What is ISO 13485 and who needs it?

ISO 13485:2016 · Scope and applicability

Quick answer

ISO 13485:2016 is the international QMS standard specifically for medical device manufacturers and their supply chains. It is accepted or required by regulators in over 100 countries and is the primary route to demonstrating QMS compliance under EU MDR, Health Canada, TGA, and MDSAP.

What ISO 13485 covers

ISO 13485:2016 specifies requirements for a quality management system (QMS) where an organisation needs to demonstrate its ability to provide medical devices and related services that consistently meet customer requirements and applicable regulatory requirements. Unlike general quality standards, ISO 13485 is purpose-built for the medical device industry, with requirements tailored to regulatory compliance, product safety and risk management throughout the device lifecycle.

The standard covers design and development, production, installation, servicing, and post-market activities. It applies to all organisations in the medical device supply chain — not just final-stage manufacturers.

Who must comply

ISO 13485 applies to any organisation that:

  • Designs, manufactures, or assembles medical devices or their components
  • Provides post-market services (maintenance, repair, sterilisation)
  • Distributes or imports medical devices (varies by jurisdiction)
  • Supplies critical components, software, or services to device manufacturers

Even if your organisation is not the legal manufacturer, if you perform regulated activities under contract, ISO 13485 clauses will apply to those activities.

Global regulatory acceptance

JurisdictionRegulatory bodyISO 13485 statusProgramme
European UnionNational Competent Authorities / NBsHarmonised (EN ISO 13485:2016)EU MDR / IVDR
CanadaHealth CanadaRequired for Class II–IVMDSAP
AustraliaTGARequired (ARTG listing)MDSAP
JapanPMDA / MHLWJPAL (equivalent QMS)MDSAP
BrazilANVISARequired (RDC 16/2013)MDSAP
USAFDANot mandated; 21 CFR 820 used (harmonisation underway)MDSAP optional

History and editions

  • 1996: First edition published — harmonised from EN 46001/46002
  • 2003: Second edition — aligned with ISO 9001:2000 structure
  • 2016: Third (current) edition — strengthened risk management, supply chain controls, regulatory requirements. Transition period ended March 2019.

MDSAP — one audit for five markets

The Medical Device Single Audit Programme (MDSAP) allows a single audit to satisfy requirements of Australia, Brazil, Canada, Japan and the USA. ISO 13485:2016 forms the QMS foundation for MDSAP. An MDSAP certificate is accepted as evidence of QMS compliance in all five participating jurisdictions, significantly reducing audit burden for internationally-active manufacturers.

Key concepts

  • QMS scope: Defines which products and processes are covered by your QMS. Exclusions from clause 7 are permitted only when not responsible for that activity.
  • Regulatory requirements: Unlike ISO 9001, compliance with applicable regulatory requirements is explicitly required throughout — not just as a customer requirement.
  • Risk management: Risk-based thinking is embedded across the standard, with direct links to ISO 14971.
  • Medical device file: Clause 4.2.3 requires a device-specific file (equivalent to DHF in FDA terminology).

Check your ISO 13485 gaps

Self-assess your QMS against all key clauses — free tool.

Try free →