iso-13485-medical-devices

By July 25th, 2026ISO Audit And Certificate7 min read

ISO 13485 Medical Devices Quality Management System

ISO 13485 is the internationally recognised standard for quality management systems (QMS) specific to the medical device industry. It provides a framework for organisations involved in the design, production, installation, and servicing of medical devices. Unlike ISO 9001, ISO 13485 places heavy emphasis on regulatory compliance, risk management, and traceability. This article covers what ISO 13485 is, how it compares to ISO 9001, and the key requirements for certification.

What Is ISO 13485?

ISO 13485:2016 specifies requirements for a QMS where an organisation needs to demonstrate its ability to provide medical devices and related services that consistently meet customer and regulatory requirements. It is harmonised with many global regulatory frameworks, including the European Medical Device Regulation (EU MDR) and the requirements of various national competent authorities.

The standard applies to:

  • Manufacturers of medical devices.
  • Design and development organisations.
  • Sterilisation service providers.
  • Distributors and importers.
  • Organisations that outsource manufacturing or services.

ISO 13485 vs. ISO 9001: Key Differences

Although ISO 13485 is built on the same high-level structure as ISO 9001, there are critical differences driven by regulatory requirements in the medical device industry.

RequirementISO 9001:2015ISO 13485:2016
Customer satisfactionCentral focus – measured and monitored.Required but balanced with regulatory compliance.
Risk managementRisk-based thinking throughout.Formal risk management per ISO 14971 required.
Design and developmentGeneral design controls.Detailed design controls with design history file (DHF).
TraceabilityRequired where appropriate.Full traceability, including implantable device registry.
ValidationValidation of processes where output cannot be verified.Mandatory process validation (sterilisation, clean room, software).
Corrective actions (CAPA)Corrective action required.Formal CAPA system with documented procedures.
Regulatory documentationNot emphasised.Regulatory file, technical file, and submission records.

Regulatory Requirements and Global Alignment

ISO 13485 is the foundation for regulatory compliance in most global markets. It aligns with or is a prerequisite for the following regulatory frameworks:

MarketRegulatory FrameworkRelationship to ISO 13485
European UnionEU MDR 2017/745ISO 13485 is harmonised (EN ISO 13485). Required for CE marking.
United StatesFDA 21 CFR 820 (QSR)FDA recognises ISO 13485; new QSR aligns closely.
CanadaCMDR SOR/98-282ISO 13485 is a requirement under the Canadian Medical Devices Regulations.
AustraliaTGA regulationsISO 13485 certification is accepted for TGA conformity.
JapanMHLW / PALISO 13485 is the basis for QMS under Japanese regulations.

Design Controls

Design controls are one of the most rigorous sections of ISO 13485. The standard requires organisations to establish, document, and maintain a design and development process that includes:

  • Design planning – define stages, responsibilities, and review points.
  • Design inputs – document functional, performance, safety, and regulatory requirements.
  • Design outputs – specifications, drawings, and acceptance criteria.
  • Design review – systematic reviews at each stage.
  • Design verification – confirm outputs meet inputs.
  • Design validation – confirm the device meets user needs and intended uses.
  • Design transfer – ensure designs are correctly translated into production.
  • Design changes – control changes through a documented process.

All of this must be captured in a design history file (DHF).

Risk Management and ISO 14971

ISO 13485 mandates that risk management is applied throughout the QMS. The standard references ISO 14971, the dedicated standard for medical device risk management. Key requirements include:

  • Establishing a risk management process with defined responsibilities.
  • Hazard identification and risk estimation.
  • Risk evaluation and control.
  • Evaluation of residual risk.
  • Risk management review and documentation in a risk management file.
  • Production and post-production monitoring of risk.

Corrective and Preventive Actions (CAPA)

CAPA is the engine of continual improvement in ISO 13485. The standard requires a documented CAPA procedure that includes:

  • Identification of non-conformities (complaints, audit findings, process deviations).
  • Investigation to determine root cause.
  • Action planning to correct and prevent recurrence.
  • Verification of effectiveness.
  • Management review of CAPA trends.
CAPA StepDescriptionDocumentation
IdentificationCapture non-conformity from any source.Non-conformity report, complaint record.
EvaluationDetermine if investigation is required; assess risk.CAPA request form.
InvestigationRoot cause analysis (5 Whys, fishbone, FMEA).Investigation report.
Action planDefine corrective and preventive actions.CAPA plan.
ImplementationExecute actions with target dates.Implementation records.
VerificationCheck effectiveness of actions.Effectiveness check report.
ClosureDocument final approval and learnings.CAPA closure record.

Sterilisation Validation

For devices labelled as sterile, ISO 13485 requires rigorous validation of sterilisation processes. This applies whether sterilisation is performed in-house or outsourced. Requirements include:

  • Selection and qualification of sterilisation methods (ethylene oxide, gamma, steam, etc.).
  • Installation qualification (IQ), operational qualification (OQ), and performance qualification (PQ).
  • Routine monitoring and control of sterilisation parameters.
  • Biological indicator testing and release criteria.
  • Records of each sterilisation cycle.

Labelling Requirements

ISO 13485 includes specific labelling requirements to ensure safety and regulatory compliance. Labels and accompanying documentation must:

  • Be reviewed and approved before release.
  • Include all applicable regulatory symbols and statements.
  • Be controlled for accuracy and version.
  • Comply with national/regional labelling regulations.
  • Include warnings, contraindications, and instructions for use.

Regulatory Submissions and Technical Files

A properly implemented ISO 13485 QMS generates the documentation needed for regulatory submissions. The standard requires the maintenance of a regulatory file for each device family. This file should contain:

  • Device description and intended purpose.
  • Design history file (DHF).
  • Risk management file (ISO 14971).
  • Clinical evaluation report (CER).
  • Sterilisation validation records.
  • Labelling and instructions for use.
  • Declaration of conformity.
  • Post-market surveillance and vigilance records.

Frequently Asked Questions

Do we need both ISO 9001 and ISO 13485 certification?

ISO 13485 is the medical-device-specific QMS standard. If you are a medical device manufacturer, ISO 13485 is typically required by regulators and notified bodies. ISO 9001 is broader and may be unnecessary if you hold ISO 13485 certification, unless your customers specifically require it.

Is ISO 13485 mandatory for CE marking under EU MDR?

Yes. ISO 13485 (as EN ISO 13485) is harmonised under the EU MDR. Certification by a notified body against ISO 13485 is a prerequisite for CE marking for most classes of medical devices.

What is the relationship between ISO 13485 and ISO 14971?

ISO 13485 requires that risk management is applied throughout the QMS. ISO 14971 provides the specific methodology for medical device risk management. Organisations certified to ISO 13485 must demonstrate conformity with ISO 14971 principles.

What is a design history file (DHF)?

The DHF is a collection of records that describe the design history of a medical device. It includes design plans, input specifications, output specifications, verification and validation results, design review minutes, and design transfer records.

How long does ISO 13485 certification take?

Depending on the complexity of your organisation and existing QMS, certification typically takes six to twelve months. This includes gap analysis, documentation development, implementation, internal audit, and the certification audit.

What are the main challenges in ISO 13485 implementation?

Common challenges include establishing robust design controls, implementing a CAPA system that addresses root causes effectively, maintaining supplier controls, and building sufficient documentation for regulatory submissions. Many organisations benefit from external consultancy to navigate these areas.

Get ISO 13485 Certified with Bitrixme

ISO 13485 certification opens doors to global medical device markets. Bitrixme provides end-to-end QMS consultancy tailored to medical device manufacturers, from gap analysis through certification audit support. We serve clients across the Middle East, Europe, and Asia.

Or reach us on WhatsApp: +973 3659 9909