ISO 13485:2016 — The Complete Guide to Medical Device Quality Management
Introduction
ISO 13485 is the quality management system standard for medical devices, and since February 2026 it is also the legal basis for FDA quality system inspections in the United States. That change makes it the single most consequential standard a device manufacturer works to: one compliant quality system now underpins market access in the EU, the US, Canada, Japan, Brazil and Australia.
ISO 13485:2016 was placed into systematic review in January 2025 and reconfirmed as current, so this is the version in force and there is no announced replacement.
This guide covers the structure clause by clause, what separates ISO 13485 from ISO 9001, how it relates to the FDA QMSR and to the EU MDR, the documentation the standard actually mandates, the findings that recur in audits, and an implementation sequence that works for a small to medium organisation.
Table of Contents
- What ISO 13485 is, and where it is required
- ISO 13485 compared with ISO 9001
- The structure: eight clauses
- Clause 4 — Quality management system
- Clause 5 — Management responsibility
- Clause 6 — Resource management
- Clause 7 — Product realization
- Clause 8 — Measurement, analysis and improvement
- ISO 13485 and the FDA QMSR
- ISO 13485 and the EU MDR
- What the standard actually mandates in writing
- The audit findings that recur
- Implementation roadmap
- ISO 13485 and MDSAP
- Where the standard stands today
- Frequently asked questions
- Conclusions
What ISO 13485 is, and where it is required
ISO 13485 applies to organisations involved in the design, production, installation and servicing of medical devices, and to suppliers and external parties providing products or services to them. It defines what the quality management system must contain: the processes, the documentation, the responsibilities and the controls needed to produce safe and effective devices consistently.
What distinguishes it from general quality standards is that it is built around regulatory obligation rather than customer satisfaction, with risk management, process validation and traceability running through every clause.
| Market | Status of ISO 13485 | What it is used for |
|---|---|---|
| United States | Incorporated by reference into 21 CFR Part 820 by the QMSR, effective 2 February 2026 | The legal standard against which the FDA inspects. Certification is not required and does not exempt from inspection. |
| European Union | Not legally mandated by the MDR, but the recognised means of meeting Article 10(9) | The reference framework Notified Bodies use when auditing a manufacturer’s quality system |
| Canada | Required through MDSAP for Class II, III and IV licences | No MDSAP certificate, no Medical Device Licence |
| Japan | Used in MHLW and PMDA quality system conformity assessment | Reduces overlap with domestic audits, through MDSAP where applicable |
| Brazil | Recognised through MDSAP | Can replace the ANVISA B-GMP inspection for several categories — see our guide to ANVISA registration |
| Australia | Accepted for TGA conformity assessment on selected routes | Through MDSAP |
The practical consequence is that a single ISO 13485-compliant quality system now satisfies quality system expectations across every major market at once. That was not true two years ago, and it is the reason the standard’s importance has increased rather than the standard itself having changed.
✦ Audit-ready kit · ISO 13485
Build your ISO 13485 QMS with confidence.
Built on 15+ years of audit experience — every SOP and template references the regulations auditors expect. Get to certification faster, with industry best practices baked in.
✓ 30 SOPs covering the full QMS scope
✓ 56 templates ready to customise
✓ Aligned with EU MDR + FDA QMSR
ISO 13485 compared with ISO 9001
The two standards share a family resemblance and serve different purposes. Treating ISO 13485 as ISO 9001 with medical device wording is the source of several recurring findings.
| Dimension | ISO 9001 | ISO 13485 |
|---|---|---|
| Primary orientation | Customer satisfaction | Regulatory compliance and consistent product safety. The primary obligation is to regulators and patients. |
| Improvement | Continual improvement of the QMS is required | Maintenance of QMS effectiveness is required. A deliberate difference, reflecting a regulatory preference for stability over change. |
| Risk | Risk-based thinking applied to the management system | Documented risk management processes across design, manufacturing and post-market, aligned with ISO 14971 |
| Quality manual | No longer required since the 2015 revision | Mandatory |
| Documented procedures | Left largely to the organisation | Six explicitly required, plus any process whose absence of documentation could affect quality |
| Sterile and implantable devices | No provisions | Specific clauses on sterile manufacturing, implantable devices and the associated records |
| Validation | Where the organisation determines it necessary | Required for processes whose output cannot be verified by subsequent monitoring, and for software used in the QMS, in production and in monitoring |
The structure: eight clauses
ISO 13485:2016 has eight clauses. The first three set scope, normative references and terms; the operational requirements run from clause 4 to clause 8.
| Clause | Title | What it governs |
|---|---|---|
| 1–3 | Scope, normative references, terms and definitions | Applicability and vocabulary. Not audited directly, but the definitions decide arguments. |
| 4 | Quality management system | General requirements, documentation, quality manual, document and record control, software validation |
| 5 | Management responsibility | Quality policy, objectives, responsibilities, management representative, management review |
| 6 | Resource management | Competence, infrastructure, work environment and contamination control |
| 7 | Product realization | Planning, customer processes, design and development, purchasing, production, monitoring equipment |
| 8 | Measurement, analysis and improvement | Feedback and complaints, internal audit, nonconforming product, data analysis, CAPA |
Clause 4 — Quality management system
Clause 4 establishes the foundations: determining the processes needed, their sequence and interaction, the criteria and methods for controlling them, and the resources to support them. Control is applied in proportion to the risk each process poses to product safety and quality.
The quality manual is a mandatory output — the documented description of the QMS scope, the documented procedures or references to them, and the interaction between processes. ISO 9001 dropped this requirement in 2015; ISO 13485 kept it.
Clause 4.1.6 is the one that catches organisations out: software used in the quality management system must be validated for its intended use, with the approach proportionate to risk. That covers the eQMS, the ERP, the document management system. The recognised method is GAMP 5, and this is a different obligation from the device software requirements of IEC 62304, which many organisations conflate.
Clause 5 — Management responsibility
Top management, not the quality department, carries the obligations in this clause. It requires a documented quality policy appropriate to the organisation and reviewed for continuing suitability; measurable quality objectives established at relevant functions and levels; and a management review at planned intervals.
The management review has defined inputs — audit results, feedback and complaints, process and product conformity, CAPA status, follow-up from previous reviews, changes affecting the QMS, regulatory changes and improvement recommendations — and defined outputs covering resource needs, process improvements and product improvements. A review that records attendance and a decision to continue has met neither.
The management representative is a designated member of management with responsibility for the QMS. Under the EU MDR a separate obligation exists: the Person Responsible for Regulatory Compliance under Article 15. The two roles are frequently held by the same person and are not the same role, and a quality manual that treats them as interchangeable will be asked to separate them.
Clause 6 — Resource management
Personnel performing work that affects product quality must be competent on the basis of education, training, skills and experience, with competence documented and the effectiveness of training evaluated. Evaluating effectiveness — not merely recording attendance — is the part most often missing.
Infrastructure covers buildings, workspace, equipment and supporting services, including the maintenance requirements where maintenance affects product quality. Work environment covers the conditions needed for conformity, including cleanliness, contamination control and, where relevant, controls for devices supplied sterile.
Clause 7 — Product realization
The longest and most audited clause, covering the product from concept to delivery.
| Sub-clause | What it covers | Where it connects |
|---|---|---|
| 7.1 | Planning of product realization, including risk management activities across realization | The risk management plan under ISO 14971 |
| 7.2 | Customer-related processes: determining requirements including regulatory ones, reviewing them, and communication including complaints | Feeds clause 8.2 complaint handling |
| 7.3 | Design and development: planning, inputs, outputs, review, verification, validation, transfer, changes and the design file | The Design History File is the bridge to the technical documentation. See our guide to ISO 13485 design controls |
| 7.4 | Purchasing: supplier evaluation and selection criteria, control proportionate to risk, verification of purchased product | See our guide to supplier qualification and the approved supplier list |
| 7.5 | Production and service provision: process control, cleanliness, installation, servicing, sterile and implantable device requirements, traceability | Process validation where output cannot be verified by later monitoring |
| 7.6 | Control of monitoring and measuring equipment: calibration, adjustment, identification, safeguarding, records | Software used here also requires validation |
Clause 8 — Measurement, analysis and improvement
Clause 8 is the evidence that the system is working. It covers feedback and complaint handling, and the reporting to regulatory authorities that follows from it; internal audit, at planned intervals, by auditors independent of the activity audited; monitoring and measurement of processes and product; control of nonconforming product, with a documented procedure covering identification, segregation, evaluation and disposition; analysis of data from feedback, conformity, process and supplier performance; and improvement, which means CAPA.
CAPA is the most scrutinised element in any regulatory audit. Clause 8.5.2 sets six requirements for corrective action and 8.5.3 five for preventive action — eleven in total, and a procedure that addresses ten has a finding waiting in it. Our guide to CAPA under ISO 13485 covers each of them, and our internal audit checklist covers the programme that feeds it.
ISO 13485 and the FDA QMSR
The Quality Management System Regulation took effect on 2 February 2026, amending 21 CFR Part 820 to incorporate ISO 13485:2016 by reference. For manufacturers who maintained two parallel quality systems — one for the FDA, one for ISO — most of that duplication is removed.
Four points qualify that, and each is a source of misunderstanding.
| Point | What it means |
|---|---|
| The QMSR is not identical to ISO 13485 | It adds FDA-specific provisions, including on labelling and packaging controls and on records, that sit alongside the incorporated standard |
| Certification does not substitute for inspection | The FDA does not require, issue or accept a certificate of conformance to ISO 13485 in place of an inspection. Compliance is assessed by FDA investigators, not by a certification body. |
| The inspection scope has widened | Records that were exempt from routine inspection under the old QSR — internal audit reports, supplier evaluations and management review records — now fall within the FDA’s reach |
| The inspection method has changed | The Quality System Inspection Technique was retired for device inspections when the QMSR took effect, replaced by the process described in the updated compliance program |
The widened inspection scope is the change with the most immediate operational consequence, and it is easy to underestimate. Internal audit reports written on the assumption that no regulator would read them — candid, self-critical, listing problems that were never formally raised — are now inspectable. The right response is not to write blander audits; it is to make sure every finding an internal audit raises has a CAPA record attached to it.
For a manufacturer already certified to ISO 13485, QMSR compliance is largely in place, and a gap analysis focused on the FDA-specific additions is the sensible next step. Where the US is one market among several, the same quality system carries into MDSAP, and the premarket route runs separately through the 510(k) or De Novo pathway.
✦ Premium bundle · ISO 13485 + MDSAP
The ultimate global QMS documentation bundle.
Combine ISO 13485 and all five MDSAP markets in one package. A deduplicated structure means you customise each document once, not twice — which matters most for CAPA, internal audit and management review, where the same procedure serves both.
✓ 41 SOPs covering both ISO 13485 and MDSAP
✓ 70+ templates with deduplicated structure
✓ Save €199 vs buying the kits separately
ISO 13485 and the EU MDR
The two are complementary and distinct. ISO 13485 defines how a quality system must be structured and operated; the MDR defines what has to be demonstrated about a specific device. Certification is not legally required by the MDR, but it is the recognised route to satisfying the quality system obligations of Article 10(9) and Annex IX, and Notified Bodies use it as their reference when auditing.
Four connection points carry most of the practical work:
- Design controls under clause 7.3 feed the Annex II technical documentation. The design file is the bridge between the quality system and the technical file, and inconsistency between the two is a routine finding.
- Post-market surveillance under MDR Articles 83 to 86 has to live inside clause 8: as an input to management review, a trigger for CAPA, and a feed into the risk management file. Our guide to EU MDR post-market surveillance covers the plan and the reporting.
- Purchasing under clause 7.4 maps onto the economic operator obligations and supply chain controls of the MDR, and onto the SOUP requirements of IEC 62304 where software components are involved.
- Management review under clause 5.6 has to take MDR-specific inputs: EUDAMED data, vigilance reports and regulatory change monitoring.
What the standard actually mandates in writing
ISO 13485 is specific about a minimum set of documented procedures. Six are required outright, regardless of device class or organisation size.
| Documented procedure | Clause | What it has to cover |
|---|---|---|
| Control of documents | 4.2.4 | Review, approval, revision, availability at point of use, control of obsolete documents, retention |
| Control of records | 4.2.5 | Identification, storage, protection, retrieval, retention period and disposition |
| Internal audit | 8.2.4 | Planning, criteria, scope, frequency, auditor independence, reporting, follow-up |
| Control of nonconforming product | 8.3 | Identification, documentation, segregation, evaluation, disposition, and handling after delivery |
| Corrective action | 8.5.2 | Six defined requirements, from review of nonconformities to review of effectiveness |
| Preventive action | 8.5.3 | Five defined requirements, with different inputs from corrective action |
Beyond those six, the standard requires documented procedures wherever their absence could adversely affect quality — which in practice covers most core processes. Records to be maintained include management review outputs, training records, product realization planning, design and development results, purchasing evaluations, calibration records, complaints, internal audit reports, nonconforming product and CAPA.
The conventional structure is four levels: the quality manual, standard operating procedures, work instructions, and forms and records. All of it is controlled under clause 4.2.4. The most common structural error is a procedure set that is too long and too detailed to be followed, which produces a system that is compliant on paper and not used in practice — and an audit samples practice.
The audit findings that recur
The same families of nonconformity appear in Notified Body audits and FDA inspections year after year.
| Finding | What it looks like | Clause |
|---|---|---|
| Design control gaps | Missing or inadequate design inputs and outputs, verification and validation plans, or design transfer | 7.3 |
| Risk management in a silo | Risk treated as a document produced once, rather than integrated from design inputs through post-market | 7.1, 8.2 |
| Software validation gaps | Software used in the quality system, in production or in monitoring not validated to a level proportionate to risk | 4.1.6, 7.5.6, 7.6 |
| Supplier management weakness | Critical suppliers qualified once and never re-evaluated; monitoring criteria undefined | 7.4 |
| CAPA effectiveness never verified | CAPAs closed when the action is implemented, with no check that the problem stopped recurring | 8.5.2 |
| Management review as a formality | Minutes recording attendance and a decision to continue, with no evidence of engagement with the data | 5.6 |
| Reactive complaint handling | Individual complaints processed, no trend analysis across them | 8.2.1, 8.4 |
Three of these seven concentrate in clause 8, which is consistent with where audits spend their time: clause 8 is where a quality system either produces evidence of its own effectiveness or does not.
Implementation roadmap
Implementing from scratch, or bringing an existing system to full compliance, is a nine to eighteen month project for most small and medium organisations. The sequence below reflects the order the work has to happen in, not the order it is usually attempted.
Phase 1, gap analysis. Compare current practice against each clause, produce a prioritised list of gaps, and decide the certification scope: which sites, which product lines, which processes. Manufacturers transitioning from the old FDA QSR should focus on what the QSR did not require — design controls for Class I devices, and the expanded documentation.
Phase 2, documentation. Start with the six mandatory procedures and build outward. Keep them concise and written for the people who will use them; a procedure nobody follows is a nonconformity waiting to be sampled.
Phase 3, roll-out and training. Training must be documented and its effectiveness evaluated, which means evidence that staff can apply the requirements, not a signed attendance sheet.
Phase 4, internal audit. At least one full cycle covering every clause in scope, conducted by trained auditors independent of the processes audited. Findings go through the CAPA system.
Phase 5, management review. A formal review covering all required inputs. This is what demonstrates that the system is operating and generating data rather than sitting in a folder.
Phase 6, certification audit. Two stages: documentation review, then on-site assessment of implementation. Major nonconformities must be resolved before the certificate issues; minor ones need a corrective action plan. Annual surveillance and a three-year recertification cycle follow.
Phases 4 and 5 are the ones organisations try to compress, and they are the ones that cannot be. The certification body needs to see a quality system that has been running: an audit that found things, CAPAs that were opened and closed, a management review that reacted to data. A system certified into existence three weeks before the audit has no history to show, and that absence is itself the finding.
ISO 13485 and MDSAP
MDSAP allows a single audit by an authorised Auditing Organization to satisfy the regulatory audit requirements of Australia, Brazil, Canada, Japan and the United States. It is voluntary except in Canada, and it remains available under the QMSR framework.
The audit covers ISO 13485 plus the country-specific regulatory requirements of each participating jurisdiction, which is why the incremental effort for an already-certified manufacturer is manageable: what is added is the regulatory layer, not the quality system. The structural difference is that MDSAP audits by process across seven chapters while most ISO 13485 systems are documented by clause, and remapping between the two is the work most often underestimated. Our guide to MDSAP audits covers the chapters, the grading system and the preparation sequence.
Where the standard stands today
ISO 13485:2016 entered systematic review in January 2025, as every ISO management system standard does on a five-year cycle, and was reconfirmed as current. There is no announced revision and no published timetable for one.
A separate guidance document on applying ISO 13485:2016 has been taken up as a work item and is expected to accompany rather than replace the standard. Topics that have been raised for a future edition include cybersecurity, artificial intelligence and the ISO Harmonized Structure, but none of that is settled and none of it is in force.
The practical answer is that the 2016 version is the version, and it is likely to remain so for some time — not least because the FDA has just written it into 21 CFR Part 820, and any future ISO revision would not apply to the QMSR automatically. Planning work against a revision that has not been announced is planning against a date that does not exist.
✦ Complete catalogue
Find the documentation you need — instantly.
Whether you need a complete kit or just one specific SOP, the catalogue has it. Individual process packages and complete bundles, all instantly downloadable and fully editable.
✓ Complete bundles or individual packages
✓ Individual process packages from €69 each
✓ ISO 13485 · MDSAP · EU MDR · EU IVDR
Frequently asked questions
Is ISO 13485 certification mandatory for EU MDR compliance?
Not explicitly. The MDR does not name the standard, but ISO 13485 is the accepted means of demonstrating compliance with the quality system requirements of Article 10(9), and Notified Bodies use it as their reference framework when auditing under conformity assessment. For Class IIa, IIb and III devices the Notified Body assessment of the quality system is mandatory, and there is no realistic route to CE marking without ISO 13485 compliance.
Does ISO 13485 certification replace an FDA inspection?
No. The QMSR incorporates ISO 13485:2016 by reference as the legal standard, but the FDA assesses compliance through its own inspections. A certificate of conformance issued by a certification body does not exempt a manufacturer from inspection, and the FDA neither requires nor issues such certificates.
How many clauses does ISO 13485 have?
Eight. Clauses 1 to 3 cover scope, normative references, and terms and definitions. The operational requirements are in clause 4 (quality management system), clause 5 (management responsibility), clause 6 (resource management), clause 7 (product realization) and clause 8 (measurement, analysis and improvement).
Which documented procedures does ISO 13485 require?
Six are required outright: control of documents, control of records, internal audit, control of nonconforming product, corrective action and preventive action. Beyond those, a documented procedure is required for any process whose absence of documentation could adversely affect quality, which in practice covers most core processes.
How long does ISO 13485 certification take?
Typically nine to eighteen months for a small or medium manufacturer, depending on the maturity of the existing system, the certification scope and the availability of a certification body. Organisations already operating under ISO 9001 or the previous FDA quality system requirements generally need less. The internal audit and management review phases cannot be compressed, because the certification body needs to see records the system has actually produced.
What is the difference between ISO 13485 and MDSAP?
ISO 13485 is the standard. MDSAP is an audit programme that uses ISO 13485 as its reference and adds the specific regulatory requirements of five participating countries. An MDSAP audit therefore covers both the standard and the national requirements, in a process-based sequence of seven chapters rather than clause by clause.
Is a new version of ISO 13485 coming?
None has been announced. ISO 13485:2016 was placed into systematic review in January 2025 and reconfirmed as current, with no published timetable for a revision. Topics including cybersecurity and artificial intelligence have been raised for a future edition, but nothing is settled. The 2016 version is the version in force.
Does ISO 13485 require validating the software used in the quality system?
Yes. Clause 4.1.6 requires validation of software used in the quality management system, with the approach proportionate to the risk associated with its use. Parallel requirements apply to software used in production and service provision under 7.5.6 and in monitoring and measurement under 7.6. The recognised method is GAMP 5. This is a separate obligation from IEC 62304, which governs software that is a medical device or embedded in one.
Conclusions
ISO 13485 became more important in February 2026 without changing a word, because the FDA wrote it into law. One quality system now serves the EU, the US, Canada, Japan, Brazil and Australia — which makes the standard the highest-leverage investment a manufacturer can make, and the most expensive thing to get wrong.
Two things separate systems that pass audits from systems that do not, and neither is about the documentation. The first is that the procedures are followed, because an audit samples practice and not the manual. The second is that clause 8 produces evidence: audits that find things, CAPAs whose effectiveness was verified, management reviews that reacted to data. A system with a complete document set and an empty record trail has nothing to show.
If you are building or upgrading the system, the ISO 13485 Documentation Kit covers the full QMS scope aligned with both the EU MDR and the FDA QMSR, and the Combined Kit extends it to the five MDSAP markets with a deduplicated structure.
Related articles
- ISO 13485 CAPA: Clauses 8.5.2 and 8.5.3 Requirements
- ISO 13485 Internal Audit Checklist
- ISO 13485 Design Controls and the Design History File
- ISO 13485 Supplier Management and Qualification
- MDSAP Audits: Process Chapters, Grading and Preparation
- ISO 14971 Risk Management for Medical Devices
- EU MDR Technical Documentation Requirements