What is ISO 13485 certification?
- What it managesDesign controls, risk management, traceability and post-market surveillance for medical devices.
- Who certifies to itDevice manufacturers, contract manufacturers, sterilisation and packaging services, importers and distributors.
- Why it matters in IndiaThe quality system behind a CDSCO licence under the Medical Devices Rules, 2017, and the entry point to EU MDR and MDSAP.
ISO 13485 is the quality management system standard for medical devices. It keeps the older eight-clause structure on purpose, because regulators around the world reference it directly, and it is far more prescriptive than ISO 9001 on documentation, design controls, risk management under ISO 14971, sterile processing and traceability. Customer satisfaction is replaced by regulatory conformity as the objective.
Edition status. ISO/TC 210 has the standard under review. The 2016 edition remains the certifiable version and the one regulators reference.
Climate action amendment. ISO 13485 deliberately stays aligned to regulation rather than to the common management system text, so it did not take the 2024 climate amendment.
ISO 13485 is not a stricter version of ISO 9001
They are structurally different standards with different objectives. ISO 13485 keeps the eight-clause layout, retains the mandatory quality manual and management representative that ISO 9001:2015 dropped, and replaces continual improvement and customer satisfaction with maintaining effectiveness and regulatory conformity. Certifying to ISO 9001 first does not shorten an ISO 13485 project by much, and an ISO 13485 certificate does not carry an ISO 9001 certificate with it.
Who needs ISO 13485?
Certification is almost always triggered by a specific buyer requirement rather than an internal decision. These are the segments where it comes up.
| Segment | What usually triggers it |
|---|---|
| Medical device manufacturers | CDSCO licensing, export market access and buyer due diligence |
| In-vitro diagnostic manufacturers | Regulatory classification and notified body expectations |
| Contract manufacturers and OEM suppliers | Customer requirement flowed down from the legal manufacturer |
| Sterilisation and packaging service providers | Part of the device supply chain and audited as such |
| Software as a medical device developers | Design controls and software validation under the same system |
| Importers and distributors of devices | Storage, traceability and vigilance obligations in scope |
The auditable clauses of ISO 13485:2016
What each clause actually demands, and what an auditor will ask to see against it.
| Clause | Title | What it requires |
|---|---|---|
| 4 | Quality management system | General and documentation requirements, including the quality manual, which ISO 13485 still mandates, and a medical device file for each device type or family. |
| 5 | Management responsibility | Management commitment, customer and regulatory focus, quality policy and objectives, a documented management representative role and management review with defined inputs. |
| 6 | Resource management | Competence, infrastructure, and the work environment and contamination control requirements that apply to sterile and cleanroom manufacturing. |
| 7 | Product realisation | The largest clause: planning, customer-related processes, design and development with mandatory design files, purchasing controls, production and service provision with process validation, and control of monitoring and measuring equipment. |
| 8 | Measurement, analysis and improvement | Feedback and complaint handling, reporting to regulatory authorities, internal audit, control of nonconforming product, advisory notices, analysis of data, and corrective and preventive action. |
| ISO 14971 | Risk management (referenced) | Risk management is required across the product lifecycle and is implemented to ISO 14971, which is a separate standard rather than a clause of ISO 13485. |
What ISO 13485 actually gets you
The regulatory backbone
The quality system that CDSCO licensing under the Medical Devices Rules, 2017 and international routes are built on.
Opens export routes
The entry point to EU MDR conformity assessment and to MDSAP, which covers several regulators through a single audit programme.
Risk management across the lifecycle
ISO 14971 integration means hazards are managed from design intent through post-market data, not assessed once at launch.
Traceability that works in a recall
Device-level traceability, with stronger requirements for implantables, is what limits a field action to affected lots.
Process validation discipline
Sterilisation, moulding, welding and software processes get validated rather than inspected after the fact.
Post-market surveillance closes the loop
Complaints and field data feed back into risk management and design, which is what regulators actually examine.
Documented information ISO 13485 requires
The records an auditor will ask for, and the clause behind each one.
| Document or record | Why the auditor wants it |
|---|---|
| Quality manual | Clause 4.2.2. Unlike ISO 9001, ISO 13485 still requires a quality manual, including the structure of the documentation. |
| Medical device file | Clause 4.2.3, per device type or family: description, specification, manufacturing, installation and servicing procedures. |
| Design and development file | Clause 7.3, covering inputs, outputs, review, verification, validation, transfer to production and change control. |
| Risk management file to ISO 14971 | Clause 7.1, across the entire product realisation lifecycle, with a risk management report. |
| Process validation records | Clause 7.5.6, for any process whose output cannot be fully verified by subsequent inspection, including sterilisation and software validation. |
| Sterile device and cleanroom records | Clause 7.5.5 and 6.4.2, including contamination control and environmental monitoring. |
| Traceability records and UDI data | Clause 7.5.9, with enhanced requirements for implantable devices. |
| Purchasing and supplier control records | Clause 7.4, including supplier evaluation criteria and verification of purchased product. |
| Complaint handling and feedback records | Clause 8.2.1 and 8.2.2, with defined timelines for investigation. |
| Regulatory reporting and advisory notice records | Clause 8.2.3 and 8.3.3, including adverse event reporting and field safety corrective actions. |
| Post-market surveillance records | Clause 8.2.1, feeding back into risk management and design. |
| Internal audit reports and management review minutes | Clauses 8.2.4 and 5.6, mandatory before stage 2. |
How to get ISO 13485 certified
Nine stages. The last two are set by ISO/IEC 17021-1 and are the same for every standard, which is why a second certification costs far less than the first.
Gap analysis against the standard
We audit what you already do against every auditable clause of ISO 13485 and hand back a gap register, not a sales document. Most organisations are already meeting 40 to 60 percent of the requirements without having written them down.
Scope, context and risk
Fix the certification scope in writing, the sites, processes and exclusions it covers, then build the clause 4 context, interested parties and the risk register that the auditor will trace everything else back to.
Documented information
Policy, objectives, process maps, procedures and the records each clause requires. We supply working templates and adapt them to how you actually operate, because an auditor tests the system you run, not the one you filed.
Implementation and training
Roll the system out across the departments in scope and run awareness training, plus competence training for the people who will hold specific responsibilities. Keep attendance and competence records; they are audited.
Internal audit
A full internal audit covering every clause and every process in scope, by someone independent of the work being audited. Findings are logged as nonconformities and closed with corrective action, and this evidence is mandatory before a certification body will proceed.
Management review
Top management formally reviews performance against the standard's required inputs: audit results, objectives, nonconformities, feedback and improvement opportunities. Minutes are a stage 1 audit deliverable.
Stage 1 audit (readiness)
The certification body reviews your documentation, confirms the scope, checks your internal audit and management review are real, and identifies what it will focus on in stage 2. Findings here are usually fixable in days.
Stage 2 audit (implementation)
An on-site or remote audit of the system in operation: interviews, records and evidence sampled against each clause. Major nonconformities must be closed before a recommendation for certification; minors are closed within an agreed window.
Certificate issued, then maintained
The certification body issues a certificate with a three-year cycle. Surveillance audits follow in years one and two, and a recertification audit before the third anniversary. Miss a surveillance audit and the certificate can be suspended or withdrawn.
Check accreditation before you buy a certificate
ISO writes standards. It does not audit anyone, does not issue certificates and does not permit its logo to be used on one, so any certificate that presents itself as issued by ISO is wrong on its face. A certificate is worth what its accreditation is worth. In India the accreditation body is the National Accreditation Board for Certification Bodies (NABCB), which operates under the Quality Council of India, accredits certification bodies against ISO/IEC 17021-1, and is a signatory to the IAF Multilateral Recognition Arrangement, which is what makes an Indian certificate acceptable abroad. Before signing, ask for the certification body's accreditation number, confirm the standard and scope are inside its accredited scope, and verify the certificate on the accreditation body's directory or on IAF CertSearch. A certificate issued in 24 hours with no audit is not a certificate a tender committee, an OEM or an enterprise security review will accept.
Start with a ISO 13485 gap analysis
A free consultation with an IncorpX certification specialist: what you already meet, what is missing, an honest timeline, and what the audit will cost.
What ISO 13485 costs
Two separate costs, paid to two different parties. Anyone quoting a single all-in number for an accredited certificate is quoting one of them and hoping you do not ask about the other.
| Cost | Paid to | What drives it |
|---|---|---|
| IncorpX professional fee | IncorpX | Fixed and quoted upfront. From ₹19,999 for ISO 13485, depending on scope, sites and how much of the system already exists. |
| Certification audit fee | The certification body | Audit days, calculated from effective headcount, number of sites and sector risk category under the IAF mandatory documents. |
| Surveillance audit fees | The certification body | Years 1 and 2 of the cycle. Typically a fraction of the initial certification audit. |
| Recertification audit fee | The certification body | Before the third anniversary, to issue a new three-year certificate. |
| Auditor travel and expenses | The certification body | At actuals, where the audit is conducted on site. |
The cheapest quote is usually the unaccredited one
If one quotation is dramatically below the others, the difference is almost never efficiency. It is the audit days. An accredited certification body cannot reduce audit duration below what the IAF mandatory documents require for your headcount and risk category, so a quote that undercuts that arithmetic is either not accredited for ISO 13485, or is not planning to conduct the audit it is quoting for.
Other ISO standards for your sector
Ordered by how often they are held alongside ISO 13485. Because clauses 4 to 10 are shared, a second standard is largely new operational content rather than a new system.
ISO 13485 guides and reference reading
Longer reference reading on ISO 13485 and on ISO certification generally.
Frequently asked questions about ISO 13485
12 questions answered against ISO 13485:2016 and the ISO/IEC 17021-1 certification rules as they stand in August 2026.
Get ISO 13485 certified without the guesswork
Talk to an IncorpX certification specialist for free. Accredited certification bodies, an honest timeline, and a gap analysis before you commit.

