Notified Bodies & Certification

Conformity-assessment and certification organizations — auditing quality management systems and issuing the ISO and EU MDR/IVDR certifications that let regulated products reach market.

What this page does not claim

A sector is an organization’s role in the value chain, not a legal category. SPEQ maps the disciplines and standards that role typically operates under; it does not determine which apply to your organization, and a count of decoded standards measures SPEQ’s coverage.

WHAT THIS SECTOR DOES

Notified bodies and certification organizations are the independent third parties that assess whether a manufacturer’s quality system and product conform to the applicable standard — and issue the certificate that lets the product reach market. For medical devices they perform the conformity assessment behind an EU MDR/IVDR CE mark; more broadly they certify management systems against ISO standards. Their independence and competence are the reason a certificate means something.

REGULATORY LANDSCAPE

Device conformity assessment runs on EU MDR (2017/745) and IVDR (2017/746), evaluating the manufacturer’s ISO 13485 quality system, ISO 14971 risk management, and IEC 62304 software lifecycle. Management-system certification bodies operate to ISO/IEC 17021, and the notified bodies themselves are designated and monitored by competent authorities. The certificate is only as credible as the assessor’s accreditation and impartiality.

THE OVERSIGHT MODEL

The relationship is inverted from the rest of the value chain: here the organization is itself the auditor. The manufacturer holds responsibility for its product and quality system; the notified body independently assesses conformity and must remain impartial — it cannot consult on the same system it certifies. Competent authorities, in turn, oversee the notified bodies, so the accountability chain runs manufacturer → notified body → competent authority.

WHAT QUALITY MEANS HERE

01

Conformity assessment (MDR/IVDR)

Evaluating technical documentation, the QMS, and clinical/performance evidence against EU MDR/IVDR before a CE certificate is issued.

02

Impartiality & competence

ISO/IEC 17021 independence, freedom from conflict of interest, and demonstrable assessor competence — the basis on which any certificate is trusted.

03

QMS & risk auditing

Auditing the manufacturer’s ISO 13485 quality system and ISO 14971 risk management, including software lifecycle controls under IEC 62304.

04

Surveillance & recertification

Ongoing surveillance audits and unannounced inspections that keep a certificate meaningful across its lifecycle, not just at issue.

56
Standards decoded
2
GxP disciplines

STANDARDS SPEQ DECODES · 56

Open the full library →
21 CFR Part 11FDAHIGH INSPECTION RISK
Electronic Records; Electronic Signatures
21 CFR Part 820FDAHIGH INSPECTION RISK
Quality Management System Regulation (QMSR) — 21 CFR Part 820
EU GMP Annex 11EMAHIGH INSPECTION RISK
Computerised Systems
EU GMP Annex 22EC
Artificial Intelligence
ICH Q9(R1)ICH
Quality Risk Management
ICH Q10ICH
Pharmaceutical Quality System
ISO 9001:2015ISO
Quality Management Systems — Requirements
ISO 13485:2016ISO
Medical Devices — Quality Management Systems — Requirements for Regulatory Purposes
ISPE GAMP 5 (2022)ISPE
Good Practice Guide: Compliant GxP Computerised Systems
MHLW Ordinance No. 136MHLW
Japan GQP — Quality Management for Marketing Authorisation Holders
ISO 14971:2019ISO
Medical Devices — Application of Risk Management to Medical Devices
ISO 22000:2018ISO
Food safety management systems — Requirements for any organization in the food chain
Regulation (EU) 2017/745ECHIGH INSPECTION RISK
Medical Device Regulation (MDR)
21 CFR Part 803FDAHIGH INSPECTION RISK
Medical Device Reporting (MDR)
IEC 62304:2006+A1:2015IEC
Medical Device Software — Software Life Cycle Processes
IEC 60601-1IEC
Medical Electrical Equipment — General Requirements for Basic Safety and Essential Performance
MoCRA (FD&C Act Ch. VI)FDA
Modernization of Cosmetics Regulation Act of 2022
Regulation (EC) No 1223/2009EC
EU Cosmetic Products Regulation
IMDRF/SaMD WG/N10IMDRF
Software as a Medical Device (SaMD): Key Definitions
IMDRF/SaMD WG/N12IMDRF
SaMD: Possible Framework for Risk Categorization and Corresponding Considerations
ISO/IEC 17025:2017ISO
General requirements for the competence of testing and calibration laboratories
ILAC MRAILAC
ILAC Mutual Recognition Arrangement
GS1 General SpecificationsGS1
GS1 General Specifications — identification keys, data attributes and barcodes
21 CFR Part 4FDAHIGH INSPECTION RISK
Regulation of Combination Products (cGMP Requirements)
ISO 20916:2019ISO
In vitro diagnostic medical devices — Clinical performance studies using specimens from human subjects
ISO 17665:2024ISOHIGH INSPECTION RISK
Sterilization of Health Care Products — Moist Heat — Requirements for the Development, Validation and Routine Control of a Sterilization Process for Medical Devices
ISO 11135:2014ISOHIGH INSPECTION RISK
Sterilization of Health-Care Products — Ethylene Oxide — Requirements for the Development, Validation and Routine Control of a Sterilization Process for Medical Devices
ISO 10993-1:2018ISOHIGH INSPECTION RISK
Biological Evaluation of Medical Devices — Part 1: Evaluation and Testing Within a Risk Management Process
ISO 14155:2026ISOHIGH INSPECTION RISK
Clinical Investigation of Medical Devices for Human Subjects — Good Clinical Practice
FDA CSA Guidance (2026)FDAHIGH INSPECTION RISK
Computer Software Assurance for Production and Quality Management System Software
IEC 81001-5-1:2021IEC
Health Software and Health IT Systems Safety, Effectiveness and Security — Part 5-1: Security — Activities in the Product Life Cycle
FDA GPSV (2002)FDAHIGH INSPECTION RISK
General Principles of Software Validation
FDA Premarket Cybersecurity (2026)FDAHIGH INSPECTION RISK
Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions
FDA PCCP for AI-Enabled DSF (2024)FDA
Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions
IEC 82304-1:2016IEC
Health Software — Part 1: General Requirements for Product Safety
Regulation (EU) 2017/746ECHIGH INSPECTION RISK
In Vitro Diagnostic Medical Devices Regulation (IVDR)
21 CFR Part 830FDA
Unique Device Identification
21 CFR Part 806FDAHIGH INSPECTION RISK
Medical Devices; Reports of Corrections and Removals
IEC 62366-1:2015+A1:2020IEC
Medical Devices — Part 1: Application of Usability Engineering to Medical Devices
ISO 11607-1:2019ISO
Packaging for Terminally Sterilized Medical Devices — Part 1: Requirements for Materials, Sterile Barrier Systems and Packaging Systems
ISO 19011:2018ISO
Guidelines for Auditing Management Systems
ISO 11737-1:2018ISO
Sterilization of Health Care Products — Microbiological Methods — Part 1: Determination of a Population of Microorganisms on Products
ISO/IEC 27001:2022ISO
Information Security, Cybersecurity and Privacy Protection — Information Security Management Systems — Requirements
IEC 62443-2-1:2024IEC
Security for Industrial Automation and Control Systems — Part 2-1: Security Program Requirements for IACS Asset Owners
IEC 62443-3-3:2013IEC
Industrial Communication Networks — Network and System Security — Part 3-3: System Security Requirements and Security Levels
21 CFR Part 3FDA
Product Jurisdiction
21 CFR Part 202FDA
Prescription Drug Advertising
21 CFR Part 807FDA
Establishment Registration and Device Listing for Manufacturers and Initial Importers of Devices
ICH M4(R4)ICH
Organisation of the Common Technical Document for the Registration of Pharmaceuticals for Human Use
ICH M8 (eCTD v4.0)ICH
Electronic Common Technical Document (eCTD)
Directive 2001/83/ECEC
Community Code Relating to Medicinal Products for Human Use
Regulation (EU) 2016/679EC
General Data Protection Regulation (GDPR)
ISO 22301:2019ISO
Security and Resilience — Business Continuity Management Systems — Requirements
ISO 31000:2018ISO
Risk Management — Guidelines
ISO 45001:2018ISO
Occupational Health and Safety Management Systems — Requirements with Guidance for Use
ISO 14001:2015ISO
Environmental Management Systems — Requirements with Guidance for Use

WHERE QUALITY FAILS

  • Conflicts of interest that undermine the impartiality of the assessment
  • Inconsistent or under-scoped audits that let nonconforming product reach market
  • Assessor competence gaps for novel technologies or software-driven devices
  • Weak post-certification surveillance that misses a QMS drifting out of control

KEY REGULATORY BODIES

Derived from the 56 standards SPEQ decodes for this sector.

GXP DISCIPLINES IN THIS SECTOR

[ MAJOR CERTIFICATION & NOTIFIED BODIES ]

Accredited certification bodies audit management systems (ISO 9001, 13485, 22000, 42001); those tagged EU Notified Body are additionally designated for medical-device conformity assessment under the MDR/IVDR.

BSI Group

ISO 9001 / 13485 / 42001 certification and one of the largest MDR & IVDR Notified Bodies.

United Kingdom · EU Notified Body · Visit ↗

TÜV SÜD

Medical-device conformity assessment (MDR/IVDR), ISO 13485 and quality-system certification.

Germany · EU Notified Body · Visit ↗

TÜV Rheinland

Product safety, ISO 13485 / 9001 certification and medical-device conformity assessment.

Germany · EU Notified Body · Visit ↗

DEKRA

Medical-device Notified Body services and management-system certification.

Germany · EU Notified Body · Visit ↗

DNV

ISO 9001 / 13485 / 22000 certification, healthcare accreditation and management-system audits.

Norway · EU Notified Body · Visit ↗

SGS

Testing, inspection and certification across ISO 9001 / 13485 / 22000 and GMP audits.

Switzerland · EU Notified Body · Visit ↗

Intertek

Testing, inspection and management-system certification (ISO 9001 / 13485 / 22000).

United Kingdom · EU Notified Body · Visit ↗

UL Solutions

Product safety, medical-device testing and ISO 13485 / 9001 certification.

United States · Visit ↗

NSF

Food safety (ISO 22000, HACCP), dietary-supplement GMP and pharma quality certification.

United States · Visit ↗

DQS

Management-system certification (ISO 9001 / 13485 / 22000 / 42001) and audits.

Germany · EU Notified Body · Visit ↗

Lloyd’s Register (LRQA)

ISO 9001 / 13485 / 22000 certification and assurance / audit services.

United Kingdom · Visit ↗

Bureau Veritas

Testing, inspection and certification across ISO 9001 / 13485 / 22000 and GMP audits.

France · Visit ↗

A curated reference list of accredited bodies. SPEQ does not certify, accredit, or endorse any organization; Notified Body designations and accreditation scopes are held by the bodies themselves.

Notified Bodies & Certification: frequently asked questions

Reference answers on what a notified bodies & certification does, what governs it, and who is accountable for quality.

What is a Notified Body?

A Notified Body is an independent organization designated by an EU competent authority to assess whether a manufacturer’s product and quality system conform to the applicable regulation before the product reaches market. For medical devices it performs the conformity assessment behind a CE mark under the EU MDR (2017/745) or IVDR (2017/746). Its independence and competence are what make a certificate meaningful.

Which standards do notified bodies assess devices against?

Device conformity assessment runs on EU MDR (2017/745) and IVDR (2017/746), evaluating the manufacturer’s ISO 13485 quality system, ISO 14971 risk management, and IEC 62304 software lifecycle. Management-system certification bodies more broadly operate to ISO/IEC 17021.

How is a notified body’s independence maintained?

Notified bodies operate to ISO/IEC 17021 requirements for impartiality: they must be free of conflicts of interest and cannot consult on the same quality system they certify. They are designated and monitored by competent authorities, so the accountability chain runs manufacturer → notified body → competent authority. A certificate is only as credible as the assessor’s accreditation and impartiality.