AQC Group regional partnerIraq

ISO 13485:2016Medical devices quality management systems

ISO 13485 is the quality management standard written for medical devices and for regulatory purposes. It asks an organization to show that it can consistently provide devices and related services that meet customer requirements and the regulatory requirements that apply to them. A certificate shows that the quality system has been audited. It is not a product approval, and it does not by itself allow a device onto any market.

Two people in cleanroom suits reading a tablet

01At a glance

Standard
ISO 13485:2016
Subject
Medical devices quality management systems
Certificate
Issued by AQC Group. Valid for three years, with a surveillance audit each year.
Often combined with
ISO 9001, ISO/IEC 27001, ISO 14001
Facts checked
9 October 2026, against iso.org

Who it is for

  • Medical device manufacturers
  • Contract manufacturers and component suppliers
  • Importers and distributors of medical devices
  • Sterilization and calibration service providers
  • Companies that install, service or repair devices
  • Developers of software that is a medical device

02What you gain

What certification to ISO 13485 gives you

A system regulators and buyers recognize

Regulators in many countries base their quality system rules for medical devices on ISO 13485 or accept it as evidence. Hospitals, distributors and device manufacturers ask for it in tenders and when they approve suppliers.

Supplying other manufacturers

Device manufacturers have to control their suppliers. A component maker, contract manufacturer or sterilization provider that holds the certificate is easier for them to approve.

Traceability when something goes wrong

Records link each device or batch to its materials, its processes and its customers. If a complaint or a field action comes, you can find the affected units and act on them.

Risk kept in view

Decisions in design, purchasing, production and servicing are made with the risk of the product in mind and are recorded, so they can be explained later to a customer or an authority.

Complaints that lead somewhere

Each complaint is recorded, investigated and checked against the reporting rules that apply to you. What is learned goes back into design and production.

03What it asks of you

What ISO 13485 asks you to have in place

In plain terms and in our words, not the standard's. The standard itself is the authority, and you will need a copy.

  1. Your role and the regulatory requirements that apply

    State what you do, whether that is design, manufacture, import, distribution, installation or servicing, and for which devices. Identify the regulatory requirements that apply to those activities in each market you supply, and build them into the system. Requirements that do not fit your activities or your devices, such as those for sterile product or installation, can be left out if you record the reason.

  2. A documented system

    The standard asks for more documents than ISO 9001 does. You need a quality manual, documented procedures for the activities it names, and a file for each device type or family that holds or points to its specifications and its instructions for manufacture, packaging, storage, handling and, where relevant, installation and servicing. Records are kept for at least the lifetime you define for the device.

  3. Management, people and premises

    Top management sets a quality policy and objectives, appoints a management representative and reviews the system at planned intervals. People whose work affects product quality are trained, and you check that the training worked. Buildings, equipment and the work environment are suitable, with documented controls for cleanliness and contamination where the product needs them.

  4. Risk management

    Apply a risk-based approach to the processes of the quality system, and document how risk is managed through the whole of product realization, from design input to servicing. ISO 14971 is the companion standard for this.

  5. Design and development

    Plan each design project in stages. Record the inputs, including intended use, safety and regulatory requirements. Review the design at planned points, verify that the outputs meet the inputs, and validate that the finished device does what its users need. Control the transfer of the design to production and every later design change, and keep a design and development file for each device type or family.

  6. Purchasing and suppliers

    Select suppliers by their ability to meet your requirements, with more control where the risk of what they supply is higher. Agree in writing that they tell you about changes before they make them. Verify what you receive. A process you outsource remains your responsibility.

  7. Production, validation and traceability

    Produce under controlled conditions, with a record for each device or batch that shows how many were made and how many were released. Validate any process whose result cannot be fully checked afterwards, such as sterilization or sealing, and validate software used in production and in the quality system. Identify product at every stage and be able to trace it. Implantable devices need fuller traceability, down to components and to where each unit was shipped.

  8. Feedback, complaints and corrective action

    Gather information from production and from the market on whether your devices meet requirements. Handle complaints promptly by a documented procedure, decide whether each must be reported to a regulatory authority, and issue advisory notices when they are needed. Control nonconforming product, including product already delivered. Investigate causes, take corrective and preventive action and check that it was effective.

04The audit

How certification to ISO 13485 works

  1. Application and quotation

    You tell us your scope, sites and headcount. We quote the audit days the standard's rules require.

  2. Stage 1 audit

    A review of your documented system and your readiness. You get a list of anything to settle before stage 2.

  3. Stage 2 audit

    The auditor follows your processes on site and samples records, to see that the system is in use and works.

  4. Decision

    Nonconformities are answered, the file is reviewed independently of the audit team, and AQC Group issues the certificate.

  5. Surveillance and recertification

    A shorter audit in each of the next two years, then a full recertification audit in the third.

What the auditor looks at

  • Device files and, where design is in scope, design and development files for a sample of devices
  • Risk management records, and how they feed decisions in design, purchasing and production
  • Validation of processes such as sterilization and sealing, and of software used in production or in the quality system
  • Batch or device records, traceability and the control of nonconforming product
  • Complaint handling, decisions on reporting to authorities, and corrective and preventive action
  • Supplier evaluation and the control of outsourced processes

What affects audit time

  • The number of people working within the scope, and the number of sites
  • Whether design and development is in the scope
  • The range and kind of devices: sterile, implantable or active devices and software bring more processes to audit
  • How much is outsourced, since the control of critical suppliers has to be examined

How certification works, step by step

06Questions

Questions about ISO 13485

Does ISO 13485 certification allow us to sell our device?

No. The certificate says that your quality management system meets the standard. It says nothing about whether a particular device is safe, effective or approved. Approval to place a device on a market is given under the rules of each country or region, and those rules usually ask for more than a quality system, such as technical documentation and product registration.

Many regulatory systems expect or recognize an ISO 13485 quality system as one part of that. Check the legal requirements that apply to you in each market you supply.

We are certified to ISO 9001. How much more is ISO 13485?

It is a separate standard, not an addition to ISO 9001. ISO 13485 follows the structure of an earlier edition of ISO 9001 and adds requirements specific to medical devices: device files, risk management in product realization, validation of processes and software, cleanliness, traceability, complaint handling and reporting to authorities. It puts less weight on customer satisfaction and continual improvement, and more on meeting requirements and keeping the system effective.

Certification to one does not show conformity to the other. Organizations that want both run one system and are audited against each standard.

We only import and distribute devices. Does it apply to us?

It can. The standard covers organizations at any stage of a device's life: design, production, storage and distribution, installation, servicing, and the supply of components or related services. A distributor or importer leaves out what it does not do, such as design and production, and is audited on what it does: supplier control, storage conditions, records of what was shipped to whom, complaint handling and field actions.

Is ISO 13485:2016 still the current edition?

Yes. ISO reviewed the standard and confirmed it in 2025, so the 2016 edition remains current. It keeps its own clause structure and does not use the common structure of ISO 9001 and most other management system standards. That matters if you plan to combine it with them.

Do we need ISO 14971 as well?

ISO 13485 asks for documented risk management throughout product realization but does not say how to do it. ISO 14971 is the international standard for applying risk management to medical devices, and it is the usual way to meet that requirement. You do not need a separate certificate for it. The auditor looks at your risk management records as part of the ISO 13485 audit.

More questions about certification

Ask about ISO 13485 for your organization.

Tell us your scope, your sites and how many people work in them. We will tell you what the audit involves.