ISO 9001
ISO 9001 quality management
ISO 9001 is the international standard for quality management systems. ComplyTrain is structured around its clause structure, so your QMS is audit-ready by design.
Standards · Pharma and medical devices
EU GMP and its annexes, the ICH guidelines, 21 CFR, the MDR and the IVDR, ISO 13485 and ISO 14971, and the IEC standards for software as a medical device. Explained in plain words, in one catalogue, with every entry linked to its source.
Overview
Medicinal products and medical devices are regulated differently, but the requirement reaches a manufacturer the same way in both.
EU GMP as a condition of your licence, the MDR and the IVDR for a device, 21 CFR in the United States. An authority or a notified body checks that you meet it.
The GMP annexes, the PIC/S guide, the ICH guidelines and the MDCG documents are what an inspector or an assessor expects to see, chapter by chapter.
ISO 13485 and ISO 14971 for a device, ICH Q10 for a pharmaceutical quality system, IEC 62304 for software, GAMP 5 for the computerised systems underneath.
Annex 11 and 21 CFR Part 11 put validation, audit trails and electronic signatures on every system that holds a regulated record. It is where most findings are written.
Search the catalogue by name, browse it by family, or answer five questions about what you make. Each entry links to its source and can be requested in ComplyTrain.
Two regulated worlds sit on this page, medicinal products and medical devices, and they share one shape. A law binds the manufacturer: you cannot make or sell without meeting it, and an authority or a notified body checks that you do. Guidance says how the inspectors expect the law to be met. And standards, mostly ISO and IEC, are how the industry builds the system that meets both. This page explains the three layers for each world, the computerised systems and the data that run through both, and where the documents come from. The explorer below then finds the ones that match what you make.
A manufacturing authorisation for a medicinal product in the EU is conditional on good manufacturing practice, and EudraLex Volume 4 is the guide every inspector uses. Part I covers finished products in nine chapters: the pharmaceutical quality system, personnel, premises and equipment, documentation, production, quality control, outsourced activities, complaints and recalls, and self-inspection. Part II covers active substances and is the EU's adoption of ICH Q7. The annexes carry the specifics: Annex 1, revised in 2022, for sterile products and the contamination control strategy behind them; Annex 11 for computerised systems; Annex 15 for qualification and validation; Annex 16 for what the Qualified Person certifies before a batch is released. The PIC/S guide is the same text harmonised for the fifty-plus authorities in the scheme, and the one an inspector from outside the EU works from.
In the United States, 21 CFR Parts 210 and 211 are the current good manufacturing practice regulations, and 21 CFR Part 11 sets the rules for electronic records and electronic signatures. The FDA takes part in PIC/S and the expectations are the same on both sides; what differs is the letter of the regulation an inspector cites.
The International Council for Harmonisation brings the regulators and industry of Europe, the United States, Japan and a growing list of others together to write one guideline that each region then adopts. Q7 is GMP for active substances. Q8 is pharmaceutical development, the origin of quality by design, the design space and the control strategy. Q9, revised in 2023, is quality risk management: the process, its tools and how formal to be. Q10 is the pharmaceutical quality system: management responsibility, process performance monitoring, corrective and preventive action, change management and management review, built on ISO quality concepts and on GMP. Q12 covers post-approval change through established conditions. E6, revised in 2025, is good clinical practice for trials. Q8, Q9 and Q10 together are the design of a modern quality system, and Q10 is what a pharmaceutical quality system audit measures you against. ISO 9001 is the shape underneath; see ISO 9001 and, for the risk process Q9 asks for, the risk management page.
Any system that creates, stores or signs a GMP record is in scope, from a laboratory information system and a manufacturing execution system to the quality software itself and a validated spreadsheet. Annex 11 and 21 CFR Part 11 say what such a system must do: be validated for its intended use, keep an audit trail, control access, and make an electronic signature as binding as a handwritten one. GAMP 5, in its 2022 second edition, is the industry's guide to doing that with a risk-based approach and without validating what does not need it. PIC/S PI 041 is the inspectors' guidance on data integrity, the ALCOA+ principles that a record must be attributable, legible, contemporaneous, original and accurate, and complete, consistent, enduring and available. Data integrity is where most GMP findings of the last decade have been written.
Regulation (EU) 2017/745, the MDR, applies since May 2021 and Regulation (EU) 2017/746, the IVDR, since May 2022, with transition periods for devices certified under the old directives. Both work the same way: the intended purpose and the classification rules put a device in a class, everything above class I is assessed by a notified body, the general safety and performance requirements in Annex I must be met and the technical documentation in Annexes II and III must show it, a clinical evaluation must support every claim, and post-market surveillance, vigilance and the unique device identifier run for the life of the product. In the United States, 21 CFR Part 820 is the quality system regulation, and from February 2026 it incorporates ISO 13485, so one device quality system now serves both markets.
Harmonised standards give a presumption of conformity with the regulation, and they are the standards a notified body audits. ISO 13485 is the quality management system, ISO 9001 in shape with what a regulator expects on top. ISO 14971 is risk management for devices, the file every design decision traces back to, with ISO/TR 24971 as its worked guidance. IEC 60601-1 covers electrical safety, IEC 62366-1 usability engineering, ISO 10993 the biological evaluation of anything in contact with the body, ISO 14155 clinical investigations, ISO 15223-1 and ISO 20417 the symbols and the information supplied with a device, and ISO 11607 the sterile barrier.
Software is a medical device when its intended purpose is medical, and since the MDR that includes a great deal of decision-support and monitoring software that was class I under the directives and is class IIa or higher now. MDCG 2019-11 is the guidance on when software qualifies and how it classifies; the IMDRF documents on software as a medical device define the term, categorise the risk and describe the clinical evaluation regulators in every major market use. The standards then follow the life cycle. IEC 62304 sets the software life-cycle processes by safety class, from planning and requirements through architecture, verification, release and maintenance. IEC 82304-1 covers health software sold as a product on general-purpose hardware. IEC 62366-1 covers the usability engineering the interface needs, ISO 14971 the risk file, and IEC 81001-5-1 with MDCG 2019-16 the cybersecurity a connected device must design in. Software in a device, embedded firmware, follows IEC 62304 too.
EudraLex, the MDCG guidance and the EU regulations are free from the European Commission and EUR-Lex; PIC/S and ICH publish their guidelines free of charge; the Code of Federal Regulations is free on the eCFR. The ISO and IEC standards are bought from ISO, IEC or your national standards body, GAMP 5 from ISPE, and the IMDRF documents are free. Every entry in the explorer below links to its source.
Not this page, and not us. For a medicinal product it is the marketing authorisation and your manufacturing licence; for a device it is the intended purpose you declare and the class it puts you in; and in both worlds the inspector, the notified body and your customers' supplier audits decide what evidence they expect to see. What the explorer can do is show you the whole map: search it by name, browse it by family, or answer five questions about what you make and see which areas manufacturers like you are commonly asked about. Each entry links to its source, to its ComplyTrain page where one exists, and otherwise to a request. ComplyTrain holds a standard as a requirement tree with the evidence against each requirement. The licence and the certificate stay yours to earn.
Standards explorer
Search EU GMP and its annexes, the ICH guidelines, 21 CFR, the MDR and IVDR and the ISO and IEC device standards together, browse them by family, or answer five questions about what you make.
Nothing matches that. Try a number, a code, or browse by family.
Which rules apply to you is set by your licence, your product classification and your markets, and the inspector or the notified body decides what evidence they expect. Treat this as a map, not a verdict.
Five questions, pick everything that applies. Nothing is stored.
The areas manufacturers like you are commonly asked about, and the rules and standards in each. Confirm against your licence and your classification.
Which rules apply to you is set by your licence, your product classification and your markets, and the inspector or the notified body decides what evidence they expect. Treat this as a map, not a verdict.
Each page sets out what the standard asks of you and how a ComplyTrain workspace is organised around it. The catalogue above holds far more than these, and any entry in it can be requested. Adding a standard to a workspace is usually a matter of days, not a project.
ISO 9001
ISO 9001 is the international standard for quality management systems. ComplyTrain is structured around its clause structure, so your QMS is audit-ready by design.
A standard usually arrives as a contract condition or a regulator's letter rather than a project anyone planned for, and often at a company with no quality manager. Software is half the answer. Skylen's consultants are the other half, and because they build on ComplyTrain from day one you keep a live system your team owns rather than a binder and a departed consultant.
A clause-by-clause read of where you stand against the standard your contract or your regulator cites, turned into a prioritised plan you could act on with us or alone.
What an assessment coversOur consultants build the system with your team - procedures, document control, the records you need to keep and the review cadence - and prepare you for the audit or the inspection.
How an engagement worksWe run and maintain the system for you, so a small team can reach and hold a standard without hiring a quality manager.
What full-service meansNot by name. The MDR requires a quality management system and lists what it must cover; ISO 13485 is the harmonised standard that gives a presumption of conformity with that requirement, and it is what a notified body audits. In practice every manufacturer above class I holds it. In the United States, 21 CFR Part 820 incorporates ISO 13485 from February 2026, so the same system serves both markets.
ISO 9001 is a voluntary standard for a quality management system that a certification body audits. GMP is law: a condition of your manufacturing licence, inspected by your medicines authority, with detailed rules for premises, batch records, release and the rest. ICH Q10 describes a pharmaceutical quality system built on ISO quality concepts and on GMP, which is how the two fit together. See ISO 9001.
It depends on its intended purpose, not on its technology. Software intended to provide information used for a medical decision, or to monitor a physiological process, is a device under the MDR, and MDCG 2019-11 walks through the qualification step by step. Software that only stores, communicates or searches data is not. A wrong answer here is expensive in both directions, so it is a question for regulatory counsel before development starts.
That every GMP record can be trusted: it is attributable to who made it, legible, made at the time, the original or a true copy, and accurate, and that it is complete, consistent, enduring and available for its retention period. Annex 11 and 21 CFR Part 11 put that on computerised systems as validation, audit trails, access control and electronic signatures. PIC/S PI 041 is the inspectors' own guidance on what they look for.
Part I and, if you handle active substances, Part II apply to everyone with a manufacturing authorisation. Annex 11 applies to anyone with a computerised system in GMP, which is everyone; Annex 15 to anyone qualifying equipment or validating a process; Annex 16 to batch certification. The rest depend on what you make: Annex 1 for sterile products, Annex 2 for biologicals, Annex 3 for radiopharmaceuticals, and so on. Your licence and your product list say which.
No. Certification is issued by an accredited certification body, a licence by your authority, and government quality assurance is exercised by the acquisition authority. ComplyTrain is the system you build, run and evidence your compliance in, and Skylen's consultants can take you through the work. The certificate stays yours to earn.
Yes, and that is what the Request access button on every entry is for. Tell us which standard and where the requirement comes from, and we come back to you on what holding it in your workspace involves, usually within one business day. Adding a standard to a workspace is usually a matter of days, not a project. ComplyTrain holds a standard as a requirement tree with your evidence against each requirement, and the tree is what we build.