How to Audit a Medical Device QMS: The ISO 13485 Internal Audit Process (2026 Guide)

This guide walks medical device manufacturers through the ISO 13485 Clause 8.2.4 internal audit requirement — including audit program design, the six-step audit process, and the five most common findings auditors cite. It also covers what changed under the FDA QMSR and the new ISO 19011:2026 audit guidance.

A clause-by-clause guide to planning, conducting, and closing out ISO 13485 internal audits under the new FDA QMSR

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Internal Audit That Used to Be Private Isn’t Anymore

For years, medical device manufacturers treated the internal audit report as an internal document — useful for finding problems, but shielded from FDA inspectors under the confidentiality provision in the old 21 CFR 820.180(c). That protection is gone.

Since February 2, 2026, the FDA’s Quality Management System Regulation (QMSR) has been in effect, and it incorporates ISO 13485:2016 by reference rather than running a parallel U.S.-specific standard alongside it. FDA’s own Final Rule FAQ is direct about what that means for audits: “The QMSR gives the FDA the authority to inspect management review, quality audits, and supplier audit reports. The exceptions that existed in the QS regulation at § 820.180(c) are not maintained in the QMSR.” That’s not a third-party interpretation — it’s FDA’s own published position.

So this isn’t limited to internal audit reports. Management review minutes and supplier audit reports lost the same protection. A checklist you run through once a year to satisfy Clause 8.2.4 on paper is no longer a low-risk approach — it’s now a document an inspector may read line by line, and so are the meetings where leadership reviewed it.

From the Floor: I’ve built and run internal audit programs at facilities with 500-plus employees, and the finding that costs organizations the most isn’t a missing procedure — it’s a corrective action that gets closed on paper before the root cause is actually fixed. As a certified ISO 9001 Internal Auditor, I’ve sat across the table from auditors who catch that in about ninety seconds. Whether you’re auditing to ISO 9001 or ISO 13485, the internal audit only works if it’s harder on you than the external one will be.

Before your next surveillance audit, most quality teams don’t fail because they misunderstand Clause 8.2.4 — they fail because their audit program looks complete on paper but hasn’t been stress-tested against real objective evidence. Run your QMS through the free ISO 13485 Gap Assessment Checklist before an inspector or a Notified Body does it for you.


In This Guide

  • What ISO 13485 Clause 8.2.4 actually requires
  • How internal audits differ from supplier and certification audits
  • What Clause 6.2 actually requires of your auditors — and what “competent” really means
  • Building a risk-based annual audit program
  • The audit process: planning, evidence, reporting, and CAPA follow-up
  • A real finding-to-CAPA example, start to finish
  • The five most common internal audit findings — and how to avoid them
  • What changes if you’re audited under MDSAP
  • What changed under the FDA QMSR and ISO 19011:2026
  • Whether you need outside help or can run this internally


👉 Start Here (Top Resources)


What Clause 8.2.4 Actually Requires

ISO 13485 requires internal audits under Clause 8.2.4 to verify that QMS processes are implemented and effective, catch nonconformities, and surface QMS deficiencies early enough that they don’t become product-safety or regulatory problems. That sounds close to ISO 9001’s internal audit clause, and it is — but ISO 13485 asks for more.

Clause 8.2.4 requires that internal audits determine conformity to planned arrangements, the requirements of the standard, the organization’s own QMS requirements, and applicable regulatory requirements — and unlike ISO 9001, ISO 13485 explicitly requires the audit program to account for regulatory requirements such as FDA 21 CFR Part 820, EU MDR, or MDSAP alongside the standard itself. Teams that build their audit program purely off the ISO 13485 clause structure, without folding in the regulatory layer, are the ones who get flagged.

Most common finding: auditors treat Clause 8.2.4 as a documentation-review exercise and skip the regulatory cross-reference entirely. If your audit checklist doesn’t ask “does this also satisfy 21 CFR Part 820 or MDR Article 10?” it isn’t finished.

Audits must assess conformity across critical processes — design and development under Clause 7.3, corrective action under Clause 8.5.2, preventive action under Clause 8.5.3, production under Clause 7.5, and document control under Clause 4.2 — using objective evidence like device history records, audit trails, and validation records. Auditors must be trained, qualified, and independent of the area they’re auditing, with that competence documented under Clause 6.2.

If you are already ISO 9001 certified → your internal audit infrastructure transfers directly, but your checklist needs a regulatory column added for every process area, not just a conformity column.


Internal Audits vs. Supplier Audits vs. Certification Audits

Comparison infographic showing internal audits, supplier audits, and certification audits under ISO 13485.
Understanding the differences between internal, supplier, and certification audits improves audit planning and regulatory compliance.

Manufacturers frequently conflate these three, and an auditor will notice immediately if your procedure does too.

Audit TypeGoverning ClausePerformed ByPrimary Purpose
Internal AuditClause 8.2.4Trained internal personnel, independent of the area auditedVerify your own QMS conforms to the standard and your own procedures
Supplier AuditClause 7.4.1Quality or supplier quality personnelVerify external providers meet quality and regulatory requirements
Certification AuditISO/IEC 17021-1Accredited third-party Notified Body or registrarDetermine whether the full QMS meets ISO 13485 for certification

ISO 13485 requires internal audits, just as its sister standard ISO 9001 does, and they exist for two reasons: to confirm the QMS meets the standard’s requirements, and to confirm the organization actually follows its own rules. A strong internal audit program is what makes a certification audit uneventful instead of a fire drill.


Auditor Competence: What Clause 6.2 Actually Requires

This is the section most audit programs get thin on, and it’s where a surprising number of otherwise solid internal audit programs fall apart under scrutiny.

Clause 6.2 requires that anyone doing work affecting product quality — and that includes auditors — be competent based on appropriate education, training, skills, and experience. ISO 13485 doesn’t spell out a fixed list of required knowledge areas the way a checklist would, but three areas consistently show up when a Notified Body reviews auditor files:

  • The standard itself. A working knowledge of ISO 13485:2016 clause structure, not just the SOPs written to satisfy it.
  • Audit methodology. Understanding of the audit cycle — planning, evidence gathering, reporting, follow-up — along with the difference between a minor observation and a major nonconformity. ISO 13485’s own note under Clause 8.2.4 points auditors toward ISO 19011 for this.
  • Applicable regulatory context. Basic familiarity with the regulations that apply to your product and markets — 21 CFR Part 820, EU MDR, MDSAP — not full legal mastery, but enough to recognize when a finding also touches a regulatory requirement.

Competence is not the same thing as certification. ISO 13485 does not require a certified internal auditor credential, and ISO 19011 doesn’t mandate formal training either — the standard’s actual requirement is that the audit process ensure objectivity and impartiality, and that competence be evaluated and documented. In practice, though, “read and understand the internal procedure” is not evidence Notified Bodies accept as sufficient. An auditor who can’t produce a training record, a completed course certificate, or documented on-the-job evaluation showing how their competence was assessed is a finding waiting to happen — even if that person is, in fact, good at the job.

What acceptable training records look like in practice:

  • A certificate of completion from an ISO 13485 internal auditor course (typically covering the standard itself plus ISO 19011 audit methodology) — see BSI vs. ISOQAR if you’re deciding where to send your team for that training
  • Internal on-the-job qualification records — a documented mentored audit or two, signed off by a qualified lead auditor
  • A training matrix that ties each auditor to the specific processes and clauses they’re qualified to audit, refreshed when the QMS or the standard changes

Auditor independence gets checked alongside competence. The most frequent failure here isn’t a skills gap — it’s a quality manager who owns a process auditing that same process, or an auditor rotation that never actually rotates the highest-risk areas like design controls.

If you are not confident your auditor files would hold up to this list → that’s a fifteen-minute file review, not a project, and it’s worth doing before your next Notified Body visit rather than during it.


Building a Risk-Based Audit Program

The audit program must cover every process, department, and site within your QMS scope, with audit frequency determined by the status and importance of each process along with the results of prior audits. High-risk processes — design and development, production, CAPA, and complaint handling — typically need at least annual coverage, while lower-risk support functions can be audited less frequently if previous results were consistently clean.

Most manufacturers get the frequency question backwards. They audit everything on a flat annual calendar instead of weighting toward where the last audit found something. If your CAPA process had a finding last year, auditing it again on the same twelve-month clock as your HR training records is a scheduling decision an inspector will question.

If you are preparing for your first surveillance audit under the new QMSR → build your program around the regulatory cross-reference first, then layer the standard’s clause structure on top of it — not the other way around.


The Internal Audit Process, Step by Step

Infographic illustrating the ISO 13485 internal audit process from planning through CAPA verification for medical device quality management systems.
The six-step ISO 13485 internal audit process helps medical device manufacturers identify nonconformities and verify corrective actions.

Prepare a checklist based on the relevant clauses of ISO 13485, your documented procedures, and applicable regulatory requirements — a good checklist prompts investigation rather than simply confirming what’s already assumed to be true.

1. Scope and schedule. Define which processes, sites, and clauses are in scope for this audit cycle.

2. Documentation review. Analyze the quality manual, procedures, and prior audit reports before setting foot on the floor — this is where checklists get mapped to specific clauses.

3. Opening meeting. Confirm scope, objectives, and methodology with the auditee before evidence-gathering begins — this sets the tone for the entire audit.

4. Evidence gathering. Collect objective evidence through interviews, direct observation, and document/record review — no finding should be written down without evidence behind it.

5. Reporting. Findings get written up, classified by severity, and routed to the process owner and management.

6. CAPA follow-up. Every corrective action needs documented root cause analysis appropriate to the significance of the nonconformity, with effectiveness verified before the CAPA is closed.

Most teams execute steps 1 through 5 competently. Step 6 is where programs fall apart — a CAPA gets marked closed the day the immediate fix is implemented, with no verification that the fix actually held.

Trigger: If your last three internal audits found the same category of nonconformity in different words each time, that’s not three separate findings — that’s one root cause your CAPA process never actually reached.

Before your next audit cycle, check your CAPA closure process against what auditors actually verify — most teams don’t realize how thin their effectiveness checks are until someone else reviews them.


A Real Finding, Start to Finish

Steps on a page are easy to nod along with. Here’s what a properly closed finding actually looks like end to end, using one of the most common design-control gaps auditors find.

StageWhat It Looked Like
FindingDuring a design and development audit, three of twelve design verification records sampled were missing the reviewer’s signature. Work was completed and dated, but sign-off wasn’t captured.
Objective EvidenceDesign History File records DHF-114, DHF-119, and DHF-122, cross-referenced against the design review meeting minutes showing the reviews occurred.
Nonconformity Statement“Design verification records DHF-114, DHF-119, and DHF-122 lack the required reviewer signature per QMS-SOP-014, Section 6.2. Design and development control per ISO 13485:2016 Clause 7.3.6 requires verification results, including necessary actions, to be recorded.”
Root CauseInvestigation traced it to a recent SOP revision that moved the sign-off step later in the workflow. Staff hadn’t been retrained on the updated sequence — the procedure changed, but the training that should have accompanied it under Clause 6.2 didn’t happen.
CorrectionThe three records were completed retroactively with the reviewer’s signature and a note explaining the delay, reviewed and accepted by the quality manager.
Corrective Action (CAPA)Retrain design team on the revised sign-off sequence; add a mandatory signature field to the design review template so records can’t be filed incomplete.
Effectiveness CheckSample the next ten design verification records over the following quarter. Zero missing signatures required to close the CAPA as effective.

Notice what makes this closeable rather than cosmetic: the root cause isn’t “people forgot” — it’s a training gap tied to a specific procedure change, and the corrective action addresses the system, not just the three records. That’s the difference between a finding that stays closed and one that reappears with different reference numbers next year.


The Five Most Common Findings

Infographic highlighting the five most common ISO 13485 internal audit findings in medical device quality management systems.
The most common ISO 13485 internal audit findings often involve documentation, CAPA effectiveness, auditor competence, and risk-based planning.

Incomplete audit records — missing reports, plans, or linked CAPAs — is one of the most frequently cited internal audit issues. A close second is failing to apply a risk-based approach to audit planning, or simply not maintaining the internal audit schedule at all. Beyond that, auditors regularly find no timely follow-up on actions from internal audits, no records showing auditor competence against the applicable regulations, and auditors who weren’t actually impartial — reviewing work they had a hand in.

Design and development controls remain the single most frequently cited nonconformity area globally — incomplete design inputs, missing verification or validation records, undocumented design changes, or no formal design transfer procedure. See Validation & Verification Requirements for how this plays out in practice.

⚠️ If your auditor rotation lets the same person audit design controls year after year without ever being audited themselves on that same process, that’s an impartiality gap that a Notified Body will flag before you do.

If you are not confident your last internal audit would hold up under this list → that’s exactly what a structured gap assessment is for, not a guess.

Check your program against these five findings before your next audit — most gaps take under 45 minutes to identify →


MDSAP: What Changes for Multi-Market Audits

If your devices sell into more than one of the five MDSAP markets — the U.S., Canada, Australia, Brazil, or Japan — your internal audit program needs to account for a different audit model, not just an extra regulatory reference.

The Medical Device Single Audit Program lets one audit by an accredited Auditing Organization satisfy the requirements of all five participating regulators at once, in place of separate national audits. It’s built on ISO 13485:2016, but it isn’t a straight overlay — MDSAP uses a process-based audit model with a defined sequence, rather than working straight down the ISO clause list, and it maps every audit task to both the relevant ISO 13485 clause and each country’s specific regulatory requirement.

The grading system is the biggest practical difference. Where an ISO 13485 certification audit typically classifies findings as minor or major, MDSAP uses a points-based Grade 1–5 scale: nonconformities affecting clauses with indirect QMS impact start lower, direct-impact clauses start higher, and points are added for repeat findings or for a nonconforming product that was actually released. Grade 4 and 5 findings must be resolved before a certificate is issued or maintained — there’s no ambiguity about severity once the math is run.

What this means for your internal audit program: if you’re pursuing or maintaining MDSAP, your internal audits should follow the MDSAP process sequence — not just walk through ISO 13485 clauses in order — so that gaps surface in the same structure an Auditing Organization will use. The recurring findings across published MDSAP audits track closely with the same weak points internal audits should already be hunting for: open CAPAs left unclosed past a reasonable window, supplier and purchasing controls that don’t demonstrate follow-through, and root cause analysis that’s thin enough to not survive a second look.

One benefit worth knowing about: MDSAP audit reports can substitute for the FDA’s routine biennial device inspections. A well-run MDSAP program isn’t just multi-market efficiency — it can reduce how often FDA shows up separately.


What Changed: QMSR and ISO 19011:2026

Two regulatory shifts affect how internal audits get run in 2026, and both are recent enough that older internal procedures may not reflect them.

Since February 2, 2026, the FDA’s QMSR has incorporated ISO 13485:2016 by reference, replacing the former Quality System Regulation, and FDA inspections now run under Compliance Program 7382.850 rather than the old QSR framework. As covered above, the practical effect for internal audits is direct: the confidentiality safe harbor that used to apply to internal audit reports, management review records, and supplier audit reports under the old 21 CFR 820.180(c) has been removed, and FDA’s own FAQ confirms it in plain language.

Separately, ISO published the fourth edition of ISO 19011 — Guidelines for auditing management systems — on May 27, 2026, replacing the 2018 edition that had guided audit programs for nearly eight years. ISO 13485 doesn’t mandate ISO 19011 compliance directly — Clause 8.2.4 references audit principles in its own language — but Notified Bodies and experienced auditors widely treat ISO 19011 as the authoritative reference for structuring an audit program, so if your internal audit SOPs still cite the 2018 edition, expect your Notified Body to ask why.

Neither change requires rebuilding your program from scratch. Both are reasons to review your internal audit SOP this year rather than next.


Quick Audit-Readiness Checklist

✅ Audit program covers every process, site, and department in your QMS scope ✅ Audit frequency is risk-weighted, not a flat annual calendar
✅ Every checklist item maps to a specific ISO 13485 clause and the applicable regulatory requirement
✅ Auditors are independent of the area they’re reviewing, with Clause 6.2 competence records on file — not just “read and understand” sign-offs
✅ Findings are backed by objective evidence — interviews, observation, or documented records
✅ CAPA effectiveness is verified before closure, not assumed
✅ If pursuing MDSAP, internal audits follow the MDSAP process sequence, not just the ISO clause order
✅ Internal audit SOP references ISO 19011:2026, not the 2018 edition
✅ Design and development records are current — this is the single most-cited finding category


FAQ

How often does ISO 13485 require internal audits?

The standard doesn’t specify a fixed interval — it requires audits “at planned intervals” based on process risk and prior audit history. Most manufacturers audit high-risk processes like design controls and CAPA annually at minimum, with lower-risk support functions audited less frequently if history is clean.

Can the same person who performs a process also audit it?

No. Clause 8.2.4 requires auditors to be independent of the area being audited. A quality manager who owns the CAPA process, for example, shouldn’t be the one auditing CAPA compliance.

Do internal auditors need a formal certification?

No. ISO 13485 requires documented competence — education, training, skills, and experience — but doesn’t mandate a specific certification. In practice, most Notified Bodies expect more than an internal read-and-understand sign-off, so a course certificate or documented mentored-audit record is the safer standard to work toward.

Does the FDA QMSR require a separate internal audit program from ISO 13485?

No. Since the QMSR incorporates ISO 13485:2016 by reference, there isn’t a separate U.S.-specific internal audit requirement layered on top — your Clause 8.2.4 program is the audit program the FDA now expects, with the regulatory cross-reference built in.

Are internal audit reports confidential from FDA inspectors?

Not anymore. FDA’s own QMSR Final Rule FAQ confirms the confidentiality exceptions under the old 21 CFR 820.180(c) — covering internal audits, management review, and supplier audits — are not maintained under the QMSR.

What’s the difference between an internal audit and a supplier audit under ISO 13485?

Internal audits (Clause 8.2.4) evaluate your own QMS. Supplier audits (Clause 7.4.1) evaluate external providers’ ability to meet your quality and regulatory requirements. Both are required, but they’re separate programs with separate scopes.

Does MDSAP replace our ISO 13485 internal audit requirement?

No, but it changes the structure. MDSAP is built on ISO 13485 and layers in country-specific regulatory requirements from up to five markets, using a process-based sequence and a points-based Grade 1–5 nonconformity system rather than the minor/major classification used in standard certification audits.

What’s the most common reason internal audit programs fail a certification audit?

Incomplete records — missing audit reports, plans, or linked CAPAs — combined with no evidence of a risk-based approach to scheduling. Both are findings a Notified Body catches quickly because they’re procedural gaps, not technical ones.

Should we hire a consultant to run our internal audits, or can we do it ourselves?

Either can work if the auditor is properly trained and genuinely independent of the process. Many manufacturers use in-house auditors for most cycles and bring in an outside auditor periodically to test whether their internal program is actually rigorous or just familiar with its own blind spots.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching your audit obligations? Start with ISO 13485 Documentation Requirements to understand what your QMS needs on paper before you audit it.

🔹 Ready to build or strengthen your audit program? 9001Simplified’s documentation templates can shortcut the SOP-writing process without a consultant retainer.

🔹 Need the standard itself to build your checklist against? Get ISO 13485:2016 from ANSI Webstore — code CC2026 takes 5% off through the end of 2026.


An internal audit program that only exists to satisfy Clause 8.2.4 on paper was already a risk before the QMSR removed the confidentiality safe harbor. Now it’s a document an inspector can read directly. The Standards Navigator will keep tracking what QMSR enforcement and ISO 19011:2026 mean for how medical device manufacturers actually run their audit programs — not just what the clause says.


Subscribe for Medical Device Compliance Updates

Most manufacturers don’t lose a certification over one bad audit finding — they lose it over a pattern of findings their own internal audit program should have caught first. Organizations that treat Clause 8.2.4 as a paperwork requirement get surprised at surveillance. Organizations that treat it as their first line of defense rarely do.

The Standards Navigator tracks how ISO 13485, the FDA QMSR, and the standards that govern medical device audits actually work in practice — not just what the clause text says.

👉 Get updates on ISO 13485 audit requirements and QMSR enforcement changes 👉 Be first to access new medical device compliance checklists and gap assessment tools

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

ISO 10993 Contact Duration Matrix- How to Select Tests (2026 Guide)

ISO 10993-1:2025 retired the old Table A.1 checklist approach to biocompatibility testing. This guide explains the current contact duration categories, how total exposure period is calculated for reusable devices, and which biological endpoints apply — including FDA’s partial recognition of the new edition.

ISO 10993 Contact Duration Matrix and Biological Endpoint Selection Explained

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Matrix Changed. If Your Biological Evaluation Plan Still Reads Like 2018, You Have a Gap

Table A.1 is gone. For seven years, biological evaluation plans were built around a single grid in Annex A of ISO 10993-1:2018 — cross-reference device category and contact duration, check the boxes, done. That table has been retired. ISO 10993-1:2025, published November 18, 2025, split it into four separate tables and rebuilt the exposure-duration logic underneath them.

ISO 10993-1:2025 is the international standard that guides biocompatibility and biological evaluation of medical devices using a risk-based framework, replacing the prescriptive checklist approach of the 2018 edition.

If your BEP still cites the 2018 ISO 10993 contact duration matrix, or if you categorized a reusable device’s contact duration based on a single use rather than total exposure period, you may already be carrying a documentation gap — one that surfaces exactly when a reviewer or notified body opens your file.

Regulatory affairs teams are asking a narrower question than “what is ISO 10993”: which biological endpoints does this specific device trigger under the current framework, and why. That’s what this guide walks through.

I’ve sat across the table from an auditor reviewing a biological evaluation plan where the contact duration category didn’t match the device’s actual use pattern — a reusable component that looked like “limited” contact on paper but was accumulating well past 24 hours across a single patient’s treatment course. The documentation existed. The categorization logic behind it didn’t hold up. That’s the gap this guide is built to close before it becomes a finding.

👉 Before you finalize your next biological evaluation plan, run it against a structured QMS gap check first. Get the free ISO 13485 Gap Assessment Checklist and confirm your documentation controls support the categorization decisions your BEP depends on.

In This Guide

  • What changed in the ISO 10993-1:2025 evaluation matrix and why Table A.1 was retired
  • The current contact duration categories and how “total exposure period” is calculated
  • How to categorize daily contact, intermittent contact, and reusable devices correctly
  • Which biological endpoints apply to each contact duration and body-contact combination
  • What FDA’s partial recognition of ISO 10993-1:2025 means for your submission
  • Common categorization mistakes that trigger additional testing requirements
  • Where to buy the current standard and where to get ISO 13485-aligned training


👉 Start Here (Top Resources)

  • ISO 10993-1:2025 — ANSI Webstore — the current edition, direct from the accredited source. Use code CC2026 for 5% off. (Eric: insert the exact ANSI product link for ISO 10993-1:2025 here.)
  • If you’re weighing whether to buy standards individually or as a set, the ANSI bundle option is worth checking before you purchase the 10993 series piece by piece.
  • ISO 13485 Training — BSI Group — for teams building biological evaluation competency into a certified QMS.
  • ISO Training Courses — ISOQAR — a second accredited training option worth comparing against BSI on schedule and price.

Why the Evaluation Matrix Was Restructured

Under ISO 10993-1:2018, Annex A Table A.1 organized devices by body contact category — surface, external communicating, implant — crossed with three contact duration bands, and listed an “X” for every biological endpoint a reviewer might expect to see addressed. Industry insiders came to call it the “Table A.1 mentality”: manufacturers treated the X’s as a mandatory checklist rather than a starting point for risk-based justification. Tests got run because they appeared in a cell, not because a documented risk assessment called for them.

ISO 10993-1:2025 splits that single table into four separate tables, each tied to a specific evaluation context, and embeds the framework more tightly into the ISO 14971 risk management process. The standard now expects a Biological Evaluation Plan built on the device’s actual risk profile — chemical characterization, materials history, intended use, contact pattern — with the tables used to check completeness, not generate a test order.

Most common finding: biological evaluation plans that cite “Table A.1” by name, or that list endpoints without a documented rationale tied to the device’s specific exposure profile. Under the current standard, that’s a gap a reviewer will flag.

If you are still building your first BEP for a device entering the medical device space, start with what the supplier controls requirements under ISO 13485 expect from your materials documentation — biological evaluation depends heavily on having reliable supplier and materials data before you ever get to a test matrix.

Contact Duration Categories, Defined

The three contact duration categories are unchanged in name but recalculated in practice:

CategoryCumulative ContactTypical Devices
LimitedUp to 24 hours totalDiagnostic swabs, single-use syringes, short procedural instruments
ProlongedMore than 24 hours, up to 30 days totalWound dressings changed over several weeks, indwelling catheters (short-term), orthodontic devices
Long-term / PermanentMore than 30 days totalImplants, permanent orthopedic hardware, long-term catheters

The category itself hasn’t moved. What changed is how you calculate “total contact” for a device that isn’t used in one continuous stretch — and that recalculation is where most categorization errors happen.

If you are evaluating a device used in short, repeated sessions → don’t categorize based on a single session length. The standard expects you to sum all contact time across the device’s full use pattern before assigning a category.

Daily Contact vs. Intermittent Contact

Comparison infographic explaining daily contact and intermittent contact under ISO 10993-1:2025 for biological evaluation of medical devices.
ISO 10993-1:2025 distinguishes between daily and intermittent contact when determining cumulative exposure for biological evaluation.

ISO 10993-1:2025 formalizes two exposure patterns that the 2018 edition handled inconsistently:

  • Daily contact — the device touches the body every day, for any portion of a day, across a defined treatment course. Total exposure is counted as calendar days from first use to last use (or replacement) on a single patient.
  • Intermittent contact — use with at least 24 hours between consecutive contacts. This is treated as repeated use of the same device, or a replacement device, under evaluation.

A wound contact layer changed daily over three weeks is the textbook example: under the 2018 edition, each dressing change might have been assessed as its own “limited” exposure. Under the current standard, the 21 cumulative contact days push the device into prolonged territory — and that shift can add endpoints your original evaluation never considered.

If you are re-evaluating a device that was cleared under the 2018 categorization logic → don’t assume your existing category still holds. Run the total exposure period calculation against the current definitions before you finalize anything for a new submission.

Reusable Devices and Total Exposure Period

Reusable devices are now categorized based on cumulative contact time for a single patient across the device’s full use pattern — not the duration of any one use, and not a multi-patient device service-life total. A reusable surgical instrument sterilized and reused across a procedure series looks brief per individual contact, but the relevant figure is how many total contact days that one patient accumulates across their treatment course, including reasonably foreseeable misuse such as use beyond the labeled reprocessing cycle count.

Bioaccumulation is a related but less settled consideration. FDA’s Supplementary Information Sheet for ISO 10993-1:2025 (Recognition No. 2-313) notes that ISO/TC 194 Working Group 1 is still developing technical reports specifically addressing bioaccumulation, intermittent contact, and reasonably foreseeable misuse. In practice: if chemical characterization data — extractables and leachables — raises a bioaccumulation concern, that finding should inform your risk assessment and may support escalating the device’s category, but document it as a risk-based judgment rather than treating it as a fixed clause requirement until the supporting technical reports are finalized.

For teams managing this inside a certified QMS, it’s a judgment call that needs to trace back to a documented decision — not a verbal risk call made in a meeting. Clause 9 of ISO 10993-1:2025 requires that biological evaluations be planned, conducted, and reported by competent personnel, with the evaluation report documenting the rationale behind risk decisions like this one. The CAPA requirements under ISO 13485 apply just as much to a categorization correction as to a nonconformance on the shop floor.

Flowchart explaining cumulative single-patient exposure for reusable medical devices under ISO 10993-1:2025.
Reusable medical devices are categorized using cumulative single-patient exposure rather than the duration of a single procedure.

Mapping Contact Category to Biological Endpoints

The biological effects under consideration haven’t fundamentally changed — cytotoxicity, sensitization, irritation, systemic toxicity, genotoxicity, implantation effects, and hemocompatibility remain the backbone, and ISO 10993-1 remains a risk-based framework, not a mandatory testing checklist. What changed is the scope of consideration required, particularly for genotoxicity:

Contact DurationBody ContactGenotoxicity Consideration
LimitedAnyCase-by-case, per risk assessment
ProlongedAll tissues except intact skinGenerally expected to be addressed per Tables 2–4 and Clause 6.5.7
Long-term / PermanentAll tissues except intact skinGenerally expected to be addressed per Tables 2–4 and Clause 6.5.7

Under the 2018 edition, genotoxicity was consistently expected for implants and long-term tissue contact, but inconsistently applied to prolonged-contact devices touching mucosal membranes or breached surfaces. ISO 10993-1:2025 narrows that inconsistency: per Tables 2–4 and Clause 6.5.7, any device requiring systemic toxicity evaluation due to prolonged or long-term contact is now generally expected to address genotoxicity as well, intact skin excepted — though this remains a risk assessment expectation to be justified within your Biological Evaluation Plan, not an automatic in vivo test order. Where existing data (toxicological risk assessment under ISO 10993-17, chemical characterization, or literature) already addresses the risk adequately, testing may not be necessary. Carcinogenicity consideration was similarly extended for long-term contact with intact mucosal membranes.

Worth flagging directly: FDA’s Supplementary Information Sheet for ISO 10993-1:2025 (Recognition No. 2-313) identifies a genuine discrepancy here. ISO 10993-1:2025 lists genotoxicity as an endpoint for consideration across all prolonged-contact device categories, while FDA’s own Table A.1 (Attachment A of its 2023 Biocompatibility Guidance) limits the genotoxicity endpoint to implanted devices, externally communicating devices with tissue/bone/dentin contact, and externally communicating devices with circulating blood contact. For a U.S. submission, don’t assume the broader ISO scope automatically controls — confirm which framework your reviewer expects you to follow.

Most common finding: biological evaluation plans for prolonged-contact mucosal devices that address systemic toxicity but don’t document a genotoxicity rationale one way or the other — an omission that was easier to overlook under the 2018 matrix and is more likely to draw a question under the current one.

If your device’s evaluation also touches sterilization residuals, review our sterilization standards overview — ethylene oxide and other sterilization residues are a recurring driver of chemical characterization findings that reshape a biological evaluation.

FDA’s Partial Recognition — What’s Excluded

FDA recognized ISO 10993-1:2025 on May 25, 2026 (Recognition No. 2-313 in FDA’s Recognized Consensus Standards database), but the recognition is partial, not full. Two carve-outs from the Supplementary Information Sheet matter for submission strategy:

  • The phrase “consumer products or” in Clause 6.5.11.3 (Low Risk Intact Skin Contacting Medical Devices) is not recognized — FDA states it conflicts with Attachment G of its 2023 biocompatibility guidance, which limits which historical-use materials qualify for reduced testing on skin-contacting devices.
  • Clause 6.9, Biological risk estimation, is not recognized — FDA holds it conflicts with the risk estimation approach already established under ISO 14971:2019, which FDA separately recognizes.

If you are preparing a 510(k), PMA, or De Novo submission → you cannot submit a full Declaration of Conformity without addressing these two exclusions directly, and the genotoxicity discrepancy above is a separate, related point worth raising with your reviewer proactively. Cite the standard, but demonstrate compliance for the excluded clauses through FDA’s existing biocompatibility guidance rather than assuming automatic alignment. FDA’s recognized standard entry and Supplementary Information Sheet have already been updated since publication — verify the current version directly against FDA’s Recognized Consensus Standards database before finalizing any submission.

For the broader shift this represents in medical device documentation expectations, see our breakdown of validation and verification requirements under ISO 13485 and the FDA QMSR.

Common Categorization Mistakes

Infographic highlighting common ISO 10993 biological evaluation and contact duration categorization mistakes for medical device manufacturers.
Many ISO 10993 audit findings result from incorrect categorization logic or incomplete biological evaluation documentation rather than testing failures.

⚠️ Categorizing by single-use duration instead of cumulative single-patient exposure. The single most common error on reusable and repeat-use devices — it understates the contact category more often than it overstates it.

⚠️ Citing “Table A.1” in a current BEP. A reference to the old table structure is a documentation red flag on its own, independent of whether the underlying science holds up.

⚠️ Assuming genotoxicity doesn’t need to be addressed for prolonged mucosal contact. Teams working from older templates default to a 2018-era endpoint list and skip documenting a rationale either way — under the current tables, that gap is more likely to draw a question.

⚠️ Assuming FDA recognition is full, or that ISO and FDA genotoxicity scope match. Building a submission strategy around blanket alignment, without addressing the excluded clauses and the genotoxicity scope discrepancy, invites an avoidable deficiency letter.

If you are unsure whether existing biological evaluation plans need revisiting → they don’t automatically require retesting, but ISO 10993-1:2025 does expect a documented review confirming prior categorization and endpoint rationale still hold under current definitions.


Quick Audit Checklist

✅ Contact duration category calculated from cumulative single-patient exposure, not single-use duration
✅ Reusable/repeat-use devices assessed for total contact days for one patient across their treatment course
✅ Genotoxicity rationale documented for prolonged/long-term contact except intact skin, per Tables 2–4 and Clause 6.5.7
✅ Biological Evaluation Plan references current ISO 10993-1:2025 structure, not legacy Table A.1
✅ FDA submission strategy accounts for the two partially-recognized clauses and the genotoxicity scope discrepancy
✅ Bioaccumulation signals from chemical characterization data reviewed and documented as a risk judgment, not assumed to require automatic escalation ✅ Existing (pre-2025) biological evaluations documented as reviewed against current definitions


FAQ

Does ISO 10993-1:2025 require me to retest devices already on the market?

No. The standard doesn’t mandate automatic retesting for devices with an acceptable safety history. It does expect a documented review confirming prior categorization and evaluation still hold, and an update if a Clause 10 production change triggers a re-review.

Is ISO 10993-1:2018 still valid to use?

FDA’s recognized standards database is the authority for U.S. submissions — verify current recognition status before relying on either edition. For new evaluation plans, aligning with the 2025 edition is the safer long-term position.

What’s the difference between “prolonged” and “long-term” contact?

Prolonged contact covers cumulative contact exceeding 24 hours but not exceeding 30 days. Long-term (permanent) contact covers cumulative contact exceeding 30 days, driven by total exposure period rather than packaging or labeling.

Does the 2025 edition apply to devices regulated under the EU MDR?

It’s generally treated as state of the art for MDR purposes, but grace periods and notified body expectations vary — confirm directly with your notified body.

Is genotoxicity testing now mandatory for every prolonged-contact device?

Not automatically. Per Tables 2–4 and Clause 6.5.7, genotoxicity is generally expected to be addressed through risk assessment for prolonged and long-term contact with all tissues except intact skin — but “addressed” can mean justified through existing toxicological or chemical characterization data, not necessarily new in vivo testing. Note also that FDA’s own Table A.1 applies genotoxicity more narrowly than ISO does, so confirm which framework governs your specific submission.

Do I need a new Biological Evaluation Plan for every device?

No blanket requirement to start over. Most manufacturers can update an existing BEP to reflect current categorization logic and endpoint scope, provided the underlying risk assessment and chemical characterization data are still valid.

How does ISO 14971 relate to my biological evaluation?

ISO 10993-1:2025 is now more tightly embedded in the ISO 14971 risk management process. See our guide on risk management in medical devices under ISO 14971 for how that framework applies.

Where do I buy the current edition of ISO 10993-1?

Through an authorized reseller such as the ANSI Webstore, which also serves international buyers and offers standards in multiple languages. ISO 10993-1:2025 — ANSI Webstore — Coupon code CC2026 applies through December 31, 2026.


📥 Free Resources

  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts
  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements

Not Sure What to Do Next?

🔹 Still researching how the current standard applies to your device? Read our Biocompatibility Standards Overview for the full picture before you build a test matrix.

🔹 Ready to build or update your Biological Evaluation Plan? Download the ISO 13485 Gap Assessment Checklist and confirm your documentation controls support the categorization decisions you’re about to make.

🔹 Need to purchase the current standard? ISO 10993-1:2025 — ANSI Webstore — code CC2026 takes 5% off, and international buyers can access the standard in multiple languages through the same source.


The Standard Changed. Your Categorization Logic Should Too.

Table A.1 was a shortcut, and shortcuts age out. ISO 10993-1:2025 asks for a defensible, risk-based answer instead of a checked box — and that’s a better position to defend in front of a reviewer regardless of which edition your notified body is citing this quarter. The Standards Navigator will keep tracking how FDA recognition and international adoption evolve as this transition plays out.


Don’t Let a Reviewer Find the Gap First

Most biological evaluation gaps don’t get caught in your own review — they get caught by a notified body auditor or an FDA reviewer, months after the plan was finalized. Manufacturers who treat contact duration categorization as a one-time exercise tend to carry that risk forward through every product change. Manufacturers who build a documented, repeatable categorization process into their QMS catch the drift before it becomes a submission delay.

The Standards Navigator tracks ISO 10993, ISO 13485, and the broader medical device compliance landscape as it evolves — including regulatory recognition changes like FDA’s partial recognition of ISO 10993-1:2025.

👉 Get updates on medical device biocompatibility and QMS requirements
👉 Be first to access new gap assessment tools and implementation resources

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

Biocompatibility Standards Explained: ISO 10993 Requirements for Medical Devices in 2026

This guide breaks down the ISO 10993 series and the sixth edition of ISO 10993-1, published in November 2025. It covers FDA’s partial recognition of the new edition in May 2026, the two clauses the agency excluded, and whether manufacturers need to revisit biological evaluation plans for devices already cleared.

What ISO 10993-1:2025 and FDA’s Partial Recognition Mean for Your Biological Evaluation Plan

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Standard Behind Your Biocompatibility Testing Just Changed — Is Your Documentation Still Defensible?

Biocompatibility standards for medical devices just changed in a way regulatory affairs teams can’t ignore. If your device has any contact with the human body, your biological evaluation plan rests on one standard: ISO 10993-1. For years, that meant the 2018 edition. That’s no longer the whole story.

ISO published a sixth edition, ISO 10993-1:2025, in November 2025. The FDA followed with recognition of that edition on May 25, 2026 — but only partial recognition. Two specific clauses were excluded outright. If your technical documentation, supplier certificates, or biological evaluation reports still cite the 2018 edition without addressing what changed, that’s a gap a reviewer or auditor will find.

This isn’t a cosmetic update. The reorganization ties biocompatibility more tightly to ISO 14971 risk management, and the FDA’s exclusions tell you exactly where the agency still wants you to lean on its own biocompatibility guidance instead of the standard’s language. This guide covers the current medical device biocompatibility testing requirements under both editions, what changed, and what FDA’s recognition decision actually means for your Biological Evaluation Plan (BEP).

I’ve been on the reviewing side of this problem before, just from the documentation control angle. As an ISO 9001 internal auditor, I’ve flagged design history files where a supplier’s certificate of conformance still referenced an outdated edition of a cited standard — the technical content hadn’t changed, but the paper trail no longer matched what the standard actually required. That’s the kind of finding that stalls a submission or an audit closeout, and it’s entirely avoidable if someone catches the edition mismatch before a reviewer does.

Before you touch a single test report, run a gap check on where your current documentation stands against the 2025 edition.

👉 Most teams don’t fail because their biocompatibility data is wrong — they fail because their documentation still points to the wrong edition of the standard. Run the ISO 13485 Gap Assessment Checklist before your next submission or audit →


In This Guide

  • What ISO 10993-1 covers and why it sits at the center of biocompatibility evaluation
  • The full ISO 10993 series, part by part
  • What actually changed in the 2025 edition
  • FDA’s partial recognition — and exactly what it excluded
  • Whether you need to retest devices already cleared under the 2018 edition
  • How biocompatibility documentation fits into your ISO 13485 QMS
  • A quick audit checklist for your next document review


👉 Start Here (Top Resources)


What Is Biocompatibility, and Why ISO 10993 Matters

Biocompatibility is the assessment of whether a device’s materials — and the way those materials contact the body — create an unacceptable biological risk. ISO 10993-1 is the standard that governs how you plan, justify, and document that biocompatibility risk assessment. It doesn’t hand you a checklist of tests to run blindly; it requires you to build a risk-based Biological Evaluation Plan (BEP) that considers the device’s materials, manufacturing processes, intended anatomical contact, and exposure duration.

That risk-based framing matters because it’s the same language FDA reviewers and notified bodies expect to see. A BEP that reads like a 2009-era test list, rather than a risk justification tied to ISO 14971, is a common source of review questions and additional information requests.

If you’re still building out your risk management process, our guide on risk management in medical devices under ISO 14971 covers the foundation ISO 10993-1 now leans on even more heavily than before.


The ISO 10993 Series at a Glance

Infographic showing the ISO 10993 series for biological evaluation of medical devices, including ISO 10993-1, -5, -6, -7, -10, -12, -17, and -18.
The ISO 10993 series consists of multiple standards that together form a complete biological evaluation framework for medical devices.

ISO 10993-1 doesn’t stand alone — it’s the framework document for a series that covers specific test methods and evaluation categories.

PartCoversStatus Note
ISO 10993-1Overall evaluation and testing within a risk management processSixth edition (2025) now partially recognized by FDA
ISO 10993-5In vitro cytotoxicity2009 edition, still current
ISO 10993-6Local effects after implantationUpdated 2026 edition
ISO 10993-7Ethylene oxide sterilization residualsUpdated 2026 edition
ISO 10993-10Irritation and skin sensitization2021 edition
ISO 10993-12Sample preparation and reference materials2021 edition, amended 2025
ISO 10993-17Toxicological risk assessment of device constituents2023 edition, amended 2025
ISO 10993-18Chemical characterization of materials2020 edition, amended 2022

Most common finding: Manufacturers cite ISO 10993-5 or -10 correctly but leave the ISO 10993-1 reference in their design history file pointing to the 2018 edition without any documented rationale for why. If your BEP hasn’t been revisited since the 2025 edition published, that’s the first thing to check.

If your device is sterilized and you haven’t looked at how the 2026 edition of ISO 10993-7 interacts with your sterilization validation, our sterilization standards overview walks through ISO 11135, 11137, 17665, and 11607 alongside it.


What Changed in ISO 10993-1:2025

The sixth edition isn’t a light refresh. ISO’s technical committee reorganized the standard and changed its title to explicitly align with the ISO 14971 risk management framework. The practical changes:

  • More detailed guidance on calculating exposure duration — including how to treat foreseeable misuse, such as a device used longer than its labeled duration.
  • Expanded guidance on device characterization and biological hazard identification, intended to reduce reliance on generic test batteries.
  • Terminology aligned with ISO 14971, so if your team already knows that standard, the 2025 edition should read more consistently — though NAMSA and other industry commentators note there isn’t yet a technical report equivalent to ISO/TR 24971 to guide interpretation of the new edition.

Here’s how the two editions compare on the points that matter most for your Biological Evaluation Plan:

Topic2018 Edition2025 Edition
Risk Management IntegrationReferenced ISO 14971More explicitly aligned throughout
Exposure DurationLimited guidanceExpanded methodology for calculating duration, including foreseeable misuse
Biological Hazard IdentificationLess detailedExpanded guidance on device characterization and hazard identification
Risk EstimationDifferent treatmentNew Clause 6.9 (excluded by FDA)

If you are preparing a Biological Evaluation Plan for a new device → start by confirming which edition your FDA reviewer or notified body expects to see referenced, since adoption isn’t uniform across regions. The EU has generally moved faster toward treating the 2025 edition as state of the art. Manufacturers should verify current adoption expectations directly with their notified body and applicable competent authorities, since implementation timing varies and is subject to change.

One shift worth flagging for regulatory teams building out a modern BEP: chemical characterization under ISO 10993-18 is playing a larger role than it used to. Rather than defaulting to a blanket biological test matrix for every device, more manufacturers are leaning on thorough chemical characterization data — extractables and leachables profiles, material composition analysis — to justify a narrower, risk-based testing strategy. ISO 10993-1:2025’s expanded hazard identification guidance reinforces this shift. A well-documented ISO 10993-18 characterization can reduce redundant biological testing, but only if the chemistry-driven rationale is documented clearly enough to withstand a reviewer’s scrutiny.

Comparison graphic showing the major differences between ISO 10993-1:2018 and ISO 10993-1:2025 for biological evaluation of medical devices.
The 2025 edition places greater emphasis on risk management integration, biological hazard identification, and exposure assessment.

ISO 10993 FDA Recognition: What’s Excluded and Why

🔑 Key FDA Takeaway FDA recognizes ISO 10993-1:2025, but excludes:

  • The “consumer products” language in Clause 6.5.11.3
  • Clause 6.9 on biological risk estimation

Manufacturers should document alternative justification using FDA guidance and ISO 14971.

On May 25, 2026, FDA updated its Recognized Consensus Standards database (Recognition No. 2-313) to include ISO 10993-1:2025 — but not in full. Two specific exclusions matter for your submissions:

  1. The phrase “consumer products or” in Clause 6.5.11.3. This clause addresses low-risk, intact-skin-contacting devices. The standard allows manufacturers to point to a material’s history of safe use in consumer products as justification for reduced testing. FDA excluded this because it conflicts with Attachment G of its 2023 biocompatibility guidance, which defines specific materials with an accepted history of use — a consumer product history alone doesn’t automatically satisfy FDA’s expectations.
  2. Clause 6.9 on biological risk estimation. FDA determined this clause conflicts with the risk estimation approach already established in the FDA-recognized ISO 14971:2019. Sponsors can’t rely on Clause 6.9 to claim conformity in a submission.

If you are under customer or notified body pressure to update your BEP quickly → prioritize reviewing these two clauses first. They’re the specific areas where citing the 2025 edition alone won’t satisfy FDA, and you’ll need to document your justification through existing FDA guidance instead.

Partial recognition means you cannot submit a clean Declaration of Conformity to the full 2025 edition. Your submission documentation needs to call out the partial recognition explicitly and show how you’re addressing the excluded clauses — silence on this point is what generates additional information requests.

Workflow illustrating FDA partial recognition of ISO 10993-1:2025 and the documentation required for excluded clauses during medical device submissions.
FDA recognizes ISO 10993-1:2025 with specific exclusions, requiring manufacturers to document alternative regulatory justifications.

Do You Need to Retest Already-Cleared Devices?

This is the objection I hear most from teams looking at this update: does a new edition mean I have to redo my biocompatibility testing on devices that already have clearance?

No — not automatically. FDA’s recognition of a newer edition doesn’t retroactively invalidate data or clearances based on the 2018 edition. If you already hold clearance under the 2018 edition → you don’t need to retest existing devices. What you do need is a documented rationale, at your next design change or periodic review, for why your BEP still reflects sound risk management even though a newer edition exists. That’s a documentation and justification exercise, not a lab exercise.

Where this becomes a live issue is new submissions and significant design changes going forward — those are where reviewers will expect to see the current edition addressed.


Where Biocompatibility Fits Into Your ISO 13485 QMS

Biocompatibility data doesn’t live in isolation — it’s part of your design and development file under ISO 13485, and it feeds directly into your risk management file under ISO 14971. If your ISO 13485 documentation structure doesn’t have a clear place for biological evaluation plans, reports, and the rationale behind edition changes, that’s a gap worth closing before your next internal audit — not after a nonconformance is written.

This also connects to supplier controls. If a component supplier’s certificate of conformance references ISO 10993-1 by edition, your incoming inspection and supplier qualification process needs a mechanism to catch when that reference goes stale — the same principle covered in our guide on common mistakes in ISO 13485 QMS implementation.

And if you’re managing devices sold in both the US and EU, the edition-adoption gap between FDA and the EU regulatory framework is one more reason to keep your MDR vs ISO 13485 documentation aligned rather than treating them as separate tracks.

👉 If your biological evaluation documentation hasn’t been reviewed since the 2025 edition published, don’t wait for a finding to tell you. Check where your QMS documentation actually stands →


Quick Audit Checklist

✅ Confirm which edition of ISO 10993-1 your current BEP references, and whether that matches what your reviewer or notified body expects
✅ Check whether your device’s biocompatibility justification relies on Clause 6.5.11.3 (consumer product history) or Clause 6.9 (risk estimation) — both need alternative justification for FDA submissions
✅ Verify supplier certificates of conformance cite current standard editions, not stale references
✅ Confirm your risk management file cross-references your BEP consistently ✅ If your device is sterilized, check the 2026 editions of ISO 10993-6 and -7 against your current validation data ⚠️ Don’t assume “FDA recognized” means “fully accepted” — verify the Supplementary Information Sheet for any standard before citing it as a full Declaration of Conformity


FAQ

What is biocompatibility testing for medical devices?

Biocompatibility testing evaluates whether the materials in a medical device, and the way those materials contact the body, could cause an unacceptable biological response. It covers areas like cytotoxicity, sensitization, irritation, and systemic toxicity, selected based on the device’s contact type and duration.

What is ISO 10993-1, and do I need to comply with it?

ISO 10993-1 is the framework standard that governs how you plan and justify a biological evaluation within a risk management process. If your device contacts the body directly or indirectly, FDA and most global regulators expect your biocompatibility strategy to follow its structure, even where full conformity isn’t feasible.

What changed between ISO 10993-1:2018 and ISO 10993-1:2025?

The 2025 edition reorganized the standard to align more closely with ISO 14971, added detailed guidance on calculating exposure duration and identifying biological hazards, and updated terminology throughout.

Has the FDA recognized ISO 10993-1:2025?

Yes, as of May 25, 2026, but only partially. FDA excluded the “consumer products” language in Clause 6.5.11.3 and all of Clause 6.9 on biological risk estimation, both of which conflict with existing FDA guidance and the FDA-recognized ISO 14971:2019.

Do I need to retest devices already cleared under the 2018 edition?

No. Existing clearances aren’t invalidated by a newer edition. You do need a documented rationale for your current approach at your next design change or periodic review.

Which parts of the ISO 10993 series apply to my device?

That depends on your device’s contact type (surface, external communicating, or implant) and contact duration (limited, prolonged, or permanent). ISO 10993-1 provides the matrix for selecting relevant parts of the series based on those two factors. We’ll be covering that contact-duration matrix in detail in an upcoming guide.

Is ISO 10993 the same as ISO 13485?

No. ISO 13485 governs your overall quality management system for medical devices. ISO 10993 is a series specifically about biological evaluation, and its outputs — your BEP and test reports — become part of the design and development records your ISO 13485 QMS requires you to maintain.

Where do I purchase ISO 10993 standards?

Individual parts and bundled packages are available through the ANSI Webstore, which also serves international buyers and offers documents in multiple languages. The ISO.org catalog describes each part but is not the recommended purchase channel.


📥 Free Resources

  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.
  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements, including where biocompatibility documentation fits.
  • AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification.

Not Sure What to Do Next?

🔹 Still researching how the 2025 edition affects your device category? Start with our breakdown of risk management under ISO 14971 — biocompatibility evaluation doesn’t stand apart from it anymore.

🔹 Ready to check where your documentation actually stands? Run the ISO 13485 Gap Assessment Checklist before your next audit or submission, not after.

🔹 Need to purchase the current standard? ISO 10993-1:2025 — ANSI Webstore, or get the full biological evaluation package bundled at roughly 45% off individual pricing if you’re assembling multiple parts of the series. Use code CC2026 for an additional 5% off through December 31, 2026.

The Standards Navigator will keep tracking how FDA recognition evolves on this standard as updates are published.


Documentation Gaps Don’t Show Up Until Someone’s Looking For Them

Teams that treat biocompatibility as a one-time lab exercise are the ones caught off guard when a standard’s edition changes underneath them. Teams that treat it as a living part of their design and risk management file catch the mismatch at their next internal review, not during an FDA question round — and it’s usually a citation that didn’t keep up, not the underlying science, that stalls a submission.

The Standards Navigator tracks these regulatory shifts as they happen — not months later when the transition deadline is already close. If ISO 10993-1:2025 affects your device, this is a good window to revisit your documentation rationale while the timeline is still in your control.

👉 Get updates on medical device compliance and biocompatibility standard changes
👉 Be first to access new gap assessment checklists and documentation tools for ISO 13485 and ISO 14971

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.