Humanize Health

ISO 13485Medical Device Quality Management

ISO 13485 is the international standard for quality management systems in the medical device industry. It sets out how a manufacturer designs, develops, produces and maintains a device under documented control, and how it proves that control to an auditor. It is the QMS baseline for CE marking in the EU, and since February 2026 the substance of FDA’s QMSR.

Full title
Medical devices — Quality management systems — Requirements for regulatory purposes
Edition
ISO 13485:2016
Issued by
International Organization for Standardization
Applies
Recognised internationally; harmonised under EU MDR and incorporated by FDA’s QMSR

What it covers

In practice

ISO 13485 was written with physical manufacturing in mind and reads that way. For a software-only device, whole clauses on sterilisation, installation and servicing are excluded or justified as non-applicable, while the design control clauses carry nearly all the weight.

The practical mapping is that your engineering process is your design control process. Requirements management, architecture, code review, test evidence and release approval have to produce the records the standard expects — generated as you work, rather than assembled afterwards. IEC 62304 then specifies what those software activities look like in detail: 13485 is the container, 62304 is the content.

Where teams get it wrong

Buying a QMS instead of building one

Template packs sell a full document tree in an afternoon. The tree is not the problem; the evidence is. An auditor reads your procedures and then asks for the records those procedures say you produce. A procedure describing a design review cadence you never held is worse than having no procedure at all.

Writing procedures the team cannot follow

The most common non-conformity is not a missing procedure — it is a procedure the engineering team does not actually work to. Write down what you genuinely do, then improve it. A modest process followed exactly beats an ambitious one honoured in the breach.

Leaving the QMS until the notified body is booked

Design controls are hostile to retrospection. Reconstructing a year of decisions, rationales and reviews after the fact is expensive, and the reconstruction is visible in the record.

Common questions

Do we need ISO 13485 certification to sell a medical device?

What is required is a compliant quality management system, not a certificate as such. But for Class IIa and above in the EU, a notified body audits your QMS as part of conformity assessment, and certification to ISO 13485 is the standard way to demonstrate it. FDA does not certify; it inspects.

How long does ISO 13485 certification take?

Six to twelve months is realistic from a standing start. The constraint is rarely writing procedures — it is generating evidence that the system has actually operated. Certification bodies expect at least one completed internal audit and management review cycle, and those take calendar time you cannot compress by working harder.

Can a software-only company exclude parts of ISO 13485?

Yes. Clauses covering sterilisation, installation, and servicing are commonly non-applicable to standalone software, provided each exclusion is documented and justified in the quality manual. What cannot be reduced is design and development control, which carries almost all the weight for a software manufacturer.

Working out how ISO 13485 applies to what you are building is usually the first conversation.

Get in touch →