ISO 13485 Clauses Explained: A Complete Clause-by-Clause Breakdown (2026)

ISO 13485:2016 has eight clauses, but only five carry auditable requirements. This ISO 13485 clauses explained guide breaks down Clauses 4 through 8 in practical terms, corrects the common DHF-to-Medical-Device-File mapping error, and explains how FDA’s Compliance Program 7382.850 — which replaced QSIT on February 2, 2026 — reorganizes inspections around six QMS Areas and four Other Applicable FDA Requirements.

What every section of ISO 13485:2016 actually requires — and where auditors dig deepest

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Standard Reads Like a Checklist. It Isn’t One.

ISO 13485:2016 has eight clauses. Five of them carry actual requirements. That structure looks simple on the page — and it’s exactly why so many quality teams underestimate how much interpretation each clause demands once an auditor starts asking “show me.” This ISO 13485 clauses explained guide breaks down what each section requires, where the requirements overlap, and what auditors and FDA investigators may look for.

The FDA’s Quality Management System Regulation (QMSR) took effect February 2, 2026, incorporating ISO 13485:2016 by reference into 21 CFR Part 820. That changes what this clause structure means in practice. FDA also replaced its inspection methodology the same day — the Quality System Inspection Technique (QSIT) is gone, replaced by Compliance Program 7382.850. Getting the clause boundaries right now has a direct line to how an FDA investigator scopes an inspection, not just how a certification body audits.

Regulatory affairs and quality professionals reading this already know ISO 13485 exists. What’s harder to find is a breakdown that goes past the clause titles and into what each section demands in practice — where the audit findings cluster, where risk management threads through clauses that don’t mention risk in their title, and where the standard’s lack of an Annex SL high-level structure changes how it should be read compared to ISO 9001.

My perspective on this comes from 25+ years in operations leadership, an ISO 9001 Internal Auditor certification, and a Six Sigma Green Belt — a lot of that time spent on both sides of the table, building QMS documentation and sitting in CAPA reviews when a gap in that documentation turned into a finding. The pattern holds across every regulated QMS I’ve worked with: teams don’t fail because they misread a clause. They fail because they treated clause boundaries as more rigid than the standard actually intends, and missed how much cross-referencing an auditor expects between clauses 4 through 8.

If you haven’t run a structured gap check against the current clause set, that’s the place to start — not a full documentation rewrite.

👉 Run the ISO 13485 Gap Assessment Checklist before you touch your quality manual — a free, structured way to see exactly which clauses your QMS already satisfies and which ones need real work before an auditor finds the gap for you.


In This Guide

  • How ISO 13485:2016 is structured, and why it doesn’t follow ISO’s Annex SL format
  • A clause-by-clause breakdown of Clauses 4 through 8
  • How FDA’s current inspection program, Compliance Program 7382.850, reorganizes inspections around six QMS Areas
  • The most common audit findings tied to specific sub-clauses
  • Where risk management actually appears throughout the standard
  • How ISO 13485 clause numbering compares to ISO 9001
  • FAQs on structure, exclusions, and transition timing


👉 Start Here (Top Resources)


ISO 13485 Clauses Explained: How the Standard Is Structured

ISO 13485 clauses explained with an eight-clause map covering the standard’s foundational and QMS requirement clauses
ISO 13485 clauses explained through an eight-clause map showing the foundational clauses and the five clauses containing QMS requirements.

ISO 13485:2016 is built around eight clauses. The first three are introductory — they define scope, point to normative references, and set terminology. They carry no auditable requirements on their own, but skipping them is a mistake most teams make once and then correct the hard way.

Clauses 4 through 8 are where the requirements live. This is the part of the standard your certification body actually audits against, clause by clause, sub-clause by sub-clause.

Here’s something worth knowing before you go further: ISO 13485 does not follow the Annex SL high-level structure that ISO 9001:2015, ISO 14001, and ISO 45001 all share. Those three standards align clause-for-clause at the top level, which is why integrated management systems work so cleanly across them. ISO 13485 kept its own structure when it was revised in 2016, specifically so it could stay independent of ISO 9001 revision cycles — a deliberate choice by the technical committee to protect regulatory stability for device manufacturers. If you’re coming from an ISO 9001 background, this is the first adjustment to make: don’t assume clause 7 means the same thing in both standards. It doesn’t.


Clauses 1 Through 3: No Requirements, But Don’t Skip Them

Clause 1 (Scope) defines what the standard covers and, critically, how exclusion and non-application work. ISO 13485 doesn’t let an organization simply skip a requirement that seems inconvenient — where a clause is excluded or considered non-applicable (say, you don’t perform installation), the scope and justification have to be documented in the quality manual under Clause 4.2.2, and be prepared to defend that justification during an audit.

Clause 2 (Normative References) points to ISO 9000:2015 for terms and definitions. You don’t need to buy ISO 9000 to comply, but auditors do expect your team to be using its vocabulary consistently — “nonconformity,” “corrective action,” and “verification” all carry specific meanings your documentation should match.

Clause 3 (Terms and Definitions) establishes the vocabulary used throughout the standard, including specific definitions for concepts like medical device, complaint, risk, and post-market surveillance. Getting comfortable with this terminology matters more than it looks like it should — auditors expect your documentation to use these terms precisely, not colloquially.

📥 Before diving into clauses 4-8: if your QMS documentation predates 2020, run it against the current ISO 13485 Documentation Requirements breakdown first. Most gaps trace back to documentation structure, not missing procedures.


Clause 4: Quality Management System

Clause 4 sets the general requirements for the QMS itself — and it’s where most audit programs start, because everything downstream depends on it.

4.1 General Requirements requires you to identify your QMS processes, map their sequence and interaction, and — this is the part that trips up contract manufacturers — maintain control over any process you outsource. Most common finding: outsourced processes (contract sterilization, contract testing, third-party calibration) that exist operationally but were never formally brought into QMS scope. If a supplier touches your product or your data, your QMS has to account for it.

4.2 Documentation Requirements covers the quality manual, the Medical Device File (Clause 4.2.3), document control, and record control. This requirement is specific to this standard — it’s not something ISO 9001 asks for. It’s a defined set of documents and references demonstrating a device meets its requirements throughout its lifecycle, and auditors will ask to see it assembled, not scattered across a dozen disconnected folders.

If your documentation still uses FDA’s old terminology, this is worth getting precise about. As of February 2, 2026, the terms Device Master Record, Device History Record, and Design History File no longer appear in 21 CFR Part 820. Those legacy record concepts weren’t simply eliminated; their applicable requirements are now addressed through the QMSR framework and ISO 13485’s own structure. Most of what a Device Master Record covered lives in the Medical Device File at Clause 4.2.3, while the Design History File corresponds to the Design and Development File at Clause 7.3.10. These aren’t simple one-for-one renamings: the Medical Device File in particular is a broader requirement than the DMR it replaced, so a straight terminology swap in your documentation will likely leave gaps a crosswalk exercise would catch.

Sub-clause 4.2.4 (control of documentation) and 4.2.5 (control of records) get their own scrutiny. Auditors typically check three things here: are documents reviewed and approved before use, is there a mechanism to prevent use of outdated versions, and are records retained for a defined, justified period. If you’re preparing for your first audit under this clause → build your document control procedure before you build anything else. Everything else in the QMS references it.


Clause 5: Management Responsibility

Clause 5 puts specific, named accountability on top management — not “the quality department,” but leadership itself.

This clause requires a documented quality policy, measurable quality objectives, evidence of planning for QMS changes, and a sub-clause I’ve seen come up repeatedly in audit findings — management review. Clause 5.6.2 is unusually prescriptive for an ISO standard: it names twelve required inputs, and a compliant management review record has to address all of them or document why one doesn’t apply — feedback, complaint handling, reporting to regulatory authorities, audits, monitoring and measurement of processes, monitoring and measurement of product, corrective action, preventive action, follow-up actions from previous reviews, changes that could affect the QMS, recommendations for improvement, and applicable new or revised regulatory requirements. A management review that skips several of these, or that doesn’t produce documented outputs and action items, is a finding waiting to happen — and under the current FDA inspection framework, it’s no longer just a certification-audit concern (more on that below).

If you are already ISO 9001 certified, this clause will feel familiar structurally — but ISO 13485 expects a tighter link between management review and regulatory requirements specifically, not just general business objectives.


Clause 6: Resource Management

Clause 6 covers human resources, infrastructure, and work environment — including contamination-control requirements under 6.4.2 that go considerably further than ISO 9001’s general treatment of work environment.

6.2 Human Resources requires documented competence for anyone whose work affects product quality — not just “trained,” but competence tied to education, skills, and experience, with evidence. 6.3 Infrastructure requires maintenance records for equipment critical to product conformity. 6.4 Work Environment and Contamination Control is where device manufacturers doing anything sterile, implantable, or otherwise contamination-sensitive get the most detailed scrutiny — cleanroom classifications, gowning procedures, and environmental monitoring data all trace back here.


Clause 7: Product Realization

Clause 7 is the largest clause in the standard, and it’s where design controls, purchasing, production, and servicing all live.

7.1 Planning of Product Realization is where ISO 13485 explicitly requires documented risk management processes within product realization, with records maintained throughout. The clause’s note points readers to ISO 14971 for further guidance on structuring that risk management activity — it’s a reference, not a formal incorporation, though in practice most organizations end up using ISO 14971’s framework to satisfy this requirement.

7.3 Design and Development is one of the sub-clauses most commonly identified as non-applicable by contract manufacturers who don’t design product — but where it applies, it can’t be excluded lightly, and the justification has to hold up to the same Clause 4.2.2 scrutiny as any other exclusion. If it applies to you, this is the densest technical section of the standard: design inputs, outputs, review, verification, validation, transfer, and change control, each with its own documented evidence trail. Most common finding: design changes made without running them back through the full verification/validation cycle, especially late in development when schedule pressure is highest.

7.4 Purchasing requires supplier evaluation criteria proportionate to risk, and re-evaluation triggers when supplier performance changes. 7.5 Production and Service Provision covers process validation for anything that can’t be fully verified by downstream inspection — sterilization is the textbook example, which is why it gets its own dedicated body of standards. 7.6 Control of Monitoring and Measuring Equipment ties directly into your calibration program.

If you are under customer or FDA pressure to show design control maturity quickly → prioritize closing out 7.3 documentation gaps before anything else in this clause. In my experience, it’s one of the first sections a regulatory reviewer or auditor asks to see in depth.


Clause 8: Measurement, Analysis and Improvement

Clause 8 is where the QMS proves it’s actually working — and where CAPA lives.

8.2 Monitoring and Measurement covers feedback, complaint handling, and internal audit. Complaint handling under this clause has to interface with FDA’s separate adverse-event reporting requirements — a complaint that may represent a reportable event under Medical Device Reporting (21 CFR Part 803) can’t remain solely an internal QMS record; it has to be evaluated independently against those reporting obligations.

8.3 Control of Nonconforming Product requires documented procedures for identifying, segregating, and dispositioning nonconforming product, including for product discovered nonconforming after delivery — which is where recall-adjacent procedures connect back into the standard.

8.5 Improvement is where corrective and preventive action requirements sit. CAPA under ISO 13485 requires root cause investigation, verification that the action taken was effective, and — a detail I’ve seen auditors check for specifically — evidence that you evaluated whether the same nonconformity could exist elsewhere in the organization before closing the CAPA. A CAPA record that fixes one instance without documenting that broader check is incomplete by this clause’s own standard, regardless of whether the immediate fix worked.

For a deeper breakdown of this clause specifically, see our full guide to CAPA requirements in ISO 13485.


Where ISO 13485 and FDA’s QMSR Overlap by Clause

FDA’s Quality Management System Regulation took effect February 2, 2026, incorporating ISO 13485:2016 by reference into 21 CFR Part 820. That’s the headline most coverage stopped at. What matters more for how you prepare is what happened on the inspection side the same day: FDA retired the Quality System Inspection Technique (QSIT), the inspection methodology it had used since 1999, and replaced it with a new compliance program manual — CP 7382.850, Inspection of Medical Device Manufacturers.

ISO 13485 clauses explained through the 2026 FDA QMSR inspection framework, including six QMS Areas and four OAFRs
ISO 13485 clauses explained in the context of the FDA QMSR and CP 7382.850 inspection framework effective February 2, 2026.

QSIT organized inspections around four subsystems. CP 7382.850 reorganizes them around six QMS Areas, each mapped to ISO 13485 clauses with FDA-specific requirements layered in:

  • Management Oversight — the QMS itself, management review, the medical device file, and product realization planning
  • Design and Development — design inputs, outputs, review, verification, validation, software validation, and transfer
  • Production and Service Provision — production planning, process validation, and servicing
  • Measurement, Analysis, and Improvement — complaint handling, feedback, internal audits, corrective and preventive action, and control of nonconforming product
  • Outsourcing and Purchasing — supplier evaluation and control
  • Change Control — how changes to product or process are managed and documented

Alongside the six QMS Areas, inspections also evaluate four Other Applicable FDA Requirements (OAFRs) that sit outside ISO 13485’s text entirely: Medical Device Reporting (21 CFR Part 803), Corrections and Removals reporting (21 CFR Part 806), Medical Device Tracking (21 CFR Part 821), and Unique Device Identification (21 CFR Part 830). This is where the clause structure above stops covering everything — these four areas are FDA-specific regulatory obligations, not ISO 13485 requirements. They’re evaluated during routine surveillance, compliance follow-up, and PMA postmarket inspections; a narrow exception can apply to certain PMA preapproval inspections when the manufacturer hasn’t yet introduced the device to the U.S. market.

The change that affects Clause 5 most directly: under the prior QSR, management review records were categorically exempt from FDA review under §820.180(c). Under CP 7382.850, that exemption is gone. Management review now sits squarely inside the Management Oversight QMS Area, and an investigator can ask to see it — which means the twelve required Clause 5.6.2 inputs covered above aren’t just a certification-audit concern anymore.

One caution worth stating plainly: ISO 13485 certification and FDA QMSR compliance are related but not identical. A QMS built cleanly against Clauses 4 through 8 covers the ISO 13485 core that QMSR incorporates, but it doesn’t automatically satisfy the four OAFRs — those require their own documented processes regardless of how strong your clause-by-clause QMS is.

If you’re not sure whether your current documentation satisfies both frameworks → our FDA QSR vs ISO 13485 comparison and MDSAP vs ISO 13485 breakdown both walk through this in more detail than fits here.

ISO 13485 vs ISO 9001: Same Numbers, Different Weight

ElementISO 13485:2016ISO 9001:2015
Structure8 clauses, own structure (not Annex SL)10 clauses, Annex SL high-level structure
Risk managementDocumented risk management required in product realization (7.1); note references ISO 14971Risk-based thinking, less prescriptive
Customer satisfaction monitoringNo direct ISO 9001-style requirement; feedback/complaints addressed via Clause 8.2Explicit requirement (Clause 9.1.2)
DocumentationMedical device file required (Clause 4.2)No equivalent requirement
Design controlsDetailed, mandatory unless justified exclusionLess detailed by comparison
Regulatory linkDirectly referenced in FDA QMSR (21 CFR 820)Not tied to a specific regulation

The clause numbers look similar enough to cause real confusion — both standards use “Clause 7” for a large operational section, but the content underneath diverges substantially. If your organization holds both certifications, don’t assume a clause 7 audit finding under one standard tells you anything about your standing under the other. For the full comparison, see ISO 9001 vs ISO 13485.

The objection I hear most on this topic: “We’re already ISO 9001 certified — how much of this is actually new work?” Realistically, expect Clauses 5 and 6 to require the least rework, since management responsibility and resource management overlap heavily in intent. Clauses 4, 7, and 8 are where the medical device-specific requirements add real documentation and process work — the medical device file, design control rigor, and CAPA’s broader-impact evaluation aren’t things a general ISO 9001 QMS already has built in.


Most teams don’t fail an ISO 13485 audit because they misunderstood a clause. They fail because they assumed a documented procedure was enough without checking whether it actually produces the evidence an auditor will ask to see.

👉 Run a structured check before that assumption gets tested in front of an auditor → ISO 13485 Gap Assessment Checklist


Quick Clause Reference Checklist

A clause tells you what’s required. It doesn’t tell you what to hand an auditor when they ask for proof. Below is a quick translation — clause by clause, requirement to evidence.

ISO 13485 clauses explained through an audit evidence checklist showing objective evidence for Clauses 4, 5, 7, and 8
ISO 13485 clauses explained through the objective evidence auditors may review for Clauses 4, 5, 7, and 8.

✅ Clause 4 — QMS scope defined, outsourced processes controlled, medical device file assembled
✅ Clause 5 — Quality policy documented, management review covering all required inputs
✅ Clause 6 — Competence records current, contamination controls documented where applicable
✅ Clause 7 — Risk management documented within product realization; ISO 14971 provides further guidance; design control records complete, supplier evaluation criteria defined
✅ Clause 8 — Complaint handling tied to regulatory reporting, CAPA records show broader-impact evaluation

⚠️ Clauses 1–3 — Exclusions and non-applicability justified in the quality manual, not just left blank

For implementation sequencing beyond the checklist above, our ISO 13485 Implementation Roadmap and ISO 13485 Gap Assessment: Step-by-Step Guide walk through the order to tackle these in.


FAQ

How many clauses does ISO 13485:2016 have?

Eight. Clauses 1 through 3 are introductory and carry no auditable requirements. Clauses 4 through 8 contain the substantive quality management system requirements that certification bodies audit against — and since February 2026, FDA investigators evaluate the same core requirements under Compliance Program 7382.850.

Does ISO 13485 follow the same structure as ISO 9001?

No. ISO 13485 does not use ISO’s Annex SL high-level structure, which ISO 9001, ISO 14001, and ISO 45001 all share. The technical committee kept ISO 13485 independent specifically to protect regulatory stability for device manufacturers, so clause numbers that look similar between the two standards often cover different scope.

Can I exclude clauses from ISO 13485?

Only with documented justification. Under Clause 4.2.2, the scope and justification for any exclusion or non-application have to be recorded in the quality manual, and you need to be prepared to defend that justification during an audit.

Which ISO 13485 clause covers risk management?

Clause 7.1 (Planning of Product Realization) is where documented risk management is explicitly required, and its note points to ISO 14971 for further guidance. But risk-related requirements aren’t confined to one clause — they surface throughout Clauses 4 through 8 rather than sitting in a single isolated section.

What’s the difference between ISO 13485 and the FDA’s QMSR?

As of February 2, 2026, FDA’s QMSR incorporates ISO 13485:2016 by reference into 21 CFR Part 820, and FDA’s inspection methodology changed to match — Compliance Program 7382.850 replaced QSIT the same day. The two frameworks are far more tightly aligned than before, but they’re not identical: four Other Applicable FDA Requirements (Medical Device Reporting, Corrections and Removals, Medical Device Tracking, and UDI) sit outside ISO 13485’s text and are evaluated in applicable inspection types, with a limited exception for certain PMA preapproval inspections when the device has not yet been introduced to the U.S. market.

What is CP 7382.850?

CP 7382.850 (Inspection of Medical Device Manufacturers) is FDA’s current compliance program manual for device inspections, effective February 2, 2026 alongside the QMSR. It replaced the Quality System Inspection Technique (QSIT) and reorganizes inspections around six QMS Areas — Management Oversight, Design and Development, Production and Service Provision, Measurement/Analysis/Improvement, Outsourcing and Purchasing, and Change Control — plus four Other Applicable FDA Requirements evaluated in most inspection types.

Do I need to buy ISO 9001 to understand ISO 13485’s terminology?

You don’t need to purchase it, but ISO 13485 does reference ISO 9000:2015 for its terms and definitions, and auditors expect consistent use of that vocabulary in your documentation.

Which clauses deserve the closest audit preparation?

In practice, Clause 4.2 (documentation control), Clause 7.3 where applicable (design and development), and Clause 8.5 (CAPA effectiveness) tend to draw sustained attention, largely because each requires ongoing documented evidence rather than a one-time procedure. The exact focus varies by organization, device type, and regulatory scope — under the current FDA inspection framework, Management Oversight and Measurement, Analysis, and Improvement are evaluated on every inspection regardless of device type.

Is a documentation kit enough to get ISO 13485 clause requirements right?

A kit gives you a starting structure, but clause-by-clause compliance depends on evidence specific to your processes — training records, design and development records, CAPA effectiveness checks. Our ISO Documentation Kits for Manufacturers page breaks down what a kit does and doesn’t cover.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching how the clauses fit together? Start with What Is ISO 13485? for the foundational overview before working through this clause breakdown a second time.

🔹 Ready to assess where your QMS actually stands? Run the ISO 13485 Gap Assessment Checklist against the clause list above — it’s built to map directly to Clauses 4 through 8.

🔹 Need the official standard text to cite exact clause language? Purchase ISO 13485:2016 through ANSI Webstore — use code CC2026 for 5% off through December 31, 2026. International-language editions are available for teams managing documentation across multiple regulatory regions.

🔹 Need your internal auditors trained on this clause structure before your next surveillance audit? ISO 13485 training through BSI Group covers the structure clause by clause with a certification body’s own instructors.

The Standards Navigator breaks down what these clauses actually demand — not just what they’re titled — so your team can walk into an audit knowing which sub-clause the finding will land on before it does.


Stay Ahead of Clause-Level Changes

Most QMS documentation doesn’t fail because a team ignored ISO 13485. It fails because someone mapped a procedure to the wrong clause once, early on, and every review since has confirmed the wrong thing.

Organizations that treat the clause structure above as a living reference — checked against actual audit findings, updated as FDA’s QMSR enforcement approach becomes clearer — walk into surveillance audits with far fewer surprises than organizations treating their quality manual as a document they wrote once and filed away.

The Standards Navigator tracks ISO 13485, QMSR, and the surrounding medical device standards landscape as they develop, not just at certification time.

👉 Get updates on ISO 13485 and medical device QMS requirements
👉 Be first to access new gap assessment tools and clause-mapping resources

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

ISO 13485 Gap Assessment: A Step-by-Step Guide for Medical Device Manufacturers (2026)

Learn how to run an ISO 13485 gap assessment step by step — from scoping and clause mapping to grading findings and building a remediation timeline before your certification audit.

How to run an ISO 13485 gap assessment before your certification body ever sees your QMS.

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Gap Assessment Is the Step Most Manufacturers Skip

Many manufacturers don’t discover their biggest ISO 13485 gaps until they systematically compare their QMS against the standard.

An ISO 13485 gap assessment gives you a structured way to find those gaps before your certification body does. It’s a clause-by-clause comparison of your current quality management system against what ISO 13485:2016 actually requires — and it’s one of the highest-leverage steps between “we think we’re ready” and “we’re ready for Stage 1.”

This guide walks through the gap assessment process step by step: how to scope it, how to run it, how to grade what you find, and how to turn the results into a remediation plan your team can actually execute before your audit window opens.

From the Floor: As a certified ISO 9001 Internal Auditor, the pattern I see most often in gap assessments — regardless of which standard is on the cover — is a QMS that has real documentation but no clause map. Procedures exist. Records exist. But nobody has walked the standard clause by clause and confirmed each requirement actually has evidence behind it. That’s exactly what a gap assessment is designed to expose, and finding it internally gives your team more control over the remediation timeline than discovering it during certification.

Before you build a remediation plan, you need to know where the gaps actually are. Run the free ISO 13485 Gap Assessment Checklist and get a clause-by-clause starting point for your own QMS.


In This Guide

  • What an ISO 13485 gap assessment actually is, and how it differs from an internal audit
  • The eight-step process, from scoping to remediation
  • How to grade findings so your team knows what to fix first
  • A readiness checklist for what “gap-assessed” should actually mean
  • Answers to the questions manufacturers ask most before their first assessment


👉 Start Here (Top Resources)

  • Own the standard you’re assessing against: ISO 13485:2016 — ANSI Webstore — you can’t run an accurate gap assessment without the current clause text in front of you. Use code CC2026 for 5% off through December 31, 2026.
  • Close the gaps once you find them: 9001Simplified — documentation kits built for manufacturers who need to build or rebuild QMS documentation without hiring a full-time consultant.
  • Get your team trained on the requirements before they run the assessment: ISO 13485 Training — BSI Group — a team that understands the clause structure finds gaps faster and more accurately than one working from intuition.

What an ISO 13485 Gap Assessment Actually Is

A gap assessment is not an audit. It’s not a certification activity, and no external party has to be involved. It’s an internal, structured comparison: for every requirement in ISO 13485:2016, does your QMS have documented evidence that requirement is met — and if not, how far off is it?

That distinction matters because it changes the tone of the exercise. An internal audit (covered in our guide on how to audit a medical device QMS) assumes a QMS is largely built and tests whether it’s being followed. A gap assessment assumes nothing — it’s asking “does this exist at all, and if it does, is it complete.”

Gap Assessment vs. Internal Audit

Gap AssessmentInternal Audit
Primary questionDoes the requirement and supporting evidence exist?Is the QMS being followed and operating effectively?
Typical timingOften performed during QMS development or transitionPerformed as part of the established audit program
Main outputGap list and remediation planAudit findings and corrective action
Evidence examinedDocuments, records, and implementation evidenceProcess implementation, records, and objective evidence
PurposeIdentify what needs to be built, changed, or strengthenedEvaluate conformity and implementation of the established QMS

Quick Answer

QuestionQuick Answer
Is a gap assessment required for ISO 13485 certification?No. It’s not a formal requirement of the standard, but it’s a practical risk-reduction step manufacturers can use to identify gaps before a certification audit.
How long does a gap assessment take?As a planning estimate, a single-site manufacturer with an existing QMS might spread the assessment across roughly 2–4 weeks of part-time effort. Actual duration varies significantly with QMS maturity, scope, number of sites, product lines, and team availability.
Can I do a gap assessment myself, or do I need a consultant?You can do it yourself with a structured checklist and a working knowledge of the standard. Consultants add value for complex or first-time QMS builds, but the assessment itself doesn’t require outside certification.
What’s the difference between a gap assessment and an internal audit?A gap assessment checks whether documentation and evidence exist against each clause. An internal audit checks whether an existing, documented QMS is actually being followed in practice.

The Eight-Step Gap Assessment Process

Step 1: Define Scope and Assemble Your Team

Before you open the standard, decide what’s actually in scope. Which sites? Which product lines? Which regulatory markets — because that determines which country-specific requirements layer on top of the ISO 13485 baseline. If you’re weighing whether MDSAP applies to your assessment scope, our MDSAP vs ISO 13485 guide walks through that decision separately.

Assemble a small cross-functional team — quality, at minimum, plus whoever owns design, production, and supplier management. A gap assessment run entirely by one person in the quality department tends to miss operational gaps that only show up on the floor.

Step 2: Gather Current QMS Documentation

Pull everything: your quality manual, procedures, work instructions, forms, records, and any prior audit findings — internal or external. If your document control system is disorganized, this step alone often reveals your first gap. See our guide on ISO 13485 documentation requirements for what a complete document set should include.

Step 3: Build Your Clause Map

At a high level, ISO 13485:2016 organizes its requirements across five main clause groups: Quality Management System (Clause 4), Management Responsibility (Clause 5), Resource Management (Clause 6), Product Realization (Clause 7), and Measurement, Analysis and Improvement (Clause 8). Build a simple matrix — clause number down one side, your corresponding procedure or record down the other. Anywhere that cell is blank is your first visible gap, before you’ve even started evaluating quality.

ISO 13485 gap assessment clause map connecting requirements to procedures, records, and objective evidence
An ISO 13485 gap assessment clause map connects each requirement to the corresponding QMS procedure, work instruction, records, and objective evidence.

Step 4: Walk Each Clause Against the Evidence

This is the core of the assessment. For each clause, ask three questions: Does a documented procedure exist? Does it match what the standard actually requires — not just what sounds similar? And is there objective evidence (records, forms, logs) that the procedure is being followed, not just written?

CAPA is worth flagging specifically here because it requires the team to connect nonconformance, root cause, corrective action, and effectiveness verification across the QMS. Our breakdown of CAPA requirements under ISO 13485 covers what auditors expect to see connected — traceable within the QMS rather than reconciled manually across separate systems.

This is often where gap assessments slow down because the work is tedious, not because it’s conceptually difficult. If your team needs a structured starting point instead of building the clause matrix from scratch → Run the free ISO 13485 Gap Assessment Checklist.

ISO 13485 gap assessment showing how procedures, records, and objective evidence demonstrate QMS conformity
An ISO 13485 gap assessment should verify not only that procedures exist, but that records provide objective evidence the QMS is being followed.

Step 5: Grade Each Finding

Not every gap carries the same weight. A missing signature on a training record is not the same category of problem as a design control process that doesn’t exist. Grade findings on a simple scale:

  • Critical — the requirement is effectively absent. No procedure, no evidence, no compensating control.
  • Major — a procedure exists but has a significant gap against the clause requirement, or evidence of following it is inconsistent.
  • Minor — the procedure and evidence both exist, but execution has small, correctable inconsistencies.

Grading matters because it drives sequencing. These labels are an internal prioritization framework, not ISO 13485-defined finding classifications — the exact grading terminology and criteria used by a certification body or regulatory program can vary. For an internal assessment, the important thing is to apply your criteria consistently so the team knows which gaps require immediate attention.

Step 6: Prioritize Remediation

Start with the gaps that present the greatest risk to QMS conformity or product and regulatory compliance. In most cases, that means addressing foundational gaps such as a missing design-control process or nonexistent CAPA system before working through lower-risk administrative issues. Major findings come next, typically grouped by clause area so one person or team can work through related gaps together rather than jumping between unrelated processes.

If you are rebuilding documentation from a critical or major finding → start with the clause itself, not a generic template. A procedure written to satisfy a checklist item without matching your actual process creates a new gap the moment an auditor asks a follow-up question.

If you are working through a backlog of minor findings → batch them by owner and set a single close-out date rather than tracking dozens of individual deadlines. Minor findings left open individually tend to get lost; batched with a deadline, they get closed.

Step 7: Build a Remediation Timeline

Attach real dates to every finding, not target quarters. Critical findings should have the shortest timeline your team can realistically execute — these are the gaps most likely to create significant problems during a certification assessment if they remain unresolved. Build in a buffer before your target certification audit date; remediation almost always takes longer than the first estimate, especially where a new procedure requires training staff to actually follow it.

Step 8: Re-Assess Before You Schedule Your Audit

A gap assessment isn’t a one-time snapshot. Once remediation work closes out your critical and major findings, re-walk those specific clauses to confirm the fix actually holds — not just that a document was updated, but that the evidence trail behind it exists. This is also the point where many manufacturers benefit from a full internal audit as a final check before scheduling Stage 1.


Common Mistakes That Undermine a Gap Assessment

Treating the assessment as a documentation review only. Confirming a procedure exists isn’t the same as confirming it’s followed. A gap assessment that never looks at records — training logs, CAPA files, supplier evaluations — will miss exactly the kind of gap an auditor finds first, because auditors ask for objective evidence, not just the procedure. Our guide on common mistakes in ISO 13485 QMS implementation covers this pattern in more depth.

Assessing against an old edition of the standard. ISO 13485:2016 is the current edition, but manufacturers working from a QMS built years ago sometimes have procedures written against superseded clause numbering. Confirm you’re assessing against the current published text before you start building your clause matrix.

Skipping the connection to FDA’s QMSR. If you sell into the United States, consider whether your gap assessment also needs to address FDA’s QMSR requirements and inspection expectations — FDA’s QMSR, effective February 2, 2026 and incorporating ISO 13485:2016 by reference, expanded what FDA can review during an inspection. Records that were previously exempt from routine inspection under the legacy QSR — management review, internal quality audit, and supplier audit records — are not exempt under QMSR. That’s worth building into your assessment scope rather than assuming an ISO 13485-only assessment automatically covers it.


Gap Assessment Readiness Checklist

✅ Scope defined — sites, product lines, and regulatory markets confirmed
✅ Cross-functional team assembled, not just quality department staff
✅ Full current QMS documentation set gathered and organized
✅ Clause matrix built against ISO 13485:2016, Clauses 4 through 8
✅ Each clause walked against both procedure and objective evidence, not procedure alone
✅ Findings graded — critical, major, minor — using consistent criteria
✅ Remediation timeline built with real dates, prioritized by severity
✅ Critical and major findings re-assessed after remediation, before scheduling your audit

ISO 13485 gap assessment process showing how manufacturers find, prioritize, remediate, and re-assess QMS gaps before certification
An ISO 13485 gap assessment turns identified QMS gaps into a prioritized remediation plan, followed by verification and re-assessment before the certification audit.

Frequently Asked Questions

Is a gap assessment required before ISO 13485 certification?

No. It’s not a formal requirement in the standard itself. It’s a risk-reduction step manufacturers use to avoid discovering major or critical nonconformities for the first time during an actual certification audit, where findings can delay certification.

How is a gap assessment different from an internal audit?

A gap assessment asks whether documentation and evidence exist at all against each clause — it’s typically run once, early, often before a QMS is fully built out. An internal audit assumes a documented QMS exists and tests whether it’s actually being followed in day-to-day operation. A common approach is to run the gap assessment first, then use internal audits on a recurring schedule once the QMS is established.

Who should be involved in a gap assessment?

At minimum, someone from quality who knows the standard well enough to interpret clause intent, plus representation from any function the clauses touch directly — design, production, supplier management. A single-person assessment tends to miss operational gaps that only surface when someone from outside quality reviews the finding.

How long does a gap assessment typically take?

As a planning estimate, a manufacturer with an existing QMS and a single site in scope might spread the assessment across roughly 2–4 weeks of part-time effort. Actual duration varies significantly with QMS maturity, scope, number of sites, product lines, and team availability — manufacturers building a QMS from scratch, or with multiple sites in scope, should expect it to take longer.

Can I use the same gap assessment for MDSAP readiness?

Largely, yes — MDSAP audits use ISO 13485:2016 requirements alongside applicable regulatory requirements from participating authorities, so a thorough ISO 13485 gap assessment covers most of the same ground. MDSAP layers those country-specific regulatory requirements on top of the ISO 13485 baseline, so if MDSAP is in scope, your assessment should also map those additional requirements. See our MDSAP vs ISO 13485 guide for how the two relate.

What happens if I find a critical gap close to my planned audit date?

Push the audit date. Scheduling a certification audit around a known critical gap doesn’t make the gap disappear — it moves the risk of discovering that gap into the certification audit, where the certification body will determine whether the issue constitutes a nonconformity and how it should be classified, instead of remaining an internal finding you controlled the timeline on.

Do I need a consultant to run a gap assessment?

Not necessarily. A structured checklist and a working knowledge of the standard’s clause structure is enough for most single-site manufacturers with an existing QMS. Consultants add the most value for first-time QMS builds, multi-site assessments, or situations where the internal team lacks bandwidth to run the assessment alongside daily operations.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still figuring out where your QMS stands? Start with the ISO 13485 Gap Assessment Checklist — it’s the fastest way to see your clause-by-clause starting point before you build a full remediation plan.

🔹 Ready to close documentation gaps you’ve already identified? 9001Simplified’s documentation kits are built for manufacturers assembling or rebuilding QMS documentation without a full-time consultant.

🔹 Need to confirm your clause matrix against the current standard? Get ISO 13485:2016 from ANSI Webstore — code CC2026 takes 5% off through December 31, 2026.

🔹 Want your team trained before they run the assessment? BSI Group’s ISO 13485 training builds the clause knowledge that makes a gap assessment faster and more accurate.

Treating a gap assessment as a formality can leave significant gaps undiscovered until the certification audit. A properly executed assessment gives your team an opportunity to find those gaps internally, assign ownership, and control the remediation timeline before the certification audit begins. The Standards Navigator will keep this guide current as ISO 13485 and its related regulatory frameworks continue to evolve.


Stay Ahead of Your Next Audit Cycle

Skipping the gap assessment step doesn’t remove the risk of undiscovered gaps — it increases the chance that a gap will first be identified during the certification process, in front of an auditor, where the certification body determines whether it constitutes a nonconformity. Running it properly moves that discovery earlier, onto your own timeline, with your team in control of the fix.

The Standards Navigator tracks how ISO 13485, MDSAP, and FDA’s QMSR continue to shift so your QMS doesn’t fall behind a requirement you didn’t know had changed.

👉 Get updates on ISO 13485 requirements and medical device compliance as they happen
👉 Be first to access new gap assessment tools and documentation resources as we build them

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

MDSAP vs ISO 13485: What’s the Difference and Do You Need Both in 2026?

MDSAP and ISO 13485 are often confused, but they answer different questions. This guide breaks down how the MDSAP audit program relates to the ISO 13485:2016 standard, what changed with FDA’s 2026 QMSR, and which manufacturers actually need MDSAP registration.

Whether the MDSAP consolidated audit program adds real value to your QMS — or scope you don’t need yet.

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Two Audits, One QMS Standard — and a Decision Most Manufacturers Get Wrong

MDSAP vs ISO 13485 is a distinction worth getting right before you scope an audit program: these are not competing options, and they are not two paths to the same certificate. Treating them as interchangeable is exactly how manufacturers end up either over-auditing themselves or discovering — mid-application — that a market they assumed was covered isn’t.

If you sell into more than one of the five MDSAP countries, this decision affects your audit calendar, your registrar spend, and your regulatory submission timeline for years. If you sell only into the EU or UK, most of what follows doesn’t apply to you at all — and that’s worth knowing before you spend a quarter evaluating a program you don’t need.

This guide breaks down exactly what MDSAP is, how it relates to ISO 13485:2016, and — now that the FDA’s Quality Management System Regulation has replaced the legacy 21 CFR Part 820 — what changed for US-market manufacturers in 2026.

From the Floor: With 25+ years in heavy industrial manufacturing and a certified ISO 9001 Internal Auditor credential, I’ve seen the same regulated-QMS failure pattern show up regardless of which standard is on the cover — 9001 or 13485. It’s not missing documentation. It’s documentation that exists but doesn’t connect: a CAPA log that references a nonconformance report that was never actually closed out in the corrective action file. Stack five regulatory authorities’ expectations on top of each other instead of one, and that gap can become a nonconformity that appears in the MDSAP audit record used by the participating Regulatory Authorities.

Before you evaluate MDSAP, confirm your QMS actually conforms to ISO 13485:2016 first — MDSAP audits against it, it doesn’t substitute for it. Run the free ISO 13485 Gap Assessment Checklist and see exactly where your documentation stands before you add audit scope on top of it.

In This Guide

  • What MDSAP actually is, and how it relates to ISO 13485:2016
  • A side-by-side comparison of both frameworks
  • What changed in 2026 with the FDA’s QMSR and the revised MDSAP Audit Approach
  • Decision-stage signals for whether MDSAP applies to your business
  • What MDSAP costs — and what it saves — compared to separate country audits
  • Documentation issues that can create problems in MDSAP-scope audits
  • A readiness checklist and answers to the questions manufacturers ask most


👉 Start Here (Top Resources)

  • Own the standard MDSAP is built on: ISO 13485:2016 — ANSI Webstore — the foundation document every MDSAP audit is measured against. Use code CC2026 for 5% off through December 31, 2026.
  • Close documentation gaps before you’re audited on them: 9001Simplified — documentation kits built for manufacturers assembling or tightening a QMS without hiring a full-time consultant.
  • Get your team trained on the underlying requirements: ISO 13485 Training — BSI Group — BSI is one of the Auditing Organizations recognized under MDSAP, and their training builds the ISO 13485 foundation your audit is scored against.

What Is ISO 13485, and What Is MDSAP Built on Top Of It?

ISO 13485:2016 is the quality management system standard for medical device manufacturers. It’s a standalone document you can certify to on its own — covered in detail in our What Is ISO 13485 guide.

MDSAP (Medical Device Single Audit Program) is not a standard. It’s a regulatory audit program. Five participating Regulatory Authorities — Australia’s TGA, Brazil’s ANVISA, Health Canada, Japan’s MHLW/PMDA, and the U.S. FDA — use a single consolidated audit, conducted by an MDSAP-recognized Auditing Organization, to assess the applicable QMS and regulatory requirements across participating markets, rather than requiring separate audits from each regulator. That audit is scored against ISO 13485:2016 as the baseline, with country-specific regulatory requirements layered on top for each market a manufacturer participates in.

Standalone ISO 13485 certification, by contrast, is issued by certification bodies accredited through national accreditation bodies — in the US, that’s typically ANAB. MDSAP Auditing Organizations go through a separate recognition process run directly by the participating Regulatory Authorities, not through the standard accreditation pathway.

In plain terms: ISO 13485 is what you’re audited against. MDSAP is who accepts that audit, and how many regulators it satisfies at once.


Quick Answer

QuestionQuick Answer
Is MDSAP the same as ISO 13485?No. MDSAP is a multi-country regulatory audit program built on top of ISO 13485:2016 — it doesn’t replace the standard, it audits against it plus country-specific requirements.
Do I need ISO 13485 certification before MDSAP?No. Your QMS must conform to ISO 13485:2016, but you don’t necessarily need a separate ISO 13485 certificate before undergoing an MDSAP audit — the MDSAP audit itself assesses that conformance.
Is MDSAP required?Only for Class II–IV Canadian market access. In the other participating MDSAP markets, participation is generally voluntary, although it can consolidate applicable regulatory assessments across multiple markets.
Does MDSAP replace FDA inspections entirely?No. MDSAP audit results can be used by FDA within its regulatory program, but FDA retains its authority to conduct inspections, including for-cause inspections.

MDSAP vs ISO 13485: Side-by-Side

CategoryISO 13485:2016MDSAP
What it isA quality management system standardA multi-jurisdiction regulatory audit program
BasisStandalone documentBuilt on ISO 13485:2016 plus country-specific regulatory requirements
Who administers itCertification bodies accredited by ANAB or an equivalent accreditation bodyAuditing Organizations recognized by the five participating Regulatory Authorities
Countries coveredGlobal — recognized wherever ISO 13485 certification is acceptedAustralia, Brazil, Canada, Japan, United States
Can you buy it?Yes — it’s a purchasable standard documentNo — it’s an audit program, not a document
Mandatory?Often required by customers, notified bodies, or regulators (EU MDR, for example)Mandatory only for Class II–IV Canadian market access; voluntary elsewhere
Audit frequencyPer your certification body’s surveillance schedule — typically annualInitial audit followed by annual surveillance audits within the certification cycle
What you getAn ISO 13485 certificateAn MDSAP certification document and audit report each participating Regulatory Authority can use within its own regulatory program

For the broader question of how ISO 13485 stacks up against the standard most manufacturers compare it to first, see ISO 9001 vs ISO 13485.


The 2026 Regulatory Shift: QMSR and the Revised MDSAP Audit Approach

MDSAP vs ISO 13485 infographic showing the 2026 FDA QMSR transition and changes to medical device quality records
MDSAP vs ISO 13485: The 2026 FDA QMSR aligns U.S. medical device quality requirements with ISO 13485:2016 and changes FDA access to management review, internal audit, and supplier audit records.

Two changes landed in 2026 that directly affect this comparison.

On February 2, 2026, the FDA’s Quality Management System Regulation (QMSR) officially took effect, replacing the legacy 21 CFR Part 820 Quality System Regulation and incorporating ISO 13485:2016 by reference. That doesn’t make US manufacturers MDSAP-compliant automatically — it means the US regulatory baseline now speaks the same structural language as ISO 13485, closing a gap that used to require manufacturers to maintain two separate documentation logics. We cover the mechanics of that shift in FDA QSR vs ISO 13485.

The QMSR also removed a long-standing FDA inspection exemption. Under the prior QSR, §820.180(c) shielded management review records, internal quality audit reports, and supplier audit reports from routine FDA inspection. The QMSR eliminates that exemption entirely — FDA’s own QMSR FAQ confirms investigators now have authority to review management review, quality audit, and supplier audit records as part of a standard inspection. For manufacturers who treated those records as internal-only, that’s a meaningful shift in what “audit-ready” documentation needs to look like.

Around the same window, the MDSAP Regulatory Authority Council released a revised Audit Approach document (MDSAP AU P0002.010), updating the audit sequence and process guidance auditors use during MDSAP assessments. If your last MDSAP audit was conducted under the prior version, don’t assume your documentation package is still current against the revised approach — verify against the current edition before your next audit window.

It can be tempting to assume that QMSR compliance automatically covers MDSAP scope. It doesn’t — QMSR alignment closes the gap between the US baseline and ISO 13485, but MDSAP still layers the applicable regulatory requirements of each participating jurisdiction on top of that baseline. Check where your QMS actually stands before you assume you’re covered → Run the ISO 13485 Gap Assessment Checklist.


Do You Need MDSAP? Decision-Stage Signals

  • If you are selling only into the EU or UK → you still need to meet the applicable medical-device QMS and conformity-assessment requirements for those markets, but MDSAP is not generally required there.
  • If you are selling into Canada at Class II, III, or IV → MDSAP is mandatory. Health Canada requires an MDSAP certificate, issued by a recognized MDSAP Auditing Organization, as part of the device license application.
  • If you sell into several of the five MDSAP countries → compare the cost and disruption of MDSAP against the separate regulatory assessments that would otherwise apply. Three or more can be a useful practical threshold for comparison, but the right number depends on your specific audit costs, inspection history, device scope, and market plans.
  • If you are already ISO 13485 certified and sell only into the US → weigh MDSAP against your actual FDA inspection frequency and any near-term expansion plans before adding audit scope you may not need yet.
MDSAP decision flowchart showing when medical device manufacturers need MDSAP for Canada and when it is generally voluntary in other markets
A practical MDSAP decision guide showing when certification is required for Canadian Class II–IV devices and when manufacturers should evaluate MDSAP based on market scope, audit costs, and regulatory strategy.

What MDSAP Actually Costs You — And What It Saves

The most common objection we hear is straightforward: MDSAP audits cost more than a standard ISO 13485 surveillance audit, so why add the expense?

That’s true in isolation — an MDSAP audit typically runs longer and costs more per audit day than a single-standard ISO 13485 surveillance visit, because the auditor is assessing conformance to multiple regulatory frameworks in one visit. But the comparison that matters isn’t MDSAP audit cost versus ISO 13485 audit cost. It’s MDSAP audit cost versus the combined cost of separate inspections from Health Canada, ANVISA, TGA, and PMDA, run independently, on different schedules, each requiring separate audit prep. For manufacturers selling across several MDSAP markets, the consolidation can make the overall audit program less costly and less disruptive than managing multiple separate regulatory assessments — but the business case depends on device classification, facility count, audit scope, your Auditing Organization, and your existing inspection cadence, so get a scoped quote rather than budgeting off a generic number.

Manufacturers building out documentation to support a broader audit scope shouldn’t be doing it from scratch. If your QMS documentation isn’t structured to hold up under multiple regulatory frameworks at once, that’s the gap to close first → 9001Simplified’s documentation kits are built for exactly this kind of consolidation work.


Documentation Issues That Can Create Problems in MDSAP Readiness

One area worth checking closely is CAPA traceability. CAPA records should connect clearly to the underlying nonconformance, investigation, corrective action, and effectiveness evidence, rather than leaving the auditor to reconcile separate systems manually — see our breakdown of common mistakes in ISO 13485 QMS implementation and the full CAPA requirements under ISO 13485 for what auditors expect to see connected.

Another area to review is how regulatory requirements are mapped into the QMS. MDSAP audits ISO 13485 alongside applicable jurisdiction-specific requirements, so documentation that only reflects one regulator’s language may need additional mapping before an MDSAP audit. Our guide on ISO 13485 documentation requirements covers how to structure it correctly the first time.


MDSAP vs ISO 13485 readiness infographic showing CAPA traceability, document control, regulatory mapping, internal audits, and audit evidence
MDSAP vs ISO 13485: MDSAP readiness depends on connected evidence across CAPA, document control, regulatory mapping, internal audits, and market scope.

MDSAP Readiness Checklist

✅ QMS is currently certified — or verified compliant — to ISO 13485:2016
✅ CAPA records cross-reference nonconformance reports within the QMS itself, not a separate tracking tool
✅ Document control system is organized by ISO 13485 clause structure, not by individual regulator language
✅ You’ve confirmed which of the five MDSAP countries you actually sell into or plan to
✅ You’ve reviewed your documentation against the revised MDSAP Audit Approach (AU P0002.010)
✅ You’ve scoped audit cost and timeline with an MDSAP-recognized Auditing Organization
✅ Internal audit process already traces process interactions, not just individual clause compliance — see how to audit a medical device QMS


Frequently Asked Questions

Is MDSAP the same thing as ISO 13485?

No. ISO 13485:2016 is the quality management system standard. MDSAP is a regulatory audit program that assesses conformance to that standard, plus country-specific requirements from five participating Regulatory Authorities, in a single consolidated audit.

Do I need to be ISO 13485 certified before I can apply for MDSAP?

Your QMS needs to conform to ISO 13485:2016 — MDSAP auditors assess that conformance directly as part of the MDSAP audit itself. In practice, most manufacturers already hold or are pursuing ISO 13485 certification before entering the MDSAP process.

Which countries does MDSAP cover?

Five participating Regulatory Authorities: Australia (TGA), Brazil (ANVISA), Canada (Health Canada), Japan (MHLW/PMDA), and the United States (FDA). A number of other regulators participate as observers or affiliate members without full recognition of MDSAP audit results.

Is MDSAP required to sell medical devices in the United States?

No. The FDA accepts MDSAP audit results as part of its compliance program, and the 2026 QMSR incorporates ISO 13485:2016 by reference, but MDSAP participation itself remains voluntary for US-only manufacturers.

How did the FDA’s 2026 QMSR change affect MDSAP?

The QMSR, effective February 2, 2026, replaced 21 CFR Part 820 and incorporated ISO 13485:2016 by reference — narrowing the gap between US regulatory expectations and the ISO 13485 baseline that MDSAP already audits against. It doesn’t grant automatic MDSAP compliance; it changes what the US regulatory floor requires your documentation to look like.

How much does an MDSAP audit cost compared to a standard ISO 13485 audit?

MDSAP audits generally run longer and cost more per audit than a single-standard ISO 13485 surveillance audit, since the scope covers multiple regulatory frameworks in one visit. Pricing varies significantly by Auditing Organization, facility count, and audit scope — get a quote scoped to your specific situation rather than relying on a general figure.

Can a small manufacturer participate in MDSAP?

Yes. Any manufacturer with a product that falls under the scope of at least one participating Regulatory Authority may apply. It tends to make the most financial sense for manufacturers selling into several of the five MDSAP countries, where consolidating audits can produce clearer savings — though the exact threshold depends on your specific cost structure.

Does an MDSAP certificate replace my ISO 13485 certificate?

Not automatically, and it depends on the market. In Canada, the MDSAP certificate has replaced the standalone ISO 13485 certificate in the device license application process for Class II–IV devices. In most other participating markets, manufacturers typically maintain both, since ISO 13485 certification is often required independently by customers or notified bodies.


📥 Free Resources

  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements before pursuing MDSAP or standalone certification.
  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.
  • AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification.

Not Sure What to Do Next?

🔹 Still researching whether MDSAP applies to you? Start with the ISO 13485 Gap Assessment Checklist — confirm your QMS conforms to ISO 13485:2016 before you evaluate adding MDSAP scope on top of it.

🔹 Ready to close documentation gaps before your next audit? 9001Simplified’s documentation kits are built for manufacturers structuring a QMS to hold up under more than one regulatory framework at once.

🔹 Need to buy the ISO 13485:2016 standard itself? Get it directly from ANSI Webstore — code CC2026 takes 5% off through December 31, 2026.

🔹 Want your team trained on the requirements before your MDSAP audit? BSI Group’s ISO 13485 training builds the foundation MDSAP auditors score against.

MDSAP isn’t a bigger version of ISO 13485 certification — it’s a different question entirely: not “is your QMS compliant,” but “how many regulators can rely on the same answer.” Get that distinction right before you scope an audit program you may not need, or miss one you do. The Standards Navigator will keep tracking how MDSAP and the 2026 QMSR shift continue to interact as more guidance comes out.


Stay Ahead of the Next Regulatory Shift

Manufacturers who treat MDSAP as “extra paperwork” usually find out the hard way — mid-application, with a Canadian import deadline already on the calendar. Manufacturers who map their audit scope to their actual markets first spend less on audits and never scramble for a certificate they didn’t know they’d need.

The Standards Navigator tracks how ISO 13485, MDSAP, and FDA’s QMSR continue to shift against each other so you don’t have to monitor five regulators’ guidance pages yourself.

👉 Get updates on medical device compliance and regulatory changes as they happen
👉 Be first to access new gap assessment tools and documentation resources as we build them

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

ISO Training for AS9100, 13485 & 50001: Avoid Costly Gaps

ISO training for AS9100, ISO 13485, and ISO 50001 each demand a different course level, not one generic ISO training course. This guide breaks down who needs awareness, internal auditor, or lead auditor training for AS9100, ISO 13485, and ISO 50001 — plus where to get accredited training for each standard.

A role-by-role training pathway guide for aerospace, medical device, and energy management systems

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Training Gap Nobody Budgets For

If you’re looking for ISO training for AS9100, ISO training for ISO 13485, or ISO training for ISO 50001, you’ve probably already run into the problem: most ISO training is built for ISO 9001 and doesn’t translate cleanly to these three standards. Manufacturers get ISO 9001 training right, then add AS9100 for an aerospace contract, ISO 13485 for a medical device line, or ISO 50001 for an energy initiative — and send the same people to the same generic “ISO awareness” course they used for quality management.

That’s a mistake, and it shows up fast. AS9100 auditors expect your team to speak to AS9101 audit requirements and IAQG OASIS supplier expectations — not generic quality-speak. ISO 13485 auditors expect design controls and CAPA competency, not general QMS awareness. ISO 50001 auditors expect your team to understand energy performance indicators, not just environmental basics.

Each of these standards has its own competency requirement and its own training hierarchy — and AS9100 adds a formal auditor authentication scheme on top, though that scheme applies specifically to certification body auditors rather than every internal auditor. Sending the wrong person to the wrong course doesn’t just waste a training budget. It leaves a documented competence gap that shows up the moment an auditor interviews the person responsible for that system.

I’ve built training matrices from the ground up during ISO 9001 implementation at a 500-employee valve and energy manufacturing operation, and the lesson translates directly to every management system standard: auditors don’t just check whether training happened. They check whether the person trained can actually explain the requirement in their own words, in their own work area. A certificate on file means nothing if the person can’t demonstrate the competency behind it.

👉 If you’re building out training for a new standard, confirm where your system already stands before you spend on courses → Download the Manufacturing Compliance Checklist


Quick Answer: Which Training Level Do You Need?

Your RoleRecommended Training Level
Executive Sponsor / LeadershipAwareness
Quality Manager / System OwnerLead Implementer
Internal AuditorStandard-specific Internal Auditor course
Certification / Third-Party AuditorLead Auditor (with AS9104/3 authentication for AS9100)
Production Supervisor / Department HeadFoundation / Requirements-level
Shop Floor / All PersonnelAwareness

In This Guide:

  • Why AS9100, ISO 13485, and ISO 50001 each need standard-specific training — not generic ISO training
  • Training levels and who needs them for each standard
  • AS9100’s unique auditor authentication requirement (AS9104/3)
  • ISO 13485 training and its connection to FDA QMSR competence requirements
  • ISO 50001 training and energy performance indicator competency
  • Where to get accredited training for each standard
  • Common training mistakes specific to these three standards


👉 Start Here (Top Resources)


Why These Three Standards Need Dedicated Training

ISO 9001, ISO 14001, and ISO 45001 share a harmonized high-level structure, which is why one training framework can reasonably cover all three — see ISO Training for Manufacturing Teams if that’s what you’re building. AS9100, ISO 13485, and ISO 50001 break from that pattern in three distinct ways:

StandardWhat breaks from the ISO 9001 pattern
AS9100Adds aerospace-specific clauses (configuration management, FAI, counterfeit parts) plus a formal auditor authentication scheme for certification auditors
ISO 13485Replaced “continual improvement” with maintaining effectiveness, and now has to align with FDA QMSR, which made ISO 13485:2016 the operative regulation as of February 2, 2026
ISO 50001Sits outside the quality/safety/environmental family — requires energy performance indicators and baseline methodology that don’t appear in any QMS or EMS course

If you’re evaluating certification bodies rather than training providers, see BSI vs ISOQAR for a full registrar comparison.


AS9100 Training: What Aerospace Suppliers Actually Need

AS9100 training carries a wrinkle the other standards on this list don’t have: a formal auditor authentication scheme. Under AS9104/3, certification body auditors seeking IAQG recognition must complete training through a Probitas Authentication-certified course. That requirement applies specifically to third-party certification auditors — internal auditors aren’t formally bound by it, but AS9104/3-aware training still benefits them, since it’s built around the same audit methodology customers and registrars expect to see reflected in your internal audit program.

A common scenario: a machine shop lands its first aerospace subcontract and assigns its existing ISO 9001-trained internal auditor to prep the QMS. The auditor knows the clause structure cold but has never worked with first article inspection requirements or configuration management controls — so the internal audit misses exactly the areas the customer’s supplier quality team will scrutinize first.

What AS9100 Training Covers Beyond ISO 9001

  • Configuration management and product safety requirements unique to aerospace
  • First article inspection (FAI) requirements under AS9102
  • Counterfeit parts prevention controls
  • Special requirements, critical items, and key characteristics
  • Risk management specific to aerospace supply chains
  • OASIS database requirements and supplier flow-down obligations

Who Needs AS9100 Training

Quality Manager / AS9100 Program Owner — Needs lead auditor or lead implementer training that specifically includes AS9104/3 authentication content. A generic ISO 9001 lead auditor credential typically does not provide sufficient coverage of aerospace-specific requirements such as AS9101, configuration management, product safety, and counterfeit parts prevention.

Internal Auditors — Need AS9100-specific internal auditor training. Formal AS9104/3 authentication isn’t required for internal auditors, but Probitas-recognized coursework still gives them the audit methodology customers and registrars expect to see — particularly useful if your organization plans to grow its internal audit program.

Production and Program Management — Need foundation-level AS9100 training covering configuration management, FAI, and counterfeit parts controls — the areas aerospace auditors probe hardest during a floor walkthrough.

All Personnel Touching Aerospace Work — Need awareness training covering product safety culture and counterfeit parts recognition, both explicit AS9100 requirements.

For a full breakdown of AS9100’s aerospace-specific clauses, see What Is AS9100? and Aerospace Supplier Compliance Standards.

Where to Get AS9100 Training

BSI Group AS9100 Training — BSI’s AS9100 catalog covers requirements through lead auditor training, with courses built around ISO 19011 audit methodology and Probitas Authentication recognition for the lead auditor level. BSI is the strongest option for AS9100 given their aerospace sector depth.

Purchase the official AS9100 standard through the ANSI Webstore before training begins — your team needs the current Rev D text in hand during coursework.

⚠️ Most common finding in aerospace audit prep: internal auditors trained only on generic ISO 9001 methodology, with no exposure to AS9104/3-aware audit practices or AS9101 audit reporting format. Formal authentication isn’t required for them, but when a customer or registrar reviews an internal audit program built entirely on ISO 9001 methodology, the gap surfaces fast.

Professional infographic mapping organizational roles to recommended ISO training levels for AS9100, ISO 13485, and ISO 50001, including executive sponsors, quality managers, auditors, supervisors, and shop floor personnel.
Assigning the appropriate ISO training to each organizational role builds competency, strengthens compliance, and improves certification readiness.

ISO 13485 Training: Meeting FDA QMSR Competence Expectations

ISO 13485 training has to accomplish something ISO 9001 training doesn’t: bridge a quality standard with an active regulatory framework. Since FDA QMSR incorporates ISO 13485:2016 by reference as the operative regulation for device manufacturers, training records now need to demonstrate competence against both the standard’s clauses and the regulatory context surrounding them.

A common scenario: a medical device startup trains its quality team on general ISO 9001 principles, assuming the overlap between the two standards covers the gap. The team performs fine on document control and internal audits — then struggles the first time a design history file review comes up, because ISO 9001 training never covered design control traceability or how a DHF ties back to risk management under ISO 14971.

What ISO 13485 Training Covers

  • Design and development controls, including design history file requirements
  • CAPA (Corrective and Preventive Action) process ownership and documentation
  • Risk management integration with ISO 14971
  • Regulatory requirements specific to device classification
  • Documentation and record retention aligned with FDA QMSR expectations
  • Internal audit methodology focused on maintaining effectiveness rather than continual improvement language

Who Needs ISO 13485 Training

Quality/Regulatory Affairs Lead — Needs requirements-level or lead implementer training that explicitly covers the FDA QMSR transition, not a course built solely around the ISO 13485 text in isolation.

Design and Development Personnel — Need training on design control requirements and design history file documentation — an area auditors and FDA reviewers scrutinize closely.

Internal Auditors — Need ISO 13485-specific internal auditor training. An ISO 9001 internal auditor credential does not adequately prepare someone to audit CAPA effectiveness or design control records.

Production and CAPA Owners — Need foundation-level training on nonconformance handling, CAPA documentation, and how “maintaining effectiveness” differs from the continual improvement language used in ISO 9001.

For deeper context on this terminology distinction, see Common Mistakes in ISO 13485 QMS and CAPA Requirements in ISO 13485.

Where to Get ISO 13485 Training

BSI Group ISO 13485 Training — BSI’s medical device training reflects direct regulatory experience across FDA, EU MDR, and global device markets — training only, not standard purchases.

Purchase the official ISO 13485:2016 standard from the ANSI Webstore — BSI does not pay commission on standards purchased directly, so route standard purchases through ANSI.

👉 Design controls and CAPA competency don’t build themselves from a training certificate alone. Pair training with a structured gap assessment before your next audit cycle → Download the ISO 13485 Gap Assessment Checklist


ISO 50001 Training: Building Energy Management Competency

ISO 50001 training is frequently treated as an extension of environmental management training. It isn’t. Energy management systems require a distinct competency set built around measurement and performance tracking rather than aspect/impact analysis.

A common scenario: a plant installs energy monitoring equipment and starts tracking consumption, assuming that satisfies the standard’s data requirements. During certification, the auditor asks how the energy performance indicators were established and what baseline period they’re measured against — and the team can’t answer, because nobody was trained on EnPI methodology specifically. The monitoring data exists; the defensible baseline behind it doesn’t.

What ISO 50001 Training Covers

  • Energy review methodology and identifying significant energy uses (SEUs)
  • Establishing energy baselines and energy performance indicators (EnPIs)
  • Legal and regulatory energy requirements
  • Data collection systems for energy monitoring
  • Internal audit methodology specific to energy management systems
  • Integration considerations with ISO 14001 for organizations running both systems

Who Needs ISO 50001 Training

Energy Manager / EnMS Owner — Needs lead implementer or requirements-level training covering EnPI methodology and energy baseline development. This is the most technical role on this list and benefits most from dedicated coursework rather than a generalist environmental credential.

Facilities and Maintenance Personnel — Need foundation training on how energy performance indicators connect to equipment operation and maintenance practices.

Internal Auditors — Need ISO 50001-specific internal auditor training. Auditing an EnMS requires evaluating energy data integrity and EnPI tracking — skills a generic management-systems auditor doesn’t automatically have.

For how ISO 50001 fits alongside other environmental and safety systems, see ISO 14001 vs ISO 50001.

Where to Get ISO 50001 Training

ISOQAR ISO 50001 Training — Awareness through internal and lead auditor courses covering EnMS audit methodology.

BSI Group ISO 50001 Training — Full training suite including on-demand eLearning fundamentals and IRCA-certified lead auditor coursework.

Purchase the official ISO 50001 standard from the ANSI Webstore before implementation training begins.


Training Level Comparison Across All Three Standards

Professional infographic showing two ISO training pathways, implementation and audit tracks, for AS9100, ISO 13485, and ISO 50001 with role-based competency progression.
Implementation and audit training follow different competency pathways, helping organizations assign the right ISO training to the right people.
StandardFoundation LevelInternal AuditorLead Auditor / ImplementerUnique Requirement
AS9100Configuration mgmt, FAI, counterfeit partsAS9104/3-aware internal audit trainingProbitas Authentication-recognized lead auditorAuditor authentication scheme
ISO 13485Design controls, CAPA basics13485-specific audit training (not ISO 9001 credential)Requirements/lead implementer with FDA QMSR contextRegulatory bridge to FDA QMSR
ISO 50001Energy review, SEU identificationEnMS-specific audit trainingEnPI methodology, lead auditor (IRCA)Data/measurement-based competency

Where to Get Training for Each Standard

Per your affiliate priority mapping and BSI’s sector depth, BSI Group is the primary training provider for AS9100 and ISO 13485. ISOQAR is primary for ISO 50001, with BSI as a secondary option for organizations wanting a single training provider across systems.

⚠️ Always purchase the standard itself through the ANSI Webstore rather than through your training provider — BSI does not pay commission on standards purchased directly through their site, and ANSI consistently offers the most competitive pricing with coupon CC2026 for 5% off through December 31, 2026.

If you’re evaluating certification bodies rather than training providers specifically, the decision criteria differ — see BSI vs ISOQAR: Which ISO Training and Certification Body Is Right for You? for a full registrar-selection comparison across all three standards.


Professional infographic comparing implementation and audit training pathways with a role-based ISO training matrix for AS9100, ISO 13485, and ISO 50001 organizations.
This role-based training matrix helps organizations match ISO training levels to specific responsibilities while distinguishing implementation and audit career pathways.

Common Training Mistakes Specific to These Standards

1. Treating AS9100 training as “ISO 9001 plus a little extra.” The auditor authentication requirement alone makes this a fundamentally different training investment, not an add-on.

2. Training ISO 13485 teams on “continual improvement” language. If your training materials use ISO 9001 terminology instead of “maintaining effectiveness,” your team will misstate a core requirement to an auditor.

3. Assuming an ISO 14001-trained environmental manager can run an EnMS. Energy performance indicators and baseline methodology are a distinct skill set that environmental training doesn’t cover.

4. Skipping FDA QMSR context in ISO 13485 training. Since QMSR made ISO 13485:2016 the operative regulation in February 2026, training that treats the standard as a standalone quality framework — without regulatory context — leaves a competence gap.

5. Using generic ISO 9001 methodology for AS9100 internal audits. Formal authentication isn’t required internally, but if your auditors have never worked with AS9104/3-aware methodology or AS9101 reporting, a customer supplier-quality audit will notice the gap.


Quick Training Readiness Checklist

✅ Quality/program owner has standard-specific lead auditor or lead implementer training — not a generic ISO 9001 credential

✅ Internal auditors have completed training specific to the standard being audited

✅ AS9100 internal auditors have exposure to AS9104/3-aware audit methodology

✅ ISO 13485 training materials use “maintaining effectiveness” language, not continual improvement

✅ ISO 50001 program owner has completed EnPI and energy baseline methodology training

✅ Training records document competence — not just attendance

✅ Training effectiveness has been evaluated, not just completed


FAQ

Can I use my ISO 9001 lead auditor credential to audit AS9100?

For internal audits, yes — with gaps. Your credential covers the shared clause structure, but AS9100 audits also require familiarity with AS9101 audit reporting and aerospace-specific clauses like configuration management and FAI. For third-party certification auditing, formal IAQG authentication under AS9104/3 is required and an ISO 9001 credential alone doesn’t satisfy it.

Does ISO 13485 training need to reference FDA QMSR specifically?

Yes, if you manufacture for the US market. Since FDA QMSR became effective February 2, 2026 and made ISO 13485:2016 the operative regulation, training that doesn’t bridge the standard to QMSR competence expectations leaves a documentation gap auditors and FDA reviewers will notice.

Is ISO 50001 training the same as ISO 14001 training?

No. ISO 50001 requires competency in energy performance indicators, energy baselines, and significant energy use identification — concepts that don’t appear in ISO 14001’s environmental aspect/impact framework.

How long does AS9100 lead auditor training take?

Most Probitas Authentication-recognized AS9100 lead auditor courses run five days, combining classroom instruction with practical audit exercises and a written examination.

Who needs the AS9104/3 authentication specifically?

Formal AS9104/3 authentication applies to certification body auditors seeking IAQG recognition — it’s not a requirement for internal auditors within your own organization. That said, internal auditors benefit from AS9104/3-aware training, since it reflects the same audit methodology your customers and registrar will expect to see.

What’s the difference between an ISO 13485 internal auditor course and an ISO 9001 internal auditor course?

An ISO 13485 course trains auditors to evaluate design controls, CAPA effectiveness, and risk management integration with ISO 14971 — none of which appear in a standard ISO 9001 internal auditor course.

Do I need separate ISO 50001 training if my team already has ISO 14001 training?

Yes. While both are environmental/sustainability-adjacent, ISO 50001’s technical focus on energy measurement and EnPI tracking requires dedicated training your ISO 14001 course won’t cover.

Where do I purchase the AS9100, ISO 13485, or ISO 50001 standards my training is based on?

Purchase all three directly from the ANSI Webstore. Use coupon code CC2026 for 5% off through December 31, 2026.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching which standard applies to you — Read What Is AS9100? or Medical Device Compliance Standards for a foundational overview before committing to a training path.

🔹 Ready to schedule training nowBSI Group’s AS9100 and ISO 13485 training catalog covers awareness through lead auditor. ISOQAR’s ISO 50001 training covers energy management specifically.

🔹 Need to purchase the standard your training is based on — Get AS9100, ISO 13485, or ISO 50001 directly from the ANSI Webstore. Use code CC2026 for 5% off through December 31, 2026.

🔹 Deciding between certification bodies, not just training providers — See BSI vs ISOQAR for a full registrar comparison.

The Standards Navigator covers training, certification, and implementation guidance across every major manufacturing standard — not just the ones with the most search volume. If your operation is expanding into aerospace, medical device, or energy management work, get your team’s competency built on standard-specific training before your first surveillance audit tests the gap.


Stay Ahead of Specialized Compliance Training

Manufacturers expanding into aerospace, medical device, or energy management work don’t usually get caught by the standard itself. They get caught because they trained their team like the new standard was just a variation on ISO 9001.

Organizations that certify cleanly recognize each standard’s distinct competency requirements early and train accordingly — an AS9100 program owner who understands AS9104/3, an ISO 13485 quality lead who speaks FDA QMSR fluently, an energy manager who can build a defensible EnPI baseline.

The Standards Navigator covers training pathways, certification body selection, and implementation guidance across every standard your operation touches — not just the most common ones.

👉 Get updates on specialized ISO training across aerospace, medical device, and energy management 👉 Be first to access new gap assessment checklists as they’re released

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

How to Audit a Medical Device QMS: The ISO 13485 Internal Audit Process (2026 Guide)

This guide walks medical device manufacturers through the ISO 13485 Clause 8.2.4 internal audit requirement — including audit program design, the six-step audit process, and the five most common findings auditors cite. It also covers what changed under the FDA QMSR and the new ISO 19011:2026 audit guidance.

A clause-by-clause guide to planning, conducting, and closing out ISO 13485 internal audits under the new FDA QMSR

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Internal Audit That Used to Be Private Isn’t Anymore

For years, medical device manufacturers treated the internal audit report as an internal document — useful for finding problems, but shielded from FDA inspectors under the confidentiality provision in the old 21 CFR 820.180(c). That protection is gone.

Since February 2, 2026, the FDA’s Quality Management System Regulation (QMSR) has been in effect, and it incorporates ISO 13485:2016 by reference rather than running a parallel U.S.-specific standard alongside it. FDA’s own Final Rule FAQ is direct about what that means for audits: “The QMSR gives the FDA the authority to inspect management review, quality audits, and supplier audit reports. The exceptions that existed in the QS regulation at § 820.180(c) are not maintained in the QMSR.” That’s not a third-party interpretation — it’s FDA’s own published position.

So this isn’t limited to internal audit reports. Management review minutes and supplier audit reports lost the same protection. A checklist you run through once a year to satisfy Clause 8.2.4 on paper is no longer a low-risk approach — it’s now a document an inspector may read line by line, and so are the meetings where leadership reviewed it.

From the Floor: I’ve built and run internal audit programs at facilities with 500-plus employees, and the finding that costs organizations the most isn’t a missing procedure — it’s a corrective action that gets closed on paper before the root cause is actually fixed. As a certified ISO 9001 Internal Auditor, I’ve sat across the table from auditors who catch that in about ninety seconds. Whether you’re auditing to ISO 9001 or ISO 13485, the internal audit only works if it’s harder on you than the external one will be.

Before your next surveillance audit, most quality teams don’t fail because they misunderstand Clause 8.2.4 — they fail because their audit program looks complete on paper but hasn’t been stress-tested against real objective evidence. Run your QMS through the free ISO 13485 Gap Assessment Checklist before an inspector or a Notified Body does it for you.


In This Guide

  • What ISO 13485 Clause 8.2.4 actually requires
  • How internal audits differ from supplier and certification audits
  • What Clause 6.2 actually requires of your auditors — and what “competent” really means
  • Building a risk-based annual audit program
  • The audit process: planning, evidence, reporting, and CAPA follow-up
  • A real finding-to-CAPA example, start to finish
  • The five most common internal audit findings — and how to avoid them
  • What changes if you’re audited under MDSAP
  • What changed under the FDA QMSR and ISO 19011:2026
  • Whether you need outside help or can run this internally


👉 Start Here (Top Resources)


What Clause 8.2.4 Actually Requires

ISO 13485 requires internal audits under Clause 8.2.4 to verify that QMS processes are implemented and effective, catch nonconformities, and surface QMS deficiencies early enough that they don’t become product-safety or regulatory problems. That sounds close to ISO 9001’s internal audit clause, and it is — but ISO 13485 asks for more.

Clause 8.2.4 requires that internal audits determine conformity to planned arrangements, the requirements of the standard, the organization’s own QMS requirements, and applicable regulatory requirements — and unlike ISO 9001, ISO 13485 explicitly requires the audit program to account for regulatory requirements such as FDA 21 CFR Part 820, EU MDR, or MDSAP alongside the standard itself. Teams that build their audit program purely off the ISO 13485 clause structure, without folding in the regulatory layer, are the ones who get flagged.

Most common finding: auditors treat Clause 8.2.4 as a documentation-review exercise and skip the regulatory cross-reference entirely. If your audit checklist doesn’t ask “does this also satisfy 21 CFR Part 820 or MDR Article 10?” it isn’t finished.

Audits must assess conformity across critical processes — design and development under Clause 7.3, corrective action under Clause 8.5.2, preventive action under Clause 8.5.3, production under Clause 7.5, and document control under Clause 4.2 — using objective evidence like device history records, audit trails, and validation records. Auditors must be trained, qualified, and independent of the area they’re auditing, with that competence documented under Clause 6.2.

If you are already ISO 9001 certified → your internal audit infrastructure transfers directly, but your checklist needs a regulatory column added for every process area, not just a conformity column.


Internal Audits vs. Supplier Audits vs. Certification Audits

Comparison infographic showing internal audits, supplier audits, and certification audits under ISO 13485.
Understanding the differences between internal, supplier, and certification audits improves audit planning and regulatory compliance.

Manufacturers frequently conflate these three, and an auditor will notice immediately if your procedure does too.

Audit TypeGoverning ClausePerformed ByPrimary Purpose
Internal AuditClause 8.2.4Trained internal personnel, independent of the area auditedVerify your own QMS conforms to the standard and your own procedures
Supplier AuditClause 7.4.1Quality or supplier quality personnelVerify external providers meet quality and regulatory requirements
Certification AuditISO/IEC 17021-1Accredited third-party Notified Body or registrarDetermine whether the full QMS meets ISO 13485 for certification

ISO 13485 requires internal audits, just as its sister standard ISO 9001 does, and they exist for two reasons: to confirm the QMS meets the standard’s requirements, and to confirm the organization actually follows its own rules. A strong internal audit program is what makes a certification audit uneventful instead of a fire drill.


Auditor Competence: What Clause 6.2 Actually Requires

This is the section most audit programs get thin on, and it’s where a surprising number of otherwise solid internal audit programs fall apart under scrutiny.

Clause 6.2 requires that anyone doing work affecting product quality — and that includes auditors — be competent based on appropriate education, training, skills, and experience. ISO 13485 doesn’t spell out a fixed list of required knowledge areas the way a checklist would, but three areas consistently show up when a Notified Body reviews auditor files:

  • The standard itself. A working knowledge of ISO 13485:2016 clause structure, not just the SOPs written to satisfy it.
  • Audit methodology. Understanding of the audit cycle — planning, evidence gathering, reporting, follow-up — along with the difference between a minor observation and a major nonconformity. ISO 13485’s own note under Clause 8.2.4 points auditors toward ISO 19011 for this.
  • Applicable regulatory context. Basic familiarity with the regulations that apply to your product and markets — 21 CFR Part 820, EU MDR, MDSAP — not full legal mastery, but enough to recognize when a finding also touches a regulatory requirement.

Competence is not the same thing as certification. ISO 13485 does not require a certified internal auditor credential, and ISO 19011 doesn’t mandate formal training either — the standard’s actual requirement is that the audit process ensure objectivity and impartiality, and that competence be evaluated and documented. In practice, though, “read and understand the internal procedure” is not evidence Notified Bodies accept as sufficient. An auditor who can’t produce a training record, a completed course certificate, or documented on-the-job evaluation showing how their competence was assessed is a finding waiting to happen — even if that person is, in fact, good at the job.

What acceptable training records look like in practice:

  • A certificate of completion from an ISO 13485 internal auditor course (typically covering the standard itself plus ISO 19011 audit methodology) — see BSI vs. ISOQAR if you’re deciding where to send your team for that training
  • Internal on-the-job qualification records — a documented mentored audit or two, signed off by a qualified lead auditor
  • A training matrix that ties each auditor to the specific processes and clauses they’re qualified to audit, refreshed when the QMS or the standard changes

Auditor independence gets checked alongside competence. The most frequent failure here isn’t a skills gap — it’s a quality manager who owns a process auditing that same process, or an auditor rotation that never actually rotates the highest-risk areas like design controls.

If you are not confident your auditor files would hold up to this list → that’s a fifteen-minute file review, not a project, and it’s worth doing before your next Notified Body visit rather than during it.


Building a Risk-Based Audit Program

The audit program must cover every process, department, and site within your QMS scope, with audit frequency determined by the status and importance of each process along with the results of prior audits. High-risk processes — design and development, production, CAPA, and complaint handling — typically need at least annual coverage, while lower-risk support functions can be audited less frequently if previous results were consistently clean.

Most manufacturers get the frequency question backwards. They audit everything on a flat annual calendar instead of weighting toward where the last audit found something. If your CAPA process had a finding last year, auditing it again on the same twelve-month clock as your HR training records is a scheduling decision an inspector will question.

If you are preparing for your first surveillance audit under the new QMSR → build your program around the regulatory cross-reference first, then layer the standard’s clause structure on top of it — not the other way around.


The Internal Audit Process, Step by Step

Infographic illustrating the ISO 13485 internal audit process from planning through CAPA verification for medical device quality management systems.
The six-step ISO 13485 internal audit process helps medical device manufacturers identify nonconformities and verify corrective actions.

Prepare a checklist based on the relevant clauses of ISO 13485, your documented procedures, and applicable regulatory requirements — a good checklist prompts investigation rather than simply confirming what’s already assumed to be true.

1. Scope and schedule. Define which processes, sites, and clauses are in scope for this audit cycle.

2. Documentation review. Analyze the quality manual, procedures, and prior audit reports before setting foot on the floor — this is where checklists get mapped to specific clauses.

3. Opening meeting. Confirm scope, objectives, and methodology with the auditee before evidence-gathering begins — this sets the tone for the entire audit.

4. Evidence gathering. Collect objective evidence through interviews, direct observation, and document/record review — no finding should be written down without evidence behind it.

5. Reporting. Findings get written up, classified by severity, and routed to the process owner and management.

6. CAPA follow-up. Every corrective action needs documented root cause analysis appropriate to the significance of the nonconformity, with effectiveness verified before the CAPA is closed.

Most teams execute steps 1 through 5 competently. Step 6 is where programs fall apart — a CAPA gets marked closed the day the immediate fix is implemented, with no verification that the fix actually held.

Trigger: If your last three internal audits found the same category of nonconformity in different words each time, that’s not three separate findings — that’s one root cause your CAPA process never actually reached.

Before your next audit cycle, check your CAPA closure process against what auditors actually verify — most teams don’t realize how thin their effectiveness checks are until someone else reviews them.


A Real Finding, Start to Finish

Steps on a page are easy to nod along with. Here’s what a properly closed finding actually looks like end to end, using one of the most common design-control gaps auditors find.

StageWhat It Looked Like
FindingDuring a design and development audit, three of twelve design verification records sampled were missing the reviewer’s signature. Work was completed and dated, but sign-off wasn’t captured.
Objective EvidenceDesign History File records DHF-114, DHF-119, and DHF-122, cross-referenced against the design review meeting minutes showing the reviews occurred.
Nonconformity Statement“Design verification records DHF-114, DHF-119, and DHF-122 lack the required reviewer signature per QMS-SOP-014, Section 6.2. Design and development control per ISO 13485:2016 Clause 7.3.6 requires verification results, including necessary actions, to be recorded.”
Root CauseInvestigation traced it to a recent SOP revision that moved the sign-off step later in the workflow. Staff hadn’t been retrained on the updated sequence — the procedure changed, but the training that should have accompanied it under Clause 6.2 didn’t happen.
CorrectionThe three records were completed retroactively with the reviewer’s signature and a note explaining the delay, reviewed and accepted by the quality manager.
Corrective Action (CAPA)Retrain design team on the revised sign-off sequence; add a mandatory signature field to the design review template so records can’t be filed incomplete.
Effectiveness CheckSample the next ten design verification records over the following quarter. Zero missing signatures required to close the CAPA as effective.

Notice what makes this closeable rather than cosmetic: the root cause isn’t “people forgot” — it’s a training gap tied to a specific procedure change, and the corrective action addresses the system, not just the three records. That’s the difference between a finding that stays closed and one that reappears with different reference numbers next year.


The Five Most Common Findings

Infographic highlighting the five most common ISO 13485 internal audit findings in medical device quality management systems.
The most common ISO 13485 internal audit findings often involve documentation, CAPA effectiveness, auditor competence, and risk-based planning.

Incomplete audit records — missing reports, plans, or linked CAPAs — is one of the most frequently cited internal audit issues. A close second is failing to apply a risk-based approach to audit planning, or simply not maintaining the internal audit schedule at all. Beyond that, auditors regularly find no timely follow-up on actions from internal audits, no records showing auditor competence against the applicable regulations, and auditors who weren’t actually impartial — reviewing work they had a hand in.

Design and development controls remain the single most frequently cited nonconformity area globally — incomplete design inputs, missing verification or validation records, undocumented design changes, or no formal design transfer procedure. See Validation & Verification Requirements for how this plays out in practice.

⚠️ If your auditor rotation lets the same person audit design controls year after year without ever being audited themselves on that same process, that’s an impartiality gap that a Notified Body will flag before you do.

If you are not confident your last internal audit would hold up under this list → that’s exactly what a structured gap assessment is for, not a guess.

Check your program against these five findings before your next audit — most gaps take under 45 minutes to identify →


MDSAP: What Changes for Multi-Market Audits

If your devices sell into more than one of the five MDSAP markets — the U.S., Canada, Australia, Brazil, or Japan — your internal audit program needs to account for a different audit model, not just an extra regulatory reference.

The Medical Device Single Audit Program lets one audit by an accredited Auditing Organization satisfy the requirements of all five participating regulators at once, in place of separate national audits. It’s built on ISO 13485:2016, but it isn’t a straight overlay — MDSAP uses a process-based audit model with a defined sequence, rather than working straight down the ISO clause list, and it maps every audit task to both the relevant ISO 13485 clause and each country’s specific regulatory requirement.

The grading system is the biggest practical difference. Where an ISO 13485 certification audit typically classifies findings as minor or major, MDSAP uses a points-based Grade 1–5 scale: nonconformities affecting clauses with indirect QMS impact start lower, direct-impact clauses start higher, and points are added for repeat findings or for a nonconforming product that was actually released. Grade 4 and 5 findings must be resolved before a certificate is issued or maintained — there’s no ambiguity about severity once the math is run.

What this means for your internal audit program: if you’re pursuing or maintaining MDSAP, your internal audits should follow the MDSAP process sequence — not just walk through ISO 13485 clauses in order — so that gaps surface in the same structure an Auditing Organization will use. The recurring findings across published MDSAP audits track closely with the same weak points internal audits should already be hunting for: open CAPAs left unclosed past a reasonable window, supplier and purchasing controls that don’t demonstrate follow-through, and root cause analysis that’s thin enough to not survive a second look.

One benefit worth knowing about: MDSAP audit reports can substitute for the FDA’s routine biennial device inspections. A well-run MDSAP program isn’t just multi-market efficiency — it can reduce how often FDA shows up separately.


What Changed: QMSR and ISO 19011:2026

Two regulatory shifts affect how internal audits get run in 2026, and both are recent enough that older internal procedures may not reflect them.

Since February 2, 2026, the FDA’s QMSR has incorporated ISO 13485:2016 by reference, replacing the former Quality System Regulation, and FDA inspections now run under Compliance Program 7382.850 rather than the old QSR framework. As covered above, the practical effect for internal audits is direct: the confidentiality safe harbor that used to apply to internal audit reports, management review records, and supplier audit reports under the old 21 CFR 820.180(c) has been removed, and FDA’s own FAQ confirms it in plain language.

Separately, ISO published the fourth edition of ISO 19011 — Guidelines for auditing management systems — on May 27, 2026, replacing the 2018 edition that had guided audit programs for nearly eight years. ISO 13485 doesn’t mandate ISO 19011 compliance directly — Clause 8.2.4 references audit principles in its own language — but Notified Bodies and experienced auditors widely treat ISO 19011 as the authoritative reference for structuring an audit program, so if your internal audit SOPs still cite the 2018 edition, expect your Notified Body to ask why.

Neither change requires rebuilding your program from scratch. Both are reasons to review your internal audit SOP this year rather than next.


Quick Audit-Readiness Checklist

✅ Audit program covers every process, site, and department in your QMS scope ✅ Audit frequency is risk-weighted, not a flat annual calendar
✅ Every checklist item maps to a specific ISO 13485 clause and the applicable regulatory requirement
✅ Auditors are independent of the area they’re reviewing, with Clause 6.2 competence records on file — not just “read and understand” sign-offs
✅ Findings are backed by objective evidence — interviews, observation, or documented records
✅ CAPA effectiveness is verified before closure, not assumed
✅ If pursuing MDSAP, internal audits follow the MDSAP process sequence, not just the ISO clause order
✅ Internal audit SOP references ISO 19011:2026, not the 2018 edition
✅ Design and development records are current — this is the single most-cited finding category


FAQ

How often does ISO 13485 require internal audits?

The standard doesn’t specify a fixed interval — it requires audits “at planned intervals” based on process risk and prior audit history. Most manufacturers audit high-risk processes like design controls and CAPA annually at minimum, with lower-risk support functions audited less frequently if history is clean.

Can the same person who performs a process also audit it?

No. Clause 8.2.4 requires auditors to be independent of the area being audited. A quality manager who owns the CAPA process, for example, shouldn’t be the one auditing CAPA compliance.

Do internal auditors need a formal certification?

No. ISO 13485 requires documented competence — education, training, skills, and experience — but doesn’t mandate a specific certification. In practice, most Notified Bodies expect more than an internal read-and-understand sign-off, so a course certificate or documented mentored-audit record is the safer standard to work toward.

Does the FDA QMSR require a separate internal audit program from ISO 13485?

No. Since the QMSR incorporates ISO 13485:2016 by reference, there isn’t a separate U.S.-specific internal audit requirement layered on top — your Clause 8.2.4 program is the audit program the FDA now expects, with the regulatory cross-reference built in.

Are internal audit reports confidential from FDA inspectors?

Not anymore. FDA’s own QMSR Final Rule FAQ confirms the confidentiality exceptions under the old 21 CFR 820.180(c) — covering internal audits, management review, and supplier audits — are not maintained under the QMSR.

What’s the difference between an internal audit and a supplier audit under ISO 13485?

Internal audits (Clause 8.2.4) evaluate your own QMS. Supplier audits (Clause 7.4.1) evaluate external providers’ ability to meet your quality and regulatory requirements. Both are required, but they’re separate programs with separate scopes.

Does MDSAP replace our ISO 13485 internal audit requirement?

No, but it changes the structure. MDSAP is built on ISO 13485 and layers in country-specific regulatory requirements from up to five markets, using a process-based sequence and a points-based Grade 1–5 nonconformity system rather than the minor/major classification used in standard certification audits.

What’s the most common reason internal audit programs fail a certification audit?

Incomplete records — missing audit reports, plans, or linked CAPAs — combined with no evidence of a risk-based approach to scheduling. Both are findings a Notified Body catches quickly because they’re procedural gaps, not technical ones.

Should we hire a consultant to run our internal audits, or can we do it ourselves?

Either can work if the auditor is properly trained and genuinely independent of the process. Many manufacturers use in-house auditors for most cycles and bring in an outside auditor periodically to test whether their internal program is actually rigorous or just familiar with its own blind spots.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching your audit obligations? Start with ISO 13485 Documentation Requirements to understand what your QMS needs on paper before you audit it.

🔹 Ready to build or strengthen your audit program? 9001Simplified’s documentation templates can shortcut the SOP-writing process without a consultant retainer.

🔹 Need the standard itself to build your checklist against? Get ISO 13485:2016 from ANSI Webstore — code CC2026 takes 5% off through the end of 2026.


An internal audit program that only exists to satisfy Clause 8.2.4 on paper was already a risk before the QMSR removed the confidentiality safe harbor. Now it’s a document an inspector can read directly. The Standards Navigator will keep tracking what QMSR enforcement and ISO 19011:2026 mean for how medical device manufacturers actually run their audit programs — not just what the clause says.


Subscribe for Medical Device Compliance Updates

Most manufacturers don’t lose a certification over one bad audit finding — they lose it over a pattern of findings their own internal audit program should have caught first. Organizations that treat Clause 8.2.4 as a paperwork requirement get surprised at surveillance. Organizations that treat it as their first line of defense rarely do.

The Standards Navigator tracks how ISO 13485, the FDA QMSR, and the standards that govern medical device audits actually work in practice — not just what the clause text says.

👉 Get updates on ISO 13485 audit requirements and QMSR enforcement changes 👉 Be first to access new medical device compliance checklists and gap assessment tools

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

ISO 10993 Contact Duration Matrix- How to Select Tests (2026 Guide)

ISO 10993-1:2025 retired the old Table A.1 checklist approach to biocompatibility testing. This guide explains the current contact duration categories, how total exposure period is calculated for reusable devices, and which biological endpoints apply — including FDA’s partial recognition of the new edition.

ISO 10993 Contact Duration Matrix and Biological Endpoint Selection Explained

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Matrix Changed. If Your Biological Evaluation Plan Still Reads Like 2018, You Have a Gap

Table A.1 is gone. For seven years, biological evaluation plans were built around a single grid in Annex A of ISO 10993-1:2018 — cross-reference device category and contact duration, check the boxes, done. That table has been retired. ISO 10993-1:2025, published November 18, 2025, split it into four separate tables and rebuilt the exposure-duration logic underneath them.

ISO 10993-1:2025 is the international standard that guides biocompatibility and biological evaluation of medical devices using a risk-based framework, replacing the prescriptive checklist approach of the 2018 edition.

If your BEP still cites the 2018 ISO 10993 contact duration matrix, or if you categorized a reusable device’s contact duration based on a single use rather than total exposure period, you may already be carrying a documentation gap — one that surfaces exactly when a reviewer or notified body opens your file.

Regulatory affairs teams are asking a narrower question than “what is ISO 10993”: which biological endpoints does this specific device trigger under the current framework, and why. That’s what this guide walks through.

I’ve sat across the table from an auditor reviewing a biological evaluation plan where the contact duration category didn’t match the device’s actual use pattern — a reusable component that looked like “limited” contact on paper but was accumulating well past 24 hours across a single patient’s treatment course. The documentation existed. The categorization logic behind it didn’t hold up. That’s the gap this guide is built to close before it becomes a finding.

👉 Before you finalize your next biological evaluation plan, run it against a structured QMS gap check first. Get the free ISO 13485 Gap Assessment Checklist and confirm your documentation controls support the categorization decisions your BEP depends on.

In This Guide

  • What changed in the ISO 10993-1:2025 evaluation matrix and why Table A.1 was retired
  • The current contact duration categories and how “total exposure period” is calculated
  • How to categorize daily contact, intermittent contact, and reusable devices correctly
  • Which biological endpoints apply to each contact duration and body-contact combination
  • What FDA’s partial recognition of ISO 10993-1:2025 means for your submission
  • Common categorization mistakes that trigger additional testing requirements
  • Where to buy the current standard and where to get ISO 13485-aligned training


👉 Start Here (Top Resources)

  • ISO 10993-1:2025 — ANSI Webstore — the current edition, direct from the accredited source. Use code CC2026 for 5% off. (Eric: insert the exact ANSI product link for ISO 10993-1:2025 here.)
  • If you’re weighing whether to buy standards individually or as a set, the ANSI bundle option is worth checking before you purchase the 10993 series piece by piece.
  • ISO 13485 Training — BSI Group — for teams building biological evaluation competency into a certified QMS.
  • ISO Training Courses — ISOQAR — a second accredited training option worth comparing against BSI on schedule and price.

Why the Evaluation Matrix Was Restructured

Under ISO 10993-1:2018, Annex A Table A.1 organized devices by body contact category — surface, external communicating, implant — crossed with three contact duration bands, and listed an “X” for every biological endpoint a reviewer might expect to see addressed. Industry insiders came to call it the “Table A.1 mentality”: manufacturers treated the X’s as a mandatory checklist rather than a starting point for risk-based justification. Tests got run because they appeared in a cell, not because a documented risk assessment called for them.

ISO 10993-1:2025 splits that single table into four separate tables, each tied to a specific evaluation context, and embeds the framework more tightly into the ISO 14971 risk management process. The standard now expects a Biological Evaluation Plan built on the device’s actual risk profile — chemical characterization, materials history, intended use, contact pattern — with the tables used to check completeness, not generate a test order.

Most common finding: biological evaluation plans that cite “Table A.1” by name, or that list endpoints without a documented rationale tied to the device’s specific exposure profile. Under the current standard, that’s a gap a reviewer will flag.

If you are still building your first BEP for a device entering the medical device space, start with what the supplier controls requirements under ISO 13485 expect from your materials documentation — biological evaluation depends heavily on having reliable supplier and materials data before you ever get to a test matrix.

Contact Duration Categories, Defined

The three contact duration categories are unchanged in name but recalculated in practice:

CategoryCumulative ContactTypical Devices
LimitedUp to 24 hours totalDiagnostic swabs, single-use syringes, short procedural instruments
ProlongedMore than 24 hours, up to 30 days totalWound dressings changed over several weeks, indwelling catheters (short-term), orthodontic devices
Long-term / PermanentMore than 30 days totalImplants, permanent orthopedic hardware, long-term catheters

The category itself hasn’t moved. What changed is how you calculate “total contact” for a device that isn’t used in one continuous stretch — and that recalculation is where most categorization errors happen.

If you are evaluating a device used in short, repeated sessions → don’t categorize based on a single session length. The standard expects you to sum all contact time across the device’s full use pattern before assigning a category.

Daily Contact vs. Intermittent Contact

Comparison infographic explaining daily contact and intermittent contact under ISO 10993-1:2025 for biological evaluation of medical devices.
ISO 10993-1:2025 distinguishes between daily and intermittent contact when determining cumulative exposure for biological evaluation.

ISO 10993-1:2025 formalizes two exposure patterns that the 2018 edition handled inconsistently:

  • Daily contact — the device touches the body every day, for any portion of a day, across a defined treatment course. Total exposure is counted as calendar days from first use to last use (or replacement) on a single patient.
  • Intermittent contact — use with at least 24 hours between consecutive contacts. This is treated as repeated use of the same device, or a replacement device, under evaluation.

A wound contact layer changed daily over three weeks is the textbook example: under the 2018 edition, each dressing change might have been assessed as its own “limited” exposure. Under the current standard, the 21 cumulative contact days push the device into prolonged territory — and that shift can add endpoints your original evaluation never considered.

If you are re-evaluating a device that was cleared under the 2018 categorization logic → don’t assume your existing category still holds. Run the total exposure period calculation against the current definitions before you finalize anything for a new submission.

Reusable Devices and Total Exposure Period

Reusable devices are now categorized based on cumulative contact time for a single patient across the device’s full use pattern — not the duration of any one use, and not a multi-patient device service-life total. A reusable surgical instrument sterilized and reused across a procedure series looks brief per individual contact, but the relevant figure is how many total contact days that one patient accumulates across their treatment course, including reasonably foreseeable misuse such as use beyond the labeled reprocessing cycle count.

Bioaccumulation is a related but less settled consideration. FDA’s Supplementary Information Sheet for ISO 10993-1:2025 (Recognition No. 2-313) notes that ISO/TC 194 Working Group 1 is still developing technical reports specifically addressing bioaccumulation, intermittent contact, and reasonably foreseeable misuse. In practice: if chemical characterization data — extractables and leachables — raises a bioaccumulation concern, that finding should inform your risk assessment and may support escalating the device’s category, but document it as a risk-based judgment rather than treating it as a fixed clause requirement until the supporting technical reports are finalized.

For teams managing this inside a certified QMS, it’s a judgment call that needs to trace back to a documented decision — not a verbal risk call made in a meeting. Clause 9 of ISO 10993-1:2025 requires that biological evaluations be planned, conducted, and reported by competent personnel, with the evaluation report documenting the rationale behind risk decisions like this one. The CAPA requirements under ISO 13485 apply just as much to a categorization correction as to a nonconformance on the shop floor.

Flowchart explaining cumulative single-patient exposure for reusable medical devices under ISO 10993-1:2025.
Reusable medical devices are categorized using cumulative single-patient exposure rather than the duration of a single procedure.

Mapping Contact Category to Biological Endpoints

The biological effects under consideration haven’t fundamentally changed — cytotoxicity, sensitization, irritation, systemic toxicity, genotoxicity, implantation effects, and hemocompatibility remain the backbone, and ISO 10993-1 remains a risk-based framework, not a mandatory testing checklist. What changed is the scope of consideration required, particularly for genotoxicity:

Contact DurationBody ContactGenotoxicity Consideration
LimitedAnyCase-by-case, per risk assessment
ProlongedAll tissues except intact skinGenerally expected to be addressed per Tables 2–4 and Clause 6.5.7
Long-term / PermanentAll tissues except intact skinGenerally expected to be addressed per Tables 2–4 and Clause 6.5.7

Under the 2018 edition, genotoxicity was consistently expected for implants and long-term tissue contact, but inconsistently applied to prolonged-contact devices touching mucosal membranes or breached surfaces. ISO 10993-1:2025 narrows that inconsistency: per Tables 2–4 and Clause 6.5.7, any device requiring systemic toxicity evaluation due to prolonged or long-term contact is now generally expected to address genotoxicity as well, intact skin excepted — though this remains a risk assessment expectation to be justified within your Biological Evaluation Plan, not an automatic in vivo test order. Where existing data (toxicological risk assessment under ISO 10993-17, chemical characterization, or literature) already addresses the risk adequately, testing may not be necessary. Carcinogenicity consideration was similarly extended for long-term contact with intact mucosal membranes.

Worth flagging directly: FDA’s Supplementary Information Sheet for ISO 10993-1:2025 (Recognition No. 2-313) identifies a genuine discrepancy here. ISO 10993-1:2025 lists genotoxicity as an endpoint for consideration across all prolonged-contact device categories, while FDA’s own Table A.1 (Attachment A of its 2023 Biocompatibility Guidance) limits the genotoxicity endpoint to implanted devices, externally communicating devices with tissue/bone/dentin contact, and externally communicating devices with circulating blood contact. For a U.S. submission, don’t assume the broader ISO scope automatically controls — confirm which framework your reviewer expects you to follow.

Most common finding: biological evaluation plans for prolonged-contact mucosal devices that address systemic toxicity but don’t document a genotoxicity rationale one way or the other — an omission that was easier to overlook under the 2018 matrix and is more likely to draw a question under the current one.

If your device’s evaluation also touches sterilization residuals, review our sterilization standards overview — ethylene oxide and other sterilization residues are a recurring driver of chemical characterization findings that reshape a biological evaluation.

FDA’s Partial Recognition — What’s Excluded

FDA recognized ISO 10993-1:2025 on May 25, 2026 (Recognition No. 2-313 in FDA’s Recognized Consensus Standards database), but the recognition is partial, not full. Two carve-outs from the Supplementary Information Sheet matter for submission strategy:

  • The phrase “consumer products or” in Clause 6.5.11.3 (Low Risk Intact Skin Contacting Medical Devices) is not recognized — FDA states it conflicts with Attachment G of its 2023 biocompatibility guidance, which limits which historical-use materials qualify for reduced testing on skin-contacting devices.
  • Clause 6.9, Biological risk estimation, is not recognized — FDA holds it conflicts with the risk estimation approach already established under ISO 14971:2019, which FDA separately recognizes.

If you are preparing a 510(k), PMA, or De Novo submission → you cannot submit a full Declaration of Conformity without addressing these two exclusions directly, and the genotoxicity discrepancy above is a separate, related point worth raising with your reviewer proactively. Cite the standard, but demonstrate compliance for the excluded clauses through FDA’s existing biocompatibility guidance rather than assuming automatic alignment. FDA’s recognized standard entry and Supplementary Information Sheet have already been updated since publication — verify the current version directly against FDA’s Recognized Consensus Standards database before finalizing any submission.

For the broader shift this represents in medical device documentation expectations, see our breakdown of validation and verification requirements under ISO 13485 and the FDA QMSR.

Common Categorization Mistakes

Infographic highlighting common ISO 10993 biological evaluation and contact duration categorization mistakes for medical device manufacturers.
Many ISO 10993 audit findings result from incorrect categorization logic or incomplete biological evaluation documentation rather than testing failures.

⚠️ Categorizing by single-use duration instead of cumulative single-patient exposure. The single most common error on reusable and repeat-use devices — it understates the contact category more often than it overstates it.

⚠️ Citing “Table A.1” in a current BEP. A reference to the old table structure is a documentation red flag on its own, independent of whether the underlying science holds up.

⚠️ Assuming genotoxicity doesn’t need to be addressed for prolonged mucosal contact. Teams working from older templates default to a 2018-era endpoint list and skip documenting a rationale either way — under the current tables, that gap is more likely to draw a question.

⚠️ Assuming FDA recognition is full, or that ISO and FDA genotoxicity scope match. Building a submission strategy around blanket alignment, without addressing the excluded clauses and the genotoxicity scope discrepancy, invites an avoidable deficiency letter.

If you are unsure whether existing biological evaluation plans need revisiting → they don’t automatically require retesting, but ISO 10993-1:2025 does expect a documented review confirming prior categorization and endpoint rationale still hold under current definitions.


Quick Audit Checklist

✅ Contact duration category calculated from cumulative single-patient exposure, not single-use duration
✅ Reusable/repeat-use devices assessed for total contact days for one patient across their treatment course
✅ Genotoxicity rationale documented for prolonged/long-term contact except intact skin, per Tables 2–4 and Clause 6.5.7
✅ Biological Evaluation Plan references current ISO 10993-1:2025 structure, not legacy Table A.1
✅ FDA submission strategy accounts for the two partially-recognized clauses and the genotoxicity scope discrepancy
✅ Bioaccumulation signals from chemical characterization data reviewed and documented as a risk judgment, not assumed to require automatic escalation ✅ Existing (pre-2025) biological evaluations documented as reviewed against current definitions


FAQ

Does ISO 10993-1:2025 require me to retest devices already on the market?

No. The standard doesn’t mandate automatic retesting for devices with an acceptable safety history. It does expect a documented review confirming prior categorization and evaluation still hold, and an update if a Clause 10 production change triggers a re-review.

Is ISO 10993-1:2018 still valid to use?

FDA’s recognized standards database is the authority for U.S. submissions — verify current recognition status before relying on either edition. For new evaluation plans, aligning with the 2025 edition is the safer long-term position.

What’s the difference between “prolonged” and “long-term” contact?

Prolonged contact covers cumulative contact exceeding 24 hours but not exceeding 30 days. Long-term (permanent) contact covers cumulative contact exceeding 30 days, driven by total exposure period rather than packaging or labeling.

Does the 2025 edition apply to devices regulated under the EU MDR?

It’s generally treated as state of the art for MDR purposes, but grace periods and notified body expectations vary — confirm directly with your notified body.

Is genotoxicity testing now mandatory for every prolonged-contact device?

Not automatically. Per Tables 2–4 and Clause 6.5.7, genotoxicity is generally expected to be addressed through risk assessment for prolonged and long-term contact with all tissues except intact skin — but “addressed” can mean justified through existing toxicological or chemical characterization data, not necessarily new in vivo testing. Note also that FDA’s own Table A.1 applies genotoxicity more narrowly than ISO does, so confirm which framework governs your specific submission.

Do I need a new Biological Evaluation Plan for every device?

No blanket requirement to start over. Most manufacturers can update an existing BEP to reflect current categorization logic and endpoint scope, provided the underlying risk assessment and chemical characterization data are still valid.

How does ISO 14971 relate to my biological evaluation?

ISO 10993-1:2025 is now more tightly embedded in the ISO 14971 risk management process. See our guide on risk management in medical devices under ISO 14971 for how that framework applies.

Where do I buy the current edition of ISO 10993-1?

Through an authorized reseller such as the ANSI Webstore, which also serves international buyers and offers standards in multiple languages. ISO 10993-1:2025 — ANSI Webstore — Coupon code CC2026 applies through December 31, 2026.


📥 Free Resources

  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts
  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements

Not Sure What to Do Next?

🔹 Still researching how the current standard applies to your device? Read our Biocompatibility Standards Overview for the full picture before you build a test matrix.

🔹 Ready to build or update your Biological Evaluation Plan? Download the ISO 13485 Gap Assessment Checklist and confirm your documentation controls support the categorization decisions you’re about to make.

🔹 Need to purchase the current standard? ISO 10993-1:2025 — ANSI Webstore — code CC2026 takes 5% off, and international buyers can access the standard in multiple languages through the same source.


The Standard Changed. Your Categorization Logic Should Too.

Table A.1 was a shortcut, and shortcuts age out. ISO 10993-1:2025 asks for a defensible, risk-based answer instead of a checked box — and that’s a better position to defend in front of a reviewer regardless of which edition your notified body is citing this quarter. The Standards Navigator will keep tracking how FDA recognition and international adoption evolve as this transition plays out.


Don’t Let a Reviewer Find the Gap First

Most biological evaluation gaps don’t get caught in your own review — they get caught by a notified body auditor or an FDA reviewer, months after the plan was finalized. Manufacturers who treat contact duration categorization as a one-time exercise tend to carry that risk forward through every product change. Manufacturers who build a documented, repeatable categorization process into their QMS catch the drift before it becomes a submission delay.

The Standards Navigator tracks ISO 10993, ISO 13485, and the broader medical device compliance landscape as it evolves — including regulatory recognition changes like FDA’s partial recognition of ISO 10993-1:2025.

👉 Get updates on medical device biocompatibility and QMS requirements
👉 Be first to access new gap assessment tools and implementation resources

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

Biocompatibility Standards Explained: ISO 10993 Requirements for Medical Devices in 2026

This guide breaks down the ISO 10993 series and the sixth edition of ISO 10993-1, published in November 2025. It covers FDA’s partial recognition of the new edition in May 2026, the two clauses the agency excluded, and whether manufacturers need to revisit biological evaluation plans for devices already cleared.

What ISO 10993-1:2025 and FDA’s Partial Recognition Mean for Your Biological Evaluation Plan

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Standard Behind Your Biocompatibility Testing Just Changed — Is Your Documentation Still Defensible?

Biocompatibility standards for medical devices just changed in a way regulatory affairs teams can’t ignore. If your device has any contact with the human body, your biological evaluation plan rests on one standard: ISO 10993-1. For years, that meant the 2018 edition. That’s no longer the whole story.

ISO published a sixth edition, ISO 10993-1:2025, in November 2025. The FDA followed with recognition of that edition on May 25, 2026 — but only partial recognition. Two specific clauses were excluded outright. If your technical documentation, supplier certificates, or biological evaluation reports still cite the 2018 edition without addressing what changed, that’s a gap a reviewer or auditor will find.

This isn’t a cosmetic update. The reorganization ties biocompatibility more tightly to ISO 14971 risk management, and the FDA’s exclusions tell you exactly where the agency still wants you to lean on its own biocompatibility guidance instead of the standard’s language. This guide covers the current medical device biocompatibility testing requirements under both editions, what changed, and what FDA’s recognition decision actually means for your Biological Evaluation Plan (BEP).

I’ve been on the reviewing side of this problem before, just from the documentation control angle. As an ISO 9001 internal auditor, I’ve flagged design history files where a supplier’s certificate of conformance still referenced an outdated edition of a cited standard — the technical content hadn’t changed, but the paper trail no longer matched what the standard actually required. That’s the kind of finding that stalls a submission or an audit closeout, and it’s entirely avoidable if someone catches the edition mismatch before a reviewer does.

Before you touch a single test report, run a gap check on where your current documentation stands against the 2025 edition.

👉 Most teams don’t fail because their biocompatibility data is wrong — they fail because their documentation still points to the wrong edition of the standard. Run the ISO 13485 Gap Assessment Checklist before your next submission or audit →


In This Guide

  • What ISO 10993-1 covers and why it sits at the center of biocompatibility evaluation
  • The full ISO 10993 series, part by part
  • What actually changed in the 2025 edition
  • FDA’s partial recognition — and exactly what it excluded
  • Whether you need to retest devices already cleared under the 2018 edition
  • How biocompatibility documentation fits into your ISO 13485 QMS
  • A quick audit checklist for your next document review


👉 Start Here (Top Resources)


What Is Biocompatibility, and Why ISO 10993 Matters

Biocompatibility is the assessment of whether a device’s materials — and the way those materials contact the body — create an unacceptable biological risk. ISO 10993-1 is the standard that governs how you plan, justify, and document that biocompatibility risk assessment. It doesn’t hand you a checklist of tests to run blindly; it requires you to build a risk-based Biological Evaluation Plan (BEP) that considers the device’s materials, manufacturing processes, intended anatomical contact, and exposure duration.

That risk-based framing matters because it’s the same language FDA reviewers and notified bodies expect to see. A BEP that reads like a 2009-era test list, rather than a risk justification tied to ISO 14971, is a common source of review questions and additional information requests.

If you’re still building out your risk management process, our guide on risk management in medical devices under ISO 14971 covers the foundation ISO 10993-1 now leans on even more heavily than before.


The ISO 10993 Series at a Glance

Infographic showing the ISO 10993 series for biological evaluation of medical devices, including ISO 10993-1, -5, -6, -7, -10, -12, -17, and -18.
The ISO 10993 series consists of multiple standards that together form a complete biological evaluation framework for medical devices.

ISO 10993-1 doesn’t stand alone — it’s the framework document for a series that covers specific test methods and evaluation categories.

PartCoversStatus Note
ISO 10993-1Overall evaluation and testing within a risk management processSixth edition (2025) now partially recognized by FDA
ISO 10993-5In vitro cytotoxicity2009 edition, still current
ISO 10993-6Local effects after implantationUpdated 2026 edition
ISO 10993-7Ethylene oxide sterilization residualsUpdated 2026 edition
ISO 10993-10Irritation and skin sensitization2021 edition
ISO 10993-12Sample preparation and reference materials2021 edition, amended 2025
ISO 10993-17Toxicological risk assessment of device constituents2023 edition, amended 2025
ISO 10993-18Chemical characterization of materials2020 edition, amended 2022

Most common finding: Manufacturers cite ISO 10993-5 or -10 correctly but leave the ISO 10993-1 reference in their design history file pointing to the 2018 edition without any documented rationale for why. If your BEP hasn’t been revisited since the 2025 edition published, that’s the first thing to check.

If your device is sterilized and you haven’t looked at how the 2026 edition of ISO 10993-7 interacts with your sterilization validation, our sterilization standards overview walks through ISO 11135, 11137, 17665, and 11607 alongside it.


What Changed in ISO 10993-1:2025

The sixth edition isn’t a light refresh. ISO’s technical committee reorganized the standard and changed its title to explicitly align with the ISO 14971 risk management framework. The practical changes:

  • More detailed guidance on calculating exposure duration — including how to treat foreseeable misuse, such as a device used longer than its labeled duration.
  • Expanded guidance on device characterization and biological hazard identification, intended to reduce reliance on generic test batteries.
  • Terminology aligned with ISO 14971, so if your team already knows that standard, the 2025 edition should read more consistently — though NAMSA and other industry commentators note there isn’t yet a technical report equivalent to ISO/TR 24971 to guide interpretation of the new edition.

Here’s how the two editions compare on the points that matter most for your Biological Evaluation Plan:

Topic2018 Edition2025 Edition
Risk Management IntegrationReferenced ISO 14971More explicitly aligned throughout
Exposure DurationLimited guidanceExpanded methodology for calculating duration, including foreseeable misuse
Biological Hazard IdentificationLess detailedExpanded guidance on device characterization and hazard identification
Risk EstimationDifferent treatmentNew Clause 6.9 (excluded by FDA)

If you are preparing a Biological Evaluation Plan for a new device → start by confirming which edition your FDA reviewer or notified body expects to see referenced, since adoption isn’t uniform across regions. The EU has generally moved faster toward treating the 2025 edition as state of the art. Manufacturers should verify current adoption expectations directly with their notified body and applicable competent authorities, since implementation timing varies and is subject to change.

One shift worth flagging for regulatory teams building out a modern BEP: chemical characterization under ISO 10993-18 is playing a larger role than it used to. Rather than defaulting to a blanket biological test matrix for every device, more manufacturers are leaning on thorough chemical characterization data — extractables and leachables profiles, material composition analysis — to justify a narrower, risk-based testing strategy. ISO 10993-1:2025’s expanded hazard identification guidance reinforces this shift. A well-documented ISO 10993-18 characterization can reduce redundant biological testing, but only if the chemistry-driven rationale is documented clearly enough to withstand a reviewer’s scrutiny.

Comparison graphic showing the major differences between ISO 10993-1:2018 and ISO 10993-1:2025 for biological evaluation of medical devices.
The 2025 edition places greater emphasis on risk management integration, biological hazard identification, and exposure assessment.

ISO 10993 FDA Recognition: What’s Excluded and Why

🔑 Key FDA Takeaway FDA recognizes ISO 10993-1:2025, but excludes:

  • The “consumer products” language in Clause 6.5.11.3
  • Clause 6.9 on biological risk estimation

Manufacturers should document alternative justification using FDA guidance and ISO 14971.

On May 25, 2026, FDA updated its Recognized Consensus Standards database (Recognition No. 2-313) to include ISO 10993-1:2025 — but not in full. Two specific exclusions matter for your submissions:

  1. The phrase “consumer products or” in Clause 6.5.11.3. This clause addresses low-risk, intact-skin-contacting devices. The standard allows manufacturers to point to a material’s history of safe use in consumer products as justification for reduced testing. FDA excluded this because it conflicts with Attachment G of its 2023 biocompatibility guidance, which defines specific materials with an accepted history of use — a consumer product history alone doesn’t automatically satisfy FDA’s expectations.
  2. Clause 6.9 on biological risk estimation. FDA determined this clause conflicts with the risk estimation approach already established in the FDA-recognized ISO 14971:2019. Sponsors can’t rely on Clause 6.9 to claim conformity in a submission.

If you are under customer or notified body pressure to update your BEP quickly → prioritize reviewing these two clauses first. They’re the specific areas where citing the 2025 edition alone won’t satisfy FDA, and you’ll need to document your justification through existing FDA guidance instead.

Partial recognition means you cannot submit a clean Declaration of Conformity to the full 2025 edition. Your submission documentation needs to call out the partial recognition explicitly and show how you’re addressing the excluded clauses — silence on this point is what generates additional information requests.

Workflow illustrating FDA partial recognition of ISO 10993-1:2025 and the documentation required for excluded clauses during medical device submissions.
FDA recognizes ISO 10993-1:2025 with specific exclusions, requiring manufacturers to document alternative regulatory justifications.

Do You Need to Retest Already-Cleared Devices?

This is the objection I hear most from teams looking at this update: does a new edition mean I have to redo my biocompatibility testing on devices that already have clearance?

No — not automatically. FDA’s recognition of a newer edition doesn’t retroactively invalidate data or clearances based on the 2018 edition. If you already hold clearance under the 2018 edition → you don’t need to retest existing devices. What you do need is a documented rationale, at your next design change or periodic review, for why your BEP still reflects sound risk management even though a newer edition exists. That’s a documentation and justification exercise, not a lab exercise.

Where this becomes a live issue is new submissions and significant design changes going forward — those are where reviewers will expect to see the current edition addressed.


Where Biocompatibility Fits Into Your ISO 13485 QMS

Biocompatibility data doesn’t live in isolation — it’s part of your design and development file under ISO 13485, and it feeds directly into your risk management file under ISO 14971. If your ISO 13485 documentation structure doesn’t have a clear place for biological evaluation plans, reports, and the rationale behind edition changes, that’s a gap worth closing before your next internal audit — not after a nonconformance is written.

This also connects to supplier controls. If a component supplier’s certificate of conformance references ISO 10993-1 by edition, your incoming inspection and supplier qualification process needs a mechanism to catch when that reference goes stale — the same principle covered in our guide on common mistakes in ISO 13485 QMS implementation.

And if you’re managing devices sold in both the US and EU, the edition-adoption gap between FDA and the EU regulatory framework is one more reason to keep your MDR vs ISO 13485 documentation aligned rather than treating them as separate tracks.

👉 If your biological evaluation documentation hasn’t been reviewed since the 2025 edition published, don’t wait for a finding to tell you. Check where your QMS documentation actually stands →


Quick Audit Checklist

✅ Confirm which edition of ISO 10993-1 your current BEP references, and whether that matches what your reviewer or notified body expects
✅ Check whether your device’s biocompatibility justification relies on Clause 6.5.11.3 (consumer product history) or Clause 6.9 (risk estimation) — both need alternative justification for FDA submissions
✅ Verify supplier certificates of conformance cite current standard editions, not stale references
✅ Confirm your risk management file cross-references your BEP consistently ✅ If your device is sterilized, check the 2026 editions of ISO 10993-6 and -7 against your current validation data ⚠️ Don’t assume “FDA recognized” means “fully accepted” — verify the Supplementary Information Sheet for any standard before citing it as a full Declaration of Conformity


FAQ

What is biocompatibility testing for medical devices?

Biocompatibility testing evaluates whether the materials in a medical device, and the way those materials contact the body, could cause an unacceptable biological response. It covers areas like cytotoxicity, sensitization, irritation, and systemic toxicity, selected based on the device’s contact type and duration.

What is ISO 10993-1, and do I need to comply with it?

ISO 10993-1 is the framework standard that governs how you plan and justify a biological evaluation within a risk management process. If your device contacts the body directly or indirectly, FDA and most global regulators expect your biocompatibility strategy to follow its structure, even where full conformity isn’t feasible.

What changed between ISO 10993-1:2018 and ISO 10993-1:2025?

The 2025 edition reorganized the standard to align more closely with ISO 14971, added detailed guidance on calculating exposure duration and identifying biological hazards, and updated terminology throughout.

Has the FDA recognized ISO 10993-1:2025?

Yes, as of May 25, 2026, but only partially. FDA excluded the “consumer products” language in Clause 6.5.11.3 and all of Clause 6.9 on biological risk estimation, both of which conflict with existing FDA guidance and the FDA-recognized ISO 14971:2019.

Do I need to retest devices already cleared under the 2018 edition?

No. Existing clearances aren’t invalidated by a newer edition. You do need a documented rationale for your current approach at your next design change or periodic review.

Which parts of the ISO 10993 series apply to my device?

That depends on your device’s contact type (surface, external communicating, or implant) and contact duration (limited, prolonged, or permanent). ISO 10993-1 provides the matrix for selecting relevant parts of the series based on those two factors. We’ll be covering that contact-duration matrix in detail in an upcoming guide.

Is ISO 10993 the same as ISO 13485?

No. ISO 13485 governs your overall quality management system for medical devices. ISO 10993 is a series specifically about biological evaluation, and its outputs — your BEP and test reports — become part of the design and development records your ISO 13485 QMS requires you to maintain.

Where do I purchase ISO 10993 standards?

Individual parts and bundled packages are available through the ANSI Webstore, which also serves international buyers and offers documents in multiple languages. The ISO.org catalog describes each part but is not the recommended purchase channel.


📥 Free Resources

  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.
  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements, including where biocompatibility documentation fits.
  • AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification.

Not Sure What to Do Next?

🔹 Still researching how the 2025 edition affects your device category? Start with our breakdown of risk management under ISO 14971 — biocompatibility evaluation doesn’t stand apart from it anymore.

🔹 Ready to check where your documentation actually stands? Run the ISO 13485 Gap Assessment Checklist before your next audit or submission, not after.

🔹 Need to purchase the current standard? ISO 10993-1:2025 — ANSI Webstore, or get the full biological evaluation package bundled at roughly 45% off individual pricing if you’re assembling multiple parts of the series. Use code CC2026 for an additional 5% off through December 31, 2026.

The Standards Navigator will keep tracking how FDA recognition evolves on this standard as updates are published.


Documentation Gaps Don’t Show Up Until Someone’s Looking For Them

Teams that treat biocompatibility as a one-time lab exercise are the ones caught off guard when a standard’s edition changes underneath them. Teams that treat it as a living part of their design and risk management file catch the mismatch at their next internal review, not during an FDA question round — and it’s usually a citation that didn’t keep up, not the underlying science, that stalls a submission.

The Standards Navigator tracks these regulatory shifts as they happen — not months later when the transition deadline is already close. If ISO 10993-1:2025 affects your device, this is a good window to revisit your documentation rationale while the timeline is still in your control.

👉 Get updates on medical device compliance and biocompatibility standard changes
👉 Be first to access new gap assessment checklists and documentation tools for ISO 13485 and ISO 14971

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

ISO 15223 Symbols Overview: What Every Medical Device Label Actually Means (2026 Guide)

ISO 15223-1:2021 governs the pictograms on every medical device label. This guide breaks down the seven symbol categories, key reference symbols, and the 2026 EU REP amendment — including exact transition deadlines under MDR and IVDR.

A regulatory affairs guide to the pictograms your labels are required to carry — and the 2026 EU REP symbol change you need to track

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.

This article is for general informational purposes and is not regulatory advice. Manufacturers should verify symbol requirements against the current version of ISO 15223-1 and applicable regulatory guidance.


ISO 15223-1:2021 is the internationally recognized standard that defines symbols used on medical device labels, packaging, and accompanying information to communicate critical safety and regulatory information without language-specific text.


The ISO 15223 Symbols That Trigger a Labeling Recall

A single wrong pictogram on a device label isn’t a cosmetic problem. It’s a labeling nonconformance that can hold up a shipment, trigger a Notified Body finding, or in the worst case, force a recall.

ISO 15223-1:2021 is the standard behind nearly every symbol on a medical device label — manufacturer, batch code, sterile, use-by date, and dozens more. It’s not optional guidance. It’s the harmonized reference regulatory affairs teams are expected to follow for CE marking label symbols, and it just changed in a way that affects almost every CE-marked device on the market.

From the floor: I’ve reviewed label proofs where a well-meaning graphics team swapped in an old sterilization icon because it “looked close enough” to what the previous product used. It wasn’t the same symbol, and it wasn’t accompanied by the batch reference the standard requires next to it. Having reviewed manufacturing and quality documentation across multiple industrial environments, I’ve repeatedly seen labeling errors originate not from misunderstanding the requirements, but from uncontrolled template reuse. That kind of small mismatch is exactly what a label review process is supposed to catch before it reaches a Notified Body’s desk — not after.

👉 Before your next label revision goes to print, confirm every symbol still matches current guidance. Most labeling nonconformances aren’t due to unfamiliarity with the standard — they’re due to reusing an old label file without checking what changed. Get the ISO 13485 Gap Assessment Checklist and confirm your revision management process is catching this before a reviewer does.


In This Guide

  • What ISO 15223-1:2021 actually covers and why it’s harmonized under MDR/IVDR
  • The seven symbol categories and what each one communicates
  • The 2026 EU REP symbol change — what changed, when, and what it means for your labels
  • Common labeling mistakes that surface in document reviews
  • FAQ


👉 Start Here


What Is ISO 15223-1:2021?

ISO 15223-1:2021, Medical devices — Symbols to be used with information to be supplied by the manufacturer — Part 1: General requirements, is now in its fourth edition. It defines the standardized pictograms manufacturers use on labels, packaging, and accompanying documentation so a device can be understood across languages and markets without translation.

It was harmonized under both EU MDR and EU IVDR in January 2022 — one of a relatively small number of standards to hold that status — which means using it correctly carries a presumption of conformity with the corresponding MDR/IVDR labeling requirements. A companion standard, ISO 15223-2, covers how new symbols get developed, selected, and validated when nothing in the existing library fits.

Because ISO 15223-1 is harmonized under MDR and IVDR, proper symbol usage can support a manufacturer’s demonstration of conformity with labeling requirements. In practice, auditors and Notified Bodies routinely review symbol usage as part of labeling assessments — this isn’t a peripheral checklist item, it’s one of the more commonly reviewed elements of a technical file.


Why Manufacturers Use Symbols

Medical devices are distributed across multiple countries and languages. Standardized symbols reduce the need for translated label text while helping manufacturers meet labeling requirements consistently across global markets. A single symbol library means the same pictogram carries the same meaning whether a device ships to Germany, Japan, or Brazil — without a separate translated label for each market.


ISO 15223-1 Medical Device Symbols Explained

ISO 15223-1 organizes its medical device label symbols into seven functional groups:

  • Manufacturing — manufacturer identity, date of manufacture, country of manufacture
  • Storage — temperature limits, humidity limits, keep dry, keep away from sunlight
  • Safe use — single use, do not use if damaged, consult instructions for use
  • Sterility — sterile, sterilization method, do not resterilize
  • IVD-specific — symbols unique to in vitro diagnostic devices
  • Transfusion/infusion — symbols for blood and infusion-related devices
  • Other — symbols that don’t fit cleanly into the categories above but are still standardized

Every symbol in the standard comes with a defined title, a description of what it communicates, and any accompanying information it must be paired with — a batch code symbol without an actual batch number next to it isn’t a valid use of the symbol.


Most Common ISO 15223-1 Medical Device Symbols

Infographic illustrating the most common ISO 15223 symbols for  medical device labeling, including manufacturer, LOT, REF, serial number, sterile, use-by date, consult instructions for use, and keep dry.
The most frequently used ISO 15223-1 symbols help communicate critical manufacturing, traceability, sterility, and safety information on medical device labels worldwide.

The following symbols represent some of the most commonly encountered markings in medical device labeling. This is not a complete list, but these symbols appear on a significant percentage of devices entering regulated markets.

Symbol TitleClauseWhat It Communicates
Manufacturer5.1.1Identifies the legal manufacturer; name and address must accompany it
Date of manufacture5.1.3The date the device was produced
Use-by date5.1.4The date after which the device should not be used
Batch code (LOT)5.1.5Identifies the manufacturing batch or lot
Catalogue number (REF)5.1.6The manufacturer’s catalogue/model number
Serial number (SN)5.1.7Identifies a specific individual device
Importer5.1.8Identifies the entity importing the device into a given market
Sterile5.2.1Device has been through a sterilization process
Do not resterilizeDevice is not to be resterilized after use
Do not use if package damagedConsult instructions for use if packaging integrity is compromised
Single useDevice is intended for one use only

This is a reference sample, not the full symbol library — the standard runs well beyond these. For the complete set of ISO 15223 symbol meanings, always validate current symbol usage against the live ISO document rather than a saved reference sheet, since amendments do get issued.


The 2026 EU REP Symbol Change

The most consequential update to this standard in years just took effect. Amendment EN ISO 15223-1:2021/A1:2025 replaces the long-standing “EC REP” symbol for a medical device’s authorized representative in the EU with a new “EU REP” symbol, and introduces a generic “XX REP” framework where “XX” is swapped for the applicable country or jurisdiction code.

The change was requested by the European Commission in May 2024, specifically to eliminate confusion between “EC” as a regulatory abbreviation and “EC” as the ISO 3166-1 country code for Ecuador. ISO adopted the amendment in March 2025, and it was formally harmonized into the Official Journal of the European Union on June 17, 2026, through Commission Implementing Decision (EU) 2026/1231 (amending MDR-side Decision 2021/1182) and Commission Implementing Decision (EU) 2026/1313 (amending IVDR-side Decision 2021/1195).

The European Commission has been explicit that this is a purely editorial change — it does not alter the authorized representative symbol’s role, responsibilities, or the device’s safety or performance profile in any way. This amendment is now one of the more consequential updates among the current round of MDR harmonized standards, given how widely the symbol appears across the CE-marked device population.

Timeline infographic illustrating the transition from the EC REP symbol to the EU REP symbol under ISO 15223-1:2021 Amendment A1:2025, including key regulatory milestones through 2031.
The transition from EC REP to EU REP includes a five-year coexistence period, allowing manufacturers to update labeling during normal revision cycles before the 2031 deadline.

👉 Planning an upcoming label revision? Download the ISO 13485 Gap Assessment Checklist to verify your revision management process is capturing changes to standards before they become audit findings.


Do You Need to Update Your Labels Right Now?

The most common objection: “Do we need to reprint every label immediately?”

No. The Commission built in a five-year coexistence period. Manufacturers may continue using the legacy “EC REP” symbol under the original EN ISO 15223-1:2021, or transition to the new “EU REP” symbol under the amendment — both are valid during this window. The old standard’s reference isn’t withdrawn until June 15, 2031 under MDR and June 17, 2031 under IVDR. After those dates, only “EU REP” confers presumption of conformity.

In practice, this means:

  • If you are about to run a new label print or design revision anyway → use the new EU REP symbol now rather than reprinting again later.
  • If your current labels are compliant and not due for revision → there is no requirement to act immediately; plan the change into your next scheduled label update.
  • If you have a Notified Body conformity review coming up → confirm with them directly whether they expect the new symbol in your current submission, since individual Notified Body expectations can vary during a transition window.

Common ISO 15223 Labeling Nonconformances

Most common finding: inconsistent symbol usage across packaging levels — the outer carton uses one version of the authorized representative symbol while the inner unit label uses another, with no documented rationale for the difference.

Other recurring issues: sterilization method symbols that don’t match the actual method used (ethylene oxide vs. irradiation vs. steam each has a distinct symbol); batch code or serial number symbols placed on a label without the actual batch or serial data adjacent to them; and reused label templates that carry forward a superseded symbol simply because nobody flagged the amendment during change control review.

⚠️ None of these mistakes require a new symbol library to fix — they require a label governance process that actually checks current symbol validity before a label goes to print, not just before the first label was ever approved.


Quick Reference Checklist

Professional infographic showing a medical device label review checklist based on ISO 15223-1, including symbol verification, sterilization validation, traceability, packaging consistency, and revision control.
A structured label review process helps manufacturers verify ISO 15223-1 symbol compliance before medical devices move into production or distribution.

✅ Current label set reviewed against the live ISO 15223-1:2021 symbol library ✅ Sterilization method symbol matches the actual method used
✅ Batch code, catalogue number, and serial number symbols paired with real data
✅ EU REP transition plan documented, even if no immediate label change is required
✅ Packaging levels (outer carton, inner unit, IFU) checked for symbol consistency
✅ Change control process flags standard amendments, not just initial approvals


FAQ

What is ISO 15223-1:2021?

It’s the international standard defining the pictograms used on medical device labels, packaging, and accompanying information — covering everything from manufacturer identity to sterilization method. It’s currently in its fourth edition and harmonized under both EU MDR and IVDR.

Do I have to switch to the EU REP symbol immediately?

No. The European Commission built in a five-year coexistence period. The legacy EC REP symbol remains valid until the original standard’s reference is withdrawn — June 15, 2031 under MDR and June 17, 2031 under IVDR.

Is the EU REP change a safety-related update?

No. The Commission has described it as a purely editorial change, made to eliminate confusion with Ecuador’s ISO 3166-1 country code. It does not change the authorized representative’s role or responsibilities.

What’s the difference between ISO 15223-1 and ISO 15223-2?

Part 1 defines the actual symbol library and how symbols must be used. Part 2 covers the process for developing, selecting, and validating a new symbol when nothing in the existing library fits a specific need.

Does every medical device need every symbol in the standard?

No. Which symbols apply depends on the device — a non-sterile reusable device won’t carry sterilization symbols, for example. The standard defines what each symbol means and how to use it correctly; it doesn’t mandate that every device carry every symbol.

What’s the most common labeling mistake regulatory teams miss?

Inconsistent symbol usage across packaging levels — using an updated symbol on one layer of packaging while an older version persists on another, usually because a label template wasn’t fully reviewed during a revision.

Where can I find the actual symbol library?

ISO 15223-1:2021 and its companion ISO 15223-2 are both available for purchase through ANSI Webstore, either individually or as a combined package.

Should my Notified Body confirm which symbol version they expect?

During the transition period, manufacturers should confirm expectations directly with their Notified Body, particularly if a labeling review or conformity assessment is already underway.


📥 Free Resources

  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements, including the revision management processes that keep labeling current.
  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system from the ground up.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements across production environments.

Not Sure What to Do Next?

🔹 Still researching how labeling symbols fit into your broader QMS? Start with ISO 13485 Documentation Requirements and Common Mistakes in ISO 13485 QMS to see where document control connects to labeling accuracy.

🔹 Ready to review your current label set? Check it against Sterilization Standards Overview and UDI Requirements Explained — both cover label-adjacent requirements that pair directly with ISO 15223-1 symbols.

🔹 Need to purchase the standard itself? Get the ISO 15223 Symbols Package from ANSI Webstore — available individually or bundled with Part 2, with code CC2026 for 5% off through December 31, 2026.


Symbols look like a small detail until one of them is wrong on a printed label already in circulation. The Standards Navigator will keep tracking the EU REP transition and any further ISO 15223 amendments as they’re published.

Don’t Let a Symbol Be the Reason for a Finding

Labeling nonconformances are some of the most avoidable findings in a Notified Body review — the standard is published, the symbols are defined, and the fix is almost always a revision management gap rather than a technical one.

The Standards Navigator tracks ISO 15223 amendments, MDR/IVDR labeling requirements, and medical device documentation standards so your labels don’t fall out of step with a standard that changed while nobody was watching.

👉 Get updates on ISO 15223, MDR/IVDR labeling changes, and medical device documentation requirements as they happen
👉 Be first to access new gap assessment tools built for medical device regulatory affairs teams

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

MDR vs. ISO 13485: What’s the Difference and Which One Do You Actually Need in 2026?

EU MDR and ISO 13485 solve different problems — one is law, the other is a certifiable QMS standard. This guide breaks down the core differences, current 2026–2027 MDR transition timelines, and a decision framework for regulatory affairs teams navigating both.

A regulatory affairs guide to two rules that get confused constantly — and cost time when they are

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Question That Stalls Every EU Market Entry Meeting

Somewhere in almost every medical device compliance kickoff, someone asks it: “We already have ISO 13485. Doesn’t that cover MDR?”

It doesn’t. And the gap between MDR vs ISO 13485 — a certified quality management system and an EU-compliant technical file — is where CE marking timelines quietly slip by six to twelve months.

MDR (Regulation (EU) 2017/745) and ISO 13485 aren’t competing standards. They aren’t interchangeable either. One is EU law. The other is a voluntary international standard that EU law happens to lean on heavily. Confusing the two doesn’t just cost time — it costs Notified Body findings, delayed submissions, and in some cases, a device that can’t legally reach the European market on schedule.

From the floor: I’ve sat in a management review where a director insisted the ISO 13485 certificate meant the technical documentation was “basically done” for an EU submission. It wasn’t. The certificate covered their quality system — design controls, CAPA, document control. It said nothing about the clinical evaluation report, MDR classification requirements, or the device-specific evidence required for conformity assessment. They spent the next quarter closing that gap instead of reviewing it calmly six months earlier. That’s the exact mistake this article exists to prevent.

👉 Before you assume your QMS certification covers your EU submission, run the gap check. Most regulatory affairs teams don’t fail because they misunderstand ISO 13485 — they fail because they assumed certification and market access were the same milestone. Get the ISO 13485 Gap Assessment Checklist and find out before a Notified Body does.

In This Guide

  • What EU MDR 2017/745 actually regulates
  • What ISO 13485 actually certifies
  • The core differences, side by side
  • Why “ISO 13485 certified” doesn’t mean “MDR compliant”
  • Where the two genuinely overlap — risk management, CAPA, design controls, and more
  • Current MDR transition timelines and 2026 developments
  • Which one you need — and when you need both
  • Common documentation mistakes that surface in Notified Body reviews
  • FAQ

Table of Contents

  1. What Is EU MDR 2017/745?
  2. What Is ISO 13485?
  3. MDR vs. ISO 13485: Core Differences
  4. Why Manufacturers Conflate the Two
  5. Where MDR and ISO 13485 Overlap
  6. MDR Transition Timelines: Where Things Stand in 2026
  7. Do You Need Both? A Decision Framework
  8. Common Mistakes That Surface in Notified Body Review
  9. Quick Reference Checklist
  10. FAQ

👉 Start Here


What Is EU MDR 2017/745?

MDR is law, not a certifiable management system standard. Regulation (EU) 2017/745 governs what a manufacturer must prove — about a specific device — before that device can carry a CE mark and legally reach the EU market.

It covers device classification (Class I through III), clinical evaluation and clinical data requirements, technical documentation per Annexes II and III, post-market surveillance and post-market clinical follow-up (PMCF), Unique Device Identification (UDI) and EUDAMED registration, and — for higher-risk devices — Notified Body conformity assessment under Annex IX.

MDR replaced the older Medical Device Directive (MDD) and Active Implantable Medical Devices Directive (AIMDD), and it raised the bar substantially on clinical evidence and post-market obligations compared to both.

What Is ISO 13485?

ISO 13485 is a voluntary, internationally recognized quality management system standard for organizations involved in the design, production, or servicing of medical devices. It’s certifiable — a Notified Body or accredited certification body audits your QMS against the standard’s clauses and issues a certificate if you pass.

ISO 13485 uses maintaining effectiveness language throughout, not the continual improvement language found in ISO 9001. It’s structured around risk-based thinking applied specifically to design controls, document and record control, supplier controls, CAPA, and management review — the operational backbone a device manufacturer needs regardless of which market it sells into.

Since FDA’s QMSR took effect February 2, 2026, 21 CFR Part 820 incorporates ISO 13485:2016 by reference — making it the enforceable quality management system standard for U.S. device manufacturers, not merely a reference point.

MDR vs. ISO 13485: Core Differences

CategoryEU MDR 2017/745ISO 13485
NatureEU law — mandatory for CE markingVoluntary international standard
ScopeDevice-specific: classification, clinical evidence, technical fileOrganization-wide: the QMS itself
Who assesses itNotified Body (device-level conformity assessment)Certification body (QMS audit)
Grants market access?Yes — required for CE marking in the EUNo — supports it, doesn’t grant it
Geographic reachEU/EEA market onlyRecognized globally; now foundational to FDA QMSR
What it producesTechnical documentation, CER, PMS/PMCF plan, EUDAMED registrationA certificate covering your quality management system
Update cycleAmended by EU legislative process (ongoing 2025–2027 reform)Revised through ISO’s standard TC 210 process
Professional infographic comparing EU MDR 2017/745 and ISO 13485:2016, highlighting differences in regulatory requirements, quality management systems, CE marking, clinical evaluation, and technical documentation for medical device manufacturers.
This infographic compares EU MDR and ISO 13485, illustrating how one governs market access while the other establishes the quality management system that supports regulatory compliance.

Quick Answer:

  • Need CE marking? → MDR is required.
  • Need a compliant medical device QMS? → ISO 13485 is required.
  • Selling medical devices in the EU? → You almost certainly need both.

The stakes behind that table are real: the European Commission’s most recent Notified Bodies survey, published March 2026, showed roughly half of submitted MDR applications had reached certificate issuance — a gap driven largely by device misclassification, incomplete technical documentation, and thin clinical evidence, not by Notified Body capacity alone.


Why Manufacturers Conflate the Two

The most common objection I hear: “We’re ISO 13485 certified — why do we need a separate MDR effort?”

Here’s the resolution: ISO 13485 certification tells a Notified Body your quality system is sound. It says nothing about whether a specific device’s clinical evidence, risk classification, or technical file meets MDR’s requirements. A company can hold a spotless ISO 13485 certificate and still receive a Notified Body finding on a device submission because the clinical evaluation report was thin, the PMCF plan was missing, or the classification rule was misapplied under Annex VIII.

Think of it this way: ISO 13485 certifies the kitchen is clean and the process is controlled. MDR conformity assessment asks whether this specific dish meets the recipe, the nutrition label is accurate, and there’s a plan to keep checking it after it ships. You need both, but they answer different questions.

👉 If you are relying on your ISO 13485 certificate as your MDR readiness proof, that’s the gap to close first. Run the ISO 13485 Gap Assessment Checklist against your current technical files before your next Notified Body interaction.

Where MDR and ISO 13485 Overlap

Venn diagram infographic showing where EU MDR 2017/745 and ISO 13485:2016 overlap, highlighting shared quality management processes including risk management, design controls, CAPA, complaint handling, and supplier controls for medical device manufacturers.
This infographic illustrates the operational areas shared by EU MDR and ISO 13485 while distinguishing the unique regulatory and quality management requirements of each framework.

If they’re really two separate things, why does everyone talk about them in the same breath? Because the same five operational areas show up in both — just assessed from different angles.

  • Risk management — MDR requires risk management per Annex I general safety and performance requirements; ISO 13485 Clause 4.1.2 requires a risk-based approach throughout the QMS. Most manufacturers run one risk management process (typically ISO 14971-aligned) that satisfies both.
  • CAPA — ISO 13485 Clause 8.5 governs corrective and preventive action as a QMS requirement. MDR’s post-market surveillance and vigilance obligations feed directly into that same CAPA process when a field issue is identified.
  • Design controls — ISO 13485 Clause 7.3 sets design and development requirements; MDR’s technical documentation under Annex II leans on those same design records as evidence of a controlled development process.
  • Supplier controls — ISO 13485 Clause 7.4 requires supplier evaluation and monitoring; MDR expects that same supplier oversight to extend into the technical file wherever a supplier-controlled process affects device safety or performance.
  • Complaint handling — ISO 13485 Clause 8.2.2 sets complaint-handling requirements; MDR’s vigilance reporting obligations under Article 87 depend on that same complaint intake process to catch reportable events.

This is the practical reason ISO 13485 certification and MDR technical documentation feel like the same conversation even though they’re legally distinct: a well-run QMS produces most of the raw material an MDR technical file needs. The gap is rarely in these five areas — it’s in whether that raw material gets assembled into a device-specific technical file the way MDR expects.

MDR Transition Timelines: Where Things Stand in 2026

The transition provisions have shifted more than once since MDR took effect in May 2021, and manufacturers still working under legacy MDD or AIMDD certificates need to track the current deadlines carefully:

  • Class III custom-made implantable devices: compliance required by May 26, 2026
  • Class III and certain implantable Class IIb devices: transition extends to December 31, 2027
  • Most other Class IIb, IIa, and Class I devices: transition extends to December 31, 2028

Legacy device status under these extended timelines requires a valid MDD/AIMDD certificate, no significant design or intended-use change, continued compliance with the original directive, and a signed agreement with an MDR-designated Notified Body.

Separately, the European Commission published a proposal on December 16, 2025 to simplify and reduce administrative burden under both MDR and its IVDR counterpart — including changes to PRRC availability requirements and certificate validity limits. That proposal is still moving through the EU’s ordinary legislative process, and current projections put final adoption no earlier than the second quarter of 2027. Nothing in that proposal changes your obligations today. Manufacturers should keep building technical documentation to the current MDR text rather than waiting on a reform that hasn’t been adopted.

Timeline infographic showing the EU MDR transition deadlines for legacy medical devices in 2026, 2027, and 2028, along with ongoing requirements for technical documentation, clinical evaluation, post-market surveillance, and Notified Body agreements.
This timeline summarizes the current EU MDR transition deadlines for legacy medical devices while highlighting the ongoing compliance activities manufacturers must maintain throughout the transition period.

Do You Need Both? A Decision Framework

  • If you are selling into the EU market → MDR compliance is mandatory, full stop. ISO 13485 certification is not legally required by MDR text, but in practice Notified Bodies expect it as evidence your QMS can sustain the technical file over time.
  • If you are U.S.-only and not yet EU-bound → FDA’s QMSR incorporates ISO 13485:2016 by reference into 21 CFR Part 820, making alignment with ISO 13485 the foundation of U.S. medical device QMS compliance as of February 2, 2026. Third-party certification isn’t mandated by FDA, but the standard’s substance now is.
  • If you are already ISO 13485 certified and expanding into the EU → treat MDR as a device-level project layered on top of your existing QMS, not a QMS rebuild. The gap is almost always in clinical evidence and technical documentation, not in your quality processes.
  • If you are under customer or investor pressure to move fast → get the ISO 13485 gap assessment done first. It surfaces documentation gaps in days instead of finding them mid-audit.

Common Mistakes That Surface in Notified Body Review

Most common finding: Clinical evaluation reports that summarize literature but never tie evidence back to the specific device’s risk profile under Annex I general safety and performance requirements.

Other recurring gaps: PMCF plans that exist as a template but were never executed against real post-market data; UDI and EUDAMED registration treated as an afterthought instead of a parallel workstream; and design change records that don’t clearly show which MDR classification rule applied after a design modification.

⚠️ A Notified Body finding on any of these doesn’t necessarily mean your ISO 13485 QMS has failed — it usually means the QMS and the MDR technical file were built as two separate projects instead of one connected effort.

Quick Reference Checklist

✅ ISO 13485 certificate current and audit-ready
✅ Technical documentation mapped to current MDR Annex II/III requirements ✅ Clinical evaluation report tied to device-specific risk profile
✅ PMCF plan active and generating real post-market data
✅ UDI assigned and EUDAMED registration current
✅ Notified Body agreement in place if relying on legacy transition timelines
✅ Design change records show which classification rule applies post-modification


FAQ

Does ISO 13485 certification satisfy MDR requirements?

No. ISO 13485 certifies your quality management system. MDR requires separate, device-specific technical documentation, clinical evidence, and — for most devices — Notified Body conformity assessment. Certification supports MDR compliance; it doesn’t substitute for it.

Is ISO 13485 mandatory for the EU market?

MDR text doesn’t explicitly mandate ISO 13485 certification, but in practice, Notified Bodies expect a certified QMS as part of demonstrating your ability to sustain compliance. Most manufacturers pursuing MDR conformity hold ISO 13485 certification for this reason.

Do U.S.-only manufacturers need to worry about MDR?

Not directly, unless you plan to sell into the EU. However, FDA’s QMSR — effective February 2, 2026 — makes ISO 13485:2016 the operative U.S. regulation, so ISO 13485 alignment now matters regardless of whether MDR applies to you.

What’s the current MDR transition deadline for legacy devices?

It depends on device classification: Class III custom-made implantables faced a May 26, 2026 deadline, Class III and certain implantable Class IIb devices extend to December 31, 2027, and most other devices extend to December 31, 2028 — provided legacy status conditions are met.

Is the EU actually changing MDR requirements soon?

The European Commission proposed simplification changes on December 16, 2025, but the proposal is still in the EU legislative process, with final adoption not expected before the second quarter of 2027. Current MDR requirements remain fully in effect in the meantime.

What’s the biggest documentation gap Notified Bodies flag?

Clinical evaluation reports that summarize literature broadly without tying the evidence directly to the specific device’s risk profile under the general safety and performance requirements.

Can one gap assessment cover both ISO 13485 certification readiness and MDR technical file readiness?

A well-structured gap assessment should flag both, but they’re different reviews at their core — one audits your QMS against ISO 13485 clauses, the other audits your technical documentation against MDR annexes. Treat them as connected but distinct workstreams.

Where should a manufacturer start if pursuing both?

Start with the QMS. A certified, functioning ISO 13485 system gives you the document control, CAPA, and design control infrastructure that MDR technical documentation depends on. Building MDR documentation on top of a shaky QMS just relocates the problem.


📥 Free Resources

  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements before certification or a Notified Body review.
  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system from the ground up.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements across production environments.

Not Sure What to Do Next?

🔹 Still researching the difference between MDR and ISO 13485? Start with What Is ISO 13485? and FDA QSR vs. ISO 13485 to ground the fundamentals before your next planning meeting.

🔹 Ready to close the documentation gap? Review ISO 13485 Documentation Requirements and Validation & Verification Requirements against your current technical files.

🔹 Need to purchase the standard itself? Get ISO 13485:2016 directly from ANSI Webstore — available internationally, with multi-language editions for global regulatory teams. Use code CC2026 for 5% off through December 31, 2026.


MDR and ISO 13485 solve different problems, and treating them as one project is how audit-ready timelines slip by a quarter or more. The Standards Navigator will keep tracking both as EU reform proposals and FDA QMSR guidance continue to evolve through 2026 and 2027.

Stop Guessing Where Your MDR Gap Actually Is

Regulatory teams that treat MDR and ISO 13485 as one combined project usually discover the gap during a Notified Body review — the worst possible time to find it. Teams that separate the two, and check each on its own terms, walk into that review with documentation that already matches what’s being asked.

The Standards Navigator tracks EU MDR developments, FDA QMSR alignment, and ISO 13485 implementation detail so medical device teams aren’t relying on outdated guidance six months into a submission.

👉 Get updates on MDR, ISO 13485, and medical device regulatory changes as they happen
👉 Be first to access new gap assessment tools and documentation resources for regulatory affairs teams

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.





Sterilization Standards Overview: ISO 11135, 11137, 17665, and 11607 Explained (2026 Guide)

This guide breaks down the four core sterilization standards governing medical devices — ISO 11135 (EtO), ISO 11137 (radiation), ISO 17665 (moist heat), and ISO 11607 (packaging). It covers validation requirements, Sterility Assurance Level, contract sterilizer responsibility, and the most common findings auditors cite in sterilization validation files.

What ISO Actually Requires for EtO, Radiation, Steam, and Sterile Packaging Validation

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Your Sterilization Validation File Is the First Thing an Auditor Opens

A device that isn’t sterile doesn’t ship. That’s the entire premise behind four ISO sterilization standards most regulatory affairs teams only fully understand after a finding forces them to.

ISO 11135 governs ethylene oxide (EtO) sterilization. ISO 11137 governs radiation sterilization (gamma, e-beam, X-ray). ISO 17665 governs moist heat (steam). ISO 11607 governs the sterile barrier packaging that has to keep the device sterile until someone opens it. Supporting all four is ISO 11737, which governs bioburden determination and the sterility test methods used to validate and verify each method. None of them are optional if you’re claiming “STERILE” on a label, and under ISO 13485 and the FDA’s Quality Management System Regulation (QMSR), your device history record has to show a validated process behind that claim — not a one-time test result.

If you’re still building out your quality management system, our ISO 13485 Implementation Roadmap covers where sterilization validation fits into the broader QMS build. If you already have a QMS and are trying to close a specific gap, keep reading.

I’ve reviewed process validation files during ISO 9001 internal audits where the finding wasn’t that the process failed — it was that nobody could produce the record proving why the acceptance criteria were set the way they were. While I haven’t personally validated a sterilization process, I’ve evaluated documentation, traceability, and process validation evidence like this as part of broader QMS audits, and the pattern holds across every process type: auditors don’t just want a passing result, they want the rationale that came before it. Miss that documentation trail and it doesn’t matter how many lots passed — the finding still lands.

Most teams miss this step — check your sterilization documentation against the full standard before your next audit →


In This Guide

  • The four core sterilization method standards and what each one actually requires
  • How ISO 11607 packaging validation fits alongside method validation
  • Sterility Assurance Level (SAL) and why 10⁻⁶ is the number that matters
  • Contract sterilizer relationships — who’s responsible for what
  • Common audit findings in sterilization validation files
  • How these standards connect to ISO 13485, ISO 14971, and the FDA QMSR


👉 Start Here (Top Resources)


Why Sterilization Standards Sit Inside Your QMS

Sterilization validation isn’t a standalone technical exercise — it’s a QMS output. ISO 13485 Clause 7.5.7 specifically requires validation of sterilization processes before routine use. The FDA’s Quality Management System Regulation (QMSR), effective February 2, 2026, makes ISO 13485:2016 the core requirement set for device manufacturers marketing in the U.S., with a defined set of FDA-specific additions layered on top — it’s not a loose reference to “many” of the standard’s requirements, it’s the operative regulation. That means your sterilization validation protocol, your acceptance criteria, and your revalidation schedule all have to trace back into your document control and CAPA systems — the same systems we covered in ISO 13485 Documentation Requirements and CAPA Requirements in ISO 13485.

If you are still finalizing your core QMS documentation → get the sterilization validation SOP structure right before you run your first qualification batch. Retrofitting documentation after the fact is where most rework happens.


The Standards Aren’t Interchangeable

Infographic comparing ISO 11135, ISO 11137, ISO 17665, and ISO 11607, showing the appropriate sterilization method, typical applications, and validation focus for medical devices.
Compare the four primary medical device sterilization standards and see when each ISO standard applies based on the sterilization method and validation requirements.

One of the biggest misconceptions in this space is that manufacturers can choose whichever sterilization standard fits their production schedule best. In reality, the applicable standard is dictated by the sterilization modality itself — not preference. ISO 11135 cannot substitute for ISO 11137, and neither one replaces the packaging validation requirements in ISO 11607. Method selection is a design and materials decision made early in development, and it determines which standard — and which validation pathway — applies for the life of the product.

Real-world example: a disposable syringe is commonly validated under ISO 11137 using gamma or e-beam radiation, while the sterile barrier system around it is separately validated under ISO 11607. An orthopedic power drill with onboard electronics, by contrast, often can’t tolerate radiation dose without degrading — which is why EtO validation under ISO 11135 becomes the practical path, even though it carries a longer aeration and residual-testing burden than radiation would.

StandardCoversValidation FocusTypical Products
ISO 11135Ethylene oxide (EtO)Gas cycle validationElectronics, plastics, mixed-material assemblies
ISO 11137Radiation (gamma / e-beam / X-ray)Dose validationDisposable, polymer-based devices
ISO 17665Moist heat (steam)Temperature/pressure qualificationReusable surgical instruments
ISO 11607Sterile packagingSeal & sterile barrier validationAll terminally sterilized devices

ISO 11135: Ethylene Oxide Sterilization

ISO 11135 covers development, validation, and routine control of EtO sterilization — the most common method for devices with mixed materials, electronics, or complex geometries that can’t tolerate radiation or heat.

The standard requires:

  • Process definition — establishing gas concentration, temperature, humidity, and exposure time that reliably achieves the target sterility assurance level
  • Installation and performance qualification — proving the chamber and load configuration actually deliver the defined process
  • Routine monitoring — biological indicators and process parameter records for every production cycle
  • EtO residual testing — confirming aeration reduces residual gas and byproducts to acceptable levels before release

Watch-outs specific to EtO: aeration time, residual limits, and material compatibility all need documented justification, not just a passing result. If you need the current edition for your validation team, ISO 11135:2014 is available through ANSI Webstore.


ISO 11137: Radiation Sterilization

ISO 11137 covers gamma, electron beam, and X-ray sterilization in three parts: requirements (Part 1), dose setting (Part 2), and dose auditing (Part 3). Radiation is common for single-use, polymer-based disposables produced at volume.

ElementWhat It CoversWhy It Matters in an Audit
Dose settingEstablishing the minimum dose that achieves the target SAL (e.g., VDmax or Method 1 approaches)Auditors want to see the substantiation data, not just the final dose
Dose auditingOngoing verification that the substantiated dose remains effective as product or process changes occurA missed dose audit is a common nonconformance
Material compatibilityPolymer aging, discoloration, and embrittlement risk at the selected doseTies directly into design verification records

If you are switching from gamma to e-beam or X-ray for the same product → you need new dose substantiation data. The modality change is not a paperwork formality. ISO 11137:2025 is the current edition covering dose-setting and dose-auditing requirements.


ISO 17665: Moist Heat Sterilization

ISO 17665 covers steam sterilization — pressurized saturated steam, typically 121°C to 134°C. It remains the preferred method for reusable surgical instruments and devices that tolerate heat and moisture, largely because it’s simple, fast, and doesn’t carry the residual or dose-substantiation burden that EtO and radiation do.

Validation under ISO 17665 centers on physical qualification (proving the autoclave load reaches and holds temperature throughout) paired with biological indicator challenge testing. The standard also requires routine control — meaning every production cycle needs monitored, recorded parameters, not just periodic spot checks. ISO 17665:2024 is the current edition.


ISO 11607: Sterile Packaging

Sterilization validation doesn’t end when the device comes out of the chamber. ISO 11607 — in two parts — governs the sterile barrier system that has to maintain sterility through distribution, storage, and shelf life until the point of use.

Part 1 covers materials, sterile barrier system design, and preformed barrier requirements. Part 2 covers validation of the forming, sealing, and assembly processes used to create that barrier. A device can pass every sterilization requirement in ISO 11135, 11137, or 17665 and still fail on the market if the package seal isn’t validated to hold sterility through the labeled shelf life.

Packaging validation goes well beyond confirming a seal exists. A complete ISO 11607 validation file typically includes seal integrity testing, burst testing, dye penetration testing, and peel strength testing to confirm the barrier holds under mechanical stress — plus transit simulation testing (ASTM D4169 is the common reference standard) to prove the package survives real-world distribution handling, and accelerated aging studies to substantiate the labeled shelf life before real-time aging data exists. Skipping any one of these doesn’t just create an audit finding — it creates a product that may not actually stay sterile on the shelf.

Most common finding: manufacturers validate the sterilization cycle thoroughly but treat packaging validation as an afterthought — seal strength testing without the accompanying shelf-life and transit simulation data auditors expect to see referenced together. ISO 11607:2019 covers both parts of the packaging validation requirement.


Sterility Assurance Level: The 10⁻⁶ Standard

Infographic illustrating the medical device sterilization validation workflow from product design and risk assessment through bioburden testing, process validation, packaging validation, Sterility Assurance Level (SAL), routine monitoring, and periodic revalidation.
Follow the complete sterilization validation workflow, from initial product design through routine monitoring and revalidation, to maintain ISO 13485 and FDA QMSR compliance.

Every one of these standards is built around the same target: a Sterility Assurance Level of 10⁻⁶, meaning no more than a one-in-a-million probability that a viable microorganism survives the sterilization process. SAL isn’t a claim you assert — it’s a number you prove through bioburden testing, biological indicator challenges, and the validation approach specified in the relevant method standard.

This is where ISO 11737 (microbiological methods) connects in. Bioburden testing under ISO 11737-1 establishes your starting point; the sterility test methods in ISO 11737-2 support validation and ongoing verification. If you haven’t mapped your bioburden data into your sterilization validation protocol, that’s a gap worth closing before your next surveillance audit.


Using a Contract Sterilizer Doesn’t Transfer the Risk

The most common objection we hear: “We use a contract sterilizer — isn’t this their responsibility?”

No. Under ISO 13485’s supplier control requirements — covered in detail in Supplier Controls for Medical Devices — the device manufacturer retains ultimate responsibility for the validated state of the sterilization process, even when a contract sterilizer physically performs it. Your quality agreement with that sterilizer needs to define who owns revalidation triggers, who reviews dose audit data, and who gets notified of process deviations. An FDA or notified body auditor will ask you these questions directly — “we outsource it” is not an acceptable answer.


Common Findings in Sterilization Validation Files

Infographic highlighting the five most common sterilization validation audit findings, including dose substantiation, packaging validation, EtO aeration and residual data, revalidation triggers, and contract sterilizer oversight.
Discover the five sterilization validation issues auditors most frequently identify during ISO 13485 and FDA QMSR assessments of medical device manufacturers.
  • Missing or incomplete dose substantiation rationale (radiation)
  • Aeration and residual data not linked to the specific product configuration tested (EtO)
  • Packaging validation treated as separate from — rather than integrated with — sterilization validation
  • Revalidation not triggered after a documented process, material, or supplier change
  • Contract sterilizer quality agreements that don’t specify deviation notification requirements

Common Sterilization Myths

  • Sterile packaging isn’t optional. It’s a validated element of the sterilization claim, not a shipping convenience.
  • Contract sterilizers don’t assume regulatory responsibility. The device manufacturer does, regardless of who runs the cycle.
  • Passing one validation run doesn’t eliminate revalidation requirements. Process, material, or supplier changes reset the clock.
  • SAL isn’t measured by a single sterility test. It’s established through bioburden data, biological indicator challenges, and the validation approach specified in the method standard — not one passing sample.

Quick Audit Checklist

  • ✅ Process definition and qualification records on file for the sterilization method used
  • ✅ Dose substantiation and dose audit data current (radiation only)
  • ✅ Residual and aeration data linked to product-specific testing (EtO only)
  • ✅ Packaging validation (ISO 11607-1 and -2) referenced alongside sterilization validation
  • ✅ Bioburden data mapped to SAL 10⁻⁶ justification
  • ✅ Contract sterilizer quality agreement defines revalidation and deviation ownership
  • ⚠️ Revalidation schedule reviewed after any process, material, or supplier change

Not sure your current documentation would hold up? Run it against the ISO 13485 Gap Assessment Checklist before your next scheduled audit →


FAQ

What’s the difference between ISO 11135 and ISO 11137?

ISO 11135 governs ethylene oxide (EtO) sterilization, a gas-based low-temperature method suited to mixed-material and electronic devices. ISO 11137 governs radiation sterilization — gamma, e-beam, and X-ray — typically used for high-volume, polymer-based disposables. They require different validation approaches: dose substantiation for radiation, and gas concentration/exposure/aeration qualification for EtO.

Does ISO 17665 apply to reusable devices?

Yes. ISO 17665 covers moist heat (steam) sterilization, which is the most common method for reusable surgical instruments and devices that tolerate heat and moisture without degradation.

Is ISO 11607 required if I use a contract packaging supplier?

Yes. ISO 11607 validation requirements apply regardless of whether packaging design and sealing are performed in-house or by a contract supplier. The device manufacturer is responsible for confirming that validation data exists and is current for the specific packaging configuration used.

What is Sterility Assurance Level (SAL) and why is 10⁻⁶ the target?

SAL is the probability that a single viable microorganism survives a sterilization process. A SAL of 10⁻⁶ means no more than a one-in-a-million chance — the internationally recognized benchmark for terminally sterilized medical devices across ISO 11135, 11137, and 17665.

Do I need to revalidate if I switch contract sterilizers?

In most cases, yes. A change in sterilizer, chamber configuration, or load pattern can affect cycle parameters even when the method and standard stay the same. Revalidation requirements should be defined in your change control procedure, not decided case by case.

How does ISO 14971 relate to sterilization validation?

ISO 14971 risk management informs the acceptance criteria and failure mode analysis behind your sterilization validation protocol — particularly for identifying what happens if sterility assurance isn’t achieved. See our breakdown in Risk Management in Medical Devices for how the two standards connect.

Does the FDA QMSR require anything beyond ISO 13485 for sterilization?

The QMSR incorporates ISO 13485 by reference, so the core sterilization validation requirement flows through Clause 7.5.7. FDA also maintains a Recognized Consensus Standards database mapping specific editions of ISO 11135, 11137, 17665, and related standards — always confirm current recognition status before citing a specific edition in a submission.

What’s the most common reason sterilization validation fails an audit?

Missing documentation trail — not process failure. Auditors most often cite an inability to produce the rationale behind acceptance criteria, dose substantiation, or revalidation triggers, even when every routine monitoring record shows a passing result.


Not Sure What to Do Next?

🔹 Still researching your sterilization pathway? Read What Is ISO 13485? to see how sterilization validation fits into the full QMS picture.

🔹 Ready to close documentation gaps before your next audit? BSI Group’s ISO 13485 training walks through the clauses that govern sterilization validation records.

🔹 Need the actual standard text for your validation team? If you’re purchasing more than one, the ANSI Webstore Medical Device Packages bundle covers ISO 13485, ISO 14971, and the sterilization standards together — often at a lower combined cost than buying each individually.


📥 Free Resources


The Documentation Trail Is the Real Deliverable

Sterilization validation isn’t a lab exercise you complete once and file away — it’s a living record your QMS has to maintain across every process, material, and supplier change. Get the documentation structure right the first time, and the biological indicator result becomes the easy part. The Standards Navigator will keep tracking updates to ISO 11135, 11137, 17665, and 11607 as FDA recognition status evolves, so you’re not caught citing a superseded edition.

📬 Stay Ahead of Your Next Sterilization Audit

Most sterilization validation findings don’t come from a failed cycle — they come from a documentation trail an auditor can’t follow six months later. Manufacturers who treat sterilization validation as a one-time project end up scrambling before every surveillance audit; the ones who build revalidation triggers into their change control process rarely get surprised.

The Standards Navigator tracks sterilization, packaging, and QMS standard updates specifically for medical device manufacturers navigating ISO 13485 and the FDA QMSR.

👉 Get updates on sterilization and medical device compliance standards 👉 Be first to access new ISO 13485 gap assessment tools and checklists

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.