ISO 13485 certification consultancy for medical devices

...without complications!

What is it and who does it apply to?

ISO 13485 certification for medical devices is the assessment, by an accredited certification body, that a company's quality management system meets the international standard specific to medical devices. It is independent of CE marking: it certifies the organisation and its processes, not a device.

ISO 13485 shares its foundations with ISO 9001 but adds what the sector demands: risk management across every process, design control, traceability, validation of special processes and post-market surveillance. A company holding ISO 9001 therefore has a head start, but not equivalence.

Manufacturers get certified, but so do importers, distributors and critical suppliers (contract manufacturers, sterilisers, laboratories) whose customers require it as evidence of supply-chain control. It is not mandatory for CE marking; what is essential is a documented and implemented system, and the certificate is the recognised way to prove it.

What the regulation requires

Regulation (EU) 2017/745 (MDR) and Regulation (EU) 2017/746 (IVDR) require the manufacturer to maintain a quality management system proportionate to the risk class and type of device. EN ISO 13485 is the harmonised standard that gives presumption of conformity with that requirement, and it is the reference used by notified bodies.

For devices in class IIa and above, the notified body audits the quality system as part of the conformity assessment; already holding the ISO 13485 certificate does not waive that audit, but it simplifies it and reduces findings.

The certificate is issued for a three-year cycle, with annual surveillance audits and a recertification audit at the end; between audits the system must be kept alive through internal audits, management review and corrective action handling.

What we do at MeDev Consulting

Certifications EN ISO 13485 / EN ISO 9001

Without complications!

System Design

We design a custom, efficient quality system compliant with regulations.

Implementation

We implement the system in your organization with continuous support.

Certification

We manage the certification process before the Notified Body.

Although it is not necessary to be certified under a quality standard to achieve CE marking success, it is essential to have a documented and implemented quality system.

ISO 13485 is a standard based on ISO 9001, its main objective is to meet customer expectations and regulatory authority requirements.

At MeDev Consulting, we handle the design and implementation of a quality system that satisfies the Notified Body while generating value for your company.

How we work

  1. 1

    Assessment

    We analyse what you already have (processes, documentation, ISO 9001 if any) against the requirements of ISO 13485 and the MDR/IVDR.

  2. 2

    System design

    We define processes, procedures and records tailored to your activity, without bureaucracy that adds no value.

  3. 3

    Implementation and training

    We put the system into operation with your team and train the people so they apply it efficiently.

  4. 4

    Internal audit and certification

    Internal audit and management review before the certification audit; support during stages 1 and 2 and closure of findings.

Frequently asked questions

What is the difference between ISO 13485 and ISO 9001?

They share structure and foundations, but ISO 13485 replaces the focus on continual improvement and customer satisfaction with regulatory compliance: risk management across every process, mandatory design control, traceability, process validation and post-market surveillance. Holding ISO 9001 helps, but it is not equivalent.

Is ISO 13485 certification mandatory for CE marking?

No. What is mandatory is an implemented quality management system in line with the MDR or IVDR. Certification is voluntary, but it is the route that notified bodies and customers recognise, and from class IIa upwards the notified body will audit that system anyway.

Who issues the ISO 13485 certificate?

An accredited certification body; many are also notified bodies. The audit takes place in two stages: a documentation review and an on-site audit to check that the system works as written.

How long is the certificate valid and what upkeep does it require?

Three years, with annual surveillance audits and a recertification audit at the end of the cycle. Between audits the system must stay alive: internal audits, management review and handling of corrective actions.

I am a distributor or importer: is certification worth it for me?

Yes. ISO 13485 explicitly covers distributors and importers, and more and more manufacturers require the certificate from their supply chain as evidence of supplier control. It also structures your own verification, traceability and surveillance duties.

How long does it take to implement and certify the system?

It depends on the starting point (whether ISO 9001 already exists, whether there is in-house product design) and on the size of the organisation. After the initial assessment we propose a firm schedule with the audit date as the goal.

What happens if the audit finds non-conformities?

That is usual in a first certification. A corrective action plan with deadlines is agreed and the certification body verifies it before issuing the certificate: major non-conformities must be closed before issue; minor ones may be closed at the surveillance audit.

Get your ISO certification with guarantees

We design and implement efficient quality systems that generate real value for your company.