Oct 2, 2026
Breaking News: What a spinal cord stretching machine really means in spine care
Regulatory

ISO 13485 and FDA QMSR in 2026 for medical device quality systems

September 15, 2026
camera, canon, lens, pet, iso, aperture, shutter, photography, photo, photographer, cat, animal, kitten, cute

Why ISO 13485 matters now

ISO 13485 is no longer only a certification term used by global medical device manufacturers. In 2026, it also sits at the center of FDA’s Quality Management System Regulation, which took effect on February 2, 2026, and amended 21 CFR Part 820. The current international edition is still ISO 13485:2016, which ISO lists as confirmed in 2025. For quality and regulatory teams, the immediate task is not to prepare for a new edition. It is to show that procedures, records, supplier controls, design controls, risk management activities, and management review processes work under ISO 13485 and under each market’s additional rules.

That distinction is important. ISO 13485 gives organizations in the medical device life cycle a quality management system framework, but it does not replace national or regional legal requirements. A certificate can support market access, supplier qualification, or audit readiness, but it does not by itself authorize a device for sale. In 2026, the practical value of ISO 13485 is as a common operating language for medical device quality systems, with jurisdiction-specific overlays for FDA, EU, Canadian, Australian, Japanese, Brazilian, and other regulatory pathways.

camera, yashica, lens, iso, aperture, shutter, photography, photo, photographer, film, old

Current status of ISO 13485

The current edition is ISO 13485:2016, Medical devices — Quality management systems — Requirements for regulatory purposes. ISO identifies it as edition 3, published in March 2016, and lists the publication as last reviewed and confirmed in 2025. As of September 15, 2026, there is no separate ISO 13485:2026 edition to implement.

The standard is designed for organizations that design, develop, manufacture, install, or service medical devices. It can also apply to suppliers and external parties that provide products or quality management system-related services to medical device organizations. In practice, contract manufacturers, sterilization providers, software suppliers, critical component suppliers, packaging providers, and service organizations may be asked by customers or regulators to align with parts of the standard, even when formal certification is not legally required.

What the standard covers

ISO 13485 uses a quality management system structure covering documented system requirements, management responsibility, resource management, product realization, and measurement, analysis, and improvement. Compared with a general quality standard, it is more closely tied to medical device regulatory expectations. The standard emphasizes documented procedures, product traceability where required, validated processes, design and development controls, supplier controls, complaint handling, and corrective action.

Risk also runs through product realization. ISO 13485 does not replace device-specific risk management under ISO 14971, but it expects risk-based thinking to influence how processes are planned, controlled, and monitored. A working QMS should be able to explain why its controls are proportionate to the device, technology, manufacturing process, and intended use.

How FDA QMSR changed the U.S. picture

FDA’s Quality Management System Regulation is the main reason many teams are revisiting ISO 13485 in 2026. FDA published the Quality System Regulation amendments in the Federal Register on February 2, 2024. The rule became effective two years later, on February 2, 2026. The revised Part 820 is now titled the Quality Management System Regulation, or QMSR.

Date Regulatory milestone Practical meaning
December 18, 1978 FDA’s original device CGMP regulation became effective U.S. device quality requirements were codified under Part 820
June 1, 1997 The 1996 Quality System Regulation became effective Design controls and modern QSR expectations shaped FDA inspections for decades
February 2, 2024 FDA published the QMSR final rule Industry received a two-year transition period
February 2, 2026 QMSR became effective FDA incorporated ISO 13485:2016 by reference and began using a new inspection approach

FDA incorporated ISO 13485:2016 and Clause 3 of ISO 9000:2015 by reference. FDA also stated that if a clause of ISO 13485 conflicts with the Federal Food, Drug, and Cosmetic Act or FDA implementing regulations, U.S. law and FDA regulations control. A company therefore should not treat QMSR as a simple swap from one checklist to another.

Several practical points are especially important for U.S.-market device manufacturers:

  • FDA does not require manufacturers to hold an ISO 13485 certificate, and it does not issue certificates of conformance to ISO 13485.
  • An ISO 13485 certificate does not exempt a manufacturer from FDA inspection.
  • FDA withdrew the Quality System Inspection Technique, known as QSIT, and moved to an updated QMSR inspection process on February 2, 2026.
  • FDA may review QMS records, including certain records created before February 2, 2026, when those records are part of the manufacturer’s quality system.
  • Management review, quality audit, and supplier audit reports are no longer covered by the same inspection exceptions that applied under the older Quality System Regulation.

What changes in daily QMS operation

The largest operational change is not the wording of ISO 13485 itself. It is the expectation that the quality system is traceable, current, and usable by the people running day-to-day processes. A QMS built around legacy FDA subparts may still contain strong controls. The organization should, however, be able to map those controls to ISO 13485 clauses and QMSR-specific requirements.

Documentation should map to current obligations

Procedures, work instructions, forms, and quality manuals should use terminology that staff and auditors can connect to the current regulatory structure. A company does not have to rename every record at once, but it should avoid a system that can only be explained through obsolete Part 820 headings. A traceability matrix linking ISO 13485 clauses, QMSR provisions, device-specific regulations, and internal procedures can reduce confusion during audits and inspections.

Risk-based controls need evidence

Many organizations describe their QMS as risk based. Inspectors and auditors usually look for evidence behind that statement. Evidence may include risk acceptability criteria, design risk files, purchasing controls based on supplier criticality, validated production processes, complaint trending, CAPA prioritization, and documented decisions on the depth of verification activities. The goal is not to label every activity as high risk. It is to show that risk decisions are consistent, justified, and updated when new information appears.

Supplier and outsourced process controls need sharper ownership

ISO 13485 places significant weight on purchased product and outsourced processes. For manufacturers that rely on contract manufacturing, cloud software, sterilization, testing, packaging, or logistics partners, supplier control should go beyond an approved supplier list. It should define selection criteria, evaluation methods, quality agreements, change notification expectations, performance monitoring, and escalation rules when nonconformities occur. See also: Implants.

Corrective action should connect problems to system learning

Complaint handling, nonconforming product control, CAPA, and management review should operate as a connected feedback loop. A complaint may trigger an investigation, reportability assessment, risk file review, supplier action, design change, or production correction. If those activities sit in separate files with no visible link, the QMS may appear procedural rather than effective.

How ISO 13485 fits with global market access

ISO 13485 is widely used because it creates a common quality system baseline. Its legal effect, however, differs by jurisdiction. The same certificate or audit report may have different value depending on the target market, device classification, and regulatory pathway.

Market or pathway How ISO 13485 is used Key limitation
United States FDA ISO 13485:2016 is incorporated by reference into QMSR as the core QMS framework FDA requirements and the FD&C Act still control, and certification is not required by FDA
European Union MDR and IVDR EN ISO 13485 can support conformity assessment when used with applicable MDR or IVDR requirements The regulation, not the standard alone, defines the manufacturer’s legal obligations
MDSAP The Medical Device Single Audit Program uses ISO 13485 as a foundation with participating regulator requirements added MDSAP has its own audit model and does not eliminate every possible regulator inspection
Canada Health Canada uses MDSAP-based quality system evidence for licensed medical device manufacturers Device licensing and post-market duties remain separate from the QMS certificate itself

The practical takeaway is that ISO 13485 can reduce duplication, but it does not create one universal approval route. A manufacturer still needs a regulatory strategy that connects device classification, technical documentation, labeling, post-market surveillance, adverse event reporting, and market-specific registration duties. For related coverage, see our Regulatory section.

Common misconceptions about 13485 after QMSR

  • Misconception 1: ISO 13485 certification equals FDA compliance. It does not. FDA may find the structure familiar, but it inspects against FDA requirements and uses FDA enforcement authority.
  • Misconception 2: QMSR removed U.S.-specific obligations. It did not. FDA retained additional provisions and stated that U.S. law controls where conflicts arise.
  • Misconception 3: Companies need an ISO 13485:2026 standard. As of September 15, 2026, the current ISO edition remains ISO 13485:2016, confirmed in 2025.
  • Misconception 4: A global QMS can ignore local addenda. A common QMS can be efficient, but it should include market-specific requirements for complaint reporting, registration, labeling, language, records, and competent authority interactions.
  • Misconception 5: Risk management is only a design activity. Design risk is central, but risk-based controls should also appear in purchasing, production, process validation, servicing, complaint handling, and CAPA.

Practical readiness checklist for quality teams

  1. Confirm the QMS scope. Define sites, devices, outsourced processes, software tools, servicing activities, and regulatory markets covered by the quality system.
  2. Create or refresh a requirements matrix. Map ISO 13485 clauses to internal procedures, FDA QMSR requirements, EU MDR or IVDR obligations where relevant, and MDSAP country-specific additions if applicable.
  3. Update terminology carefully. Align procedures with current QMSR and ISO 13485 language without destroying useful legacy records.
  4. Test record retrieval. Confirm that management review outputs, internal audit reports, supplier audit reports, design and development files, process validation records, training files, complaints, and CAPA records can be retrieved promptly.
  5. Review supplier controls. Check quality agreements, supplier risk classifications, outsourced process monitoring, and change notification expectations.
  6. Run an internal audit against the current framework. Do not audit only to old Part 820 terminology if FDA is a target market.
  7. Train process owners, not only the quality department. Management, engineering, production, purchasing, regulatory affairs, and post-market teams should understand how their records support the QMS.
  8. Monitor standard and regulatory updates. ISO standards are periodically reviewed, and regulators may update guidance, inspection programs, and harmonized standard lists.

A strong ISO 13485 system is not measured by the number of procedures alone. It is measured by whether the organization can consistently design, manufacture, release, monitor, and improve devices in a way that meets customer needs, regulatory requirements, and patient safety expectations.

Frequently asked questions

Is ISO 13485 mandatory for all medical device companies?

Not universally. ISO 13485 is an international standard, and its legal effect depends on the market. In some jurisdictions or conformity assessment routes, certification or ISO 13485-based audits are important. In others, the obligation is compliance with a regulation that incorporates or aligns with the standard. Companies should evaluate requirements by device type, role, and target jurisdiction.

Does FDA require ISO 13485 certification now?

No. FDA’s QMSR incorporates ISO 13485:2016 by reference, but FDA does not require a certificate of conformance to ISO 13485 and does not issue such certificates. Manufacturers must comply with applicable FDA requirements, and FDA inspections are not waived merely because a company holds an ISO 13485 certificate.

Is there an ISO 13485:2026 edition?

As of September 15, 2026, ISO’s current listed edition remains ISO 13485:2016. ISO states that the standard was reviewed and confirmed in 2025. Teams should still monitor ISO and regulator updates because future revisions would need to be evaluated for quality system and regulatory impact.

Is ISO 13485 enough for EU MDR compliance?

No. ISO 13485 can support a manufacturer’s quality management system and may help demonstrate conformity where harmonized standards apply, but the EU MDR and IVDR contain broader legal obligations. Technical documentation, clinical or performance evaluation, post-market surveillance, vigilance, UDI, labeling, and economic operator duties must be addressed separately.

What should a company review first if it was built around the old FDA QSR?

Start with a gap assessment that maps old procedures to ISO 13485 clauses and QMSR requirements. Then prioritize inspection-facing records, including management review, internal audits, supplier audits, complaints, CAPA, design controls, process validation, and purchasing controls. The goal is to show continuity where controls remain effective and to update gaps where terminology, records, or responsibilities no longer match the current framework.