For medical device manufacturers in India, ISO 13485 certification sits at the intersection of customer expectations, export market access and domestic regulation. ISO 13485:2016 is the international standard for quality management systems for medical devices, and it is the quality system reference that regulators in many markets build on. This article explains what the standard requires, how it differs from ISO 9001, and how it relates — accurately — to the Medical Devices Rules, 2017 administered by CDSCO.

What ISO 13485:2016 is

ISO 13485:2016 specifies requirements for a quality management system where an organisation needs to demonstrate its ability to provide medical devices and related services that consistently meet customer and applicable regulatory requirements. It applies to organisations involved in one or more stages of the device life cycle: design and development, production, storage and distribution, installation, servicing, and the supply of components and services to device manufacturers.

Unlike ISO 9001:2015, ISO 13485:2016 does not follow the High Level Structure. Its clauses run from 4 (quality management system) to 8 (measurement, analysis and improvement), in a structure closer to the older ISO 9001:2008. Organisations running both standards need to map between them rather than assume the clause numbers line up.

How ISO 13485 differs from ISO 9001

  • Regulatory requirements are built into the system throughout, not just considered as one input among many
  • The emphasis is on maintaining the effectiveness of the system, rather than on continual improvement for its own sake
  • Risk management is applied to product realisation, and in practice is expected to follow ISO 14971:2019 for medical device risk management
  • Documentation requirements are more extensive, including a medical device file for each device type or family (clause 4.2.3)
  • Validation is explicit — of software used in the quality system (4.1.6), of production and service processes whose output cannot be fully verified (7.5.6), and of sterilisation and sterile barrier systems (7.5.7)
  • Complaint handling (8.2.2) and reporting to regulatory authorities (8.2.3) are specific requirements, as are advisory notices
  • Exclusions of design and development and other clause 6, 7 and 8 requirements are permitted only where justified and consistent with regulatory requirements

ISO 13485 and the Medical Devices Rules, 2017

In India, medical devices are regulated under the Medical Devices Rules, 2017, framed under the Drugs and Cosmetics Act, 1940, which came into force on 1 January 2018. The rules classify devices by risk into Class A (low), Class B (low to moderate), Class C (moderate to high) and Class D (high). Manufacturing licences for Class A and B devices are issued by the State Licensing Authority, and for Class C and D devices by the Central Licensing Authority, through CDSCO. Devices were brought under the licensing regime in phases, and the rules have been amended several times since they were notified, so manufacturers should confirm the current position for their device class directly from CDSCO notifications.

The rules require manufacturers to comply with the quality management system requirements set out in the Fifth Schedule, which are closely aligned with ISO 13485. That alignment is why many Indian manufacturers use ISO 13485 as the backbone of their regulatory quality system. It is also why an ISO 13485 system that has been built properly makes regulatory inspection and audit considerably more straightforward.

Why ISO 13485 matters for export markets

For manufacturers selling abroad, ISO 13485 is frequently the starting point. In the European Union, conformity assessment under Regulation (EU) 2017/745 on medical devices involves quality management system assessment by a notified body, and EN ISO 13485 is the harmonised standard used to demonstrate conformity with the QMS requirements. In the United States, the FDA’s Quality Management System Regulation, which took effect on 2 February 2026, incorporates ISO 13485:2016 by reference. The Medical Device Single Audit Program, used by regulators in Australia, Brazil, Canada, Japan and the United States, is also built around ISO 13485.

Each of these routes has its own audit and approval process. An accredited ISO 13485 certificate helps demonstrate a working system, but it does not by itself grant market access in any of these jurisdictions.

The requirements that generate most audit findings

Design and development files

Clause 7.3 requires planned and documented design and development, including verification, validation, design transfer to production (7.3.8), control of changes (7.3.9) and a design and development file for each device type (7.3.10). Findings commonly arise where design inputs are not traceable to outputs, where validation was performed on prototypes that differ from production devices, or where design changes were made without assessing their effect on devices already delivered.

Process and software validation

Special processes — sealing, moulding, bonding, welding, sterilisation — must be validated before use and revalidated when changes occur. Software used in production, in the quality system or in monitoring and measurement must also be validated proportionately to the risk associated with its use. Spreadsheet calculations and small in-house tools are frequently overlooked.

Complaint handling and vigilance

Every complaint must be evaluated to determine whether it represents an event that must be reported to a regulatory authority, and records must show that decision. A complaint log that records the customer’s issue and the replacement shipped, but not the reportability decision or the investigation, does not meet clause 8.2.2.

Supplier control

Clause 7.4 requires supplier evaluation and control proportionate to the risk of the purchased product, with purchasing information that includes, where applicable, a requirement for suppliers to notify you of changes. Critical component suppliers and sterilisation subcontractors receive particular attention.

What to expect from the certification audit

Audit duration and auditor competence for ISO 13485 certification are governed by IAF MD 9, which sets requirements specific to medical device quality management systems, including technical competence for the device areas being audited. Expect auditors to sample device files, design history, validation reports, complaint records and supplier controls, and to trace individual devices from order through production and release.

If you manufacture or supply medical devices or components and are planning ISO 13485 certification, talk to our team about your device types, scope and audit planning, or request a quote with your site and product details.