Skip to content
ISO & CertificationPublished Aug 20, 2026 · 11 min read

ISO 9001 vs AS9100, IATF 16949 and ISO 13485.

ISO 9001 is the generic quality management system standard. AS9100 (aerospace), IATF 16949 (automotive) and ISO 13485 (medical devices) are the sector standards built on the same foundation — but each adds requirements that reflect what goes wrong in that industry, and they are not interchangeable. Choosing the wrong target wastes a certification cycle; certifying to a sector standard you were never asked for wastes audit days every year after that.

Share
Executive summary

AS9100 and IATF 16949 contain the full text of ISO 9001 plus sector additions, so certifying to either satisfies an ISO 9001 requirement in practice. ISO 13485 is structurally different: it is aligned to ISO 9001:2008, is not built on the Annex SL high-level structure, and certification to it does not confer ISO 9001 certification.

The deciding factor is almost never technical preference — it is your customer base and regulator. Aerospace primes flow down AS9100, automotive OEMs flow down IATF 16949 through the customer-specific requirements, and medical device market access effectively requires ISO 13485.

Key takeaways
  • 01ISO 9001 is the baseline; AS9100, IATF 16949 and ISO 13485 are sector standards built from it.
  • 02AS9100D = ISO 9001:2015 in full, plus ~100 aerospace additions (configuration management, counterfeit parts, first article inspection, product safety).
  • 03IATF 16949 cannot be certified alone — it is applied together with ISO 9001 and mandatory customer-specific requirements.
  • 04ISO 13485 is risk- and regulation-driven rather than continual-improvement-driven, and does not include ISO 9001 certification.
  • 05Certify to what your customers and regulators require, not to the longest list; each additional standard adds annual surveillance audit days.
At a glance

The four standards compared

Use this to identify the target standard before any gap analysis starts.

AS9100 and IATF 16949 build on ISO 9001; ISO 13485 has deliberately diverged from it.
StandardSectorRelationship to ISO 9001Certification driver
ISO 9001:2015Any organisationThe baseline standardCustomer pre-qualification, tender requirements
AS9100D (EN/JISQ 9100)Aviation, space and defenceContains ISO 9001:2015 in full plus aerospace additionsPrime contractor flow-down; OASIS registration
IATF 16949:2016Automotive production and service partsApplied as a supplement to ISO 9001:2015 — not standaloneOEM contractual requirement plus customer-specific requirements
ISO 13485:2016Medical devicesStandalone; aligned to ISO 9001:2008 structure, not Annex SLRegulatory market access (MDR, MDSAP, FDA expectations)
Aerospace

What AS9100 adds to ISO 9001

AS9100D reproduces every clause of ISO 9001:2015 and then adds requirements written by the aerospace industry through the IAQG.

  • Product safety — an explicit requirement to plan, implement and control processes affecting product safety (8.1.3).
  • Counterfeit part prevention — controls to avoid counterfeit or suspect unapproved parts entering the supply chain (8.1.4).
  • Configuration management — identification, traceability and control of configuration and change through the product life (8.1.2).
  • First article inspection (FAI) — verification of a representative first production item against all design characteristics (8.5.1.3).
  • Special requirements, critical items and key characteristics — identification and specific control of features whose variation affects fit, form, function or safety.
  • Extended supplier control — approval, monitoring and flow-down of requirements to sub-tier suppliers, including test and NDT sources.
  • Enhanced documentation, risk management and on-time delivery performance monitoring.

Certification is registered in the IAQG OASIS database, which primes check directly. In practice, an organisation with a working ISO 9001 system is closing a defined set of aerospace-specific gaps rather than rebuilding a system.

Automotive

What IATF 16949 adds — and why it is never certified alone

IATF 16949:2016 is published as a supplement to ISO 9001:2015: the document contains only the automotive additions, and the two are audited together. The certificate covers the combined requirements, and the certification process itself is far more prescriptive than ISO 9001 — audit days, auditor qualification, remote support locations and non-conformance response timelines are all fixed by the IATF Rules.

On top of the standard sit customer-specific requirements (CSRs) issued by each OEM. These are mandatory and auditable, so two certified suppliers can be operating to materially different requirements depending on who they ship to.

  • Core tools embedded as requirements: APQP, PPAP, FMEA, MSA and SPC.
  • Product safety, with defined responsibilities and escalation.
  • Contingency planning for production interruption, including cyber and utility events.
  • Total productive maintenance and tooling/gauge management.
  • Embedded software development and warranty management where applicable.
  • Mandatory customer-specific requirements flowed through the whole supply chain.
Medical devices

Why ISO 13485 is the odd one out

ISO 13485:2016 shares its ancestry with ISO 9001 but was deliberately kept aligned to the ISO 9001:2008 structure rather than moving to the Annex SL format used by ISO 9001:2015. Its purpose is regulatory: to demonstrate an ability to consistently supply medical devices meeting customer and applicable regulatory requirements, not to drive continual improvement of business performance.

The practical consequences are significant. Where ISO 9001 asks for improvement, ISO 13485 asks for maintained effectiveness. Documentation and records requirements are heavier and explicitly prescribed. Risk management runs through the whole product life cycle and is tied to ISO 14971. And certification to ISO 13485 does not mean you are ISO 9001 certified — if a non-medical customer asks for ISO 9001, you need it separately.

01

Design and development files

A documented design and development file is required per device or device family, including verification, validation and design transfer records.

02

Sterile and cleanroom controls

Specific requirements for cleanliness, contamination control, sterile barrier and installation/servicing activities.

03

Traceability and UDI

Device-level traceability, distribution records and recall capability, aligned to regulatory identification schemes.

04

Regulatory reporting

Complaint handling, adverse event reporting and advisory notices are explicit clauses, not general improvement processes.

Decision

Which standard do you actually need?

  1. Step 01

    Read the contract, not the market

    Check current and target customer pre-qualification documents and purchase order terms. The required standard is almost always written there, along with any customer-specific requirements.

  2. Step 02

    Identify your regulator

    Medical devices are regulator-driven: market access, not commercial preference, sets the standard. Aerospace and defence add export control and airworthiness obligations alongside AS9100.

  3. Step 03

    Check what your certification covers

    If you supply more than one sector, decide whether one certificate serves all of them. AS9100 or IATF 16949 satisfies an ISO 9001 request in practice; ISO 13485 does not.

  4. Step 04

    Cost the surveillance, not just the certificate

    Every additional standard adds annual surveillance audit days, internal audit scope and management review content for the life of the certificate.

Getting certified

The readiness path is the same shape for all four

Whichever standard applies, the route is a clause-level gap analysis, remediation of the gaps with usable documentation and real process change, a full internal audit and management review cycle, then a mock Stage 2 before the certification body arrives. What changes between standards is the content of the gap list and the evidence the auditor expects to see, not the sequence.

The certification decision itself always rests with an accredited certification body. Readiness work and the certification audit are separate roles and cannot be performed by the same organisation.

Not sure which standard your customers require?

Independent ISO 9001 consulting with clause-level gap analysis, documentation, internal audits and mock audits — and sector experience across AS9100, IATF 16949 and ISO 13485.

ISO 9001 consulting
Frequently asked

Questions we get on this topic

Is AS9100 the same as ISO 9001?

No. AS9100D contains the complete text of ISO 9001:2015 and adds around 100 aerospace-specific requirements covering product safety, counterfeit parts, configuration management, first article inspection, critical items and extended supplier control. An AS9100 certificate demonstrates conformity with ISO 9001 as well, which is why aerospace suppliers rarely hold both.

Can you certify to IATF 16949 without ISO 9001?

No. IATF 16949:2016 is written as a supplement to ISO 9001:2015 and contains only the automotive additions. The two are audited together and the certification covers the combined requirements, along with the customer-specific requirements of the OEMs you supply.

Does ISO 13485 replace ISO 9001?

Not automatically. ISO 13485:2016 is a standalone standard aligned to the older ISO 9001:2008 structure, focused on regulatory compliance rather than continual improvement. Certification to ISO 13485 does not give you ISO 9001 certification, so organisations serving both medical and non-medical customers sometimes hold both.

Which quality standard should a manufacturer certify to first?

The one your customers and regulator require. If no sector standard is contractually demanded, ISO 9001 is the sensible baseline. If a prime contractor or OEM has already flowed down AS9100 or IATF 16949, run the gap analysis against that standard directly rather than certifying to ISO 9001 first and repeating the exercise.

How much extra work is a sector standard over ISO 9001?

For an organisation with a working ISO 9001 system, the sector layer is typically a defined gap list rather than a rebuild — configuration management, first article inspection and counterfeit part controls for AS9100; the core tools and customer-specific requirements for IATF 16949. ISO 13485 is closer to a separate system because of the design file, risk management and regulatory reporting requirements.

Get in touch

Need a clause-level view of where you stand?

Tell us your target standard and current state — we'll return a gap and readiness plan within one business day.

Book a gap analysis