Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 13485 Certification — ISO 13485:2016 medical device quality management

ISO 13485 Certification Explained: A Clear, Essential Guide

ISO 13485 certification is how a medical device organisation demonstrates that its
quality management system meets the international standard for devices. This guide covers what the
process actually involves, how long it takes, what drives the cost, and what changed when the FDA
began enforcing QMSR.

What ISO 13485 certification is — and is not

Certification is an independent audit of your quality management system against
ISO 13485:2016,
carried out by an accredited certification body. It results in a certificate covering a defined
scope: your legal entity, sites and device types.

ISO 13485 certification is not market approval. It does not clear a device for
sale in any jurisdiction. CE marking under EU MDR needs a notified body conformity assessment;
US market entry needs 510(k), De Novo or PMA as applicable. Certification demonstrates the
system is sound — the device still has its own regulatory route. Conflating the two is
the single most common misunderstanding among first-time applicants.

Why this matters more since February 2026

The FDA published the Quality Management System Regulation (QMSR) in January 2024 and began enforcing it on 2 February 2026. It amends 21 CFR Part 820 to incorporate ISO 13485:2016 by reference, replacing most of the old Quality System Regulation text. The FDA also retired the Quality System Inspection Technique (QSIT) on that date and now inspects against Compliance Program 7382.850.

The practical consequence: for a manufacturer selling into the United States, ISO 13485 is no longer just a commercial or CE-marking convenience. Its requirements are the substance of the federal regulation. A QMS built to ISO 13485 is now the same QMS the FDA expects to inspect.

The stages of ISO 13485 certification

  1. Gap analysis (optional but sensible). Compare what you do against what the
    standard requires, before anyone external looks.
  2. Implementation. Build the QMS: documentation, risk management, design controls,
    supplier controls, and the records that evidence them. This is where most of the elapsed time goes.
  3. Internal audit and management review. Both are mandatory before the
    certification audit. A certification body will ask to see them and will raise a nonconformity if
    they are missing.
  4. Stage 1 audit. A documentation and readiness review. The auditor checks your
    quality manual, scope, medical device file, procedures and whether internal audit and management
    review have genuinely run. Stage 1 findings tell you whether stage 2 is realistic.
  5. Stage 2 audit. The full assessment of implementation and effectiveness, on
    site, sampling records and interviewing staff.
  6. Nonconformity closure. Majors must be corrected and verified before the
    certificate is issued; minors usually need a corrective action plan.
  7. Surveillance and recertification. Surveillance audits annually, full
    recertification on a three-year cycle.

ISO 13485 certification: how long it takes

For an organisation starting from no formal QMS, nine to eighteen months to
certificate is realistic. Six months is achievable only if you already run a mature quality system
and are essentially re-badging it. The gating factors are rarely the audits themselves — they
are design history documentation, supplier evaluation records, and accumulating enough operating
history for internal audit and management review to have something real to examine.

What drives ISO 13485 certification cost

  • Audit days, which scale with headcount, number of sites and device risk class.
  • Scope — design and development in scope costs more than manufacture alone.
  • Consultancy, if you use it, which is usually the largest single line.
  • Documentation effort — the internal time to write the QMS, which is the
    cost most often underestimated and the one a template set reduces most directly.
  • Remediation after stage 1 or 2, which is avoidable with an honest gap analysis.

Certification body fees are the visible cost; internal effort is usually the larger one.

Choosing an ISO 13485 certification body

Check that it is accredited by a recognised body, that its accreditation covers ISO 13485 and
your device codes, and — if you need CE marking — whether it is also a notified body under
EU MDR. Using one organisation for both can simplify auditing, but they remain separate assessments
with separate scopes.

Common reasons first audits fail

  • No internal audit or management review yet. Both are prerequisites, not
    follow-ups.
  • Risk management that stops at a document. ISO 13485 threads risk through the
    whole product lifecycle — see our guide to
    ISO 13485 risk management.
  • Design and development records that cannot be reconstructed. Design controls are
    audited in detail and gaps here are hard to remediate late.
  • Supplier evaluation asserted but not evidenced.
  • A scope statement that does not match what the company actually does.

References

More on ISO 13485

All of these are covered by the ISO 13485 Toolkit, or try the free ISO 13485 templates first.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.