20 certification schemes

ISO 13485:2016

ISO 13485 Certification

The quality management standard for organisations that design, produce, install or service medical devices for regulated markets.

Standard
ISO 13485:2016
Indicative timeline
12-20 weeks, depending on scope and readiness
Discipline
ISO Standards
Assessment type
Independent third-party assessment

The standard

Overview

ISO 13485:2016 sets out quality management system requirements for organisations involved at any stage of the medical device life cycle, from design and production through to storage, distribution, installation and servicing. It keeps a clause structure numbered 4 to 8 rather than the harmonised structure used by newer ISO standards, and places risk management and regulatory obligation at the centre of every process.

Certification shows regulators, distributors and hospital procurement teams that the organisation runs a documented, controlled and traceable quality system. It underpins the quality evidence used in UKCA and CE conformity assessment, although conformity assessment itself is carried out by an Approved Body or notified body and is a separate activity.

UKCert assesses in two stages. Stage 1 reviews the medical device file, risk management records, procedures and the regulatory markets in scope. Stage 2 tests how design controls, process validation, traceability, complaint handling and regulatory reporting work in practice.

Who this is for

  • Manufacturers placing medical devices on the UK or export markets
  • Contract manufacturers and component suppliers to device makers
  • In vitro diagnostic and laboratory device producers
  • Developers of software as a medical device
  • Sterilisation, distribution, installation and servicing providers

What it gives you

Why organisations certify

What a certified ISO 13485:2016 assessment gives you once the certificate is issued.

Regulatory alignment

Maps quality system evidence to UK Medical Devices Regulations and to the quality requirements applied during UKCA and CE conformity assessment.

Risk-based control

Risk management runs through design, purchasing, production and servicing, so hazards are identified, controlled and reviewed across the whole device life cycle.

Design control discipline

Design planning, verification, validation, transfer and change control are documented, so design decisions can be reconstructed years after a device is released.

Traceability and recall

Batch, lot and serial records make field safety actions, advisory notices and recalls faster to scope and easier to evidence to regulators.

Supply chain access

Device makers, distributors and hospital procurement teams routinely ask suppliers for ISO 13485 certification before awarding contracts or approving new components.

Multi-market recognition

ISO 13485 is the reference quality standard across the UK, EU and other regulated markets, reducing duplicated system work between regulatory submissions.

Scope

What the assessment covers

The areas an assessor works through. Your final scope is confirmed in writing before any audit is booked.

  • Medical device file and technical documentation
  • Design and development controls, including design transfer
  • Risk management integrated with ISO 14971
  • Process validation, including sterilisation and software validation
  • Cleanliness, contamination and work environment controls
  • Traceability records for implantable devices
  • Complaint handling and reporting to regulatory authorities
  • Supplier evaluation and purchasing verification

How it runs

The assessment, stage by stage

From first enquiry to certificate. Each stage is agreed with you before it starts.

  1. Scope and application

    We confirm device classes, sites, processes and any non-applicable clauses, then agree audit duration and the regulatory markets the certificate is intended to support.

  2. Stage 1 review

    A documentation and readiness review of the quality manual, medical device files, risk management records and internal audit results, identifying gaps before the main assessment.

  3. Gap closure

    You address the Stage 1 findings and confirm readiness. Where preparation is needed, Stage 2 is scheduled to allow the system to generate operating records.

  4. Stage 2 assessment

    Auditors test implementation across design, production, servicing and post-market activities, interviewing staff and sampling records at each site included in the scope.

  5. Certification decision

    Nonconformities are graded major or minor. Once corrections and corrective actions are accepted, an independent reviewer takes the certification decision and the certificate is issued.

  6. Surveillance and recertification

    Surveillance audits are carried out annually against a sampled programme. A full recertification audit covers the whole system before the three-year certificate expires.

Questions

ISO 13485:2016 — frequently asked

Anything here that does not cover your situation, put it to an assessor rather than guessing at it.

Ask a question

For most organisations the route from readiness to certificate runs twelve to twenty weeks, depending on device class, number of sites and whether design and development sits inside the scope. Manufacturers with sterile products or extensive process validation tend towards the longer end. Distributors and servicing organisations are often shorter. The system also needs enough operating history to produce internal audit and management review records.

Certificates run for three years. Surveillance audits take place annually and a recertification audit covering the full system is carried out before expiry. The certificate stays valid through that cycle provided surveillance is completed on schedule and nonconformities are closed within the agreed timescales. Changes to scope, sites or device range should be notified so the certificate remains accurate.

No. ISO 13485 is a voluntary standard rather than a statutory requirement. The UK Medical Devices Regulations 2002 require manufacturers to operate a quality system appropriate to the device class, and ISO 13485 is the recognised way to demonstrate one. Conformity assessment for UKCA marking is carried out by a UK Approved Body, which is separate from ISO 13485 certification.

Surveillance samples the system rather than repeating Stage 2 in full. Each visit covers management review, internal audit, complaints and regulatory reporting, corrective action, changes since the last audit and use of certification marks. Remaining clauses are sampled across the cycle so the whole standard is covered by recertification. Major nonconformities left open can lead to suspension.

No. MDSAP is a separate audit programme run by participating regulators, and the FDA Quality Management System Regulation incorporates ISO 13485 but adds its own requirements and inspection route. An ISO 13485 system provides most of the underlying structure for both, but each needs its own audit or inspection. We assess against ISO 13485:2016 only.

Certifying against more than one standard?

Where you hold several standards, shared clauses are assessed once in a combined visit rather than as separate audits. Talk it through with an assessor before you decide what ISO 13485:2016 should sit alongside.