REGQUALITYREVIEW

Evidence for systems that carry regulated work.

Medical Devices · Primary-source analysis

ISO 13485 governs the device QMS—not a software badge

ISO's current record defines a medical-device quality-management-system standard for organizations across the lifecycle. It does not certify an application or make a configured workflow conforming by itself.

Editorial figure by RegQuality Review. Source context: ISO — ISO 13485:2016.

The governed object is the quality management system

ISO's title and public explanation place ISO 13485 at the level of an organization's medical-device quality management system. The record reaches design, production, installation, servicing, suppliers, and related external parties rather than defining one application as the quality system.

A platform may support controlled documents, training, change, supplier, complaint, corrective-action, and other records. The organization still owns the processes, responsibilities, product context, regulatory interpretation, and evidence that make those records meaningful.

The edition and current status belong in the record

The ISO page identifies Edition 3, a March 2016 publication date, and a 2025 confirmation. Those facts support a precise version field and avoid the vague claim that a system simply supports ISO 13485 without saying which edition is being mapped.

Confirmation means the published edition remains current in ISO's lifecycle record. It does not establish that a provider's template, content library, or marketing page has been updated, validated, purchased, configured, or adopted in a buyer's controlled environment.

A mapping is not a conformity conclusion

Requirements mapping can help teams locate where procedures, records, approvals, and evidence live. Its usefulness depends on the buyer's processes, product scope, jurisdictions, supplier relationships, validation approach, access controls, change controls, and retained history.

A feature name or standards badge cannot establish effective operation, certification, regulatory acceptance, or device conformity. Buyers should ask which exact workflow was mapped, who approved the interpretation, what configuration was tested, and which evidence can be exported for review.

The public page is not the licensed requirements

ISO's public page provides authoritative identity, status, edition, scope, and high-level explanation. The detailed requirements are in the protected standard, so a public product evaluation should not reconstruct clauses or present a summary as the complete normative text.

The safer buyer test starts with the official edition and the organization's authorized requirements source, then traces representative processes through roles, records, exceptions, change history, and evidence retrieval. That tests the operating system without implying that the publication or a software provider performs certification.

Enterprise buyer test

Translate this change into the exact population, record type, workflow stage, decision owner, effective date, and evidence that could be affected. Ask current or prospective providers to demonstrate the named workflow with representative data and an exception—not a polished feature tour. Record what official documentation establishes, what a provider states, what the team observes, and what remains unresolved.

A defensible review also identifies the dependency outside the product. Authority interpretation, policy configuration, data quality, integrations, human judgment, approval rights, release governance, training, and retained evidence may remain customer or service responsibilities. The evaluation should preserve those boundaries instead of treating a technology claim as the complete operating model.

What we will watch next

RegQuality Review will watch the named source and affected market records for later evidence that changes status, scope, availability, implementation timing, workflow consequence, or the limits of the initial report. A later announcement does not silently overwrite this dated account; the change ledger preserves the sequence.

Primary source: ISO — ISO 13485:2016 · Official consensus-standard record.

Evidence boundary: This article independently analyzes ISO's public record for ISO 13485:2016 reviewed August 9, 2026. It does not reproduce the licensed standard and is not quality, regulatory, validation, certification, conformity-assessment, product, clinical, or legal advice.

Editorial record: Published August 9, 2026; updated August 9, 2026. Corrections policy.