What ISO 13485 Covers

QMS for medical devices across the full lifecycle: design and development, purchasing, production, installation, servicing, storage, distribution, and decommissioning.

Design Controls & DHF/Tech File

Disciplined design and development with complete design history files, technical documentation, verification and validation records.

Risk Management Integration

Risk management integration and traceability to requirements and tests throughout the device lifecycle.

Sterile Devices & Cleanroom

Sterile device controls and cleanroom management where applicable to device classification and manufacturing.

Supplier Control

Comprehensive supplier control and outsourced process management with qualification and ongoing evaluation.

UDI, Labeling & IFU Control

Unique device identification, labeling control, instructions for use management, complaint handling, and CAPA.

Post-Market Surveillance

Post-market surveillance, feedback, vigilance, trending, and improvement (Clause 8) for continuous monitoring.

Who ISO 13485 is For

Organization Types

Manufacturers

OEMs and legal manufacturers responsible for design, production, and post-market activities.

Contract Manufacturers

Critical suppliers, sterilization providers, and packaging companies in the device supply chain.

Distributors & Service Providers

Distribution and service organizations where applicable to their role in device lifecycle.

Device Classification & Lifecycle

All Device Classes

Applies to all device classes (I, IIa, IIb, III). Higher classes add depth and rigor, not different fundamentals.

Class I
Low risk
Class IIa
Low-medium risk
Class IIb
Medium-high risk
Class III
High risk

Lifecycle Coverage

Design Manufacturing Distribution Post-Market

How ISO 13485 Differs from ISO 9001

Key differences that make ISO 13485 specifically suited for medical device regulatory environments.

Purpose

ISO 9001:

General quality management for customer satisfaction and continuous improvement

ISO 13485:

Regulatory purpose — prioritizing risk, documentation, and process control over generic improvement

Design Controls

ISO 9001:

Basic design and development requirements

ISO 13485:

Prescriptive design control records, verification/validation traceability, and device file requirements

Risk Integration

ISO 9001:

Risk-based thinking encouraged

ISO 13485:

Risk management embedded throughout realization and post-market surveillance — pairs with ISO 14971

Documentation

ISO 9001:

Flexible documentation approach

ISO 13485:

Extensive documented information requirements for regulatory compliance and traceability

Post-Market Activities

ISO 9001:

Customer feedback and satisfaction monitoring

ISO 13485:

Comprehensive post-market surveillance, vigilance reporting, and feedback systems (Clause 8)

Regulatory Alignment

ISO 13485 alignment with major regulatory frameworks worldwide.

USA — FDA QMSR

FDA replaced the QSR with the Quality Management System Regulation (QMSR), harmonized to ISO 13485:2016. Enforcement starts February 2, 2026.

Certification to ISO 13485 is not itself required by FDA, but compliance must be aligned to QMSR requirements.

Key Point: ISO 13485 provides the framework for QMSR compliance, making FDA inspections more straightforward.

EU — MDR Requirements

ISO 13485 supports EU MDR QMS expectations but MDR imposes additional requirements for clinical evaluation, post-market surveillance, and vigilance.

Use ISO 13485 as the QMS backbone and map MDR Article 10.9 processes for complete compliance.

Key Point: Notified bodies expect ISO 13485 conformance plus MDR-specific clinical and PMS processes.

Implementation Timeline & Complexity

Realistic Timeline Expectations

Weeks 1–4

Gap Assessment & Planning

Current state analysis, gap identification, resource planning, and project setup.

Weeks 5–12

QMS Development

Policy creation, procedure development, template deployment, and initial training.

Weeks 13–20

Implementation & Validation

Process validation, software validation, supplier qualification, and system testing.

Weeks 21–28

Audit Readiness

Internal audits, management review, CAPA closure, and certification audit preparation.

Typical range: 16–28 weeks for single-site SME with existing controls; large/multi-site often 6–12 months.

Complexity Drivers

High Complexity Factors

Software as a Medical Device (SaMD), Class III devices, sterile manufacturing, multiple sites, extensive supplier networks, legacy design history files.

Medium Complexity

Class IIa/IIb devices, cleanroom operations, moderate design activity, established supplier base, single manufacturing site.

Lower Complexity

Class I devices, limited design activity, contract manufacturing only, well-established processes, single product line.

Common Gap Areas

  • Incomplete design history and traceability
  • Weak risk-benefit linkage documentation
  • Supplier qualification and re-evaluation
  • Process and software validation
  • PMS signal management and CAPA effectiveness

What AEC Provides

Comprehensive deliverable package for ISO 13485 implementation and certification readiness.

QMS Foundation Package

Quality Manual
Quality Policy & Objectives
Process Map & Interactions
KPI Dashboard & Metrics

Core Procedures

Design & Development Control
Document & Record Control
Supplier Control & Evaluation
Production & Validation
UDI & Labeling Control
Traceability Management
Sterility & Cleaning (where applicable)
Complaint Handling & CAPA
Nonconforming Product Control
Internal Audit Program
Management Review
Post-Market Surveillance & Vigilance

Templates & Tools

DHF/Tech File Index
DMR/Device File Templates
Design Plan & Requirements Matrix
V&V Protocol & Report Templates
Risk Management File Kit (ISO 14971)
Usability Engineering Templates
Software Lifecycle Checklists
Change Control Forms
Batch Record Templates
Validation Protocols
PMS Plan & Report Templates
Trend Analysis Tools

Regulatory Mapping & Support

ISO 13485 ↔ FDA QMSR Mapping
ISO 13485 ↔ EU MDR Article 10.9 Mapping
Internal Audit Checklists
Mock Certification Audit
CAPA Tracking System
Certification Body Liaison

Benefits & Business Case

Regulatory Readiness

Full preparation for FDA QMSR inspections and EU MDR compliance audits with documented QMS alignment.

Market Access

Global customer recognition of ISO 13485-conformant QMS, supporting notified body approvals and international sales.

Operational Excellence

Design right-first-time, validated processes, superior supplier quality, fewer complaints and recalls.

Faster Submissions

Clean design history files and technical documentation accelerate regulatory submission and approval processes.

Risk Management

Integrated risk management throughout device lifecycle reduces liability and improves patient safety outcomes.

Competitive Advantage

Third-party validated QMS provides competitive differentiation and customer confidence in quality systems.

ISO 13485 Training Programs

Comprehensive training pathway from awareness to expert-level auditing capabilities.

Foundation Awareness

1 Day

Introduction to ISO 13485 requirements, medical device QMS fundamentals, and regulatory context for all staff.

Learn More

Internal Auditor

2 Days

ISO 19011-based internal auditing skills specific to medical device QMS and regulatory requirements.

Learn More

Implementer/Practitioner

3–4 Days

Advanced implementation skills for QMS development, design controls, and regulatory compliance management.

Learn More

Lead Auditor

5 Days
CQI/IRCA

CQI/IRCA certified lead auditor course for certification body auditing and third-party assessment capabilities.

Enroll Now

Industry-Specific Modules

Design Control Deep-Dive

Advanced workshop on design controls, DHF management, V&V protocols, and design transfer.

ISO 14971 Risk File Clinic

Hands-on workshop for risk management file development and ISO 13485 integration.

Software Lifecycle & CSV

Software as Medical Device lifecycle, computer system validation, and cybersecurity considerations.

PMS & Vigilance Workshop

Post-market surveillance program design, vigilance reporting, and trend analysis techniques.

Frequently Asked Questions

Does ISO 13485 replace ISO 14971?

No. ISO 13485 embeds risk management requirements throughout the standard, but ISO 14971 defines the specific device risk management process and Risk Management File structure. Both standards work together — use ISO 13485 as the QMS framework and ISO 14971 for the risk management methodology.

Will ISO 13485 certification satisfy FDA requirements?

FDA’s QMSR (effective Feb 2, 2026) is harmonized to ISO 13485:2016. While FDA does not require ISO 13485 certification, compliance must meet QMSR requirements which align with ISO 13485. Certification provides strong evidence of QMSR compliance during FDA inspections.

How does ISO 13485 help with EU MDR compliance?

ISO 13485 provides the quality management system backbone required by EU MDR Article 10.9. However, MDR adds specific requirements for clinical evaluation, post-market clinical follow-up, and enhanced vigilance that must be mapped and implemented beyond ISO 13485 requirements.

What about post-market surveillance requirements?

ISO 13485 Clause 8 requires comprehensive post-market surveillance including feedback systems, complaint handling, trending, and improvement. This aligns with FDA post-market requirements and provides the foundation for EU MDR post-market surveillance and vigilance reporting.

What is the typical audit cycle for ISO 13485?

ISO 13485 follows a standard 3-year certification cycle with annual surveillance audits. Initial certification includes Stage 1 (document review) and Stage 2 (implementation audit). Surveillance audits occur at 12 and 24 months, with full recertification at 36 months.

Ready to Implement ISO 13485?

Get started with our comprehensive ISO 13485 implementation and certification support designed specifically for medical device companies.

Gap Assessment

Comprehensive evaluation of your current QMS against ISO 13485 requirements with detailed implementation roadmap.

Get Gap Assessment

Internal Auditor Training

Develop internal competency with our medical device-specific internal auditor certification program.

Book Training

Mock Certification Audit

Pre-certification audit simulation to ensure readiness and identify any final gaps before formal assessment.

Request Mock Audit

Questions about ISO 13485 implementation for your medical device company?

Talk to Our Medical Device Experts