Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Infographic answering is ISO 13485 worth it in 2026 with audit days, QMSR date and MDSAP regulators

Is ISO 13485 Worth It? The Complete 2026 Cost-Benefit Case

Is ISO 13485 worth it in 2026? For a company that places medical devices on the European or Canadian market, yes — and the arithmetic is not close. For a US-only manufacturer, the answer changed on 2 February 2026, and not in the direction most people assume. This is the cost-benefit case, with the audit days priced off the accreditation rule your certification body actually has to follow.

The complication behind is ISO 13485 worth it is that ISO 13485 is the rare standard that regulators reference but do not always accept a certificate for. Three jurisdictions treat it three different ways. Get that wrong and you either buy a certificate nobody asked for, or skip one that blocks a licence application.

Free gap assessment

How much of ISO 13485 could you evidence today?

Score clauses 4 to 8, free, with the FDA QMSR and EU MDR duties kept separate so you can see what is the standard and what is the regulator.

Run the free ISO 13485 gap assessment →

Is ISO 13485 worth it? The short answer by situation

Find your row before you read the cost model.

Your situationVerdictWhy
CE marking a Class IIa/IIb/III device under EU MDRYes — effectively mandatoryYour notified body audits a QMS against Article 10(9). EN ISO 13485:2016+A11:2021 is the harmonised route.
Applying for a Health Canada licence (Class II–IV)Yes, but as MDSAPHealth Canada asks for an MDSAP certificate, not a plain ISO 13485 one.
Selling in the US only, post-QMSROptional — high readiness valueFDA will not issue or require a certificate. You get inspection readiness, not market access.
Contract manufacturer or component supplierUsually yesCustomers push their Article 10 and Part 820 obligations down the chain in purchasing controls.
Pre-revenue, design not frozenNot yetDesign controls need real design history to audit. Build the system, certify later.
Software that is not a medical deviceNoISO 27001 or SOC 2 answers the questions your buyers are actually asking.

What ISO 13485 certification really costs over three years

The largest invoice line is not negotiable and not a matter of opinion. Certification bodies auditing ISO 13485 work to ISO/IEC 17021-1 plus IAF MD 9:2023 Issue 5, issued 20 November 2023. Its Annex D is normative, and Table D.1 fixes the initial audit time — Stage 1 and Stage 2 combined — from your effective number of personnel. (IAF itself ceased operations on 1 January 2026 and its accreditation-forum role passed to Global ACI; the mandatory documents carried across unchanged.)

Medical device audits run materially longer than generic quality audits, because MD 9 disapplies the ISO 9001 table and substitutes its own:

Effective personnelISO 13485 initial audit daysGeneric QMS days for comparisonIndicative initial CB fee
1–531.5$3,300 – $5,400
16–2553$5,500 – $9,000
26–4564$6,600 – $10,800
86–125107$11,000 – $18,000

Fees assume an indicative US day rate of $1,100 – $1,800, which no standard sets. Treat it as a budgeting band, not a quote, and note that travel is excluded from audit time and billed separately. Surveillance runs at roughly one third of the initial audit time each year, with a practical floor of one day. Recertification is recalculated at the end of the three-year cycle.

So a 20-person device manufacturer is looking at something like this across a full cycle:

LineYear 1Years 2–3Three-year total
Certification body audit days5 days — $5,500–$9,000~1.7 days each year — $3,700–$6,100$9,200 – $15,100
Certificate, application and travel$800–$2,500$700–$2,000$1,500 – $4,500
Documentation (templates route)$99—$99
Documentation (consultant route)$15,000–$40,000$0–$8,000$15,000 – $48,000
Internal staff time400–900 hours150–300 hours/year700–1,500 hours

Two honest observations, and together they settle is ISO 13485 worth it for most mid-sized manufacturers. First, the staff-time line is bigger than everything above it and appears on no quote you will ever receive. Second, the spread between the templates route and the consultant route is larger than the entire audit bill. That is where the decision actually gets made.

What you get back

European market access you cannot buy another way

The strongest case that ISO 13485 is worth it starts in Europe. EU MDR Article 10(9) requires manufacturers to establish, document, implement and maintain a quality management system. EN ISO 13485:2016+A11:2021 was cited as a harmonised standard under the MDR in January 2022 and under the IVDR shortly after, which gives you a presumption of conformity for the parts it covers. Read the qualifier carefully: the amendment’s Annex ZA lists where the standard does not reach Article 10, and those gaps are yours to close. Certification is the on-ramp, not the finish line.

A Canadian licence application that will actually be processed

Health Canada has required an MDSAP certificate as QMS evidence for Class II, III and IV device licences since 2019. MDSAP is audited against ISO 13485:2016 plus the country-specific requirements of five regulators — FDA, Health Canada, the TGA in Australia, ANVISA in Brazil and MHLW/PMDA in Japan. A standalone ISO 13485 certificate does not substitute for it. If Canada is anywhere on your roadmap, plan the MDSAP route from the start rather than certifying twice.

Inspection readiness in the United States — but not a passport

This is the part that changed. The FDA’s Quality Management System Regulation took effect on 2 February 2026, amending 21 CFR Part 820 to incorporate ISO 13485:2016 by reference. Most of Part 820 now points at a clause of the standard instead of restating the requirement. A handful of sections survive because FDA judged the standard insufficient: scope, definitions, incorporation by reference, the quality management system requirements, control of records, and device labeling and packaging controls.

What did not change is FDA’s position on certificates. Its QMSR guidance is unambiguous: FDA will not require certificates of conformance to ISO 13485, will not issue them, and a certificate will not exempt a manufacturer from an FDA inspection. FDA also retired the Quality System Inspection Technique on 2 February 2026 in favour of the updated compliance program. So the US value of certification is that an accredited auditor has already walked your system against the text your investigator will now be applying — which is worth real money the week an inspection lands, and worth nothing as a document you wave at the door.

Stability, which is worth more than it sounds

ISO/TC 210 reconfirmed ISO 13485:2016 at systematic review, and there is no revision project running. Anyone certifying this year is not buying into a transition deadline — a genuine contrast with ISO 9001, where the 2026 edition forces a migration. Your three-year cycle will be audited against the edition you implemented.

Is ISO 13485 worth it for a small device manufacturer?

Run the arithmetic rather than the argument. A five-person Class IIa manufacturer sits in the 1–5 band: three initial audit days, so $3,300 to $5,400 in certification body fees, plus one surveillance day a year at $1,100 to $1,800. Add certificate and travel costs and the three-year external bill lands somewhere around $6,000 to $10,000.

Now price the alternative. One CE marking application stalled at a notified body for a quarter, one distributor agreement that lapses because you cannot evidence a QMS, one Health Canada licence you cannot apply for — any of those costs more than the certificate, usually by an order of magnitude. That is the whole case. Is ISO 13485 worth it at this size? If a regulated market is in your plan, the question is really whether you can afford the delay of not having it.

The variable you control is the documentation route. Three hundred hours of a quality manager writing procedures from scratch, at a fully loaded cost, dwarfs the audit fee. Templates collapse that line without touching the audit line.

When ISO 13485 is not worth it

Anyone asking is ISO 13485 worth it deserves the four situations where the honest answer is no, or not yet:

  • US-only, with no international plan. FDA neither wants nor accepts the certificate. Implement the standard, because Part 820 now points at it, but paying a certification body for a document your only regulator ignores is a discretionary purchase. Spend it on internal audit capability instead.
  • Design not frozen. Design controls are the clause set auditors probe hardest, and they need a real design history file with real review records. Certifying before you have one produces findings, not a certificate.
  • You are not a manufacturer. Distributors, importers and some component suppliers have obligations that ISO 13485 does not map to cleanly. Check what your customer’s purchasing controls actually demand before assuming certification is the answer.
  • Cash runway under twelve months. The audit fee is affordable; the 400 to 900 hours of internal effort in year one is not, if those hours are the ones building your device.

How to make the return larger

Assume you have answered is ISO 13485 worth it with a yes. Five levers make the return larger, in order of size:

  • Scope precisely. Table D.1 keys off effective personnel within the certification scope, counted across shifts. Sites and functions genuinely outside the scope do not belong in the count. This is the cheapest legitimate reduction available.
  • Choose MDSAP once, not ISO 13485 then MDSAP. If Canada, Brazil, Australia or Japan is plausible within three years, start there. MDSAP carries its own audit time and is not a discount, but doing it twice is worse.
  • Map to QMSR while you write, not after. The clauses Part 820 still states in its own words — records control, labeling and packaging controls, definitions — are exactly where a 13485-only system leaves a hole.
  • Reuse the ISO 14971 risk management file. It is required anyway, feeds clause 7.1 planning and post-market surveillance, and is the single most reused artefact in the pack.
  • Do not pay a consultant to produce documents. Pay one for gap assessment and internal audit, where judgement is the product. Document generation is a solved problem.

If you are taking the documentation in-house, our ISO 13485 Toolkit is the 126-template pack for exactly this job — aligned to ISO 13485:2016 and cross-referenced to FDA QMSR, EU MDR/IVDR and ISO 14971, for $99. Against an audit day rate, it pays for itself if it saves two hours.

Is ISO 13485 worth it? Frequently asked questions

Does the FDA accept an ISO 13485 certificate under the QMSR?

No. FDA has stated it will not require certificates of conformance to ISO 13485 and will not issue them, and that holding one does not exempt a manufacturer from inspection. The QMSR incorporates the standard’s requirements; it does not import third-party certification.

Is ISO 13485 worth it if I already hold ISO 9001?

The systems overlap, but ISO 13485 adds regulatory obligations ISO 9001 has no equivalent for — design controls, the medical device file, sterile product requirements, traceability and complaint handling. Expect to reuse document control and management review, and to build most of the rest. See our ISO 13485 vs ISO 9001 comparison for the clause-level differences.

How long does certification take?

Six to eighteen months from kickoff for most first-time manufacturers, with the spread driven by documentation maturity rather than company size. Our ISO 13485 certification timeline breaks it down phase by phase.

Can we get certified without a consultant?

Yes, and many small manufacturers do. The binding constraint is having someone who can run a competent internal audit before Stage 2, since unaudited systems are the most common reason first attempts stall. Buy that skill; template the rest.

Will ISO 13485 be revised soon?

No revision project is under way. ISO/TC 210 reconfirmed the 2016 edition at systematic review, and the FDA’s decision to incorporate that exact edition by reference makes near-term change less likely, not more.

The verdict

Is ISO 13485 worth it? For anyone touching the EU or Canadian markets, the question is academic — certification is the price of entry and the three-year external cost is small against a single stalled approval. For US-only manufacturers, the QMSR made the standard mandatory in substance while leaving certification optional in form, so the right move is to implement fully and certify only if a customer, an investor or an export plan asks for the paper. The one decision that genuinely moves the number is how you produce the documentation, not which certification body you choose.

Start with the full picture in our guide to ISO 13485 certification, then price your own audit days against the ISO 13485 certification cost breakdown and check your US position with the QMSR vs ISO 13485 gap analysis.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.