An ISO 13485 certificate is not FDA compliance, and it is not an EU MDR conformity assessment. Since 2 February 2026 the US quality regulation has been built on ISO 13485 — but with additions on top, and your management review and internal audit records are now inspectable in a way they never were before.
This assessment scores 89 questions: clauses 4 to 8 of the standard, then the FDA and EU duties in their own sections so you can see exactly where the standard stops and the regulator starts. It is free, it saves as you go, and you can stop and come back to it.
What this is
A clause-by-clause pass over ISO 13485:2016, which remains current after its 2025 systematic review. We have the background elsewhere — the standard explained, the mandatory documents, certification, the FDA QMSR and how QMSR compares to the standard. Come here when you want a score.
What it covers
| Area | Questions |
|---|---|
| Scope and regulatory role | 4 |
| 4 — Quality management system, Medical Device File, documents and records | 9 |
| 5 — Management responsibility and management review | 11 |
| 6 — Resources, competence, work environment and contamination | 4 |
| 7 — Product realization, design, purchasing, production and sterilisation | 30 |
| 8 — Feedback, complaints, audit, nonconformity and CAPA | 14 |
| FDA QMSR overlay | 7 |
| EU MDR and IVDR overlay | 10 |
Why the overlays are separate
This is where most off-the-shelf tools go wrong. ISO 13485 requires a procedure for reporting to regulatory authorities but sets no deadline at all — the clocks come from the regulations, and they are measured in days. It requires a Medical Device File, which is not EU technical documentation. It says nothing about general safety and performance requirements, the Person Responsible for Regulatory Compliance, unique device identification or periodic safety update reports.
Fold those into the clause questions and you get a score that says you are compliant when you are only certified. So they sit in their own sections, and you can see the two pictures side by side.
Where a 9001 mindset gets it wrong
There is no Annex SL here. No context of the organisation, no interested parties, no risks and opportunities clause, no organisational knowledge. Clauses run 4 to 8 on the older architecture, and the 2024 climate-change amendment does not apply to this standard at all.
There is no continual improvement obligation in the ISO 9001 sense, and no customer satisfaction requirement. The standard talks about maintaining effectiveness, and the analogue of satisfaction is feedback from production and post-production — a wider duty, not a survey.
The quality manual, the management representative and preventive action all survive here after ISO 9001 dropped them. Systems converted from a 9001 base often no longer have a preventive action procedure at all.
Named procedures, not “documented information”. ISO 13485 specifies particular documented procedures by name, and the assessment asks for them individually.
How the scoring works
| Status | Weight | Means |
|---|---|---|
| Not started | 0% | No policy, process or activity exists |
| Planned | 25% | Agreed and scheduled, nothing in place yet |
| Partially implemented | 50% | In place for part of the scope, or applied inconsistently |
| Implemented, not evidenced | 75% | Operating as intended, but you could not prove it today |
| Implemented and evidenced | 100% | Operating as intended, with records someone could sample |
| Not applicable | — | A justified exclusion, removed from the score |
Not applicable carries a specific meaning in this standard. Where a requirement is qualified as “appropriate”, it is treated as appropriate unless you can document a justification otherwise — so the burden of proof sits with you, and the justification belongs in your quality manual.
Free score, or the full report
The assessment and your overall score are free. The full report is a one-off $39 and gives you every question with your status and notes, the score broken down by clause and overlay, a prioritised gap list, and the documents from the ISO 13485 Toolkit that close each gap — as a PDF and a working Excel file.
How long does it take?
About 45 minutes. Clause 7 is half the assessment; if you do not sterilise, implant or install, several of those are not applicable and it moves faster.
What to do with your score
Below 40% — start with the risk management file and the Medical Device File. The risk file is the single most commonly raised nonconformity in this standard, and the device file is usually content that exists but was never compiled.
40–70% — look at the two overlays separately. A strong clause score with a weak overlay score is the specific failure mode this assessment is built to expose.
Above 70% — check whether the risk file is actually live. Feed it your last quarter of complaints, CAPAs and process changes and see whether anything moves. If nothing does, it is frozen at design freeze, and an auditor will find that.
Frequently asked questions
Is this assessment really free?
Yes. All 89 questions, the breakdown by clause and overlay, and your overall score cost nothing. The $39 report is optional.
Is ISO 13485 being revised?
No. The 2016 edition was reconfirmed by systematic review in 2025 and remains current. Claims of a 2026 or 2027 revision circulating on social media are not supported by anything ISO has published.
Does an ISO 13485 certificate satisfy the FDA?
No. FDA does not require, issue or accept certificates of conformance to ISO 13485, and MDSAP certification does not exempt you from inspection. The standard is now the body of the US requirement, but with additions on design controls, complaint and servicing record content, labelling and packaging, and the obligations that sit outside the quality regulation entirely.
What changed most in practice under the QMSR?
Management review records, internal audit reports and supplier audit reports are now inspectable. Under the old regulation they were exempt from routine inspection. Keep writing candid findings — but make sure the record around them shows they were acted on.
Does it cover EU MDR?
It covers the MDR and IVDR duties that sit alongside the standard, as a scoping check rather than a full conformity assessment: the responsible person, safety and performance requirements, technical documentation, clinical evaluation, post-market surveillance, vigilance clocks, identification and registration, and the declaration of conformity.
Can I use this for a client?
Yes. Run one assessment per client organisation.
What happens to my answers?
They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.