GUIDE: ISO 13485 Quality Management
How to Implement a QMS for Medical Devices: A Step-by-Step ISO 13485 Compliance Guide
ISO 13485 is the international standard for quality management systems in medical device manufacturing and supply. Certification demonstrates that an organisation can consistently design, produce, and deliver safe and effective medical devices. This guide walks through each phase of implementing a conforming QMS from gap assessment through certification audit, with the specific actions, documents, and common failure points that determine whether an implementation succeeds or stalls.
Quick Overview
What ISO 13485 Is
An internationally recognised QMS standard specifically for organisations involved in one or more stages of the medical device lifecycle, including design, development, production, storage, distribution, installation, and servicing. Conformance is required by regulators in the EU (MDR/IVDR), Canada (MDSAP), Australia (TGA), Japan (JPAL), and many other markets.
Regulatory Basis
ISO 13485:2016 is the current edition. It is harmonised with EU MDR 2017/745, EU IVDR 2017/746, and FDA 21 CFR Part 820 Quality System Regulation (which was updated in 2024 to align more closely with ISO 13485). Organisations pursuing MDSAP must meet ISO 13485:2016 as the baseline standard.
Typical Timeline
Initial certification for an organisation building a QMS from scratch typically takes 12 to 24 months depending on organisation size, product complexity, current documentation maturity, and resource availability. Organisations with an existing ISO 9001 QMS can transition faster, typically in 6 to 12 months. Planning for the longer end of the range is prudent.
Who This Guide Is For
Quality managers and directors leading the ISO 13485 implementation project. Regulatory affairs professionals coordinating certification timelines with market submissions. Operations and engineering managers responsible for process documentation. Organisations building or upgrading a medical device QMS for the first time or transitioning from ISO 13485:2003.
What You Will Learn
How to scope the QMS and identify which ISO 13485 clauses apply to your operations
How to conduct a gap assessment and prioritise implementation activities
How to structure the document hierarchy: quality manual, procedures, work instructions, and records
How to implement risk-based process controls across design, production, and post-market
How to build and run effective internal audit and management review programmes
How to select a notified body or certification body and prepare for the Stage 1 and Stage 2 audits
The most common nonconformities found in ISO 13485 certification audits and how to prevent them
How to maintain certification through surveillance audits and recertification cycles
Prerequisites
Executive commitment and resource allocation
ISO 13485 implementation requires sustained investment of staff time, documentation resources, training, and certification audit fees. Top management commitment is not a soft prerequisite; the standard explicitly requires it at Clause 5.1. Without visible leadership commitment and dedicated resource allocation, implementation projects stall, documentation remains draft, and internal audits get deprioritised. Establish the project mandate and budget before starting.
Designated Management Representative
ISO 13485 Clause 5.5.2 requires top management to appoint a member of management with responsibility and authority for ensuring the QMS is established and maintained. This person, commonly called the Management Representative or QMS Owner, must have sufficient seniority and organisational access to drive cross-functional compliance. Identify this person before initiating the gap assessment.
Understanding of your product and regulatory classification
The ISO 13485 QMS scope depends heavily on what you make, what regulatory markets you target, and what risk class your products fall into. A Class I device manufacturer in a single market has a different QMS scope than a Class III device manufacturer pursuing global certification under MDSAP. Before scoping the QMS, confirm your product classifications and target market regulatory requirements with your regulatory affairs team.
Required Documents and Resources
Document / Resource
Purpose
When Needed
ISO 13485:2016 standard text
Primary requirements reference for all documentation and process design
Before gap assessment
Gap assessment template (clause-by-clause)
Baseline status of current practices against each ISO 13485 clause
Step 1
Quality manual template
Top-level QMS document describing scope, exclusions, and process interactions
Step 3
Document control procedure and forms
Controls all QMS documents from creation through obsolescence
Step 3 (first procedure drafted)
Risk management procedure (aligned with ISO 14971)
Governs product risk management throughout the device lifecycle
Step 4
Internal audit programme and checklist
Required by Clause 8.2.4; must cover all QMS processes at planned intervals
Step 6
Certification body (notified body or accredited CB)
Conducts Stage 1 and Stage 2 certification audits
Step 7
Step-by-Step Implementation
1
Conduct a Gap Assessment Against ISO 13485:2016
Objective: Establish your baseline and identify what needs to be built
Why It Matters
Without a structured gap assessment, implementation teams either overbuild (documenting processes that already conform) or underbuild (missing entire clause areas). The gap assessment produces a prioritised work plan that ensures effort is directed where the gaps are largest and where the certification audit risk is highest.
Actions
Map each clause of ISO 13485:2016 to your current documented procedures and practices. For each clause, assign a status: conforming, partially conforming, or not addressed. Document objective evidence for conforming areas so you are not re-doing work that already exists. Identify the clauses with the largest gaps and estimate the effort required to close them. Prioritise based on certification criticality and implementation dependency (document control and record control must be in place before other procedures can be properly controlled).
Expected Outcome
A clause-by-clause gap assessment report identifying conforming areas, gaps, and priorities. A project plan with milestones for each implementation phase, resource assignments, and a realistic target certification date.
Tip
Use a certified quality consultant for the gap assessment if your internal team has not conducted one before. An experienced assessor will identify gaps that internal staff who are close to the processes often miss, particularly in risk management integration, post-market surveillance, and regulatory reporting obligations.
2
Define the QMS Scope and Organisational Context
Objective: Establish what the QMS covers and does not cover
Why It Matters
The scope defines the boundaries of certification. A scope that is too narrow may exclude processes that regulators expect to be covered. A scope that is too broad includes processes not yet ready for certification, increasing audit risk. Scope definition also determines which ISO 13485 clauses apply and whether any clause exclusions are justified.
Actions
Define the scope in terms of products and services, device types, manufacturing sites and locations, and the applicable lifecycle phases (design, manufacture, distribution, servicing). Identify any ISO 13485 clause exclusions with documented justification; note that Clause 7.3 (Design and Development) can only be excluded if your organisation does not perform design and development and this exclusion is acceptable under applicable regulatory requirements. Draft the scope statement that will appear in the Quality Manual.
Expected Outcome
A documented scope statement describing the products, services, sites, and lifecycle phases covered, with any clause exclusions and their justification. This scope statement becomes a permanent part of the Quality Manual.
Warning
Do not exclude Clause 7.3 unless you have confirmed with your regulatory affairs team that this exclusion is acceptable for all of your target regulatory markets. Some markets do not accept design and development exclusions regardless of contractual arrangements.
3
Build the Document Hierarchy: Manual, Procedures, Work Instructions, Records
Objective: Create a controlled, navigable, audit-ready document system
ISO 13485 requires documented information at multiple levels. The structure most organisations use is a four-tier hierarchy, though the standard does not prescribe a specific structure.
Tier 1
Quality Manual
QMS scope, policy, process interactions, clause exclusions
Tier 2
Procedures (SOPs)
Who does what, when, and how at the department level
Tier 3
Work Instructions
Step-by-step task instructions for specific operations
Tier 4
Records and Forms
Objective evidence that procedures were followed
Begin with the document control procedure itself, because every other document you create must be controlled under it. Then draft the quality manual. Then develop the required procedures in order of implementation priority, starting with those that underpin all other processes: CAPA, internal audit, management review, supplier control, and nonconforming product. Work instructions and forms are developed in parallel with the procedures they support.
4
Implement Risk-Based Process Controls Across the Device Lifecycle
Objective: Integrate risk management into every major QMS process
Why It Matters
ISO 13485:2016 has a stronger risk-based approach than the 2003 edition. Risk management is not limited to product design; it informs decisions across supplier selection, production process validation, complaint handling, and post-market surveillance. An organisation that applies risk management only in the design file and nowhere else will find gaps throughout the certification audit.
Actions
Implement a risk management procedure aligned with ISO 14971:2019. Apply risk management outputs to: design and development inputs and outputs; supplier qualification criteria; process validation acceptance criteria; monitoring and measurement controls; and post-market surveillance trigger thresholds. Document how risk management outputs influence each of these areas. The connection between risk management and process decisions must be traceable in records, not just stated in procedures.
Expected Outcome
A documented risk management procedure referencing ISO 14971. Risk files for each product or product family. Documented connections between risk management outputs and process design decisions across the QMS.
Tip
Risk management integration is one of the areas where certification auditors look most closely at the 2016 version requirements. Having a risk procedure that references all the right clauses but no records showing it was actually applied to process decisions is a common major nonconformity finding.
5
Train the Workforce and Establish Competency Records
Objective: Ensure all personnel affecting product quality are trained and records confirm it
Actions
Define the competency requirements for each role that affects product quality. These requirements should specify the education, training, skills, and experience needed. For each person in a relevant role, assess their current competency against the requirements, identify gaps, and provide training to close them. Document the training provided and evaluate its effectiveness. Maintain competency records for each person as part of the QMS record-keeping requirements under Clause 6.2.
QMS training must cover: the quality policy and quality objectives; each person’s role in achieving those objectives; the consequences of non-conformance; and the specific QMS procedures and work instructions relevant to their job function. General HIPAA or safety training does not satisfy QMS competency requirements.
Expected Outcome
Documented competency requirements for each quality-relevant role. Individual training records showing training completed, dates, and effectiveness evaluation. A training matrix mapping roles to required training modules.
Warning
Competency records that show only that training was attended, with no effectiveness evaluation, do not fully satisfy Clause 6.2. The standard requires evidence that personnel are competent, not just that they attended training. Incorporate practical demonstration, assessment, or supervisor sign-off as part of the training completion process.
6
Run the Internal Audit Programme and Management Review
Objective: Verify QMS implementation before the certification body sees it
Why It Matters
The internal audit programme serves two functions in an implementation context: it verifies that procedures are actually being followed (not just documented), and it generates the audit records and CAPA closure evidence that the certification auditor will review during the Stage 2 audit. An organisation that arrives at Stage 2 with no completed internal audit cycle has not demonstrated that the QMS is operational.
Actions
Complete at least one full internal audit cycle covering all QMS processes and clauses before scheduling the Stage 2 certification audit. Document findings as nonconformities or observations. Initiate CAPAs for all nonconformities and close them before Stage 2. Conduct a management review meeting covering all inputs required by Clause 5.6: audit results, feedback, process performance, corrective and preventive actions, and resource needs. Document the management review outputs including decisions and action items.
Expected Outcome
Completed internal audit schedule and reports covering all QMS processes. Closed CAPAs for all internal audit nonconformities. A documented management review meeting with minutes, inputs, outputs, and action item tracking.
Tip
Internal auditors must be independent from the areas they audit. If your quality team is small, this may require training operational staff to conduct audits of each other’s areas, or engaging an external auditor for the pre-certification internal audit cycle. Do not have the QMS author audit their own procedures.
7
Select a Certification Body and Prepare for the Stage 1 and Stage 2 Audits
Objective: Select the right certification body and pass both audit stages
Certification Body Selection
For CE marking under EU MDR/IVDR, you must use a notified body designated for medical devices. For markets outside the EU, an accredited certification body (CB) under IAF MLA can issue ISO 13485 certificates. For MDSAP, you must use an MDSAP-authorised audit organisation. Select your CB early: lead times for initial certification audits are typically 3 to 9 months depending on the CB’s schedule and your product complexity.
Stage 1 Audit
The Stage 1 (documentation review) audit typically involves the CB reviewing your Quality Manual, key procedures, and QMS scope. The auditor assesses whether the QMS is sufficiently developed to proceed to Stage 2. Stage 1 findings are typically minor; major gaps at Stage 1 require remediation before Stage 2 is scheduled.
Stage 2 Audit
The Stage 2 (certification) audit is conducted on-site. Auditors review records, interview personnel, observe processes, and verify that the QMS is implemented and effective. They will review CAPA closure, internal audit records, management review minutes, training records, supplier qualification records, and process validation documentation. Prepare process owners for auditor interviews. Stage 2 nonconformities must be addressed within the timeframe specified by the CB (typically 90 days for major nonconformities).
Tip
Conduct a mock Stage 2 audit 4 to 8 weeks before the scheduled audit date. Use an external consultant who was not involved in building the QMS. Address the findings before the real audit. The investment in a mock audit almost always identifies gaps that internal teams missed.
Best Practices
Build the QMS around your actual processes, not the standard’s structure
Mapping the QMS document structure directly to the ISO 13485 clause numbers is a common approach that produces documents that are easy for auditors to read but hard for employees to use. Design procedures around how work actually flows in your organisation, and then cross-reference to ISO 13485 clauses. Staff are more likely to follow procedures that reflect how they actually work.
Involve process owners in writing their own procedures
Procedures written by the quality team and handed to operations for sign-off frequently do not reflect actual practice and are often not followed. Engage the people who perform the work in drafting the procedures that govern it. This takes more time during implementation but produces procedures that are accurate, owned, and adhered to. Procedures that describe what should happen rather than what does happen will fail during internal audits and Stage 2.
Plan for the post-certification maintenance burden before certification
Many organisations invest heavily in initial certification and underinvest in the ongoing programme. Surveillance audits occur annually; recertification occurs every three years. Internal audits, management reviews, CAPA processes, and document controls must continue operating between external audits. Organisations that treat certification as a finish line rather than a starting point typically find themselves unprepared for the first surveillance audit.
Common Mistakes
Mistake
What to Do Instead
Writing procedures before the document control procedure is in place
Document control must be the first procedure approved. All subsequent documents must be created and controlled under it. Procedures drafted before document control exists cannot be considered controlled documents until they are retrospectively brought under the system.
Excluding design and development without regulatory confirmation
Confirm with regulatory affairs that the Clause 7.3 exclusion is acceptable for every target market before including it in the Quality Manual. Discovering midway through a regulatory submission that the exclusion is not accepted in that market requires QMS changes during an active regulatory review.
Treating the CAPA system as a corrective action system only
ISO 13485 requires both corrective and preventive action. Preventive action requires identifying potential nonconformities and taking action before they occur. A CAPA log that contains only responses to actual incidents does not demonstrate preventive action capability and will draw an observation during audit.
Scheduling the Stage 2 audit before the internal audit cycle is complete
The Stage 2 auditor will ask to review internal audit records. If the internal audit programme has not completed a full cycle, this is a major gap. Plan the Stage 2 date to allow at least 8 weeks after the internal audit cycle closes, giving time to resolve findings and close CAPAs.
Compliance Notes
Key Regulatory and Standard References
ISO 13485:2016: The primary QMS standard. All implementation activities should trace back to specific clause requirements. The 2016 version has significantly enhanced risk-based requirements compared to the 2003 edition.
ISO 14971:2019: The international standard for medical device risk management. ISO 13485 references risk management throughout; ISO 14971 is the specific standard that defines how to perform it. A conforming ISO 13485 QMS requires risk management aligned with ISO 14971.
EU MDR 2017/745 and IVDR 2017/746: EU regulations requiring a QMS conforming to the quality system requirements of Annex IX. ISO 13485 certification does not automatically demonstrate MDR/IVDR compliance; notified body assessment of the technical documentation and clinical evaluation is separately required.
21 CFR Part 820 (US FDA QSR): In 2024, FDA finalised revisions to 21 CFR Part 820 to align it more closely with ISO 13485:2016. Organisations certified to ISO 13485:2016 are largely positioned for FDA QSR conformance, though specific FDA requirements such as design history files and device master records have specific content requirements.
MDSAP: The Medical Device Single Audit Program allows a single audit to satisfy regulatory requirements in Australia, Brazil, Canada, Japan, and the United States. ISO 13485:2016 is the foundation standard; MDSAP adds jurisdiction-specific requirements as supplementary audit criteria.
Troubleshooting
The Stage 1 audit identified documentation gaps in core procedures
Address Stage 1 findings before accepting Stage 2 scheduling from the CB. Do not attempt to rush Stage 2 with outstanding Stage 1 gaps. Each gap identified at Stage 1 will be reviewed again at Stage 2, and a gap that was identified but not addressed becomes a major nonconformity at Stage 2. Take the time to close the gaps properly.
Process owners are not following the documented procedures
Procedure non-compliance is almost always a procedure design problem, not a behaviour problem. Review whether the procedure accurately reflects how the work is actually done. If the procedure does not match practice, revise the procedure. If the procedure is accurate but not being followed, the training and management review processes need to address it. Do not simply rewrite the procedure to match current non-compliant practice without understanding why the gap exists.
Major nonconformity issued during Stage 2
Do not panic. Major nonconformities during Stage 2 are not uncommon and do not automatically result in certification refusal. Most CBs allow a defined period (typically 90 days) for major nonconformity closure. Respond with a root cause analysis, immediate containment, a corrective action, and a systemic prevention measure. Vague responses that commit to retraining without identifying root cause are frequently rejected by CBs as inadequate.
Quick Checklist: ISO 13485 Implementation
Foundation
Gap assessment completed and project plan approved
QMS scope and clause exclusions documented
Management Representative designated and active
Document control procedure approved and operational
Quality manual drafted and approved by top management
Implementation
All required procedures drafted, reviewed, and approved
Risk management procedure and risk files in place
Competency requirements defined for all quality-relevant roles
Training records current for all affected personnel
Supplier qualification records complete for critical suppliers
Pre-Certification
Full internal audit cycle completed with all findings closed
Management review conducted and documented
Mock Stage 2 audit conducted and findings addressed
Certification body selected and Stage 1 scheduled
Stage 1 findings closed before Stage 2 is accepted
Key Takeaways
ISO 13485 certification is a programme, not a project
The implementation effort produces a QMS that must be sustained indefinitely through surveillance audits, recertification, CAPA activity, internal audits, and management reviews. Organisations that approach it as a one-time project complete certification and then find the QMS degrading through neglect. The resource model that maintains certification must be in place before you apply for it.
Risk management integration is the most common gap in the 2016 standard
Organisations transitioning from the 2003 version frequently apply risk management at the product level and nowhere else. The 2016 edition requires risk-based thinking across supplier selection, process design, monitoring and measurement, and post-market surveillance. Auditors evaluate whether risk management outputs are visible in process records, not just in product risk files.
The internal audit cycle is your best preparation for Stage 2
An organisation that arrives at Stage 2 with a completed internal audit cycle, closed CAPAs, and a documented management review has already demonstrated that the QMS is operational. An organisation that arrives without these elements is essentially asking the certification auditor to conduct the first real assessment of a system that has never been internally reviewed. Complete the full internal audit cycle and give yourself time to address findings before scheduling Stage 2.
Frequently Asked Questions
How does ISO 13485 certification relate to FDA 21 CFR Part 820 compliance?
ISO 13485:2016 and 21 CFR Part 820 address similar subject matter but are separate requirements. FDA’s 2024 revision of 21 CFR Part 820 aligned it more closely with ISO 13485:2016, reducing the gap between the two. However, ISO 13485 certification does not constitute FDA QSR compliance. FDA conducts its own inspections against 21 CFR Part 820 and does not recognise ISO 13485 certificates as substitutes. For devices marketed in the US, QSR conformance must be demonstrated to FDA through inspection, while ISO 13485 certification satisfies requirements in other markets. Some differences remain, including FDA-specific requirements for design history files, device master records, and complaint handling procedures.
Can a small organisation implement ISO 13485 without a dedicated quality department?
Yes. ISO 13485 requires that QMS functions (document control, CAPA, internal audit, management review, supplier management) be operational and responsibility assigned, not that a dedicated department exist. Small organisations often assign these to senior technical or regulatory staff. The risk is that QMS maintenance competes with operational priorities. A part-time dedicated quality resource is more sustainable than distributing QMS responsibilities across staff with competing primary functions, and avoids the common pattern of a QMS that passes initial certification then degrades between surveillance audits because no one owns the maintenance burden.
What is the difference between an ISO 13485 certificate and EU MDR CE marking?
They are different and both may be required for EU market access. ISO 13485 certification covers the quality management system. CE marking under EU MDR 2017/745 requires a notified body to assess the technical documentation for the specific device, including clinical evaluation, conformity to applicable common specifications, and performance testing. For Class IIa, IIb, and III devices, the notified body assesses both the QMS (via a QMS audit aligned with MDR Annex IX) and the device technical documentation. ISO 13485 certification from a notified body designated under MDR supports but does not substitute for the full MDR conformity assessment.
How long does ISO 13485 certification remain valid and what is required to maintain it?
Three years from the certification date, subject to satisfactory annual surveillance audits in years one and two. Recertification in year three involves a full reassessment. Certificates can be suspended if major nonconformities from surveillance audits are not adequately resolved.
Government and Regulatory Sources
Related VelSafe Articles
Building a QMS That Passes Audits and Supports Your Business
ISO 13485 certification is the entry point for most global medical device markets. Getting there requires structured execution: gap assessment, scoping, document development, risk management integration, training, internal auditing, and a well-prepared certification audit. The organisations that achieve and maintain certification do so by treating the QMS as a genuine operational system, not a documentation exercise. The documentation has to reflect actual practice, the internal audit programme has to be genuinely critical rather than confirmatory, and the CAPA system has to address root causes rather than symptoms. Those habits are what makes certification durable. Find more medical device compliance resources at velsafe.com.