention periods vary by customer contract and registrar requirement rather than a single fixed AS9100 rule — many aerospace customers require retention well beyond typical ISO 9001 timeframes, sometimes for the life of the program. Check your specific customer flow-down requirements rather than assuming a default period applies.

Do I need separate documentation for each customer?

Not necessarily separate systems, but you likely need customer-specific supplemental requirements layered onto your core AS9100 documentation — most aerospace OEMs have their own flow-down requirements beyond the base standard.

What is a common AS9100 documentation finding?

One recurring documentation problem is records that exist individually but aren’t cross-referenced — an FAI with no linked traceability record, or a traceability record that doesn’t tie back to the part it supports. The documents technically exist; they just don’t function as a connected system.

Can I use the same documentation system for ISO 9001 and AS9100?

Largely yes for the shared core structure, but AS9100-specific records (FAI, counterfeit parts prevention, configuration management, FOD control) have no ISO 9001 equivalent and need to be built as additions, not substitutions.

Do I need software to manage AS9100 documentation, or can spreadsheets work?

Spreadsheets can work for a small shop with limited part numbers, but the risk grows with volume — the more parts and revisions you’re tracking, the easier it becomes for records to silently disconnect from each other, which is the exact failure pattern auditors catch most often.

How much documentation does a small aerospace supplier actually need?

The same core record types as a larger supplier — a small shop doesn’t get a reduced list of required records. What differs is the complexity of the system used to manage them; a simpler operation can often meet the same requirements with a leaner, more manual system than a high-volume supplier needs.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching what AS9100 documentation actually requires? Start with What Is AS9100? for the full standard overview.

🔹 Ready to build your documentation structure? Buy the current AS9100 Rev D standard through ANSI Webstore — you can’t build compliant documentation from an outdated edition.

🔹 Need training to get your team up to speed? BSI Group’s AS9100 training courses cover documentation requirements clause by clause.

🔹 Want a professional gap assessment first? Download the free AS9100 Rev D Gap Assessment Checklist.

Documentation is where AS9100 audits are actually won or lost — not in the quality manual, but in whether your records connect to the parts they’re supposed to trace. Get the structure right from the beginning, and maintaining audit-ready evidence becomes far easier. That’s the standard The Standards Navigator holds every AS9100 guide to.


Stay Ahead of Your Next AS9100 Audit

Most aerospace suppliers don’t fail audits because they lack documentation — they fail because their documentation doesn’t connect. FAI records that don’t reference traceability. Traceability that doesn’t tie to configuration. Individually complete, collectively disconnected.

Suppliers who struggle treat documentation as a checklist exercise, built once and left alone. Suppliers who succeed build cross-referencing into every record from day one, so nothing has to be reconstructed under audit pressure.

The Standards Navigator covers AS9100 implementation for aerospace suppliers building audit-ready quality systems from the ground up.

👉 Get updates on AS9100 and aerospace compliance

👉 Be first to access new gap assessment checklists and documentation templates

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

AS9100 Certification Bodies: Ranked & Reviewed (2026)

Not every AS9100 certification body brings the same aerospace expertise to an audit. This guide breaks down what AS9100 accreditation actually requires, which certification bodies are active in the space, and the questions to ask before signing with a registrar.

Comparing accredited AS9100 registrars — what to look for, what to avoid, and which body fits your operation

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Choosing the Wrong Registrar Costs More Than the Audit

Not all AS9100 certification bodies operate the same way. Some assign a dedicated aerospace lead auditor who understands configuration management and counterfeit parts controls on sight. Others rotate generalist auditors who spend half of Stage 1 relearning your industry — and bill you for the education.

A certificate issued by an appropriately accredited certification body is intended to demonstrate conformity to the same AS9100 requirements, regardless of which body issues it. What can differ significantly is the accreditation scope, auditor expertise, scheduling, audit experience, customer acceptance, and overall certification experience. For a supplier chasing a Tier 1 customer deadline, that difference is real money and real risk.

If you’re comparing registrars for the first time, this guide breaks down what accreditation actually means, which bodies are active in the AS9100 space, and how to evaluate quotes so you’re not choosing on price alone. If you’re already certified and evaluating a switch, the sections on auditor consistency and surveillance cadence will matter most to you.

From the floor: I’ve sat through registrar selection more than once at a heavy industrial manufacturing operation — comparing quotes side by side, all technically accredited, all wildly different in price and turnaround. The number that mattered wasn’t the quote total. It was how the registrar answered questions about auditor aerospace experience, how they’d handle surveillance-audit continuity year over year, and what their process looked like if a Stage 2 audit turned up a major finding. One bidder had clearly never audited anything with configuration management or counterfeit-parts controls in scope, and it showed the moment we started asking specifics. That’s the conversation that should happen before you sign, not the one that happens after your first nonconformance over something your auditor didn’t understand.

Before you request quotes, run a clause-by-clause gap check. Most organizations don’t get burned by picking the wrong registrar — they get burned by walking into Stage 1 not knowing where their gaps are. → AS9100 Rev D Gap Assessment Checklist — 74 items, clause-by-clause, built for aerospace suppliers preparing for certification.


In This Guide

  • What AS9100 accreditation actually requires
  • How to verify a registrar is legitimately accredited
  • What separates a good aerospace auditor from a generalist
  • How these certification bodies were evaluated, and which fit different supplier profiles
  • Questions to ask before signing a registrar contract
  • Cost and timeline expectations by registrar type
  • What to do after you select a certification body


👉 Start Here (Top Resources)

👉 Get the official AS9100 Rev D standard before you approach any registrar → AS9100 / SAE Standards — ANSI Webstore

👉 Get your team trained on AS9100 requirements ahead of Stage 1 → BSI Group AS9100 Training

👉 Run a clause-by-clause gap check before requesting quotes → AS9100 Rev D Gap Assessment Checklist


What Does AS9100 Accreditation Actually Mean?

AS9100 certification isn’t something any registrar can simply decide to offer. Certification bodies (also called registrars or CBs) must hold appropriate accreditation and scope to issue an accredited AS9100 certificate — meaning an independent accreditation body has verified the CB is competent to audit against the standard.

For AS9100 specifically, that accreditation runs through a recognized national accreditation body — in the U.S., ANAB accredits more AS9100 certification bodies than any other accreditation body, though it isn’t the only IAF-recognized option (IAS is also recognized). Accreditation is evaluated against ISO/IEC 17021-1 plus the aerospace-specific IAQG 9104-series requirements developed by the International Aerospace Quality Group (IAQG). Holding ISO 9001 accreditation does not automatically mean a certification body also holds AS9100 accreditation — the two are evaluated and scoped separately, and a registrar without current AS9100 accreditation scope cannot issue an accredited AS9100 certificate that meets the applicable certification-scheme requirements, regardless of how experienced their auditors sound on a sales call.

This matters because a certificate from a body without properly scoped accreditation isn’t just a paperwork issue — it may not satisfy your customer’s supplier-qualification requirements, potentially costing you both certification time and audit expense.

For background on what the standard itself requires before you get to registrar selection, see What Is AS9100? and AS9100 vs ISO 9001.


How to Verify a Registrar Is Legitimately Accredited

Don’t take a sales rep’s word for current AS9100 scope. Verify it directly:

1. Check the OASIS database. The IAQG OASIS Certified Supplier Directory is the official record of AS9100-certified organizations and the certification bodies that issued their certificates. If a registrar’s certifications aren’t showing up in OASIS, that’s a serious red flag.

2. Confirm current accreditation scope directly with the accreditation body. ANAB accredits more AS9100 certification bodies in the U.S. than any other accreditation body and publishes which certification bodies hold active accreditation and what scopes each one covers — some registrars are accredited for aerospace manufacturing but not for MRO (AS9110) or distribution (AS9120). If a registrar cites a different IAF-recognized accreditation body, confirm that body’s scope listing directly rather than assuming it’s equivalent to ANAB’s.

3. Ask what your accredited scope actually covers. Rather than asking whether a registrar covers a specific code, ask: “What is your current accredited AS9100 scope, and does it cover the activities, products, and industry sector included in my proposed certification scope?” Have the registrar confirm the applicable industry and technical scope classifications directly — don’t assume a single code number settles the question.

4. Ask for the accreditation certificate, not a logo on a website. A registrar’s marketing page listing “AS9100 Accredited” isn’t proof — request the actual accreditation certificate showing current scope and expiration.

⚠️ Most common finding: Suppliers under customer pressure sometimes select a registrar based on price and turnaround time alone, without confirming current AS9100 scope in detail — then discover during Stage 2 that a scope gap means the certificate won’t satisfy their customer’s supplier requirements.


What Separates a Good Aerospace Auditor From a Generalist

AS9100 certification bodies review with an auditor examining a first article inspection report beside a precision aerospace component
Choosing the right AS9100 certification bodies means looking beyond the certificate to auditor experience and aerospace expertise.

AS9100 auditors need aerospace-specific fluency that a generalist ISO 9001 auditor may not have. This is the criteria worth keeping in mind as you read the comparisons below — it’s the difference that actually separates certification bodies in practice once you’ve confirmed that the appropriate accreditation and scope are in place. When evaluating a registrar, ask specifically about auditor experience in:

  • Configuration management — Clause 8.1.2’s requirements go well beyond typical ISO 9001 document control
  • Counterfeit parts prevention — Clause 8.1.4 requires audit-ready evidence most non-aerospace auditors have never evaluated
  • First article inspection (FAI) — auditors unfamiliar with the AS9102 forms published by SAE International will struggle to evaluate your FAI records meaningfully
  • Special processes and traceability — Clause 8.5.2 traceability requirements are more stringent than general manufacturing

If you are preparing for your first AS9100 certification → confirm the specific auditor assigned to your account has aerospace industry audit hours, not just AS9100 training credentials. Ask the registrar directly; reputable ones will tell you.

For a deeper look at the traceability and counterfeit-parts requirements auditors will actually test against, see AS9100 Traceability Requirements and AS9100 Counterfeit Parts Standards.


How These Certification Bodies Were Evaluated

Before comparing specific bodies, here’s the criteria behind the categories below:

  • AS9100 accreditation status and scope
  • Aerospace auditor availability and depth of aerospace-specific experience
  • Geographic coverage and multi-site capability
  • Ability to combine AS9100 audits with ISO 9001, ISO 14001, or other management-system audits
  • Fit for different supplier types — manufacturers, MRO organizations, distributors
  • Scheduling flexibility and certification-cycle support

These are editorial recommendations based on accreditation scope, aerospace specialization, geographic coverage, multi-standard capability, and fit for different supplier profiles — not customer satisfaction scores, audit outcome data, or any undisclosed commercial relationship. Always verify current accreditation status yourself through OASIS and ANAB before requesting quotes.


AS9100 Certification Bodies Worth Comparing

The six bodies below are established, accredited names in aerospace quality certification worth including in your quote comparison — not a claim that they’re the only six, or objectively the “best” six, available. Dozens of ANAB-accredited bodies issue AS9100 certificates. Always verify current scope through OASIS before signing with any registrar.

If you already have a strong sense of which profile matches your operation → skip to that category below rather than reading all six in order.

AS9100 certification bodies compared by aerospace focus, multi-site operations, manufacturing, and industrial certification needs
AS9100 certification bodies serve different operational needs, from aerospace-focused suppliers and multi-site operations to combined industrial certification.

Best Overall for Multi-Standard Aerospace Suppliers: BSI Group

Why I’d consider them: BSI certifies against a very wide range of standards — AS9100 alongside ISO 9001, AS9110, AS9120, ISO 14001, and most other major management-system standards. If your operation is pursuing more than one certification, or expects to add standards later, that breadth means fewer registrar relationships to manage over time. Ask specifically whether your account would be assigned one lead auditor across all standards or separate auditors per standard — that affects both cost and consistency.

Best for Aerospace-Focused Certification Experience: Perry Johnson Registrars (PJR)

Why I’d consider them: PJR maintains multiple international accreditations (ANAB, UKAS, JAB) and markets a dedicated aerospace audit staff. For a supplier whose top priority is an auditor who won’t need aerospace concepts explained from scratch, this is worth a direct conversation about auditor assignment. Ask for the assigned auditor’s aerospace sector history before you sign, not after.

Best for Manufacturers Entering Aerospace Supply Chains: NSF-ISR

Why I’d consider them: NSF-ISR has a strong general manufacturing and industrial certification presence. For a fabricator or machine shop pursuing AS9100 for the first time as a new aerospace supplier, a registrar with broad industrial-certification familiarity alongside aerospace scope can be a comfortable entry point. Ask how many first-time AS9100 clients they’ve certified in the past year — that experience matters more than tenure alone for a first certification.

Best for Global or Multi-Site Operations: DEKRA Certification

Why I’d consider them: DEKRA’s global reach and integrated auditing across multiple management-system standards make them worth considering for suppliers with international sites. If multi-site consistency is a priority, ask specifically how auditor assignment and certification scope will be coordinated across locations — that coordination is where multi-site certifications most often run into trouble.

Best for Defense and Marine-Adjacent Aerospace: ABS Quality Evaluations

Why I’d consider them: ABS has a long-standing presence in industrial and aerospace certification, with particular relevance for suppliers whose work overlaps defense or marine-adjacent aerospace segments. Ask directly whether their auditor pool has experience with your specific product category — defense-adjacent scope can carry additional documentation expectations worth confirming up front.

Best for Combined Aerospace and Industrial-Process Certification: DNV

Why I’d consider them: DNV brings deep process-industry audit experience alongside aerospace capability — a reasonable fit for suppliers whose certification needs span both aerospace and broader industrial processes. Ask whether a combined audit across your process and aerospace scopes is possible in a single visit, since that’s where DNV’s dual background can actually save audit days.

At a glance:

Best ForCertification Body
Multi-standard aerospace suppliersBSI Group
Aerospace-focused certification experiencePerry Johnson Registrars (PJR)
Manufacturers entering aerospace supply chainsNSF-ISR
Global or multi-site operationsDEKRA Certification
Defense and marine-adjacent aerospaceABS Quality Evaluations
Combined aerospace and industrial-process certificationDNV

For training — as distinct from certification itself — BSI also offers AS9100-specific coursework covering requirements, internal auditing, and lead auditor preparation.

→ Auditors move faster through Stage 1 when your internal team already knows the standard cold: BSI Group AS9100 Training

For a broader comparison of certification bodies across ISO standards generally — not aerospace-specific — see Best ISO Certification Bodies.


Questions to Ask Before You Sign

Bring these ten questions into every registrar call:

✅ What is your current accredited scope for AS9100, and does it cover the activities, products, and industry sector included in my proposed certification scope? (For U.S. certification bodies, confirm the applicable scope through ANAB.)
✅ Who will be the lead auditor assigned to my account, and what aerospace sectors have they audited?
✅ Will the same auditor normally return for surveillance audits, or should I expect rotation?
✅ How many aerospace-specific audits has my assigned lead auditor conducted in the past 12 months?
✅ What is your typical Stage 1 to Stage 2 turnaround time, and what is the planned audit duration?
✅ What happens if my assigned auditor becomes unavailable close to the scheduled audit date?
✅ What is included in the quoted price — are travel expenses included or billed separately?
✅ What is your nonconformance grading criteria, and what happens if Stage 2 produces a major finding?
✅ How are audit-day schedule changes typically handled?
✅ Can my certificate scope accommodate future expansion — additional sites, products, or standards?

AS9100 certification bodies comparison as an operations manager reviews registrar questions before signing
Compare AS9100 certification bodies carefully before signing, including accreditation, aerospace experience, audit approach, cost, and NCR handling.

If you are under customer pressure to certify quickly → prioritize registrars with confirmed availability in your timeframe over the lowest quote. A registrar that can’t schedule Stage 1 for four months doesn’t help you meet a customer deadline, regardless of price.


Cost and Timeline: What to Expect

These are planning ranges, not fixed market prices. Actual AS9100 certification fees depend on employee count, number of sites, audit complexity, applicable scope, operational complexity, shift structure, travel, audit days required, and whether other management systems are audited together.

FactorTypical Planning RangeNotes
Stage 1 + Stage 2 audit fees$8,000–$18,000Varies by facility size, employee count, and site complexity
Annual surveillance audits$3,000–$7,000 per yearRequired to maintain certification between three-year recertification cycles
Recertification audit$6,000–$12,000Every three years, comparable in scope to initial certification

Ask any registrar directly whether combining AS9100 with an existing ISO 9001 or ISO 14001 audit could reduce total audit days — this varies by registrar and by how your existing certifications are scheduled, so get it confirmed in your specific quote rather than assuming a standard discount applies.

On timeline: the 3–6 month range you’ll often hear for “registrar selection to certificate issuance” assumes your QMS is already substantially implemented and you’re simply at the registrar-selection and audit-scheduling stage. It is not a full AS9100 implementation timeline. If you’re starting without an existing QMS, expect considerably longer — see AS9100 Implementation Timeline for phase-by-phase ranges depending on your starting point.

For a full breakdown of certification costs beyond registrar fees — internal audit prep, documentation, and consulting — see How Much Does AS9100 Certification Cost?.


Common Mistakes When Selecting a Registrar

Choosing on price alone. The cheapest quote often reflects less aerospace-specific auditor experience, not efficiency. A registrar that costs more but assigns a dedicated aerospace lead auditor typically pays for itself in fewer findings and less audit-day confusion.

Not confirming scope in detail before signing. As covered above — AS9100 accreditation doesn’t automatically cover AS9110 (MRO) or AS9120 (distribution). If your business spans more than one, confirm scope for each. See AS9110 vs AS9120 if you’re uncertain which applies to your operation.

Assuming certification body and consultant can be the same entity. Certification bodies must maintain impartiality, and accredited certification activities are subject to strict rules governing consulting and conflicts of interest. A certification body should not be building the QMS it is then responsible for certifying. If a “certification body” is offering to build your documentation and then certify you, ask directly how that’s structured to avoid a conflict.

Ignoring auditor turnover history. Ask how long auditors typically stay assigned to accounts. Frequent auditor rotation means re-explaining your operation’s context every surveillance cycle.


What to Do After You Select a Certification Body

Step 1 — Confirm scope and schedule your Stage 1 readiness review. Most registrars offer an optional pre-assessment to catch major gaps before the audit clock starts.

Step 2 — Run your internal gap assessment first. Don’t walk into a pre-assessment blind. → AS9100 Rev D Gap Assessment Checklist

Step 3 — Address FAI, traceability, and counterfeit parts documentation early. These are the areas generalist QMS documentation most often misses. See First Article Inspection Requirements and FOD Control Standards.

Step 4 — Close the knowledge gap before Stage 1, not during it. An auditor testing your team on requirements they’ve never formally learned is one of the most avoidable sources of Stage 1 findings. → BSI Group AS9100 Training


FAQ

Can any ISO 9001 certification body also certify AS9100?

Not automatically. A registrar must hold separate, specific accreditation for AS9100 through ANAB (or an equivalent IAF-recognized accreditation body), evaluated against ISO/IEC 17021-1 plus the IAQG 9104-series requirements. ISO 9001 accreditation does not automatically extend to AS9100 — the two are scoped and evaluated separately.

How do I verify a certification body is actually accredited for AS9100?

Check the IAQG OASIS Certified Supplier Directory, which lists certified organizations and the registrars that issued their certificates, and confirm current scope directly with ANAB. Don’t rely solely on a registrar’s own marketing claims.

Is the cheapest registrar always the wrong choice?

Not automatically — but a significant price gap usually reflects a difference in auditor aerospace experience, scheduling flexibility, or accreditation scope. Compare quotes on auditor qualifications and turnaround time, not just the number.

Do I need a different registrar for AS9100, AS9110, and AS9120?

Not necessarily the same body, but you do need separate accreditation scope confirmed for each standard you’re certifying against, since they cover different operations — manufacturing, MRO, and distribution respectively. See AS9110 vs AS9120 for the distinction.

Can I switch certification bodies mid-cycle if I’m unhappy with my current one?

Yes, though timing matters — most organizations switch at their three-year recertification point rather than mid-cycle, since transferring an active certificate involves a transfer audit process. Talk to your prospective new registrar about transfer procedures before your current cycle ends.

Does a certification body also provide consulting or documentation help?

Generally, no — accredited certification bodies are subject to impartiality rules that treat consulting on your QMS documentation as a conflict of interest with certifying that same QMS. For documentation support, work with a separate consultant or a documentation kit, then bring an independent registrar in for certification.

How long does AS9100 certification take once I’ve selected a registrar?

If your QMS is already substantially implemented, expect roughly 3–6 months from signing with a registrar to certificate issuance, depending on internal readiness and registrar scheduling availability. This is the certification phase only — it doesn’t include building a QMS from scratch. See AS9100 Implementation Timeline for full phase-by-phase ranges depending on your starting point.

What happens if my registrar’s AS9100 accreditation scope doesn’t cover my activities or products?

Your certificate may not satisfy customer supplier-qualification requirements even if the audit itself goes well. Confirm that the certification body’s accredited scope covers the activities and products included in your proposed certification scope before signing, not after certification.


📥 Free Resources

AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification

ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements

ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system

Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments

Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts


Not Sure What to Do Next?

🔹 You’re still researching registrar options → What Is AS9100? → AS9100 vs ISO 9001 → Aerospace Supplier Compliance Standards

🔹 You’re ready to request registrar quotes → Run your gap assessment first → AS9100 Rev D Gap Assessment Checklist

🔹 You need your team trained before Stage 1 → BSI Group AS9100 Training

🔹 You still need to buy the official AS9100 Rev D standard → AS9100 / SAE Standards — ANSI Webstore

🔹 You want to understand certification costs and timeline first → How Much Does AS9100 Certification Cost? → AS9100 Implementation Timeline


The Registrar You Choose Is Part of Your Quality System

Certification is not a one-time transaction — it’s a multi-year relationship with surveillance audits every year and recertification every three. Choosing an accredited body with genuine aerospace auditor experience, transparent scope, and consistent auditor assignment saves far more over that relationship than a lower first-year quote.

At The Standards Navigator, complex standards are translated into practical, real-world guidance you can act on.

Aerospace suppliers don’t fail audits because the requirements are a mystery — they fail because they picked a registrar that didn’t understand their industry, or walked into Stage 1 without a real gap assessment behind them.

Organizations that treat registrar selection as a checkbox end up re-explaining their operation to a new auditor every surveillance cycle. Organizations that vet accreditation scope and auditor experience up front build a certification relationship that gets faster and smoother every year.

At The Standards Navigator, aerospace compliance gets the same clause-level treatment as everything else on this site — no fluff, no generic advice.

👉 Get updates on AS9100 certification, audits, and aerospace supply chain compliance
👉 Be first to access new gap assessment tools and aerospace-specific guides

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

ISO 45001 vs ISO 50001: Which Safety and Energy Management Standard Does Your Operation Actually Need? (2026 Guide)

This guide compares ISO 45001 and ISO 50001 for manufacturers weighing safety versus energy management certification. It breaks down clause structure, standard pricing, certification triggers, and the most common mistakes teams make pursuing either standard. It also covers when facilities genuinely need both certifications versus when sequencing one after the other makes more sense.

How manufacturers decide between occupational safety and energy management certification

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Two Certifications, Two Very Different Problems

A plant manager doesn’t usually confuse safety and energy management. But when both show up on the same certification roadmap — often because a customer, insurer, or corporate sustainability mandate is pushing for both — the ISO 45001 vs ISO 50001 decision starts to feel more complicated than it actually is.

They don’t overlap much at all.

ISO 45001 exists to keep people from getting hurt. ISO 50001 exists to make sure your facility isn’t wasting energy it’s paying for. Both are voluntary management system standards. Both follow the same high-level structure. Both can be certified by an accredited registrar, resulting in a certificate you can put on a wall or a bid package. Past that, they’re solving two separate problems with two separate data sets, two separate risk registers, and — in most facilities — two separate teams.

From the Floor: I’ve sat in enough capital planning meetings to know that energy costs get treated as a fixed line item until someone forces the conversation — usually a spike in the utility bill or a customer asking about carbon reporting. In a fabrication environment, the big draws are exactly what you’d expect: compressed air systems, welding equipment, and cure ovens for coatings work. None of that gets measured systematically unless something formal requires it. That’s the gap ISO 50001 is built to close — not safety incidents, but the slow bleed of energy nobody’s tracking.

If you’re deciding whether your operation needs one of these standards, both, or neither yet, the fastest way through this decision is a structured gap check — not guesswork.

👉 Get the Manufacturing Compliance Checklist — Before you commit budget to either certification, run your operation against the core ISO, OSHA, and quality requirements that apply to production environments. Most teams find gaps in under 45 minutes.


In This Guide

  • What ISO 45001 and ISO 50001 actually cover
  • Quick answer: which standard fits which situation
  • Certification requirements, clause structure, and cost side by side
  • Who typically needs both
  • Common mistakes when pursuing either standard
  • Where to buy the standards and get training


👉 Start Here: Top Resources


Quick Answer: ISO 45001 vs ISO 50001

QuestionISO 45001ISO 50001
What it managesWorker health and safety riskEnergy performance and consumption
Core outcomeFewer injuries and incidentsImproved energy performance
Who typically drives itEHS / safety managerFacilities / energy manager, sometimes operations
Typical triggerCustomer requirement, insurance, incident historyUtility cost pressure, sustainability reporting, energy regulation
Legally mandatory?No — voluntary, though some contracts require itNo — voluntary, though some supply chains require it

If your driving concern is incidents, near-misses, or a customer asking about your safety program, that’s ISO 45001. If your driving concern is a utility bill that keeps climbing or a customer sustainability questionnaire, that’s ISO 50001. Many facilities don’t need to pursue both in the same certification cycle unless a specific contract or corporate mandate is forcing it.


What ISO 45001 Actually Requires

ISO 45001:2018 is the international standard for occupational health and safety (OH&S) management systems. It replaced OHSAS 18001 and is built on the same Annex SL high-level structure used across ISO 9001 and ISO 14001, which is one reason facilities already certified to those standards tend to find ISO 45001 implementation faster. ISO maintains the official scope and summary of the standard at iso.org, though that summary doesn’t substitute for the full requirements text you’ll need for actual implementation.

The standard requires organizations to identify hazards, assess OH&S risk, set objectives for reducing that risk, and demonstrate continual improvement — all under the same Plan-Do-Check-Act cycle used across the ISO management system family. It puts specific weight on worker participation and consultation, which is a heavier emphasis than most legacy safety programs are built around. OSHA’s own recordkeeping and general duty clause requirements, published at osha.gov, remain the regulatory floor in the U.S. regardless of whether a facility pursues ISO 45001 certification — the standard sits on top of that floor, not in place of it.

Most common finding: Facilities that already run a documented OSHA program tend to underestimate how much additional documentation ISO 45001 requires around worker consultation and leadership accountability — those clauses go beyond what OSHA compliance alone typically covers.


What ISO 50001 Actually Requires

ISO 45001 vs ISO 50001 article graphic showing an ISO 50001 energy performance dashboard, EnPI tracking, energy baseline, and continual improvement
ISO 45001 vs ISO 50001: ISO 50001 focuses on measuring and improving energy performance through energy baselines, EnPIs, targets, and continual improvement.

ISO 50001:2018 received the 2024 climate-action amendments, which added climate-change considerations to the management system’s context and interested-party requirements. That’s an amendment to the existing 2018 edition, not a new edition of the standard. The core structure hasn’t changed: establish an energy baseline, set energy performance indicators (EnPIs), and demonstrate measurable, continual improvement in energy performance — not just improvement in your management processes, but in your actual energy numbers.

From the Floor: In heavy fabrication, energy conversations rarely start with “let’s implement an energy management system.” They start with a compressor that runs unloaded all weekend, a cure oven that sits at temperature between jobs, or a welding bay where nobody has ever assigned energy consumption to the process. ISO 50001 gives operations a framework for turning those observations into measurable energy performance decisions instead of hallway complaints about the utility bill.

That’s the detail that trips people up. ISO 45001 doesn’t require you to hit a specific injury rate — it requires you to manage the system that reduces risk. ISO 50001 is more demanding on demonstrated energy performance: the standard requires organizations to establish, implement, maintain, and continually improve the EnMS while demonstrating improvement in energy performance. You can’t satisfy the standard with paperwork alone if your energy use isn’t actually trending in the right direction. The U.S. Department of Energy publishes separate technical guidance at energy.gov for organizations building out energy baselines and performance indicators, which can be a useful supplement alongside the standard itself.

An energy performance indicator (EnPI) is simply the metric you use to prove the trend is real — something like kWh per production unit, kWh per ton of material processed, energy consumption per operating hour, or energy consumption per batch. Pick a metric tied to actual output rather than relying solely on total facility consumption, because seasonal swings and production-volume changes can distort the picture.

👉 Setting up your first EnPI baseline without guidance is where most ISO 50001 implementations stall out. ISO 50001 Training from BSI and ISO 50001 Training from ISOQAR both cover EnPI methodology from the ground up, not just the paperwork.

If you are already tracking utility costs by building or by process line → you have the foundation ISO 50001 auditors expect to see; if you’re not, that’s the first gap to close before pursuing certification.


Clause Structure and Certification Cost Comparison

CategoryISO 45001:2018ISO 50001:2018
Structure10 clauses, Annex SL high-level structure10 clauses, Annex SL high-level structure
Core requirementManage OH&S risk, reduce injury/illnessEstablish EnPIs, demonstrate energy performance improvement
Standard PDF price$321.00 list / $256.80 ANSI member$293.00 list / $234.40 ANSI member
Typical driverCustomer/insurance requirement, incident historyUtility cost, sustainability reporting, energy regulation
Owning departmentEHS / SafetyFacilities / Energy / sometimes Operations

ANSI Webstore prices checked August 2026; prices may change — confirm current pricing before budgeting.

Standard purchase price is one line item — implementation and audit costs are the larger investment for either standard. For a full breakdown of ISO 45001 certification, audit, and implementation costs, see our ISO 45001 cost guide. Before selecting a registrar for either standard, verify their scope of accreditation through ANAB (anab.ansi.org) or IAF (iaf.nu) — not every accredited certification body carries scope for both OH&S and energy management audits.

If you’re evaluating both standards for your facility, check whether the ANSI bundle option covers both — compare the bundle price against purchasing each standard separately before you check out.


Do You Need Both?

Manufacturers typically don’t pursue ISO 45001 and ISO 50001 in the same cycle unless one of three things is happening:

  1. A major customer’s supplier scorecard requires both safety and energy management certification.
  2. Corporate ESG or sustainability reporting is pulling energy data into the same governance structure as safety data.
  3. The facility already holds ISO 9001 and/or ISO 14001 and is expanding its integrated management system to cover the full Annex SL family.

⚠️ If none of those apply to you right now, chasing both standards in the same year usually means neither implementation gets the attention it needs. Sequence them.

If you are already ISO 14001 certified → energy data collection is likely partially in place already, since environmental management systems frequently track energy as an aspect. That overlap is worth exploring before you start ISO 50001 from zero. We cover that specific comparison in ISO 14001 vs ISO 50001.

ISO 45001 vs ISO 50001 decision matrix comparing occupational health and safety management with energy management
ISO 45001 vs ISO 50001: Compare safety management, energy performance, key data, and implementation priorities for manufacturing operations.

Common Mistakes When Pursuing Either Standard

  • Treating ISO 50001 like a documentation exercise. Auditors want to see actual energy performance data trending in the right direction, not just a policy binder.
  • Underestimating worker participation requirements in ISO 45001. Facilities transitioning from legacy safety programs can discover gaps here during certification audits, particularly when participation is documented weakly.
  • Assuming one certification body handles both equally well. Confirm registrar experience with the specific standard before signing a contract — not every registrar has deep bench strength in energy management audits.
  • Skipping a baseline before setting objectives. For ISO 50001 specifically, you cannot demonstrate “improvement” without a documented starting point.

For a deeper look at where operations typically go wrong on the safety side specifically, see Common Mistakes in ISO 45001 Implementation.

Most operations managers don’t fail these audits because they misunderstand the standard. They fail because they assumed existing programs already covered the gap. Run a structured check before you commit to either certification path →

👉 Download the Manufacturing Compliance Checklist — see where your current safety and operational documentation actually stands against ISO requirements before you scope a project.


Readiness Checklist

✅ You track incidents, near-misses, or OH&S metrics in a documented format ✅ You know your facility’s baseline energy consumption by process or building ✅ Leadership has assigned clear ownership for whichever standard you’re pursuing
✅ You’ve confirmed whether a customer or contract actually requires certification, or just alignment
✅ You’ve budgeted for both the standard purchase and the registrar audit — not just one


Objection: “We Don’t Have the Budget or Headcount for Both”

This is the most common objection, and it’s usually a sequencing problem, not a resourcing problem. Most operations don’t need ISO 45001 and ISO 50001 running in parallel. Pick the one tied to your most immediate business driver — a customer requirement, an insurance conversation, or a utility cost that’s become impossible to ignore — and sequence the other for a later cycle. Trying to run both from zero at once is where budgets and internal bandwidth actually break down.

ISO 45001 vs ISO 50001 Stage 2 audit comparison showing occupational safety and energy management audit evidence
ISO 45001 vs ISO 50001: A Stage 2 audit examines different evidence for occupational health and safety management and energy management systems.

FAQ

Is ISO 45001 or ISO 50001 required by law?

Neither is legally mandatory in the U.S. Some customer contracts, insurance requirements, or international supply chain agreements may require one or both as a condition of doing business, but neither is a government regulation on its own.

Can one person manage both certifications?

In smaller operations, yes — but the skill sets are different. OH&S risk assessment and energy performance indicator tracking draw on different technical backgrounds, so expect a learning curve if one person is covering both.

How long does ISO 50001 certification take compared to ISO 45001?

Timelines are similar in structure — gap assessment, implementation, internal audit, Stage 1, Stage 2 — but ISO 50001 timelines depend heavily on how much energy metering infrastructure already exists. Facilities without submetering in place typically need additional time to establish a reliable baseline.

Does ISO 14001 certification make ISO 50001 easier?

Often, yes. Environmental management systems frequently already track energy as a significant aspect, which can shorten the baseline-gathering phase for ISO 50001. It’s not automatic, but the data collection habits usually transfer.

Is ISO 50001 only relevant for large facilities?

No. ISO 50001 applies regardless of facility size. Smaller operations sometimes see a faster payback because energy waste is easier to identify and correct when the operation is less complex.

What’s the single biggest difference between the two standards in a Stage 2 audit?

ISO 45001 audits focus heavily on documented risk assessments, worker consultation records, and incident investigation processes. ISO 50001 audits focus on your energy data — EnPIs, baseline documentation, and measurable performance trends. Auditors for the two standards are looking at fundamentally different evidence.

Do we need new equipment to pursue ISO 50001?

Not necessarily. Some facilities need submetering to establish a credible baseline, but many can start with existing utility billing data and building-level metering before investing in more granular monitoring.

Which standard should a fabrication shop pursue first?

For most fabrication and welding operations, safety risk (ISO 45001) is the more immediate driver — customer scorecards and insurance conversations tend to prioritize it. Energy management (ISO 50001) becomes the priority once utility costs or sustainability reporting requirements start showing up in bid packages.


📥 Free Resources

  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.
  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system.
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.

Not Sure What to Do Next?

🔹 Still researching which standard fits your operation? Start with the ISO 45001 Certification Guide or explore ISO Training for AS9100, ISO 13485 & ISO 50001 to understand what implementation actually looks like before committing.

🔹 Ready to start implementation? Get the Manufacturing Compliance Checklist and run a structured gap assessment before you scope a project with a consultant or registrar.

🔹 Need to buy the standard? If you’ve already decided which management system fits your operation, purchase ISO 45001:2018 or ISO 50001:2018 directly from ANSI Webstore — use code CC2026 for 5% off through December 31, 2026. If you’re implementing both, check the available bundle option before purchasing separately.

🔹 Getting your team certified to audit or lead either system? BSI and ISOQAR both run internal auditor and implementation courses for ISO 45001 and ISO 50001 — worth comparing before you pick one.

Whichever standard fits your situation, the fastest path forward isn’t guessing — it’s a structured comparison against your actual operation. The Standards Navigator covers both sides of this decision in plain, practitioner-level terms, without the sales pitch a registrar or consultant will give you.


Stop Guessing Which Standard Your Operation Needs

Facilities that wait for an audit finding or a customer scorecard to force the decision end up scrambling — picking whichever standard is most urgent instead of the one that actually fits their risk profile. Facilities that get ahead of it treat the decision as a planning exercise, not a fire drill.

The Standards Navigator breaks down ISO 45001, ISO 50001, and every standard in between in terms manufacturers can actually use on the shop floor — not the abstract language most registrars lead with.

👉 Get updates on ISO 45001, ISO 50001, and the full safety and energy management cluster
👉 Be first to access new gap assessment checklists and implementation resources as they publish

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.