Combo Medical Device ISO 13485 and ISO 9001 Management Review Toolkit

$249

Four files: the combined quality and medical device management review deck and minutes form, for ISO 9001:2015 and for ISO 9001:2026, both paired with ISO 13485:2016. ISO 13485 is not being revised, so only the quality certificate moves — the transition planner in the 2026 deck is scoped to it and says so. Includes a two-slide asymmetry comparison.

Includes a one-page transition planner

ISO 9001:2026 published on September 16, 2026. ISO 13485:2016 is not being revised on this timetable, so only your quality certificate moves — and that is exactly the kind of partial transition that gets planned badly. One slide in this deck is the plan: nine milestones, each with an owner, a target date and a status, worked backwards from the two dates you do not control.

Most transition guidance is a list of what changed. A list is not a plan. It does not tell you when documentation has to be finished, when training has to be done, or when your internal audits have to be complete so the findings are closed before the registrar walks in. Those dates are all derived from one fixed point, and the planner derives them.

Four files, because you need both editions

Your quality certificate still says ISO 9001:2015, and it says that until your transition audit closes. Your device certificate does not move at all. This quarter's combined review has to be held against the editions on your certificates. Both pairs are in the package.

ISO 9001:2015 + ISO 13485:2016 deck and minutes form
56 slides · 24 pages · 32 sections
Run this year's combined review against the editions on your certificates. Use it until your transition audit closes.
ISO 9001:2026 + ISO 13485:2016 deck and minutes form
61 slides · 26 pages · 35 sections
Plan with it now, present from it once you transition. Contains the transition planner, scoped to the quality certificate alone.

What the transition planner asks you to fix

  • The two anchor dates — your next surveillance audit and your recertification audit. Your registrar sets them. Everything else follows from them.
  • Planning completed by — including the clause-by-clause outline of what has to change, the effort, and who does each part.
  • Documentation updated · registrar audit scheduled · training completed · implementation · internal audits completed · registrar transition audit completed — each with an owner, a target date and a status.

Certification bodies need roughly nine to twelve months to be accredited to a new edition, so the first 2026 certificates are not expected before about mid-2027. Aim at a 2027 or 2028 surveillance visit. Auditor capacity tightens sharply in the final year of any transition, and the organizations that wait are the ones that discover their registrar has no slots left.

The gap between the two standards just got wider

ISO 13485:2016 has no context clause and is not being revised. Every requirement ISO 9001:2026 added therefore has no device equivalent, and each of the three is marked quality-only so nothing appears to be required of a device system that is not.

Interested parties, 9.3.2 c) A named ISO 9001 input with no ISO 13485 counterpart. For a device organization the regulatory authority is the interested party whose requirements change most often, and those already have their own section — this one is for everyone else.
Risks and opportunities split, 9.3.2 g) and h) ISO 13485 addresses risk at 7.1 and points to ISO 14971, and has no concept of opportunity at all. The ISO 14971 file is referenced in the risk section, not substituted for the answer, and kept out of the opportunities section entirely.
Climate change, 4.1 Required by ISO 9001:2026, absent from ISO 13485. One determination for the organization is simpler than scoping it to one system. A reference slide gives the routes, including the one device organizations should notice: a sustainability claim on labeling is a regulated claim.
Retained became available ISO 9001:2015 said retain documented information as evidence; the 2026 edition says available. ISO 13485 requires a record regardless, so retention governs the shared record. The form says so plainly.

What is in each pair

  • A deck you present from and a form that becomes the record, generated from the same section list. Section 14 on the slide is Section 14 on the form. The presenter and the recorder are never on different items.
  • Every section anchored to the requirement it satisfies, with the clause or clauses printed under the title, and single-standard requirements marked as such so nothing appears to be required of a system it is not required of.
  • An asymmetry comparison across two slides — seven ISO 13485 requirements with no ISO 9001 equivalent, and six ISO 9001 requirements with no ISO 13485 equivalent, each showing where it lands in the agenda. An organization building its review from one clause list will be missing the other list entirely.
  • Terms used in this review — plain-language explanations of every term that carries a specific meaning, with the clause where each is defined. The review does not depend on who has read the standards most recently.
  • Before you hold this review — each section mapped to the record that feeds it, and what to do if you do not have it. This is the page that stops a review being held on data that does not exist.
  • Worked examples with completed data, each labeled and built to be replaced. They interlock: a device complaint and an industrial nonconformity follow different routes from the same finding, and a device-critical provider's performance is recorded where a general one would not be.
  • Document control on every slide and every page, applied through the slide master so it cannot be dropped from a slide added later, plus a cover record identity block: organization, period covered, date held, called by, recorded by, and your own record reference.

What this does not do

It does not transition your system. It plans the transition and records the management reviews that the transition requires, which are two of the things a registrar will ask for and not all of them.

It does not reproduce the text of any standard. You still need your own licensed copy of each.

Questions

Why am I paying for the older edition when it has been superseded?
Because you are still certified to it. ISO withdrew the 2015 edition on publication, but existing certificates remain valid through a transition period expected to run three years, and your review has to be held against the edition on your certificate until your transition audit closes. You get both so you can run this year's review correctly and plan next year's at the same time.

How long do we have?
The transition is expected to run three years from publication, to around September 2029, subject to confirmation by the accreditation community. That is the outer limit, not the target — see the note above about registrar capacity.

Does a management review against the new edition have to happen before the transition audit?
Yes, along with an internal audit. Both are inputs a registrar will look for as evidence the system is operating to the new edition rather than merely documented to it. The 2026 pair is how you produce one.

Does ISO 13485 transition too?
Not on this timetable. ISO 13485:2016 remains the current edition, and since February 2, 2026 it is incorporated into 21 CFR Part 820 under the QMSR, which makes device management review records inspectable. The transition planner in this toolkit covers the quality certificate only, and says so on its face.

Can we just renumber our existing deck?
You could, and the renumbering is the easy part. What renumbering does not give you is a section for interested parties, a second section separating opportunities from risks, or a record of the climate change determination — and in a combined system each of those has to be marked as applying to one certificate and not the other.

Who wrote it?
Management Systems International, LLC — a veteran-owned, female-owned ISO consulting firm founded in 1998. Across 28 years MSI has supported 80+ certifications, attended 200+ audits, and trained 600+ professionals.

Where to go next

MSI's QMS interviews course prepares the people who will be questioned during a certification or surveillance audit, including the ones who will be asked what the management review concluded.

MSI's ISO procedure templates and guides are editable Word procedures and full documentation packages covering every clause this review reports on — the system behind the record, and the documentation your transition plan says has to be updated.

Questions before you buy? Call 760-434-9141 or toll-free 888-914-9141, or visit msi-international.com.

Delivered as two .pptx and two .docx files, fully editable, no protection and no macros. Worked examples use a fictional organization created by MSI for illustration only, marked as such throughout and intended to be replaced with your own data.
© 2026 Management Systems International, LLC. All rights reserved.