Compliance 10 min read

ISO 13485 and EU MDR: How the Two Fit Together

J

Jared Clark

August 16, 2026

Every device manufacturer I've worked with eventually asks some version of the same question: "We're ISO 13485 certified — doesn't that mean we're MDR compliant?" No. And the gap between those two things is where a surprising number of otherwise well-run companies get stuck at Notified Body review.

ISO 13485:2016 is a quality management system standard. EU MDR — Regulation (EU) 2017/745 — is a law. One tells you how to build and run a QMS. The other tells you what you're legally required to prove before you can put a device on the EU market. They were built to work together, and in practice they overlap heavily, but they are not the same document doing the same job, and treating them as interchangeable is how technical files end up incomplete.

What ISO 13485 Actually Is

ISO 13485:2016 is the international standard for quality management systems specific to medical devices, published by ISO and adopted as a harmonized European standard under EN ISO 13485:2016. It's built on the ISO 9001 process-approach skeleton but adds device-specific requirements: risk management woven through the product lifecycle (clause 7.1), design and development controls (clause 7.3), specific requirements for sterile devices and implantables, and traceability obligations that go well beyond what a general manufacturing QMS needs.

The standard is voluntary in the sense that no regulator makes you get certified to it by name. But it is the QMS framework that regulators, Notified Bodies, and the FDA (through its QMSR harmonization, effective February 2026) all recognize as the baseline. If your QMS isn't built on ISO 13485's structure, you're building your own equivalent from scratch, which is a much harder audit story to tell.

What EU MDR Actually Is

EU MDR is Regulation (EU) 2017/745, which replaced the Medical Device Directive (93/42/EEC) and the Active Implantable Medical Device Directive (90/385/EEC). It became fully applicable on May 26, 2021, with staggered transition provisions since extended by Regulation (EU) 2023/607.

MDR is not a QMS standard. It's a legal framework covering classification rules (Annex VIII), general safety and performance requirements (Annex I), conformity assessment procedures (Annexes IX through XI), clinical evaluation (Article 61 and Annex XIV), post-market surveillance (Articles 83–86), and vigilance reporting (Articles 87–92). It also creates roles ISO 13485 never mentions: the Person Responsible for Regulatory Compliance (Article 15), the European database EUDAMED, and Unique Device Identification (Article 27).

Article 10(9) of MDR requires manufacturers to establish, document, implement, maintain, and continually improve a quality management system — and then lists eleven specific elements that system must cover, from regulatory compliance strategy to resource management to risk management to post-market surveillance. If you line that list up against ISO 13485's clause structure, the overlap is close to total. That's deliberate. It's also not complete.

Where They Overlap, and Where They Don't

The honest way to think about this: ISO 13485 gives you most of the QMS scaffolding MDR requires, but MDR asks a few things ISO 13485 doesn't address at all, and it asks some things ISO 13485 addresses more loosely than MDR expects.

Requirement ISO 13485:2016 EU MDR 2017/745
QMS process approach Clause 4.1, full requirement Article 10(9), by reference
Design and development controls Clause 7.3 Annex I, Chapter II (general requirements)
Risk management Referenced throughout; assumes ISO 14971 Article 10(2), Annex I clause 3 — mandatory ISO 14971-aligned process
Clinical evidence Not addressed Article 61, Annex XIV — clinical evaluation report required
Post-market surveillance Clause 8.2.1 (feedback), general Articles 83–86 — PMS plan, PSUR, PMCF are specific deliverables
Vigilance/incident reporting Not addressed Articles 87–92, specific timelines (e.g., 15-day serious incident reporting)
Person Responsible for Regulatory Compliance Not addressed Article 15 — named role required
UDI and EUDAMED registration Not addressed Article 27, Article 29
Economic operator obligations (importer, distributor) Not addressed Articles 13, 14
Notified Body conformity assessment Not addressed (ISO 13485 is certified by any accredited certification body) Annex IX — specifically requires a Notified Body for most classes

That last row is worth sitting with. ISO 13485 certification can be issued by any accredited certification body. MDR conformity assessment for most device classes requires a Notified Body specifically designated under MDR — a much smaller, more heavily scrutinized pool of auditing organizations. Your ISO 13485 certificate and your MDR CE certificate may not even come from the same organization, and having one does not automatically produce the other.

The Notified Body Connection: Annex IX

This is where the two documents actually meet in practice. MDR Annex IX — "Conformity assessment based on a quality management system and on assessment of technical documentation" — is the pathway most manufacturers of Class IIa, IIb, and III devices use. Annex IX, section 2, requires the Notified Body to assess the manufacturer's QMS against requirements that map almost line for line onto ISO 13485 clauses. In practice, most Notified Bodies conduct a combined audit: they check your QMS against MDR Article 10(9) and Annex IX simultaneously with your ISO 13485 clause structure, because auditing the same system twice against two different frameworks would be wasteful for everyone.

That's the good news. The QMS audit is largely one audit. The bad news is that Annex IX also requires sampling of technical documentation — the actual device files, not just the system that produces them. A Notified Body can find your QMS fully compliant with ISO 13485 and still reject a specific device's technical file because the clinical evaluation, risk file, or PMS documentation for that device doesn't meet MDR's substantive requirements. The system can be sound and the paperwork for a given SKU can still be wrong.

Where Manufacturers Get Caught Out

I've reviewed technical files where the QMS was genuinely solid — ISO 13485 certified for years, clean audit history — and the gap was always in the same three places.

Clinical evaluation depth. ISO 13485 clause 7.3.3 requires design inputs that include applicable regulatory requirements, but it doesn't tell you what MDR Annex XIV demands for clinical evidence. Under MDD, a literature-based clinical evaluation was often sufficient. Under MDR, Article 61(4) sets a much higher bar for demonstrating equivalence, and MDCG 2020-13 (the clinical evaluation assessment report template, published July 2020) shows exactly how strictly Notified Bodies now scrutinize that equivalence claim. A QMS can produce a clinical evaluation report on schedule and still produce one that doesn't survive Annex XIV review.

Post-market surveillance as a living system, not a filing cabinet. ISO 13485 clause 8.2.1 treats customer feedback as an input to the QMS. MDR Articles 83–86 turn that into a formal PMS plan, a PSUR (Periodic Safety Update Report) for higher-risk classes, and PMCF (post-market clinical follow-up) activity that has to feed back into the clinical evaluation and risk management file on a defined cycle. A manufacturer with an ISO 13485 complaint-handling procedure that's never been rebuilt around MDR's PMS plan template is compliant with the standard and not compliant with the regulation.

The economic operator chain. MDR introduced defined obligations for importers and distributors (Articles 13–14) that simply don't exist in ISO 13485's scope. A manufacturer whose QMS controls outsourced processes under ISO 13485 clause 4.1.2.2 still needs a separate MDR-specific mechanism to verify that its EU importer and distributors are meeting their own regulatory obligations — the standard's supplier-control clause doesn't reach that far.

Building One QMS That Actually Satisfies Both

The practical answer isn't two systems. It's one ISO 13485-structured QMS with MDR-specific modules bolted onto the clauses that need them. Concretely, that means:

  • Building the risk management process on ISO 14971:2019 explicitly, cross-referenced to MDR Annex I clause 3, rather than treating risk management as a generic ISO 13485 clause 7.1 activity.
  • Writing a standalone PMS procedure that maps to MDR Articles 83–86 with its own document control, rather than folding it into the general clause 8.2.1 feedback procedure.
  • Assigning the Person Responsible for Regulatory Compliance (Article 15) as a named role in the QMS organizational chart, not just a job description that exists outside the quality system.
  • Adding UDI assignment and EUDAMED registration steps into the design and development output stage (clause 7.3.6) so device data isn't reconstructed after the fact.
  • Treating vigilance reporting timelines (the 15-day serious incident window, the 2-day window for serious public health threats under Article 87) as QMS-controlled records, not a separate compliance side-process.

Done this way, your ISO 13485 certificate and your MDR technical documentation stop being two separate compliance projects run by two different teams on two different timelines. They become one system with two audiences: the certification body checking your QMS, and the Notified Body checking both your QMS and your device files under Annex IX.

A Word on Timing

Regulation (EU) 2023/607 extended MDR's transitional deadlines for devices with valid MDD certificates, staggered by risk class — but the extension came with a hard condition: manufacturers had to have a signed agreement with a Notified Body in place by September 26, 2024 to qualify for the extended timeline. That deadline has passed. If your device is still operating under an MDD certificate today, the question isn't whether MDR applies to you — it's whether you locked in the transition path before that cutoff. Manufacturers still working through this should treat the QMS alignment work described above as immediate, not aspirational.

Where Certify Consulting Fits

I work with manufacturers building or repairing exactly this bridge — QMS structures that pass ISO 13485 certification and hold up under Annex IX scrutiny at the same time. If you want a second set of eyes on where your current system has ISO 13485 coverage but an MDR-shaped gap, my ISO 13485 consulting page walks through how that engagement typically runs, and you can reach out directly through contact us if you want to talk through your specific device classification and timeline.

FAQ

Does ISO 13485 certification automatically satisfy EU MDR requirements? No. ISO 13485 certification demonstrates a compliant quality management system, but MDR conformity assessment under Annex IX also requires Notified Body review of device-specific technical documentation, clinical evaluation, and post-market surveillance — none of which ISO 13485 certification alone verifies.

Is ISO 13485 certification legally required to sell medical devices in the EU? MDR doesn't name ISO 13485 by number as mandatory, but Article 10(9) requires a QMS covering elements that closely mirror ISO 13485's structure, and in practice every Notified Body conducts its Annex IX QMS assessment against that standard's clause framework. Operating without it makes conformity assessment substantially harder.

Can any certification body issue an ISO 13485 certificate that also covers MDR? No. ISO 13485 certificates can come from any accredited certification body, but MDR conformity assessment for most device classes requires a Notified Body specifically designated under MDR — a distinct, smaller pool of organizations with their own designation scope per device type.

What MDR requirements does ISO 13485 not cover at all? Clinical evaluation (Article 61), UDI and EUDAMED registration (Articles 27, 29), the Person Responsible for Regulatory Compliance (Article 15), and economic operator obligations for importers and distributors (Articles 13–14) all fall outside ISO 13485's scope and require MDR-specific procedures layered onto the QMS.

What happened to the MDR transition deadlines? Regulation (EU) 2023/607 extended transition deadlines for devices with valid MDD certificates, staggered by device class, but only for manufacturers who had a signed Notified Body agreement in place by September 26, 2024. That condition has now passed, so any device still relying on legacy certificates should confirm its transition status immediately rather than assume more runway exists.

Last updated: 2026-08-16

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.