
What Is ISO 13485 and How Does It Relate to the MDR?
Short answer: ISO 13485 is the quality management system (QMS) standard for medical devices; the current version is ISO 13485:2016. It defines the processes that let an organisation consistently meet customer and regulatory requirements across the design, manufacture, storage, distribution and servicing of medical devices. MDR (Regulation (EU) 2017/745) Article 10(9) requires a manufacturer to have a QMS proportionate to the device's class and type; ISO 13485 is the de facto standard for meeting that obligation, but is not sufficient on its own for MDR compliance.
Key takeaways
- ISO 13485 is a risk-based medical device QMS standard; structurally similar to ISO 9001 but focused on safety, effectiveness and regulatory compliance rather than customer satisfaction/continual improvement.
- The MDR mandates a QMS (Art. 10(9)); an ISO 13485 certificate largely meets that expectation.
- Many MDR requirements are not covered by ISO 13485: the detail of PMS/PMCF/PSUR, UDI, EUDAMED, PRRC, the depth of clinical evaluation, vigilance timelines, the SSCP.
- Certification is done by an accredited certification body; it is different from an MDR notified body certificate.
This article is part of the What is the EU MDR? pillar and complements The MDR compliance process: 8 steps.
What ISO 13485:2016 covers
Using a process approach, the standard addresses:
- Quality management system — documentation, the medical device file, control of records.
- Management responsibility — quality policy, objectives, management review.
- Resource management — competence, training, infrastructure, work environment and contamination control.
- Product realisation — design and development (inputs/outputs, verification, validation, transfer, changes), purchasing and supplier control, production and service provision, process validation, traceability, cleanliness, installation, servicing, sterility.
- Measurement, analysis and improvement — feedback, complaint handling, reporting to regulatory authorities, internal audit, nonconforming product, CAPA.
The 2016 revision spread risk-based thinking across all processes, strengthened the emphasis on regulatory compliance, and clarified expectations for software validation (including QMS software), supplier control and the medical device file.

ISO 13485 vs ISO 9001
| Topic | ISO 9001:2015 | ISO 13485:2016 |
|---|---|---|
| Purpose | Customer satisfaction, general quality | Safe and effective medical devices, regulatory compliance |
| Structure | Annex SL (10 clauses) | Its own structure (Clauses 4–8), not Annex SL |
| Continual improvement | Central theme | Emphasis on "maintaining the effectiveness of the QMS" |
| Risk | General "risks and opportunities" | Product-safety focused, linked to ISO 14971 |
| Documentation | More flexible | More mandatory procedures and records |
| Regulation | General reference | "Applicable regulatory requirements" in every process |
An organisation can run both; for most medical device manufacturers, ISO 13485 is the one that matters.
Why the MDR requires a QMS
MDR Article 10(9) requires the manufacturer to establish a documented, maintained QMS proportionate to the device's class and type, and lists the minimum scope: a regulatory compliance strategy, classification, management of clinical evaluation, PMS/PMCF, vigilance, supply chain control, UDI assignment, resource management (including the PRRC), and so on. This list overlaps heavily with ISO 13485 processes, which is why an ISO 13485 certificate is the core evidence of QMS conformity in a notified body audit.
When ISO 13485 is published as a harmonised standard in the EU Official Journal, it provides a presumption of conformity for the requirements it covers (check the current list for the published version and any restrictions).

MDR requirements ISO 13485 does not cover
Even with an ISO 13485 certificate, for the MDR you must additionally build:
- The depth of clinical evaluation (Annex XIV, MDCG 2020-1/2022-2) and the CER.
- The PMS plan, PSUR, PMCF plan and report — with the content and frequency the MDR requires.
- Vigilance reporting timelines and thresholds (Articles 87–92), trend reporting.
- UDI assignment rules and EUDAMED (ÜTS in Türkiye) registrations.
- PRRC appointment and evidence of competence (Article 15).
- The technical documentation (Annexes II–III) and GSPR (Annex I) evidence.
- The SSCP for Class III/implants.
- The declaration of conformity and CE marking processes.
In short: ISO 13485 defines "how you operate"; the MDR defines "what you must prove." Together they give full compliance.
Certification process and timeline
- Gap analysis — assessing current practice against ISO 13485 and the MDR.
- System build — procedures, records, training, the medical device file.
- Implementation period — usually at least 3 months generating records.
- Internal audit + management review.
- Certification audit — Stage 1 (documentation/readiness) + Stage 2 (implementation).
- Closing non-conformities + certificate (valid 3 years, annual surveillance, recertification at 3 years).
Typical duration: 4–8 months from scratch. Note: you obtain the ISO 13485 certificate from an accredited certification body; that body may or may not be the same as your MDR notified body.
Relationship to MDSAP
MDSAP (Medical Device Single Audit Program) uses a single ISO 13485-based audit to cover the requirements of multiple countries (USA, Canada, Australia, Brazil, Japan). The EU does not recognise MDSAP, but notified bodies may consider MDSAP reports as an input. MDSAP is mandatory for the Canadian market.

Frequently asked questions
Is ISO 13485 mandatory? The standard itself is voluntary; but because the MDR mandates a QMS and ISO 13485 is the de facto standard, it is effectively mandatory in practice.
Is an ISO 13485 certificate a CE certificate? No. ISO 13485 is a QMS certificate; the device's CE marking additionally requires an MDR conformity assessment.
Is there a simplified version for small manufacturers? The standard is the same; but the QMS can be scaled to the organisation's size under the "proportionality" principle.
I am only a distributor — do I need ISO 13485? Not mandatory, but recommended for organisations doing storage/distribution/servicing, and some manufacturers require it by contract.
Will ISO 13485:2016 be updated? The standard is reviewed periodically; track the current status via ISO and your national standards body.
How MEGACERT helps
We provide ISO 13485 implementation from scratch, integration of MDR-specific procedures, internal auditor training and certification audit preparation. Let us map your QMS's MDR gaps in a free 30-minute call. → Contact. Scope of consulting: What does an MDR consultant do? (cluster link)
Sources
- ISO 13485:2016 — Medical devices — Quality management systems — Requirements for regulatory purposes.
- Regulation (EU) 2017/745, Article 10(9). EUR-Lex.
- European Commission. Harmonised standards for medical devices. https://health.ec.europa.eu/medical-devices-topics-interest/harmonised-standards_en
- IMDRF MDSAP documents. https://www.imdrf.org
- ISO 14971:2019 — risk management (used alongside ISO 13485).
Last updated: 30 August 2026. General information only.