Services / ISO 13485 certification
ISO 13485 certification for medical device companies and suppliers
A medical device quality management certificate for manufacturers, contract manufacturers and component suppliers, audited by EUROTECH from $800.
From $800Certified by EUROTECH

- Accredited by IAB and INTAQS
- Issuing certificates since 2004
- Online or on-site audits worldwide
- Verify any EUROTECH certificate
What the ISO 13485 audit covers
ISO 13485 sets quality management requirements for organizations involved in the life cycle of medical devices: design and development, production, storage and distribution, installation, servicing, and the supply of components or services to device makers. It is built on ISO 9001 ideas but goes further on documentation, risk and regulatory requirements.
The audit checks how you control the things that matter for patient safety and device performance. That includes your quality manual and procedures, risk management across product realization, design controls where design is in scope, supplier control, production and process controls, validation of special processes such as sterilization or software, traceability, complaint handling, feedback and the way you report to regulators when required.
The scope statement on the certificate names the device types or services and the activities, for example contract manufacture of machined orthopedic components, or distribution of single-use surgical instruments. A precise scope is what your customers and their auditors read first.
- Stage 1 review of your quality manual, procedures and readiness
- Stage 2 audit of design, production, suppliers, complaints and records
- Certification decision and three-year certificate
- Certificate listed on our verification portal
- Yearly surveillance audits and recertification
Who needs it, and which audit format fits
ISO 13485 is asked for by device manufacturers, contract manufacturers, sterilization and packaging providers, component and raw material suppliers, software developers and distributors. Component suppliers are often asked for it by their device-maker customers as a condition of supplier approval.
Document-heavy parts of the audit, such as the design history, risk files, procedures and complaint records, can be reviewed online. Production, clean areas, warehouses and special processes are best seen on site. For manufacturing sites we recommend that Stage 2 includes an on-site visit; for distributors or software companies with no physical production, more of the audit can run remotely.
If you already hold ISO 9001, keep in mind that ISO 13485 is a separate standard with extra requirements, not an add-on. Many companies hold both, and parts of the audit can be combined where the processes are shared.
Software is a growing part of ISO 13485 work. If you develop software that is itself a medical device, or software used in production or quality records, the auditor will look at how it is specified, validated and changed under control.
What drives the price
ISO 13485 certification with EUROTECH starts at $800. Audit time depends on the risk and complexity of what you do, not only on size.
- Device risk and type: sterile, implantable or active devices need more audit time than simple non-sterile products
- Design and development in scope or not
- Special processes such as sterilization, cleaning validation, welding or software validation
- Number of employees and sites, including outsourced processes you control
- Audit format and travel for on-site parts
We set out the audit days and all fees for the three-year cycle in a written quote. Ready, well-organized records shorten the audit: a complete device master record or technical documentation index, current risk files and closed complaint investigations make a real difference.
Outsourced processes count as part of your system. If a supplier sterilizes, packages or tests your devices, you remain responsible for controlling that process, and the audit time reflects it.
How ISO 13485 certification works with us

Step 1
Classification and QMS gap
Tell us your devices, activities and markets. We confirm the ISO 13485 scope and quote the audit in writing.

Step 2
Design and risk files
Stage 1 reviews your quality manual, risk management and design or technical documentation.

Step 3
Production audit
Stage 2 follows a product through purchasing, production, validation, release and complaints.

Step 4
Certificate and market access
After the decision you receive the ISO 13485 certificate, with yearly surveillance audits.
Regulations in your markets
We certify ISO 13485 for companies in the USA, Europe, Asia and Africa. ISO 13485 asks you to identify the regulatory requirements of the markets you supply and build them into your system, so the audit always looks at those requirements too.
In the USA, the FDA Quality Management System Regulation, which took effect on 2 February 2026, incorporates ISO 13485:2016 by reference, so a sound ISO 13485 system supports FDA compliance. In the European Union, the MDR and IVDR require a quality system, and for most device classes a notified body must audit it. Other markets have their own registration and vigilance rules.
The auditor samples how you apply these requirements: complaint handling that triggers vigilance reporting, labelling controls, unique device identification where it applies, and records retention.
What to expect during the audit
Expect the auditor to follow one product through your system: from the design inputs or customer specification, through risk analysis, purchasing of components, production records and inspection, to release, distribution and any complaints. Gaps along that path are where findings usually appear.
Validation records are checked closely. If a process cannot be fully verified by inspecting the output, for example sterilization, sealing or bonding, it must be validated and revalidated when something changes. Supplier control is another focus: the auditor checks that critical suppliers are evaluated, monitored and controlled in proportion to their risk.
Complaint files are a frequent source of findings. Each complaint should be logged, assessed for whether it must be reported to a regulator, investigated where needed and closed with a decision on corrective action. The auditor will open several files and check each step.
Training and competence are checked for people whose work affects product quality, including operators of validated processes and the staff who handle complaints. Records should show what training was given and how its effectiveness was judged.
Findings are graded as major or minor and the certification decision is made on the evidence. You receive a written report explaining each finding.
Keeping the certificate
Between audits, keep complaint handling, corrective and preventive action, internal audits and management reviews running. Surveillance audits sample these, together with design changes, new products, new suppliers and any recalls or field safety actions since the last visit.
Tell us about significant changes such as a new product family, a new site or moving a special process to a supplier. They may change the scope or the audit time, and planning them into the next visit is easier than finding them on audit day.
ISO 13485:2016 is the current edition. If you also plan EU market access, read our MDR and IVDR page: the notified body route is separate from this certificate.
Keep your list of applicable regulations current as you enter new markets, because new registration or reporting duties change what the auditor will sample.
Good to know: an EUROTECH ISO 13485 certificate shows your quality system meets ISO 13485. It does not replace the quality system certificate a notified body issues under the EU MDR or IVDR, and it is not an MDSAP audit. For EU market access see our MDR and IVDR service.
Questions buyers ask
How much does ISO 13485 certification cost?
With EUROTECH it starts at $800. Device risk, design scope, special processes, staff, sites and audit format set the final price.
Does an ISO 13485 certificate let us sell in the EU?
No. For most device classes the EU MDR or IVDR requires a notified body to assess your quality system and technical documentation. Our ISO 13485 certificate supports that but does not replace it.
Is ISO 13485 the same as ISO 9001?
No. ISO 13485 is a separate standard for medical devices with stricter requirements on documentation, risk management, validation, traceability and regulatory reporting.
Do component suppliers need ISO 13485?
It is not legally required for most suppliers, but device makers often ask for it as part of supplier approval.
Does ISO 13485 help with FDA compliance?
Yes. Since 2 February 2026 the FDA Quality Management System Regulation incorporates ISO 13485:2016 by reference. FDA inspections remain separate from certification.
Can the audit be done online?
Document reviews can be online. Production, clean areas and special processes are best audited on site, and we recommend an on-site visit for manufacturers.
Related services
- MDR and IVDR
From $2,000
- ISO 9001 certification
From $800
- GMP certification
From $1,500
Get a quote for ISO 13485 certification
Tell us your company, sites and the standard you need. We reply with a written quote and the audit plan.
Prefer to talk? Call +1 307 205 1833
Monday to Friday, 09:00 to 18:00 (US Mountain Time)
