I hear some version of this question from almost every pharmaceutical client who's also chasing ISO 9001: "If we're already compliant with FDA's cGMP regulations, why do we need a whole separate certification?"
It's a fair question. The honest answer is that the two systems overlap more than most people expect. But the overlap isn't total, and the gaps are exactly where companies get into trouble.
Current Good Manufacturing Practice, codified at 21 CFR Parts 210 and 211, is a legal requirement for anyone manufacturing finished pharmaceuticals for the U.S. market. ISO 9001:2015 is a voluntary, internationally recognized quality management system standard that applies to virtually any industry. One is law. The other is a certification you choose to pursue.
Both are built around the same idea, though: a company that controls its processes, documents its decisions, and corrects its own mistakes will produce a consistent, safe product. Once you see that shared premise, the overlap stops being surprising.
This article covers what each standard actually governs, where the requirements map onto each other almost clause-for-clause, where they genuinely diverge, and how to build one integrated quality system instead of running two in parallel and hoping nobody notices the seams.
What Each Standard Actually Governs
FDA cGMP (21 CFR Parts 210 and 211)
cGMP is enforceable federal regulation. FDA investigators cite specific subparts during inspections, and violations can trigger a Form 483, a warning letter, or, in serious cases, a consent decree or product seizure.
The regulation is prescriptive in places most standards aren't. A few examples:
- 21 CFR 211.100 requires written procedures for production and process controls.
- 21 CFR 211.192 requires a documented investigation of any batch that fails to meet its specifications.
- 21 CFR 211.22 requires a quality control unit with the authority to approve or reject all materials, in-process product, and finished product.
There's no ambiguity about whether these apply. They apply, and FDA will ask to see the paperwork.
ISO 9001:2015
ISO 9001 is a generic quality management system standard. It doesn't tell you how to make a tablet or validate a filling line. It tells you how to run a management system capable of controlling whatever process you point it at. Among its core requirements:
- Define your quality objectives and document them (clause 6.2).
- Control your documented information (clause 7.5).
- Plan and control production or service provision (clause 8.5.1).
- Monitor and measure performance (clause 9.1).
- Act on nonconformities and drive corrective action (clause 10.2).
Certification is issued by an accredited third-party registrar and renewed on a surveillance cycle, typically annual audits against a three-year certificate.
The core difference in posture is this: cGMP tells you what a compliant pharmaceutical quality system must contain, and ISO 9001 tells you how a quality system, generically, ought to function. A company can be fully cGMP compliant without ever touching ISO 9001. It's much harder to be ISO 9001 certified and functionally cGMP compliant, because ISO 9001 alone doesn't specify pharmaceutical-specific controls like environmental monitoring, aseptic processing, or stability testing.
Where the Two Systems Genuinely Overlap
The overlap isn't incidental. FDA's 2004 initiative, "Pharmaceutical cGMPs for the 21st Century: A Risk-Based Approach," explicitly drew on ISO quality system concepts and on the International Council for Harmonisation's ICH Q10 guideline, "Pharmaceutical Quality System," finalized in 2008. ICH Q10 was written specifically to bridge ISO 9000-series concepts with existing GMP requirements. It's the clearest evidence that the two frameworks were never meant to be strangers to each other.
Here's where the clause-level mapping is tightest:
| Function | cGMP Citation | ISO 9001:2015 Clause | What Both Require |
|---|---|---|---|
| Document control | 21 CFR 211.180–211.198 | Clause 7.5 | Controlled, current, retrievable records with defined retention |
| Management responsibility | 21 CFR 211.22 (quality unit) | Clause 5.1, 5.3 | A defined authority responsible for quality decisions |
| Process control | 21 CFR 211.100, 211.110 | Clause 8.5.1 | Written procedures governing production steps |
| Investigating failures | 21 CFR 211.192 | Clause 10.2 | Documented investigation and root cause analysis |
| Corrective action | 21 CFR 211.192 | Clause 10.2 | Action taken to prevent recurrence |
| Internal audit | Implied via 211.22, enforced via FDA inspection | Clause 9.2 | Self-assessment against defined requirements |
| Training | 21 CFR 211.25 | Clause 7.2 | Documented competence for quality-affecting work |
| Supplier control | 21 CFR 211.84 (component testing) | Clause 8.4 | Verification that externally provided materials meet requirements |
| Management review | Not explicitly named; expected via quality unit oversight | Clause 9.3 | Periodic leadership review of system performance |
If you already hold a functioning cGMP quality system, you are, in practice, already doing most of what ISO 9001 asks for. What you're usually missing isn't the activity. It's the formal structure ISO auditors expect around it, including:
- A documented quality manual or equivalent.
- A defined internal audit program with a schedule and trained auditors.
- A management review meeting with a fixed agenda and recorded outputs.
- Objective evidence that risk-based thinking (clause 6.1) gets applied outside the batch-failure context, where cGMP already forces it.
That last point is the one I see missed most often. ISO 9001 expects risk thinking applied to the whole business, including things cGMP never asks about: customer complaints about invoicing, supplier financial stability, IT system reliability. cGMP is scoped to product quality and patient safety. ISO 9001 is scoped to customer satisfaction and organizational risk. That's a wider net.
Where the Two Standards Diverge
Enforceability
This is the sharpest divide. FDA cGMP is law, enforced through inspection authority under the Federal Food, Drug, and Cosmetic Act. Noncompliance carries real regulatory consequence.
ISO 9001 certification is a market credential, not a legal requirement. Losing it means losing the certificate, not facing federal enforcement action. A company can let its ISO 9001 certification lapse and keep manufacturing. It cannot let its cGMP compliance lapse and keep manufacturing legally.
Prescriptiveness
cGMP tells you specific things you must do: maintain equipment cleaning logs under 211.67, establish expiration dating under 211.137. ISO 9001 tells you to establish a process and demonstrate it's effective, and largely leaves the "how" to you.
That's why a food company, a software company, and a pharmaceutical company can all hold ISO 9001 certificates that look structurally similar on paper while their day-to-day controls look nothing alike.
Scope of Application
cGMP applies only to the manufacture of drug products intended for the U.S. market. (Devices sit under a parallel framework: FDA's February 2, 2024 final rule established the Quality Management System Regulation, harmonizing the old 21 CFR Part 820 with ISO 13485:2016.)
ISO 9001 applies to the whole organization: sales, purchasing, HR, IT, facilities, anything that touches the product or service delivered to a customer. A pharmaceutical company pursuing both will find that ISO 9001 pulls departments into the quality conversation that cGMP never touched.
The Audit Experience
An FDA inspection is unannounced or minimally announced, adversarial by design, and can result in a 483 observation that becomes part of a public record. An ISO 9001 surveillance audit is scheduled, collaborative in tone, and results in a private nonconformity report to the certified organization and its registrar.
Teams that have only ever prepared for FDA inspections sometimes underestimate how differently a registrar auditor approaches the same quality system. It shows in how they document, or fail to document, routine decisions.
Why Pursue Both
For companies selling into global markets, dual conformance solves a real commercial problem. A U.S.-based contract manufacturer holding only cGMP compliance can struggle to win business from a European or Asian brand owner whose supplier quality agreements require ISO 9001 certification as a baseline qualifying credential, independent of whatever drug-specific approval also applies. ISO 9001 becomes a portable signal of system maturity that a foreign customer's procurement team can verify without understanding FDA regulation at all.
There's an internal argument too. cGMP, read narrowly, can produce a quality system that's excellent at catching batch failures and weak at catching organizational drift, because it never asks the company to look at customer satisfaction trends, supplier performance scorecards, or cross-functional risk outside the manufacturing floor. ISO 9001's management review (clause 9.3) and continual improvement clause (10.3) force that wider view. I've watched companies surface process risks through an ISO management review that their cGMP quality unit had no mechanism to catch, simply because cGMP was never designed to ask that question.
On cost and timeline: for a single-site solid-dose or supplement manufacturer that already runs a working cGMP quality system, a gap assessment against ISO 9001:2015 typically takes four to eight weeks of calendar time, most of it spent mapping existing SOPs, batch records, and deviation files against the nine clause areas in the table above rather than writing anything new. The internal audit program and management review structure are usually the two items built from scratch; everything else is closing formatting and cross-reference gaps in documentation that already exists.
Building One Integrated System Instead of Two Parallel Ones
The mistake I see most often is treating cGMP and ISO 9001 as two separate compliance projects, on two separate calendars, with two separate document sets, audited by two separate teams who don't talk to each other. That approach doubles the workload for a fraction of the benefit.
A better approach, in order:
- Map existing cGMP documentation against ISO 9001 clauses first, before writing anything new. Most of what clause 7.5 (documented information), clause 8.5 (production control), and clause 10.2 (nonconformity and corrective action) require already exists somewhere in your batch records, SOPs, and deviation system. The gap assessment is usually a formatting and cross-referencing exercise, not a from-scratch build.
- Assign one quality function ownership of both, even if the language differs. Your cGMP quality unit under 211.22 and your ISO 9001 "top management" representative under clause 5.3 should be the same people wearing two hats, not two competing power centers.
- Build one internal audit program that checks both, using a combined checklist that pulls citations from 21 CFR 211 and ISO 9001:2015 side by side. This is the single highest-leverage move, because internal audit is the mechanism that catches gaps before an external auditor or FDA investigator does.
- Run one management review meeting, satisfying clause 9.3's required inputs (audit results, customer feedback, process performance, corrective action status, resource adequacy) while giving your cGMP quality unit the same visibility it's supposed to maintain under its own authority. Two meetings covering ninety percent of the same content is waste, not thoroughness.
- Train your team on the difference in audit posture, not just the difference in content. Staff who've only faced FDA inspections need to understand that a registrar auditor checks for system evidence and continual improvement narrative, not just raw compliance. Staff who've only worked in ISO-certified, non-regulated industries need to understand that an FDA 483 observation carries weight an ISO nonconformity never will.
If you're building this system from scratch, our ISO 9001 consulting services and GMP certification support are built around exactly this kind of dual-track gap assessment.
A Practical Gut Check
Three questions tell you how close you already are to dual conformance:
- Does every corrective action get root-caused and closed with documented effectiveness verification, not just a signature?
- Does your management review actually change resource allocation or priorities, or is it a status report nobody acts on?
- Could an outside auditor, cGMP or ISO, pull any batch record or process file and trace it back to an approved procedure without anyone explaining a gap out loud?
If the honest answer to any of those is no, that's where to start. Not with a new binder of policies.
Frequently Asked Questions
Does ISO 9001 certification satisfy FDA cGMP requirements?
No. ISO 9001 certification does not exempt a pharmaceutical manufacturer from cGMP compliance under 21 CFR Parts 210 and 211, and it carries no legal standing with FDA. The two run on parallel tracks: one is a regulatory requirement enforced by inspection, the other is a voluntary certification issued by an accredited registrar.
Can a company be cGMP compliant without ISO 9001 certification?
Yes, and most small and mid-size pharmaceutical manufacturers operate exactly this way. cGMP compliance is mandatory for U.S. drug manufacturing regardless of whether the company holds any ISO certification. ISO 9001 becomes relevant mainly when customers, particularly international ones, require it as a supplier qualification credential.
What is ICH Q10 and how does it relate to ISO 9001?
ICH Q10, "Pharmaceutical Quality System," is a guideline finalized in 2008 by the International Council for Harmonisation that was written explicitly to apply ISO 9000 quality management concepts within the existing regulatory framework for pharmaceuticals. It's the clearest formal bridge between the two systems and is widely used as a reference model for integrating them.
Which clauses of ISO 9001:2015 map most directly to cGMP requirements?
Clause 7.5 (documented information) maps closely to cGMP recordkeeping under 21 CFR 211.180–211.198. Clause 8.5.1 (control of production) maps to process controls under 211.100 and 211.110. Clause 10.2 (nonconformity and corrective action) maps to failure investigation under 211.192. Clause 9.3 (management review) has no direct cGMP citation but is implicitly expected through the quality unit's oversight authority under 211.22.
Is dual cGMP and ISO 9001 conformance worth pursuing for a small pharmaceutical manufacturer?
It depends on your customer base, but there's a concrete way to test it. If your buyers are exclusively domestic and don't require ISO 9001 in their supplier qualification process, the audit cost, typically a multi-week gap assessment plus an annual surveillance cycle, may not be worth it yet. If you sell into international markets or serve brand owners with formal supplier quality agreements, that same gap assessment usually pays for itself the first time it unlocks a contract that required the certificate as a condition of bidding.
If you're weighing whether dual conformance makes sense for your operation, walk through where your existing system already covers ISO 9001 and where it doesn't before committing to either audit calendar.
Last updated: 2026-08-18
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.