Skip to main content
v2026.11,610 entries · CC-BY 4.0

ISO 13485 Certification: Scope, Stages and Audit Preparation

What the ISO 13485 certification process actually requires: how the scope statement on your certificate is fixed, the IAF MD 9 audit-day table your quote should reconcile to, what stage 1 and stage 2 each test, which nonconformities block the certification decision and for how long, and the surveillance and recertification obligations that follow.

Ask about ISO 13485 Certification: Scope, Stages and Audit Preparation

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Written and maintained by CASRAI Editorial Board

Last updated

An ISO 13485 certificate is not a grade. It is a scope statement with an expiry date, issued by a certification body against a defined set of device technical areas and named sites. Two organizations can both be “ISO 13485 certified” and hold certificates that mean materially different things, because one covers design, development and sterile manufacture of active implantable devices at three sites and the other covers distribution of finished devices from one warehouse.

This guide covers the certification process: how the scope on your certificate gets fixed, how many audit days you should expect to be quoted, what stage 1 and stage 2 actually do, which nonconformities stop the certification decision and for how long, and what surveillance and recertification oblige you to keep doing for three years. For the standard itself — the clause structure, the evidence an auditor asks for at each clause, and the FDA QMSR overlay — see CASRAI’s companion guide to ISO 13485 and medical device quality management systems. This page deliberately does not restate it.

The standard you conform to is not the standard that governs your audit

This is the structural point most certification guidance skips, and it explains almost everything else on this page.

ISO 13485 tells you what your quality management system must do. It says nothing about how a certification body must audit you. Those requirements live in two other documents, and both are the real authority for audit mechanics:

  • ISO/IEC 17021-1:2015, Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1: Requirements. This is the generic conformity-assessment standard that governs every accredited management-system certification body, across ISO 9001, ISO 14001, ISO 27001 and ISO 13485 alike. Its Clause 9 defines the two-stage initial audit, the certification decision, surveillance, recertification, suspension and appeals.
  • IAF MD 9:2023, Application of ISO/IEC 17021-1 in the Field of Medical Device Quality Management Systems (ISO 13485) — the device-sector mandatory document that layers additional requirements on top. It is freely published: Issue 5, issued and applicable 20 November 2023. Its own opening statement is that all clauses of ISO/IEC 17021-1 continue to apply and that it supersedes none of them.

Practically: if your certification body proposes something about audit duration, site sampling or how a finding will be closed, the document to check it against is IAF MD 9 or ISO/IEC 17021-1 — not ISO 13485. A great deal of what feels like an individual auditor’s discretion is in fact prescribed.

A note on sourcing, because it matters for a page like this. ISO 13485 and ISO/IEC 17021-1 are copyrighted and must be purchased from ISO or a national member body; no standard text is reproduced here. Clause numbers and requirements are cited and paraphrased. IAF MD 9 is a freely published IAF document and is linked above so you can read it yourself. Where a figure varies by certification body — fees above all — this page says so rather than presenting one body’s number as general.

What changed on 1 January 2026: IAF is gone, the documents are not

If you are checking your certification body’s accreditation, note that the landscape changed recently. The International Accreditation Forum (IAF) and the International Laboratory Accreditation Cooperation (ILAC) merged into a single body, Global Accreditation Cooperation Incorporated (Global ACI), which commenced full operations on 1 January 2026; IAF ceased operations on the same date. The IAF Multilateral Recognition Arrangement (IAF MLA) and the ILAC Mutual Recognition Arrangement have been integrated into a single GAC MRA. See the launch announcement and UKAS’s notice.

Two consequences. First, the IAF mandatory documents themselves remain in force and remain the criteria — the merger changed the organisation, not the requirements, and IAF MD 9:2023 Issue 5 is still what your certification body is assessed against. Second, procurement language and supplier questionnaires that say “accredited by an IAF MLA signatory” are now referring to an arrangement that has been folded into the GAC MRA; if you maintain supplier-qualification templates, that phrasing is worth updating. The underlying check is unchanged in substance: your certification body should hold accreditation from a recognised accreditation body, for ISO 13485, and for the technical areas your devices fall into.

The scope statement is the decision you make first and live with longest

Everything downstream — audit days, auditor qualifications, which sites get visited, what you may legitimately claim to a customer — follows from scope. It is also the part organizations most often treat as administrative wording rather than as a decision.

The rule that stops you carving out the awkward parts

IAF MD 9 MD 8.2.1 is short and consequential. The certification body shall precisely document the scope of certification, and it shall not exclude part of processes, products or services from the scope — unless allowed by regulatory authorities — where those processes, products or services have an influence on the safety and quality of products.

Read that against the common temptation. An organization with a shaky sterilization process, an immature design-control system, or a servicing operation nobody wants audited will sometimes ask whether that activity can simply sit outside the certified scope for the first cycle. Under MD 8.2.1 the answer is generally no, and a certification body that agrees is exposing its own accreditation. This is a different mechanism from ISO 13485’s own provision for non-application of Clause 7 requirements: non-application is about requirements that genuinely do not apply to what you do (and must be justified in the quality manual), whereas MD 8.2.1 is about not excising activities you actually perform that bear on product safety and quality.

Technical areas: the vocabulary your certificate is actually written in

Annex A of IAF MD 9 is normative and defines the medical device technical areas. The certification body uses them for three things: to help define the scope of certification, to identify what technical qualification its auditors need for that area (including competence in specific sterilization processes), and to select a suitably qualified audit team. There are seven tables:

  • A.1.1 — Non-active medical devices. General non-active non-implantable devices; devices for anaesthesia, emergency and intensive care; injection, infusion, transfusion and dialysis; orthopaedic and rehabilitation; devices with a measuring function; ophthalmologic; instruments; contraceptive; disinfecting/cleaning/rinsing; IVF and ART; devices for ingestion. Plus non-active implants (cardiovascular, orthopaedic, functional, soft tissue), wound care (bandages and dressings, suture material and clamps), and non-active dental devices, materials and implants.
  • A.1.2 — Active (non-implantable) medical devices. Extra-corporal circulation, infusion and haemopheresis; respiratory and hyperbaric; stimulation or inhibition; active surgical, ophthalmologic and dental; active disinfection and sterilization devices; rehabilitation devices and active prostheses; patient positioning and transport; IVF/ART; software, including software design for medical devices; medical gas supply systems; imaging devices (ionizing and non-ionizing); monitoring devices, split between vital and non-vital physiological parameters; radiation and thermo therapy; hyperthermia/hypothermia; extracorporal shock-wave therapy.
  • A.1.3 — Active implantable medical devices. Stimulation/inhibition; devices delivering drugs or other substances; devices substituting or replacing organ functions.
  • A.1.4 — In vitro diagnostic medical devices. Reagents, calibrators and control materials by discipline — clinical chemistry, immunochemistry, haematology/haemostasis/immunohaematology, microbiology, infectious immunology, histology/cytology, genetic testing — plus IVD instruments and software.
  • A.1.5 — Sterilization methods. Ethylene oxide (EOG), moist heat, aseptic processing, radiation (gamma, x-ray, electron beam), low temperature steam and formaldehyde, dry heat, hydrogen peroxide.
  • A.1.6 — Devices incorporating or utilizing specific substances or technologies. Medicinal substances; tissues of animal origin; derivatives of human blood; micromechanics; nanomaterials; biologically active coatings or materials, or devices wholly or mainly absorbed.
  • A.1.7 — Parts and services. Raw materials; components; subassemblies; calibration services; distribution services; maintenance services; transportation services; other services including packaging and device-related consulting.

Where a certification body seeks accreditation for a technical area, it must give the accreditation body a list of the medical devices concerned including their risk classification — determined against an appropriate national, regional or international scheme, with EU 2017/745 Annex VIII, GHTF/SG1/N77:2012 and national regulations such as FDA’s given as the examples — together with a concise statement of intended purpose.

If you make parts, not devices: read Table A.1.7 carefully

Suppliers to device manufacturers frequently pursue ISO 13485 certification, and Table A.1.7 is the one that applies to them. Two things follow, and both cut in the supplier’s favour or against it depending on the case.

In the supplier’s favour: where an audit is performed for an organization that only manufactures parts and offers services under Table A.1.7, IAF MD 9 MD 9.2.2.1 provides that the audit team does not have to demonstrate technical competence at the same level as for a manufacturer providing finished medical devices. Annex C similarly exempts auditors working solely under Table A.1.7 from the four-year medical-device work-experience requirement, and sets their continuing professional development minimum at 8 hours per year rather than the 16 hours required for Tables A.1.1 to A.1.6.

Against it: Annex A is explicit that where the degree of influence is high enough, the certification body is required to hold accreditation for the finished-device technical areas in Tables A.1.1 to A.1.6 rather than for parts and services — giving two triggers as examples. One is where an organization promotes itself or its products as supporting a medical device in one of the main technical areas (the example given is fasteners marketed with clear intent to support implanted devices). The other is contract manufacturers making nearly complete medical devices. If your marketing says “for implantable applications”, you have arguably moved yourself out of Table A.1.7.

Annex A also carries a note worth flagging for anyone certifying a calibration operation: organizations providing calibration services should be accredited to ISO/IEC 17025. That is a different instrument from ISO 13485 certification, and CASRAI covers the distinction in the ISO/IEC 17025 guide and the practical verification steps in how to verify an ISO/IEC 17025 accreditation before you sign.

How many audit days: the table your quote should reconcile to

Audit duration is not a commercial variable a certification body sets freely. IAF MD 9 MD 9.1.4 makes IAF MD 5 (Determination of Audit Time) apply, except for its environmental and occupational-health provisions and except for its table QMS 1 — which is replaced for ISO 13485 by Annex D, Table D.1. That table is the starting point for the audit time of an initial certification audit, meaning stage 1 plus stage 2 combined, keyed to the effective number of personnel.

Effective number of personnel Audit time, stage 1 + stage 2 (days) Effective number of personnel Audit time, stage 1 + stage 2 (days)
1–5 3 626–875 15
6–10 4 876–1175 16
11–15 4.5 1176–1550 17
16–25 5 1551–2025 18
26–45 6 2026–2675 19
46–65 7 2676–3450 20
66–85 8 3451–4350 21
86–125 10 4351–5450 22
126–175 11 5451–6800 23
176–275 12 6801–8500 24
276–425 13 8501–10700 25
426–625 14 >10700 Follow the progression above

Source: IAF MD 9:2023 Issue 5, Annex D, Table D.1 (normative). Reproduced as factual data; read the document itself for the full annex.

What moves the number, and by how much

Annex D lists the adjustment factors, and the caps on reductions are the part worth knowing before you negotiate.

Factors that increase audit time include: more than one main technical area in scope (the time shall be increased to address the additional area’s requirements); complexity of the devices; use of suppliers for processes or parts critical to device function or user safety, including own-label products, where the manufacturer cannot provide sufficient evidence of conformity — in which case additional time may be allowed to audit each supplier; installation and servicing at customer sites, which may require site visits or installation-record review; poor regulatory compliance history; and multiple shifts or production lines.

Factors that reduce audit time include a scope that is not manufacturing but activities such as wholesale, retail, transportation or equipment maintenance, and reductions in the product range or in the design or production processes since the last audit. The cap: reductions shall not exceed 20% in total from Table D.1. The one exception is audits performed solely for a certification scope of distribution or transportation services, where the reduction may reach 50%.

Combining ISO 9001 and ISO 13485. Where a certification body conducts an ISO 9001 and ISO 13485 audit together, Annex D requires that a minimum of 25% be added to the minimum number of audit days calculated per Annex D — and this applies whether the body calls it an integrated audit or a combined audit. A quote that offers both standards for the ISO 13485 day count alone is not compliant. For integrated audits with standards other than ISO 9001, IAF MD 11 governs.

What “audit time” does and does not include

Audit time covers on-site time at the client’s premises — physical or virtual — plus off-site time spent on planning, document review, interacting with client personnel and report writing. It expressly excludes design dossier reviews, type examinations, pre-market approval audits and similar activities. Separately, MD 9.1.4 requires that time needed to audit national or regional regulatory requirements and dossier reviews be additional and justified, so that it does not diminish the audit of the QMS itself. If you are combining ISO 13485 certification with an EU MDR conformity assessment, expect a bigger number for that reason and check the split is stated.

On fees: IAF MD 9 sets audit days, not prices. Day rates, travel and expenses, application and certificate fees, and the cost of transfer or scope-extension work vary substantially between certification bodies and between countries, and there is no published general figure to quote. Compare quotes on day count first — that number is governed and should reconcile to Table D.1 with stated adjustments — and only then on rate.

Stage 1: the readiness audit that fixes your scope

Under ISO/IEC 17021-1 9.3.1.2, the initial certification audit is conducted in two stages, and stage 1 has four defined objectives: review the client’s documented management system; evaluate the client’s preparedness for stage 2; review the client’s status and understanding regarding the requirements of the standard; and obtain the necessary information regarding the scope. Planning must ensure those objectives can be met, and the client must be informed of any on-site activities during stage 1.

That fourth objective is why stage 1 matters more than its “documentation review” reputation suggests. Stage 1 is where the certificate’s scope statement, the applicable technical areas, the sites, and any Clause 7 non-application justification are settled. Arriving at stage 1 without a defensible scope statement and a written justification for every non-applied requirement is the most common way to lose time at this stage.

IAF MD 9 adds one device-specific provision at MD 9.3.1.2: where higher-risk medical devices are concerned — the example given is GHTF class C and D — stage 1 should be performed on site. If you make higher-risk devices and your certification body proposes a purely remote stage 1, that is a question worth asking.

Stage 2: implementation and effectiveness, on site

ISO/IEC 17021-1 9.3.1.3 sets the purpose of stage 2 as evaluating the implementation, including effectiveness, of the management system, and states that stage 2 takes place at site. It addresses information and evidence; performance monitoring, measuring, reporting and reviewing against key performance objectives and targets; performance in meeting applicable statutory, regulatory and contractual requirements; operational control of processes; internal auditing and management review; and management responsibility for the client’s policies. Under 9.3.1.4, the team then analyses all information and evidence from both stages together to agree the audit conclusions.

The distinction that trips people up: stage 1 asks whether the system is described; stage 2 asks whether it is done, and whether doing it works. A complete, elegant procedure with no records behind it passes stage 1 and fails stage 2. For what an auditor asks you to produce clause by clause at stage 2, see the evidence walkthrough in the ISO 13485 guide.

One important carve-out at MD 9.3.1: where a certification body has already audited a client against a regulatory scheme that includes or goes beyond ISO 13485’s requirements, it does not need to repeat the audit for the ISO 13485 elements previously covered, provided it can demonstrate that all of IAF MD 9’s requirements have been complied with. The example the document gives is the European Medical Device Regulations. This is the formal basis for the combined Notified Body assessment that many manufacturers experience as one visit — and it is a real efficiency, not a favour.

Nonconformities and the certification decision: what actually blocks a certificate

How findings are graded major or minor, and how the NCR/NCAR response cycle runs, is covered in CASRAI’s guide to nonconformity grading and the NCR/NCAR process. What follows is the narrower question that guide does not answer: what a grading does to the certification decision, and on what timetable.

The decision rule

ISO/IEC 17021-1 9.5.2 requires a review before the certification decision that confirms three things: that the information provided by the audit team is sufficient; that major nonconformities are closed; and that minor nonconformities have been reviewed and have a plan for corrective action. That asymmetry is the whole practical difference between the two gradings at decision time. A minor needs a credible plan. A major needs to be closed — correction and corrective action implemented, with the effectiveness verified.

The six-month cliff

The hardest number in the certification process, and the one most worth putting in your project plan, is at 9.5.3.2: if the certification body is not able to verify the implementation of corrections and corrective actions for any major nonconformity within six months after the last day of stage 2, it shall conduct another stage 2 before recommending certification.

So a major finding does not merely delay you. It starts a six-month clock, and missing that clock costs you a repeat of the entire stage 2 audit — the days, the fee, and the calendar. This is why “we will fix it properly next quarter” is the wrong answer to a major, and why root-cause work on a major should start the week the finding is raised rather than after the report is formally issued. See CASRAI’s CAPA definition for the correction / corrective action / effectiveness-verification sequence the closure depends on.

What counts as a major in the device sector, specifically

IAF MD 9 MD 9.4.5 gives six examples of major nonconformities that require acceptance and verification of the effectiveness of correction and corrective action. These are device-specific and worth reading as a gap-assessment prompt rather than as a definition:

  1. Failure to fully address applicable requirements and implement an entire process for the quality management system — the examples given are the absence of a complaint-handling system or of a training system.
  2. Failure to implement applicable QMS requirements.
  3. Failure to implement appropriate corrective and preventive action when an investigation of post-market data indicates a pattern of product defects.
  4. Products placed on the market that cause undue risk to patients and/or users when the device is used according to its product labelling.
  5. The existence of products that clearly do not comply with the client’s specifications and/or regulatory requirements.
  6. Repeated nonconformities from previous audits.

Item 6 deserves emphasis because it is entirely within your control and is the one organizations walk into. A minor closed with a shallow correction that does not address root cause reappears at the next surveillance — and reappearing is itself grounds for a major. That is the mechanism by which a weak CAPA system converts a manageable finding into a certification risk two years later. Items 3 and 4 connect the certification audit to post-market obligations; CASRAI covers those in field safety corrective action, FSCA vs recall vs field safety notice.

How the finding must be written

ISO/IEC 17021-1 9.4.5.3 requires that a nonconformity be recorded against a specific requirement, with a clear statement of the nonconformity identifying in detail the objective evidence it rests on, and that it be discussed with the client to ensure the evidence is accurate and understood. It also requires that the auditor refrain from suggesting the cause of nonconformities or their solution.

Two practical consequences. A finding that cites no specific clause and no objective evidence is not a properly recorded nonconformity, and you are entitled to say so at the closing meeting rather than after the report lands. And an auditor who declines to tell you how to fix something is complying with the standard, not being unhelpful — suggesting the remedy would compromise the impartiality of the body that later has to judge whether your remedy worked.

Multi-site: the sampling rule that catches manufacturers out

For many management-system standards, an organization with many sites can be certified on the basis of a sampled subset, with the sample size derived from IAF MD 1. ISO 13485 curtails this sharply.

IAF MD 9 MD 9.1.5 states that sites involved in design, development and manufacturing of medical devices — that is, sites falling under Tables A.1.1 to A.1.6 — cannot be sampled.

Every design site and every manufacturing site in scope is audited. Sampling remains available only for site types outside those tables. This is the single largest driver of cost surprise for a multi-site manufacturer that budgeted using ISO 9001 experience, and it should be settled at the application-review stage, not discovered when the audit plan arrives. A related provision at MD 9.1.2.1 requires the certification body to determine and document, where the applicant uses outsourced processes, whether specific competence is needed in the audit team to evaluate the control of that outsourced process — so your outsourcing map is an input to team selection as well as to scope. CASRAI’s guides to quality agreements and supplier audits cover the control evidence behind that.

After the certificate: surveillance, short-notice audits and recertification

Certification is a three-year cycle, and roughly two-thirds of your total audit exposure sits after the certificate is issued. The first cycle begins with the certification decision; subsequent cycles begin with the recertification decision. ISO/IEC 17021-1 requires surveillance at intervals no greater than one year, and recertification within the three-year cycle. Confirm the exact anniversary rule your certification body applies against your own contract — the programme is governed, but the scheduling detail is administered by the body.

Surveillance audits

Under 9.6.2.1, surveillance activities must include on-site auditing, and may additionally include enquiries to the client, review of the client’s public statements about its operations such as promotional material and website claims, requests for documented information, and other monitoring. Under 9.6.2.2, surveillance audits are on-site but are not necessarily full system audits; each surveillance includes a review of internal audits and management review, actions taken on nonconformities from the previous audit, complaints handling, effectiveness of the system in achieving the client’s objectives and the intended results, progress of planned continual-improvement activities, continuing operational control, review of any changes, and use of certification marks.

IAF MD 9 MD 9.6.2.2 adds one device-specific requirement on top: the surveillance programme shall include a review of actions taken for notification of adverse events, advisory notices and recalls. If you have had a vigilance event or issued an advisory notice since the last audit, it is on the surveillance agenda by mandate, not by the auditor’s choice.

Short-notice and unannounced audits

ISO/IEC 17021-1 9.6.4.2 allows audits at short notice or unannounced to investigate complaints, respond to changes, or follow up on suspended clients, with two conditions: the certification body must have described and made known in advance the conditions under which such audits will be conducted, and it must exercise additional care in assigning the team, because the client has no opportunity to object to team members.

IAF MD 9 MD 9.6.4.2 expands the device-sector triggers considerably. Short-notice or unannounced audits may be required when devices in the scope of certification indicate a possible significant deficiency in the QMS; when significant safety and performance information becomes known to the certification body; when significant changes occur that were submitted as required by regulations or otherwise become known and could affect the decision on regulatory compliance; or when required by public law or the relevant regulatory authority. The document is careful that none of the changes listed should automatically trigger such an audit, but the examples given are a useful list of what you should be notifying your certification body about:

  • QMS changes: new ownership; extension to manufacturing and/or design control; a new facility or site change, including relocating a manufacturing operation or centralising design and development functions across several manufacturing sites; new processes or process changes, including significant modifications to special processes — the example given is moving sterilization from a supplier to an on-site facility, or changing the sterilization method; and modifications to the defined authority of the management representative that affect QMS effectiveness or regulatory compliance, or the capability and authority to assure that only safe and effective devices are released.
  • Product changes: new products or categories; adding a new device category to the manufacturing scope — the examples given are adding sterile single-use dialysis sets to a scope limited to haemodialysis equipment, or adding magnetic resonance imaging to a scope limited to ultrasound.
  • Both: changes in standards or regulations; post-market surveillance and vigilance.

The document adds that an unannounced or short-notice audit may also be necessary if the certification body has justifiable concerns about the implementation of corrective actions or about compliance with the standard and regulatory requirements.

Recertification

Under 9.6.3.1.2, recertification activity includes reviewing the previous surveillance audit reports. Under 9.6.3.1.3, recertification may need a stage 1 where there have been significant changes to the management system or changes to legislation — and the accompanying note observes that such changes can occur at any time in the cycle, in which case the certification body might perform a special audit under 9.6.4, which may or may not be a two-stage audit. A QMSR transition or an MDR scope change mid-cycle is exactly the situation contemplated.

Under 9.6.3.2.1, the recertification audit must include an on-site audit addressing the effectiveness of the management system relative to the scope of certification, demonstrated commitment to maintaining effectiveness and improvement, and effectiveness in achieving the client’s objectives and intended results.

And the deadline that matters, at 9.6.3.2.2: for any major nonconformity, time limits for correction and corrective action are defined and completed prior to the expiration of certification. A major raised at a recertification audit scheduled close to expiry gives you no slack at all. That is the practical argument for booking recertification comfortably before the certificate expires rather than against it — the standard sets the deadline at expiry, and expiry does not move.

Suspension, withdrawal and scope reduction

ISO/IEC 17021-1 9.6.5 requires the certification body to have a policy and documented procedure for suspension, withdrawal and reduction of scope, specifying the actions it will take. Under suspension, the client’s certification is temporarily invalid — not merely flagged. The body restores it if the issue causing suspension is resolved; failure to resolve results in withdrawal or in reduction of the scope of certification, and a note records that in most cases suspension would not exceed six months. Scope reduction excludes the parts not meeting the requirements — which returns you to the opening point of this guide: your scope statement is the live object, and it can shrink.

Two disclosure provisions follow from this in the device sector. IAF MD 9 MD 8.1.3 requires that, where required by law or by the relevant regulatory authority, the certification body provide information about certifications granted, suspended or withdrawn to that regulatory authority. And MD 5.1.2 requires the body to establish appropriate agreements with clients to release audit report information to regulators that recognise ISO 13485. Your audit report is not a private document in the way a commercial consultancy report is; plan on that basis.

Appeals against a certification decision are governed by 9.7, which requires a documented process and, critically, that the people handling an appeal are different from those who carried out the audit and made the certification decision, with no discriminatory action against the appellant.

Choosing a certification body: what to check before you sign

The questions below are all answerable from published requirements rather than from a sales conversation.

  1. Is it accredited, and for your technical areas? An unaccredited “ISO 13485 certificate” is a private attestation, not an accredited one, and regulators and customers treat the two differently. Check that the body holds accreditation for ISO 13485 and for the Annex A technical areas your devices fall into — scope of accreditation is granted per technical area, not as a blanket. CASRAI covers what an accreditation body’s mark does and does not mean in the ANAB accreditation guide and the ANAB definition.
  2. Has anyone from the body consulted on your QMS? IAF MD 9 MD 5.2.3 requires the body and its auditors to be impartial and free from engagements that could affect objectivity, and specifically not involved in the design, manufacture, construction, marketing, installation, servicing or supply of the device or associated parts and services; not involved in the design, construction, implementation or maintenance of the QMS being audited; and not an authorised representative of the client. It lists compromising examples: an auditor holding stock in the client, an auditor currently employed by a manufacturer of similar or competitive devices, and an auditor who is staff at a research or medical institute, or a consultant, with a commercial contract or equivalent interest with a manufacturer of similar devices. If the same firm implemented your QMS, it cannot certify it.
  3. Is the audit team qualified for your technical area? MD 9.2.2.1 requires the team to have competence for the technical area of the audit scope; devices that are sterile or intended for end-user sterilization require competence in the relevant sterilization process from Table A.1.5. Under Annex C, auditors need knowledge corresponding to post-secondary education (typically four years) or equivalent experience in a relevant field — biology or microbiology, chemistry or biochemistry, computer and software technology, electrical/electronic/mechanical or bioengineering, human physiology, medicine, pharmacy, physics or biophysics — plus, in general, a minimum of four years of full-time work experience in medical devices or a related sector, with advanced degrees substituting for at most two of those years. For first authorization, MD 7.2.5 requires experience across the entire audit process gained as a trainee in a minimum of four audits totalling at least 20 days in an accredited QMS programme, of which at least 50% shall be against ISO 13485; audit team leaders additionally need at least three ISO 13485 audits in the team-leader role under a qualified team leader’s supervision.
  4. Who makes the certification decision? MD 7.2.8 requires the personnel making the certification decision to meet the Annex B competences — as a group where a group decides, and individually where one person decides. The decision is not the audit team’s to make.
  5. Can it combine what you actually need? If you need MDSAP, an MDR/IVDR conformity assessment, or ISO 9001 alongside ISO 13485, ask how the body sequences them and how audit time is allocated. Remember the 25% minimum uplift for an ISO 9001 combination, and MD 9.3.1’s provision for not repeating elements already covered by a regulatory scheme that meets or exceeds ISO 13485.

MDSAP is a different audit, not a stronger certificate

The Medical Device Single Audit Program is a regulatory audit against a published model, conducted by an MDSAP-recognised auditing organization and intended to satisfy several participating regulators at once. Per FDA’s MDSAP page, the participating members are Australia’s Therapeutic Goods Administration, Brazil’s ANVISA, Health Canada, Japan’s MHLW and PMDA, and the U.S. FDA; the EU, Singapore’s HSA, the UK’s MHRA and the WHO Prequalification of IVDs Programme participate as official observers. FDA’s own wording is that it “may continue to accept MDSAP audit reports as a substitute for routine Agency inspections”, with firms conducting Electronic Product Radiation Control activities remaining subject to FDA inspection for those activities.

MDSAP is therefore not an ISO 13485 certification audit conducted to a higher standard — it is a distinct assessment with a distinct purpose, though certification bodies commonly run the two together. Note also that FDA does not certify anyone to ISO 13485 and does not require a certificate; under the QMSR it requires compliance with 21 CFR Part 820 and verifies that by inspection. See CASRAI’s Part 820 subpart-by-subpart map and QMSR transition status.

A stage 1 readiness checklist

Assembled from the ISO/IEC 17021-1 and IAF MD 9 requirements above — these are the items whose absence most reliably costs time at stage 1, because each one is something the certification body needs in order to do its own job.

  • A written scope statement naming the devices, the activities (design, manufacture, sterile processing, distribution, servicing) and every site, drafted against the Annex A technical areas rather than in your own marketing vocabulary.
  • A justification for every excluded activity, tested against MD 8.2.1: does the excluded process, product or service influence the safety and quality of products? If yes, it stays in scope.
  • A written Clause 7 non-application justification in the quality manual for every requirement you have not applied — distinct from scope exclusion, and required by ISO 13485 itself.
  • A device list with risk classifications and a concise statement of intended purpose for each, against a named classification scheme — the certification body needs this for its own accreditation scope and for team selection.
  • A site list flagged by activity, with design/development/manufacturing sites identified, because MD 9.1.5 means none of them can be sampled out.
  • An outsourced-process map, which drives the MD 9.1.2.1 competence determination for the audit team.
  • A completed internal audit cycle and at least one management review — both are stage 1 inputs and both are re-examined at every subsequent surveillance under 9.6.2.2.
  • Your effective number of personnel, computed and defensible, since it selects the row in Table D.1 that determines your audit days.
  • Any adverse event, advisory notice or recall history assembled with the actions taken, because MD 9.6.2.2 puts it on the agenda regardless.

Frequently asked questions

How long does ISO 13485 certification take?

The audit itself is governed: IAF MD 9 Annex D Table D.1 sets stage 1 plus stage 2 at 3 days for 1–5 effective personnel, 5 days for 16–25, 10 days for 86–125, and so on, adjusted for the factors in Annex D. The elapsed calendar time is not governed and depends almost entirely on your readiness, on certification body scheduling, and on whether a major nonconformity is raised. The one hard deadline to plan around is ISO/IEC 17021-1 9.5.3.2: corrections and corrective actions for a major must be verifiable within six months of the last day of stage 2, or a repeat stage 2 is required.

How much does ISO 13485 certification cost?

There is no general published figure, and any single number you see quoted is one certification body’s pricing in one market. What is standardised is the day count, via Table D.1 and Annex D’s adjustment factors. Compare quotes on days first — confirm the table row, the technical areas driving any increase, and that reductions stay within the 20% cap (or 50% for a distribution/transportation-only scope) — and treat day rate, travel, application and certificate fees as the genuinely variable part.

What is the difference between stage 1 and stage 2?

Stage 1 reviews your documented system, evaluates your preparedness for stage 2, checks your understanding of the standard’s requirements, and obtains the information needed to fix the certification scope (ISO/IEC 17021-1 9.3.1.2). Stage 2 evaluates the implementation and effectiveness of the system on site (9.3.1.3). Stage 1 asks whether the system is described; stage 2 asks whether it is done and whether it works.

Can a major nonconformity stop me getting certified?

Yes, in a specific way. ISO/IEC 17021-1 9.5.2 requires major nonconformities to be closed before the certification decision, while minor nonconformities need only be reviewed with a corrective action plan in place. And 9.5.3.2 requires that if the body cannot verify implementation of the correction and corrective action for a major within six months after the last day of stage 2, it must conduct another stage 2 before recommending certification. At recertification, 9.6.3.2.2 requires major nonconformities to be corrected before the certificate expires.

Can my multi-site organization be certified on a sample of sites?

Not for the sites that matter most. IAF MD 9 MD 9.1.5 states that sites involved in design, development and manufacturing of medical devices — Tables A.1.1 to A.1.6 — cannot be sampled. Sampling remains possible for other site types, but every design and manufacturing site in scope is audited.

How often are surveillance audits, and what do they cover?

Certification runs on a three-year cycle with surveillance at intervals no greater than one year. Surveillance audits are on-site but not necessarily full system audits; under ISO/IEC 17021-1 9.6.2.2 each covers internal audits and management review, actions on previous findings, complaints handling, system effectiveness, continual-improvement progress, operational control, changes, and use of certification marks. IAF MD 9 MD 9.6.2.2 adds a mandatory review of actions taken for notification of adverse events, advisory notices and recalls.

Can my certification body be forced to show my audit report to a regulator?

Effectively, yes. IAF MD 9 MD 5.1.2 requires certification bodies to establish agreements with clients to release audit report information to regulators that recognise ISO 13485, and MD 8.1.3 requires them, where required by law or the relevant regulatory authority, to report certifications granted, suspended or withdrawn to that authority.

Is ISO 13485 certification the same as a CE mark or FDA clearance?

No. Certification attests that your quality management system conforms to ISO 13485 within a defined scope. It is not a device-specific marketing authorisation. EU market access runs through MDR/IVDR conformity assessment (for which ISO 13485 certification is supporting evidence, commonly assessed in the same visit under MD 9.3.1), and U.S. market access runs through 510(k), De Novo or PMA — separate determinations about a specific device. FDA does not issue ISO 13485 certificates and does not require one.

Where can I read the requirements myself?

IAF MD 9:2023 Issue 5 is freely published and is the device-sector document; read Annex A (technical areas) and Annex D (audit time) in particular. ISO/IEC 17021-1:2015 and ISO 13485:2016 are copyrighted and must be purchased from ISO or a national member body (ANSI in the U.S., BSI in the UK, DIN in Germany). Note that ISO 13485:2016 is separately available for inspection at FDA and the National Archives under the incorporation-by-reference provisions cited in 21 CFR 820.7.

Related CASRAI resources

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 44,322 indexed passages, and every answer cites the ones it drew on.