A regulatory affairs guide to two rules that get confused constantly — and cost time when they are
Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.
The Question That Stalls Every EU Market Entry Meeting
Somewhere in almost every medical device compliance kickoff, someone asks it: “We already have ISO 13485. Doesn’t that cover MDR?”
It doesn’t. And the gap between MDR vs ISO 13485 — a certified quality management system and an EU-compliant technical file — is where CE marking timelines quietly slip by six to twelve months.
MDR (Regulation (EU) 2017/745) and ISO 13485 aren’t competing standards. They aren’t interchangeable either. One is EU law. The other is a voluntary international standard that EU law happens to lean on heavily. Confusing the two doesn’t just cost time — it costs Notified Body findings, delayed submissions, and in some cases, a device that can’t legally reach the European market on schedule.
From the floor: I’ve sat in a management review where a director insisted the ISO 13485 certificate meant the technical documentation was “basically done” for an EU submission. It wasn’t. The certificate covered their quality system — design controls, CAPA, document control. It said nothing about the clinical evaluation report, MDR classification requirements, or the device-specific evidence required for conformity assessment. They spent the next quarter closing that gap instead of reviewing it calmly six months earlier. That’s the exact mistake this article exists to prevent.
👉 Before you assume your QMS certification covers your EU submission, run the gap check. Most regulatory affairs teams don’t fail because they misunderstand ISO 13485 — they fail because they assumed certification and market access were the same milestone. Get the ISO 13485 Gap Assessment Checklist and find out before a Notified Body does.
In This Guide
- What EU MDR 2017/745 actually regulates
- What ISO 13485 actually certifies
- The core differences, side by side
- Why “ISO 13485 certified” doesn’t mean “MDR compliant”
- Where the two genuinely overlap — risk management, CAPA, design controls, and more
- Current MDR transition timelines and 2026 developments
- Which one you need — and when you need both
- Common documentation mistakes that surface in Notified Body reviews
- FAQ
Table of Contents
- What Is EU MDR 2017/745?
- What Is ISO 13485?
- MDR vs. ISO 13485: Core Differences
- Why Manufacturers Conflate the Two
- Where MDR and ISO 13485 Overlap
- MDR Transition Timelines: Where Things Stand in 2026
- Do You Need Both? A Decision Framework
- Common Mistakes That Surface in Notified Body Review
- Quick Reference Checklist
- FAQ
👉 Start Here
- ISO 13485:2016 — Purchase the Official Standard — the current edition, direct from ANSI Webstore, available in multiple languages for international regulatory teams.
- ISO 13485 Training Courses — BSI Group — structured training for teams building out clause-by-clause understanding ahead of certification or an MDR technical file build.
What Is EU MDR 2017/745?
MDR is law, not a certifiable management system standard. Regulation (EU) 2017/745 governs what a manufacturer must prove — about a specific device — before that device can carry a CE mark and legally reach the EU market.
It covers device classification (Class I through III), clinical evaluation and clinical data requirements, technical documentation per Annexes II and III, post-market surveillance and post-market clinical follow-up (PMCF), Unique Device Identification (UDI) and EUDAMED registration, and — for higher-risk devices — Notified Body conformity assessment under Annex IX.
MDR replaced the older Medical Device Directive (MDD) and Active Implantable Medical Devices Directive (AIMDD), and it raised the bar substantially on clinical evidence and post-market obligations compared to both.
What Is ISO 13485?
ISO 13485 is a voluntary, internationally recognized quality management system standard for organizations involved in the design, production, or servicing of medical devices. It’s certifiable — a Notified Body or accredited certification body audits your QMS against the standard’s clauses and issues a certificate if you pass.
ISO 13485 uses maintaining effectiveness language throughout, not the continual improvement language found in ISO 9001. It’s structured around risk-based thinking applied specifically to design controls, document and record control, supplier controls, CAPA, and management review — the operational backbone a device manufacturer needs regardless of which market it sells into.
Since FDA’s QMSR took effect February 2, 2026, 21 CFR Part 820 incorporates ISO 13485:2016 by reference — making it the enforceable quality management system standard for U.S. device manufacturers, not merely a reference point.
MDR vs. ISO 13485: Core Differences
| Category | EU MDR 2017/745 | ISO 13485 |
|---|---|---|
| Nature | EU law — mandatory for CE marking | Voluntary international standard |
| Scope | Device-specific: classification, clinical evidence, technical file | Organization-wide: the QMS itself |
| Who assesses it | Notified Body (device-level conformity assessment) | Certification body (QMS audit) |
| Grants market access? | Yes — required for CE marking in the EU | No — supports it, doesn’t grant it |
| Geographic reach | EU/EEA market only | Recognized globally; now foundational to FDA QMSR |
| What it produces | Technical documentation, CER, PMS/PMCF plan, EUDAMED registration | A certificate covering your quality management system |
| Update cycle | Amended by EU legislative process (ongoing 2025–2027 reform) | Revised through ISO’s standard TC 210 process |

Quick Answer:
- Need CE marking? → MDR is required.
- Need a compliant medical device QMS? → ISO 13485 is required.
- Selling medical devices in the EU? → You almost certainly need both.
The stakes behind that table are real: the European Commission’s most recent Notified Bodies survey, published March 2026, showed roughly half of submitted MDR applications had reached certificate issuance — a gap driven largely by device misclassification, incomplete technical documentation, and thin clinical evidence, not by Notified Body capacity alone.
Why Manufacturers Conflate the Two
The most common objection I hear: “We’re ISO 13485 certified — why do we need a separate MDR effort?”
Here’s the resolution: ISO 13485 certification tells a Notified Body your quality system is sound. It says nothing about whether a specific device’s clinical evidence, risk classification, or technical file meets MDR’s requirements. A company can hold a spotless ISO 13485 certificate and still receive a Notified Body finding on a device submission because the clinical evaluation report was thin, the PMCF plan was missing, or the classification rule was misapplied under Annex VIII.
Think of it this way: ISO 13485 certifies the kitchen is clean and the process is controlled. MDR conformity assessment asks whether this specific dish meets the recipe, the nutrition label is accurate, and there’s a plan to keep checking it after it ships. You need both, but they answer different questions.
👉 If you are relying on your ISO 13485 certificate as your MDR readiness proof, that’s the gap to close first. Run the ISO 13485 Gap Assessment Checklist against your current technical files before your next Notified Body interaction.
Where MDR and ISO 13485 Overlap

If they’re really two separate things, why does everyone talk about them in the same breath? Because the same five operational areas show up in both — just assessed from different angles.
- Risk management — MDR requires risk management per Annex I general safety and performance requirements; ISO 13485 Clause 4.1.2 requires a risk-based approach throughout the QMS. Most manufacturers run one risk management process (typically ISO 14971-aligned) that satisfies both.
- CAPA — ISO 13485 Clause 8.5 governs corrective and preventive action as a QMS requirement. MDR’s post-market surveillance and vigilance obligations feed directly into that same CAPA process when a field issue is identified.
- Design controls — ISO 13485 Clause 7.3 sets design and development requirements; MDR’s technical documentation under Annex II leans on those same design records as evidence of a controlled development process.
- Supplier controls — ISO 13485 Clause 7.4 requires supplier evaluation and monitoring; MDR expects that same supplier oversight to extend into the technical file wherever a supplier-controlled process affects device safety or performance.
- Complaint handling — ISO 13485 Clause 8.2.2 sets complaint-handling requirements; MDR’s vigilance reporting obligations under Article 87 depend on that same complaint intake process to catch reportable events.
This is the practical reason ISO 13485 certification and MDR technical documentation feel like the same conversation even though they’re legally distinct: a well-run QMS produces most of the raw material an MDR technical file needs. The gap is rarely in these five areas — it’s in whether that raw material gets assembled into a device-specific technical file the way MDR expects.
MDR Transition Timelines: Where Things Stand in 2026
The transition provisions have shifted more than once since MDR took effect in May 2021, and manufacturers still working under legacy MDD or AIMDD certificates need to track the current deadlines carefully:
- Class III custom-made implantable devices: compliance required by May 26, 2026
- Class III and certain implantable Class IIb devices: transition extends to December 31, 2027
- Most other Class IIb, IIa, and Class I devices: transition extends to December 31, 2028
Legacy device status under these extended timelines requires a valid MDD/AIMDD certificate, no significant design or intended-use change, continued compliance with the original directive, and a signed agreement with an MDR-designated Notified Body.
Separately, the European Commission published a proposal on December 16, 2025 to simplify and reduce administrative burden under both MDR and its IVDR counterpart — including changes to PRRC availability requirements and certificate validity limits. That proposal is still moving through the EU’s ordinary legislative process, and current projections put final adoption no earlier than the second quarter of 2027. Nothing in that proposal changes your obligations today. Manufacturers should keep building technical documentation to the current MDR text rather than waiting on a reform that hasn’t been adopted.

Do You Need Both? A Decision Framework
- If you are selling into the EU market → MDR compliance is mandatory, full stop. ISO 13485 certification is not legally required by MDR text, but in practice Notified Bodies expect it as evidence your QMS can sustain the technical file over time.
- If you are U.S.-only and not yet EU-bound → FDA’s QMSR incorporates ISO 13485:2016 by reference into 21 CFR Part 820, making alignment with ISO 13485 the foundation of U.S. medical device QMS compliance as of February 2, 2026. Third-party certification isn’t mandated by FDA, but the standard’s substance now is.
- If you are already ISO 13485 certified and expanding into the EU → treat MDR as a device-level project layered on top of your existing QMS, not a QMS rebuild. The gap is almost always in clinical evidence and technical documentation, not in your quality processes.
- If you are under customer or investor pressure to move fast → get the ISO 13485 gap assessment done first. It surfaces documentation gaps in days instead of finding them mid-audit.
Common Mistakes That Surface in Notified Body Review
Most common finding: Clinical evaluation reports that summarize literature but never tie evidence back to the specific device’s risk profile under Annex I general safety and performance requirements.
Other recurring gaps: PMCF plans that exist as a template but were never executed against real post-market data; UDI and EUDAMED registration treated as an afterthought instead of a parallel workstream; and design change records that don’t clearly show which MDR classification rule applied after a design modification.
⚠️ A Notified Body finding on any of these doesn’t necessarily mean your ISO 13485 QMS has failed — it usually means the QMS and the MDR technical file were built as two separate projects instead of one connected effort.
Quick Reference Checklist
✅ ISO 13485 certificate current and audit-ready
✅ Technical documentation mapped to current MDR Annex II/III requirements ✅ Clinical evaluation report tied to device-specific risk profile
✅ PMCF plan active and generating real post-market data
✅ UDI assigned and EUDAMED registration current
✅ Notified Body agreement in place if relying on legacy transition timelines
✅ Design change records show which classification rule applies post-modification
FAQ
Does ISO 13485 certification satisfy MDR requirements?
No. ISO 13485 certifies your quality management system. MDR requires separate, device-specific technical documentation, clinical evidence, and — for most devices — Notified Body conformity assessment. Certification supports MDR compliance; it doesn’t substitute for it.
Is ISO 13485 mandatory for the EU market?
MDR text doesn’t explicitly mandate ISO 13485 certification, but in practice, Notified Bodies expect a certified QMS as part of demonstrating your ability to sustain compliance. Most manufacturers pursuing MDR conformity hold ISO 13485 certification for this reason.
Do U.S.-only manufacturers need to worry about MDR?
Not directly, unless you plan to sell into the EU. However, FDA’s QMSR — effective February 2, 2026 — makes ISO 13485:2016 the operative U.S. regulation, so ISO 13485 alignment now matters regardless of whether MDR applies to you.
What’s the current MDR transition deadline for legacy devices?
It depends on device classification: Class III custom-made implantables faced a May 26, 2026 deadline, Class III and certain implantable Class IIb devices extend to December 31, 2027, and most other devices extend to December 31, 2028 — provided legacy status conditions are met.
Is the EU actually changing MDR requirements soon?
The European Commission proposed simplification changes on December 16, 2025, but the proposal is still in the EU legislative process, with final adoption not expected before the second quarter of 2027. Current MDR requirements remain fully in effect in the meantime.
What’s the biggest documentation gap Notified Bodies flag?
Clinical evaluation reports that summarize literature broadly without tying the evidence directly to the specific device’s risk profile under the general safety and performance requirements.
Can one gap assessment cover both ISO 13485 certification readiness and MDR technical file readiness?
A well-structured gap assessment should flag both, but they’re different reviews at their core — one audits your QMS against ISO 13485 clauses, the other audits your technical documentation against MDR annexes. Treat them as connected but distinct workstreams.
Where should a manufacturer start if pursuing both?
Start with the QMS. A certified, functioning ISO 13485 system gives you the document control, CAPA, and design control infrastructure that MDR technical documentation depends on. Building MDR documentation on top of a shaky QMS just relocates the problem.
📥 Free Resources
- ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements before certification or a Notified Body review.
- ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system from the ground up.
- Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements across production environments.
Not Sure What to Do Next?
🔹 Still researching the difference between MDR and ISO 13485? Start with What Is ISO 13485? and FDA QSR vs. ISO 13485 to ground the fundamentals before your next planning meeting.
🔹 Ready to close the documentation gap? Review ISO 13485 Documentation Requirements and Validation & Verification Requirements against your current technical files.
🔹 Need to purchase the standard itself? Get ISO 13485:2016 directly from ANSI Webstore — available internationally, with multi-language editions for global regulatory teams. Use code CC2026 for 5% off through December 31, 2026.
MDR and ISO 13485 solve different problems, and treating them as one project is how audit-ready timelines slip by a quarter or more. The Standards Navigator will keep tracking both as EU reform proposals and FDA QMSR guidance continue to evolve through 2026 and 2027.
Stop Guessing Where Your MDR Gap Actually Is
Regulatory teams that treat MDR and ISO 13485 as one combined project usually discover the gap during a Notified Body review — the worst possible time to find it. Teams that separate the two, and check each on its own terms, walk into that review with documentation that already matches what’s being asked.
The Standards Navigator tracks EU MDR developments, FDA QMSR alignment, and ISO 13485 implementation detail so medical device teams aren’t relying on outdated guidance six months into a submission.
👉 Get updates on MDR, ISO 13485, and medical device regulatory changes as they happen
👉 Be first to access new gap assessment tools and documentation resources for regulatory affairs teams
Subscribe below to stay ahead.
The Standards Navigator — Industrial Compliance. Clearly Explained.



























