ISO 9001 vs AS9100, IATF 16949 and ISO 13485.
ISO 9001 is the generic quality management system standard. AS9100 (aerospace), IATF 16949 (automotive) and ISO 13485 (medical devices) are the sector standards built on the same foundation — but each adds requirements that reflect what goes wrong in that industry, and they are not interchangeable. Choosing the wrong target wastes a certification cycle; certifying to a sector standard you were never asked for wastes audit days every year after that.
AS9100 and IATF 16949 contain the full text of ISO 9001 plus sector additions, so certifying to either satisfies an ISO 9001 requirement in practice. ISO 13485 is structurally different: it is aligned to ISO 9001:2008, is not built on the Annex SL high-level structure, and certification to it does not confer ISO 9001 certification.
The deciding factor is almost never technical preference — it is your customer base and regulator. Aerospace primes flow down AS9100, automotive OEMs flow down IATF 16949 through the customer-specific requirements, and medical device market access effectively requires ISO 13485.
- 01ISO 9001 is the baseline; AS9100, IATF 16949 and ISO 13485 are sector standards built from it.
- 02AS9100D = ISO 9001:2015 in full, plus ~100 aerospace additions (configuration management, counterfeit parts, first article inspection, product safety).
- 03IATF 16949 cannot be certified alone — it is applied together with ISO 9001 and mandatory customer-specific requirements.
- 04ISO 13485 is risk- and regulation-driven rather than continual-improvement-driven, and does not include ISO 9001 certification.
- 05Certify to what your customers and regulators require, not to the longest list; each additional standard adds annual surveillance audit days.
The four standards compared
Use this to identify the target standard before any gap analysis starts.
| Standard | Sector | Relationship to ISO 9001 | Certification driver |
|---|---|---|---|
| ISO 9001:2015 | Any organisation | The baseline standard | Customer pre-qualification, tender requirements |
| AS9100D (EN/JISQ 9100) | Aviation, space and defence | Contains ISO 9001:2015 in full plus aerospace additions | Prime contractor flow-down; OASIS registration |
| IATF 16949:2016 | Automotive production and service parts | Applied as a supplement to ISO 9001:2015 — not standalone | OEM contractual requirement plus customer-specific requirements |
| ISO 13485:2016 | Medical devices | Standalone; aligned to ISO 9001:2008 structure, not Annex SL | Regulatory market access (MDR, MDSAP, FDA expectations) |
What AS9100 adds to ISO 9001
AS9100D reproduces every clause of ISO 9001:2015 and then adds requirements written by the aerospace industry through the IAQG.
- Product safety — an explicit requirement to plan, implement and control processes affecting product safety (8.1.3).
- Counterfeit part prevention — controls to avoid counterfeit or suspect unapproved parts entering the supply chain (8.1.4).
- Configuration management — identification, traceability and control of configuration and change through the product life (8.1.2).
- First article inspection (FAI) — verification of a representative first production item against all design characteristics (8.5.1.3).
- Special requirements, critical items and key characteristics — identification and specific control of features whose variation affects fit, form, function or safety.
- Extended supplier control — approval, monitoring and flow-down of requirements to sub-tier suppliers, including test and NDT sources.
- Enhanced documentation, risk management and on-time delivery performance monitoring.
Certification is registered in the IAQG OASIS database, which primes check directly. In practice, an organisation with a working ISO 9001 system is closing a defined set of aerospace-specific gaps rather than rebuilding a system.
What IATF 16949 adds — and why it is never certified alone
IATF 16949:2016 is published as a supplement to ISO 9001:2015: the document contains only the automotive additions, and the two are audited together. The certificate covers the combined requirements, and the certification process itself is far more prescriptive than ISO 9001 — audit days, auditor qualification, remote support locations and non-conformance response timelines are all fixed by the IATF Rules.
On top of the standard sit customer-specific requirements (CSRs) issued by each OEM. These are mandatory and auditable, so two certified suppliers can be operating to materially different requirements depending on who they ship to.
- Core tools embedded as requirements: APQP, PPAP, FMEA, MSA and SPC.
- Product safety, with defined responsibilities and escalation.
- Contingency planning for production interruption, including cyber and utility events.
- Total productive maintenance and tooling/gauge management.
- Embedded software development and warranty management where applicable.
- Mandatory customer-specific requirements flowed through the whole supply chain.
Why ISO 13485 is the odd one out
ISO 13485:2016 shares its ancestry with ISO 9001 but was deliberately kept aligned to the ISO 9001:2008 structure rather than moving to the Annex SL format used by ISO 9001:2015. Its purpose is regulatory: to demonstrate an ability to consistently supply medical devices meeting customer and applicable regulatory requirements, not to drive continual improvement of business performance.
The practical consequences are significant. Where ISO 9001 asks for improvement, ISO 13485 asks for maintained effectiveness. Documentation and records requirements are heavier and explicitly prescribed. Risk management runs through the whole product life cycle and is tied to ISO 14971. And certification to ISO 13485 does not mean you are ISO 9001 certified — if a non-medical customer asks for ISO 9001, you need it separately.
Design and development files
A documented design and development file is required per device or device family, including verification, validation and design transfer records.
Sterile and cleanroom controls
Specific requirements for cleanliness, contamination control, sterile barrier and installation/servicing activities.
Traceability and UDI
Device-level traceability, distribution records and recall capability, aligned to regulatory identification schemes.
Regulatory reporting
Complaint handling, adverse event reporting and advisory notices are explicit clauses, not general improvement processes.
Which standard do you actually need?
- Step 01
Read the contract, not the market
Check current and target customer pre-qualification documents and purchase order terms. The required standard is almost always written there, along with any customer-specific requirements.
- Step 02
Identify your regulator
Medical devices are regulator-driven: market access, not commercial preference, sets the standard. Aerospace and defence add export control and airworthiness obligations alongside AS9100.
- Step 03
Check what your certification covers
If you supply more than one sector, decide whether one certificate serves all of them. AS9100 or IATF 16949 satisfies an ISO 9001 request in practice; ISO 13485 does not.
- Step 04
Cost the surveillance, not just the certificate
Every additional standard adds annual surveillance audit days, internal audit scope and management review content for the life of the certificate.
The readiness path is the same shape for all four
Whichever standard applies, the route is a clause-level gap analysis, remediation of the gaps with usable documentation and real process change, a full internal audit and management review cycle, then a mock Stage 2 before the certification body arrives. What changes between standards is the content of the gap list and the evidence the auditor expects to see, not the sequence.
The certification decision itself always rests with an accredited certification body. Readiness work and the certification audit are separate roles and cannot be performed by the same organisation.
Not sure which standard your customers require?
Independent ISO 9001 consulting with clause-level gap analysis, documentation, internal audits and mock audits — and sector experience across AS9100, IATF 16949 and ISO 13485.
Questions we get on this topic
Is AS9100 the same as ISO 9001?
No. AS9100D contains the complete text of ISO 9001:2015 and adds around 100 aerospace-specific requirements covering product safety, counterfeit parts, configuration management, first article inspection, critical items and extended supplier control. An AS9100 certificate demonstrates conformity with ISO 9001 as well, which is why aerospace suppliers rarely hold both.
Can you certify to IATF 16949 without ISO 9001?
No. IATF 16949:2016 is written as a supplement to ISO 9001:2015 and contains only the automotive additions. The two are audited together and the certification covers the combined requirements, along with the customer-specific requirements of the OEMs you supply.
Does ISO 13485 replace ISO 9001?
Not automatically. ISO 13485:2016 is a standalone standard aligned to the older ISO 9001:2008 structure, focused on regulatory compliance rather than continual improvement. Certification to ISO 13485 does not give you ISO 9001 certification, so organisations serving both medical and non-medical customers sometimes hold both.
Which quality standard should a manufacturer certify to first?
The one your customers and regulator require. If no sector standard is contractually demanded, ISO 9001 is the sensible baseline. If a prime contractor or OEM has already flowed down AS9100 or IATF 16949, run the gap analysis against that standard directly rather than certifying to ISO 9001 first and repeating the exercise.
How much extra work is a sector standard over ISO 9001?
For an organisation with a working ISO 9001 system, the sector layer is typically a defined gap list rather than a rebuild — configuration management, first article inspection and counterfeit part controls for AS9100; the core tools and customer-specific requirements for IATF 16949. ISO 13485 is closer to a separate system because of the design file, risk management and regulatory reporting requirements.
Need a clause-level view of where you stand?
Tell us your target standard and current state — we'll return a gap and readiness plan within one business day.
