Medical Device Compliance Standards: What Manufacturers Need to Know in 2026

Medical device manufacturers face a layered compliance framework — ISO 13485, ISO 14971, FDA QMSR, and EU MDR each impose specific requirements that must work together as an integrated system. This guide explains the core standards, how they interact, and what manufacturers need to prioritize at each stage of the compliance process.

The regulatory framework every medical device manufacturer must understand before the first audit

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Compliance Gap That Gets Medical Device Manufacturers in Trouble

Most medical device manufacturers don’t fail audits because they ignored the requirements. They fail because they didn’t understand how the requirements connect — and which standards they were actually obligated to meet.

The medical device compliance standards landscape is layered. ISO 13485 sets the QMS framework. ISO 14971 governs risk management. FDA regulations run parallel to international standards and don’t always align. Supplier controls, sterilization validation, design controls, and labeling each carry their own standard reference. A manufacturer who treats these as independent checkboxes instead of an integrated system is building toward an audit finding — or worse, a product recall.

The stakes are not abstract. The FDA issued 483 observations totaling thousands of findings in the medical device sector last year. Most cited documentation gaps, inadequate CAPA processes, or failure to meet design control requirements — all areas governed by the standards covered in this guide.

I’ve worked in quality systems that span heavy industrial, energy, and manufacturing environments — and the pattern I’ve seen across every sector is the same: organizations that struggle with audits are usually managing compliance requirements in silos. In the medical device world, that problem is amplified because the regulatory framework is both more complex and less forgiving than most industrial standards. Getting the structure right before your first audit is not optional — it’s the difference between certification and a warning letter.

Before you map your compliance requirements, download the ISO 13485 Gap Assessment Checklist — it walks you through every clause so you can identify exactly where your QMS falls short before an auditor does → ISO 13485 Gap Assessment Checklist

In This Guide:

  • The core standards every medical device manufacturer must know
  • How ISO 13485, ISO 14971, and FDA regulations interact
  • US vs. EU regulatory requirements compared
  • Supplier control and special process standards
  • Decision-stage guidance: what to prioritize based on where you are in the compliance process

👉 Start Here — Top Resources


The Core Standard: ISO 13485:2016

ISO 13485:2016 infographic showing clause structure and comparison of ISO 13485 versus ISO 9001 requirements for medical device quality management systems.
A visual breakdown of ISO 13485:2016 requirements and how they differ from ISO 9001 for medical device manufacturers.

ISO 13485:2016 is the international standard for quality management systems specific to medical device manufacturers and their supply chains. It is the foundation of medical device compliance worldwide.

ISO 13485 is not simply ISO 9001 with medical device language added. The two standards share structural similarities through the harmonized high-level clause structure, but ISO 13485 imposes stricter requirements in several critical areas ISO 9001 leaves to organizational discretion:

Requirement AreaISO 9001:2015ISO 13485:2016
Risk managementRisk-based thinking (general)Formal risk management required (links to ISO 14971)
Design controlsRequiredMore prescriptive — validation, verification, design transfer
CAPARequiredMore detailed — specific investigation and effectiveness checks
Regulatory requirementsNot addressedExplicitly required — must identify and meet applicable regs
Sterile product controlsNot addressedSpecific controls for sterile devices
Supplier controlsRequiredMore stringent — supplier qualification and monitoring
Document and record retentionNot specifiedSpecific retention periods tied to device lifetime

If you are ISO 9001 certified and entering the medical device market, you are not starting from scratch — but you are adding significant requirements. The gap is larger than most manufacturers expect.

If you need the standard itself, ISO 13485:2016 is available through the ANSI Webstore — use code CC2026 for 5% off through December 31, 2026.

Most common finding: Inadequate document control — specifically, failure to control the review and approval of documents and maintain records of changes. ISO 13485 Clause 4.2 is one of the most frequently cited areas in FDA 483 observations.


Risk Management: ISO 14971:2019

ISO 14971 is the international standard for risk management applied to medical devices. It is not optional if you are manufacturing medical devices — ISO 13485 explicitly requires you to apply risk management throughout the product lifecycle, and ISO 14971 is the recognized method for doing it.

ISO 14971:2019 defines the process for:

  • Identifying hazards associated with a medical device
  • Estimating and evaluating associated risks
  • Controlling those risks
  • Monitoring the effectiveness of controls

The relationship between ISO 13485 and ISO 14971 is not optional. ISO 13485 Clause 7.1 requires organizations to establish risk management requirements for product realization. ISO 14971 is the standard that defines what “proper” risk management looks like. Auditors will look for evidence that your risk management file connects directly to your design controls, production processes, and post-market surveillance activities.

ISO 14971 vs. ISO 13485 — understanding how they interact is one of the most common questions from manufacturers building a QMS for the first time.

If your risk management files exist independently of your design control documentation — that is an audit finding waiting to happen. Most teams miss the linkage between hazard identification in the risk management file and the verification/validation activities in the design history file.

Run your gap assessment before you go further — most QMS gaps in medical device companies trace back to missing connections between ISO 14971 risk files and ISO 13485 design controls: ISO 13485 Gap Assessment Checklist


US Regulatory Requirements: FDA QMSR and 21 CFR Part 820

US medical device manufacturers operate under FDA jurisdiction. The Quality Management System Regulation (QMSR), which took effect February 2, 2026, replaced the legacy Quality System Regulation (QSR) under 21 CFR Part 820.

The QMSR represents a significant shift: it incorporates ISO 13485:2016 by reference as the baseline for device QMS requirements. This means FDA-regulated manufacturers who are ISO 13485 certified are closer to QMSR compliance than they were under the old QSR — but important differences remain.

AreaISO 13485:2016FDA QMSR (2026)
ScopeInternationalUS market devices only
ComplaintsRequiredRequired + specific MDR reporting timelines
Corrections and removalsAddressed in CAPASpecific FDA reporting requirements (21 CFR Part 806)
UDINot addressedRequired for most device classes
Electronic recordsNot specified21 CFR Part 11 compliance required
Third-party auditsRequired for ISO 13485 certificationFDA inspections — not third-party certification

Understanding the relationship between FDA QSR and ISO 13485 is essential for US manufacturers — the two frameworks are now more aligned than before, but they are not identical.

If you are selling devices in the US market, FDA QMSR compliance is a legal requirement, not a voluntary certification. ISO 13485 certification does not satisfy FDA obligations — it demonstrates QMS capability but does not substitute for an FDA inspection.

Comparison infographic showing US FDA QMSR and EU MDR regulatory pathways for medical device manufacturers and ISO 13485 quality system requirements.
A side-by-side comparison of US FDA QMSR and EU MDR pathways showing how medical device compliance differs across global markets.

EU Requirements: MDR and CE Marking

Selling medical devices in the European Union requires CE marking under the EU Medical Device Regulation (MDR 2017/745), which replaced the Medical Device Directive (MDD) and came into full effect in 2021. The transition deadline for legacy MDD-certified devices has been extended but enforcement has tightened significantly.

Key MDR requirements relevant to QMS:

MDR RequirementConnection to ISO 13485
Technical documentationDesign history file / DHF requirements
Clinical evaluationPost-market clinical follow-up (PMCF)
Unique Device Identification (UDI)Traceability requirements
Post-market surveillance (PMS)Customer feedback and complaint monitoring
Notified Body auditISO 13485 certification is typically required
Person Responsible for Regulatory Compliance (PRRC)Management responsibility — ISO 13485 Clause 5

The MDR is more prescriptive than ISO 13485 in clinical evidence requirements. If you are exporting to the EU, your clinical evaluation report and post-market surveillance plan must meet MDR requirements that go beyond what ISO 13485 explicitly requires.

If you are selling in both the US and EU markets, you are managing two regulatory frameworks simultaneously. This is where a well-structured ISO 13485 QMS becomes particularly valuable — it provides the common foundation that both frameworks build on.


Supplier Controls and Special Process Standards

ISO 13485 Clause 7.4 imposes stricter supplier control requirements than most manufacturers new to the medical device space expect. You are not simply verifying that a supplier has a quality system — you are responsible for ensuring that purchased products and services meet specified requirements and that critical suppliers are evaluated, approved, and monitored.

For medical device manufacturers, supplier controls must address:

  • Supplier qualification — documented criteria for evaluation and approval
  • Incoming inspection — defined acceptance criteria for purchased product
  • Critical supplier monitoring — ongoing performance data, not just initial qualification
  • Supplier audits — for high-risk or critical component suppliers
  • Flow-down requirements — pushing your quality requirements into the supply chain

Special processes — sterilization, biocompatibility testing, coating, welding on implantable components — require additional validation documentation. The relevant standards include:

ProcessStandard Reference
Sterilization (EO, radiation, steam)ISO 11135, ISO 11137, ISO 17665
BiocompatibilityISO 10993 series
Packaging validationASTM F2132, ISO 11607
Software validationIEC 62304
Electrical safetyIEC 60601 series

These are not optional for manufacturers of the relevant device types. If your device is sterilized, you need sterilization validation documentation. If it contacts patient tissue, you need biocompatibility data. Gaps in special process validation are among the most serious findings an FDA inspector or Notified Body auditor can cite.


Design Controls and Validation Standards

ISO 13485 design controls infographic showing the Design History File process from inputs through outputs, verification, validation, and design transfer.
A visual guide to the ISO 13485 design controls process and how design inputs become validated, production-ready medical devices.

Design controls are where ISO 13485 certification and FDA compliance intersect most directly. ISO 13485 Clause 7.3 requires a structured design and development process covering:

  • Design and development planning
  • Design inputs (requirements)
  • Design outputs (specifications)
  • Design review at defined stages
  • Design verification (does it meet inputs?)
  • Design validation (does it meet user needs?)
  • Design transfer (can it be manufactured consistently?)
  • Design changes (controlled and documented)

The design history file (DHF) is the physical record of this entire process. It is the first thing an FDA inspector or Notified Body auditor will request. Manufacturers who build their DHF as a collection of unconnected documents — rather than as a traceable record linking inputs to outputs to verification to validation — create significant risk for themselves.

If you are new to building a medical device QMS and need a structured path through these requirements, the ISO 13485 Implementation Roadmap on The Standards Navigator covers the full sequence from gap assessment through certification.

BSI Group offers ISO 13485 training covering both requirements understanding and implementation — useful for teams building their first medical device QMS or transitioning from a general ISO 9001 system.


Labeling and Traceability Standards

Labeling compliance is a specific, frequently cited area in FDA 483 observations. Under both FDA QMSR and MDR requirements, device labeling must meet defined content and format requirements — and the label must be controlled as a quality record.

Key labeling standards and requirements:

  • ISO 15223-1 — symbols used in medical device labeling (required for EU MDR compliance)
  • 21 CFR Part 801 — FDA labeling requirements for US devices
  • UDI requirements — FDA requires Unique Device Identification on most device labels, with submission to the GUDID database

Traceability connects directly to your CAPA and complaint handling processes. If a complaint involves a specific lot or device unit, your traceability records must be sufficient to identify affected products, investigate the root cause, and determine corrective action scope. ISO 13485 Clause 7.5.9 addresses traceability explicitly — and auditors will test it.


How the Standards Work Together

Layered medical device compliance standards infographic showing ISO 13485 as the foundation with ISO 14971, FDA QMSR, EU MDR, supplier controls, CAPA, and traceability requirements.
A visual framework showing how ISO 13485, FDA QMSR, EU MDR, and supporting standards connect into an integrated medical device compliance system.

The most important thing to understand about medical device compliance is that these standards are not independent — they form an integrated system. Here is how they connect:

StandardRole in the System
ISO 13485:2016QMS framework — the backbone that everything else connects to
ISO 14971:2019Risk management process — required by ISO 13485, referenced throughout
FDA QMSRUS regulatory layer — builds on ISO 13485, adds FDA-specific requirements
EU MDREU regulatory layer — requires ISO 13485 certification via Notified Body
IEC 62304Software lifecycle — required if your device includes software
ISO 10993Biocompatibility — required for patient-contacting devices
ISO 15223Labeling symbols — required for EU MDR labeling compliance

A manufacturer who has ISO 13485 certification, a complete ISO 14971 risk management file, and solid FDA QMSR documentation has built the framework that all additional standards layer onto. The common mistake is treating each standard as a separate compliance project rather than building the integrated system first.

If you are deciding between prioritizing FDA QMSR or ISO 13485 certification first: in most cases, building to ISO 13485 gives you the QMS foundation that both US and EU regulatory compliance require. The ISO 13485 Documentation Requirements article covers what your QMS documentation set must include.


Quick Compliance Checklist

Use this as a starting reference — not a substitute for a clause-by-clause gap assessment.

✅ ISO 13485:2016 obtained and QMS scope defined
✅ Risk management procedure in place referencing ISO 14971
✅ Design controls documented — inputs, outputs, verification, validation, transfer
✅ CAPA process established with effectiveness verification
✅ Supplier qualification and monitoring program documented
✅ Document and record control procedures in place with defined retention periods
✅ Internal audit program scheduled and resourced
✅ Management review process defined and conducted
✅ Complaint handling and MDR/vigilance reporting process established
✅ UDI requirements evaluated and implemented where applicable
✅ Applicable special process validations identified and documented
✅ Labeling reviewed against ISO 15223 (EU) and 21 CFR Part 801 (US)

⚠️ If you cannot check most of these — complete a formal gap assessment before committing to a certification timeline.


FAQ

Is ISO 13485 certification required to sell medical devices?

ISO 13485 certification is not legally required by US law — the FDA requires QMSR compliance, not ISO 13485 certification specifically. However, ISO 13485 certification is required to sell devices in the EU under MDR, and it is increasingly required by OEM customers and contract manufacturers as a condition of doing business. Most manufacturers targeting both markets pursue certification.

How is ISO 13485 different from ISO 9001?

ISO 13485 is a sector-specific standard derived from ISO 9001 but with significantly stricter requirements in risk management, design controls, CAPA, supplier controls, and regulatory compliance. It does not include the continual improvement emphasis that ISO 9001 requires — instead it focuses on consistent compliance with regulatory requirements. A detailed comparison is covered here.

Do I need ISO 14971 if I am ISO 13485 certified?

Yes. ISO 13485 explicitly requires risk management throughout the product lifecycle and references ISO 14971 as the applicable method. You are not ISO 13485 compliant if your risk management process does not meet ISO 14971 requirements. The two standards work together — you cannot separate them.

What is the FDA QMSR and how is it different from the old QSR?

The Quality Management System Regulation (QMSR) took effect February 2, 2026 and replaced 21 CFR Part 820 (the Quality System Regulation). The QMSR incorporates ISO 13485:2016 by reference, making it more aligned with the international standard. Key differences remain around FDA-specific reporting requirements, UDI obligations, and 21 CFR Part 11 electronic records requirements. A full breakdown of FDA QSR vs ISO 13485 is here.

How long does it take to get ISO 13485 certified?

For a manufacturer building a QMS from scratch, 12–18 months is a realistic timeline. Organizations with an existing ISO 9001 QMS can often close the gap in 6–12 months, depending on how many medical device-specific requirements need to be added. The ISO 13485 Implementation Roadmap covers the full timeline in detail.

What is a Notified Body and do I need one?

A Notified Body is an organization designated by EU member states to assess conformity of medical devices under the MDR. If you are seeking CE marking for Class IIa, IIb, or Class III devices, you must engage a Notified Body — they conduct the audits that verify ISO 13485 compliance and technical documentation. BSI Group is one of the major Notified Bodies offering both training and certification services.

What are the most common ISO 13485 audit findings?

The most frequently cited areas include: inadequate document and record control (Clause 4.2), incomplete CAPA processes with missing effectiveness verification (Clause 8.5.2), insufficient supplier qualification documentation (Clause 7.4), and gaps in design control records — particularly missing design verification and validation evidence (Clause 7.3). Common mistakes in ISO 13485 QMS implementation covers these in detail.

Do my suppliers need to be ISO 13485 certified?

Not necessarily — but you are responsible for ensuring purchased product meets specifications regardless. Whether a supplier needs ISO 13485 certification depends on their criticality and what they supply. Critical component suppliers and contract manufacturers of finished devices are typically expected to be certified. Commodity suppliers may only require documented incoming inspection.


📥 Free Resources

ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements — medical device articles only

ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system

Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments

Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts

AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification


Not Sure What to Do Next?

🔹 Still researching your compliance requirements? Start with a gap assessment against ISO 13485 before you invest in implementation. Download the free ISO 13485 Gap Assessment Checklist — it maps every clause so you know exactly where you stand.

🔹 Ready to build your QMS? ISO 13485 training through BSI Group covers requirements, implementation, and internal auditor training — the right sequence for a team building their first medical device QMS.

🔹 Need the standard itself? Buy ISO 13485:2016 through the ANSI Webstore — use code CC2026 for 5% off through December 31, 2026. International buyers can purchase in multiple languages.


Medical device compliance is not a single standard — it is a framework of interconnected requirements that must be built and maintained as a system. Understanding how ISO 13485, ISO 14971, FDA QMSR, and EU MDR relate to each other is the first step toward building a QMS that holds up under audit. The Standards Navigator covers each of these standards in depth — start with the resources above and build from there.


Stay Current on Medical Device Compliance

Regulatory changes in the medical device space don’t slow down. FDA QMSR took effect in 2026. EU MDR enforcement is intensifying. ISO 14971 continues to be misapplied by manufacturers who treat risk management as a documentation exercise rather than an integrated process.

Organizations that keep pace with these changes have one thing in common — they’re not waiting for an audit finding to tell them something changed. The ones that struggle are managing compliance reactively, updating their QMS only when a customer or inspector forces the issue.

The Standards Navigator covers ISO 13485, ISO 14971, FDA regulatory requirements, and the full medical device compliance framework — from standard purchase through certification and ongoing surveillance.

👉 Get updates when new medical device compliance articles publish
👉 Be first to access the ISO 13485 Documentation Kit when it launches

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

ISO 13485 Implementation Roadmap: How to Build a Compliant Medical Device QMS in 2026

ISO 13485:2016 is now US federal law under the FDA QMSR, making a compliant medical device QMS mandatory rather than optional. This roadmap walks manufacturers through a seven-phase implementation — from gap assessment and scope through risk management, documentation, CAPA, and certification — covering both the international certification path and FDA inspection readiness for US manufacturers building from the ground up.

A step-by-step guide to implementing ISO 13485:2016 — from gap assessment to certification and FDA QMSR readiness

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Building a Medical Device QMS Is No Longer Optional in the United States

For years, ISO 13485 sat in a strange position for US manufacturers. It was the global benchmark for medical device quality management — required to sell in the EU, Canada, and most of the world — but inside the United States it was voluntary. You complied with FDA’s Quality System Regulation, and ISO 13485 was a nice-to-have for export.

That changed on February 2, 2026. FDA’s Quality Management System Regulation (QMSR) took effect, replacing the old Quality System Regulation and incorporating ISO 13485:2016 by reference directly into 21 CFR Part 820. The practical effect is blunt: ISO 13485:2016 is now part of US federal law. FDA inspections are conducted against it. The standard you could once ignore at home is now the framework your inspector arrives with.

So whether you are a US manufacturer preparing for your first QMSR-aligned FDA inspection, or an international supplier chasing your first ISO 13485 certificate to unlock the EU market, you face the same task: build a quality management system that survives outside scrutiny. This roadmap walks you through it — clause by clause, phase by phase — from the day you decide to start to the day a registrar or an FDA investigator walks through the door.

This ISO 13485 implementation roadmap is a long article because building a medical device QMS is a long project. Use the table of contents to jump to where you are.


Before you build anything, find out where you actually stand. Most teams overestimate how compliant their existing processes are — and discover the gaps during the certification audit or FDA inspection, when fixing them is expensive and the clock is running. Run a clause-by-clause check against ISO 13485:2016 first.

👉 Download the free ISO 13485 Gap Assessment Checklist and benchmark your QMS in an afternoon, before you commit budget to implementation.


In This Guide

  • Why ISO 13485 implementation looks different in 2026 (QMSR, EU reforms)
  • The realistic timeline and cost of a full implementation
  • A seven-phase roadmap from gap assessment to certificate
  • How risk management (ISO 14971) and design controls fit into the QMS
  • The documentation you actually need — and where teams over-build
  • Internal audit, management review, and Stage 1 / Stage 2 audit preparation
  • FDA QMSR inspection readiness for US manufacturers
  • The mistakes that fail audits — and how to avoid them


👉 Start Here (Top Resources)

If you are implementing ISO 13485 from scratch, these are the three resources that move the project fastest:

  • Build your documentation without a consultant. A complete, pre-written ISO 13485 documentation kit gives you the quality manual, procedures, and records templates structured to the standard — so you spend your time tailoring, not drafting from a blank page. 👉 See the ISO 13485 documentation kits at 9001Simplified
  • Get the official standard. You cannot implement a clause you have not read. Buy ISO 13485:2016 from the ANSI Webstore — use code CC2026 for 5% off through December 31, 2026. ANSI serves international buyers and offers standards in multiple languages.
  • Train your internal team. Your management representative and internal auditors need formal training. BSI Group offers ISO 13485 training courses spanning awareness through lead auditor.

What Makes 2026 Different

ISO 13485:2016 is still the current edition — and it will be for a while. ISO postponed the next revision deliberately to let the 2016 edition “bed in,” with a new version not expected before roughly 2028–2029. So the standard you implement today is the standard you will operate under for years. That stability is good news: it means your implementation work has a long shelf life.

What has shifted is the regulatory context around the standard.

In the United States, the QMSR is the headline. FDA now incorporates ISO 13485:2016 into 21 CFR Part 820, layered with a handful of FDA-specific additions — labeling, UDI, and certain record and definition provisions — that go beyond the ISO text. A critical nuance: the QMSR is “version locked” to the 2016 edition. Future ISO 13485 revisions will not automatically apply in the US unless FDA initiates new rulemaking. Certification to ISO 13485 is still not legally required in the US — FDA inspects you directly — but building your QMS to the standard is now the most direct path to QMSR compliance.

In the European Union, the pressure point is notified body capacity, not the standard itself. EU Implementing Regulation 2026/977, published in May 2026 and applying from February 25, 2027, finally imposes hard maximum timelines on notified bodies — 30 days to review an application and sign a contract, 120 days for the QMS audit, 90 days for product verification, and 20 days to issue the certificate, with capped clock-stops and transparent quotations. For manufacturers, the message is that the certification path is becoming more predictable, but you still need a clean, audit-ready QMS to take advantage of it.

One more 2026 wrinkle worth flagging if your devices touch biocompatibility: FDA’s recognition of the sixth edition of ISO 10993-1 is partial. Notably, FDA does not recognize Clause 6.9 on biological risk estimation, holding that it conflicts with the recognized risk management standard ISO 14971:2019. If your risk files cite ISO 10993-1 wholesale, that is now a deficiency-letter risk in US submissions. Keep biological risk inside the ISO 14971 framework. We cover biocompatibility in depth separately — for this roadmap, just know that your risk management process is the anchor, not the 10993 series.

If you sell only in the US → build to ISO 13485:2016 for QMSR compliance and skip certification unless a customer demands it. If you sell internationally → you need an actual ISO 13485 certificate from an accredited registrar, so plan for a Stage 1 / Stage 2 audit. If you sell in both markets → build one QMS to ISO 13485:2016 and bolt on the FDA-specific QMSR additions; do not run two parallel systems.

QMSR vs ISO 13485 at a Glance

The two frameworks now share a core, but they are not identical. This is where US and international readers diverge — and where a single well-built QMS can serve both.

DimensionISO 13485:2016FDA QMSR (21 CFR Part 820)
Legal statusVoluntary international standardMandatory US federal regulation
Core requirementsThe full ISO 13485 QMSIncorporates ISO 13485:2016 by reference
Proof of complianceCertificate from accredited registrarFDA inspection — no certificate issued
Added requirementsNone beyond the standardLabeling, UDI, certain records & definitions
Risk managementReferences ISO 14971Requires ISO 14971 framework; rejects ISO 10993-1 Clause 6.9
Version handlingISO may revise (~2028–2029)“Version locked” to the 2016 edition
Who needs itAnyone selling internationallyAny device manufacturer marketing in the US

For the full treatment, see our dedicated FDA QSR vs ISO 13485 comparison.


Timeline and Cost: What to Expect

A realistic ISO 13485 implementation runs 6 to 12 months for a small-to-mid-size manufacturer building from a limited starting point. Companies already operating a mature ISO 9001 system or a legacy QSR-based system can move faster; companies starting from informal processes should plan for the full year.

ISO 13485 implementation timeline infographic showing a phased 6 to 12 month roadmap for medical device manufacturers progressing from gap assessment through certification.
A visual roadmap showing a realistic ISO 13485 implementation timeline from assessment through certification readiness.
PhaseTypical durationWhat drives it
Gap assessment & scope2–4 weeksSize of the gap between current practice and the standard
Process & documentation build8–16 weeksWhether you draft from scratch or start from templates
Implementation & operation8–12 weeksYou need real records, not just documents — audits want evidence
Internal audit & management review3–4 weeksMust be complete before a registrar will proceed to Stage 2
Certification (Stage 1 + Stage 2)6–10 weeksRegistrar scheduling and any nonconformity closure

On cost, the single biggest variable is whether you hire a consultant to draft your system or build it yourself from a structured template. Consultant-led implementations commonly run $15,000–$50,000+ depending on device class and company size. A template-driven build can cut the documentation labor dramatically. For a full breakdown, see our guide on how much ISO 13485 certification costs.


Phase 1 — Foundation: Scope, Standard, and Leadership Commitment

Everything downstream depends on getting three things right at the start.

Define your QMS scope. ISO 13485 lets you exclude certain requirements — for example, design and development (Clause 7.3) if you are a contract manufacturer building to a customer’s design. But exclusions must be justified and documented, and you cannot exclude something just because it is inconvenient. Map which clauses apply to your role: manufacturer, specification developer, contract manufacturer, sterilization provider, or importer. Your scope statement is the first thing a registrar reads and the boundary an FDA investigator works within.

Acquire and read the standard. This sounds obvious and gets skipped constantly. You cannot delegate compliance with a document nobody on the team has read end to end. Buy the official ISO 13485:2016 text from the ANSI Webstore — apply coupon CC2026 for 5% off through the end of 2026 — and have your management representative work through it clause by clause. If you also need the risk management standard, ISO 14971:2019 is available there too. ANSI’s catalog covers international buyers and multiple languages, which matters if your QMS spans sites.

Secure genuine leadership commitment. Clause 5 puts top management on the hook — quality policy, quality objectives, resource allocation, and management review are not delegable to a quality manager working in isolation. The fastest implementations have an executive sponsor who clears roadblocks. The ones that stall have a quality team trying to impose a system the leadership treats as paperwork.

If you are a contract manufacturer → document your design and development exclusion now, with justification, before you build the rest of the system around it.

⚠️ Common pitfall: Claiming a Clause 7.3 exclusion you can’t defend. If your team does any design input — even tweaking a customer’s spec for manufacturability — a registrar may reject the exclusion and you’ll be retrofitting design controls mid-project. Decide your true scope honestly before you build.


Most ISO 13485 projects don’t fail on the standard — they fail on documentation that nobody can find, follow, or defend in an audit. Before you write a single procedure, make sure you know which records the standard actually requires.

👉 Run the gap assessment and map your existing documents against the clauses — it turns “we think we’re covered” into a defensible list.


Phase 2 — Plan: Processes, Roles, and Competence

ISO 13485 is a process-based standard. Before documentation, map your actual processes and how they connect — the “sequence and interaction” the standard requires.

Identify your core processes. At minimum: management processes (planning, review, resourcing), product realization (design, purchasing, production, servicing), and support processes (document control, records, CAPA, internal audit). For each, define inputs, outputs, owners, and the records that prove it ran.

Appoint a management representative. Clause 5.5.2 requires a member of management responsible for the QMS. This person owns the system, reports its performance to leadership, and is typically the registrar’s main point of contact.

Plan competence and training. Clause 6.2 requires that personnel performing work affecting product quality are competent — with records to prove it. This includes your internal auditors, who must be trained and independent of the areas they audit. Formal training shortens the learning curve here; BSI Group’s ISO 13485 course catalog runs from awareness through lead auditor, and the lead-auditor tier is what equips your internal audit program to find problems before the registrar does. For audit methodology itself, note that the underlying guidance standard, ISO 19011, was updated to a 2026 edition in May 2026 — worth referencing when you write your internal audit procedure.

⚠️ Common pitfall: Treating internal auditor “independence” as a formality. Having someone audit their own department is one of the most common nonconformities — and it quietly undermines every finding that audit produces. Cross-train auditors so no one reviews work they own.


Phase 3 — Risk Management and Design Controls

This is where ISO 13485 separates itself from ISO 9001, and where the most consequential implementation decisions live.

Risk management is the spine. ISO 13485 threads risk-based thinking through the entire product lifecycle, and it leans on ISO 14971:2019 as the method. You need a risk management process, a risk management file for each device or device family, and evidence that risk controls are verified and monitored in production and post-market. As noted earlier, keep biological risk inside this ISO 14971 framework rather than importing a separate scoring approach — that alignment is exactly what FDA expects under the QMSR.

Design controls (Clause 7.3) apply if you develop devices. This is the discipline FDA investigators scrutinize hardest, because design failures are where patients get hurt. You need:

Design control elementWhat it requires
Design and development planningA documented plan with stages, reviews, and responsibilities
Design inputsRequirements derived from intended use, user needs, and regulation
Design outputsSpecifications that can be verified against inputs
Design reviewFormal reviews at planned stages with independent reviewers
Design verificationEvidence outputs meet inputs
Design validationEvidence the device meets user needs in actual or simulated use
Design transferControlled handoff to production
Design changesControlled, reviewed, and documented changes
Design history file (DHF)The complete record of the above

If you are a US manufacturer, the QMSR keeps design controls firmly in play — they map directly onto the ISO 13485 Clause 7.3 requirements, which is one reason a single ISO-aligned system now serves both purposes.

If you are preparing your first device submission → build the risk management file and design history file in parallel with the QMS, not after. Auditors and investigators expect to see them populated, not planned.

⚠️ Common pitfall: Building the risk file as a one-time document for the submission, then never touching it again. Risk management is a living, lifecycle requirement — production and post-market data have to feed back into it. A risk file frozen at launch is a finding waiting to happen.


Phase 4 — Build the Documentation

Now you write the system. ISO 13485 expects a defined documentation hierarchy: a quality manual, documented procedures, work instructions, forms, and the records they generate.

ISO 13485 documentation architecture infographic showing the five-layer quality management documentation hierarchy from quality manual through records.
A visual breakdown of the five documentation layers used to build and maintain an ISO 13485 quality management system.

The required documents. ISO 13485:2016 explicitly requires certain documented procedures — document control, record control, management review, internal audit, control of nonconforming product, CAPA, and several product-realization procedures among them. A medical device file (technical documentation) is required for each device type. Our breakdown of ISO 13485 documentation requirements lists exactly what the standard mandates versus what is optional.

Where teams over-build. The most common documentation mistake is writing procedures more detailed and rigid than the operation can actually follow. Every sentence in a procedure is a commitment an auditor can hold you to. If your procedure says calibration happens every 90 days and a record shows 95, that is a nonconformity you created with your own words. Write to what you do; improve what you do separately.

Start from a structured template, not a blank page. Drafting an entire ISO 13485 documentation set from scratch is where 6-month projects become 12-month projects. A complete documentation kit gives you the quality manual, every required procedure, and the records templates already structured to the clauses — so your team spends its hours tailoring language to your operation instead of reinventing the architecture of a QMS.

👉 See what’s included in the 9001Simplified ISO 13485 documentation kit — it is the no-consultant route most small manufacturers should evaluate first.

Set up document and record control before you generate volume. Clauses 4.2.4 and 4.2.5 require controlled documents and controlled records. Get the control mechanism — versioning, approval, retention, retrieval — working before you have hundreds of documents to retrofit.

⚠️ Common pitfall: Over-documenting. Teams write procedures so detailed and rigid that the floor can’t actually follow them — then every deviation from their own paperwork becomes a nonconformity. Document what you genuinely do, keep procedures lean, and push the specifics down into work instructions where they’re easier to change.


Phase 5 — Implement and Operate

A documented QMS proves nothing. Auditors and investigators want records that show the system ran.

This is the phase teams underestimate. You can write a CAPA procedure in a day; demonstrating that CAPA actually works requires real CAPAs opened, investigated, and closed over weeks. Plan for an operating period — typically 8 to 12 weeks minimum — where the system runs and generates genuine evidence: training records, calibration records, completed reviews, supplier evaluations, nonconformance reports, and CAPA records.

A registrar will not progress to a certification audit, and an FDA investigator will not be satisfied, by documents alone. Both want to trace a process from requirement to record to outcome. Build that evidence trail before you invite anyone to inspect it.

If you are under customer pressure to certify quickly → start operating the system in parallel with finishing documentation, so your evidence trail is already accumulating when the documents are signed off.

⚠️ Common pitfall: Booking the certification audit before the system has actually run. A registrar can tell the difference between a QMS that has operated for three months and one that generated all its records last week. Backdated or thin evidence is the fastest way to turn a Stage 2 audit into a list of nonconformities.


Phase 6 — CAPA, Supplier Controls, and Production Controls

Three areas generate the most audit findings and FDA 483 observations. Get them right and you de-risk the entire certification.

CAPA (Corrective and Preventive Action). This is the single most-cited area in medical device QMS audits. A weak CAPA system — actions opened and never closed, root causes not actually identified, effectiveness never verified — signals to an auditor that the whole system is decorative. Your CAPA process must show genuine root cause analysis, defined actions, and verified effectiveness. Our deep dive on CAPA requirements in ISO 13485 covers the failure modes in detail.

Supplier and purchasing controls (Clause 7.4). You are accountable for what your suppliers provide. You need defined supplier evaluation criteria, approved-supplier records, and controls proportionate to the risk the purchased product carries. Flow your quality requirements down in writing — handshake arrangements do not survive audits.

Production and process controls (Clauses 7.5). This includes process validation for any process whose output cannot be fully verified by later inspection — sterilization and certain welding or molding processes are classic examples — plus identification, traceability, and handling of product. Cleanliness, contamination control, and installation/servicing requirements apply where relevant to your device.

A documentation kit accelerates this layer too. The CAPA log, supplier evaluation forms, nonconformance records, and validation templates are exactly the high-stakes documents you do not want to invent under deadline.

👉 A structured kit gives you defensible templates for all three areas so your effort goes into running the processes, not formatting the paperwork.

Avoid the recurring traps documented in our guide to common mistakes in ISO 13485 QMS implementation — most failures are predictable.

⚠️ Common pitfall: Closing CAPAs without verifying effectiveness. “We retrained the operator” is not a closed CAPA — it’s an action with no proof it worked. Auditors reopen these constantly. Every CAPA needs a defined effectiveness check and evidence it passed before you close it.


Phase 7 — Internal Audit, Management Review, and Certification

Before any external party inspects you, inspect yourself.

Internal audit (Clause 8.2.4). Conduct a full internal audit of your QMS against ISO 13485 using trained, independent auditors. This is your dress rehearsal — the audit that finds problems while you still control the timeline and the narrative. Document findings, open CAPAs, and close them.

Management review (Clause 5.6). Top management formally reviews QMS performance against defined inputs — audit results, customer feedback, process performance, CAPA status, and more — and produces documented outputs and decisions. Registrars treat a missing or hollow management review as a serious gap.

The certification audit (international path). An accredited registrar conducts a two-stage audit:

StageFocusOutcome
Stage 1Documentation review and readinessConfirms the system is ready for Stage 2; identifies gaps
Stage 2On-site implementation auditVerifies the system operates as documented; raises any nonconformities

Close any nonconformities, and the registrar issues your certificate — typically valid for three years with annual surveillance audits. Choosing an accredited registrar matters; verify accreditation through bodies like ANAB or the relevant IAF member. Our guide to the best ISO certification bodies walks through selection.

⚠️ Common pitfall: Running a hollow management review to check the box. A review that doesn’t actually examine audit results, CAPA status, and process performance — and produce real decisions — is treated by registrars as a serious gap, because it signals leadership isn’t engaged. Make it substantive, and keep the minutes.


FDA QMSR Inspection Readiness

If you are a US manufacturer, your “certification audit” may instead be an FDA inspection — and the bar is the QMSR, which now runs on ISO 13485:2016 plus FDA’s additions.

Practical readiness steps:

  • Map ISO 13485 to the QMSR additions. Most of your ISO-aligned system satisfies Part 820 directly. Layer in the FDA-specific requirements — labeling and packaging controls, UDI, and certain record and complaint-handling provisions — that exceed the ISO text.
  • Keep your records inspection-ready, not audit-ready-once. FDA inspections are unannounced or short-notice. The evidence trail from Phase 5 has to be standing, not assembled on demand.
  • Treat CAPA and complaint handling as the focal points. These are where 483 observations concentrate. A clean, closed-loop CAPA system is your strongest signal of control.
  • Understand the relationship between the two frameworks. Our comparison of FDA QSR vs ISO 13485 explains exactly what the QMSR changed and where the frameworks now align.

For US manufacturers selling internationally, the efficient move is one ISO 13485 QMS with the QMSR additions built in — not two systems. The frameworks now overlap by design.


Quick Implementation Checklist

Use this as a high-level progress tracker. Each item maps to a phase above.

  • ✅ QMS scope defined and exclusions justified in writing
  • ✅ Official ISO 13485:2016 (and ISO 14971:2019) acquired and read
  • ✅ Top management commitment secured; quality policy and objectives set
  • ✅ Management representative appointed
  • ✅ Core processes mapped with owners, inputs, outputs, and records
  • ✅ Personnel competence and internal auditor training in place
  • ✅ Risk management process and risk management file established (ISO 14971)
  • ✅ Design controls and design history file in place (if you develop devices)
  • ✅ Quality manual, required procedures, and record templates written
  • ✅ Document control and record control operating before volume builds
  • ✅ System operated long enough to generate genuine records (8–12 weeks)
  • ✅ CAPA system demonstrably closing the loop with verified effectiveness
  • ✅ Supplier evaluation and purchasing controls documented and flowed down
  • ✅ Process validation completed where output can’t be fully verified
  • ✅ Full internal audit completed; findings closed
  • ✅ Management review conducted with documented outputs
  • ✅ Registrar selected (international) or QMSR inspection readiness confirmed (US)
  • ✅ Stage 1 and Stage 2 audit passed; nonconformities closed

FAQ

How long does ISO 13485 implementation take?

For a small-to-mid-size manufacturer building from a limited starting point, plan for 6 to 12 months. Companies with a mature ISO 9001 system or a legacy QSR-based system can move faster, while organizations starting from informal processes should plan for the full year. The longest single phase is usually documentation, followed by the operating period needed to generate real records.

Is ISO 13485 certification required in the United States?

No. FDA inspects US manufacturers directly against the QMSR, which incorporates ISO 13485:2016 — certification by a third-party registrar is not legally required. However, building your QMS to ISO 13485 is now the most direct path to QMSR compliance, and certification is required to sell in the EU, Canada, and most international markets. Many US manufacturers certify anyway to serve global customers and demonstrate a recognized standard of control.

What is the difference between ISO 13485 and the FDA QMSR?

The QMSR, effective February 2, 2026, replaced FDA’s old Quality System Regulation and incorporates ISO 13485:2016 by reference into 21 CFR Part 820, plus FDA-specific additions covering labeling, UDI, and certain records. The two are now largely aligned by design. The QMSR is “version locked” to the 2016 edition, so future ISO 13485 revisions will not automatically apply in the US. See our full FDA QSR vs ISO 13485 comparison for detail.

Do I need ISO 14971 to implement ISO 13485?

Effectively, yes. ISO 13485 threads risk-based thinking through the product lifecycle and relies on the methodology in ISO 14971:2019 for risk management. You need a documented risk management process and a risk management file for each device. We explain the relationship in ISO 14971 vs ISO 13485.

Can a contract manufacturer exclude design controls?

Yes, if you build strictly to a customer’s design and do not perform design and development activities. ISO 13485 permits excluding Clause 7.3, but the exclusion must be justified and documented in your QMS scope. You cannot exclude a requirement simply because it is burdensome — only because it genuinely does not apply to your role.

What causes most ISO 13485 audit findings?

CAPA weaknesses lead the list — actions that never close, root causes not genuinely identified, and effectiveness never verified. Document and record control, supplier controls, and process validation are also frequent finding areas. Our guide to common ISO 13485 QMS mistakes covers the recurring patterns.

Should I hire a consultant or use a documentation kit?

It depends on device class, internal capacity, and budget. Consultant-led implementations offer hands-on guidance but commonly run $15,000–$50,000 or more. A structured documentation kit gives you the full QMS architecture — manual, procedures, and record templates — at a fraction of that cost, so your team tailors rather than drafts from scratch. Many small manufacturers start with a kit and bring in targeted consulting only for device-specific risk and design questions.

What is ISO 13485 and who needs it?

ISO 13485 is the international quality management system standard for organizations involved in the medical device lifecycle — design, production, storage, distribution, installation, and servicing. It applies to manufacturers, specification developers, contract manufacturers, sterilization providers, and importers. Our primer, What Is ISO 13485?, covers the fundamentals.


📥 Free Resources

Practical tools to support your implementation — download what fits your project:

  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements, clause by clause, before committing to implementation.
  • ISO 9001 Roadmap — step-by-step implementation guide for organizations building or improving a quality management system, useful if you operate an ISO 9001 base alongside 13485.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.
  • AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification, for teams operating across aerospace and medical device lines.

Not Sure What to Do Next?

Your next step depends on where you are in the project:

  • 🔹 If you haven’t assessed your gap yet → start with the free ISO 13485 Gap Assessment Checklist. Don’t commit budget to implementation until you know the size of the gap.
  • 🔹 If you’re ready to build documentation → evaluate a complete ISO 13485 documentation kit before paying consultant rates to draft from scratch. It is the fastest route to an audit-ready document set for most small manufacturers.
  • 🔹 If you’re comparing the US and international paths → read FDA QSR vs ISO 13485 and how much ISO 13485 costs to scope budget and timeline before you choose.

Building an ISO 13485 QMS is a real project, but it is a known one. The clauses are fixed, the phases are sequential, and the failure modes are predictable. Move through it in order, build real evidence as you go, and inspect yourself before anyone else does — and a certification audit or FDA inspection becomes a confirmation, not a gamble. The Standards Navigator exists to make exactly this kind of industrial compliance work clear and survivable for the people who have to actually do it.


Most teams don’t fail ISO 13485 because they misunderstand the standard — they fail because they assumed they were compliant and found out during the audit. The organizations that struggle treat the QMS as paperwork to satisfy a registrar. The organizations that succeed treat it as the operating system that proves their devices are safe — and they build evidence from day one.

The Standards Navigator covers medical device compliance from QMSR readiness to risk management, CAPA, and certification — written from operational and quality management experience, not generic theory.

  • 👉 Get updates on medical device QMS, ISO 13485, and FDA QMSR compliance
  • 👉 Be first to access new gap assessment tools, documentation guides, and implementation resources

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

Aerospace Supplier Compliance Standards: What Every Supplier Needs to Know in 2026

Aerospace suppliers face a layered compliance landscape — AS9100 certification is the baseline, but NADCAP accreditation, First Article Inspection, counterfeit parts controls, and customer flow-down requirements are equally enforced. This guide covers every standard and program aerospace primes audit against, with practical checklists and implementation guidance for quality managers.

The complete guide to AS9100, NADCAP, FAI, and the quality requirements aerospace primes actually enforce

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Aerospace Supply Chain Has a Short Memory for Second Chances

You get one bad audit. One missed First Article Inspection. One nonconformance that reaches the flight line. That is all it takes to lose an aerospace contract you spent years building.

Aerospace primes — Boeing, Lockheed Martin, Raytheon, Northrop Grumman — do not operate on goodwill. They operate on documented, auditable evidence that every supplier in their chain meets a defined set of compliance requirements. Those requirements are not flexible. They are not negotiable. And they are layered — meaning AS9100 certification alone does not cover everything your customer may require.

This aerospace supplier compliance standards guide breaks down the full compliance landscape: the standards, the programs, the certification requirements, and what aerospace suppliers actually get audited against on the shop floor.

If you are preparing for your first aerospace contract, adding an aerospace customer to an existing customer base, or trying to understand why your customer’s supplier quality team keeps asking for documentation you did not know you needed — this is where to start.

Before your Stage 1 audit, know exactly where your QMS stands. Run a clause-by-clause gap assessment now — before your registrar does. Download the AS9100 Rev D Gap Assessment Checklist →


In This Guide

  • The AS9100 Rev D standard and what it requires beyond ISO 9001
  • NADCAP accreditation — what it is, which processes require it, and when it applies
  • First Article Inspection (AS9102) — scope, deliverables, and common findings
  • Counterfeit parts prevention and AS5553/AS6174
  • FOD control requirements
  • Customer-specific flow-down requirements and how to manage them
  • How to verify a supplier’s certifications before awarding a contract


👉 Start Here — Top Resources for Aerospace Suppliers

Before you read further, these are the resources aerospace suppliers actually use:


AS9100 Rev D: The Foundation of Aerospace Quality

Quality engineers review aerospace supplier compliance standards inside a modern aircraft manufacturing facility with a fuselage assembly, machining equipment, and inspection stations
Quality personnel review engineering documentation on the aerospace shop floor while aircraft structures and manufacturing operations continue in the background.

AS9100 is the non-negotiable baseline. Every organization supplying parts, assemblies, or services to the aerospace and defense industry — whether you are a Tier 1, Tier 2, or Tier 3 supplier — is expected to hold AS9100 certification or demonstrate that your QMS meets equivalent requirements.

AS9100 Rev D is the current revision, published in 2016. It incorporates all of ISO 9001:2015 verbatim and adds aerospace-specific requirements on top of the quality management foundation. The IAQG — International Aerospace Quality Group — governs the standard and maintains the OASIS certification database.

What AS9100 Adds Beyond ISO 9001

The standard adds requirements that reflect the risk profile of aerospace manufacturing — where a single nonconformance can have catastrophic consequences. Key additions include:

AS9100 RequirementISO 9001 EquivalentWhy It Matters in Aerospace
Risk management (beyond Clause 6.1)Risk-based thinkingFormal risk identification, mitigation, and tracking for each program
Configuration managementNot requiredEnsures part revisions are controlled and traceable across the supply chain
First Article Inspection (FAI)Not requiredRequired verification that first production part meets all design requirements
Product/process change controlChange managementAny deviation from approved baseline requires documented approval
Counterfeit parts preventionNot requiredDocumented controls to prevent unapproved or fraudulent parts from entering the supply chain
FOD preventionNot requiredForeign Object Damage/Debris programs with documented procedures
Customer-designated special requirementsNot requiredFlow-down and implementation of prime contractor requirements
Key characteristicsNot requiredIdentification and control of dimensions or features with elevated risk

Most common finding: Organizations that are ISO 9001 certified assume the gap to AS9100 is small. It is not. The configuration management, FOD, and counterfeit parts requirements alone require building procedures that do not exist in a typical ISO 9001 QMS.

If you are already ISO 9001 certified, the AS9100 vs ISO 9001 comparison breaks down every additional requirement clause by clause.

For complete scope on what AS9100 certification involves, what it costs, and how long it takes, the What Is AS9100? pillar article covers the full picture.


NADCAP: Special Process Accreditation

NDT technician performing ultrasonic testing on an aerospace aluminum component using an ultrasonic probe and portable inspection instrument displaying waveform data.
An NDT technician conducts ultrasonic inspection on an aerospace component to verify material integrity and identify potential internal defects.

NADCAP is separate from AS9100 — and your customer will require both.

NADCAP — National Aerospace and Defense Contractors Accreditation Program — is a special process accreditation program managed by the Performance Review Institute (PRI). It applies to organizations performing specific high-risk manufacturing processes where process control is critical to product integrity.

AS9100 certifies your quality management system. NADCAP accredits specific processes within that system. A machined airframe component supplier may need AS9100 certification. If that same supplier performs heat treating, NDT, or chemical processing in-house, NADCAP accreditation is required for those processes — regardless of AS9100 status.

Processes That Require NADCAP Accreditation

Process CategoryExamples
Heat TreatingAnnealing, aging, stress relief, case hardening
Non-Destructive Testing (NDT)Ultrasonic, radiographic, penetrant, magnetic particle, eddy current
Chemical ProcessingAnodizing, plating, passivation, conversion coating
WeldingFusion welding per aerospace specifications
CoatingsThermal spray, paint (where specified by prime)
CompositesLay-up, cure, bonding operations
Electrical/Electronic ProcessingSoldering, conformal coating
Fluid Distribution SystemsTube bending, assembly

What NADCAP Audits Cover

NADCAP audits are process-specific and technically rigorous. Auditors evaluate process parameters, equipment qualification, operator qualification, traceability of materials, and conformance to applicable customer and industry specifications.

A NADCAP audit is not a QMS audit — it is a process performance audit. Findings are classified as Critical, Major, or Minor. Critical findings result in immediate suspension of work.

If you are a supplier: Do not assume your customer will accept your subcontractor’s NADCAP accreditation for flow-down purposes without reviewing the approved scope. NADCAP accreditation is scope-specific. Heat treating accreditation for aluminum alloys does not cover titanium heat treating.

If your aerospace customer has asked for NADCAP compliance in your supplier requirements — and you are not sure what processes in your facility are in scope — your AS9100 QMS needs a process risk review before your next customer audit. Download the AS9100 Rev D Gap Assessment Checklist →


First Article Inspection: AS9102

First Article Inspection is one of the most frequently cited sources of supplier nonconformances in aerospace.

AS9102 — Aerospace First Article Inspection Requirement — defines the methodology for verifying that the first production article (or first article after a significant change) meets all engineering, design, and manufacturing requirements. The standard is separate from AS9100 but is required by AS9100 Rev D Clause 8.1.3.

What FAI Covers

A complete FAI under AS9102 includes three forms:

FormTitleScope
Form 1Design DocumentationVerification that the correct drawing revision, specifications, and notes are captured
Form 2Product AccountabilityBill of materials, materials certification, and raw material traceability
Form 3Characteristic AccountabilityMeasurement of every dimension and characteristic on the drawing — not a sample

Form 3 is where most suppliers get tripped up. Every characteristic on the engineering drawing — not a selected subset — must be measured and documented. This includes tolerances, surface finishes, thread forms, and any geometric dimensioning and tolerancing (GD&T) callouts.

When FAI Is Required

FAI is not a one-time event. AS9102 specifies that a new or updated FAI is required when:

  • A new part number is introduced to production
  • A drawing or specification is revised (full or partial FAI, depending on the scope of change)
  • A manufacturing process, facility, or tooling is changed in a way that could affect form, fit, or function
  • Production has been inactive for more than two years

Most common finding: Suppliers treat FAI as a drawing check rather than a full measurement event. Partial FAIs submitted without Form 2 material traceability or without measuring all Form 3 characteristics are rejected by customer quality teams and result in production holds.


Counterfeit Parts Standards: AS5553 and AS6174

Counterfeit parts are a documented safety risk in aerospace. The FAA, DoD, and aerospace primes have all implemented mandatory controls. Your QMS must address them explicitly.

Two SAE standards define the requirements:

AS5553 — Fraudulent/Counterfeit Electronic Parts: Avoidance, Detection, Mitigation, and Disposition. Applies to electronic components — integrated circuits, semiconductors, connectors, and any electronics where counterfeit substitution is a risk.

AS6174 — Counterfeit Materiel: Avoidance, Detection, Mitigation, and Disposition. Broader scope covering raw materials, fasteners, and other non-electronic hardware.

What Your QMS Must Include

A compliant counterfeit parts program under AS9100 Rev D requires documented procedures covering:

  • Approved supplier lists (ASL): Purchasing only from authorized manufacturers, franchised distributors, or approved aftermarket sources
  • Receiving inspection: Risk-based inspection criteria for parts that cannot be sourced from authorized channels
  • Traceability: Certificate of conformance, test reports, and chain of custody documentation for all parts
  • Suspect/confirmed counterfeit parts: Quarantine, reporting, and disposition procedures — including mandatory reporting to GIDEP (Government-Industry Data Exchange Program) for defense contracts
  • Training: Evidence that personnel involved in procurement and receiving inspection are trained to identify suspect parts

If you are a manufacturer and not a distributor, the most critical element is your approved supplier list and purchasing controls — because your customer’s AS9100 audit will verify that you are buying from controlled sources.


FOD Control Requirements

Aerospace tool control shadow board displaying torque wrenches, calipers, safety wire pliers, borescope, and precision hand tools with one tracked tool removed.
A structured tool control system helps aerospace manufacturers maintain accountability, prevent FOD incidents, and ensure every tool is tracked throughout production.

Foreign Object Damage and Debris is a zero-tolerance issue in aerospace.

FOD — Foreign Object Damage or Debris — refers to any substance, material, or item that could potentially damage equipment or endanger personnel. A loose fastener in a fuel system. A rag left in an aircraft cavity. Metal chips in a precision assembly. In aerospace, these are not housekeeping issues — they are quality system failures.

AS9100 Rev D Clause 8.5.1 requires documented controls to prevent FOD throughout manufacturing, assembly, and test operations. Customer-specific FOD requirements are typically more detailed and flow down through purchase order terms.

Minimum FOD Program Elements

✅ Written FOD prevention procedure specific to your facility and processes
✅ Designated FOD critical areas with defined access controls
✅ Tool control program — shadow boards, tool counts, calibrated tool tracking
✅ Contamination controls during assembly and inspection operations
✅ FOD walks and documented area inspections on defined frequency
✅ Employee training and awareness records
✅ FOD incident reporting and corrective action process
✅ Customer notification procedure when FOD is suspected or confirmed

Most common finding: FOD programs exist as a procedure document but are not operationally active. Auditors look for evidence — completed FOD walk records, tool control logs, training records — not just a written procedure. The procedure without the records is a Major finding.


Customer Flow-Down Requirements

Your prime contractor’s requirements are your requirements.

This is the element that surprises suppliers who are new to aerospace. AS9100 certification means you have a compliant quality management system. It does not mean your prime contractor’s specific engineering, quality, and documentation requirements are automatically met. Those flow down — meaning they are passed from the prime to you through purchase order terms, quality clauses, and source control documentation.

Common Flow-Down Requirements

CategoryExamples
Quality planFirst Article requirements, inspection frequencies, statistical process control
EngineeringSpecification compliance, drawing revision control, DER approvals
MaterialMaterial certifications, approved material sources, trace requirements
ManufacturingApproved process specifications (e.g. BAC, SPE, DPS), NADCAP process approvals
DocumentationRecord retention requirements (typically 10+ years for flight-critical parts)
Access and oversightRight-to-access for customer source inspection, government source inspection
ReportingGIDEP reporting, escape reporting, timelines for nonconformance notification

Managing Flow-Down in Your QMS

Your QMS must have a documented process for:

  1. Reviewing purchase orders for quality clauses before accepting the order
  2. Translating customer requirements into internal work instructions and inspection plans
  3. Verifying that sub-tier suppliers (your suppliers) receive applicable flow-down requirements
  4. Maintaining records that demonstrate compliance with customer-specific requirements

If you are receiving flow-down requirements you do not understand: Your customer’s supplier quality team is your first contact. Do not guess. Documenting a misunderstood requirement incorrectly is worse than asking for clarification — because the audit finding will be a major nonconformance, not a simple misunderstanding.

If you are evaluating whether your quality system is ready for AS9100 certification, start with the How Much Does AS9100 Certification Cost? article for a complete breakdown of what certification actually involves.

BSI Group offers AS9100 training specifically designed for suppliers building compliant QMS documentation — covering the clause requirements and flow-down obligations that come with aerospace contracts.


How to Verify Supplier Certifications

Never take a supplier’s word for AS9100 certification. Verify it directly.

The IAQG OASIS Database is the official global registry for AS9100, AS9110, and AS9120 certifications. Every accredited certification is listed with scope, effective date, expiration date, and the certification body that issued it. If a supplier claims AS9100 certification and they are not in OASIS, the certification is not valid.

What to Verify in OASIS

  • Certification status: Active, suspended, or withdrawn
  • Scope of certification: Does it cover the specific product category or process your supplier is performing?
  • Expiration date: AS9100 certificates expire and require surveillance audits — a certificate that has not been renewed is not valid
  • Certification body: Is the CB accredited by a recognized accreditation body (ANAB, DAkkS, UKAS)?

For NADCAP accreditation verification, the PRI supplier database at pri-network.org lists all accredited suppliers by commodity and scope.

If you are a quality manager building or updating an approved supplier list for an aerospace program — your supplier evaluation process needs to include OASIS verification as a mandatory step before award and at each annual review.


Compliance Checklist for Aerospace Suppliers

Use this checklist to assess your current compliance posture before a customer audit or certification audit.

Quality Management System
✅ AS9100 Rev D certification current and active in OASIS
✅ QMS manual and procedures documented and controlled
✅ Internal audit program covers all AS9100 clauses — not just ISO 9001 requirements
✅ Management review records demonstrate review of aerospace-specific metrics

First Article Inspection
✅ FAI procedure documented per AS9102
✅ Form 1, Form 2, and Form 3 completed for all active part numbers
✅ FAI triggers defined — changes that require new or partial FAI
✅ FAI records retained and retrievable

Counterfeit Parts
✅ Counterfeit parts prevention procedure in place
✅ Approved supplier list (ASL) current and controls defined
✅ Receiving inspection criteria address suspect parts
✅ Personnel training records current

FOD
✅ FOD prevention procedure active and specific to your facility
✅ FOD walk and inspection records maintained on required frequency
✅ Tool control program in place with records
✅ Employee training documented

Flow-Down
✅ Purchase order review process in place
✅ Customer quality clauses translated to internal requirements
✅ Sub-tier flow-down process documented and verified
✅ Record retention meets customer requirements (typically 10+ years)

NADCAP (if applicable)
✅ All in-scope special processes identified
✅ NADCAP accreditation current for each process
✅ Scope of accreditation matches actual work performed
✅ Sub-tier NADCAP requirements verified and documented


FAQ

What is the difference between AS9100 and NADCAP?

AS9100 Rev D is a quality management system standard that certifies your organization’s overall quality processes — planning, documentation, corrective action, customer satisfaction, and so on. NADCAP is a special process accreditation that applies to specific manufacturing processes such as heat treating, NDT, chemical processing, and welding. AS9100 certification is a QMS-level requirement. NADCAP is a process-level requirement. Aerospace suppliers performing special processes are typically required to hold both.

Do I need AS9100 certification to supply aerospace parts?

In most cases, yes — if you are a direct supplier (Tier 1 or Tier 2) to an aerospace prime or defense contractor. Some lower-tier commodity suppliers may not be required to hold AS9100 certification, but customer flow-down requirements and purchase order quality clauses will define the specific requirement. Review your customer’s supplier quality requirements before assuming certification is not needed.

How do I know if my process requires NADCAP accreditation?

Review your customer’s purchase order quality clauses and their approved supplier requirements document. Primes typically maintain a list of processes that require NADCAP accreditation for their programs. If you perform heat treating, NDT, chemical processing, or welding on aerospace parts and your customer has not specified NADCAP — ask. The absence of a requirement on the PO does not always mean the requirement does not exist.

What is a First Article Inspection and when is it required?

A First Article Inspection (FAI) is a formal verification process, defined by AS9102, that the first production article meets all design and engineering requirements. It is required for new part introductions, after drawing or specification revisions, after significant manufacturing process or tooling changes, and after production gaps of two or more years. A complete FAI requires documentation on three forms covering design documents, material traceability, and measurement of every drawing characteristic.

How long does AS9100 certification take?

For an organization with no existing quality management system, the implementation and certification process typically takes 9 to 18 months. Organizations already certified to ISO 9001 can typically close the gap to AS9100 in 6 to 12 months, depending on the number of additional requirements that need to be built out. The How Much Does AS9100 Certification Cost? article covers timelines and costs in detail.

What is the OASIS database and how do I use it?

OASIS — Online Aerospace Supplier Information System — is the IAQG-maintained database of all AS9100, AS9110, and AS9120 certifications worldwide. You can search by organization name, location, or CAGE code to verify a supplier’s certification status, scope, expiration date, and issuing certification body. Access it at oasis.sae.org. Verifying supplier certifications in OASIS should be a standard step in your approved supplier list maintenance process.

What are customer flow-down requirements in aerospace?

Flow-down requirements are the specific quality, engineering, documentation, and process requirements that a prime contractor passes down to their supply chain through purchase order terms and quality clauses. They are legally binding once accepted on a PO. Common examples include FAI requirements, material certification requirements, NADCAP requirements for special processes, record retention periods, and customer source inspection rights. Your QMS must have a documented process for reviewing, implementing, and flowing these requirements to your own sub-tier suppliers.

Can I use my ISO 9001 certification for aerospace customers temporarily while pursuing AS9100?

In most cases, no. ISO 9001 certification does not meet AS9100 requirements. Some customers may grant a temporary waiver for lower-risk commodity suppliers, but for any direct aerospace supply involving flight-critical parts or assemblies, AS9100 certification is typically required before production can begin. Discuss your timeline with your customer’s supplier quality team — do not assume a waiver will be granted.


📥 Free Resources

AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification. Covers every AS9100-specific requirement beyond ISO 9001.

ISO 9001 Roadmap — Step-by-step implementation guide for manufacturers building or improving a quality management system. Useful as a foundation before layering AS9100 requirements.

Manufacturing Compliance Checklist — Practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.

Supplier Quality Checklist — Evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.

ISO 13485 Gap Assessment Checklist — Free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements.


Not Sure What to Do Next?

🔹 If you are new to aerospace and need to understand AS9100 from the ground up — start with What Is AS9100? for a complete overview of the standard, certification process, and supply chain requirements.

🔹 If you are ready to buy the AS9100 Rev D standard — purchase the official document through the ANSI Webstore. Use code CC2026 for 5% off through December 31, 2026. The standard is available in digital and print formats and ships internationally.

🔹 If you need AS9100 training for your team or are selecting a certification bodyBSI Group offers the full range of AS9100 courses from awareness through lead auditor, and serves as both a training provider and accredited certification body.

Aerospace compliance is not a project with a finish line. Certification is the beginning. The organizations that hold their approvals and grow within the supply chain are the ones that build compliance into operations — not just into audit prep.

The Standards Navigator covers the full aerospace compliance landscape, from AS9100 certification requirements to NADCAP process accreditation and FAI methodology. Use the resources above to make your next audit a confirmation of what you already know — not a discovery of what you missed.


Stay Ahead of Aerospace Compliance Changes

Losing an aerospace approval because a standard revision or customer requirement changed while you were focused on production is the most preventable kind of failure. Most organizations that fall behind on compliance don’t miss the requirement — they miss the update.

The suppliers who keep their approvals long-term are the ones who treat compliance information the same way they treat production scheduling: as an ongoing operational discipline, not a one-time project.

The Standards Navigator covers AS9100, NADCAP, FAI, and the full aerospace supplier compliance landscape — explained in plain language for quality managers and operations teams who need to act on the information, not just read it.

👉 Get updates when new aerospace compliance articles are published
👉 Be first to access new AS9100 implementation resources and checklists

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

AS9100 vs ISO 9001: Key Differences for Aerospace Suppliers (2026 Guide)

AS9100 and ISO 9001 are both quality management system standards — but they serve fundamentally different purposes. AS9100 Rev D incorporates every ISO 9001 requirement and adds over 100 aerospace-specific requirements covering product safety, configuration management, first article inspection, and counterfeit parts prevention. This guide explains exactly where the standards differ, who needs AS9100, and how ISO 9001 certification reduces your implementation timeline.

How AS9100 Rev D builds on ISO 9001 — and what aerospace suppliers need to know before choosing a certification path

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Question Every Aerospace Supplier Asks Eventually

You are ISO 9001 certified — or you are thinking about getting there. Then a prime contractor drops a supplier questionnaire on your desk with one question that changes the conversation: Are you AS9100 certified?

Those four letters carry weight in aerospace. They signal that your quality management system has been evaluated against requirements that go well beyond general manufacturing. Traceability, configuration management, first article inspection, counterfeit parts prevention — these are not optional considerations in aerospace. They are audited requirements.

The difference between AS9100 and ISO 9001 is not just a longer checklist. It is a fundamentally different level of risk tolerance built into the standard itself. Understanding that distinction before you invest in certification is the difference between a smooth implementation and a year of unexpected rework.

This guide breaks down exactly where AS9100 expands on ISO 9001, who needs which standard, and how to navigate certification if you are coming from an ISO 9001 foundation.


⚠️ Not sure where your QMS stands against AS9100 requirements? Most aerospace suppliers don’t fail certification audits because they don’t understand the standard. They fail because they assumed their ISO 9001 foundation covered more than it did. Run a clause-by-clause gap check before you commit to an implementation timeline.

👉 Download the free AS9100 Rev D Gap Assessment Checklist →


In This Guide

  • What AS9100 is and how it relates to ISO 9001
  • The four AS9100-specific requirement areas that have no ISO 9001 equivalent
  • A clause-by-clause comparison table
  • Who needs AS9100 vs. who can stay with ISO 9001
  • How to use an existing ISO 9001 certification as a foundation
  • Certification cost and timeline comparison

👉 Start Here — Top Resources for This Topic


What Is AS9100 Rev D?

AS9100 is the quality management system standard for the aerospace, aviation, and defense industries. It is published by SAE International and managed by the International Aerospace Quality Group (IAQG).

Rev D — the current revision — was released in 2016 and aligned AS9100 with the ISO 9001:2015 structure. Every requirement in ISO 9001:2015 is incorporated directly into AS9100 Rev D. The aerospace-specific additions sit on top of that foundation — often embedded within the same clause structure.

The standard uses the term Aerospace Quality Management System (AQMS) rather than QMS — a minor but document-important distinction if your QMS manual language needs to align with the standard.

2026 update: The IAQG is developing IA9100, a globally harmonized successor that will replace regional variants including AS9100 (Americas), EN 9100 (Europe), and JISQ 9100 (Asia-Pacific). Final publication is targeted for Q4 2026 with a 24–36 month transition window. Organizations certifying today should certify to AS9100 Rev D — IAQG guidance confirms this is the correct path now.

For the full scope of AS9100 before comparing it to ISO 9001, see What Is AS9100? — The Complete Guide.


How AS9100 Builds on ISO 9001

ISO 9001:2015 provides the quality management framework. AS9100 Rev D starts there and expands.

LayerStandardWhat It Covers
FoundationISO 9001:2015Quality management system — any industry
Aerospace additionsAS9100 Rev D100+ aerospace-specific requirements on top
CombinedAS9100 Rev D fullComplete aerospace quality management system

You cannot hold an AS9100 certification without meeting every ISO 9001 requirement. The reverse is not true — ISO 9001 certification does not satisfy AS9100 requirements.

In practical terms: if you are already ISO 9001 certified, your QMS covers roughly 70–75% of what AS9100 requires. The remaining 25–30% is where most implementation effort concentrates — and where most audit findings are issued.


The Four Key Differences Between AS9100 and ISO 9001

Infographic comparing the four major differences between AS9100 and ISO 9001, including product safety, configuration management, first article inspection, and counterfeit parts prevention.
AS9100 builds on ISO 9001 by adding aerospace-specific requirements for safety, configuration control, first article inspection, and counterfeit parts prevention.

1. Product Safety and Risk Management

ISO 9001 requires risk-based thinking throughout the QMS. AS9100 goes further — it requires explicit, documented product safety considerations and assigns responsibility for communicating safety-critical requirements throughout the supply chain.

Where ISO 9001 says “consider risk,” AS9100 says “identify critical items, establish controls for key characteristics, and document how safety requirements flow to every affected process.”

In a fabrication or machining environment, this means identifying which dimensions, materials, or process parameters are safety-critical — and creating documented evidence that those specific requirements are controlled and verified at every step.

Most common finding: Organizations carrying over their ISO 9001 risk register without adding the AS9100-required safety-criticality designation to individual product characteristics.

2. Configuration Management

ISO 9001 has no equivalent requirement. AS9100 requires a formal configuration management process that controls the definition of a product throughout its lifecycle — including design documentation, approved deviations, and change control.

Your QMS must include a documented process for managing engineering changes, maintaining configuration baselines, and controlling which revision of a drawing, specification, or process document applies to any given production lot.

If you manufacture to customer-furnished drawings in aerospace, your configuration management process must trace which revision was active at time of manufacture — and any deviations from that revision must be formally approved.

3. First Article Inspection (FAI) Requirements

AS9100 requires that organizations establish, document, and implement a first article inspection process — verifying that the product realization process can produce conforming product before full production begins.

The governing document for FAI in aerospace is AS9102. AS9100 does not replicate all of AS9102’s requirements, but it does require that an FAI process exists and is maintained. If your prime contractor flows down AS9102 requirements, you need to address those specifics as well.

ISO 9001 has no first article inspection requirement. This is one of the clearest examples of the risk gap between the two standards.

If you are already ISO 9001 certified → review your current first article or pre-production verification process. It likely needs formal documentation, defined acceptance criteria, and records retention aligned with AS9100 before your Stage 1 audit.

4. Counterfeit Parts Prevention

AS9100 requires a documented process to detect and prevent the use of counterfeit or unapproved parts in aerospace products. This includes supplier controls, parts identification verification, and handling procedures for suspect material.

ISO 9001 addresses supplier controls but makes no mention of counterfeit parts. In aerospace, this is not a theoretical risk — counterfeit electronic components, fasteners, and raw materials have caused documented failures. AS9100 treats it as an auditable requirement.

Your QMS must include counterfeit part risk mitigation in the procurement process, suspect parts handling procedures, and evidence that your suppliers understand and comply with the requirement.


AS9100 vs ISO 9001: Clause-by-Clause Comparison

Both standards share the same high-level clause structure (Clauses 4–10). The table below shows where AS9100 adds requirements within that structure.

Aerospace engineering drawing with revision control block, quality approval stamp, precision-machined component, and mechanical pencil illustrating AS9100 configuration management and document control requirements.
Configuration management in AS9100 requires organizations to control engineering revisions, document changes, and maintain traceability throughout the product lifecycle.
ClauseISO 9001:2015 RequirementAS9100 Rev D Addition
4 — ContextDetermine internal/external issuesAdd: identify applicable statutory/regulatory requirements for aerospace
5 — LeadershipTop management QMS commitmentAdd: communicate importance of meeting aerospace customer requirements
6 — PlanningRisk and opportunity assessmentAdd: product safety risk — identify safety-critical items explicitly
7 — SupportCompetence, awareness, communicationAdd: employee awareness of contribution to product safety and conformity
8.1 — OperationsPlan production/service provisionAdd: configuration management, counterfeit parts prevention, FAI process
8.4 — External providersSupplier evaluation and monitoringAdd: AS9100 flow-down; approved supplier list management
8.5 — Production controlProcess controls and identificationAdd: key characteristics, critical items, lot/serial traceability
8.6 — ReleaseVerification of conformityAdd: documented authority for concessions/deviations; objective evidence retention
9 — PerformanceInternal audits, management reviewAdd: trend analysis of quality data; corrective action effectiveness review
10 — ImprovementNonconformance and corrective actionAdd: escape point analysis; prevent recurrence at supply chain level

Who Needs AS9100 vs. ISO 9001?

You need AS9100 if:

  • ✅ You manufacture, overhaul, or maintain aerospace or defense components
  • ✅ Your customer is a prime contractor (Boeing, Airbus, Lockheed Martin, Raytheon, L3Harris, etc.)
  • ✅ Your purchase orders or supplier agreements specify AS9100 certification
  • ✅ You are pursuing DCMA oversight or government contract qualification
  • ✅ You are on — or want to be on — an Approved Supplier List (ASL) for an aerospace customer

ISO 9001 alone is sufficient if:

  • ✅ You manufacture for non-aerospace industries only
  • ✅ Your customer requires ISO 9001 but does not specify AS9100
  • ✅ You are a commercial manufacturer considering AS9100 as a future growth target

The gray area — Tier 2 and Tier 3 suppliers:

Not every supplier in the aerospace supply chain is required to hold AS9100. Some Tier 2 and Tier 3 suppliers hold ISO 9001 — but the trend is toward AS9100 flow-down requirements going deeper into supply chains. If your prime contractor has added AS9100 to their supplier qualification requirements in the last two years, that is a signal.

Check the IAQG OASIS database to verify certification status of suppliers you are evaluating — and to understand what your prime contractor is likely to require.

If you are evaluating whether AS9100 applies to your organization → review the supplier flow-down requirements in your prime contractor agreement first. The answer is almost always in the purchase order or the Supplier Quality Requirements (SQR) document.


⚠️ Waiting until a customer audit to discover your AS9100 gaps is a costly mistake. Most findings at Stage 1 audits come from undocumented FAI processes, missing configuration management records, and supplier flow-down gaps — all addressable before the auditor walks in the door.

👉 Run the AS9100 Rev D Gap Assessment now — it takes under 45 minutes →


Can ISO 9001 Certification Serve as a Foundation?

Yes — and it is the most efficient path to AS9100.

If you are already ISO 9001 certified, your QMS infrastructure is in place. Document control, internal audit, CAPA, and management review all carry over. The transition work focuses on the AS9100-specific additions.

👉 Run the AS9100 Rev D Gap Assessment before you build your implementation plan — clause-by-clause, free, takes under 45 minutes →

Realistic scope of the gap for an ISO 9001-certified organization:

AreaISO 9001 StatusAS9100 Gap Work Required
Document controlCompliantMinimal — add configuration management layer
Risk managementCompliantModerate — add product safety and critical item designation
Supplier controlsCompliantSignificant — add AS9100 flow-down, approved supplier list, counterfeit prevention
Production controlsCompliantModerate — add key characteristics, lot/serial traceability
First article inspectionNot addressedNew process — build from scratch or formalize existing practice
Internal audit programCompliantMinimal — add aerospace-specific audit criteria
Split-panel aerospace quality management graphic showing ISO 9001 as the foundation on the left and expanded AS9100 requirements, including first article inspection and configuration management documentation, on the right.
ISO 9001 provides a strong quality management foundation, but AS9100 adds aerospace-specific requirements for configuration management, first article inspection, product safety, and counterfeit parts prevention.

Most ISO 9001-certified organizations completing AS9100 gap remediation report 6–12 months of active implementation before Stage 1 audit readiness. Organizations starting from scratch typically need 12–18 months.

If you are already ISO 9001 certified → focus your implementation effort on the four AS9100-specific requirements that have no ISO 9001 equivalent: product safety documentation, configuration management, first article inspection, and counterfeit parts prevention.


Certification Cost and Timeline Comparison

FactorISO 9001AS9100 Rev D
Standard document cost~$175 (ANSI Webstore) — or buy AS9100 and ISO 9001 together and save~$140 (SAE/ANSI)
Implementation timeline (from scratch)9–12 months12–18 months
Implementation timeline (from ISO 9001)N/A6–12 months
Stage 1 audit cost$1,500–$3,000$2,000–$4,500
Stage 2 audit cost$3,000–$8,000$5,000–$12,000
Annual surveillance audit$2,000–$5,000$3,000–$6,500
Consultant support (optional)$5,000–$25,000$10,000–$40,000
Certification body optionsWide choiceMust be IAQG-approved

For a full breakdown by company size and scope, see How Much Does AS9100 Certification Cost?

One critical distinction: AS9100 auditors must be approved through the IAQG certification scheme. Not every ISO 9001 registrar is authorized to issue AS9100 certificates. BSI Group and ISOQAR are both IAQG-approved — BSI Group offers AS9100-specific audit preparation and lead auditor training if you want to build internal competency before your Stage 2 audit. Verify your certification body’s IAQG approval status before engaging.


How to Get Certified: Next Steps

If you are starting from an ISO 9001 foundation:

  1. Download the gap assessment checklist and work through it clause by clause

If your documentation infrastructure needs rebuilding around the AS9100-specific additions, 9001Simplified’s QMS documentation kits provide the ISO 9001 foundation layer that maps directly into AS9100 implementation — cutting initial document build time by 40–60% compared to starting from blank procedures.

  1. Identify your critical items — flag which product characteristics carry safety implications
  2. Build your configuration management process — a documented change control log is a starting point
  3. Formalize your FAI process — if you already do first article checks informally, document them to AS9102 framework
  4. Update your supplier controls — add AS9100 flow-down language to purchase orders and supplier questionnaires
  5. Select an IAQG-approved certification body — get quotes from at least two before committing
  6. Complete your internal audit against the full AS9100 requirements
  7. Schedule your Stage 1 audit — confirm documentation readiness before Stage 2 is booked

If you are starting without ISO 9001:

Consider building to AS9100 directly — you will need to meet every ISO 9001 requirement anyway. Starting with ISO 9001 as an intermediate milestone adds cost and time without a corresponding benefit unless your customer base genuinely splits between ISO 9001 and AS9100 requirements.

If under customer pressure to certify quickly → prioritize training and select your certification body before building documentation. Audit scheduling lead times at major certification bodies currently run 2–4 months.


📥 Free Resources


AS9100 Rev D gap assessment checklist showing aerospace quality management requirements, audit readiness evaluation, and certification preparation for aerospace manufacturers and suppliers.
Use an AS9100 Rev D gap assessment checklist to identify quality management system weaknesses before your certification audit.

📬 Stay Ahead of Your Next Audit

AS9100 auditors find the same gaps year after year — configuration management records, FAI documentation, and supplier flow-down evidence. We track what is actually being flagged in the field and send it directly to your inbox.

Subscribe and get the AS9100 Rev D Gap Assessment Checklist delivered immediately.

Sign up here →


FAQ

Is AS9100 the same as ISO 9001?

No. AS9100 contains every requirement in ISO 9001:2015 but adds more than 100 aerospace-specific requirements covering product safety, configuration management, first article inspection, counterfeit parts prevention, and traceability. ISO 9001 is a general-industry standard; AS9100 is specific to aerospace, aviation, and defense.

Can I be certified to both AS9100 and ISO 9001?

AS9100 certification already incorporates all ISO 9001 requirements, so holding an AS9100 certificate demonstrates compliance with both. Many organizations hold a single AS9100 certificate. Some certification bodies will issue both certificates simultaneously if your customer base specifically requires the ISO 9001 certificate by name.

Does ISO 9001 certification help with AS9100 certification?

Yes, significantly. An existing ISO 9001 QMS provides the document control, internal audit, CAPA, and management review infrastructure that AS9100 builds on. Most ISO 9001-certified organizations can reach AS9100 audit readiness in 6–12 months rather than the 12–18 months typically required from scratch.

Who manages AS9100?

AS9100 is published by SAE International and managed by the International Aerospace Quality Group (IAQG), a consortium of aerospace manufacturers including Boeing, Airbus, and Lockheed Martin. Certification auditors must be approved through the IAQG scheme.

What is IA9100 and does it replace AS9100?

IA9100 is the globally harmonized successor to AS9100 currently being developed by the IAQG. It will replace regional variants including AS9100, EN 9100, and JISQ 9100. Final publication is targeted for Q4 2026 with a 24–36 month transition window. Organizations should certify to AS9100 Rev D now — IAQG guidance confirms this is the correct path.

Do all aerospace suppliers need AS9100?

Not all — but the requirement is flowing deeper into supply chains. Tier 1 suppliers to major primes almost universally require AS9100. Tier 2 and Tier 3 suppliers are increasingly seeing it added to supplier qualification requirements. Verify your specific requirements by reviewing your purchase orders, Supplier Quality Requirements documents, and any flow-down clauses from your prime contractor.

How long does AS9100 certification take?

From a standing start with no existing QMS: 12–18 months. From an existing ISO 9001 certification: 6–12 months. Timeline depends on scope, number of sites, and the extent of gap remediation required after your initial assessment.

What is the difference between AS9100 and NADCAP?

AS9100 is a quality management system standard covering the organization’s overall AQMS. NADCAP (National Aerospace and Defense Contractors Accreditation Program) is a process-specific accreditation program covering special processes — heat treatment, NDT, chemical processing, welding, and others. Many aerospace suppliers hold both. They are complementary, not competing certifications.


Not Sure What to Do Next?

🔹 Need the AS9100 Rev D standard documentBuy AS9100 Rev D — ANSI Webstore. Use code CC2026 for 5% off.

🔹 Need training before your auditAS9100 Lead Auditor and Implementation Courses — BSI Group

🔹 Building your ISO 9001 foundation firstBuy ISO 9001:2015 — ANSI Webstore and review the ISO 9001 Certification Guide before committing to an AS9100 timeline.

The gap between ISO 9001 and AS9100 is real — but it is not insurmountable. Aerospace suppliers make this transition every day. The ones who do it efficiently run their gap assessment first, build their implementation plan around the actual findings, and select a certification body before they start writing procedures. The Standards Navigator covers every step of that process. Start with the gap assessment — everything else follows.


AS9100 vs ISO 9001: The Gap Is Closeable. Start with the Right Information.

The aerospace suppliers that struggle with AS9100 transition are almost always the ones working from assumptions — assuming their ISO 9001 foundation covers more than it does, assuming FAI is informal enough to pass, assuming their supplier flow-down language is sufficient.

The ones that pass their first AS9100 Stage 1 audit without major findings are the ones who ran the gap assessment before they called a consultant.

At The Standards Navigator, AS9100, ISO 9001, and the full aerospace compliance landscape are covered in plain-language, field-level detail — from the standard itself to implementation strategy, audit preparation, and certification body selection.

👉 Get updates on aerospace quality standards, implementation guidance, and compliance insights delivered directly.

👉 Be first to access new AS9100 guides, checklists, and tools as they publish.

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

How Much Does AS9100 Certification Cost in 2026? A Complete Breakdown

AS9100 Rev D certification costs vary significantly by company size, existing QMS maturity, and audit scope. This guide breaks down every cost component — from the standard itself to Stage 2 audit fees and ongoing surveillance costs — with realistic 2026 figures for small shops through large manufacturers.

AS9100 Rev D certification costs, audit fees, implementation expenses, and how to budget for aerospace quality compliance

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Number That Stops Most Aerospace Suppliers Cold

You need AS9100 certification. Your prime contractor has made that clear. The question isn’t whether you’ll pursue it — it’s whether you can survive the budget shock when you start getting quotes.

Most shops walk into this process expecting a number and walk out with a range so wide it feels useless. That’s not an accident. AS9100 certification costs depend on a half-dozen variables that the certification bodies won’t resolve until they’ve assessed your operation in detail.

Here’s what I can tell you: the cost is real, the range is legitimate, and if you understand the components, you can budget accurately and avoid the expensive surprises that derail timelines.

This guide breaks down every cost element — from the standard itself to the Stage 2 certification audit — and gives you realistic numbers for 2026.


Quality manager reviewing AS9100 certification documentation inside an aerospace manufacturing facility with aerospace components, inspection equipment, and production personnel in the background.
Understanding AS9100 certification costs starts with evaluating your quality system, documentation, internal audits, and aerospace compliance readiness.

Before you start collecting quotes, know where your gaps are. Most organizations underestimate implementation time because they skip the gap assessment. Run ours first — it’s clause-by-clause, it’s free, and it will tell you exactly where you’re exposed before you commit to a timeline.

👉 Download the AS9100 Rev D Gap Assessment Checklist →


In This Guide

  • What drives AS9100 certification costs
  • The cost of the AS9100 standard itself
  • Implementation and consulting costs
  • Training costs
  • Certification body (registrar) audit fees
  • Ongoing surveillance and recertification costs
  • Total cost estimates by company size
  • How to reduce your certification spend without cutting corners
  • FAQ

👉 Start Here — Top Resources for AS9100 Certification

Before diving into the numbers, these are the resources readers at this stage actually use:


What Drives AS9100 Certification Costs

AS9100 certification costs are not fixed. Every quote you receive will be shaped by these variables:

Cost DriverLow-Cost ScenarioHigh-Cost Scenario
Company sizeUnder 50 employees500+ employees
Number of sitesSingle facilityMultiple locations
Existing QMSISO 9001 already certifiedNo QMS in place
Process complexitySimple machining or assemblyDesign authority, software, multi-discipline
Consultant involvementInternal resources onlyFull consultant engagement
Certification body choiceRegional, competitive pricingTier 1 global registrar
Timeline pressure18–24 months6–9 months (expedited)

The aerospace and defense sectors carry stricter safety and quality requirements than general industry. That rigor gets reflected in audit time. AS9100 audits run longer than ISO 9001 audits for the same organization size — plan for it.


Cost of the AS9100 Standard

You cannot implement a standard you haven’t read. The official AS9100 Rev D document is the starting point for everything that follows.

AS9100 Rev D is maintained by SAE International and the International Aerospace Quality Group (IAQG). It is available through the ANSI Webstore alongside related aerospace standards.

Current pricing (2026):

  • AS9100 Rev D standard: approximately $170–$220 (PDF or print)
  • AS9100 standards collection package: available with multi-standard savings

Purchase AS9100 Rev D — ANSI Webstore → Use code CC2026 for 5% off through December 31, 2026.

You will also want access to related documents during implementation:

  • AS9104/1 — requirements for aviation, space, and defense quality management system certification programs (your registrar follows this)
  • AS9101 — quality management systems audit requirements for aviation, space, and defense organizations
  • ISO 9001:2015 — AS9100 incorporates ISO 9001 in full; you need both if your team doesn’t already know the base standard

If you are already ISO 9001 certified, your team knows the foundation. The incremental cost is the delta — roughly 25% of AS9100’s requirements go beyond ISO 9001.


Implementation and Consulting Costs

This is where the range gets wide. Implementation costs depend almost entirely on where you’re starting from.

Starting from scratch (no QMS)

If your shop has no documented quality management system, expect 12–24 months of internal effort and significant documentation work. A consultant will accelerate this but adds direct cost.

Typical consulting fee structures:

Engagement TypeTypical CostWhat You Get
Full implementation consulting$15,000–$60,000+Gap assessment through Stage 2 audit support
Project-based (documentation only)$5,000–$15,000QMS manual, procedures, work instructions
Hourly advisory$150–$350/hourTargeted support for specific gaps or audit prep
Pre-assessment (gap audit only)$2,000–$5,000Structured gap report against AS9100 requirements
AS9100 certification cost drivers infographic showing seven variables that affect certification costs, including company size, QMS maturity, number of sites, consultant involvement, certification body selection, implementation timeline, and timeline pressure, with Year 1 investment ranges by organization size.
AS9100 certification costs vary significantly based on company size, QMS maturity, site count, implementation strategy, and certification scope.

Starting from ISO 9001

This is the most common scenario for mid-size manufacturers moving into aerospace supply chains. Your QMS foundation is intact. The work is additive — closing the gap on AS9100-specific requirements including:

  • Risk management (beyond ISO 9001 Clause 6 — more prescriptive in aerospace)
  • Configuration management
  • First article inspection (FAI) requirements per AS9102
  • Key characteristics identification and control
  • Product/process change control
  • Counterfeit parts prevention

Budget $8,000–$25,000 in consulting if you need external support for the transition. Internal teams with a qualified QMS lead can do much of this work without outside help.

If you are building your QMS documentation from scratch, documentation kits can cut your build time significantly. 9001Simplified’s documentation packages cover ISO 9001 foundations that map directly into AS9100 implementation — the same clause structure, the same documented information requirements, ready to adapt for aerospace-specific additions.


Training Costs

AS9100 certification requires trained internal auditors. It also requires that your quality team understands the standard at a level that holds up under registrar scrutiny. Training is not optional — it’s both a certification requirement and a practical necessity.

Training cost ranges (2026):

Training TypeFormatTypical Cost
AS9100 Awareness (overview)Online, self-paced$200–$600/person
AS9100 Internal AuditorClassroom or virtual, 3 days$1,200–$2,500/person
AS9100 Lead Auditor (Probitas-certified)Classroom or virtual, 5 days$1,800–$2,500/person
Implementation workshopOn-site, 2 days$3,000–$8,000 (group)

Most organizations certify 1–2 internal auditors and send 1–2 quality personnel through awareness training. Budget $3,000–$8,000 for a small to mid-size shop’s initial training investment.

AS9100 Training Courses — BSI Group →

BSI Group offers AS9100 lead auditor, internal auditor, and implementation training with both virtual and classroom options. Their aerospace quality training is recognized across the IAQG community.


Certification Body (Registrar) Audit Fees

The registrar audit is the largest single external expense. This is what you pay the certification body to perform Stage 1 (document review), Stage 2 (on-site certification audit), and issue the AS9100 certificate.

How registrars determine your audit time:

AS9100 audit time is calculated using IAQG and IAF guidelines — typically based on employee count, process complexity, number of shifts, and scope of operations. Aerospace audits are more labor-intensive than general industry audits of equivalent size.

Auditor day rates (2026):

Auditor fees typically run $1,500–$3,000 per audit day, plus travel and accommodation where on-site presence is required. Virtual audit options can reduce travel costs but are not available for all certification bodies or scopes.

Initial certification audit duration by company size:

Company SizeTypical Audit DaysEstimated Audit Fee Range
Under 25 employees2–3 days$3,000–$9,000
25–100 employees3–5 days$4,500–$15,000
100–250 employees5–8 days$7,500–$24,000
250–500 employees7–12 days$10,500–$36,000
500+ employees10+ days$15,000–$60,000+

Registration fees, application fees, and certificate issuance fees are additional — typically $500–$2,000 depending on the certification body.

OASIS database registration is mandatory. Your certification body will register your AS9100 certificate in the IAQG OASIS database — this is how prime contractors verify supplier certification status. Confirm your registrar is OASIS-registered before engaging.

Most organizations that fail their Stage 2 audit don’t fail because they misunderstood the standard. They fail because they assumed their documented system matched what was actually happening on the floor. Before you schedule your audit, run a structured internal audit against every AS9100 clause. Your gap assessment checklist will tell you where you’re exposed.

👉 Download the AS9100 Rev D Gap Assessment Checklist →


Ongoing Costs After Certification

AS9100 certification cycle infographic showing the three-year certification timeline, including initial certification, Year 1 surveillance audit, Year 2 surveillance audit, and Year 3 recertification audit requirements.
AS9100 certification is not a one-time event. Organizations must complete surveillance audits and recertification audits throughout a continuous three-year certification cycle.

AS9100 certification is a three-year cycle with annual surveillance audits. Budget for the full cycle, not just the initial certification.

Ongoing cost structure:

ActivityFrequencyTypical Cost
Annual surveillance auditYears 1 and 2$2,000–$8,000/year
Recertification auditYear 3$4,000–$15,000
Internal audit programOngoingInternal labor cost
Management reviewAnnual minimumInternal labor cost
Continual improvement activitiesOngoingVariable

Three-year total external cost (registrar fees only):

  • Initial certification: $5,000–$36,000
  • Year 1 surveillance: $2,000–$8,000
  • Year 2 surveillance: $2,000–$8,000
  • Year 3 recertification: $4,000–$15,000
  • Three-year total (registrar fees): $13,000–$67,000

This is external cost only. Internal labor — quality manager time, audit preparation, document maintenance, management review — adds significantly to the true cost of maintaining certification.


Total AS9100 Certification Cost by Company Size

Quality manager reviewing an AS9100 certification budget and cost estimate inside an aerospace manufacturing facility while evaluating certification planning, audit expenses, and compliance investments.
Effective AS9100 certification planning requires understanding both initial implementation costs and ongoing audit expenses throughout the certification cycle.

These figures represent all-in estimates for the first year of certification, including the standard, implementation, training, and audit fees. Consulting costs assume partial external engagement.

Company SizeStandard + TrainingImplementationAudit FeesTotal Year 1 Estimate
Small (under 25 employees)$2,000–$4,000$3,000–$10,000$4,000–$10,000$9,000–$24,000
Mid-size (25–100 employees)$3,000–$6,000$8,000–$25,000$6,000–$18,000$17,000–$49,000
Large (100–250 employees)$4,000–$8,000$15,000–$40,000$10,000–$28,000$29,000–$76,000
Enterprise (250+ employees)$7,000–$10,000$25,000–$80,000+$20,000–$60,000+$52,000–$150,000+

These ranges align with industry data showing SMEs spending $8,000–$30,000 for initial certification (audit fees alone) and total first-year costs of $10,000–$50,000 for organizations with some QMS foundation already in place.

If you are already ISO 9001 certified, reduce the implementation estimate by 30–50%. Your documentation foundation, internal audit program, and management system structure already exist. You are closing gaps, not building from scratch.


How to Reduce Your AS9100 Certification Costs

Cost reduction in AS9100 certification comes from three levers: preparation quality, consultant leverage, and timeline management.

Lever 1 — Do the gap assessment before anything else

A structured gap assessment identifies your actual compliance posture before you engage a consultant or registrar. Organizations that skip this step pay consultants to discover what they could have identified themselves. The AS9100 Rev D Gap Assessment Checklist is built for exactly this purpose.

Lever 2 — Build internal competency before engaging consultants

Train your internal quality lead before you bring in external help. One person with a solid understanding of AS9100 Rev D requirements will cut your consulting hours significantly. The pre-certification investment in AS9100 internal auditor training pays for itself on the first consultant engagement.

Lever 3 — Don’t rush the timeline

Compressed timelines require more consultant hours, more registrar pre-assessment support, and more internal overtime. An 18–24 month implementation done at a sustainable pace typically costs 20–35% less than a 9–12 month expedited push. If your customer isn’t pressing a specific date, don’t create artificial urgency.

Lever 4 — Get multiple registrar quotes

Audit fees vary significantly between certification bodies. Get quotes from at least three accredited registrars before committing. Verify OASIS registration status through the IAF and confirm aerospace-specific auditor qualifications before selecting on price alone.

Lever 5 — Use documentation frameworks

Documentation build time is one of the largest internal cost drivers for organizations starting from scratch. Pre-built QMS documentation frameworks — procedure templates, quality manual structures, record templates — cut initial build time by 40–60% compared to building from blank documents.

9001Simplified’s documentation kits provide the ISO 9001 foundation layer that maps directly into AS9100 implementation. If you need the quality management system built before you can tackle aerospace-specific additions, this is the fastest starting point available.


📥 Free Resources


Not Sure What to Do Next?

🔹 If you need to purchase the AS9100 Rev D standardBuy it through the ANSI Webstore using code CC2026 for 5% off. That is the official SAE/IAQG document — there is no substitute.

🔹 If your team needs AS9100 trainingBSI Group’s AS9100 training catalog covers internal auditor, lead auditor, and implementation training in virtual and classroom formats.

🔹 If you need to build your QMS documentation9001Simplified’s documentation packages give you the ISO 9001 foundation layer that AS9100 builds on.

The Standards Navigator covers every step of the AS9100 certification journey. Start with the gap assessment, understand what you’re building, and make every dollar in your certification budget count.


Frequently Asked Questions

How much does AS9100 certification cost for a small company?

A small company with under 25 employees can expect total first-year AS9100 costs of $9,000–$24,000, assuming some QMS foundation exists. This includes the standard, basic training, limited consulting, and the certification audit. Companies with no existing quality management system should budget toward the higher end or beyond, particularly if a full-service consultant is needed.

Is AS9100 more expensive than ISO 9001 to certify?

Yes, typically 20–40% more for the initial certification audit alone. The audit takes longer because AS9100 has additional requirements beyond ISO 9001 — risk management, configuration management, first article inspection, and more — that require specific auditor competency and additional audit time. If you are already ISO 9001 certified, the premium is lower because your foundation is in place.

How long does AS9100 certification take?

Most organizations complete initial AS9100 certification in 12–24 months. Organizations already certified to ISO 9001 with a competent internal quality function can target the lower end of that range. Compressed timelines of 6–12 months are possible but increase cost and risk of audit failure.

How long does AS9100 certification take?

Most organizations complete initial AS9100 certification in 12–24 months. Organizations already certified to ISO 9001 with a competent internal quality function can target the lower end of that range. Compressed timelines of 6–12 months are possible but increase cost and risk of audit failure.

Do I need a consultant to get AS9100 certified?

No, but it depends on your internal capability. Organizations with an experienced quality manager who understands AS9100 requirements can implement with minimal external support. The gap assessment, internal auditor training, and documentation frameworks reduce the dependency on consultants significantly. Most small to mid-size shops benefit from targeted consulting support on specific gaps rather than full-service engagement.

What happens if I fail my AS9100 Stage 2 audit?

A Stage 2 audit failure does not end the process. The registrar will issue nonconformances — major or minor. Major nonconformances require a corrective action plan and evidence of resolution before certification is issued, which may require a return visit. This adds cost (additional audit days) and delays your timeline. Prevention is the correct strategy: run structured internal audits against every clause before your Stage 2 date.

How much do annual surveillance audits cost for AS9100?

Annual surveillance audits typically cost $2,000–$8,000 per year depending on company size and registrar. They are shorter than the initial certification audit — usually 1–3 days — but are required in Years 1 and 2 of the three-year certification cycle. Recertification in Year 3 costs similarly to the initial certification audit.

Can I use a virtual audit for AS9100 certification?

Some certification bodies offer hybrid or virtual audit options, which can reduce travel costs meaningfully. However, not all registrars and not all scopes are suitable for fully virtual audits under AS9100 requirements. Confirm with your certification body before assuming virtual is available for your operation.

What is the OASIS database and why does it matter for cost?

The IAQG OASIS database is the official registry where AS9100 certificates are recorded. Prime contractors and customers verify supplier certification through OASIS — not through the certificate document alone. Your certification body is required to register your certificate in OASIS. Registrars that are not OASIS-registered cannot issue valid AS9100 certifications. There is no workaround. Selecting an unaccredited or non-OASIS-registered body wastes your entire investment.


The Standards Navigator provides practical guidance on ISO standards and industrial compliance for manufacturing professionals. For more on the AS9100 certification process, see our complete AS9100 guide and our Buy AS9100 article.


Don’t schedule your AS9100 audit until you know where your gaps are. Most certification delays and re-audit fees trace back to assumptions about compliance that a structured gap check would have caught. Run the AS9100 Rev D Gap Assessment Checklist before you commit to a timeline — it’s clause-by-clause, it’s free, and it takes less time than one conversation with a consultant.

👉 Download the AS9100 Rev D Gap Assessment Checklist →


Stay Ahead of Every Audit — Join The Standards Navigator

Most quality managers find out about a new requirement when an auditor cites it.

Don’t be that team.

The Standards Navigator publishes practical breakdowns of ISO standards, aerospace compliance requirements, and audit preparation guidance written by someone who has spent 25 years on the floor — not in a classroom.

No filler. No generic compliance tips. Just the specific guidance that keeps your QMS audit-ready and your certification on track.

What subscribers get:

✅ New articles on AS9100, ISO 9001, ISO 13485, and industrial compliance standards — as they publish
✅ Practical audit prep guidance tied to real nonconformance patterns
✅ Early access to gap assessment checklists, implementation tools, and documentation resources
✅ Cost breakdowns and certification body comparisons you won’t find condensed anywhere else

Subscribe

* indicates required

No spam. No sales pitches. Unsubscribe any time. Join the quality managers, compliance professionals, and aerospace suppliers who read The Standards Navigator every week.

Buy AS9100 Rev D Standard: Where to Get the Official Document in 2026

AS9100 Rev D is the quality management standard for aviation, space, and defense — and it must be purchased from an authorized source. This guide covers where to buy it, current pricing, format options, what the document includes, and what the upcoming IA9100 transition means for buyers in 2026.

How to purchase AS9100 Rev D from authorized sources — pricing, formats, and what comes with the standard

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


If You’re Sourcing AS9100, You Need to Get This Right

AS9100 Rev D is the quality management standard for aviation, space, and defense. If you’re a supplier to Boeing, Lockheed Martin, Raytheon, or any prime contractor in the aerospace sector, there’s a good chance AS9100 certification is either already required or will be before your next contract renewal.

Getting the standard wrong at the start creates problems that compound. Counterfeit copies circulate online. Outdated revisions get used for implementation. Organizations spend months building a QMS to the wrong requirements and then face nonconformances during Stage 1 audit because the auditor is working from the current text and they’re not.

This guide covers exactly where to buy AS9100 Rev D, what you’re actually getting when you purchase it, the formats available, and what to know about the upcoming transition to IA9100.


In This Guide:

  • Where to buy AS9100 Rev D from authorized sources
  • Pricing and format options (PDF vs. print)
  • What the standard document includes
  • Related aerospace standards worth purchasing together
  • What the IA9100 transition means for buyers in 2026
  • How to verify your certification body is OASIS-listed

👉 Start Here — Top Resources for AS9100

👉 Buy AS9100 Rev D (PDF or Print): ANSI Webstore — Official SAE/AS9100 Standard — use code CC2026 for 5% off through December 31, 2026

👉 Save on Standard Bundles: ANSI Standard Packages — up to 50% off

👉 Build Your AS9100 QMS Documentation: 9001Simplified — Documentation Kits for Aerospace QMS

👉 AS9100 Training Courses: BSI Group — AS9100 Training and Certification

👉 ISO 9001 Training (Foundation for AS9100): ISOQAR — ISO/AS9100 Training Courses


Where to Buy AS9100 Rev D

AS9100 Rev D is published by SAE International on behalf of the International Aerospace Quality Group (IAQG). It is not freely available. To access the official, enforceable text of the standard, you must purchase it from an authorized source.

There are three legitimate options:

SourceFormat AvailableBest For
ANSI WebstorePDF, print, multi-user, bundlesU.S. buyers; international orders; bundle purchases — multiple languages available
SAE International (sae.org)PDF, printDirect from publisher; SAE members may receive discounts
BSI GroupPDF, printUK and European buyers; combined standard and training purchases
Comparison infographic showing authorized AS9100 Rev D purchase sources versus unauthorized sources, including pricing ranges, compliance benefits, and risks of unofficial copies.
Purchasing AS9100 Rev D from authorized sources helps ensure document accuracy, compliance, support, and access to the latest revision.

The ANSI Webstore is the recommended source for most buyers. It carries the full SAE AS9100 series in PDF and print formats, processes international orders, offers standards in multiple languages, and includes bundle packages that reduce per-standard cost when you need more than one document. Use code CC2026 at checkout for 5% off through December 31, 2026.

Avoid third-party resellers offering discounted PDFs, “free downloads,” or document-sharing platforms. Copies obtained outside authorized channels are almost always outdated, incomplete, or counterfeit — and your registrar will ask to see that you’re working from a current, controlled copy of the standard.

See also: Where to Buy ISO Standards — Complete Guide to Official Sources


Pricing and Formats

AS9100 Rev D pricing through the ANSI Webstore runs approximately $200–$260 for a single-user PDF. Hardcopy print editions are similarly priced. Multi-user and enterprise licenses are available for organizations that need broader access.

FormatPrice RangeNotes
Single-user PDF$200–$260Immediate download; searchable; single-user license only
Hardcopy (print)$200–$260Physical copy; useful for shop floor reference; single license
PDF Multi-User$400–$500Shared access across your implementation team
Enterprise License$1,000–$1,800Organization-wide access; contact ANSI for quote
Bundle (AS9100 + related standards)Up to 50% offBest value when purchasing multiple aerospace standards together

If you’re buying AS9100 alongside AS9102 (first article inspection), AS9101 (audit requirements), or ISO 9001, the ANSI standard bundle packages are worth evaluating — savings of up to 50% off list price apply when you bundle. That’s meaningful when you’re stacking multiple documents for a full implementation.

For a full breakdown of what AS9100 certification costs beyond the standard itself — including registrar fees, audit costs, and consultant expenses — see How Much Does ISO Certification Cost?


What the Standard Includes

AS9100 Rev D is the full quality management system requirements document for aviation, space, and defense. It is built on the ISO 9001:2015 framework — every clause from ISO 9001 is present — with aerospace-specific additions layered on top.

When you purchase AS9100 Rev D, you get:

  • The complete text of all 10 clauses, including all aerospace add-ons
  • Annex A — mapping of clause additions to ISO 9001 structure
  • Annex B — quality management principles (informative)
  • Bibliography of related standards

Key aerospace-specific requirements that go beyond ISO 9001 include:

Requirement AreaAS9100-Specific Addition
Product safetyDedicated clause — must identify, document, and manage product safety risks
Counterfeit parts preventionExplicit controls required for prevention, detection, and disposition of counterfeit EEE parts
Configuration managementRequired for products throughout lifecycle — more rigorous than ISO 9001 traceability requirements
First article inspectionReferenced requirement — cross-references AS9102 for full FAI requirements
Human factorsAddressed explicitly — organizations must consider human factors in their processes
Operational risk managementExpanded beyond ISO 9001 risk-based thinking — more prescriptive requirements

The standard text itself does not include implementation guidance, checklists, or templates. Those are separate documents. If your team needs a ready-made documentation system, 9001Simplified’s aerospace documentation kits are built to the AS9100 clause structure and can significantly compress implementation time.

See also: ISO Documentation Packages — Are They Worth It for Manufacturing?


⚠️ Most teams don’t fail AS9100 audits because they misread the standard. They fail because they assumed their existing QMS covered it. If you haven’t run a clause-by-clause gap check against Rev D, do it before you schedule your Stage 1.

👉 Download the AS9100 Rev D Gap Assessment Checklist — free


AS9100 Rev D references several companion standards. If you’re implementing or certifying to AS9100, these are the documents your auditor will expect you to know — and in some cases, demonstrate compliance with.

StandardWhat It CoversRequired?
AS9101FAudit requirements for aviation, space, and defenseUsed by your registrar during audits — worth understanding
AS9102BFirst Article Inspection (FAI) requirementsFrequently customer-mandated; cross-referenced in AS9100
AS5553Counterfeit parts avoidance, detection, mitigationDirectly referenced by Clause 8.1.4 of AS9100
ISO 9001:2015Quality management system requirements (base standard)AS9100 incorporates ISO 9001 in full — purchasing separately is optional
AS9110QMS requirements for aviation maintenance organizationsMRO-specific — not needed unless you’re an aviation maintenance operation
AS9120QMS requirements for aviation distributorsDistributors only — not a manufacturing standard

For most manufacturers, the priority purchases alongside AS9100 Rev D are AS9102 if your customers require FAI, and AS5553 if you handle electronic or electromechanical components. Both are available through ANSI standard bundle packages. The full SAE International aerospace standards catalog is available if you need to browse the complete series before deciding.

If you are also ISO 9001 certified — or working toward it as a foundation for AS9100 — see What Is AS9100? for a full breakdown of how the two standards relate clause by clause.


The IA9100 Transition — What Buyers Need to Know in 2026

This is the most important context for anyone buying AS9100 in 2026.

The IAQG is in the process of rebranding and revising AS9100 Rev D as IA9100 — where “IA” stands for International Aerospace. The name change reflects the IAQG’s goal of publishing a single, unified global document rather than separate regional versions. The target publication date is late 2026, aligned with the anticipated release of ISO 9001:2026.

What this means practically:

  • AS9100 Rev D remains the current, enforceable standard. Buy it now if you need to implement or certify to AS9100. It is the document your registrar will audit against.
  • The transition window after IA9100 publishes will likely be two to three years. Organizations with current AS9100 Rev D certificates will have time to transition — similar to how ISO 9001:2015 gave organizations three years to move from 2008.
  • Key changes expected in IA9100 include expanded product safety requirements, new information security clauses, stronger counterfeit parts controls, and alignment with the revised ISO 9001 high-level structure.
  • You are not behind by purchasing Rev D today. Every organization that certifies in 2026 will need to transition later — that’s standard practice in ISO and aerospace standards management.
Timeline infographic showing the expected transition from AS9100 Rev D certification to IA9100 publication and the anticipated 2-3 year aerospace industry transition period.
This timeline illustrates the expected path from AS9100 Rev D certification to the future IA9100 standard and transition window.

⚠️ Buyer’s Note: If you see a listing for “IA9100” or “AS9100 Rev E” as a published, purchasable standard in 2026, verify the source carefully. As of June 2026, IA9100 has not been published. AS9100 Rev D (2016) is the current edition.

For a deeper look at what AS9100 requires and how certification works, see What Is AS9100? — Complete Guide to the Aerospace Quality Standard.

See also: ISO Implementation Timeline for Manufacturers and Best ISO Certification Bodies — Ranked and Reviewed for 2026


How to Verify Your Certification Body Is OASIS-Listed

Not every ISO 9001 registrar is accredited to certify AS9100. This is a common mistake — organizations assume that because a CB holds ISO 9001 accreditation, they can issue an AS9100 certificate. They can’t unless they hold separate AS9100 accreditation.

The IAQG maintains the OASIS database — the authoritative registry of AS9100-certified organizations and accredited certification bodies. Before you sign with a registrar:

  • ✅ Search the OASIS database to confirm your CB is listed and active for AS9100
  • ✅ Verify ANAB accreditation for AS9100 in North America — this is the recognized accreditation body
  • ✅ Ask specifically which aerospace sectors and scopes the CB is accredited for — aerospace scopes vary
  • ✅ Confirm your organization’s OASIS listing after certification — your prime contractor customers will check it

An AS9100 certificate from an unaccredited CB is not recognized by prime contractors, DoD, or the commercial aerospace supply chain. This is not a technicality. It is a disqualifier for contract eligibility in most aerospace programs.

If you are evaluating which certification body to use → see Best ISO Certification Bodies — Ranked and Reviewed for 2026 for a full breakdown of accredited options.

If you are comparing AS9100 certification against your existing ISO 9001 scope → see ISO 9001 Certification Guide for how the two audit processes compare.er for contract eligibility.


Frequently Asked Questions

Where can I buy AS9100 Rev D officially?

AS9100 Rev D is published by SAE International and available through authorized resellers including the ANSI Webstore, SAE.org directly, and BSI Group. The ANSI Webstore is the recommended source for U.S. and international buyers — use code CC2026 for 5% off through December 31, 2026.

How much does AS9100 Rev D cost?

A single-user PDF runs approximately $200–$260 through most authorized resellers. Hardcopy editions are similarly priced. Multi-user PDFs run $400–$500, and enterprise licenses run $1,000–$1,800. Bundle pricing through ANSI reduces costs significantly when you’re purchasing multiple aerospace standards together.

Is AS9100 Rev D the same as ISO 9001?

No — but it contains all of ISO 9001:2015. AS9100 Rev D incorporates the full ISO 9001:2015 text and adds aerospace-specific requirements on top: product safety, counterfeit parts prevention, configuration management, first article inspection references, human factors, and expanded operational risk management. If you are certified to AS9100, you are also meeting ISO 9001 requirements — but not the reverse.

Should I wait for IA9100 before implementing AS9100?

No. AS9100 Rev D is the current, enforceable standard. IA9100 is expected in late 2026 with a transition window of approximately two to three years after publication. If your customers require AS9100 certification now, implement and certify to Rev D. You will transition to IA9100 when it’s published, as every currently-certified organization will need to do.

Can I share the AS9100 PDF with my whole team?

Not on a single-user license. Standard single-user PDF licenses do not permit multi-user access. If your implementation team needs simultaneous access, purchase a multi-user license. Using a single-user PDF across your organization is a license violation your registrar may flag during document control review — a finding you do not want going into Stage 1.

Do I need to buy AS9101 separately?

AS9101F (audit requirements) is used by your registrar, not your organization. You are not required to purchase it, but many quality managers find it useful for understanding what auditors will look for during Stage 1 and Stage 2 assessments. It’s available separately through ANSI.

What’s the difference between AS9100, AS9110, and AS9120?

AS9100 is for aerospace manufacturers. AS9110 is for aviation maintenance, repair, and overhaul organizations. AS9120 is for aviation distributors. Most companies in the aerospace manufacturing supply chain need AS9100. The standard you need is determined by your scope of work, not your customer’s preference.

Is a free version of AS9100 available anywhere?

No. There is no legally free version of AS9100 Rev D. Documents labeled “free AS9100 download” online are either counterfeit, illegally distributed, or are summaries rather than the full standard text. Your QMS must be built from the official, current document — auditors will ask to see your controlled copy.


📥 Free Resources for Aerospace QMS Implementation


Not Sure What to Do Next?

🔹 If you’re ready to buy the standard: AS9100 Rev D — ANSI Webstore — use code CC2026 for 5% off

🔹 If you need multiple standards: ANSI Standard Packages — up to 50% off bundles

🔹 If you need training before you implement: BSI Group — AS9100 Training Courses

🔹 If you’re not sure whether AS9100 applies to you: What Is AS9100? — Complete Guide

🔹 If you need to find an accredited registrar: Best ISO Certification Bodies — Ranked for 2026

🔹 If you want to check your gap before you commit: AS9100 Rev D Gap Assessment Checklist — free download

The Standards Navigator covers AS9100, ISO 9001, ISO 13485, and the full range of standards affecting aerospace, manufacturing, and defense supply chains. If you found this useful, there’s more where it came from.


Stay Ahead of AS9100 and IA9100 Changes

The IA9100 transition is coming. When it publishes, certified organizations will have a limited window to update their QMS. Subscribers to The Standards Navigator get clause-level breakdowns, implementation guidance, and audit prep resources delivered directly — before the deadline pressure hits.

👉 Subscribe below and get the AS9100 Rev D Gap Assessment Checklist free. Know exactly where your QMS stands before your next audit.

Subscribe

* indicates required

What Is AS9100? The Complete Guide to Aerospace Quality Management (2026)

AS9100 Rev D is the quality management system standard for aviation, space, and defense. It builds on ISO 9001 and adds over 100 aerospace-specific requirements — product safety, counterfeit parts prevention, configuration management, first article inspection, and more. If your organization supplies to aerospace primes, this is not optional. This guide covers what AS9100 requires, how it differs from ISO 9001, what certification costs, and what the upcoming IA9100 revision means for your organization.

The aerospace quality management standard explained — what AS9100 Rev D requires, who needs it, how it differs from ISO 9001, the five core tools, certification costs, and what IA9100 means for your organization.

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


AS9100 Is Not Optional in Aerospace. It Is the Price of Entry.

If your organization supplies to Boeing, Lockheed Martin, Raytheon, Airbus, or any Tier 1 aerospace prime — AS9100 certification is not a differentiator. It is a baseline requirement. Without it, you do not get on the approved supplier list. Full stop.

AS9100 Rev D is the quality management system standard for the aviation, space, and defense industries. It builds on ISO 9001:2015 and adds over 100 aerospace-specific requirements covering product safety, configuration management, counterfeit parts prevention, first article inspection, key characteristics, and human factors — areas where ISO 9001 alone is insufficient for the risk profile of aerospace manufacturing.

This guide covers what AS9100 actually requires, who publishes it, how it differs from ISO 9001, what the five core tools are, what certification costs, and what you need to know about the upcoming transition to IA9100.


In This Guide

  • What AS9100 is and who publishes it
  • AS9100 Rev D — the current edition and what it requires
  • How AS9100 differs from ISO 9001
  • The aerospace-specific requirements ISO 9001 doesn’t cover
  • The five core tools of AS9100
  • Who needs AS9100 certification
  • AS9100 certification process — Stage 1 and Stage 2
  • AS9100 certification costs
  • IA9100 — the upcoming revision and what it means
  • Where to buy the AS9100 standard
  • Training and certification resources


👉 Start Here (Top Resources)

👉 Purchase the official AS9100 Rev D standard from the authorized source → SAE AS9100D — ANSI Webstore — use coupon CC2026 for 5% off through December 31, 2026

👉 Get AS9100 certified with an accredited aerospace certification body → BSI Group AS9100 Certification

👉 Get AS9100 training for your team → BSI Group AS9100 Training

👉 Save up to 50% buying aerospace standards as a bundle → ANSI Standard Packages


What Is AS9100?

AS9100 is the international quality management system standard for the aviation, space, and defense industries. The current edition is AS9100 Rev D, formally designated SAE AS9100D:2016 — Quality Management Systems: Requirements for Aviation, Space, and Defense Organizations.

It is published by the International Aerospace Quality Group (IAQG) — a consortium of aerospace manufacturers from the Americas, Asia/Pacific, and Europe — and distributed in the United States through the Society of Automotive Engineers (SAE) and the ANSI Webstore.

AS9100 is used globally across three regional designations:

RegionDesignationRequirements
AmericasAS9100 Rev DIdentical requirements
EuropeEN9100:2018Identical requirements
Asia/PacificJISQ9100:2016Identical requirements

All three are functionally equivalent. A certificate issued under any of them is recognized across the global aerospace supply chain.

AS9100 is built on the foundation of ISO 9001:2015 — it includes all ISO 9001 requirements verbatim and adds over 100 aerospace-specific requirements on top. Organizations certified to AS9100 automatically satisfy ISO 9001 requirements. The reverse is not true.

For a full comparison of the two standards, see AS9100 vs ISO 9001.


AS9100 Rev D — The Current Edition

AS9100 Rev D was published in September 2016 and became the only version accepted for certification in September 2018 when the transition period from Rev C closed. It remains the current active standard.

Rev D introduced the most significant structural changes in the standard’s history — primarily because it aligned with the simultaneously released ISO 9001:2015, which introduced risk-based thinking as a foundational requirement and eliminated prescriptive documentation requirements in favor of a results-based approach.

What Rev D Changed From Rev C

AreaRev C ApproachRev D Approach
Risk managementPreventive action clauseRisk-based thinking embedded throughout
DocumentationPrescribed procedures and recordsDocumented information — flexible and scalable
LeadershipManagement representative requiredTop management direct accountability
Product safetyImplied through quality controlsExplicit dedicated clause
Counterfeit partsGeneral supplier controlsDedicated counterfeit parts prevention requirement
Human factorsNot addressedExplicit human factors clause
Configuration managementBasic requirementExpanded requirements

Rev D also introduced specific requirements for key characteristics — the product and process features that most affect safety, fit, form, and function — and strengthened first article inspection (FAI) requirements under AS9102.

Most common finding in Rev D audits: Organizations that mapped their Rev C system to Rev D clause numbers without genuinely embedding risk-based thinking throughout their processes. The standard is not just restructured — it requires a different way of thinking about quality management.


AS9100 vs ISO 9001 — Key Differences

Comparison infographic showing the key differences between ISO 9001 and AS9100 Rev D, including aerospace-specific requirements such as product safety, counterfeit parts prevention, configuration management, and first article inspection.
AS9100 builds upon ISO 9001 by adding more than 100 aerospace-specific requirements focused on safety, risk, traceability, and product integrity.

AS9100 Rev D contains all of ISO 9001:2015 plus approximately 105 additional aerospace-specific requirements. The additions are not cosmetic — they address the specific risk profile of aviation, space, and defense manufacturing, where product failures can result in loss of life and billions in liability.

Requirement AreaISO 9001:2015AS9100 Rev D
Product safetyNot explicitly addressedDedicated clause — must identify and manage product safety risks
Counterfeit partsNot addressedExplicit requirement to prevent counterfeit part use
Configuration managementNot addressedRequired — must control product configuration throughout lifecycle
First article inspectionNot requiredRequired for new parts and significant changes (AS9102)
Key characteristicsNot addressedRequired — identify, control, and document key characteristics
Human factorsNot addressedRequired — consider human factors in design and production
Customer-designated special requirementsBasic supplier controlsEnhanced flow-down requirements to sub-tier suppliers
Project managementNot addressedRequired for programs above a defined complexity threshold
Risk managementRisk-based thinkingRisk-based thinking plus specific product and program risk requirements
Production process verificationStandard process controlFirst article inspection plus ongoing process monitoring

The practical implication: an organization with ISO 9001 certification has the QMS foundation but needs significant additional controls to meet AS9100 requirements. The gap is not insurmountable — but it is real, and underestimating it is the most common implementation mistake.

For organizations already certified to ISO 9001, see ISO 9001 Certification Guide for the foundational QMS requirements that carry directly into AS9100.


Aerospace-Specific Requirements

These are the clauses and requirements in AS9100 Rev D that have no direct equivalent in ISO 9001. They are where most nonconformances occur in organizations transitioning from ISO 9001 or building an aerospace QMS for the first time.

Product Safety (Clause 8.1.1)

AS9100 requires organizations to identify product safety risks, implement controls, and maintain documentation that traces safety-critical decisions throughout the product lifecycle. This is not a general quality objective — it is a formal, documented process.

Most common finding: Product safety risk assessments that exist as standalone documents rather than being integrated into design controls, supplier qualification, and production process planning.

Counterfeit Parts Prevention (Clause 8.1.4)

Organizations must implement controls to detect and prevent the use of counterfeit or suspect unapproved parts. This includes procurement controls, approved supplier lists, incoming inspection procedures, and training for personnel involved in purchasing and receiving.

The counterfeit parts problem is significant in aerospace — the FAA and DoD have documented thousands of counterfeit parts incidents. AS9100 treats this as a systemic risk requiring a systemic response, not just an inspection step.

Most common finding: Counterfeit parts procedures that address purchasing but not the full supply chain — particularly for legacy parts and spot-buy procurement.

Configuration Management (Clause 8.1.3)

Configuration management ensures that the product delivered matches the approved design — and that any changes to the design are controlled, approved, and documented throughout the product’s lifecycle. This is particularly critical in defense programs where product configurations may be legally specified in contracts.

Most common finding: Configuration management that covers the initial production baseline but lacks controls for engineering changes, customer-approved deviations, and product updates in the field.

Key Characteristics (Clause 8.1.2)

Key characteristics are the features of a product or process whose variation most significantly affects safety, fit, form, function, or service life. AS9100 requires organizations to identify key characteristics, establish controls for them, and communicate them to suppliers.

In practice this means manufacturing engineers and quality engineers working together to identify which dimensions, material properties, or process parameters are truly critical — and building specific inspection and control plans around them rather than treating all characteristics equally.

First Article Inspection (FAI)

AS9100 references AS9102 — the First Article Inspection standard — which requires a documented review of the first production article against engineering drawings and specifications before series production begins. FAI is required for new parts and for significant design or process changes.

FAI is one of the most rigorous requirements new AS9100 implementers underestimate. A complete FAI includes dimensional verification, material certifications, process documentation, and a formal review package that must be retained as a quality record.

Most common finding: FAI records that are incomplete, filed incorrectly, or not updated after engineering changes that should have triggered a partial or full re-FAI.

Human Factors (Clause 8.1.5)

AS9100 requires organizations to consider human factors in the design of work processes and environments — particularly in maintenance, assembly, and inspection operations where human error can have safety consequences.

This is not an ergonomics requirement. It is a quality control requirement — addressing how process design, workstation layout, lighting, task complexity, and shift patterns affect the likelihood of errors in safety-critical operations.


The Five Core Tools of AS9100

Infographic showing the Five Core Automotive Quality Tools framework, including APQP, FMEA, Control Plan, MSA, and PPAP, arranged in a continuous improvement cycle used in IATF 16949 and automotive quality management systems.
The Five Core Tools work together as an integrated framework that helps automotive manufacturers prevent defects, reduce risk, and achieve consistent product quality.

The aerospace supply chain — particularly in the defense sector — references five core quality tools that support AS9100 implementation. Organizations pursuing certification should have working knowledge of all five.

StepToolPurposeWhen Used
1APQP (Advanced Product Quality Planning)Structured product development process that defines what will be built and how — integrating quality planning from design through productionNew product launches, design changes
2FMEA (Failure Mode and Effects Analysis)Systematic identification of potential failure modes and their effects on safety and quality — used to prioritize risk reduction before production beginsDesign, process, and system risk analysis
3Control PlanDocument that specifies control methods, reaction plans, and responsibilities for each step in the production process to prevent defectsProduction process control
4MSA (Measurement System Analysis)Evaluation of measurement equipment and processes to ensure measurement systems are accurate and reliable before production data is trustedGauge R&R studies, calibration validation
5PPAP (Production Part Approval Process)Formal submission that validates all requirements are met and obtains customer approval before production launchCustomer approval before production

These tools originated in the automotive sector (they are also requirements of IATF 16949) and were adopted by aerospace because they provide structured methods for quality planning that align with AS9100’s risk-based approach. For a comparison of automotive and aerospace quality standards, see ISO 9001 vs IATF 16949.


Who Needs AS9100 Certification?

AS9100 certification is required or effectively required in the following situations:

Prime Contractors and Tier 1 Suppliers

Boeing, Lockheed Martin, Northrop Grumman, Raytheon, Airbus, and other aerospace primes require AS9100 certification from their direct suppliers. This requirement flows down through the supply chain — Tier 1 suppliers typically require AS9100 from their Tier 2 suppliers for safety-critical work.

OASIS Database Registration

The OASIS database (Online Aerospace Supplier Information System) is the global registry of AS9100, AS9110, and AS9120 certified organizations. Prime contractors use OASIS to verify supplier certification status. If you are not in OASIS, you cannot demonstrate certification to a prime.

Certification to AS9100 by an IAQG-recognized certification body results in automatic OASIS registration.

Defense Contractors

U.S. Department of Defense contracts frequently specify AS9100 or an equivalent quality management system. DFARS clauses and contract quality requirements often reference the IAQG 9100 series. Organizations pursuing defense work should verify specific contractual quality requirements — some programs require additional standards beyond AS9100.

MRO and Repair Stations

Maintenance, Repair, and Overhaul (MRO) organizations and FAA Part 145 repair stations often pursue AS9110 — the AS9100 variant for aviation maintenance organizations — rather than AS9100 itself. AS9110 addresses the specific quality requirements of maintenance operations.

Aviation Parts Distributors

Organizations that distribute aviation parts without performing manufacturing use AS9120 — the AS9100 variant for distributors. AS9120 focuses on traceability, documentation, and counterfeit parts prevention in the distribution chain.

For a full breakdown of which ISO and quality standards apply to different manufacturing operations, see ISO Standards Required for Manufacturing.


The AS9100 Certification Process

AS9100 certification follows the same two-stage audit structure as ISO 9001, with additional aerospace-specific audit requirements governed by AS9104/1 — the standard that defines how certification bodies must conduct AS9100 audits.

Stage 1 — Documentation Review

The certification body reviews your QMS documentation — the quality manual, procedures, work instructions, and records — against AS9100 requirements. Stage 1 identifies gaps that must be addressed before the Stage 2 audit.

Stage 1 for AS9100 is more rigorous than ISO 9001 Stage 1 because auditors must verify that aerospace-specific documentation is present — FAI procedures, key characteristics identification, counterfeit parts controls, product safety risk processes, and configuration management documentation.

Typical duration: 1–2 days on-site or remote.

Stage 2 — System Audit

The certification body conducts a full on-site audit of your QMS in operation. Auditors evaluate not just whether procedures exist but whether they are being followed, whether records are accurate, and whether the system is producing conforming products.

AS9100 Stage 2 audits routinely include shop floor walkthroughs, review of production records, FAI package review, supplier qualification records, and interviews with operators and inspectors — not just quality and management staff.

Typical duration: 2–5 days depending on organization size and scope.

Surveillance Audits

AS9100 certificates are valid for three years. Annual surveillance audits are required in years 1 and 2. The surveillance audit scope is determined by the certification body but must cover a rotating sample of the certified QMS — it is not a light-touch check-in.

Recertification

A full recertification audit is required in year 3. If your organization is preparing for recertification, treat it with the same rigor as the initial certification audit — auditors are looking at three years of records, trends, and management review history.


AS9100 Certification Costs

AS9100 certification is more expensive than ISO 9001 certification — the audit is longer, the audit requirements are more stringent, and IAQG-accredited auditors command a premium over general ISO 9001 auditors.

Typical Cost Ranges (2026)

Cost CategorySmall Org (under 50 employees)Mid-Size Org (50–250 employees)Large Org (250+ employees)
Standard purchase (AS9100D)~$200~$200~$200
Gap assessment$3,000–$8,000$8,000–$20,000$20,000–$40,000
Implementation (internal)$15,000–$40,000$40,000–$100,000$100,000–$250,000+
Consultant (if used)$10,000–$25,000$25,000–$60,000$60,000–$150,000+
Stage 1 + Stage 2 audit$8,000–$15,000$15,000–$30,000$30,000–$60,000+
Annual surveillance audits$4,000–$8,000/yr$8,000–$15,000/yr$15,000–$30,000/yr

These are ranges, not quotes. The single biggest cost variable is internal labor — the hours your quality team, engineers, and production personnel spend on implementation. Organizations that underestimate internal labor consistently run over budget.

Factors That Drive Cost Up

  • Multiple sites — each site requires separate audit coverage
  • Complex scope — machining, welding, special processes, and NDT all require additional audit time
  • Low starting point — organizations with no formal QMS pay significantly more for implementation than those building on an existing ISO 9001 system
  • Special processes — welding, heat treatment, plating, NDT, and similar processes require specific procedure documentation and personnel qualification records that take significant time to build

The ROI Case

AS9100 certification pays for itself through contract access. A single aerospace contract that requires AS9100 certification — and that your organization could not pursue without it — typically exceeds the full cost of certification in revenue. The question is rarely whether AS9100 is worth the cost. The question is whether your organization is positioned to win the contracts that certification unlocks.

For a full cost breakdown with calculator, see ISO Certification Cost Calculator.


IA9100 — The Upcoming Revision

This is the most important current development in aerospace quality management that every AS9100-certified organization should be tracking.

Timeline infographic showing the anticipated transition from AS9100 Rev D to IA9100, including development activities beginning in 2022, a target publication date of 2026, a 2 to 3 year transition period, and expected industry adoption by 2028 to 2029.
This roadmap illustrates the expected evolution from AS9100 Rev D to IA9100 and highlights the key milestones aerospace organizations should monitor as the next generation aerospace quality standard develops.

The IAQG is developing the next revision of AS9100, which will be published under the new name IA9100. Beginning in 2022, IAQG adopted a new global naming convention — all new standards and revisions now use the “IA” prefix rather than the regional designations (AS9100 for Americas, EN9100 for Europe, JISQ9100 for Asia/Pacific). IA9100 will be a single unified global document, replacing all three regional versions simultaneously.

Why the Timing Matters

IA9100 is being developed in parallel with ISO 9001:2026, which is scheduled for publication in Q3 2026. This is intentional — AS9100 and its successor IA9100 incorporate ISO 9001 text verbatim, so IA9100 cannot be finalized until ISO 9001:2026 is published. ISO 9001:2026 is expected to introduce updates to risk-based thinking, change management, and sustainability considerations — all of which IA9100 must incorporate. The IAQG has indicated a 2026 release target for IA9100 to coincide with the ISO 9001:2026 publication.

For organizations already certified to AS9100 Rev D, the verbatim inclusion of ISO 9001 text in IA9100 means continuity — not a complete rewrite. The QMS foundation you build today carries forward. The changes will be additive, not a teardown.

Timeline

MilestoneTiming
IAQG new naming convention adopted2022
IA9100 development begins2022
ISO 9001:2026 target publicationQ3 2026
IA9100 target publication2026 (aligned with ISO 9001:2026)
Transition window (historical precedent)2–3 years after publication

What This Means for Your Organization

Organizations currently certified to AS9100 Rev D do not need to do anything differently today. Rev D remains the valid and active standard. Certification bodies are still issuing AS9100 Rev D certificates.

What you should do:

✅ Continue pursuing or maintaining AS9100 Rev D certification — there is no reason to wait for IA9100

✅ Begin monitoring IAQG communications for formal transition requirements

✅ Note that the transition window (estimated 2–3 years) gives certified organizations significant time to adapt

⚠️ Do not let IA9100 uncertainty delay certification decisions — the aerospace supply chain is not pausing AS9100 requirements while the revision is finalized


Where to Buy the AS9100 Standard

AS9100 Rev D is an SAE standard distributed through authorized channels. The ANSI Webstore is the authorized U.S. source for SAE standards and serves international buyers with standards available in multiple languages.

SAE AS9100D — ANSI Webstore — use coupon CC2026 for 5% off through December 31, 2026

Save up to 50% on ANSI Standard Packages — bundles covering AS9100 with ISO 9001 and related aerospace standards

The ANSI Webstore also offers a SAE AS9100D and ISO 9001 QMS Requirements Set — a bundle that includes AS9100D, ISO 9001:2015, and the ISO 9001 amendment, which is particularly useful for organizations building a combined AS9100/ISO 9001 system or transitioning from ISO 9001 to AS9100.

For a full guide on purchasing from authorized sources, see Where to Buy ISO Standards.


AS9100 Training and Certification Resources

Pursuing AS9100 certification requires trained personnel — internal auditors who understand the aerospace-specific requirements, quality managers who can build and maintain a compliant system, and leadership that understands what AS9100 commitments mean operationally.

Training Options

👉 BSI Group AS9100 Training — BSI Group is one of the most recognized certification bodies globally, offering AS9100 foundation, internal auditor, and lead auditor training. Their training is built around real audit experience and reflects what auditors actually look for.

👉 ISOQAR AS9100 Training — ISOQAR offers ISO-family training courses covering auditor qualifications and QMS implementation. Position alongside BSI as a second training option for your team.

Choosing an AS9100 Certification Body

Only certification bodies accredited under the IAQG’s ICOP (International Certification Organization for OASIS) scheme can issue AS9100 certificates that appear in the OASIS database. Verify any certification body’s ICOP accreditation status directly at ANAB before signing a contract — this is non-negotiable. A certificate from a non-ICOP certification body does not satisfy prime contractor requirements.

Major ICOP-accredited certification bodies include BSI Group, Bureau Veritas, DNV, Intertek, DEKRA, NQA, Perry Johnson Registrars, and SGS. For a ranked comparison of certification bodies, see Best ISO Certification Bodies.


AS9100 Implementation Checklist

Before your Stage 1 audit, verify these aerospace-specific elements are in place:

✅ Product safety risk assessment documented and integrated into operations

✅ Counterfeit parts prevention procedure — procurement, receiving, and storage controls

✅ Configuration management procedure covering design baseline, changes, and deviations

✅ Key characteristics identified on drawings and linked to control plans

✅ First Article Inspection (FAI) procedure referencing AS9102

✅ Human factors considered in work instruction and process design

✅ Special process controls — welding procedures, heat treatment specs, NDT procedures, qualified personnel records

✅ Supplier qualification records for all external providers supplying safety-critical items

✅ OASIS registration completed after certification

✅ Internal auditors trained to AS9100 Rev D requirements — not just ISO 9001

Download the Free AS9100 Rev D Gap Assessment Checklist

Knowing the requirements is one thing. Knowing where your organization actually stands against them is another.

The AS9100 Rev D Gap Assessment Checklist gives you a structured, clause-by-clause evaluation of your current QMS across 74 requirements and 12 sections — including the four AS9100-specific areas that generate the majority of first-time audit failures:

  • Product safety (Clause 8.1.1)
  • Counterfeit parts prevention (Clause 8.1.4)
  • Configuration management (Clause 8.1.3)
  • Key characteristics (Clause 8.1.2)

Mark each item YES, PARTIAL, or NO. The scoring guide tells you exactly where you stand and what to prioritize before you invest in certification.

It takes under 45 minutes and is completely free.

👉 Download the AS9100 Rev D Gap Assessment Checklist

AS9100 Rev D gap assessment checklist showing aerospace quality management requirements, audit readiness evaluation, and certification preparation for aerospace manufacturers and suppliers.
Use an AS9100 Rev D gap assessment checklist to identify quality management system weaknesses before your certification audit.

Frequently Asked Questions

What is AS9100 certification?

AS9100 certification is formal third-party verification that an organization’s quality management system meets the requirements of AS9100 Rev D — the aerospace industry quality standard. Certification is issued by IAQG-accredited certification bodies and results in registration in the OASIS database, which prime contractors use to verify supplier qualification.

What is the difference between AS9100 and ISO 9001?

AS9100 Rev D includes all ISO 9001:2015 requirements plus approximately 105 aerospace-specific additions covering product safety, counterfeit parts prevention, configuration management, key characteristics, first article inspection, and human factors. Organizations certified to AS9100 automatically satisfy ISO 9001 requirements. ISO 9001 certification alone does not satisfy AS9100 requirements.

What does AS9100 Rev D mean?

Rev D indicates the fourth major revision of the AS9100 standard. AS9100 was first published in 1999 (Rev A), revised in 2001 (Rev B), 2004 (Rev C), and 2016 (Rev D). Rev D is the current active edition and the only version accepted for certification. A new revision — to be rebranded as IA9100 — is expected in late 2026.

How long does AS9100 certification take?

Organizations with no existing QMS typically require 12–24 months to implement AS9100 and achieve certification. Organizations with an existing ISO 9001 system can often achieve AS9100 certification in 6–12 months, depending on the gap between their current QMS and AS9100’s aerospace-specific requirements. See How Long Does ISO Certification Take for a phase-by-phase timeline breakdown.

Do I need AS9100 if I already have ISO 9001?

ISO 9001 is the foundation of AS9100 — but it is not a substitute. If your aerospace customers or contracts require AS9100 certification, ISO 9001 alone does not satisfy that requirement. The aerospace-specific requirements in AS9100 (product safety, counterfeit parts, configuration management, FAI, key characteristics) are not addressed in ISO 9001.

What is OASIS and why does it matter?

OASIS (Online Aerospace Supplier Information System) is the global database of AS9100, AS9110, and AS9120 certified organizations maintained by the IAQG. Prime contractors use OASIS to verify that suppliers hold valid certification from an ICOP-accredited certification body. Only certification bodies operating under ICOP accreditation can register certifications in OASIS. A certificate from a non-ICOP body does not appear in OASIS and does not satisfy prime contractor supplier qualification requirements.

What is IA9100 and when will it replace AS9100?

IA9100 is the next revision of the AS9100 aerospace quality management standard, developed by the IAQG. Beginning in 2022, IAQG adopted a new global naming convention — all new standards and revisions now use the “IA” prefix. IA9100 is being developed in parallel with ISO 9001:2026 because IA9100 incorporates ISO 9001 text verbatim and cannot be finalized until ISO 9001:2026 is published. ISO 9001:2026 is expected to introduce updates to risk-based thinking, change management, and sustainability considerations — all of which IA9100 must incorporate. ISO 9001:2026 is scheduled for Q3 2026, and the IAQG has indicated a 2026 release target for IA9100 as well. Once published, organizations will have a formal IAQG-defined transition period — historically 2–3 years — to migrate from AS9100 Rev D. Because IA9100 incorporates ISO 9001 text verbatim, the transition will be additive rather than a complete system rewrite. Both the IAQG and NASA have explicitly stated that organizations should continue certifying to AS9100 Rev D now rather than waiting for IA9100.

How much does AS9100 certification cost?

AS9100 certification costs vary significantly by organization size and complexity. A small organization (under 50 employees) with a limited scope can expect total first-year costs of $30,000–$80,000 including implementation, training, and audit fees. Mid-size organizations typically spend $80,000–$200,000. Annual surveillance audits run $4,000–$15,000 depending on size. See How Much Does ISO Certification Cost for a full breakdown.


📥 Free Resources


Not Sure What to Do Next?

🔹 You need the official AS9100 Rev D standard

SAE AS9100D — ANSI Webstore — use coupon CC2026 for 5% off through December 31, 2026

🔹 You want to save buying AS9100 with ISO 9001 and related standards

Save up to 50% on ANSI Standard Packages — AS9100D and ISO 9001 bundle available

🔹 You’re ready to pursue AS9100 certification

BSI Group AS9100 Certification

🔹 You need AS9100 training for your quality team

BSI Group AS9100 Training

ISOQAR ISO Training Courses

🔹 You want to understand how AS9100 compares to ISO 9001

ISO 9001 vs IATF 16949 — covers the ISO 9001 vs industry-specific standard comparison framework

ISO 9001 Certification Guide

🔹 You want to understand certification costs before committing

How Much Does ISO Certification Cost?

ISO Certification Cost Calculator

🔹 You need a certification body recommendation

Best ISO Certification Bodies

🔹 You want to understand implementation timelines

How Long Does ISO Certification Take?

ISO Implementation Timeline for Manufacturers


AS9100 Is the Standard. The Question Is When.

If your organization is in aerospace, defense, or aviation manufacturing — or wants to be — AS9100 certification is not a question of if. It is a question of when and how to get there efficiently.

The organizations that struggle with AS9100 are almost always the ones that treat it as a documentation project rather than a genuine quality system. The organizations that pass their first audit without major findings are the ones that understand the standard’s intent — that in aerospace, quality failures are not defects you rework or customer complaints you manage. They are incidents with consequences that cannot be reversed.

At The Standards Navigator, AS9100 and the broader aerospace compliance landscape are covered in depth — from the standard itself to implementation strategy, audit preparation, and certification body selection.

👉 Get updates on aerospace quality standards, implementation guidance, and compliance insights delivered directly.

👉 Be first to access new AS9100 guides, tools, and checklists as they publish.

Subscribe below to stay ahead.

Subscribe

* indicates required

ISO 14001, ISO 9001, and ISO 45001 Transition (2026) Guide

ISO 14001:2026 is published. ISO 9001:2026 arrives in September. ISO 45001:2027 has its DIS ballot open. Three major management system standard revisions landing within 18 months of each other — what the changes mean, why the overlapping transition deadlines create a planning problem most manufacturers haven’t solved yet, and four actions to take now before the window tightens.

Three major management system standards are revising within three years of each other. What manufacturers need to plan for now — before the window gets tight.

Last Updated: July 2026


Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


📋 Free Download: Manufacturing Compliance Checklist — ISO 9001, 14001, 45001 & OSHA — 50 items with gap scoring across all systems.


Three Standards. Three Transition Clocks. One Planning Problem Most Manufacturers Haven’t Solved Yet.

In heavy industrial manufacturing, the worst compliance situations are rarely the ones that arrive without warning. They’re the ones where the warning was visible months in advance — and nobody acted on it because each individual deadline felt manageable on its own.

That’s the situation most manufacturers managing ISO 9001, ISO 14001, and ISO 45001 certifications are in right now.

ISO 14001:2026 published in April 2026. ISO 9001:2026 is expected in September 2026 — the FDIS ballot closes July 9, 2026, the last formal checkpoint before publication. ISO 45001:2027 has its DIS ballot open as of March 2026, with publication expected mid-2027. Three major management system standard revisions landing within roughly 18 months of each other.

Each one individually is manageable. Each one comes with a three-year transition period. Each one, evaluated in isolation, looks like something you can handle when the time comes.

The problem is they’re not arriving in isolation. For manufacturers running integrated management systems — or running three separate QMS, EMS, and OH&S programs that share auditors, procedures, and personnel — the transition timelines overlap in a way that most planning cycles haven’t accounted for.

This article covers the timeline, what’s changing in each standard, and four actions to take now before the window tightens.


In This Guide

  • The current status and timeline for all three standard revisions
  • What is changing in ISO 14001:2026 — the key updates
  • What is expected in ISO 9001:2026 — the FDIS direction
  • What is emerging in ISO 45001:2027 — early DIS signals
  • The integrated management system advantage in a triple transition
  • Four actions to take now before the transition window tightens
  • Decision-stage guidance for organizations at different points in their certification journey


Start Here (Top Resources)

🔖 Get ISO 14001:2026 → ANSI Webstore — ANSI is the official U.S. distributor of ISO standards, ensuring you receive the controlled, compliant version required for certification audits. Use coupon CC2026 for 5% off.

🔖 Train your team on ISO 14001, ISO 9001, and ISO 45001 → BSI Group — BSI Group is a founding member of ISO and one of the world’s largest providers of ISO training courses, recognized by certification bodies globally.

🔖 Build compliant management system documentation → 9001Simplified — 9001Simplified provides ready-to-use documentation kits that dramatically reduce the internal labor required to build a compliant QMS from scratch.

🔖 Pursue or maintain ISO certification → ISOQAR — ISOQAR is a UKAS-accredited certification body — one of the most recognized in the industry for ISO management system certification.

Browse the Standards Library or explore standards by compliance area to identify which standards apply to your organization.


The Triple Transition Timeline

Infographic timeline comparing ISO 14001:2026, ISO 9001:2026, and projected ISO 45001:2027 revisions, including publication dates and expected certification transition deadlines through 2030.
The Triple Transition Timeline illustrates how ISO 14001, ISO 9001, and ISO 45001 revisions are unfolding between 2026 and 2030, helping organizations plan integrated management system updates.
Standard Current Version New Version Publication Transition Deadline
ISO 14001 ISO 14001:2015 ISO 14001:2026 April 2026 ✓ Published April 2029 (expected)
ISO 9001 ISO 9001:2015 ISO 9001:2026 September 2026 (FDIS submitted) September 2029 (expected)
ISO 45001 ISO 45001:2018 ISO 45001:2027 2027 (DIS stage — TBC) ~2030 (projected)

Three-year transition periods mean organizations have time — but not unlimited time. The clock on ISO 14001 started in April 2026. The ISO 9001 clock starts in September. ISO 45001 follows in 2027, though no confirmed publication date has been issued.

Sources: BSI Group and SGS confirm September 2026 as the ISO 9001:2026 publication target.

For an organization managing all three certifications, the transition window runs from now through approximately 2030. That sounds comfortable until you factor in what transition actually requires: gap analysis against each new standard, internal audit updates, procedure revisions, management review inputs, and surveillance audits that will eventually evaluate the new requirements.

⚠️ Certification bodies must be trained and accredited to new standards before they can issue certificates. For ISO 9001:2026, GACI accreditation guidance will be issued after publication — based on typical 9–12 month accreditation cycles, Q3 2027 is a reasonable industry projection for first certificates, though no confirmed date has been issued. Plan your transition timeline around certification body readiness, not just publication dates.


ISO 14001:2026 — What Changed

ISO 14001:2026 published in April 2026 — the first revision since 2015. The revision builds on the 2024 climate change amendment (ISO 14001:2015/Amd 1:2024) and goes further in several areas that matter for manufacturing operations.

Climate change is now fully embedded. The 2024 amendment required organizations to consider climate change in their environmental management systems. ISO 14001:2026 integrates that requirement more deeply — climate-related risks and opportunities are now explicitly part of the planning and risk management process, not an optional consideration.

Life-cycle perspective is strengthened. Environmental aspects must now be assessed more holistically across the product life cycle — from raw material sourcing through end-of-life disposal. For manufacturers, this means environmental assessment can no longer stop at the facility gate. Upstream supplier impacts and downstream customer use are in scope.

Biodiversity and pollution prevention are more explicit. The revision sharpens language around pollution prevention, resource use efficiency, and biodiversity considerations. Organizations in industries with direct environmental footprints — coatings, fabrication, chemical processing — will see more specific audit scrutiny in these areas.

Planning clauses are reorganized. The structure around risks, opportunities, and change management is clearer in the 2026 version. For organizations that have always treated environmental risk management as a compliance checklist rather than a genuine planning input, this is the revision that makes that gap visible.

At this point, most EHS managers should: → Pull your current ISO 14001:2015 environmental aspects register and evaluate it against the life-cycle and climate requirements of the 2026 revision. If your aspects assessment stops at your facility boundary, it needs to be expanded. Get ISO 14001:2026 from ANSI Webstore — use CC2026 for 5% off. ANSI is the official U.S. distributor of ISO standards, ensuring you receive the controlled, compliant version required for certification audits.


📋 Free Download: Manufacturing Compliance Checklist — ISO 9001, 14001, 45001 & OSHA — 50 items with gap scoring across all systems.


ISO 9001:2026 — What’s Coming

ISO 9001:2026 infographic highlighting upcoming quality management system changes including quality culture, ethical leadership, risk and opportunity management, supply chain resilience, and the 2026 to 2029 transition timeline.
ISO 9001:2026 builds on the existing framework while introducing stronger expectations for quality culture, ethical leadership, risk management, and supply chain resilience.

ISO 9001:2026 is not published yet — ISO/FDIS 9001 reached stage 50.20 as of April 2026, confirming the FDIS ballot has been initiated — confirmed on ISO’s official standards page and reported by DQS Global, a DAKKS-accredited certification body. ⚠️ The ballot closes July 9, 2026. Only editorial changes are possible after that point — the technical content of ISO 9001:2026 is effectively locked. The direction is clear enough to plan against.

The revision is evolutionary, not revolutionary. The core Annex SL structure remains. Clause numbering stays intact. Organizations certified to ISO 9001:2015 are not facing a rebuild — they’re facing a targeted update.

Quality culture and ethical conduct are new emphasis areas. The 2026 version introduces more explicit expectations around leadership’s role in establishing a culture of quality — not just documenting a quality policy, but demonstrating that quality values are embedded in how the organization operates. Ethical conduct and integrity within leadership are specifically called out.

Risk and opportunity management is sharpened. Risks and opportunities are expected to be addressed more distinctly in the 2026 version — with clearer guidance on how each is identified, evaluated, and acted upon. Organizations that have treated Clause 6.1 as a one-time planning exercise rather than an ongoing process will find the 2026 expectations more demanding.

Supply chain resilience enters the picture. The disruptions of recent years are reflected in 2026’s increased emphasis on supply chain management and organizational resilience. Clause 8.4 language around external providers is expected to be more specific about resilience and continuity considerations.

The transition timeline is specific. Publication in September 2026 triggers a three-year transition period — organizations will need to be certified to ISO 9001:2026 by September 2029. First certificates will follow — certification bodies must complete training and receive accreditation guidance from GACI after publication. Based on typical 9–12 month accreditation cycles, Q3 2027 is a reasonable industry projection, though no confirmed date has been issued.

If you are currently implementing ISO 9001:2015 for the first time → Proceed. Your 2015 certificate remains valid through September 2029 and the transition to 2026 is not a rebuild. The ISO 9001 Implementation Roadmap covers the full 5-phase process from gap assessment to Stage 2 audit clearance.


➡️ BSI Group ISO 9001 and ISO 14001 Training — Transition training for ISO 9001:2026 and ISO 14001:2026 covering gap analysis, new requirements, and audit preparation. BSI Group is a founding member of ISO and one of the world’s largest providers of ISO training courses, recognized by certification bodies globally.


ISO 45001:2027 — Early Signals

ISO 45001:2027 is the furthest out — but the revision entered the DIS stage in early 2026, and the direction of the revision is visible in the committee draft material. Publication is expected mid-2027, with a three‑year transition period expected, likely running through 2030.

Worker wellbeing expands beyond physical safety. The current ISO 45001:2018 standard focuses on occupational health and safety in a traditional sense. The 2027 revision explicitly expands scope to include psychosocial hazards — stress, burnout, workplace violence, mental health — as core OH&S considerations. This is a meaningful shift for manufacturers whose safety programs have focused primarily on physical hazard controls.

Climate change is integrated as an OH&S requirement. Climate-related risks — heat stress, extreme weather events, air quality impacts — are being incorporated into the OH&S risk framework. For operations in industries with outdoor or climate-exposed work environments, this will require new hazard identification and control measures.

New working models are addressed. Remote work, hybrid arrangements, and contractor-heavy operations are explicitly considered in the 2027 revision. The definition of “workplace” is expanding, and with it, the scope of OH&S responsibility.

Leadership accountability is stronger. Management’s active role in safety culture — not just policy sign-off — is a recurring theme across the 2027 draft. The expectation is demonstrable leadership engagement, not just documented commitment.

ESG and supply chain responsibility. The revision extends OH&S considerations to the supply chain, consistent with the direction ISO 9001:2026 and ISO 14001:2026 are also taking. For manufacturers with complex supplier networks, this creates new audit scope.


The Common Thread Across All Three

Reading the three revisions together, a consistent direction emerges — and it matters for how organizations approach transition planning.

All three standards are moving from compliance to performance. The 2026/2027 revisions across quality, environmental, and safety management systems reflect a shared expectation: that management systems demonstrate real outcomes, not just documented processes. Certification bodies auditing against these revised standards will be looking for evidence of genuine system effectiveness, not procedure compliance.

All three embed climate and sustainability more explicitly. ISO 14001:2026 integrates climate requirements into its planning clauses. ISO 9001:2026 adds resilience and supply chain sustainability language. ISO 45001:2027 adds climate-related OH&S risks. Organizations that have managed these as separate environmental compliance obligations are going to find them converging into a single integrated requirement set.

All three strengthen leadership expectations. Quality culture in ISO 9001:2026, environmental leadership in ISO 14001:2026, safety culture in ISO 45001:2027. Leadership’s role is not just policy ownership — it’s demonstrated behavioral commitment. That is an audit finding waiting for organizations whose top management signs off on policy documents but isn’t visible in the management system.

All three align with the updated Annex SL high-level structure. This means integration across the three standards is structurally easier in the revised versions than it was in the 2015/2018 versions. For organizations running integrated management systems, the 2026/2027 revisions are actually an opportunity — the common structure means a single integrated gap assessment covers significant ground across all three.


The Integrated Management System Advantage

Integrated Management System diagram showing ISO 9001, ISO 14001, and ISO 45001 overlap for quality, environmental, and safety management
A visual representation of how ISO 9001, ISO 14001, and ISO 45001 integrate into a single management system to improve quality, environmental performance, and workplace safety.

Organizations managing ISO 9001, ISO 14001, and ISO 45001 as separate programs face the triple transition as three independent projects. Organizations managing them as an integrated management system (IMS) face it as one.

The practical difference is significant. An IMS shares a single management review process — one review covers QMS, EMS, and OH&S inputs and outputs. It shares an internal audit program — one audit cycle covers all three standards. It shares document control, training records, and corrective action systems. When revisions land, an IMS organization updates one system. A siloed organization updates three.

The 2026/2027 revisions accelerate this advantage because of the common thematic direction across all three standards. A gap analysis that covers climate integration, leadership requirements, and supply chain scope serves all three transitions simultaneously. A management review that adds resilience and sustainability performance inputs serves ISO 9001, ISO 14001, and ISO 45001 at the same time.

If your organization manages the three standards in separate programs, the triple transition is a legitimate reason to evaluate IMS consolidation now — not because it’s required, but because the administrative burden of three independent transition projects under overlapping deadlines is the kind of thing that creates compliance gaps.


Approach Gap Analysis Internal Audit Management Review Procedure Updates Transition Risk
Siloed programs 3 separate assessments 3 separate cycles 3 separate reviews 3 separate update projects High — deadline convergence
Integrated IMS 1 integrated assessment 1 combined cycle 1 combined review 1 coordinated update Lower — shared infrastructure

Four Actions to Take Now

Infographic outlining four actions organizations should take now to prepare for ISO 14001:2026, ISO 9001:2026, and ISO 45001 transition requirements, including gap assessments, audit planning, management review evaluation, and internal audit integration.
Four practical actions organizations can take today to prepare for upcoming ISO 14001, ISO 9001, and ISO 45001 transition requirements and avoid last-minute certification challenges.

1. Get ISO 14001:2026 and run a gap assessment against your current EMS.

The clock is running on ISO 14001. Your 2015 certification remains valid through approximately April 2029 — but the gap assessment takes time, procedure updates take time, and your surveillance audit schedule may not align with your ideal transition timeline. Start the gap assessment now while you have room to plan. Get the standard from ANSI Webstore — use CC2026 for 5% off.

For the full ISO 9001:2026 transition timeline including certification body accreditation milestones, 9001Simplified’s revision guide is the most detailed publicly available planning reference.

2. Map your surveillance audit schedule against the transition deadlines.

Your certification body will eventually conduct a transition audit for each standard. Knowing when your next surveillance audit is scheduled — and whether it falls before or after each publication date — tells you when you need to have your transition work complete. A surveillance audit in early 2027 for ISO 14001 means your 14001 transition needs to be done before that visit, not by 2029.

3. Evaluate your management review process against the new common requirements.

Climate change, resilience, supply chain performance, and leadership accountability are showing up across all three revisions. Adding these as management review inputs now — before the standards require it — positions your organization to demonstrate proactive compliance rather than reactive scrambling. It also means your management review minutes start building a record of these considerations before your first transition audit.

4. Consolidate your internal audit program if you haven’t already.

If you’re running separate audit cycles for quality, environmental, and safety, consider whether an integrated audit program would serve all three transitions more efficiently. A single annual audit cycle that covers ISO 9001, ISO 14001, and ISO 45001 in one planned program gives you a single update project when the revised standards require audit checklist changes. It also means your internal auditors need transition training once, not three times.

At this point, most operations and EHS managers overseeing all three certifications should: → Start with the Manufacturing Compliance Checklist — it covers ISO 9001, 14001, 45001 and OSHA across 50 items with gap scoring. It gives you a current-state baseline across all three systems before you invest in transition-specific gap analysis tools.


Why Organizations Delay Transition Planning

“We have until 2029 — there’s no urgency.”

The three-year transition period is real. The urgency is not about the deadline — it’s about the gap between when a transition deadline is announced and when certification bodies can actually audit against the new standard. For ISO 9001:2026, first certificates aren’t expected until Q3 2027 at the earliest, because certification bodies need 9–12 months after publication to complete training and accreditation. If your next ISO 9001 surveillance audit falls in late 2027, you may be audited against the 2026 standard whether you planned for it or not.

“Each transition is manageable — we’ll handle them one at a time.”

Handling ISO 14001:2026 now, ISO 9001:2026 in late 2026, and ISO 45001:2027 in 2027–2028 as three sequential projects is a reasonable approach — if your internal audit program, management review schedule, and quality personnel capacity can absorb three consecutive transition projects. Organizations with lean QMS teams consistently discover that sequential transition management creates a permanent state of transition, where the team finishes one standard’s update cycle and immediately starts the next. Integrated planning reduces that burden significantly.

“We don’t know enough about ISO 9001:2026 and ISO 45001:2027 yet to plan.”

You know enough. The FDIS direction for ISO 9001:2026 is clear — quality culture, ethics, resilience, supply chain. The DIS signals for ISO 45001:2027 are clear — wellbeing, climate, new working models, leadership accountability. Waiting for final publication to start thinking about these themes means your gap assessment starts at zero when the standard publishes. Starting now means your gap assessment starts from a position of partial readiness.


Frequently Asked Questions

Do I need to transition all three standards at the same time?

No — each standard has its own transition deadline and you can manage them sequentially. The case for coordinated planning is efficiency, not obligation. ISO 14001:2026 is already published, so that transition clock is running. ISO 9001:2026 publishes in September 2026. ISO 45001:2027 publishes mid-2027. Three separate deadlines — but organizations that plan them together avoid three separate periods of transition disruption.

Will my current certifications become invalid when the new standards publish?

No. Your current ISO 9001:2015, ISO 14001:2015, and ISO 45001:2018 certificates remain valid through their respective transition deadlines — approximately 2029, 2029, and 2030. You do not need to take immediate action on certification. You do need to plan for transition before those deadlines.

What is the transition period for ISO 14001:2026?

The transition period is expected to be three years from publication — approximately April 2029. Your certification body will confirm the exact transition deadline once IAF guidance is issued. Plan against April 2029 as the working assumption.

When will certification bodies start auditing against ISO 9001:2026?

Not immediately after publication. Certification bodies must complete training and accreditation to the new standard — a process that typically takes 9–12 months. First ISO 9001:2026 certificates are not expected until at least Q3 2027. This means organizations pursuing ISO 9001 certification for the first time should implement ISO 9001:2015 now — it remains the auditable standard through the transition period.

What does the ISO 45001:2027 revision mean for manufacturers with mostly physical hazard environments?

The 2027 revision expands OH&S scope to include psychosocial hazards and climate-related risks — which will require manufacturers to broaden their hazard identification processes. For facilities with outdoor operations, heat stress and extreme weather become OH&S planning inputs. For all facilities, psychosocial hazard assessment becomes an expected element of the risk identification process.

Should we pursue an integrated management system before the triple transition?

If your organization manages ISO 9001, ISO 14001, and ISO 45001 as separate programs, the triple transition is a legitimate trigger to evaluate IMS consolidation. It is not required — but the efficiency gains during three overlapping transition projects are real. The decision depends on your internal resource capacity and how much administrative redundancy your current siloed programs create. BSI Group offers integrated management system training that covers all three standards simultaneously. BSI Group training — BSI Group is a founding member of ISO and one of the world’s largest providers of ISO training courses, recognized by certification bodies globally.

What are the key changes in ISO 14001:2026 for manufacturers?

Climate change fully embedded in planning requirements, life-cycle perspective extended beyond facility boundaries, stronger biodiversity and pollution prevention language, and reorganized planning clauses around risks and opportunities. For manufacturers in industries with direct environmental footprints — coatings, fabrication, chemical processing — the life-cycle and climate requirements are the most operationally significant changes.

Do ISO 9001:2026 and ISO 45001:2027 change the Annex SL structure?

No. All three revised standards maintain the Annex SL high-level structure — the common clause framework that enables integrated management systems. This is by design: ISO intends the common structure to make multi-standard integration easier, and the 2026/2027 revisions maintain that compatibility.


Free Resources

📋 Free Download: Manufacturing Compliance Checklist — ISO 9001, 14001, 45001 & OSHA — 50 items with gap scoring across all systems.

📋 Free Download: Supplier Quality Checklist — ISO 9001 Clause 8.4 — all supplier controls auditors evaluate, 45 items with scoring.

📋 Free Download: ISO 9001 Implementation Roadmap — The exact 5-phase process from gap assessment to Stage 2 audit clearance.

📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items — ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


Not Sure What to Do Next?

→ You need ISO 14001:2026 now → ANSI Webstore — Use CC2026 for 5% off. ANSI is the official U.S. distributor of ISO standards.

→ You need to train your team on the revised standards → BSI Group Training — ISO 14001, ISO 9001, and ISO 45001 transition training available. BSI Group is a founding member of ISO and one of the world’s largest providers of ISO training courses.

→ You need to build or update management system documentation → 9001Simplified Documentation Kits — ready-to-use documentation kits for ISO 9001, 14001, and integrated management systems.

→ You are ready to pursue or maintain ISO certification → ISOQAR — UKAS-accredited, one of the most recognized certification bodies in the industry.

→ You need to understand what changed specifically in ISO 14001:2026 → What’s New in ISO 14001:2026

→ You need a current-state baseline across all three systems → Manufacturing Compliance Checklist — free, 50 items covering ISO 9001, 14001, 45001 and OSHA.

→ You need to understand ISO 9001 implementation from the ground up → ISO 9001 Implementation Roadmap

→ You want to understand how ISO 9001 and ISO 14001 relate to each other → explore standards by compliance area

→ You want to browse all manufacturing standards in one place → Standards Library


Still figuring out where to start?

The best first step for most organizations managing all three certifications: → Download the free Manufacturing Compliance Checklist — 50 items across ISO 9001, 14001, 45001 and OSHA with gap scoring. It gives you a current-state picture across all three systems in 20 minutes, before you spend anything on transition planning.

📋 Free Download: Manufacturing Compliance Checklist — ISO 9001, 14001, 45001 & OSHA — 50 items with gap scoring across all systems.


The Window Is Open. It Won’t Stay That Way.

Three-year transition periods create the illusion of distance. They don’t.

The organizations that handle standard transitions well are not the ones that wait for the final published standard and then scramble to close gaps. They’re the ones that track the direction of the revision, run a preliminary gap assessment while the draft is still in ballot, update management review inputs before the standard requires it, and arrive at their first transition audit with documented evidence of preparation — not a stack of recently revised procedures.

ISO 14001:2026 is published. The ISO 9001:2026 FDIS is in ballot. The ISO 45001:2027 DIS ballot is open. All three revision directions are clear enough to plan against right now.

For manufacturers running all three certifications, the planning decision isn’t whether to prepare. It’s whether to prepare for one integrated transition or three sequential ones.

At The Standards Navigator, complex standards are translated into practical, real-world guidance you can act on.

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

ISO 13485 Documentation Requirements (2026)

Every document and record ISO 13485 requires — with clause references, document control requirements under Section 4.2, record retention rules, how QMSR changed the documentation landscape, and the seven gaps auditors find most consistently. Built as a reference document quality managers can use before their next audit.

Every document your QMS must have, what auditors check first, and why the gaps between your procedures and your records are where most findings live.

Last Updated: May 2026


Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items covering ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


The Binder on the Shelf Is Not a QMS

Years ago, working in a nuclear component facility, I watched a certification audit go sideways in the first thirty minutes. The quality manager had spent six months building what looked like a complete quality management system — binders, procedures, forms, the works. The auditor asked to see the document register. The quality manager pointed to the binder. The auditor asked how documents were controlled at the point of use. The quality manager pointed to the binder again.

The binder was the system. It sat on a shelf in the quality office. The machinists on the floor had printed copies of procedures from three years prior. Nobody had a current revision of anything. The audit did not go well.

ISO 13485 documentation is not about having paperwork. It is about having the right documents, in the right format, accessible to the right people, at the right time — and being able to prove all of that during an audit. The standard is specific about what must be documented, what must be retained as records, and what that documentation must demonstrate.

Under QMSR, which took effect February 2, 2026, FDA now evaluates ISO 13485 documentation requirements against the framework directly. Organizations that treat documentation as a filing exercise rather than a quality system function are finding that gap at inspection.

This article covers every documentation requirement ISO 13485 imposes, where auditors look first, and what a compliant documentation system actually looks like in practice.


In This Guide

  • The difference between documents and records under ISO 13485 — and why it matters for audits
  • Every mandatory document the standard requires
  • Every mandatory record the standard requires
  • Document control requirements under Section 4.2
  • Record retention rules under Section 4.2.5
  • The most common documentation gaps auditors find
  • How QMSR changed the documentation landscape for U.S. medical device manufacturers
  • Decision-stage guidance for organizations at different points in their documentation journey


Start Here (Top Resources)

🔖 Get ISO 13485:2016 → ANSI Webstore — ANSI is the official U.S. distributor of ISO standards, ensuring you receive the controlled, compliant version required for certification audits. Use coupon CC2026 for 5% off.

🔖 Build compliant QMS documentation → 9001Simplified — 9001Simplified provides ready-to-use documentation kits that dramatically reduce the internal labor required to build a compliant QMS from scratch.

🔖 Train your team on ISO 13485 documentation requirements → BSI Group — BSI Group is a founding member of ISO and one of the world’s largest providers of ISO training courses, recognized by certification bodies globally.

🔖 Pursue or maintain ISO 13485 certification → ISOQAR — ISOQAR is a UKAS-accredited certification body — one of the most recognized in the industry for ISO management system certification.

Browse the What Is ISO 13485? pillar article for full clause context, or use the ISO 13485 Gap Assessment Checklist to identify your specific documentation gaps before your next audit.


Documents vs. Records: The Distinction That Drives Compliance

ISO 13485 treats documents and records as separate categories with different requirements. Confusing them is one of the most consistent sources of documentation findings in surveillance audits.

Documents are instructions, procedures, specifications, and plans — the things that tell people what to do. They are living documents: they can be revised, updated, and superseded. Section 4.2.4 governs their control.

Records are evidence that something was done — completed forms, test results, inspection reports, calibration data, training sign-offs. They are fixed in time: once a record is created, it cannot be altered without creating a documented amendment. Section 4.2.5 governs their control.

The practical distinction matters for two reasons. First, the control requirements differ. Documents need revision control, approval, distribution, and obsolescence management. Records need legibility, identification, storage protection, retrieval, and defined retention periods. A documentation system that applies the same controls to both will have gaps in one or the other.

Second, auditors evaluate them separately. When an auditor asks for a procedure, they are asking for a document. When they ask for evidence, they are asking for a record. Handing an auditor a completed form when they asked for a procedure — or a procedure when they asked for evidence — signals a documentation system that does not understand its own structure.

At this point, most quality managers building or auditing a documentation system should: → Map your document inventory against your record inventory separately. If your document register includes completed forms alongside controlled procedures, your system architecture has a structural problem. 9001Simplified’s documentation kits include pre-structured document and record registers built for ISO 13485 compliance. 9001Simplified provides ready-to-use documentation kits that dramatically reduce the internal labor required to build a compliant QMS from scratch.


Mandatory Documents Under ISO 13485

ISO 13485 requires specific documented procedures and plans across multiple clauses. These are not optional — certification bodies audit for their existence and their content.

ISO 13485 documentation infographic illustrating mandatory quality management system documents with interconnected process icons for quality manuals, risk management, design planning, procedures, records retention, purchasing controls, and document control requirements.
Certification bodies expect documented procedures, controlled records, and defined plans that demonstrate the quality system operates consistently and remains audit ready — see the full list in the table below.
DocumentClauseWhat It Must Cover
Quality Manual4.2.2Scope of the QMS, exclusions with justification, documented procedures or references, description of QMS process interactions
Document Control Procedure4.2.4Approval, review, revision control, distribution, obsolescence management, external documents
Records Control Procedure4.2.5Identification, storage, protection, retrieval, retention periods, disposition
Management Review Procedure5.6Inputs, outputs, frequency, documentation requirements
Competence, Training & Awareness Procedure6.2How competence is determined, how training is delivered, how competence is evaluated and recorded
Infrastructure Procedure6.3Maintenance of buildings, equipment, and supporting services affecting product quality
Work Environment Procedure6.4Control of work environment conditions where required for product conformity
Risk Management Procedure7.1Risk management process across the product lifecycle, per ISO 14971
Customer-Related Processes Procedure7.2Requirements determination, review, and customer communication
Design & Development Procedure7.3Planning, inputs, outputs, review, verification, validation, transfer, changes (if design is not excluded)
Purchasing Procedure7.4Supplier evaluation, selection, monitoring, and purchasing information
Production & Service Controls Procedure7.5Control of production and service provision, cleanliness, installation, and servicing
Identification & Traceability Procedure7.5.3Product identification throughout realization and traceability requirements
Customer Property Procedure7.5.4Control and safeguarding of customer-supplied product or data
Preservation Procedure7.5.5Preservation of product during processing and delivery
Monitoring & Measurement Equipment Procedure7.6Calibration, verification, and control of measuring equipment
Feedback Procedure8.2.1Post-market surveillance and feedback collection
Complaint Handling Procedure8.2.2Complaint receipt, investigation, and regulatory reporting decisions
Internal Audit Procedure8.2.4Audit planning, conduct, reporting, and follow-up
Nonconforming Product Procedure8.3Identification, segregation, evaluation, and disposition
CAPA Procedure8.5.2 / 8.5.3Corrective and preventive action process, including root cause analysis and effectiveness verification

⚠️ If your organization excludes design and development under Clause 7.3, that exclusion must be justified in the Quality Manual and documented. Exclusions without documented justification are a consistent finding in initial certification audits.


📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items covering ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


Mandatory Records Under ISO 13485

Records are the evidence your QMS operated as documented. The standard specifies which records must be maintained — these are the minimum. Your procedures may require additional records.

RecordClauseWhat It Must Demonstrate
Management Review Minutes5.6.3Inputs reviewed, decisions made, actions assigned with owners and timelines
Education, Training, Skills & Experience6.2Competence evaluated, training completed, results recorded
Infrastructure Maintenance6.3Maintenance activities and results for quality-critical equipment
Risk Management Records7.1Risk analysis, risk evaluation, risk control, residual risk assessment, post-production monitoring
Customer Requirements Review7.2.2Requirements determined and confirmed before commitment
Design & Development Records7.3Inputs, outputs, reviews, verifications, validations, transfer, and changes (if not excluded)
Design & Development Changes7.3.9Change description, evaluation, verification, validation, approval
Supplier Evaluation Records7.4.1Evaluation criteria, results, and re-evaluation decisions
Production Process Validation7.5.2Validation protocols, results, equipment qualifications
Traceability Records7.5.3.2Unique device identification and traceability through production
Customer Property Records7.5.4Receipt, condition assessment, and disposition of customer property
Calibration Records7.6Equipment identification, calibration standard, results, next due date
Internal Audit Records8.2.4Audit plans, findings, nonconformances, corrective actions, follow-up
Product Monitoring & Measurement8.2.6Evidence of conformity and identification of release authority
Nonconforming Product Records8.3Nature of nonconformity, disposition decision, concession records if applicable
CAPA Records8.5.2 / 8.5.3Root cause analysis, action taken, effectiveness verification with criteria and evidence

➡️ 9001Simplified Documentation Kits — Pre-built ISO 13485 procedures, forms, and record templates covering every mandatory document and record listed above. 9001Simplified provides ready-to-use documentation kits that dramatically reduce the internal labor required to build a compliant QMS from scratch.


Document Control: What Section 4.2.4 Actually Requires

Section 4.2.4 sets out seven specific requirements for document control. Each one has a practical implementation implication — and each one is evaluated individually during audits.

1. Documents must be approved before use. Approval must be by authorized personnel. Your document control procedure must define who has approval authority for each document type. A document approved by someone outside that authority — or with no documented approval at all — is a nonconformance.

2. Documents must be reviewed, updated as necessary, and re-approved. Review frequency should be defined in your procedure. Documents that have never been reviewed since initial creation are a finding in surveillance audits — particularly if the regulatory environment or production process has changed.

3. Changes and current revision status must be identified. Every controlled document needs a revision identifier — a number, letter, or date — and your document register needs to reflect current revision status. Auditors check this against what is in use.

4. Relevant versions must be available at points of use. This is the binder-on-the-shelf failure. Current controlled versions must be accessible where work is performed. If people work from printed copies, you need a controlled printing process. If work is performed on a production floor, current procedures must be accessible there — not only in the quality office.

5. Documents must be legible and identifiable. This sounds obvious. It is consistently violated by organizations that allow handwritten annotations, informal updates, or degraded printed copies to remain in service.

6. External documents must be identified and controlled. This includes customer drawings, regulatory guidance documents, referenced standards, and supplier specifications. External documents that affect product quality must be listed in your document control system and their current version verified.

7. Obsolete documents must be prevented from unintended use. Obsolete documents must either be removed from all points of use or clearly marked as obsolete. Finding an active workstation with a superseded procedure is a major nonconformance — regardless of whether anyone was actually using it.

If you are under active FDA inspection pressure → BSI Group ISO 13485 Training covers document control implementation and audit preparation in depth. BSI Group is a founding member of ISO and one of the world’s largest providers of ISO training courses, recognized by certification bodies globally.


Record Retention: What Section 4.2.5 Actually Requires

Section 4.2.5 requires that records be retained for a period at least equal to the lifetime of the medical device, but not less than two years from the date of product release by the organization.

That two-year floor is the minimum. In practice, most medical device records should be retained significantly longer:

  • Implantable devices — the device lifetime may span decades. Records need to match.
  • Devices with long service lives — the same logic applies.
  • FDA QMSR requirements — align with ISO 13485 on the two-year minimum but your complaint handling procedure may require longer retention for MDR-related records.
  • Customer contractual requirements — OEM customers increasingly specify record retention periods in their supplier quality agreements. These requirements take precedence where they are more stringent than the standard’s minimum.

Your records control procedure must define retention periods for each record type. A blanket “two years” policy applied to all records — including design history files and risk management records for long-life devices — is not compliant.

ProviderWhat You GetBest For
ANSI WebstoreISO 13485:2016 official standardAny organization needing the controlled, compliant version of the standard
9001SimplifiedQMS documentation kits with record templatesOrganizations building documentation from scratch or rebuilding after a major finding
BSI GroupISO 13485 training coursesTeams implementing documentation systems or preparing for initial certification
ISOQARISO 13485 certificationOrganizations ready to pursue or maintain certification

Most organizations building documentation systems from scratch need all three:

This combination covers the standard, the knowledge, and the implementation infrastructure.


The Most Common Documentation Gaps

ISO 13485 documentation gaps infographic illustrating seven common audit findings, including outdated document registers, incomplete supplier records, weak CAPA evidence, missing procedures, and disconnected risk management records within medical device quality systems.
Documentation failures rarely appear as isolated findings. They create chains of audit problems across CAPA, supplier controls, training, management review, and risk management. The gap is usually discovered long after it was created.

These are the findings that appear most consistently in ISO 13485 surveillance audits and QMSR inspections. Each one points to a specific procedure or record requirement.

The Quality Manual references procedures that don’t exist. A common initial certification shortcut is writing a Quality Manual that references a full set of documented procedures — then discovering during the surveillance audit that several of those procedures were never finalized. The Quality Manual and the document register must be synchronized.

The document register is not current. Document registers that haven’t been updated in months, that show revision numbers inconsistent with what is in use, or that are missing entire document categories are a consistent finding. The register is the first thing many auditors check.

Risk management records stop at design transfer. ISO 14971 requires risk management across the product lifecycle. Design-phase risk files with no post-production updates — no connection to complaint data, service reports, or CAPA findings — are incomplete regardless of how thorough the original analysis was. See ISO 14971 vs ISO 13485 for the full lifecycle requirement.

CAPA records close without effectiveness verification evidence. A CAPA record that reads “action implemented — problem resolved” with no supporting data is not a closed CAPA — it is an open finding waiting to be issued. For the complete breakdown of what effectiveness verification requires, see CAPA Requirements in ISO 13485.

Supplier qualification records are incomplete or outdated. An approved supplier list without corresponding qualification evidence, or qualification records for suppliers whose scope has changed without requalification, are consistently cited findings under Clause 7.4.

Training records prove attendance, not competence. Sign-off sheets showing who attended a training session are not competence records. The record must show what competence was evaluated, by what method, and what the result was. See Common Mistakes in ISO 13485 QMS for the full breakdown of this finding.

Management review minutes record presentations, not decisions. Minutes that describe what was presented in management review without documenting what was decided are a major finding under Section 5.6.3. Every input reviewed must produce a documented output — a decision, an action, or a rationale for no action.


How QMSR Changed the Documentation Landscape

FDA’s Quality Management System Regulation, effective February 2, 2026, aligns U.S. medical device QMS requirements with ISO 13485:2016. For documentation, the practical changes are significant.

The Device Master Record (DMR) structure is now explicitly required. Under QMSR, the DMR — which must include device specifications, production process specifications, quality assurance procedures, packaging and labeling specifications, and installation and maintenance procedures — is a specific documentation requirement that ISO 13485 certification alone does not fully address.

Complaint files under 21 CFR 820.198 remain a separate requirement. ISO 13485 requires a complaint handling procedure. QMSR additionally requires that complaint files contain specific elements — including the decision on whether the complaint required investigation and, if so, the results of that investigation — that go beyond what most ISO 13485 complaint procedures specify.

MDR procedures must be documented separately. Medical Device Reporting obligations are a regulatory requirement that sits outside ISO 13485 but must be addressed in your QMS documentation under QMSR.

⚠️ FDA QMSR compliance date was February 2, 2026. If your documentation system has not been reviewed against the four QMSR-specific bridge requirements since that date, that review is overdue. The ISO 13485 Gap Assessment Checklist covers all four QMSR bridge requirements explicitly alongside the standard ISO 13485 clause requirements.

For the full regulatory alignment picture, see FDA QSR vs ISO 13485.

Infographic explaining the major operational and regulatory changes introduced under the FDA QMSR, including terminology alignment, expanded risk management, inspection changes, and ISO 13485 document control requirements.
The FDA’s QMSR transition introduced major changes beyond terminology — expanding risk management expectations, changing inspection structure, and aligning medical device quality systems directly with ISO 13485.

Why Organizations Delay Getting Documentation Right

“We’ll clean it up before the surveillance audit.”

This is the most common delay rationalization — and it consistently produces the worst outcomes. Documentation gaps that accumulate over 11 months cannot be credibly remediated in the 30 days before a surveillance visit. Auditors can identify recently created records. A CAPA file dated three weeks before the audit for a problem that complaint data shows has existed for eight months is not evidence of a functioning QMS — it is evidence of audit preparation, which auditors treat as a different category of finding.

“Our documentation was good enough for initial certification.”

Initial certification evaluates documentation at a point in time against a system that was built to be audited. Surveillance audits evaluate whether that system has been maintained — which means they look at records created since the last audit, not at procedures written before it. Organizations that passed initial certification and then stopped maintaining their documentation systems often face multiple major nonconformances at the first surveillance visit.

“We don’t have the internal resources to build this properly.”

This objection is real — but the cost of building documentation properly before certification is substantially lower than the cost of remediation after a major nonconformance. A documentation kit from 9001Simplified covers every mandatory document and record template in a ready-to-use format. 9001Simplified provides ready-to-use documentation kits that dramatically reduce the internal labor required to build a compliant QMS from scratch. The internal labor required to customize a pre-built kit is a fraction of what is required to build from scratch — and a fraction of what remediation costs after a finding.


Frequently Asked Questions

What documents are required by ISO 13485?

ISO 13485 requires documented procedures covering quality manual, document control, records control, management review, training and competence, risk management, customer requirements, purchasing, production controls, identification and traceability, calibration, feedback, complaint handling, internal audit, nonconforming product, and CAPA. The full list with clause references is in the Mandatory Documents table above.

What records are required by ISO 13485?

ISO 13485 requires records covering management reviews, training and competence evaluations, risk management activities, design and development (if not excluded), supplier evaluations, calibration, internal audits, product monitoring, nonconforming product dispositions, and CAPA activities. The full list with clause references is in the Mandatory Records table above.

How long must ISO 13485 records be retained?

The standard requires retention for at least the lifetime of the device, with a minimum of two years from product release. For implantable devices and devices with long service lives, the retention period is typically longer and should be defined in your records control procedure. FDA QMSR aligns with this minimum but specific record types — particularly MDR-related records — may require longer retention.

Does ISO 13485 require a Quality Manual?

Yes. Section 4.2.2 requires a Quality Manual that defines the scope of the QMS, documents or references procedures, and describes the interactions between QMS processes. The Quality Manual is one of the first documents an auditor requests.

Can we use electronic records to meet ISO 13485 requirements?

Yes — electronic records are acceptable provided your document control system ensures they are controlled, legible, retrievable, and protected from unauthorized modification. Electronic systems used to manage controlled documents must themselves be validated if they affect product quality.

What is the difference between a controlled document and a record under ISO 13485?

A controlled document is an instruction, procedure, or specification that tells people what to do — it can be revised and must be version-controlled. A record is evidence that something was done — it is fixed in time and must be retained according to your records control procedure. Section 4.2.4 governs controlled documents; Section 4.2.5 governs records. The distinction is fundamental to building a compliant documentation system.

Does design and development documentation apply to all medical device manufacturers?

Only if the manufacturer performs design and development activities. If your organization manufactures to customer specifications and does not perform design activities, you may be eligible to exclude Clause 7.3 — but that exclusion must be documented and justified in your Quality Manual. Contract manufacturers who claim a 7.3 exclusion without justification are consistently cited at initial certification.

How do FDA QMSR documentation requirements differ from ISO 13485?

QMSR aligns with ISO 13485 but adds four specific requirements: the Device Master Record structure, complaint files under 21 CFR 820.198, Medical Device Reporting procedures, and corrections and removals procedures. ISO 13485 certification alone does not cover these four requirements. The ISO 13485 Gap Assessment Checklist addresses all four explicitly.

What is the first thing an auditor looks at for ISO 13485 documentation?

Most auditors start with the document register — to verify that controlled documents are listed, revision levels are current, and the register reflects what is actually in use. From there they move to the Quality Manual to verify scope and procedure references. Gaps in either of those two items typically expand the audit’s scope significantly.


Free Resources

📋 Free Download: Manufacturing Compliance Checklist — ISO 9001, 14001, 45001 & OSHA — 50 items with gap scoring across all systems.

📋 Free Download: Supplier Quality Checklist — ISO 9001 Clause 8.4 — all supplier controls auditors evaluate, 45 items with scoring.

📋 Free Download: ISO 9001 Implementation Roadmap — The exact 5-phase process from gap assessment to Stage 2 audit clearance.

📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items — ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


Not Sure What to Do Next?

→ You need the official ISO 13485:2016 standard → ANSI Webstore — Use CC2026 for 5% off. ANSI is the official U.S. distributor of ISO standards.

→ You need to build ISO 13485 documentation from scratch → 9001Simplified Documentation Kits — ready-to-use procedures, forms, and record templates for every mandatory document.

→ You need to train your team on documentation requirements → BSI Group ISO 13485 Training — BSI Group is a founding member of ISO and one of the world’s largest providers of ISO training courses.

→ You are ready to pursue ISO 13485 certification → ISOQAR — UKAS-accredited, one of the most recognized certification bodies in the industry.

→ You need to assess your documentation gaps before your next audit → ISO 13485 Gap Assessment Checklist — free, 64 items.

→ You need to understand how QMSR changed your documentation obligations → FDA QSR vs ISO 13485

→ You need to understand CAPA record requirements in depth → CAPA Requirements in ISO 13485

→ You need to understand the most common documentation audit findings → Common Mistakes in ISO 13485 QMS

→ You need to understand how risk management documentation connects to your QMS → ISO 14971 vs ISO 13485

→ You need to understand the full ISO 13485 clause structure → What Is ISO 13485?

→ You want to buy ISO 13485 → Buy ISO 13485

→ You want to browse all medical device standards → explore standards by compliance area


Still figuring out where to start?

If you are not ready to commit to a documentation build yet — that is normal. Most organizations spend several weeks between identifying gaps and starting remediation.

The best next step: → Download the free ISO 13485 Gap Assessment Checklist — it takes 20 minutes and tells you exactly which documents and records you are missing before you spend anything.

Feature image promoting an ISO 13485 Gap Assessment Checklist for medical device manufacturers, contract manufacturers, and component suppliers preparing for certification and FDA QMSR compliance.
ISO 13485 Gap Assessment Checklist designed to help medical device manufacturers identify compliance gaps, prioritize actions, and prepare for certification and FDA QMSR requirements.

📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items — ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


The Binder Is Not the System

Documentation is not ISO 13485’s most technically demanding requirement. But it is the foundation every other requirement rests on. Without controlled documents, procedures cannot be consistently followed. Without records, there is no evidence that procedures were followed at all. Without a document control system that connects what is written to what people actually use, the gap between those two things grows quietly — until an auditor measures it.

The organizations that handle documentation audits well are not the ones with the most sophisticated quality management software or the thickest procedure binders. They are the ones whose documentation reflects how work actually gets done — current, accessible, and connected to the records that prove it.

That alignment takes discipline to build and discipline to maintain. It does not take complexity.

At The Standards Navigator, complex standards are translated into practical, real-world guidance you can act on.

Subscribe below to stay ahead.

Subscribe

* indicates required

Common Mistakes in ISO 13485 QMS (2026)

Seven ISO 13485 QMS mistakes that consistently produce major nonconformances — document control drift, management review gaps, supplier qualification failures, CAPA records closed without verification, risk management treated as a one-time activity, competence records that prove attendance not ability, and internal audits that never find anything. With clause references and fixes for each.

The audit findings that derail medical device manufacturers — and the fixes that prevent them.

Last Updated: May 2026


Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items covering ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


Your QMS Passed Initial Certification. Now the Surveillance Audit Found Three Major Nonconformances.

This scenario plays out more often than most quality managers expect.

Initial certification audits are thorough — but they happen at a fixed point in time, against a QMS that was built specifically to pass them. Surveillance audits arrive 12 months later and evaluate how the system actually operates day to day. That gap between what was built and what runs is where most findings live.

The mistakes in this article are not obscure edge cases. They are the findings that certification bodies issue most consistently, that FDA investigators flag most frequently under QMSR, and that experienced quality practitioners see repeated across organizations of every size. Some of them look like documentation failures. Most of them are process failures wearing documentation’s clothes.

If you are preparing for a first certification audit, a surveillance visit, or an FDA QMSR inspection, this list tells you where to look before the auditor does.


In This Guide

  • The most common mistakes in ISO 13485 QMS by clause
  • Why document control failures are almost never about documents
  • The management review gap that catches organizations by surprise
  • How supplier qualification problems compound over time
  • What auditors find when they look at CAPA records
  • The risk management connection most QMS procedures miss
  • Decision-stage guidance for organizations at different points in their compliance journey


Start Here (Top Resources)

🔖 Get ISO 13485:2016 → ANSI Webstore — ANSI is the official U.S. distributor of ISO standards, ensuring you receive the controlled, compliant version required for certification audits. Use coupon CC2026 for 5% off.

🔖 Build compliant QMS documentation → 9001Simplified — 9001Simplified provides ready-to-use documentation kits that dramatically reduce the internal labor required to build a compliant QMS from scratch.

🔖 Train your team on ISO 13485 → BSI Group — BSI Group is a founding member of ISO and one of the world’s largest providers of ISO training courses, recognized by certification bodies globally.

🔖 Pursue or maintain ISO 13485 certification → ISOQAR — ISOQAR is a UKAS-accredited certification body — one of the most recognized in the industry for ISO management system certification.

Browse the What Is ISO 13485? pillar article for full clause context, or use the ISO 13485 Gap Assessment Checklist to identify your specific gaps before your next audit.


Mistake 1: Document Control That Controls Nothing

The clause: ISO 13485 Section 4.2 — Document Control

What auditors find: Obsolete procedures still accessible in shared drives. Forms in use that don’t match the current controlled version. Employees working from printed copies with no revision date. Documents approved by someone whose role no longer includes that authority.

Document control failures are the most consistently cited finding in ISO 13485 surveillance audits — not because organizations don’t have document control procedures, but because those procedures don’t match how people actually access and use documents day to day.

The standard requires that documents be reviewed and approved before use, that current versions are available at points of use, and that obsolete documents are prevented from unintended use. Each of those three requirements has failed in organizations that had a document control procedure on file.

The fix: Document control is an access problem, not a paperwork problem. The question is not “do we have a procedure?” — it’s “can an employee working right now reach a document that has been superseded?” If the answer is yes, your document control system is not functioning regardless of what your procedure says.

Audit your access architecture — shared drives, QMS software, printed SOPs at workstations — before an auditor does. Every document a user can reach should be the current controlled version. Everything else should require deliberate action to retrieve.

At this point, most quality managers in this position should: → Pull your document control procedure and map it against actual employee access. If those two things don’t match, 9001Simplified’s documentation kits include document control templates built specifically for ISO 13485 compliance. 9001Simplified provides ready-to-use documentation kits that dramatically reduce the internal labor required to build a compliant QMS from scratch.


Mistake 2: Management Review Without Documented Outputs

The clause: ISO 13485 Section 5.6 — Management Review

What auditors find: Meeting minutes that record attendance and agenda items but contain no documented decisions. Review inputs listed without evidence they were actually analyzed. Action items described without owners, deadlines, or follow-up records. Reviews conducted annually when the organization’s risk profile warranted more frequent review.

ISO 13485 Section 5.6.3 is explicit: management review outputs must include decisions and actions related to improvement of the QMS, improvement of product to meet customer requirements, and resource needs. A management review that happened but produced no documented decisions is a nonconformance — regardless of what was discussed in the room.

This finding catches organizations off guard because the review itself felt thorough. Leadership reviewed quality objectives, discussed complaint trends, walked through audit results. But the meeting minutes read like a summary of what was presented, not a record of what was decided.

The fix: Management review outputs need to look like decisions, not summaries. For each input reviewed, the record should show: what the data indicated, what conclusion was reached, and what — if anything — will be done about it. “Complaint trend reviewed — no action required” is a decision. “Complaint data presented” is not.

⚠️ Under QMSR, FDA inspectors now evaluate management review as part of every inspection. Inspectors who find management reviews without documented outputs routinely cite this as a systemic QMS failure, not an administrative lapse.


Mistake 3: Supplier Qualification on Paper Only

ISO 13485 supplier qualification infographic illustrating risk-based supplier controls under Clause 7.4, featuring a supplier risk tier matrix, qualification lifecycle process, ongoing monitoring activities, and common supplier management mistakes.
Supplier qualification under ISO 13485 is not a one-time approval exercise. Risk classification, qualification activities, performance monitoring, and periodic re-evaluation must work as a continuous lifecycle.

The clause: ISO 13485 Section 7.4 — Purchasing / Supplier Controls

What auditors find: An approved supplier list that has not been updated in years. Suppliers qualified based on a questionnaire with no follow-up evaluation. Critical suppliers with no documented performance monitoring. Qualification records for suppliers whose scope of supply has expanded beyond what was originally evaluated.

Supplier qualification failures compound over time in a way that most other QMS failures don’t. A supplier that was qualified five years ago may have changed ownership, changed manufacturing processes, changed subcontractors, or expanded into new product categories — none of which triggered a requalification because the procedure didn’t require one.

ISO 13485 requires that purchasing controls be proportionate to the risk the supplier presents to product quality and patient safety. That proportionality has to be reflected in your qualification criteria, your monitoring frequency, and your records. An approved supplier list populated with names and no evaluation data is not a supplier qualification program.

The fix: Supplier qualification is a living process, not a one-time gate. Your procedure should define evaluation criteria by supplier risk tier, monitoring frequency, requalification triggers, and what happens when a supplier fails to meet performance criteria. If you are using the Supplier Quality Checklist, the ISO 13485 Clause 7.4 section identifies every supplier control element auditors evaluate — including the ones most procedures leave undocumented.


📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items covering ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


Mistake 4: CAPA Records That Close Without Verification

ISO 13485 CAPA infographic comparing incorrect and correct closure methods, showing the difference between closing corrective actions without effectiveness verification and closing them with documented objective evidence under Clause 8.5.2.
CAPA is not complete when action is implemented. Under ISO 13485 Clause 8.5.2, closure requires effectiveness verification supported by defined criteria, monitoring, objective evidence, and documented results.

The clause: ISO 13485 Section 8.5.2 — Corrective Action

What auditors find: CAPAs closed at implementation with no effectiveness check. Effectiveness verifications that consist of a single sentence — “action implemented, problem resolved” — with no supporting data. Criteria for effectiveness that were defined after the action was taken rather than before. The same problem recurring in a subsequent audit cycle.

Closing a CAPA without effectiveness verification is one of the most consistently cited major nonconformances in ISO 13485 audits. The standard requires that corrective actions be reviewed for effectiveness — and that review must be documented, must use defined criteria, and must be supported by evidence.

The pattern most organizations fall into is treating CAPA closure as an administrative step rather than a quality decision. Someone implements the action, marks the record complete, and moves on. The question “did this actually work?” never gets formally answered.

The fix: Effectiveness verification criteria must be established before the corrective action is implemented — not after. The criteria should be specific enough that a different person reviewing the record could objectively determine whether they were met. “No recurrence for 90 days” is a criterion. “Situation improved” is not.

For a complete breakdown of CAPA requirements under ISO 13485 Clause 8.5.2 — including the InfuTronix case study and the six mandatory data inputs under Section 8.4 — see CAPA Requirements in ISO 13485.


➡️ BSI Group ISO 13485 Training — Covers CAPA, supplier controls, management review, and all major ISO 13485 clauses. BSI Group is a founding member of ISO and one of the world’s largest providers of ISO training courses, recognized by certification bodies globally.


Mistake 5: Risk Management Treated as a One-Time Activity

The clause: ISO 13485 Section 7.1 / ISO 14971

What auditors find: Risk files created during design and never updated. Post-market surveillance data that has no documented connection to risk management. Field failures that triggered a CAPA but never prompted a review of the corresponding risk file. Risk management plans that reference ISO 14971 but contain no evidence of post-production monitoring.

Risk management documentation under Clause 7.1 is now the top QMSR inspection finding — 25 citations in the first three months of QMSR inspection data, ahead of CAPA. That displacement reflects a systematic failure in how most organizations treat risk: as a design-phase activity rather than a lifecycle responsibility.

ISO 14971 is explicit that risk management extends across the entire product lifecycle. Post-market surveillance data, complaint trends, service reports, and CAPA findings are all risk management inputs. When those data sources exist in separate systems with no documented connection to the risk file, the risk management process is incomplete — regardless of how thorough the original risk analysis was.

The fix: Your risk management procedure should define how post-production information feeds back into risk files. When a complaint trend reaches a defined threshold, when a CAPA is opened for a field failure, when a service report pattern emerges — each of those events should trigger a documented review of the relevant risk analysis. That review should produce a documented decision: residual risk is still acceptable, or risk control measures need updating.

For the full picture of how ISO 14971 and ISO 13485 interact at the clause level, see ISO 14971 vs ISO 13485.


Mistake 6: Training Records That Prove Attendance, Not Competence

The clause: ISO 13485 Section 6.2 — Human Resources / Competence

What auditors find: Training records that show who attended a session and when, with no evidence of what was covered or whether it was understood. Competence assessments that consist of a supervisor signature with no evaluation criteria. Personnel performing quality-critical tasks without documented evidence that they are qualified to do so. New employees signed off on procedures they completed training on — but with no record of how competence was evaluated.

ISO 13485 Section 6.2 requires that personnel performing work affecting product quality are competent — and that competence is evaluated and the results are recorded. Attendance is not competence. Completing a training module is not competence. Competence is the demonstrated ability to apply knowledge and skills to produce the required outcome.

This distinction becomes a major finding when an auditor pulls the training record for someone who made a quality-critical decision and finds a sign-off sheet.

The fix: Competence evaluation needs defined criteria for each quality-critical role — what knowledge and skill is required, and how it will be evaluated. That evaluation can be a practical demonstration, a written assessment, a supervised work period with documented sign-off, or another method appropriate to the task. The key is that the record shows what was evaluated and what the result was — not just that training occurred.

If you are building competence frameworks from scratch, BSI Group’s ISO 13485 training courses include role-based competency models that align with Section 6.2 requirements. BSI Group is a founding member of ISO and one of the world’s largest providers of ISO training courses, recognized by certification bodies globally.


Mistake 7: Internal Audits That Don’t Find Anything

The clause: ISO 13485 Section 8.2.4 — Internal Audit

What auditors find: Internal audit programs that audit the same low-risk processes repeatedly while avoiding the areas where problems actually exist. Audit reports that describe observations as “satisfactory” or “no issues found” across every clause. Internal auditors who have never issued a nonconformance. Audit findings that are consistently minor and never escalate to CAPA.

An internal audit program that finds nothing is either auditing the wrong things or auditing them incorrectly. Certification bodies and FDA investigators specifically look at the output of your internal audit program — not just whether audits were conducted on schedule. If your internal audit findings never trigger a CAPA and never surface anything your surveillance audit finds, that incongruence is a finding in itself.

ISO 13485 requires that the internal audit program take into account the status and importance of the processes to be audited and the results of previous audits. A risk-based audit program will allocate more frequency and depth to high-risk processes — CAPA, supplier controls, complaint handling, design controls — and less to lower-risk administrative processes.

The fix: Evaluate your internal audit program against what your surveillance audits and FDA inspections have actually found. If there is a consistent gap — if surveillance audits find things your internal audits missed — that gap is the finding. Your audit program needs to be harder on the areas that matter most, not easier.

If you need to develop your internal audit capability, ISOQAR offers ISO 13485 internal auditor training and certification support. ISOQAR is a UKAS-accredited certification body — one of the most recognized in the industry for ISO management system certification.

At this point, most quality managers preparing for their next audit should: → Cross-reference your last three internal audit reports against your last surveillance audit finding. If the surveillance audit found something your internal audits missed, that’s the gap to close first. Get the ISO 13485 Gap Assessment Checklist to run a structured review across all clauses.


Common Misconceptions About ISO 13485 QMS

ISO 13485 infographic illustrating common misconceptions about quality management systems, comparing myths versus reality around certification, QMSR alignment, and major nonconformances in medical device quality systems.
Some of the most expensive ISO 13485 mistakes begin as assumptions. Certification is not a finish line, ISO 13485 and QMSR are not identical, and a major nonconformance does not automatically mean certification loss.

“Passing initial certification means the QMS is compliant.”

Initial certification confirms that a QMS met the standard’s requirements at a specific point in time, as evaluated against a specific set of records. Surveillance audits evaluate whether the system continues to operate as documented. Organizations that build a QMS to pass initial certification and then don’t maintain it operationally consistently accumulate findings by the first surveillance audit. Certification is not a destination — it is a recurring obligation.

“ISO 13485 and FDA QMSR requirements are now the same thing.”

QMSR, which took effect February 2, 2026, aligns FDA’s device QMS requirements with ISO 13485 — but does not make them identical. Four FDA-specific requirements exist in QMSR that ISO 13485 certification alone does not cover: complaint files under 21 CFR 820.198, MDR procedures, corrections and removals, and the device master record structure. An organization that is ISO 13485 certified is not automatically QMSR compliant. The ISO 13485 Gap Assessment Checklist covers all four QMSR bridge requirements explicitly.

“A major nonconformance means we will lose certification.”

A major nonconformance means the certification body has identified a significant gap in the QMS — one that has the potential to affect product quality or patient safety. It does not automatically result in suspension or withdrawal of certification. It triggers a corrective action requirement with a defined response timeline. Organizations that respond with a documented root cause analysis and credible corrective action plan typically resolve major nonconformances without losing certification. The risk is not the finding — it is the failure to respond adequately.


Frequently Asked Questions

What is the most common ISO 13485 audit finding?

Document control failures under Section 4.2 are consistently the most common finding in surveillance audits. CAPA effectiveness verification failures and management review output gaps follow closely. Under QMSR inspections, risk management documentation under Clause 7.1 is now the leading finding.

How many nonconformances are typical in an ISO 13485 surveillance audit?

There is no typical number. A mature QMS with active internal audit and CAPA programs may receive zero nonconformances. A QMS that has been maintained administratively rather than operationally may receive multiple majors. What matters is whether findings from one audit cycle are genuinely closed before the next one.

What is the difference between a major and minor nonconformance in ISO 13485?

A major nonconformance indicates a systematic failure that has the potential to affect product quality or patient safety — or the complete absence of a required process. A minor nonconformance indicates an isolated lapse or a process weakness that does not constitute a systematic failure. Major nonconformances require a documented corrective action plan with a defined response timeline. Minor nonconformances are typically addressed at the next surveillance audit.

Can we self-declare ISO 13485 compliance without certification?

Self-declaration against ISO 13485 is not recognized in the medical device industry in the way it is sometimes used in other sectors. Customers, regulatory bodies, and OEMs expect third-party certification from an accredited body. Self-declaration provides no audit trail and no independent verification of compliance. If you are building toward certification, ISOQAR is a UKAS-accredited certification body — one of the most recognized in the industry for ISO management system certification.

How long does it take to fix a major nonconformance?

Certification bodies typically allow 30 to 90 days to respond to a major nonconformance with a documented corrective action plan, evidence of root cause analysis, and initial implementation evidence. Full closure — including effectiveness verification — may take longer depending on the nature of the finding. The timeline should be proposed by the organization and accepted by the certification body.

What is the best way to prepare for an ISO 13485 surveillance audit?

Run a structured internal audit against the clauses most likely to surface findings — Section 4.2 (document control), Section 5.6 (management review), Section 7.4 (supplier controls), Section 8.2.4 (internal audit), and Section 8.5.2 (CAPA). Pull a sample of CAPA records and verify that effectiveness verifications are complete. Review your management review minutes for documented outputs. Check that your approved supplier list reflects current qualification status. The ISO 13485 Gap Assessment Checklist covers all of this in 64 structured items.

Do these mistakes also apply under FDA QMSR?

Yes — and in some cases the stakes are higher. QMSR inspections evaluate every subsystem, every inspection. Document control failures, CAPA gaps, and management review deficiencies that might result in a minor nonconformance from a certification body can result in a 483 observation or warning letter from FDA. See FDA QSR vs ISO 13485 for the full regulatory alignment picture.


Free Resources

📋 Free Download: Manufacturing Compliance Checklist — ISO 9001, 14001, 45001 & OSHA — 50 items with gap scoring across all systems.

📋 Free Download: Supplier Quality Checklist — ISO 9001 Clause 8.4 — all supplier controls auditors evaluate, 45 items with scoring.

📋 Free Download: ISO 9001 Implementation Roadmap — The exact 5-phase process from gap assessment to Stage 2 audit clearance.

📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items — ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


Not Sure What to Do Next?

→ You need the official ISO 13485:2016 standard → ANSI Webstore — Use CC2026 for 5% off. ANSI is the official U.S. distributor of ISO standards.

→ You need to assess your QMS gaps before your next audit → ISO 13485 Gap Assessment Checklist — free, 64 items

→ You need to build or rebuild QMS documentation → 9001Simplified Documentation Kits — 9001Simplified provides ready-to-use documentation kits that dramatically reduce the internal labor required to build a compliant QMS from scratch.

→ You need to train your team on ISO 13485 requirements → BSI Group ISO 13485 Training — BSI Group is a founding member of ISO and one of the world’s largest providers of ISO training courses.

→ You are ready to pursue or maintain ISO 13485 certification → ISOQAR — UKAS-accredited, one of the most recognized certification bodies in the industry.

→ You need to understand CAPA requirements in depth → CAPA Requirements in ISO 13485

→ You need to understand how risk management connects to your QMS → ISO 14971 vs ISO 13485 and What Is ISO 14971?

→ You need to understand how QMSR changed your compliance obligations → FDA QSR vs ISO 13485

→ You need to understand what ISO 13485 covers at the clause level → What Is ISO 13485?

→ You need to understand the cost of ISO 13485 certification → How Much Does ISO 13485 Cost?

→ You want to buy ISO 13485 → Buy ISO 13485

→ You want to browse all medical device standards → explore standards by compliance area


Still figuring out where to start?

If you are not ready to invest in training or documentation yet — that is normal. Most organizations take several weeks to move from identifying gaps to committing to a remediation plan.

The best next step for most organizations at this stage: → Download the free ISO 13485 Gap Assessment Checklist — it takes 20 minutes and tells you exactly where your QMS has gaps before you spend anything.

📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items — ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


The Gap Between What Was Built and What Runs

Most ISO 13485 QMS failures are not failures of intent. The organizations that receive major nonconformances typically built their systems with genuine effort. What they built, however, was optimized for initial certification — not for the ongoing operational reality that surveillance audits and FDA inspections evaluate.

Document control systems that work at go-live drift as people find workarounds. CAPA programs that close records efficiently lose track of effectiveness. Management reviews that felt thorough produce minutes that record what was presented rather than what was decided. None of these failures are dramatic. They accumulate quietly, and they surface at the worst possible time.

The difference between a QMS that passes surveillance audits consistently and one that doesn’t is not sophistication. It is the discipline to evaluate what the system actually does — not just what the procedures say it does — on a regular basis.

At The Standards Navigator, complex standards are translated into practical, real-world guidance you can act on.

Subscribe below to stay ahead.

Subscribe

* indicates required