ISO 9001:2026 and Life Sciences: What Changes for Dual Certificates

Many life sciences manufacturers hold ISO 13485 or another sector scheme and keep ISO 9001 for the broader organization: corporate functions, non-device sites, suppliers, or customers who still ask for 9001 on the purchase order. ISO 9001:2026 is the next revision of that foundation standard. Dual-certificate firms need a plan that updates the 9001 layer without opening a second, conflicting quality manual for the 13485 or pharmaceutical GMP site.
This article is a quality-system reading of what dual certificates should do as 9001:2026 lands. It is not a substitute for the published ISO text or your registrar's transition rules. Buy the standard, read the official amendment and transition communiques from ISO and IAF, and confirm dates with your certification body.
Why dual certificates exist
ISO 13485 is not "9001 plus devices." It drops some 9001 clauses (customer satisfaction as a driver, certain continual-improvement framing) and adds device-specific ones (risk, sterile, regulatory, advisory notices). A company that makes devices and also runs a non-device service business, a distribution arm, or a corporate shared-service center often keeps 9001 on those scopes.
Pharma and biologics sites similarly may hold 9001 next to GMP because a customer or a non-GMP process (warehouse network, engineering services) sits in the 9001 scope.
The risk of 2026 is duplication: two document pyramids, two internal audit programs, two management reviews, two CAPA definitions.
What to watch in 9001:2026 (without inventing clause numbers)
Public ISO development communications for the 9001 revision have emphasized climate and context, stronger alignment with the harmonized structure, and clearer expectations on change, knowledge, and performance evaluation. Treat those themes as planning inputs. Do not quote clause text you have not verified in the published document.
For a dual-certificate quality leader, the practical questions are:
- Does the new 9001 language on context and interested parties force a rewrite of the 13485 quality manual's "organization context" section, or can one context analysis serve both?
- Will climate-related and sustainability expectations sit in the 9001 scope only, or will customers start asking device sites for the same evidence?
- Are there tighter requirements on determining and controlling changes that overlap QMSR / 13485 change control?
- Does the revision change documented-information expectations in a way that conflicts with your Part 11 / Annex 11 electronic records?
Write those questions into the transition plan. Answer them with a gap table against the published standard the week you can buy it.
One quality system, two certificates
The durable model:
Single process landscape. Document control, training, internal audit, CAPA, change control, management review, supplier control are one set of procedures. Scope statements and exclusions live in the certificates, not in duplicate SOPs.
Scope map. A one-page matrix: legal entity, site, product/service, certificate (9001, 13485, MDSAP, GMP). Auditors should be able to see why the machine shop is 9001-only and the cleanroom is 13485.
Shared risk method, different residual-risk rules. 14971 remains the device risk method. 9001 risk-based thinking can use a simpler operational risk log for non-device processes. Do not force FMEA on the cafeteria, and do not let device design use a 9001 "opportunity" sticky note.
Management review with a common agenda plus annexes. One meeting can cover both certificates if the minutes show the 13485-required inputs (feedback, complaints, advisory notices, new regulatory requirements) and the 9001 performance inputs. Annex the device metrics rather than running a second two-hour meeting that repeats headcount and audit status.
Transition mechanics
Registrars will publish transition windows after ISO and IAF do. Historically, 9001 revisions have allowed a multi-year window from publication to mandatory certification against the new edition. Do not assume the window. Put a calendar hold to:
- Obtain the published standard and official mapping annex
- Complete a documented gap analysis signed by quality leadership
- Update the quality manual and affected procedures
- Train internal auditors on new evidence expectations
- Run one internal audit cycle against the new edition before the registrar
- Align the 13485 / MDSAP audit program so you are not audited twice in the same month on the same clauses
If your 13485 certificate is mid-cycle, ask the registrar whether a combined audit can pick up 9001:2026 transition without an extra full-system visit.
Climate, context, and life sciences reality
If 9001:2026 expands how organizations consider climate and environmental context, dual-certificate firms should decide scope early.
- Device design controls already consider environmental conditions of use and storage. That is 13485 / 14971, not a sustainability report.
- Corporate 9001 scope may need energy, logistics, or climate-risk context for business continuity. Keep that evidence in the corporate layer.
- Do not copy a climate paragraph into the DHF unless it is a true design input (operating temperature, storage, transport).
Customers may still ask for ESG questionnaires. Answer them from the corporate system. Do not invent a parallel "green CAPA" inside the device QMS.
Documented information and electronic records
9001 revisions tend to talk about documented information rather than "procedures and records" as separate worlds. Your 13485 and Part 11 procedures already distinguish documents (need change control) from records (need integrity and retention). Keep that distinction. Map any new 9001 wording to existing SOP numbers. Resist a registrar's suggestion to rewrite every form header unless the gap analysis says you must.
Internal auditors
Dual-certificate auditors need a qualification matrix: who is competent to audit 13485 design control versus who can audit 9001 purchasing at the corporate office. After 9001:2026, add a short module on whatever actually changed, then witness one audit. Competency is a first live audit, not a slide deck.
What not to do
- Do not maintain two CAPA SOPs with different definitions of "effectiveness."
- Do not let 9001 "continual improvement" projects bypass device change control.
- Do not delay the 9001 gap analysis until the last six months of the IAF window.
- Do not claim alignment with 9001:2026 in marketing before you hold the certificate.
Starter plan for the quality director
This quarter:
- Confirm current scopes and expiry dates for 9001 and 13485 / MDSAP
- Name a transition owner (one person)
- Subscribe to ISO, IAF, and your registrar's 9001:2026 notices
- Draft the scope map even before the new text is in hand
- List procedures that are already shared versus certificate-specific
When the standard is in hand, fill the gap table in two weeks, not two quarters.
Dual certificates only pay for themselves when the factory runs one system. 9001:2026 is a chance to clean the join, not a reason to grow a second manual.
If you want to see how one validated QMS can hold dual-certificate scope, audit, and CAPA without parallel binders, visit cloudtheapp.com/demo.
About Cloudtheapp
Cloudtheapp is an AI-Powered Configurable Validated Cloud Platform built to provide the most configurable, easy-to-use Quality Management and Regulatory Compliance SaaS software on the market.
We believe that having a single platform to manage compliance and transformation needs is essential for businesses in the modern world. We've created an innovative configurable cloud platform built for the compliance world so you can easily implement ready-made applications with no additional installs or infrastructure required – and without writing a single line of code!
Our experienced professionals have over three decades of software development experience between them, giving us unparalleled insight into how to build powerful solutions to address real challenges.
We have created an interconnected ecosystem where everyone involved in this process can collaborate successfully while minimizing disruption of any sort as well as ensuring entire organization's data remains visible always for better use making sure businesses always stay compliant.
We excelled in creating the most configurable, easy-to-use Quality Management and Regulatory Compliance SaaS software that requires light administration, so your staff has time to focus on streamlining their compliance process, innovate faster and minimize risk associated with non-compliance.
We will continue to strive towards engineering smarter tools for administrative staff so they can focus on building safe and quality products.
With years of experience in the industry, we are committed to providing our customers with reliable and secure solutions enabling them to be agile and move ahead confidently.