ISOQuality Systems MaturityStandard
ISO 13485:2016

Medical Devices — Quality Management Systems — Requirements for Regulatory Purposes

Specifies requirements for a quality management system for organisations involved in the design, development, production, installation, and servicing of medical devices. Emphasises safety and effectiveness requirements distinct from general ISO 9001.

LAST REVISED
March 2016
PRODUCT AREAS
Devices

What this does not cover

stated in the document's own scope
  • Specifies QMS requirements; it does not itself specify the risk-management process, which it references out to ISO 14971.
  • Covers the management system, not the technical safety and performance of a particular device type — those come from product standards (for example IEC 60601-1 for medical electrical equipment).
  • Is a QMS standard for regulatory purposes, not a general business-excellence model; the continual-improvement/customer-satisfaction framing belongs to ISO 9001.
  • Does not grant market authorisation; conformity supports, but does not replace, the applicable regulatory clearance or CE-marking route.
SOURCE & PROVENANCE
ISSUING BODY
International Organization for Standardization
JURISDICTION
International
DOCUMENT ID
ISO 13485:2016
Official site — International Organization for Standardization

Always verify against the current published text before relying on it for a submission or inspection.

Overview

ISO 13485:2016 specifies the requirements for a quality management system where an organisation needs to demonstrate its ability to provide medical devices and related services that consistently meet customer and applicable regulatory requirements. It applies across the device lifecycle — design and development, production, storage and distribution, installation, servicing, and final decommissioning — and to suppliers and other external parties that provide these functions. Although it shares roots with ISO 9001, it is a stand-alone standard: its emphasis is regulatory compliance and the maintenance of effective processes (risk-based, documented, and traceable) rather than the continual-improvement and customer-satisfaction focus of the general QMS standard.

Scope & applicability

Medical device manufacturers, distributors, importers, and suppliers to the medical device industry. Required for CE marking under EU MDR/IVDR and expected by FDA under 21 CFR Part 820.

Legal basis & how it acquires force

ISO 13485 is a voluntary international consensus standard published by ISO; it is not law in itself. It acquires force through adoption and reference. In the European Union it is a harmonised standard supporting the Medical Device Regulation (EU) 2017/745 and the IVDR (EU) 2017/746, so conformity gives a presumption of conformity with the corresponding QMS requirements. In the United States, FDA incorporated ISO 13485:2016 by reference into the Quality Management System Regulation (21 CFR Part 820, the QMSR), effective 2 February 2026, replacing the former Quality System Regulation. It also underpins the MDSAP audit programme.

Document structure

PartCovers
Clause 4 — Quality management systemGeneral and documentation requirements, the quality manual, medical device file, and control of documents and records
Clause 5 — Management responsibilityManagement commitment, customer/regulatory focus, quality policy, planning, responsibility and authority, and management review
Clause 6 — Resource managementHuman resources and competence, infrastructure, work environment, and contamination control
Clause 7 — Product realizationPlanning, customer-related processes, design and development, purchasing, production and service provision, and control of monitoring equipment
Clause 8 — Measurement, analysis and improvementFeedback, complaint handling, reporting to authorities, internal audit, nonconforming product, CAPA, and improvement

Key requirements

  • Design and development controls with documented DHF
  • Risk management throughout the product lifecycle (references ISO 14971)
  • Post-market surveillance and complaint handling system
  • Customer communication and feedback processes
  • Traceability — unique device identification (UDI) linkage

Revision notes

Third edition March 2016. Significant restructuring from 2003 version. Greater emphasis on risk management and risk-based decisions throughout.

CHECKING ACCESS

Checking your Professional access…

Where this control fails

live FDA enforcement
See all FDA enforcement →

Live FDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.

International alignment

ISO 13485 is the QMS baseline the major device jurisdictions converge on: it is harmonised under the EU MDR/IVDR, incorporated by reference into FDA’s QMSR (21 CFR 820) from 2 February 2026, and is the QMS standard audited under the Medical Device Single Audit Program (MDSAP) recognised by Australia, Brazil, Canada, Japan, and the United States. It is aligned with, but deliberately distinct from, ISO 9001, and it works alongside ISO 14971 for the risk-management process it references.

ISO 13485:2016: frequently asked questions

Quick answers to common questions about ISO 13485:2016.

Is ISO 13485 mandatory?

The standard itself is voluntary, but it acquires force through regulation. It is harmonised under the EU MDR/IVDR and, in the United States, FDA incorporated ISO 13485:2016 by reference into the QMSR (21 CFR Part 820) effective 2 February 2026, so it is the QMS regulators expect medical-device organisations to meet.

What is the difference between ISO 13485 and ISO 9001?

ISO 13485 is a stand-alone QMS standard focused on regulatory compliance, safety, and effectiveness of medical devices, with documented, risk-based, traceable processes. ISO 9001 is a general QMS emphasising continual improvement and customer satisfaction. They share structure but are certified separately.

How does ISO 13485 relate to FDA’s QMSR?

FDA’s Quality Management System Regulation incorporates ISO 13485:2016 by reference (with some additional FDA-specific requirements), replacing the former Quality System Regulation from 2 February 2026 — so meeting ISO 13485 is the core of QMSR compliance.

Does ISO 13485 cover risk management?

It requires a risk-management process across product realization but does not define that process itself — it references ISO 14971, the medical-device risk-management standard, for the method.