International standard for Medical Device Quality Management Systems.
Overview
What is ISO 13485?
ISO 13485 is an internationally recognized quality management system standard specifically developed for organizations involved in the design, development, production, installation, and servicing of medical devices and related services. The standard establishes requirements for a quality management system in which an organization needs to demonstrate its ability to provide medical devices and related services that consistently meet customer requirements and applicable regulatory requirements.
Unlike ISO 9001, which emphasizes continual improvement driven by customer satisfaction, ISO 13485 is focused primarily on the consistent fulfillment of customer and regulatory requirements. The standard addresses the specific needs of the medical device industry, including requirements for risk management throughout the product lifecycle, validation and verification of processes and equipment, traceability of devices and components, and documented control of processes that may affect product safety and performance.
ISO 13485 is applicable to organizations at all stages of the medical device supply chain and is widely used as a basis for regulatory submissions, supplier qualification, and market access programs across the European Union, Canada, the United States, Australia, Japan, and other regulated markets.
Key Themes
What does the standard focus on?
Medical Device Quality
The standard establishes a comprehensive framework for managing quality across the full medical device lifecycle, from design and development through production, packaging, labeling, storage, distribution, installation, and servicing.
Regulatory Compliance
ISO 13485 is structured to align with medical device regulatory requirements across key markets, requiring organizations to identify applicable regulations, integrate regulatory obligations into the QMS, and maintain current knowledge of requirements affecting their products and operations.
Risk Management
The standard requires the integration of risk management principles throughout the product and process lifecycle, addressing risks to patient safety, device performance, and regulatory compliance in a structured, documented, and systematic manner consistent with ISO 14971.
Product Safety
Requirements covering design controls, production controls, process validation, incoming inspection, and post-market activities are oriented toward ensuring that medical devices perform as intended and do not pose unacceptable risks to patients, users, or third parties.
Validation and Verification
Validation and verification of products, processes, software, and equipment are fundamental requirements of the standard, ensuring that critical processes consistently produce outputs meeting predetermined specifications before devices are released for use.
Traceability
Organizations must establish and maintain traceability systems enabling the identification of devices, components, materials, and production history. Traceability requirements support effective post-market surveillance, complaint investigations, and field safety corrective actions.
Documented Processes
ISO 13485 places significant emphasis on documented procedures, work instructions, and records as the foundation for consistent process execution, regulatory compliance, and audit readiness across all quality-affecting activities.
Continual Improvement
The standard requires systematic improvement of QMS effectiveness through corrective and preventive action processes, internal audit, management review, analysis of data, and the monitoring of post-market feedback and complaint data.
Applicability
Who typically implements ISO 13485?
Medical Device Manufacturers
Organizations that produce finished medical devices for sale or supply in regulated markets, for whom ISO 13485 certification is typically required or expected as a precondition for regulatory approval, market access, and customer qualification.
Medical Device Designers and Developers
Organizations involved in the design and development of medical devices, including contract design organizations, that require a structured quality management framework to govern design controls, risk management, and design verification and validation activities.
Medical Device Distributors
Organizations that import, store, and distribute medical devices and are required by applicable regulations or by their supply chain partners to demonstrate a quality management system meeting ISO 13485 requirements.
Medical Device Service Providers
Organizations providing installation, maintenance, repair, or servicing of medical devices, where quality management requirements apply to service delivery, spare parts management, and documentation of service activities.
Component Manufacturers
Manufacturers of components, sub-assemblies, and materials that are incorporated into finished medical devices, where supply chain qualification requirements oblige them to demonstrate compliance with ISO 13485.
Sterilization Service Providers
Organizations providing sterilization services for medical devices, for whom ISO 13485 certification is typically required alongside specific sterilization process standards to demonstrate quality management of critical processes.
Contract Manufacturers
Contract manufacturing organizations producing medical devices or device components to customer specifications, where the device manufacturer requires evidence that production quality is managed under a certified ISO 13485 quality management system.
Healthcare Technology Organizations
Organizations developing healthcare software, diagnostic tools, or other healthcare technology products that meet the regulatory definition of a medical device, and that are subject to regulatory quality management system requirements.
Installers
Organizations that install medical devices at customer sites, particularly complex capital equipment, where installation activities form part of the regulated supply and are subject to quality management requirements.
Supply Chain Organizations
Broader medical device supply chain participants, including logistics providers, specialist packaging suppliers, and calibration service providers, who are required by their customers to demonstrate ISO 13485 certification as a condition of supply.
Benefits
Why organizations pursue certification
Improved Product Quality
Structured design controls, process validation, incoming inspection, and in-process quality controls reduce the incidence of product defects, non-conforming outputs, and quality-related field issues across the device lifecycle.
Enhanced Regulatory Confidence
ISO 13485 certification is widely recognized by regulatory authorities as evidence of a structured quality management system capable of consistently meeting device design, production, and post-market obligations.
Improved Patient Safety
Systematic risk management, validation requirements, and post-market surveillance processes reduce the likelihood of patient harm arising from device failures, misuse, or inadequately controlled production processes.
Better Risk Management
Integration of risk management throughout the QMS ensures that potential hazards to patients, users, and third parties are identified, evaluated, and controlled in a documented and auditable manner consistent with ISO 14971 requirements.
Improved Process Consistency
Documented procedures, process validation, equipment qualification, and personnel competence requirements ensure that quality-affecting processes are performed consistently, reducing variability and the risk of non-conforming product.
Greater Market Access
ISO 13485 certification is accepted or required in multiple key markets, including the EU, Canada, and Australia, as evidence of a compliant quality management system and a practical foundation for obtaining and maintaining marketing authorisations.
Enhanced Customer Confidence
Independent certification provides customers, healthcare providers, and procurement organizations with assurance that the organization’s quality management system has been assessed against an internationally recognized standard.
Stronger Supplier and Stakeholder Trust
Certification supports supplier qualification processes and strengthens confidence among supply chain partners, distributors, and regulatory bodies in the organization’s ability to manage quality consistently across all relevant activities.
Support for Regulatory Approval Processes
A certified ISO 13485 QMS provides documentary evidence required to support regulatory submissions, CE marking, Health Canada licenses, and other market authorisation applications for medical devices.
Regulatory Context
Is ISO 13485 certification required?
ISO 13485 certification is generally voluntary as a matter of international standard, but regulatory authorities in many major markets require or strongly expect medical device manufacturers and supply chain participants to maintain a quality management system meeting ISO 13485 or equivalent requirements as a precondition for obtaining and maintaining regulatory approval to market medical devices.
In Canada, the Medical Device Regulations require manufacturers to hold an ISO 13485 certificate issued by a Registrar recognized by Health Canada. In the European Union, ISO 13485 is harmonized under the Medical Device Regulation and In Vitro Diagnostic Regulation, and conformance is used by Notified Bodies to assess whether a manufacturer’s quality management system meets regulatory requirements. In Australia, the Therapeutic Goods Administration recognizes ISO 13485 as the baseline quality management system standard for medical device manufacturers.
Even where certification is not formally mandated, ISO 13485 is frequently required by customers, distributors, hospital procurement programs, and supply chain qualification processes as a non-negotiable condition of supplier approval. Organizations without a certified QMS may find market access and commercial opportunities in the medical device sector significantly restricted.
Certification Journey
How certification works
01
Application
The organization submits an application identifying its scope of activities, device categories, applicable regulatory markets, sites, and the specific standard requirements applicable to its products and processes.
02
Application Review
Exelera reviews the application, assesses the proposed scope, identifies applicable regulatory requirements, product risk classifications, and any specific audit requirements associated with the organization’s device activities, and prepares the certification proposal and audit program.
03
Stage 1 Audit
Review of the QMS documentation including the quality manual, procedures, design and development documentation, risk management files, validation records, and organizational readiness for the Stage 2 conformance assessment.
04
Stage 2 Audit
On-site evaluation of the implementation and effectiveness of the QMS, including design controls, risk management integration, production and process controls, validation activities, traceability systems, and conformity with all applicable standard requirements.
05
Certification Decision
Independent review of audit findings by a Certification Decision Maker not involved in the audit, followed by a formal certification decision.
06
Certificate Issuance
Following a positive certification decision, Exelera issues the certificate and publishes the organization on the public certification register. Certificate details include scope, standard, and effective dates.
07
Surveillance Audit — Year 1
Scheduled surveillance visit conducted no later than 12 months after the certification decision to verify continued conformance, assess changes to the QMS or device scope, and review post-market and corrective action performance.
08
Surveillance Audit — Year 2
Continued verification of QMS implementation, design change controls, validation maintenance, traceability systems, and application of corrective and preventive actions from prior audit cycles.
09
Recertification Audit
Comprehensive reassessment of the full QMS scope conducted prior to renewal of the certification cycle at the end of year three, evaluating the continued effectiveness of all quality management system elements.
10
Certification Renewal
Following a successful recertification audit and positive certification decision, a new three-year certification cycle commences.
FAQ
Common questions
ISO 9001 is a general quality management system standard applicable to any type of organization, emphasizing customer satisfaction and continual improvement driven by organizational performance data. ISO 13485 is a sector-specific standard developed for organizations in the medical device industry, with a primary focus on consistently meeting regulatory requirements and demonstrating fitness for purpose across the device lifecycle. ISO 13485 contains additional requirements specific to medical devices, including mandatory risk management integration, validation and verification of special processes, traceability obligations, and post-market requirements that are not present in ISO 9001. An organization may hold both certifications, but ISO 13485 is the recognized standard for medical device quality management system conformance.
Any organization involved in any stage of the medical device lifecycle can implement ISO 13485, including manufacturers, designers, component suppliers, distributors, sterilization providers, service organizations, installers, and supply chain participants whose activities may affect device safety or performance. The standard is designed to allow organizations to exclude clauses not relevant to their specific activities, provided the exclusions do not affect the organization’s ability to meet its regulatory and customer obligations. The scope of certification reflects the organization’s specific activities rather than applying the full standard uniformly to all participants.
No. ISO 13485 certification does not replace, substitute for, or confer regulatory approval for specific medical devices or markets. It demonstrates that the organization’s quality management system meets the requirements of the standard, and it is accepted by regulatory authorities in several markets as evidence of a structured QMS as part of broader regulatory compliance. Organizations remain responsible for obtaining all applicable regulatory approvals, registrations, and marketing authorisations for their specific devices and intended markets, which involve additional technical, clinical, and regulatory requirements beyond QMS certification.
Yes. ISO 13485 can be implemented by distributors and importers of medical devices as well as by manufacturers. Distributors may be required to demonstrate compliance by applicable regulations — for example, under the EU Medical Device Regulation, economic operators including importers and distributors have specific obligations. The scope of a distributor’s certification will reflect the activities undertaken, typically covering storage, handling, distribution, complaint management, and post-market obligations, with design and development clauses excluded where not applicable.
The time required depends on the organization’s size, device risk classification, complexity of processes, geographic scope, and the maturity of its existing quality management documentation. For a small organization with established quality documentation and moderate device risk, the process from initial application to certificate issuance typically takes between four and eight months. Organizations with higher-risk devices, complex design and development activities, multiple sites, or significant validation requirements may require a longer program.
Following initial certification, surveillance audits are conducted annually — with the first surveillance no later than 12 months after the certification decision and the second no later than 24 months. A full recertification audit is required at the end of the three-year certification cycle before the certificate can be renewed. Unannounced audits may also form part of the surveillance program for certain market-specific regulatory requirements.
ISO 13485 certificates are valid for three years from the date of the certification decision, subject to satisfactory completion of annual surveillance audits. Certification lapses if surveillance audits are not completed within the required timeframe, or if the certificate is suspended or withdrawn due to nonconformity or other grounds. Some regulatory programs impose additional requirements governing certificate maintenance.
Certification transfers are possible in most cases. Exelera will review the existing certificate, audit history, nonconformity status, and current conformance evidence as part of the transfer assessment. Transfer audits are typically shorter than initial certification audits, reflecting the documented history of conformance. Contact Exelera for guidance on the transfer process and required documentation, including any specific requirements associated with market recognition programs.
Remote audit activities are possible for certain elements of the assessment, including documentation review, interviews, and software or system walkthroughs. Exelera’s standard approach for ISO 13485 audits requires on-site audit activities for key process areas, particularly for Stage 2 and recertification audits, given the importance of directly observing production processes, special processes, and physical verification activities. Some regulatory recognition programs impose additional restrictions on remote auditing. Remote auditing options are discussed and agreed as part of audit planning.
Applications can be submitted through the Exelera website or by contacting the certification team directly. The application process involves providing information about the organization’s scope of activities, device types and risk classifications, target regulatory markets, number of sites, employee headcount, and existing quality management documentation. Exelera will review the application, identify any specific regulatory or program requirements applicable to the scope, and prepare a certification proposal for consideration.
Related Standards
Standards commonly implemented alongside ISO 13485