ISO 13485 Medical Devices Quality Management Systems

  • Overview
  • Benefits of Certification
  • Why Work With NSF?
  • Certification Process
  • ISO 13485:2016 Revision

ISO 13485 sets regulatory requirements or, when specified, customer requirements for a management system for medical devices or services. The primary objective of ISO 13485 is to harmonize medical device regulatory requirements for quality management systems. The standard is specific to organizations providing medical devices or services, regardless of the type or size of the organization. Based on the ISO 9001 process approach to quality management, ISO 13485 focuses on what manufacturers must do to provide safe and effective medical devices.

Benefits of Certification

The benefits of ISO 13485 certification include demonstration of regulatory compliance and more effective risk management. Certification aids compliance to national or international regulatory requirements. Certification also confirms to customers, suppliers and other stakeholders that the organization is in a state of control over its operations.

Third-party certification is preferred in many international markets, and is the accepted basis and starting point to achieve the medical device CE mark. It can also be used as a bench mark to meet good manufacturing practice (GMP) compliance in the United States. An ISO 13485 certified quality management system can aid access to U.S. and international markets.

In addition, certification:

  • Enables your organization to prepare for product-to-market regulatory requirements for the medical device markets of Europe, Australia, Asia and all major developed as well as emerging markets
  • Provides confidence of quality risk management and good manufacturing practices within the medical device supply chain throughout the medical device product life cycle
  • Provides assurance that appropriate regulatory requirements are implemented within your organizational processes
  • Provides confidence that best practice validation and GMP have been implemented and evaluated

Why Work With NSF?

Our experienced auditors bring real-world knowledge and practical experience to our auditing program. In addition:

  • NSF-ISR offers value-added auditing. Our approach ensures audits focus on important business areas and, where applicable, upcoming changes to regulatory requirements.
  • Our stringent auditor training and ongoing evaluations ensure consistency of your audits. Our lead auditors are assigned long term to provide continuity.
  • Additional services including expert training and education in medical device design, testing and manufacture are available through NSF's health sciences team.
  • We offer combined or integrated audits with other standards, e.g. ISO 9001, AS 9100 or IATF 16949.

Certification Process

The NSF-ISR ISO 13485 quality systems certification process consists of these steps:

  1. Application and Contract
    Your company submits an application and signs a contract (master agreement).
  2. Audit Team Assignment
    NSF-ISR assigns an auditor team.
  3. Document Review
    We perform a document review (when required) for the management system (MS) and issue a report of conformance or nonconformance.
  4. On-Site Readiness Review (ORR-Stage 1 Audit)
    As the first stage of the certification process, NSF-ISR verifies readiness of the MS to continue with the certification process.
  5. Certification Audit (Stage 2)
    Our audit team conducts an on-site audit to verify conformity to the specified standard.
  6. Independent Review
    A certification board reviewer recommends the final certification/recertification decision.
  7. Notification of Certification
    We notify your organization in writing, issue the certificate and publish the certification in our online listings.
  8. Surveillance Audits
    NSF-ISR performs semiannual or annual audits to verify the MS is being maintained.
  9. Reassessment
    NSF-ISR performs reassessment audits in accordance with requirements.

ISO 13485:2016 Revision

The International Organization for Standardization (ISO) published the updated ISO 13485 medical devices quality management systems standard on March 1, 2016. ISO 13485:2016 can be used by organizations involved in the production, post-production, storage, distribution, installation, servicing, final decommission and disposal of medical devices. There is also a provision for services associated with the medical device industry.

Key improvements in the 2016 version include:

  • Expansion of the standard’s applicability to include all organizations involved in the life cycle of the product, from inception to end of life
  • Enhanced transparency of requirements
  • Greater focus on post-market surveillance (including complaint handling)
  • Improved alignment with regulatory requirements
  • Greater applicability of the standard throughout the medical device’s life cycle
  • More emphasis on implementing the appropriate infrastructure, particularly for the production of sterile medical devices

Timeline for transition:

  • January 18, 2017: NSF-ISR is fully accredited to ISO 13485:2016, clients can begin transitioning.
  • September 14, 2018: ISO 9001:2015 transition deadline. Organizations that have ISO 9001 with ISO 13485 may need to separate their audits.
  • November 30, 2018: All ISO 13485 clients will have until this date to complete their upgrade audit. A review will be conducted for clients who have not upgraded their medical devices certificate to determine the extent of their recertification status.
  • February 28, 2019: Deadline for all NSF-ISR clients registered to ISO 13485:2003 will be required to upgrade to the 2016 standard.
  • March 1, 2019: Clients certified to ISO 13485:2003 will be dropped from the NSF-ISR system on if they have failed to upgrade their certification by this date.

Transition Guide

NSF-ISR has developed a helpful guide to the newly revised ISO 13485:2016 standard. Download the guide

Upgrade Planner and Delta Checklist

NSF-ISR has developed an exclusive document that captures areas of new requirements, changes and updates from the previous version of the standard. Once completed, you can send it to your NSF-ISR Lead Auditor to confirm the effective implementation of your ISO 13485:2016. Download the checklist


NSF International, NSF’s parent company, offers a number of medical device courses and webinars. View the courses and webinars

Use of any NSF International training or consulting service does not, in any way, make NSF-ISR certification simpler, easier, faster or less expensive. NSF-ISR is a wholly owned subsidiary and makes impartial certification evaluations and decisions independent of any NSF International services.

Contact NSF International

  • Mailing List

  • Or contact the nearest NSF location
  • [x] Close