Learn
What Is ISO 9001 in Healthcare?
If you work in hospital quality or compliance, you've likely seen "ISO 9001" mentioned alongside accreditation standards, especially if your hospital is accredited through DNV. ISO 9001 didn't originate in healthcare, it's a general-purpose quality management standard that hospitals have adapted, and in some cases are required, to use. Here's what it actually is, how its principles apply to a hospital setting, and how it connects to accreditation.
Key takeaways
- ISO 9001 is a general-purpose management-system standard, not a clinical one. It governs how a hospital runs, documents, and improves its processes.
- CMS does not require it. DNV does, DNV phases the requirement in across the accreditation cycle and states hospitals achieve ISO 9001 certification at the end of their fourth annual survey.
- ISO 9001:2015 is the edition in force. A revision expected as ISO 9001:2026 has passed its final ballot and is under publication, with a transition period to follow.
- Certification is a cycle, not an event: internal audits, management review, and CAPA have to keep producing evidence between surveys.
What Is ISO 9001?
ISO 9001 is an international standard for quality management systems (QMS), published by the International Organization for Standardization. It defines requirements an organization must meet to demonstrate it consistently delivers services that meet customer and regulatory requirements, and that it is actively working to improve.
The current published edition is ISO 9001:2015, still the version organizations are certified against today. A revised edition, expected to be published as ISO 9001:2026, passed its Final Draft International Standard ballot on 9 July 2026 and is now under publication, with ISO expecting it to replace ISO 9001:2015 in September 2026 and a transition period for certified organizations to follow (ISO 9001:2015, Quality management systems; ISO: ISO 9001 under publication). Until that transition happens, ISO 9001:2015 remains the standard in force.
ISO 9001 is deliberately generic, it applies to manufacturers, service companies, government agencies, and healthcare organizations alike. It doesn't prescribe what a hospital should do clinically; it prescribes how the organization should manage, document, and continually improve the systems behind consistent, quality output.
The Core Principles Behind ISO 9001
ISO 9001:2015 is built on quality management principles described in the companion standard ISO 9000, including customer focus, leadership, engagement of people, process approach, improvement, evidence-based decision making, and relationship management. Three show up most directly in how hospitals operationalize the standard:
Process approach. Rather than managing a hospital as disconnected departments, ISO 9001 asks organizations to understand their work as interrelated processes, admission through discharge, medication management, sterile processing, with defined inputs, outputs, and owners. It's the same systems-thinking mindset behind CMS's Conditions of Participation.
Risk-based thinking. ISO 9001:2015 formally embedded "risk-based thinking" throughout the standard, replacing the older, separate concept of "preventive action." Organizations are expected to identify risks to conformity and address them proactively, not just react after something goes wrong, which maps naturally onto patient safety risk assessments, FMEAs, and proactive risk registers.
Continual improvement and PDCA. ISO 9001 is structured around the Plan-Do-Check-Act (PDCA) cycle: plan a process and its objectives, execute it, check performance against those objectives, and act to improve. This cycle repeats continuously, which is why certification is never "set it and forget it": it requires ongoing internal audits, management review, corrective action, and documented evidence of improvement over time.
What ISO 9001 Certification Actually Involves
Achieving and keeping ISO 9001 certification is a multi-step process: a gap assessment against the standard, QMS design and documentation (processes, quality objectives, required records), implementation in daily practice, required internal audits, formal management review of performance and risk, and an external certification audit by an accredited third-party registrar, typically in two stages, followed by annual surveillance audits and recertification roughly every three years.
How ISO 9001 Applies to Hospitals and Health Systems
Hospitals aren't required by CMS to hold ISO 9001 certification simply to participate in Medicare. For hospitals accredited under bodies like The Joint Commission or HFAP, ISO 9001 is typically an optional framework some organizations adopt voluntarily to strengthen governance or document control, not a regulatory or accreditation requirement. That changes for one specific group: hospitals accredited through DNV.
See it on your open findings.
A demo takes a nonconformity you have open right now and walks it through to a closed corrective action, the entry it came from, the similar findings it matches, and the effectiveness check that closes it.

ISO 9001 and DNV NIAHO Accreditation
DNV's hospital accreditation program, NIAHO (National Integrated Accreditation for Healthcare Organizations), is built by integrating the Medicare Conditions of Participation with ISO 9001 quality management principles into a single, unified survey process (DNV: NIAHO accreditation for acute care hospitals). Hospitals are expected to demonstrate ISO 9001-aligned practices, document control, internal audit programs, CAPA, and management review, from the start of accreditation.
Rather than requiring full ISO 9001 certification on day one, DNV phases the requirement in across a hospital's accreditation cycle: hospitals must achieve compliance with the ISO 9001 standard, whether through formal third-party certification or by demonstrating conformance to ISO 9001 principles during survey, and DNV states that hospitals achieve ISO 9001 certification at the end of their fourth annual survey (DNV: NIAHO accreditation for hospitals). In practice, a newly NIAHO-accredited hospital doesn't need to walk in the door ISO-certified, but it does need a functioning ISO 9001-style quality management system well before that milestone, and DNV surveyors assess progress toward it at each annual survey.
Benefits of ISO 9001 for Hospitals
Beyond satisfying a DNV requirement, hospitals that genuinely operationalize ISO 9001 principles tend to see more consistent processes across departments and shifts, stronger document control so staff always work from the current approved version of a policy, a structured CAPA discipline that closes the loop on problems instead of letting them stall, better audit readiness because internal audits and management review are already built into daily operations, and a common quality language that unifies accreditation, regulatory, and internal improvement work under one system instead of several disconnected ones.
How a Software QMS Supports ISO 9001 Conformance
ISO 9001 conformance depends on being able to show, not just claim, that document control, internal audits, risk management, CAPA, and management review are actually happening, on schedule, with a clear record. That's difficult to sustain with static documents and disconnected spreadsheets, especially across a multi-department hospital.
This is the gap Medlaunch Concepts' platform is built to close. My Policy keeps controlled documents current with version history and attestations; Quality Core runs internal audits, rounds, and the CAPA lifecycle DNV surveyors expect to see; Risk Management maintains a live risk registry tied to actual incident and safety event data; and Relevance BI turns all of it into the ongoing KPI monitoring that ISO 9001's "check" and "act" steps require. Clara, Medlaunch's AI agent, works across all of it to help surface gaps before a surveyor does. None of this replaces the work of building a real quality culture, but it gives hospitals a defensible, continuously current record of the ISO 9001-aligned system DNV expects to see.
Frequently asked questions
Does CMS require hospitals to be ISO 9001 certified?
No. ISO 9001 certification is not a CMS Condition of Participation. It becomes a requirement specifically for hospitals accredited through DNV's NIAHO program, which is built on ISO 9001 principles.
Is ISO 9001 the same as Joint Commission accreditation?
No. They're separate processes with separate standards and surveyors. Some hospitals pursue both, but Joint Commission accreditation does not require ISO 9001 certification.
How long does it take a hospital to become ISO 9001 certified?
It varies with how mature existing quality processes are, but building out documentation, running required internal audits, and completing a two-stage external audit typically takes many months to a year or more for organizations starting from a limited framework.
Is ISO 9001:2015 still current, or has it been replaced?
As of mid-2026, ISO 9001:2015 is still the current, valid edition. A revised edition (expected as ISO 9001:2026) passed its Final Draft International Standard ballot on 9 July 2026 and is under publication, with ISO expecting it to replace ISO 9001:2015 in September 2026, after which certified organizations get a transition period to migrate.
References
- ISO 9001:2015, Quality management systems, Requirements (ISO.org)
- ISO 9001, Quality management systems, Requirements, next edition at stage 60.00, under publication (ISO.org)
- DNV: NIAHO accreditation for acute care hospitals
- DNV: NIAHO accreditation for hospitals
- DNV: NIAHO Accreditation Requirements, Revision 25-1 (Updated)
Keep reading
Related from Medlaunch
NIAHO Standards
The DNV accreditation program that folds ISO 9001 into the Medicare Conditions of Participation, chapter by chapter.
Read more →What Is a Quality Management System?
What a hospital QMS has to contain, and what it has to produce as evidence between surveys.
Read more →What Are CMS Tags?
How survey citations map back to specific CoP regulations, and what to do with them once they land.
Read more →See this working in practice.
Book a demo and we will show you how Medlaunch handles it against your own policies and standards.