Notified Bodies & Certification

Conformity-assessment and certification organizations — auditing quality management systems and issuing the ISO and EU MDR/IVDR certifications that let regulated products reach market.

Assess your quality system →Explore GxP disciplines →
WHAT THIS SECTOR DOES

Notified bodies and certification organizations are the independent third parties that assess whether a manufacturer’s quality system and product conform to the applicable standard — and issue the certificate that lets the product reach market. For medical devices they perform the conformity assessment behind an EU MDR/IVDR CE mark; more broadly they certify management systems against ISO standards. Their independence and competence are the reason a certificate means something.

REGULATORY LANDSCAPE

Device conformity assessment runs on EU MDR (2017/745) and IVDR (2017/746), evaluating the manufacturer’s ISO 13485 quality system, ISO 14971 risk management, and IEC 62304 software lifecycle. Management-system certification bodies operate to ISO/IEC 17021, and the notified bodies themselves are designated and monitored by competent authorities. The certificate is only as credible as the assessor’s accreditation and impartiality.

THE OVERSIGHT MODEL

The relationship is inverted from the rest of the value chain: here the organization is itself the auditor. The manufacturer holds responsibility for its product and quality system; the notified body independently assesses conformity and must remain impartial — it cannot consult on the same system it certifies. Competent authorities, in turn, oversee the notified bodies, so the accountability chain runs manufacturer → notified body → competent authority.

19
Standards decoded
2
GxP disciplines
WHAT QUALITY MEANS HERE
01

Conformity assessment (MDR/IVDR)

Evaluating technical documentation, the QMS, and clinical/performance evidence against EU MDR/IVDR before a CE certificate is issued.

02

Impartiality & competence

ISO/IEC 17021 independence, freedom from conflict of interest, and demonstrable assessor competence — the basis on which any certificate is trusted.

03

QMS & risk auditing

Auditing the manufacturer’s ISO 13485 quality system and ISO 14971 risk management, including software lifecycle controls under IEC 62304.

04

Surveillance & recertification

Ongoing surveillance audits and unannounced inspections that keep a certificate meaningful across its lifecycle, not just at issue.

GXP DISCIPLINES IN THIS SECTOR
CSVComputerised System ValidationQMSQuality Management Systems
STANDARDS SPEQ DECODES · 19
Open the full library →
21 CFR Part 11FDAHIGH INSPECTION RISK
Electronic Records; Electronic Signatures
21 CFR Part 820FDAHIGH INSPECTION RISK
Quality System Regulation (QSR) for Medical Devices
EU GMP Annex 11EMAHIGH INSPECTION RISK
Computerised Systems
ISO 9001:2015ISO
Quality Management Systems — Requirements
ISO 13485:2016ISO
Medical Devices — Quality Management Systems — Requirements for Regulatory Purposes
ISPE GAMP 5 (2022)ISPE
Good Practice Guide: Compliant GxP Computerised Systems
ISO 14971:2019ISO
Medical Devices — Application of Risk Management to Medical Devices
ISO 22000:2018ISO
Food safety management systems — Requirements for any organization in the food chain
Regulation (EU) 2017/745ECHIGH INSPECTION RISK
Medical Device Regulation (MDR)
21 CFR Part 803FDAHIGH INSPECTION RISK
Medical Device Reporting (MDR)
IEC 62304:2006+A1:2015IEC
Medical Device Software — Software Life Cycle Processes
IEC 60601-1IEC
Medical Electrical Equipment — General Requirements for Basic Safety and Essential Performance
MoCRA (FD&C Act Ch. VI)FDA
Modernization of Cosmetics Regulation Act of 2022
Regulation (EC) No 1223/2009EC
EU Cosmetic Products Regulation
IMDRF/SaMD WG/N10IMDRF
Software as a Medical Device (SaMD): Key Definitions
IMDRF/SaMD WG/N12IMDRF
SaMD: Possible Framework for Risk Categorization and Corresponding Considerations
ISO/IEC 17025:2017ISO
General requirements for the competence of testing and calibration laboratories
ILAC MRAILAC
ILAC Mutual Recognition Arrangement
GS1 General SpecificationsGS1
GS1 General Specifications — identification keys, data attributes and barcodes
WHERE QUALITY FAILS
  • Conflicts of interest that undermine the impartiality of the assessment
  • Inconsistent or under-scoped audits that let nonconforming product reach market
  • Assessor competence gaps for novel technologies or software-driven devices
  • Weak post-certification surveillance that misses a QMS drifting out of control
KEY REGULATORY BODIES
FDAEMAISOISPEECIECIMDRFILACGS1

Derived from the 19 standards SPEQ decodes for this sector.

[ MAJOR CERTIFICATION & NOTIFIED BODIES ]

The bodies that certify and assess the regulated value chain.

Accredited certification bodies audit management systems (ISO 9001, 13485, 22000, 42001); those tagged EU Notified Body are additionally designated for medical-device conformity assessment under the MDR/IVDR.

BSI GroupUnited Kingdom

ISO 9001 / 13485 / 42001 certification and one of the largest MDR & IVDR Notified Bodies.

EU NOTIFIED BODYVisit ↗
TÜV SÜDGermany

Medical-device conformity assessment (MDR/IVDR), ISO 13485 and quality-system certification.

EU NOTIFIED BODYVisit ↗
TÜV RheinlandGermany

Product safety, ISO 13485 / 9001 certification and medical-device conformity assessment.

EU NOTIFIED BODYVisit ↗
DEKRAGermany

Medical-device Notified Body services and management-system certification.

EU NOTIFIED BODYVisit ↗
DNVNorway

ISO 9001 / 13485 / 22000 certification, healthcare accreditation and management-system audits.

EU NOTIFIED BODYVisit ↗
SGSSwitzerland

Testing, inspection and certification across ISO 9001 / 13485 / 22000 and GMP audits.

EU NOTIFIED BODYVisit ↗
IntertekUnited Kingdom

Testing, inspection and management-system certification (ISO 9001 / 13485 / 22000).

EU NOTIFIED BODYVisit ↗
UL SolutionsUnited States

Product safety, medical-device testing and ISO 13485 / 9001 certification.

Visit ↗
NSFUnited States

Food safety (ISO 22000, HACCP), dietary-supplement GMP and pharma quality certification.

Visit ↗
DQSGermany

Management-system certification (ISO 9001 / 13485 / 22000 / 42001) and audits.

EU NOTIFIED BODYVisit ↗
Lloyd’s Register (LRQA)United Kingdom

ISO 9001 / 13485 / 22000 certification and assurance / audit services.

Visit ↗
Bureau VeritasFrance

Testing, inspection and certification across ISO 9001 / 13485 / 22000 and GMP audits.

Visit ↗

A curated reference list of accredited bodies. SPEQ does not certify, accredit, or endorse any organization; Notified Body designations and accreditation scopes are held by the bodies themselves.

REGULATED INDUSTRIES
The product industries this sector serves →
THE SPEQ FRAMEWORK
Regulatory intelligence → execution → maturity →
Weekly Briefing

Intelligence for Notified Bodies & Certification

The enforcement actions, guidance, and quality signals that shape sponsor–provider oversight — curated for Notified Bodies & Certification and delivered free each week.

Read a past issue →