- What they do
- Assessor
- Which standards
- On the public register for FDA 21 CFR 820/QMSR, ISO 13485.
- Standards
- Pricing
- Not published
Framework Quality & Manufacturing
ISO 13485
ISO 13485 is the international quality management system standard for medical devices, written for regulatory purposes.
It covers the whole life cycle: design and development, risk management, purchasing and supplier control, production and process validation, sterilization and cleanliness where relevant, traceability, complaint handling, vigilance reporting, and post-market activities.
The current edition is ISO 13485:2016; no new edition has been published and ISO/TC 210 has not announced a revision date (verify). Since February 2, 2026 the standard is also the technical core of the US FDA's Quality Management System Regulation, and it is the basis of MDSAP audits and of most notified body QMS assessments under the EU MDR and IVDR.
In writing, the standard requires a quality manual, documented procedures for a long list of processes, a medical device file for each device type or family, design and development files, risk management files, validation records, and complaint and advisory notice procedures.
Unlike ISO 9001, it requires procedures to be documented wherever the standard says so and does not let an organization skip clauses without justifying exclusions.
Who has to comply
Voluntary as a standard, but effectively required for medical device manufacturers and many of their critical suppliers. Regulators in Canada (MDSAP mandatory), the EU (via notified body assessment), Australia, Japan, Brazil, and now the US (QMSR) rely on it. Contract manufacturers, sterilizers, and component suppliers are usually asked for certification by their customers.
What the assessor asks to see
Quality manual, scope, and role of the organization (manufacturer, importer, distributor, contract manufacturer); regulatory requirements register by market; medical device files; design and development planning, inputs, outputs, verification, validation, transfer, and change records; risk management files per ISO 14971; usability and software life cycle records where applicable; supplier evaluation and agreements; purchasing and incoming inspection; production records, process validation (including sterilization, packaging, software), and equipment maintenance; cleanliness and contamination control; identification, traceability, and UDI; labeling; storage and distribution; installation and servicing; complaint handling and vigilance decisions; advisory notices and recalls; CAPA; internal audits; management review; training and competence.
Where the requirement sits: 4.2.4 control of documents; 4.2.5 control of records; 6.2 competence/training; 4.1.1 documented QMS
ISO 13485 and the FDA QMSR
FDA's QMSR (21 CFR Part 820, effective February 2, 2026) incorporates ISO 13485:2016 by reference with FDA-specific additions. An ISO 13485 certificate is not required for FDA compliance and does not by itself satisfy it, but a well-run ISO 13485 system now maps almost one-to-one to what FDA investigators check.
MDSAP audits, which are built on ISO 13485, can be accepted by FDA in place of routine surveillance inspections.
What AllyMatter does here
Document and record control layer only.
AllyMatter publishes this site.
Assessors
Who assesses ISO 13485
Accredited certification bodies for ISO 13485 (many are also EU notified bodies and MDSAP auditing organizations); MDSAP-recognized auditing organizations for the single audit program; notified bodies for EU MDR/IVDR conformity assessment.
Accredited by National accreditation bodies under the Global ACI (formerly IAF) multilateral arrangement for ISO 13485 certification; the MDSAP regulatory authority council for MDSAP auditing organizations; EU member state designating authorities for notified bodies.
Public register of assessors: https://www.iafcertsearch.org/
- What they do
- Assessor
- Which standards
- On the public register for FDA 21 CFR 820/QMSR, ISO 13485.
- Standards
- Pricing
- Not published
- What they do
- Assessor
- Which standards
- On the public register for FDA 21 CFR 820/QMSR, ISO 13485.
- Standards
- Pricing
- Not published
- What they do
- Assessor
- Which standards
- On the public register for FDA 21 CFR 820/QMSR, ISO 13485.
- Standards
- Pricing
- Not published
- What they do
- Assessor
- Which standards
- On the public register for FDA 21 CFR 820/QMSR, ISO 13485.
- Standards
- Pricing
- Not published
Consultants
Who helps with ISO 13485
A very mature consultant ecosystem exists alongside the device regulatory affairs community. Consultants build the QMS, write the medical device file and technical documentation structure, run risk management per ISO 14971, prepare design history and validation records, run mock audits, and support notified body or MDSAP audits.
First certifications typically take six to twelve months.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Archlight is a vCISO / ISO 27001 consultancy based in Minneapolis, MN, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- BEMO is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Control and Function is a vCISO / ISO 27001 consultancy based in Denver, CO, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Coral Esecure is a vCISO / ISO 27001 consultancy based in New Jersey, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Cycore is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Genius GRC is a vCISO / ISO 27001 consultancy based in Woodstock, GA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Illumen is a vCISO / ISO 27001 consultancy based in Pacific Northwest, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Neutral Partners is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Securis360 is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Soter Advisory is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Testpros is a vCISO / ISO 27001 consultancy based in Reston, VA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- TrustedCISO is a vCISO / ISO 27001 consultancy based in Remote, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Software
Tools for ISO 13485
Tools that name this framework in their own material.
Related reading
- Medical device quality management: the importance of ISO 13485Sets out how ISO 13485 differs from ISO 9001 on risk, design controls and validation, and why regulators lean on it.BSI Group
- FDA releases final rule harmonizing Quality System Regulation with ISO 13485Covers how ISO 13485:2016 became the backbone of US device quality expectations, and what FDA kept on top of it.Regulatory Affairs Professionals Society
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for ISO 13485
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of ISO 13485 in AllyMatter
Approve the policies ISO 13485 asks for, keep every version, and record a named acknowledgment from each person who has to read them.