Skip to main content

Glossary > ISO 13485

ISO 13485

weasl Author Maren Fichtner
Author: Maren Fichtner | October 8, 2026

Definition: What is ISO 13485?

ISO 13485 is the internationally recognized standard for quality management systems used by manufacturers and suppliers of medical devices. It ensures that the design, development, production, installation, and maintenance of medical devices consistently meet customer and regulatory requirements, and serves in practice as key evidence of compliance with the quality management requirements of the EU Medical Device Regulation (MDR) as well as comparable international regulatory frameworks such as FDA 21 CFR Part 820.

Publisher: International Organization for Standardization (ISO)

Current edition: ISO 13485:2016

Who is ISO 13485 intended for?

The standard is intended for organizations throughout the entire medical device value chain – manufacturers, component suppliers, and service providers such as sterilization facilities or distribution organizations. It is applicable regardless of industry or size – from small medical technology startups to international corporations – and is expected by nearly all European Notified Bodies to serve as the basis for conformity assessment.

Overview of core requirements

  • Risk management: systematic application throughout the entire product life cycle, in accordance with ISO 14971

  • Design and development control: documented validation and verification of new and modified products

  • Traceability: seamless traceability of batches, components, and test records down to the individual product

  • Change control: formal evaluation and approval process for every change to processes or products

  • Device History Record (DHR): complete, tamper-proof record of all manufacturing and testing steps

  • Regulatory documentation: documentation that is directly incorporated into regulatory approval procedures

Differences from ISO 9001 and the MDR

ISO 13485 adopts the basic structure of ISO 9001 but deliberately omits certain general requirements – such as the systematic measurement of customer satisfaction – and instead supplements it with industry-specific requirements for risk management, product safety, and regulatory traceability, which are mandatory for medical devices. Compared to the MDR, ISO 13485 is a voluntary standard for quality management systems, whereas the MDR is directly applicable EU law that additionally governs specific product requirements and the conformity assessment procedure for CE marking. ISO 13485 certification does not replace MDR compliance, but in practice it serves as the most important basis for demonstrating such compliance.

Consequences of noncompliance

Without valid ISO 13485 certification, obtaining CE marking under the MDR is virtually impossible in practice, which completely blocks market access in the EU. For existing certifications, nonconformities identified during surveillance audits lead to corrective actions; in the event of a recurrence, the certificate may be suspended or revoked – with immediate consequences for market authorization and potential field safety corrective actions for products that have already been shipped.

Related standards

  • MDR – EU Medical Device Regulation 2017/745

  • ISO 9001 – basic quality management standard

  • FDA 21 CFR Part 820 – U.S. quality management requirements for medical devices

  • IVDR – EU regulation on in vitro diagnostic medical devices

Frequently asked questions about ISO 13485

Is ISO 13485 required by law?

Not directly, but without them, market authorization under the MDR or the FDA is hardly realistic in practice.

What is the difference compared to the MDR?

ISO 13485 governs the quality management system, while the MDR is EU law that sets forth specific product requirements and CE marking.

What is the difference from ISO 9001?

ISO 13485 omits certain general requirements and instead adds medical device-specific requirements for risk management and traceability.

How long is a certification valid?

Typically three years, with annual surveillance audits and recertification before the expiration date.

Successfully implementing ISO 13485

weasl product flyer

The greatest effort is required to maintain a complete device history record: Every manufacturing and testing step must be tamper-proof, time-stamped, and available for audit at any time. Connected worker platforms like weasl automatically document work and inspection steps as the process unfolds and provide the complete DHR at the push of a button – without handwritten lists or Excel spreadsheets that no longer stand up to inspection.

Learn more about weasl and request our product brochure now.

GUIDE. CONNECT. EMPOWER.

weasl is the execution layer between ERP/MES and actual operations. As an AI-powered connected worker platform, weasl helps manufacturing companies execute production and assembly processes digitally, reliably, and transparently.

GET IN TOUCH

  +49 351 847 150 

   contact@weasl.com

   Contact form