Skip to content
Compliance Manuals advanced Mar 28, 2026 · 14 min read

ISO 13485 Quality Management for Medical Device Manufacturers

A technical overview of ISO 13485 requirements for medical device manufacturers. Covers documentation, process control, risk management, and audit preparation.

By Medives Compliance Team
ISO 13485quality managementcompliancecertificationaudit

ISO 13485 is the international standard for quality management systems (QMS) in the medical device industry. It's essential for ensuring product quality and regulatory compliance across global markets.

What is ISO 13485?

ISO 13485 specifies requirements for a QMS where an organization needs to demonstrate its ability to provide medical devices and related services that consistently meet customer and regulatory requirements. It is harmonized with EU MDR and recognized by regulatory authorities worldwide.

Key Requirements

1. Quality Management System

  • Documented QMS including quality manual, procedures, and work instructions
  • Control of documents and records
  • Management of quality objectives and KPIs

2. Management Responsibility

  • Top management commitment and leadership
  • Quality policy and objectives
  • Management review (at least annually)
  • Resource allocation

3. Resource Management

  • Competence, training, and awareness
  • Infrastructure and work environment
  • Contamination control (where applicable)

4. Product Realization

  • Planning of product realization processes
  • Customer-related processes
  • Design and development (ISO 13485 Clause 7.3)
  • Purchasing and supplier management
  • Production and service provision
  • Control of monitoring and measuring equipment

5. Measurement, Analysis, and Improvement

  • Monitoring and measurement (customer satisfaction, internal audit, process monitoring)
  • Control of nonconforming product
  • Corrective and preventive actions (CAPA)
  • Statistical techniques

Risk Management Integration

ISO 13485 works hand-in-hand with ISO 14971 (risk management for medical devices):

  • Risk-based thinking must be embedded throughout the QMS
  • Design controls must address known hazards
  • Production controls must mitigate identified risks
  • Post-market surveillance must monitor residual risk

Documentation Hierarchy

  1. Quality Manual: Top-level QMS description
  2. Procedures: How processes are controlled (typically 20–30 procedures)
  3. Work Instructions: Step-by-step task guidance
  4. Forms and Records: Evidence of compliance

Audit Preparation

Internal Audits

  • Conducted at planned intervals (typically annually)
  • Cover all QMS processes and clauses
  • Must be performed by competent, independent auditors

Certification Audit (Stage 1 & 2)

  • Stage 1: Documentation review (1–2 days)
  • Stage 2: On-site assessment (2–5 days depending on scope)
  • Nonconformities must be addressed within 90 days

Surveillance Audits

  • Annual audits after certification
  • Cover subset of QMS processes
  • Re-certification every 3 years

Benefits for International Buyers

  • Ensures consistent product quality across batches
  • Facilitates regulatory compliance in target markets
  • Reduces supply chain risk and recall probability
  • Enables smoother audits and inspections
  • Supports long-term supplier relationships

Cost and Timeline

PhaseDurationCost Range
Gap analysis1–2 weeks$2,000–$5,000
Documentation4–8 weeks$5,000–$15,000
Implementation3–6 months$10,000–$30,000
Certification audit1–2 weeks$5,000–$25,000
Annual surveillance$2,000–$8,000/year