Category: Industry Guides

Practical engineering references for sheet metal fabrication, deep drawing and metal stamping. Draw ratios, bend allowances, tolerance standards and process selection — the reference material engineers actually search for.

  • ISO 9001 vs ISO 13485 vs IATF 16949: Which Certification Does Your Supplier Actually Need?

    Procurement specifications routinely demand certifications that the part in question does not require, and just as routinely accept certificates that were never verified. The ISO 9001 vs ISO 13485 comparison is a good example: ISO 9001 is a general quality management standard applicable to any organisation, while ISO 13485 is a medical device standard built around regulatory obligation, risk management and lifetime traceability. They are not tiers of the same thing, and holding the second does not make a supplier better at the first.

    IATF 16949 is different again — an automotive standard layered on top of ISO 9001, built around defect prevention, statistical process control and the core tools that OEM supply chains run on.

    The practical question for a buyer is not which certificate is most impressive. It is whether your regulatory or customer obligation actually flows down to the component supplier, and if it does, whether the certificate you have been shown is genuine, accredited, in scope and in date. This guide covers both halves.

    ISO 9001 vs ISO 13485 - inspection and measurement area at the XCWY plant
    The inspection and measurement area at the XCWY plant

    ISO 9001 vs ISO 13485 vs IATF 16949: what each standard covers

    ISO 9001:2015

    A general quality management system standard applicable to any organisation in any sector. Specifically, it requires defined processes, documented responsibilities, control of nonconforming product, corrective action, internal audit, management review and continual improvement.

    Its strength is universality; its limitation is that it does not prescribe sector-specific technical controls. It tells you the supplier runs a managed system. However, it does not tell you the supplier can hold a particular tolerance.

    ISO 13485:2016

    A medical device quality management standard. Although derived from ISO 9001, it is built for regulatory compliance rather than customer satisfaction, and adds risk management throughout the product lifecycle, design controls, sterile and cleanroom provisions where relevant, extensive documentation, and traceability retained for the device’s lifetime.

    Critically, “continual improvement” is de-emphasised relative to consistency: in a regulated environment, an unvalidated change is a risk, not an improvement.

    IATF 16949:2016

    An automotive sector standard applied alongside ISO 9001, which must be held as well. In addition, it brings the core tools — APQP, PPAP, FMEA, MSA and SPC — plus requirements on defect prevention, control of the sub-supplier chain and a zero-defect philosophy. It is demanding to obtain and maintain, and it is normally required of direct suppliers to vehicle manufacturers.

    Comparison table

    Aspect ISO 9001:2015 ISO 13485:2016 IATF 16949:2016
    Sector Any Medical devices Automotive
    Primary orientation Customer satisfaction, improvement Regulatory compliance, safety Defect prevention, supply chain control
    Requires ISO 9001 as a base No, standalone Yes
    Risk management Risk-based thinking Formal, lifecycle-wide FMEA-driven
    Documentation burden Moderate High High
    Traceability As specified by customer Device lifetime retention Full chain, defined retention
    Mandated tools None specified Design controls, risk file APQP, PPAP, FMEA, MSA, SPC
    Typical holder Any manufacturer Device makers and regulated component suppliers Direct automotive suppliers

    Does the requirement really flow down to a component supplier?

    This is where most unnecessary cost enters a specification.

    Medical devices

    The device manufacturer carries the regulatory obligation. Whether that obligation flows down to a metal component supplier depends on the component’s role and the manufacturer’s own risk assessment. A structural bracket inside a non-sterile instrument housing is a different proposition from a component in the sterile fluid path of an implantable device.

    Many device manufacturers work with ISO 9001 certified component suppliers under their own supplier control procedures, specifying the material traceability, inspection documentation and change control they need contractually rather than requiring the supplier to hold ISO 13485. Whether that is acceptable is a decision for your regulatory function, not for a supplier’s marketing page.

    Automotive

    In practice, vehicle manufacturers generally require IATF 16949 of their direct suppliers. Tier 1 customers frequently accept Tier 2 and Tier 3 component suppliers with ISO 9001 plus PPAP documentation, at the discretion of the Tier 1 customer and their supplier quality manual. Again, the flow-down is defined by your customer’s requirements, not by a general rule.

    What XCWY holds, stated plainly

    We hold ISO 9001:2015, registration 34025Q30296R0S, issued by Beijing Tongguan Inspection and Certification, accredited by IAF and CNAS under C340-M, valid 30 May 2025 to 29 May 2028, with the scope “Production and Sales of Metal Stamping Parts (Including Export)”.

    However, we do not hold ISO 13485, IATF 16949, AS9100 or UL listing. Our team supplies PPAP Level 3 documentation, EN 10204 3.1 material certificates and full inspection records, but documentation capability is not certification and we will not present it as such. If your specification requires the manufacturer to hold one of those certificates, we are not the right supplier — and it is better to establish that now than during a supplier audit. Full details are published on our certifications page.

    ISO 9001 vs ISO 13485 claims: how to verify a certificate

    Most buyers accept a PDF. Five checks take about ten minutes and catch nearly everything.

    1. Get the registration number as text. Not an image. If a supplier will not provide the number in a form you can type into a registry, treat that as the answer.
    2. Read the scope wording. A certificate scoped to “trading services” or “sales” describes a trading company. Ours reads “Production and Sales of Metal Stamping Parts (Including Export)” — the production wording is what indicates manufacturing.
    3. Check the accreditation, not just the issuer. Certification bodies vary widely in rigour. Accreditation by a recognised national body, and recognition through the IAF multilateral arrangement, is what gives a certificate standing internationally. Ours carries CNAS accreditation C340-M and IAF recognition.
    4. Check the validity dates. Expired certificates are still displayed surprisingly often.
    5. Verify in the registry. For Chinese certificates, search the registration number at cnca.gov.cn. Thirty seconds of checking beats any marketing claim.

    What to specify instead when certification does not flow down

    If your regulatory function confirms that supplier certification is not mandatory, specify the underlying controls directly. This gets you what the certificate was a proxy for, without paying for scope you do not need.

    • Material traceability. EN 10204 3.1 mill test certificates traceable to the heat number, on every lot.
    • First article approval. A signed dimensional report against the drawing, approved before production release.
    • Change control. Written notification before any change to material, process, tooling or sub-supplier. This is the single most valuable clause in most component supply agreements.
    • Inspection records. In-process sampling and final AQL results supplied with each shipment.
    • Corrective action. A defined response time for nonconformity — ours is an 8D report within 48 hours.
    • Third-party inspection rights. The right to have SGS, Bureau Veritas, TÜV or Intertek inspect before shipment.
    • Cleanliness or packaging requirements. Where relevant, specify them explicitly rather than assuming a standard applies.

    Therefore, our quality page sets out the four inspection gates and the documentation set, while sector-specific boundaries appear on the medical device parts and EV and automotive pages.

    A short decision sequence

    1. Establish with your regulatory or quality function whether certification genuinely flows down to this component.
    2. If it does, require the certificate, verify it in the registry, and check the scope covers the process you are buying.
    3. If it does not, specify the underlying controls contractually and verify them through first article approval and inspection.
    4. Either way, verify the certificate you are shown rather than accepting a logo.
    5. Reassess if the component’s role changes — a part that moves closer to a regulated function may change the answer.

    Frequently Asked Questions

    What is the difference between ISO 9001 vs ISO 13485?

    ISO 9001 is a general quality management standard focused on customer satisfaction and continual improvement, applicable to any sector. By contrast, ISO 13485 is a medical device standard oriented toward regulatory compliance, with formal risk management, design controls and traceability retained for the device lifetime. Importantly, it is a standalone standard rather than an add-on to ISO 9001.

    Does my metal parts supplier need ISO 13485?

    It depends on the component’s role in the device and your own regulatory risk assessment, and it is a decision for your quality function rather than the supplier. Many device manufacturers use ISO 9001 certified component suppliers under their own supplier controls, specifying traceability and inspection contractually. Components in sterile or patient-contacting paths generally face stricter requirements.

    Is IATF 16949 required for all automotive parts?

    It is generally required of direct suppliers to vehicle manufacturers, while Tier 2 and Tier 3 component suppliers are often accepted with ISO 9001 plus PPAP documentation. The requirement is set by your customer’s supplier quality manual, so confirm it there rather than assuming. PPAP capability and IATF certification are not the same thing.

    How do I verify an ISO certificate is genuine?

    Obtain the registration number as text and search it in the issuing country’s national registry — for Chinese certificates, cnca.gov.cn. Then confirm the certification body is accredited by a recognised national body and covered by the IAF multilateral arrangement, and check the validity dates. Finally, read the scope wording to confirm it covers production rather than trading.

    Can a supplier provide PPAP without holding IATF 16949?

    Yes. PPAP is a documentation package covering process flow, PFMEA, control plan, measurement systems analysis, dimensional results and material certification, and any capable supplier can produce one. IATF 16949 certifies a full management system, which is a broader requirement. Whether PPAP alone is acceptable is set by your customer.

    Does ISO 9001 certification guarantee part quality?

    No. It indicates that a managed quality system exists with defined processes, inspection and corrective action, which is necessary but not sufficient. However, it says nothing about whether the supplier can hold your specific tolerance or run your material. Verify capability separately through first article inspection and, where warranted, third-party audit.

    Tell us the requirement and we will confirm the fit honestly

    If your specification names a certification, send it with your drawing and we will confirm plainly whether we meet it. Where we do not, we will say so rather than qualify our way around it. Quotations return within 3 business hours with design-for-manufacture feedback included. Email xcwystamping@xcwybj.com or use the quote request form.

  • Hello world!

    Welcome to WordPress. This is your first post. Edit or delete it, then start writing!