ISO 9001 is a baseline; 13485 is medical-specific

Engineers sourcing machined components for medical programs ask this question constantly. The short answer: ISO 9001:2015 is a general quality management standard that works for any industry — it requires process definition, corrective action, management review, and customer satisfaction measurement. ISO 13485 builds on that framework but adds medical-device-specific requirements: risk management across the entire product realization chain, full traceability from raw material to finished device, regulatory compliance, documented work instructions at every step, and controls that a typical 9001 shop simply does not implement.

For a non-critical bracket or fixture that never touches a patient, a 9001 shop is perfectly adequate. For any component that goes into a Class II or III device, contacts the patient, or carries a performance specification affecting safety, ISO 13485 alignment is not optional — it is how you satisfy FDA 21 CFR 820 and EU MDR obligations.

Traceability: the biggest practical difference

Under ISO 9001, traceability is required only to the extent defined in the customer contract — that can mean a job number on a router and nothing more. Under ISO 13485, traceability is mandatory and specific. Every lot of raw material is tied to a mill heat number, that heat number is recorded on the job router, the router travels with the parts through every operation, and every part or lot is traceable from incoming material through shipping. If a material lot is recalled, a 13485 shop can tell you exactly which parts were made from it and where they went.

  • Material test reports retained and linked to job number and shipment record
  • Operator and inspector identification at every operation step
  • Lot traceability maintained through secondary ops: anodize, passivation, laser marking
  • Records retained for device lifetime plus regulatory minimum, not just a few years

Risk management and work instructions

ISO 13485 requires risk management per ISO 14971. Before cutting metal on a medical part, there is a documented risk assessment covering material mix-up, dimensional non-conformance, contamination from cutting fluids, sharp edges, biocompatibility, and any other identified failure mode. Work instructions specify exactly which cutting tool, which inspection instrument, which sampling frequency, and what to do if a measurement goes out of tolerance. A machinist cannot decide to change the approach on a critical feature.

Compare this to a typical ISO 9001 shop where a machinist can change feeds, speeds, or clamping strategy as long as the part meets print. That flexibility is efficient for industrial work. On a medical component where a dimensional error could end up in a patient, documented process control is essential.

Document control: changes leave a paper trail

In a 13485 environment, changing an insert grade, moving a part to a different machine, or switching a secondary-op supplier requires a documented engineering change request, quality manager approval, and often customer notification depending on change classification. The change control process typically adds 1-3 business days compared to the rapid iteration possible in a 9001 environment. The trade-off is that production parts are made under a validated process that does not drift between lots.

RequirementISO 9001:2015ISO 13485:2016
TraceabilityAs required by contractMandatory: heat-to-ship, full lot traceability
Risk managementRisk-based thinking (broad)ISO 14971 FMEA / risk file per part
Work instructionsProcesses defined, flexibility allowedStep-by-step, operator-specific documents
Change controlInternal processFormal ECN, customer notification per agreement
Contamination controlNot specifically addressedRequired where product demands it
Regulatory complianceNot in scopeFDA / EU MDR / other regional requirements
Records retentionOrganization-defined minimumDevice lifetime + regulatory minimum (often 10+ years)

Checking scope and auditing reality

An ISO 13485 certificate for injection molding does not cover CNC machining. Always verify the scope on the certificate and, for critical parts, request a sample Device History Record (DHR) and Device Master Record (DMR) for a similar part. The certificate tells you the shop passed an audit; the DHR tells you how the system actually runs day to day. Look for material cert linkage, inspection records, non-conformance handling, and calibration status of the inspection equipment used.

Our medical machining baseline

We hold ISO 9001:2015 as a baseline and apply 13485-aligned processes for medical components: full traceability, documented control plans, incoming material verification with mill certs on file, Zeiss CMM inspection with Cpk reporting on critical dimensions, and clean assembly areas for contamination-controlled parts. FAI reports are provided at no charge on new medical parts, and prototypes typically ship in 5-7 working days.

Frequently Asked Questions

  • Can an ISO 9001 shop make medical parts?

    For non-critical components that do not contact the patient or affect device safety (brackets, enclosures, assembly fixturing), yes. For patient-contacting or performance-critical components in Class II or III devices, ISO 13485 is needed to satisfy FDA 21 CFR 820 or EU MDR.

  • Does ISO 13485 replace ISO 9001?

    ISO 13485 is a standalone standard based on the ISO 9001 process model but with medical-specific additions. A shop certified to 13485 meets most 9001 requirements, but they are separate certifications with separate audits.

  • What is a DHR and DMR?

    The Device Master Record (DMR) is the complete documentation package for building a component: drawings, specs, work instructions, inspection criteria. The Device History Record (DHR) is the production record for a specific lot, proving it was built per the DMR — material lots, operators, inspection data, non-conformances.

  • How long must 13485 records be retained?

    ISO 13485 requires records for the device lifetime plus any regulatory minimum. For FDA-regulated devices, that is typically 10 years from shipment, but it varies by device class and region.

  • Is a certificate enough, or should I audit the supplier?

    Certification means an accredited auditor reviewed the system. For critical components, a supplier questionnaire or audit reviewing DHR samples, calibration records, and non-conformance history is good practice.