ISO 13485 Explained
An independent overview from DQS, an accredited certification body.
ISO 13485 is the international standard for quality management systems in the medical device sector. It specifies requirements for a quality management system that an organization needs to demonstrate to provide medical devices and related services that consistently meet customer and applicable regulatory requirements. The current version is ISO 13485:2016, supplemented in the European Union by EN ISO 13485:2016/A11:2021. This European amendment establishes the relationship between ISO 13485:2016 and the requirements of the EU Medical Device Regulation (MDR 2017/745) and In Vitro Diagnostic Medical Device Regulation (IVDR 2017/746), supporting manufacturers in demonstrating conformity with applicable regulatory requirements. In the United States, the FDA’s Quality Management System Regulation (QMSR) took effect on February 2, 2026, incorporating ISO 13485:2016 by reference into 21 CFR Part 820. No formal revision of ISO 13485 is currently scheduled, although review activity is expected as new technologies and regulatory expectations evolve (Status May 2026).
Already have a medical device quality management system in place?
If your organization has implemented a quality management system based on ISO 13485 and you’re looking for a certification partner, our dedicated certification page has everything you need — from process overview to a personalized quote.
Key Facts at a Glance
| Full Title | ISO 13485 — Medical devices — Quality management systems — Requirements for regulatory purposes |
| Published by | International Organization for Standardization (ISO), Technical Committee ISO/TC 210 |
| First Published | 1996 (first edition); ISO 13485:2016 (current edition) |
| Current Version | ISO 13485:2016. In the EU: EN ISO 13485:2016/A11:2021 adds Annexes ZA and ZB referencing the MDR and IVDR. No formal ISO revision is currently scheduled (Status May 2026). |
| Management System Type | Quality Management system (QMS) for medical devices |
| Applicable to | Organizations involved in any stage of the medical device life cycle: design and development, production, storage, distribution, installation, servicing, and final decommissioning, as well as suppliers and service providers. |
| Certifiable | Yes. Independent third-party certification by an accredited certification body is the most widely recognized way to demonstrate conformity. It is also required by many legal manufacturers as a quality benchmark for suppliers and is referenced by several regulators worldwide. |
| Structure | Eight clause; the requirement clauses are Clauses 4–8 (Quality Management System, Management Responsibility, Resource Management, Product Realization, Measurement, Analysis and Improvement). Not aligned to the High Level Structure (Annex SL). |
| Related Standards | ISO 9001; MDSAP (Medical Device Single Audit Program), ISO 14791, the ISO 10993 series, IEC 62304, IEC 62366-1, ISO 14155 and others. |
Why ISO 13485 is so important in the regulatory landscape?
Regulatory Pressure Across Major Markets
The medical device sector is one of the most heavily regulated areas of the global economy, and the regulatory map has continued to tighten. In the European Union, the Medical Device Regulation (MDR, Regulation (EU) 2017/745) and the In Vitro Diagnostic Regulation (IVDR, Regulation (EU) 2017/746) require manufacturers and authorized representatives to operate a quality management system; EN ISO 13485:2016/A11:2021 is the harmonized standard used by most manufacturers as the QMS backbone for MDR and IVDR conformity assessment. In the United States, the FDA’s Quality Management System Regulation (QMSR) took effect on February 2, 2026, replacing the former 21 CFR Part 820 (Quality System Regulation) by incorporating ISO 13485:2016 by reference, with FDA-specific additions on labeling, complaint handling, and recordkeeping. Health Canada has long required ISO 13485 certification under the Medical Device Single Audit Program (MDSAP), and other major regulators (Brazil’s ANVISA, Australia’s TGA, Japan’s PMDA, South Africa´s SAHPRA) accept or require MDSAP audits based on ISO 13485.
Supply Chain Expectations and Notified Body Scrutiny
The regulatory environment has produced concrete expectations along the medical device value chain. Notified bodies in the EU and certification bodies elsewhere examine supplier control, design and development records, post-market surveillance, and risk management with increasing rigor. Tier-N suppliers of components, sterilization services, packaging, and contract manufacturing are expected to operate ISO 13485-compliant quality management systems as a condition of working with original equipment manufacturers (OEMs). Software-as-a-medical-device (SaMD) developers, distributors, importers, and service providers face equivalent expectations relative to their role in the medical device life cycle.
Patient Safety, Risk Management, and Post-Market Discipline
The standard’s underlying logic is patient safety. ISO 13485 requires that risk management be applied across product realization, in line with ISO 14971 (the most common norm for risk management for medical devices), and that organizations operate complaint handling, post-market surveillance, vigilance, and corrective and preventive action processes capable of identifying and addressing safety issues in the field. The combination of pre-market design discipline and post-market feedback loops is what distinguishes the medical device QMS from generic quality management.
Accredited vs. Non-Accredited Certification: Why It Matters
When selecting a certification partner, it is important to distinguish between accredited and non-accredited certification. Accredited certification means that the certification body itself is formally assessed, approved, and continuously monitored by an independent accreditation body. This provides additional assurance regarding competence, impartiality, audit methodology, and international acceptance. Non-accredited certificates may confirm that an assessment has taken place, but they generally do not provide the same level of external oversight, regulatory credibility, or market recognition.
Working with an accredited certification body therefore offers clear advantages: certificates are more widely trusted by regulators, customers, procurement organizations, and business partners; they are better suited to regulated markets and supplier qualification processes; and they provide stronger evidence that the audit has been performed under recognized rules and controlled accreditation requirements. DQS holds ISO 13485 accreditations under internationally recognized accreditation bodies, including DAkkS in Germany, ANAB in the United States, and the Standards Council of Canada, supporting the international acceptance and credibility of its certificates.
Core Requirements for ISO 13485
ISO 13485:2016 is structured in eight clauses. Clauses 1 to 3 cover scope, normative references, and terms and definitions. The requirement clauses — against which an organization is audited — are Clauses 4 to 8.
Clause 4 — Quality Management System
The organization documents, implements, and maintains a quality management system. Requirements cover general QMS requirements (including controls over outsourced processes and software used in the QMS), the quality manual, document control, and control of records. Documentation requirements are explicit and detailed by design, reflecting the regulatory purpose of the standard.
Clause 5 — Management Responsibility
Top management establishes the quality policy and quality objectives, conducts management reviews, and ensures the availability of resources. The clause specifies the management representative role, internal communication, and the responsibilities and authorities required to operate the quality management system.
Clause 6 — Resource Management
Requirements address the provision of resources, including human resources (competence, training, awareness), infrastructure, and the work environment. For sterile devices and active implantable devices, contamination control and work environment requirements are specifically called out.
Clause 7 — Product Realization
The largest clause covers the medical device life cycle: planning of product realization, customer-related processes, design and development, purchasing (including supplier evaluation and re-evaluation), production and service provision, identification and traceability, control of monitoring and measuring equipment, and risk management activities applied throughout. Specific requirements apply to sterile devices, implantable devices, and devices requiring installation or servicing.
Clause 8 — Measurement, Analysis and Improvement
The organization plans and implements monitoring, measurement, analysis, and improvement processes, including feedback (post-market surveillance), complaint handling, reporting to regulatory authorities, internal audit, monitoring and measurement of processes and product, control of nonconforming product, analysis of data, and corrective and preventive action (CAPA). The clause is where the standard’s connection to post-market vigilance is most explicit.
Target Groups and Application Areas for ISO 13485
ISO 13485 is the de facto global reference for organizations operating anywhere in the medical device life cycle. Typical user groups include:
- Medical device manufacturers, from small SaMD developers and start-ups to large multinational OEMs.
- In vitro diagnostic (IVD) device manufacturers, where the parallel EU IVDR transition has driven significant uptake of ISO 13485-based QMS implementations.
- Contract manufacturers and design houses, which need to be able to integrate seamlessly into customer QMS audits.
- Component suppliers, sterilization services, packaging providers, and software development service providers, who increasingly need certification or assessed conformance as a condition of supply.
- Distributors, importers, and authorized representatives with regulatory obligations under the MDR, IVDR, or comparable national regimes.
- Installers and service providers for medical devices that require professional installation or maintenance.
A well-designed medical device quality management system supports informed decisions by giving leadership and operational managers structured, traceable information about design, production, supplier performance, and post-market behavior. It provides the basis for evidence-based management of patient safety and regulatory compliance; the system itself does not act, but it enables the people in the organization to make better-informed decisions
Standards Related to ISO 13485
Harmonized Structure and Typical Combinations
Unlike most other ISO management system standards, ISO 13485 is not aligned to the High Level Structure (Annex SL). This is a deliberate choice by ISO/TC 210, intended to keep the standard stable for medical device regulators that have incorporated it by reference. Organizations that operate ISO 13485 alongside ISO 9001 typically run a single integrated QMS in which ISO 9001 elements are layered onto the ISO 13485 baseline, recognizing that the two share intellectual heritage but no longer share clause structure. Many medical device manufacturers also operate ISO 14001 (environment) and ISO 45001 (occupational health and safety) systems in parallel, but the integration with ISO 13485 is necessarily lighter because of the structural difference.
The ISO 9001 Connection
ISO 13485 was originally derived from ISO 9001 and has shared its conceptual approach for decades. The 2016 edition of ISO 13485 was, however, intentionally not aligned to the 2015 revision of ISO 9001, and there is no current indication that ISO/TC 210 plans to align with ISO 9001:2026. Organizations should therefore not assume that conformance with one standard implies conformance with the other; the requirements differ in important areas, particularly around documentation, risk management, regulatory reporting, design and development, and post-market activities.
MDSAP and Regulatory Wrappers
The Medical Device Single Audit Program (MDSAP) is an audit program that uses ISO 13485:2016 as its core standard and adds country-specific requirements for participating regulators (Australia’s TGA, Brazil’s ANVISA, Health Canada, the US FDA, and Japan’s PMDA/MHLW). A successful MDSAP audit is recognized by the participating regulators in different ways — mandatory in some, accepted as evidence in others. EN ISO 13485:2016/A11:2021 is the European harmonized version of the standard, with Annexes ZA and ZB clarifying how the standard maps to the EU MDR and IVDR. The FDA Quality Management System Regulation (QMSR), effective February 2, 2026, incorporates ISO 13485:2016 by reference and adds FDA-specific provisions on labeling, complaint handling, and recordkeeping; QMSR explicitly does not auto-update to future ISO 13485 revisions without separate FDA rulemaking.
Risk Management and Adjacent Technical Standards
ISO 13485 is closely linked to a set of risk and product safety standards that are not certifiable management system standards but are referenced by ISO 13485 or required by regulators. ISO 14971 (application of risk management to medical devices) is the recognized risk management reference. IEC 62304 (medical device software life cycle processes), IEC 62366-1 (usability engineering), and the IEC 60601 series (electrical safety of medical electrical equipment) are technical product standards that interact with the ISO 13485 QMS but are not themselves QMS certifications. These should not be described as equivalent to ISO 13485.
About DQS as a certification body
This article is part of the DQS Knowledge Center, a resource on management system standards and certification processes. For context on who produced it:
- One of Germany’s first management system certifiers—DQS issued its first certificate in 1986 and has audited and certified management systems for over 40 years.
- Operates from more than 80 offices in 60 countries with a worldwide network of more than 3,000 auditors.
- Accredited for ISO 13485 alongside related standards such as ISO 9001, ISO 14001, and ISO/IEC 27001—so integrated management systems can be certified from a single provider.
- Member of IQNet, the international certification network, supporting cross-border recognition of DQS certificates.
The articles in this Knowledge Center are written and reviewed by DQS specialists working with these standards in audit practice. Where applicable, content is verified against the current version of the standard, the issuing body’s official publications, and recent regulatory or accreditation guidance. This article was last reviewed on 3 June 2026.
Frequently Asked Questions about ISO 13485 Certification
Is ISO 13485 mandatory?
ISO 13485 itself is a voluntary international standard. However, certification or demonstrated conformance to ISO 13485 is required, accepted, or strongly expected by most major medical device regulators worldwide — including the EU (via the MDR and IVDR), Health Canada (via MDSAP), and, since February 2, 2026, the US FDA (via the Quality Management System Regulation that incorporates ISO 13485:2016 by reference). In practice, organizations placing medical devices on a major regulated market need to operate an ISO 13485-conformant quality management system.
What is the current version os ISO 13485?
The currently published version is ISO 13485:2016. In Europe, the harmonized version EN ISO 13485:2016/A11:2021 adds informative Annexes ZA and ZB that link the standard to the EU MDR and IVDR. No formal ISO revision is currently scheduled.
How does ISO 13485 relate to the FDA Quality Management System Regulation (QMSR)?
The FDA QMSR took effect on February 2, 2026, replacing the previous 21 CFR Part 820 (Quality System Regulation). The QMSR incorporates ISO 13485:2016 by reference and supplements it with FDA-specific requirements covering labeling, complaint handling, recordkeeping, and certain device history information. A certified ISO 13485 quality management system therefore provides the structural backbone for QMSR compliance, but ISO 13485 certification by itself does not constitute FDA approval of any device.
How does ISO 13485 relate to ISO 9001?
ISO 13485 was historically derived from ISO 9001 but has since evolved into an independent standard. The 2016 edition is intentionally not aligned to the Annex SL High Level Structure used in ISO 9001:2015 and the forthcoming ISO 9001:2026. The two standards therefore share intellectual heritage but no longer share clause numbering or structure. ISO 13485 certification does not imply ISO 9001 conformance, and ISO 9001 certification does not satisfy ISO 13485 requirements.
What is the difference between ISO 13485 and EU MDR/IVDR?
ISO 13485 specifies requirements for a quality management system; the MDR (Regulation (EU) 2017/745) and IVDR (Regulation (EU) 2017/746) are EU laws governing the placement of medical devices and in vitro diagnostics on the EU market. EN ISO 13485:2016/A11:2021 explains, via Annexes ZA and ZB, how the standard’s requirements map to specific MDR and IVDR obligations. Conformance to ISO 13485 supports MDR and IVDR conformity assessment but does not, by itself, deliver MDR or IVDR conformity — device-specific requirements, technical documentation, post-market surveillance, and notified body involvement remain separate obligations.
Does ISO 13485 certify medical devices?
No. ISO 13485 specifies requirements for the quality management system used to design, manufacture, distribute, and service medical devices. Devices themselves are subject to separate regulatory pathways: CE marking under the MDR or IVDR in the EU, FDA clearance or approval under the relevant pathway in the US, license issuance under the Medical Devices Regulations in Canada, and so on. ISO 13485 certification is one input to those device-level processes, not a substitute for them.
How long is an ISO 13485 certificate valid?
An accredited ISO 13485 certificate is typically issued with a maximum validity of three years, subject to annual surveillance audits during the cycle and to a recertification audit before the certificate expires. The exact audit calendar depends on the accreditation rules applied to the certification body.