ISO 13485 – Medical devices

ISO 13485 is the quality management standard for medical devices. It largely follows the structure of ISO 9001 but shifts the emphasis. The primary concern is not improvement, it is evidence. Every product has to be safe and effective, and exactly that has to remain demonstrable, over years, for every single batch.

This is why the standard is specific where ISO 9001 leaves room. It requires documented procedures, fixed retention periods and a consistent link to risk. Anyone coming from an existing ISO 9001 system tends to underestimate that difference. The structure already fits; what is missing is the depth of evidence.

Who it applies to

Where it usually goes wrong

Software validation is overlooked

The standard requires documented evidence of suitability for every piece of software that controls quality-relevant processes or holds records. This does not only mean the ERP system. It also means the test software at the measuring station, the document management system and the calibration records. In most businesses a list of these systems exists, and it is too short.

What is missing most often is the self-built solutions: the spreadsheet with a macro that evaluates test values, or the Access form used for batch traceability. Those are precisely the tools that are quality-relevant, yet they rarely appear on the list. In the audit they are the first thing we ask about. Evidence of suitability need not be thick: purpose, requirements, test cases, result, release. If it emerges along the way that the spreadsheet is no longer up to its job, the route via Software & databases is usually the more honest one.

Traceability and change control break at the edges

Within a company's own production, traceability almost always works. Batches are recorded, test reports are on file, the chain is closed. The problems arise at the edges. For bought-in parts, the batch information from the upstream supplier is often missing. Rework is carried out but not documented as a step in its own right. Returns from the market re-enter the process without their history travelling with them.

Change control shows the same pattern. A change to the product pulls a series of records behind it: risk analysis, verification, technical documentation and, in some cases, informing the notified body (benannte Stelle). Nobody follows that chain through systematically. Usually it exists only in one person's head. When that person is unavailable, it surfaces at the next audit.

Supplier evaluation stays a list

Suppliers are qualified once. Questionnaire completed, certificate filed, approval granted, and after that nothing happens. The list grows, but it is never evaluated.

The standard requires ongoing evaluation. It calls for criteria, a regular review and a response when a supplier no longer meets those criteria. This needs no elaborate machinery. Complaints, delivery reliability and inspection results are available anyway. They simply have to be brought together and looked at once a year.

How we support you

We begin with a baseline assessment. What exists, what is actually lived, what is genuinely missing? In businesses with an ISO 9001 system the gap is often smaller than feared, but it sits in unexpected places. Out of that comes a plan with clear priorities.

We then build up or slim down, carry out internal audits and prepare you for the notified body. Details under Building a management system and Internal audits & gap analyses.

Software validation and the evidence trail are our own trade. We do not only assess whether a solution will hold up. Where needed, we build it.

Who handles this at our end

Marion Rammé – IRCA certified and registered QMS / EMS / OHSMS Lead Auditor #01194927

Rüdiger Rammé – IRCA certified and registered QMS / OHSMS Lead Auditor #01192806

Michael Bremer – subject matter expert for laboratory accreditation, medical devices and measurement uncertainty

The team in detail

Frequently asked questions

How long does it take to reach certification?

Expect nine to eighteen months if you start without a management system. From a well-kept ISO 9001 system it goes considerably faster. The time factor is rarely us; it is the evidence. Validations, risk files and technical documentation need input from your own people.

What does it cost?

Projects of this kind typically range between 10,000 and 50,000 euros. What decides it is the size of the company, the product risk, the maturity of the existing documentation and the share you take on yourselves. The certification body charges its fees separately.

We are already certified to ISO 9001. How much does that help?

A fair amount. The high-level structure, the process landscape and the audit routine can all be carried over. What you mainly have to add is depth of evidence: documented procedures, traceability, risk management across the product life cycle, and the retention periods. The two standards can be run well as a single system.

Do we really have to validate every spreadsheet?

Every one that controls a quality-relevant process or holds records. A spreadsheet for holiday planning does not fall under it; one holding test values does. The evidence is manageable: purpose, requirements, test cases, result and release. The effort only arises the first time.

Does ISO 13485 cover the MDR?

No. ISO 13485 is no substitute for the MDR, Regulation (EU) 2017/745. It does, however, support the MDR's requirements for a quality management system to a large extent and is in practice the usual route towards them. The regulatory assessment of your specific product belongs in the hands of your notified body (benannte Stelle).

Let us talk about it

The first conversation is free and without obligation.

Get in touch