ISO 13485
ISO 13485:2016 — the international Quality Management System standard for medical devices, harmonised with EU MDR/IVDR, accepted under MDSAP, and as of 2 February 2026 the substantive backbone of FDA's new Quality Management System Regulation (QMSR) replacing 21 CFR Part 820. What it requires, how it differs from ISO 9001, and how it is operationalised on the shop floor.
01What ISO 13485 actually is
ISO 13485 is the international consensus standard that specifies requirements for a quality management system where an organisation needs to demonstrate its ability to provide medical devices and related services that consistently meet customer and applicable regulatory requirements. It was first published in 1996, with the current edition ISO 13485:2016 and an Amendment 1 published in 2021 (a minor amendment principally about climate-action wording and a scope clarification).
ISO 13485 is a regulatory standard, not a generic quality standard. Its structure deliberately mirrors ISO 9001 in many places, but it strips out the customer-satisfaction emphasis of 9001 and replaces it with explicit requirements for regulatory compliance, risk management, design controls, sterile/implantable device controls, and post-market surveillance. It is referenced as the harmonised standard for QMS under EU MDR 2017/745 Article 10(9), accepted by all five MDSAP regulators (FDA, Health Canada, TGA, ANVISA, MHLW/PMDA), and — from 2 February 2026 — incorporated by reference into the FDA's new Quality Management System Regulation (QMSR), replacing the long-standing 21 CFR Part 820 Quality System Regulation.
02The structure of ISO 13485:2016 — clauses 4 through 8
ISO 13485 is organised in eight clauses. The first three are scope and normative references. The five substantive clauses define the QMS.
- Clause 4 — Quality Management System. General QMS requirements, document control, record control, the quality manual, the requirement to define each device's role in the supply chain (manufacturer, importer, distributor, contract manufacturer).
- Clause 5 — Management Responsibility. Top management's accountability for the QMS: policy, planning, responsibility and authority, management representative, internal communication, management review.
- Clause 6 — Resource Management. Human resources (competence, training, awareness), infrastructure (buildings, equipment, IT), work environment and contamination control, particularly for sterile devices.
- Clause 7 — Product Realisation. The biggest clause. Planning of product realisation, customer-related processes, design and development (the famous clause 7.3 — design controls), purchasing, production and service provision (including process validation), control of monitoring and measuring equipment.
- Clause 8 — Measurement, Analysis and Improvement. Feedback, complaint handling, reporting to regulatory authorities, internal audit, monitoring of processes and product, control of nonconforming product, analysis of data, CAPA, and the explicit improvement clause.
Every clause has an 'shall' requirement (mandatory) and most have a 'shall maintain documented information' or 'shall retain records' obligation. The records and documents collectively constitute the auditable evidence of the QMS.
03Design Controls — clause 7.3, the heart of medical-device QMS
Clause 7.3 (Design and development) is where ISO 13485 most clearly diverges from ISO 9001. It mandates a documented design-control process producing a Design History File (DHF) that proves the device was developed against user needs, with risk management integrated throughout, and verified and validated before release to manufacturing.
7.3.2 Design and development planning
A plan that describes the stages, the responsibilities, the reviews, the verification and validation activities, the design-transfer activities and the risk-management activities. Updated as the design evolves.
7.3.3 Design inputs
User needs, intended use, regulatory requirements, applicable standards, and results from risk management. Inputs must be reviewed for adequacy and approved.
7.3.4 Design outputs
The drawings, specifications, code, labelling artwork, training materials and the DMR content. Outputs must be in a form that allows verification against inputs and must include or reference acceptance criteria.
7.3.5 Design review
Formal reviews at defined stages, with participants representing functions affected by the stage, plus independent reviewers. Documented.
7.3.6 Design verification
Confirmation that outputs meet inputs. Testing, inspection, analysis. Documented with results.
7.3.7 Design validation
Confirmation, often through clinical evaluation, that the device meets the user needs and intended use. Performed on initial production units or equivalents.
7.3.8 Design transfer
The formal handover from design to manufacturing. The DMR is the artefact; transfer is the act of approving it.
7.3.9 Control of design changes
Every change after the initial transfer goes through review, verification, validation (as appropriate) and approval before implementation. Risk re-assessment is required.
7.3.10 Design and development files
The DHF — one file per device or per device family — retained for the device's life plus the regulatory minimum.
04Risk management — the ISO 14971 partnership
ISO 13485 references ISO 14971 — the medical-device risk-management standard — as the source for the risk-management process. The interplay is explicit: 13485 clauses 7.1, 7.3.3, 7.3.7, 7.3.9, 7.5.1, 8.2.1 and 8.5.2 all require risk-management activities or outputs. The DHF must include the risk-management file from ISO 14971.
In a well-run device QMS, the risk-management file is updated continuously — at design transfer, at every design change, at every CAPA, at every post-market signal that changes the residual risk picture. EU MDR Annex I and FDA's expectations under QMSR both treat the risk file as a living document; a static one is a routine audit finding.
05ISO 13485 vs ISO 9001 — what is added, what is removed
| Topic | ISO 9001:2015 | ISO 13485:2016 |
|---|---|---|
| Customer satisfaction | Central focus, measured and reported | Replaced by 'meeting customer and applicable regulatory requirements' — satisfaction surveys are not required |
| Risk-based thinking | Generic, applied to the QMS as a whole | Specific to product safety and effectiveness via ISO 14971 |
| Design controls | Generic 'design and development' clause | Detailed clause 7.3 with mandatory DHF and design transfer |
| Process validation | Required only when output cannot be verified by monitoring | Required for any process whose output cannot be verified — and specifically called out for sterilisation, sterile-barrier systems, software |
| Documented procedures | Few specific procedures required; organisation chooses | Specific documented procedures required for control of documents, records, design, purchasing, production, monitoring, CAPA, complaint handling, regulatory reporting |
| Continual improvement | Required as a QMS objective | Required, but framed as effectiveness and suitability rather than satisfaction-driven improvement |
| Regulatory reporting | Not addressed | Clause 8.2.3 mandatory: report adverse events and field actions per applicable regulation |
| Sterile / implantable controls | Not addressed | Specific clauses for sterile-device manufacturing environments and implantable traceability |
An organisation certified to ISO 9001 cannot claim ISO 13485 conformance without significant additional work — typically design-control implementation, sterile-controls evidence, validated processes, and a regulatory-reporting procedure that doesn't exist in 9001-land.
06FDA QMSR — the February 2026 change that matters to US manufacturers
On 2 February 2024 the FDA published the final Quality Management System Regulation (QMSR) rule, amending 21 CFR Part 820 to incorporate ISO 13485:2016 by reference. The effective date is 2 February 2026 — a two-year transition. After that date, the substantive QMS requirements for medical-device manufacturers selling in the US are the ISO 13485 clauses, augmented by the FDA-specific provisions retained in Part 820 (which become a much thinner regulation focused on the things ISO does not address: device-history-record specifics, complaint-files specifics, definitions, applicability).
The practical impact: a manufacturer already certified to ISO 13485 and exporting to Europe needs to add the FDA-specific Part 820 retained provisions (notably the DHR detail in old §820.184 and complaint-handling detail in old §820.198, both substantially preserved) to its existing QMS. A manufacturer currently certified only to Part 820 needs to upgrade to full ISO 13485 — design-control language, management-responsibility specifics, supplier-controls structure all change in non-trivial ways. The FDA has stated it will continue its inspectional cadence; QSIT (the existing inspection technique) is being updated into a 'QMSR Inspection Technique' guidance.
07MDSAP — one audit, five regulators
The Medical Device Single Audit Program (MDSAP) is an IMDRF-coordinated programme under which a single audit by an authorised auditing organisation satisfies the regulatory inspection needs of five participating regulators: FDA (US), Health Canada, TGA (Australia), ANVISA (Brazil), and MHLW/PMDA (Japan). Health Canada has made MDSAP mandatory for licence-holding manufacturers since January 2019. FDA accepts MDSAP audit reports in lieu of routine surveillance inspections. The other three regulators use MDSAP variably.
MDSAP audits are conducted against ISO 13485 plus the country-specific regulatory requirements of each participating regulator. The audit model is process-based and covers seven tasks: management, measurement-analysis-improvement, medical device adverse events and advisory notices reporting, design and development, production and service controls, purchasing, and device marketing authorisation and facility registration. The non-conformity grading scale (Grade 1 through 5) is more granular than typical ISO certification audits.
08Eight ways an ISO 13485 system fails audit
- Risk-management file frozen at design transfer. CAPA outcomes, post-market signals and design changes have updated the residual risk picture but the file does not show it.
- Design changes implemented without 7.3.9 review and re-verification. The change-control system exists but only catches major changes.
- Supplier controls weak — approved-supplier list with no evidence of qualification, no periodic re-evaluation, no audit programme proportionate to risk.
- Process validation done at IQ/OQ/PQ and never re-validated. Equipment moved, parameters drifted, software updated — no re-qualification.
- Complaints not classified for regulatory reporting. Threshold for MDR (US) or MIR (EU) decisions is informal; some events that should be reported aren't.
- Internal audit programme covers ISO clauses but never asks 'is this clause being implemented effectively?' — auditors check existence, not effectiveness.
- Management review is a slide-deck once a year. The clause requires inputs (audits, complaints, CAPA, supplier performance, changes, etc) and outputs (decisions, resource needs). Most reviews skip the outputs.
- Training records show attendance but not competence. Clause 6.2 requires demonstrated competence for personnel performing work affecting product quality.
09How V5 Ultimate handles ISO 13485 in practice
V5's medical-devices industry profile is built so that the records the QMS demands — DHF, DMR, DHR, complaint files, CAPA, supplier qualification, risk-management file, training records, audit-trail evidence — are produced as the by-product of running the shop floor, not as a separate documentation exercise.
- Document control (clause 4.2.4): every controlled document has approved versions, effective dates, distribution lists, and acknowledgement records; obsolete versions are retained and locked.
- Design controls (clause 7.3): DHF as a structured object with inputs, outputs, reviews, verification/validation, design transfer, and change records — each design change re-evaluating the risk file.
- Production and service provision (clause 7.5): work orders execute against the DMR snapshot; the eDHR captures per-unit evidence; process validation status is tracked at the process-step level.
- Purchasing (clause 7.4): supplier qualification, periodic re-evaluation, incoming inspection records, supplier corrective-action requests.
- CAPA (clause 8.5.2/8.5.3) and complaint handling (clause 8.2.2): one workflow from intake through investigation, root cause, action, effectiveness check; regulatory-reporting decision built in.
- Management responsibility (clause 5): policy, objectives, management-review meetings with structured inputs and recorded outputs, all available on the audit view.
- QMSR (2026) ready: the platform handles both the ISO 13485 substance and the retained Part 820 specifics (DHR detail, complaint-file detail) without parallel systems.
Frequently asked questions
Q.Is ISO 13485 certification mandatory?+
Certification itself is voluntary. But ISO 13485 conformance is mandatory in most major markets: EU MDR Article 10(9) requires a QMS, with ISO 13485 the harmonised standard presumed to satisfy it; Health Canada requires MDSAP certification (which audits against ISO 13485) for licence holders; FDA's QMSR from 2 February 2026 incorporates ISO 13485 by reference. In practice, every commercial medical-device manufacturer operates an ISO 13485 QMS.
Q.How long does certification take?+
For a company starting from scratch, building the QMS, generating the records, running a Stage 1 readiness audit and a Stage 2 certification audit typically takes 9–18 months. Companies upgrading from ISO 9001 typically need 6–12 months. The first surveillance audit is usually a year after initial certification; recertification every three years.
Q.Does ISO 13485 require electronic records?+
No — the standard is technology-neutral. But the volume and traceability demands of clause 7.3 (design controls), clause 7.5 (production records, DHRs), clause 8 (CAPA, complaints, audit trail) make paper systems impractical at any meaningful scale. Almost every manufacturer above start-up scale runs electronic. Electronic records bring 21 CFR Part 11 / Annex 11 controls into play.
Q.What is the difference between ISO 13485 and 21 CFR 820?+
Until 2 February 2026: 820 is the US FDA's QMS regulation, similar in concept to ISO 13485 but with FDA-specific wording, structure and a few different requirements (notably design-controls scope and management-responsibility language). From 2 February 2026: Part 820 becomes QMSR, which incorporates ISO 13485:2016 by reference for the substantive QMS requirements and retains FDA-specific provisions (DHR specifics, complaint specifics, definitions) on top. After QMSR, ISO 13485 + the retained Part 820 sections = US QMS regulation.
Q.Do I need both ISO 13485 and ISO 14971?+
Yes, effectively. ISO 13485 references ISO 14971 as the risk-management framework; you cannot satisfy 13485's risk-management requirements without implementing 14971 (or a demonstrably equivalent process — but no regulator accepts that without convincing). The standards are sold separately and read together.
Q.Does ISO 13485 apply to software-as-a-medical-device (SaMD)?+
Yes. SaMD is a medical device under FDA, EU MDR and most regulatory definitions. ISO 13485 applies, with the additional standard IEC 62304 for software life-cycle and ISO 14971 for risk. Design controls (clause 7.3) substantially shape SaMD development — the DHF includes the software development plan, the software requirements specification, the architecture and detailed design, the verification and validation evidence.
Primary sources
- ISO 13485:2016 — Medical devices — Quality management systems — Requirements for regulatory purposes
- ISO 13485:2016/Amd 1:2021 — Climate action amendment + scope clarifications
- FDA QMSR final rule — 21 CFR Part 820 amended to incorporate ISO 13485 by reference (Jan 2024; effective 2 Feb 2026)
- 21 CFR Part 820 (current QSR; superseded 2 Feb 2026)
- EU MDR 2017/745 — Article 10(9) QMS obligations
- MDSAP Program Documents — IMDRF
- ISO 14971:2019 — Application of risk management to medical devices
Further reading
- DHF — Design History FileWhat ISO 13485 §7.3 produces over the device life.
- DMR — Device Master RecordThe product-and-process master that drives manufacturing.
- DHR — Device History RecordPer-unit evidence the QMS demands as proof of conformance.
- eDHR — electronic DHRHow V5 binds DHRs to the QMS in real time.
- CAPAClause 8.5.2/8.5.3 — the QMS engine for systemic improvement.
- UDIThe labelling and traceability obligation the QMS must support.
- How V5 satisfies ISO 13485Document, record, design, supplier and CAPA control end-to-end.
- Medical-devices industry viewISO 13485 in context with EU MDR, FDA QMSR and MDSAP.
Explore this topic
ISO 13485 sits inside 2 overlapping topic clusters in our glossary. Every neighbour is one click away.
GS1 identifiers, barcodes, ASNs and the rules that require lot-level traceability.
Device-specific rules, submissions and the standards that bind them.
V5 Ultimate ships with the ISO 13485 controls already wired in — audit trail, e-signatures, validation evidence. Free trial, no credit card, onboard in days, not months.
