What is ISO 13485 and who needs it?
ISO 13485:2016 · Scope and applicability
Quick answer
ISO 13485:2016 is the international QMS standard specifically for medical device manufacturers and their supply chains. It is accepted or required by regulators in over 100 countries and is the primary route to demonstrating QMS compliance under EU MDR, Health Canada, TGA, and MDSAP.
What ISO 13485 covers
ISO 13485:2016 specifies requirements for a quality management system (QMS) where an organisation needs to demonstrate its ability to provide medical devices and related services that consistently meet customer requirements and applicable regulatory requirements. Unlike general quality standards, ISO 13485 is purpose-built for the medical device industry, with requirements tailored to regulatory compliance, product safety and risk management throughout the device lifecycle.
The standard covers design and development, production, installation, servicing, and post-market activities. It applies to all organisations in the medical device supply chain — not just final-stage manufacturers.
Who must comply
ISO 13485 applies to any organisation that:
- Designs, manufactures, or assembles medical devices or their components
- Provides post-market services (maintenance, repair, sterilisation)
- Distributes or imports medical devices (varies by jurisdiction)
- Supplies critical components, software, or services to device manufacturers
Even if your organisation is not the legal manufacturer, if you perform regulated activities under contract, ISO 13485 clauses will apply to those activities.
Global regulatory acceptance
| Jurisdiction | Regulatory body | ISO 13485 status | Programme |
|---|---|---|---|
| European Union | National Competent Authorities / NBs | Harmonised (EN ISO 13485:2016) | EU MDR / IVDR |
| Canada | Health Canada | Required for Class II–IV | MDSAP |
| Australia | TGA | Required (ARTG listing) | MDSAP |
| Japan | PMDA / MHLW | JPAL (equivalent QMS) | MDSAP |
| Brazil | ANVISA | Required (RDC 16/2013) | MDSAP |
| USA | FDA | Not mandated; 21 CFR 820 used (harmonisation underway) | MDSAP optional |
History and editions
- 1996: First edition published — harmonised from EN 46001/46002
- 2003: Second edition — aligned with ISO 9001:2000 structure
- 2016: Third (current) edition — strengthened risk management, supply chain controls, regulatory requirements. Transition period ended March 2019.
MDSAP — one audit for five markets
The Medical Device Single Audit Programme (MDSAP) allows a single audit to satisfy requirements of Australia, Brazil, Canada, Japan and the USA. ISO 13485:2016 forms the QMS foundation for MDSAP. An MDSAP certificate is accepted as evidence of QMS compliance in all five participating jurisdictions, significantly reducing audit burden for internationally-active manufacturers.
Key concepts
- QMS scope: Defines which products and processes are covered by your QMS. Exclusions from clause 7 are permitted only when not responsible for that activity.
- Regulatory requirements: Unlike ISO 9001, compliance with applicable regulatory requirements is explicitly required throughout — not just as a customer requirement.
- Risk management: Risk-based thinking is embedded across the standard, with direct links to ISO 14971.
- Medical device file: Clause 4.2.3 requires a device-specific file (equivalent to DHF in FDA terminology).