ISO 13485:2016 Medical devices — Quality management systems — Requirements for regulatory purposes
ISO 13485 specifies quality-management-system requirements for organizations involved in one or more stages of the medical-device lifecycle and emphasizes regulatory requirements, risk-based processes, supplier control, documentation, and product realization.
What the authority record establishes
ISO 13485 specifies quality-management-system requirements for organizations involved in one or more stages of the medical-device lifecycle and emphasizes regulatory requirements, risk-based processes, supplier control, documentation, and product realization.
Voluntary as an ISO standard unless incorporated into regulation, conformity-assessment scheme, contract, or organizational policy; incorporated by reference in FDA QMSR
The exact official title, issuing body, jurisdiction, version or application record, and linked source define the scope of this page. Readers should not transfer the authority's status to a commercial product or infer transaction-, patient-, system-, site-, or organization-specific applicability from this summary.
Why it matters to this market
The standard is a central organizing reference for medical-device QMS design and is incorporated into the U.S. QMSR. Buyers need systems that can express their own processes and evidence without treating a vendor template as the standard itself.
Affected operating stages
- Quality-System Governance
- Design And Development
- Purchasing And Supplier Control
- Production And Service Provision
- Measurement And Analysis
- Complaints And Feedback
- CAPA And Improvement
Capabilities to examine
Controlled Documents
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for controlled documents.
Training Management
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for training management.
Quality Events And Deviations
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for quality events and deviations.
CAPA
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for CAPA.
Change Control
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for change control.
Audit And Inspection Management
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for audit and inspection management.
Supplier Quality
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for supplier quality.
Complaints And Post-Market Quality
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for complaints and post-market quality.
Quality Risk Management
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for quality risk management.
Design Controls And Product Traceability
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for design controls and product traceability.
Analytics And Management Review
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for analytics and management review.
Affected buyer audiences
- medical-device and IVD manufacturers
- critical suppliers and service providers
- quality and regulatory leaders
- certification and internal-audit teams
- software and system owners
Implementation questions
- Which entities, products, populations, transactions, systems, sites, or jurisdictions are actually within scope?
- What is binding, what is guidance, and what is a technical or consensus standard?
- Which publication, adoption, effective, application, transition, and enforcement dates differ?
- Who owns legal, clinical, quality, regulatory, policy, or operational interpretation?
- How will a source revision affect open work and historical decisions?
Interpretation boundary
ISO publishes the standard and does not certify organizations or software. The public ISO page summarizes scope; detailed requirements are in the licensed standard.