ISO 13485 Medical Devices Quality Management System
ISO 13485 is the internationally recognised standard for quality management systems (QMS) specific to the medical device industry. It provides a framework for organisations involved in the design, production, installation, and servicing of medical devices. Unlike ISO 9001, ISO 13485 places heavy emphasis on regulatory compliance, risk management, and traceability. This article covers what ISO 13485 is, how it compares to ISO 9001, and the key requirements for certification.
What Is ISO 13485?
ISO 13485:2016 specifies requirements for a QMS where an organisation needs to demonstrate its ability to provide medical devices and related services that consistently meet customer and regulatory requirements. It is harmonised with many global regulatory frameworks, including the European Medical Device Regulation (EU MDR) and the requirements of various national competent authorities.
The standard applies to:
- Manufacturers of medical devices.
- Design and development organisations.
- Sterilisation service providers.
- Distributors and importers.
- Organisations that outsource manufacturing or services.
ISO 13485 vs. ISO 9001: Key Differences
Although ISO 13485 is built on the same high-level structure as ISO 9001, there are critical differences driven by regulatory requirements in the medical device industry.
| Requirement | ISO 9001:2015 | ISO 13485:2016 |
|---|---|---|
| Customer satisfaction | Central focus – measured and monitored. | Required but balanced with regulatory compliance. |
| Risk management | Risk-based thinking throughout. | Formal risk management per ISO 14971 required. |
| Design and development | General design controls. | Detailed design controls with design history file (DHF). |
| Traceability | Required where appropriate. | Full traceability, including implantable device registry. |
| Validation | Validation of processes where output cannot be verified. | Mandatory process validation (sterilisation, clean room, software). |
| Corrective actions (CAPA) | Corrective action required. | Formal CAPA system with documented procedures. |
| Regulatory documentation | Not emphasised. | Regulatory file, technical file, and submission records. |
Regulatory Requirements and Global Alignment
ISO 13485 is the foundation for regulatory compliance in most global markets. It aligns with or is a prerequisite for the following regulatory frameworks:
| Market | Regulatory Framework | Relationship to ISO 13485 |
|---|---|---|
| European Union | EU MDR 2017/745 | ISO 13485 is harmonised (EN ISO 13485). Required for CE marking. |
| United States | FDA 21 CFR 820 (QSR) | FDA recognises ISO 13485; new QSR aligns closely. |
| Canada | CMDR SOR/98-282 | ISO 13485 is a requirement under the Canadian Medical Devices Regulations. |
| Australia | TGA regulations | ISO 13485 certification is accepted for TGA conformity. |
| Japan | MHLW / PAL | ISO 13485 is the basis for QMS under Japanese regulations. |
Design Controls
Design controls are one of the most rigorous sections of ISO 13485. The standard requires organisations to establish, document, and maintain a design and development process that includes:
- Design planning – define stages, responsibilities, and review points.
- Design inputs – document functional, performance, safety, and regulatory requirements.
- Design outputs – specifications, drawings, and acceptance criteria.
- Design review – systematic reviews at each stage.
- Design verification – confirm outputs meet inputs.
- Design validation – confirm the device meets user needs and intended uses.
- Design transfer – ensure designs are correctly translated into production.
- Design changes – control changes through a documented process.
All of this must be captured in a design history file (DHF).
Risk Management and ISO 14971
ISO 13485 mandates that risk management is applied throughout the QMS. The standard references ISO 14971, the dedicated standard for medical device risk management. Key requirements include:
- Establishing a risk management process with defined responsibilities.
- Hazard identification and risk estimation.
- Risk evaluation and control.
- Evaluation of residual risk.
- Risk management review and documentation in a risk management file.
- Production and post-production monitoring of risk.
Corrective and Preventive Actions (CAPA)
CAPA is the engine of continual improvement in ISO 13485. The standard requires a documented CAPA procedure that includes:
- Identification of non-conformities (complaints, audit findings, process deviations).
- Investigation to determine root cause.
- Action planning to correct and prevent recurrence.
- Verification of effectiveness.
- Management review of CAPA trends.
| CAPA Step | Description | Documentation |
|---|---|---|
| Identification | Capture non-conformity from any source. | Non-conformity report, complaint record. |
| Evaluation | Determine if investigation is required; assess risk. | CAPA request form. |
| Investigation | Root cause analysis (5 Whys, fishbone, FMEA). | Investigation report. |
| Action plan | Define corrective and preventive actions. | CAPA plan. |
| Implementation | Execute actions with target dates. | Implementation records. |
| Verification | Check effectiveness of actions. | Effectiveness check report. |
| Closure | Document final approval and learnings. | CAPA closure record. |
Sterilisation Validation
For devices labelled as sterile, ISO 13485 requires rigorous validation of sterilisation processes. This applies whether sterilisation is performed in-house or outsourced. Requirements include:
- Selection and qualification of sterilisation methods (ethylene oxide, gamma, steam, etc.).
- Installation qualification (IQ), operational qualification (OQ), and performance qualification (PQ).
- Routine monitoring and control of sterilisation parameters.
- Biological indicator testing and release criteria.
- Records of each sterilisation cycle.
Labelling Requirements
ISO 13485 includes specific labelling requirements to ensure safety and regulatory compliance. Labels and accompanying documentation must:
- Be reviewed and approved before release.
- Include all applicable regulatory symbols and statements.
- Be controlled for accuracy and version.
- Comply with national/regional labelling regulations.
- Include warnings, contraindications, and instructions for use.
Regulatory Submissions and Technical Files
A properly implemented ISO 13485 QMS generates the documentation needed for regulatory submissions. The standard requires the maintenance of a regulatory file for each device family. This file should contain:
- Device description and intended purpose.
- Design history file (DHF).
- Risk management file (ISO 14971).
- Clinical evaluation report (CER).
- Sterilisation validation records.
- Labelling and instructions for use.
- Declaration of conformity.
- Post-market surveillance and vigilance records.
Frequently Asked Questions
Do we need both ISO 9001 and ISO 13485 certification?
ISO 13485 is the medical-device-specific QMS standard. If you are a medical device manufacturer, ISO 13485 is typically required by regulators and notified bodies. ISO 9001 is broader and may be unnecessary if you hold ISO 13485 certification, unless your customers specifically require it.
Is ISO 13485 mandatory for CE marking under EU MDR?
Yes. ISO 13485 (as EN ISO 13485) is harmonised under the EU MDR. Certification by a notified body against ISO 13485 is a prerequisite for CE marking for most classes of medical devices.
What is the relationship between ISO 13485 and ISO 14971?
ISO 13485 requires that risk management is applied throughout the QMS. ISO 14971 provides the specific methodology for medical device risk management. Organisations certified to ISO 13485 must demonstrate conformity with ISO 14971 principles.
What is a design history file (DHF)?
The DHF is a collection of records that describe the design history of a medical device. It includes design plans, input specifications, output specifications, verification and validation results, design review minutes, and design transfer records.
How long does ISO 13485 certification take?
Depending on the complexity of your organisation and existing QMS, certification typically takes six to twelve months. This includes gap analysis, documentation development, implementation, internal audit, and the certification audit.
What are the main challenges in ISO 13485 implementation?
Common challenges include establishing robust design controls, implementing a CAPA system that addresses root causes effectively, maintaining supplier controls, and building sufficient documentation for regulatory submissions. Many organisations benefit from external consultancy to navigate these areas.
Get ISO 13485 Certified with Bitrixme
ISO 13485 certification opens doors to global medical device markets. Bitrixme provides end-to-end QMS consultancy tailored to medical device manufacturers, from gap analysis through certification audit support. We serve clients across the Middle East, Europe, and Asia.
Or reach us on WhatsApp: +973 3659 9909