Compliance & StandardsGlossary

What Is ISO 13485?

Also known as: ISO 13485:2016, medical device QMS

Definition

ISO 13485 is the international quality management system standard for organizations involved in the design, production, installation, or servicing of medical devices, emphasizing regulatory compliance, risk management, and documented traceability throughout the product lifecycle.

ISO 13485 Explained

ISO 13485:2016 shares ancestry with ISO 9001 but has deliberately diverged. It did not adopt the Annex SL high-level structure used by the 2015 edition of ISO 9001, retaining instead a clause structure that regulators and notified bodies had already built around. Where ISO 9001 emphasizes customer satisfaction and continual improvement, ISO 13485 emphasizes meeting customer and applicable regulatory requirements and maintaining the effectiveness of the system - a subtle shift that reflects its purpose as a regulatory instrument rather than a business improvement framework.

Documentation is heavier and deliberately so. The standard requires a quality manual, documented procedures across defined areas, and for each device type or family a medical device file containing the specification, manufacturing and inspection requirements, and installation and servicing requirements. Records must be retained for at least the lifetime of the device as defined by the organization, and never less than periods set by regulation. This retention requirement alone shapes archiving strategy for ERP, MES, and document management systems.

Risk management runs through the whole standard and is applied to the product and to the processes, with ISO 14971 the companion standard for medical device risk management. Design and development controls are prescriptive: planning, inputs, outputs, review, verification, validation, transfer to production, change control, and a design history file. Software used in the quality system, in production, or in monitoring and measurement must be validated for its intended use, an obligation that reaches ERP configuration, label printing systems, and any automated inspection tooling.

Traceability and identification requirements are stricter than in general industry. Implantable devices carry heightened traceability, including records of components, materials, and work environment conditions, plus records of the personnel performing key operations. Unique Device Identification requirements from FDA and EU MDR layer on top, requiring device identifiers and production identifiers such as lot, serial, expiration, and manufacture date to be encoded, printed, and submitted to regulatory databases.

Regulatory alignment has tightened. FDA's Quality Management System Regulation final rule, issued in 2024, incorporates ISO 13485:2016 by reference into 21 CFR Part 820, replacing much of the legacy Quality System Regulation text with a compliance date in early 2026. In Europe, the harmonized version of the standard supports conformity assessment under the Medical Device Regulation. Certification to ISO 13485 does not by itself grant market access - it supports the regulatory submissions and notified body assessments that do.

Why It Matters

  • It is the practical prerequisite for medical device market access in most jurisdictions and underpins notified body assessment under EU MDR.
  • Record retention tied to device lifetime forces long-horizon archiving strategy across ERP, MES, and document control systems.
  • Software validation requirements apply to ERP configuration and label printing, making system changes a controlled, evidence-producing activity.
  • FDA's incorporation of the standard into 21 CFR Part 820 aligns US and international expectations, reducing duplicate systems for global manufacturers.

In Practice

Software validation is where ERP projects collide with ISO 13485. A configuration change to a label format, a lot numbering scheme, or an inspection plan is a change to validated software and requires documented impact assessment, test evidence, and approval before production use. Teams that treat ERP configuration as routine IT work generate findings quickly. Building a lightweight validation package template - intended use, risk assessment, test script, results, approval - into the change request process keeps velocity reasonable while satisfying auditors.

Frequently Asked Questions

What is the difference between ISO 13485 and ISO 9001?

ISO 13485 targets medical devices and prioritizes regulatory compliance, risk management, and documentation over the continual improvement and customer satisfaction emphasis of ISO 9001. It requires a quality manual, a medical device file, design controls, software validation, and long record retention. It also did not adopt the Annex SL structure, so the two standards no longer align clause by clause.

Does ISO 13485 certification satisfy FDA requirements?

It substantially aligns with them. FDA's Quality Management System Regulation incorporates ISO 13485:2016 by reference into 21 CFR Part 820, with a compliance date in early 2026. However, FDA retains additional requirements around records, complaint handling, and reporting, and certification by a notified body does not replace FDA inspection or clearance and approval pathways for a device.

Working with ISO 13485 in a live environment? Our engineers do this every day - and our AI agents automate most of it.