What is ISO 13485?
ISO 13485:2016 specifies quality management system requirements for organisations involved in the life cycle of a medical device. The current, third edition was published in 2016. Unlike ISO 9001, the standard does not require demonstrating continual business improvement — the priorities are maintaining the effectiveness of the system, device safety and meeting regulatory requirements, with decisions grounded in risk management.
The structure spans clauses 4-8: the quality management system and documentation (including the medical device file and QMS software validation), management responsibility, resource management, product realisation (from planning and design through purchasing to production and validation of special processes), and measurement, analysis and improvement — with complaints, reporting to regulatory authorities, control of nonconforming product and the CAPA system.
Distinctive requirements include: a medical device file for each device type, validation of processes whose output cannot be fully verified by inspection (for example sterilisation), batch traceability — extended for implantable devices — and complaint handling and advisory notices with notification of regulatory authorities.
Who is it for?
The standard addresses the entire medical device value chain: manufacturers, but also suppliers of components and services (for example sterilisation, contract manufacturing, distribution, servicing), importers and authorised representatives. The organisation declares its regulatory role in the system and applies the requirements accordingly — justified exclusions from clause 7 are permitted (for example design at a contract manufacturer).
It applies to classic physical devices as well as software as a medical device (SaMD) and in vitro diagnostic devices. For software companies ISO 13485 works hand in hand with IEC 62304 (medical device software life cycle) and ISO 14971 (risk management) — the QMS is the framework within which those processes operate.
ISO 13485, the MDR and other markets
In the European Union, the Medical Device Regulation (EU) 2017/745 requires manufacturers to operate a quality management system (Article 10(9)). The European version of the standard — EN ISO 13485:2016 — is harmonised under the MDR and IVDR, so applying it gives a presumption of conformity with the requirements it covers. For most device classes (I sterile and with a measuring function, IIa, IIb, III) the quality system is assessed by a notified body as part of conformity assessment — an ISO 13485 certificate does not replace that assessment, but it is its natural foundation and makes it considerably easier.
Beyond the EU the standard is equally important: the MDSAP (Medical Device Single Audit Program) bases its audit on ISO 13485 and lets a single audit cover the regulatory requirements of the United States, Canada, Brazil, Japan and Australia — with Canada requiring MDSAP certification from manufacturers of class II-IV devices. The US FDA has harmonised its quality system regulation with ISO 13485, incorporating the standard by reference in the updated QMSR (21 CFR Part 820).
What does certification look like?
The ISO 13485 certificate is issued by an accredited certification body after a two-stage audit: Stage 1 (documentation and readiness review) and Stage 2 (on-site implementation audit — production, batch records, complaints, CAPA, process validations). The certificate is valid for 3 years, with annual surveillance audits and recertification at the end of the cycle. If the device requires notified body assessment under the MDR, the quality system audit is often combined with the ISO 13485 certification audit — saving time and cost.
ISO 13485 audits are technically deeper than typical ISO 9001 audits: the auditor walks the production line with batch records (device history record), runs “raw material to customer” traceability exercises, examines special process validations and analyses complaints and CAPAs in detail. Findings most often concern QMS software validation, completeness of the medical device file, statistical rationale for sample sizes, and overdue CAPAs.
How long does it take and what does it cost?
Implementing an ISO 13485 system typically takes 6 to 12 months — longer than ISO 9001, because the standard demands deep technical documentation: the medical device file, risk management files, process and software validations, plus a working complaint and CAPA process. A medical start-up building the system from scratch alongside device development can align the implementation with preparing MDR technical documentation — much of the work is shared.
The cost comprises the certification audit and surveillance audits (audit days depend on headcount, scope and special processes), optional consultant or test house support, and your own team’s time — usually the largest item. For MDR manufacturers, separate notified body fees for device conformity assessment come on top. A well-organised, electronic quality system significantly shortens both the implementation and the audits themselves.
How does Guardiso help?
Guardiso organises your medical device quality system in one place — from the first self-assessment, through documentation and evidence, to the certification body audit.
- All 61 requirements of the standard (clauses 4-8) seeded automatically when you enable it — with implementation statuses and assigned owners.
- Quality policies and procedures generated from templates, with versioning, approval and full document control.
- A risk register supporting the risk-based approach — linking risks to requirements, controls and evidence.
- Recurring tasks that guard deadlines: management reviews, internal audits, supplier re-evaluations, CAPA reviews and revalidations.
- Compliance evidence collected in one place — training records, validation protocols, data analyses — ready to show the auditor.
- An auditor portal: the certification or notified body gets controlled access to documentation without files being emailed around.
- Cross-mapping to related frameworks (ISO 9001, IEC 62304, ISO 27001) — shared system elements are done once.
