top of page

ISO 13485 Certification: A Complete Guide with Consulting Support for Medical Device Companies | My ISO Consultants

Writer: My ISO Jay
My ISO Jay
Apr 17
6 min read

Updated: Sep 18

ISO 13485:2016 remains the internationally recognized quality management system standard for organizations involved in medical devices and related services. It is designed around the regulatory environment of the medical device industry and emphasizes controlled processes, documented information, risk management, traceability, supplier controls, complaint handling, corrective action, and the ability to consistently meet applicable customer and regulatory requirements.


For medical device companies pursuing certification, the goal is not simply to build a set of procedures for an auditor. The Quality Management System (QMS) must reflect how the organization actually operates, produce reliable objective evidence, and be implemented well enough to withstand internal audits, certification audits, customer scrutiny, and applicable regulatory oversight.


2026 Update: ISO 13485 and the FDA QMSR

This topic is especially relevant in 2026. ISO 13485:2016 remains the current published edition of ISO 13485. In the United States, the FDA's Quality Management System Regulation (QMSR) became effective on February 2, 2026 and incorporated ISO 13485:2016 by reference into 21 CFR Part 820.


That change makes familiarity with ISO 13485 even more important for U.S. medical device manufacturers, but ISO 13485 certification and FDA compliance are not the same thing. Certification is performed by an independent certification body, while FDA compliance is a regulatory obligation. Organizations subject to the QMSR must still meet the applicable FDA requirements in addition to maintaining an effective quality management system.


The FDA also replaced its former QSIT inspection approach with the inspection process described in Compliance Program 7382.850 beginning February 2, 2026. Companies preparing for ISO 13485 certification should therefore make sure their QMS is not only certification-ready but also aligned with the regulatory requirements that apply to their products and operations.


Who Should Consider ISO 13485 Certification?

ISO 13485 can apply to organizations involved in one or more stages of the medical device life cycle, depending on their role and regulatory obligations. Certification is not universally mandatory for every organization, but it may be required by customers, supply-chain partners, regulators, or market-access programs.


  • Medical device manufacturers.

  • Contract manufacturers.

  • Component and critical-service suppliers.

  • Organizations involved in design and development.

  • Organizations performing installation or servicing activities.

  • Organizations supporting regulated medical device production or quality processes.


The correct certification scope should reflect the organization's actual activities, products, services, locations, and applicable regulatory responsibilities.


Key ISO 13485 Requirements Medical Device Companies Need to Address


Quality Management System and Document Control

The QMS needs controlled procedures, records, responsibilities, and process interactions that support consistent implementation. Documentation should match real operations rather than existing only to satisfy an auditor.


Management Responsibility and Resources

Leadership must establish responsibilities, provide appropriate resources, review QMS performance, and make sure employees performing quality-affecting work are competent.


Risk Management

Risk management must be integrated into appropriate medical device realization activities and supported by documented processes and evidence. ISO 14971:2019 is the internationally recognized standard for medical device risk management and is widely used alongside ISO 13485 to structure hazard identification, risk evaluation, risk control, and post-production monitoring.


Design, Purchasing, Production, and Supplier Controls

Applicable controls need to address how products are designed, purchased, produced, verified, released, and supported. Supplier qualification and monitoring are especially important when externally provided products or services can affect device quality or regulatory compliance.


Traceability, Records, Complaints, and Corrective Action

The organization must retain appropriate evidence that required activities were completed and that product and process controls are functioning. Complaint handling, nonconforming product controls, corrective action, and other post-market or feedback processes need to be defined and implemented where applicable.


Internal Auditing and Management Review

Before certification, the organization should have enough implementation history and objective evidence to evaluate the QMS through internal auditing and management review. These activities help identify gaps before the certification body evaluates the system.


The ISO 13485 Certification Process

The exact certification process depends on the certification body and the condition of the existing QMS, but most organizations move through the same basic readiness stages.


  • Define the certification scope and applicable activities.

  • Perform a gap analysis against ISO 13485:2016 and relevant regulatory requirements.

  • Develop or refine the QMS and required documented information.

  • Implement the processes across the organization and collect objective evidence.

  • Train employees and process owners on their responsibilities.

  • Complete internal audits and management review.

  • Correct identified gaps and verify corrective actions.

  • Select an appropriate certification body and complete the external certification audit process.

  • Maintain the QMS after certification through ongoing monitoring, auditing, management review, and corrective action.


A mature ISO 9001 system can provide a useful foundation, but ISO 13485 has medical-device-specific requirements and a stronger regulatory focus. Organizations should not assume that an ISO 9001 certificate or an existing general QMS automatically satisfies ISO 13485.


Common Challenges When Preparing for ISO 13485 Certification


  • Existing procedures do not match how work is actually performed.

  • Documentation is incomplete, inconsistent, or difficult to control.

  • Risk management activities are disconnected from design, production, supplier, complaint, or post-market processes.

  • Supplier controls do not reflect the risk or criticality of the supplied product or service.

  • Responsibilities for regulatory and quality activities are unclear.

  • Internal audits are too limited or are completed too late in the certification schedule.

  • Corrective actions close paperwork without demonstrating that the underlying problem was effectively addressed.

  • The organization treats certification as a documentation project instead of an implementation project.

  • U.S. manufacturers continue relying on outdated QSR or QSIT terminology after the QMSR became effective.


Identifying these issues early is usually less disruptive and less expensive than discovering them during the certification audit or an FDA inspection.


How ISO 13485 Consulting Support Can Help

A qualified ISO 13485 consultant can help an organization understand what is actually required, identify gaps in the existing system, and build a practical implementation plan around the company's real operations. The consultant should help the organization create a usable QMS rather than forcing generic templates into processes that do not match the business.


  • Certification scope and readiness review.

  • Gap analysis and prioritized implementation plan.

  • QMS development or refinement.

  • Document and record-control improvements.

  • Process alignment across departments.

  • Risk-management and supplier-control support.

  • Internal audit and management-review readiness.

  • Corrective-action support.

  • Certification-audit preparation.

  • Ongoing QMS maintenance and improvement support.


Organizations that need structured implementation or certification-readiness support can use My ISO Consultants' ISO 13485 consulting services to evaluate the current system, identify practical priorities, and prepare the QMS for certification and ongoing regulatory expectations.


How to Choose an ISO 13485 Consultant

The right consultant should understand both management-system implementation and the realities of regulated medical device operations. Before selecting a consultant, evaluate whether the provider can explain how the work will be scoped, how responsibilities will be divided, and what deliverables the organization will receive.


  • Relevant ISO 13485 and medical device quality-system experience.

  • Understanding of the organization's products, processes, and regulatory environment.

  • A practical implementation approach rather than template-only consulting.

  • Experience with internal auditing and certification readiness.

  • Clear project phases, responsibilities, deliverables, and milestones.

  • Ability to work with the organization's existing QMS instead of rebuilding strong processes unnecessarily.


A consultant can support implementation and readiness, but the certification decision belongs to the independent certification body. Consulting should strengthen the organization's system and evidence, not promise or guarantee certification.


Frequently Asked Questions


Is ISO 13485 certification required for every medical device company?

No. ISO 13485 certification is not universally required for every medical device organization. Whether it is required depends on the organization's role, customers, contracts, regulatory pathway, target markets, and supply-chain expectations. Even when certification is not mandatory, many organizations use ISO 13485 as the framework for a controlled medical device QMS.


Does ISO 13485 certification automatically mean a company complies with the FDA QMSR?

No. The FDA QMSR incorporates ISO 13485:2016 by reference, which creates substantial alignment, but ISO 13485 certification does not replace FDA regulatory obligations or FDA oversight. A U.S. medical device manufacturer must still identify and meet all FDA requirements that apply to its products and operations.


How long does ISO 13485 certification readiness take?

The timeline depends on the size and complexity of the organization, the maturity of the existing QMS, the certification scope, device and regulatory complexity, employee availability, and the number of gaps that need to be corrected. A useful timeline should be based on an initial system review rather than a generic fixed estimate.


What should we expect from an ISO 13485 consultant?

A professional consultant should evaluate the current QMS, identify meaningful gaps, help prioritize implementation work, strengthen required documentation and process controls, support internal audit and management-review readiness, and prepare the organization for the independent certification process. The goal should be a maintainable system that works in practice, not simply a package of documents.


Do we need ISO 14971 to comply with ISO 13485?

ISO 13485 requires risk management to be integrated into applicable medical device realization processes. ISO 14971:2019 is the internationally recognized standard for medical device risk management and is commonly used to establish a structured process for identifying hazards, evaluating risks, implementing risk controls, and monitoring risk throughout the device life cycle. ISO 13485 does not itself require certification to ISO 14971, but applicable regulatory, customer, or product requirements may make alignment with ISO 14971 important.


Conclusion

ISO 13485 certification can provide medical device organizations with a structured, internationally recognized quality management framework, but successful certification depends on implementation rather than paperwork alone. The strongest systems connect documented requirements to real processes, risk controls, supplier oversight, records, internal auditing, management review, and applicable regulatory obligations.


If your organization is preparing for certification, updating an existing medical device QMS, or aligning its quality system with current 2026 expectations, My ISO Consultants provides ISO 13485 consulting services to help identify gaps, strengthen implementation, and prepare for certification readiness.



ISO 13485 Certified
ISO 13485 Certification

 

(844) MYISOPRO

PO Box 4372

Crestline, CA 92325

We service the entire United States and most countries, but we consider the following areas of California, Arizona, Texas and Nevada "Local" to us: San Bernardino County, Riverside County, Los Angeles County, Orange County, San Diego County, Ventura County, Sacramento County, San Jose, Santa Clara County, Fresno County, Phoenix Area, San Antonio, Austin, Reno and Las Vegas areas

© 2025 by My ISO Consultants

bottom of page