Sep 4, 2026
Breaking News: MDR classes explained for EU medical device classification
Regulatory

ISO 13485 certified companies and what the certificate actually proves

August 30, 2026
camera, lens, nikon, strap, map, travel, adventure, iso, shutter, aperture, technology, iso, iso, iso, iso, iso

What ISO 13485 certified companies are

ISO 13485 certified companies are organizations whose medical device quality management system has been independently audited against ISO 13485:2016 for a defined scope, location and set of activities. The phrase does not mean that ISO approved the company, that every product made by the company is cleared for sale, or that a supplier can replace your own regulatory due diligence. For medical device manufacturers, buyers and quality teams, the practical question is narrower: does the certificate cover the process, site and responsibility you intend to rely on?

As of August 30, 2026, ISO lists ISO 13485:2016 as the published and confirmed edition of the standard. ISO describes it as a quality management system standard for organizations involved in the design, production, installation and servicing of medical devices and related services. For more regulatory context, see the site’s Regulatory section.

camera, canon, lens, iso, aperture, shutter, photography, photo, photographer, people, iso, iso, iso, iso, iso, people

The certificate should be treated as evidence of a controlled management system, not as a guarantee of product performance. In practice, it is a starting point for supplier qualification, technical documentation review, quality agreement drafting and market-specific compliance checks.

What the certificate covers and what it does not cover

A common mistake is to read ISO 13485 certification as a company-wide badge. Certification is tied to a stated scope. That scope may cover design and development, manufacture, installation, servicing, distribution, sterilization management, packaging, software development or other defined activities. It may apply to one legal entity and one or more listed sites, not necessarily every facility owned by the group.

ISO also makes an important distinction: ISO develops standards, but it does not perform certification or issue certificates. Certification is normally performed by an external certification body. For regulated medical device use, buyers should prefer certificates issued by accredited certification bodies or, where relevant, recognized auditing organizations.

Item to read on the certificate What it tells you Why it matters
Standard edition Usually ISO 13485:2016 Confirms which requirements were used for the audit.
Legal entity The organization that holds the certificate A parent company certificate may not cover a subsidiary or contract site.
Site address The audited physical locations Manufacturing, warehousing and design sites may be treated differently.
Scope statement Activities and device categories covered A machining scope does not automatically cover sterile barrier packaging or design control.
Certification body and accreditation Who issued the certificate and under what recognition Helps distinguish credible third-party certification from weak marketing claims.
Issue and expiry dates Certification cycle status An expired or suspended certificate should not support supplier approval.

The most useful certificate is specific. A vague scope such as medical devices, without process, product or service boundaries, is less helpful than a scope that identifies design, manufacture, distribution or servicing of defined device families.

Why ISO 13485 matters more after the FDA QMSR transition

For companies selling into the United States, the regulatory context changed significantly on February 2, 2026. FDA’s Quality Management System Regulation became effective on that date after the final rule was published on February 2, 2024. The revised 21 CFR Part 820 incorporates ISO 13485:2016 by reference and renames the former Quality System Regulation as the Quality Management System Regulation.

This does not mean that U.S. medical device manufacturers must obtain an ISO 13485 certificate. FDA’s QMSR frequently asked questions state that FDA will not require certificates of conformance to ISO 13485 and will not issue such certificates. FDA also continues to conduct inspections. In other words, certification may provide a strong foundation for QMSR alignment, but it does not prove full U.S. compliance on its own.

For ISO 13485 certified companies already selling in the U.S., the practical task is to review gaps between the certified QMS and FDA-specific requirements. Areas that often need explicit attention include FDA definitions, record requirements, complaint handling interfaces, labeling and packaging controls, adverse event reporting links, recall procedures and inspection readiness. The certificate can reduce duplication, but it cannot replace a regulatory compliance program.

How certification fits with EU MDR, Canada and MDSAP

ISO 13485 is widely used because it maps well to regulatory expectations, but each market uses it differently. The European Union Medical Device Regulation requires manufacturers to establish, document, implement, maintain and keep effective a quality management system under Article 10(9). ISO 13485 is commonly used to structure that system, but an ISO 13485 certificate alone is not a CE certificate and does not authorize placing a device on the EU market.

Under the EU MDR, the manufacturer still needs the applicable conformity assessment route, technical documentation, clinical evaluation, post-market surveillance, vigilance procedures, economic operator controls and, for many devices, notified body involvement. ISO 13485 helps organize these responsibilities, but the MDR assessment remains a regulatory conformity assessment rather than a simple quality certificate review.

Canada places heavier regulatory weight on the quality system certificate for many device classes. Health Canada requires quality management system evidence for Class II, III and IV medical devices, and the current framework relies on ISO 13485 certification issued through the Medical Device Single Audit Program for relevant licensing purposes. This is one reason many manufacturers treat MDSAP participation as more than a customer preference when Canada is a target market.

MDSAP also changes how a certificate should be read. The program allows a recognized auditing organization to conduct one audit that addresses the applicable quality management system requirements of participating regulatory authorities. MDSAP program materials identify Australia, Brazil, Canada, Japan and the United States as participating regulatory authorities. However, MDSAP does not remove country-specific product registration, technical file, labeling, vigilance or import requirements.

How to verify ISO 13485 certified companies before relying on them

Verification should be documented, especially when the company supplies a critical component, finished device, sterile service, software function, testing service or outsourced manufacturing step. A buyer should not rely only on a logo in a brochure or a supplier questionnaire response.

  1. Request the certificate itself. Ask for the current certificate, including all pages, annexes and scope details.
  2. Match the legal entity. Confirm that the name on the certificate matches the contracting party, manufacturing party or design-responsible entity.
  3. Check the site. Make sure the relevant facility is listed. A sales office certificate is not proof that the production site is certified.
  4. Read the scope against your risk. Confirm that the audited scope covers the process you are outsourcing or the device-related service you are buying.
  5. Confirm status with the issuer. Where possible, verify the certificate through the certification body, accreditation body or IAF CertSearch database. The ISO Survey is useful for certification statistics, but it is not a substitute for checking an individual certificate.
  6. Review regulatory fit. Decide whether ordinary ISO 13485 certification is enough, or whether MDSAP, EU MDR notified body review, FDA QMSR readiness or another market-specific control is needed.
  7. Maintain supplier controls. Use quality agreements, change notification clauses, audit rights, nonconformance reporting expectations and performance monitoring.

The result should be a risk-based supplier decision, not a yes-or-no reaction to the presence of a certificate. A low-risk catalog component supplier may need less oversight than a contract manufacturer performing final release activities for a Class III implantable device.

How different types of companies use ISO 13485 certification

Legal manufacturers usually use ISO 13485 as the backbone of their device lifecycle quality system. Their system should connect design control, supplier management, production, process validation, traceability, complaint handling, corrective and preventive action, post-market surveillance and management review. For them, certification is often part of demonstrating maturity to regulators, notified bodies, distributors and customers. See also: Implants.

Contract manufacturers use certification to show that outsourced production is controlled. Still, the legal manufacturer remains responsible for defining specifications, approving suppliers, maintaining technical documentation and ensuring regulatory compliance. A contract manufacturer certificate is valuable only when it covers the specific process being outsourced, such as molding, machining, assembly, packaging, sterilization coordination or finished device manufacturing.

Component suppliers may be ISO 13485 certified even when they do not place finished medical devices on the market. This can be useful for high-risk or custom components, but it should not be confused with device approval. The purchasing manufacturer still has to define acceptance criteria, incoming inspection, change control and traceability needs.

Software and software as a medical device companies may also pursue ISO 13485 certification. In those cases, the certificate should be read alongside software lifecycle, cybersecurity, risk management, usability and post-market monitoring expectations. A software company can be certified to ISO 13485 and still need additional evidence to satisfy device-specific regulatory submissions.

Distributors and importers may hold ISO 13485 certification for distribution, storage, installation or servicing activities. That can support process discipline, but it does not replace obligations assigned to economic operators under local law.

Red flags when reviewing a certificate

Several warning signs should trigger follow-up. One is language that says ISO certified without naming the standard. Another is use of the ISO logo in a way that suggests ISO issued the certificate, which ISO says is not permitted for certification claims. A third is a certificate issued by an unknown body with no credible accreditation trail.

Other red flags include an expired certificate, a scope that excludes the activity you need, a certificate that covers only headquarters while production is elsewhere, refusal to provide the certificate number, or marketing claims that imply ISO 13485 certification equals FDA clearance, CE marking or product approval. None of those claims should be accepted without supporting regulatory evidence.

For critical suppliers, ask whether there have been major nonconformities, scope suspensions, significant process changes, site moves or changes of certification body. Some details may be confidential, but a mature supplier should be able to explain how its certification status is maintained and how customers are notified of changes.

Frequently asked questions

Are ISO 13485 certified companies approved by ISO?

No. ISO develops and publishes standards, but it does not certify organizations or issue ISO 13485 certificates. Certification is performed by external certification bodies or recognized auditing organizations, depending on the scheme.

Does ISO 13485 certification prove FDA compliance in 2026?

No. Since February 2, 2026, FDA’s QMSR incorporates ISO 13485:2016 by reference, so certification can be a strong starting point. However, FDA does not require ISO 13485 certificates, does not issue them and does not treat them as a substitute for FDA inspection or FDA-specific legal requirements.

Is ISO 13485 mandatory for every medical device company?

The standard itself does not force certification. Whether a company needs ISO 13485 certification depends on its role, device class, customer contracts and target markets. Canada requires quality system certificate evidence for many Class II, III and IV licensing situations, while the EU MDR requires a quality management system and still relies on the applicable regulatory conformity assessment route.

How can buyers find a reliable list of certified companies?

There is no single marketing list that should be treated as definitive. Buyers can use certificate databases, certification body lookups, accreditation body records and IAF CertSearch where available, but individual certificate verification remains essential.

Can ISO 9001 replace ISO 13485 for a medical device supplier?

Sometimes ISO 9001 may be acceptable for low-risk, non-device-specific suppliers, but it is not a medical device regulatory QMS standard. When the supplier affects device safety, performance, traceability, sterile integrity, software function or regulatory compliance, ISO 13485 is usually the more relevant framework.