Skip to main content
v2026.11,610 entries · CC-BY 4.0

ISO 13485: Medical Device Quality Management Systems Explained

ISO 13485:2016 is the standalone international standard for medical-device quality management systems. This guide covers how it differs from ISO 9001, its design-control and design-history-file requirements, and how it relates to FDA QMSR and EU MDR/IVDR.

Ask about ISO 13485: Medical Device Quality Management Systems Explained

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

ISO 13485:2016, Medical devices — Quality management systems — Requirements for regulatory purposes, is the international standard that defines what a quality management system (QMS) must do for an organization involved in the design, production, installation, or servicing of medical devices. It is the standard that certification bodies audit against when a device manufacturer says it is “ISO 13485 certified,” and it is also the standard the U.S. FDA now incorporates directly into federal regulation.

Researchers, core-facility staff, and lab managers most often meet ISO 13485 at the point where a research prototype, assay, or device concept is being positioned for eventual regulatory submission — because that is exactly where design controls and the design history file start to matter, often well before a device reaches full commercial manufacturing.

ISO 13485 is not an ISO 9001 add-on

The single most common misunderstanding is treating ISO 13485 as a medical-device “flavor” of ISO 9001 — a supplementary checklist layered on top of a generic quality standard. It is not. ISO 13485:2016 is a fully standalone, freestanding QMS standard in its own right, and it differs from ISO 9001 in ways that matter operationally, not just administratively:

  • Structure. ISO 9001:2015 was rewritten to follow the ISO/IEC Directives Part 1 “Annex SL” high-level structure shared across modern management-system standards (with clauses like “context of the organization” and “leadership”). ISO 13485:2016 deliberately did not follow Annex SL — ISO/TC 210 concluded those concepts weren’t necessary for the medical-device quality model and kept the structure inherited from the 2003 edition (planning for the 2016 revision had begun before Annex SL was finalized). The two standards share substantial content and are commonly implemented together, but they are no longer structurally aligned clause-for-clause the way people sometimes assume.
  • Regulatory purpose is written into the standard itself. ISO 9001 is a general-purpose QMS standard applicable to any industry, with customer satisfaction and continual improvement as its organizing goals. ISO 13485’s explicit purpose — stated in its own title — is to support an organization’s ability to meet applicable regulatory requirements, and its clauses reference regulatory obligations (device files, risk management, traceability, complaint handling, adverse-event/vigilance reporting, advisory notices) that have no ISO 9001 equivalent.
  • Risk management is a pervasive, standalone obligation. ISO 13485 requires risk management to be applied throughout the product realization process and cross-references ISO 14971 (medical device risk management) directly. ISO 9001’s approach to “risk-based thinking” is a general management-planning concept; ISO 13485’s is a documented, product-safety-driven discipline that touches design, production, and post-market activities.
  • Continual improvement is narrower by design. ISO 13485 emphasizes maintaining the effectiveness of the QMS and meeting regulatory requirements over open-ended continual improvement, reflecting that in a regulated device environment, change itself carries risk and must be controlled, not just encouraged.

The practical consequence: an organization cannot treat ISO 9001 certification as “covering” ISO 13485 obligations, and vice versa. Many device manufacturers hold both certifications, but they are assessed, and often audited, separately.

Certification, not accreditation — the same trap as ISO 17025

CASRAI’s ISO/IEC 17025 guide covers a vocabulary trap that trips up the same audience here in reverse. ISO/IEC 17025 is a competence standard for testing and calibration laboratories, and conformity to it is accreditation — a scope-bounded attestation of technical competence for specific tests or calibrations, granted by an accreditation body.

ISO 13485 works the other way: like ISO 9001, it is a management-system standard, and conformity to it is certification — an organization-wide (or site/scope-wide) attestation, issued by a certification body (in the EU medical-device context, often a Notified Body performing a combined ISO 13485 certification and MDR/IVDR conformity assessment), that the QMS itself meets the standard’s requirements. A device manufacturer is “ISO 13485 certified,” never “ISO 13485 accredited” — the reverse error to the one made about ISO 17025. Keep the two standards and the two words straight: 17025 is accreditation of technical competence within a scope; 13485 is certification of a management system.

How ISO 13485:2016 is structured

Like its ISO 9001:2008-lineage predecessor, ISO 13485:2016 is organized into clauses 4 through 8:

  • Clause 4 — Quality management system. General QMS requirements plus documentation requirements (quality manual, medical device file, document and record control).
  • Clause 5 — Management responsibility. Management commitment, customer focus, quality policy and objectives, planning, responsibility/authority/communication, and management review.
  • Clause 6 — Resource management. Human resources (competence, training), infrastructure, and work environment/contamination control.
  • Clause 7 — Product realization. Planning, customer-related processes, design and development (7.3, see below), purchasing, production and service provision (including sterile product and installation/servicing requirements), and control of monitoring/measuring equipment.
  • Clause 8 — Measurement, analysis and improvement. Feedback (including a formal complaint-handling process and reporting to regulatory authorities), internal audit, monitoring of processes and product, control of nonconforming product, analysis of data, and improvement — including corrective action (8.5.2) and preventive action (8.5.3), the clauses that underpin a device manufacturer’s CAPA system.

Design controls and the design history file

This is the section of ISO 13485 that research-stage work most often touches, because it governs the transition from a research concept to a controlled, traceable device design — frequently well before formal manufacturing begins.

Clause 7.3, Design and development, requires a documented, staged process covering:

  • Design and development planning
  • Design inputs — the functional, performance, usability, and regulatory requirements the design must satisfy
  • Design outputs — specifications, drawings, and other outputs that can be verified against inputs
  • Design review — formal, documented reviews at appropriate stages
  • Design verification — confirming outputs meet inputs
  • Design validation — confirming the resulting device meets user needs and intended use, normally under actual or simulated use conditions
  • Design transfer — ensuring the verified/validated design is correctly translated into production specifications
  • Control of design changes
  • A design and development file (7.3.10) that demonstrates conformity to the plan and to the clause’s requirements

The design history file (DHF) is the term of art for this record set in U.S. practice, defined at 21 CFR 820.30(j) (legacy Quality System Regulation) as the compilation of records describing the design history of a finished device. It performs the same function as ISO 13485’s 7.3.10 design file: a chronological, auditable trail showing that every design input was addressed, every output was verified, and the final design was validated before release. For research teams, the practical implication is that DHF discipline — version-controlled requirements, traceable verification/validation records, documented design reviews — is worth establishing early, because reconstructing it retroactively once a device moves toward regulatory submission is far more costly than maintaining it as the design work happens.

How ISO 13485 relates to FDA regulation: QSR to QMSR

For decades, U.S. device manufacturers worked under the FDA’s own Quality System Regulation (QSR), codified at 21 CFR Part 820, which was similar in substance to ISO 13485 but not textually identical — creating duplicate documentation burden for manufacturers selling into both the U.S. and international markets. The FDA closed that gap with the Quality Management System Regulation (QMSR), which took effect February 2, 2026, replacing most of legacy Part 820 and incorporating ISO 13485:2016 by reference as the QMS requirement for device manufacturers, with a small set of FDA-specific additions layered on top (for example, U.S.-specific labeling and UDI provisions, and 21 CFR 820.10(c) directing manufacturers to ISO 13485 Clause 7.3 for design controls). In practice, this means an ISO 13485-conformant QMS is now, with limited FDA-specific supplements, the U.S. regulatory baseline for device manufacturers as well as the international one — a research team building toward a U.S. submission and an EU submission is increasingly working from the same underlying QMS standard rather than two parallel systems.

How ISO 13485 relates to EU MDR and IVDR

In the European Union, the Medical Device Regulation (MDR, Regulation (EU) 2017/745) and In Vitro Diagnostic Regulation (IVDR, Regulation (EU) 2017/746) are the binding legal instruments a manufacturer must satisfy to place a device on the EU market — they are law, not a voluntary standard. ISO 13485 certification is not, by itself, legally sufficient to demonstrate MDR/IVDR conformity, but it is treated as strong supporting evidence of an adequate QMS, and Notified Bodies conducting MDR/IVDR conformity assessments commonly combine their audit with an ISO 13485 certification audit in a single process. The regulation and the standard address different questions: MDR/IVDR sets the legal requirements a device and its manufacturer must meet (classification, clinical evaluation, technical documentation, post-market surveillance, vigilance); ISO 13485 defines the quality-system infrastructure — including design controls, risk management, and document control — that makes it possible to demonstrate and sustain that conformity over the device’s lifecycle.

Frequently asked questions

Is ISO 13485 mandatory?

ISO 13485 itself is a voluntary international standard, not a law. It becomes effectively mandatory in practice because regulators and market requirements point to it: the EU’s MDR/IVDR conformity-assessment process relies heavily on it, many national regulators outside the EU and US require or strongly favor it, and as of February 2, 2026 the FDA’s QMSR incorporates ISO 13485:2016 by reference for U.S. device manufacturers.

Do I need ISO 13485 for a research prototype that isn’t a commercial device yet?

Not immediately, but design-control discipline is worth adopting early. Because the design history file must show the design’s development from the start, retrofitting inputs, verification, and review records after the fact is far harder than maintaining them contemporaneously as the design work happens — a lab that expects a device concept to eventually seek regulatory clearance benefits from establishing basic design-control habits well before formal QMS certification is pursued.

Is ISO 13485 certification the same as FDA clearance or approval?

No. ISO 13485 certification (or QMSR conformance) demonstrates that a manufacturer’s quality management system meets the standard’s requirements. It says nothing on its own about whether a specific device has received FDA marketing authorization (510(k) clearance, De Novo, or PMA approval) or EU MDR/IVDR conformity for that device — those are separate, device-specific regulatory determinations that typically rely on, but are distinct from, QMS certification.

What’s the difference between ISO 13485 and ISO 9001 in one sentence?

ISO 9001 is a general-purpose QMS standard organized around customer satisfaction and continual improvement, while ISO 13485 is a standalone, differently-structured standard built specifically to support regulatory compliance and product safety for medical devices, with mandatory risk-management and design-control obligations ISO 9001 does not impose.

Related CASRAI resources

  • Laboratory Compliance & Quality — the full cluster overview, including how GxP, accreditation, and device-quality frameworks fit together.
  • ISO/IEC 17025 — the accreditation standard for testing and calibration laboratories, and the accreditation-vs-certification distinction in the opposite direction.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →