HomeFrameworksQuality & ManufacturingISO 13485

Framework  Quality & Manufacturing

ISO 13485

ISO 13485 is the international quality management system standard for medical devices, written for regulatory purposes.

It covers the whole life cycle: design and development, risk management, purchasing and supplier control, production and process validation, sterilization and cleanliness where relevant, traceability, complaint handling, vigilance reporting, and post-market activities.

The current edition is ISO 13485:2016; no new edition has been published and ISO/TC 210 has not announced a revision date (verify). Since February 2, 2026 the standard is also the technical core of the US FDA's Quality Management System Regulation, and it is the basis of MDSAP audits and of most notified body QMS assessments under the EU MDR and IVDR.

In writing, the standard requires a quality manual, documented procedures for a long list of processes, a medical device file for each device type or family, design and development files, risk management files, validation records, and complaint and advisory notice procedures.

Unlike ISO 9001, it requires procedures to be documented wherever the standard says so and does not let an organization skip clauses without justifying exclusions.

AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedSOP QA-014 rev 9by name, on record
Design Control Meets Proofwith AllyMatter
Sterilize the Paper TrailEvery controlled procedure, acknowledged by the people who follow it
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every operator and QA tech on record
Revision-bound, re-collected when the SOP changes
03
Open the DHF conversation with the trail
From $29/mo, 20 editors, unlimited staff (published)

Who has to comply

Voluntary as a standard, but effectively required for medical device manufacturers and many of their critical suppliers. Regulators in Canada (MDSAP mandatory), the EU (via notified body assessment), Australia, Japan, Brazil, and now the US (QMSR) rely on it. Contract manufacturers, sterilizers, and component suppliers are usually asked for certification by their customers.

What the assessor asks to see

Quality manual, scope, and role of the organization (manufacturer, importer, distributor, contract manufacturer); regulatory requirements register by market; medical device files; design and development planning, inputs, outputs, verification, validation, transfer, and change records; risk management files per ISO 14971; usability and software life cycle records where applicable; supplier evaluation and agreements; purchasing and incoming inspection; production records, process validation (including sterilization, packaging, software), and equipment maintenance; cleanliness and contamination control; identification, traceability, and UDI; labeling; storage and distribution; installation and servicing; complaint handling and vigilance decisions; advisory notices and recalls; CAPA; internal audits; management review; training and competence.

Where the requirement sits: 4.2.4 control of documents; 4.2.5 control of records; 6.2 competence/training; 4.1.1 documented QMS

ISO 13485 and the FDA QMSR

FDA's QMSR (21 CFR Part 820, effective February 2, 2026) incorporates ISO 13485:2016 by reference with FDA-specific additions. An ISO 13485 certificate is not required for FDA compliance and does not by itself satisfy it, but a well-run ISO 13485 system now maps almost one-to-one to what FDA investigators check.

MDSAP audits, which are built on ISO 13485, can be accepted by FDA in place of routine surveillance inspections.

What AllyMatter does here

Document and record control layer only.

AllyMatter publishes this site.

Assessors

Who assesses ISO 13485

Accredited certification bodies for ISO 13485 (many are also EU notified bodies and MDSAP auditing organizations); MDSAP-recognized auditing organizations for the single audit program; notified bodies for EU MDR/IVDR conformity assessment.

Accredited by National accreditation bodies under the Global ACI (formerly IAF) multilateral arrangement for ISO 13485 certification; the MDSAP regulatory authority council for MDSAP auditing organizations; EU member state designating authorities for notified bodies.

Public register of assessors: https://www.iafcertsearch.org/

BSI Group America Inc.On the public register
What they do
Assessor
Which standards
On the public register for FDA 21 CFR 820/QMSR, ISO 13485.
Standards
FDA 21 CFR 820/QMSRISO 13485
Pricing
Not published
DEKRA Certification B.V.On the public register
What they do
Assessor
Which standards
On the public register for FDA 21 CFR 820/QMSR, ISO 13485.
Standards
FDA 21 CFR 820/QMSRISO 13485
Pricing
Not published
DNV Product Assurance ASOn the public register
What they do
Assessor
Which standards
On the public register for FDA 21 CFR 820/QMSR, ISO 13485.
Standards
FDA 21 CFR 820/QMSRISO 13485
Pricing
Not published
DQS Medizinprodukte GmbHOn the public register
What they do
Assessor
Which standards
On the public register for FDA 21 CFR 820/QMSR, ISO 13485.
Standards
FDA 21 CFR 820/QMSRISO 13485
Pricing
Not published
Intertek Testing Services NA Inc.On the public register
What they do
Assessor
Which standards
On the public register for FDA 21 CFR 820/QMSR, ISO 13485.
Standards
FDA 21 CFR 820/QMSRISO 13485
Pricing
Not published

Consultants

Who helps with ISO 13485

A very mature consultant ecosystem exists alongside the device regulatory affairs community. Consultants build the QMS, write the medical device file and technical documentation structure, run risk management per ISO 14971, prepare design history and validation records, run mock audits, and support notified body or MDSAP audits.

First certifications typically take six to twelve months.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

ArchlightMinneapolis, MN, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Archlight is a vCISO / ISO 27001 consultancy based in Minneapolis, MN, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
BEMOUSANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
BEMO is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Control and FunctionDenver, CO, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Control and Function is a vCISO / ISO 27001 consultancy based in Denver, CO, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Coral EsecureNew Jersey, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Coral Esecure is a vCISO / ISO 27001 consultancy based in New Jersey, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
CycoreMiami, FL, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Cycore is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Genius GRCWoodstock, GA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Genius GRC is a vCISO / ISO 27001 consultancy based in Woodstock, GA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
IllumenPacific Northwest, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Illumen is a vCISO / ISO 27001 consultancy based in Pacific Northwest, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Neutral PartnersMiami, FL, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Neutral Partners is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Securis360Pittsburgh, PA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Securis360 is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Soter AdvisoryUSANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Soter Advisory is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
TestprosReston, VA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Testpros is a vCISO / ISO 27001 consultancy based in Reston, VA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
TrustedCISORemote, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
TrustedCISO is a vCISO / ISO 27001 consultancy based in Remote, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published

Related reading

  1. Medical device quality management: the importance of ISO 13485Sets out how ISO 13485 differs from ISO 9001 on risk, design controls and validation, and why regulators lean on it.BSI Group
  2. FDA releases final rule harmonizing Quality System Regulation with ISO 13485Covers how ISO 13485:2016 became the backbone of US device quality expectations, and what FDA kept on top of it.Regulatory Affairs Professionals Society

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for ISO 13485

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Run the Policy Side of ISO 13485 in AllyMatter

Approve the policies ISO 13485 asks for, keep every version, and record a named acknowledgment from each person who has to read them.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.