ISO 13485 Clauses Explained: A Complete Clause-by-Clause Breakdown (2026)

ISO 13485:2016 has eight clauses, but only five carry auditable requirements. This ISO 13485 clauses explained guide breaks down Clauses 4 through 8 in practical terms, corrects the common DHF-to-Medical-Device-File mapping error, and explains how FDA’s Compliance Program 7382.850 — which replaced QSIT on February 2, 2026 — reorganizes inspections around six QMS Areas and four Other Applicable FDA Requirements.

What every section of ISO 13485:2016 actually requires — and where auditors dig deepest

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Standard Reads Like a Checklist. It Isn’t One.

ISO 13485:2016 has eight clauses. Five of them carry actual requirements. That structure looks simple on the page — and it’s exactly why so many quality teams underestimate how much interpretation each clause demands once an auditor starts asking “show me.” This ISO 13485 clauses explained guide breaks down what each section requires, where the requirements overlap, and what auditors and FDA investigators may look for.

The FDA’s Quality Management System Regulation (QMSR) took effect February 2, 2026, incorporating ISO 13485:2016 by reference into 21 CFR Part 820. That changes what this clause structure means in practice. FDA also replaced its inspection methodology the same day — the Quality System Inspection Technique (QSIT) is gone, replaced by Compliance Program 7382.850. Getting the clause boundaries right now has a direct line to how an FDA investigator scopes an inspection, not just how a certification body audits.

Regulatory affairs and quality professionals reading this already know ISO 13485 exists. What’s harder to find is a breakdown that goes past the clause titles and into what each section demands in practice — where the audit findings cluster, where risk management threads through clauses that don’t mention risk in their title, and where the standard’s lack of an Annex SL high-level structure changes how it should be read compared to ISO 9001.

My perspective on this comes from 25+ years in operations leadership, an ISO 9001 Internal Auditor certification, and a Six Sigma Green Belt — a lot of that time spent on both sides of the table, building QMS documentation and sitting in CAPA reviews when a gap in that documentation turned into a finding. The pattern holds across every regulated QMS I’ve worked with: teams don’t fail because they misread a clause. They fail because they treated clause boundaries as more rigid than the standard actually intends, and missed how much cross-referencing an auditor expects between clauses 4 through 8.

If you haven’t run a structured gap check against the current clause set, that’s the place to start — not a full documentation rewrite.

👉 Run the ISO 13485 Gap Assessment Checklist before you touch your quality manual — a free, structured way to see exactly which clauses your QMS already satisfies and which ones need real work before an auditor finds the gap for you.


In This Guide

  • How ISO 13485:2016 is structured, and why it doesn’t follow ISO’s Annex SL format
  • A clause-by-clause breakdown of Clauses 4 through 8
  • How FDA’s current inspection program, Compliance Program 7382.850, reorganizes inspections around six QMS Areas
  • The most common audit findings tied to specific sub-clauses
  • Where risk management actually appears throughout the standard
  • How ISO 13485 clause numbering compares to ISO 9001
  • FAQs on structure, exclusions, and transition timing


👉 Start Here (Top Resources)


ISO 13485 Clauses Explained: How the Standard Is Structured

ISO 13485 clauses explained with an eight-clause map covering the standard’s foundational and QMS requirement clauses
ISO 13485 clauses explained through an eight-clause map showing the foundational clauses and the five clauses containing QMS requirements.

ISO 13485:2016 is built around eight clauses. The first three are introductory — they define scope, point to normative references, and set terminology. They carry no auditable requirements on their own, but skipping them is a mistake most teams make once and then correct the hard way.

Clauses 4 through 8 are where the requirements live. This is the part of the standard your certification body actually audits against, clause by clause, sub-clause by sub-clause.

Here’s something worth knowing before you go further: ISO 13485 does not follow the Annex SL high-level structure that ISO 9001:2015, ISO 14001, and ISO 45001 all share. Those three standards align clause-for-clause at the top level, which is why integrated management systems work so cleanly across them. ISO 13485 kept its own structure when it was revised in 2016, specifically so it could stay independent of ISO 9001 revision cycles — a deliberate choice by the technical committee to protect regulatory stability for device manufacturers. If you’re coming from an ISO 9001 background, this is the first adjustment to make: don’t assume clause 7 means the same thing in both standards. It doesn’t.


Clauses 1 Through 3: No Requirements, But Don’t Skip Them

Clause 1 (Scope) defines what the standard covers and, critically, how exclusion and non-application work. ISO 13485 doesn’t let an organization simply skip a requirement that seems inconvenient — where a clause is excluded or considered non-applicable (say, you don’t perform installation), the scope and justification have to be documented in the quality manual under Clause 4.2.2, and be prepared to defend that justification during an audit.

Clause 2 (Normative References) points to ISO 9000:2015 for terms and definitions. You don’t need to buy ISO 9000 to comply, but auditors do expect your team to be using its vocabulary consistently — “nonconformity,” “corrective action,” and “verification” all carry specific meanings your documentation should match.

Clause 3 (Terms and Definitions) establishes the vocabulary used throughout the standard, including specific definitions for concepts like medical device, complaint, risk, and post-market surveillance. Getting comfortable with this terminology matters more than it looks like it should — auditors expect your documentation to use these terms precisely, not colloquially.

📥 Before diving into clauses 4-8: if your QMS documentation predates 2020, run it against the current ISO 13485 Documentation Requirements breakdown first. Most gaps trace back to documentation structure, not missing procedures.


Clause 4: Quality Management System

Clause 4 sets the general requirements for the QMS itself — and it’s where most audit programs start, because everything downstream depends on it.

4.1 General Requirements requires you to identify your QMS processes, map their sequence and interaction, and — this is the part that trips up contract manufacturers — maintain control over any process you outsource. Most common finding: outsourced processes (contract sterilization, contract testing, third-party calibration) that exist operationally but were never formally brought into QMS scope. If a supplier touches your product or your data, your QMS has to account for it.

4.2 Documentation Requirements covers the quality manual, the Medical Device File (Clause 4.2.3), document control, and record control. This requirement is specific to this standard — it’s not something ISO 9001 asks for. It’s a defined set of documents and references demonstrating a device meets its requirements throughout its lifecycle, and auditors will ask to see it assembled, not scattered across a dozen disconnected folders.

If your documentation still uses FDA’s old terminology, this is worth getting precise about. As of February 2, 2026, the terms Device Master Record, Device History Record, and Design History File no longer appear in 21 CFR Part 820. Those legacy record concepts weren’t simply eliminated; their applicable requirements are now addressed through the QMSR framework and ISO 13485’s own structure. Most of what a Device Master Record covered lives in the Medical Device File at Clause 4.2.3, while the Design History File corresponds to the Design and Development File at Clause 7.3.10. These aren’t simple one-for-one renamings: the Medical Device File in particular is a broader requirement than the DMR it replaced, so a straight terminology swap in your documentation will likely leave gaps a crosswalk exercise would catch.

Sub-clause 4.2.4 (control of documentation) and 4.2.5 (control of records) get their own scrutiny. Auditors typically check three things here: are documents reviewed and approved before use, is there a mechanism to prevent use of outdated versions, and are records retained for a defined, justified period. If you’re preparing for your first audit under this clause → build your document control procedure before you build anything else. Everything else in the QMS references it.


Clause 5: Management Responsibility

Clause 5 puts specific, named accountability on top management — not “the quality department,” but leadership itself.

This clause requires a documented quality policy, measurable quality objectives, evidence of planning for QMS changes, and a sub-clause I’ve seen come up repeatedly in audit findings — management review. Clause 5.6.2 is unusually prescriptive for an ISO standard: it names twelve required inputs, and a compliant management review record has to address all of them or document why one doesn’t apply — feedback, complaint handling, reporting to regulatory authorities, audits, monitoring and measurement of processes, monitoring and measurement of product, corrective action, preventive action, follow-up actions from previous reviews, changes that could affect the QMS, recommendations for improvement, and applicable new or revised regulatory requirements. A management review that skips several of these, or that doesn’t produce documented outputs and action items, is a finding waiting to happen — and under the current FDA inspection framework, it’s no longer just a certification-audit concern (more on that below).

If you are already ISO 9001 certified, this clause will feel familiar structurally — but ISO 13485 expects a tighter link between management review and regulatory requirements specifically, not just general business objectives.


Clause 6: Resource Management

Clause 6 covers human resources, infrastructure, and work environment — including contamination-control requirements under 6.4.2 that go considerably further than ISO 9001’s general treatment of work environment.

6.2 Human Resources requires documented competence for anyone whose work affects product quality — not just “trained,” but competence tied to education, skills, and experience, with evidence. 6.3 Infrastructure requires maintenance records for equipment critical to product conformity. 6.4 Work Environment and Contamination Control is where device manufacturers doing anything sterile, implantable, or otherwise contamination-sensitive get the most detailed scrutiny — cleanroom classifications, gowning procedures, and environmental monitoring data all trace back here.


Clause 7: Product Realization

Clause 7 is the largest clause in the standard, and it’s where design controls, purchasing, production, and servicing all live.

7.1 Planning of Product Realization is where ISO 13485 explicitly requires documented risk management processes within product realization, with records maintained throughout. The clause’s note points readers to ISO 14971 for further guidance on structuring that risk management activity — it’s a reference, not a formal incorporation, though in practice most organizations end up using ISO 14971’s framework to satisfy this requirement.

7.3 Design and Development is one of the sub-clauses most commonly identified as non-applicable by contract manufacturers who don’t design product — but where it applies, it can’t be excluded lightly, and the justification has to hold up to the same Clause 4.2.2 scrutiny as any other exclusion. If it applies to you, this is the densest technical section of the standard: design inputs, outputs, review, verification, validation, transfer, and change control, each with its own documented evidence trail. Most common finding: design changes made without running them back through the full verification/validation cycle, especially late in development when schedule pressure is highest.

7.4 Purchasing requires supplier evaluation criteria proportionate to risk, and re-evaluation triggers when supplier performance changes. 7.5 Production and Service Provision covers process validation for anything that can’t be fully verified by downstream inspection — sterilization is the textbook example, which is why it gets its own dedicated body of standards. 7.6 Control of Monitoring and Measuring Equipment ties directly into your calibration program.

If you are under customer or FDA pressure to show design control maturity quickly → prioritize closing out 7.3 documentation gaps before anything else in this clause. In my experience, it’s one of the first sections a regulatory reviewer or auditor asks to see in depth.


Clause 8: Measurement, Analysis and Improvement

Clause 8 is where the QMS proves it’s actually working — and where CAPA lives.

8.2 Monitoring and Measurement covers feedback, complaint handling, and internal audit. Complaint handling under this clause has to interface with FDA’s separate adverse-event reporting requirements — a complaint that may represent a reportable event under Medical Device Reporting (21 CFR Part 803) can’t remain solely an internal QMS record; it has to be evaluated independently against those reporting obligations.

8.3 Control of Nonconforming Product requires documented procedures for identifying, segregating, and dispositioning nonconforming product, including for product discovered nonconforming after delivery — which is where recall-adjacent procedures connect back into the standard.

8.5 Improvement is where corrective and preventive action requirements sit. CAPA under ISO 13485 requires root cause investigation, verification that the action taken was effective, and — a detail I’ve seen auditors check for specifically — evidence that you evaluated whether the same nonconformity could exist elsewhere in the organization before closing the CAPA. A CAPA record that fixes one instance without documenting that broader check is incomplete by this clause’s own standard, regardless of whether the immediate fix worked.

For a deeper breakdown of this clause specifically, see our full guide to CAPA requirements in ISO 13485.


Where ISO 13485 and FDA’s QMSR Overlap by Clause

FDA’s Quality Management System Regulation took effect February 2, 2026, incorporating ISO 13485:2016 by reference into 21 CFR Part 820. That’s the headline most coverage stopped at. What matters more for how you prepare is what happened on the inspection side the same day: FDA retired the Quality System Inspection Technique (QSIT), the inspection methodology it had used since 1999, and replaced it with a new compliance program manual — CP 7382.850, Inspection of Medical Device Manufacturers.

ISO 13485 clauses explained through the 2026 FDA QMSR inspection framework, including six QMS Areas and four OAFRs
ISO 13485 clauses explained in the context of the FDA QMSR and CP 7382.850 inspection framework effective February 2, 2026.

QSIT organized inspections around four subsystems. CP 7382.850 reorganizes them around six QMS Areas, each mapped to ISO 13485 clauses with FDA-specific requirements layered in:

  • Management Oversight — the QMS itself, management review, the medical device file, and product realization planning
  • Design and Development — design inputs, outputs, review, verification, validation, software validation, and transfer
  • Production and Service Provision — production planning, process validation, and servicing
  • Measurement, Analysis, and Improvement — complaint handling, feedback, internal audits, corrective and preventive action, and control of nonconforming product
  • Outsourcing and Purchasing — supplier evaluation and control
  • Change Control — how changes to product or process are managed and documented

Alongside the six QMS Areas, inspections also evaluate four Other Applicable FDA Requirements (OAFRs) that sit outside ISO 13485’s text entirely: Medical Device Reporting (21 CFR Part 803), Corrections and Removals reporting (21 CFR Part 806), Medical Device Tracking (21 CFR Part 821), and Unique Device Identification (21 CFR Part 830). This is where the clause structure above stops covering everything — these four areas are FDA-specific regulatory obligations, not ISO 13485 requirements. They’re evaluated during routine surveillance, compliance follow-up, and PMA postmarket inspections; a narrow exception can apply to certain PMA preapproval inspections when the manufacturer hasn’t yet introduced the device to the U.S. market.

The change that affects Clause 5 most directly: under the prior QSR, management review records were categorically exempt from FDA review under §820.180(c). Under CP 7382.850, that exemption is gone. Management review now sits squarely inside the Management Oversight QMS Area, and an investigator can ask to see it — which means the twelve required Clause 5.6.2 inputs covered above aren’t just a certification-audit concern anymore.

One caution worth stating plainly: ISO 13485 certification and FDA QMSR compliance are related but not identical. A QMS built cleanly against Clauses 4 through 8 covers the ISO 13485 core that QMSR incorporates, but it doesn’t automatically satisfy the four OAFRs — those require their own documented processes regardless of how strong your clause-by-clause QMS is.

If you’re not sure whether your current documentation satisfies both frameworks → our FDA QSR vs ISO 13485 comparison and MDSAP vs ISO 13485 breakdown both walk through this in more detail than fits here.

ISO 13485 vs ISO 9001: Same Numbers, Different Weight

ElementISO 13485:2016ISO 9001:2015
Structure8 clauses, own structure (not Annex SL)10 clauses, Annex SL high-level structure
Risk managementDocumented risk management required in product realization (7.1); note references ISO 14971Risk-based thinking, less prescriptive
Customer satisfaction monitoringNo direct ISO 9001-style requirement; feedback/complaints addressed via Clause 8.2Explicit requirement (Clause 9.1.2)
DocumentationMedical device file required (Clause 4.2)No equivalent requirement
Design controlsDetailed, mandatory unless justified exclusionLess detailed by comparison
Regulatory linkDirectly referenced in FDA QMSR (21 CFR 820)Not tied to a specific regulation

The clause numbers look similar enough to cause real confusion — both standards use “Clause 7” for a large operational section, but the content underneath diverges substantially. If your organization holds both certifications, don’t assume a clause 7 audit finding under one standard tells you anything about your standing under the other. For the full comparison, see ISO 9001 vs ISO 13485.

The objection I hear most on this topic: “We’re already ISO 9001 certified — how much of this is actually new work?” Realistically, expect Clauses 5 and 6 to require the least rework, since management responsibility and resource management overlap heavily in intent. Clauses 4, 7, and 8 are where the medical device-specific requirements add real documentation and process work — the medical device file, design control rigor, and CAPA’s broader-impact evaluation aren’t things a general ISO 9001 QMS already has built in.


Most teams don’t fail an ISO 13485 audit because they misunderstood a clause. They fail because they assumed a documented procedure was enough without checking whether it actually produces the evidence an auditor will ask to see.

👉 Run a structured check before that assumption gets tested in front of an auditor → ISO 13485 Gap Assessment Checklist


Quick Clause Reference Checklist

A clause tells you what’s required. It doesn’t tell you what to hand an auditor when they ask for proof. Below is a quick translation — clause by clause, requirement to evidence.

ISO 13485 clauses explained through an audit evidence checklist showing objective evidence for Clauses 4, 5, 7, and 8
ISO 13485 clauses explained through the objective evidence auditors may review for Clauses 4, 5, 7, and 8.

✅ Clause 4 — QMS scope defined, outsourced processes controlled, medical device file assembled
✅ Clause 5 — Quality policy documented, management review covering all required inputs
✅ Clause 6 — Competence records current, contamination controls documented where applicable
✅ Clause 7 — Risk management documented within product realization; ISO 14971 provides further guidance; design control records complete, supplier evaluation criteria defined
✅ Clause 8 — Complaint handling tied to regulatory reporting, CAPA records show broader-impact evaluation

⚠️ Clauses 1–3 — Exclusions and non-applicability justified in the quality manual, not just left blank

For implementation sequencing beyond the checklist above, our ISO 13485 Implementation Roadmap and ISO 13485 Gap Assessment: Step-by-Step Guide walk through the order to tackle these in.


FAQ

How many clauses does ISO 13485:2016 have?

Eight. Clauses 1 through 3 are introductory and carry no auditable requirements. Clauses 4 through 8 contain the substantive quality management system requirements that certification bodies audit against — and since February 2026, FDA investigators evaluate the same core requirements under Compliance Program 7382.850.

Does ISO 13485 follow the same structure as ISO 9001?

No. ISO 13485 does not use ISO’s Annex SL high-level structure, which ISO 9001, ISO 14001, and ISO 45001 all share. The technical committee kept ISO 13485 independent specifically to protect regulatory stability for device manufacturers, so clause numbers that look similar between the two standards often cover different scope.

Can I exclude clauses from ISO 13485?

Only with documented justification. Under Clause 4.2.2, the scope and justification for any exclusion or non-application have to be recorded in the quality manual, and you need to be prepared to defend that justification during an audit.

Which ISO 13485 clause covers risk management?

Clause 7.1 (Planning of Product Realization) is where documented risk management is explicitly required, and its note points to ISO 14971 for further guidance. But risk-related requirements aren’t confined to one clause — they surface throughout Clauses 4 through 8 rather than sitting in a single isolated section.

What’s the difference between ISO 13485 and the FDA’s QMSR?

As of February 2, 2026, FDA’s QMSR incorporates ISO 13485:2016 by reference into 21 CFR Part 820, and FDA’s inspection methodology changed to match — Compliance Program 7382.850 replaced QSIT the same day. The two frameworks are far more tightly aligned than before, but they’re not identical: four Other Applicable FDA Requirements (Medical Device Reporting, Corrections and Removals, Medical Device Tracking, and UDI) sit outside ISO 13485’s text and are evaluated in applicable inspection types, with a limited exception for certain PMA preapproval inspections when the device has not yet been introduced to the U.S. market.

What is CP 7382.850?

CP 7382.850 (Inspection of Medical Device Manufacturers) is FDA’s current compliance program manual for device inspections, effective February 2, 2026 alongside the QMSR. It replaced the Quality System Inspection Technique (QSIT) and reorganizes inspections around six QMS Areas — Management Oversight, Design and Development, Production and Service Provision, Measurement/Analysis/Improvement, Outsourcing and Purchasing, and Change Control — plus four Other Applicable FDA Requirements evaluated in most inspection types.

Do I need to buy ISO 9001 to understand ISO 13485’s terminology?

You don’t need to purchase it, but ISO 13485 does reference ISO 9000:2015 for its terms and definitions, and auditors expect consistent use of that vocabulary in your documentation.

Which clauses deserve the closest audit preparation?

In practice, Clause 4.2 (documentation control), Clause 7.3 where applicable (design and development), and Clause 8.5 (CAPA effectiveness) tend to draw sustained attention, largely because each requires ongoing documented evidence rather than a one-time procedure. The exact focus varies by organization, device type, and regulatory scope — under the current FDA inspection framework, Management Oversight and Measurement, Analysis, and Improvement are evaluated on every inspection regardless of device type.

Is a documentation kit enough to get ISO 13485 clause requirements right?

A kit gives you a starting structure, but clause-by-clause compliance depends on evidence specific to your processes — training records, design and development records, CAPA effectiveness checks. Our ISO Documentation Kits for Manufacturers page breaks down what a kit does and doesn’t cover.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching how the clauses fit together? Start with What Is ISO 13485? for the foundational overview before working through this clause breakdown a second time.

🔹 Ready to assess where your QMS actually stands? Run the ISO 13485 Gap Assessment Checklist against the clause list above — it’s built to map directly to Clauses 4 through 8.

🔹 Need the official standard text to cite exact clause language? Purchase ISO 13485:2016 through ANSI Webstore — use code CC2026 for 5% off through December 31, 2026. International-language editions are available for teams managing documentation across multiple regulatory regions.

🔹 Need your internal auditors trained on this clause structure before your next surveillance audit? ISO 13485 training through BSI Group covers the structure clause by clause with a certification body’s own instructors.

The Standards Navigator breaks down what these clauses actually demand — not just what they’re titled — so your team can walk into an audit knowing which sub-clause the finding will land on before it does.


Stay Ahead of Clause-Level Changes

Most QMS documentation doesn’t fail because a team ignored ISO 13485. It fails because someone mapped a procedure to the wrong clause once, early on, and every review since has confirmed the wrong thing.

Organizations that treat the clause structure above as a living reference — checked against actual audit findings, updated as FDA’s QMSR enforcement approach becomes clearer — walk into surveillance audits with far fewer surprises than organizations treating their quality manual as a document they wrote once and filed away.

The Standards Navigator tracks ISO 13485, QMSR, and the surrounding medical device standards landscape as they develop, not just at certification time.

👉 Get updates on ISO 13485 and medical device QMS requirements
👉 Be first to access new gap assessment tools and clause-mapping resources

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

ISO 13485 Gap Assessment: A Step-by-Step Guide for Medical Device Manufacturers (2026)

Learn how to run an ISO 13485 gap assessment step by step — from scoping and clause mapping to grading findings and building a remediation timeline before your certification audit.

How to run an ISO 13485 gap assessment before your certification body ever sees your QMS.

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Gap Assessment Is the Step Most Manufacturers Skip

Many manufacturers don’t discover their biggest ISO 13485 gaps until they systematically compare their QMS against the standard.

An ISO 13485 gap assessment gives you a structured way to find those gaps before your certification body does. It’s a clause-by-clause comparison of your current quality management system against what ISO 13485:2016 actually requires — and it’s one of the highest-leverage steps between “we think we’re ready” and “we’re ready for Stage 1.”

This guide walks through the gap assessment process step by step: how to scope it, how to run it, how to grade what you find, and how to turn the results into a remediation plan your team can actually execute before your audit window opens.

From the Floor: As a certified ISO 9001 Internal Auditor, the pattern I see most often in gap assessments — regardless of which standard is on the cover — is a QMS that has real documentation but no clause map. Procedures exist. Records exist. But nobody has walked the standard clause by clause and confirmed each requirement actually has evidence behind it. That’s exactly what a gap assessment is designed to expose, and finding it internally gives your team more control over the remediation timeline than discovering it during certification.

Before you build a remediation plan, you need to know where the gaps actually are. Run the free ISO 13485 Gap Assessment Checklist and get a clause-by-clause starting point for your own QMS.


In This Guide

  • What an ISO 13485 gap assessment actually is, and how it differs from an internal audit
  • The eight-step process, from scoping to remediation
  • How to grade findings so your team knows what to fix first
  • A readiness checklist for what “gap-assessed” should actually mean
  • Answers to the questions manufacturers ask most before their first assessment


👉 Start Here (Top Resources)

  • Own the standard you’re assessing against: ISO 13485:2016 — ANSI Webstore — you can’t run an accurate gap assessment without the current clause text in front of you. Use code CC2026 for 5% off through December 31, 2026.
  • Close the gaps once you find them: 9001Simplified — documentation kits built for manufacturers who need to build or rebuild QMS documentation without hiring a full-time consultant.
  • Get your team trained on the requirements before they run the assessment: ISO 13485 Training — BSI Group — a team that understands the clause structure finds gaps faster and more accurately than one working from intuition.

What an ISO 13485 Gap Assessment Actually Is

A gap assessment is not an audit. It’s not a certification activity, and no external party has to be involved. It’s an internal, structured comparison: for every requirement in ISO 13485:2016, does your QMS have documented evidence that requirement is met — and if not, how far off is it?

That distinction matters because it changes the tone of the exercise. An internal audit (covered in our guide on how to audit a medical device QMS) assumes a QMS is largely built and tests whether it’s being followed. A gap assessment assumes nothing — it’s asking “does this exist at all, and if it does, is it complete.”

Gap Assessment vs. Internal Audit

Gap AssessmentInternal Audit
Primary questionDoes the requirement and supporting evidence exist?Is the QMS being followed and operating effectively?
Typical timingOften performed during QMS development or transitionPerformed as part of the established audit program
Main outputGap list and remediation planAudit findings and corrective action
Evidence examinedDocuments, records, and implementation evidenceProcess implementation, records, and objective evidence
PurposeIdentify what needs to be built, changed, or strengthenedEvaluate conformity and implementation of the established QMS

Quick Answer

QuestionQuick Answer
Is a gap assessment required for ISO 13485 certification?No. It’s not a formal requirement of the standard, but it’s a practical risk-reduction step manufacturers can use to identify gaps before a certification audit.
How long does a gap assessment take?As a planning estimate, a single-site manufacturer with an existing QMS might spread the assessment across roughly 2–4 weeks of part-time effort. Actual duration varies significantly with QMS maturity, scope, number of sites, product lines, and team availability.
Can I do a gap assessment myself, or do I need a consultant?You can do it yourself with a structured checklist and a working knowledge of the standard. Consultants add value for complex or first-time QMS builds, but the assessment itself doesn’t require outside certification.
What’s the difference between a gap assessment and an internal audit?A gap assessment checks whether documentation and evidence exist against each clause. An internal audit checks whether an existing, documented QMS is actually being followed in practice.

The Eight-Step Gap Assessment Process

Step 1: Define Scope and Assemble Your Team

Before you open the standard, decide what’s actually in scope. Which sites? Which product lines? Which regulatory markets — because that determines which country-specific requirements layer on top of the ISO 13485 baseline. If you’re weighing whether MDSAP applies to your assessment scope, our MDSAP vs ISO 13485 guide walks through that decision separately.

Assemble a small cross-functional team — quality, at minimum, plus whoever owns design, production, and supplier management. A gap assessment run entirely by one person in the quality department tends to miss operational gaps that only show up on the floor.

Step 2: Gather Current QMS Documentation

Pull everything: your quality manual, procedures, work instructions, forms, records, and any prior audit findings — internal or external. If your document control system is disorganized, this step alone often reveals your first gap. See our guide on ISO 13485 documentation requirements for what a complete document set should include.

Step 3: Build Your Clause Map

At a high level, ISO 13485:2016 organizes its requirements across five main clause groups: Quality Management System (Clause 4), Management Responsibility (Clause 5), Resource Management (Clause 6), Product Realization (Clause 7), and Measurement, Analysis and Improvement (Clause 8). Build a simple matrix — clause number down one side, your corresponding procedure or record down the other. Anywhere that cell is blank is your first visible gap, before you’ve even started evaluating quality.

ISO 13485 gap assessment clause map connecting requirements to procedures, records, and objective evidence
An ISO 13485 gap assessment clause map connects each requirement to the corresponding QMS procedure, work instruction, records, and objective evidence.

Step 4: Walk Each Clause Against the Evidence

This is the core of the assessment. For each clause, ask three questions: Does a documented procedure exist? Does it match what the standard actually requires — not just what sounds similar? And is there objective evidence (records, forms, logs) that the procedure is being followed, not just written?

CAPA is worth flagging specifically here because it requires the team to connect nonconformance, root cause, corrective action, and effectiveness verification across the QMS. Our breakdown of CAPA requirements under ISO 13485 covers what auditors expect to see connected — traceable within the QMS rather than reconciled manually across separate systems.

This is often where gap assessments slow down because the work is tedious, not because it’s conceptually difficult. If your team needs a structured starting point instead of building the clause matrix from scratch → Run the free ISO 13485 Gap Assessment Checklist.

ISO 13485 gap assessment showing how procedures, records, and objective evidence demonstrate QMS conformity
An ISO 13485 gap assessment should verify not only that procedures exist, but that records provide objective evidence the QMS is being followed.

Step 5: Grade Each Finding

Not every gap carries the same weight. A missing signature on a training record is not the same category of problem as a design control process that doesn’t exist. Grade findings on a simple scale:

  • Critical — the requirement is effectively absent. No procedure, no evidence, no compensating control.
  • Major — a procedure exists but has a significant gap against the clause requirement, or evidence of following it is inconsistent.
  • Minor — the procedure and evidence both exist, but execution has small, correctable inconsistencies.

Grading matters because it drives sequencing. These labels are an internal prioritization framework, not ISO 13485-defined finding classifications — the exact grading terminology and criteria used by a certification body or regulatory program can vary. For an internal assessment, the important thing is to apply your criteria consistently so the team knows which gaps require immediate attention.

Step 6: Prioritize Remediation

Start with the gaps that present the greatest risk to QMS conformity or product and regulatory compliance. In most cases, that means addressing foundational gaps such as a missing design-control process or nonexistent CAPA system before working through lower-risk administrative issues. Major findings come next, typically grouped by clause area so one person or team can work through related gaps together rather than jumping between unrelated processes.

If you are rebuilding documentation from a critical or major finding → start with the clause itself, not a generic template. A procedure written to satisfy a checklist item without matching your actual process creates a new gap the moment an auditor asks a follow-up question.

If you are working through a backlog of minor findings → batch them by owner and set a single close-out date rather than tracking dozens of individual deadlines. Minor findings left open individually tend to get lost; batched with a deadline, they get closed.

Step 7: Build a Remediation Timeline

Attach real dates to every finding, not target quarters. Critical findings should have the shortest timeline your team can realistically execute — these are the gaps most likely to create significant problems during a certification assessment if they remain unresolved. Build in a buffer before your target certification audit date; remediation almost always takes longer than the first estimate, especially where a new procedure requires training staff to actually follow it.

Step 8: Re-Assess Before You Schedule Your Audit

A gap assessment isn’t a one-time snapshot. Once remediation work closes out your critical and major findings, re-walk those specific clauses to confirm the fix actually holds — not just that a document was updated, but that the evidence trail behind it exists. This is also the point where many manufacturers benefit from a full internal audit as a final check before scheduling Stage 1.


Common Mistakes That Undermine a Gap Assessment

Treating the assessment as a documentation review only. Confirming a procedure exists isn’t the same as confirming it’s followed. A gap assessment that never looks at records — training logs, CAPA files, supplier evaluations — will miss exactly the kind of gap an auditor finds first, because auditors ask for objective evidence, not just the procedure. Our guide on common mistakes in ISO 13485 QMS implementation covers this pattern in more depth.

Assessing against an old edition of the standard. ISO 13485:2016 is the current edition, but manufacturers working from a QMS built years ago sometimes have procedures written against superseded clause numbering. Confirm you’re assessing against the current published text before you start building your clause matrix.

Skipping the connection to FDA’s QMSR. If you sell into the United States, consider whether your gap assessment also needs to address FDA’s QMSR requirements and inspection expectations — FDA’s QMSR, effective February 2, 2026 and incorporating ISO 13485:2016 by reference, expanded what FDA can review during an inspection. Records that were previously exempt from routine inspection under the legacy QSR — management review, internal quality audit, and supplier audit records — are not exempt under QMSR. That’s worth building into your assessment scope rather than assuming an ISO 13485-only assessment automatically covers it.


Gap Assessment Readiness Checklist

✅ Scope defined — sites, product lines, and regulatory markets confirmed
✅ Cross-functional team assembled, not just quality department staff
✅ Full current QMS documentation set gathered and organized
✅ Clause matrix built against ISO 13485:2016, Clauses 4 through 8
✅ Each clause walked against both procedure and objective evidence, not procedure alone
✅ Findings graded — critical, major, minor — using consistent criteria
✅ Remediation timeline built with real dates, prioritized by severity
✅ Critical and major findings re-assessed after remediation, before scheduling your audit

ISO 13485 gap assessment process showing how manufacturers find, prioritize, remediate, and re-assess QMS gaps before certification
An ISO 13485 gap assessment turns identified QMS gaps into a prioritized remediation plan, followed by verification and re-assessment before the certification audit.

Frequently Asked Questions

Is a gap assessment required before ISO 13485 certification?

No. It’s not a formal requirement in the standard itself. It’s a risk-reduction step manufacturers use to avoid discovering major or critical nonconformities for the first time during an actual certification audit, where findings can delay certification.

How is a gap assessment different from an internal audit?

A gap assessment asks whether documentation and evidence exist at all against each clause — it’s typically run once, early, often before a QMS is fully built out. An internal audit assumes a documented QMS exists and tests whether it’s actually being followed in day-to-day operation. A common approach is to run the gap assessment first, then use internal audits on a recurring schedule once the QMS is established.

Who should be involved in a gap assessment?

At minimum, someone from quality who knows the standard well enough to interpret clause intent, plus representation from any function the clauses touch directly — design, production, supplier management. A single-person assessment tends to miss operational gaps that only surface when someone from outside quality reviews the finding.

How long does a gap assessment typically take?

As a planning estimate, a manufacturer with an existing QMS and a single site in scope might spread the assessment across roughly 2–4 weeks of part-time effort. Actual duration varies significantly with QMS maturity, scope, number of sites, product lines, and team availability — manufacturers building a QMS from scratch, or with multiple sites in scope, should expect it to take longer.

Can I use the same gap assessment for MDSAP readiness?

Largely, yes — MDSAP audits use ISO 13485:2016 requirements alongside applicable regulatory requirements from participating authorities, so a thorough ISO 13485 gap assessment covers most of the same ground. MDSAP layers those country-specific regulatory requirements on top of the ISO 13485 baseline, so if MDSAP is in scope, your assessment should also map those additional requirements. See our MDSAP vs ISO 13485 guide for how the two relate.

What happens if I find a critical gap close to my planned audit date?

Push the audit date. Scheduling a certification audit around a known critical gap doesn’t make the gap disappear — it moves the risk of discovering that gap into the certification audit, where the certification body will determine whether the issue constitutes a nonconformity and how it should be classified, instead of remaining an internal finding you controlled the timeline on.

Do I need a consultant to run a gap assessment?

Not necessarily. A structured checklist and a working knowledge of the standard’s clause structure is enough for most single-site manufacturers with an existing QMS. Consultants add the most value for first-time QMS builds, multi-site assessments, or situations where the internal team lacks bandwidth to run the assessment alongside daily operations.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still figuring out where your QMS stands? Start with the ISO 13485 Gap Assessment Checklist — it’s the fastest way to see your clause-by-clause starting point before you build a full remediation plan.

🔹 Ready to close documentation gaps you’ve already identified? 9001Simplified’s documentation kits are built for manufacturers assembling or rebuilding QMS documentation without a full-time consultant.

🔹 Need to confirm your clause matrix against the current standard? Get ISO 13485:2016 from ANSI Webstore — code CC2026 takes 5% off through December 31, 2026.

🔹 Want your team trained before they run the assessment? BSI Group’s ISO 13485 training builds the clause knowledge that makes a gap assessment faster and more accurate.

Treating a gap assessment as a formality can leave significant gaps undiscovered until the certification audit. A properly executed assessment gives your team an opportunity to find those gaps internally, assign ownership, and control the remediation timeline before the certification audit begins. The Standards Navigator will keep this guide current as ISO 13485 and its related regulatory frameworks continue to evolve.


Stay Ahead of Your Next Audit Cycle

Skipping the gap assessment step doesn’t remove the risk of undiscovered gaps — it increases the chance that a gap will first be identified during the certification process, in front of an auditor, where the certification body determines whether it constitutes a nonconformity. Running it properly moves that discovery earlier, onto your own timeline, with your team in control of the fix.

The Standards Navigator tracks how ISO 13485, MDSAP, and FDA’s QMSR continue to shift so your QMS doesn’t fall behind a requirement you didn’t know had changed.

👉 Get updates on ISO 13485 requirements and medical device compliance as they happen
👉 Be first to access new gap assessment tools and documentation resources as we build them

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

MDSAP vs ISO 13485: What’s the Difference and Do You Need Both in 2026?

MDSAP and ISO 13485 are often confused, but they answer different questions. This guide breaks down how the MDSAP audit program relates to the ISO 13485:2016 standard, what changed with FDA’s 2026 QMSR, and which manufacturers actually need MDSAP registration.

Whether the MDSAP consolidated audit program adds real value to your QMS — or scope you don’t need yet.

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Two Audits, One QMS Standard — and a Decision Most Manufacturers Get Wrong

MDSAP vs ISO 13485 is a distinction worth getting right before you scope an audit program: these are not competing options, and they are not two paths to the same certificate. Treating them as interchangeable is exactly how manufacturers end up either over-auditing themselves or discovering — mid-application — that a market they assumed was covered isn’t.

If you sell into more than one of the five MDSAP countries, this decision affects your audit calendar, your registrar spend, and your regulatory submission timeline for years. If you sell only into the EU or UK, most of what follows doesn’t apply to you at all — and that’s worth knowing before you spend a quarter evaluating a program you don’t need.

This guide breaks down exactly what MDSAP is, how it relates to ISO 13485:2016, and — now that the FDA’s Quality Management System Regulation has replaced the legacy 21 CFR Part 820 — what changed for US-market manufacturers in 2026.

From the Floor: With 25+ years in heavy industrial manufacturing and a certified ISO 9001 Internal Auditor credential, I’ve seen the same regulated-QMS failure pattern show up regardless of which standard is on the cover — 9001 or 13485. It’s not missing documentation. It’s documentation that exists but doesn’t connect: a CAPA log that references a nonconformance report that was never actually closed out in the corrective action file. Stack five regulatory authorities’ expectations on top of each other instead of one, and that gap can become a nonconformity that appears in the MDSAP audit record used by the participating Regulatory Authorities.

Before you evaluate MDSAP, confirm your QMS actually conforms to ISO 13485:2016 first — MDSAP audits against it, it doesn’t substitute for it. Run the free ISO 13485 Gap Assessment Checklist and see exactly where your documentation stands before you add audit scope on top of it.

In This Guide

  • What MDSAP actually is, and how it relates to ISO 13485:2016
  • A side-by-side comparison of both frameworks
  • What changed in 2026 with the FDA’s QMSR and the revised MDSAP Audit Approach
  • Decision-stage signals for whether MDSAP applies to your business
  • What MDSAP costs — and what it saves — compared to separate country audits
  • Documentation issues that can create problems in MDSAP-scope audits
  • A readiness checklist and answers to the questions manufacturers ask most


👉 Start Here (Top Resources)

  • Own the standard MDSAP is built on: ISO 13485:2016 — ANSI Webstore — the foundation document every MDSAP audit is measured against. Use code CC2026 for 5% off through December 31, 2026.
  • Close documentation gaps before you’re audited on them: 9001Simplified — documentation kits built for manufacturers assembling or tightening a QMS without hiring a full-time consultant.
  • Get your team trained on the underlying requirements: ISO 13485 Training — BSI Group — BSI is one of the Auditing Organizations recognized under MDSAP, and their training builds the ISO 13485 foundation your audit is scored against.

What Is ISO 13485, and What Is MDSAP Built on Top Of It?

ISO 13485:2016 is the quality management system standard for medical device manufacturers. It’s a standalone document you can certify to on its own — covered in detail in our What Is ISO 13485 guide.

MDSAP (Medical Device Single Audit Program) is not a standard. It’s a regulatory audit program. Five participating Regulatory Authorities — Australia’s TGA, Brazil’s ANVISA, Health Canada, Japan’s MHLW/PMDA, and the U.S. FDA — use a single consolidated audit, conducted by an MDSAP-recognized Auditing Organization, to assess the applicable QMS and regulatory requirements across participating markets, rather than requiring separate audits from each regulator. That audit is scored against ISO 13485:2016 as the baseline, with country-specific regulatory requirements layered on top for each market a manufacturer participates in.

Standalone ISO 13485 certification, by contrast, is issued by certification bodies accredited through national accreditation bodies — in the US, that’s typically ANAB. MDSAP Auditing Organizations go through a separate recognition process run directly by the participating Regulatory Authorities, not through the standard accreditation pathway.

In plain terms: ISO 13485 is what you’re audited against. MDSAP is who accepts that audit, and how many regulators it satisfies at once.


Quick Answer

QuestionQuick Answer
Is MDSAP the same as ISO 13485?No. MDSAP is a multi-country regulatory audit program built on top of ISO 13485:2016 — it doesn’t replace the standard, it audits against it plus country-specific requirements.
Do I need ISO 13485 certification before MDSAP?No. Your QMS must conform to ISO 13485:2016, but you don’t necessarily need a separate ISO 13485 certificate before undergoing an MDSAP audit — the MDSAP audit itself assesses that conformance.
Is MDSAP required?Only for Class II–IV Canadian market access. In the other participating MDSAP markets, participation is generally voluntary, although it can consolidate applicable regulatory assessments across multiple markets.
Does MDSAP replace FDA inspections entirely?No. MDSAP audit results can be used by FDA within its regulatory program, but FDA retains its authority to conduct inspections, including for-cause inspections.

MDSAP vs ISO 13485: Side-by-Side

CategoryISO 13485:2016MDSAP
What it isA quality management system standardA multi-jurisdiction regulatory audit program
BasisStandalone documentBuilt on ISO 13485:2016 plus country-specific regulatory requirements
Who administers itCertification bodies accredited by ANAB or an equivalent accreditation bodyAuditing Organizations recognized by the five participating Regulatory Authorities
Countries coveredGlobal — recognized wherever ISO 13485 certification is acceptedAustralia, Brazil, Canada, Japan, United States
Can you buy it?Yes — it’s a purchasable standard documentNo — it’s an audit program, not a document
Mandatory?Often required by customers, notified bodies, or regulators (EU MDR, for example)Mandatory only for Class II–IV Canadian market access; voluntary elsewhere
Audit frequencyPer your certification body’s surveillance schedule — typically annualInitial audit followed by annual surveillance audits within the certification cycle
What you getAn ISO 13485 certificateAn MDSAP certification document and audit report each participating Regulatory Authority can use within its own regulatory program

For the broader question of how ISO 13485 stacks up against the standard most manufacturers compare it to first, see ISO 9001 vs ISO 13485.


The 2026 Regulatory Shift: QMSR and the Revised MDSAP Audit Approach

MDSAP vs ISO 13485 infographic showing the 2026 FDA QMSR transition and changes to medical device quality records
MDSAP vs ISO 13485: The 2026 FDA QMSR aligns U.S. medical device quality requirements with ISO 13485:2016 and changes FDA access to management review, internal audit, and supplier audit records.

Two changes landed in 2026 that directly affect this comparison.

On February 2, 2026, the FDA’s Quality Management System Regulation (QMSR) officially took effect, replacing the legacy 21 CFR Part 820 Quality System Regulation and incorporating ISO 13485:2016 by reference. That doesn’t make US manufacturers MDSAP-compliant automatically — it means the US regulatory baseline now speaks the same structural language as ISO 13485, closing a gap that used to require manufacturers to maintain two separate documentation logics. We cover the mechanics of that shift in FDA QSR vs ISO 13485.

The QMSR also removed a long-standing FDA inspection exemption. Under the prior QSR, §820.180(c) shielded management review records, internal quality audit reports, and supplier audit reports from routine FDA inspection. The QMSR eliminates that exemption entirely — FDA’s own QMSR FAQ confirms investigators now have authority to review management review, quality audit, and supplier audit records as part of a standard inspection. For manufacturers who treated those records as internal-only, that’s a meaningful shift in what “audit-ready” documentation needs to look like.

Around the same window, the MDSAP Regulatory Authority Council released a revised Audit Approach document (MDSAP AU P0002.010), updating the audit sequence and process guidance auditors use during MDSAP assessments. If your last MDSAP audit was conducted under the prior version, don’t assume your documentation package is still current against the revised approach — verify against the current edition before your next audit window.

It can be tempting to assume that QMSR compliance automatically covers MDSAP scope. It doesn’t — QMSR alignment closes the gap between the US baseline and ISO 13485, but MDSAP still layers the applicable regulatory requirements of each participating jurisdiction on top of that baseline. Check where your QMS actually stands before you assume you’re covered → Run the ISO 13485 Gap Assessment Checklist.


Do You Need MDSAP? Decision-Stage Signals

  • If you are selling only into the EU or UK → you still need to meet the applicable medical-device QMS and conformity-assessment requirements for those markets, but MDSAP is not generally required there.
  • If you are selling into Canada at Class II, III, or IV → MDSAP is mandatory. Health Canada requires an MDSAP certificate, issued by a recognized MDSAP Auditing Organization, as part of the device license application.
  • If you sell into several of the five MDSAP countries → compare the cost and disruption of MDSAP against the separate regulatory assessments that would otherwise apply. Three or more can be a useful practical threshold for comparison, but the right number depends on your specific audit costs, inspection history, device scope, and market plans.
  • If you are already ISO 13485 certified and sell only into the US → weigh MDSAP against your actual FDA inspection frequency and any near-term expansion plans before adding audit scope you may not need yet.
MDSAP decision flowchart showing when medical device manufacturers need MDSAP for Canada and when it is generally voluntary in other markets
A practical MDSAP decision guide showing when certification is required for Canadian Class II–IV devices and when manufacturers should evaluate MDSAP based on market scope, audit costs, and regulatory strategy.

What MDSAP Actually Costs You — And What It Saves

The most common objection we hear is straightforward: MDSAP audits cost more than a standard ISO 13485 surveillance audit, so why add the expense?

That’s true in isolation — an MDSAP audit typically runs longer and costs more per audit day than a single-standard ISO 13485 surveillance visit, because the auditor is assessing conformance to multiple regulatory frameworks in one visit. But the comparison that matters isn’t MDSAP audit cost versus ISO 13485 audit cost. It’s MDSAP audit cost versus the combined cost of separate inspections from Health Canada, ANVISA, TGA, and PMDA, run independently, on different schedules, each requiring separate audit prep. For manufacturers selling across several MDSAP markets, the consolidation can make the overall audit program less costly and less disruptive than managing multiple separate regulatory assessments — but the business case depends on device classification, facility count, audit scope, your Auditing Organization, and your existing inspection cadence, so get a scoped quote rather than budgeting off a generic number.

Manufacturers building out documentation to support a broader audit scope shouldn’t be doing it from scratch. If your QMS documentation isn’t structured to hold up under multiple regulatory frameworks at once, that’s the gap to close first → 9001Simplified’s documentation kits are built for exactly this kind of consolidation work.


Documentation Issues That Can Create Problems in MDSAP Readiness

One area worth checking closely is CAPA traceability. CAPA records should connect clearly to the underlying nonconformance, investigation, corrective action, and effectiveness evidence, rather than leaving the auditor to reconcile separate systems manually — see our breakdown of common mistakes in ISO 13485 QMS implementation and the full CAPA requirements under ISO 13485 for what auditors expect to see connected.

Another area to review is how regulatory requirements are mapped into the QMS. MDSAP audits ISO 13485 alongside applicable jurisdiction-specific requirements, so documentation that only reflects one regulator’s language may need additional mapping before an MDSAP audit. Our guide on ISO 13485 documentation requirements covers how to structure it correctly the first time.


MDSAP vs ISO 13485 readiness infographic showing CAPA traceability, document control, regulatory mapping, internal audits, and audit evidence
MDSAP vs ISO 13485: MDSAP readiness depends on connected evidence across CAPA, document control, regulatory mapping, internal audits, and market scope.

MDSAP Readiness Checklist

✅ QMS is currently certified — or verified compliant — to ISO 13485:2016
✅ CAPA records cross-reference nonconformance reports within the QMS itself, not a separate tracking tool
✅ Document control system is organized by ISO 13485 clause structure, not by individual regulator language
✅ You’ve confirmed which of the five MDSAP countries you actually sell into or plan to
✅ You’ve reviewed your documentation against the revised MDSAP Audit Approach (AU P0002.010)
✅ You’ve scoped audit cost and timeline with an MDSAP-recognized Auditing Organization
✅ Internal audit process already traces process interactions, not just individual clause compliance — see how to audit a medical device QMS


Frequently Asked Questions

Is MDSAP the same thing as ISO 13485?

No. ISO 13485:2016 is the quality management system standard. MDSAP is a regulatory audit program that assesses conformance to that standard, plus country-specific requirements from five participating Regulatory Authorities, in a single consolidated audit.

Do I need to be ISO 13485 certified before I can apply for MDSAP?

Your QMS needs to conform to ISO 13485:2016 — MDSAP auditors assess that conformance directly as part of the MDSAP audit itself. In practice, most manufacturers already hold or are pursuing ISO 13485 certification before entering the MDSAP process.

Which countries does MDSAP cover?

Five participating Regulatory Authorities: Australia (TGA), Brazil (ANVISA), Canada (Health Canada), Japan (MHLW/PMDA), and the United States (FDA). A number of other regulators participate as observers or affiliate members without full recognition of MDSAP audit results.

Is MDSAP required to sell medical devices in the United States?

No. The FDA accepts MDSAP audit results as part of its compliance program, and the 2026 QMSR incorporates ISO 13485:2016 by reference, but MDSAP participation itself remains voluntary for US-only manufacturers.

How did the FDA’s 2026 QMSR change affect MDSAP?

The QMSR, effective February 2, 2026, replaced 21 CFR Part 820 and incorporated ISO 13485:2016 by reference — narrowing the gap between US regulatory expectations and the ISO 13485 baseline that MDSAP already audits against. It doesn’t grant automatic MDSAP compliance; it changes what the US regulatory floor requires your documentation to look like.

How much does an MDSAP audit cost compared to a standard ISO 13485 audit?

MDSAP audits generally run longer and cost more per audit than a single-standard ISO 13485 surveillance audit, since the scope covers multiple regulatory frameworks in one visit. Pricing varies significantly by Auditing Organization, facility count, and audit scope — get a quote scoped to your specific situation rather than relying on a general figure.

Can a small manufacturer participate in MDSAP?

Yes. Any manufacturer with a product that falls under the scope of at least one participating Regulatory Authority may apply. It tends to make the most financial sense for manufacturers selling into several of the five MDSAP countries, where consolidating audits can produce clearer savings — though the exact threshold depends on your specific cost structure.

Does an MDSAP certificate replace my ISO 13485 certificate?

Not automatically, and it depends on the market. In Canada, the MDSAP certificate has replaced the standalone ISO 13485 certificate in the device license application process for Class II–IV devices. In most other participating markets, manufacturers typically maintain both, since ISO 13485 certification is often required independently by customers or notified bodies.


📥 Free Resources

  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements before pursuing MDSAP or standalone certification.
  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.
  • AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification.

Not Sure What to Do Next?

🔹 Still researching whether MDSAP applies to you? Start with the ISO 13485 Gap Assessment Checklist — confirm your QMS conforms to ISO 13485:2016 before you evaluate adding MDSAP scope on top of it.

🔹 Ready to close documentation gaps before your next audit? 9001Simplified’s documentation kits are built for manufacturers structuring a QMS to hold up under more than one regulatory framework at once.

🔹 Need to buy the ISO 13485:2016 standard itself? Get it directly from ANSI Webstore — code CC2026 takes 5% off through December 31, 2026.

🔹 Want your team trained on the requirements before your MDSAP audit? BSI Group’s ISO 13485 training builds the foundation MDSAP auditors score against.

MDSAP isn’t a bigger version of ISO 13485 certification — it’s a different question entirely: not “is your QMS compliant,” but “how many regulators can rely on the same answer.” Get that distinction right before you scope an audit program you may not need, or miss one you do. The Standards Navigator will keep tracking how MDSAP and the 2026 QMSR shift continue to interact as more guidance comes out.


Stay Ahead of the Next Regulatory Shift

Manufacturers who treat MDSAP as “extra paperwork” usually find out the hard way — mid-application, with a Canadian import deadline already on the calendar. Manufacturers who map their audit scope to their actual markets first spend less on audits and never scramble for a certificate they didn’t know they’d need.

The Standards Navigator tracks how ISO 13485, MDSAP, and FDA’s QMSR continue to shift against each other so you don’t have to monitor five regulators’ guidance pages yourself.

👉 Get updates on medical device compliance and regulatory changes as they happen
👉 Be first to access new gap assessment tools and documentation resources as we build them

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

How to Audit a Medical Device QMS: The ISO 13485 Internal Audit Process (2026 Guide)

This guide walks medical device manufacturers through the ISO 13485 Clause 8.2.4 internal audit requirement — including audit program design, the six-step audit process, and the five most common findings auditors cite. It also covers what changed under the FDA QMSR and the new ISO 19011:2026 audit guidance.

A clause-by-clause guide to planning, conducting, and closing out ISO 13485 internal audits under the new FDA QMSR

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Internal Audit That Used to Be Private Isn’t Anymore

For years, medical device manufacturers treated the internal audit report as an internal document — useful for finding problems, but shielded from FDA inspectors under the confidentiality provision in the old 21 CFR 820.180(c). That protection is gone.

Since February 2, 2026, the FDA’s Quality Management System Regulation (QMSR) has been in effect, and it incorporates ISO 13485:2016 by reference rather than running a parallel U.S.-specific standard alongside it. FDA’s own Final Rule FAQ is direct about what that means for audits: “The QMSR gives the FDA the authority to inspect management review, quality audits, and supplier audit reports. The exceptions that existed in the QS regulation at § 820.180(c) are not maintained in the QMSR.” That’s not a third-party interpretation — it’s FDA’s own published position.

So this isn’t limited to internal audit reports. Management review minutes and supplier audit reports lost the same protection. A checklist you run through once a year to satisfy Clause 8.2.4 on paper is no longer a low-risk approach — it’s now a document an inspector may read line by line, and so are the meetings where leadership reviewed it.

From the Floor: I’ve built and run internal audit programs at facilities with 500-plus employees, and the finding that costs organizations the most isn’t a missing procedure — it’s a corrective action that gets closed on paper before the root cause is actually fixed. As a certified ISO 9001 Internal Auditor, I’ve sat across the table from auditors who catch that in about ninety seconds. Whether you’re auditing to ISO 9001 or ISO 13485, the internal audit only works if it’s harder on you than the external one will be.

Before your next surveillance audit, most quality teams don’t fail because they misunderstand Clause 8.2.4 — they fail because their audit program looks complete on paper but hasn’t been stress-tested against real objective evidence. Run your QMS through the free ISO 13485 Gap Assessment Checklist before an inspector or a Notified Body does it for you.


In This Guide

  • What ISO 13485 Clause 8.2.4 actually requires
  • How internal audits differ from supplier and certification audits
  • What Clause 6.2 actually requires of your auditors — and what “competent” really means
  • Building a risk-based annual audit program
  • The audit process: planning, evidence, reporting, and CAPA follow-up
  • A real finding-to-CAPA example, start to finish
  • The five most common internal audit findings — and how to avoid them
  • What changes if you’re audited under MDSAP
  • What changed under the FDA QMSR and ISO 19011:2026
  • Whether you need outside help or can run this internally


👉 Start Here (Top Resources)


What Clause 8.2.4 Actually Requires

ISO 13485 requires internal audits under Clause 8.2.4 to verify that QMS processes are implemented and effective, catch nonconformities, and surface QMS deficiencies early enough that they don’t become product-safety or regulatory problems. That sounds close to ISO 9001’s internal audit clause, and it is — but ISO 13485 asks for more.

Clause 8.2.4 requires that internal audits determine conformity to planned arrangements, the requirements of the standard, the organization’s own QMS requirements, and applicable regulatory requirements — and unlike ISO 9001, ISO 13485 explicitly requires the audit program to account for regulatory requirements such as FDA 21 CFR Part 820, EU MDR, or MDSAP alongside the standard itself. Teams that build their audit program purely off the ISO 13485 clause structure, without folding in the regulatory layer, are the ones who get flagged.

Most common finding: auditors treat Clause 8.2.4 as a documentation-review exercise and skip the regulatory cross-reference entirely. If your audit checklist doesn’t ask “does this also satisfy 21 CFR Part 820 or MDR Article 10?” it isn’t finished.

Audits must assess conformity across critical processes — design and development under Clause 7.3, corrective action under Clause 8.5.2, preventive action under Clause 8.5.3, production under Clause 7.5, and document control under Clause 4.2 — using objective evidence like device history records, audit trails, and validation records. Auditors must be trained, qualified, and independent of the area they’re auditing, with that competence documented under Clause 6.2.

If you are already ISO 9001 certified → your internal audit infrastructure transfers directly, but your checklist needs a regulatory column added for every process area, not just a conformity column.


Internal Audits vs. Supplier Audits vs. Certification Audits

Comparison infographic showing internal audits, supplier audits, and certification audits under ISO 13485.
Understanding the differences between internal, supplier, and certification audits improves audit planning and regulatory compliance.

Manufacturers frequently conflate these three, and an auditor will notice immediately if your procedure does too.

Audit TypeGoverning ClausePerformed ByPrimary Purpose
Internal AuditClause 8.2.4Trained internal personnel, independent of the area auditedVerify your own QMS conforms to the standard and your own procedures
Supplier AuditClause 7.4.1Quality or supplier quality personnelVerify external providers meet quality and regulatory requirements
Certification AuditISO/IEC 17021-1Accredited third-party Notified Body or registrarDetermine whether the full QMS meets ISO 13485 for certification

ISO 13485 requires internal audits, just as its sister standard ISO 9001 does, and they exist for two reasons: to confirm the QMS meets the standard’s requirements, and to confirm the organization actually follows its own rules. A strong internal audit program is what makes a certification audit uneventful instead of a fire drill.


Auditor Competence: What Clause 6.2 Actually Requires

This is the section most audit programs get thin on, and it’s where a surprising number of otherwise solid internal audit programs fall apart under scrutiny.

Clause 6.2 requires that anyone doing work affecting product quality — and that includes auditors — be competent based on appropriate education, training, skills, and experience. ISO 13485 doesn’t spell out a fixed list of required knowledge areas the way a checklist would, but three areas consistently show up when a Notified Body reviews auditor files:

  • The standard itself. A working knowledge of ISO 13485:2016 clause structure, not just the SOPs written to satisfy it.
  • Audit methodology. Understanding of the audit cycle — planning, evidence gathering, reporting, follow-up — along with the difference between a minor observation and a major nonconformity. ISO 13485’s own note under Clause 8.2.4 points auditors toward ISO 19011 for this.
  • Applicable regulatory context. Basic familiarity with the regulations that apply to your product and markets — 21 CFR Part 820, EU MDR, MDSAP — not full legal mastery, but enough to recognize when a finding also touches a regulatory requirement.

Competence is not the same thing as certification. ISO 13485 does not require a certified internal auditor credential, and ISO 19011 doesn’t mandate formal training either — the standard’s actual requirement is that the audit process ensure objectivity and impartiality, and that competence be evaluated and documented. In practice, though, “read and understand the internal procedure” is not evidence Notified Bodies accept as sufficient. An auditor who can’t produce a training record, a completed course certificate, or documented on-the-job evaluation showing how their competence was assessed is a finding waiting to happen — even if that person is, in fact, good at the job.

What acceptable training records look like in practice:

  • A certificate of completion from an ISO 13485 internal auditor course (typically covering the standard itself plus ISO 19011 audit methodology) — see BSI vs. ISOQAR if you’re deciding where to send your team for that training
  • Internal on-the-job qualification records — a documented mentored audit or two, signed off by a qualified lead auditor
  • A training matrix that ties each auditor to the specific processes and clauses they’re qualified to audit, refreshed when the QMS or the standard changes

Auditor independence gets checked alongside competence. The most frequent failure here isn’t a skills gap — it’s a quality manager who owns a process auditing that same process, or an auditor rotation that never actually rotates the highest-risk areas like design controls.

If you are not confident your auditor files would hold up to this list → that’s a fifteen-minute file review, not a project, and it’s worth doing before your next Notified Body visit rather than during it.


Building a Risk-Based Audit Program

The audit program must cover every process, department, and site within your QMS scope, with audit frequency determined by the status and importance of each process along with the results of prior audits. High-risk processes — design and development, production, CAPA, and complaint handling — typically need at least annual coverage, while lower-risk support functions can be audited less frequently if previous results were consistently clean.

Most manufacturers get the frequency question backwards. They audit everything on a flat annual calendar instead of weighting toward where the last audit found something. If your CAPA process had a finding last year, auditing it again on the same twelve-month clock as your HR training records is a scheduling decision an inspector will question.

If you are preparing for your first surveillance audit under the new QMSR → build your program around the regulatory cross-reference first, then layer the standard’s clause structure on top of it — not the other way around.


The Internal Audit Process, Step by Step

Infographic illustrating the ISO 13485 internal audit process from planning through CAPA verification for medical device quality management systems.
The six-step ISO 13485 internal audit process helps medical device manufacturers identify nonconformities and verify corrective actions.

Prepare a checklist based on the relevant clauses of ISO 13485, your documented procedures, and applicable regulatory requirements — a good checklist prompts investigation rather than simply confirming what’s already assumed to be true.

1. Scope and schedule. Define which processes, sites, and clauses are in scope for this audit cycle.

2. Documentation review. Analyze the quality manual, procedures, and prior audit reports before setting foot on the floor — this is where checklists get mapped to specific clauses.

3. Opening meeting. Confirm scope, objectives, and methodology with the auditee before evidence-gathering begins — this sets the tone for the entire audit.

4. Evidence gathering. Collect objective evidence through interviews, direct observation, and document/record review — no finding should be written down without evidence behind it.

5. Reporting. Findings get written up, classified by severity, and routed to the process owner and management.

6. CAPA follow-up. Every corrective action needs documented root cause analysis appropriate to the significance of the nonconformity, with effectiveness verified before the CAPA is closed.

Most teams execute steps 1 through 5 competently. Step 6 is where programs fall apart — a CAPA gets marked closed the day the immediate fix is implemented, with no verification that the fix actually held.

Trigger: If your last three internal audits found the same category of nonconformity in different words each time, that’s not three separate findings — that’s one root cause your CAPA process never actually reached.

Before your next audit cycle, check your CAPA closure process against what auditors actually verify — most teams don’t realize how thin their effectiveness checks are until someone else reviews them.


A Real Finding, Start to Finish

Steps on a page are easy to nod along with. Here’s what a properly closed finding actually looks like end to end, using one of the most common design-control gaps auditors find.

StageWhat It Looked Like
FindingDuring a design and development audit, three of twelve design verification records sampled were missing the reviewer’s signature. Work was completed and dated, but sign-off wasn’t captured.
Objective EvidenceDesign History File records DHF-114, DHF-119, and DHF-122, cross-referenced against the design review meeting minutes showing the reviews occurred.
Nonconformity Statement“Design verification records DHF-114, DHF-119, and DHF-122 lack the required reviewer signature per QMS-SOP-014, Section 6.2. Design and development control per ISO 13485:2016 Clause 7.3.6 requires verification results, including necessary actions, to be recorded.”
Root CauseInvestigation traced it to a recent SOP revision that moved the sign-off step later in the workflow. Staff hadn’t been retrained on the updated sequence — the procedure changed, but the training that should have accompanied it under Clause 6.2 didn’t happen.
CorrectionThe three records were completed retroactively with the reviewer’s signature and a note explaining the delay, reviewed and accepted by the quality manager.
Corrective Action (CAPA)Retrain design team on the revised sign-off sequence; add a mandatory signature field to the design review template so records can’t be filed incomplete.
Effectiveness CheckSample the next ten design verification records over the following quarter. Zero missing signatures required to close the CAPA as effective.

Notice what makes this closeable rather than cosmetic: the root cause isn’t “people forgot” — it’s a training gap tied to a specific procedure change, and the corrective action addresses the system, not just the three records. That’s the difference between a finding that stays closed and one that reappears with different reference numbers next year.


The Five Most Common Findings

Infographic highlighting the five most common ISO 13485 internal audit findings in medical device quality management systems.
The most common ISO 13485 internal audit findings often involve documentation, CAPA effectiveness, auditor competence, and risk-based planning.

Incomplete audit records — missing reports, plans, or linked CAPAs — is one of the most frequently cited internal audit issues. A close second is failing to apply a risk-based approach to audit planning, or simply not maintaining the internal audit schedule at all. Beyond that, auditors regularly find no timely follow-up on actions from internal audits, no records showing auditor competence against the applicable regulations, and auditors who weren’t actually impartial — reviewing work they had a hand in.

Design and development controls remain the single most frequently cited nonconformity area globally — incomplete design inputs, missing verification or validation records, undocumented design changes, or no formal design transfer procedure. See Validation & Verification Requirements for how this plays out in practice.

⚠️ If your auditor rotation lets the same person audit design controls year after year without ever being audited themselves on that same process, that’s an impartiality gap that a Notified Body will flag before you do.

If you are not confident your last internal audit would hold up under this list → that’s exactly what a structured gap assessment is for, not a guess.

Check your program against these five findings before your next audit — most gaps take under 45 minutes to identify →


MDSAP: What Changes for Multi-Market Audits

If your devices sell into more than one of the five MDSAP markets — the U.S., Canada, Australia, Brazil, or Japan — your internal audit program needs to account for a different audit model, not just an extra regulatory reference.

The Medical Device Single Audit Program lets one audit by an accredited Auditing Organization satisfy the requirements of all five participating regulators at once, in place of separate national audits. It’s built on ISO 13485:2016, but it isn’t a straight overlay — MDSAP uses a process-based audit model with a defined sequence, rather than working straight down the ISO clause list, and it maps every audit task to both the relevant ISO 13485 clause and each country’s specific regulatory requirement.

The grading system is the biggest practical difference. Where an ISO 13485 certification audit typically classifies findings as minor or major, MDSAP uses a points-based Grade 1–5 scale: nonconformities affecting clauses with indirect QMS impact start lower, direct-impact clauses start higher, and points are added for repeat findings or for a nonconforming product that was actually released. Grade 4 and 5 findings must be resolved before a certificate is issued or maintained — there’s no ambiguity about severity once the math is run.

What this means for your internal audit program: if you’re pursuing or maintaining MDSAP, your internal audits should follow the MDSAP process sequence — not just walk through ISO 13485 clauses in order — so that gaps surface in the same structure an Auditing Organization will use. The recurring findings across published MDSAP audits track closely with the same weak points internal audits should already be hunting for: open CAPAs left unclosed past a reasonable window, supplier and purchasing controls that don’t demonstrate follow-through, and root cause analysis that’s thin enough to not survive a second look.

One benefit worth knowing about: MDSAP audit reports can substitute for the FDA’s routine biennial device inspections. A well-run MDSAP program isn’t just multi-market efficiency — it can reduce how often FDA shows up separately.


What Changed: QMSR and ISO 19011:2026

Two regulatory shifts affect how internal audits get run in 2026, and both are recent enough that older internal procedures may not reflect them.

Since February 2, 2026, the FDA’s QMSR has incorporated ISO 13485:2016 by reference, replacing the former Quality System Regulation, and FDA inspections now run under Compliance Program 7382.850 rather than the old QSR framework. As covered above, the practical effect for internal audits is direct: the confidentiality safe harbor that used to apply to internal audit reports, management review records, and supplier audit reports under the old 21 CFR 820.180(c) has been removed, and FDA’s own FAQ confirms it in plain language.

Separately, ISO published the fourth edition of ISO 19011 — Guidelines for auditing management systems — on May 27, 2026, replacing the 2018 edition that had guided audit programs for nearly eight years. ISO 13485 doesn’t mandate ISO 19011 compliance directly — Clause 8.2.4 references audit principles in its own language — but Notified Bodies and experienced auditors widely treat ISO 19011 as the authoritative reference for structuring an audit program, so if your internal audit SOPs still cite the 2018 edition, expect your Notified Body to ask why.

Neither change requires rebuilding your program from scratch. Both are reasons to review your internal audit SOP this year rather than next.


Quick Audit-Readiness Checklist

✅ Audit program covers every process, site, and department in your QMS scope ✅ Audit frequency is risk-weighted, not a flat annual calendar
✅ Every checklist item maps to a specific ISO 13485 clause and the applicable regulatory requirement
✅ Auditors are independent of the area they’re reviewing, with Clause 6.2 competence records on file — not just “read and understand” sign-offs
✅ Findings are backed by objective evidence — interviews, observation, or documented records
✅ CAPA effectiveness is verified before closure, not assumed
✅ If pursuing MDSAP, internal audits follow the MDSAP process sequence, not just the ISO clause order
✅ Internal audit SOP references ISO 19011:2026, not the 2018 edition
✅ Design and development records are current — this is the single most-cited finding category


FAQ

How often does ISO 13485 require internal audits?

The standard doesn’t specify a fixed interval — it requires audits “at planned intervals” based on process risk and prior audit history. Most manufacturers audit high-risk processes like design controls and CAPA annually at minimum, with lower-risk support functions audited less frequently if history is clean.

Can the same person who performs a process also audit it?

No. Clause 8.2.4 requires auditors to be independent of the area being audited. A quality manager who owns the CAPA process, for example, shouldn’t be the one auditing CAPA compliance.

Do internal auditors need a formal certification?

No. ISO 13485 requires documented competence — education, training, skills, and experience — but doesn’t mandate a specific certification. In practice, most Notified Bodies expect more than an internal read-and-understand sign-off, so a course certificate or documented mentored-audit record is the safer standard to work toward.

Does the FDA QMSR require a separate internal audit program from ISO 13485?

No. Since the QMSR incorporates ISO 13485:2016 by reference, there isn’t a separate U.S.-specific internal audit requirement layered on top — your Clause 8.2.4 program is the audit program the FDA now expects, with the regulatory cross-reference built in.

Are internal audit reports confidential from FDA inspectors?

Not anymore. FDA’s own QMSR Final Rule FAQ confirms the confidentiality exceptions under the old 21 CFR 820.180(c) — covering internal audits, management review, and supplier audits — are not maintained under the QMSR.

What’s the difference between an internal audit and a supplier audit under ISO 13485?

Internal audits (Clause 8.2.4) evaluate your own QMS. Supplier audits (Clause 7.4.1) evaluate external providers’ ability to meet your quality and regulatory requirements. Both are required, but they’re separate programs with separate scopes.

Does MDSAP replace our ISO 13485 internal audit requirement?

No, but it changes the structure. MDSAP is built on ISO 13485 and layers in country-specific regulatory requirements from up to five markets, using a process-based sequence and a points-based Grade 1–5 nonconformity system rather than the minor/major classification used in standard certification audits.

What’s the most common reason internal audit programs fail a certification audit?

Incomplete records — missing audit reports, plans, or linked CAPAs — combined with no evidence of a risk-based approach to scheduling. Both are findings a Notified Body catches quickly because they’re procedural gaps, not technical ones.

Should we hire a consultant to run our internal audits, or can we do it ourselves?

Either can work if the auditor is properly trained and genuinely independent of the process. Many manufacturers use in-house auditors for most cycles and bring in an outside auditor periodically to test whether their internal program is actually rigorous or just familiar with its own blind spots.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching your audit obligations? Start with ISO 13485 Documentation Requirements to understand what your QMS needs on paper before you audit it.

🔹 Ready to build or strengthen your audit program? 9001Simplified’s documentation templates can shortcut the SOP-writing process without a consultant retainer.

🔹 Need the standard itself to build your checklist against? Get ISO 13485:2016 from ANSI Webstore — code CC2026 takes 5% off through the end of 2026.


An internal audit program that only exists to satisfy Clause 8.2.4 on paper was already a risk before the QMSR removed the confidentiality safe harbor. Now it’s a document an inspector can read directly. The Standards Navigator will keep tracking what QMSR enforcement and ISO 19011:2026 mean for how medical device manufacturers actually run their audit programs — not just what the clause says.


Subscribe for Medical Device Compliance Updates

Most manufacturers don’t lose a certification over one bad audit finding — they lose it over a pattern of findings their own internal audit program should have caught first. Organizations that treat Clause 8.2.4 as a paperwork requirement get surprised at surveillance. Organizations that treat it as their first line of defense rarely do.

The Standards Navigator tracks how ISO 13485, the FDA QMSR, and the standards that govern medical device audits actually work in practice — not just what the clause text says.

👉 Get updates on ISO 13485 audit requirements and QMSR enforcement changes 👉 Be first to access new medical device compliance checklists and gap assessment tools

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

Biocompatibility Standards Explained: ISO 10993 Requirements for Medical Devices in 2026

This guide breaks down the ISO 10993 series and the sixth edition of ISO 10993-1, published in November 2025. It covers FDA’s partial recognition of the new edition in May 2026, the two clauses the agency excluded, and whether manufacturers need to revisit biological evaluation plans for devices already cleared.

What ISO 10993-1:2025 and FDA’s Partial Recognition Mean for Your Biological Evaluation Plan

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Standard Behind Your Biocompatibility Testing Just Changed — Is Your Documentation Still Defensible?

Biocompatibility standards for medical devices just changed in a way regulatory affairs teams can’t ignore. If your device has any contact with the human body, your biological evaluation plan rests on one standard: ISO 10993-1. For years, that meant the 2018 edition. That’s no longer the whole story.

ISO published a sixth edition, ISO 10993-1:2025, in November 2025. The FDA followed with recognition of that edition on May 25, 2026 — but only partial recognition. Two specific clauses were excluded outright. If your technical documentation, supplier certificates, or biological evaluation reports still cite the 2018 edition without addressing what changed, that’s a gap a reviewer or auditor will find.

This isn’t a cosmetic update. The reorganization ties biocompatibility more tightly to ISO 14971 risk management, and the FDA’s exclusions tell you exactly where the agency still wants you to lean on its own biocompatibility guidance instead of the standard’s language. This guide covers the current medical device biocompatibility testing requirements under both editions, what changed, and what FDA’s recognition decision actually means for your Biological Evaluation Plan (BEP).

I’ve been on the reviewing side of this problem before, just from the documentation control angle. As an ISO 9001 internal auditor, I’ve flagged design history files where a supplier’s certificate of conformance still referenced an outdated edition of a cited standard — the technical content hadn’t changed, but the paper trail no longer matched what the standard actually required. That’s the kind of finding that stalls a submission or an audit closeout, and it’s entirely avoidable if someone catches the edition mismatch before a reviewer does.

Before you touch a single test report, run a gap check on where your current documentation stands against the 2025 edition.

👉 Most teams don’t fail because their biocompatibility data is wrong — they fail because their documentation still points to the wrong edition of the standard. Run the ISO 13485 Gap Assessment Checklist before your next submission or audit →


In This Guide

  • What ISO 10993-1 covers and why it sits at the center of biocompatibility evaluation
  • The full ISO 10993 series, part by part
  • What actually changed in the 2025 edition
  • FDA’s partial recognition — and exactly what it excluded
  • Whether you need to retest devices already cleared under the 2018 edition
  • How biocompatibility documentation fits into your ISO 13485 QMS
  • A quick audit checklist for your next document review


👉 Start Here (Top Resources)


What Is Biocompatibility, and Why ISO 10993 Matters

Biocompatibility is the assessment of whether a device’s materials — and the way those materials contact the body — create an unacceptable biological risk. ISO 10993-1 is the standard that governs how you plan, justify, and document that biocompatibility risk assessment. It doesn’t hand you a checklist of tests to run blindly; it requires you to build a risk-based Biological Evaluation Plan (BEP) that considers the device’s materials, manufacturing processes, intended anatomical contact, and exposure duration.

That risk-based framing matters because it’s the same language FDA reviewers and notified bodies expect to see. A BEP that reads like a 2009-era test list, rather than a risk justification tied to ISO 14971, is a common source of review questions and additional information requests.

If you’re still building out your risk management process, our guide on risk management in medical devices under ISO 14971 covers the foundation ISO 10993-1 now leans on even more heavily than before.


The ISO 10993 Series at a Glance

Infographic showing the ISO 10993 series for biological evaluation of medical devices, including ISO 10993-1, -5, -6, -7, -10, -12, -17, and -18.
The ISO 10993 series consists of multiple standards that together form a complete biological evaluation framework for medical devices.

ISO 10993-1 doesn’t stand alone — it’s the framework document for a series that covers specific test methods and evaluation categories.

PartCoversStatus Note
ISO 10993-1Overall evaluation and testing within a risk management processSixth edition (2025) now partially recognized by FDA
ISO 10993-5In vitro cytotoxicity2009 edition, still current
ISO 10993-6Local effects after implantationUpdated 2026 edition
ISO 10993-7Ethylene oxide sterilization residualsUpdated 2026 edition
ISO 10993-10Irritation and skin sensitization2021 edition
ISO 10993-12Sample preparation and reference materials2021 edition, amended 2025
ISO 10993-17Toxicological risk assessment of device constituents2023 edition, amended 2025
ISO 10993-18Chemical characterization of materials2020 edition, amended 2022

Most common finding: Manufacturers cite ISO 10993-5 or -10 correctly but leave the ISO 10993-1 reference in their design history file pointing to the 2018 edition without any documented rationale for why. If your BEP hasn’t been revisited since the 2025 edition published, that’s the first thing to check.

If your device is sterilized and you haven’t looked at how the 2026 edition of ISO 10993-7 interacts with your sterilization validation, our sterilization standards overview walks through ISO 11135, 11137, 17665, and 11607 alongside it.


What Changed in ISO 10993-1:2025

The sixth edition isn’t a light refresh. ISO’s technical committee reorganized the standard and changed its title to explicitly align with the ISO 14971 risk management framework. The practical changes:

  • More detailed guidance on calculating exposure duration — including how to treat foreseeable misuse, such as a device used longer than its labeled duration.
  • Expanded guidance on device characterization and biological hazard identification, intended to reduce reliance on generic test batteries.
  • Terminology aligned with ISO 14971, so if your team already knows that standard, the 2025 edition should read more consistently — though NAMSA and other industry commentators note there isn’t yet a technical report equivalent to ISO/TR 24971 to guide interpretation of the new edition.

Here’s how the two editions compare on the points that matter most for your Biological Evaluation Plan:

Topic2018 Edition2025 Edition
Risk Management IntegrationReferenced ISO 14971More explicitly aligned throughout
Exposure DurationLimited guidanceExpanded methodology for calculating duration, including foreseeable misuse
Biological Hazard IdentificationLess detailedExpanded guidance on device characterization and hazard identification
Risk EstimationDifferent treatmentNew Clause 6.9 (excluded by FDA)

If you are preparing a Biological Evaluation Plan for a new device → start by confirming which edition your FDA reviewer or notified body expects to see referenced, since adoption isn’t uniform across regions. The EU has generally moved faster toward treating the 2025 edition as state of the art. Manufacturers should verify current adoption expectations directly with their notified body and applicable competent authorities, since implementation timing varies and is subject to change.

One shift worth flagging for regulatory teams building out a modern BEP: chemical characterization under ISO 10993-18 is playing a larger role than it used to. Rather than defaulting to a blanket biological test matrix for every device, more manufacturers are leaning on thorough chemical characterization data — extractables and leachables profiles, material composition analysis — to justify a narrower, risk-based testing strategy. ISO 10993-1:2025’s expanded hazard identification guidance reinforces this shift. A well-documented ISO 10993-18 characterization can reduce redundant biological testing, but only if the chemistry-driven rationale is documented clearly enough to withstand a reviewer’s scrutiny.

Comparison graphic showing the major differences between ISO 10993-1:2018 and ISO 10993-1:2025 for biological evaluation of medical devices.
The 2025 edition places greater emphasis on risk management integration, biological hazard identification, and exposure assessment.

ISO 10993 FDA Recognition: What’s Excluded and Why

🔑 Key FDA Takeaway FDA recognizes ISO 10993-1:2025, but excludes:

  • The “consumer products” language in Clause 6.5.11.3
  • Clause 6.9 on biological risk estimation

Manufacturers should document alternative justification using FDA guidance and ISO 14971.

On May 25, 2026, FDA updated its Recognized Consensus Standards database (Recognition No. 2-313) to include ISO 10993-1:2025 — but not in full. Two specific exclusions matter for your submissions:

  1. The phrase “consumer products or” in Clause 6.5.11.3. This clause addresses low-risk, intact-skin-contacting devices. The standard allows manufacturers to point to a material’s history of safe use in consumer products as justification for reduced testing. FDA excluded this because it conflicts with Attachment G of its 2023 biocompatibility guidance, which defines specific materials with an accepted history of use — a consumer product history alone doesn’t automatically satisfy FDA’s expectations.
  2. Clause 6.9 on biological risk estimation. FDA determined this clause conflicts with the risk estimation approach already established in the FDA-recognized ISO 14971:2019. Sponsors can’t rely on Clause 6.9 to claim conformity in a submission.

If you are under customer or notified body pressure to update your BEP quickly → prioritize reviewing these two clauses first. They’re the specific areas where citing the 2025 edition alone won’t satisfy FDA, and you’ll need to document your justification through existing FDA guidance instead.

Partial recognition means you cannot submit a clean Declaration of Conformity to the full 2025 edition. Your submission documentation needs to call out the partial recognition explicitly and show how you’re addressing the excluded clauses — silence on this point is what generates additional information requests.

Workflow illustrating FDA partial recognition of ISO 10993-1:2025 and the documentation required for excluded clauses during medical device submissions.
FDA recognizes ISO 10993-1:2025 with specific exclusions, requiring manufacturers to document alternative regulatory justifications.

Do You Need to Retest Already-Cleared Devices?

This is the objection I hear most from teams looking at this update: does a new edition mean I have to redo my biocompatibility testing on devices that already have clearance?

No — not automatically. FDA’s recognition of a newer edition doesn’t retroactively invalidate data or clearances based on the 2018 edition. If you already hold clearance under the 2018 edition → you don’t need to retest existing devices. What you do need is a documented rationale, at your next design change or periodic review, for why your BEP still reflects sound risk management even though a newer edition exists. That’s a documentation and justification exercise, not a lab exercise.

Where this becomes a live issue is new submissions and significant design changes going forward — those are where reviewers will expect to see the current edition addressed.


Where Biocompatibility Fits Into Your ISO 13485 QMS

Biocompatibility data doesn’t live in isolation — it’s part of your design and development file under ISO 13485, and it feeds directly into your risk management file under ISO 14971. If your ISO 13485 documentation structure doesn’t have a clear place for biological evaluation plans, reports, and the rationale behind edition changes, that’s a gap worth closing before your next internal audit — not after a nonconformance is written.

This also connects to supplier controls. If a component supplier’s certificate of conformance references ISO 10993-1 by edition, your incoming inspection and supplier qualification process needs a mechanism to catch when that reference goes stale — the same principle covered in our guide on common mistakes in ISO 13485 QMS implementation.

And if you’re managing devices sold in both the US and EU, the edition-adoption gap between FDA and the EU regulatory framework is one more reason to keep your MDR vs ISO 13485 documentation aligned rather than treating them as separate tracks.

👉 If your biological evaluation documentation hasn’t been reviewed since the 2025 edition published, don’t wait for a finding to tell you. Check where your QMS documentation actually stands →


Quick Audit Checklist

✅ Confirm which edition of ISO 10993-1 your current BEP references, and whether that matches what your reviewer or notified body expects
✅ Check whether your device’s biocompatibility justification relies on Clause 6.5.11.3 (consumer product history) or Clause 6.9 (risk estimation) — both need alternative justification for FDA submissions
✅ Verify supplier certificates of conformance cite current standard editions, not stale references
✅ Confirm your risk management file cross-references your BEP consistently ✅ If your device is sterilized, check the 2026 editions of ISO 10993-6 and -7 against your current validation data ⚠️ Don’t assume “FDA recognized” means “fully accepted” — verify the Supplementary Information Sheet for any standard before citing it as a full Declaration of Conformity


FAQ

What is biocompatibility testing for medical devices?

Biocompatibility testing evaluates whether the materials in a medical device, and the way those materials contact the body, could cause an unacceptable biological response. It covers areas like cytotoxicity, sensitization, irritation, and systemic toxicity, selected based on the device’s contact type and duration.

What is ISO 10993-1, and do I need to comply with it?

ISO 10993-1 is the framework standard that governs how you plan and justify a biological evaluation within a risk management process. If your device contacts the body directly or indirectly, FDA and most global regulators expect your biocompatibility strategy to follow its structure, even where full conformity isn’t feasible.

What changed between ISO 10993-1:2018 and ISO 10993-1:2025?

The 2025 edition reorganized the standard to align more closely with ISO 14971, added detailed guidance on calculating exposure duration and identifying biological hazards, and updated terminology throughout.

Has the FDA recognized ISO 10993-1:2025?

Yes, as of May 25, 2026, but only partially. FDA excluded the “consumer products” language in Clause 6.5.11.3 and all of Clause 6.9 on biological risk estimation, both of which conflict with existing FDA guidance and the FDA-recognized ISO 14971:2019.

Do I need to retest devices already cleared under the 2018 edition?

No. Existing clearances aren’t invalidated by a newer edition. You do need a documented rationale for your current approach at your next design change or periodic review.

Which parts of the ISO 10993 series apply to my device?

That depends on your device’s contact type (surface, external communicating, or implant) and contact duration (limited, prolonged, or permanent). ISO 10993-1 provides the matrix for selecting relevant parts of the series based on those two factors. We’ll be covering that contact-duration matrix in detail in an upcoming guide.

Is ISO 10993 the same as ISO 13485?

No. ISO 13485 governs your overall quality management system for medical devices. ISO 10993 is a series specifically about biological evaluation, and its outputs — your BEP and test reports — become part of the design and development records your ISO 13485 QMS requires you to maintain.

Where do I purchase ISO 10993 standards?

Individual parts and bundled packages are available through the ANSI Webstore, which also serves international buyers and offers documents in multiple languages. The ISO.org catalog describes each part but is not the recommended purchase channel.


📥 Free Resources

  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.
  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements, including where biocompatibility documentation fits.
  • AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification.

Not Sure What to Do Next?

🔹 Still researching how the 2025 edition affects your device category? Start with our breakdown of risk management under ISO 14971 — biocompatibility evaluation doesn’t stand apart from it anymore.

🔹 Ready to check where your documentation actually stands? Run the ISO 13485 Gap Assessment Checklist before your next audit or submission, not after.

🔹 Need to purchase the current standard? ISO 10993-1:2025 — ANSI Webstore, or get the full biological evaluation package bundled at roughly 45% off individual pricing if you’re assembling multiple parts of the series. Use code CC2026 for an additional 5% off through December 31, 2026.

The Standards Navigator will keep tracking how FDA recognition evolves on this standard as updates are published.


Documentation Gaps Don’t Show Up Until Someone’s Looking For Them

Teams that treat biocompatibility as a one-time lab exercise are the ones caught off guard when a standard’s edition changes underneath them. Teams that treat it as a living part of their design and risk management file catch the mismatch at their next internal review, not during an FDA question round — and it’s usually a citation that didn’t keep up, not the underlying science, that stalls a submission.

The Standards Navigator tracks these regulatory shifts as they happen — not months later when the transition deadline is already close. If ISO 10993-1:2025 affects your device, this is a good window to revisit your documentation rationale while the timeline is still in your control.

👉 Get updates on medical device compliance and biocompatibility standard changes
👉 Be first to access new gap assessment checklists and documentation tools for ISO 13485 and ISO 14971

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

Supplier Controls for Medical Devices: ISO 13485 Requirements Explained (2026)

ISO 13485 supplier controls are among the most audited requirements in medical device QMS certifications. This guide covers Section 7.4 — evaluation criteria, purchasing document requirements, incoming inspection, re-evaluation, and the common audit findings that derail supplier programs before Stage 2.

How to build a compliant supplier qualification and monitoring program that holds up under notified body scrutiny

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Your Supplier Is Now Your Risk — and Your Auditor Knows It

Supplier nonconformances are among the top findings in ISO 13485 audits. Not because manufacturers don’t care about their supply chain — but because most supplier controls for medical devices are built for appearance rather than function. They look complete on paper. They fall apart under scrutiny.

When a notified body or FDA investigator walks into your facility, they aren’t just looking at what happens on your production floor. They’re asking who made your components, how you selected them, what evidence you have that they’re capable, and what happens when they fail to deliver compliant product.

If your answers are “we have an approved vendor list” and “we send them a purchase order with our spec,” you’re in trouble.

I’ve audited supplier programs for a global manufacturer of many different types of valves and the gaps I found most often had nothing to do with the suppliers themselves. They had to do with how the manufacturer defined their requirements, communicated them, and verified compliance after the fact. A supplier can’t meet a requirement you never clearly documented. That’s your problem, not theirs, and it shows up in your audit findings.

Before you work through your supplier qualification process, run your current program through the ISO 13485 gap assessment checklist first.

👉 Download the ISO 13485 Gap Assessment Checklist → — free checklist for medical device manufacturers assessing their QMS against ISO 13485:2016 requirements, including supplier control clauses.


In This Guide

  • What ISO 13485 Section 7.4 actually requires for supplier controls
  • How to build a compliant supplier qualification and evaluation process
  • What your purchasing documents must include under 7.4.2
  • Verification of purchased product — incoming inspection and beyond
  • Common audit findings in supplier control programs
  • How supplier controls tie into your risk management process under ISO 14971
  • A quick audit checklist for your supplier control program


👉 Start Here: Top Resources for ISO 13485 Supplier Controls


What ISO 13485 Section 7.4 Requires

ISO 13485:2016 addresses purchasing and supplier controls in Section 7.4, which breaks into three requirements:

  • 7.4.1 — Purchasing process: You must establish criteria for evaluating, selecting, and monitoring suppliers. The criteria must be based on the supplier’s ability to meet your requirements. Records of evaluation results must be maintained.
  • 7.4.2 — Purchasing information: Purchasing documents must clearly describe the product or service being ordered, including applicable specifications, procedures, or quality system requirements you’re flowing down.
  • 7.4.3 — Verification of purchased product: You must establish and implement the inspection or other activities necessary to verify that purchased product meets requirements.

This is not a checkbox exercise. The standard requires documented procedures, records, and evidence that your program actually functions — not just that it exists.

One important distinction from ISO 9001: ISO 13485 is more prescriptive about what supplier evaluation must cover and what records must be maintained. If you’re coming from an ISO 9001 background, expect your notified body to go deeper on supplier documentation than you may be used to.

For a full comparison of how supplier control requirements differ between the two standards, see: ISO 9001 vs ISO 13485


Supplier Qualification: How to Evaluate and Approve Suppliers

Supplier controls for medical devices infographic showing a risk-based supplier evaluation framework, Approved Supplier List process, regulatory review, technical capability assessment, and periodic supplier re-evaluation for medical device manufacturers.
ISO 13485 supplier approval requires documented evaluation, risk classification, qualification records, and ongoing supplier monitoring before suppliers remain on the Approved Supplier List.

Your Approved Supplier List (ASL) is the foundation of your supplier control program. But the list itself isn’t the requirement — the process that populates and maintains it is.

Supplier Evaluation Criteria

Your procedure must define how you evaluate a new supplier before adding them to your ASL. At minimum, this should include:

Evaluation CategoryWhat to AssessEvidence Required
Quality systemISO 13485, ISO 9001, or equivalent QMSCertificate, audit report, questionnaire
Regulatory complianceFDA registration, CE marking, applicable regulationsRegulatory filings, declarations
Technical capabilityAbility to meet your specification requirementsCapability studies, sample approval
Delivery and financial stabilityRisk to supply continuityReferences, business history
Product/service risk classificationImpact on device safety and performanceRisk assessment (see Section 7 below)

Not every supplier gets the same level of scrutiny. A supplier providing sterile packaging components gets evaluated differently than a supplier providing cardboard shipping boxes. Your procedure must define those tiers — and the evaluation rigor that goes with each.

Most common finding: Approved Supplier Lists that include suppliers with no documented evaluation on file. The vendor was added years ago, the person who approved them is gone, and there’s no record of what they were evaluated on.


Purchasing Controls: What Your POs and Specs Must Cover

Section 7.4.2 is where many organizations have significant gaps. Purchase orders and specifications must be clear enough that a supplier knows exactly what’s expected — and clear enough that you can verify compliance on receipt.

What Purchasing Documents Must Include

At minimum, your purchasing documents should specify:

  • Product description, part number, and revision level
  • Applicable specifications (dimensional, material, performance)
  • Quality requirements you’re flowing down (e.g., certificate of conformance, first article inspection, CAPA notification requirements)
  • Any regulatory or standards requirements the supplier must meet
  • Change notification requirements — the supplier must tell you before they change anything that affects your product
ISO 13485 purchasing controls infographic comparing a weak purchase order to an audit-ready controlled purchasing package with specifications, quality requirements, and verification controls.
ISO 13485 purchasing documents must define specifications, quality flow-down requirements, and verification expectations to support compliant supplier controls.

That last point is critical and frequently missed. Supplier-initiated changes — new sub-tier suppliers, process changes, facility moves, material substitutions — must not reach your production floor without your review and approval. If your purchase order doesn’t require the supplier to notify you of changes, you have no contractual basis to enforce it.

If your purchasing documents and quality flow-downs aren’t documented in a controlled procedure, your QMS documentation requirements aren’t complete. See: ISO 13485 Documentation Requirements


Most teams don’t discover their purchasing document gaps until a notified body auditor requests three supplier files during a Stage 2 audit. Run the gap check now, while you still have time to fix it.

👉 Download the ISO 13485 Gap Assessment Checklist →


Verification of Purchased Product

Section 7.4.3 requires you to verify that purchased product meets requirements before it enters your production process. What that looks like depends on the product, the supplier, and the risk level involved.

Incoming Inspection Options

Verification MethodWhen to UseWhat to Document
100% incoming inspectionHigh-risk components, new suppliers, history of nonconformancesInspection records, acceptance/rejection criteria
Statistical samplingEstablished suppliers, lower-risk componentsSampling plan (AQL level), records of results
Certificate of conformance reviewEstablished, well-performing suppliersCOC receipt record, periodic verification
Supplier data reviewHigh-confidence qualified suppliers onlyData review records, approval basis
Skip-lot inspectionExtended high-performance track recordDefined criteria for skip-lot qualification

Your incoming inspection procedure must define the method for each supplier or product category — and your records must show you actually performed it.

What Auditors Look For

Auditors will ask to see incoming inspection records for specific lots. They will cross-reference the purchase order revision, the inspection criteria in your procedure, and the actual record. Discrepancies between any of these three are nonconformances.

They will also ask: what happens when incoming inspection finds a nonconformance? Your CAPA process must connect directly to your incoming inspection findings.

For how CAPA integrates with supplier nonconformances, see: CAPA Requirements in ISO 13485


Ongoing Supplier Monitoring and Re-Evaluation

Qualifying a supplier once is not enough. ISO 13485 requires ongoing monitoring and periodic re-evaluation of your suppliers.

What Ongoing Monitoring Looks Like

Your procedure should define what data you collect and at what frequency to assess supplier performance. Common metrics include:

  • Incoming acceptance rate — percentage of lots accepted without rejection
  • On-time delivery rate — consistently late suppliers are a supply risk
  • Nonconformance rate — corrective action requests issued per time period
  • Customer complaints attributable to supplied components
  • CAPA closure rate — how quickly suppliers respond to and close corrective actions you’ve issued

Re-Evaluation Requirements

Most organizations set an annual re-evaluation cycle. At re-evaluation, you’re reviewing the supplier’s performance data, confirming their certification is still valid, and deciding whether they remain on the ASL — or whether their approval level changes.

Re-Evaluation OutcomeAction
Strong performanceMaintain or upgrade approval level
Acceptable but issues notedIssue corrective action, increase monitoring frequency
Poor performanceProbationary status, increase incoming inspection
Failed or uncertifiedRemove from ASL, qualify replacement

If a supplier is removed from your ASL, your records must reflect that decision and any transition actions taken. An audit trail gap here — particularly if a product from a de-listed supplier made it into production — creates significant liability.

BSI Group offers ISO 13485 training that covers supplier management as part of QMS implementation — useful for quality managers building or rebuilding a supplier program from scratch.


How Supplier Controls Connect to ISO 14971 Risk Management

Risk-based supplier controls infographic showing ISO 13485 and ISO 14971 supplier tiering, supplier monitoring KPIs, risk classification, and supplier re-evaluation workflow for medical device manufacturers.
Risk-based supplier controls connect ISO 14971 risk analysis with ISO 13485 qualification, monitoring, verification, and supplier re-evaluation activities.

Your supplier tier system shouldn’t be arbitrary. It should be driven by a risk assessment.

ISO 14971 — the risk management standard for medical devices — requires you to identify hazards and estimate risks throughout the product life cycle. The components and materials your suppliers provide are part of that risk picture.

Risk-Based Supplier Tiering

Risk TierComponent ExamplesSupplier Control Level
CriticalSterile packaging, implantable components, direct patient-contact materialsFull qualification, audits, COC per lot
MajorElectronic subassemblies, precision machined partsQualification + periodic re-evaluation, sampling
MinorNon-product-contact materials, standard hardwareBasic approval, periodic review
AdministrativeCalibration services, software toolsContract review, credentials verification

Documenting the risk basis for each tier — and linking it to your ISO 14971 risk file — gives you a defensible rationale for your supplier control decisions. Auditors respond well to risk-based reasoning. They respond poorly to “that’s how we’ve always done it.”

For a full breakdown of how ISO 14971 and ISO 13485 work together: ISO 14971 vs ISO 13485


Common Audit Findings in Supplier Control Programs

These are the findings that show up repeatedly in ISO 13485 audits — and the ones your program should be specifically designed to prevent.

Most common finding #1: Suppliers on the ASL with no qualification records. Vendors added informally, without documented evaluation. No basis for their approval on file.

Most common finding #2: Purchase orders that don’t flow down quality requirements. The PO has a part number and a price. It does not reference a specification revision level, a certificate of conformance requirement, or any CAPA notification obligation.

Most common finding #3: Incoming inspection records that don’t match procedures. The procedure says AQL sampling on a specific plan. The records show visual inspection only. Or no records at all.

Most common finding #4: No re-evaluation records for suppliers on the ASL for more than 12 months. Annual re-evaluation is defined in the procedure. No evidence it was performed.

Most common finding #5: Supplier CAPAs not tracked or closed. A corrective action was issued to a supplier. There’s no record of their response or whether the root cause was resolved.

If any of those five sound familiar, your supplier control program has audit risk right now.


Quick Audit Checklist: Supplier Controls

Run through this before your next internal audit or notified body review:

✅ Documented supplier evaluation criteria based on product risk level

✅ Approved Supplier List with documented evaluation records for every supplier

✅ Procedure defines supplier tiers and the control requirements for each tier

✅ Purchasing documents (POs, specs) include product description, revision level, and quality flow-down requirements

✅ Change notification requirement communicated to and acknowledged by suppliers

✅ Incoming inspection procedure defines method by product/supplier category

✅ Incoming inspection records maintained and linked to purchase orders

✅ Nonconforming purchased product procedure exists and connects to CAPA

✅ Supplier performance data collected and reviewed at defined frequency

✅ Annual re-evaluation records on file for all active suppliers

✅ De-listed supplier records maintained with transition documentation

✅ Risk basis documented for supplier tier assignments (links to ISO 14971 risk file)


FAQ

What does ISO 13485 Section 7.4 require for supplier controls?

Section 7.4 of ISO 13485:2016 requires three elements: a documented process for evaluating, selecting, and monitoring suppliers (7.4.1); purchasing documents that clearly specify product requirements and quality flow-down obligations (7.4.2); and a defined process for verifying that purchased product meets requirements before use (7.4.3). All three require documented procedures and maintained records — not just policy statements.

How do I build an Approved Supplier List that satisfies ISO 13485 auditors?

Your Approved Supplier List must be backed by documented evaluation records for every supplier on it. The evaluation criteria should be defined in your procedure and applied consistently. Auditors will select suppliers from the list at random and ask to see their qualification records. If a supplier was added without documented evaluation, that’s a nonconformance regardless of how long they’ve been on the list.

Do all suppliers need the same level of evaluation under ISO 13485?

No. ISO 13485 supports a risk-based approach to supplier controls. Suppliers providing critical components — those that directly affect device safety or performance — require more rigorous qualification and monitoring than suppliers of low-risk or non-product-contact materials. Your procedure must define the risk tiers and the control requirements for each.

What must purchase orders include to satisfy ISO 13485 Section 7.4.2?

Purchase orders and associated documents must describe the product clearly enough to verify compliance on receipt. This includes the product description, specification revision level, applicable standards or regulatory requirements, quality requirements being flowed down (such as a certificate of conformance), and change notification obligations. A purchase order that only includes a part number and price is not compliant with 7.4.2.

How often do I need to re-evaluate suppliers under ISO 13485?

ISO 13485 requires periodic re-evaluation but does not specify a frequency. Most quality management systems set annual re-evaluation as the standard cycle. What matters is that your procedure defines the frequency, that re-evaluation is actually performed on schedule, and that records are maintained showing the outcome and any actions taken.

What happens if a supplier fails re-evaluation?

Your procedure must define the response to poor supplier performance. Options include issuing a corrective action request, increasing the incoming inspection level, placing the supplier on probationary status, or removing them from the Approved Supplier List. Whatever action is taken must be documented. If a supplier is removed from the ASL, records must reflect the decision and any transition activities.

How do supplier controls connect to CAPA in ISO 13485?

Any nonconformance associated with purchased product — identified at incoming inspection, during production, or through customer complaints — should trigger your CAPA process. CAPAs issued to suppliers must be tracked to closure, with evidence that the root cause was addressed. A CAPA issued to a supplier with no follow-up record is a frequent audit finding.

Does ISO 13485 require supplier audits?

ISO 13485 does not explicitly require supplier audits, but it requires you to evaluate and monitor suppliers — and for high-risk suppliers, a supplier audit may be the most effective and defensible method. Your procedure should define when supplier audits are required based on risk level and performance history.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching whether your supplier program meets 13485 requirements? Start with the free ISO 13485 Gap Assessment Checklist to identify specific gaps before you invest in implementation.

🔹 Ready to build or rebuild your supplier control program? BSI Group’s ISO 13485 training covers supplier management as part of a full QMS implementation curriculum — practical, not academic.

🔹 Need the standard itself to verify clause requirements? Buy ISO 13485:2016 from the ANSI Webstore — use code CC2026 for 5% off through December 31, 2026.


Supplier controls are one of the most audited areas in ISO 13485 — and one of the most correctable. The common findings aren’t caused by complexity. They’re caused by supplier programs that were built fast, never formalized, and never tested against the actual clause requirements. The Standards Navigator covers ISO 13485 implementation from gap assessment through certification, with practical guidance built on real QMS and quality management experience.


Stay Ahead of ISO 13485 Supplier Control Requirements

Supplier nonconformances are consistently among the top audit findings in ISO 13485 certifications — not because the requirements are unclear, but because most programs were built to satisfy an initial audit and never updated to reflect actual supplier performance data.

Organizations that maintain clean supplier records and re-evaluate on a defined schedule rarely have corrective actions in this area. Organizations that treat supplier qualification as a one-time event get findings every surveillance cycle.

The Standards Navigator covers the full ISO 13485 implementation picture — from documentation requirements to CAPA processes to supplier controls — with guidance built for regulatory affairs and quality professionals who need to get it right, not just get it done.

👉 Get updates on ISO 13485 implementation requirements and audit readiness 👉 Be first to access new ISO 13485 compliance resources and checklists

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

ISO/TR 14969 Explained: What It Was, Why It Was Withdrawn, and What Replaces It in 2026

ISO/TR 14969:2004 — the companion guidance document for ISO 13485:2003 — was officially withdrawn when ISO 13485 was revised to its 2016 edition. Quality professionals still referencing it in QMS procedures are citing an obsolete document. This article explains what ISO/TR 14969 covered, why it was withdrawn, and what replaces it: the ISO 13485:2016 Practical Guide.

The guidance document for ISO 13485 has changed — here’s what medical device quality professionals need to know today

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Standard That Guided ISO 13485 Compliance Is Gone — Here’s What That Means

If you searched for ISO/TR 14969, you already ran into a dead end. The document is no longer current. It was officially withdrawn.

That matters more than it sounds. Quality professionals in the medical device space still reference ISO/TR 14969 in internal procedures, training materials, and supplier documentation. Some consultants still cite it. If you are building or auditing a QMS right now, you need to know what replaced it — and whether your documentation is anchored to an obsolete source.

ISO/TR 14969:2004 was withdrawn by ISO when ISO 13485 was revised to its 2016 edition. The technical report was tied to ISO 13485:2003. When the 2016 version introduced risk-based process controls, expanded post-market surveillance requirements, and global regulatory alignment language, the 2004 guidance became misaligned — and in some clauses, actively misleading. In its place, ISO published a new handbook: ISO 13485:2016 — Medical Devices — A Practical Guide.

Now, in 2026, the stakes are higher. The FDA’s Quality Management System Regulation (QMSR) took effect February 2, 2026, formally replacing 21 CFR Part 820 with ISO 13485:2016 as the baseline for U.S. device compliance. Organizations that built their QMS on ISO 13485:2003 interpretations — or whose procedures still reference ISO/TR 14969 — face a two-layer exposure: outdated guidance and regulatory non-alignment.

I’ve seen this pattern play out in quality systems that looked solid on paper. During a QMS documentation review I supported at a contract manufacturer with FDA-regulated device components, the team found five procedures that traced their CAPA language back to 14969 interpretation. The procedures hadn’t been reviewed since 2019. They weren’t wrong, exactly — but they were missing the risk-proportionate framing the 2016 standard requires. No findings yet. That changes when the next surveillance audit runs QMSR expectations against legacy documentation.

Before you go further — if your team is preparing for ISO 13485 certification or a surveillance audit, run a gap check first:

👉 Download the ISO 13485 Gap Assessment Checklist — Free checklist for medical device manufacturers assessing their QMS against ISO 13485:2016 requirements.


In This Guide

  • What ISO/TR 14969 was and what it covered
  • Why it was withdrawn
  • What replaced it — the ISO 13485:2016 Practical Guide, including its structure and chapter mapping
  • Why 2026 is the year this gap becomes a compliance liability (FDA QMSR)
  • How to update your QMS documentation to reflect current guidance
  • Where to purchase the current standard and guidance documents
  • FAQ

👉 Start Here — Top Resources


What Was ISO/TR 14969?

ISO/TR 14969:2004 was a Technical Report published by ISO’s Technical Committee 210 (ISO/TC 210), the group responsible for quality management and general aspects for medical devices.

TR stands for Technical Report. Unlike a full ISO standard, a Technical Report carries no requirements. It cannot be used as the basis for certification or regulatory inspection. Its purpose was interpretive: help organizations understand what ISO 13485 required and how to meet those requirements in practice.

ISO/TR 14969 provided clause-by-clause guidance on ISO 13485:2003. It explained intent, offered implementation examples, and clarified language that auditors and manufacturers found ambiguous. The document mirrored the clause structure of ISO 13485:2003 and covered:

  • Scope and application — how requirements applied across different organization types (manufacturers, service providers, distributors)
  • Quality management system (Clause 4) — documentation requirements, records, and what was required vs. recommended
  • Management responsibility (Clause 5) — how top management commitment was assessed and evidenced
  • Resource management (Clause 6) — personnel competency requirements, infrastructure, and work environment controls
  • Product realization (Clause 7) — planning, design controls, purchasing, production, and process validation
  • Measurement, analysis, and improvement (Clause 8) — feedback, internal audits, nonconformance control, CAPA, and data analysis

Most common finding: Organizations that built their QMS procedures using ISO/TR 14969 as a reference may have clause citations, interpretive notes, or CAPA language that is now misaligned with ISO 13485:2016. Those gaps become findings during document reviews and surveillance audits.


Why Was ISO/TR 14969 Withdrawn?

Comparison chart showing differences between withdrawn ISO/TR 14969 guidance and ISO 13485:2016 Practical Guide.
Compare legacy ISO/TR 14969 guidance with the current ISO 13485 implementation approach.

ISO/TR 14969:2004 was withdrawn because ISO 13485 itself was substantially revised in 2016. When the 2016 edition introduced new and modified requirements, the 2004 guidance document became misaligned — and in some areas, a liability.

Change AreaISO 13485:2003 / TR 14969ISO 13485:2016
Risk-based process controlLimited risk languageRisk-based approach embedded throughout QMS structure
Regulatory requirementsAligned primarily to EU directivesExpanded global alignment (FDA, TGA, Health Canada, EU MDR)
Post-market surveillanceGeneral requirementsExplicit feedback loop and monitoring requirements
Software validationBasic guidanceExpanded requirements for QMS software validation
Outsourced processesCovered in Clause 4.1Risk-proportionate controls based on risk and external party capability
Supplier controlsStandard purchasing controlsRisk-proportionate controls with clearer documentation requirements

A technical report tied to the 2003 standard could not guide organizations through requirements that didn’t exist until 2016. ISO withdrew the document and directed users to the replacement handbook.


What Replaced ISO/TR 14969? Structure and Clause Mapping

Timeline showing ISO/TR 14969 withdrawal and transition to ISO 13485:2016 Practical Guide and FDA QMSR requirements.
See how ISO/TR 14969 evolved into today’s ISO 13485 guidance framework.

The current guidance document is the ISO 13485:2016 — Medical Devices — A Practical Guide, published by ISO in 2017 and authored by technical experts from ISO/TC 210. In the United States it was adopted by AAMI as AAMI/ISO 13485:2016 — A Practical Guide, available through the ANSI Webstore. AAMI explicitly identifies it as the replacement for ISO/TR 14969.

The handbook runs approximately 214 pages and is organized to mirror the clause structure of ISO 13485:2016, making it a direct lookup reference when you’re working through specific requirements. Here’s how it maps:

Handbook SectionISO 13485:2016 ClauseKey Guidance Provided
Introduction & ScopeClause 1Applicability across organization types; what “regulatory purposes” means in practice
Quality Management SystemClause 4Risk-based QMS design; documentation hierarchy; outsourced process controls
Management ResponsibilityClause 5Top management commitment evidence; quality planning; management review inputs/outputs
Resource ManagementClause 6Competency records; infrastructure qualification; work environment controls
Product RealizationClause 7Design controls; purchasing controls; production process validation; sterilization; servicing
Measurement, Analysis & ImprovementClause 8Feedback systems; complaint handling; internal audit; CAPA; statistical methods

Beyond clause-level guidance, the Practical Guide also includes:

  • Regulatory notes specific to different markets — particularly useful for EU MDR and FDA QMSR alignment
  • Worked examples of how to apply risk-based thinking to QMS process selection and documentation intensity
  • Transition guidance for organizations moving from ISO 13485:2003-based systems to the 2016 edition

One practical limitation worth knowing: the Practical Guide is a 214-page document that, despite its name, is not always light reading. Industry reviewers have noted that some sections contain circular references and that the guidance on risk-based approach — one of the biggest paradigm shifts in the 2016 standard — spans only a few pages for a topic that has generated ongoing debate between manufacturers and notified bodies. Having the Practical Guide alongside a current training course is more effective than relying on the handbook alone.

👉 If you’re preparing for Stage 1 audit and haven’t run a full clause-by-clause gap check, do that before you open the Practical Guide. Download the ISO 13485 Gap Assessment Checklist to identify gaps first — then use the handbook to close them.


Why This Matters More in 2026: FDA QMSR and Dual Compliance

This isn’t just a document housekeeping issue. In 2026, it’s a compliance liability with a hard regulatory edge.

The FDA QMSR took effect February 2, 2026. It formally replaced 21 CFR Part 820 — the U.S. Quality System Regulation that governed device manufacturing for nearly 30 years — with ISO 13485:2016 as the legal baseline for U.S. medical device quality systems. Manufacturers who previously maintained a 21 CFR Part 820-based QMS now need to be running against ISO 13485:2016 requirements, including the interpretive framework the 2016 standard uses.

That has a direct impact on ISO/TR 14969 references. Here’s why:

ISO/TR 14969 pre-dates both ISO 13485:2016 and FDA QMSR. Any QMS procedure, work instruction, or training record that traces its authority back to 14969 guidance — rather than the 2016 standard and current Practical Guide — is not aligned to the regulatory expectations your FDA inspector will be applying.

Specific areas where this creates dual exposure:

  • CAPA requirements — 14969 guidance on CAPA pre-dates the 2016 standard’s risk-proportionate framing. FDA inspectors applying QMSR expectations will scrutinize whether your CAPA process scales corrective action depth to risk level. Procedures built on 14969 interpretation often don’t.
  • Post-market surveillance — The 2016 standard significantly strengthened feedback loop requirements. 14969 guidance reflects the lighter 2003 language. Under QMSR, FDA expects active post-market data feeding back into the QMS — not just complaint logs.
  • Software validation for QMS applications — If your document control system, CAPA software, or ERP was validated against 14969 guidance language, that validation basis needs review under the 2016 standard’s expanded software validation requirements.

I worked with a team at a supplier to a large device OEM during QMSR transition prep. Their internal audit procedure had been solid for years — well-written, consistently followed. When we mapped it against QMSR expectations, the issue wasn’t procedure quality. It was that the criteria used to determine audit frequency and depth hadn’t been updated since the 2003-era documentation. Risk-based audit scheduling — required under the 2016 standard — wasn’t in the procedure. The OEM’s supplier quality team flagged it in a pre-audit review before the FDA did. That’s the window you want to catch this in.

For a detailed breakdown of the QMSR transition and what changes for manufacturers, see FDA QSR vs ISO 13485.


How to Update Your QMS for Current Guidance

Five-step workflow for updating QMS documentation from ISO/TR 14969 to ISO 13485:2016 guidance.
Use this workflow to systematically remove obsolete guidance from your QMS.

If your QMS procedures, work instructions, or training materials reference ISO/TR 14969, here’s how to address it systematically.

Step 1 — Document search Run a controlled search of your document management system for “ISO/TR 14969,” “TR 14969,” and “14969:2004.” Flag every document where the reference appears. Include training materials and supplier quality agreements.

Step 2 — Classify each reference Not every reference creates a compliance gap. Categorize:

✅ Citation-only reference — the procedure logic is sound; only the document reference needs updating
⚠️ Interpretive reference — procedure was built around 14969 guidance that may not align with current Practical Guide interpretation (CAPA framing, risk-based audit criteria, outsourced process controls)
⚠️ Training material reference — auditors check training records; outdated citations get flagged

Step 3 — Batch the citation updates For straightforward citation updates, consolidate them into a single planned revision cycle. Update the reference from “ISO/TR 14969” to “ISO 13485:2016” or the Practical Guide as appropriate. Document the rationale in your change control record.

Step 4 — Cross-reference interpretive references against the Practical Guide For procedures built on 14969 interpretation, map them against the equivalent clause in the ISO 13485:2016 Practical Guide. Pay specific attention to: CAPA (Clause 8.5), outsourced process controls (Clause 4.1), internal audit (Clause 8.2), and post-market surveillance feedback (Clause 8.2.1). These are the areas where the 2016 guidance diverges most from 2003-era interpretation.

Step 5 — Update internal auditor training records If your ISO 13485 internal auditor training references 14969, update the training materials and re-document competency verification. This is consistently one of the overlooked items in QMS transitions — and it surfaces in audits.

Do the gap assessment before you start revising. Chasing individual references without knowing your overall QMS posture is working in the wrong order. The ISO 13485 Gap Assessment Checklist gives you the full picture first.


✅ Quick Checklist: ISO/TR 14969 Reference Review

  • [ ] Searched QMS document system for all 14969 references
  • [ ] Searched training materials and supplier quality agreements
  • [ ] Classified references as citation-only or interpretive
  • [ ] Verified CAPA procedure aligns with 2016 risk-proportionate framing — not 14969
  • [ ] Verified internal audit frequency and depth criteria include risk-based logic
  • [ ] Verified post-market surveillance feedback procedure reflects 2016 requirements
  • [ ] Updated training materials to remove obsolete guidance document references
  • [ ] Confirmed training records reflect ISO 13485:2016 Practical Guide as current source
  • [ ] Completed a full ISO 13485:2016 gap assessment against all 8 clauses

Where to Buy ISO 13485 and the Current Guidance Handbook

DocumentDescriptionSource
ISO 13485:2016The current active standard — required for certificationANSI Webstore
ISO 13485:2016 Practical Guide214-page official guidance handbook replacing ISO/TR 14969ANSI Webstore — available individually or in bundles
ISO 13485 / ISO 14971 BundleStandard + risk management standard packageANSI Webstore bundle
ISO/TR 14969:2004Withdrawn — historical reference onlyAvailable as historical document only

Use coupon code CC2026 for 5% off at the ANSI Webstore — valid through December 31, 2026. ANSI serves international buyers and offers standards in multiple languages where available.

For more on building your ISO 13485 QMS documentation, see ISO 13485 Documentation Requirements and the ISO 13485 Implementation Roadmap.


FAQ

Is ISO/TR 14969 still valid?

No. ISO/TR 14969:2004 was officially withdrawn by ISO when ISO 13485 was revised to its 2016 edition. It is no longer current and should not be used as implementation guidance for an ISO 13485:2016-aligned QMS. It remains available as a historical document only. The replacement is the ISO 13485:2016 — Medical Devices — A Practical Guide.

What replaced ISO/TR 14969?

ISO/TR 14969 was replaced by the ISO 13485:2016 — Medical Devices — A Practical Guide, a 214-page companion handbook published by ISO in 2017 and authored by ISO/TC 210 technical experts. In the United States, it was adopted by AAMI as AAMI/ISO 13485:2016 and is available through the ANSI Webstore. AAMI explicitly identifies it as the replacement for ISO/TR 14969.

Can I still reference ISO/TR 14969 in my QMS procedures?

It is not prohibited, but it creates audit risk — especially now that FDA QMSR is in effect. A reference to a withdrawn guidance document signals that your documentation system may not be current. Best practice is to replace ISO/TR 14969 citations with ISO 13485:2016 clause references or the Practical Guide, and to verify that any procedure logic built on 14969 interpretation still holds against the 2016 standard.

Does ISO/TR 14969 apply to FDA QMSR compliance?

No. ISO/TR 14969 was guidance for ISO 13485:2003. The FDA QMSR — effective February 2, 2026 — harmonizes U.S. requirements with ISO 13485:2016. QMSR compliance requires alignment with the 2016 standard and its current guidance documents. Organizations still referencing 14969 in CAPA, audit, or post-market surveillance procedures should treat QMSR implementation as the trigger to complete that cleanup.

What is the difference between a Technical Report and an ISO standard?

An ISO Technical Report carries no requirements and cannot serve as the basis for certification or regulatory inspection. ISO/TR 14969 was a TR — it existed to help organizations interpret and implement ISO 13485, not to define binding requirements. The ISO 13485:2016 Practical Guide serves the same interpretive purpose.

How is ISO/TR 14969 different from ISO 13485?

ISO 13485 is the requirements standard — it defines what a QMS must do to be certifiable. ISO/TR 14969 was guidance only — it explained how to interpret and meet those requirements. The standard is mandatory for certification; the guidance document was optional but widely used. ISO 13485:2016 is the current active standard.

Do I need to buy the ISO 13485:2016 Practical Guide separately from the standard?

Yes. The standard and the Practical Guide are separate publications. The standard defines the requirements; the Practical Guide explains clause intent and provides implementation examples. Bundle packages combining ISO 13485:2016, the Practical Guide, and ISO 14971 are available at the ANSI Webstore at savings compared to individual purchases. For manufacturers building or overhauling a QMS, having both is strongly recommended.

Where can I get ISO 13485 training that covers the current guidance?

BSI Group offers ISO 13485 training at awareness, requirements, implementation, internal auditor, and lead auditor levels — all aligned to the 2016 edition. BSI is both an accredited training provider and a recognized certification body. Pairing their implementation or internal auditor course with the Practical Guide gives you a working command of the 2016 requirements, not just familiarity with the document.


📥 Free Resources

  • ISO 13485 Gap Assessment Checklist — Free checklist for medical device manufacturers assessing their QMS against ISO 13485:2016 requirements before certification or a surveillance audit
  • ISO 9001 Roadmap — Step-by-step implementation guide for manufacturers building or improving a quality management system
  • Manufacturing Compliance Checklist — Practical compliance reference covering key ISO, OSHA, and quality requirements for production environments
  • Supplier Quality Checklist — Evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts
  • AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification

Not Sure What to Do Next?

🔹 Still researching ISO 13485 requirements? Start with What Is ISO 13485? for a full breakdown of the standard’s scope, structure, and who needs it.

🔹 Building or upgrading your ISO 13485 QMS? The ISO 13485 Implementation Roadmap walks you through the sequence from gap assessment to certification-ready documentation. For training on the 2016 requirements, BSI Group’s ISO 13485 courses include implementation-level coverage that goes well beyond the handbook itself.

🔹 Ready to purchase the standard? Get ISO 13485:2016 at the ANSI Webstore in digital or print. Use code CC2026 for 5% off through December 31, 2026.


The Standards Navigator covers the full medical device compliance standards landscape — from ISO 13485 implementation to FDA QMSR alignment. If your QMS has to hold up against both ISO certification and FDA inspection, the guidance document you’re working from matters as much as the standard itself.


Stay Current on ISO 13485 and Medical Device Compliance

QMS procedures built on outdated guidance don’t fail audits immediately. They fail them on the third surveillance cycle, when nobody remembers where the language came from. The FDA QMSR has made that timeline shorter.

The Standards Navigator covers ISO 13485 implementation, QMSR transition, risk management requirements, and the documentation controls that keep QMS systems audit-ready across both regulatory frameworks.

👉 Get updates on the medical device compliance standards cluster 👉 Be first to access new ISO 13485 implementation resources and checklists

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

Medical Device Compliance Standards: What Manufacturers Need to Know in 2026

Medical device manufacturers face a layered compliance framework — ISO 13485, ISO 14971, FDA QMSR, and EU MDR each impose specific requirements that must work together as an integrated system. This guide explains the core standards, how they interact, and what manufacturers need to prioritize at each stage of the compliance process.

The regulatory framework every medical device manufacturer must understand before the first audit

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Compliance Gap That Gets Medical Device Manufacturers in Trouble

Most medical device manufacturers don’t fail audits because they ignored the requirements. They fail because they didn’t understand how the requirements connect — and which standards they were actually obligated to meet.

The medical device compliance standards landscape is layered. ISO 13485 sets the QMS framework. ISO 14971 governs risk management. FDA regulations run parallel to international standards and don’t always align. Supplier controls, sterilization validation, design controls, and labeling each carry their own standard reference. A manufacturer who treats these as independent checkboxes instead of an integrated system is building toward an audit finding — or worse, a product recall.

The stakes are not abstract. The FDA issued 483 observations totaling thousands of findings in the medical device sector last year. Most cited documentation gaps, inadequate CAPA processes, or failure to meet design control requirements — all areas governed by the standards covered in this guide.

I’ve worked in quality systems that span heavy industrial, energy, and manufacturing environments — and the pattern I’ve seen across every sector is the same: organizations that struggle with audits are usually managing compliance requirements in silos. In the medical device world, that problem is amplified because the regulatory framework is both more complex and less forgiving than most industrial standards. Getting the structure right before your first audit is not optional — it’s the difference between certification and a warning letter.

Before you map your compliance requirements, download the ISO 13485 Gap Assessment Checklist — it walks you through every clause so you can identify exactly where your QMS falls short before an auditor does → ISO 13485 Gap Assessment Checklist

In This Guide:

  • The core standards every medical device manufacturer must know
  • How ISO 13485, ISO 14971, and FDA regulations interact
  • US vs. EU regulatory requirements compared
  • Supplier control and special process standards
  • Decision-stage guidance: what to prioritize based on where you are in the compliance process

👉 Start Here — Top Resources


The Core Standard: ISO 13485:2016

ISO 13485:2016 infographic showing clause structure and comparison of ISO 13485 versus ISO 9001 requirements for medical device quality management systems.
A visual breakdown of ISO 13485:2016 requirements and how they differ from ISO 9001 for medical device manufacturers.

ISO 13485:2016 is the international standard for quality management systems specific to medical device manufacturers and their supply chains. It is the foundation of medical device compliance worldwide.

ISO 13485 is not simply ISO 9001 with medical device language added. The two standards share structural similarities through the harmonized high-level clause structure, but ISO 13485 imposes stricter requirements in several critical areas ISO 9001 leaves to organizational discretion:

Requirement AreaISO 9001:2015ISO 13485:2016
Risk managementRisk-based thinking (general)Formal risk management required (links to ISO 14971)
Design controlsRequiredMore prescriptive — validation, verification, design transfer
CAPARequiredMore detailed — specific investigation and effectiveness checks
Regulatory requirementsNot addressedExplicitly required — must identify and meet applicable regs
Sterile product controlsNot addressedSpecific controls for sterile devices
Supplier controlsRequiredMore stringent — supplier qualification and monitoring
Document and record retentionNot specifiedSpecific retention periods tied to device lifetime

If you are ISO 9001 certified and entering the medical device market, you are not starting from scratch — but you are adding significant requirements. The gap is larger than most manufacturers expect.

If you need the standard itself, ISO 13485:2016 is available through the ANSI Webstore — use code CC2026 for 5% off through December 31, 2026.

Most common finding: Inadequate document control — specifically, failure to control the review and approval of documents and maintain records of changes. ISO 13485 Clause 4.2 is one of the most frequently cited areas in FDA 483 observations.


Risk Management: ISO 14971:2019

ISO 14971 is the international standard for risk management applied to medical devices. It is not optional if you are manufacturing medical devices — ISO 13485 explicitly requires you to apply risk management throughout the product lifecycle, and ISO 14971 is the recognized method for doing it.

ISO 14971:2019 defines the process for:

  • Identifying hazards associated with a medical device
  • Estimating and evaluating associated risks
  • Controlling those risks
  • Monitoring the effectiveness of controls

The relationship between ISO 13485 and ISO 14971 is not optional. ISO 13485 Clause 7.1 requires organizations to establish risk management requirements for product realization. ISO 14971 is the standard that defines what “proper” risk management looks like. Auditors will look for evidence that your risk management file connects directly to your design controls, production processes, and post-market surveillance activities.

ISO 14971 vs. ISO 13485 — understanding how they interact is one of the most common questions from manufacturers building a QMS for the first time.

If your risk management files exist independently of your design control documentation — that is an audit finding waiting to happen. Most teams miss the linkage between hazard identification in the risk management file and the verification/validation activities in the design history file.

Run your gap assessment before you go further — most QMS gaps in medical device companies trace back to missing connections between ISO 14971 risk files and ISO 13485 design controls: ISO 13485 Gap Assessment Checklist


US Regulatory Requirements: FDA QMSR and 21 CFR Part 820

US medical device manufacturers operate under FDA jurisdiction. The Quality Management System Regulation (QMSR), which took effect February 2, 2026, replaced the legacy Quality System Regulation (QSR) under 21 CFR Part 820.

The QMSR represents a significant shift: it incorporates ISO 13485:2016 by reference as the baseline for device QMS requirements. This means FDA-regulated manufacturers who are ISO 13485 certified are closer to QMSR compliance than they were under the old QSR — but important differences remain.

AreaISO 13485:2016FDA QMSR (2026)
ScopeInternationalUS market devices only
ComplaintsRequiredRequired + specific MDR reporting timelines
Corrections and removalsAddressed in CAPASpecific FDA reporting requirements (21 CFR Part 806)
UDINot addressedRequired for most device classes
Electronic recordsNot specified21 CFR Part 11 compliance required
Third-party auditsRequired for ISO 13485 certificationFDA inspections — not third-party certification

Understanding the relationship between FDA QSR and ISO 13485 is essential for US manufacturers — the two frameworks are now more aligned than before, but they are not identical.

If you are selling devices in the US market, FDA QMSR compliance is a legal requirement, not a voluntary certification. ISO 13485 certification does not satisfy FDA obligations — it demonstrates QMS capability but does not substitute for an FDA inspection.

Comparison infographic showing US FDA QMSR and EU MDR regulatory pathways for medical device manufacturers and ISO 13485 quality system requirements.
A side-by-side comparison of US FDA QMSR and EU MDR pathways showing how medical device compliance differs across global markets.

EU Requirements: MDR and CE Marking

Selling medical devices in the European Union requires CE marking under the EU Medical Device Regulation (MDR 2017/745), which replaced the Medical Device Directive (MDD) and came into full effect in 2021. The transition deadline for legacy MDD-certified devices has been extended but enforcement has tightened significantly.

Key MDR requirements relevant to QMS:

MDR RequirementConnection to ISO 13485
Technical documentationDesign history file / DHF requirements
Clinical evaluationPost-market clinical follow-up (PMCF)
Unique Device Identification (UDI)Traceability requirements
Post-market surveillance (PMS)Customer feedback and complaint monitoring
Notified Body auditISO 13485 certification is typically required
Person Responsible for Regulatory Compliance (PRRC)Management responsibility — ISO 13485 Clause 5

The MDR is more prescriptive than ISO 13485 in clinical evidence requirements. If you are exporting to the EU, your clinical evaluation report and post-market surveillance plan must meet MDR requirements that go beyond what ISO 13485 explicitly requires.

If you are selling in both the US and EU markets, you are managing two regulatory frameworks simultaneously. This is where a well-structured ISO 13485 QMS becomes particularly valuable — it provides the common foundation that both frameworks build on.


Supplier Controls and Special Process Standards

ISO 13485 Clause 7.4 imposes stricter supplier control requirements than most manufacturers new to the medical device space expect. You are not simply verifying that a supplier has a quality system — you are responsible for ensuring that purchased products and services meet specified requirements and that critical suppliers are evaluated, approved, and monitored.

For medical device manufacturers, supplier controls must address:

  • Supplier qualification — documented criteria for evaluation and approval
  • Incoming inspection — defined acceptance criteria for purchased product
  • Critical supplier monitoring — ongoing performance data, not just initial qualification
  • Supplier audits — for high-risk or critical component suppliers
  • Flow-down requirements — pushing your quality requirements into the supply chain

Special processes — sterilization, biocompatibility testing, coating, welding on implantable components — require additional validation documentation. The relevant standards include:

ProcessStandard Reference
Sterilization (EO, radiation, steam)ISO 11135, ISO 11137, ISO 17665
BiocompatibilityISO 10993 series
Packaging validationASTM F2132, ISO 11607
Software validationIEC 62304
Electrical safetyIEC 60601 series

These are not optional for manufacturers of the relevant device types. If your device is sterilized, you need sterilization validation documentation. If it contacts patient tissue, you need biocompatibility data. Gaps in special process validation are among the most serious findings an FDA inspector or Notified Body auditor can cite.


Design Controls and Validation Standards

ISO 13485 design controls infographic showing the Design History File process from inputs through outputs, verification, validation, and design transfer.
A visual guide to the ISO 13485 design controls process and how design inputs become validated, production-ready medical devices.

Design controls are where ISO 13485 certification and FDA compliance intersect most directly. ISO 13485 Clause 7.3 requires a structured design and development process covering:

  • Design and development planning
  • Design inputs (requirements)
  • Design outputs (specifications)
  • Design review at defined stages
  • Design verification (does it meet inputs?)
  • Design validation (does it meet user needs?)
  • Design transfer (can it be manufactured consistently?)
  • Design changes (controlled and documented)

The design history file (DHF) is the physical record of this entire process. It is the first thing an FDA inspector or Notified Body auditor will request. Manufacturers who build their DHF as a collection of unconnected documents — rather than as a traceable record linking inputs to outputs to verification to validation — create significant risk for themselves.

If you are new to building a medical device QMS and need a structured path through these requirements, the ISO 13485 Implementation Roadmap on The Standards Navigator covers the full sequence from gap assessment through certification.

BSI Group offers ISO 13485 training covering both requirements understanding and implementation — useful for teams building their first medical device QMS or transitioning from a general ISO 9001 system.


Labeling and Traceability Standards

Labeling compliance is a specific, frequently cited area in FDA 483 observations. Under both FDA QMSR and MDR requirements, device labeling must meet defined content and format requirements — and the label must be controlled as a quality record.

Key labeling standards and requirements:

  • ISO 15223-1 — symbols used in medical device labeling (required for EU MDR compliance)
  • 21 CFR Part 801 — FDA labeling requirements for US devices
  • UDI requirements — FDA requires Unique Device Identification on most device labels, with submission to the GUDID database

Traceability connects directly to your CAPA and complaint handling processes. If a complaint involves a specific lot or device unit, your traceability records must be sufficient to identify affected products, investigate the root cause, and determine corrective action scope. ISO 13485 Clause 7.5.9 addresses traceability explicitly — and auditors will test it.


How the Standards Work Together

Layered medical device compliance standards infographic showing ISO 13485 as the foundation with ISO 14971, FDA QMSR, EU MDR, supplier controls, CAPA, and traceability requirements.
A visual framework showing how ISO 13485, FDA QMSR, EU MDR, and supporting standards connect into an integrated medical device compliance system.

The most important thing to understand about medical device compliance is that these standards are not independent — they form an integrated system. Here is how they connect:

StandardRole in the System
ISO 13485:2016QMS framework — the backbone that everything else connects to
ISO 14971:2019Risk management process — required by ISO 13485, referenced throughout
FDA QMSRUS regulatory layer — builds on ISO 13485, adds FDA-specific requirements
EU MDREU regulatory layer — requires ISO 13485 certification via Notified Body
IEC 62304Software lifecycle — required if your device includes software
ISO 10993Biocompatibility — required for patient-contacting devices
ISO 15223Labeling symbols — required for EU MDR labeling compliance

A manufacturer who has ISO 13485 certification, a complete ISO 14971 risk management file, and solid FDA QMSR documentation has built the framework that all additional standards layer onto. The common mistake is treating each standard as a separate compliance project rather than building the integrated system first.

If you are deciding between prioritizing FDA QMSR or ISO 13485 certification first: in most cases, building to ISO 13485 gives you the QMS foundation that both US and EU regulatory compliance require. The ISO 13485 Documentation Requirements article covers what your QMS documentation set must include.


Quick Compliance Checklist

Use this as a starting reference — not a substitute for a clause-by-clause gap assessment.

✅ ISO 13485:2016 obtained and QMS scope defined
✅ Risk management procedure in place referencing ISO 14971
✅ Design controls documented — inputs, outputs, verification, validation, transfer
✅ CAPA process established with effectiveness verification
✅ Supplier qualification and monitoring program documented
✅ Document and record control procedures in place with defined retention periods
✅ Internal audit program scheduled and resourced
✅ Management review process defined and conducted
✅ Complaint handling and MDR/vigilance reporting process established
✅ UDI requirements evaluated and implemented where applicable
✅ Applicable special process validations identified and documented
✅ Labeling reviewed against ISO 15223 (EU) and 21 CFR Part 801 (US)

⚠️ If you cannot check most of these — complete a formal gap assessment before committing to a certification timeline.


FAQ

Is ISO 13485 certification required to sell medical devices?

ISO 13485 certification is not legally required by US law — the FDA requires QMSR compliance, not ISO 13485 certification specifically. However, ISO 13485 certification is required to sell devices in the EU under MDR, and it is increasingly required by OEM customers and contract manufacturers as a condition of doing business. Most manufacturers targeting both markets pursue certification.

How is ISO 13485 different from ISO 9001?

ISO 13485 is a sector-specific standard derived from ISO 9001 but with significantly stricter requirements in risk management, design controls, CAPA, supplier controls, and regulatory compliance. It does not include the continual improvement emphasis that ISO 9001 requires — instead it focuses on consistent compliance with regulatory requirements. A detailed comparison is covered here.

Do I need ISO 14971 if I am ISO 13485 certified?

Yes. ISO 13485 explicitly requires risk management throughout the product lifecycle and references ISO 14971 as the applicable method. You are not ISO 13485 compliant if your risk management process does not meet ISO 14971 requirements. The two standards work together — you cannot separate them.

What is the FDA QMSR and how is it different from the old QSR?

The Quality Management System Regulation (QMSR) took effect February 2, 2026 and replaced 21 CFR Part 820 (the Quality System Regulation). The QMSR incorporates ISO 13485:2016 by reference, making it more aligned with the international standard. Key differences remain around FDA-specific reporting requirements, UDI obligations, and 21 CFR Part 11 electronic records requirements. A full breakdown of FDA QSR vs ISO 13485 is here.

How long does it take to get ISO 13485 certified?

For a manufacturer building a QMS from scratch, 12–18 months is a realistic timeline. Organizations with an existing ISO 9001 QMS can often close the gap in 6–12 months, depending on how many medical device-specific requirements need to be added. The ISO 13485 Implementation Roadmap covers the full timeline in detail.

What is a Notified Body and do I need one?

A Notified Body is an organization designated by EU member states to assess conformity of medical devices under the MDR. If you are seeking CE marking for Class IIa, IIb, or Class III devices, you must engage a Notified Body — they conduct the audits that verify ISO 13485 compliance and technical documentation. BSI Group is one of the major Notified Bodies offering both training and certification services.

What are the most common ISO 13485 audit findings?

The most frequently cited areas include: inadequate document and record control (Clause 4.2), incomplete CAPA processes with missing effectiveness verification (Clause 8.5.2), insufficient supplier qualification documentation (Clause 7.4), and gaps in design control records — particularly missing design verification and validation evidence (Clause 7.3). Common mistakes in ISO 13485 QMS implementation covers these in detail.

Do my suppliers need to be ISO 13485 certified?

Not necessarily — but you are responsible for ensuring purchased product meets specifications regardless. Whether a supplier needs ISO 13485 certification depends on their criticality and what they supply. Critical component suppliers and contract manufacturers of finished devices are typically expected to be certified. Commodity suppliers may only require documented incoming inspection.


📥 Free Resources

ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements — medical device articles only

ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system

Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments

Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts

AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification


Not Sure What to Do Next?

🔹 Still researching your compliance requirements? Start with a gap assessment against ISO 13485 before you invest in implementation. Download the free ISO 13485 Gap Assessment Checklist — it maps every clause so you know exactly where you stand.

🔹 Ready to build your QMS? ISO 13485 training through BSI Group covers requirements, implementation, and internal auditor training — the right sequence for a team building their first medical device QMS.

🔹 Need the standard itself? Buy ISO 13485:2016 through the ANSI Webstore — use code CC2026 for 5% off through December 31, 2026. International buyers can purchase in multiple languages.


Medical device compliance is not a single standard — it is a framework of interconnected requirements that must be built and maintained as a system. Understanding how ISO 13485, ISO 14971, FDA QMSR, and EU MDR relate to each other is the first step toward building a QMS that holds up under audit. The Standards Navigator covers each of these standards in depth — start with the resources above and build from there.


Stay Current on Medical Device Compliance

Regulatory changes in the medical device space don’t slow down. FDA QMSR took effect in 2026. EU MDR enforcement is intensifying. ISO 14971 continues to be misapplied by manufacturers who treat risk management as a documentation exercise rather than an integrated process.

Organizations that keep pace with these changes have one thing in common — they’re not waiting for an audit finding to tell them something changed. The ones that struggle are managing compliance reactively, updating their QMS only when a customer or inspector forces the issue.

The Standards Navigator covers ISO 13485, ISO 14971, FDA regulatory requirements, and the full medical device compliance framework — from standard purchase through certification and ongoing surveillance.

👉 Get updates when new medical device compliance articles publish
👉 Be first to access the ISO 13485 Documentation Kit when it launches

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

ISO 13485 Implementation Roadmap: How to Build a Compliant Medical Device QMS in 2026

ISO 13485:2016 is now US federal law under the FDA QMSR, making a compliant medical device QMS mandatory rather than optional. This roadmap walks manufacturers through a seven-phase implementation — from gap assessment and scope through risk management, documentation, CAPA, and certification — covering both the international certification path and FDA inspection readiness for US manufacturers building from the ground up.

A step-by-step guide to implementing ISO 13485:2016 — from gap assessment to certification and FDA QMSR readiness

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Building a Medical Device QMS Is No Longer Optional in the United States

For years, ISO 13485 sat in a strange position for US manufacturers. It was the global benchmark for medical device quality management — required to sell in the EU, Canada, and most of the world — but inside the United States it was voluntary. You complied with FDA’s Quality System Regulation, and ISO 13485 was a nice-to-have for export.

That changed on February 2, 2026. FDA’s Quality Management System Regulation (QMSR) took effect, replacing the old Quality System Regulation and incorporating ISO 13485:2016 by reference directly into 21 CFR Part 820. The practical effect is blunt: ISO 13485:2016 is now part of US federal law. FDA inspections are conducted against it. The standard you could once ignore at home is now the framework your inspector arrives with.

So whether you are a US manufacturer preparing for your first QMSR-aligned FDA inspection, or an international supplier chasing your first ISO 13485 certificate to unlock the EU market, you face the same task: build a quality management system that survives outside scrutiny. This roadmap walks you through it — clause by clause, phase by phase — from the day you decide to start to the day a registrar or an FDA investigator walks through the door.

This ISO 13485 implementation roadmap is a long article because building a medical device QMS is a long project. Use the table of contents to jump to where you are.


Before you build anything, find out where you actually stand. Most teams overestimate how compliant their existing processes are — and discover the gaps during the certification audit or FDA inspection, when fixing them is expensive and the clock is running. Run a clause-by-clause check against ISO 13485:2016 first.

👉 Download the free ISO 13485 Gap Assessment Checklist and benchmark your QMS in an afternoon, before you commit budget to implementation.


In This Guide

  • Why ISO 13485 implementation looks different in 2026 (QMSR, EU reforms)
  • The realistic timeline and cost of a full implementation
  • A seven-phase roadmap from gap assessment to certificate
  • How risk management (ISO 14971) and design controls fit into the QMS
  • The documentation you actually need — and where teams over-build
  • Internal audit, management review, and Stage 1 / Stage 2 audit preparation
  • FDA QMSR inspection readiness for US manufacturers
  • The mistakes that fail audits — and how to avoid them


👉 Start Here (Top Resources)

If you are implementing ISO 13485 from scratch, these are the three resources that move the project fastest:

  • Build your documentation without a consultant. A complete, pre-written ISO 13485 documentation kit gives you the quality manual, procedures, and records templates structured to the standard — so you spend your time tailoring, not drafting from a blank page. 👉 See the ISO 13485 documentation kits at 9001Simplified
  • Get the official standard. You cannot implement a clause you have not read. Buy ISO 13485:2016 from the ANSI Webstore — use code CC2026 for 5% off through December 31, 2026. ANSI serves international buyers and offers standards in multiple languages.
  • Train your internal team. Your management representative and internal auditors need formal training. BSI Group offers ISO 13485 training courses spanning awareness through lead auditor.

What Makes 2026 Different

ISO 13485:2016 is still the current edition — and it will be for a while. ISO postponed the next revision deliberately to let the 2016 edition “bed in,” with a new version not expected before roughly 2028–2029. So the standard you implement today is the standard you will operate under for years. That stability is good news: it means your implementation work has a long shelf life.

What has shifted is the regulatory context around the standard.

In the United States, the QMSR is the headline. FDA now incorporates ISO 13485:2016 into 21 CFR Part 820, layered with a handful of FDA-specific additions — labeling, UDI, and certain record and definition provisions — that go beyond the ISO text. A critical nuance: the QMSR is “version locked” to the 2016 edition. Future ISO 13485 revisions will not automatically apply in the US unless FDA initiates new rulemaking. Certification to ISO 13485 is still not legally required in the US — FDA inspects you directly — but building your QMS to the standard is now the most direct path to QMSR compliance.

In the European Union, the pressure point is notified body capacity, not the standard itself. EU Implementing Regulation 2026/977, published in May 2026 and applying from February 25, 2027, finally imposes hard maximum timelines on notified bodies — 30 days to review an application and sign a contract, 120 days for the QMS audit, 90 days for product verification, and 20 days to issue the certificate, with capped clock-stops and transparent quotations. For manufacturers, the message is that the certification path is becoming more predictable, but you still need a clean, audit-ready QMS to take advantage of it.

One more 2026 wrinkle worth flagging if your devices touch biocompatibility: FDA’s recognition of the sixth edition of ISO 10993-1 is partial. Notably, FDA does not recognize Clause 6.9 on biological risk estimation, holding that it conflicts with the recognized risk management standard ISO 14971:2019. If your risk files cite ISO 10993-1 wholesale, that is now a deficiency-letter risk in US submissions. Keep biological risk inside the ISO 14971 framework. We cover biocompatibility in depth separately — for this roadmap, just know that your risk management process is the anchor, not the 10993 series.

If you sell only in the US → build to ISO 13485:2016 for QMSR compliance and skip certification unless a customer demands it. If you sell internationally → you need an actual ISO 13485 certificate from an accredited registrar, so plan for a Stage 1 / Stage 2 audit. If you sell in both markets → build one QMS to ISO 13485:2016 and bolt on the FDA-specific QMSR additions; do not run two parallel systems.

QMSR vs ISO 13485 at a Glance

The two frameworks now share a core, but they are not identical. This is where US and international readers diverge — and where a single well-built QMS can serve both.

DimensionISO 13485:2016FDA QMSR (21 CFR Part 820)
Legal statusVoluntary international standardMandatory US federal regulation
Core requirementsThe full ISO 13485 QMSIncorporates ISO 13485:2016 by reference
Proof of complianceCertificate from accredited registrarFDA inspection — no certificate issued
Added requirementsNone beyond the standardLabeling, UDI, certain records & definitions
Risk managementReferences ISO 14971Requires ISO 14971 framework; rejects ISO 10993-1 Clause 6.9
Version handlingISO may revise (~2028–2029)“Version locked” to the 2016 edition
Who needs itAnyone selling internationallyAny device manufacturer marketing in the US

For the full treatment, see our dedicated FDA QSR vs ISO 13485 comparison.


Timeline and Cost: What to Expect

A realistic ISO 13485 implementation runs 6 to 12 months for a small-to-mid-size manufacturer building from a limited starting point. Companies already operating a mature ISO 9001 system or a legacy QSR-based system can move faster; companies starting from informal processes should plan for the full year.

ISO 13485 implementation timeline infographic showing a phased 6 to 12 month roadmap for medical device manufacturers progressing from gap assessment through certification.
A visual roadmap showing a realistic ISO 13485 implementation timeline from assessment through certification readiness.
PhaseTypical durationWhat drives it
Gap assessment & scope2–4 weeksSize of the gap between current practice and the standard
Process & documentation build8–16 weeksWhether you draft from scratch or start from templates
Implementation & operation8–12 weeksYou need real records, not just documents — audits want evidence
Internal audit & management review3–4 weeksMust be complete before a registrar will proceed to Stage 2
Certification (Stage 1 + Stage 2)6–10 weeksRegistrar scheduling and any nonconformity closure

On cost, the single biggest variable is whether you hire a consultant to draft your system or build it yourself from a structured template. Consultant-led implementations commonly run $15,000–$50,000+ depending on device class and company size. A template-driven build can cut the documentation labor dramatically. For a full breakdown, see our guide on how much ISO 13485 certification costs.


Phase 1 — Foundation: Scope, Standard, and Leadership Commitment

Everything downstream depends on getting three things right at the start.

Define your QMS scope. ISO 13485 lets you exclude certain requirements — for example, design and development (Clause 7.3) if you are a contract manufacturer building to a customer’s design. But exclusions must be justified and documented, and you cannot exclude something just because it is inconvenient. Map which clauses apply to your role: manufacturer, specification developer, contract manufacturer, sterilization provider, or importer. Your scope statement is the first thing a registrar reads and the boundary an FDA investigator works within.

Acquire and read the standard. This sounds obvious and gets skipped constantly. You cannot delegate compliance with a document nobody on the team has read end to end. Buy the official ISO 13485:2016 text from the ANSI Webstore — apply coupon CC2026 for 5% off through the end of 2026 — and have your management representative work through it clause by clause. If you also need the risk management standard, ISO 14971:2019 is available there too. ANSI’s catalog covers international buyers and multiple languages, which matters if your QMS spans sites.

Secure genuine leadership commitment. Clause 5 puts top management on the hook — quality policy, quality objectives, resource allocation, and management review are not delegable to a quality manager working in isolation. The fastest implementations have an executive sponsor who clears roadblocks. The ones that stall have a quality team trying to impose a system the leadership treats as paperwork.

If you are a contract manufacturer → document your design and development exclusion now, with justification, before you build the rest of the system around it.

⚠️ Common pitfall: Claiming a Clause 7.3 exclusion you can’t defend. If your team does any design input — even tweaking a customer’s spec for manufacturability — a registrar may reject the exclusion and you’ll be retrofitting design controls mid-project. Decide your true scope honestly before you build.


Most ISO 13485 projects don’t fail on the standard — they fail on documentation that nobody can find, follow, or defend in an audit. Before you write a single procedure, make sure you know which records the standard actually requires.

👉 Run the gap assessment and map your existing documents against the clauses — it turns “we think we’re covered” into a defensible list.


Phase 2 — Plan: Processes, Roles, and Competence

ISO 13485 is a process-based standard. Before documentation, map your actual processes and how they connect — the “sequence and interaction” the standard requires.

Identify your core processes. At minimum: management processes (planning, review, resourcing), product realization (design, purchasing, production, servicing), and support processes (document control, records, CAPA, internal audit). For each, define inputs, outputs, owners, and the records that prove it ran.

Appoint a management representative. Clause 5.5.2 requires a member of management responsible for the QMS. This person owns the system, reports its performance to leadership, and is typically the registrar’s main point of contact.

Plan competence and training. Clause 6.2 requires that personnel performing work affecting product quality are competent — with records to prove it. This includes your internal auditors, who must be trained and independent of the areas they audit. Formal training shortens the learning curve here; BSI Group’s ISO 13485 course catalog runs from awareness through lead auditor, and the lead-auditor tier is what equips your internal audit program to find problems before the registrar does. For audit methodology itself, note that the underlying guidance standard, ISO 19011, was updated to a 2026 edition in May 2026 — worth referencing when you write your internal audit procedure.

⚠️ Common pitfall: Treating internal auditor “independence” as a formality. Having someone audit their own department is one of the most common nonconformities — and it quietly undermines every finding that audit produces. Cross-train auditors so no one reviews work they own.


Phase 3 — Risk Management and Design Controls

This is where ISO 13485 separates itself from ISO 9001, and where the most consequential implementation decisions live.

Risk management is the spine. ISO 13485 threads risk-based thinking through the entire product lifecycle, and it leans on ISO 14971:2019 as the method. You need a risk management process, a risk management file for each device or device family, and evidence that risk controls are verified and monitored in production and post-market. As noted earlier, keep biological risk inside this ISO 14971 framework rather than importing a separate scoring approach — that alignment is exactly what FDA expects under the QMSR.

Design controls (Clause 7.3) apply if you develop devices. This is the discipline FDA investigators scrutinize hardest, because design failures are where patients get hurt. You need:

Design control elementWhat it requires
Design and development planningA documented plan with stages, reviews, and responsibilities
Design inputsRequirements derived from intended use, user needs, and regulation
Design outputsSpecifications that can be verified against inputs
Design reviewFormal reviews at planned stages with independent reviewers
Design verificationEvidence outputs meet inputs
Design validationEvidence the device meets user needs in actual or simulated use
Design transferControlled handoff to production
Design changesControlled, reviewed, and documented changes
Design history file (DHF)The complete record of the above

If you are a US manufacturer, the QMSR keeps design controls firmly in play — they map directly onto the ISO 13485 Clause 7.3 requirements, which is one reason a single ISO-aligned system now serves both purposes.

If you are preparing your first device submission → build the risk management file and design history file in parallel with the QMS, not after. Auditors and investigators expect to see them populated, not planned.

⚠️ Common pitfall: Building the risk file as a one-time document for the submission, then never touching it again. Risk management is a living, lifecycle requirement — production and post-market data have to feed back into it. A risk file frozen at launch is a finding waiting to happen.


Phase 4 — Build the Documentation

Now you write the system. ISO 13485 expects a defined documentation hierarchy: a quality manual, documented procedures, work instructions, forms, and the records they generate.

ISO 13485 documentation architecture infographic showing the five-layer quality management documentation hierarchy from quality manual through records.
A visual breakdown of the five documentation layers used to build and maintain an ISO 13485 quality management system.

The required documents. ISO 13485:2016 explicitly requires certain documented procedures — document control, record control, management review, internal audit, control of nonconforming product, CAPA, and several product-realization procedures among them. A medical device file (technical documentation) is required for each device type. Our breakdown of ISO 13485 documentation requirements lists exactly what the standard mandates versus what is optional.

Where teams over-build. The most common documentation mistake is writing procedures more detailed and rigid than the operation can actually follow. Every sentence in a procedure is a commitment an auditor can hold you to. If your procedure says calibration happens every 90 days and a record shows 95, that is a nonconformity you created with your own words. Write to what you do; improve what you do separately.

Start from a structured template, not a blank page. Drafting an entire ISO 13485 documentation set from scratch is where 6-month projects become 12-month projects. A complete documentation kit gives you the quality manual, every required procedure, and the records templates already structured to the clauses — so your team spends its hours tailoring language to your operation instead of reinventing the architecture of a QMS.

👉 See what’s included in the 9001Simplified ISO 13485 documentation kit — it is the no-consultant route most small manufacturers should evaluate first.

Set up document and record control before you generate volume. Clauses 4.2.4 and 4.2.5 require controlled documents and controlled records. Get the control mechanism — versioning, approval, retention, retrieval — working before you have hundreds of documents to retrofit.

⚠️ Common pitfall: Over-documenting. Teams write procedures so detailed and rigid that the floor can’t actually follow them — then every deviation from their own paperwork becomes a nonconformity. Document what you genuinely do, keep procedures lean, and push the specifics down into work instructions where they’re easier to change.


Phase 5 — Implement and Operate

A documented QMS proves nothing. Auditors and investigators want records that show the system ran.

This is the phase teams underestimate. You can write a CAPA procedure in a day; demonstrating that CAPA actually works requires real CAPAs opened, investigated, and closed over weeks. Plan for an operating period — typically 8 to 12 weeks minimum — where the system runs and generates genuine evidence: training records, calibration records, completed reviews, supplier evaluations, nonconformance reports, and CAPA records.

A registrar will not progress to a certification audit, and an FDA investigator will not be satisfied, by documents alone. Both want to trace a process from requirement to record to outcome. Build that evidence trail before you invite anyone to inspect it.

If you are under customer pressure to certify quickly → start operating the system in parallel with finishing documentation, so your evidence trail is already accumulating when the documents are signed off.

⚠️ Common pitfall: Booking the certification audit before the system has actually run. A registrar can tell the difference between a QMS that has operated for three months and one that generated all its records last week. Backdated or thin evidence is the fastest way to turn a Stage 2 audit into a list of nonconformities.


Phase 6 — CAPA, Supplier Controls, and Production Controls

Three areas generate the most audit findings and FDA 483 observations. Get them right and you de-risk the entire certification.

CAPA (Corrective and Preventive Action). This is the single most-cited area in medical device QMS audits. A weak CAPA system — actions opened and never closed, root causes not actually identified, effectiveness never verified — signals to an auditor that the whole system is decorative. Your CAPA process must show genuine root cause analysis, defined actions, and verified effectiveness. Our deep dive on CAPA requirements in ISO 13485 covers the failure modes in detail.

Supplier and purchasing controls (Clause 7.4). You are accountable for what your suppliers provide. You need defined supplier evaluation criteria, approved-supplier records, and controls proportionate to the risk the purchased product carries. Flow your quality requirements down in writing — handshake arrangements do not survive audits.

Production and process controls (Clauses 7.5). This includes process validation for any process whose output cannot be fully verified by later inspection — sterilization and certain welding or molding processes are classic examples — plus identification, traceability, and handling of product. Cleanliness, contamination control, and installation/servicing requirements apply where relevant to your device.

A documentation kit accelerates this layer too. The CAPA log, supplier evaluation forms, nonconformance records, and validation templates are exactly the high-stakes documents you do not want to invent under deadline.

👉 A structured kit gives you defensible templates for all three areas so your effort goes into running the processes, not formatting the paperwork.

Avoid the recurring traps documented in our guide to common mistakes in ISO 13485 QMS implementation — most failures are predictable.

⚠️ Common pitfall: Closing CAPAs without verifying effectiveness. “We retrained the operator” is not a closed CAPA — it’s an action with no proof it worked. Auditors reopen these constantly. Every CAPA needs a defined effectiveness check and evidence it passed before you close it.


Phase 7 — Internal Audit, Management Review, and Certification

Before any external party inspects you, inspect yourself.

Internal audit (Clause 8.2.4). Conduct a full internal audit of your QMS against ISO 13485 using trained, independent auditors. This is your dress rehearsal — the audit that finds problems while you still control the timeline and the narrative. Document findings, open CAPAs, and close them.

Management review (Clause 5.6). Top management formally reviews QMS performance against defined inputs — audit results, customer feedback, process performance, CAPA status, and more — and produces documented outputs and decisions. Registrars treat a missing or hollow management review as a serious gap.

The certification audit (international path). An accredited registrar conducts a two-stage audit:

StageFocusOutcome
Stage 1Documentation review and readinessConfirms the system is ready for Stage 2; identifies gaps
Stage 2On-site implementation auditVerifies the system operates as documented; raises any nonconformities

Close any nonconformities, and the registrar issues your certificate — typically valid for three years with annual surveillance audits. Choosing an accredited registrar matters; verify accreditation through bodies like ANAB or the relevant IAF member. Our guide to the best ISO certification bodies walks through selection.

⚠️ Common pitfall: Running a hollow management review to check the box. A review that doesn’t actually examine audit results, CAPA status, and process performance — and produce real decisions — is treated by registrars as a serious gap, because it signals leadership isn’t engaged. Make it substantive, and keep the minutes.


FDA QMSR Inspection Readiness

If you are a US manufacturer, your “certification audit” may instead be an FDA inspection — and the bar is the QMSR, which now runs on ISO 13485:2016 plus FDA’s additions.

Practical readiness steps:

  • Map ISO 13485 to the QMSR additions. Most of your ISO-aligned system satisfies Part 820 directly. Layer in the FDA-specific requirements — labeling and packaging controls, UDI, and certain record and complaint-handling provisions — that exceed the ISO text.
  • Keep your records inspection-ready, not audit-ready-once. FDA inspections are unannounced or short-notice. The evidence trail from Phase 5 has to be standing, not assembled on demand.
  • Treat CAPA and complaint handling as the focal points. These are where 483 observations concentrate. A clean, closed-loop CAPA system is your strongest signal of control.
  • Understand the relationship between the two frameworks. Our comparison of FDA QSR vs ISO 13485 explains exactly what the QMSR changed and where the frameworks now align.

For US manufacturers selling internationally, the efficient move is one ISO 13485 QMS with the QMSR additions built in — not two systems. The frameworks now overlap by design.


Quick Implementation Checklist

Use this as a high-level progress tracker. Each item maps to a phase above.

  • ✅ QMS scope defined and exclusions justified in writing
  • ✅ Official ISO 13485:2016 (and ISO 14971:2019) acquired and read
  • ✅ Top management commitment secured; quality policy and objectives set
  • ✅ Management representative appointed
  • ✅ Core processes mapped with owners, inputs, outputs, and records
  • ✅ Personnel competence and internal auditor training in place
  • ✅ Risk management process and risk management file established (ISO 14971)
  • ✅ Design controls and design history file in place (if you develop devices)
  • ✅ Quality manual, required procedures, and record templates written
  • ✅ Document control and record control operating before volume builds
  • ✅ System operated long enough to generate genuine records (8–12 weeks)
  • ✅ CAPA system demonstrably closing the loop with verified effectiveness
  • ✅ Supplier evaluation and purchasing controls documented and flowed down
  • ✅ Process validation completed where output can’t be fully verified
  • ✅ Full internal audit completed; findings closed
  • ✅ Management review conducted with documented outputs
  • ✅ Registrar selected (international) or QMSR inspection readiness confirmed (US)
  • ✅ Stage 1 and Stage 2 audit passed; nonconformities closed

FAQ

How long does ISO 13485 implementation take?

For a small-to-mid-size manufacturer building from a limited starting point, plan for 6 to 12 months. Companies with a mature ISO 9001 system or a legacy QSR-based system can move faster, while organizations starting from informal processes should plan for the full year. The longest single phase is usually documentation, followed by the operating period needed to generate real records.

Is ISO 13485 certification required in the United States?

No. FDA inspects US manufacturers directly against the QMSR, which incorporates ISO 13485:2016 — certification by a third-party registrar is not legally required. However, building your QMS to ISO 13485 is now the most direct path to QMSR compliance, and certification is required to sell in the EU, Canada, and most international markets. Many US manufacturers certify anyway to serve global customers and demonstrate a recognized standard of control.

What is the difference between ISO 13485 and the FDA QMSR?

The QMSR, effective February 2, 2026, replaced FDA’s old Quality System Regulation and incorporates ISO 13485:2016 by reference into 21 CFR Part 820, plus FDA-specific additions covering labeling, UDI, and certain records. The two are now largely aligned by design. The QMSR is “version locked” to the 2016 edition, so future ISO 13485 revisions will not automatically apply in the US. See our full FDA QSR vs ISO 13485 comparison for detail.

Do I need ISO 14971 to implement ISO 13485?

Effectively, yes. ISO 13485 threads risk-based thinking through the product lifecycle and relies on the methodology in ISO 14971:2019 for risk management. You need a documented risk management process and a risk management file for each device. We explain the relationship in ISO 14971 vs ISO 13485.

Can a contract manufacturer exclude design controls?

Yes, if you build strictly to a customer’s design and do not perform design and development activities. ISO 13485 permits excluding Clause 7.3, but the exclusion must be justified and documented in your QMS scope. You cannot exclude a requirement simply because it is burdensome — only because it genuinely does not apply to your role.

What causes most ISO 13485 audit findings?

CAPA weaknesses lead the list — actions that never close, root causes not genuinely identified, and effectiveness never verified. Document and record control, supplier controls, and process validation are also frequent finding areas. Our guide to common ISO 13485 QMS mistakes covers the recurring patterns.

Should I hire a consultant or use a documentation kit?

It depends on device class, internal capacity, and budget. Consultant-led implementations offer hands-on guidance but commonly run $15,000–$50,000 or more. A structured documentation kit gives you the full QMS architecture — manual, procedures, and record templates — at a fraction of that cost, so your team tailors rather than drafts from scratch. Many small manufacturers start with a kit and bring in targeted consulting only for device-specific risk and design questions.

What is ISO 13485 and who needs it?

ISO 13485 is the international quality management system standard for organizations involved in the medical device lifecycle — design, production, storage, distribution, installation, and servicing. It applies to manufacturers, specification developers, contract manufacturers, sterilization providers, and importers. Our primer, What Is ISO 13485?, covers the fundamentals.


📥 Free Resources

Practical tools to support your implementation — download what fits your project:

  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements, clause by clause, before committing to implementation.
  • ISO 9001 Roadmap — step-by-step implementation guide for organizations building or improving a quality management system, useful if you operate an ISO 9001 base alongside 13485.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.
  • AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification, for teams operating across aerospace and medical device lines.

Not Sure What to Do Next?

Your next step depends on where you are in the project:

  • 🔹 If you haven’t assessed your gap yet → start with the free ISO 13485 Gap Assessment Checklist. Don’t commit budget to implementation until you know the size of the gap.
  • 🔹 If you’re ready to build documentation → evaluate a complete ISO 13485 documentation kit before paying consultant rates to draft from scratch. It is the fastest route to an audit-ready document set for most small manufacturers.
  • 🔹 If you’re comparing the US and international paths → read FDA QSR vs ISO 13485 and how much ISO 13485 costs to scope budget and timeline before you choose.

Building an ISO 13485 QMS is a real project, but it is a known one. The clauses are fixed, the phases are sequential, and the failure modes are predictable. Move through it in order, build real evidence as you go, and inspect yourself before anyone else does — and a certification audit or FDA inspection becomes a confirmation, not a gamble. The Standards Navigator exists to make exactly this kind of industrial compliance work clear and survivable for the people who have to actually do it.


Most teams don’t fail ISO 13485 because they misunderstand the standard — they fail because they assumed they were compliant and found out during the audit. The organizations that struggle treat the QMS as paperwork to satisfy a registrar. The organizations that succeed treat it as the operating system that proves their devices are safe — and they build evidence from day one.

The Standards Navigator covers medical device compliance from QMSR readiness to risk management, CAPA, and certification — written from operational and quality management experience, not generic theory.

  • 👉 Get updates on medical device QMS, ISO 13485, and FDA QMSR compliance
  • 👉 Be first to access new gap assessment tools, documentation guides, and implementation resources

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

ISO 13485 Documentation Requirements (2026)

Every document and record ISO 13485 requires — with clause references, document control requirements under Section 4.2, record retention rules, how QMSR changed the documentation landscape, and the seven gaps auditors find most consistently. Built as a reference document quality managers can use before their next audit.

Every document your QMS must have, what auditors check first, and why the gaps between your procedures and your records are where most findings live.

Last Updated: May 2026


Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items covering ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


The Binder on the Shelf Is Not a QMS

Years ago, working in a nuclear component facility, I watched a certification audit go sideways in the first thirty minutes. The quality manager had spent six months building what looked like a complete quality management system — binders, procedures, forms, the works. The auditor asked to see the document register. The quality manager pointed to the binder. The auditor asked how documents were controlled at the point of use. The quality manager pointed to the binder again.

The binder was the system. It sat on a shelf in the quality office. The machinists on the floor had printed copies of procedures from three years prior. Nobody had a current revision of anything. The audit did not go well.

ISO 13485 documentation is not about having paperwork. It is about having the right documents, in the right format, accessible to the right people, at the right time — and being able to prove all of that during an audit. The standard is specific about what must be documented, what must be retained as records, and what that documentation must demonstrate.

Under QMSR, which took effect February 2, 2026, FDA now evaluates ISO 13485 documentation requirements against the framework directly. Organizations that treat documentation as a filing exercise rather than a quality system function are finding that gap at inspection.

This article covers every documentation requirement ISO 13485 imposes, where auditors look first, and what a compliant documentation system actually looks like in practice.


In This Guide

  • The difference between documents and records under ISO 13485 — and why it matters for audits
  • Every mandatory document the standard requires
  • Every mandatory record the standard requires
  • Document control requirements under Section 4.2
  • Record retention rules under Section 4.2.5
  • The most common documentation gaps auditors find
  • How QMSR changed the documentation landscape for U.S. medical device manufacturers
  • Decision-stage guidance for organizations at different points in their documentation journey


Start Here (Top Resources)

🔖 Get ISO 13485:2016 → ANSI Webstore — ANSI is the official U.S. distributor of ISO standards, ensuring you receive the controlled, compliant version required for certification audits. Use coupon CC2026 for 5% off.

🔖 Build compliant QMS documentation → 9001Simplified — 9001Simplified provides ready-to-use documentation kits that dramatically reduce the internal labor required to build a compliant QMS from scratch.

🔖 Train your team on ISO 13485 documentation requirements → BSI Group — BSI Group is a founding member of ISO and one of the world’s largest providers of ISO training courses, recognized by certification bodies globally.

🔖 Pursue or maintain ISO 13485 certification → ISOQAR — ISOQAR is a UKAS-accredited certification body — one of the most recognized in the industry for ISO management system certification.

Browse the What Is ISO 13485? pillar article for full clause context, or use the ISO 13485 Gap Assessment Checklist to identify your specific documentation gaps before your next audit.


Documents vs. Records: The Distinction That Drives Compliance

ISO 13485 treats documents and records as separate categories with different requirements. Confusing them is one of the most consistent sources of documentation findings in surveillance audits.

Documents are instructions, procedures, specifications, and plans — the things that tell people what to do. They are living documents: they can be revised, updated, and superseded. Section 4.2.4 governs their control.

Records are evidence that something was done — completed forms, test results, inspection reports, calibration data, training sign-offs. They are fixed in time: once a record is created, it cannot be altered without creating a documented amendment. Section 4.2.5 governs their control.

The practical distinction matters for two reasons. First, the control requirements differ. Documents need revision control, approval, distribution, and obsolescence management. Records need legibility, identification, storage protection, retrieval, and defined retention periods. A documentation system that applies the same controls to both will have gaps in one or the other.

Second, auditors evaluate them separately. When an auditor asks for a procedure, they are asking for a document. When they ask for evidence, they are asking for a record. Handing an auditor a completed form when they asked for a procedure — or a procedure when they asked for evidence — signals a documentation system that does not understand its own structure.

At this point, most quality managers building or auditing a documentation system should: → Map your document inventory against your record inventory separately. If your document register includes completed forms alongside controlled procedures, your system architecture has a structural problem. 9001Simplified’s documentation kits include pre-structured document and record registers built for ISO 13485 compliance. 9001Simplified provides ready-to-use documentation kits that dramatically reduce the internal labor required to build a compliant QMS from scratch.


Mandatory Documents Under ISO 13485

ISO 13485 requires specific documented procedures and plans across multiple clauses. These are not optional — certification bodies audit for their existence and their content.

ISO 13485 documentation infographic illustrating mandatory quality management system documents with interconnected process icons for quality manuals, risk management, design planning, procedures, records retention, purchasing controls, and document control requirements.
Certification bodies expect documented procedures, controlled records, and defined plans that demonstrate the quality system operates consistently and remains audit ready — see the full list in the table below.
DocumentClauseWhat It Must Cover
Quality Manual4.2.2Scope of the QMS, exclusions with justification, documented procedures or references, description of QMS process interactions
Document Control Procedure4.2.4Approval, review, revision control, distribution, obsolescence management, external documents
Records Control Procedure4.2.5Identification, storage, protection, retrieval, retention periods, disposition
Management Review Procedure5.6Inputs, outputs, frequency, documentation requirements
Competence, Training & Awareness Procedure6.2How competence is determined, how training is delivered, how competence is evaluated and recorded
Infrastructure Procedure6.3Maintenance of buildings, equipment, and supporting services affecting product quality
Work Environment Procedure6.4Control of work environment conditions where required for product conformity
Risk Management Procedure7.1Risk management process across the product lifecycle, per ISO 14971
Customer-Related Processes Procedure7.2Requirements determination, review, and customer communication
Design & Development Procedure7.3Planning, inputs, outputs, review, verification, validation, transfer, changes (if design is not excluded)
Purchasing Procedure7.4Supplier evaluation, selection, monitoring, and purchasing information
Production & Service Controls Procedure7.5Control of production and service provision, cleanliness, installation, and servicing
Identification & Traceability Procedure7.5.3Product identification throughout realization and traceability requirements
Customer Property Procedure7.5.4Control and safeguarding of customer-supplied product or data
Preservation Procedure7.5.5Preservation of product during processing and delivery
Monitoring & Measurement Equipment Procedure7.6Calibration, verification, and control of measuring equipment
Feedback Procedure8.2.1Post-market surveillance and feedback collection
Complaint Handling Procedure8.2.2Complaint receipt, investigation, and regulatory reporting decisions
Internal Audit Procedure8.2.4Audit planning, conduct, reporting, and follow-up
Nonconforming Product Procedure8.3Identification, segregation, evaluation, and disposition
CAPA Procedure8.5.2 / 8.5.3Corrective and preventive action process, including root cause analysis and effectiveness verification

⚠️ If your organization excludes design and development under Clause 7.3, that exclusion must be justified in the Quality Manual and documented. Exclusions without documented justification are a consistent finding in initial certification audits.


📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items covering ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


Mandatory Records Under ISO 13485

Records are the evidence your QMS operated as documented. The standard specifies which records must be maintained — these are the minimum. Your procedures may require additional records.

RecordClauseWhat It Must Demonstrate
Management Review Minutes5.6.3Inputs reviewed, decisions made, actions assigned with owners and timelines
Education, Training, Skills & Experience6.2Competence evaluated, training completed, results recorded
Infrastructure Maintenance6.3Maintenance activities and results for quality-critical equipment
Risk Management Records7.1Risk analysis, risk evaluation, risk control, residual risk assessment, post-production monitoring
Customer Requirements Review7.2.2Requirements determined and confirmed before commitment
Design & Development Records7.3Inputs, outputs, reviews, verifications, validations, transfer, and changes (if not excluded)
Design & Development Changes7.3.9Change description, evaluation, verification, validation, approval
Supplier Evaluation Records7.4.1Evaluation criteria, results, and re-evaluation decisions
Production Process Validation7.5.2Validation protocols, results, equipment qualifications
Traceability Records7.5.3.2Unique device identification and traceability through production
Customer Property Records7.5.4Receipt, condition assessment, and disposition of customer property
Calibration Records7.6Equipment identification, calibration standard, results, next due date
Internal Audit Records8.2.4Audit plans, findings, nonconformances, corrective actions, follow-up
Product Monitoring & Measurement8.2.6Evidence of conformity and identification of release authority
Nonconforming Product Records8.3Nature of nonconformity, disposition decision, concession records if applicable
CAPA Records8.5.2 / 8.5.3Root cause analysis, action taken, effectiveness verification with criteria and evidence

➡️ 9001Simplified Documentation Kits — Pre-built ISO 13485 procedures, forms, and record templates covering every mandatory document and record listed above. 9001Simplified provides ready-to-use documentation kits that dramatically reduce the internal labor required to build a compliant QMS from scratch.


Document Control: What Section 4.2.4 Actually Requires

Section 4.2.4 sets out seven specific requirements for document control. Each one has a practical implementation implication — and each one is evaluated individually during audits.

1. Documents must be approved before use. Approval must be by authorized personnel. Your document control procedure must define who has approval authority for each document type. A document approved by someone outside that authority — or with no documented approval at all — is a nonconformance.

2. Documents must be reviewed, updated as necessary, and re-approved. Review frequency should be defined in your procedure. Documents that have never been reviewed since initial creation are a finding in surveillance audits — particularly if the regulatory environment or production process has changed.

3. Changes and current revision status must be identified. Every controlled document needs a revision identifier — a number, letter, or date — and your document register needs to reflect current revision status. Auditors check this against what is in use.

4. Relevant versions must be available at points of use. This is the binder-on-the-shelf failure. Current controlled versions must be accessible where work is performed. If people work from printed copies, you need a controlled printing process. If work is performed on a production floor, current procedures must be accessible there — not only in the quality office.

5. Documents must be legible and identifiable. This sounds obvious. It is consistently violated by organizations that allow handwritten annotations, informal updates, or degraded printed copies to remain in service.

6. External documents must be identified and controlled. This includes customer drawings, regulatory guidance documents, referenced standards, and supplier specifications. External documents that affect product quality must be listed in your document control system and their current version verified.

7. Obsolete documents must be prevented from unintended use. Obsolete documents must either be removed from all points of use or clearly marked as obsolete. Finding an active workstation with a superseded procedure is a major nonconformance — regardless of whether anyone was actually using it.

If you are under active FDA inspection pressure → BSI Group ISO 13485 Training covers document control implementation and audit preparation in depth. BSI Group is a founding member of ISO and one of the world’s largest providers of ISO training courses, recognized by certification bodies globally.


Record Retention: What Section 4.2.5 Actually Requires

Section 4.2.5 requires that records be retained for a period at least equal to the lifetime of the medical device, but not less than two years from the date of product release by the organization.

That two-year floor is the minimum. In practice, most medical device records should be retained significantly longer:

  • Implantable devices — the device lifetime may span decades. Records need to match.
  • Devices with long service lives — the same logic applies.
  • FDA QMSR requirements — align with ISO 13485 on the two-year minimum but your complaint handling procedure may require longer retention for MDR-related records.
  • Customer contractual requirements — OEM customers increasingly specify record retention periods in their supplier quality agreements. These requirements take precedence where they are more stringent than the standard’s minimum.

Your records control procedure must define retention periods for each record type. A blanket “two years” policy applied to all records — including design history files and risk management records for long-life devices — is not compliant.

ProviderWhat You GetBest For
ANSI WebstoreISO 13485:2016 official standardAny organization needing the controlled, compliant version of the standard
9001SimplifiedQMS documentation kits with record templatesOrganizations building documentation from scratch or rebuilding after a major finding
BSI GroupISO 13485 training coursesTeams implementing documentation systems or preparing for initial certification
ISOQARISO 13485 certificationOrganizations ready to pursue or maintain certification

Most organizations building documentation systems from scratch need all three:

This combination covers the standard, the knowledge, and the implementation infrastructure.


The Most Common Documentation Gaps

ISO 13485 documentation gaps infographic illustrating seven common audit findings, including outdated document registers, incomplete supplier records, weak CAPA evidence, missing procedures, and disconnected risk management records within medical device quality systems.
Documentation failures rarely appear as isolated findings. They create chains of audit problems across CAPA, supplier controls, training, management review, and risk management. The gap is usually discovered long after it was created.

These are the findings that appear most consistently in ISO 13485 surveillance audits and QMSR inspections. Each one points to a specific procedure or record requirement.

The Quality Manual references procedures that don’t exist. A common initial certification shortcut is writing a Quality Manual that references a full set of documented procedures — then discovering during the surveillance audit that several of those procedures were never finalized. The Quality Manual and the document register must be synchronized.

The document register is not current. Document registers that haven’t been updated in months, that show revision numbers inconsistent with what is in use, or that are missing entire document categories are a consistent finding. The register is the first thing many auditors check.

Risk management records stop at design transfer. ISO 14971 requires risk management across the product lifecycle. Design-phase risk files with no post-production updates — no connection to complaint data, service reports, or CAPA findings — are incomplete regardless of how thorough the original analysis was. See ISO 14971 vs ISO 13485 for the full lifecycle requirement.

CAPA records close without effectiveness verification evidence. A CAPA record that reads “action implemented — problem resolved” with no supporting data is not a closed CAPA — it is an open finding waiting to be issued. For the complete breakdown of what effectiveness verification requires, see CAPA Requirements in ISO 13485.

Supplier qualification records are incomplete or outdated. An approved supplier list without corresponding qualification evidence, or qualification records for suppliers whose scope has changed without requalification, are consistently cited findings under Clause 7.4.

Training records prove attendance, not competence. Sign-off sheets showing who attended a training session are not competence records. The record must show what competence was evaluated, by what method, and what the result was. See Common Mistakes in ISO 13485 QMS for the full breakdown of this finding.

Management review minutes record presentations, not decisions. Minutes that describe what was presented in management review without documenting what was decided are a major finding under Section 5.6.3. Every input reviewed must produce a documented output — a decision, an action, or a rationale for no action.


How QMSR Changed the Documentation Landscape

FDA’s Quality Management System Regulation, effective February 2, 2026, aligns U.S. medical device QMS requirements with ISO 13485:2016. For documentation, the practical changes are significant.

The Device Master Record (DMR) structure is now explicitly required. Under QMSR, the DMR — which must include device specifications, production process specifications, quality assurance procedures, packaging and labeling specifications, and installation and maintenance procedures — is a specific documentation requirement that ISO 13485 certification alone does not fully address.

Complaint files under 21 CFR 820.198 remain a separate requirement. ISO 13485 requires a complaint handling procedure. QMSR additionally requires that complaint files contain specific elements — including the decision on whether the complaint required investigation and, if so, the results of that investigation — that go beyond what most ISO 13485 complaint procedures specify.

MDR procedures must be documented separately. Medical Device Reporting obligations are a regulatory requirement that sits outside ISO 13485 but must be addressed in your QMS documentation under QMSR.

⚠️ FDA QMSR compliance date was February 2, 2026. If your documentation system has not been reviewed against the four QMSR-specific bridge requirements since that date, that review is overdue. The ISO 13485 Gap Assessment Checklist covers all four QMSR bridge requirements explicitly alongside the standard ISO 13485 clause requirements.

For the full regulatory alignment picture, see FDA QSR vs ISO 13485.

Infographic explaining the major operational and regulatory changes introduced under the FDA QMSR, including terminology alignment, expanded risk management, inspection changes, and ISO 13485 document control requirements.
The FDA’s QMSR transition introduced major changes beyond terminology — expanding risk management expectations, changing inspection structure, and aligning medical device quality systems directly with ISO 13485.

Why Organizations Delay Getting Documentation Right

“We’ll clean it up before the surveillance audit.”

This is the most common delay rationalization — and it consistently produces the worst outcomes. Documentation gaps that accumulate over 11 months cannot be credibly remediated in the 30 days before a surveillance visit. Auditors can identify recently created records. A CAPA file dated three weeks before the audit for a problem that complaint data shows has existed for eight months is not evidence of a functioning QMS — it is evidence of audit preparation, which auditors treat as a different category of finding.

“Our documentation was good enough for initial certification.”

Initial certification evaluates documentation at a point in time against a system that was built to be audited. Surveillance audits evaluate whether that system has been maintained — which means they look at records created since the last audit, not at procedures written before it. Organizations that passed initial certification and then stopped maintaining their documentation systems often face multiple major nonconformances at the first surveillance visit.

“We don’t have the internal resources to build this properly.”

This objection is real — but the cost of building documentation properly before certification is substantially lower than the cost of remediation after a major nonconformance. A documentation kit from 9001Simplified covers every mandatory document and record template in a ready-to-use format. 9001Simplified provides ready-to-use documentation kits that dramatically reduce the internal labor required to build a compliant QMS from scratch. The internal labor required to customize a pre-built kit is a fraction of what is required to build from scratch — and a fraction of what remediation costs after a finding.


Frequently Asked Questions

What documents are required by ISO 13485?

ISO 13485 requires documented procedures covering quality manual, document control, records control, management review, training and competence, risk management, customer requirements, purchasing, production controls, identification and traceability, calibration, feedback, complaint handling, internal audit, nonconforming product, and CAPA. The full list with clause references is in the Mandatory Documents table above.

What records are required by ISO 13485?

ISO 13485 requires records covering management reviews, training and competence evaluations, risk management activities, design and development (if not excluded), supplier evaluations, calibration, internal audits, product monitoring, nonconforming product dispositions, and CAPA activities. The full list with clause references is in the Mandatory Records table above.

How long must ISO 13485 records be retained?

The standard requires retention for at least the lifetime of the device, with a minimum of two years from product release. For implantable devices and devices with long service lives, the retention period is typically longer and should be defined in your records control procedure. FDA QMSR aligns with this minimum but specific record types — particularly MDR-related records — may require longer retention.

Does ISO 13485 require a Quality Manual?

Yes. Section 4.2.2 requires a Quality Manual that defines the scope of the QMS, documents or references procedures, and describes the interactions between QMS processes. The Quality Manual is one of the first documents an auditor requests.

Can we use electronic records to meet ISO 13485 requirements?

Yes — electronic records are acceptable provided your document control system ensures they are controlled, legible, retrievable, and protected from unauthorized modification. Electronic systems used to manage controlled documents must themselves be validated if they affect product quality.

What is the difference between a controlled document and a record under ISO 13485?

A controlled document is an instruction, procedure, or specification that tells people what to do — it can be revised and must be version-controlled. A record is evidence that something was done — it is fixed in time and must be retained according to your records control procedure. Section 4.2.4 governs controlled documents; Section 4.2.5 governs records. The distinction is fundamental to building a compliant documentation system.

Does design and development documentation apply to all medical device manufacturers?

Only if the manufacturer performs design and development activities. If your organization manufactures to customer specifications and does not perform design activities, you may be eligible to exclude Clause 7.3 — but that exclusion must be documented and justified in your Quality Manual. Contract manufacturers who claim a 7.3 exclusion without justification are consistently cited at initial certification.

How do FDA QMSR documentation requirements differ from ISO 13485?

QMSR aligns with ISO 13485 but adds four specific requirements: the Device Master Record structure, complaint files under 21 CFR 820.198, Medical Device Reporting procedures, and corrections and removals procedures. ISO 13485 certification alone does not cover these four requirements. The ISO 13485 Gap Assessment Checklist addresses all four explicitly.

What is the first thing an auditor looks at for ISO 13485 documentation?

Most auditors start with the document register — to verify that controlled documents are listed, revision levels are current, and the register reflects what is actually in use. From there they move to the Quality Manual to verify scope and procedure references. Gaps in either of those two items typically expand the audit’s scope significantly.


Free Resources

📋 Free Download: Manufacturing Compliance Checklist — ISO 9001, 14001, 45001 & OSHA — 50 items with gap scoring across all systems.

📋 Free Download: Supplier Quality Checklist — ISO 9001 Clause 8.4 — all supplier controls auditors evaluate, 45 items with scoring.

📋 Free Download: ISO 9001 Implementation Roadmap — The exact 5-phase process from gap assessment to Stage 2 audit clearance.

📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items — ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


Not Sure What to Do Next?

→ You need the official ISO 13485:2016 standard → ANSI Webstore — Use CC2026 for 5% off. ANSI is the official U.S. distributor of ISO standards.

→ You need to build ISO 13485 documentation from scratch → 9001Simplified Documentation Kits — ready-to-use procedures, forms, and record templates for every mandatory document.

→ You need to train your team on documentation requirements → BSI Group ISO 13485 Training — BSI Group is a founding member of ISO and one of the world’s largest providers of ISO training courses.

→ You are ready to pursue ISO 13485 certification → ISOQAR — UKAS-accredited, one of the most recognized certification bodies in the industry.

→ You need to assess your documentation gaps before your next audit → ISO 13485 Gap Assessment Checklist — free, 64 items.

→ You need to understand how QMSR changed your documentation obligations → FDA QSR vs ISO 13485

→ You need to understand CAPA record requirements in depth → CAPA Requirements in ISO 13485

→ You need to understand the most common documentation audit findings → Common Mistakes in ISO 13485 QMS

→ You need to understand how risk management documentation connects to your QMS → ISO 14971 vs ISO 13485

→ You need to understand the full ISO 13485 clause structure → What Is ISO 13485?

→ You want to buy ISO 13485 → Buy ISO 13485

→ You want to browse all medical device standards → explore standards by compliance area


Still figuring out where to start?

If you are not ready to commit to a documentation build yet — that is normal. Most organizations spend several weeks between identifying gaps and starting remediation.

The best next step: → Download the free ISO 13485 Gap Assessment Checklist — it takes 20 minutes and tells you exactly which documents and records you are missing before you spend anything.

Feature image promoting an ISO 13485 Gap Assessment Checklist for medical device manufacturers, contract manufacturers, and component suppliers preparing for certification and FDA QMSR compliance.
ISO 13485 Gap Assessment Checklist designed to help medical device manufacturers identify compliance gaps, prioritize actions, and prepare for certification and FDA QMSR requirements.

📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items — ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


The Binder Is Not the System

Documentation is not ISO 13485’s most technically demanding requirement. But it is the foundation every other requirement rests on. Without controlled documents, procedures cannot be consistently followed. Without records, there is no evidence that procedures were followed at all. Without a document control system that connects what is written to what people actually use, the gap between those two things grows quietly — until an auditor measures it.

The organizations that handle documentation audits well are not the ones with the most sophisticated quality management software or the thickest procedure binders. They are the ones whose documentation reflects how work actually gets done — current, accessible, and connected to the records that prove it.

That alignment takes discipline to build and discipline to maintain. It does not take complexity.

At The Standards Navigator, complex standards are translated into practical, real-world guidance you can act on.

Subscribe below to stay ahead.

Subscribe

* indicates required