ISO 13485 Consultants for Medical Device Manufacturers
Compliance Management Solutions helps medical device manufacturers establish practical, compliant and audit-ready ISO 13485 quality management systems that fit the business rather than sitting on top of it. We design and implement the system, audit it independently, and prepare you for certification, whether you are launching a new device company, entering new markets or rebuilding a system that no longer reflects how you work.
Talk to us about your quality system Call +61 4 33 124 266
What ISO 13485 is
ISO 13485:2016, Medical devices: Quality management systems: Requirements for regulatory purposes, sets out the requirements for a quality management system where an organisation needs to show it can consistently provide medical devices and related services that meet customer and regulatory requirements. It applies at any stage of the device life cycle, from design and production to storage, distribution, installation and servicing, and to suppliers of those organisations. The current edition was published in 2016, and ISO lists it as confirmed, with no revision under way as of September 2026.
It began as a set of particular requirements for applying ISO 9001, but has evolved into a stand-alone standard. A business already certified to ISO 9001 still has real work to do, although much of its system can be carried across.
Why it matters for market access
ISO 13485 is the quality management system standard that regulators and their auditors use around the world, but how it is used differs by market:
- Australia. The TGA audits manufacturers' quality management systems against ISO 13485:2016 alongside the Therapeutic Goods Act and Regulations. Under a TGA order, a system that meets ISO 13485 is treated as meeting the quality management system parts of the full, production and product quality assurance procedures. Our conformity assessment page explains which procedure each device class uses.
- European Union. The EU MDR requires every manufacturer (other than for investigational devices) to maintain a quality management system, and EN ISO 13485:2016 is a harmonised standard under the MDR and IVDR.
- United States. Since 2 February 2026, the FDA's Quality Management System Regulation incorporates ISO 13485:2016 by reference. The FDA does not require ISO 13485 certification and still inspects. See our FDA 510(k) page.
- MDSAP. The Medical Device Single Audit Program is based on ISO 13485 plus the requirements of its members: the TGA, Brazil's ANVISA, Health Canada, Japan's MHLW and PMDA, and the US FDA. All Canadian medical device licence holders participate in it.
A certificate is not the same as ARTG evidence. The TGA states that an ISO 13485 certificate is not acceptable manufacturer evidence for non-IVD medical devices, and it stopped accepting ISO 13485 certificates for most IVD applications in May 2023. For ARTG inclusion, the TGA looks for conformity assessment evidence, such as a TGA certificate or evidence from a comparable overseas regulator, and for MDSAP it needs the certificate to show the manufacturer was assessed against the relevant Australian regulations. ISO 13485 is what those assessments audit against, so the quality system still has to be built to it.
Not every device needs an assessed quality system in Australia. A Class I device that is not sterile and has no measuring function, and a Class 1 IVD, can be supplied on the manufacturer's Declaration of Conformity, although the manufacturer must still keep technical documentation and a post-market system.
How we help
- Complete ISO 13485:2016 implementation: quality manual and procedure development, risk-based process mapping, and SOP, form and template creation.
- The processes auditors look at closely: design and development, supplier and purchasing controls, and CAPA, complaint handling and post-market surveillance.
- Gap assessments and independent internal audits in accordance with ISO 19011, against ISO 13485, MDR, IVDR and MDSAP, with each nonconformity supported by a practical recommendation.
- Internal audit preparation and management review implementation, so the system is running and producing records before certification.
- Readiness for certification, including coordinated quotations and liaison with notified body partners.
- Risk management to ISO 14971, and integration with existing ISO 9001, OH&S or environmental management systems.
- Staff training and ongoing compliance support, including our ISO 13485 courses and a four-day lead auditor training workshop.
Our team has worked on every side of the audit table, as first, second and third-party ISO 13485 auditors. Our director, George Loizou, has worked as a notified body and MDSAP auditing organisation lead auditor and as a notified body technical file reviewer, so we build systems with the certification auditor's questions in mind.
How implementation works
- Gap assessment against ISO 13485 and the regulations of your target markets.
- Process mapping of how the business actually operates, with the risks at each step.
- Documentation: quality manual, procedures, forms and records, written to fit those processes.
- Training so staff can run the system, not just read it.
- Operation: the system runs long enough to produce records, including supplier controls, complaints and CAPA.
- Internal audit and management review, with any nonconformities corrected.
- Certification audit by an independent certification body, usually in two stages, followed by surveillance audits.
The TGA's own list of common problems with new quality systems includes treating the system as a collection of documents rather than a business system, building it on the structure of ISO 13485 rather than on how the business operates, and building it around what the certifying body is thought to want. Designing around the business avoids all three.
What auditors most often find
The TGA has published the ISO 13485 clauses most often cited in its audits between July 2021 and June 2023:
| Clause | Area | Major | Minor |
|---|---|---|---|
| 4.2.1 | Documentation, including regulatory requirements | 16 | 7 |
| 4.1 | General quality system requirements | 15 | 25 |
| 7.4.1 | Supplier management | 12 | 20 |
| 8.5.2 | Corrective action | 12 | 14 |
| 4.2.4 | Document control | 10 | 30 |
| 4.2.5 | Record control | 6 | 35 |
| 8.2.4 | Internal audit | 5 | 26 |
| 7.5.1 | Control of production and service provision | 7 | 19 |
| 6.2 | Competence and training | 7 | 22 |
More than half the manufacturers the TGA audited over that period had nonconformities in document and record control, and initial audits produced more nonconformities than surveillance or recertification audits.
Certification
ISO 13485 certificates are issued by independent certification bodies. JASANZ is the accreditation body for Australia and New Zealand; certification bodies may also be accredited by another signatory to the international mutual recognition arrangement. Certificates from accredited bodies can be checked on IAF CertSearch. Certification usually runs on a three-year cycle: an initial audit in two stages, surveillance audits in the following years, then recertification. For higher-risk devices the first stage is normally on site. As the TGA puts it, audits are usually every year, although some certifying bodies schedule them differently.
Frequently asked questions
Is ISO 13485 certification mandatory in Australia?
Not for every device. Manufacturers of certain devices must have a formal quality management system that is independently assessed, but a Class I device that is not sterile and has no measuring function, and a Class 1 IVD, can be supplied on the manufacturer's Declaration of Conformity without an assessed quality management system. The TGA also states that not all manufacturers are required to hold TGA or third-party certification.
Is an ISO 13485 certificate enough for ARTG inclusion?
No. The TGA states that an ISO 13485 certificate is not acceptable manufacturer evidence for non-IVD medical devices, and it stopped accepting ISO 13485 certificates for most IVD applications in May 2023. What the TGA accepts is conformity assessment evidence, such as a TGA conformity assessment certificate or evidence from a comparable overseas regulator, much of which is itself based on audits against ISO 13485.
Who issues ISO 13485 certificates?
Independent certification bodies. JASANZ is the accreditation body for Australia and New Zealand; certification bodies may also be accredited by another signatory to the international mutual recognition arrangement. Certificates issued by accredited bodies can be checked using IAF CertSearch.
Does the FDA require ISO 13485 certification?
No. Since 2 February 2026, the FDA's Quality Management System Regulation incorporates ISO 13485:2016 by reference, but the FDA has said it does not intend to require ISO 13485 certification, and it will not accept a certificate as a substitute for an inspection.
How often is an ISO 13485 system audited?
Certification usually runs on a three-year cycle: an initial two-stage audit, surveillance audits in the following years, and a recertification audit. MDSAP works the same way, with annual audits within a three-year certification cycle.
Can we leave design and development out of our quality system?
Only where the applicable regulations permit it, and the claim of conformity must reflect the exclusion. Other requirements in clauses 6, 7 and 8 can be treated as not applicable only where they do not apply to your activities or device, and the justification must be recorded.
Is Compliance Management Solutions a certification body?
No. We do not issue ISO 13485 certificates. We design and implement the quality management system, audit it independently, and prepare you for the certification audit, and we coordinate quotations and liaison with notified body partners.
Further reading
- ISO 13485 QMS implementation services
- Independent internal audits to ISO 19011
- How to implement ISO 13485 properly
- ISO 13485 implementation guide for medtech
- ISO 13485 for medical device market readiness
- MDSAP: what medical device manufacturers need to know
Regulatory information on this page is drawn from TGA, FDA, EU and MDSAP sources and ISO's published data as current at September 2026, linked above. It is general information, not advice for a specific device.