Environmental Audit Guide: How to Run an ISO 14001 Internal Audit in 2026

This guide breaks down how to run an ISO 14001-compliant internal environmental audit in 2026, including the audit process step by step, common findings registrars flag, and what changed under the restructured 2026 revision. It covers auditor independence requirements, corrective action tracking, and how internal audits differ from certification visits.

ISO 14001 internal audit process, environmental compliance audit checklist, and what changed under the 2026 revision

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Your Internal Audit Is the Real Test — Not the Certification Visit

Most companies find out their EMS has a gap the hard way: during the certification audit, in front of the registrar, with a nonconformity on the record.

That’s backwards. The internal audit is where you’re supposed to find that gap. Environmental audits don’t fail companies. Skipped ones do. If your internal audit program is doing its job, very few surprises should remain by the time the certification audit rolls around.

Under ISO 14001:2026, that internal audit process just got more specific. Auditors now have to define audit objectives — not just scope and criteria. Management review has been restructured into three distinct pieces: inputs, process, and results. And Clause 10.1 is gone, folded into corrective action and continual improvement. If your internal audit program hasn’t been updated to reflect that, you’re auditing against a standard that no longer exists.


What Is an ISO 14001 Internal Audit?

An ISO 14001 internal audit is a systematic review of an organization’s environmental management system (EMS) to verify conformity with ISO 14001 requirements, applicable legal obligations, and internal procedures. The purpose is to identify gaps and drive corrective action before an external certification or surveillance audit — not after one flags them for you.

From the Floor: I’ve sat in enough surveillance audits to know the pattern — the finding the registrar flags is almost never a surprise to the people running the plant. Someone knew about it. It just never made it into a documented internal audit finding, so nothing forced a corrective action before the external auditor walked in. The internal audit isn’t paperwork. It’s the only thing standing between “we knew about that” and a major nonconformity on your certificate.

👉 Most EMS gaps get found six weeks too late. Run the Manufacturing Compliance Checklist against your current environmental controls before you schedule your next audit — not after.


In This Guide:

  • What an ISO 14001 environmental audit actually covers
  • Internal audits vs. certification audits — what’s different
  • What changed for internal audits under ISO 14001:2026
  • The audit process, step by step
  • Common findings and how to catch them early
  • Who should conduct your audit (and why it can’t be the EMS owner)
  • Preparing for your next audit


👉 Start Here (Top Resources)


What an ISO 14001 Environmental Audit Actually Covers

An environmental management system audit isn’t a plant walkthrough with a clipboard. It’s a documented, evidence-based comparison of what your EMS says you do against what’s actually happening on-site — the core of any legitimate EMS internal audit.

Infographic illustrating the key areas covered during an ISO 14001 internal audit, including legal compliance, environmental aspects, operational controls, corrective actions, objectives, and management review.
An ISO 14001 internal audit evaluates every critical element of an environmental management system to verify compliance and improve overall EMS effectiveness.

That means checking:

  • Legal and other compliance obligations — do your environmental permits, discharge limits, and EPA reporting obligations match what’s actually being tracked?
  • Aspects and impacts — is the register current, or is it the same list from your last certification cycle?
  • Objectives and targets — are they being measured, or just listed?
  • Operational controls — spill response, waste handling, emissions controls — are they followed as written, or as remembered?
  • Nonconformity and corrective action — is there a closed loop, or do findings sit open for months?

If you’re integrating this with a quality or safety audit, the Integrated Management Systems guide walks through how ISO 9001, ISO 14001, and ISO 45001 share enough clause structure to run a combined audit efficiently — worth reading before you build a standalone EMS-only audit program from scratch.


Internal Audits vs. Certification Audits

CategoryInternal AuditCertification (External) Audit
Who conducts itTrained internal staff or a contracted third partyAccredited registrar auditor
PurposeFind gaps before they become findingsVerify conformance for the certificate
FrequencyPlanned intervals — typically annual, often more frequent for high-risk areasAnnually (surveillance) or every 3 years (recertification)
Consequence of a missCorrective action, no external recordNonconformity on your certification record
Standard governing methodISO 19011:2018ISO/IEC 17021-1 (registrar accreditation)

If you are preparing for your first EMS certification → run at least one full internal audit cycle before you schedule the certification visit. A registrar auditor should never be the first person to see your gaps.

Before you select a registrar, confirm they’re actually accredited. ANAB accredits certification bodies operating in the U.S., and the IAF maintains the broader international framework accreditation bodies operate under — worth checking either before you commit to a certification audit date.


ISO 14001:2026 Internal Audit Requirements and Changes

Three changes matter most for how you run your audit program:

1. Audit objectives are now required, not just scope and criteria. Your audit plan has to state why you’re auditing a given area — risk exposure, a prior finding, a process change — not just what you’re covering and against what criteria.

2. Management review is restructured into three sub-clauses. Inputs, process, and results are now distinct. If your management review meeting minutes still run as one long list, they no longer map cleanly to the clause structure a registrar auditor will be checking against.

3. Clause 10.1 is gone. Its content is folded into 10.2 (nonconformity and corrective action) and 10.3 (continual improvement). That’s not a cosmetic change — it changes how your corrective action records need to be structured to trace back to a clause.

For the full breakdown of what changed at the standard level, see ISO 14001:2026 vs. 2015: What’s New at a Glance. If your documentation hasn’t been updated to match, start with ISO 14001 Documentation Requirements before your next internal audit — auditing against outdated document structure just produces findings you’ll have to redo.

If you are still certified to ISO 14001:2015 → you have until April 14, 2029 before that certificate stops being valid. That sounds like plenty of runway until you count backward through gap analysis, documentation updates, training, and at least one internal audit cycle before the certification audit itself.


👉 Not sure your internal audit program actually catches what a registrar will flag?

Get the Manufacturing Compliance Checklist and compare it against your current audit scope in under 45 minutes.


ISO 14001 Internal Audit Process: Step-by-Step Guide

Step-by-step infographic illustrating the ISO 14001 internal audit process, from defining audit objectives through verifying corrective actions before certification.
Following a structured ISO 14001 internal audit process helps organizations identify environmental management system gaps before external certification audits.
  1. Define objectives, scope, and criteria. Under 2026, objectives are a separate, required element — don’t skip straight to scope.
  2. Assign an independent auditor. Someone who doesn’t own the process being audited. Small operations often rotate this across departments or bring in outside help.
  3. Review documentation first. Permits, legal obligations, aspects and impacts, training records, and prior corrective actions should all be reviewed before stepping onto the shop floor.
  4. Conduct the on-site audit. Interviews, physical observation, records sampling — not just one or the other.
  5. Document findings against clause references. Every finding should trace to a specific clause, not a general impression.
  6. Close the loop. Corrective actions get assigned, tracked, and verified — not just logged and forgotten.
  7. Feed results into management review. Under the restructured clause, audit results are now an explicit input, not an assumed one.

Most common finding: aspects and impacts registers that were current at the last certification cycle and haven’t been touched since. Auditors catch this fast — new equipment, new chemicals, or a process change with no corresponding register update is one of the most frequent nonconformities in EMS audits.


👉 Want to know what auditors miss most often before it costs you a nonconformity? Compare the Manufacturing Compliance Checklist against your current EMS before your next internal audit.


Common Findings in Environmental Audits

Professional infographic highlighting the most common ISO 14001 internal audit findings, including outdated aspects registers, legal register gaps, corrective actions, training records, operational controls, and measurable objectives.
The most common ISO 14001 internal audit findings are preventable when organizations maintain current documentation, verify compliance, and close corrective actions promptly.
  • Objectives without measurement. A target exists on paper but nobody’s tracking progress against it.
  • Corrective actions that never closed. Opened after the last audit, never verified as effective.
  • Legal register gaps. A permit renewed or a regulation changed, and the register wasn’t updated.
  • Training records that don’t match current roles. Someone changed positions; their environmental training record didn’t follow them.
  • Operational controls that exist in the procedure but not in practice. The spill kit is where the SOP says it should be — six months ago. It’s since been moved, borrowed, or depleted.

If you are already ISO 9001 certified → your nonconformity and corrective action process likely already exists in a form the EMS can reuse. Don’t build a parallel CAPA system — extend the one you have. What Happens If You Fail an ISO 9001 Audit? covers how registrars evaluate corrective action effectiveness, and the same logic applies almost directly to EMS findings.


Who Should Conduct Your Internal Audit

The auditor has to be independent of the area being audited — that’s non-negotiable under ISO 19011. In practice, that means one of three models:

  • Cross-trained internal staff, rotated so nobody audits their own department
  • A shared internal audit function, common in integrated ISO 9001/14001/45001 programs
  • A contracted third-party auditor, useful for smaller operations without the headcount to rotate

At the Baker Hughes facility in Jacksonville, with roughly 500 employees across the site, we rotated internal auditors across departments every cycle specifically so no one ever audited their own area — a small operations team doesn’t always have that luxury, which is exactly why the third-party option exists.

If you are under customer pressure to certify quickly → don’t skip the independence requirement to save time. A registrar will flag a self-audited process immediately, and it becomes a finding of its own.

Objection: “We don’t have the resources for a full internal audit cycle.”

This is the most common reason internal audits get skipped or rushed — and it’s the wrong place to cut corners. A partial audit that misses aspects and impacts or corrective action tracking doesn’t save time. It just moves the gap to the certification visit, where it costs more — in registrar fees, in corrective action deadlines, and in the credibility hit of a nonconformity on record.

A properly scoped internal audit, run against a current checklist, typically takes less time than most operations managers assume. That’s especially true once objectives and criteria are clearly defined up front instead of improvised on-site.


Preparing for Your Next Audit — Quick Checklist

✅ Legal register updated within the last 12 months
✅ Aspects and impacts register reflects current operations — not last cycle’s ✅ All prior corrective actions closed and verified
✅ Objectives have measurable, tracked progress
✅ Audit objectives defined — not just scope and criteria
✅ Management review documentation split into inputs / process / results
✅ Auditor independence confirmed for every area covered

If you’re building or refreshing your audit documentation from the ground up, the ISO 14001 Certification Guide and ISO Implementation Timeline for Manufacturers both map out where an internal audit cycle fits into the broader certification timeline.

If you’re evaluating training or certification bodies to support your audit program, Best ISO Certification Bodies compares options side by side. And if you’re weighing whether to purchase ISO 9001, ISO 14001, and ISO 45001 together for an integrated audit program, buying the standards as a bundle saves meaningfully compared to purchasing each one separately — worth checking before you buy individually.


FAQ

How often does ISO 14001 require internal audits?

The standard requires audits at “planned intervals” — it doesn’t dictate a fixed frequency. Most certified organizations run internal audits annually at minimum, with higher-risk areas audited more frequently.

Can the same person who manages the EMS conduct the internal audit?

No. ISO 19011 requires auditor independence from the area being audited. The EMS owner can coordinate the audit program but shouldn’t audit their own processes.

What’s the difference between an internal audit and a management review?

The internal audit evaluates conformance and effectiveness at the process level. Management review is a higher-level evaluation by top management that now takes audit results as a required input under the restructured 2026 clause.

Do I need to redo my internal audit program for ISO 14001:2026?

Not from scratch, but your audit plan needs to explicitly define objectives, your management review documentation needs to reflect the three-part structure, and your corrective action records need to trace to Clause 10.2/10.3 instead of the now-removed 10.1.

What happens if my internal audit finds a major issue right before a certification audit?

Address it. A documented internal audit finding with an active corrective action in progress is normal EMS operation — registrars expect to see open corrective actions occasionally. What damages you is a finding that should have been caught internally and wasn’t.

Is ISO 19011 a certifiable standard?

No. ISO 19011 is a guidance standard for auditing management systems generally — it’s not something you get certified against, but it’s the reference most competent internal auditors are trained on.

Is an environmental compliance audit the same as an ISO 14001 internal audit?

Not quite. A general environmental compliance audit checks against regulatory requirements — permits, discharge limits, reporting obligations. An ISO 14001 internal audit checks against those plus your EMS’s own documented procedures, objectives, and conformance to the standard itself. Most organizations run them together, since the underlying evidence overlaps heavily.

Can I combine my ISO 14001 audit with my ISO 9001 or ISO 45001 audit?

Yes, and many organizations do, given the shared high-level structure across the three standards. See the Integrated Management Systems guide for how to structure it.

How long does an ISO 14001:2015 certificate stay valid after the 2026 edition published?

Until April 14, 2029. After that, ISO 14001:2015 certificates are no longer valid — organizations must transition to ISO 14001:2026.


📥 Free Resources

  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts

Not Sure What to Do Next?

🔹 Still researching what an EMS audit actually requires? Read the ISO 14001 Certification Guide for the full certification path before you build an audit program around it.

🔹 Ready to strengthen your internal audit program? ISO 14001 Internal Auditor Training through BSI Group or the equivalent ISOQAR course will get your team auditing against the current clause structure.

🔹 Need the standard itself to audit against? ISO 14001:2026 — ANSI Webstore is the current edition — auditing against the 2015 text after April 2026 means checking your EMS against requirements that no longer apply.


Don’t Let the Next Audit Be the One That Catches You Off Guard

Environmental audits don’t fail companies. Skipped ones do. The gap that shows up in a surveillance audit was almost always visible internally months earlier — it just never made it into a documented finding with a corrective action attached. Build the audit cycle now, and the certification visit stops being an event you dread. That’s the standard The Standards Navigator holds every EMS article to — clear, practitioner-level guidance, not theory.

Most operations managers don’t lose sleep over the audit itself. They lose sleep over what they don’t know is broken until a registrar finds it. Organizations that run a disciplined internal audit cycle walk into certification visits with confidence. Organizations that treat the internal audit as a formality walk in exposed — and find out in front of the one person whose findings go on the record.

The Standards Navigator tracks every clause-level change to ISO 14001 as it happens, so your audit program is never built against an outdated standard.

👉 Get updates on ISO 14001 audit and certification changes
👉 Be first to access new EMS audit checklists and gap assessment tools

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

ISO 14001 Documentation Requirements: What Manufacturers Need for 2026

ISO 14001:2026 replaces the 2015 edition’s documentation language and adds one genuinely new requirement — planning of changes under Clause 6.3. This guide breaks down what organizations actually need to update in their EMS documentation, from the aspects register to compliance obligations tracing, before their next transition audit.

Building an Environmental Management System That Passes Audit — Not Just Paperwork

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Your EMS Documentation Was Built for 2015. The Audit Is Coming for 2026.

ISO 14001 documentation requirements changed with the 2026 revision, and most environmental management systems haven’t caught up yet.

Most environmental management systems aren’t wrong. They’re simply aligned to an earlier version of the standard.

ISO 14001:2026 went live April 15, 2026, and certificate holders have until approximately April–May 2029 to transition — the exact date depends on the formal IAF/Global ACI transition document, not yet published. That sounds like plenty of runway. It isn’t, if your EMS manual, aspects register, and compliance obligations log still speak the language of the 2015 edition and your next surveillance audit is scheduled for next spring.

This isn’t about starting your documentation over. It’s about knowing exactly which documents need rewording, which need restructuring, and which need to exist for the first time.

The requirements discussed below are based on the published ISO 14001:2026 revision and current transition guidance available at the time of writing. Registrar-specific audit approaches are still developing during this transition period, so confirm interpretation of any clause with your certification body before finalizing documentation changes.

From the Floor: I’ve been at the table with an environmental auditor who pulled our aspects register and asked how abnormal operating conditions — startup, shutdown, upset conditions — were being captured separately from normal operations. We had them addressed operationally, but not documented that way, and it turned into a finding we had to close out with a corrective action plan. That’s the gap 2026 is designed to force into the open before an auditor finds it for you.

If you’re not certain your current EMS documentation would survive that conversation, run the gap check before you touch a single procedure →


Get the Manufacturing Compliance Checklist Before You Touch a Single Procedure

Before you start rewriting anything, get a clear picture of where your environmental and quality documentation actually stands today. The Manufacturing Compliance Checklist gives you a practical reference across ISO, OSHA, and quality requirements — so you’re not guessing which gaps matter most.

👉 Download the Manufacturing Compliance Checklist — most teams find at least one documentation gap they didn’t know they had.


In This Guide

  • What documented information ISO 14001:2026 actually requires
  • The one genuinely new clause your EMS has never had to address before
  • How your environmental aspects register needs to change
  • What “documented information” now means versus the old 2015 wording
  • A clause-by-clause comparison table you can hand to your management rep
  • Common mistakes industrial sites make during the transition
  • Whether to update your existing EMS or start fresh


👉 Start Here (Top Resources)


Why ISO 14001:2026 Changed the Documentation Rules

The 2015 edition used two different phrases for two different obligations, and most EMS documentation quoted them without much thought: “maintain documented information” for your controlled documents, and “retain documented information as evidence” for your records.

ISO 14001:2026 collapses that distinction into a single standard: documented information now has to be available, whether it’s a procedure your team follows or a record proving you followed it. It’s a terminology shift more than a content shift — but if your EMS manual and procedures quote the old phrasing verbatim, an auditor working from the 2026 clause structure is going to notice.

Here’s the part that matters more than the wording: no new document types are required by the language change itself. What’s actually driving new documentation work is the handful of clauses that were restructured or added outright — and that’s where most organizations are underestimating the lift.

If you’re already ISO 9001 certified → you’ll recognize this pattern immediately, since ISO 9001:2015 introduced its own Clause 6.3 on planning of changes years ago. ISO 14001 is simply catching up to the harmonized structure your QMS already uses.


Mandatory Documented Information Under ISO 14001:2026

Strip away the terminology change and the 2026 edition still requires the same core categories of documented information certified operations have carried since 2015, updated in scope:

  • EMS scope and policy statement — renumbered clause references, no substantive content change
  • Environmental aspects and impacts register — now must explicitly separate normal and abnormal operating conditions
  • Compliance obligations register — must show a traceable path from each legal or other requirement to the EMS element that addresses it
  • Objectives and environmental management programs — unchanged in substance, referenced under updated clause numbers
  • Planning of changes records — new under Clause 6.3, with no 2015 equivalent
  • Supplier and contractor documentation — expanded population under the broadened Clause 8.1 language
  • Monitoring, measurement, and internal audit records — same intent, updated cross-references

Most organizations already have five or six of these seven categories. The gap is almost always the planning-of-changes record and the abnormal-conditions split inside the aspects register — because neither was formally required before.


The Environmental Aspects and Impacts Register

Infographic showing an ISO 14001:2026 environmental aspects register that separates normal operations, abnormal conditions, and emergency situations for environmental impact evaluation.
ISO 14001:2026 requires organizations to identify and evaluate environmental aspects across normal operations, abnormal conditions, and emergency situations.

Your aspects register is probably the single document your registrar spends the most time on, and it’s the one seeing the most functional change under 2026.

The requirement now: your register has to demonstrate that you’ve captured environmental aspects under normal operating conditions, abnormal conditions (startup, shutdown, maintenance), and emergency situations — and cross-reference the emergency entries to your emergency preparedness procedure. A register that only reflects steady-state operations, however thorough, is going to draw a finding.

Most common finding: Aspects registers that address normal production runs in detail but treat startup and shutdown as an afterthought — usually a single line item instead of a documented breakdown.

Abnormal conditions worth documenting separately typically include:

  • Furnace or oven startup and cool-down cycles
  • Tank cleaning or vessel entry activities
  • Planned maintenance outages
  • Emergency generator testing or operation
  • Production line commissioning or decommissioning

There’s also a stronger expectation of life-cycle thinking built into how aspects are identified — not just what happens on-site, but upstream and downstream impacts tied to materials and outsourced processes.


Compliance Obligations and Interested Parties

The 2026 revision expects your compliance obligations register to do more than list applicable regulations. Auditors are now looking for a visible, traceable line from each obligation to the specific EMS element — procedure, control, or monitoring activity — that demonstrates you’re meeting it.

If your register currently reads as a static list of permits and regulations with no connection to your operational controls, that’s the gap to close first. This is also where your interested-parties analysis under Clause 4.2 gets tested — reviewers want to see that the needs and expectations you identified actually feed into what you monitor and report on.


Clause 6.3: The One Genuinely New Requirement

Infographic illustrating a suggested implementation workflow for ISO 14001:2026 Clause 6.3 planning of changes, emphasizing controlled EMS changes and preserving intended environmental management outcomes.
A suggested implementation workflow showing how organizations can plan and manage EMS changes under ISO 14001:2026 Clause 6.3 while maintaining intended environmental management outcomes.

This is the clause that didn’t exist in any form under ISO 14001:2015, and it’s the one most facilities haven’t built a process for yet.

Clause 6.3 — Planning of Changes requires that when your organization determines a need for changes affecting the EMS, those changes are carried out in a planned, controlled manner that ensures the system continues to achieve its intended outcomes. In practice, that means documenting: what’s changing, why, what could go wrong, and how you’ll manage the transition — before you make the change, not after an auditor asks about it.

Examples of the kind of changes this clause is built for:

  • Installing a new paint line or coating process
  • Switching waste disposal or recycling vendors
  • Changing chemical or raw material suppliers
  • Expanding production capacity or adding a shift
  • Modifying air emission controls or wastewater treatment equipment

From the Floor: The changes that create audit findings are rarely the major capital projects — those get reviewed, budgeted, and documented as a matter of course. It’s the smaller changes that slip through: switching waste vendors, changing a chemical supplier, moving a piece of equipment nobody thought to route through the EMS. Clause 6.3 exists because those are exactly the changes that don’t get caught until an auditor asks who approved them.

If a change like this happens without a documented planning record behind it, that’s the gap an auditor is now specifically trained to look for.

If you are updating your EMS for the 2026 transition → this is the clause to build a template for first, since you’ll need to demonstrate the process on the very changes you’re currently making to comply with the revision itself.

⚠️ Organizations that skip formalizing this process often end up retroactively documenting changes they’ve already made — which is a harder conversation with an auditor than showing a process that was followed in real time.


2015 vs. 2026: Documentation Comparison Table

Requirement AreaISO 14001:2015ISO 14001:2026
Documentation language“Maintain” (documents) / “retain” (records) as two separate termsSingle unified requirement: documented information “available”
Risks and opportunitiesBundled into Clause 6.1.1 with aspects and obligationsIsolated as its own planning step under Clause 6.1.4
Planning of changesNo formal requirementNew Clause 6.3 — documented change process required
Aspects register scopeNormal operating conditions emphasizedNormal, abnormal, and emergency conditions must be distinguished
Operational control scope“Outsourced processes”“Externally provided processes, products, and services” — broader supplier population
Climate considerationsAddressed via 2024 amendment onlyIntegrated directly into core clauses alongside biodiversity and resource use

If you’re weighing whether to buy the 2026 edition individually or as part of a bundle, the ANSI Webstore bundle option is worth comparing against the standalone purchase — bundling with related management system standards is often the more cost-effective route if you’re running an integrated system.

In practical terms, most organizations will spend the majority of their transition effort updating the aspects register and creating a repeatable planning-of-changes process, rather than rewriting the entire EMS from the ground up.

Side-by-side infographic comparing ISO 14001:2015 and ISO 14001:2026 documentation requirements, highlighting key transition updates for environmental management systems.
A visual comparison of ISO 14001:2015 and ISO 14001:2026 documentation requirements, showing the most significant updates organizations should address during their EMS transition.

Common Documentation Mistakes During Transition

Objection: “Our 2015 documentation already passed audit — why touch it now?” Passing audit under the old edition doesn’t mean your documentation will pass under the new clause structure. Registrars are already training their auditors on the 2026 requirements, and a surveillance audit scheduled in 2027 or 2028 will be assessed against them, not the edition you originally certified to.

The mistakes showing up most often:

  1. Find-and-replace without understanding intent. Swapping “maintain” for “available” throughout the EMS manual without addressing the actual scope changes in Clauses 6.1.4, 6.3, and 8.1.
  2. Treating Clause 6.3 as paperwork instead of process. Writing a one-time memo about the transition rather than building a repeatable change-management procedure.
  3. Leaving the aspects register unchanged. Assuming the existing register is compliant because it was compliant in 2015, without adding the abnormal-conditions and emergency cross-reference detail.
  4. Waiting until the transition deadline gets close. April 2029 feels distant. Registrars are already scheduling 2026-aligned surveillance audits well ahead of it.

Update Your Existing EMS or Build From Scratch?

If you’re already certified to ISO 14001:2015, you are not starting over. The 2026 edition is a refinement of an existing system, not a replacement of its logic. Your realistic path is: gap-assess your current documentation against the six changed areas above, update language and structure where required, and build the one document type — the planning-of-changes process — that genuinely didn’t exist before.

If you’re building an EMS for the first time → build directly to the 2026 clause structure from day one. There’s no reason to document against a standard that’s already been superseded.

If you’re under customer or supply-chain pressure to certify quickly → prioritize the aspects register and compliance obligations trace first. Those are the two documents auditors spend the most time on, and the ones most likely to generate findings if incomplete.

Need structured training before your team starts rewriting procedures? Compare ISO 14001 training through BSI Group against ISO 14001 training through ISOQAR before committing your team’s time.

Most teams underestimate how long the aspects register rebuild takes — check where yours actually stands before your next audit window closes in →


Quick Audit-Readiness Checklist

✅ EMS manual and procedures updated to reflect “available” documented information language
✅ Aspects register distinguishes normal, abnormal, and emergency conditions ✅ Compliance obligations register shows a traceable path to specific EMS controls
✅ Planning-of-changes process documented and in active use — not retroactive
✅ Supplier/contractor documentation reflects the broadened Clause 8.1 population
✅ Interested-parties analysis under Clause 4.2 connects to what you actually monitor

⚠️ If more than two of these are unchecked, a formal gap assessment should come before your next scheduled audit


FAQ

Does ISO 14001:2026 require entirely new documents?

No. The core documentation categories carry over from 2015. The one genuinely new requirement is the planning-of-changes process under Clause 6.3 — everything else is updated scope or terminology within existing document types.

Does ISO 14001:2026 require entirely new documents?

No. The core documentation categories carry over from 2015. The one genuinely new requirement is the planning-of-changes process under Clause 6.3 — everything else is updated scope or terminology within existing document types.

What is the transition deadline for ISO 14001:2015 certificate holders?

Certificates issued under ISO 14001:2015 must transition to the 2026 edition by approximately April–May 2029 — the exact date depends on the formal IAF/Global ACI transition document, not yet published. Registrars are expected to begin scheduling 2026-aligned audits well before that date.

Do we need to rewrite our entire EMS manual immediately?

No. Most guidance recommends updating terminology and scope at your next scheduled document review rather than rewriting everything at once, provided you prioritize the substantive changes — aspects register, compliance obligations trace, and the new change-management process.

What’s the difference between “maintained” and “available” documented information?

Under 2015, “maintain” applied to controlled documents and “retain” applied to records as evidence. The 2026 edition unifies both under a single requirement that documented information be available — the underlying intent for both documents and records hasn’t changed.

Does our aspects register need to list every abnormal condition individually?

It needs to demonstrate that abnormal conditions — startup, shutdown, maintenance — were identified and assessed separately from normal operations, with emergency situations cross-referenced to your emergency preparedness procedure. The level of granularity should match your operational risk.

How does Clause 6.3 differ from a standard management-of-change procedure we might already run for safety?

If you already have a formal management-of-change process for safety or quality purposes, Clause 6.3 can often be integrated into it rather than built separately — the requirement is that EMS-affecting changes go through a planned, documented process, not that it be a standalone system.

Is ISO 14001:2026 harder to document than the 2015 edition?

Not fundamentally harder — but the requirements are more specific about what your documentation needs to demonstrate, which means vague or thin documentation that passed under 2015 is more likely to draw findings now.

Should we buy the ISO 14001:2026 standard individually or as part of a bundle?

That depends on whether you’re managing an integrated system alongside ISO 9001 or ISO 45001. If you are, a bundle purchase is often more cost-effective than buying each standard individually.

Will my current ISO 14001:2015 certification become invalid?

Not immediately. Certificates issued under the 2015 edition remain valid through the transition window, currently set to close approximately April–May 2029. After that date, certificates that haven’t transitioned to the 2026 edition are no longer recognized.

Can we transition to ISO 14001:2026 during a regular surveillance audit?

In most cases, yes. Certification bodies are expected to fold the 2026 transition into an organization’s existing surveillance audit cycle rather than requiring a separate standalone audit — confirm the specific approach with your registrar, since implementation is still being finalized across certification bodies.

How long does an ISO 14001:2026 transition typically take?

For an organization with a functioning 2015-edition EMS, a transition timeline of 12–18 months is a reasonable planning window — covering gap assessment, documentation updates, internal audit against the new clause structure, and the transition audit itself. Organizations building an EMS from scratch should plan for a longer implementation timeline overall.

What documents does an auditor typically request first during a 2026 transition audit?

The environmental aspects and impacts register and the compliance obligations register are typically the first documents an auditor reviews, since both changed substantively under the 2026 revision. Evidence of a planning-of-changes process under Clause 6.3 is likely to receive increased scrutiny during transition audits, particularly for any EMS-affecting changes made during the transition itself.


📥 Free Resources

  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts

Not Sure What to Do Next?

🔹 Still researching the 2026 changes? Read ISO 14001:2026 vs. 2015: What’s New at a Glance for the full clause-by-clause breakdown before you touch your documentation.

🔹 Ready to start closing documentation gaps? Download the Manufacturing Compliance Checklist and identify where your EMS stands today.

🔹 Need to buy the standard itself? Get the official ISO 14001:2026 edition through ANSI Webstore, or compare training through BSI Group and ISOQAR if your team needs structured training first.

Documentation gaps don’t show up on your schedule — they show up on your auditor’s. The Standards Navigator will keep tracking the ISO 14001:2026 transition as certification bodies finalize their audit approach, so you’re not finding out what changed from a nonconformance report.


Stay Ahead of the ISO 14001:2026 Transition

Most organizations won’t find out their EMS documentation is out of date until an auditor tells them. The ones handling this well are treating the 2026 transition as a scheduled documentation review, not a scramble three months before their next audit.

Before your next surveillance audit, run a 10-minute documentation gap review using the Manufacturing Compliance Checklist. Most organizations discover at least one missing EMS control, undocumented obligation, or outdated procedure they didn’t know was sitting there.

The Standards Navigator tracks the ISO 14001:2026 rollout, transition timelines, and documentation requirements as certification bodies finalize their audit approach — so you’re working from what’s actually being enforced, not just what’s technically published.

👉 Get updates on ISO 14001 and environmental management system requirements
👉 Be first to access new EMS documentation resources as they’re built

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

ISO 14001:2026 vs 2015: What’s New at a Glance

A fast, table-first comparison of ISO 14001:2026 against the 2015 edition for organizations that already know the standard. Covers the one genuinely new requirement — Clause 6.3 change management — with a practical change-log format you can start using immediately.

A Fast Reference for Organizations Already Running an EMS

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


You Already Know ISO 14001. Here’s Exactly What’s Different.

You’re not here to learn what an EMS is. You already run one. You just need to know what changed between the standard you certified against and the one that published April 15, 2026 — fast, without wading through a full certification guide.

Short versionof ISO 14001:2026 vs 2015 – the structure didn’t change. One genuinely new clause did. Everything else is clarification and terminology alignment. This page is the delta, laid out for quick scanning — not a rewrite of what you already know about ISO 14001.

If you’re looking for the full certification process, costs, and implementation steps instead of just the delta → the ISO 14001 Certification Guide covers all of that in depth.

From the Floor: I’ve reviewed EMS gap assessments that were little more than a 2015 checklist with a new date stamped on it. That’s the risk with moderate revisions: they look insignificant until an auditor asks for evidence of a requirement that didn’t formally exist before. Clause 6.3 is exactly that kind of gap.

Before your certification body flags a gap you didn’t know existed → check yours now.

👉 Download the Manufacturing Compliance Checklist — cross-check your EMS against what’s actually changing, in about 20 minutes.

ISO 14001:2026 vs 2015 Key Changes at a Glance

  • New Clause 6.3 — formal change management
  • Expanded environmental context considerations (climate, biodiversity, resource use, pollution)
  • Documented internal audit objectives now required
  • Revised management review structure (7 inputs, 6 result areas)
  • Updated terminology and documentation language across the standard

In This Guide

  • The complete clause-by-clause comparison table, 2015 vs 2026
  • A deep dive on Clause 6.3 — the one requirement that’s genuinely new
  • A practical change-log format you can put to use today
  • What to check before your next surveillance audit


👉 Start Here (Top Resources)


The Complete Comparison Table

Side-by-side infographic comparing ISO 14001:2026 vs 2015, highlighting Clause 6.3, environmental context updates, audit objectives, and EMS documentation changes.
A visual comparison of ISO 14001:2015 and ISO 14001:2026 showing the most significant environmental management system updates organizations need to understand.

Sources used for this comparison: ISO 14001:2026, its Annex A implementation guidance, and transition materials published by major certification bodies including BSI and SGS.

ClauseISO 14001:2015ISO 14001:2026
4 — ContextGeneral environmental issuesClimate change, biodiversity, resource scarcity, and pollution named explicitly
5 — LeadershipCommitment centered on management rolesExtends to all relevant roles, not just management
6 — PlanningNo formal change requirementNew Clause 6.3 — formal change management
7 — Support“Maintain” / “retain” documented informationStandardized to “available as documented information”
8 — Operation“Outsourced processes”“Externally provided processes, products, or services”
9 — Performance EvaluationInternal audits without documented objectivesClause 9.2.2 requires documented audit objectives
9.3 — Management ReviewGeneral inputs/outputs listRestructured into three sub-clauses: 9.3.1 General, 9.3.2 Inputs, 9.3.3 Results
10 — ImprovementStandalone continual improvement clauseAbsorbed into 10.2–10.3, renumbered — requirements unchanged

Nothing here requires rebuilding your EMS. Most of it is terminology alignment with ISO 9001 and ISO 45001. Organizations managing multiple certifications should also review our guide to integrated management systems — this alignment actually simplifies shared documentation across all three standards.

How Big a Transition Is This?

For most mature, actively-managed ISO 14001-certified organizations, this should be measured in weeks, not months. If you already evaluate environmental impacts when you make operational changes — you’re just not writing it down consistently — this is a formalization exercise, not a rebuild. Organizations that treated their 2015 EMS as a checklist to pass one audit will have more ground to cover. Either way, Clause 6.3 change management is the one area worth reviewing first.

The One Real Addition: Clause 6.3

For most organizations, Clause 6.3 is the change most likely to require a genuinely new process rather than a documentation or terminology update. Some auditors and consultants will point out that the expanded context requirements or the new audit-objective rule also introduce meaningful new expectations — that’s a fair read too. But Clause 6.3 is the one standalone requirement that didn’t exist in any form in 2015: organizations must now determine, plan, and manage changes that affect — or could affect — the intended outcomes of the EMS.

That covers:

  • New processes, equipment, or facilities
  • Supplier or externally provided service changes
  • Product changes with environmental impact
  • Regulatory or legislative changes affecting compliance obligations

A formal written procedure isn’t mandated — but evidence is. Change forms, meeting minutes, or a documented workflow log all satisfy it. An informal, undocumented process does not, and that’s exactly the gap most 2015-era EMS programs have right now.

If you changed a supplier, coating system, or piece of equipment in the last 18 months with zero documentation showing the environmental impact was evaluated → that’s a nonconformance waiting to happen, not a hypothetical.

Infographic illustrating a practical implementation framework for ISO 14001:2026 Clause 6.3, showing five recommended steps for managing environmental management system changes.
A practical implementation framework illustrating one effective approach for documenting and managing EMS changes to support ISO 14001:2026 Clause 6.3 compliance.

Build Your Change Log

You don’t need a 20-page procedure to satisfy Clause 6.3 — you need a record. At minimum, each entry should capture:

What changed — the process, supplier, equipment, or product involved

Why — the business or operational reason for the change

Environmental impact evaluated — aspects and impacts considered before the change was made, not after

Who approved it — name and role, tied to your existing EMS authority structure

Monitoring after the change — how you confirmed the environmental impact matched what you expected

For many organizations, a spreadsheet with these five columns is sufficient evidence of a functioning process — provided records are maintained consistently and reviewed during your normal management review cycle. Auditors are looking for a pattern of documented decisions, not a specific software platform or format.

If you’d rather start from a built-out procedure than a blank spreadsheet, 9001Simplified’s documentation kits include change management templates that map directly to Clause 6.3.

Example ISO 14001:2026 environmental change log showing how organizations can document EMS changes, approvals, environmental impact evaluations, and post-change monitoring.
An example environmental change log demonstrating one practical way organizations can document EMS changes and support ISO 14001:2026 Clause 6.3 compliance.

Quick Audit-Prep Checklist

✅ Change log started and backdated as far as your records allow

✅ Context analysis reviewed against climate, biodiversity, resource, and pollution factors

✅ Internal audit plan updated to include documented objectives

✅ Management review agenda restructured around the new inputs/results format

✅ Documentation language updated to “available as documented information”


Frequently Asked Questions

Is ISO 14001:2026 a new standard or an amendment?

A full new edition — the fourth. It replaces ISO 14001:2015 entirely, including the 2024 climate change amendment, rather than adding to it.

Does my ISO 14001:2015 internal audit history still count?

Yes. Past audits remain valid records. What changes going forward is that new audits need documented objectives under Clause 9.2.2 — that’s not retroactive.

What’s the fastest way to find our gaps?

Start with the comparison table above and check Clause 6.3 first — it’s the one requirement most 2015-era systems genuinely lack. Everything else is usually a documentation-language update, not a missing practice.

What is the transition period for ISO 14001:2026?

Three years from publication is the standard IAF/Global ACI transition window for a major ISO management system revision. Applied to an April 15, 2026 publication date, that points to approximately April–May 2029 — sources vary on the exact month because the formal IAF/Global ACI mandatory transition document hasn’t been published yet. The full ISO 14001:2026 transition timeline will be confirmed once that document is issued; until then, your certification body’s guidance is the most reliable date for your specific certificate.

Is there an official ISO summary of the changes?

ISO doesn’t publish a plain-language change summary — only the standard itself, which includes Annex A implementation guidance. Certification bodies like BSI and SGS have published their own change guides, which is where most of the clause-level detail on this page is sourced from.

Do I need to update my EMS documentation before my next audit, or can it wait?

If your next surveillance or recertification audit falls after your certification body has transitioned to 2026-edition accreditation, you could be evaluated against elements of it. Starting your change log now costs nothing and builds an evidence trail either way.

Where do I go for the full implementation and certification process?

The ISO 14001 Certification Guide covers the complete process — costs, timeline, documentation requirements, and how ISO 14001 works alongside ISO 9001 and ISO 45001.


📥 Free Resources

  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system, with documentation discipline that applies directly to EMS change control.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.

Not Sure What to Do Next?

🔹 Just needed the delta? You’ve got it above — bookmark the comparison table and the change-log template.

🔹 Want the full picture — cost, process, timeline, documentation? Read the ISO 14001 Certification Guide.

🔹 Managing ISO 9001 and ISO 45001 alongside this transition? See the ISO 14001, ISO 9001 & ISO 45001 Transition Guide for how the three timelines overlap.

🔹 Running a production facility and need the operational side of this? ISO 14001 for Production Facilities covers implementation on the shop floor.

🔹 Need to purchase the standard? ISO 14001:2026 — ANSI Webstore — code CC2026 for 5% off.


This isn’t a revision that requires panic — it’s one that requires a paper trail. The Standards Navigator will keep this page updated as certification bodies finalize their own 2026 accreditation timelines.


Don’t Let a Documentation Gap Become a Nonconformance

The organizations that sail through their transition audit aren’t the ones with the most comprehensive EMS — they’re the ones who documented change as they went, instead of reconstructing eighteen months of history the week before an audit.

👉 Get updates on ISO 14001, ISO 9001, and ISO 45001 transition requirements as they develop

👉 Be first to access new EMS gap-assessment and documentation resources as they’re built

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

ISO Training for AS9100, 13485 & 50001: Avoid Costly Gaps

ISO training for AS9100, ISO 13485, and ISO 50001 each demand a different course level, not one generic ISO training course. This guide breaks down who needs awareness, internal auditor, or lead auditor training for AS9100, ISO 13485, and ISO 50001 — plus where to get accredited training for each standard.

A role-by-role training pathway guide for aerospace, medical device, and energy management systems

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Training Gap Nobody Budgets For

If you’re looking for ISO training for AS9100, ISO training for ISO 13485, or ISO training for ISO 50001, you’ve probably already run into the problem: most ISO training is built for ISO 9001 and doesn’t translate cleanly to these three standards. Manufacturers get ISO 9001 training right, then add AS9100 for an aerospace contract, ISO 13485 for a medical device line, or ISO 50001 for an energy initiative — and send the same people to the same generic “ISO awareness” course they used for quality management.

That’s a mistake, and it shows up fast. AS9100 auditors expect your team to speak to AS9101 audit requirements and IAQG OASIS supplier expectations — not generic quality-speak. ISO 13485 auditors expect design controls and CAPA competency, not general QMS awareness. ISO 50001 auditors expect your team to understand energy performance indicators, not just environmental basics.

Each of these standards has its own competency requirement and its own training hierarchy — and AS9100 adds a formal auditor authentication scheme on top, though that scheme applies specifically to certification body auditors rather than every internal auditor. Sending the wrong person to the wrong course doesn’t just waste a training budget. It leaves a documented competence gap that shows up the moment an auditor interviews the person responsible for that system.

I’ve built training matrices from the ground up during ISO 9001 implementation at a 500-employee valve and energy manufacturing operation, and the lesson translates directly to every management system standard: auditors don’t just check whether training happened. They check whether the person trained can actually explain the requirement in their own words, in their own work area. A certificate on file means nothing if the person can’t demonstrate the competency behind it.

👉 If you’re building out training for a new standard, confirm where your system already stands before you spend on courses → Download the Manufacturing Compliance Checklist


Quick Answer: Which Training Level Do You Need?

Your RoleRecommended Training Level
Executive Sponsor / LeadershipAwareness
Quality Manager / System OwnerLead Implementer
Internal AuditorStandard-specific Internal Auditor course
Certification / Third-Party AuditorLead Auditor (with AS9104/3 authentication for AS9100)
Production Supervisor / Department HeadFoundation / Requirements-level
Shop Floor / All PersonnelAwareness

In This Guide:

  • Why AS9100, ISO 13485, and ISO 50001 each need standard-specific training — not generic ISO training
  • Training levels and who needs them for each standard
  • AS9100’s unique auditor authentication requirement (AS9104/3)
  • ISO 13485 training and its connection to FDA QMSR competence requirements
  • ISO 50001 training and energy performance indicator competency
  • Where to get accredited training for each standard
  • Common training mistakes specific to these three standards


👉 Start Here (Top Resources)


Why These Three Standards Need Dedicated Training

ISO 9001, ISO 14001, and ISO 45001 share a harmonized high-level structure, which is why one training framework can reasonably cover all three — see ISO Training for Manufacturing Teams if that’s what you’re building. AS9100, ISO 13485, and ISO 50001 break from that pattern in three distinct ways:

StandardWhat breaks from the ISO 9001 pattern
AS9100Adds aerospace-specific clauses (configuration management, FAI, counterfeit parts) plus a formal auditor authentication scheme for certification auditors
ISO 13485Replaced “continual improvement” with maintaining effectiveness, and now has to align with FDA QMSR, which made ISO 13485:2016 the operative regulation as of February 2, 2026
ISO 50001Sits outside the quality/safety/environmental family — requires energy performance indicators and baseline methodology that don’t appear in any QMS or EMS course

If you’re evaluating certification bodies rather than training providers, see BSI vs ISOQAR for a full registrar comparison.


AS9100 Training: What Aerospace Suppliers Actually Need

AS9100 training carries a wrinkle the other standards on this list don’t have: a formal auditor authentication scheme. Under AS9104/3, certification body auditors seeking IAQG recognition must complete training through a Probitas Authentication-certified course. That requirement applies specifically to third-party certification auditors — internal auditors aren’t formally bound by it, but AS9104/3-aware training still benefits them, since it’s built around the same audit methodology customers and registrars expect to see reflected in your internal audit program.

A common scenario: a machine shop lands its first aerospace subcontract and assigns its existing ISO 9001-trained internal auditor to prep the QMS. The auditor knows the clause structure cold but has never worked with first article inspection requirements or configuration management controls — so the internal audit misses exactly the areas the customer’s supplier quality team will scrutinize first.

What AS9100 Training Covers Beyond ISO 9001

  • Configuration management and product safety requirements unique to aerospace
  • First article inspection (FAI) requirements under AS9102
  • Counterfeit parts prevention controls
  • Special requirements, critical items, and key characteristics
  • Risk management specific to aerospace supply chains
  • OASIS database requirements and supplier flow-down obligations

Who Needs AS9100 Training

Quality Manager / AS9100 Program Owner — Needs lead auditor or lead implementer training that specifically includes AS9104/3 authentication content. A generic ISO 9001 lead auditor credential typically does not provide sufficient coverage of aerospace-specific requirements such as AS9101, configuration management, product safety, and counterfeit parts prevention.

Internal Auditors — Need AS9100-specific internal auditor training. Formal AS9104/3 authentication isn’t required for internal auditors, but Probitas-recognized coursework still gives them the audit methodology customers and registrars expect to see — particularly useful if your organization plans to grow its internal audit program.

Production and Program Management — Need foundation-level AS9100 training covering configuration management, FAI, and counterfeit parts controls — the areas aerospace auditors probe hardest during a floor walkthrough.

All Personnel Touching Aerospace Work — Need awareness training covering product safety culture and counterfeit parts recognition, both explicit AS9100 requirements.

For a full breakdown of AS9100’s aerospace-specific clauses, see What Is AS9100? and Aerospace Supplier Compliance Standards.

Where to Get AS9100 Training

BSI Group AS9100 Training — BSI’s AS9100 catalog covers requirements through lead auditor training, with courses built around ISO 19011 audit methodology and Probitas Authentication recognition for the lead auditor level. BSI is the strongest option for AS9100 given their aerospace sector depth.

Purchase the official AS9100 standard through the ANSI Webstore before training begins — your team needs the current Rev D text in hand during coursework.

⚠️ Most common finding in aerospace audit prep: internal auditors trained only on generic ISO 9001 methodology, with no exposure to AS9104/3-aware audit practices or AS9101 audit reporting format. Formal authentication isn’t required for them, but when a customer or registrar reviews an internal audit program built entirely on ISO 9001 methodology, the gap surfaces fast.

Professional infographic mapping organizational roles to recommended ISO training levels for AS9100, ISO 13485, and ISO 50001, including executive sponsors, quality managers, auditors, supervisors, and shop floor personnel.
Assigning the appropriate ISO training to each organizational role builds competency, strengthens compliance, and improves certification readiness.

ISO 13485 Training: Meeting FDA QMSR Competence Expectations

ISO 13485 training has to accomplish something ISO 9001 training doesn’t: bridge a quality standard with an active regulatory framework. Since FDA QMSR incorporates ISO 13485:2016 by reference as the operative regulation for device manufacturers, training records now need to demonstrate competence against both the standard’s clauses and the regulatory context surrounding them.

A common scenario: a medical device startup trains its quality team on general ISO 9001 principles, assuming the overlap between the two standards covers the gap. The team performs fine on document control and internal audits — then struggles the first time a design history file review comes up, because ISO 9001 training never covered design control traceability or how a DHF ties back to risk management under ISO 14971.

What ISO 13485 Training Covers

  • Design and development controls, including design history file requirements
  • CAPA (Corrective and Preventive Action) process ownership and documentation
  • Risk management integration with ISO 14971
  • Regulatory requirements specific to device classification
  • Documentation and record retention aligned with FDA QMSR expectations
  • Internal audit methodology focused on maintaining effectiveness rather than continual improvement language

Who Needs ISO 13485 Training

Quality/Regulatory Affairs Lead — Needs requirements-level or lead implementer training that explicitly covers the FDA QMSR transition, not a course built solely around the ISO 13485 text in isolation.

Design and Development Personnel — Need training on design control requirements and design history file documentation — an area auditors and FDA reviewers scrutinize closely.

Internal Auditors — Need ISO 13485-specific internal auditor training. An ISO 9001 internal auditor credential does not adequately prepare someone to audit CAPA effectiveness or design control records.

Production and CAPA Owners — Need foundation-level training on nonconformance handling, CAPA documentation, and how “maintaining effectiveness” differs from the continual improvement language used in ISO 9001.

For deeper context on this terminology distinction, see Common Mistakes in ISO 13485 QMS and CAPA Requirements in ISO 13485.

Where to Get ISO 13485 Training

BSI Group ISO 13485 Training — BSI’s medical device training reflects direct regulatory experience across FDA, EU MDR, and global device markets — training only, not standard purchases.

Purchase the official ISO 13485:2016 standard from the ANSI Webstore — BSI does not pay commission on standards purchased directly, so route standard purchases through ANSI.

👉 Design controls and CAPA competency don’t build themselves from a training certificate alone. Pair training with a structured gap assessment before your next audit cycle → Download the ISO 13485 Gap Assessment Checklist


ISO 50001 Training: Building Energy Management Competency

ISO 50001 training is frequently treated as an extension of environmental management training. It isn’t. Energy management systems require a distinct competency set built around measurement and performance tracking rather than aspect/impact analysis.

A common scenario: a plant installs energy monitoring equipment and starts tracking consumption, assuming that satisfies the standard’s data requirements. During certification, the auditor asks how the energy performance indicators were established and what baseline period they’re measured against — and the team can’t answer, because nobody was trained on EnPI methodology specifically. The monitoring data exists; the defensible baseline behind it doesn’t.

What ISO 50001 Training Covers

  • Energy review methodology and identifying significant energy uses (SEUs)
  • Establishing energy baselines and energy performance indicators (EnPIs)
  • Legal and regulatory energy requirements
  • Data collection systems for energy monitoring
  • Internal audit methodology specific to energy management systems
  • Integration considerations with ISO 14001 for organizations running both systems

Who Needs ISO 50001 Training

Energy Manager / EnMS Owner — Needs lead implementer or requirements-level training covering EnPI methodology and energy baseline development. This is the most technical role on this list and benefits most from dedicated coursework rather than a generalist environmental credential.

Facilities and Maintenance Personnel — Need foundation training on how energy performance indicators connect to equipment operation and maintenance practices.

Internal Auditors — Need ISO 50001-specific internal auditor training. Auditing an EnMS requires evaluating energy data integrity and EnPI tracking — skills a generic management-systems auditor doesn’t automatically have.

For how ISO 50001 fits alongside other environmental and safety systems, see ISO 14001 vs ISO 50001.

Where to Get ISO 50001 Training

ISOQAR ISO 50001 Training — Awareness through internal and lead auditor courses covering EnMS audit methodology.

BSI Group ISO 50001 Training — Full training suite including on-demand eLearning fundamentals and IRCA-certified lead auditor coursework.

Purchase the official ISO 50001 standard from the ANSI Webstore before implementation training begins.


Training Level Comparison Across All Three Standards

Professional infographic showing two ISO training pathways, implementation and audit tracks, for AS9100, ISO 13485, and ISO 50001 with role-based competency progression.
Implementation and audit training follow different competency pathways, helping organizations assign the right ISO training to the right people.
StandardFoundation LevelInternal AuditorLead Auditor / ImplementerUnique Requirement
AS9100Configuration mgmt, FAI, counterfeit partsAS9104/3-aware internal audit trainingProbitas Authentication-recognized lead auditorAuditor authentication scheme
ISO 13485Design controls, CAPA basics13485-specific audit training (not ISO 9001 credential)Requirements/lead implementer with FDA QMSR contextRegulatory bridge to FDA QMSR
ISO 50001Energy review, SEU identificationEnMS-specific audit trainingEnPI methodology, lead auditor (IRCA)Data/measurement-based competency

Where to Get Training for Each Standard

Per your affiliate priority mapping and BSI’s sector depth, BSI Group is the primary training provider for AS9100 and ISO 13485. ISOQAR is primary for ISO 50001, with BSI as a secondary option for organizations wanting a single training provider across systems.

⚠️ Always purchase the standard itself through the ANSI Webstore rather than through your training provider — BSI does not pay commission on standards purchased directly through their site, and ANSI consistently offers the most competitive pricing with coupon CC2026 for 5% off through December 31, 2026.

If you’re evaluating certification bodies rather than training providers specifically, the decision criteria differ — see BSI vs ISOQAR: Which ISO Training and Certification Body Is Right for You? for a full registrar-selection comparison across all three standards.


Professional infographic comparing implementation and audit training pathways with a role-based ISO training matrix for AS9100, ISO 13485, and ISO 50001 organizations.
This role-based training matrix helps organizations match ISO training levels to specific responsibilities while distinguishing implementation and audit career pathways.

Common Training Mistakes Specific to These Standards

1. Treating AS9100 training as “ISO 9001 plus a little extra.” The auditor authentication requirement alone makes this a fundamentally different training investment, not an add-on.

2. Training ISO 13485 teams on “continual improvement” language. If your training materials use ISO 9001 terminology instead of “maintaining effectiveness,” your team will misstate a core requirement to an auditor.

3. Assuming an ISO 14001-trained environmental manager can run an EnMS. Energy performance indicators and baseline methodology are a distinct skill set that environmental training doesn’t cover.

4. Skipping FDA QMSR context in ISO 13485 training. Since QMSR made ISO 13485:2016 the operative regulation in February 2026, training that treats the standard as a standalone quality framework — without regulatory context — leaves a competence gap.

5. Using generic ISO 9001 methodology for AS9100 internal audits. Formal authentication isn’t required internally, but if your auditors have never worked with AS9104/3-aware methodology or AS9101 reporting, a customer supplier-quality audit will notice the gap.


Quick Training Readiness Checklist

✅ Quality/program owner has standard-specific lead auditor or lead implementer training — not a generic ISO 9001 credential

✅ Internal auditors have completed training specific to the standard being audited

✅ AS9100 internal auditors have exposure to AS9104/3-aware audit methodology

✅ ISO 13485 training materials use “maintaining effectiveness” language, not continual improvement

✅ ISO 50001 program owner has completed EnPI and energy baseline methodology training

✅ Training records document competence — not just attendance

✅ Training effectiveness has been evaluated, not just completed


FAQ

Can I use my ISO 9001 lead auditor credential to audit AS9100?

For internal audits, yes — with gaps. Your credential covers the shared clause structure, but AS9100 audits also require familiarity with AS9101 audit reporting and aerospace-specific clauses like configuration management and FAI. For third-party certification auditing, formal IAQG authentication under AS9104/3 is required and an ISO 9001 credential alone doesn’t satisfy it.

Does ISO 13485 training need to reference FDA QMSR specifically?

Yes, if you manufacture for the US market. Since FDA QMSR became effective February 2, 2026 and made ISO 13485:2016 the operative regulation, training that doesn’t bridge the standard to QMSR competence expectations leaves a documentation gap auditors and FDA reviewers will notice.

Is ISO 50001 training the same as ISO 14001 training?

No. ISO 50001 requires competency in energy performance indicators, energy baselines, and significant energy use identification — concepts that don’t appear in ISO 14001’s environmental aspect/impact framework.

How long does AS9100 lead auditor training take?

Most Probitas Authentication-recognized AS9100 lead auditor courses run five days, combining classroom instruction with practical audit exercises and a written examination.

Who needs the AS9104/3 authentication specifically?

Formal AS9104/3 authentication applies to certification body auditors seeking IAQG recognition — it’s not a requirement for internal auditors within your own organization. That said, internal auditors benefit from AS9104/3-aware training, since it reflects the same audit methodology your customers and registrar will expect to see.

What’s the difference between an ISO 13485 internal auditor course and an ISO 9001 internal auditor course?

An ISO 13485 course trains auditors to evaluate design controls, CAPA effectiveness, and risk management integration with ISO 14971 — none of which appear in a standard ISO 9001 internal auditor course.

Do I need separate ISO 50001 training if my team already has ISO 14001 training?

Yes. While both are environmental/sustainability-adjacent, ISO 50001’s technical focus on energy measurement and EnPI tracking requires dedicated training your ISO 14001 course won’t cover.

Where do I purchase the AS9100, ISO 13485, or ISO 50001 standards my training is based on?

Purchase all three directly from the ANSI Webstore. Use coupon code CC2026 for 5% off through December 31, 2026.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching which standard applies to you — Read What Is AS9100? or Medical Device Compliance Standards for a foundational overview before committing to a training path.

🔹 Ready to schedule training nowBSI Group’s AS9100 and ISO 13485 training catalog covers awareness through lead auditor. ISOQAR’s ISO 50001 training covers energy management specifically.

🔹 Need to purchase the standard your training is based on — Get AS9100, ISO 13485, or ISO 50001 directly from the ANSI Webstore. Use code CC2026 for 5% off through December 31, 2026.

🔹 Deciding between certification bodies, not just training providers — See BSI vs ISOQAR for a full registrar comparison.

The Standards Navigator covers training, certification, and implementation guidance across every major manufacturing standard — not just the ones with the most search volume. If your operation is expanding into aerospace, medical device, or energy management work, get your team’s competency built on standard-specific training before your first surveillance audit tests the gap.


Stay Ahead of Specialized Compliance Training

Manufacturers expanding into aerospace, medical device, or energy management work don’t usually get caught by the standard itself. They get caught because they trained their team like the new standard was just a variation on ISO 9001.

Organizations that certify cleanly recognize each standard’s distinct competency requirements early and train accordingly — an AS9100 program owner who understands AS9104/3, an ISO 13485 quality lead who speaks FDA QMSR fluently, an energy manager who can build a defensible EnPI baseline.

The Standards Navigator covers training pathways, certification body selection, and implementation guidance across every standard your operation touches — not just the most common ones.

👉 Get updates on specialized ISO training across aerospace, medical device, and energy management 👉 Be first to access new gap assessment checklists as they’re released

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

How to Audit a Medical Device QMS: The ISO 13485 Internal Audit Process (2026 Guide)

This guide walks medical device manufacturers through the ISO 13485 Clause 8.2.4 internal audit requirement — including audit program design, the six-step audit process, and the five most common findings auditors cite. It also covers what changed under the FDA QMSR and the new ISO 19011:2026 audit guidance.

A clause-by-clause guide to planning, conducting, and closing out ISO 13485 internal audits under the new FDA QMSR

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Internal Audit That Used to Be Private Isn’t Anymore

For years, medical device manufacturers treated the internal audit report as an internal document — useful for finding problems, but shielded from FDA inspectors under the confidentiality provision in the old 21 CFR 820.180(c). That protection is gone.

Since February 2, 2026, the FDA’s Quality Management System Regulation (QMSR) has been in effect, and it incorporates ISO 13485:2016 by reference rather than running a parallel U.S.-specific standard alongside it. FDA’s own Final Rule FAQ is direct about what that means for audits: “The QMSR gives the FDA the authority to inspect management review, quality audits, and supplier audit reports. The exceptions that existed in the QS regulation at § 820.180(c) are not maintained in the QMSR.” That’s not a third-party interpretation — it’s FDA’s own published position.

So this isn’t limited to internal audit reports. Management review minutes and supplier audit reports lost the same protection. A checklist you run through once a year to satisfy Clause 8.2.4 on paper is no longer a low-risk approach — it’s now a document an inspector may read line by line, and so are the meetings where leadership reviewed it.

From the Floor: I’ve built and run internal audit programs at facilities with 500-plus employees, and the finding that costs organizations the most isn’t a missing procedure — it’s a corrective action that gets closed on paper before the root cause is actually fixed. As a certified ISO 9001 Internal Auditor, I’ve sat across the table from auditors who catch that in about ninety seconds. Whether you’re auditing to ISO 9001 or ISO 13485, the internal audit only works if it’s harder on you than the external one will be.

Before your next surveillance audit, most quality teams don’t fail because they misunderstand Clause 8.2.4 — they fail because their audit program looks complete on paper but hasn’t been stress-tested against real objective evidence. Run your QMS through the free ISO 13485 Gap Assessment Checklist before an inspector or a Notified Body does it for you.


In This Guide

  • What ISO 13485 Clause 8.2.4 actually requires
  • How internal audits differ from supplier and certification audits
  • What Clause 6.2 actually requires of your auditors — and what “competent” really means
  • Building a risk-based annual audit program
  • The audit process: planning, evidence, reporting, and CAPA follow-up
  • A real finding-to-CAPA example, start to finish
  • The five most common internal audit findings — and how to avoid them
  • What changes if you’re audited under MDSAP
  • What changed under the FDA QMSR and ISO 19011:2026
  • Whether you need outside help or can run this internally


👉 Start Here (Top Resources)


What Clause 8.2.4 Actually Requires

ISO 13485 requires internal audits under Clause 8.2.4 to verify that QMS processes are implemented and effective, catch nonconformities, and surface QMS deficiencies early enough that they don’t become product-safety or regulatory problems. That sounds close to ISO 9001’s internal audit clause, and it is — but ISO 13485 asks for more.

Clause 8.2.4 requires that internal audits determine conformity to planned arrangements, the requirements of the standard, the organization’s own QMS requirements, and applicable regulatory requirements — and unlike ISO 9001, ISO 13485 explicitly requires the audit program to account for regulatory requirements such as FDA 21 CFR Part 820, EU MDR, or MDSAP alongside the standard itself. Teams that build their audit program purely off the ISO 13485 clause structure, without folding in the regulatory layer, are the ones who get flagged.

Most common finding: auditors treat Clause 8.2.4 as a documentation-review exercise and skip the regulatory cross-reference entirely. If your audit checklist doesn’t ask “does this also satisfy 21 CFR Part 820 or MDR Article 10?” it isn’t finished.

Audits must assess conformity across critical processes — design and development under Clause 7.3, corrective action under Clause 8.5.2, preventive action under Clause 8.5.3, production under Clause 7.5, and document control under Clause 4.2 — using objective evidence like device history records, audit trails, and validation records. Auditors must be trained, qualified, and independent of the area they’re auditing, with that competence documented under Clause 6.2.

If you are already ISO 9001 certified → your internal audit infrastructure transfers directly, but your checklist needs a regulatory column added for every process area, not just a conformity column.


Internal Audits vs. Supplier Audits vs. Certification Audits

Comparison infographic showing internal audits, supplier audits, and certification audits under ISO 13485.
Understanding the differences between internal, supplier, and certification audits improves audit planning and regulatory compliance.

Manufacturers frequently conflate these three, and an auditor will notice immediately if your procedure does too.

Audit TypeGoverning ClausePerformed ByPrimary Purpose
Internal AuditClause 8.2.4Trained internal personnel, independent of the area auditedVerify your own QMS conforms to the standard and your own procedures
Supplier AuditClause 7.4.1Quality or supplier quality personnelVerify external providers meet quality and regulatory requirements
Certification AuditISO/IEC 17021-1Accredited third-party Notified Body or registrarDetermine whether the full QMS meets ISO 13485 for certification

ISO 13485 requires internal audits, just as its sister standard ISO 9001 does, and they exist for two reasons: to confirm the QMS meets the standard’s requirements, and to confirm the organization actually follows its own rules. A strong internal audit program is what makes a certification audit uneventful instead of a fire drill.


Auditor Competence: What Clause 6.2 Actually Requires

This is the section most audit programs get thin on, and it’s where a surprising number of otherwise solid internal audit programs fall apart under scrutiny.

Clause 6.2 requires that anyone doing work affecting product quality — and that includes auditors — be competent based on appropriate education, training, skills, and experience. ISO 13485 doesn’t spell out a fixed list of required knowledge areas the way a checklist would, but three areas consistently show up when a Notified Body reviews auditor files:

  • The standard itself. A working knowledge of ISO 13485:2016 clause structure, not just the SOPs written to satisfy it.
  • Audit methodology. Understanding of the audit cycle — planning, evidence gathering, reporting, follow-up — along with the difference between a minor observation and a major nonconformity. ISO 13485’s own note under Clause 8.2.4 points auditors toward ISO 19011 for this.
  • Applicable regulatory context. Basic familiarity with the regulations that apply to your product and markets — 21 CFR Part 820, EU MDR, MDSAP — not full legal mastery, but enough to recognize when a finding also touches a regulatory requirement.

Competence is not the same thing as certification. ISO 13485 does not require a certified internal auditor credential, and ISO 19011 doesn’t mandate formal training either — the standard’s actual requirement is that the audit process ensure objectivity and impartiality, and that competence be evaluated and documented. In practice, though, “read and understand the internal procedure” is not evidence Notified Bodies accept as sufficient. An auditor who can’t produce a training record, a completed course certificate, or documented on-the-job evaluation showing how their competence was assessed is a finding waiting to happen — even if that person is, in fact, good at the job.

What acceptable training records look like in practice:

  • A certificate of completion from an ISO 13485 internal auditor course (typically covering the standard itself plus ISO 19011 audit methodology) — see BSI vs. ISOQAR if you’re deciding where to send your team for that training
  • Internal on-the-job qualification records — a documented mentored audit or two, signed off by a qualified lead auditor
  • A training matrix that ties each auditor to the specific processes and clauses they’re qualified to audit, refreshed when the QMS or the standard changes

Auditor independence gets checked alongside competence. The most frequent failure here isn’t a skills gap — it’s a quality manager who owns a process auditing that same process, or an auditor rotation that never actually rotates the highest-risk areas like design controls.

If you are not confident your auditor files would hold up to this list → that’s a fifteen-minute file review, not a project, and it’s worth doing before your next Notified Body visit rather than during it.


Building a Risk-Based Audit Program

The audit program must cover every process, department, and site within your QMS scope, with audit frequency determined by the status and importance of each process along with the results of prior audits. High-risk processes — design and development, production, CAPA, and complaint handling — typically need at least annual coverage, while lower-risk support functions can be audited less frequently if previous results were consistently clean.

Most manufacturers get the frequency question backwards. They audit everything on a flat annual calendar instead of weighting toward where the last audit found something. If your CAPA process had a finding last year, auditing it again on the same twelve-month clock as your HR training records is a scheduling decision an inspector will question.

If you are preparing for your first surveillance audit under the new QMSR → build your program around the regulatory cross-reference first, then layer the standard’s clause structure on top of it — not the other way around.


The Internal Audit Process, Step by Step

Infographic illustrating the ISO 13485 internal audit process from planning through CAPA verification for medical device quality management systems.
The six-step ISO 13485 internal audit process helps medical device manufacturers identify nonconformities and verify corrective actions.

Prepare a checklist based on the relevant clauses of ISO 13485, your documented procedures, and applicable regulatory requirements — a good checklist prompts investigation rather than simply confirming what’s already assumed to be true.

1. Scope and schedule. Define which processes, sites, and clauses are in scope for this audit cycle.

2. Documentation review. Analyze the quality manual, procedures, and prior audit reports before setting foot on the floor — this is where checklists get mapped to specific clauses.

3. Opening meeting. Confirm scope, objectives, and methodology with the auditee before evidence-gathering begins — this sets the tone for the entire audit.

4. Evidence gathering. Collect objective evidence through interviews, direct observation, and document/record review — no finding should be written down without evidence behind it.

5. Reporting. Findings get written up, classified by severity, and routed to the process owner and management.

6. CAPA follow-up. Every corrective action needs documented root cause analysis appropriate to the significance of the nonconformity, with effectiveness verified before the CAPA is closed.

Most teams execute steps 1 through 5 competently. Step 6 is where programs fall apart — a CAPA gets marked closed the day the immediate fix is implemented, with no verification that the fix actually held.

Trigger: If your last three internal audits found the same category of nonconformity in different words each time, that’s not three separate findings — that’s one root cause your CAPA process never actually reached.

Before your next audit cycle, check your CAPA closure process against what auditors actually verify — most teams don’t realize how thin their effectiveness checks are until someone else reviews them.


A Real Finding, Start to Finish

Steps on a page are easy to nod along with. Here’s what a properly closed finding actually looks like end to end, using one of the most common design-control gaps auditors find.

StageWhat It Looked Like
FindingDuring a design and development audit, three of twelve design verification records sampled were missing the reviewer’s signature. Work was completed and dated, but sign-off wasn’t captured.
Objective EvidenceDesign History File records DHF-114, DHF-119, and DHF-122, cross-referenced against the design review meeting minutes showing the reviews occurred.
Nonconformity Statement“Design verification records DHF-114, DHF-119, and DHF-122 lack the required reviewer signature per QMS-SOP-014, Section 6.2. Design and development control per ISO 13485:2016 Clause 7.3.6 requires verification results, including necessary actions, to be recorded.”
Root CauseInvestigation traced it to a recent SOP revision that moved the sign-off step later in the workflow. Staff hadn’t been retrained on the updated sequence — the procedure changed, but the training that should have accompanied it under Clause 6.2 didn’t happen.
CorrectionThe three records were completed retroactively with the reviewer’s signature and a note explaining the delay, reviewed and accepted by the quality manager.
Corrective Action (CAPA)Retrain design team on the revised sign-off sequence; add a mandatory signature field to the design review template so records can’t be filed incomplete.
Effectiveness CheckSample the next ten design verification records over the following quarter. Zero missing signatures required to close the CAPA as effective.

Notice what makes this closeable rather than cosmetic: the root cause isn’t “people forgot” — it’s a training gap tied to a specific procedure change, and the corrective action addresses the system, not just the three records. That’s the difference between a finding that stays closed and one that reappears with different reference numbers next year.


The Five Most Common Findings

Infographic highlighting the five most common ISO 13485 internal audit findings in medical device quality management systems.
The most common ISO 13485 internal audit findings often involve documentation, CAPA effectiveness, auditor competence, and risk-based planning.

Incomplete audit records — missing reports, plans, or linked CAPAs — is one of the most frequently cited internal audit issues. A close second is failing to apply a risk-based approach to audit planning, or simply not maintaining the internal audit schedule at all. Beyond that, auditors regularly find no timely follow-up on actions from internal audits, no records showing auditor competence against the applicable regulations, and auditors who weren’t actually impartial — reviewing work they had a hand in.

Design and development controls remain the single most frequently cited nonconformity area globally — incomplete design inputs, missing verification or validation records, undocumented design changes, or no formal design transfer procedure. See Validation & Verification Requirements for how this plays out in practice.

⚠️ If your auditor rotation lets the same person audit design controls year after year without ever being audited themselves on that same process, that’s an impartiality gap that a Notified Body will flag before you do.

If you are not confident your last internal audit would hold up under this list → that’s exactly what a structured gap assessment is for, not a guess.

Check your program against these five findings before your next audit — most gaps take under 45 minutes to identify →


MDSAP: What Changes for Multi-Market Audits

If your devices sell into more than one of the five MDSAP markets — the U.S., Canada, Australia, Brazil, or Japan — your internal audit program needs to account for a different audit model, not just an extra regulatory reference.

The Medical Device Single Audit Program lets one audit by an accredited Auditing Organization satisfy the requirements of all five participating regulators at once, in place of separate national audits. It’s built on ISO 13485:2016, but it isn’t a straight overlay — MDSAP uses a process-based audit model with a defined sequence, rather than working straight down the ISO clause list, and it maps every audit task to both the relevant ISO 13485 clause and each country’s specific regulatory requirement.

The grading system is the biggest practical difference. Where an ISO 13485 certification audit typically classifies findings as minor or major, MDSAP uses a points-based Grade 1–5 scale: nonconformities affecting clauses with indirect QMS impact start lower, direct-impact clauses start higher, and points are added for repeat findings or for a nonconforming product that was actually released. Grade 4 and 5 findings must be resolved before a certificate is issued or maintained — there’s no ambiguity about severity once the math is run.

What this means for your internal audit program: if you’re pursuing or maintaining MDSAP, your internal audits should follow the MDSAP process sequence — not just walk through ISO 13485 clauses in order — so that gaps surface in the same structure an Auditing Organization will use. The recurring findings across published MDSAP audits track closely with the same weak points internal audits should already be hunting for: open CAPAs left unclosed past a reasonable window, supplier and purchasing controls that don’t demonstrate follow-through, and root cause analysis that’s thin enough to not survive a second look.

One benefit worth knowing about: MDSAP audit reports can substitute for the FDA’s routine biennial device inspections. A well-run MDSAP program isn’t just multi-market efficiency — it can reduce how often FDA shows up separately.


What Changed: QMSR and ISO 19011:2026

Two regulatory shifts affect how internal audits get run in 2026, and both are recent enough that older internal procedures may not reflect them.

Since February 2, 2026, the FDA’s QMSR has incorporated ISO 13485:2016 by reference, replacing the former Quality System Regulation, and FDA inspections now run under Compliance Program 7382.850 rather than the old QSR framework. As covered above, the practical effect for internal audits is direct: the confidentiality safe harbor that used to apply to internal audit reports, management review records, and supplier audit reports under the old 21 CFR 820.180(c) has been removed, and FDA’s own FAQ confirms it in plain language.

Separately, ISO published the fourth edition of ISO 19011 — Guidelines for auditing management systems — on May 27, 2026, replacing the 2018 edition that had guided audit programs for nearly eight years. ISO 13485 doesn’t mandate ISO 19011 compliance directly — Clause 8.2.4 references audit principles in its own language — but Notified Bodies and experienced auditors widely treat ISO 19011 as the authoritative reference for structuring an audit program, so if your internal audit SOPs still cite the 2018 edition, expect your Notified Body to ask why.

Neither change requires rebuilding your program from scratch. Both are reasons to review your internal audit SOP this year rather than next.


Quick Audit-Readiness Checklist

✅ Audit program covers every process, site, and department in your QMS scope ✅ Audit frequency is risk-weighted, not a flat annual calendar
✅ Every checklist item maps to a specific ISO 13485 clause and the applicable regulatory requirement
✅ Auditors are independent of the area they’re reviewing, with Clause 6.2 competence records on file — not just “read and understand” sign-offs
✅ Findings are backed by objective evidence — interviews, observation, or documented records
✅ CAPA effectiveness is verified before closure, not assumed
✅ If pursuing MDSAP, internal audits follow the MDSAP process sequence, not just the ISO clause order
✅ Internal audit SOP references ISO 19011:2026, not the 2018 edition
✅ Design and development records are current — this is the single most-cited finding category


FAQ

How often does ISO 13485 require internal audits?

The standard doesn’t specify a fixed interval — it requires audits “at planned intervals” based on process risk and prior audit history. Most manufacturers audit high-risk processes like design controls and CAPA annually at minimum, with lower-risk support functions audited less frequently if history is clean.

Can the same person who performs a process also audit it?

No. Clause 8.2.4 requires auditors to be independent of the area being audited. A quality manager who owns the CAPA process, for example, shouldn’t be the one auditing CAPA compliance.

Do internal auditors need a formal certification?

No. ISO 13485 requires documented competence — education, training, skills, and experience — but doesn’t mandate a specific certification. In practice, most Notified Bodies expect more than an internal read-and-understand sign-off, so a course certificate or documented mentored-audit record is the safer standard to work toward.

Does the FDA QMSR require a separate internal audit program from ISO 13485?

No. Since the QMSR incorporates ISO 13485:2016 by reference, there isn’t a separate U.S.-specific internal audit requirement layered on top — your Clause 8.2.4 program is the audit program the FDA now expects, with the regulatory cross-reference built in.

Are internal audit reports confidential from FDA inspectors?

Not anymore. FDA’s own QMSR Final Rule FAQ confirms the confidentiality exceptions under the old 21 CFR 820.180(c) — covering internal audits, management review, and supplier audits — are not maintained under the QMSR.

What’s the difference between an internal audit and a supplier audit under ISO 13485?

Internal audits (Clause 8.2.4) evaluate your own QMS. Supplier audits (Clause 7.4.1) evaluate external providers’ ability to meet your quality and regulatory requirements. Both are required, but they’re separate programs with separate scopes.

Does MDSAP replace our ISO 13485 internal audit requirement?

No, but it changes the structure. MDSAP is built on ISO 13485 and layers in country-specific regulatory requirements from up to five markets, using a process-based sequence and a points-based Grade 1–5 nonconformity system rather than the minor/major classification used in standard certification audits.

What’s the most common reason internal audit programs fail a certification audit?

Incomplete records — missing audit reports, plans, or linked CAPAs — combined with no evidence of a risk-based approach to scheduling. Both are findings a Notified Body catches quickly because they’re procedural gaps, not technical ones.

Should we hire a consultant to run our internal audits, or can we do it ourselves?

Either can work if the auditor is properly trained and genuinely independent of the process. Many manufacturers use in-house auditors for most cycles and bring in an outside auditor periodically to test whether their internal program is actually rigorous or just familiar with its own blind spots.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching your audit obligations? Start with ISO 13485 Documentation Requirements to understand what your QMS needs on paper before you audit it.

🔹 Ready to build or strengthen your audit program? 9001Simplified’s documentation templates can shortcut the SOP-writing process without a consultant retainer.

🔹 Need the standard itself to build your checklist against? Get ISO 13485:2016 from ANSI Webstore — code CC2026 takes 5% off through the end of 2026.


An internal audit program that only exists to satisfy Clause 8.2.4 on paper was already a risk before the QMSR removed the confidentiality safe harbor. Now it’s a document an inspector can read directly. The Standards Navigator will keep tracking what QMSR enforcement and ISO 19011:2026 mean for how medical device manufacturers actually run their audit programs — not just what the clause says.


Subscribe for Medical Device Compliance Updates

Most manufacturers don’t lose a certification over one bad audit finding — they lose it over a pattern of findings their own internal audit program should have caught first. Organizations that treat Clause 8.2.4 as a paperwork requirement get surprised at surveillance. Organizations that treat it as their first line of defense rarely do.

The Standards Navigator tracks how ISO 13485, the FDA QMSR, and the standards that govern medical device audits actually work in practice — not just what the clause text says.

👉 Get updates on ISO 13485 audit requirements and QMSR enforcement changes 👉 Be first to access new medical device compliance checklists and gap assessment tools

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

ISO 10993 Contact Duration Matrix- How to Select Tests (2026 Guide)

ISO 10993-1:2025 retired the old Table A.1 checklist approach to biocompatibility testing. This guide explains the current contact duration categories, how total exposure period is calculated for reusable devices, and which biological endpoints apply — including FDA’s partial recognition of the new edition.

ISO 10993 Contact Duration Matrix and Biological Endpoint Selection Explained

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Matrix Changed. If Your Biological Evaluation Plan Still Reads Like 2018, You Have a Gap

Table A.1 is gone. For seven years, biological evaluation plans were built around a single grid in Annex A of ISO 10993-1:2018 — cross-reference device category and contact duration, check the boxes, done. That table has been retired. ISO 10993-1:2025, published November 18, 2025, split it into four separate tables and rebuilt the exposure-duration logic underneath them.

ISO 10993-1:2025 is the international standard that guides biocompatibility and biological evaluation of medical devices using a risk-based framework, replacing the prescriptive checklist approach of the 2018 edition.

If your BEP still cites the 2018 ISO 10993 contact duration matrix, or if you categorized a reusable device’s contact duration based on a single use rather than total exposure period, you may already be carrying a documentation gap — one that surfaces exactly when a reviewer or notified body opens your file.

Regulatory affairs teams are asking a narrower question than “what is ISO 10993”: which biological endpoints does this specific device trigger under the current framework, and why. That’s what this guide walks through.

I’ve sat across the table from an auditor reviewing a biological evaluation plan where the contact duration category didn’t match the device’s actual use pattern — a reusable component that looked like “limited” contact on paper but was accumulating well past 24 hours across a single patient’s treatment course. The documentation existed. The categorization logic behind it didn’t hold up. That’s the gap this guide is built to close before it becomes a finding.

👉 Before you finalize your next biological evaluation plan, run it against a structured QMS gap check first. Get the free ISO 13485 Gap Assessment Checklist and confirm your documentation controls support the categorization decisions your BEP depends on.

In This Guide

  • What changed in the ISO 10993-1:2025 evaluation matrix and why Table A.1 was retired
  • The current contact duration categories and how “total exposure period” is calculated
  • How to categorize daily contact, intermittent contact, and reusable devices correctly
  • Which biological endpoints apply to each contact duration and body-contact combination
  • What FDA’s partial recognition of ISO 10993-1:2025 means for your submission
  • Common categorization mistakes that trigger additional testing requirements
  • Where to buy the current standard and where to get ISO 13485-aligned training


👉 Start Here (Top Resources)

  • ISO 10993-1:2025 — ANSI Webstore — the current edition, direct from the accredited source. Use code CC2026 for 5% off. (Eric: insert the exact ANSI product link for ISO 10993-1:2025 here.)
  • If you’re weighing whether to buy standards individually or as a set, the ANSI bundle option is worth checking before you purchase the 10993 series piece by piece.
  • ISO 13485 Training — BSI Group — for teams building biological evaluation competency into a certified QMS.
  • ISO Training Courses — ISOQAR — a second accredited training option worth comparing against BSI on schedule and price.

Why the Evaluation Matrix Was Restructured

Under ISO 10993-1:2018, Annex A Table A.1 organized devices by body contact category — surface, external communicating, implant — crossed with three contact duration bands, and listed an “X” for every biological endpoint a reviewer might expect to see addressed. Industry insiders came to call it the “Table A.1 mentality”: manufacturers treated the X’s as a mandatory checklist rather than a starting point for risk-based justification. Tests got run because they appeared in a cell, not because a documented risk assessment called for them.

ISO 10993-1:2025 splits that single table into four separate tables, each tied to a specific evaluation context, and embeds the framework more tightly into the ISO 14971 risk management process. The standard now expects a Biological Evaluation Plan built on the device’s actual risk profile — chemical characterization, materials history, intended use, contact pattern — with the tables used to check completeness, not generate a test order.

Most common finding: biological evaluation plans that cite “Table A.1” by name, or that list endpoints without a documented rationale tied to the device’s specific exposure profile. Under the current standard, that’s a gap a reviewer will flag.

If you are still building your first BEP for a device entering the medical device space, start with what the supplier controls requirements under ISO 13485 expect from your materials documentation — biological evaluation depends heavily on having reliable supplier and materials data before you ever get to a test matrix.

Contact Duration Categories, Defined

The three contact duration categories are unchanged in name but recalculated in practice:

CategoryCumulative ContactTypical Devices
LimitedUp to 24 hours totalDiagnostic swabs, single-use syringes, short procedural instruments
ProlongedMore than 24 hours, up to 30 days totalWound dressings changed over several weeks, indwelling catheters (short-term), orthodontic devices
Long-term / PermanentMore than 30 days totalImplants, permanent orthopedic hardware, long-term catheters

The category itself hasn’t moved. What changed is how you calculate “total contact” for a device that isn’t used in one continuous stretch — and that recalculation is where most categorization errors happen.

If you are evaluating a device used in short, repeated sessions → don’t categorize based on a single session length. The standard expects you to sum all contact time across the device’s full use pattern before assigning a category.

Daily Contact vs. Intermittent Contact

Comparison infographic explaining daily contact and intermittent contact under ISO 10993-1:2025 for biological evaluation of medical devices.
ISO 10993-1:2025 distinguishes between daily and intermittent contact when determining cumulative exposure for biological evaluation.

ISO 10993-1:2025 formalizes two exposure patterns that the 2018 edition handled inconsistently:

  • Daily contact — the device touches the body every day, for any portion of a day, across a defined treatment course. Total exposure is counted as calendar days from first use to last use (or replacement) on a single patient.
  • Intermittent contact — use with at least 24 hours between consecutive contacts. This is treated as repeated use of the same device, or a replacement device, under evaluation.

A wound contact layer changed daily over three weeks is the textbook example: under the 2018 edition, each dressing change might have been assessed as its own “limited” exposure. Under the current standard, the 21 cumulative contact days push the device into prolonged territory — and that shift can add endpoints your original evaluation never considered.

If you are re-evaluating a device that was cleared under the 2018 categorization logic → don’t assume your existing category still holds. Run the total exposure period calculation against the current definitions before you finalize anything for a new submission.

Reusable Devices and Total Exposure Period

Reusable devices are now categorized based on cumulative contact time for a single patient across the device’s full use pattern — not the duration of any one use, and not a multi-patient device service-life total. A reusable surgical instrument sterilized and reused across a procedure series looks brief per individual contact, but the relevant figure is how many total contact days that one patient accumulates across their treatment course, including reasonably foreseeable misuse such as use beyond the labeled reprocessing cycle count.

Bioaccumulation is a related but less settled consideration. FDA’s Supplementary Information Sheet for ISO 10993-1:2025 (Recognition No. 2-313) notes that ISO/TC 194 Working Group 1 is still developing technical reports specifically addressing bioaccumulation, intermittent contact, and reasonably foreseeable misuse. In practice: if chemical characterization data — extractables and leachables — raises a bioaccumulation concern, that finding should inform your risk assessment and may support escalating the device’s category, but document it as a risk-based judgment rather than treating it as a fixed clause requirement until the supporting technical reports are finalized.

For teams managing this inside a certified QMS, it’s a judgment call that needs to trace back to a documented decision — not a verbal risk call made in a meeting. Clause 9 of ISO 10993-1:2025 requires that biological evaluations be planned, conducted, and reported by competent personnel, with the evaluation report documenting the rationale behind risk decisions like this one. The CAPA requirements under ISO 13485 apply just as much to a categorization correction as to a nonconformance on the shop floor.

Flowchart explaining cumulative single-patient exposure for reusable medical devices under ISO 10993-1:2025.
Reusable medical devices are categorized using cumulative single-patient exposure rather than the duration of a single procedure.

Mapping Contact Category to Biological Endpoints

The biological effects under consideration haven’t fundamentally changed — cytotoxicity, sensitization, irritation, systemic toxicity, genotoxicity, implantation effects, and hemocompatibility remain the backbone, and ISO 10993-1 remains a risk-based framework, not a mandatory testing checklist. What changed is the scope of consideration required, particularly for genotoxicity:

Contact DurationBody ContactGenotoxicity Consideration
LimitedAnyCase-by-case, per risk assessment
ProlongedAll tissues except intact skinGenerally expected to be addressed per Tables 2–4 and Clause 6.5.7
Long-term / PermanentAll tissues except intact skinGenerally expected to be addressed per Tables 2–4 and Clause 6.5.7

Under the 2018 edition, genotoxicity was consistently expected for implants and long-term tissue contact, but inconsistently applied to prolonged-contact devices touching mucosal membranes or breached surfaces. ISO 10993-1:2025 narrows that inconsistency: per Tables 2–4 and Clause 6.5.7, any device requiring systemic toxicity evaluation due to prolonged or long-term contact is now generally expected to address genotoxicity as well, intact skin excepted — though this remains a risk assessment expectation to be justified within your Biological Evaluation Plan, not an automatic in vivo test order. Where existing data (toxicological risk assessment under ISO 10993-17, chemical characterization, or literature) already addresses the risk adequately, testing may not be necessary. Carcinogenicity consideration was similarly extended for long-term contact with intact mucosal membranes.

Worth flagging directly: FDA’s Supplementary Information Sheet for ISO 10993-1:2025 (Recognition No. 2-313) identifies a genuine discrepancy here. ISO 10993-1:2025 lists genotoxicity as an endpoint for consideration across all prolonged-contact device categories, while FDA’s own Table A.1 (Attachment A of its 2023 Biocompatibility Guidance) limits the genotoxicity endpoint to implanted devices, externally communicating devices with tissue/bone/dentin contact, and externally communicating devices with circulating blood contact. For a U.S. submission, don’t assume the broader ISO scope automatically controls — confirm which framework your reviewer expects you to follow.

Most common finding: biological evaluation plans for prolonged-contact mucosal devices that address systemic toxicity but don’t document a genotoxicity rationale one way or the other — an omission that was easier to overlook under the 2018 matrix and is more likely to draw a question under the current one.

If your device’s evaluation also touches sterilization residuals, review our sterilization standards overview — ethylene oxide and other sterilization residues are a recurring driver of chemical characterization findings that reshape a biological evaluation.

FDA’s Partial Recognition — What’s Excluded

FDA recognized ISO 10993-1:2025 on May 25, 2026 (Recognition No. 2-313 in FDA’s Recognized Consensus Standards database), but the recognition is partial, not full. Two carve-outs from the Supplementary Information Sheet matter for submission strategy:

  • The phrase “consumer products or” in Clause 6.5.11.3 (Low Risk Intact Skin Contacting Medical Devices) is not recognized — FDA states it conflicts with Attachment G of its 2023 biocompatibility guidance, which limits which historical-use materials qualify for reduced testing on skin-contacting devices.
  • Clause 6.9, Biological risk estimation, is not recognized — FDA holds it conflicts with the risk estimation approach already established under ISO 14971:2019, which FDA separately recognizes.

If you are preparing a 510(k), PMA, or De Novo submission → you cannot submit a full Declaration of Conformity without addressing these two exclusions directly, and the genotoxicity discrepancy above is a separate, related point worth raising with your reviewer proactively. Cite the standard, but demonstrate compliance for the excluded clauses through FDA’s existing biocompatibility guidance rather than assuming automatic alignment. FDA’s recognized standard entry and Supplementary Information Sheet have already been updated since publication — verify the current version directly against FDA’s Recognized Consensus Standards database before finalizing any submission.

For the broader shift this represents in medical device documentation expectations, see our breakdown of validation and verification requirements under ISO 13485 and the FDA QMSR.

Common Categorization Mistakes

Infographic highlighting common ISO 10993 biological evaluation and contact duration categorization mistakes for medical device manufacturers.
Many ISO 10993 audit findings result from incorrect categorization logic or incomplete biological evaluation documentation rather than testing failures.

⚠️ Categorizing by single-use duration instead of cumulative single-patient exposure. The single most common error on reusable and repeat-use devices — it understates the contact category more often than it overstates it.

⚠️ Citing “Table A.1” in a current BEP. A reference to the old table structure is a documentation red flag on its own, independent of whether the underlying science holds up.

⚠️ Assuming genotoxicity doesn’t need to be addressed for prolonged mucosal contact. Teams working from older templates default to a 2018-era endpoint list and skip documenting a rationale either way — under the current tables, that gap is more likely to draw a question.

⚠️ Assuming FDA recognition is full, or that ISO and FDA genotoxicity scope match. Building a submission strategy around blanket alignment, without addressing the excluded clauses and the genotoxicity scope discrepancy, invites an avoidable deficiency letter.

If you are unsure whether existing biological evaluation plans need revisiting → they don’t automatically require retesting, but ISO 10993-1:2025 does expect a documented review confirming prior categorization and endpoint rationale still hold under current definitions.


Quick Audit Checklist

✅ Contact duration category calculated from cumulative single-patient exposure, not single-use duration
✅ Reusable/repeat-use devices assessed for total contact days for one patient across their treatment course
✅ Genotoxicity rationale documented for prolonged/long-term contact except intact skin, per Tables 2–4 and Clause 6.5.7
✅ Biological Evaluation Plan references current ISO 10993-1:2025 structure, not legacy Table A.1
✅ FDA submission strategy accounts for the two partially-recognized clauses and the genotoxicity scope discrepancy
✅ Bioaccumulation signals from chemical characterization data reviewed and documented as a risk judgment, not assumed to require automatic escalation ✅ Existing (pre-2025) biological evaluations documented as reviewed against current definitions


FAQ

Does ISO 10993-1:2025 require me to retest devices already on the market?

No. The standard doesn’t mandate automatic retesting for devices with an acceptable safety history. It does expect a documented review confirming prior categorization and evaluation still hold, and an update if a Clause 10 production change triggers a re-review.

Is ISO 10993-1:2018 still valid to use?

FDA’s recognized standards database is the authority for U.S. submissions — verify current recognition status before relying on either edition. For new evaluation plans, aligning with the 2025 edition is the safer long-term position.

What’s the difference between “prolonged” and “long-term” contact?

Prolonged contact covers cumulative contact exceeding 24 hours but not exceeding 30 days. Long-term (permanent) contact covers cumulative contact exceeding 30 days, driven by total exposure period rather than packaging or labeling.

Does the 2025 edition apply to devices regulated under the EU MDR?

It’s generally treated as state of the art for MDR purposes, but grace periods and notified body expectations vary — confirm directly with your notified body.

Is genotoxicity testing now mandatory for every prolonged-contact device?

Not automatically. Per Tables 2–4 and Clause 6.5.7, genotoxicity is generally expected to be addressed through risk assessment for prolonged and long-term contact with all tissues except intact skin — but “addressed” can mean justified through existing toxicological or chemical characterization data, not necessarily new in vivo testing. Note also that FDA’s own Table A.1 applies genotoxicity more narrowly than ISO does, so confirm which framework governs your specific submission.

Do I need a new Biological Evaluation Plan for every device?

No blanket requirement to start over. Most manufacturers can update an existing BEP to reflect current categorization logic and endpoint scope, provided the underlying risk assessment and chemical characterization data are still valid.

How does ISO 14971 relate to my biological evaluation?

ISO 10993-1:2025 is now more tightly embedded in the ISO 14971 risk management process. See our guide on risk management in medical devices under ISO 14971 for how that framework applies.

Where do I buy the current edition of ISO 10993-1?

Through an authorized reseller such as the ANSI Webstore, which also serves international buyers and offers standards in multiple languages. ISO 10993-1:2025 — ANSI Webstore — Coupon code CC2026 applies through December 31, 2026.


📥 Free Resources

  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts
  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements

Not Sure What to Do Next?

🔹 Still researching how the current standard applies to your device? Read our Biocompatibility Standards Overview for the full picture before you build a test matrix.

🔹 Ready to build or update your Biological Evaluation Plan? Download the ISO 13485 Gap Assessment Checklist and confirm your documentation controls support the categorization decisions you’re about to make.

🔹 Need to purchase the current standard? ISO 10993-1:2025 — ANSI Webstore — code CC2026 takes 5% off, and international buyers can access the standard in multiple languages through the same source.


The Standard Changed. Your Categorization Logic Should Too.

Table A.1 was a shortcut, and shortcuts age out. ISO 10993-1:2025 asks for a defensible, risk-based answer instead of a checked box — and that’s a better position to defend in front of a reviewer regardless of which edition your notified body is citing this quarter. The Standards Navigator will keep tracking how FDA recognition and international adoption evolve as this transition plays out.


Don’t Let a Reviewer Find the Gap First

Most biological evaluation gaps don’t get caught in your own review — they get caught by a notified body auditor or an FDA reviewer, months after the plan was finalized. Manufacturers who treat contact duration categorization as a one-time exercise tend to carry that risk forward through every product change. Manufacturers who build a documented, repeatable categorization process into their QMS catch the drift before it becomes a submission delay.

The Standards Navigator tracks ISO 10993, ISO 13485, and the broader medical device compliance landscape as it evolves — including regulatory recognition changes like FDA’s partial recognition of ISO 10993-1:2025.

👉 Get updates on medical device biocompatibility and QMS requirements
👉 Be first to access new gap assessment tools and implementation resources

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

Biocompatibility Standards Explained: ISO 10993 Requirements for Medical Devices in 2026

This guide breaks down the ISO 10993 series and the sixth edition of ISO 10993-1, published in November 2025. It covers FDA’s partial recognition of the new edition in May 2026, the two clauses the agency excluded, and whether manufacturers need to revisit biological evaluation plans for devices already cleared.

What ISO 10993-1:2025 and FDA’s Partial Recognition Mean for Your Biological Evaluation Plan

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Standard Behind Your Biocompatibility Testing Just Changed — Is Your Documentation Still Defensible?

Biocompatibility standards for medical devices just changed in a way regulatory affairs teams can’t ignore. If your device has any contact with the human body, your biological evaluation plan rests on one standard: ISO 10993-1. For years, that meant the 2018 edition. That’s no longer the whole story.

ISO published a sixth edition, ISO 10993-1:2025, in November 2025. The FDA followed with recognition of that edition on May 25, 2026 — but only partial recognition. Two specific clauses were excluded outright. If your technical documentation, supplier certificates, or biological evaluation reports still cite the 2018 edition without addressing what changed, that’s a gap a reviewer or auditor will find.

This isn’t a cosmetic update. The reorganization ties biocompatibility more tightly to ISO 14971 risk management, and the FDA’s exclusions tell you exactly where the agency still wants you to lean on its own biocompatibility guidance instead of the standard’s language. This guide covers the current medical device biocompatibility testing requirements under both editions, what changed, and what FDA’s recognition decision actually means for your Biological Evaluation Plan (BEP).

I’ve been on the reviewing side of this problem before, just from the documentation control angle. As an ISO 9001 internal auditor, I’ve flagged design history files where a supplier’s certificate of conformance still referenced an outdated edition of a cited standard — the technical content hadn’t changed, but the paper trail no longer matched what the standard actually required. That’s the kind of finding that stalls a submission or an audit closeout, and it’s entirely avoidable if someone catches the edition mismatch before a reviewer does.

Before you touch a single test report, run a gap check on where your current documentation stands against the 2025 edition.

👉 Most teams don’t fail because their biocompatibility data is wrong — they fail because their documentation still points to the wrong edition of the standard. Run the ISO 13485 Gap Assessment Checklist before your next submission or audit →


In This Guide

  • What ISO 10993-1 covers and why it sits at the center of biocompatibility evaluation
  • The full ISO 10993 series, part by part
  • What actually changed in the 2025 edition
  • FDA’s partial recognition — and exactly what it excluded
  • Whether you need to retest devices already cleared under the 2018 edition
  • How biocompatibility documentation fits into your ISO 13485 QMS
  • A quick audit checklist for your next document review


👉 Start Here (Top Resources)


What Is Biocompatibility, and Why ISO 10993 Matters

Biocompatibility is the assessment of whether a device’s materials — and the way those materials contact the body — create an unacceptable biological risk. ISO 10993-1 is the standard that governs how you plan, justify, and document that biocompatibility risk assessment. It doesn’t hand you a checklist of tests to run blindly; it requires you to build a risk-based Biological Evaluation Plan (BEP) that considers the device’s materials, manufacturing processes, intended anatomical contact, and exposure duration.

That risk-based framing matters because it’s the same language FDA reviewers and notified bodies expect to see. A BEP that reads like a 2009-era test list, rather than a risk justification tied to ISO 14971, is a common source of review questions and additional information requests.

If you’re still building out your risk management process, our guide on risk management in medical devices under ISO 14971 covers the foundation ISO 10993-1 now leans on even more heavily than before.


The ISO 10993 Series at a Glance

Infographic showing the ISO 10993 series for biological evaluation of medical devices, including ISO 10993-1, -5, -6, -7, -10, -12, -17, and -18.
The ISO 10993 series consists of multiple standards that together form a complete biological evaluation framework for medical devices.

ISO 10993-1 doesn’t stand alone — it’s the framework document for a series that covers specific test methods and evaluation categories.

PartCoversStatus Note
ISO 10993-1Overall evaluation and testing within a risk management processSixth edition (2025) now partially recognized by FDA
ISO 10993-5In vitro cytotoxicity2009 edition, still current
ISO 10993-6Local effects after implantationUpdated 2026 edition
ISO 10993-7Ethylene oxide sterilization residualsUpdated 2026 edition
ISO 10993-10Irritation and skin sensitization2021 edition
ISO 10993-12Sample preparation and reference materials2021 edition, amended 2025
ISO 10993-17Toxicological risk assessment of device constituents2023 edition, amended 2025
ISO 10993-18Chemical characterization of materials2020 edition, amended 2022

Most common finding: Manufacturers cite ISO 10993-5 or -10 correctly but leave the ISO 10993-1 reference in their design history file pointing to the 2018 edition without any documented rationale for why. If your BEP hasn’t been revisited since the 2025 edition published, that’s the first thing to check.

If your device is sterilized and you haven’t looked at how the 2026 edition of ISO 10993-7 interacts with your sterilization validation, our sterilization standards overview walks through ISO 11135, 11137, 17665, and 11607 alongside it.


What Changed in ISO 10993-1:2025

The sixth edition isn’t a light refresh. ISO’s technical committee reorganized the standard and changed its title to explicitly align with the ISO 14971 risk management framework. The practical changes:

  • More detailed guidance on calculating exposure duration — including how to treat foreseeable misuse, such as a device used longer than its labeled duration.
  • Expanded guidance on device characterization and biological hazard identification, intended to reduce reliance on generic test batteries.
  • Terminology aligned with ISO 14971, so if your team already knows that standard, the 2025 edition should read more consistently — though NAMSA and other industry commentators note there isn’t yet a technical report equivalent to ISO/TR 24971 to guide interpretation of the new edition.

Here’s how the two editions compare on the points that matter most for your Biological Evaluation Plan:

Topic2018 Edition2025 Edition
Risk Management IntegrationReferenced ISO 14971More explicitly aligned throughout
Exposure DurationLimited guidanceExpanded methodology for calculating duration, including foreseeable misuse
Biological Hazard IdentificationLess detailedExpanded guidance on device characterization and hazard identification
Risk EstimationDifferent treatmentNew Clause 6.9 (excluded by FDA)

If you are preparing a Biological Evaluation Plan for a new device → start by confirming which edition your FDA reviewer or notified body expects to see referenced, since adoption isn’t uniform across regions. The EU has generally moved faster toward treating the 2025 edition as state of the art. Manufacturers should verify current adoption expectations directly with their notified body and applicable competent authorities, since implementation timing varies and is subject to change.

One shift worth flagging for regulatory teams building out a modern BEP: chemical characterization under ISO 10993-18 is playing a larger role than it used to. Rather than defaulting to a blanket biological test matrix for every device, more manufacturers are leaning on thorough chemical characterization data — extractables and leachables profiles, material composition analysis — to justify a narrower, risk-based testing strategy. ISO 10993-1:2025’s expanded hazard identification guidance reinforces this shift. A well-documented ISO 10993-18 characterization can reduce redundant biological testing, but only if the chemistry-driven rationale is documented clearly enough to withstand a reviewer’s scrutiny.

Comparison graphic showing the major differences between ISO 10993-1:2018 and ISO 10993-1:2025 for biological evaluation of medical devices.
The 2025 edition places greater emphasis on risk management integration, biological hazard identification, and exposure assessment.

ISO 10993 FDA Recognition: What’s Excluded and Why

🔑 Key FDA Takeaway FDA recognizes ISO 10993-1:2025, but excludes:

  • The “consumer products” language in Clause 6.5.11.3
  • Clause 6.9 on biological risk estimation

Manufacturers should document alternative justification using FDA guidance and ISO 14971.

On May 25, 2026, FDA updated its Recognized Consensus Standards database (Recognition No. 2-313) to include ISO 10993-1:2025 — but not in full. Two specific exclusions matter for your submissions:

  1. The phrase “consumer products or” in Clause 6.5.11.3. This clause addresses low-risk, intact-skin-contacting devices. The standard allows manufacturers to point to a material’s history of safe use in consumer products as justification for reduced testing. FDA excluded this because it conflicts with Attachment G of its 2023 biocompatibility guidance, which defines specific materials with an accepted history of use — a consumer product history alone doesn’t automatically satisfy FDA’s expectations.
  2. Clause 6.9 on biological risk estimation. FDA determined this clause conflicts with the risk estimation approach already established in the FDA-recognized ISO 14971:2019. Sponsors can’t rely on Clause 6.9 to claim conformity in a submission.

If you are under customer or notified body pressure to update your BEP quickly → prioritize reviewing these two clauses first. They’re the specific areas where citing the 2025 edition alone won’t satisfy FDA, and you’ll need to document your justification through existing FDA guidance instead.

Partial recognition means you cannot submit a clean Declaration of Conformity to the full 2025 edition. Your submission documentation needs to call out the partial recognition explicitly and show how you’re addressing the excluded clauses — silence on this point is what generates additional information requests.

Workflow illustrating FDA partial recognition of ISO 10993-1:2025 and the documentation required for excluded clauses during medical device submissions.
FDA recognizes ISO 10993-1:2025 with specific exclusions, requiring manufacturers to document alternative regulatory justifications.

Do You Need to Retest Already-Cleared Devices?

This is the objection I hear most from teams looking at this update: does a new edition mean I have to redo my biocompatibility testing on devices that already have clearance?

No — not automatically. FDA’s recognition of a newer edition doesn’t retroactively invalidate data or clearances based on the 2018 edition. If you already hold clearance under the 2018 edition → you don’t need to retest existing devices. What you do need is a documented rationale, at your next design change or periodic review, for why your BEP still reflects sound risk management even though a newer edition exists. That’s a documentation and justification exercise, not a lab exercise.

Where this becomes a live issue is new submissions and significant design changes going forward — those are where reviewers will expect to see the current edition addressed.


Where Biocompatibility Fits Into Your ISO 13485 QMS

Biocompatibility data doesn’t live in isolation — it’s part of your design and development file under ISO 13485, and it feeds directly into your risk management file under ISO 14971. If your ISO 13485 documentation structure doesn’t have a clear place for biological evaluation plans, reports, and the rationale behind edition changes, that’s a gap worth closing before your next internal audit — not after a nonconformance is written.

This also connects to supplier controls. If a component supplier’s certificate of conformance references ISO 10993-1 by edition, your incoming inspection and supplier qualification process needs a mechanism to catch when that reference goes stale — the same principle covered in our guide on common mistakes in ISO 13485 QMS implementation.

And if you’re managing devices sold in both the US and EU, the edition-adoption gap between FDA and the EU regulatory framework is one more reason to keep your MDR vs ISO 13485 documentation aligned rather than treating them as separate tracks.

👉 If your biological evaluation documentation hasn’t been reviewed since the 2025 edition published, don’t wait for a finding to tell you. Check where your QMS documentation actually stands →


Quick Audit Checklist

✅ Confirm which edition of ISO 10993-1 your current BEP references, and whether that matches what your reviewer or notified body expects
✅ Check whether your device’s biocompatibility justification relies on Clause 6.5.11.3 (consumer product history) or Clause 6.9 (risk estimation) — both need alternative justification for FDA submissions
✅ Verify supplier certificates of conformance cite current standard editions, not stale references
✅ Confirm your risk management file cross-references your BEP consistently ✅ If your device is sterilized, check the 2026 editions of ISO 10993-6 and -7 against your current validation data ⚠️ Don’t assume “FDA recognized” means “fully accepted” — verify the Supplementary Information Sheet for any standard before citing it as a full Declaration of Conformity


FAQ

What is biocompatibility testing for medical devices?

Biocompatibility testing evaluates whether the materials in a medical device, and the way those materials contact the body, could cause an unacceptable biological response. It covers areas like cytotoxicity, sensitization, irritation, and systemic toxicity, selected based on the device’s contact type and duration.

What is ISO 10993-1, and do I need to comply with it?

ISO 10993-1 is the framework standard that governs how you plan and justify a biological evaluation within a risk management process. If your device contacts the body directly or indirectly, FDA and most global regulators expect your biocompatibility strategy to follow its structure, even where full conformity isn’t feasible.

What changed between ISO 10993-1:2018 and ISO 10993-1:2025?

The 2025 edition reorganized the standard to align more closely with ISO 14971, added detailed guidance on calculating exposure duration and identifying biological hazards, and updated terminology throughout.

Has the FDA recognized ISO 10993-1:2025?

Yes, as of May 25, 2026, but only partially. FDA excluded the “consumer products” language in Clause 6.5.11.3 and all of Clause 6.9 on biological risk estimation, both of which conflict with existing FDA guidance and the FDA-recognized ISO 14971:2019.

Do I need to retest devices already cleared under the 2018 edition?

No. Existing clearances aren’t invalidated by a newer edition. You do need a documented rationale for your current approach at your next design change or periodic review.

Which parts of the ISO 10993 series apply to my device?

That depends on your device’s contact type (surface, external communicating, or implant) and contact duration (limited, prolonged, or permanent). ISO 10993-1 provides the matrix for selecting relevant parts of the series based on those two factors. We’ll be covering that contact-duration matrix in detail in an upcoming guide.

Is ISO 10993 the same as ISO 13485?

No. ISO 13485 governs your overall quality management system for medical devices. ISO 10993 is a series specifically about biological evaluation, and its outputs — your BEP and test reports — become part of the design and development records your ISO 13485 QMS requires you to maintain.

Where do I purchase ISO 10993 standards?

Individual parts and bundled packages are available through the ANSI Webstore, which also serves international buyers and offers documents in multiple languages. The ISO.org catalog describes each part but is not the recommended purchase channel.


📥 Free Resources

  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.
  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements, including where biocompatibility documentation fits.
  • AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification.

Not Sure What to Do Next?

🔹 Still researching how the 2025 edition affects your device category? Start with our breakdown of risk management under ISO 14971 — biocompatibility evaluation doesn’t stand apart from it anymore.

🔹 Ready to check where your documentation actually stands? Run the ISO 13485 Gap Assessment Checklist before your next audit or submission, not after.

🔹 Need to purchase the current standard? ISO 10993-1:2025 — ANSI Webstore, or get the full biological evaluation package bundled at roughly 45% off individual pricing if you’re assembling multiple parts of the series. Use code CC2026 for an additional 5% off through December 31, 2026.

The Standards Navigator will keep tracking how FDA recognition evolves on this standard as updates are published.


Documentation Gaps Don’t Show Up Until Someone’s Looking For Them

Teams that treat biocompatibility as a one-time lab exercise are the ones caught off guard when a standard’s edition changes underneath them. Teams that treat it as a living part of their design and risk management file catch the mismatch at their next internal review, not during an FDA question round — and it’s usually a citation that didn’t keep up, not the underlying science, that stalls a submission.

The Standards Navigator tracks these regulatory shifts as they happen — not months later when the transition deadline is already close. If ISO 10993-1:2025 affects your device, this is a good window to revisit your documentation rationale while the timeline is still in your control.

👉 Get updates on medical device compliance and biocompatibility standard changes
👉 Be first to access new gap assessment checklists and documentation tools for ISO 13485 and ISO 14971

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

ISO 15223 Symbols Overview: What Every Medical Device Label Actually Means (2026 Guide)

ISO 15223-1:2021 governs the pictograms on every medical device label. This guide breaks down the seven symbol categories, key reference symbols, and the 2026 EU REP amendment — including exact transition deadlines under MDR and IVDR.

A regulatory affairs guide to the pictograms your labels are required to carry — and the 2026 EU REP symbol change you need to track

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.

This article is for general informational purposes and is not regulatory advice. Manufacturers should verify symbol requirements against the current version of ISO 15223-1 and applicable regulatory guidance.


ISO 15223-1:2021 is the internationally recognized standard that defines symbols used on medical device labels, packaging, and accompanying information to communicate critical safety and regulatory information without language-specific text.


The ISO 15223 Symbols That Trigger a Labeling Recall

A single wrong pictogram on a device label isn’t a cosmetic problem. It’s a labeling nonconformance that can hold up a shipment, trigger a Notified Body finding, or in the worst case, force a recall.

ISO 15223-1:2021 is the standard behind nearly every symbol on a medical device label — manufacturer, batch code, sterile, use-by date, and dozens more. It’s not optional guidance. It’s the harmonized reference regulatory affairs teams are expected to follow for CE marking label symbols, and it just changed in a way that affects almost every CE-marked device on the market.

From the floor: I’ve reviewed label proofs where a well-meaning graphics team swapped in an old sterilization icon because it “looked close enough” to what the previous product used. It wasn’t the same symbol, and it wasn’t accompanied by the batch reference the standard requires next to it. Having reviewed manufacturing and quality documentation across multiple industrial environments, I’ve repeatedly seen labeling errors originate not from misunderstanding the requirements, but from uncontrolled template reuse. That kind of small mismatch is exactly what a label review process is supposed to catch before it reaches a Notified Body’s desk — not after.

👉 Before your next label revision goes to print, confirm every symbol still matches current guidance. Most labeling nonconformances aren’t due to unfamiliarity with the standard — they’re due to reusing an old label file without checking what changed. Get the ISO 13485 Gap Assessment Checklist and confirm your revision management process is catching this before a reviewer does.


In This Guide

  • What ISO 15223-1:2021 actually covers and why it’s harmonized under MDR/IVDR
  • The seven symbol categories and what each one communicates
  • The 2026 EU REP symbol change — what changed, when, and what it means for your labels
  • Common labeling mistakes that surface in document reviews
  • FAQ


👉 Start Here


What Is ISO 15223-1:2021?

ISO 15223-1:2021, Medical devices — Symbols to be used with information to be supplied by the manufacturer — Part 1: General requirements, is now in its fourth edition. It defines the standardized pictograms manufacturers use on labels, packaging, and accompanying documentation so a device can be understood across languages and markets without translation.

It was harmonized under both EU MDR and EU IVDR in January 2022 — one of a relatively small number of standards to hold that status — which means using it correctly carries a presumption of conformity with the corresponding MDR/IVDR labeling requirements. A companion standard, ISO 15223-2, covers how new symbols get developed, selected, and validated when nothing in the existing library fits.

Because ISO 15223-1 is harmonized under MDR and IVDR, proper symbol usage can support a manufacturer’s demonstration of conformity with labeling requirements. In practice, auditors and Notified Bodies routinely review symbol usage as part of labeling assessments — this isn’t a peripheral checklist item, it’s one of the more commonly reviewed elements of a technical file.


Why Manufacturers Use Symbols

Medical devices are distributed across multiple countries and languages. Standardized symbols reduce the need for translated label text while helping manufacturers meet labeling requirements consistently across global markets. A single symbol library means the same pictogram carries the same meaning whether a device ships to Germany, Japan, or Brazil — without a separate translated label for each market.


ISO 15223-1 Medical Device Symbols Explained

ISO 15223-1 organizes its medical device label symbols into seven functional groups:

  • Manufacturing — manufacturer identity, date of manufacture, country of manufacture
  • Storage — temperature limits, humidity limits, keep dry, keep away from sunlight
  • Safe use — single use, do not use if damaged, consult instructions for use
  • Sterility — sterile, sterilization method, do not resterilize
  • IVD-specific — symbols unique to in vitro diagnostic devices
  • Transfusion/infusion — symbols for blood and infusion-related devices
  • Other — symbols that don’t fit cleanly into the categories above but are still standardized

Every symbol in the standard comes with a defined title, a description of what it communicates, and any accompanying information it must be paired with — a batch code symbol without an actual batch number next to it isn’t a valid use of the symbol.


Most Common ISO 15223-1 Medical Device Symbols

Infographic illustrating the most common ISO 15223 symbols for  medical device labeling, including manufacturer, LOT, REF, serial number, sterile, use-by date, consult instructions for use, and keep dry.
The most frequently used ISO 15223-1 symbols help communicate critical manufacturing, traceability, sterility, and safety information on medical device labels worldwide.

The following symbols represent some of the most commonly encountered markings in medical device labeling. This is not a complete list, but these symbols appear on a significant percentage of devices entering regulated markets.

Symbol TitleClauseWhat It Communicates
Manufacturer5.1.1Identifies the legal manufacturer; name and address must accompany it
Date of manufacture5.1.3The date the device was produced
Use-by date5.1.4The date after which the device should not be used
Batch code (LOT)5.1.5Identifies the manufacturing batch or lot
Catalogue number (REF)5.1.6The manufacturer’s catalogue/model number
Serial number (SN)5.1.7Identifies a specific individual device
Importer5.1.8Identifies the entity importing the device into a given market
Sterile5.2.1Device has been through a sterilization process
Do not resterilizeDevice is not to be resterilized after use
Do not use if package damagedConsult instructions for use if packaging integrity is compromised
Single useDevice is intended for one use only

This is a reference sample, not the full symbol library — the standard runs well beyond these. For the complete set of ISO 15223 symbol meanings, always validate current symbol usage against the live ISO document rather than a saved reference sheet, since amendments do get issued.


The 2026 EU REP Symbol Change

The most consequential update to this standard in years just took effect. Amendment EN ISO 15223-1:2021/A1:2025 replaces the long-standing “EC REP” symbol for a medical device’s authorized representative in the EU with a new “EU REP” symbol, and introduces a generic “XX REP” framework where “XX” is swapped for the applicable country or jurisdiction code.

The change was requested by the European Commission in May 2024, specifically to eliminate confusion between “EC” as a regulatory abbreviation and “EC” as the ISO 3166-1 country code for Ecuador. ISO adopted the amendment in March 2025, and it was formally harmonized into the Official Journal of the European Union on June 17, 2026, through Commission Implementing Decision (EU) 2026/1231 (amending MDR-side Decision 2021/1182) and Commission Implementing Decision (EU) 2026/1313 (amending IVDR-side Decision 2021/1195).

The European Commission has been explicit that this is a purely editorial change — it does not alter the authorized representative symbol’s role, responsibilities, or the device’s safety or performance profile in any way. This amendment is now one of the more consequential updates among the current round of MDR harmonized standards, given how widely the symbol appears across the CE-marked device population.

Timeline infographic illustrating the transition from the EC REP symbol to the EU REP symbol under ISO 15223-1:2021 Amendment A1:2025, including key regulatory milestones through 2031.
The transition from EC REP to EU REP includes a five-year coexistence period, allowing manufacturers to update labeling during normal revision cycles before the 2031 deadline.

👉 Planning an upcoming label revision? Download the ISO 13485 Gap Assessment Checklist to verify your revision management process is capturing changes to standards before they become audit findings.


Do You Need to Update Your Labels Right Now?

The most common objection: “Do we need to reprint every label immediately?”

No. The Commission built in a five-year coexistence period. Manufacturers may continue using the legacy “EC REP” symbol under the original EN ISO 15223-1:2021, or transition to the new “EU REP” symbol under the amendment — both are valid during this window. The old standard’s reference isn’t withdrawn until June 15, 2031 under MDR and June 17, 2031 under IVDR. After those dates, only “EU REP” confers presumption of conformity.

In practice, this means:

  • If you are about to run a new label print or design revision anyway → use the new EU REP symbol now rather than reprinting again later.
  • If your current labels are compliant and not due for revision → there is no requirement to act immediately; plan the change into your next scheduled label update.
  • If you have a Notified Body conformity review coming up → confirm with them directly whether they expect the new symbol in your current submission, since individual Notified Body expectations can vary during a transition window.

Common ISO 15223 Labeling Nonconformances

Most common finding: inconsistent symbol usage across packaging levels — the outer carton uses one version of the authorized representative symbol while the inner unit label uses another, with no documented rationale for the difference.

Other recurring issues: sterilization method symbols that don’t match the actual method used (ethylene oxide vs. irradiation vs. steam each has a distinct symbol); batch code or serial number symbols placed on a label without the actual batch or serial data adjacent to them; and reused label templates that carry forward a superseded symbol simply because nobody flagged the amendment during change control review.

⚠️ None of these mistakes require a new symbol library to fix — they require a label governance process that actually checks current symbol validity before a label goes to print, not just before the first label was ever approved.


Quick Reference Checklist

Professional infographic showing a medical device label review checklist based on ISO 15223-1, including symbol verification, sterilization validation, traceability, packaging consistency, and revision control.
A structured label review process helps manufacturers verify ISO 15223-1 symbol compliance before medical devices move into production or distribution.

✅ Current label set reviewed against the live ISO 15223-1:2021 symbol library ✅ Sterilization method symbol matches the actual method used
✅ Batch code, catalogue number, and serial number symbols paired with real data
✅ EU REP transition plan documented, even if no immediate label change is required
✅ Packaging levels (outer carton, inner unit, IFU) checked for symbol consistency
✅ Change control process flags standard amendments, not just initial approvals


FAQ

What is ISO 15223-1:2021?

It’s the international standard defining the pictograms used on medical device labels, packaging, and accompanying information — covering everything from manufacturer identity to sterilization method. It’s currently in its fourth edition and harmonized under both EU MDR and IVDR.

Do I have to switch to the EU REP symbol immediately?

No. The European Commission built in a five-year coexistence period. The legacy EC REP symbol remains valid until the original standard’s reference is withdrawn — June 15, 2031 under MDR and June 17, 2031 under IVDR.

Is the EU REP change a safety-related update?

No. The Commission has described it as a purely editorial change, made to eliminate confusion with Ecuador’s ISO 3166-1 country code. It does not change the authorized representative’s role or responsibilities.

What’s the difference between ISO 15223-1 and ISO 15223-2?

Part 1 defines the actual symbol library and how symbols must be used. Part 2 covers the process for developing, selecting, and validating a new symbol when nothing in the existing library fits a specific need.

Does every medical device need every symbol in the standard?

No. Which symbols apply depends on the device — a non-sterile reusable device won’t carry sterilization symbols, for example. The standard defines what each symbol means and how to use it correctly; it doesn’t mandate that every device carry every symbol.

What’s the most common labeling mistake regulatory teams miss?

Inconsistent symbol usage across packaging levels — using an updated symbol on one layer of packaging while an older version persists on another, usually because a label template wasn’t fully reviewed during a revision.

Where can I find the actual symbol library?

ISO 15223-1:2021 and its companion ISO 15223-2 are both available for purchase through ANSI Webstore, either individually or as a combined package.

Should my Notified Body confirm which symbol version they expect?

During the transition period, manufacturers should confirm expectations directly with their Notified Body, particularly if a labeling review or conformity assessment is already underway.


📥 Free Resources

  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements, including the revision management processes that keep labeling current.
  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system from the ground up.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements across production environments.

Not Sure What to Do Next?

🔹 Still researching how labeling symbols fit into your broader QMS? Start with ISO 13485 Documentation Requirements and Common Mistakes in ISO 13485 QMS to see where document control connects to labeling accuracy.

🔹 Ready to review your current label set? Check it against Sterilization Standards Overview and UDI Requirements Explained — both cover label-adjacent requirements that pair directly with ISO 15223-1 symbols.

🔹 Need to purchase the standard itself? Get the ISO 15223 Symbols Package from ANSI Webstore — available individually or bundled with Part 2, with code CC2026 for 5% off through December 31, 2026.


Symbols look like a small detail until one of them is wrong on a printed label already in circulation. The Standards Navigator will keep tracking the EU REP transition and any further ISO 15223 amendments as they’re published.

Don’t Let a Symbol Be the Reason for a Finding

Labeling nonconformances are some of the most avoidable findings in a Notified Body review — the standard is published, the symbols are defined, and the fix is almost always a revision management gap rather than a technical one.

The Standards Navigator tracks ISO 15223 amendments, MDR/IVDR labeling requirements, and medical device documentation standards so your labels don’t fall out of step with a standard that changed while nobody was watching.

👉 Get updates on ISO 15223, MDR/IVDR labeling changes, and medical device documentation requirements as they happen
👉 Be first to access new gap assessment tools built for medical device regulatory affairs teams

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

MDR vs. ISO 13485: What’s the Difference and Which One Do You Actually Need in 2026?

EU MDR and ISO 13485 solve different problems — one is law, the other is a certifiable QMS standard. This guide breaks down the core differences, current 2026–2027 MDR transition timelines, and a decision framework for regulatory affairs teams navigating both.

A regulatory affairs guide to two rules that get confused constantly — and cost time when they are

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Question That Stalls Every EU Market Entry Meeting

Somewhere in almost every medical device compliance kickoff, someone asks it: “We already have ISO 13485. Doesn’t that cover MDR?”

It doesn’t. And the gap between MDR vs ISO 13485 — a certified quality management system and an EU-compliant technical file — is where CE marking timelines quietly slip by six to twelve months.

MDR (Regulation (EU) 2017/745) and ISO 13485 aren’t competing standards. They aren’t interchangeable either. One is EU law. The other is a voluntary international standard that EU law happens to lean on heavily. Confusing the two doesn’t just cost time — it costs Notified Body findings, delayed submissions, and in some cases, a device that can’t legally reach the European market on schedule.

From the floor: I’ve sat in a management review where a director insisted the ISO 13485 certificate meant the technical documentation was “basically done” for an EU submission. It wasn’t. The certificate covered their quality system — design controls, CAPA, document control. It said nothing about the clinical evaluation report, MDR classification requirements, or the device-specific evidence required for conformity assessment. They spent the next quarter closing that gap instead of reviewing it calmly six months earlier. That’s the exact mistake this article exists to prevent.

👉 Before you assume your QMS certification covers your EU submission, run the gap check. Most regulatory affairs teams don’t fail because they misunderstand ISO 13485 — they fail because they assumed certification and market access were the same milestone. Get the ISO 13485 Gap Assessment Checklist and find out before a Notified Body does.

In This Guide

  • What EU MDR 2017/745 actually regulates
  • What ISO 13485 actually certifies
  • The core differences, side by side
  • Why “ISO 13485 certified” doesn’t mean “MDR compliant”
  • Where the two genuinely overlap — risk management, CAPA, design controls, and more
  • Current MDR transition timelines and 2026 developments
  • Which one you need — and when you need both
  • Common documentation mistakes that surface in Notified Body reviews
  • FAQ

Table of Contents

  1. What Is EU MDR 2017/745?
  2. What Is ISO 13485?
  3. MDR vs. ISO 13485: Core Differences
  4. Why Manufacturers Conflate the Two
  5. Where MDR and ISO 13485 Overlap
  6. MDR Transition Timelines: Where Things Stand in 2026
  7. Do You Need Both? A Decision Framework
  8. Common Mistakes That Surface in Notified Body Review
  9. Quick Reference Checklist
  10. FAQ

👉 Start Here


What Is EU MDR 2017/745?

MDR is law, not a certifiable management system standard. Regulation (EU) 2017/745 governs what a manufacturer must prove — about a specific device — before that device can carry a CE mark and legally reach the EU market.

It covers device classification (Class I through III), clinical evaluation and clinical data requirements, technical documentation per Annexes II and III, post-market surveillance and post-market clinical follow-up (PMCF), Unique Device Identification (UDI) and EUDAMED registration, and — for higher-risk devices — Notified Body conformity assessment under Annex IX.

MDR replaced the older Medical Device Directive (MDD) and Active Implantable Medical Devices Directive (AIMDD), and it raised the bar substantially on clinical evidence and post-market obligations compared to both.

What Is ISO 13485?

ISO 13485 is a voluntary, internationally recognized quality management system standard for organizations involved in the design, production, or servicing of medical devices. It’s certifiable — a Notified Body or accredited certification body audits your QMS against the standard’s clauses and issues a certificate if you pass.

ISO 13485 uses maintaining effectiveness language throughout, not the continual improvement language found in ISO 9001. It’s structured around risk-based thinking applied specifically to design controls, document and record control, supplier controls, CAPA, and management review — the operational backbone a device manufacturer needs regardless of which market it sells into.

Since FDA’s QMSR took effect February 2, 2026, 21 CFR Part 820 incorporates ISO 13485:2016 by reference — making it the enforceable quality management system standard for U.S. device manufacturers, not merely a reference point.

MDR vs. ISO 13485: Core Differences

CategoryEU MDR 2017/745ISO 13485
NatureEU law — mandatory for CE markingVoluntary international standard
ScopeDevice-specific: classification, clinical evidence, technical fileOrganization-wide: the QMS itself
Who assesses itNotified Body (device-level conformity assessment)Certification body (QMS audit)
Grants market access?Yes — required for CE marking in the EUNo — supports it, doesn’t grant it
Geographic reachEU/EEA market onlyRecognized globally; now foundational to FDA QMSR
What it producesTechnical documentation, CER, PMS/PMCF plan, EUDAMED registrationA certificate covering your quality management system
Update cycleAmended by EU legislative process (ongoing 2025–2027 reform)Revised through ISO’s standard TC 210 process
Professional infographic comparing EU MDR 2017/745 and ISO 13485:2016, highlighting differences in regulatory requirements, quality management systems, CE marking, clinical evaluation, and technical documentation for medical device manufacturers.
This infographic compares EU MDR and ISO 13485, illustrating how one governs market access while the other establishes the quality management system that supports regulatory compliance.

Quick Answer:

  • Need CE marking? → MDR is required.
  • Need a compliant medical device QMS? → ISO 13485 is required.
  • Selling medical devices in the EU? → You almost certainly need both.

The stakes behind that table are real: the European Commission’s most recent Notified Bodies survey, published March 2026, showed roughly half of submitted MDR applications had reached certificate issuance — a gap driven largely by device misclassification, incomplete technical documentation, and thin clinical evidence, not by Notified Body capacity alone.


Why Manufacturers Conflate the Two

The most common objection I hear: “We’re ISO 13485 certified — why do we need a separate MDR effort?”

Here’s the resolution: ISO 13485 certification tells a Notified Body your quality system is sound. It says nothing about whether a specific device’s clinical evidence, risk classification, or technical file meets MDR’s requirements. A company can hold a spotless ISO 13485 certificate and still receive a Notified Body finding on a device submission because the clinical evaluation report was thin, the PMCF plan was missing, or the classification rule was misapplied under Annex VIII.

Think of it this way: ISO 13485 certifies the kitchen is clean and the process is controlled. MDR conformity assessment asks whether this specific dish meets the recipe, the nutrition label is accurate, and there’s a plan to keep checking it after it ships. You need both, but they answer different questions.

👉 If you are relying on your ISO 13485 certificate as your MDR readiness proof, that’s the gap to close first. Run the ISO 13485 Gap Assessment Checklist against your current technical files before your next Notified Body interaction.

Where MDR and ISO 13485 Overlap

Venn diagram infographic showing where EU MDR 2017/745 and ISO 13485:2016 overlap, highlighting shared quality management processes including risk management, design controls, CAPA, complaint handling, and supplier controls for medical device manufacturers.
This infographic illustrates the operational areas shared by EU MDR and ISO 13485 while distinguishing the unique regulatory and quality management requirements of each framework.

If they’re really two separate things, why does everyone talk about them in the same breath? Because the same five operational areas show up in both — just assessed from different angles.

  • Risk management — MDR requires risk management per Annex I general safety and performance requirements; ISO 13485 Clause 4.1.2 requires a risk-based approach throughout the QMS. Most manufacturers run one risk management process (typically ISO 14971-aligned) that satisfies both.
  • CAPA — ISO 13485 Clause 8.5 governs corrective and preventive action as a QMS requirement. MDR’s post-market surveillance and vigilance obligations feed directly into that same CAPA process when a field issue is identified.
  • Design controls — ISO 13485 Clause 7.3 sets design and development requirements; MDR’s technical documentation under Annex II leans on those same design records as evidence of a controlled development process.
  • Supplier controls — ISO 13485 Clause 7.4 requires supplier evaluation and monitoring; MDR expects that same supplier oversight to extend into the technical file wherever a supplier-controlled process affects device safety or performance.
  • Complaint handling — ISO 13485 Clause 8.2.2 sets complaint-handling requirements; MDR’s vigilance reporting obligations under Article 87 depend on that same complaint intake process to catch reportable events.

This is the practical reason ISO 13485 certification and MDR technical documentation feel like the same conversation even though they’re legally distinct: a well-run QMS produces most of the raw material an MDR technical file needs. The gap is rarely in these five areas — it’s in whether that raw material gets assembled into a device-specific technical file the way MDR expects.

MDR Transition Timelines: Where Things Stand in 2026

The transition provisions have shifted more than once since MDR took effect in May 2021, and manufacturers still working under legacy MDD or AIMDD certificates need to track the current deadlines carefully:

  • Class III custom-made implantable devices: compliance required by May 26, 2026
  • Class III and certain implantable Class IIb devices: transition extends to December 31, 2027
  • Most other Class IIb, IIa, and Class I devices: transition extends to December 31, 2028

Legacy device status under these extended timelines requires a valid MDD/AIMDD certificate, no significant design or intended-use change, continued compliance with the original directive, and a signed agreement with an MDR-designated Notified Body.

Separately, the European Commission published a proposal on December 16, 2025 to simplify and reduce administrative burden under both MDR and its IVDR counterpart — including changes to PRRC availability requirements and certificate validity limits. That proposal is still moving through the EU’s ordinary legislative process, and current projections put final adoption no earlier than the second quarter of 2027. Nothing in that proposal changes your obligations today. Manufacturers should keep building technical documentation to the current MDR text rather than waiting on a reform that hasn’t been adopted.

Timeline infographic showing the EU MDR transition deadlines for legacy medical devices in 2026, 2027, and 2028, along with ongoing requirements for technical documentation, clinical evaluation, post-market surveillance, and Notified Body agreements.
This timeline summarizes the current EU MDR transition deadlines for legacy medical devices while highlighting the ongoing compliance activities manufacturers must maintain throughout the transition period.

Do You Need Both? A Decision Framework

  • If you are selling into the EU market → MDR compliance is mandatory, full stop. ISO 13485 certification is not legally required by MDR text, but in practice Notified Bodies expect it as evidence your QMS can sustain the technical file over time.
  • If you are U.S.-only and not yet EU-bound → FDA’s QMSR incorporates ISO 13485:2016 by reference into 21 CFR Part 820, making alignment with ISO 13485 the foundation of U.S. medical device QMS compliance as of February 2, 2026. Third-party certification isn’t mandated by FDA, but the standard’s substance now is.
  • If you are already ISO 13485 certified and expanding into the EU → treat MDR as a device-level project layered on top of your existing QMS, not a QMS rebuild. The gap is almost always in clinical evidence and technical documentation, not in your quality processes.
  • If you are under customer or investor pressure to move fast → get the ISO 13485 gap assessment done first. It surfaces documentation gaps in days instead of finding them mid-audit.

Common Mistakes That Surface in Notified Body Review

Most common finding: Clinical evaluation reports that summarize literature but never tie evidence back to the specific device’s risk profile under Annex I general safety and performance requirements.

Other recurring gaps: PMCF plans that exist as a template but were never executed against real post-market data; UDI and EUDAMED registration treated as an afterthought instead of a parallel workstream; and design change records that don’t clearly show which MDR classification rule applied after a design modification.

⚠️ A Notified Body finding on any of these doesn’t necessarily mean your ISO 13485 QMS has failed — it usually means the QMS and the MDR technical file were built as two separate projects instead of one connected effort.

Quick Reference Checklist

✅ ISO 13485 certificate current and audit-ready
✅ Technical documentation mapped to current MDR Annex II/III requirements ✅ Clinical evaluation report tied to device-specific risk profile
✅ PMCF plan active and generating real post-market data
✅ UDI assigned and EUDAMED registration current
✅ Notified Body agreement in place if relying on legacy transition timelines
✅ Design change records show which classification rule applies post-modification


FAQ

Does ISO 13485 certification satisfy MDR requirements?

No. ISO 13485 certifies your quality management system. MDR requires separate, device-specific technical documentation, clinical evidence, and — for most devices — Notified Body conformity assessment. Certification supports MDR compliance; it doesn’t substitute for it.

Is ISO 13485 mandatory for the EU market?

MDR text doesn’t explicitly mandate ISO 13485 certification, but in practice, Notified Bodies expect a certified QMS as part of demonstrating your ability to sustain compliance. Most manufacturers pursuing MDR conformity hold ISO 13485 certification for this reason.

Do U.S.-only manufacturers need to worry about MDR?

Not directly, unless you plan to sell into the EU. However, FDA’s QMSR — effective February 2, 2026 — makes ISO 13485:2016 the operative U.S. regulation, so ISO 13485 alignment now matters regardless of whether MDR applies to you.

What’s the current MDR transition deadline for legacy devices?

It depends on device classification: Class III custom-made implantables faced a May 26, 2026 deadline, Class III and certain implantable Class IIb devices extend to December 31, 2027, and most other devices extend to December 31, 2028 — provided legacy status conditions are met.

Is the EU actually changing MDR requirements soon?

The European Commission proposed simplification changes on December 16, 2025, but the proposal is still in the EU legislative process, with final adoption not expected before the second quarter of 2027. Current MDR requirements remain fully in effect in the meantime.

What’s the biggest documentation gap Notified Bodies flag?

Clinical evaluation reports that summarize literature broadly without tying the evidence directly to the specific device’s risk profile under the general safety and performance requirements.

Can one gap assessment cover both ISO 13485 certification readiness and MDR technical file readiness?

A well-structured gap assessment should flag both, but they’re different reviews at their core — one audits your QMS against ISO 13485 clauses, the other audits your technical documentation against MDR annexes. Treat them as connected but distinct workstreams.

Where should a manufacturer start if pursuing both?

Start with the QMS. A certified, functioning ISO 13485 system gives you the document control, CAPA, and design control infrastructure that MDR technical documentation depends on. Building MDR documentation on top of a shaky QMS just relocates the problem.


📥 Free Resources

  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements before certification or a Notified Body review.
  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system from the ground up.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements across production environments.

Not Sure What to Do Next?

🔹 Still researching the difference between MDR and ISO 13485? Start with What Is ISO 13485? and FDA QSR vs. ISO 13485 to ground the fundamentals before your next planning meeting.

🔹 Ready to close the documentation gap? Review ISO 13485 Documentation Requirements and Validation & Verification Requirements against your current technical files.

🔹 Need to purchase the standard itself? Get ISO 13485:2016 directly from ANSI Webstore — available internationally, with multi-language editions for global regulatory teams. Use code CC2026 for 5% off through December 31, 2026.


MDR and ISO 13485 solve different problems, and treating them as one project is how audit-ready timelines slip by a quarter or more. The Standards Navigator will keep tracking both as EU reform proposals and FDA QMSR guidance continue to evolve through 2026 and 2027.

Stop Guessing Where Your MDR Gap Actually Is

Regulatory teams that treat MDR and ISO 13485 as one combined project usually discover the gap during a Notified Body review — the worst possible time to find it. Teams that separate the two, and check each on its own terms, walk into that review with documentation that already matches what’s being asked.

The Standards Navigator tracks EU MDR developments, FDA QMSR alignment, and ISO 13485 implementation detail so medical device teams aren’t relying on outdated guidance six months into a submission.

👉 Get updates on MDR, ISO 13485, and medical device regulatory changes as they happen
👉 Be first to access new gap assessment tools and documentation resources for regulatory affairs teams

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.





ISO 9001:2026 Is Coming — What Manufacturers Should Do Right Now

The ISO 9001:2026 FDIS ballot closes July 9, 2026, moving the revision closer to its expected September 2026 publication. This guide covers the confirmed timeline, the four biggest changes coming, and what certified and uncertified manufacturers should do right now — without touching a currently valid QMS.

What the FDIS Ballot Closing Means for Your Certification Timeline

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Ballot Just Closed. Here’s What That Actually Means for You.

On July 9, 2026, the Final Draft International Standard (FDIS) ballot for ISO 9001:2026 closed. That’s a real milestone — the technical content of the revision is now locked. No more comments, no more redlines. What’s left is a yes/no vote from ISO member bodies and, assuming approval, formal publication expected in September 2026.

Here’s what that milestone does not mean: it does not mean ISO 9001:2015 stopped being certifiable today. It does not mean your registrar is going to show up next quarter demanding a new QMS. And it does not mean you need to panic-rewrite your quality manual this week.

What it does mean is that the window to prepare — calmly, on your own schedule, instead of during a scramble — just opened wider. Manufacturers who start reviewing the coming changes now will walk into their transition audit in 2027 or 2028 with a head start. Manufacturers who wait for the “official” publication date to even look at what’s changing will be doing gap analysis under a deadline instead of on their own terms.

From the Floor: I helped a mid-size weld supply company navigate through the ISO 9001:2015 transition and saw firsthand what happens when a revision catches a QMS flat-footed. The technical changes weren’t the hard part. The hard part was cramming eighteen months of documentation review into six because nobody started early. That’s the mistake I’m not interested in watching manufacturers repeat with this revision.

If you are already ISO 9001:2015 certified and want a head start before your next surveillance cycle, run your current QMS against a structured gap check now — before the standard is even published →

👉 Get the ISO 9001 Roadmap — a step-by-step implementation and readiness guide built for manufacturers, updated for what’s coming in the 2026 revision.

In This Guide

  • What actually happened on July 9, 2026, and what stage the revision is at now
  • The confirmed publication and transition timeline
  • The four biggest changes coming in ISO 9001:2026
  • What to do right now if you’re already certified
  • What to do right now if you’re not yet certified
  • The most common mistake manufacturers make with standard revisions
  • Whether you need to take any action today (short answer: no — but read this anyway)


👉 Start Here (Top Resources)


What Happened on July 9, 2026

The FDIS is the last drafting stage before formal publication. Unlike the earlier Draft International Standard (DIS) stage — where technical content was still open to comment — the FDIS ballot is strictly a yes/no vote on the finished text. ISO member bodies can flag editorial issues, but the substance of the standard is done.

The ballot closing on July 9, 2026 marks the completion of the final approval stage before publication. Barring an unexpected outcome during ballot resolution, ISO 9001:2026 remains on track for publication in September 2026. Barring an unusual rejection at this stage — which is rare for management system standards this far along — ISO 9001:2026 is expected to publish in September 2026. ISO/TC 176/SC 2 — the ISO technical subcommittee responsible for ISO 9001 — is the authoritative source tracking the revision’s progress, and their committee updates confirm this timeline directly.

Most common finding: Organizations that assume “not published yet” means “nothing to do yet” consistently underestimate how much internal review time a revision actually takes — even a modest one.


The Confirmed Timeline

Infographic showing the ISO 9001:2026 revision timeline from the 2025 Draft International Standard through the July 2026 FDIS ballot, expected September 2026 publication, and anticipated three-year transition period.
A visual timeline of the ISO 9001:2026 revision process, highlighting key milestones from the Draft International Standard to the expected transition period for certified organizations.
StageDateStatus
Draft International Standard (DIS) publishedAugust 27, 2025Complete
DIS comment period closed, technical consensus reachedEarly 2026Complete
Final Draft International Standard (FDIS) ballotClosed July 9, 2026Complete
Formal publication of ISO 9001:2026Expected September 2026Pending
Transition period for ISO 9001:2015 certificate holders~3 years from publicationExpected to run to approximately September 2029

⚠️ ISO 9001:2015 remains the only certifiable version of the standard right now. Nothing changes for audits, certifications, or QMS requirements until ISO 9001:2026 is formally published and your certification body confirms transition procedures. Don’t change your documented QMS based on the draft — change it once the transition guidance is confirmed.


What’s Actually Changing in ISO 9001:2026

Infographic highlighting the four biggest confirmed changes expected in ISO 9001:2026, including leadership and quality culture, risk and opportunity management, quality policy, and climate context.
This infographic summarizes the four key themes expected in the ISO 9001:2026 revision, helping manufacturers understand where to focus their transition planning.

The core clause structure — Plan-Do-Check-Act, the ten-clause Harmonized Structure, risk-based thinking — is not being rebuilt. This is an evolutionary revision, not a rewrite. The confirmed areas of change center on four themes:

AreaWhat’s ChangingWhy It Matters on the Shop Floor
Leadership & quality cultureTop management must explicitly demonstrate and promote quality culture and ethical behavior, not just policy commitmentAuditors will start asking how culture shows up in behavior, not just in the quality manual
Risk and opportunity managementClause 6.1 is being split into clearer sub-sections distinguishing risk treatment from opportunity pursuitYour risk register may need a structural update, not just new content
Quality policyClause 5.2 requirements are tightened to explicitly connect policy to organizational contextGeneric, boilerplate quality policies will be more exposed in audits
Climate contextFormal integration of climate-related considerations into Clause 4.1 context-of-the-organization requirementsFacilities with environmental exposure (fabrication, coatings, energy) should expect this to come up in context reviews

These four themes are drawn from the confirmed DIS/FDIS commentary tracked by ISO/TC 176/SC 2 and reflected in certification-body FDIS briefings; final wording won’t be public until formal publication, but the substance is locked at this stage.

Here’s what each one could actually look like on the floor:

Quality culture and leadership. This isn’t a new policy statement — it’s evidence. Think visible leadership participation in corrective-action reviews, quality KPIs discussed in leadership meetings (not just buried in a QMS report), and recognition tied to quality performance rather than just output. Auditors will likely start asking to see this, not just read about it.

Risk and opportunity management. If your risk register currently lumps “things that could go wrong” and “things we could improve” into one column, this is the change to watch. Splitting them means your CAPA-driven risk items and your strategic-opportunity items may need separate tracking and separate review cadence.

Quality policy. A generic policy statement — “we are committed to quality” — won’t hold up as well once policy has to explicitly tie to organizational context. A fabrication shop’s policy should read differently than a Tier 1 automotive supplier’s, and the revision is designed to expose the ones that don’t.

Climate context. For a coatings operation, a railcar service facility, or an energy-sector manufacturer, this likely means documenting how weather exposure, emissions requirements, or environmental permitting already shape your operations — not adding new environmental management requirements on top of ISO 9001.

None of these require you to touch your certified QMS today. They do tell you where your internal audit program should start paying closer attention over the next 12–18 months.


If You’re Already Certified to ISO 9001:2015

If you are already ISO 9001:2015 certified → your certificate remains fully valid. Nothing about your current status changes today. Your job right now is preparation, not action.

If you are heading into a surveillance audit in the next 6–12 months → this is the ideal window to start a light-touch internal review of how your quality policy, leadership commitment statements, and risk register would hold up against the themes above. You’re not rewriting anything — you’re identifying gaps early.

If you are under customer or contract pressure to show revision-readiness → get ahead of the conversation now. A documented internal gap review, even an informal one, is something you can point to if a customer or auditor asks what you’re doing about the upcoming revision.

Run a structured check against the coming changes before your next surveillance audit, not after your registrar flags something →

👉 Download the Manufacturing Compliance Checklist — a practical reference covering ISO, OSHA, and quality requirements manufacturers can use to spot gaps before they become findings.

Decision flow infographic helping manufacturers determine whether to prepare for the ISO 9001:2026 transition based on their current ISO 9001 certification status.
This decision guide shows the recommended next steps for both certified and non-certified organizations preparing for the upcoming ISO 9001:2026 revision.

If You’re Not Yet Certified

If you are not yet certified and are evaluating whether to start now or wait → start now. ISO 9001:2015 is still the only certifiable version, the transition window will run for roughly three years past publication, and the 2026 changes are evolutionary rather than structural. Building your QMS to 2015 requirements today puts you in a strong position to absorb the 2026 updates with minor adjustments rather than a second implementation project.

If you are choosing between a consultant and a documentation kit for your first build → this decision matters more with a revision on the horizon, because you want a foundation flexible enough to update rather than replace. See our ISO Implementation Packages vs. Consultants comparison for a full breakdown.

Most first-time QMS builds don’t fail because the standard is misunderstood — they fail because the documentation was never structured to be updated. Build it right the first time →

👉 Explore 9001Simplified’s documentation kits — built on the current 2015 structure and easier to adapt when the transition guidance is confirmed.


The Mistake Most Manufacturers Make With Standard Revisions

Every ISO 9001 revision cycle produces the same pattern: organizations wait for the “final” publication before doing anything, then compress 18 months of review into six once the transition clock starts. It happened with the 2015 revision. It’s likely to happen again here, even though this revision is smaller in scope.

The objection I hear most is some version of: “Why would I prepare for a standard that isn’t even published yet?” Fair question. The answer is that none of the confirmed changes require you to touch your certified system today — but reviewing your quality policy, leadership commitment language, and risk register against where the standard is heading costs you almost nothing now and saves real time later. You’re not implementing anything. You’re reading ahead.


Gap-Assessment Snapshot

Use this as a quick self-rating before your next management review. Score each area honestly — this isn’t a formal audit, just a starting point for where to focus first.

AreaCurrent Readiness (High / Med / Low)Action Needed
Leadership & quality cultureReview how leadership commitment is demonstrated, not just documented
Quality policyAlign policy language explicitly to organizational context
Risk managementSeparate risk-treatment items from opportunity items in your register
Climate contextUpdate context-of-the-organization analysis to reflect environmental exposure

Quick Readiness Checklist

✅ Confirm your certification body’s current guidance — some registrars will issue transition bulletins ahead of formal IAF confirmation
✅ Review your quality policy for generic language that doesn’t tie to organizational context
✅ Check whether your risk register separates risk treatment from opportunity pursuit
✅ Note where leadership commitment is documented — policy statement only, or observable practice too
✅ If your facility has environmental exposure, flag climate-related context for your next management review
✅ Do not revise your documented QMS based on the draft — wait for confirmed transition guidance


FAQ

Is ISO 9001:2026 published yet?

No. As of July 9, 2026, the FDIS ballot has closed but the standard has not been formally published. Publication is expected in September 2026.

Can I still get certified to ISO 9001:2015 right now?

Yes. ISO 9001:2015 is the only certifiable version of the standard until ISO 9001:2026 is published and certification bodies confirm transition procedures.

How long will the transition period be?

Based on the approach used for recent ISO management system revisions, a three-year transition period is expected, running to approximately September 2029 — though this will be confirmed once the standard is formally published.

Do I need to change my QMS documentation today?

No. Nothing in your certified quality management system needs to change based on the draft. Wait for confirmed transition guidance from your certification body.

What are the biggest changes coming in ISO 9001:2026?

Expanded leadership requirements around quality culture and ethical behavior, a clearer split between risk treatment and opportunity management in Clause 6.1, tightened quality policy requirements in Clause 5.2, and formal integration of climate-related context into Clause 4.1.

Is this a major rewrite of ISO 9001?

No. The core Plan-Do-Check-Act structure, the ten-clause Harmonized Structure, and risk-based thinking all remain intact. This is an evolutionary revision, not a restructuring.

Should I wait to start my first ISO 9001 certification until the 2026 version is out?

No. Building to ISO 9001:2015 now, with the three-year transition window ahead, puts you in a stronger position than waiting — and the 2026 changes are incremental rather than structural.

Where can I track official updates on the revision?

ISO’s own committee pages and your certification body’s published bulletins are the most reliable sources. Avoid making QMS changes based on secondhand summaries of the draft.


📥 Free Resources

  • ISO 9001 Roadmap — a step-by-step implementation guide for manufacturers building or improving a quality management system ahead of the 2026 transition.
  • Manufacturing Compliance Checklist — a practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.
  • Supplier Quality Checklist — an evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.

Not Sure What to Do Next?

🔹 Still researching what’s changing? Read our full ISO 14001 / ISO 9001 / ISO 45001 2026 Transition Guide for the harmonized-structure view across all three standards.

🔹 Ready to start a gap review of your current QMS? Grab the ISO 9001 Roadmap and work through it against your existing documentation.

🔹 Need to buy the current standard to review against? Purchase ISO 9001:2015 through ANSI Webstore — code CC2026 for 5% off.

🔹 Building or rebuilding your QMS documentation from scratch? 9001Simplified’s documentation kits give you a 2015-based structure built to adapt when transition guidance is confirmed.


The FDIS ballot closing is a procedural milestone, not a deadline. But it’s the clearest signal yet that ISO 9001:2026 is close, and the manufacturers who read ahead now will be the ones who aren’t scrambling in 2027. The companies that transition smoothly won’t necessarily be the ones with the best quality systems — they’ll be the ones that started preparing before the deadline forced them to. At The Standards Navigator, we’ll keep tracking this revision clause by clause as confirmed details land.

Stay Ahead of the ISO 9001:2026 Transition

Most manufacturers don’t lose ground on a standard revision because the changes are hard — they lose ground because they wait for the official publication date to even start looking. By then, the transition clock is already running and everyone else’s registrar is booked solid too.

Organizations that start reviewing their quality policy, leadership documentation, and risk register now will walk into their first 2026-based audit prepared. Organizations that wait will be doing the same work under pressure, competing for the same registrar time slots as everyone else.

The Standards Navigator tracks every confirmed development in the ISO 9001:2026 revision as it happens — no speculation, no secondhand summaries.

👉 Get updates on the ISO 9001:2026 transition as confirmed details are published
👉 Be first to access new gap-assessment tools built specifically for the 2026 changes

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.