ISO 13485 requirements for medical device makers cover five things: a documented quality management system, management responsibility, competent people and the right infrastructure, controlled product realization from design through service, and measurement that drives improvement. The current version is ISO 13485:2016, and it is the standard regulators across the US, Canada, EU, Australia, Brazil and Japan expect you to build your quality system around. If you design, mold, assemble or service a medical device, this guide walks through every clause and what an auditor actually looks for.
I’ve sat through enough certification audits to know the standard itself is the easy part. The hard part is running a quality system that matches what your procedures say you do. That gap, between the procedure manual and the shop floor, is where nearly every non-conformity comes from.
One note on dates before we start. ISO 13485:2016 is still the current edition as of 2026. No revision is in progress, so if you have seen marketing material promising an updated standard, treat that claim with suspicion.
Table of Contents
- What Is ISO 13485 and Who Needs It?
- ISO 13485 Requirements for Medical Device Makers at a Glance
- Quality Management System Requirements
- Management Responsibility and Quality Objectives
- Resources, Training, and Infrastructure
- Design and Development Controls
- Supplier and Purchasing Controls
- Production and Service Provision
- Identification, Traceability, and Monitoring
- Nonconforming Product and Corrective Action
- Internal Audits and Management Review
- How to Prepare for an ISO 13485 Certification Audit
- Frequently Asked Questions
- Conclusion: Start With a Gap Analysis
What Is ISO 13485 and Who Needs It?

ISO 13485 is an international standard that specifies requirements for a quality management system for organizations that design, produce, install or service medical devices. It covers the full device lifecycle rather than a single manufacturing step, which is why it reaches into design controls and post-market complaints as much as it reaches into molding and inspection.
Any organization touching the medical device lifecycle needs it: device manufacturers, contract manufacturers, component and material suppliers, sterilization service providers, importers and distributors. If you run an injection molding shop that makes parts for a device company, you are in scope, and your customer will almost certainly require a certificate as a condition of the purchasing agreement.
ISO 13485 shares its skeleton with ISO 9001, and companies often start there. The two standards look similar on paper and behave very differently in an audit. ISO 9001 rewards continuous improvement and customer satisfaction; ISO 13485 rewards documented evidence of safety and regulatory compliance.
| Point of comparison | ISO 13485 | ISO 9001 |
|---|---|---|
| Core focus | Device safety and regulatory compliance | Customer satisfaction and process improvement |
| Continuous improvement | Not required; maintenance of the system is the goal | Core requirement |
| Risk management | Mandatory throughout design and production | Optional and mostly informal |
| Design controls | Required, documented design lifecycle | Addressed only if design is claimed |
| Documented information | Extensive, with defined records required | Documentation kept to a minimum |
| Regulatory approval | Supports submissions and market access | No regulatory content |
| Certification | Third-party certification, market-driven | Third-party certification, often voluntary |
| Management review | Mandatory with defined inputs and outputs | Mandatory, fewer prescribed inputs |
Worth separating three words people use interchangeably. Compliance means your organization meets the requirements of the standard. Certification means an accredited third party verified that and issued a certificate. Regulatory approval means a regulator like FDA cleared or approved your device, or a notified body issued your CE certificate. ISO 13485 sits in the middle: it is not a regulatory approval, but most regulators treat a certified quality system as strong evidence you control your processes.
ISO 13485 Requirements for Medical Device Makers at a Glance
Clauses 1 through 3 are scope, references and definitions. Everything an auditor tests lives in clauses 4 through 8. This table maps each one to the practical work it generates.
| Clause | What it covers | What you actually do |
|---|---|---|
| 4. Quality management system | Documented QMS, scope, process interaction, record control | Write the quality manual and procedures, map process interactions, control documents and records |
| 5. Management responsibility | Leadership, quality policy, objectives, management review | Top management sets policy, appoints a management representative, runs reviews on a set schedule |
| 6. Resource management | Competence, infrastructure, work environment, monitoring equipment | Build training and competency records, maintain equipment, run a calibration program |
| 7. Product realization | Planning, customer processes, design, purchasing, production, service, measurement | Run design controls, qualify suppliers, validate processes, control identification and traceability |
| 8. Measurement, analysis, improvement | Feedback, complaint handling, internal audit, nonconforming product, corrective action | Operate CAPA, handle complaints and adverse events, audit your own system, close non-conformities |
Read that table as a set of connected loops rather than five separate projects. A design change, for example, is a clause 7 event that triggers clause 4 record control, clause 8 nonconforming product review and a new risk file entry. Manufacturers who treat clauses as separate checklists end up with a system that passes a document review and fails on day one of the site audit.
How ISO 13485 maps to other systems you already run
One QMS can satisfy several frameworks at once, which is why building it deliberately pays off. The FDA Quality Management System Regulation now incorporates ISO 13485:2016 by reference into 21 CFR Part 820, adding FDA-specific provisions on records, reporting and device history records, so an ISO 13485 system covers most of the QMSR with a smaller set of additional obligations on top. In Europe, conformity assessment under EU MDR relies on a notified body’s quality system review, and ISO 13485 is the harmonized standard behind it, so the same evidence supports CE marking.
For companies selling in several markets, MDSAP lets a single audit against ISO 13485 cover the United States, Canada, Brazil, Australia and Japan instead of running five separate country audits. The trade is real: one audit instead of five, but each participating regulator’s requirements have to be mapped into your procedures rather than assumed.
Quality Management System Requirements
Clause 4 requires a documented quality management system that covers everything your organization does that affects product conformity. The system needs a defined scope, and the scope statement should name the sites, the product categories and the processes in or out of scope. Exclusions are limited and must be justified. You cannot exclude purchasing control because your material comes from a single vendor.
You also need at least six documented procedures under clause 4.2.2. In practice most manufacturers end up with 25 or more procedures covering document control, record control, internal audit, nonconforming product, corrective action, monitoring and measuring equipment, purchasing, production control, identification and traceability, and design and development.
Process interaction is the part organizations get wrong. Clause 4.4 asks you to define the relationships between your processes, including which inputs come from where and which outputs feed the next process. A diagram showing design outputs flowing into purchasing, production and verification is usually enough to satisfy an auditor, and it becomes genuinely useful the first time you trace a complaint back to a supplier lot number.
Record control sits alongside document control and gets less attention than it deserves. Records prove that your system works; they are not procedures that tell you what to do. Under clause 4.2.5 they must be legible, retrievable, protected from loss and kept for the retention period your regulation requires, which for a device under 21 CFR Part 820 is two years past the device’s expected life and no less than two years from the date of commercialization. If you store records electronically, your system has to hold up under 21 CFR Part 11 scrutiny, which is where medical grade material requirements and supplier documentation habits start to collide.
Management Responsibility and Quality Objectives
Clause 5 puts the burden on top management, not on the quality department. Auditors read management review minutes before they read anything else, and weak minutes are a reliable predictor of a finding.
What the standard asks for is specific. Top management has to establish and document a quality policy appropriate to the purpose of the organization, commit to meeting requirements and improving the QMS, and make that commitment understood at every level. You need documented quality objectives that are measurable, consistent with the policy, and tracked. You need at least one management representative with defined authority and responsibility, separate from the quality role where your size allows it. And you need regular communication about the importance of meeting requirements.
Management review under clause 5.6 has prescribed inputs: feedback, process performance and product conformity, corrective and preventive action, audit results, and any changes that could affect the QMS. The outputs must include decisions and actions. Running reviews quarterly instead of annually is a pattern that shows up in most mature quality organizations, and it tends to catch drift earlier than an annual cadence does.
Quality objectives should tie to work people already do. A mold shop might target first-pass yield on a production family, or scrap rate per cavity. Objectives nobody reports on are the ones that quietly stop being true.
Resources, Training, and Infrastructure
Clause 6 covers what you need to have in place to make product that conforms: people, infrastructure, environment and measurement equipment.
Competence comes first. Clause 6.2 requires you to determine the competence needed for each role, provide training, and keep records. The record has to show not just that someone attended, but that they can do the job. For operators, that usually means a documented qualification: run a qualification part, hit the acceptance criteria, sign it off. For engineers working on design controls, the evidence is usually review of their actual design history file contributions.
Training that people forget is a common finding, and the fix is boring: shorter sessions tied to the actual procedure version, delivered on the floor where the work happens, followed by a competency check. Sending everyone to a two-day course and filing the certificates is not the same thing.
Infrastructure includes the facilities, utilities and equipment needed for conformity, plus documented maintenance schedules. The work environment clause matters more than most manufacturers expect. It covers contamination control, temperature and humidity limits, and the controls you need where the product or process is sensitive to the environment, which for many medical device molding operations means a clean, controlled room around parts that must stay free of particulates.
Monitoring and measuring equipment must be identified, calibrated to traceable standards, protected from damage, and assessed for prior invalid results when it is found out of tolerance. A calibration program that schedules instruments on a spreadsheet and tracks out-of-tolerance impact is the difference between passing and getting a major finding. Our guide to calibration program requirements for manufacturing covers the setup in more depth.
Design and Development Controls
Design controls are where most medical device QMS work concentrates, and where auditors spend the most time. Clause 7.3 lays out a nine-stage lifecycle with documented inputs and outputs at each stage.
| Stage | What you produce | Typical evidence |
|---|---|---|
| Planning | Design and development plan, roles, interfaces | Plan naming reviewers, stages and deliverables |
| Inputs | Design inputs from user needs, intended use, regulatory and risk requirements | Inputs list, traceability matrix |
| Outputs | Drawings, specs, BOM, process instructions, acceptance criteria | Released drawings and specifications |
| Review | Formal design review at each stage | Minutes, attendance, action items closed |
| Verification | Evidence outputs meet inputs | Test reports, inspection results |
| Validation | Evidence the device meets user needs and intended use | Usability validation, clinical or bench validation report |
| Transfer | Design moved to production with documented controls | Transfer package, pilot run results |
| Changes | Controlled design change with impact assessment | Change request, risk file update, revalidation decision |
| Files | Design history file assembled and maintained | DHF index with links to every artifact |
Verification and validation are not interchangeable, and auditors check that you understand the difference. Verification asks whether the design output meets the design input: a bench test, a dimensional report, a software unit test. Validation asks whether the device does what a user needs it to do in the intended use setting. A design can pass every verification test and still fail validation if the workflow turns out to be confusing on a hospital floor.
Risk management runs through all of it. ISO 13485 requires risk-based thinking across design and development, which most organizations satisfy through ISO 14971. The practical test is whether your risk management file is a living document. A risk file written once at design freeze and never touched again is a major finding waiting to happen, and a change to a component or a software version is supposed to trigger an assessment that either updates the file or documents why no update is needed.
Traceability is what makes the whole thing auditable: user needs to design inputs, inputs to outputs, outputs to verification and validation activities. Keep it in a system that can survive design freeze. Spreadsheets work until the number of requirements crosses a few hundred, then they quietly stop matching the drawings.
If your device includes software, expect questions on software lifecycle documentation, and for connected devices, cybersecurity. Section 4.1.6 of the 2016 revision extended lifecycle expectations to include software used in the QMS itself, and auditors increasingly ask how cybersecurity risk is captured for connected hardware.
What design controls look like at a small company
The standard does not scale down for headcount, only for documentation depth. A ten-person team can run design controls with a handful of records: a plan per device, an inputs and outputs list, one design review per major revision, verification and validation reports, and a change log. What you cannot skip is the sequence. Reviews that happen after validation, or risk files that appear only at submission, read to an auditor as a system built backwards for the audit rather than for the device.
Contract manufacturers often hold more of the design history file than they realize. If production engineering there generates work instructions, inspection plans or acceptance criteria from your drawings, those are design outputs and belong in the DHF. Agree early who owns each artifact, in a design transfer plan, before the first article runs.
Supplier and Purchasing Controls
Clause 7.4 controls what comes in the door. You need documented criteria for selecting and evaluating suppliers, based at minimum on the impact of the purchased product on device quality, the supplier’s ability to meet your requirements, and past performance.
Evaluation has to happen before you place an order, not after a problem. That means an initial qualification that can be a paper review, a sample approval, a process audit or a combination, scaled to the risk of the part. A raw material used in a sterile barrier or a patient-contacting polymer deserves more than a certificate of analysis on file. If you work with polymers, medical grade plastics requirements cover what that qualification evidence actually has to include.
Re-evaluation runs on a schedule you define. Two years is typical for critical suppliers, three for routine ones, and faster after any quality event.
Purchasing information must state the requirements clearly enough that a supplier can price and build to them: specifications, drawings, quality system requirements, process and equipment requirements, and delivery expectations. Then verify what arrives. Incoming inspection needs defined criteria and a plan; full inspection on every lot is expensive and usually unnecessary, so sampling with a documented basis is the normal choice. The key word is documented, in both directions: which products get sampled, how much, and how often.
Contract manufacturers deserve their own treatment. Outsourced processes stay inside your scope under clause 7.4.8, so you need a quality agreement, defined audit rights, and an assessment of what your partner is qualified to do versus what you must keep in house. Companies that lean on an ISO 13485 certified contract manufacturer do not skip supplier control, they redirect it.
Production and Service Provision
Clause 7.5 covers everything between receiving materials and shipping finished product. It starts with a documented production plan, then controlled conditions: temperature, humidity, contamination, and lighting where inspection depends on it. Your process instructions have to be written, current and available to the people running them.
Where the output cannot be fully verified by later testing, you validate the process and revalidate it when something changes. Sterilization is the obvious case, but injection molding with critical dimensions, welding, adhesive bonding and cleanroom assembly all fall in the same category. The usual IQ, OQ and PQ sequence is a familiar structure, and the documentation has to show the acceptance criteria were defined before the runs, not after.
Devices that depend on manufacturing controls the standard calls for particular attention include sterile devices, implantable devices, devices containing biological material and devices manufactured in a controlled work environment such as a cleanroom. Sterile devices add sterilization validation, bioburden and packaging validation, and a defined shelf life. Implantable devices add individual serial number traceability and, usually, a UDI on the label.
Service provision covers installation, servicing and the feedback those activities generate. For most manufacturers this is where complaint handling starts, so the handover from service to the complaint system has to be clean and documented.
Identification, Traceability, and Monitoring
Identification and traceability under clause 7.5.3 is a sequence with four parts: identify the product, trace it forward to the customer, trace it backward to the raw material, and identify the measurement equipment used in the process. Backward traceability is where most device manufacturers lose points, because it requires lot and serial control that ties back through work-in-progress to purchased material.
The practical test an auditor runs is simple: pick a finished unit, ask where it went, then ask which resin lot was in the cavity. If the answer takes more than a few minutes, the identification system is not doing its job.
Customer property, covered under 7.5.4, matters more than it sounds. If a customer sends you molds, fixtures or components to process, you have to identify them, maintain them, and document any damage. That applies to customer-owned molds sitting in your building right now.
Monitoring and measuring equipment under clause 7.6 needs documented calibration to standards traceable to national or international references, verification before use, protection against damage, and an assessment of previously completed work if the instrument is found out of tolerance. That last clause is the one that generates the most work: a cal report showing a gauge was out by 0.4 units at the time you used it means someone has to go back through the affected product.
Nonconforming Product and Corrective Action
Clause 8.2.2 requires you to control nonconforming product so it never gets used by mistake. The control has to cover identifying it, isolating it, documenting what happened, and deciding its disposition. Most organizations use four dispositions: use as is, rework, repair or scrap.
Use as is is the one that gets scrutinized. It requires a concession, usually with a named approver and a documented rationale, and in regulated markets the approval frequently has to include the customer. Rework and repair both produce records and both need instructions, because reworking a part without one is a non-conformity every time.
Feedback in clause 8.2.1 covers both positive and negative, so complaints sit here alongside internal sources. A complaint handling system needs defined intake, evaluation, investigation, response and trending. The complaint record has to capture enough to reconstruct the event, and the investigation has to feed back into CAPA and, where the signal warrants, into the risk management file.
Regulatory reporting sits alongside complaints. Adverse event reporting thresholds, field corrective actions and advisory notices have to be in a written procedure with a decision tree and defined timelines, so nobody has to improvise when a call comes in on a Friday afternoon.
Clause 8.5.2 corrective action is the engine of the whole standard. The sequence is: define the problem, find the root cause, act, verify the action worked, and record all of it. Findings that show up repeatedly as the same non-conformity usually mean the root cause analysis stopped at the symptom. The verification of effectiveness check is where organizations get pressured for time and routinely fail, and it is exactly what an auditor samples first.
One operational note worth borrowing from shop floors: procedure text that no one is willing to update after a process change is the single most common root cause behind repeat non-conformities.
Post-market feedback has to come back inside the system
Clause 8.2.1 expects feedback to be a closed loop, and the loop closes at the risk management file, not at the complaint log. Complaint rates by failure mode, by lot and by supplier belong in the review that feeds the risk file and the design inputs for the next revision. Manufacturers who treat complaints as an administrative burden end up re-learning the same failure in the field that they already had data on in production.
Internal Audits and Management Review
Clause 5.6.2 sets the minimum: internal audits at planned intervals, by trained auditors who are not auditing their own work. Everything else, scheduling, scope and method, is yours to define.
Build the program on risk. Audit the areas that touch device safety, the suppliers with the most history and the processes where non-conformities cluster, and set a cycle for the rest. A risk-based program that covers all clauses across a year beats a full sweep of everything that never reaches the high-risk processes.
Auditors need to be trained, independent for the area they audit, and given the authority to look at records as well as talk to people. Findings need an owner, a correction and, where the finding is real, a corrective action with effectiveness verification. Closing the corrective action is not the same as closing the finding, and experienced auditors check that distinction.
Management review, covered above in clause 5, is the meeting where all of this gets decided. The inputs are prescribed, so if you walk in without complaint trends, CAPA status, audit results and process performance data prepared, the review cannot do its job.
How to Prepare for an ISO 13485 Certification Audit

Certification runs in stages and the sequence matters, because you cannot skip the middle of it and still pass the end of it. Here is the order that works for most companies building a quality system from nothing.
- Run a gap analysis. Walk clauses 4 through 8 against what you actually do today. The output is a list of gaps with owners and dates, and it becomes your implementation plan.
- Define the scope and write the quality manual. This is the anchor document. Keep it short enough that people read it.
- Build the procedures and forms. Six required procedures plus the ones your process needs. Build the templates before you write the text so the records come out consistent.
- Train the organization. Everyone who touches the QMS, including people who only handle records. Competency evidence, not attendance sheets.
- Run the system for real. At least one full management review, one internal audit cycle and real CAPA records before anyone from a certification body arrives. An audit on day one of a system gives you nothing to show.
- Do a mock audit. Have someone outside the team audit against the standard. The findings are free.
- Apply to an accredited certification body. Book well ahead. Firms that perform certification often quote months of lead time before a Stage 2 date, and that queue is the part of the timeline teams fail to plan for.
- Close non-conformities. Findings from the audit need correction, root cause, corrective action and effectiveness verification before the certificate decision.
The audit itself has two stages. Stage 1 is documentation: the auditor reviews your quality manual, procedures, records and scope, and tells you where the gaps are. Treat Stage 1 findings as homework with a deadline, not as a formality. Stage 2 is on site, where the auditor checks whether what your procedures describe matches what your people do. Expect interviews at every level, walkthroughs of production and the service areas, and sampling back into records.
After certification you are on a three-year cycle. Surveillance audits happen once a year in the usual pattern, and a re-certification audit closes the cycle. Ask your certification body about the exact schedule at the closing meeting, and put the dates in a shared calendar immediately.
A maintenance calendar makes the ongoing work less painful than it sounds. Quarterly is management review, internal audit tracking and objective review. Annually is the full internal audit program, supplier re-evaluation, competency reassessment and calibration. After every design or process change, the change control and risk file update.
Six mistakes companies make against ISO 13485 requirements
Retroactive documentation is the big one. Teams that wait until they are “ready” end up reconstructing design inputs from memory two years later, and the records show it. The second is overbuilding: buying an eQMS and writing fifty procedures before a single device exists, then letting the system rot while the team goes back to working. Risk management treated as a one-time exercise, weak supplier qualification, siloed quality and manufacturing teams, and designs that work on the bench but were never reviewed for manufacturability round out the list most consultants see repeatedly.
None of those are technical problems. They are timing and attention problems, which is why catching them in the gap analysis stage costs days instead of months.
Frequently Asked Questions
What are the ISO 13485 requirements for medical device manufacturers?
They cover five areas: a documented quality management system (clause 4), management responsibility including quality policy and management review (clause 5), resources such as competence, infrastructure and calibrated equipment (clause 6), product realization covering design controls, purchasing, production, service, identification and traceability (clause 7), and measurement, analysis and improvement including complaints, internal audits, nonconforming product and corrective action (clause 8).
What are the mandatory documents required by ISO 13485?
At minimum you need a quality manual and six documented procedures: control of documents, control of records, internal audit, control of nonconforming product, corrective action, and control of monitoring and measuring equipment. In practice most manufacturers also maintain procedures for purchasing, design and development, production and service provision, identification and traceability, complaints, and regulatory reporting, plus a medical device file for each device type.
Is ISO 13485 mandatory for medical devices?
Not as a standalone legal requirement in most countries. In the US, ISO 13485 is the route FDA accepts to satisfy the Quality Management System Regulation, which incorporates ISO 13485 by reference into 21 CFR Part 820. In the EU, a notified body assessment against ISO 13485 is required for most device classes before CE marking. In practice, device makers need it because regulators, notified bodies and customers expect it.
How long does ISO 13485 certification take?
Most companies run six to twelve months from gap analysis to certification audit, and small startups with little documentation take closer to the longer end. Adding the queue for a Stage 2 audit date, which is commonly several months, calendar time runs longer than the work itself. Starting with design and supplier controls early makes the difference, since retroactive documentation is the main reason timelines slip.
What is the difference between ISO 13485 and FDA QMSR?
ISO 13485 is a voluntary international standard written by ISO. The FDA Quality Management System Regulation is the US regulation that incorporates ISO 13485:2016 by reference into 21 CFR Part 820, adding FDA-specific provisions on records, reporting and device history records. Holding an ISO 13485 certificate covers most of the QMSR, but it does not cover the added FDA obligations.
Can you self-certify ISO 13485?
You can build a compliant system and declare conformity yourself, but the certificate that customers and notified bodies ask for has to come from an accredited third party. In the EU, a notified body is legally required for most device classes. Choosing a certification body accredited under ISO/IEC 17021 for medical device QMS certification is the part worth checking before you sign anything.
Conclusion: Start With a Gap Analysis
Start with a clause-by-clause gap analysis and get honest about the answers, especially for design controls and supplier qualification, since those are where the largest gaps usually sit. From there, work in order: quality manual, procedures, training, one full internal audit cycle and management review, then the certification body.
The ISO 13485 requirements for medical device makers are not difficult to read. They are demanding to run honestly, because the standard keeps asking for evidence that your process works the way you say it does. A system built that way pays for itself twice: it shortens regulatory submissions, and it removes the scramble of reconstructing records after something goes wrong.
One last thing to keep in view. ISO 13485 organizes your quality system. It does not replace FDA, EU MDR or any other market-specific regulation, and it does not clear your device for market. It is the foundation those submissions rest on, so build it to last rather than to pass a single audit. And if your site runs molding, assembly or material handling work, our guide to OSHA requirements for a plastics plant covers the safety side your quality system should sit alongside.