+ 1-510-330-1361
Most companies pursue ISO 13485 only after an outside force requires it — a key customer adds it to their approved supplier requirements, an FDA inspection raises serious questions about the existing quality system, or EU MDR obligations through Notified Body assessments push others there — and many bring in consultants to help navigate the process. Whatever brought you here, this guide covers what the standard actually requires, why it exists in its current form, and what certification realistically involves for a medical device manufacturer or supplier.
MG Environmental Consulting supports medical device manufacturers, contract manufacturers, and component suppliers through ISO 13485 certification, starting with the initial gap assessment and continuing through the certification audit and ongoing surveillance. Those trying to figure out where to start, or who have been through a gap analysis and need help closing what it found, will find that is exactly the kind of work we do.
The ISO Survey 2024, developed in collaboration with the International Accreditation Forum, reported 31,215 valid ISO 13485:2016 certificates worldwide at year-end 2024, covering 43,957 registered sites. That number has grown steadily and is expected to keep climbing as regulatory bodies globally align their quality system requirements to this standard.
ISO 13485:2016 is the international standard for quality management systems in the medical device industry. It was published by the International Organization for Standardization and applies to organizations involved in the design, manufacture, installation, and servicing of medical devices and related services. It replaced the 2003 edition and brought substantially stronger requirements around risk management, supplier oversight, and software validation.
The reason this standard exists, and the reason regulators take it seriously, is straightforward. Medical device failures don’t just mean unhappy customers. A nonconforming surgical implant, diagnostic device, or patient monitoring system can directly harm or kill someone. ISO 13485 gives regulators, procurement bodies, and healthcare systems a structured, auditable way to verify that a manufacturer’s processes are genuinely under control, not just described in a manual on a shelf.
Organizations coming from ISO 9001 sometimes assume the transition to ISO 13485 will be straightforward. Some of the foundational concepts are shared: process-based thinking, documented information, internal audits, management review. But the differences are significant enough that the two standards really are distinct frameworks with different priorities.
ISO 9001 treats risk-based thinking as a general principle that runs through the standard. ISO 13485 treats risk management as a specific, documented discipline that must be applied throughout product realization. The corresponding standard is ISO 14971, and auditors expect to see it woven into your design process, your production controls, and your post-market surveillance activities. What they’re looking for is traceability: you identified a hazard, you implemented a control, you assessed whether the residual risk is acceptable. That chain of evidence needs to exist in your records.
ISO 13485 is a documentation-heavy standard, and that’s not incidental. It requires a Device Master Record (DMR) containing all specifications, production procedures, and quality requirements for a finished device, and a Device History Record (DHR) documenting the actual production history of each batch or unit. Both must be maintained in a controlled manner and retrievable on demand during regulatory inspections. Incomplete or disorganized device records are consistently among the most cited deficiencies in both FDA inspections and certification audits.
Clause 7.3 requires a structured design and development process with defined stages, documented inputs and outputs, formal reviews, verification activities, validation activities, and controlled design transfer. The key word in all of that is documented. It’s not enough to go through the right steps. You need records showing that each step happened, that outputs were reviewed against inputs, and that the finished device was validated against user needs under actual or simulated conditions.
I’ve seen manufacturers with genuinely good engineering practices get tripped up in audits because the work was done correctly but the records weren’t there. Good engineering isn’t the same as a conforming design control process.
Where manufacturing processes produce output that can’t be fully verified through post-process inspection, ISO 13485 requires process validation. This covers sterilization, injection molding of critical components, adhesive bonding, certain welding processes, and clean room assembly, among others. Validation work must be captured in a protocol, an execution record, and a validation report that together demonstrate the process reliably produces a conforming product under defined conditions.
Clause 7.4 requires documented criteria for supplier evaluation and selection, an approved supplier list, and supplier monitoring activities proportionate to the risk of the purchased product or service. This means periodic re-evaluations, not a one-time qualification that never gets revisited. The standard holds you responsible for what your suppliers deliver. If a nonconforming component makes it through incoming inspection, the corrective action still lands on your QMS.
Clause 8 covers monitoring, measurement, and improvement. Medical device manufacturers must operate a post-market surveillance system that collects and analyzes real-world data: complaint records, adverse event reports, service data, and feedback from the field. The corrective and preventive action (CAPA) process must be documented and must include effectiveness checks confirming that root causes were actually addressed, not just that actions were taken. This is an area where weak systems are easy to spot. If your CAPA records show that the same issue recurs quarterly and each time it gets a new corrective action, the system isn’t working.
In February 2024, the FDA finalized its Quality Management System Regulation (QMSR), which replaced the legacy Quality System Regulation under 21 CFR Part 820 with requirements that align directly to ISO 13485:2016. The rule took effect February 2, 2026.
For US device manufacturers, this is the most significant change to FDA quality system requirements in decades. It means the gap between FDA compliance and ISO 13485 conformance has largely closed. Manufacturers who previously maintained two separate quality systems, one for the FDA and one for international markets, can now operate within a single harmonized framework. Those who don’t yet hold ISO 13485 certification but sell in the US are already subject to requirements that mirror it.
Most small to mid-size device manufacturers complete certification in six to twelve months. Multi-site operations and organizations with broad product portfolios typically take longer. Here is how the process actually unfolds.
The gap analysis compares your current quality management practices against ISO 13485:2016 clause by clause. The output should identify three distinct types of gaps: processes that don’t exist at all, processes that exist but aren’t documented, and processes that are documented but don’t match how work is actually done. Each type requires a different response. Treating all three the same way usually results in documentation that looks complete but doesn’t close the real gaps.
Build out your quality manual, documented procedures, work instructions, and record forms based on what the gap analysis found. Certain documented procedures are explicitly required by ISO 13485 and can’t be omitted: document control, record control, internal audits, control of nonconforming products, corrective action, and preventive action. Your Device Master Record structure also needs to be established at this stage.
A binder full of procedures doesn’t create a functioning quality system. The documented processes need to be deployed into actual daily work, and your people need to understand their role in the system. Competency-based training, where you actually verify that someone can perform the task correctly rather than just confirm they attended a session, satisfies the standard better and produces better real-world outcomes.
Before the certification audit, run a full internal audit of your QMS against ISO 13485 requirements. Use auditors who are trained and independent from the areas they review. Document the findings, review them in a formal management review meeting with the required agenda items: audit results, complaint data, process performance, customer feedback, and regulatory compliance status. Close the corrective actions before the external audit. Non-conformances found internally are opportunities. Non-conformances found by the certification body become formal findings.
The certification body conducts a Stage 1 audit that reviews your documented QMS for conformance to the standard. The Stage 2 audit is on-site and verifies that the documented system is actually implemented and generates objective evidence. Both stages need to go well. Successful completion results in a three-year certificate with annual surveillance audits in years one and two.
"The organizations that struggle after certification are almost always the ones that built the QMS around the audit rather than around their actual production processes. A quality system that only functions when an auditor is watching isn't really a quality system."
— Puneet Gupta, ISO Consultant, MG Environmental Consulting
Treating document control as a clerical task rather than a controlled process is the most common and consequential mistake we see. ISO 13485 requires that documents are reviewed and approved before they’re released, that obsolete versions can’t be accidentally used, and that changes go through a formal process. Organizations using shared drives with informal naming conventions almost always end up with version control problems that generate major nonconformances.
Writing procedures around an ideal process rather than the actual one is closely related. If your work instruction says incoming inspection is performed with calibrated measurement equipment but your calibration records are two years out of date, your documentation and your reality are misaligned. Auditors find this fast. But more importantly, it’s a real risk that exists whether or not an auditor ever sees it.
Underestimating the supplier control requirements is a gap we see often in organizations transitioning from informal supplier relationships into a formal QMS. Prior purchasing history and a good working relationship don’t satisfy Clause 7.4. Defined selection criteria, documented evaluations, and records of ongoing supplier monitoring are all required.
“We had a great experience working with MG Enviro. Their team was clear, professional, and easy to work with. They made the ISO certification process smooth and straightforward, highly recommend them."
— Puneet Gupta, ISO Consultant, MG Environmental Consulting
MG Environmental Consulting provides gap assessments, quality management system documentation development, internal auditor training, and pre-certification audit support for medical device manufacturers and suppliers pursuing ISO 13485 certification. We work with organizations across California and nationally, including startup device developers building a quality management system from the ground up and established manufacturers aligning with the new FDA Quality Management System Regulation requirements.
To speak with a consultant, call (510) 332-1321.