ISO Training for AS9100, 13485 & 50001: Avoid Costly Gaps

ISO training for AS9100, ISO 13485, and ISO 50001 each demand a different course level, not one generic ISO training course. This guide breaks down who needs awareness, internal auditor, or lead auditor training for AS9100, ISO 13485, and ISO 50001 — plus where to get accredited training for each standard.

A role-by-role training pathway guide for aerospace, medical device, and energy management systems

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Training Gap Nobody Budgets For

If you’re looking for ISO training for AS9100, ISO training for ISO 13485, or ISO training for ISO 50001, you’ve probably already run into the problem: most ISO training is built for ISO 9001 and doesn’t translate cleanly to these three standards. Manufacturers get ISO 9001 training right, then add AS9100 for an aerospace contract, ISO 13485 for a medical device line, or ISO 50001 for an energy initiative — and send the same people to the same generic “ISO awareness” course they used for quality management.

That’s a mistake, and it shows up fast. AS9100 auditors expect your team to speak to AS9101 audit requirements and IAQG OASIS supplier expectations — not generic quality-speak. ISO 13485 auditors expect design controls and CAPA competency, not general QMS awareness. ISO 50001 auditors expect your team to understand energy performance indicators, not just environmental basics.

Each of these standards has its own competency requirement and its own training hierarchy — and AS9100 adds a formal auditor authentication scheme on top, though that scheme applies specifically to certification body auditors rather than every internal auditor. Sending the wrong person to the wrong course doesn’t just waste a training budget. It leaves a documented competence gap that shows up the moment an auditor interviews the person responsible for that system.

I’ve built training matrices from the ground up during ISO 9001 implementation at a 500-employee valve and energy manufacturing operation, and the lesson translates directly to every management system standard: auditors don’t just check whether training happened. They check whether the person trained can actually explain the requirement in their own words, in their own work area. A certificate on file means nothing if the person can’t demonstrate the competency behind it.

👉 If you’re building out training for a new standard, confirm where your system already stands before you spend on courses → Download the Manufacturing Compliance Checklist


Quick Answer: Which Training Level Do You Need?

Your RoleRecommended Training Level
Executive Sponsor / LeadershipAwareness
Quality Manager / System OwnerLead Implementer
Internal AuditorStandard-specific Internal Auditor course
Certification / Third-Party AuditorLead Auditor (with AS9104/3 authentication for AS9100)
Production Supervisor / Department HeadFoundation / Requirements-level
Shop Floor / All PersonnelAwareness

In This Guide:

  • Why AS9100, ISO 13485, and ISO 50001 each need standard-specific training — not generic ISO training
  • Training levels and who needs them for each standard
  • AS9100’s unique auditor authentication requirement (AS9104/3)
  • ISO 13485 training and its connection to FDA QMSR competence requirements
  • ISO 50001 training and energy performance indicator competency
  • Where to get accredited training for each standard
  • Common training mistakes specific to these three standards


👉 Start Here (Top Resources)


Why These Three Standards Need Dedicated Training

ISO 9001, ISO 14001, and ISO 45001 share a harmonized high-level structure, which is why one training framework can reasonably cover all three — see ISO Training for Manufacturing Teams if that’s what you’re building. AS9100, ISO 13485, and ISO 50001 break from that pattern in three distinct ways:

StandardWhat breaks from the ISO 9001 pattern
AS9100Adds aerospace-specific clauses (configuration management, FAI, counterfeit parts) plus a formal auditor authentication scheme for certification auditors
ISO 13485Replaced “continual improvement” with maintaining effectiveness, and now has to align with FDA QMSR, which made ISO 13485:2016 the operative regulation as of February 2, 2026
ISO 50001Sits outside the quality/safety/environmental family — requires energy performance indicators and baseline methodology that don’t appear in any QMS or EMS course

If you’re evaluating certification bodies rather than training providers, see BSI vs ISOQAR for a full registrar comparison.


AS9100 Training: What Aerospace Suppliers Actually Need

AS9100 training carries a wrinkle the other standards on this list don’t have: a formal auditor authentication scheme. Under AS9104/3, certification body auditors seeking IAQG recognition must complete training through a Probitas Authentication-certified course. That requirement applies specifically to third-party certification auditors — internal auditors aren’t formally bound by it, but AS9104/3-aware training still benefits them, since it’s built around the same audit methodology customers and registrars expect to see reflected in your internal audit program.

A common scenario: a machine shop lands its first aerospace subcontract and assigns its existing ISO 9001-trained internal auditor to prep the QMS. The auditor knows the clause structure cold but has never worked with first article inspection requirements or configuration management controls — so the internal audit misses exactly the areas the customer’s supplier quality team will scrutinize first.

What AS9100 Training Covers Beyond ISO 9001

  • Configuration management and product safety requirements unique to aerospace
  • First article inspection (FAI) requirements under AS9102
  • Counterfeit parts prevention controls
  • Special requirements, critical items, and key characteristics
  • Risk management specific to aerospace supply chains
  • OASIS database requirements and supplier flow-down obligations

Who Needs AS9100 Training

Quality Manager / AS9100 Program Owner — Needs lead auditor or lead implementer training that specifically includes AS9104/3 authentication content. A generic ISO 9001 lead auditor credential typically does not provide sufficient coverage of aerospace-specific requirements such as AS9101, configuration management, product safety, and counterfeit parts prevention.

Internal Auditors — Need AS9100-specific internal auditor training. Formal AS9104/3 authentication isn’t required for internal auditors, but Probitas-recognized coursework still gives them the audit methodology customers and registrars expect to see — particularly useful if your organization plans to grow its internal audit program.

Production and Program Management — Need foundation-level AS9100 training covering configuration management, FAI, and counterfeit parts controls — the areas aerospace auditors probe hardest during a floor walkthrough.

All Personnel Touching Aerospace Work — Need awareness training covering product safety culture and counterfeit parts recognition, both explicit AS9100 requirements.

For a full breakdown of AS9100’s aerospace-specific clauses, see What Is AS9100? and Aerospace Supplier Compliance Standards.

Where to Get AS9100 Training

BSI Group AS9100 Training — BSI’s AS9100 catalog covers requirements through lead auditor training, with courses built around ISO 19011 audit methodology and Probitas Authentication recognition for the lead auditor level. BSI is the strongest option for AS9100 given their aerospace sector depth.

Purchase the official AS9100 standard through the ANSI Webstore before training begins — your team needs the current Rev D text in hand during coursework.

⚠️ Most common finding in aerospace audit prep: internal auditors trained only on generic ISO 9001 methodology, with no exposure to AS9104/3-aware audit practices or AS9101 audit reporting format. Formal authentication isn’t required for them, but when a customer or registrar reviews an internal audit program built entirely on ISO 9001 methodology, the gap surfaces fast.

Professional infographic mapping organizational roles to recommended ISO training levels for AS9100, ISO 13485, and ISO 50001, including executive sponsors, quality managers, auditors, supervisors, and shop floor personnel.
Assigning the appropriate ISO training to each organizational role builds competency, strengthens compliance, and improves certification readiness.

ISO 13485 Training: Meeting FDA QMSR Competence Expectations

ISO 13485 training has to accomplish something ISO 9001 training doesn’t: bridge a quality standard with an active regulatory framework. Since FDA QMSR incorporates ISO 13485:2016 by reference as the operative regulation for device manufacturers, training records now need to demonstrate competence against both the standard’s clauses and the regulatory context surrounding them.

A common scenario: a medical device startup trains its quality team on general ISO 9001 principles, assuming the overlap between the two standards covers the gap. The team performs fine on document control and internal audits — then struggles the first time a design history file review comes up, because ISO 9001 training never covered design control traceability or how a DHF ties back to risk management under ISO 14971.

What ISO 13485 Training Covers

  • Design and development controls, including design history file requirements
  • CAPA (Corrective and Preventive Action) process ownership and documentation
  • Risk management integration with ISO 14971
  • Regulatory requirements specific to device classification
  • Documentation and record retention aligned with FDA QMSR expectations
  • Internal audit methodology focused on maintaining effectiveness rather than continual improvement language

Who Needs ISO 13485 Training

Quality/Regulatory Affairs Lead — Needs requirements-level or lead implementer training that explicitly covers the FDA QMSR transition, not a course built solely around the ISO 13485 text in isolation.

Design and Development Personnel — Need training on design control requirements and design history file documentation — an area auditors and FDA reviewers scrutinize closely.

Internal Auditors — Need ISO 13485-specific internal auditor training. An ISO 9001 internal auditor credential does not adequately prepare someone to audit CAPA effectiveness or design control records.

Production and CAPA Owners — Need foundation-level training on nonconformance handling, CAPA documentation, and how “maintaining effectiveness” differs from the continual improvement language used in ISO 9001.

For deeper context on this terminology distinction, see Common Mistakes in ISO 13485 QMS and CAPA Requirements in ISO 13485.

Where to Get ISO 13485 Training

BSI Group ISO 13485 Training — BSI’s medical device training reflects direct regulatory experience across FDA, EU MDR, and global device markets — training only, not standard purchases.

Purchase the official ISO 13485:2016 standard from the ANSI Webstore — BSI does not pay commission on standards purchased directly, so route standard purchases through ANSI.

👉 Design controls and CAPA competency don’t build themselves from a training certificate alone. Pair training with a structured gap assessment before your next audit cycle → Download the ISO 13485 Gap Assessment Checklist


ISO 50001 Training: Building Energy Management Competency

ISO 50001 training is frequently treated as an extension of environmental management training. It isn’t. Energy management systems require a distinct competency set built around measurement and performance tracking rather than aspect/impact analysis.

A common scenario: a plant installs energy monitoring equipment and starts tracking consumption, assuming that satisfies the standard’s data requirements. During certification, the auditor asks how the energy performance indicators were established and what baseline period they’re measured against — and the team can’t answer, because nobody was trained on EnPI methodology specifically. The monitoring data exists; the defensible baseline behind it doesn’t.

What ISO 50001 Training Covers

  • Energy review methodology and identifying significant energy uses (SEUs)
  • Establishing energy baselines and energy performance indicators (EnPIs)
  • Legal and regulatory energy requirements
  • Data collection systems for energy monitoring
  • Internal audit methodology specific to energy management systems
  • Integration considerations with ISO 14001 for organizations running both systems

Who Needs ISO 50001 Training

Energy Manager / EnMS Owner — Needs lead implementer or requirements-level training covering EnPI methodology and energy baseline development. This is the most technical role on this list and benefits most from dedicated coursework rather than a generalist environmental credential.

Facilities and Maintenance Personnel — Need foundation training on how energy performance indicators connect to equipment operation and maintenance practices.

Internal Auditors — Need ISO 50001-specific internal auditor training. Auditing an EnMS requires evaluating energy data integrity and EnPI tracking — skills a generic management-systems auditor doesn’t automatically have.

For how ISO 50001 fits alongside other environmental and safety systems, see ISO 14001 vs ISO 50001.

Where to Get ISO 50001 Training

ISOQAR ISO 50001 Training — Awareness through internal and lead auditor courses covering EnMS audit methodology.

BSI Group ISO 50001 Training — Full training suite including on-demand eLearning fundamentals and IRCA-certified lead auditor coursework.

Purchase the official ISO 50001 standard from the ANSI Webstore before implementation training begins.


Training Level Comparison Across All Three Standards

Professional infographic showing two ISO training pathways, implementation and audit tracks, for AS9100, ISO 13485, and ISO 50001 with role-based competency progression.
Implementation and audit training follow different competency pathways, helping organizations assign the right ISO training to the right people.
StandardFoundation LevelInternal AuditorLead Auditor / ImplementerUnique Requirement
AS9100Configuration mgmt, FAI, counterfeit partsAS9104/3-aware internal audit trainingProbitas Authentication-recognized lead auditorAuditor authentication scheme
ISO 13485Design controls, CAPA basics13485-specific audit training (not ISO 9001 credential)Requirements/lead implementer with FDA QMSR contextRegulatory bridge to FDA QMSR
ISO 50001Energy review, SEU identificationEnMS-specific audit trainingEnPI methodology, lead auditor (IRCA)Data/measurement-based competency

Where to Get Training for Each Standard

Per your affiliate priority mapping and BSI’s sector depth, BSI Group is the primary training provider for AS9100 and ISO 13485. ISOQAR is primary for ISO 50001, with BSI as a secondary option for organizations wanting a single training provider across systems.

⚠️ Always purchase the standard itself through the ANSI Webstore rather than through your training provider — BSI does not pay commission on standards purchased directly through their site, and ANSI consistently offers the most competitive pricing with coupon CC2026 for 5% off through December 31, 2026.

If you’re evaluating certification bodies rather than training providers specifically, the decision criteria differ — see BSI vs ISOQAR: Which ISO Training and Certification Body Is Right for You? for a full registrar-selection comparison across all three standards.


Professional infographic comparing implementation and audit training pathways with a role-based ISO training matrix for AS9100, ISO 13485, and ISO 50001 organizations.
This role-based training matrix helps organizations match ISO training levels to specific responsibilities while distinguishing implementation and audit career pathways.

Common Training Mistakes Specific to These Standards

1. Treating AS9100 training as “ISO 9001 plus a little extra.” The auditor authentication requirement alone makes this a fundamentally different training investment, not an add-on.

2. Training ISO 13485 teams on “continual improvement” language. If your training materials use ISO 9001 terminology instead of “maintaining effectiveness,” your team will misstate a core requirement to an auditor.

3. Assuming an ISO 14001-trained environmental manager can run an EnMS. Energy performance indicators and baseline methodology are a distinct skill set that environmental training doesn’t cover.

4. Skipping FDA QMSR context in ISO 13485 training. Since QMSR made ISO 13485:2016 the operative regulation in February 2026, training that treats the standard as a standalone quality framework — without regulatory context — leaves a competence gap.

5. Using generic ISO 9001 methodology for AS9100 internal audits. Formal authentication isn’t required internally, but if your auditors have never worked with AS9104/3-aware methodology or AS9101 reporting, a customer supplier-quality audit will notice the gap.


Quick Training Readiness Checklist

✅ Quality/program owner has standard-specific lead auditor or lead implementer training — not a generic ISO 9001 credential

✅ Internal auditors have completed training specific to the standard being audited

✅ AS9100 internal auditors have exposure to AS9104/3-aware audit methodology

✅ ISO 13485 training materials use “maintaining effectiveness” language, not continual improvement

✅ ISO 50001 program owner has completed EnPI and energy baseline methodology training

✅ Training records document competence — not just attendance

✅ Training effectiveness has been evaluated, not just completed


FAQ

Can I use my ISO 9001 lead auditor credential to audit AS9100?

For internal audits, yes — with gaps. Your credential covers the shared clause structure, but AS9100 audits also require familiarity with AS9101 audit reporting and aerospace-specific clauses like configuration management and FAI. For third-party certification auditing, formal IAQG authentication under AS9104/3 is required and an ISO 9001 credential alone doesn’t satisfy it.

Does ISO 13485 training need to reference FDA QMSR specifically?

Yes, if you manufacture for the US market. Since FDA QMSR became effective February 2, 2026 and made ISO 13485:2016 the operative regulation, training that doesn’t bridge the standard to QMSR competence expectations leaves a documentation gap auditors and FDA reviewers will notice.

Is ISO 50001 training the same as ISO 14001 training?

No. ISO 50001 requires competency in energy performance indicators, energy baselines, and significant energy use identification — concepts that don’t appear in ISO 14001’s environmental aspect/impact framework.

How long does AS9100 lead auditor training take?

Most Probitas Authentication-recognized AS9100 lead auditor courses run five days, combining classroom instruction with practical audit exercises and a written examination.

Who needs the AS9104/3 authentication specifically?

Formal AS9104/3 authentication applies to certification body auditors seeking IAQG recognition — it’s not a requirement for internal auditors within your own organization. That said, internal auditors benefit from AS9104/3-aware training, since it reflects the same audit methodology your customers and registrar will expect to see.

What’s the difference between an ISO 13485 internal auditor course and an ISO 9001 internal auditor course?

An ISO 13485 course trains auditors to evaluate design controls, CAPA effectiveness, and risk management integration with ISO 14971 — none of which appear in a standard ISO 9001 internal auditor course.

Do I need separate ISO 50001 training if my team already has ISO 14001 training?

Yes. While both are environmental/sustainability-adjacent, ISO 50001’s technical focus on energy measurement and EnPI tracking requires dedicated training your ISO 14001 course won’t cover.

Where do I purchase the AS9100, ISO 13485, or ISO 50001 standards my training is based on?

Purchase all three directly from the ANSI Webstore. Use coupon code CC2026 for 5% off through December 31, 2026.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching which standard applies to you — Read What Is AS9100? or Medical Device Compliance Standards for a foundational overview before committing to a training path.

🔹 Ready to schedule training nowBSI Group’s AS9100 and ISO 13485 training catalog covers awareness through lead auditor. ISOQAR’s ISO 50001 training covers energy management specifically.

🔹 Need to purchase the standard your training is based on — Get AS9100, ISO 13485, or ISO 50001 directly from the ANSI Webstore. Use code CC2026 for 5% off through December 31, 2026.

🔹 Deciding between certification bodies, not just training providers — See BSI vs ISOQAR for a full registrar comparison.

The Standards Navigator covers training, certification, and implementation guidance across every major manufacturing standard — not just the ones with the most search volume. If your operation is expanding into aerospace, medical device, or energy management work, get your team’s competency built on standard-specific training before your first surveillance audit tests the gap.


Stay Ahead of Specialized Compliance Training

Manufacturers expanding into aerospace, medical device, or energy management work don’t usually get caught by the standard itself. They get caught because they trained their team like the new standard was just a variation on ISO 9001.

Organizations that certify cleanly recognize each standard’s distinct competency requirements early and train accordingly — an AS9100 program owner who understands AS9104/3, an ISO 13485 quality lead who speaks FDA QMSR fluently, an energy manager who can build a defensible EnPI baseline.

The Standards Navigator covers training pathways, certification body selection, and implementation guidance across every standard your operation touches — not just the most common ones.

👉 Get updates on specialized ISO training across aerospace, medical device, and energy management 👉 Be first to access new gap assessment checklists as they’re released

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

How to Audit a Medical Device QMS: The ISO 13485 Internal Audit Process (2026 Guide)

This guide walks medical device manufacturers through the ISO 13485 Clause 8.2.4 internal audit requirement — including audit program design, the six-step audit process, and the five most common findings auditors cite. It also covers what changed under the FDA QMSR and the new ISO 19011:2026 audit guidance.

A clause-by-clause guide to planning, conducting, and closing out ISO 13485 internal audits under the new FDA QMSR

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Internal Audit That Used to Be Private Isn’t Anymore

For years, medical device manufacturers treated the internal audit report as an internal document — useful for finding problems, but shielded from FDA inspectors under the confidentiality provision in the old 21 CFR 820.180(c). That protection is gone.

Since February 2, 2026, the FDA’s Quality Management System Regulation (QMSR) has been in effect, and it incorporates ISO 13485:2016 by reference rather than running a parallel U.S.-specific standard alongside it. FDA’s own Final Rule FAQ is direct about what that means for audits: “The QMSR gives the FDA the authority to inspect management review, quality audits, and supplier audit reports. The exceptions that existed in the QS regulation at § 820.180(c) are not maintained in the QMSR.” That’s not a third-party interpretation — it’s FDA’s own published position.

So this isn’t limited to internal audit reports. Management review minutes and supplier audit reports lost the same protection. A checklist you run through once a year to satisfy Clause 8.2.4 on paper is no longer a low-risk approach — it’s now a document an inspector may read line by line, and so are the meetings where leadership reviewed it.

From the Floor: I’ve built and run internal audit programs at facilities with 500-plus employees, and the finding that costs organizations the most isn’t a missing procedure — it’s a corrective action that gets closed on paper before the root cause is actually fixed. As a certified ISO 9001 Internal Auditor, I’ve sat across the table from auditors who catch that in about ninety seconds. Whether you’re auditing to ISO 9001 or ISO 13485, the internal audit only works if it’s harder on you than the external one will be.

Before your next surveillance audit, most quality teams don’t fail because they misunderstand Clause 8.2.4 — they fail because their audit program looks complete on paper but hasn’t been stress-tested against real objective evidence. Run your QMS through the free ISO 13485 Gap Assessment Checklist before an inspector or a Notified Body does it for you.


In This Guide

  • What ISO 13485 Clause 8.2.4 actually requires
  • How internal audits differ from supplier and certification audits
  • What Clause 6.2 actually requires of your auditors — and what “competent” really means
  • Building a risk-based annual audit program
  • The audit process: planning, evidence, reporting, and CAPA follow-up
  • A real finding-to-CAPA example, start to finish
  • The five most common internal audit findings — and how to avoid them
  • What changes if you’re audited under MDSAP
  • What changed under the FDA QMSR and ISO 19011:2026
  • Whether you need outside help or can run this internally


👉 Start Here (Top Resources)


What Clause 8.2.4 Actually Requires

ISO 13485 requires internal audits under Clause 8.2.4 to verify that QMS processes are implemented and effective, catch nonconformities, and surface QMS deficiencies early enough that they don’t become product-safety or regulatory problems. That sounds close to ISO 9001’s internal audit clause, and it is — but ISO 13485 asks for more.

Clause 8.2.4 requires that internal audits determine conformity to planned arrangements, the requirements of the standard, the organization’s own QMS requirements, and applicable regulatory requirements — and unlike ISO 9001, ISO 13485 explicitly requires the audit program to account for regulatory requirements such as FDA 21 CFR Part 820, EU MDR, or MDSAP alongside the standard itself. Teams that build their audit program purely off the ISO 13485 clause structure, without folding in the regulatory layer, are the ones who get flagged.

Most common finding: auditors treat Clause 8.2.4 as a documentation-review exercise and skip the regulatory cross-reference entirely. If your audit checklist doesn’t ask “does this also satisfy 21 CFR Part 820 or MDR Article 10?” it isn’t finished.

Audits must assess conformity across critical processes — design and development under Clause 7.3, corrective action under Clause 8.5.2, preventive action under Clause 8.5.3, production under Clause 7.5, and document control under Clause 4.2 — using objective evidence like device history records, audit trails, and validation records. Auditors must be trained, qualified, and independent of the area they’re auditing, with that competence documented under Clause 6.2.

If you are already ISO 9001 certified → your internal audit infrastructure transfers directly, but your checklist needs a regulatory column added for every process area, not just a conformity column.


Internal Audits vs. Supplier Audits vs. Certification Audits

Comparison infographic showing internal audits, supplier audits, and certification audits under ISO 13485.
Understanding the differences between internal, supplier, and certification audits improves audit planning and regulatory compliance.

Manufacturers frequently conflate these three, and an auditor will notice immediately if your procedure does too.

Audit TypeGoverning ClausePerformed ByPrimary Purpose
Internal AuditClause 8.2.4Trained internal personnel, independent of the area auditedVerify your own QMS conforms to the standard and your own procedures
Supplier AuditClause 7.4.1Quality or supplier quality personnelVerify external providers meet quality and regulatory requirements
Certification AuditISO/IEC 17021-1Accredited third-party Notified Body or registrarDetermine whether the full QMS meets ISO 13485 for certification

ISO 13485 requires internal audits, just as its sister standard ISO 9001 does, and they exist for two reasons: to confirm the QMS meets the standard’s requirements, and to confirm the organization actually follows its own rules. A strong internal audit program is what makes a certification audit uneventful instead of a fire drill.


Auditor Competence: What Clause 6.2 Actually Requires

This is the section most audit programs get thin on, and it’s where a surprising number of otherwise solid internal audit programs fall apart under scrutiny.

Clause 6.2 requires that anyone doing work affecting product quality — and that includes auditors — be competent based on appropriate education, training, skills, and experience. ISO 13485 doesn’t spell out a fixed list of required knowledge areas the way a checklist would, but three areas consistently show up when a Notified Body reviews auditor files:

  • The standard itself. A working knowledge of ISO 13485:2016 clause structure, not just the SOPs written to satisfy it.
  • Audit methodology. Understanding of the audit cycle — planning, evidence gathering, reporting, follow-up — along with the difference between a minor observation and a major nonconformity. ISO 13485’s own note under Clause 8.2.4 points auditors toward ISO 19011 for this.
  • Applicable regulatory context. Basic familiarity with the regulations that apply to your product and markets — 21 CFR Part 820, EU MDR, MDSAP — not full legal mastery, but enough to recognize when a finding also touches a regulatory requirement.

Competence is not the same thing as certification. ISO 13485 does not require a certified internal auditor credential, and ISO 19011 doesn’t mandate formal training either — the standard’s actual requirement is that the audit process ensure objectivity and impartiality, and that competence be evaluated and documented. In practice, though, “read and understand the internal procedure” is not evidence Notified Bodies accept as sufficient. An auditor who can’t produce a training record, a completed course certificate, or documented on-the-job evaluation showing how their competence was assessed is a finding waiting to happen — even if that person is, in fact, good at the job.

What acceptable training records look like in practice:

  • A certificate of completion from an ISO 13485 internal auditor course (typically covering the standard itself plus ISO 19011 audit methodology) — see BSI vs. ISOQAR if you’re deciding where to send your team for that training
  • Internal on-the-job qualification records — a documented mentored audit or two, signed off by a qualified lead auditor
  • A training matrix that ties each auditor to the specific processes and clauses they’re qualified to audit, refreshed when the QMS or the standard changes

Auditor independence gets checked alongside competence. The most frequent failure here isn’t a skills gap — it’s a quality manager who owns a process auditing that same process, or an auditor rotation that never actually rotates the highest-risk areas like design controls.

If you are not confident your auditor files would hold up to this list → that’s a fifteen-minute file review, not a project, and it’s worth doing before your next Notified Body visit rather than during it.


Building a Risk-Based Audit Program

The audit program must cover every process, department, and site within your QMS scope, with audit frequency determined by the status and importance of each process along with the results of prior audits. High-risk processes — design and development, production, CAPA, and complaint handling — typically need at least annual coverage, while lower-risk support functions can be audited less frequently if previous results were consistently clean.

Most manufacturers get the frequency question backwards. They audit everything on a flat annual calendar instead of weighting toward where the last audit found something. If your CAPA process had a finding last year, auditing it again on the same twelve-month clock as your HR training records is a scheduling decision an inspector will question.

If you are preparing for your first surveillance audit under the new QMSR → build your program around the regulatory cross-reference first, then layer the standard’s clause structure on top of it — not the other way around.


The Internal Audit Process, Step by Step

Infographic illustrating the ISO 13485 internal audit process from planning through CAPA verification for medical device quality management systems.
The six-step ISO 13485 internal audit process helps medical device manufacturers identify nonconformities and verify corrective actions.

Prepare a checklist based on the relevant clauses of ISO 13485, your documented procedures, and applicable regulatory requirements — a good checklist prompts investigation rather than simply confirming what’s already assumed to be true.

1. Scope and schedule. Define which processes, sites, and clauses are in scope for this audit cycle.

2. Documentation review. Analyze the quality manual, procedures, and prior audit reports before setting foot on the floor — this is where checklists get mapped to specific clauses.

3. Opening meeting. Confirm scope, objectives, and methodology with the auditee before evidence-gathering begins — this sets the tone for the entire audit.

4. Evidence gathering. Collect objective evidence through interviews, direct observation, and document/record review — no finding should be written down without evidence behind it.

5. Reporting. Findings get written up, classified by severity, and routed to the process owner and management.

6. CAPA follow-up. Every corrective action needs documented root cause analysis appropriate to the significance of the nonconformity, with effectiveness verified before the CAPA is closed.

Most teams execute steps 1 through 5 competently. Step 6 is where programs fall apart — a CAPA gets marked closed the day the immediate fix is implemented, with no verification that the fix actually held.

Trigger: If your last three internal audits found the same category of nonconformity in different words each time, that’s not three separate findings — that’s one root cause your CAPA process never actually reached.

Before your next audit cycle, check your CAPA closure process against what auditors actually verify — most teams don’t realize how thin their effectiveness checks are until someone else reviews them.


A Real Finding, Start to Finish

Steps on a page are easy to nod along with. Here’s what a properly closed finding actually looks like end to end, using one of the most common design-control gaps auditors find.

StageWhat It Looked Like
FindingDuring a design and development audit, three of twelve design verification records sampled were missing the reviewer’s signature. Work was completed and dated, but sign-off wasn’t captured.
Objective EvidenceDesign History File records DHF-114, DHF-119, and DHF-122, cross-referenced against the design review meeting minutes showing the reviews occurred.
Nonconformity Statement“Design verification records DHF-114, DHF-119, and DHF-122 lack the required reviewer signature per QMS-SOP-014, Section 6.2. Design and development control per ISO 13485:2016 Clause 7.3.6 requires verification results, including necessary actions, to be recorded.”
Root CauseInvestigation traced it to a recent SOP revision that moved the sign-off step later in the workflow. Staff hadn’t been retrained on the updated sequence — the procedure changed, but the training that should have accompanied it under Clause 6.2 didn’t happen.
CorrectionThe three records were completed retroactively with the reviewer’s signature and a note explaining the delay, reviewed and accepted by the quality manager.
Corrective Action (CAPA)Retrain design team on the revised sign-off sequence; add a mandatory signature field to the design review template so records can’t be filed incomplete.
Effectiveness CheckSample the next ten design verification records over the following quarter. Zero missing signatures required to close the CAPA as effective.

Notice what makes this closeable rather than cosmetic: the root cause isn’t “people forgot” — it’s a training gap tied to a specific procedure change, and the corrective action addresses the system, not just the three records. That’s the difference between a finding that stays closed and one that reappears with different reference numbers next year.


The Five Most Common Findings

Infographic highlighting the five most common ISO 13485 internal audit findings in medical device quality management systems.
The most common ISO 13485 internal audit findings often involve documentation, CAPA effectiveness, auditor competence, and risk-based planning.

Incomplete audit records — missing reports, plans, or linked CAPAs — is one of the most frequently cited internal audit issues. A close second is failing to apply a risk-based approach to audit planning, or simply not maintaining the internal audit schedule at all. Beyond that, auditors regularly find no timely follow-up on actions from internal audits, no records showing auditor competence against the applicable regulations, and auditors who weren’t actually impartial — reviewing work they had a hand in.

Design and development controls remain the single most frequently cited nonconformity area globally — incomplete design inputs, missing verification or validation records, undocumented design changes, or no formal design transfer procedure. See Validation & Verification Requirements for how this plays out in practice.

⚠️ If your auditor rotation lets the same person audit design controls year after year without ever being audited themselves on that same process, that’s an impartiality gap that a Notified Body will flag before you do.

If you are not confident your last internal audit would hold up under this list → that’s exactly what a structured gap assessment is for, not a guess.

Check your program against these five findings before your next audit — most gaps take under 45 minutes to identify →


MDSAP: What Changes for Multi-Market Audits

If your devices sell into more than one of the five MDSAP markets — the U.S., Canada, Australia, Brazil, or Japan — your internal audit program needs to account for a different audit model, not just an extra regulatory reference.

The Medical Device Single Audit Program lets one audit by an accredited Auditing Organization satisfy the requirements of all five participating regulators at once, in place of separate national audits. It’s built on ISO 13485:2016, but it isn’t a straight overlay — MDSAP uses a process-based audit model with a defined sequence, rather than working straight down the ISO clause list, and it maps every audit task to both the relevant ISO 13485 clause and each country’s specific regulatory requirement.

The grading system is the biggest practical difference. Where an ISO 13485 certification audit typically classifies findings as minor or major, MDSAP uses a points-based Grade 1–5 scale: nonconformities affecting clauses with indirect QMS impact start lower, direct-impact clauses start higher, and points are added for repeat findings or for a nonconforming product that was actually released. Grade 4 and 5 findings must be resolved before a certificate is issued or maintained — there’s no ambiguity about severity once the math is run.

What this means for your internal audit program: if you’re pursuing or maintaining MDSAP, your internal audits should follow the MDSAP process sequence — not just walk through ISO 13485 clauses in order — so that gaps surface in the same structure an Auditing Organization will use. The recurring findings across published MDSAP audits track closely with the same weak points internal audits should already be hunting for: open CAPAs left unclosed past a reasonable window, supplier and purchasing controls that don’t demonstrate follow-through, and root cause analysis that’s thin enough to not survive a second look.

One benefit worth knowing about: MDSAP audit reports can substitute for the FDA’s routine biennial device inspections. A well-run MDSAP program isn’t just multi-market efficiency — it can reduce how often FDA shows up separately.


What Changed: QMSR and ISO 19011:2026

Two regulatory shifts affect how internal audits get run in 2026, and both are recent enough that older internal procedures may not reflect them.

Since February 2, 2026, the FDA’s QMSR has incorporated ISO 13485:2016 by reference, replacing the former Quality System Regulation, and FDA inspections now run under Compliance Program 7382.850 rather than the old QSR framework. As covered above, the practical effect for internal audits is direct: the confidentiality safe harbor that used to apply to internal audit reports, management review records, and supplier audit reports under the old 21 CFR 820.180(c) has been removed, and FDA’s own FAQ confirms it in plain language.

Separately, ISO published the fourth edition of ISO 19011 — Guidelines for auditing management systems — on May 27, 2026, replacing the 2018 edition that had guided audit programs for nearly eight years. ISO 13485 doesn’t mandate ISO 19011 compliance directly — Clause 8.2.4 references audit principles in its own language — but Notified Bodies and experienced auditors widely treat ISO 19011 as the authoritative reference for structuring an audit program, so if your internal audit SOPs still cite the 2018 edition, expect your Notified Body to ask why.

Neither change requires rebuilding your program from scratch. Both are reasons to review your internal audit SOP this year rather than next.


Quick Audit-Readiness Checklist

✅ Audit program covers every process, site, and department in your QMS scope ✅ Audit frequency is risk-weighted, not a flat annual calendar
✅ Every checklist item maps to a specific ISO 13485 clause and the applicable regulatory requirement
✅ Auditors are independent of the area they’re reviewing, with Clause 6.2 competence records on file — not just “read and understand” sign-offs
✅ Findings are backed by objective evidence — interviews, observation, or documented records
✅ CAPA effectiveness is verified before closure, not assumed
✅ If pursuing MDSAP, internal audits follow the MDSAP process sequence, not just the ISO clause order
✅ Internal audit SOP references ISO 19011:2026, not the 2018 edition
✅ Design and development records are current — this is the single most-cited finding category


FAQ

How often does ISO 13485 require internal audits?

The standard doesn’t specify a fixed interval — it requires audits “at planned intervals” based on process risk and prior audit history. Most manufacturers audit high-risk processes like design controls and CAPA annually at minimum, with lower-risk support functions audited less frequently if history is clean.

Can the same person who performs a process also audit it?

No. Clause 8.2.4 requires auditors to be independent of the area being audited. A quality manager who owns the CAPA process, for example, shouldn’t be the one auditing CAPA compliance.

Do internal auditors need a formal certification?

No. ISO 13485 requires documented competence — education, training, skills, and experience — but doesn’t mandate a specific certification. In practice, most Notified Bodies expect more than an internal read-and-understand sign-off, so a course certificate or documented mentored-audit record is the safer standard to work toward.

Does the FDA QMSR require a separate internal audit program from ISO 13485?

No. Since the QMSR incorporates ISO 13485:2016 by reference, there isn’t a separate U.S.-specific internal audit requirement layered on top — your Clause 8.2.4 program is the audit program the FDA now expects, with the regulatory cross-reference built in.

Are internal audit reports confidential from FDA inspectors?

Not anymore. FDA’s own QMSR Final Rule FAQ confirms the confidentiality exceptions under the old 21 CFR 820.180(c) — covering internal audits, management review, and supplier audits — are not maintained under the QMSR.

What’s the difference between an internal audit and a supplier audit under ISO 13485?

Internal audits (Clause 8.2.4) evaluate your own QMS. Supplier audits (Clause 7.4.1) evaluate external providers’ ability to meet your quality and regulatory requirements. Both are required, but they’re separate programs with separate scopes.

Does MDSAP replace our ISO 13485 internal audit requirement?

No, but it changes the structure. MDSAP is built on ISO 13485 and layers in country-specific regulatory requirements from up to five markets, using a process-based sequence and a points-based Grade 1–5 nonconformity system rather than the minor/major classification used in standard certification audits.

What’s the most common reason internal audit programs fail a certification audit?

Incomplete records — missing audit reports, plans, or linked CAPAs — combined with no evidence of a risk-based approach to scheduling. Both are findings a Notified Body catches quickly because they’re procedural gaps, not technical ones.

Should we hire a consultant to run our internal audits, or can we do it ourselves?

Either can work if the auditor is properly trained and genuinely independent of the process. Many manufacturers use in-house auditors for most cycles and bring in an outside auditor periodically to test whether their internal program is actually rigorous or just familiar with its own blind spots.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching your audit obligations? Start with ISO 13485 Documentation Requirements to understand what your QMS needs on paper before you audit it.

🔹 Ready to build or strengthen your audit program? 9001Simplified’s documentation templates can shortcut the SOP-writing process without a consultant retainer.

🔹 Need the standard itself to build your checklist against? Get ISO 13485:2016 from ANSI Webstore — code CC2026 takes 5% off through the end of 2026.


An internal audit program that only exists to satisfy Clause 8.2.4 on paper was already a risk before the QMSR removed the confidentiality safe harbor. Now it’s a document an inspector can read directly. The Standards Navigator will keep tracking what QMSR enforcement and ISO 19011:2026 mean for how medical device manufacturers actually run their audit programs — not just what the clause says.


Subscribe for Medical Device Compliance Updates

Most manufacturers don’t lose a certification over one bad audit finding — they lose it over a pattern of findings their own internal audit program should have caught first. Organizations that treat Clause 8.2.4 as a paperwork requirement get surprised at surveillance. Organizations that treat it as their first line of defense rarely do.

The Standards Navigator tracks how ISO 13485, the FDA QMSR, and the standards that govern medical device audits actually work in practice — not just what the clause text says.

👉 Get updates on ISO 13485 audit requirements and QMSR enforcement changes 👉 Be first to access new medical device compliance checklists and gap assessment tools

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

ISO 10993 Contact Duration Matrix- How to Select Tests (2026 Guide)

ISO 10993-1:2025 retired the old Table A.1 checklist approach to biocompatibility testing. This guide explains the current contact duration categories, how total exposure period is calculated for reusable devices, and which biological endpoints apply — including FDA’s partial recognition of the new edition.

ISO 10993 Contact Duration Matrix and Biological Endpoint Selection Explained

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Matrix Changed. If Your Biological Evaluation Plan Still Reads Like 2018, You Have a Gap

Table A.1 is gone. For seven years, biological evaluation plans were built around a single grid in Annex A of ISO 10993-1:2018 — cross-reference device category and contact duration, check the boxes, done. That table has been retired. ISO 10993-1:2025, published November 18, 2025, split it into four separate tables and rebuilt the exposure-duration logic underneath them.

ISO 10993-1:2025 is the international standard that guides biocompatibility and biological evaluation of medical devices using a risk-based framework, replacing the prescriptive checklist approach of the 2018 edition.

If your BEP still cites the 2018 ISO 10993 contact duration matrix, or if you categorized a reusable device’s contact duration based on a single use rather than total exposure period, you may already be carrying a documentation gap — one that surfaces exactly when a reviewer or notified body opens your file.

Regulatory affairs teams are asking a narrower question than “what is ISO 10993”: which biological endpoints does this specific device trigger under the current framework, and why. That’s what this guide walks through.

I’ve sat across the table from an auditor reviewing a biological evaluation plan where the contact duration category didn’t match the device’s actual use pattern — a reusable component that looked like “limited” contact on paper but was accumulating well past 24 hours across a single patient’s treatment course. The documentation existed. The categorization logic behind it didn’t hold up. That’s the gap this guide is built to close before it becomes a finding.

👉 Before you finalize your next biological evaluation plan, run it against a structured QMS gap check first. Get the free ISO 13485 Gap Assessment Checklist and confirm your documentation controls support the categorization decisions your BEP depends on.

In This Guide

  • What changed in the ISO 10993-1:2025 evaluation matrix and why Table A.1 was retired
  • The current contact duration categories and how “total exposure period” is calculated
  • How to categorize daily contact, intermittent contact, and reusable devices correctly
  • Which biological endpoints apply to each contact duration and body-contact combination
  • What FDA’s partial recognition of ISO 10993-1:2025 means for your submission
  • Common categorization mistakes that trigger additional testing requirements
  • Where to buy the current standard and where to get ISO 13485-aligned training


👉 Start Here (Top Resources)

  • ISO 10993-1:2025 — ANSI Webstore — the current edition, direct from the accredited source. Use code CC2026 for 5% off. (Eric: insert the exact ANSI product link for ISO 10993-1:2025 here.)
  • If you’re weighing whether to buy standards individually or as a set, the ANSI bundle option is worth checking before you purchase the 10993 series piece by piece.
  • ISO 13485 Training — BSI Group — for teams building biological evaluation competency into a certified QMS.
  • ISO Training Courses — ISOQAR — a second accredited training option worth comparing against BSI on schedule and price.

Why the Evaluation Matrix Was Restructured

Under ISO 10993-1:2018, Annex A Table A.1 organized devices by body contact category — surface, external communicating, implant — crossed with three contact duration bands, and listed an “X” for every biological endpoint a reviewer might expect to see addressed. Industry insiders came to call it the “Table A.1 mentality”: manufacturers treated the X’s as a mandatory checklist rather than a starting point for risk-based justification. Tests got run because they appeared in a cell, not because a documented risk assessment called for them.

ISO 10993-1:2025 splits that single table into four separate tables, each tied to a specific evaluation context, and embeds the framework more tightly into the ISO 14971 risk management process. The standard now expects a Biological Evaluation Plan built on the device’s actual risk profile — chemical characterization, materials history, intended use, contact pattern — with the tables used to check completeness, not generate a test order.

Most common finding: biological evaluation plans that cite “Table A.1” by name, or that list endpoints without a documented rationale tied to the device’s specific exposure profile. Under the current standard, that’s a gap a reviewer will flag.

If you are still building your first BEP for a device entering the medical device space, start with what the supplier controls requirements under ISO 13485 expect from your materials documentation — biological evaluation depends heavily on having reliable supplier and materials data before you ever get to a test matrix.

Contact Duration Categories, Defined

The three contact duration categories are unchanged in name but recalculated in practice:

CategoryCumulative ContactTypical Devices
LimitedUp to 24 hours totalDiagnostic swabs, single-use syringes, short procedural instruments
ProlongedMore than 24 hours, up to 30 days totalWound dressings changed over several weeks, indwelling catheters (short-term), orthodontic devices
Long-term / PermanentMore than 30 days totalImplants, permanent orthopedic hardware, long-term catheters

The category itself hasn’t moved. What changed is how you calculate “total contact” for a device that isn’t used in one continuous stretch — and that recalculation is where most categorization errors happen.

If you are evaluating a device used in short, repeated sessions → don’t categorize based on a single session length. The standard expects you to sum all contact time across the device’s full use pattern before assigning a category.

Daily Contact vs. Intermittent Contact

Comparison infographic explaining daily contact and intermittent contact under ISO 10993-1:2025 for biological evaluation of medical devices.
ISO 10993-1:2025 distinguishes between daily and intermittent contact when determining cumulative exposure for biological evaluation.

ISO 10993-1:2025 formalizes two exposure patterns that the 2018 edition handled inconsistently:

  • Daily contact — the device touches the body every day, for any portion of a day, across a defined treatment course. Total exposure is counted as calendar days from first use to last use (or replacement) on a single patient.
  • Intermittent contact — use with at least 24 hours between consecutive contacts. This is treated as repeated use of the same device, or a replacement device, under evaluation.

A wound contact layer changed daily over three weeks is the textbook example: under the 2018 edition, each dressing change might have been assessed as its own “limited” exposure. Under the current standard, the 21 cumulative contact days push the device into prolonged territory — and that shift can add endpoints your original evaluation never considered.

If you are re-evaluating a device that was cleared under the 2018 categorization logic → don’t assume your existing category still holds. Run the total exposure period calculation against the current definitions before you finalize anything for a new submission.

Reusable Devices and Total Exposure Period

Reusable devices are now categorized based on cumulative contact time for a single patient across the device’s full use pattern — not the duration of any one use, and not a multi-patient device service-life total. A reusable surgical instrument sterilized and reused across a procedure series looks brief per individual contact, but the relevant figure is how many total contact days that one patient accumulates across their treatment course, including reasonably foreseeable misuse such as use beyond the labeled reprocessing cycle count.

Bioaccumulation is a related but less settled consideration. FDA’s Supplementary Information Sheet for ISO 10993-1:2025 (Recognition No. 2-313) notes that ISO/TC 194 Working Group 1 is still developing technical reports specifically addressing bioaccumulation, intermittent contact, and reasonably foreseeable misuse. In practice: if chemical characterization data — extractables and leachables — raises a bioaccumulation concern, that finding should inform your risk assessment and may support escalating the device’s category, but document it as a risk-based judgment rather than treating it as a fixed clause requirement until the supporting technical reports are finalized.

For teams managing this inside a certified QMS, it’s a judgment call that needs to trace back to a documented decision — not a verbal risk call made in a meeting. Clause 9 of ISO 10993-1:2025 requires that biological evaluations be planned, conducted, and reported by competent personnel, with the evaluation report documenting the rationale behind risk decisions like this one. The CAPA requirements under ISO 13485 apply just as much to a categorization correction as to a nonconformance on the shop floor.

Flowchart explaining cumulative single-patient exposure for reusable medical devices under ISO 10993-1:2025.
Reusable medical devices are categorized using cumulative single-patient exposure rather than the duration of a single procedure.

Mapping Contact Category to Biological Endpoints

The biological effects under consideration haven’t fundamentally changed — cytotoxicity, sensitization, irritation, systemic toxicity, genotoxicity, implantation effects, and hemocompatibility remain the backbone, and ISO 10993-1 remains a risk-based framework, not a mandatory testing checklist. What changed is the scope of consideration required, particularly for genotoxicity:

Contact DurationBody ContactGenotoxicity Consideration
LimitedAnyCase-by-case, per risk assessment
ProlongedAll tissues except intact skinGenerally expected to be addressed per Tables 2–4 and Clause 6.5.7
Long-term / PermanentAll tissues except intact skinGenerally expected to be addressed per Tables 2–4 and Clause 6.5.7

Under the 2018 edition, genotoxicity was consistently expected for implants and long-term tissue contact, but inconsistently applied to prolonged-contact devices touching mucosal membranes or breached surfaces. ISO 10993-1:2025 narrows that inconsistency: per Tables 2–4 and Clause 6.5.7, any device requiring systemic toxicity evaluation due to prolonged or long-term contact is now generally expected to address genotoxicity as well, intact skin excepted — though this remains a risk assessment expectation to be justified within your Biological Evaluation Plan, not an automatic in vivo test order. Where existing data (toxicological risk assessment under ISO 10993-17, chemical characterization, or literature) already addresses the risk adequately, testing may not be necessary. Carcinogenicity consideration was similarly extended for long-term contact with intact mucosal membranes.

Worth flagging directly: FDA’s Supplementary Information Sheet for ISO 10993-1:2025 (Recognition No. 2-313) identifies a genuine discrepancy here. ISO 10993-1:2025 lists genotoxicity as an endpoint for consideration across all prolonged-contact device categories, while FDA’s own Table A.1 (Attachment A of its 2023 Biocompatibility Guidance) limits the genotoxicity endpoint to implanted devices, externally communicating devices with tissue/bone/dentin contact, and externally communicating devices with circulating blood contact. For a U.S. submission, don’t assume the broader ISO scope automatically controls — confirm which framework your reviewer expects you to follow.

Most common finding: biological evaluation plans for prolonged-contact mucosal devices that address systemic toxicity but don’t document a genotoxicity rationale one way or the other — an omission that was easier to overlook under the 2018 matrix and is more likely to draw a question under the current one.

If your device’s evaluation also touches sterilization residuals, review our sterilization standards overview — ethylene oxide and other sterilization residues are a recurring driver of chemical characterization findings that reshape a biological evaluation.

FDA’s Partial Recognition — What’s Excluded

FDA recognized ISO 10993-1:2025 on May 25, 2026 (Recognition No. 2-313 in FDA’s Recognized Consensus Standards database), but the recognition is partial, not full. Two carve-outs from the Supplementary Information Sheet matter for submission strategy:

  • The phrase “consumer products or” in Clause 6.5.11.3 (Low Risk Intact Skin Contacting Medical Devices) is not recognized — FDA states it conflicts with Attachment G of its 2023 biocompatibility guidance, which limits which historical-use materials qualify for reduced testing on skin-contacting devices.
  • Clause 6.9, Biological risk estimation, is not recognized — FDA holds it conflicts with the risk estimation approach already established under ISO 14971:2019, which FDA separately recognizes.

If you are preparing a 510(k), PMA, or De Novo submission → you cannot submit a full Declaration of Conformity without addressing these two exclusions directly, and the genotoxicity discrepancy above is a separate, related point worth raising with your reviewer proactively. Cite the standard, but demonstrate compliance for the excluded clauses through FDA’s existing biocompatibility guidance rather than assuming automatic alignment. FDA’s recognized standard entry and Supplementary Information Sheet have already been updated since publication — verify the current version directly against FDA’s Recognized Consensus Standards database before finalizing any submission.

For the broader shift this represents in medical device documentation expectations, see our breakdown of validation and verification requirements under ISO 13485 and the FDA QMSR.

Common Categorization Mistakes

Infographic highlighting common ISO 10993 biological evaluation and contact duration categorization mistakes for medical device manufacturers.
Many ISO 10993 audit findings result from incorrect categorization logic or incomplete biological evaluation documentation rather than testing failures.

⚠️ Categorizing by single-use duration instead of cumulative single-patient exposure. The single most common error on reusable and repeat-use devices — it understates the contact category more often than it overstates it.

⚠️ Citing “Table A.1” in a current BEP. A reference to the old table structure is a documentation red flag on its own, independent of whether the underlying science holds up.

⚠️ Assuming genotoxicity doesn’t need to be addressed for prolonged mucosal contact. Teams working from older templates default to a 2018-era endpoint list and skip documenting a rationale either way — under the current tables, that gap is more likely to draw a question.

⚠️ Assuming FDA recognition is full, or that ISO and FDA genotoxicity scope match. Building a submission strategy around blanket alignment, without addressing the excluded clauses and the genotoxicity scope discrepancy, invites an avoidable deficiency letter.

If you are unsure whether existing biological evaluation plans need revisiting → they don’t automatically require retesting, but ISO 10993-1:2025 does expect a documented review confirming prior categorization and endpoint rationale still hold under current definitions.


Quick Audit Checklist

✅ Contact duration category calculated from cumulative single-patient exposure, not single-use duration
✅ Reusable/repeat-use devices assessed for total contact days for one patient across their treatment course
✅ Genotoxicity rationale documented for prolonged/long-term contact except intact skin, per Tables 2–4 and Clause 6.5.7
✅ Biological Evaluation Plan references current ISO 10993-1:2025 structure, not legacy Table A.1
✅ FDA submission strategy accounts for the two partially-recognized clauses and the genotoxicity scope discrepancy
✅ Bioaccumulation signals from chemical characterization data reviewed and documented as a risk judgment, not assumed to require automatic escalation ✅ Existing (pre-2025) biological evaluations documented as reviewed against current definitions


FAQ

Does ISO 10993-1:2025 require me to retest devices already on the market?

No. The standard doesn’t mandate automatic retesting for devices with an acceptable safety history. It does expect a documented review confirming prior categorization and evaluation still hold, and an update if a Clause 10 production change triggers a re-review.

Is ISO 10993-1:2018 still valid to use?

FDA’s recognized standards database is the authority for U.S. submissions — verify current recognition status before relying on either edition. For new evaluation plans, aligning with the 2025 edition is the safer long-term position.

What’s the difference between “prolonged” and “long-term” contact?

Prolonged contact covers cumulative contact exceeding 24 hours but not exceeding 30 days. Long-term (permanent) contact covers cumulative contact exceeding 30 days, driven by total exposure period rather than packaging or labeling.

Does the 2025 edition apply to devices regulated under the EU MDR?

It’s generally treated as state of the art for MDR purposes, but grace periods and notified body expectations vary — confirm directly with your notified body.

Is genotoxicity testing now mandatory for every prolonged-contact device?

Not automatically. Per Tables 2–4 and Clause 6.5.7, genotoxicity is generally expected to be addressed through risk assessment for prolonged and long-term contact with all tissues except intact skin — but “addressed” can mean justified through existing toxicological or chemical characterization data, not necessarily new in vivo testing. Note also that FDA’s own Table A.1 applies genotoxicity more narrowly than ISO does, so confirm which framework governs your specific submission.

Do I need a new Biological Evaluation Plan for every device?

No blanket requirement to start over. Most manufacturers can update an existing BEP to reflect current categorization logic and endpoint scope, provided the underlying risk assessment and chemical characterization data are still valid.

How does ISO 14971 relate to my biological evaluation?

ISO 10993-1:2025 is now more tightly embedded in the ISO 14971 risk management process. See our guide on risk management in medical devices under ISO 14971 for how that framework applies.

Where do I buy the current edition of ISO 10993-1?

Through an authorized reseller such as the ANSI Webstore, which also serves international buyers and offers standards in multiple languages. ISO 10993-1:2025 — ANSI Webstore — Coupon code CC2026 applies through December 31, 2026.


📥 Free Resources

  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts
  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements

Not Sure What to Do Next?

🔹 Still researching how the current standard applies to your device? Read our Biocompatibility Standards Overview for the full picture before you build a test matrix.

🔹 Ready to build or update your Biological Evaluation Plan? Download the ISO 13485 Gap Assessment Checklist and confirm your documentation controls support the categorization decisions you’re about to make.

🔹 Need to purchase the current standard? ISO 10993-1:2025 — ANSI Webstore — code CC2026 takes 5% off, and international buyers can access the standard in multiple languages through the same source.


The Standard Changed. Your Categorization Logic Should Too.

Table A.1 was a shortcut, and shortcuts age out. ISO 10993-1:2025 asks for a defensible, risk-based answer instead of a checked box — and that’s a better position to defend in front of a reviewer regardless of which edition your notified body is citing this quarter. The Standards Navigator will keep tracking how FDA recognition and international adoption evolve as this transition plays out.


Don’t Let a Reviewer Find the Gap First

Most biological evaluation gaps don’t get caught in your own review — they get caught by a notified body auditor or an FDA reviewer, months after the plan was finalized. Manufacturers who treat contact duration categorization as a one-time exercise tend to carry that risk forward through every product change. Manufacturers who build a documented, repeatable categorization process into their QMS catch the drift before it becomes a submission delay.

The Standards Navigator tracks ISO 10993, ISO 13485, and the broader medical device compliance landscape as it evolves — including regulatory recognition changes like FDA’s partial recognition of ISO 10993-1:2025.

👉 Get updates on medical device biocompatibility and QMS requirements
👉 Be first to access new gap assessment tools and implementation resources

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

Biocompatibility Standards Explained: ISO 10993 Requirements for Medical Devices in 2026

This guide breaks down the ISO 10993 series and the sixth edition of ISO 10993-1, published in November 2025. It covers FDA’s partial recognition of the new edition in May 2026, the two clauses the agency excluded, and whether manufacturers need to revisit biological evaluation plans for devices already cleared.

What ISO 10993-1:2025 and FDA’s Partial Recognition Mean for Your Biological Evaluation Plan

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Standard Behind Your Biocompatibility Testing Just Changed — Is Your Documentation Still Defensible?

Biocompatibility standards for medical devices just changed in a way regulatory affairs teams can’t ignore. If your device has any contact with the human body, your biological evaluation plan rests on one standard: ISO 10993-1. For years, that meant the 2018 edition. That’s no longer the whole story.

ISO published a sixth edition, ISO 10993-1:2025, in November 2025. The FDA followed with recognition of that edition on May 25, 2026 — but only partial recognition. Two specific clauses were excluded outright. If your technical documentation, supplier certificates, or biological evaluation reports still cite the 2018 edition without addressing what changed, that’s a gap a reviewer or auditor will find.

This isn’t a cosmetic update. The reorganization ties biocompatibility more tightly to ISO 14971 risk management, and the FDA’s exclusions tell you exactly where the agency still wants you to lean on its own biocompatibility guidance instead of the standard’s language. This guide covers the current medical device biocompatibility testing requirements under both editions, what changed, and what FDA’s recognition decision actually means for your Biological Evaluation Plan (BEP).

I’ve been on the reviewing side of this problem before, just from the documentation control angle. As an ISO 9001 internal auditor, I’ve flagged design history files where a supplier’s certificate of conformance still referenced an outdated edition of a cited standard — the technical content hadn’t changed, but the paper trail no longer matched what the standard actually required. That’s the kind of finding that stalls a submission or an audit closeout, and it’s entirely avoidable if someone catches the edition mismatch before a reviewer does.

Before you touch a single test report, run a gap check on where your current documentation stands against the 2025 edition.

👉 Most teams don’t fail because their biocompatibility data is wrong — they fail because their documentation still points to the wrong edition of the standard. Run the ISO 13485 Gap Assessment Checklist before your next submission or audit →


In This Guide

  • What ISO 10993-1 covers and why it sits at the center of biocompatibility evaluation
  • The full ISO 10993 series, part by part
  • What actually changed in the 2025 edition
  • FDA’s partial recognition — and exactly what it excluded
  • Whether you need to retest devices already cleared under the 2018 edition
  • How biocompatibility documentation fits into your ISO 13485 QMS
  • A quick audit checklist for your next document review


👉 Start Here (Top Resources)


What Is Biocompatibility, and Why ISO 10993 Matters

Biocompatibility is the assessment of whether a device’s materials — and the way those materials contact the body — create an unacceptable biological risk. ISO 10993-1 is the standard that governs how you plan, justify, and document that biocompatibility risk assessment. It doesn’t hand you a checklist of tests to run blindly; it requires you to build a risk-based Biological Evaluation Plan (BEP) that considers the device’s materials, manufacturing processes, intended anatomical contact, and exposure duration.

That risk-based framing matters because it’s the same language FDA reviewers and notified bodies expect to see. A BEP that reads like a 2009-era test list, rather than a risk justification tied to ISO 14971, is a common source of review questions and additional information requests.

If you’re still building out your risk management process, our guide on risk management in medical devices under ISO 14971 covers the foundation ISO 10993-1 now leans on even more heavily than before.


The ISO 10993 Series at a Glance

Infographic showing the ISO 10993 series for biological evaluation of medical devices, including ISO 10993-1, -5, -6, -7, -10, -12, -17, and -18.
The ISO 10993 series consists of multiple standards that together form a complete biological evaluation framework for medical devices.

ISO 10993-1 doesn’t stand alone — it’s the framework document for a series that covers specific test methods and evaluation categories.

PartCoversStatus Note
ISO 10993-1Overall evaluation and testing within a risk management processSixth edition (2025) now partially recognized by FDA
ISO 10993-5In vitro cytotoxicity2009 edition, still current
ISO 10993-6Local effects after implantationUpdated 2026 edition
ISO 10993-7Ethylene oxide sterilization residualsUpdated 2026 edition
ISO 10993-10Irritation and skin sensitization2021 edition
ISO 10993-12Sample preparation and reference materials2021 edition, amended 2025
ISO 10993-17Toxicological risk assessment of device constituents2023 edition, amended 2025
ISO 10993-18Chemical characterization of materials2020 edition, amended 2022

Most common finding: Manufacturers cite ISO 10993-5 or -10 correctly but leave the ISO 10993-1 reference in their design history file pointing to the 2018 edition without any documented rationale for why. If your BEP hasn’t been revisited since the 2025 edition published, that’s the first thing to check.

If your device is sterilized and you haven’t looked at how the 2026 edition of ISO 10993-7 interacts with your sterilization validation, our sterilization standards overview walks through ISO 11135, 11137, 17665, and 11607 alongside it.


What Changed in ISO 10993-1:2025

The sixth edition isn’t a light refresh. ISO’s technical committee reorganized the standard and changed its title to explicitly align with the ISO 14971 risk management framework. The practical changes:

  • More detailed guidance on calculating exposure duration — including how to treat foreseeable misuse, such as a device used longer than its labeled duration.
  • Expanded guidance on device characterization and biological hazard identification, intended to reduce reliance on generic test batteries.
  • Terminology aligned with ISO 14971, so if your team already knows that standard, the 2025 edition should read more consistently — though NAMSA and other industry commentators note there isn’t yet a technical report equivalent to ISO/TR 24971 to guide interpretation of the new edition.

Here’s how the two editions compare on the points that matter most for your Biological Evaluation Plan:

Topic2018 Edition2025 Edition
Risk Management IntegrationReferenced ISO 14971More explicitly aligned throughout
Exposure DurationLimited guidanceExpanded methodology for calculating duration, including foreseeable misuse
Biological Hazard IdentificationLess detailedExpanded guidance on device characterization and hazard identification
Risk EstimationDifferent treatmentNew Clause 6.9 (excluded by FDA)

If you are preparing a Biological Evaluation Plan for a new device → start by confirming which edition your FDA reviewer or notified body expects to see referenced, since adoption isn’t uniform across regions. The EU has generally moved faster toward treating the 2025 edition as state of the art. Manufacturers should verify current adoption expectations directly with their notified body and applicable competent authorities, since implementation timing varies and is subject to change.

One shift worth flagging for regulatory teams building out a modern BEP: chemical characterization under ISO 10993-18 is playing a larger role than it used to. Rather than defaulting to a blanket biological test matrix for every device, more manufacturers are leaning on thorough chemical characterization data — extractables and leachables profiles, material composition analysis — to justify a narrower, risk-based testing strategy. ISO 10993-1:2025’s expanded hazard identification guidance reinforces this shift. A well-documented ISO 10993-18 characterization can reduce redundant biological testing, but only if the chemistry-driven rationale is documented clearly enough to withstand a reviewer’s scrutiny.

Comparison graphic showing the major differences between ISO 10993-1:2018 and ISO 10993-1:2025 for biological evaluation of medical devices.
The 2025 edition places greater emphasis on risk management integration, biological hazard identification, and exposure assessment.

ISO 10993 FDA Recognition: What’s Excluded and Why

🔑 Key FDA Takeaway FDA recognizes ISO 10993-1:2025, but excludes:

  • The “consumer products” language in Clause 6.5.11.3
  • Clause 6.9 on biological risk estimation

Manufacturers should document alternative justification using FDA guidance and ISO 14971.

On May 25, 2026, FDA updated its Recognized Consensus Standards database (Recognition No. 2-313) to include ISO 10993-1:2025 — but not in full. Two specific exclusions matter for your submissions:

  1. The phrase “consumer products or” in Clause 6.5.11.3. This clause addresses low-risk, intact-skin-contacting devices. The standard allows manufacturers to point to a material’s history of safe use in consumer products as justification for reduced testing. FDA excluded this because it conflicts with Attachment G of its 2023 biocompatibility guidance, which defines specific materials with an accepted history of use — a consumer product history alone doesn’t automatically satisfy FDA’s expectations.
  2. Clause 6.9 on biological risk estimation. FDA determined this clause conflicts with the risk estimation approach already established in the FDA-recognized ISO 14971:2019. Sponsors can’t rely on Clause 6.9 to claim conformity in a submission.

If you are under customer or notified body pressure to update your BEP quickly → prioritize reviewing these two clauses first. They’re the specific areas where citing the 2025 edition alone won’t satisfy FDA, and you’ll need to document your justification through existing FDA guidance instead.

Partial recognition means you cannot submit a clean Declaration of Conformity to the full 2025 edition. Your submission documentation needs to call out the partial recognition explicitly and show how you’re addressing the excluded clauses — silence on this point is what generates additional information requests.

Workflow illustrating FDA partial recognition of ISO 10993-1:2025 and the documentation required for excluded clauses during medical device submissions.
FDA recognizes ISO 10993-1:2025 with specific exclusions, requiring manufacturers to document alternative regulatory justifications.

Do You Need to Retest Already-Cleared Devices?

This is the objection I hear most from teams looking at this update: does a new edition mean I have to redo my biocompatibility testing on devices that already have clearance?

No — not automatically. FDA’s recognition of a newer edition doesn’t retroactively invalidate data or clearances based on the 2018 edition. If you already hold clearance under the 2018 edition → you don’t need to retest existing devices. What you do need is a documented rationale, at your next design change or periodic review, for why your BEP still reflects sound risk management even though a newer edition exists. That’s a documentation and justification exercise, not a lab exercise.

Where this becomes a live issue is new submissions and significant design changes going forward — those are where reviewers will expect to see the current edition addressed.


Where Biocompatibility Fits Into Your ISO 13485 QMS

Biocompatibility data doesn’t live in isolation — it’s part of your design and development file under ISO 13485, and it feeds directly into your risk management file under ISO 14971. If your ISO 13485 documentation structure doesn’t have a clear place for biological evaluation plans, reports, and the rationale behind edition changes, that’s a gap worth closing before your next internal audit — not after a nonconformance is written.

This also connects to supplier controls. If a component supplier’s certificate of conformance references ISO 10993-1 by edition, your incoming inspection and supplier qualification process needs a mechanism to catch when that reference goes stale — the same principle covered in our guide on common mistakes in ISO 13485 QMS implementation.

And if you’re managing devices sold in both the US and EU, the edition-adoption gap between FDA and the EU regulatory framework is one more reason to keep your MDR vs ISO 13485 documentation aligned rather than treating them as separate tracks.

👉 If your biological evaluation documentation hasn’t been reviewed since the 2025 edition published, don’t wait for a finding to tell you. Check where your QMS documentation actually stands →


Quick Audit Checklist

✅ Confirm which edition of ISO 10993-1 your current BEP references, and whether that matches what your reviewer or notified body expects
✅ Check whether your device’s biocompatibility justification relies on Clause 6.5.11.3 (consumer product history) or Clause 6.9 (risk estimation) — both need alternative justification for FDA submissions
✅ Verify supplier certificates of conformance cite current standard editions, not stale references
✅ Confirm your risk management file cross-references your BEP consistently ✅ If your device is sterilized, check the 2026 editions of ISO 10993-6 and -7 against your current validation data ⚠️ Don’t assume “FDA recognized” means “fully accepted” — verify the Supplementary Information Sheet for any standard before citing it as a full Declaration of Conformity


FAQ

What is biocompatibility testing for medical devices?

Biocompatibility testing evaluates whether the materials in a medical device, and the way those materials contact the body, could cause an unacceptable biological response. It covers areas like cytotoxicity, sensitization, irritation, and systemic toxicity, selected based on the device’s contact type and duration.

What is ISO 10993-1, and do I need to comply with it?

ISO 10993-1 is the framework standard that governs how you plan and justify a biological evaluation within a risk management process. If your device contacts the body directly or indirectly, FDA and most global regulators expect your biocompatibility strategy to follow its structure, even where full conformity isn’t feasible.

What changed between ISO 10993-1:2018 and ISO 10993-1:2025?

The 2025 edition reorganized the standard to align more closely with ISO 14971, added detailed guidance on calculating exposure duration and identifying biological hazards, and updated terminology throughout.

Has the FDA recognized ISO 10993-1:2025?

Yes, as of May 25, 2026, but only partially. FDA excluded the “consumer products” language in Clause 6.5.11.3 and all of Clause 6.9 on biological risk estimation, both of which conflict with existing FDA guidance and the FDA-recognized ISO 14971:2019.

Do I need to retest devices already cleared under the 2018 edition?

No. Existing clearances aren’t invalidated by a newer edition. You do need a documented rationale for your current approach at your next design change or periodic review.

Which parts of the ISO 10993 series apply to my device?

That depends on your device’s contact type (surface, external communicating, or implant) and contact duration (limited, prolonged, or permanent). ISO 10993-1 provides the matrix for selecting relevant parts of the series based on those two factors. We’ll be covering that contact-duration matrix in detail in an upcoming guide.

Is ISO 10993 the same as ISO 13485?

No. ISO 13485 governs your overall quality management system for medical devices. ISO 10993 is a series specifically about biological evaluation, and its outputs — your BEP and test reports — become part of the design and development records your ISO 13485 QMS requires you to maintain.

Where do I purchase ISO 10993 standards?

Individual parts and bundled packages are available through the ANSI Webstore, which also serves international buyers and offers documents in multiple languages. The ISO.org catalog describes each part but is not the recommended purchase channel.


📥 Free Resources

  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.
  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements, including where biocompatibility documentation fits.
  • AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification.

Not Sure What to Do Next?

🔹 Still researching how the 2025 edition affects your device category? Start with our breakdown of risk management under ISO 14971 — biocompatibility evaluation doesn’t stand apart from it anymore.

🔹 Ready to check where your documentation actually stands? Run the ISO 13485 Gap Assessment Checklist before your next audit or submission, not after.

🔹 Need to purchase the current standard? ISO 10993-1:2025 — ANSI Webstore, or get the full biological evaluation package bundled at roughly 45% off individual pricing if you’re assembling multiple parts of the series. Use code CC2026 for an additional 5% off through December 31, 2026.

The Standards Navigator will keep tracking how FDA recognition evolves on this standard as updates are published.


Documentation Gaps Don’t Show Up Until Someone’s Looking For Them

Teams that treat biocompatibility as a one-time lab exercise are the ones caught off guard when a standard’s edition changes underneath them. Teams that treat it as a living part of their design and risk management file catch the mismatch at their next internal review, not during an FDA question round — and it’s usually a citation that didn’t keep up, not the underlying science, that stalls a submission.

The Standards Navigator tracks these regulatory shifts as they happen — not months later when the transition deadline is already close. If ISO 10993-1:2025 affects your device, this is a good window to revisit your documentation rationale while the timeline is still in your control.

👉 Get updates on medical device compliance and biocompatibility standard changes
👉 Be first to access new gap assessment checklists and documentation tools for ISO 13485 and ISO 14971

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

ISO 15223 Symbols Overview: What Every Medical Device Label Actually Means (2026 Guide)

ISO 15223-1:2021 governs the pictograms on every medical device label. This guide breaks down the seven symbol categories, key reference symbols, and the 2026 EU REP amendment — including exact transition deadlines under MDR and IVDR.

A regulatory affairs guide to the pictograms your labels are required to carry — and the 2026 EU REP symbol change you need to track

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.

This article is for general informational purposes and is not regulatory advice. Manufacturers should verify symbol requirements against the current version of ISO 15223-1 and applicable regulatory guidance.


ISO 15223-1:2021 is the internationally recognized standard that defines symbols used on medical device labels, packaging, and accompanying information to communicate critical safety and regulatory information without language-specific text.


The ISO 15223 Symbols That Trigger a Labeling Recall

A single wrong pictogram on a device label isn’t a cosmetic problem. It’s a labeling nonconformance that can hold up a shipment, trigger a Notified Body finding, or in the worst case, force a recall.

ISO 15223-1:2021 is the standard behind nearly every symbol on a medical device label — manufacturer, batch code, sterile, use-by date, and dozens more. It’s not optional guidance. It’s the harmonized reference regulatory affairs teams are expected to follow for CE marking label symbols, and it just changed in a way that affects almost every CE-marked device on the market.

From the floor: I’ve reviewed label proofs where a well-meaning graphics team swapped in an old sterilization icon because it “looked close enough” to what the previous product used. It wasn’t the same symbol, and it wasn’t accompanied by the batch reference the standard requires next to it. Having reviewed manufacturing and quality documentation across multiple industrial environments, I’ve repeatedly seen labeling errors originate not from misunderstanding the requirements, but from uncontrolled template reuse. That kind of small mismatch is exactly what a label review process is supposed to catch before it reaches a Notified Body’s desk — not after.

👉 Before your next label revision goes to print, confirm every symbol still matches current guidance. Most labeling nonconformances aren’t due to unfamiliarity with the standard — they’re due to reusing an old label file without checking what changed. Get the ISO 13485 Gap Assessment Checklist and confirm your revision management process is catching this before a reviewer does.


In This Guide

  • What ISO 15223-1:2021 actually covers and why it’s harmonized under MDR/IVDR
  • The seven symbol categories and what each one communicates
  • The 2026 EU REP symbol change — what changed, when, and what it means for your labels
  • Common labeling mistakes that surface in document reviews
  • FAQ


👉 Start Here


What Is ISO 15223-1:2021?

ISO 15223-1:2021, Medical devices — Symbols to be used with information to be supplied by the manufacturer — Part 1: General requirements, is now in its fourth edition. It defines the standardized pictograms manufacturers use on labels, packaging, and accompanying documentation so a device can be understood across languages and markets without translation.

It was harmonized under both EU MDR and EU IVDR in January 2022 — one of a relatively small number of standards to hold that status — which means using it correctly carries a presumption of conformity with the corresponding MDR/IVDR labeling requirements. A companion standard, ISO 15223-2, covers how new symbols get developed, selected, and validated when nothing in the existing library fits.

Because ISO 15223-1 is harmonized under MDR and IVDR, proper symbol usage can support a manufacturer’s demonstration of conformity with labeling requirements. In practice, auditors and Notified Bodies routinely review symbol usage as part of labeling assessments — this isn’t a peripheral checklist item, it’s one of the more commonly reviewed elements of a technical file.


Why Manufacturers Use Symbols

Medical devices are distributed across multiple countries and languages. Standardized symbols reduce the need for translated label text while helping manufacturers meet labeling requirements consistently across global markets. A single symbol library means the same pictogram carries the same meaning whether a device ships to Germany, Japan, or Brazil — without a separate translated label for each market.


ISO 15223-1 Medical Device Symbols Explained

ISO 15223-1 organizes its medical device label symbols into seven functional groups:

  • Manufacturing — manufacturer identity, date of manufacture, country of manufacture
  • Storage — temperature limits, humidity limits, keep dry, keep away from sunlight
  • Safe use — single use, do not use if damaged, consult instructions for use
  • Sterility — sterile, sterilization method, do not resterilize
  • IVD-specific — symbols unique to in vitro diagnostic devices
  • Transfusion/infusion — symbols for blood and infusion-related devices
  • Other — symbols that don’t fit cleanly into the categories above but are still standardized

Every symbol in the standard comes with a defined title, a description of what it communicates, and any accompanying information it must be paired with — a batch code symbol without an actual batch number next to it isn’t a valid use of the symbol.


Most Common ISO 15223-1 Medical Device Symbols

Infographic illustrating the most common ISO 15223 symbols for  medical device labeling, including manufacturer, LOT, REF, serial number, sterile, use-by date, consult instructions for use, and keep dry.
The most frequently used ISO 15223-1 symbols help communicate critical manufacturing, traceability, sterility, and safety information on medical device labels worldwide.

The following symbols represent some of the most commonly encountered markings in medical device labeling. This is not a complete list, but these symbols appear on a significant percentage of devices entering regulated markets.

Symbol TitleClauseWhat It Communicates
Manufacturer5.1.1Identifies the legal manufacturer; name and address must accompany it
Date of manufacture5.1.3The date the device was produced
Use-by date5.1.4The date after which the device should not be used
Batch code (LOT)5.1.5Identifies the manufacturing batch or lot
Catalogue number (REF)5.1.6The manufacturer’s catalogue/model number
Serial number (SN)5.1.7Identifies a specific individual device
Importer5.1.8Identifies the entity importing the device into a given market
Sterile5.2.1Device has been through a sterilization process
Do not resterilizeDevice is not to be resterilized after use
Do not use if package damagedConsult instructions for use if packaging integrity is compromised
Single useDevice is intended for one use only

This is a reference sample, not the full symbol library — the standard runs well beyond these. For the complete set of ISO 15223 symbol meanings, always validate current symbol usage against the live ISO document rather than a saved reference sheet, since amendments do get issued.


The 2026 EU REP Symbol Change

The most consequential update to this standard in years just took effect. Amendment EN ISO 15223-1:2021/A1:2025 replaces the long-standing “EC REP” symbol for a medical device’s authorized representative in the EU with a new “EU REP” symbol, and introduces a generic “XX REP” framework where “XX” is swapped for the applicable country or jurisdiction code.

The change was requested by the European Commission in May 2024, specifically to eliminate confusion between “EC” as a regulatory abbreviation and “EC” as the ISO 3166-1 country code for Ecuador. ISO adopted the amendment in March 2025, and it was formally harmonized into the Official Journal of the European Union on June 17, 2026, through Commission Implementing Decision (EU) 2026/1231 (amending MDR-side Decision 2021/1182) and Commission Implementing Decision (EU) 2026/1313 (amending IVDR-side Decision 2021/1195).

The European Commission has been explicit that this is a purely editorial change — it does not alter the authorized representative symbol’s role, responsibilities, or the device’s safety or performance profile in any way. This amendment is now one of the more consequential updates among the current round of MDR harmonized standards, given how widely the symbol appears across the CE-marked device population.

Timeline infographic illustrating the transition from the EC REP symbol to the EU REP symbol under ISO 15223-1:2021 Amendment A1:2025, including key regulatory milestones through 2031.
The transition from EC REP to EU REP includes a five-year coexistence period, allowing manufacturers to update labeling during normal revision cycles before the 2031 deadline.

👉 Planning an upcoming label revision? Download the ISO 13485 Gap Assessment Checklist to verify your revision management process is capturing changes to standards before they become audit findings.


Do You Need to Update Your Labels Right Now?

The most common objection: “Do we need to reprint every label immediately?”

No. The Commission built in a five-year coexistence period. Manufacturers may continue using the legacy “EC REP” symbol under the original EN ISO 15223-1:2021, or transition to the new “EU REP” symbol under the amendment — both are valid during this window. The old standard’s reference isn’t withdrawn until June 15, 2031 under MDR and June 17, 2031 under IVDR. After those dates, only “EU REP” confers presumption of conformity.

In practice, this means:

  • If you are about to run a new label print or design revision anyway → use the new EU REP symbol now rather than reprinting again later.
  • If your current labels are compliant and not due for revision → there is no requirement to act immediately; plan the change into your next scheduled label update.
  • If you have a Notified Body conformity review coming up → confirm with them directly whether they expect the new symbol in your current submission, since individual Notified Body expectations can vary during a transition window.

Common ISO 15223 Labeling Nonconformances

Most common finding: inconsistent symbol usage across packaging levels — the outer carton uses one version of the authorized representative symbol while the inner unit label uses another, with no documented rationale for the difference.

Other recurring issues: sterilization method symbols that don’t match the actual method used (ethylene oxide vs. irradiation vs. steam each has a distinct symbol); batch code or serial number symbols placed on a label without the actual batch or serial data adjacent to them; and reused label templates that carry forward a superseded symbol simply because nobody flagged the amendment during change control review.

⚠️ None of these mistakes require a new symbol library to fix — they require a label governance process that actually checks current symbol validity before a label goes to print, not just before the first label was ever approved.


Quick Reference Checklist

Professional infographic showing a medical device label review checklist based on ISO 15223-1, including symbol verification, sterilization validation, traceability, packaging consistency, and revision control.
A structured label review process helps manufacturers verify ISO 15223-1 symbol compliance before medical devices move into production or distribution.

✅ Current label set reviewed against the live ISO 15223-1:2021 symbol library ✅ Sterilization method symbol matches the actual method used
✅ Batch code, catalogue number, and serial number symbols paired with real data
✅ EU REP transition plan documented, even if no immediate label change is required
✅ Packaging levels (outer carton, inner unit, IFU) checked for symbol consistency
✅ Change control process flags standard amendments, not just initial approvals


FAQ

What is ISO 15223-1:2021?

It’s the international standard defining the pictograms used on medical device labels, packaging, and accompanying information — covering everything from manufacturer identity to sterilization method. It’s currently in its fourth edition and harmonized under both EU MDR and IVDR.

Do I have to switch to the EU REP symbol immediately?

No. The European Commission built in a five-year coexistence period. The legacy EC REP symbol remains valid until the original standard’s reference is withdrawn — June 15, 2031 under MDR and June 17, 2031 under IVDR.

Is the EU REP change a safety-related update?

No. The Commission has described it as a purely editorial change, made to eliminate confusion with Ecuador’s ISO 3166-1 country code. It does not change the authorized representative’s role or responsibilities.

What’s the difference between ISO 15223-1 and ISO 15223-2?

Part 1 defines the actual symbol library and how symbols must be used. Part 2 covers the process for developing, selecting, and validating a new symbol when nothing in the existing library fits a specific need.

Does every medical device need every symbol in the standard?

No. Which symbols apply depends on the device — a non-sterile reusable device won’t carry sterilization symbols, for example. The standard defines what each symbol means and how to use it correctly; it doesn’t mandate that every device carry every symbol.

What’s the most common labeling mistake regulatory teams miss?

Inconsistent symbol usage across packaging levels — using an updated symbol on one layer of packaging while an older version persists on another, usually because a label template wasn’t fully reviewed during a revision.

Where can I find the actual symbol library?

ISO 15223-1:2021 and its companion ISO 15223-2 are both available for purchase through ANSI Webstore, either individually or as a combined package.

Should my Notified Body confirm which symbol version they expect?

During the transition period, manufacturers should confirm expectations directly with their Notified Body, particularly if a labeling review or conformity assessment is already underway.


📥 Free Resources

  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements, including the revision management processes that keep labeling current.
  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system from the ground up.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements across production environments.

Not Sure What to Do Next?

🔹 Still researching how labeling symbols fit into your broader QMS? Start with ISO 13485 Documentation Requirements and Common Mistakes in ISO 13485 QMS to see where document control connects to labeling accuracy.

🔹 Ready to review your current label set? Check it against Sterilization Standards Overview and UDI Requirements Explained — both cover label-adjacent requirements that pair directly with ISO 15223-1 symbols.

🔹 Need to purchase the standard itself? Get the ISO 15223 Symbols Package from ANSI Webstore — available individually or bundled with Part 2, with code CC2026 for 5% off through December 31, 2026.


Symbols look like a small detail until one of them is wrong on a printed label already in circulation. The Standards Navigator will keep tracking the EU REP transition and any further ISO 15223 amendments as they’re published.

Don’t Let a Symbol Be the Reason for a Finding

Labeling nonconformances are some of the most avoidable findings in a Notified Body review — the standard is published, the symbols are defined, and the fix is almost always a revision management gap rather than a technical one.

The Standards Navigator tracks ISO 15223 amendments, MDR/IVDR labeling requirements, and medical device documentation standards so your labels don’t fall out of step with a standard that changed while nobody was watching.

👉 Get updates on ISO 15223, MDR/IVDR labeling changes, and medical device documentation requirements as they happen
👉 Be first to access new gap assessment tools built for medical device regulatory affairs teams

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

MDR vs. ISO 13485: What’s the Difference and Which One Do You Actually Need in 2026?

EU MDR and ISO 13485 solve different problems — one is law, the other is a certifiable QMS standard. This guide breaks down the core differences, current 2026–2027 MDR transition timelines, and a decision framework for regulatory affairs teams navigating both.

A regulatory affairs guide to two rules that get confused constantly — and cost time when they are

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Question That Stalls Every EU Market Entry Meeting

Somewhere in almost every medical device compliance kickoff, someone asks it: “We already have ISO 13485. Doesn’t that cover MDR?”

It doesn’t. And the gap between MDR vs ISO 13485 — a certified quality management system and an EU-compliant technical file — is where CE marking timelines quietly slip by six to twelve months.

MDR (Regulation (EU) 2017/745) and ISO 13485 aren’t competing standards. They aren’t interchangeable either. One is EU law. The other is a voluntary international standard that EU law happens to lean on heavily. Confusing the two doesn’t just cost time — it costs Notified Body findings, delayed submissions, and in some cases, a device that can’t legally reach the European market on schedule.

From the floor: I’ve sat in a management review where a director insisted the ISO 13485 certificate meant the technical documentation was “basically done” for an EU submission. It wasn’t. The certificate covered their quality system — design controls, CAPA, document control. It said nothing about the clinical evaluation report, MDR classification requirements, or the device-specific evidence required for conformity assessment. They spent the next quarter closing that gap instead of reviewing it calmly six months earlier. That’s the exact mistake this article exists to prevent.

👉 Before you assume your QMS certification covers your EU submission, run the gap check. Most regulatory affairs teams don’t fail because they misunderstand ISO 13485 — they fail because they assumed certification and market access were the same milestone. Get the ISO 13485 Gap Assessment Checklist and find out before a Notified Body does.

In This Guide

  • What EU MDR 2017/745 actually regulates
  • What ISO 13485 actually certifies
  • The core differences, side by side
  • Why “ISO 13485 certified” doesn’t mean “MDR compliant”
  • Where the two genuinely overlap — risk management, CAPA, design controls, and more
  • Current MDR transition timelines and 2026 developments
  • Which one you need — and when you need both
  • Common documentation mistakes that surface in Notified Body reviews
  • FAQ

Table of Contents

  1. What Is EU MDR 2017/745?
  2. What Is ISO 13485?
  3. MDR vs. ISO 13485: Core Differences
  4. Why Manufacturers Conflate the Two
  5. Where MDR and ISO 13485 Overlap
  6. MDR Transition Timelines: Where Things Stand in 2026
  7. Do You Need Both? A Decision Framework
  8. Common Mistakes That Surface in Notified Body Review
  9. Quick Reference Checklist
  10. FAQ

👉 Start Here


What Is EU MDR 2017/745?

MDR is law, not a certifiable management system standard. Regulation (EU) 2017/745 governs what a manufacturer must prove — about a specific device — before that device can carry a CE mark and legally reach the EU market.

It covers device classification (Class I through III), clinical evaluation and clinical data requirements, technical documentation per Annexes II and III, post-market surveillance and post-market clinical follow-up (PMCF), Unique Device Identification (UDI) and EUDAMED registration, and — for higher-risk devices — Notified Body conformity assessment under Annex IX.

MDR replaced the older Medical Device Directive (MDD) and Active Implantable Medical Devices Directive (AIMDD), and it raised the bar substantially on clinical evidence and post-market obligations compared to both.

What Is ISO 13485?

ISO 13485 is a voluntary, internationally recognized quality management system standard for organizations involved in the design, production, or servicing of medical devices. It’s certifiable — a Notified Body or accredited certification body audits your QMS against the standard’s clauses and issues a certificate if you pass.

ISO 13485 uses maintaining effectiveness language throughout, not the continual improvement language found in ISO 9001. It’s structured around risk-based thinking applied specifically to design controls, document and record control, supplier controls, CAPA, and management review — the operational backbone a device manufacturer needs regardless of which market it sells into.

Since FDA’s QMSR took effect February 2, 2026, 21 CFR Part 820 incorporates ISO 13485:2016 by reference — making it the enforceable quality management system standard for U.S. device manufacturers, not merely a reference point.

MDR vs. ISO 13485: Core Differences

CategoryEU MDR 2017/745ISO 13485
NatureEU law — mandatory for CE markingVoluntary international standard
ScopeDevice-specific: classification, clinical evidence, technical fileOrganization-wide: the QMS itself
Who assesses itNotified Body (device-level conformity assessment)Certification body (QMS audit)
Grants market access?Yes — required for CE marking in the EUNo — supports it, doesn’t grant it
Geographic reachEU/EEA market onlyRecognized globally; now foundational to FDA QMSR
What it producesTechnical documentation, CER, PMS/PMCF plan, EUDAMED registrationA certificate covering your quality management system
Update cycleAmended by EU legislative process (ongoing 2025–2027 reform)Revised through ISO’s standard TC 210 process
Professional infographic comparing EU MDR 2017/745 and ISO 13485:2016, highlighting differences in regulatory requirements, quality management systems, CE marking, clinical evaluation, and technical documentation for medical device manufacturers.
This infographic compares EU MDR and ISO 13485, illustrating how one governs market access while the other establishes the quality management system that supports regulatory compliance.

Quick Answer:

  • Need CE marking? → MDR is required.
  • Need a compliant medical device QMS? → ISO 13485 is required.
  • Selling medical devices in the EU? → You almost certainly need both.

The stakes behind that table are real: the European Commission’s most recent Notified Bodies survey, published March 2026, showed roughly half of submitted MDR applications had reached certificate issuance — a gap driven largely by device misclassification, incomplete technical documentation, and thin clinical evidence, not by Notified Body capacity alone.


Why Manufacturers Conflate the Two

The most common objection I hear: “We’re ISO 13485 certified — why do we need a separate MDR effort?”

Here’s the resolution: ISO 13485 certification tells a Notified Body your quality system is sound. It says nothing about whether a specific device’s clinical evidence, risk classification, or technical file meets MDR’s requirements. A company can hold a spotless ISO 13485 certificate and still receive a Notified Body finding on a device submission because the clinical evaluation report was thin, the PMCF plan was missing, or the classification rule was misapplied under Annex VIII.

Think of it this way: ISO 13485 certifies the kitchen is clean and the process is controlled. MDR conformity assessment asks whether this specific dish meets the recipe, the nutrition label is accurate, and there’s a plan to keep checking it after it ships. You need both, but they answer different questions.

👉 If you are relying on your ISO 13485 certificate as your MDR readiness proof, that’s the gap to close first. Run the ISO 13485 Gap Assessment Checklist against your current technical files before your next Notified Body interaction.

Where MDR and ISO 13485 Overlap

Venn diagram infographic showing where EU MDR 2017/745 and ISO 13485:2016 overlap, highlighting shared quality management processes including risk management, design controls, CAPA, complaint handling, and supplier controls for medical device manufacturers.
This infographic illustrates the operational areas shared by EU MDR and ISO 13485 while distinguishing the unique regulatory and quality management requirements of each framework.

If they’re really two separate things, why does everyone talk about them in the same breath? Because the same five operational areas show up in both — just assessed from different angles.

  • Risk management — MDR requires risk management per Annex I general safety and performance requirements; ISO 13485 Clause 4.1.2 requires a risk-based approach throughout the QMS. Most manufacturers run one risk management process (typically ISO 14971-aligned) that satisfies both.
  • CAPA — ISO 13485 Clause 8.5 governs corrective and preventive action as a QMS requirement. MDR’s post-market surveillance and vigilance obligations feed directly into that same CAPA process when a field issue is identified.
  • Design controls — ISO 13485 Clause 7.3 sets design and development requirements; MDR’s technical documentation under Annex II leans on those same design records as evidence of a controlled development process.
  • Supplier controls — ISO 13485 Clause 7.4 requires supplier evaluation and monitoring; MDR expects that same supplier oversight to extend into the technical file wherever a supplier-controlled process affects device safety or performance.
  • Complaint handling — ISO 13485 Clause 8.2.2 sets complaint-handling requirements; MDR’s vigilance reporting obligations under Article 87 depend on that same complaint intake process to catch reportable events.

This is the practical reason ISO 13485 certification and MDR technical documentation feel like the same conversation even though they’re legally distinct: a well-run QMS produces most of the raw material an MDR technical file needs. The gap is rarely in these five areas — it’s in whether that raw material gets assembled into a device-specific technical file the way MDR expects.

MDR Transition Timelines: Where Things Stand in 2026

The transition provisions have shifted more than once since MDR took effect in May 2021, and manufacturers still working under legacy MDD or AIMDD certificates need to track the current deadlines carefully:

  • Class III custom-made implantable devices: compliance required by May 26, 2026
  • Class III and certain implantable Class IIb devices: transition extends to December 31, 2027
  • Most other Class IIb, IIa, and Class I devices: transition extends to December 31, 2028

Legacy device status under these extended timelines requires a valid MDD/AIMDD certificate, no significant design or intended-use change, continued compliance with the original directive, and a signed agreement with an MDR-designated Notified Body.

Separately, the European Commission published a proposal on December 16, 2025 to simplify and reduce administrative burden under both MDR and its IVDR counterpart — including changes to PRRC availability requirements and certificate validity limits. That proposal is still moving through the EU’s ordinary legislative process, and current projections put final adoption no earlier than the second quarter of 2027. Nothing in that proposal changes your obligations today. Manufacturers should keep building technical documentation to the current MDR text rather than waiting on a reform that hasn’t been adopted.

Timeline infographic showing the EU MDR transition deadlines for legacy medical devices in 2026, 2027, and 2028, along with ongoing requirements for technical documentation, clinical evaluation, post-market surveillance, and Notified Body agreements.
This timeline summarizes the current EU MDR transition deadlines for legacy medical devices while highlighting the ongoing compliance activities manufacturers must maintain throughout the transition period.

Do You Need Both? A Decision Framework

  • If you are selling into the EU market → MDR compliance is mandatory, full stop. ISO 13485 certification is not legally required by MDR text, but in practice Notified Bodies expect it as evidence your QMS can sustain the technical file over time.
  • If you are U.S.-only and not yet EU-bound → FDA’s QMSR incorporates ISO 13485:2016 by reference into 21 CFR Part 820, making alignment with ISO 13485 the foundation of U.S. medical device QMS compliance as of February 2, 2026. Third-party certification isn’t mandated by FDA, but the standard’s substance now is.
  • If you are already ISO 13485 certified and expanding into the EU → treat MDR as a device-level project layered on top of your existing QMS, not a QMS rebuild. The gap is almost always in clinical evidence and technical documentation, not in your quality processes.
  • If you are under customer or investor pressure to move fast → get the ISO 13485 gap assessment done first. It surfaces documentation gaps in days instead of finding them mid-audit.

Common Mistakes That Surface in Notified Body Review

Most common finding: Clinical evaluation reports that summarize literature but never tie evidence back to the specific device’s risk profile under Annex I general safety and performance requirements.

Other recurring gaps: PMCF plans that exist as a template but were never executed against real post-market data; UDI and EUDAMED registration treated as an afterthought instead of a parallel workstream; and design change records that don’t clearly show which MDR classification rule applied after a design modification.

⚠️ A Notified Body finding on any of these doesn’t necessarily mean your ISO 13485 QMS has failed — it usually means the QMS and the MDR technical file were built as two separate projects instead of one connected effort.

Quick Reference Checklist

✅ ISO 13485 certificate current and audit-ready
✅ Technical documentation mapped to current MDR Annex II/III requirements ✅ Clinical evaluation report tied to device-specific risk profile
✅ PMCF plan active and generating real post-market data
✅ UDI assigned and EUDAMED registration current
✅ Notified Body agreement in place if relying on legacy transition timelines
✅ Design change records show which classification rule applies post-modification


FAQ

Does ISO 13485 certification satisfy MDR requirements?

No. ISO 13485 certifies your quality management system. MDR requires separate, device-specific technical documentation, clinical evidence, and — for most devices — Notified Body conformity assessment. Certification supports MDR compliance; it doesn’t substitute for it.

Is ISO 13485 mandatory for the EU market?

MDR text doesn’t explicitly mandate ISO 13485 certification, but in practice, Notified Bodies expect a certified QMS as part of demonstrating your ability to sustain compliance. Most manufacturers pursuing MDR conformity hold ISO 13485 certification for this reason.

Do U.S.-only manufacturers need to worry about MDR?

Not directly, unless you plan to sell into the EU. However, FDA’s QMSR — effective February 2, 2026 — makes ISO 13485:2016 the operative U.S. regulation, so ISO 13485 alignment now matters regardless of whether MDR applies to you.

What’s the current MDR transition deadline for legacy devices?

It depends on device classification: Class III custom-made implantables faced a May 26, 2026 deadline, Class III and certain implantable Class IIb devices extend to December 31, 2027, and most other devices extend to December 31, 2028 — provided legacy status conditions are met.

Is the EU actually changing MDR requirements soon?

The European Commission proposed simplification changes on December 16, 2025, but the proposal is still in the EU legislative process, with final adoption not expected before the second quarter of 2027. Current MDR requirements remain fully in effect in the meantime.

What’s the biggest documentation gap Notified Bodies flag?

Clinical evaluation reports that summarize literature broadly without tying the evidence directly to the specific device’s risk profile under the general safety and performance requirements.

Can one gap assessment cover both ISO 13485 certification readiness and MDR technical file readiness?

A well-structured gap assessment should flag both, but they’re different reviews at their core — one audits your QMS against ISO 13485 clauses, the other audits your technical documentation against MDR annexes. Treat them as connected but distinct workstreams.

Where should a manufacturer start if pursuing both?

Start with the QMS. A certified, functioning ISO 13485 system gives you the document control, CAPA, and design control infrastructure that MDR technical documentation depends on. Building MDR documentation on top of a shaky QMS just relocates the problem.


📥 Free Resources

  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements before certification or a Notified Body review.
  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system from the ground up.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements across production environments.

Not Sure What to Do Next?

🔹 Still researching the difference between MDR and ISO 13485? Start with What Is ISO 13485? and FDA QSR vs. ISO 13485 to ground the fundamentals before your next planning meeting.

🔹 Ready to close the documentation gap? Review ISO 13485 Documentation Requirements and Validation & Verification Requirements against your current technical files.

🔹 Need to purchase the standard itself? Get ISO 13485:2016 directly from ANSI Webstore — available internationally, with multi-language editions for global regulatory teams. Use code CC2026 for 5% off through December 31, 2026.


MDR and ISO 13485 solve different problems, and treating them as one project is how audit-ready timelines slip by a quarter or more. The Standards Navigator will keep tracking both as EU reform proposals and FDA QMSR guidance continue to evolve through 2026 and 2027.

Stop Guessing Where Your MDR Gap Actually Is

Regulatory teams that treat MDR and ISO 13485 as one combined project usually discover the gap during a Notified Body review — the worst possible time to find it. Teams that separate the two, and check each on its own terms, walk into that review with documentation that already matches what’s being asked.

The Standards Navigator tracks EU MDR developments, FDA QMSR alignment, and ISO 13485 implementation detail so medical device teams aren’t relying on outdated guidance six months into a submission.

👉 Get updates on MDR, ISO 13485, and medical device regulatory changes as they happen
👉 Be first to access new gap assessment tools and documentation resources for regulatory affairs teams

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.





Sterilization Standards Overview: ISO 11135, 11137, 17665, and 11607 Explained (2026 Guide)

This guide breaks down the four core sterilization standards governing medical devices — ISO 11135 (EtO), ISO 11137 (radiation), ISO 17665 (moist heat), and ISO 11607 (packaging). It covers validation requirements, Sterility Assurance Level, contract sterilizer responsibility, and the most common findings auditors cite in sterilization validation files.

What ISO Actually Requires for EtO, Radiation, Steam, and Sterile Packaging Validation

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Your Sterilization Validation File Is the First Thing an Auditor Opens

A device that isn’t sterile doesn’t ship. That’s the entire premise behind four ISO sterilization standards most regulatory affairs teams only fully understand after a finding forces them to.

ISO 11135 governs ethylene oxide (EtO) sterilization. ISO 11137 governs radiation sterilization (gamma, e-beam, X-ray). ISO 17665 governs moist heat (steam). ISO 11607 governs the sterile barrier packaging that has to keep the device sterile until someone opens it. Supporting all four is ISO 11737, which governs bioburden determination and the sterility test methods used to validate and verify each method. None of them are optional if you’re claiming “STERILE” on a label, and under ISO 13485 and the FDA’s Quality Management System Regulation (QMSR), your device history record has to show a validated process behind that claim — not a one-time test result.

If you’re still building out your quality management system, our ISO 13485 Implementation Roadmap covers where sterilization validation fits into the broader QMS build. If you already have a QMS and are trying to close a specific gap, keep reading.

I’ve reviewed process validation files during ISO 9001 internal audits where the finding wasn’t that the process failed — it was that nobody could produce the record proving why the acceptance criteria were set the way they were. While I haven’t personally validated a sterilization process, I’ve evaluated documentation, traceability, and process validation evidence like this as part of broader QMS audits, and the pattern holds across every process type: auditors don’t just want a passing result, they want the rationale that came before it. Miss that documentation trail and it doesn’t matter how many lots passed — the finding still lands.

Most teams miss this step — check your sterilization documentation against the full standard before your next audit →


In This Guide

  • The four core sterilization method standards and what each one actually requires
  • How ISO 11607 packaging validation fits alongside method validation
  • Sterility Assurance Level (SAL) and why 10⁻⁶ is the number that matters
  • Contract sterilizer relationships — who’s responsible for what
  • Common audit findings in sterilization validation files
  • How these standards connect to ISO 13485, ISO 14971, and the FDA QMSR


👉 Start Here (Top Resources)


Why Sterilization Standards Sit Inside Your QMS

Sterilization validation isn’t a standalone technical exercise — it’s a QMS output. ISO 13485 Clause 7.5.7 specifically requires validation of sterilization processes before routine use. The FDA’s Quality Management System Regulation (QMSR), effective February 2, 2026, makes ISO 13485:2016 the core requirement set for device manufacturers marketing in the U.S., with a defined set of FDA-specific additions layered on top — it’s not a loose reference to “many” of the standard’s requirements, it’s the operative regulation. That means your sterilization validation protocol, your acceptance criteria, and your revalidation schedule all have to trace back into your document control and CAPA systems — the same systems we covered in ISO 13485 Documentation Requirements and CAPA Requirements in ISO 13485.

If you are still finalizing your core QMS documentation → get the sterilization validation SOP structure right before you run your first qualification batch. Retrofitting documentation after the fact is where most rework happens.


The Standards Aren’t Interchangeable

Infographic comparing ISO 11135, ISO 11137, ISO 17665, and ISO 11607, showing the appropriate sterilization method, typical applications, and validation focus for medical devices.
Compare the four primary medical device sterilization standards and see when each ISO standard applies based on the sterilization method and validation requirements.

One of the biggest misconceptions in this space is that manufacturers can choose whichever sterilization standard fits their production schedule best. In reality, the applicable standard is dictated by the sterilization modality itself — not preference. ISO 11135 cannot substitute for ISO 11137, and neither one replaces the packaging validation requirements in ISO 11607. Method selection is a design and materials decision made early in development, and it determines which standard — and which validation pathway — applies for the life of the product.

Real-world example: a disposable syringe is commonly validated under ISO 11137 using gamma or e-beam radiation, while the sterile barrier system around it is separately validated under ISO 11607. An orthopedic power drill with onboard electronics, by contrast, often can’t tolerate radiation dose without degrading — which is why EtO validation under ISO 11135 becomes the practical path, even though it carries a longer aeration and residual-testing burden than radiation would.

StandardCoversValidation FocusTypical Products
ISO 11135Ethylene oxide (EtO)Gas cycle validationElectronics, plastics, mixed-material assemblies
ISO 11137Radiation (gamma / e-beam / X-ray)Dose validationDisposable, polymer-based devices
ISO 17665Moist heat (steam)Temperature/pressure qualificationReusable surgical instruments
ISO 11607Sterile packagingSeal & sterile barrier validationAll terminally sterilized devices

ISO 11135: Ethylene Oxide Sterilization

ISO 11135 covers development, validation, and routine control of EtO sterilization — the most common method for devices with mixed materials, electronics, or complex geometries that can’t tolerate radiation or heat.

The standard requires:

  • Process definition — establishing gas concentration, temperature, humidity, and exposure time that reliably achieves the target sterility assurance level
  • Installation and performance qualification — proving the chamber and load configuration actually deliver the defined process
  • Routine monitoring — biological indicators and process parameter records for every production cycle
  • EtO residual testing — confirming aeration reduces residual gas and byproducts to acceptable levels before release

Watch-outs specific to EtO: aeration time, residual limits, and material compatibility all need documented justification, not just a passing result. If you need the current edition for your validation team, ISO 11135:2014 is available through ANSI Webstore.


ISO 11137: Radiation Sterilization

ISO 11137 covers gamma, electron beam, and X-ray sterilization in three parts: requirements (Part 1), dose setting (Part 2), and dose auditing (Part 3). Radiation is common for single-use, polymer-based disposables produced at volume.

ElementWhat It CoversWhy It Matters in an Audit
Dose settingEstablishing the minimum dose that achieves the target SAL (e.g., VDmax or Method 1 approaches)Auditors want to see the substantiation data, not just the final dose
Dose auditingOngoing verification that the substantiated dose remains effective as product or process changes occurA missed dose audit is a common nonconformance
Material compatibilityPolymer aging, discoloration, and embrittlement risk at the selected doseTies directly into design verification records

If you are switching from gamma to e-beam or X-ray for the same product → you need new dose substantiation data. The modality change is not a paperwork formality. ISO 11137:2025 is the current edition covering dose-setting and dose-auditing requirements.


ISO 17665: Moist Heat Sterilization

ISO 17665 covers steam sterilization — pressurized saturated steam, typically 121°C to 134°C. It remains the preferred method for reusable surgical instruments and devices that tolerate heat and moisture, largely because it’s simple, fast, and doesn’t carry the residual or dose-substantiation burden that EtO and radiation do.

Validation under ISO 17665 centers on physical qualification (proving the autoclave load reaches and holds temperature throughout) paired with biological indicator challenge testing. The standard also requires routine control — meaning every production cycle needs monitored, recorded parameters, not just periodic spot checks. ISO 17665:2024 is the current edition.


ISO 11607: Sterile Packaging

Sterilization validation doesn’t end when the device comes out of the chamber. ISO 11607 — in two parts — governs the sterile barrier system that has to maintain sterility through distribution, storage, and shelf life until the point of use.

Part 1 covers materials, sterile barrier system design, and preformed barrier requirements. Part 2 covers validation of the forming, sealing, and assembly processes used to create that barrier. A device can pass every sterilization requirement in ISO 11135, 11137, or 17665 and still fail on the market if the package seal isn’t validated to hold sterility through the labeled shelf life.

Packaging validation goes well beyond confirming a seal exists. A complete ISO 11607 validation file typically includes seal integrity testing, burst testing, dye penetration testing, and peel strength testing to confirm the barrier holds under mechanical stress — plus transit simulation testing (ASTM D4169 is the common reference standard) to prove the package survives real-world distribution handling, and accelerated aging studies to substantiate the labeled shelf life before real-time aging data exists. Skipping any one of these doesn’t just create an audit finding — it creates a product that may not actually stay sterile on the shelf.

Most common finding: manufacturers validate the sterilization cycle thoroughly but treat packaging validation as an afterthought — seal strength testing without the accompanying shelf-life and transit simulation data auditors expect to see referenced together. ISO 11607:2019 covers both parts of the packaging validation requirement.


Sterility Assurance Level: The 10⁻⁶ Standard

Infographic illustrating the medical device sterilization validation workflow from product design and risk assessment through bioburden testing, process validation, packaging validation, Sterility Assurance Level (SAL), routine monitoring, and periodic revalidation.
Follow the complete sterilization validation workflow, from initial product design through routine monitoring and revalidation, to maintain ISO 13485 and FDA QMSR compliance.

Every one of these standards is built around the same target: a Sterility Assurance Level of 10⁻⁶, meaning no more than a one-in-a-million probability that a viable microorganism survives the sterilization process. SAL isn’t a claim you assert — it’s a number you prove through bioburden testing, biological indicator challenges, and the validation approach specified in the relevant method standard.

This is where ISO 11737 (microbiological methods) connects in. Bioburden testing under ISO 11737-1 establishes your starting point; the sterility test methods in ISO 11737-2 support validation and ongoing verification. If you haven’t mapped your bioburden data into your sterilization validation protocol, that’s a gap worth closing before your next surveillance audit.


Using a Contract Sterilizer Doesn’t Transfer the Risk

The most common objection we hear: “We use a contract sterilizer — isn’t this their responsibility?”

No. Under ISO 13485’s supplier control requirements — covered in detail in Supplier Controls for Medical Devices — the device manufacturer retains ultimate responsibility for the validated state of the sterilization process, even when a contract sterilizer physically performs it. Your quality agreement with that sterilizer needs to define who owns revalidation triggers, who reviews dose audit data, and who gets notified of process deviations. An FDA or notified body auditor will ask you these questions directly — “we outsource it” is not an acceptable answer.


Common Findings in Sterilization Validation Files

Infographic highlighting the five most common sterilization validation audit findings, including dose substantiation, packaging validation, EtO aeration and residual data, revalidation triggers, and contract sterilizer oversight.
Discover the five sterilization validation issues auditors most frequently identify during ISO 13485 and FDA QMSR assessments of medical device manufacturers.
  • Missing or incomplete dose substantiation rationale (radiation)
  • Aeration and residual data not linked to the specific product configuration tested (EtO)
  • Packaging validation treated as separate from — rather than integrated with — sterilization validation
  • Revalidation not triggered after a documented process, material, or supplier change
  • Contract sterilizer quality agreements that don’t specify deviation notification requirements

Common Sterilization Myths

  • Sterile packaging isn’t optional. It’s a validated element of the sterilization claim, not a shipping convenience.
  • Contract sterilizers don’t assume regulatory responsibility. The device manufacturer does, regardless of who runs the cycle.
  • Passing one validation run doesn’t eliminate revalidation requirements. Process, material, or supplier changes reset the clock.
  • SAL isn’t measured by a single sterility test. It’s established through bioburden data, biological indicator challenges, and the validation approach specified in the method standard — not one passing sample.

Quick Audit Checklist

  • ✅ Process definition and qualification records on file for the sterilization method used
  • ✅ Dose substantiation and dose audit data current (radiation only)
  • ✅ Residual and aeration data linked to product-specific testing (EtO only)
  • ✅ Packaging validation (ISO 11607-1 and -2) referenced alongside sterilization validation
  • ✅ Bioburden data mapped to SAL 10⁻⁶ justification
  • ✅ Contract sterilizer quality agreement defines revalidation and deviation ownership
  • ⚠️ Revalidation schedule reviewed after any process, material, or supplier change

Not sure your current documentation would hold up? Run it against the ISO 13485 Gap Assessment Checklist before your next scheduled audit →


FAQ

What’s the difference between ISO 11135 and ISO 11137?

ISO 11135 governs ethylene oxide (EtO) sterilization, a gas-based low-temperature method suited to mixed-material and electronic devices. ISO 11137 governs radiation sterilization — gamma, e-beam, and X-ray — typically used for high-volume, polymer-based disposables. They require different validation approaches: dose substantiation for radiation, and gas concentration/exposure/aeration qualification for EtO.

Does ISO 17665 apply to reusable devices?

Yes. ISO 17665 covers moist heat (steam) sterilization, which is the most common method for reusable surgical instruments and devices that tolerate heat and moisture without degradation.

Is ISO 11607 required if I use a contract packaging supplier?

Yes. ISO 11607 validation requirements apply regardless of whether packaging design and sealing are performed in-house or by a contract supplier. The device manufacturer is responsible for confirming that validation data exists and is current for the specific packaging configuration used.

What is Sterility Assurance Level (SAL) and why is 10⁻⁶ the target?

SAL is the probability that a single viable microorganism survives a sterilization process. A SAL of 10⁻⁶ means no more than a one-in-a-million chance — the internationally recognized benchmark for terminally sterilized medical devices across ISO 11135, 11137, and 17665.

Do I need to revalidate if I switch contract sterilizers?

In most cases, yes. A change in sterilizer, chamber configuration, or load pattern can affect cycle parameters even when the method and standard stay the same. Revalidation requirements should be defined in your change control procedure, not decided case by case.

How does ISO 14971 relate to sterilization validation?

ISO 14971 risk management informs the acceptance criteria and failure mode analysis behind your sterilization validation protocol — particularly for identifying what happens if sterility assurance isn’t achieved. See our breakdown in Risk Management in Medical Devices for how the two standards connect.

Does the FDA QMSR require anything beyond ISO 13485 for sterilization?

The QMSR incorporates ISO 13485 by reference, so the core sterilization validation requirement flows through Clause 7.5.7. FDA also maintains a Recognized Consensus Standards database mapping specific editions of ISO 11135, 11137, 17665, and related standards — always confirm current recognition status before citing a specific edition in a submission.

What’s the most common reason sterilization validation fails an audit?

Missing documentation trail — not process failure. Auditors most often cite an inability to produce the rationale behind acceptance criteria, dose substantiation, or revalidation triggers, even when every routine monitoring record shows a passing result.


Not Sure What to Do Next?

🔹 Still researching your sterilization pathway? Read What Is ISO 13485? to see how sterilization validation fits into the full QMS picture.

🔹 Ready to close documentation gaps before your next audit? BSI Group’s ISO 13485 training walks through the clauses that govern sterilization validation records.

🔹 Need the actual standard text for your validation team? If you’re purchasing more than one, the ANSI Webstore Medical Device Packages bundle covers ISO 13485, ISO 14971, and the sterilization standards together — often at a lower combined cost than buying each individually.


📥 Free Resources


The Documentation Trail Is the Real Deliverable

Sterilization validation isn’t a lab exercise you complete once and file away — it’s a living record your QMS has to maintain across every process, material, and supplier change. Get the documentation structure right the first time, and the biological indicator result becomes the easy part. The Standards Navigator will keep tracking updates to ISO 11135, 11137, 17665, and 11607 as FDA recognition status evolves, so you’re not caught citing a superseded edition.

📬 Stay Ahead of Your Next Sterilization Audit

Most sterilization validation findings don’t come from a failed cycle — they come from a documentation trail an auditor can’t follow six months later. Manufacturers who treat sterilization validation as a one-time project end up scrambling before every surveillance audit; the ones who build revalidation triggers into their change control process rarely get surprised.

The Standards Navigator tracks sterilization, packaging, and QMS standard updates specifically for medical device manufacturers navigating ISO 13485 and the FDA QMSR.

👉 Get updates on sterilization and medical device compliance standards 👉 Be first to access new ISO 13485 gap assessment tools and checklists

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

Validation & Verification Requirements: What ISO 13485 and the New FDA QMSR Actually Demand (2026 Guide)

ISO 13485 Clause 7.3 requires distinct verification and validation evidence — and the FDA’s new QMSR, effective February 2, 2026, makes the distinction matter more than ever. This guide breaks down design verification, design validation, process validation, and software validation requirements, and shows manufacturers how to build a traceability matrix that survives an audit or inspection.

ISO 13485 verification and validation requirements explained for medical device manufacturers navigating the QMSR transition

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Documentation Gap That Fails Design History Files

A design verification report that confirms the device meets its own specifications is not the same thing as a validation report that confirms the device meets the user’s actual needs. Auditors know the difference. Regulatory affairs teams sometimes don’t find out until an FDA inspector or notified body assessor pulls the Design History File and asks for both — and only one exists.

That gap has gotten more consequential, not less. The FDA’s Quality Management System Regulation took effect February 2, 2026, formally incorporating ISO 13485:2016 into 21 CFR Part 820 by reference. Verification and validation records that used to satisfy QSR expectations are now being evaluated against ISO 13485 Clause 7.3 directly — and the two frameworks don’t document V&V identically.

From the Floor: As a certified ISO 9001 Internal Auditor, I’ve sat across the table from teams who could produce a stack of test reports but couldn’t answer a simple question: which of these prove the design meets the specification, and which prove it meets the user’s need? Verification and validation get treated as interchangeable paperwork until an auditor separates them — and by then it’s a finding, not a conversation. The QMS documentation discipline that catches this before an audit is the same discipline that catches it before a submission.

If your last internal audit didn’t clearly separate verification evidence from validation evidence, that’s the gap worth closing first.

Run a clause-by-clause gap check before your next surveillance audit or FDA inspection — the ISO 13485 Gap Assessment Checklist below is built for exactly this kind of documentation review. Most teams miss the verification/validation split until it’s flagged.

👉 ISO 13485 Gap Assessment Checklist


In This Guide

  • What verification and validation mean under ISO 13485 Clause 7.3, and why they are not interchangeable
  • How process validation (Clause 7.5.6) differs from design validation
  • Software validation requirements for devices and manufacturing/QMS software
  • What changed under the FDA QMSR effective February 2, 2026
  • The most common V&V documentation failures found in audits and inspections
  • How to structure a verification and validation plan that survives scrutiny


👉 Start Here (Top Resources)

If you’re building or auditing a verification and validation process, these are the two resources worth starting with:


Verification vs. Validation: The Core Distinction

Comparison infographic explaining the differences between ISO 13485 verification and validation requirements under ISO 13485:2016, including design inputs, intended use, testing methods, timing, applicable clauses, and common audit findings.
This comparison illustrates how verification and validation serve different purposes under ISO 13485 and why both are required for compliant medical device design controls.

Verification confirms that design outputs meet design inputs. Validation confirms that the finished device meets user needs and intended use. That one-sentence distinction is where most documentation failures start, because the two activities can look procedurally similar — testing, measuring, comparing results against criteria — while answering completely different questions.

ElementDesign VerificationDesign Validation
Question answeredDid we build the design correctly?Did we build the correct design?
Compared againstDesign inputs / specificationsUser needs / intended use
Typical methodsBench testing, inspection, analysis, comparison to similar designsClinical evaluation, simulated use testing, human factors studies
TimingThroughout design and developmentUnder defined operating conditions, on initial production units or equivalent
ISO 13485 clause7.3.67.3.7
Common failureTesting against internal spec only, no traceability to inputValidating on prototypes instead of production-equivalent units

Most common finding: auditors and FDA investigators repeatedly cite validation performed on non-representative units — bench prototypes, early builds, or units built on equipment that doesn’t match production. ISO 13485 Clause 7.3.7 specifically requires validation on production or production-equivalent units, under defined operating conditions.


Verification and Validation in Practice: An Infusion Pump Example

Take a manufacturer developing an infusion pump. Design verification confirms the device meets its own engineering specifications:

  • ✅ Flow rate accuracy within the specified tolerance
  • ✅ Battery life meets the stated runtime under load
  • ✅ Alarm volume meets the decibel specification

Design validation confirms something different — that the device works safely in the hands of the people who will actually use it:

  • ✅ Nurses can operate the pump correctly and safely during simulated or actual clinical use
  • ✅ The alarm is audible and distinguishable in a realistic hospital environment, not a quiet test lab
  • ✅ Labeling and instructions for use are understood by the intended users without additional training

A pump can pass every verification test and still fail validation — accurate flow rate and long battery life mean nothing if a nurse under time pressure misreads the alarm or misinterprets the instructions. That’s the gap Clause 7.3.7 is built to catch, and it’s why validation has to happen on production-equivalent units under conditions that resemble actual use.


Design Verification Requirements

Clause 7.3.6 requires that design verification confirms outputs meet input requirements, with results and conclusions recorded, including the methods, dates, and individuals performing the verification. In practice, that means every design input needs a traceable verification activity — not a general statement that “the device was tested.”

If you are building a Design History File from scratch → start with a traceability matrix that maps every design input to its verification method and result before writing a single test protocol. Retrofitting traceability after testing is where most rework happens.

If you are already ISO 9001 certified and adding ISO 13485 → your existing design control process likely covers verification structurally, but it almost certainly lacks the input-to-output traceability rigor ISO 13485 auditors expect. That’s the gap to close first, not the documentation format.

👉 Before You Build Another Test Protocol

Most verification failures aren’t testing failures — they’re traceability failures. Run your design inputs against your current verification records now and find the gaps before an assessor does. →


Design Validation Requirements

Design validation under Clause 7.3.7 must be performed on production or production-equivalent units, under defined operating conditions, and must include risk analysis where applicable — which is where ISO 14971 risk management intersects directly with design controls. Validation isn’t complete until it addresses actual clinical or user-environment conditions, not lab conditions that approximate them.

Objection: “Our device is low-risk — do we really need formal simulated-use validation?” Even Class I and low-risk Class II devices need validation evidence proportional to risk, and “proportional” still means documented, traceable, and tied to intended use. A shorter validation plan is defensible. No validation plan is not.

Clinical evaluation, when required, and human factors/usability testing both fall under validation, not verification — a distinction that matters for regulatory submissions referencing FDA guidance on human factors engineering.


Process Validation Under Clause 7.5.6

Infographic explaining the three phases of process validation under ISO 13485, including Installation Qualification (IQ), Operational Qualification (OQ), and Performance Qualification (PQ), with key activities, outputs, and compliance requirements.
This infographic explains the roles of IQ, OQ, and PQ in process validation, helping manufacturers understand how each qualification stage supports ISO 13485 and FDA QMSR compliance.

Separate from design validation, ISO 13485 Clause 7.5.6 requires validation of processes where the resulting output cannot be verified by subsequent monitoring or measurement — sterilization, certain sealing and bonding processes, injection molding parameters, and software used in production are the classic examples.

Process validation requires:

  • ✅ Defined criteria for review and approval of the process
  • ✅ Approval of equipment and qualification of personnel
  • ✅ Use of specific methods, procedures, and acceptance criteria
  • ✅ Requirements for records (Clause 4.2.5)
  • ✅ Revalidation criteria, including criteria for triggering revalidation

Most auditors and FDA investigators expect this evidence structured around three stages: Installation Qualification (IQ), Operational Qualification (OQ), and Performance Qualification (PQ).

Installation Qualification (IQ) confirms that equipment and supporting systems are installed correctly, according to the manufacturer’s specifications and the site’s own installation requirements — including verified utilities, calibration status, and documentation of the as-installed configuration, not just a checklist that the equipment arrived and was plugged in.

Operational Qualification (OQ) confirms that the equipment operates as intended across its full specified operating range, not just at a single nominal setting. For a sterilization process, that means testing at the upper and lower bounds of temperature, time, and pressure defined in the process specification — not only the target parameters.

Performance Qualification (PQ) confirms that the process consistently produces conforming output under actual production conditions, typically across multiple runs and, where risk warrants it, multiple operators, shifts, or lots. PQ is where most revalidation triggers get defined, since it establishes the baseline the process must continue to meet.

If you are validating a sterilization or bonding process for the first time → build your IQ/OQ/PQ protocol before ordering test units. Retrofitting an IQ after OQ testing has already started is a common finding, and it undermines the traceability an assessor is looking for.

If your process hasn’t changed but your equipment or facility has → IQ typically needs to be repeated even when OQ and PQ parameters stay the same, since IQ is tied to the specific installation, not the process design.

Skipping straight to PQ — running production and calling the passing output “validation” — is one of the most common shortcuts auditors flag, because it skips the evidence that the equipment itself is capable of consistently meeting the operating range the process depends on.

If you are outsourcing sterilization or bonding processes → your supplier controls documentation needs to show that you’ve verified the supplier’s process validation, not just received a certificate of conformance.


Software Validation Requirements

Software validation shows up in two places under ISO 13485, and conflating them is a recurring audit finding: software that is part of the device (or used in its production) versus software used for quality management purposes, such as electronic QMS platforms or CAPA tracking tools. Both require validation appropriate to their use, application, and risk — but the depth and method differ substantially, and design-control software validation should be traceable back to the same input/output structure as hardware verification.


What the FDA QMSR Changed for U.S. Manufacturers

The FDA’s Quality Management System Regulation replaced the legacy Quality System Regulation under 21 CFR Part 820, effective February 2, 2026, incorporating ISO 13485:2016 by reference rather than maintaining a separately worded U.S. regulation. For manufacturers who were already ISO 13485 certified, the operational impact on verification and validation practices is smaller than the documentation-mapping impact: DHF, DMR, and DHR content doesn’t necessarily need renaming, but it does need a clear mapping showing where ISO 13485 Clause 7.3 requirements are satisfied within existing U.S. records.

If you were operating under legacy QSR language only → this is the trigger to formally adopt ISO 13485 Clause 7.3 verification/validation terminology and structure, since FDA inspectors are now trained against the ISO clause structure, not the old Part 820 subparts.


Common V&V Documentation Failures

The same handful of gaps show up repeatedly in ISO 13485 QMS audits:

  • No traceability matrix linking design inputs to verification methods and results
  • Validation performed on prototypes rather than production-equivalent units
  • Missing revalidation criteria for processes that later change equipment, materials, or parameters
  • Software validation treated as one-size-fits-all instead of scaled to risk and application
  • Verification and validation dates, methods, and personnel not fully recorded, leaving conclusions without traceable support

👉 Before Your Next Notified Body Assessment

If you’re not confident your traceability matrix would hold up under document review, that’s the exact gap the ISO 13485 Gap Assessment Checklist was built to catch — in under 45 minutes. →


Building a Verification & Validation Plan That Holds Up

A defensible V&V plan starts with the traceability matrix, not the test protocols. Build it in this order:

  1. List every design input and requirement
  2. Map each input to a specific verification method and acceptance criterion
  3. Identify which requirements also require validation evidence, and under what conditions
  4. Define production-equivalent unit criteria before validation begins
  5. Build revalidation triggers into the plan up front — not as an afterthought after a process change

This structure is what turns a stack of individual test reports into a Design History File that answers an assessor’s questions instead of prompting more of them.

Workflow infographic illustrating how verification and validation fit into the ISO 13485 design control process, from user needs and design inputs through production-equivalent units, validation, and Design History File documentation.
This workflow shows how verification and validation integrate into ISO 13485 design controls to produce a complete, traceable Design History File for regulatory compliance.

Quick Audit Checklist

  • ✅ Every design input has a documented verification method and result
  • ✅ Validation was performed on production or production-equivalent units
  • ✅ Risk analysis is referenced in the validation rationale
  • ✅ Process validation records include revalidation criteria
  • ✅ Software validation is scaled to intended use and risk
  • ✅ Verification and validation records include dates, methods, and personnel
  • ⚠️ Watch for validation evidence copied from an earlier device without device-specific justification

FAQ

What is the difference between verification and validation in ISO 13485?

Verification confirms design outputs meet design inputs — did we build it correctly. Validation confirms the finished device meets user needs and intended use — did we build the correct thing. They require separate evidence and cannot substitute for each other.

Does ISO 13485 require validation on production units?

Yes. Clause 7.3.7 requires design validation on production or production-equivalent units under defined operating conditions, not on early prototypes or bench models that don’t reflect final manufacturing.

What processes require process validation under Clause 7.5.6?

Any process where output cannot be fully verified by later inspection or testing — common examples include sterilization, certain welding and bonding processes, injection molding, and adhesive curing.

How did the FDA QMSR affect verification and validation requirements?

The QMSR, effective February 2, 2026, incorporates ISO 13485:2016 into 21 CFR Part 820 by reference. Manufacturers now need documentation that maps clearly to ISO 13485 Clause 7.3, even if internal DHF/DMR/DHR naming stays the same.

Do low-risk devices still need design validation?

Yes, though the depth can scale with risk. A shorter, risk-justified validation plan is acceptable; skipping validation entirely is not.

Does software need separate validation from the device it’s part of?

Software validation is required both for software that’s part of or used in producing the device, and for software used for quality management purposes — but the required depth and method differ by application and risk.

What’s the most common finding auditors cite for validation?

Validation conducted on non-representative units — prototypes or early builds that don’t match production configuration or manufacturing conditions.

Where does risk management fit into verification and validation?

ISO 14971 risk management activities feed directly into what needs validation and how rigorously, particularly for design validation rationale and process revalidation triggers.


📥 Free Resources

  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements, including design control and V&V documentation gaps
  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts
  • AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification

Not Sure What to Do Next?

🔹 Still researching your V&V documentation gaps? Start with the ISO 13485 Gap Assessment Checklist — it maps directly to Clause 7.3 verification and validation requirements.

🔹 Ready to build a compliant V&V process? BSI Group’s ISO 13485 training covers Clause 7.3 requirements in the depth a design control rebuild needs.

🔹 Need the standard itself to build your traceability matrix against? Get ISO 13485:2016 from ANSI Webstore — code CC2026 takes 5% off, and international formats are available.


Verification proves your engineers met the specification. Validation proves your customers can safely use the product. Auditors expect both. Regulators require both. A complete Design History File demonstrates both through traceable evidence — not one comprehensive-sounding report that tries to do both jobs at once.


Stay Ahead of the Next V&V Finding

Design History File gaps rarely surface during routine work — they surface during an audit or inspection, when there’s no time left to fix them. Manufacturers who catch the verification/validation split early walk into assessments with a traceability matrix that answers questions before they’re asked. Manufacturers who don’t spend the assessment explaining why validation was performed on a prototype.

The Standards Navigator tracks ISO 13485, QMSR, and medical device compliance requirements as they develop — including changes that affect how verification and validation get documented.

👉 Get updates on ISO 13485 and QMSR compliance changes
👉 Be first to access new medical device gap assessment tools and checklists

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

Supplier Controls for Medical Devices: ISO 13485 Requirements Explained (2026)

ISO 13485 supplier controls are among the most audited requirements in medical device QMS certifications. This guide covers Section 7.4 — evaluation criteria, purchasing document requirements, incoming inspection, re-evaluation, and the common audit findings that derail supplier programs before Stage 2.

How to build a compliant supplier qualification and monitoring program that holds up under notified body scrutiny

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Your Supplier Is Now Your Risk — and Your Auditor Knows It

Supplier nonconformances are among the top findings in ISO 13485 audits. Not because manufacturers don’t care about their supply chain — but because most supplier controls for medical devices are built for appearance rather than function. They look complete on paper. They fall apart under scrutiny.

When a notified body or FDA investigator walks into your facility, they aren’t just looking at what happens on your production floor. They’re asking who made your components, how you selected them, what evidence you have that they’re capable, and what happens when they fail to deliver compliant product.

If your answers are “we have an approved vendor list” and “we send them a purchase order with our spec,” you’re in trouble.

I’ve audited supplier programs for a global manufacturer of many different types of valves and the gaps I found most often had nothing to do with the suppliers themselves. They had to do with how the manufacturer defined their requirements, communicated them, and verified compliance after the fact. A supplier can’t meet a requirement you never clearly documented. That’s your problem, not theirs, and it shows up in your audit findings.

Before you work through your supplier qualification process, run your current program through the ISO 13485 gap assessment checklist first.

👉 Download the ISO 13485 Gap Assessment Checklist → — free checklist for medical device manufacturers assessing their QMS against ISO 13485:2016 requirements, including supplier control clauses.


In This Guide

  • What ISO 13485 Section 7.4 actually requires for supplier controls
  • How to build a compliant supplier qualification and evaluation process
  • What your purchasing documents must include under 7.4.2
  • Verification of purchased product — incoming inspection and beyond
  • Common audit findings in supplier control programs
  • How supplier controls tie into your risk management process under ISO 14971
  • A quick audit checklist for your supplier control program


👉 Start Here: Top Resources for ISO 13485 Supplier Controls


What ISO 13485 Section 7.4 Requires

ISO 13485:2016 addresses purchasing and supplier controls in Section 7.4, which breaks into three requirements:

  • 7.4.1 — Purchasing process: You must establish criteria for evaluating, selecting, and monitoring suppliers. The criteria must be based on the supplier’s ability to meet your requirements. Records of evaluation results must be maintained.
  • 7.4.2 — Purchasing information: Purchasing documents must clearly describe the product or service being ordered, including applicable specifications, procedures, or quality system requirements you’re flowing down.
  • 7.4.3 — Verification of purchased product: You must establish and implement the inspection or other activities necessary to verify that purchased product meets requirements.

This is not a checkbox exercise. The standard requires documented procedures, records, and evidence that your program actually functions — not just that it exists.

One important distinction from ISO 9001: ISO 13485 is more prescriptive about what supplier evaluation must cover and what records must be maintained. If you’re coming from an ISO 9001 background, expect your notified body to go deeper on supplier documentation than you may be used to.

For a full comparison of how supplier control requirements differ between the two standards, see: ISO 9001 vs ISO 13485


Supplier Qualification: How to Evaluate and Approve Suppliers

Supplier controls for medical devices infographic showing a risk-based supplier evaluation framework, Approved Supplier List process, regulatory review, technical capability assessment, and periodic supplier re-evaluation for medical device manufacturers.
ISO 13485 supplier approval requires documented evaluation, risk classification, qualification records, and ongoing supplier monitoring before suppliers remain on the Approved Supplier List.

Your Approved Supplier List (ASL) is the foundation of your supplier control program. But the list itself isn’t the requirement — the process that populates and maintains it is.

Supplier Evaluation Criteria

Your procedure must define how you evaluate a new supplier before adding them to your ASL. At minimum, this should include:

Evaluation CategoryWhat to AssessEvidence Required
Quality systemISO 13485, ISO 9001, or equivalent QMSCertificate, audit report, questionnaire
Regulatory complianceFDA registration, CE marking, applicable regulationsRegulatory filings, declarations
Technical capabilityAbility to meet your specification requirementsCapability studies, sample approval
Delivery and financial stabilityRisk to supply continuityReferences, business history
Product/service risk classificationImpact on device safety and performanceRisk assessment (see Section 7 below)

Not every supplier gets the same level of scrutiny. A supplier providing sterile packaging components gets evaluated differently than a supplier providing cardboard shipping boxes. Your procedure must define those tiers — and the evaluation rigor that goes with each.

Most common finding: Approved Supplier Lists that include suppliers with no documented evaluation on file. The vendor was added years ago, the person who approved them is gone, and there’s no record of what they were evaluated on.


Purchasing Controls: What Your POs and Specs Must Cover

Section 7.4.2 is where many organizations have significant gaps. Purchase orders and specifications must be clear enough that a supplier knows exactly what’s expected — and clear enough that you can verify compliance on receipt.

What Purchasing Documents Must Include

At minimum, your purchasing documents should specify:

  • Product description, part number, and revision level
  • Applicable specifications (dimensional, material, performance)
  • Quality requirements you’re flowing down (e.g., certificate of conformance, first article inspection, CAPA notification requirements)
  • Any regulatory or standards requirements the supplier must meet
  • Change notification requirements — the supplier must tell you before they change anything that affects your product
ISO 13485 purchasing controls infographic comparing a weak purchase order to an audit-ready controlled purchasing package with specifications, quality requirements, and verification controls.
ISO 13485 purchasing documents must define specifications, quality flow-down requirements, and verification expectations to support compliant supplier controls.

That last point is critical and frequently missed. Supplier-initiated changes — new sub-tier suppliers, process changes, facility moves, material substitutions — must not reach your production floor without your review and approval. If your purchase order doesn’t require the supplier to notify you of changes, you have no contractual basis to enforce it.

If your purchasing documents and quality flow-downs aren’t documented in a controlled procedure, your QMS documentation requirements aren’t complete. See: ISO 13485 Documentation Requirements


Most teams don’t discover their purchasing document gaps until a notified body auditor requests three supplier files during a Stage 2 audit. Run the gap check now, while you still have time to fix it.

👉 Download the ISO 13485 Gap Assessment Checklist →


Verification of Purchased Product

Section 7.4.3 requires you to verify that purchased product meets requirements before it enters your production process. What that looks like depends on the product, the supplier, and the risk level involved.

Incoming Inspection Options

Verification MethodWhen to UseWhat to Document
100% incoming inspectionHigh-risk components, new suppliers, history of nonconformancesInspection records, acceptance/rejection criteria
Statistical samplingEstablished suppliers, lower-risk componentsSampling plan (AQL level), records of results
Certificate of conformance reviewEstablished, well-performing suppliersCOC receipt record, periodic verification
Supplier data reviewHigh-confidence qualified suppliers onlyData review records, approval basis
Skip-lot inspectionExtended high-performance track recordDefined criteria for skip-lot qualification

Your incoming inspection procedure must define the method for each supplier or product category — and your records must show you actually performed it.

What Auditors Look For

Auditors will ask to see incoming inspection records for specific lots. They will cross-reference the purchase order revision, the inspection criteria in your procedure, and the actual record. Discrepancies between any of these three are nonconformances.

They will also ask: what happens when incoming inspection finds a nonconformance? Your CAPA process must connect directly to your incoming inspection findings.

For how CAPA integrates with supplier nonconformances, see: CAPA Requirements in ISO 13485


Ongoing Supplier Monitoring and Re-Evaluation

Qualifying a supplier once is not enough. ISO 13485 requires ongoing monitoring and periodic re-evaluation of your suppliers.

What Ongoing Monitoring Looks Like

Your procedure should define what data you collect and at what frequency to assess supplier performance. Common metrics include:

  • Incoming acceptance rate — percentage of lots accepted without rejection
  • On-time delivery rate — consistently late suppliers are a supply risk
  • Nonconformance rate — corrective action requests issued per time period
  • Customer complaints attributable to supplied components
  • CAPA closure rate — how quickly suppliers respond to and close corrective actions you’ve issued

Re-Evaluation Requirements

Most organizations set an annual re-evaluation cycle. At re-evaluation, you’re reviewing the supplier’s performance data, confirming their certification is still valid, and deciding whether they remain on the ASL — or whether their approval level changes.

Re-Evaluation OutcomeAction
Strong performanceMaintain or upgrade approval level
Acceptable but issues notedIssue corrective action, increase monitoring frequency
Poor performanceProbationary status, increase incoming inspection
Failed or uncertifiedRemove from ASL, qualify replacement

If a supplier is removed from your ASL, your records must reflect that decision and any transition actions taken. An audit trail gap here — particularly if a product from a de-listed supplier made it into production — creates significant liability.

BSI Group offers ISO 13485 training that covers supplier management as part of QMS implementation — useful for quality managers building or rebuilding a supplier program from scratch.


How Supplier Controls Connect to ISO 14971 Risk Management

Risk-based supplier controls infographic showing ISO 13485 and ISO 14971 supplier tiering, supplier monitoring KPIs, risk classification, and supplier re-evaluation workflow for medical device manufacturers.
Risk-based supplier controls connect ISO 14971 risk analysis with ISO 13485 qualification, monitoring, verification, and supplier re-evaluation activities.

Your supplier tier system shouldn’t be arbitrary. It should be driven by a risk assessment.

ISO 14971 — the risk management standard for medical devices — requires you to identify hazards and estimate risks throughout the product life cycle. The components and materials your suppliers provide are part of that risk picture.

Risk-Based Supplier Tiering

Risk TierComponent ExamplesSupplier Control Level
CriticalSterile packaging, implantable components, direct patient-contact materialsFull qualification, audits, COC per lot
MajorElectronic subassemblies, precision machined partsQualification + periodic re-evaluation, sampling
MinorNon-product-contact materials, standard hardwareBasic approval, periodic review
AdministrativeCalibration services, software toolsContract review, credentials verification

Documenting the risk basis for each tier — and linking it to your ISO 14971 risk file — gives you a defensible rationale for your supplier control decisions. Auditors respond well to risk-based reasoning. They respond poorly to “that’s how we’ve always done it.”

For a full breakdown of how ISO 14971 and ISO 13485 work together: ISO 14971 vs ISO 13485


Common Audit Findings in Supplier Control Programs

These are the findings that show up repeatedly in ISO 13485 audits — and the ones your program should be specifically designed to prevent.

Most common finding #1: Suppliers on the ASL with no qualification records. Vendors added informally, without documented evaluation. No basis for their approval on file.

Most common finding #2: Purchase orders that don’t flow down quality requirements. The PO has a part number and a price. It does not reference a specification revision level, a certificate of conformance requirement, or any CAPA notification obligation.

Most common finding #3: Incoming inspection records that don’t match procedures. The procedure says AQL sampling on a specific plan. The records show visual inspection only. Or no records at all.

Most common finding #4: No re-evaluation records for suppliers on the ASL for more than 12 months. Annual re-evaluation is defined in the procedure. No evidence it was performed.

Most common finding #5: Supplier CAPAs not tracked or closed. A corrective action was issued to a supplier. There’s no record of their response or whether the root cause was resolved.

If any of those five sound familiar, your supplier control program has audit risk right now.


Quick Audit Checklist: Supplier Controls

Run through this before your next internal audit or notified body review:

✅ Documented supplier evaluation criteria based on product risk level

✅ Approved Supplier List with documented evaluation records for every supplier

✅ Procedure defines supplier tiers and the control requirements for each tier

✅ Purchasing documents (POs, specs) include product description, revision level, and quality flow-down requirements

✅ Change notification requirement communicated to and acknowledged by suppliers

✅ Incoming inspection procedure defines method by product/supplier category

✅ Incoming inspection records maintained and linked to purchase orders

✅ Nonconforming purchased product procedure exists and connects to CAPA

✅ Supplier performance data collected and reviewed at defined frequency

✅ Annual re-evaluation records on file for all active suppliers

✅ De-listed supplier records maintained with transition documentation

✅ Risk basis documented for supplier tier assignments (links to ISO 14971 risk file)


FAQ

What does ISO 13485 Section 7.4 require for supplier controls?

Section 7.4 of ISO 13485:2016 requires three elements: a documented process for evaluating, selecting, and monitoring suppliers (7.4.1); purchasing documents that clearly specify product requirements and quality flow-down obligations (7.4.2); and a defined process for verifying that purchased product meets requirements before use (7.4.3). All three require documented procedures and maintained records — not just policy statements.

How do I build an Approved Supplier List that satisfies ISO 13485 auditors?

Your Approved Supplier List must be backed by documented evaluation records for every supplier on it. The evaluation criteria should be defined in your procedure and applied consistently. Auditors will select suppliers from the list at random and ask to see their qualification records. If a supplier was added without documented evaluation, that’s a nonconformance regardless of how long they’ve been on the list.

Do all suppliers need the same level of evaluation under ISO 13485?

No. ISO 13485 supports a risk-based approach to supplier controls. Suppliers providing critical components — those that directly affect device safety or performance — require more rigorous qualification and monitoring than suppliers of low-risk or non-product-contact materials. Your procedure must define the risk tiers and the control requirements for each.

What must purchase orders include to satisfy ISO 13485 Section 7.4.2?

Purchase orders and associated documents must describe the product clearly enough to verify compliance on receipt. This includes the product description, specification revision level, applicable standards or regulatory requirements, quality requirements being flowed down (such as a certificate of conformance), and change notification obligations. A purchase order that only includes a part number and price is not compliant with 7.4.2.

How often do I need to re-evaluate suppliers under ISO 13485?

ISO 13485 requires periodic re-evaluation but does not specify a frequency. Most quality management systems set annual re-evaluation as the standard cycle. What matters is that your procedure defines the frequency, that re-evaluation is actually performed on schedule, and that records are maintained showing the outcome and any actions taken.

What happens if a supplier fails re-evaluation?

Your procedure must define the response to poor supplier performance. Options include issuing a corrective action request, increasing the incoming inspection level, placing the supplier on probationary status, or removing them from the Approved Supplier List. Whatever action is taken must be documented. If a supplier is removed from the ASL, records must reflect the decision and any transition activities.

How do supplier controls connect to CAPA in ISO 13485?

Any nonconformance associated with purchased product — identified at incoming inspection, during production, or through customer complaints — should trigger your CAPA process. CAPAs issued to suppliers must be tracked to closure, with evidence that the root cause was addressed. A CAPA issued to a supplier with no follow-up record is a frequent audit finding.

Does ISO 13485 require supplier audits?

ISO 13485 does not explicitly require supplier audits, but it requires you to evaluate and monitor suppliers — and for high-risk suppliers, a supplier audit may be the most effective and defensible method. Your procedure should define when supplier audits are required based on risk level and performance history.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching whether your supplier program meets 13485 requirements? Start with the free ISO 13485 Gap Assessment Checklist to identify specific gaps before you invest in implementation.

🔹 Ready to build or rebuild your supplier control program? BSI Group’s ISO 13485 training covers supplier management as part of a full QMS implementation curriculum — practical, not academic.

🔹 Need the standard itself to verify clause requirements? Buy ISO 13485:2016 from the ANSI Webstore — use code CC2026 for 5% off through December 31, 2026.


Supplier controls are one of the most audited areas in ISO 13485 — and one of the most correctable. The common findings aren’t caused by complexity. They’re caused by supplier programs that were built fast, never formalized, and never tested against the actual clause requirements. The Standards Navigator covers ISO 13485 implementation from gap assessment through certification, with practical guidance built on real QMS and quality management experience.


Stay Ahead of ISO 13485 Supplier Control Requirements

Supplier nonconformances are consistently among the top audit findings in ISO 13485 certifications — not because the requirements are unclear, but because most programs were built to satisfy an initial audit and never updated to reflect actual supplier performance data.

Organizations that maintain clean supplier records and re-evaluate on a defined schedule rarely have corrective actions in this area. Organizations that treat supplier qualification as a one-time event get findings every surveillance cycle.

The Standards Navigator covers the full ISO 13485 implementation picture — from documentation requirements to CAPA processes to supplier controls — with guidance built for regulatory affairs and quality professionals who need to get it right, not just get it done.

👉 Get updates on ISO 13485 implementation requirements and audit readiness 👉 Be first to access new ISO 13485 compliance resources and checklists

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

UDI Requirements for Medical Devices: What Manufacturers Must Know in 2026

Medical device manufacturers must maintain a Unique Device Identification (UDI) system under 21 CFR Parts 801 and 830. This guide covers the DI/PI structure, GUDID submission requirements, FDA-accredited issuing agencies, direct marking for reusable devices, and how UDI compliance integrates with ISO 13485 and the FDA QMSR — including the audit findings that catch teams off guard.

What UDI requirements for medical devices mean and how to build a compliant Unique Device Identification system under FDA QMSR and ISO 13485

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Your UDI System Has More Moving Parts Than You Think

Most medical device manufacturers know they need a UDI on their label. What most don’t account for until an audit is how many systems, procedures, and records that single barcode touches.

Your UDI isn’t just a labeling requirement. It links to your Device History Record, your GUDID submission, your CAPA system, your design change controls, and your post-market surveillance process. Miss any of those connections, and you have a UDI that looks right on the label but falls apart the moment an FDA investigator starts pulling threads.

That’s the compliance gap this article closes.

The FDA’s Unique Device Identification system, mandated under 21 CFR Part 801 and Part 830, requires medical device manufacturers to assign a standardized identifier to every device, submit key data to the Global Unique Device Identification Database (GUDID), and maintain records that connect that identifier throughout the product lifecycle. As of February 2, 2026, UDI compliance is also explicitly woven into the FDA Quality Management System Regulation (QMSR) framework under 21 CFR Part 820 — meaning your QMS and your UDI system are no longer separate compliance tracks.

I’ve walked through FDA QMSR inspections where the UDI records looked clean on paper but couldn’t be tied back to the Device History Record for a specific lot. The inspector didn’t raise a UDI finding — she raised a recordkeeping finding under QMSR. That’s how connected these systems have become. If your UDI implementation lives in a spreadsheet outside your QMS, you have an audit finding waiting to happen.

If you are building or auditing your ISO 13485 QMS and aren’t sure whether your traceability documentation covers UDI requirements, run a clause-by-clause gap check before your next audit.

👉 Download the ISO 13485 Gap Assessment Checklist — free tool for medical device QMS teams assessing compliance before a certification or surveillance audit


In This Guide

  • What UDI is and why the FDA created it
  • The two components of every UDI: Device Identifier and Production Identifier
  • Who counts as the “labeler” and what that means for your responsibilities
  • GUDID: what to submit, when, and how to stay current
  • FDA-accredited issuing agencies: GS1, HIBCC, and ICCBBA compared
  • Direct marking requirements for reusable devices
  • UDI exemptions and exceptions — what’s actually covered
  • How UDI integrates with ISO 13485, QMSR, and your QMS
  • Common UDI audit findings and how to avoid them
  • UDI for SaMD and combination products

Table of Contents


👉 Start Here: Top Resources for UDI Compliance

Before diving in, here are the tools most useful for teams building or auditing a UDI system:


What Is the FDA UDI System?

The Unique Device Identification (UDI) system is an FDA-mandated framework requiring medical device manufacturers to assign a standardized, globally unique identifier to every device placed on the US market. The legal authority comes from Section 519(f) of the Federal Food, Drug, and Cosmetic Act. The implementing regulations live in two places:

  • 21 CFR Part 801, Subpart B — labeling requirements for UDI placement on device labels and packaging
  • 21 CFR Part 830 — UDI system specifications, including issuing agency accreditation and GUDID data submission

The FDA published its final UDI rule in September 2013 and phased in compliance requirements by device class. As of December 2022, enforcement delays for Class I and unclassified devices have largely expired. Any device entering the US market in 2026 should operate under full UDI compliance unless a formal exemption applies.

Why UDI exists. The system creates a single, unambiguous way to identify a medical device across its entire lifecycle — from manufacturing through distribution, clinical use, post-market surveillance, and recall. Before UDI, adverse event reports frequently identified devices by trade name only, making it difficult or impossible for FDA to link events to specific device versions, lots, or manufacturing runs. UDI closed that gap.

The practical impact is straightforward: every adverse event, complaint, CAPA, recall, or MDR filed with FDA can now be linked to an exact device version via its UDI. That connection runs both directions — your GUDID record and your internal Device History Record need to tell the same story.


The Two Components of UDI Requirements for Medical Devices

Every UDI consists of two segments. Both must appear on the label for most device types.

Device Identifier (DI)

The Device Identifier is the fixed, mandatory portion of the UDI. It identifies the labeler and the specific version or model of the device. The DI is:

  • Issued by an FDA-accredited issuing agency (GS1, HIBCC, or ICCBBA)
  • The primary key for GUDID submissions — all device attribute data is registered under the DI
  • Searchable in the public AccessGUDID database hosted by the National Library of Medicine

A new DI is required when:

  • A device change results in a new version or model
  • A change affects the intended use of the device
  • A change introduces major differences in safety or performance
  • A new FDA regulatory submission (510(k), De Novo, PMA) is triggered

The DI assignment decision is a change control issue. Your QMS procedures need to define the threshold at which a design or manufacturing change triggers a new DI — and that procedure needs to be followed consistently.

Production Identifier (PI)

The Production Identifier is the variable portion of the UDI. It identifies specific production characteristics of a device unit and must be included whenever the corresponding information appears on the device label.

PI ElementInclude When…
Lot or batch numberLot number appears on label
Serial numberSerial number appears on label
Manufacturing dateManufacturing date appears on label
Expiration dateExpiration date appears on label
Distinct identification codeRequired for HCT/P devices regulated as medical devices
Diagram showing the two components of UDI requirements for medical devices, including the Device Identifier (DI) and Production Identifier (PI) with key data elements used for FDA UDI compliance.
Every UDI consists of two parts: the Device Identifier (DI), which identifies the device version and labeler, and the Production Identifier (PI), which captures lot, serial number, expiration date, and manufacturing date information.

Class I devices are not required to include a PI — the DI alone satisfies UDI requirements for Class I. All dates on labels must follow the YYYY-MM-DD format per 21 CFR 801.18.


Who Is the Labeler?

Under 21 CFR Part 830, the labeler is the entity that causes the label to be applied to the device. In most cases, that is the manufacturer. But contract manufacturers, specification developers, repackagers, and relabelers can all become the labeler depending on who is responsible for what appears on the final label.

This matters because the labeler is responsible for:

  • Assigning the DI through an accredited issuing agency
  • Submitting device attribute data to GUDID before the device is placed on the market
  • Maintaining and updating GUDID records when device attributes change
  • Ensuring the UDI appears correctly on the label, packaging, and (where required) directly on the device

If your organization contracts out labeling, or if you are a specification developer whose devices are manufactured and labeled by a contract manufacturer, establish in writing who holds labeler responsibility. Ambiguity here surfaces as a finding in both FDA inspections and ISO 13485 audits.


FDA-Accredited Issuing Agencies

Three organizations are accredited by FDA to issue UDIs for medical devices distributed in the US:

AgencyStandard UsedCode TypeBest For
GS1GTIN (Global Trade Item Number)NumericMost medical device manufacturers; broadest global compatibility
HIBCCHIBC (Health Industry Bar Code)AlphanumericHealthcare-specific supply chains; common in hospital settings
ICCBBAISBT 128AlphanumericBlood products, HCT/Ps, and products of human origin
Comparison chart of FDA-accredited UDI issuing agencies for medical devices including GS1, HIBCC, and ICCBBA with code types and recommended use cases.
Visual comparison of the three FDA-accredited UDI issuing agencies showing code formats and ideal implementation scenarios for medical device manufacturers.

GS1 is the most widely used issuing agency among medical device manufacturers and provides the broadest compatibility across global regulatory systems, including the EU’s EUDAMED. GS1 charges an initial enrollment fee and an annual renewal based on company revenue. HIBCC charges a one-time Labeler Identification Code (LIC) fee. ICCBBA is category-specific and is the required issuing agency for ISBT 128-regulated products.

Your issuing agency choice has long-term implications. It affects how your UDI is structured, what barcode symbology you use, how your labels integrate with distributor and hospital systems, and how you manage multi-jurisdiction compliance. Most manufacturers establish this relationship during product development, not during pre-market submission — don’t defer this decision.


GUDID: Submission Requirements and Timelines

GUDID — the Global Unique Device Identification Database — is FDA’s public repository for device identification data. The AccessGUDID platform, hosted by the National Library of Medicine, makes this data publicly searchable by clinicians, regulators, and purchasing organizations.

What You Must Submit

For every DI, you must submit:

  • Device description and proprietary name
  • Device class (I, II, III)
  • Whether the device contains latex or DEHP
  • Whether the device is labeled sterile
  • Whether the device is a single-use device
  • Packaging quantity and configuration
  • MRI safety information (where applicable)
  • Issuing agency and DI
  • Company contact information

Submission must occur before the device is placed on the market — not after the label is printed, not concurrent with distribution, before.

Submitting to GUDID

There are two submission paths:

  • Manual entry via the FDA GUDID web interface — suitable for small product portfolios
  • Electronic submission via XML upload through the Electronic Submissions Gateway (ESG) — required for larger portfolios; validated interface required under 21 CFR Part 11 where applicable

If electronic submission is not technologically feasible, a waiver may be requested in writing to FDA’s Center for Devices and Radiological Health.

Keeping GUDID Current

GUDID records must be updated whenever device attribute data changes. This is where most manufacturers fall short. A device name change, a sterilization method update, a packaging configuration change — each triggers an obligation to update GUDID. Build that trigger into your change control procedure, not as an afterthought.

If your QMS doesn’t currently have a documented procedure connecting design and manufacturing changes to GUDID update obligations, that is a gap auditors will find.

👉 Download the ISO 13485 Gap Assessment Checklist — includes traceability and labeling controls relevant to UDI compliance


Labeling Format Requirements

Under 21 CFR Part 801, the UDI must appear on the device label in two forms:

  1. Human Readable Interpretation (HRI) — plain text that can be read without scanning equipment
  2. Automatic Identification and Data Capture (AIDC) — a machine-readable format, typically a barcode or 2D data matrix, that can be electronically captured

Both formats must appear on the label and on all packaging levels intended for commercial distribution. Shipping containers used solely for logistics are exempt.

Barcode readability is a compliance issue, not just a quality issue. In 2026, “it looked fine when we printed it” is not a defensible audit response. Barcode print quality must be verified against ISO/IEC quality grades, and your label verification records must be maintained in the Device History Record. If your production line doesn’t include end-of-line barcode scan verification, that is an audit exposure.


Direct Marking for Reusable Devices

Reusable devices — those intended to be used more than once and reprocessed between uses — must bear the UDI directly on the device itself, in addition to the label and packaging. This is called direct part marking (DPM).

Direct marking methods vary by device material and design:

  • Laser etching
  • Chemical etching
  • Electrochemical etching
  • Inkjet or dot peen marking

The DI (not necessarily the full UDI with PI) must be permanently marked on the device. The marking must remain legible after reprocessing for the expected service life of the device. Validation records for the direct marking process, including legibility after simulated reprocessing cycles, belong in the Design History File and should be cross-referenced in the Device Master Record.


UDI Exemptions and Exceptions

Not every device is required to bear a UDI. Exemptions under 21 CFR 801.30 include:

✅ Class I devices exempt from GMP requirements under 21 CFR Parts 862–892 ✅ Individual single-use devices packaged together in a single device package, not intended for individual commercial distribution (the outer package must still bear a UDI)
✅ Devices used solely for research, teaching, or chemical analysis — not for clinical use
✅ Custom devices under 21 CFR 812.3(b)
✅ Investigational devices under 21 CFR Part 812
✅ Veterinary devices not intended for human use
✅ Devices intended for export from the United States
✅ Devices held by the Strategic National Stockpile under approved alternatives

What is not exempt: accessories. Even if the primary device is exempt, accessories regulated as medical devices require a UDI unless they independently qualify for an exemption.

If you believe a device qualifies for an exemption or need an alternative approach, 21 CFR 801.55 provides a formal process for requesting an exception from FDA.


UDI and Your ISO 13485 QMS

ISO 13485:2016 doesn’t mention UDI by name. It doesn’t need to. The standard’s traceability and labeling requirements create the documented control infrastructure that UDI compliance depends on.

The relevant ISO 13485 clauses that intersect with UDI:

ClauseRelevance to UDI
7.5.8 — IdentificationDevices must be identified throughout production and storage — UDI is the primary identification mechanism for marketed devices
7.5.9 — TraceabilityRecords must enable tracing of device identity, components, and processing history — the DI/PI structure directly supports this
7.6 — Control of monitoring and measuring equipmentBarcode scan verification equipment must be calibrated and maintained
8.3 — Control of nonconforming productUDI enables precise identification of affected lots in nonconformance handling
4.2.4 — Control of recordsGUDID submission records, AIDC verification logs, and change control documentation are QMS records

As of February 2026, the FDA QMSR under 21 CFR Part 820 aligns US quality system requirements with ISO 13485:2016. That alignment means FDA inspectors now assess QMS infrastructure — including traceability controls — through the lens of ISO 13485 clause structure. Your UDI system needs to fit inside that framework, not sit beside it.

If you are building your ISO 13485 QMS from the ground up, the BSI Group ISO 13485 training program covers design controls, traceability, and labeling requirements in the context of FDA regulatory expectations — a practical foundation for teams that need to connect QMS infrastructure to UDI compliance.


UDI for Software and Combination Products

Software as a Medical Device (SaMD)

Software devices follow the same UDI principles as hardware devices, with adaptations for how the identifier is displayed. For standalone software distributed in packaged or downloaded form:

  • The UDI must be displayed when the software is launched, or accessible through a menu
  • Software distributed in packaged form and as a download may display the same DI
  • A new DI is required when software changes affect the intended use or introduce a new regulatory submission
  • For AI/ML-enabled devices operating under a Predetermined Change Control Plan, algorithm updates within approved boundaries may require only PI updates; changes outside the approved plan require a new DI

Combination Products

Combination products — products that combine two or more of a drug, device, and/or biological — carry UDI requirements on each device constituent part. The specifics depend on how the combination product is classified (device-led or drug-led) and whether the constituent parts would independently require UDI. FDA issued draft guidance in June 2025 addressing UDI requirements for combination products with device constituent parts — review the current guidance on FDA.gov for your specific product configuration.


Common UDI Audit Findings

Dark navy infographic showing five common UDI audit findings for medical devices including DI reassignment controls, GUDID updates, direct part marking validation, CAPA linkage, and submission timing requirements.
Quick-reference graphic highlighting five common UDI audit findings that frequently appear during FDA inspections and internal compliance reviews.

These are the gaps most frequently identified during FDA inspections and ISO 13485 audits related to UDI:

⚠️ GUDID records not updated after a design or manufacturing change. The change control procedure doesn’t include a UDI/GUDID review step.

⚠️ Barcode verification records not maintained in the DHR. Labels are printed and inspected visually, but scan verification results aren’t documented.

⚠️ No documented procedure defining when a design change triggers a new DI. The threshold for DI reassignment is ambiguous.

⚠️ Direct part marking not validated. Reusable device marking process was implemented without legibility testing after reprocessing.

⚠️ UDI not linked to CAPA or complaint records. When a CAPA is opened, the affected device version is identified by trade name only — not by DI/lot.

⚠️ UDI submission timing. Device reached distribution before GUDID submission was completed.

Most of these findings have one root cause: UDI compliance was treated as a labeling project rather than a QMS integration project. Getting it right requires connecting your UDI system to change control, CAPA, complaint handling, and post-market surveillance — not just to your label artwork approval process.

Most auditors don’t find UDI problems in the labeling department. They find them in the QMS.


✅ UDI Compliance Quick Checklist

Before your next audit, verify:

  • [ ] DIs assigned through an FDA-accredited issuing agency (GS1, HIBCC, or ICCBBA)
  • [ ] GUDID records complete and submitted before device placement on market
  • [ ] Both HRI and AIDC formats present on all commercial distribution labels and packaging
  • [ ] Barcode print quality verified and records maintained in DHR
  • [ ] Change control procedure includes a UDI/GUDID review trigger
  • [ ] Direct marking validated for all reusable devices (legibility after reprocessing documented)
  • [ ] UDI (DI + lot/serial) linkage established in CAPA and complaint records
  • [ ] GUDID records updated after any applicable device attribute change
  • [ ] Exemption rationale documented for any device or packaging level excluded from UDI
  • [ ] UDI training completed and documented for personnel responsible for labeling, change control, and GUDID management

Frequently Asked Questions

What is a UDI in medical devices?

A UDI — Unique Device Identifier — is a standardized code assigned to medical devices that enables consistent identification throughout the device’s distribution and use. It consists of a Device Identifier (fixed, identifies the labeler and device version) and a Production Identifier (variable, identifies lot, serial number, expiration date, or manufacturing date). The FDA requires UDIs under 21 CFR Parts 801 and 830, and the system is enforced as part of the broader FDA QMSR quality system framework.

Is UDI required for all medical devices?

Most medical devices distributed in the United States are required to bear a UDI. Exemptions exist for certain Class I devices exempt from GMP requirements, custom devices, investigational devices, devices used solely for research, and devices intended for export. Individual single-use devices packaged in bulk are also exempt (but their outer packaging is not). Check 21 CFR 801.30 for the complete exemption list, and document any exemption determination in your quality system records.

What is GUDID and what do I need to submit?

GUDID — the Global Unique Device Identification Database — is FDA’s public repository for device identification data. Manufacturers (labelers) must submit Device Identifier data for each version or model of a device before it is placed on the market. Required data includes device description, device class, packaging information, single-use status, sterility, latex content, and MRI safety information. Records must be kept current whenever device attributes change.

What is the difference between a Device Identifier and a Production Identifier?

The Device Identifier (DI) is the fixed portion of the UDI — it identifies the labeler and the specific device version or model. It is issued by an FDA-accredited issuing agency and is the primary key in GUDID. The Production Identifier (PI) is the variable portion — it captures specific production data such as lot number, serial number, expiration date, or manufacturing date. The PI must be included whenever the corresponding information appears on the device label.

Which issuing agency should I use — GS1, HIBCC, or ICCBBA?

Most medical device manufacturers use GS1, which offers the broadest global supply chain and regulatory system compatibility. HIBCC is common in hospital-centric supply chains and is preferred by some healthcare systems. ICCBBA (ISBT 128) is required for blood products, tissues, and human-derived products. Select based on your product category, existing supply chain barcode infrastructure, customer requirements, and multi-jurisdiction needs. The decision has long-term implications — establish your issuing agency relationship during product development.

What are the UDI requirements for reusable devices?

Reusable medical devices — those intended for use more than once and reprocessed between uses — must bear the UDI directly on the device itself (direct part marking), in addition to the label and packaging. The DI must be permanently marked and must remain legible after reprocessing for the device’s expected service life. Validation records for the marking process, including legibility testing after simulated reprocessing, are required.

How does UDI connect to my ISO 13485 QMS?

UDI compliance depends on the same documented control infrastructure required by ISO 13485:2016 — traceability (Clause 7.5.9), device identification (7.5.8), control of records (4.2.4), and nonconforming product management (8.3). Under the FDA QMSR effective February 2026, FDA inspectors assess quality system infrastructure through ISO 13485 clause structure. Your UDI system must be integrated into your QMS — change control, CAPA, complaint handling, and post-market surveillance — not maintained as a separate labeling function.

What happens if my GUDID record is out of date?

An outdated GUDID record is a regulatory violation and an audit finding. It can also create downstream problems: if a recall is issued, FDA uses GUDID data to identify the scope of affected devices. If your records don’t accurately reflect the current device configuration, the recall scope may be incorrectly defined. Keep GUDID current by building a GUDID review trigger into your change control procedure.


📥 Free Resources

ISO 13485 Gap Assessment Checklist — free clause-by-clause gap assessment tool for medical device QMS teams preparing for certification, surveillance audits, or FDA QMSR alignment. Covers traceability, labeling, CAPA, and design controls.

AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause gap assessment for aerospace suppliers — included here for teams operating in both medical device and aerospace quality systems.

ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system.

Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.

Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.


Not Sure What to Do Next?

🔹 Still building your UDI knowledge base? Start with What Is ISO 13485? for an overview of the QMS standard that governs your traceability and labeling systems, then review ISO 13485 Documentation Requirements to understand what records your UDI system needs to generate.

🔹 Ready to assess your current QMS against ISO 13485 requirements? Download the ISO 13485 Gap Assessment Checklist and work through the traceability and labeling sections before your next audit or inspection.

🔹 Need to purchase the standard? ISO 13485:2016 is available from the ANSI Webstore — the authorized source for US manufacturers. Use code CC2026 for 5% off through December 31, 2026. The ANSI Webstore serves international buyers and offers standards in multiple languages.


UDI isn’t a checkbox. It’s the data backbone that connects your device to every regulatory touchpoint across its lifecycle — from your first GUDID submission to a potential recall years after launch. Getting the system right means integrating it into your QMS from day one, not retrofitting it after an audit finding.

The Standards Navigator covers medical device quality and compliance requirements with the same direct, practitioner-grounded approach you need to make good decisions — not just check boxes.


Subscribe and Stay Ahead

Teams that struggle with UDI compliance share one common trait: they treat it as a labeling project. Teams that pass FDA inspections treat it as a QMS integration project — and they built the documentation before the auditor walked in.

Organizations that build UDI compliance into their change control, CAPA, and post-market surveillance from the start don’t scramble before inspections. They already have the records. Organizations that don’t maintain connected systems spend inspection days searching for GUDID submission confirmations and barcode verification logs across disconnected folders and spreadsheets.

The Standards Navigator covers ISO 13485, FDA QMSR, UDI, risk management, and the full spectrum of medical device compliance requirements — for quality professionals who need the detail, not the overview.

👉 Get updates on medical device compliance and QMS implementation
👉 Be first to access new ISO 13485 resources and checklists

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.