Which ISO audit do you need: ISO 13485, ISO 9001, or a mock audit?
This page sorts the ISO audits by standard and by audit type and points you to the right service: full certification to ISO 13485:2016 for medical device and IVD manufacturers, the audit to ISO 9001:2015 for the cross-industry case, and the mock audit as a trial run ahead of the notified body. Supplier and CMO audits to ISO 19011 we run across both, because they play the same role in either world of standards.
Overview
Which standard and which audit type apply to your case?
Audit preparation across internal, supplier, and certification audits · ISO 13485:2016, ISO 9001:2015, ISO 19011
Last updated: August 11, 2026
For medical device and IVD manufacturers under MDR (EU 2017/745) and IVDR (EU 2017/746), ISO 13485:2016 is effectively the baseline, because notified bodies require a certified quality management system. What decides which of our pages is your case:
- Medical device and IVD manufacturers take the full certification path to ISO 13485:2016, from the gap analysis through QMS setup to surveillance and recertification. The detail on this sits on the ISO 13485 certification page.
- If you are certifying to ISO 9001:2015 only, without an ISO 13485 component, you will find the cross-industry detail on the ISO 9001 audit page, including context analysis and risk-based thinking.
- The step from an ISO 9001:2015 system to ISO 13485:2016 is underestimated, because the stricter risk approach, the traceability, and the regulatory link to MDR and IVDR have to be built from scratch.
- Suppliers, CMOs, and sterilization service providers are inadequately qualified and controlled, even though under ISO 13485:2016 they count as part of the manufacturer's own quality management system. We run these audits across both standards.
Services
How we support you
Supplier and subcontractor audits
Audits of CMOs, sterilization service providers, and critical suppliers against the requirements of ISO 13485:2016, on site across Europe as well as remote or hybrid audits to ISO 19011. Deliverable: an audit report per supplier and a qualification program for the supplier network.
How we work together
What it comes down to
Which ISO audit is due is decided by the standard and by the audit type, not by the date. Medical device and IVD manufacturers take the full certification path to ISO 13485:2016, because under MDR (EU 2017/745) and IVDR (EU 2017/746) notified bodies require a certified quality management system; that path sits on our ISO 13485 certification page. If you are certifying to ISO 9001:2015 only, without an ISO 13485 component, you will find the cross-industry detail on our dedicated ISO 9001 audit page.
Two audit types cut across both standards. The mock audit simulates the certification audit under real conditions, gives the team an audit routine, and creates the time to work through major and minor findings before the real date, rather than seeing them there for the first time; how it runs is set out on the mock audits page. Supplier and CMO audits we run across both: under ISO 13485:2016, CMOs, sterilization service providers, and critical suppliers count as part of the manufacturer's own quality management system, so qualification records must be in place before the audit itself begins.
Not on this page: audits to ISO/IEC 27001 and GxP audits to GMP, GLP, and GCP. Both are out of scope here and are addressed in dedicated services that we link to above.
Common pitfalls
Where projects commonly fail
The move from ISO 9001:2015 to ISO 13485:2016 is treated as an extension rather than a rebuild.
The stricter risk approach, the end-to-end traceability, and the link to MDR and IVDR are missing, so the existing system does not hold up in the audit.
Suppliers and CMOs are not treated as part of the manufacturer's own quality management system.
Where supplier audits and qualification records are missing, the notified body challenges the purchasing and outsourcing processes under ISO 13485:2016.
The mock audit is skipped or scheduled too late.
Without a realistic trial audit before the date, there is no time to close the major and minor findings found, and open points hit the team only at the real audit.
Quality Management & Compliance
Do any of these pitfalls apply to you?
In a first call we assess your situation and say what needs clarifying first in your case. Without obligation, reply usually within one working day.
FAQ
Frequently asked questions
Sources
- ISO 13485:2016: Quality management systems for medical devices
- ISO 9001:2015: Quality management systems, requirements
- ISO 19011: Guidelines for auditing management systems
- Regulation (EU) 2017/745 (MDR) and Regulation (EU) 2017/746 (IVDR): primary text, QMS requirements
- Writer material: iso-audits.md (source material, Entourage website writer)
Life Science Journal
Regulatory updates, straight to your inbox.
New requirements, authority decisions and practice notes. Once a month, unsubscribe any time.
Case Studies
What this looks like in practice
Latest insights
All insights →Regulations & standards considered
- ISO 13485:2016 (quality management systems for medical devices)
- ISO 9001:2015 (quality management systems)
- ISO 19011 (guidelines for auditing management systems)
- Regulation (EU) 2017/745 (MDR)
- Regulation (EU) 2017/746 (IVDR)
- ISO/IEC 27001 (out of scope, see related pages)
Related topics
ISO 9001 Audit →
The cross-industry path to ISO 9001:2015 in detail
ISO 13485 Certification →
The full certification path to ISO 13485:2016
Mock Audits. →
Simulated certification audits for preparation, in detail
GxP Audits (GMP, GLP, GCP) →
Out of scope here: audits to GMP, GLP, and GCP instead of ISO standard audits
Inspection Readiness →
Preparing for regulatory inspections beyond the ISO audit
Have a concrete project?
Briefly outline your situation. We'll respond with an initial assessment, usually within one business day.
Prefer direct? +49 89 4161170-0
info@theentourage.de
- Reply usually within one working day
- 4 offices: DE · CH · IT · US
- 100% life sciences

