731 901 601
ISO 13485 – a quality management system designed for the medical devices industry

ISO 13485 – a quality management system designed for the medical devices industry

The medical devices industry is one of the most heavily regulated industrial sectors in the world. Every product – from a plaster to advanced diagnostic equipment – must meet stringent safety and quality requirements before it reaches a patient or a healthcare facility. ISO 13485 is an international standard for quality management systems designed specifically for this sector – and is increasingly becoming a prerequisite for doing business, rather than merely a source of competitive advantage.

What is ISO 13485 and where does it come from?

ISO 13485 (full title: ‘Medical devices – Quality management systems – Requirements for regulatory purposes’) is a standard developed by the International Organisation for Standardisation, aimed at organisations involved in the life cycle of medical devices. The current version – ISO 13485:2016 – is the third edition of the standard and replaced the 2003 version, introducing a much stronger focus on compliance with regulatory requirements and risk management as an integral part of the quality management system.

The standard is based on ISO 9001, but is not simply an extension of it. ISO 13485 is a stand-alone standard – it contains requirements specific to medical devices, omits certain elements of ISO 9001 that are irrelevant to this sector (e.g. it replaces the concept of continuous improvement with maintaining the effectiveness of the system) and adds requirements not found in ISO 9001, such as process validation, the supervision of sterile devices, and detailed requirements regarding documentation and traceability. A company holding ISO 13485 certification does not automatically receive confirmation of compliance with ISO 9001 – these are two separate certificates, although simultaneous certification to both standards is possible.

ISO 13485 is a standard harmonised with EU law – its implementation is recognised by the European Commission as one of the key elements in demonstrating compliance with the MDR (2017/745) on medical devices and the IVDR (2017/746) on in vitro diagnostic medical devices.

Who it applies to – a wider group than just manufacturers

A common misconception is the belief that ISO 13485 applies exclusively to manufacturers of medical devices. The standard explicitly states that it is intended for all organisations involved in one or more stages of a medical device’s life cycle – regardless of their size or business profile.

In practice, ISO 13485 certification may apply to a wide variety of entities:

  • Manufacturers of medical devices of all classes – from plasters and syringes (Class I) to implants and high-risk diagnostic equipment (Class III)
  • Subcontractors and component suppliers – companies manufacturing components for medical devices, packaging and excipients
  • Importers and distributors – particularly those who repackage devices, alter their labelling or distribute non-EU devices within the EU
  • Service companies – involved in the installation, calibration and servicing of medical equipment
  • Organisations conducting clinical trials – in relation to processes involving medical devices covered by the standard
  • Sterilisation service providers – acting as subcontractors to manufacturers of sterile devices

The final manufacturer’s responsibility for all processes – including those carried out by subcontractors – is particularly emphasised in ISO 13485:2016. The fact that a supplier has a certified system in place significantly facilitates the manufacturer’s conformity assessment.

The role of ISO 13485 in the regulatory ecosystem

ISO 13485 does not operate in isolation from the law – it is closely linked to EU and national regulations on medical devices.

The MDR has been in force since 26 May 2021 and replaced the previous Directive 93/42/EEC. The ISO 13485 standard helps medical device manufacturers and providers of related services to comply with this regulation. For manufacturers of higher-class devices (Classes IIa, IIb, III, and Is, Im, Ir), having a certified quality management system compliant with ISO 13485 is practically a requirement set by the notified bodies carrying out the conformity assessment. ISO 13485 certification alone is not sufficient to obtain the CE marking – however, in practice, it is required by notified bodies as proof that the company has an effective quality management system.

For manufacturers of Class I devices – which are not formally subject to supervision by a notified body – ISO 13485 certification is not legally mandatory; however, the MDR’s requirements regarding the quality management system are, in practice, consistent with the standard’s requirements for all device classes, making the implementation of ISO 13485 the most effective way to meet them.

Outside the EU, ISO 13485 certification is recognised globally – in the US, Canadian, Australian and Japanese markets – as proof that an organisation manages the quality of its medical devices in accordance with a recognised international standard.

Read other posts

EUDR and the furniture and timber industry – why your international customers will soon be asking for documents you don’t yet have

EUDR and the furniture and timber industry – why your international customers will soon be asking for documents you don’t yet have

Poland is one of Europe’s largest furniture exporters. Polish timber and timber products are sold across the EU. read more
GMP in pharmaceutical transport – what requirements must a transport company meet?

GMP in pharmaceutical transport – what requirements must a transport company meet?

Transport companies serving the pharmaceutical industry operate in one of the most demanding sectors of logistics. read more
ISO 27018 – why cloud providers who hold this certification win tenders that others miss out on

ISO 27018 – why cloud providers who hold this certification win tenders that others miss out on

Today’s cloud services market is a market built on trust. Companies and institutions considering moving data to the cloud – particularly the personal data of customers, patients, employees or students – are no longer simply looking for the cheapest or fastest solution. read more
More posts