731 901 601
ISO 13485 and the MDR – how does the standard support compliance with EU medical device legislation?

ISO 13485 and the MDR – how does the standard support compliance with EU medical device legislation?

Regulation (EU) 2017/745 of the European Parliament and of the Council – commonly known as the MDR – has been in force since 26 May 2021 and replaced the previous Directive 93/42/EEC. For manufacturers and distributors of medical devices, this meant a fundamental change in the requirements concerning conformity assessment, technical documentation and post-market surveillance. ISO 13485, although a voluntary standard, has in practice become one of the key tools for demonstrating compliance with the MDR – and on multiple fronts simultaneously.

What the MDR requires and how ISO 13485 addresses this

The MDR requires medical device manufacturers to implement a quality management system (QMS) covering all aspects of their activities relating to the device – from design and manufacture, through post-market surveillance, to the management of adverse events. The requirements for the QMS are set out in Article 10 of the MDR and include, amongst other things, risk management, process validation, control of non-conforming devices, control of documentation and traceability.

ISO 13485 is not a standard harmonised with the MDR in a formal legal sense – its application does not automatically lead to a presumption of conformity with the Regulation, as is the case with harmonised standards. However, it is widely recognised by notified bodies as a standard whose fulfilment demonstrates that a manufacturer has an effective and properly organised quality management system. In practice, this means that a manufacturer seeking conformity assessment by a notified body is in a much stronger position if they can present an ISO 13485 certificate – rather than having to prove from scratch that their quality system meets the requirements of the MDR.

There are extensive substantive links between the standard and the Regulation. The MDR’s requirements on risk management correspond to those of ISO 13485 regarding the application of ISO 14971. The MDR’s requirements on the validation of manufacturing processes are consistent with Section 7.5 of the standard. The Post-Market Surveillance (PMS) system required by the MDR is reflected in the requirements of ISO 13485 concerning monitoring and measurement after a device has been placed on the market. We have set out the detailed requirements for a quality management system in accordance with ISO 13485 in a separate article.

Key areas in which ISO 13485 supports compliance with the MDR

How does ISO 13485 help to meet the requirements for a PMS? The MDR requires manufacturers to actively collect and analyse data relating to the device after it has been placed on the market – including complaints, adverse events, clinical trial results and data from the literature. ISO 13485 requires the same as part of the product monitoring and measurement process, including the obligation to analyse data and incorporate the results into the management system review. A well-structured ISO 13485 system provides a ready-made process infrastructure for the PMS required by the MDR.

How does the standard support the requirements for technical documentation? The MDR requires complete technical documentation for the device, including a description of the device, the results of the clinical evaluation, the risk analysis, biosafety data and the results of validation. ISO 13485, in the section on design and development control, requires the documentation of all design inputs and outputs, the results of verification and validation, and the management of design changes. Compliance with the standard’s requirements in this area forms the foundation of the technical documentation required by the MDR.

What about traceability and the UDI system? From 26 May 2025, the MDR requires a UDI (Unique Device Identifier) code to be included on the labels of all Class I devices and for devices to be registered in the European EUDAMED database. ISO 13485 has for years required documented traceability of devices – from raw materials and components, through production, to delivery to the customer. A company that has implemented ISO 13485 already has traceability mechanisms in place, which can be relatively easily extended to meet the requirements of the UDI system.

How does ISO 13485 support the supplier oversight required by the MDR? The MDR places responsibility on the manufacturer for suppliers and subcontractors involved in the product manufacturing process. ISO 13485 requires a documented system for the assessment, selection, monitoring and reassessment of suppliers of critical components and services. In practice, a supplier’s ISO 13485 certificate is one of the strongest pieces of evidence confirming that the final manufacturer exercises appropriate oversight of the supply chain.

ISO 13485 and the MDR – what the standard covers and what it does not replace

ISO 13485 is a powerful tool for supporting compliance with the MDR, but it is not a substitute for it. There are several key differences between the standard and the regulation that manufacturers must bear in mind.

The MDR requires a clinical evaluation of the device – a documented analysis of clinical data confirming safety and clinical effectiveness. ISO 13485 does not contain any requirements regarding clinical evaluation – this is a purely regulatory requirement that must be met regardless of certification to the standard.

The MDR imposes requirements regarding the registration of entities and devices in the EUDAMED database, as well as reporting obligations to regulatory authorities, which ISO 13485 does not address.

Finally, the MDR defines device risk classes (I, IIa, IIb, III) and assigns different conformity assessment pathways to them – some of which require the involvement of a notified body, regardless of whether an ISO 13485 certificate is held. The standard supports the assessment process but does not replace it.

The optimal approach is to treat ISO 13485 and the MDR as complementary tools: the standard establishes a quality management system which serves as the infrastructure for meeting regulatory requirements, whilst the MDR defines the legal obligations, compliance with which is documented and managed by that system. If you are planning to implement ISO 13485 or are preparing your organisation to meet the requirements of the MDR, find out what the ISO 13485 certification process involves and how we can support your company.

Read other posts

Supplies for the military and NATO – how does AQAP certification open up a market to which others have no access?

Supplies for the military and NATO – how does AQAP certification open up a market to which others have no access?

Defence spending in Poland is growing at a rate not seen for decades. The defence budget has exceeded 4% of GDP, programmes to modernise the armed forces are underway, and Poland has become one of the key focal points for NATO investment in Central Europe. read more
Deposit-refund schemes and the PPWR – how is the regulation changing the approach to returnable packaging?

Deposit-refund schemes and the PPWR – how is the regulation changing the approach to returnable packaging?

In October 2025, a deposit-refund scheme was launched in Poland for selected single-use packaging – PET bottles up to 3 litres, glass bottles up to 1.5 litres and aluminium cans up to 1 litre. read more
EU Regulation on deforestation-free products

EU Regulation on deforestation-free products

EU Regulation 2023/1115 of 31 May 2023 on deforestation-free products (the European Deforestation-Free Products Act), commonly referred to as the EUDR Regulation, is a key element of the European Union’s policy to combat deforestation and forest degradation worldwide. read more
More posts