Written and maintained by CASRAI Editorial Board
Last updated
ISO 13485:2016, Medical devices — Quality management systems — Requirements for regulatory purposes, is the international standard that defines what a quality management system (QMS) must do for an organization involved in the design, production, installation, or servicing of medical devices. LAC Health maintains a live glossary entry for ISO 13485 aimed at procurement teams sourcing certified devices. It is the standard that certification bodies audit against when a device manufacturer says it is “ISO 13485 certified,” and it is also the standard the U.S. FDA now incorporates directly into federal regulation.
Researchers, core-facility staff, and lab managers most often meet ISO 13485 at the point where a research prototype, assay, or device concept is being positioned for eventual regulatory submission — because that is exactly where design controls and the design history file start to matter, often well before a device reaches full commercial manufacturing.
The standard’s exact designation, edition and date are confirmed in U.S. federal regulation rather than paraphrased here: 21 CFR 820.7(b) incorporates by reference “ISO 13485:2016(E), Medical devices — Quality management systems — Requirements for regulatory purposes, Third edition, March 1, 2016.” The full normative text is copyrighted and must be purchased from ISO or a national member body; this guide describes what each clause requires and cites clause numbers, and does not reproduce the standard’s wording.
ISO 13485 is not an ISO 9001 add-on
The single most common misunderstanding is treating ISO 13485 as a medical-device “flavor” of ISO 9001 — a supplementary checklist layered on top of a generic quality standard. It is not. ISO 13485:2016 is a fully standalone, freestanding QMS standard in its own right, and it differs from ISO 9001 in ways that matter operationally, not just administratively:
- Structure. ISO 9001:2015 was rewritten to follow the ISO/IEC Directives Part 1 “Annex SL” high-level structure shared across modern management-system standards (with clauses like “context of the organization” and “leadership”). ISO 13485:2016 deliberately did not follow Annex SL — ISO/TC 210 concluded those concepts weren’t necessary for the medical-device quality model and kept the structure inherited from the 2003 edition (planning for the 2016 revision had begun before Annex SL was finalized). The two standards share substantial content and are commonly implemented together, but they are no longer structurally aligned clause-for-clause the way people sometimes assume.
- Regulatory purpose is written into the standard itself. ISO 9001 is a general-purpose QMS standard applicable to any industry, with customer satisfaction and continual improvement as its organizing goals. ISO 13485’s explicit purpose — stated in its own title — is to support an organization’s ability to meet applicable regulatory requirements, and its clauses reference regulatory obligations (device files, risk management, traceability, complaint handling, adverse-event/vigilance reporting, advisory notices) that have no ISO 9001 equivalent.
- Risk management is a pervasive, standalone obligation. ISO 13485 requires risk management to be applied throughout the product realization process and cross-references ISO 14971, the medical device risk management standard, directly. ISO 9001’s approach to “risk-based thinking” is a general management-planning concept; ISO 13485’s is a documented, product-safety-driven discipline that touches design, production, and post-market activities.
- Continual improvement is narrower by design. ISO 13485 emphasizes maintaining the effectiveness of the QMS and meeting regulatory requirements over open-ended continual improvement, reflecting that in a regulated device environment, change itself carries risk and must be controlled, not just encouraged.
The practical consequence: an organization cannot treat ISO 9001 certification as “covering” ISO 13485 obligations, and vice versa. Many device manufacturers hold both certifications, but they are assessed, and often audited, separately.
The seven ISO 9001 deltas that generate findings
Organizations arriving from a mature ISO 9001:2015 system usually have the hard parts — process discipline, document control, internal audit — already working. What catches them out is that ISO 9001:2015 removed several requirements that ISO 13485:2016 still mandates, so a system built to the newer general standard is missing artefacts the device standard expects to exist. These are the recurring gaps, clause by clause:
- Mandatory documented procedures are back (throughout). ISO 9001:2015 abolished the concept of the six required documented procedures and replaced it with the looser “documented information.” ISO 13485:2016 explicitly requires documented procedures at many named clauses — document control (4.2.4), records control (4.2.5), training (6.2), design and development (7.3), purchasing (7.4.1), production and service provision including process validation (7.5), complaint handling (8.2.2), reporting to regulatory authorities (8.2.3), internal audit (8.2.4), control of nonconforming product (8.3), corrective action (8.5.2) and preventive action (8.5.3). A 9001-derived system that documented these as “processes” in a flowchart tool, without a controlled procedure document, has a gap at each one.
- The quality manual (4.2.2) still exists. ISO 9001:2015 dropped it. ISO 13485:2016 still requires one, and it must describe the QMS scope, reference or include the documented procedures, and describe the interaction between processes — including a justification for any non-applied requirement.
- The management representative (5.5.2) is a named role. ISO 9001:2015 removed the requirement to appoint one. ISO 13485 keeps it as a specific appointment from within management, with defined responsibility for QMS processes, for reporting on QMS effectiveness to top management, and for promoting awareness of regulatory requirements.
- Preventive action (8.5.3) survived as its own clause. ISO 9001:2015 deleted preventive action and folded its intent into risk-based thinking. ISO 13485 retains corrective action (8.5.2) and preventive action (8.5.3) as separate requirements, each requiring a documented procedure. A CAPA system that treats “preventive action” as a synonym for risk assessment, with no records of preventive actions actually raised, is a standing finding. See CASRAI’s CAPA definition for the correction / corrective action / preventive action distinction the clause depends on.
- The medical device file (4.2.3) has no ISO 9001 equivalent at all. For each device type or family, the organization must establish and maintain a file containing or referencing the product specification, manufacturing and inspection specifications, and the requirements for installation and servicing where applicable. This is a per-device-family artefact, not a system-level one, and organizations that have never had to produce one tend to discover on audit day that the information exists but is scattered across engineering, production and regulatory systems with no controlling index.
- Records retention is measured against the device, not the calendar. Clause 4.2.5 ties retention to the lifetime of the device as defined by the organization, subject to applicable regulatory requirements, with a floor expressed in the clause rather than left to organizational policy. A generic “seven-year retention” policy inherited from a 9001 system is not, by itself, a conforming answer — the auditable position is a documented lifetime per device family, and a retention rule derived from it.
- Software used in the QMS must be validated (4.1.6, 7.5.6, 7.6). ISO 13485 requires documented procedures for validating computer software applications used in the quality management system, in production and service provision, and in monitoring and measurement — with the validation approach proportionate to the risk associated with the software’s use. ISO 9001 has no such requirement. In practice this reaches eQMS platforms, LIMS, statistical process control tools and, awkwardly for many organizations, spreadsheets used in release or acceptance decisions. CASRAI’s computer system validation guide covers the GAMP 5 and IQ/OQ/PQ machinery usually applied here.
One further asymmetry worth naming: ISO 13485 permits requirements in Clause 7 not to be applied where they are not applicable to the organization’s activities or the device, but it requires that non-application be recorded and justified in the quality manual. Non-application is a documented decision with a stated rationale, not an omission — and the justification is one of the first things a stage 1 audit looks at.
Certification, not accreditation — the same trap as ISO 17025
CASRAI’s ISO/IEC 17025 guide covers a vocabulary trap that trips up the same audience here in reverse. ISO/IEC 17025 is a competence standard for testing and calibration laboratories, and conformity to it is accreditation — a scope-bounded attestation of technical competence for specific tests or calibrations, granted by an accreditation body.
ISO 13485 works the other way: like ISO 9001, it is a management-system standard, and conformity to it is certification — an organization-wide (or site/scope-wide) attestation, issued by a certification body (in the EU medical-device context, often a Notified Body performing a combined ISO 13485 certification and MDR/IVDR conformity assessment), that the QMS itself meets the standard’s requirements. A device manufacturer is “ISO 13485 certified,” never “ISO 13485 accredited” — the reverse error to the one made about ISO 17025. Keep the two standards and the two words straight: 17025 is accreditation of technical competence within a scope; 13485 is certification of a management system.
How ISO 13485:2016 is structured
Like its ISO 9001:2008-lineage predecessor, ISO 13485:2016 is organized into clauses 4 through 8:
- Clause 4 — Quality management system. General QMS requirements plus documentation requirements (quality manual, medical device file, document and record control).
- Clause 5 — Management responsibility. Management commitment, customer focus, quality policy and objectives, planning, responsibility/authority/communication, and management review.
- Clause 6 — Resource management. Human resources (competence, training), infrastructure, and work environment/contamination control.
- Clause 7 — Product realization. Planning, customer-related processes, design and development (7.3, see below), purchasing, production and service provision (including sterile product and installation/servicing requirements), and control of monitoring/measuring equipment.
- Clause 8 — Measurement, analysis and improvement. Feedback (including a formal complaint-handling process and reporting to regulatory authorities — the clause through which field safety corrective action and recall reporting obligations reach the QMS), internal audit, monitoring of processes and product, control of nonconforming product, analysis of data, and improvement — including corrective action (8.5.2) and preventive action (8.5.3), the clauses that underpin a device manufacturer’s CAPA system.
Clauses 1 to 3 (scope, normative references, terms and definitions) are not auditable requirements in the same sense, but Clause 1 matters procedurally because it is where the scope of the QMS — and any non-applied Clause 7 requirements — get pinned down.
Clause by clause: what an auditor asks you to produce
A note on sourcing. The requirement descriptions below are drawn from the clause structure of ISO 13485:2016 and, where a requirement is mirrored in U.S. regulation, from the text of 21 CFR Part 820 linked in the following section. The specific evidence items — the particular records an assessor is likely to ask for at each clause — are a practitioner-level inference about common audit practice, not requirements stated in the standard and not sourced from a certification body’s published audit protocol. Treat them as a preparation aid, and treat your certification body’s or Notified Body’s own audit plan as authoritative for what will actually be sampled.
Clause 4 — Quality management system
What the clause requires. Document the QMS and the organization’s role or roles under applicable regulatory requirements (4.1.1); identify the QMS processes and apply a risk-based approach to controlling them (4.1.2); control outsourced processes through a written agreement proportionate to risk (4.1.5); validate software used in the QMS (4.1.6). Then the documentation layer: quality manual (4.2.2), medical device file per device type or family (4.2.3), control of documents (4.2.4) and control of records (4.2.5).
What an assessor is likely to ask for. The quality manual, opened to the scope statement and the justification for any non-applied Clause 7 requirement. The medical device file index for one named device, then a spot-check that each referenced document actually resolves. The list of outsourced processes with the corresponding quality agreements, and evidence the controls are proportionate to the risk each supplier carries. Validation records for at least one piece of QMS software — typically the eQMS or document-control system itself. A document change history for a recently revised controlled procedure, showing reviewer, approver, effective date, and evidence the obsolete version was withdrawn from points of use.
Clause 5 — Management responsibility
What the clause requires. Top-management commitment (5.1); a quality policy including a commitment to comply with requirements and maintain QMS effectiveness (5.3); measurable quality objectives consistent with that policy, established at relevant functions and levels (5.4.1); QMS planning that preserves QMS integrity when changes are made (5.4.2); defined and communicated responsibilities and authorities (5.5.1); an appointed management representative (5.5.2); internal communication (5.5.3); and management review at documented planned intervals (5.6), with defined inputs (5.6.2) and outputs (5.6.3).
What an assessor is likely to ask for. The appointment record for the management representative — a named individual, in writing, with the clause-specific responsibilities stated. The last management review pack, checked input by input against 5.6.2: feedback, complaint handling, reporting to regulatory authorities, audits, monitoring and measurement of processes and product, corrective and preventive action, follow-up from the previous review, changes that could affect the QMS, recommendations for improvement, and new or revised applicable regulatory requirements. That last input is where reviews most often come apart: an auditor will look for a specific, dated discussion of a real regulatory change — the QMSR transition being the obvious recent example — rather than a standing agenda line with nothing recorded under it. Quality objectives are then traced from the policy down to a measurable target with an owner and a current value.
Clause 6 — Resource management
What the clause requires. Determine and provide resources (6.1). Establish competence criteria, provide training or other action, and — distinctively — evaluate the effectiveness of that action, ensuring personnel are aware of the relevance of their activities and how they contribute to quality objectives (6.2), with records retained. Document infrastructure requirements including maintenance where maintenance can affect product quality (6.3). Document work-environment requirements and, where contamination could affect the device, arrangements for contamination control — with specific requirements for sterile devices and for controlling contamination by micro-organisms or particulate matter (6.4).
What an assessor is likely to ask for. A competence matrix mapping roles to required competencies, then the training file for one named operator sampled from a batch record they signed. Attendance sheets alone do not satisfy 6.2 — the effectiveness evaluation is the part usually missing, and a read-and-understood signature is weak evidence of it where the task is technical. Documented maintenance intervals for equipment whose failure could affect product, with the actual maintenance records for one asset. For cleanroom or controlled-environment operations: environmental monitoring trend data, gowning qualification records, and the documented rationale for the monitoring limits themselves.
Clause 7 — Product realization
What the clause requires. Plan product realization with risk management documented throughout (7.1). Determine and review customer and regulatory requirements, including user-training requirements (7.2.1–7.2.2), and establish communication arrangements including advisory notices (7.2.3). Design and development under 7.3 (covered in detail in the next section). Purchasing: evaluate and select suppliers against documented criteria, with the extent of control proportionate to the supplier’s effect on the device, and re-evaluate them (7.4.1); include in purchasing information a written agreement that the supplier notifies the organization of changes (7.4.2); verify purchased product (7.4.3). Production and service provision: controlled conditions (7.5.1), product cleanliness (7.5.2), installation (7.5.3), servicing (7.5.4), particular requirements for sterile devices (7.5.5), validation of processes whose output cannot be verified by subsequent monitoring (7.5.6), validation of sterilization and sterile-barrier processes (7.5.7), identification (7.5.8), traceability with additional requirements for implantable devices (7.5.9), customer property (7.5.10), preservation (7.5.11). Finally, control of monitoring and measuring equipment (7.6).
What an assessor is likely to ask for. A supplier file for one purchased critical component: the evaluation against documented criteria, the approval decision, the purchase agreement containing the change-notification clause, the re-evaluation record, and the incoming verification results. CASRAI’s vendor qualification, supplier audit and incoming inspection sampling plan guides cover the machinery behind that file; a second-party audit report is the usual evidence for a high-risk supplier. For 7.5.6, the process validation package — protocol with pre-defined acceptance criteria, executed results, and the documented triggers for revalidation. For 7.5.7, sterilization records per batch, tied to a validated cycle; see sterilization validation for the IQ/OQ/PQ structure across steam, EtO and radiation. For 7.5.9, a traceability exercise run live: an assessor picks a serial number or lot and asks you to walk forward to distribution and backward to component lots, usually against the clock. For 7.6, a calibration certificate for one gauge with its metrological traceability chain intact (see what “NIST-traceable” actually means) — followed by the harder question of what you did about product already released when an instrument was found out of tolerance.
Clause 8 — Measurement, analysis and improvement
What the clause requires. A documented feedback process gathering data from production and post-production activities, feeding both risk management and product-realization inputs (8.2.1). Documented complaint handling (8.2.2). Documented procedures for reporting to regulatory authorities where applicable regulatory requirements require notification of complaints meeting reporting criteria (8.2.3). Internal audit at planned intervals, with a documented programme accounting for the status and importance of processes and areas, and auditors not auditing their own work (8.2.4). Monitoring and measurement of processes (8.2.5) and of product (8.2.6). Control of nonconforming product, split into product detected before delivery (8.3.2), product detected after delivery including advisory-notice issuance (8.3.3), and rework (8.3.4). Analysis of data (8.4). Improvement (8.5.1), corrective action (8.5.2) and preventive action (8.5.3).
What an assessor is likely to ask for. The complaint log, sampled — and then, for a complaint you determined was not reportable, the documented rationale for that determination. Non-reportability decisions with no recorded reasoning are among the most commonly cited gaps at 8.2.2/8.2.3, because the record is the only thing distinguishing a considered judgment from an omission. The internal audit programme showing risk-based frequency rather than a flat annual sweep, plus the independence of the assigned auditor for the area being sampled. For CAPA: a closed record traced end to end — problem statement, root cause with the analysis behind it, action taken, verification that the action was effective, and evidence that the change did not adversely affect the finished device. For 8.3.4, a rework record showing re-inspection against the medical device file specification and an assessment of any adverse effect of the rework itself. CASRAI’s nonconformity guide covers how findings raised against these clauses get graded major or minor and how the NCR/NCAR response cycle then runs.
Design controls and the design history file
This is the section of ISO 13485 that research-stage work most often touches, because it governs the transition from a research concept to a controlled, traceable device design — frequently well before formal manufacturing begins.
Clause 7.3, Design and development, requires a documented, staged process covering:
- Design and development planning
- Design inputs — the functional, performance, usability, and regulatory requirements the design must satisfy
- Design outputs — specifications, drawings, and other outputs that can be verified against inputs
- Design review — formal, documented reviews at appropriate stages
- Design verification — confirming outputs meet inputs
- Design validation — confirming the resulting device meets user needs and intended use, normally under actual or simulated use conditions
- Design transfer — ensuring the verified/validated design is correctly translated into production specifications
- Control of design changes
- A design and development file (7.3.10) that demonstrates conformity to the plan and to the clause’s requirements
The design history file (DHF) is the term of art for this record set in U.S. practice, defined at 21 CFR 820.30(j) (legacy Quality System Regulation) as the compilation of records describing the design history of a finished device. It performs the same function as ISO 13485’s 7.3.10 design file: a chronological, auditable trail showing that every design input was addressed, every output was verified, and the final design was validated before release. For research teams, the practical implication is that DHF discipline — version-controlled requirements, traceable verification/validation records, documented design reviews — is worth establishing early, because reconstructing it retroactively once a device moves toward regulatory submission is far more costly than maintaining it as the design work happens.
What an assessor is likely to ask for at 7.3. The single most predictable request is a design traceability matrix: each design input traced to the output that satisfies it, to the verification activity that confirmed it, and to the validation evidence covering the corresponding user need. Orphans in either direction — an input with no verification, an output tracing to nothing — are what the matrix exists to expose. Beyond that: design review minutes showing the participation of a function independent of the stage being reviewed; a verification protocol with acceptance criteria fixed before execution, and the signed report against them; validation performed on units representative of production, with the justification for that representativeness recorded; a design transfer record demonstrating that production specifications derive from verified outputs; and a design change record showing the change was evaluated for its effect on constituent parts, on product already delivered, and on the risk file. Where the device has a user interface, human-factors evidence sits inside design validation — see CASRAI’s guide to FDA human factors and usability engineering. Where it contacts the body, biological evaluation under ISO 10993 sits inside design verification — see FDA guidance on biocompatibility. For software-driven devices, Software as a Medical Device (SaMD) classification determines how much of this applies to the software itself.
How ISO 13485 relates to FDA regulation: QSR to QMSR
For decades, U.S. device manufacturers worked under the FDA’s own Quality System Regulation (QSR), codified at 21 CFR Part 820, which was similar in substance to ISO 13485 but not textually identical — creating duplicate documentation burden for manufacturers selling into both the U.S. and international markets. The FDA closed that gap with the Quality Management System Regulation (QMSR), published as a final rule at 89 FR 7523 on February 2, 2024 (amended at 89 FR 82945, October 15, 2024) and effective February 2, 2026, replacing most of legacy Part 820 and incorporating ISO 13485:2016 by reference as the QMS requirement for device manufacturers, with a small set of FDA-specific additions layered on top. In practice, this means an ISO 13485-conformant QMS is now, with limited FDA-specific supplements, the U.S. regulatory baseline for device manufacturers as well as the international one — a research team building toward a U.S. submission and an EU submission is increasingly working from the same underlying QMS standard rather than two parallel systems. CASRAI’s 21 CFR overview places Part 820 among the other device and research parts of Title 21, and the companion guide to 21 CFR Part 820 subpart by subpart maps where each legacy Quality System Regulation section went and what the transition actually changes for a manufacturer.
Inside the QMSR: which clauses carry extra U.S. requirements
The QMSR is short — most of Part 820 is now reserved. What remains is worth reading in full, because it is precisely the delta between “ISO 13485 conformant” and “U.S. compliant.” Every item below is from the current text of 21 CFR Part 820 on eCFR.
- § 820.7 — what is actually incorporated. Two documents: ISO 13485:2016(E), third edition, March 1, 2016, IBR-approved for §§ 820.1, 820.3, 820.10, 820.35 and 820.45; and Clause 3 (terms and definitions) of ISO 9000:2015(E), IBR-approved for § 820.3 only. The vocabulary standard is part of the regulation, which is easy to miss.
- § 820.3 — definitions that override the standard. ISO 13485 and ISO 9000 Clause 3 definitions apply, except that Federal Food, Drug, and Cosmetic Act section 201 definitions supersede the correlating ISO terms — explicitly including “device” and “labeling,” which displace ISO 13485’s “medical device” and “labelling.” Beyond that, “organization” is defined to mean “manufacturer” as defined in the part; “implantable medical device” takes the meaning of “implant” at 21 CFR 860.3; “rework” is defined against the medical device file; and “safety and performance” takes the meaning of “safety and effectiveness” in ISO 13485 Clause 0.1, with the regulation stating that the phrasing does not relieve a manufacturer of any obligation to provide reasonable assurance of safety and effectiveness. § 820.3 also adds terms ISO 13485 does not define or use: batch or lot, component, finished device, and remanufacturer. If your QMS glossary points only at ISO 13485, it is not the U.S. glossary.
- § 820.10(b) — four named clause bridges. The regulation names four ISO 13485 clauses that cannot be satisfied by the clause alone and specifies the U.S. part each must be read with: Clause 7.5.8 (identification) with Part 830 for unique device identification; Clause 7.5.9.1 (traceability, general) with Part 821 for device tracking where applicable; Clause 8.2.3 (reporting to regulatory authorities) with Part 803, requiring notification of FDA for complaints meeting the medical device reporting criteria; and Clauses 7.2.3, 8.2.3 and 8.3.3 with Part 806 for advisory notices, corrections and removals. These four are the highest-yield place to check an imported QMS: an ISO 13485 procedure written for a non-U.S. market will satisfy the clause and still miss the U.S. part.
- § 820.10(c) — design controls are class-scoped, not universal. Compliance with Clause 7.3 and its subclauses is required for class II and class III devices, plus class I devices that are automated with computer software, plus five specifically listed class I devices: tracheobronchial suction catheter (868.6810), non-powdered surgeon’s glove (878.4460), protective restraint (880.6760), manual radionuclide applicator system (892.5650), and radionuclide teletherapy source (892.5740). Every other class I device is outside the U.S. design-control requirement — a distinction ISO 13485 itself does not draw.
- § 820.10(d) — implantable traceability extends to life-supporting devices. Clause 7.5.9.2, which ISO 13485 frames around implantable devices, is required in the U.S. for manufacturers of devices that support or sustain life where failure in normal use could reasonably be expected to cause significant injury.
- § 820.10(e) — the enforcement hook. Failure to comply with any applicable requirement of the part renders the device adulterated under section 501(h) of the FD&C Act. That is what converts a QMS gap into a regulatory action, and it is why “we hold a valid ISO 13485 certificate” is not a defence to an FDA finding.
- § 820.35 — prescribed record fields. On top of Clause 4.2.5, complaint records for reportable, investigated, or determined-to-need-investigation complaints must capture seven specified items: device name; date the complaint was received; any UDI or UPC and other device identification; complainant name, address and phone number; nature and details of the complaint; any correction or corrective action taken; and any reply to the complainant. Where an investigation is not performed because a similar complaint was already investigated, the justification must be recorded. Servicing records under Clause 7.5.4 must capture six items: device name; any UDI or UPC and other identification; date of service; who performed it; the service performed; and any test and inspection data. And the UDI must be recorded for each device or batch, on top of Clauses 7.5.1, 7.5.8 and 7.5.9. These are enumerated fields, not principles — a complaint form missing one of them is a documentable gap.
- § 820.45 — labeling and packaging controls. On top of Clause 7.5.1, manufacturers must document procedures describing the activities that ensure integrity, inspection, storage and operations for labeling and packaging. Labeling and packaging must be examined for accuracy before release or storage, covering the correct UDI or UPC or other identification, expiration date, storage instructions, handling instructions and any additional processing instructions; the release of labeling for use must be documented under Clause 4.2.5; and operations must prevent mixups, with inspection results likewise documented. Legacy Part 820 handled this at 820.120 and 820.130; the QMSR preserved it as a supplemental provision precisely because ISO 13485 does not carry equivalent specificity.
Two consequences follow that organizations often get backwards. First, FDA does not certify anyone to ISO 13485, and does not require a certificate. It requires compliance with Part 820 and verifies that by inspection. A certification body’s ISO 13485 certificate is evidence a manufacturer may find useful, but it is not the U.S. compliance mechanism. Second, the QMSR is not a like-for-like translation: a system that conforms to ISO 13485 but has never implemented §§ 820.3, 820.10(b)–(d), 820.35 and 820.45 is not compliant, and those five provisions are short enough to gap-assess in an afternoon.
How ISO 13485 relates to EU MDR and IVDR
In the European Union, the Medical Device Regulation (MDR, Regulation (EU) 2017/745) and In Vitro Diagnostic Regulation (IVDR, Regulation (EU) 2017/746) are the binding legal instruments a manufacturer must satisfy to place a device on the EU market — they are law, not a voluntary standard. ISO 13485 certification is not, by itself, legally sufficient to demonstrate MDR/IVDR conformity, but it is treated as strong supporting evidence of an adequate QMS, and Notified Bodies conducting MDR/IVDR conformity assessments commonly combine their audit with an ISO 13485 certification audit in a single process. The regulation and the standard address different questions: MDR/IVDR sets the legal requirements a device and its manufacturer must meet (classification, clinical evaluation, technical documentation, post-market surveillance, vigilance); ISO 13485 defines the quality-system infrastructure — including design controls, risk management, and document control — that makes it possible to demonstrate and sustain that conformity over the device’s lifecycle.
How the audit itself is structured
Initial certification to a management-system standard normally runs in two stages: a stage 1 readiness review, largely documentary, which examines the quality manual, scope, non-application justifications, internal audit and management review records, and confirms the organization is ready to be assessed; and a stage 2 audit, on site, which samples the implementation of each clause against objective evidence. Certificates are typically issued for a three-year cycle with surveillance audits in the intervening years and a recertification audit before expiry. The mechanics of that process — how the scope statement on the certificate is fixed, the IAF MD 9 table that governs how many audit days you are quoted, and the six-month deadline a major nonconformity puts on the certification decision — are covered in CASRAI’s guide to the ISO 13485 certification process, stage by stage. Findings are graded — the major/minor distinction, and the nonconformity report and corrective-action response cycle that follows, are covered in CASRAI’s nonconformity guide.
Running in parallel is the Medical Device Single Audit Program (MDSAP), under which an MDSAP-recognised auditing organization conducts a single regulatory audit intended to satisfy the requirements of several participating regulators at once. Per FDA’s MDSAP page, the participating members are Australia’s Therapeutic Goods Administration, Brazil’s ANVISA, Health Canada, Japan’s MHLW and PMDA, and the U.S. FDA; the EU, Singapore’s HSA, the UK’s MHRA and the WHO Prequalification of IVDs Programme participate as official observers. The provision that matters most to a U.S. manufacturer is FDA’s statement that it may continue to accept MDSAP audit reports as a substitute for routine Agency inspections — firms with Electronic Product Radiation Control activities remain subject to FDA inspection for those activities regardless. MDSAP is a distinct audit against a published model, not the same thing as an ISO 13485 certification audit, though certification bodies commonly run them together.
Frequently asked questions
Is ISO 13485 mandatory?
ISO 13485 itself is a voluntary international standard, not a law. It becomes effectively mandatory in practice because regulators and market requirements point to it: the EU’s MDR/IVDR conformity-assessment process relies heavily on it, many national regulators outside the EU and US require or strongly favor it, and as of February 2, 2026 the FDA’s QMSR incorporates ISO 13485:2016 by reference for U.S. device manufacturers.
Does the QMSR mean I need an ISO 13485 certificate to sell in the U.S.?
No. The QMSR requires manufacturers to document a quality management system complying with ISO 13485 and the supplemental provisions in 21 CFR Part 820 — it does not require third-party certification, and FDA verifies compliance by inspection rather than by reviewing a certificate. A certificate can be commercially useful and is required or expected in other markets, but conformity to the standard and possession of a certificate are different things. The one place a third-party audit substitutes for an FDA inspection is MDSAP, where FDA has stated it may accept MDSAP audit reports in place of routine Agency inspections.
Do I need ISO 13485 for a research prototype that isn’t a commercial device yet?
Not immediately, but design-control discipline is worth adopting early. Because the design history file must show the design’s development from the start, retrofitting inputs, verification, and review records after the fact is far harder than maintaining them contemporaneously as the design work happens — a lab that expects a device concept to eventually seek regulatory clearance benefits from establishing basic design-control habits well before formal QMS certification is pursued.
Is ISO 13485 certification the same as FDA clearance or approval?
No. ISO 13485 certification (or QMSR conformance) demonstrates that a manufacturer’s quality management system meets the standard’s requirements. It says nothing on its own about whether a specific device has received FDA marketing authorization (510(k) clearance, De Novo, or PMA approval) or EU MDR/IVDR conformity for that device — those are separate, device-specific regulatory determinations that typically rely on, but are distinct from, QMS certification.
What’s the difference between ISO 13485 and ISO 9001 in one sentence?
ISO 9001 is a general-purpose QMS standard organized around customer satisfaction and continual improvement, while ISO 13485 is a standalone, differently-structured standard built specifically to support regulatory compliance and product safety for medical devices, with mandatory risk-management and design-control obligations ISO 9001 does not impose.
Which ISO 13485 clauses generate the most audit findings?
There is no authoritative public dataset of ISO 13485 nonconformity frequency, so treat any ranked list — including this one — as practitioner observation rather than measured fact. The clauses that most reliably produce gaps in systems migrated from ISO 9001:2015 are the ones ISO 9001 no longer requires: documented procedures at named clauses, the quality manual (4.2.2), the medical device file (4.2.3), the management representative (5.5.2) and preventive action (8.5.3). The clauses that most reliably produce gaps in otherwise-mature device systems are the evidence-heavy ones: training effectiveness evaluation (6.2), process validation and its revalidation triggers (7.5.6), traceability under time pressure (7.5.9), and the documented rationale for complaint non-reportability decisions (8.2.2 and 8.2.3).
Where can I read the actual text of ISO 13485:2016?
The standard is copyrighted and is not freely available; it must be purchased from ISO or a national member body (ANSI in the U.S., BSI in the UK, DIN in Germany, and so on). Note that because 21 CFR 820.7 incorporates it by reference, the incorporated edition is also available for inspection at FDA and at the National Archives and Records Administration under the reading-room provisions in 1 CFR part 51 — the details are stated in the text of § 820.7 itself.
Related CASRAI resources
- Laboratory Compliance & Quality — the full cluster overview, including how GxP, accreditation, and device-quality frameworks fit together.
- ISO/IEC 17025 — the accreditation standard for testing and calibration laboratories, and the accreditation-vs-certification distinction in the opposite direction.
- Nonconformity: major vs. minor and the NCR/NCAR process — how findings raised against the clauses above are graded and closed.
- 21 CFR — where Part 820 sits among the other device, drug and research parts of Title 21.
- ISO 14971 and the risk management file — the risk management method Clause 7.1 requires you to apply, what the file must trace hazard by hazard, and where ISO/TR 24971 supplies the guidance.
- 21 CFR Part 820: subpart-by-subpart map and QMSR transition status — the U.S. regulation itself: what each reserved subpart used to require, what DMR, DHR and DHF are called now, and the inspection change that landed with it.
- CAPA — the corrective/preventive distinction that Clauses 8.5.2 and 8.5.3 keep separate.
- Quality agreements and supplier audits — the Clause 4.1.5 and 7.4 evidence layer.
- GxP compliance — how the device QMS framework sits alongside GLP, GCP, GMP and GDP.
- IEC 62304 software lifecycle processes — the software-specific lifecycle standard that operates inside an ISO 13485 quality management system.








