Skip to content
Entourage

Which ISO audit do you need: ISO 13485, ISO 9001, or a mock audit?

This page sorts the ISO audits by standard and by audit type and points you to the right service: full certification to ISO 13485:2016 for medical device and IVD manufacturers, the audit to ISO 9001:2015 for the cross-industry case, and the mock audit as a trial run ahead of the notified body. Supplier and CMO audits to ISO 19011 we run across both, because they play the same role in either world of standards.

Overview

Which standard and which audit type apply to your case?

Audit preparation across internal, supplier, and certification audits · ISO 13485:2016, ISO 9001:2015, ISO 19011

Last updated: August 11, 2026

For medical device and IVD manufacturers under MDR (EU 2017/745) and IVDR (EU 2017/746), ISO 13485:2016 is effectively the baseline, because notified bodies require a certified quality management system. What decides which of our pages is your case:

  • Medical device and IVD manufacturers take the full certification path to ISO 13485:2016, from the gap analysis through QMS setup to surveillance and recertification. The detail on this sits on the ISO 13485 certification page.
  • If you are certifying to ISO 9001:2015 only, without an ISO 13485 component, you will find the cross-industry detail on the ISO 9001 audit page, including context analysis and risk-based thinking.
  • The step from an ISO 9001:2015 system to ISO 13485:2016 is underestimated, because the stricter risk approach, the traceability, and the regulatory link to MDR and IVDR have to be built from scratch.
  • Suppliers, CMOs, and sterilization service providers are inadequately qualified and controlled, even though under ISO 13485:2016 they count as part of the manufacturer's own quality management system. We run these audits across both standards.

Services

How we support you

What it comes down to

Which ISO audit is due is decided by the standard and by the audit type, not by the date. Medical device and IVD manufacturers take the full certification path to ISO 13485:2016, because under MDR (EU 2017/745) and IVDR (EU 2017/746) notified bodies require a certified quality management system; that path sits on our ISO 13485 certification page. If you are certifying to ISO 9001:2015 only, without an ISO 13485 component, you will find the cross-industry detail on our dedicated ISO 9001 audit page.

Two audit types cut across both standards. The mock audit simulates the certification audit under real conditions, gives the team an audit routine, and creates the time to work through major and minor findings before the real date, rather than seeing them there for the first time; how it runs is set out on the mock audits page. Supplier and CMO audits we run across both: under ISO 13485:2016, CMOs, sterilization service providers, and critical suppliers count as part of the manufacturer's own quality management system, so qualification records must be in place before the audit itself begins.

Not on this page: audits to ISO/IEC 27001 and GxP audits to GMP, GLP, and GCP. Both are out of scope here and are addressed in dedicated services that we link to above.

Common pitfalls

Where projects commonly fail

The move from ISO 9001:2015 to ISO 13485:2016 is treated as an extension rather than a rebuild.

The stricter risk approach, the end-to-end traceability, and the link to MDR and IVDR are missing, so the existing system does not hold up in the audit.

Suppliers and CMOs are not treated as part of the manufacturer's own quality management system.

Where supplier audits and qualification records are missing, the notified body challenges the purchasing and outsourcing processes under ISO 13485:2016.

The mock audit is skipped or scheduled too late.

Without a realistic trial audit before the date, there is no time to close the major and minor findings found, and open points hit the team only at the real audit.

Quality Management & Compliance

Do any of these pitfalls apply to you?

In a first call we assess your situation and say what needs clarifying first in your case. Without obligation, reply usually within one working day.

FAQ

Frequently asked questions

ISO 9001:2015 is the general quality management standard. ISO 13485:2016 is specific to medical devices, requires a stricter risk approach and end-to-end traceability, and is aligned with MDR and IVDR. Companies holding ISO 9001:2015 regularly underestimate the effort of the transition.

Sources
  • ISO 13485:2016: Quality management systems for medical devices
  • ISO 9001:2015: Quality management systems, requirements
  • ISO 19011: Guidelines for auditing management systems
  • Regulation (EU) 2017/745 (MDR) and Regulation (EU) 2017/746 (IVDR): primary text, QMS requirements
  • Writer material: iso-audits.md (source material, Entourage website writer)

Life Science Journal

Regulatory updates, straight to your inbox.

New requirements, authority decisions and practice notes. Once a month, unsubscribe any time.

Regulations & standards considered

  • ISO 13485:2016 (quality management systems for medical devices)
  • ISO 9001:2015 (quality management systems)
  • ISO 19011 (guidelines for auditing management systems)
  • Regulation (EU) 2017/745 (MDR)
  • Regulation (EU) 2017/746 (IVDR)
  • ISO/IEC 27001 (out of scope, see related pages)

Have a concrete project?

Briefly outline your situation. We'll respond with an initial assessment, usually within one business day.

Prefer direct? +49 89 4161170-0
info@theentourage.de

  • Reply usually within one working day
  • 4 offices: DE · CH · IT · US
  • 100% life sciences