ISO 13485 certification is how a medical device organisation demonstrates that its
quality management system meets the international standard for devices. This guide covers what the
process actually involves, how long it takes, what drives the cost, and what changed when the FDA
began enforcing QMSR.
What ISO 13485 certification is — and is not
Certification is an independent audit of your quality management system against
ISO 13485:2016,
carried out by an accredited certification body. It results in a certificate covering a defined
scope: your legal entity, sites and device types.
ISO 13485 certification is not market approval. It does not clear a device for
sale in any jurisdiction. CE marking under EU MDR needs a notified body conformity assessment;
US market entry needs 510(k), De Novo or PMA as applicable. Certification demonstrates the
system is sound — the device still has its own regulatory route. Conflating the two is
the single most common misunderstanding among first-time applicants.
Why this matters more since February 2026
The FDA published the Quality Management System Regulation (QMSR) in January 2024 and began enforcing it on 2 February 2026. It amends 21 CFR Part 820 to incorporate ISO 13485:2016 by reference, replacing most of the old Quality System Regulation text. The FDA also retired the Quality System Inspection Technique (QSIT) on that date and now inspects against Compliance Program 7382.850.
The practical consequence: for a manufacturer selling into the United States, ISO 13485 is no longer just a commercial or CE-marking convenience. Its requirements are the substance of the federal regulation. A QMS built to ISO 13485 is now the same QMS the FDA expects to inspect.
The stages of ISO 13485 certification
- Gap analysis (optional but sensible). Compare what you do against what the
standard requires, before anyone external looks. - Implementation. Build the QMS: documentation, risk management, design controls,
supplier controls, and the records that evidence them. This is where most of the elapsed time goes. - Internal audit and management review. Both are mandatory before the
certification audit. A certification body will ask to see them and will raise a nonconformity if
they are missing. - Stage 1 audit. A documentation and readiness review. The auditor checks your
quality manual, scope, medical device file, procedures and whether internal audit and management
review have genuinely run. Stage 1 findings tell you whether stage 2 is realistic. - Stage 2 audit. The full assessment of implementation and effectiveness, on
site, sampling records and interviewing staff. - Nonconformity closure. Majors must be corrected and verified before the
certificate is issued; minors usually need a corrective action plan. - Surveillance and recertification. Surveillance audits annually, full
recertification on a three-year cycle.
ISO 13485 certification: how long it takes
For an organisation starting from no formal QMS, nine to eighteen months to
certificate is realistic. Six months is achievable only if you already run a mature quality system
and are essentially re-badging it. The gating factors are rarely the audits themselves — they
are design history documentation, supplier evaluation records, and accumulating enough operating
history for internal audit and management review to have something real to examine.
What drives ISO 13485 certification cost
- Audit days, which scale with headcount, number of sites and device risk class.
- Scope — design and development in scope costs more than manufacture alone.
- Consultancy, if you use it, which is usually the largest single line.
- Documentation effort — the internal time to write the QMS, which is the
cost most often underestimated and the one a template set reduces most directly. - Remediation after stage 1 or 2, which is avoidable with an honest gap analysis.
Certification body fees are the visible cost; internal effort is usually the larger one.
Choosing an ISO 13485 certification body
Check that it is accredited by a recognised body, that its accreditation covers ISO 13485 and
your device codes, and — if you need CE marking — whether it is also a notified body under
EU MDR. Using one organisation for both can simplify auditing, but they remain separate assessments
with separate scopes.
Common reasons first audits fail
- No internal audit or management review yet. Both are prerequisites, not
follow-ups. - Risk management that stops at a document. ISO 13485 threads risk through the
whole product lifecycle — see our guide to
ISO 13485 risk management. - Design and development records that cannot be reconstructed. Design controls are
audited in detail and gaps here are hard to remediate late. - Supplier evaluation asserted but not evidenced.
- A scope statement that does not match what the company actually does.
References
- ISO 13485:2016 — the standard itself on iso.org.
- FDA Quality Management System Regulation (QMSR) — the rule that incorporated ISO 13485 into 21 CFR Part 820.
More on ISO 13485
- ISO 13485 certification — you are here
- ISO 13485 mandatory documents
- ISO 13485 risk management
- ISO 13485 vs ISO 9001
- ISO 13485 internal audit
- ISO 13485 risk assessment template
All of these are covered by the ISO 13485 Toolkit, or try the free ISO 13485 templates first.