ISO 13485:2016 Medical Devices Quality Management System
ISO 13485 is not optional in medical devices — it is the gateway to CE marking, CDSCO licensing and most global market approvals. Its emphasis is regulatory conformity and traceability, not continual improvement.
4.9/5 average client rating · 1200+ engagements delivered
How ISO 13485 differs from ISO 9001
ISO 13485 shares the ancestry of ISO 9001 but deliberately diverges: it prioritises maintaining effective processes and meeting regulatory requirements over continual improvement, and it retains prescriptive documentation requirements that ISO 9001:2015 removed.
Design and development controls, risk management throughout the product realisation lifecycle, and full traceability from raw material to distributed unit are non-negotiable. A quality manual and documented procedures remain mandatory.
- Medical device file for each device family, and a documented quality manual
- Design and development planning, inputs, outputs, review, verification, validation, transfer and change control
- Risk management integrated across the product lifecycle in line with ISO 14971
- Process validation including sterilisation, software and cleanroom processes
- Traceability, identification, UDI readiness and controlled distribution records
- Complaint handling, vigilance, adverse event reporting, advisory notices and post-market surveillance
Key facts
| Standard | ISO 13485:2016 |
|---|---|
| Regulatory links | EU MDR 2017/745, CDSCO Medical Devices Rules 2017, US FDA QMSR (harmonised with ISO 13485 from 2026) |
| Companion standards | ISO 14971 risk management, IEC 62304 software lifecycle, IEC 62366 usability |
| Typical timeline | 14–24 weeks depending on device class and design activity |
| Applies to | Manufacturers, contract manufacturers, sterilisers, distributors and software as a medical device |
What the engagement covers
We build a QMS that satisfies the standard and the specific market approvals you are targeting — the two are related but not identical.
Regulatory strategy
Device classification, applicable regulations by target market, and the approval pathway your QMS must support.
Design controls
Design history file structure, phase gates, verification and validation protocols, and design transfer to manufacturing.
Risk management file
ISO 14971 hazard analysis, risk control, benefit-risk analysis and production/post-production information loop.
Process validation
IQ/OQ/PQ protocols for manufacturing, sterilisation, cleanroom and software processes.
Supplier & material control
Supplier qualification, incoming inspection, traceability and change notification agreements.
Post-market system
Complaint handling, vigilance and field safety corrective action, PMS plan and periodic safety reporting.
Who needs it
Anyone in the medical device supply chain whose activity affects device safety or performance.
- Medical device manufacturers and OEMs across all classes
- Contract manufacturers, component and sterile packaging suppliers
- Software as a Medical Device and digital health platform developers
- Sterilisation, calibration and testing service providers
- Importers and distributors requiring a QMS for CDSCO or EU registration
Market access
Certification underpins CE marking under EU MDR, CDSCO licensing and recognition in most regulated markets.
Regulatory defensibility
A complete design history and risk management file is what survives a notified body or regulator inspection.
FDA convergence
The US QMSR harmonises with ISO 13485, so a compliant QMS materially reduces future FDA readiness effort.
Fewer post-market surprises
Validated processes and traceability make root cause investigation and field action fast and bounded.
How the engagement runs
Classification & gap assessment
Device classification per target market, applicable requirements mapped, and QMS gap assessment.
QMS architecture
Quality manual, procedure hierarchy, medical device files and document/record control system.
Design & risk implementation
Design control process deployed on a live project, with risk management file built to ISO 14971.
Validation & production controls
Process validation, sterilisation and software validation, traceability and inspection systems.
Certification & registration
Internal audit, management review, notified body or certification body audit support, and registration dossier alignment.
What you receive
- Regulatory strategy note and device classification rationale
- Quality manual, procedures and medical device file structure
- Design control process with design history file templates
- ISO 14971 risk management plan, hazard analysis and risk management report
- Process, sterilisation and software validation protocols and reports
- Supplier qualification, traceability and UDI readiness framework
- Post-market surveillance, complaint and vigilance procedures with audit support
ISO 13485 — frequently asked questions
It is necessary but not sufficient. Under EU MDR you also need a technical documentation file, clinical evaluation, post-market surveillance and vigilance system, UDI compliance and, for most classes, notified body involvement. ISO 13485 is the QMS backbone that carries all of it.
They share structure but differ in intent. ISO 13485 requires a quality manual and documented procedures, emphasises regulatory compliance and risk over continual improvement, and adds design controls, validation and traceability requirements. Holding ISO 9001 helps, but is not a substitute.
Yes. SaMD manufacturers need ISO 13485, plus IEC 62304 for the software lifecycle, ISO 14971 for risk and usually IEC 62366 for usability. We build the QMS so your agile development process still satisfies design control and traceability requirements.
The Medical Devices Rules 2017 require a manufacturing licence with a QMS conforming to Schedule 5, which aligns closely with ISO 13485. Certification substantially shortens licence processing and audit outcomes, and we prepare the dossier alongside the QMS.
Longer than the rest of the QMS combined, because auditors want to see it applied to a real project. We typically deploy it on one active development programme and build the design history file as the project progresses, which adds four to eight weeks but produces genuine evidence.
Still not sure what applies to you?
Ask an assessor directly — we answer scoping questions before anyone talks about a fee.
Get a realistic timeline and a fixed fee
A 30-minute call is usually enough to scope ISO 13485 accurately. You will leave with a timeline, an evidence checklist and a number — whether or not you engage us.