Certifications

ISO 9001 vs ISO 13485 vs AS9100: What Each Certification Actually Checks

A provider’s certification badges tell you almost nothing on their own. ISO 9001, ISO 13485, and AS9100 all sound like “this company has good quality control,” and providers list them exactly that way, but they audit different things for different reasons. Here’s what each one actually covers.

Standard Industry scope What it specifically audits beyond a general QMS Recertification cycle
ISO 9001 Any industry Leadership commitment, planning, resource management, process control, monitoring and corrective action. The general-purpose baseline. 3 years, annual surveillance audits
ISO 13485 Medical devices Risk management across the product lifecycle, design controls, device traceability, regulatory compliance specific to medical devices. Aligned with ISO 9001 but is a separate standard, not built on top of it. 3 years, annual surveillance audits
AS9100 Aerospace, space, defense Everything in ISO 9001 plus over 100 aerospace-specific clauses: airworthiness, configuration management, counterfeit-parts prevention, product safety, full supply-chain traceability. Built directly on ISO 9001. 3 years, annual surveillance audits

The distinction that actually matters when you’re picking a provider: ISO 9001 certifies that a company has a documented, followed quality process. It says nothing about what that process is optimized for. A provider certified only to ISO 9001 can be excellent, or can simply have decent paperwork, and there’s no way to tell which from the badge alone.

ISO 13485 and AS9100 are different because they force specific things ISO 9001 doesn’t require: 13485 forces design-history documentation and risk files that trace a part back through its whole lifecycle, which is the paper trail a medical device recall actually depends on. AS9100 forces counterfeit-parts prevention and configuration control, which matters for aerospace supply chains and essentially never comes up in a general manufacturing job.

None of these three standards test material biocompatibility, mechanical performance, or dimensional accuracy directly. They test whether a company has a documented, auditable process and follows it. A certified provider can still produce a bad part; the certification just means there’s a paper trail explaining how and why it happened, and a documented process for fixing it. For biocompatibility specifically, that’s a separate material-level certification (USP Class ratings, ISO 10993 sub-tests), not something ISO 13485 tests on its own.

If a provider’s marketing leans hard on “ISO certified” without saying which standard, that’s worth asking about directly. “ISO certified” alone could mean ISO 9001, which every serious manufacturer should have as a baseline, not evidence of anything specific to your part.

Sources