ISO 13485 Requirements: A Clause-by-Clause Guide
The ISO 13485 requirements are the clause-based rules a medical device organization must meet to build a compliant quality management system (QMS) — spanning documented QMS controls, management responsibility, resources, product realization, and measurement, analysis and improvement. They are set out in ISO 13485:2016, the current version titled “Medical devices – Quality management systems – Requirements for regulatory purposes.” This guide walks through each clause, the documentation and records they demand, and how the standard’s risk-based, regulation-aligned approach shapes what auditors expect to see.
If you want the wider picture of what the standard is and how it fits the US regulatory landscape, read our companion article on ISO 13485 for medical devices. This page stays focused on the requirements themselves.
How the ISO 13485 Requirements Are Structured
ISO 13485:2016 organizes its requirements into a numbered clause structure. Clauses 1 to 3 cover scope, normative references, and terms. The certifiable requirements — the parts an organization is audited against — live in Clauses 4 through 8:
- Clause 4 – Quality Management System (including documentation)
- Clause 5 – Management Responsibility
- Clause 6 – Resource Management
- Clause 7 – Product Realization
- Clause 8 – Measurement, Analysis and Improvement
A key point that trips up teams coming from ISO 9001: ISO 13485 does not use the Annex SL high-level structure that ISO 9001:2015 adopted. It keeps its own clause layout, which is deliberately more prescriptive and documentation-heavy because it exists to support regulatory compliance rather than general business improvement. Certification is always awarded to the organization, not to an individual or to a specific device.
Clause 4 – Quality Management System and Documentation
Clause 4 sets the foundation. The organization must establish, document, implement, and maintain a QMS and continually keep it effective. In practice this means defining the QMS processes, their sequence and interactions, and the criteria and methods needed to control them.
The documentation requirements are extensive and specific. You are expected to maintain:
- A quality manual that describes the scope of the QMS, any exclusions or non-applicable requirements with justification, and the documented procedures.
- A medical device file for each device type or family, containing or referencing the product specifications, manufacturing, and monitoring records.
- Documented procedures for controlling documents and records.
Clause 4 also requires the organization to define its role (manufacturer, importer, distributor, etc.) under applicable regulatory requirements. Document control and record control are called out explicitly — records must remain legible, retrievable, and retained for a defined period that meets regulatory expectations.
Clause 5 – Management Responsibility
Clause 5 places accountability on top management. Leaders must demonstrate commitment to the QMS, define and communicate a quality policy, and set measurable quality objectives at relevant functions.
Requirements here include:
- Ensuring customer and applicable regulatory requirements are determined and met.
- Defining responsibilities and authorities and making them known throughout the organization.
- Appointing a management representative with responsibility for the QMS and for reporting on its performance and any need for improvement.
- Conducting management reviews at planned intervals, with documented inputs (audit results, feedback, process performance, CAPA status, regulatory changes) and outputs (improvement actions, resource needs).
Clause 6 – Resource Management
Clause 6 requires the organization to determine and provide the resources needed to run the QMS and to meet regulatory and customer requirements. This covers:
- Human resources — personnel performing work affecting product quality must be competent based on appropriate education, training, skills, and experience, and the organization must retain records of that competence.
- Infrastructure — buildings, workspace, equipment, and supporting services, including documented requirements for maintenance where it affects product quality.
- Work environment and contamination control — documented requirements for the work environment, plus special arrangements for sterile devices or where contamination could affect the device.
Clause 7 – Product Realization
Clause 7 is the largest and most technical clause, covering the full lifecycle from planning to delivery. Its sub-requirements include:
Planning and Customer-Related Processes
Plan and develop the processes needed for product realization, including risk management activities and verification, validation, monitoring, and inspection criteria specific to the product.
Design and Development
One of the most scrutinized areas. The requirements demand documented design and development planning, defined inputs (functional, performance, safety, and regulatory requirements), verified outputs, formal review, verification, and validation, and controlled design transfer to production. Every design change must be controlled, reviewed, and documented, and a design and development file maintained for each device.
Purchasing
Ensure purchased product conforms to specified purchasing requirements. This means evaluating and selecting suppliers against defined criteria, keeping records of supplier evaluation, and verifying incoming product.
Production and Service Provision
Control production under defined conditions — documented procedures, controlled work instructions, defined process parameters, and product identification and traceability throughout. Where output cannot be fully verified by later monitoring, the process must be validated (for example, sterilization). Requirements also cover preservation of product and handling of customer property.
Control of Monitoring and Measuring Equipment
Determine the monitoring and measurement to be undertaken and the equipment needed. That equipment must be calibrated or verified against traceable standards, safeguarded from adjustment, and its calibration status recorded.
Clause 8 – Measurement, Analysis and Improvement
Clause 8 closes the loop by requiring the organization to plan and implement monitoring, measurement, analysis, and improvement. Its requirements include:
- Feedback and complaint handling — gather feedback from production and post-production, and operate a documented complaint-handling process.
- Reporting to regulatory authorities — notify authorities of adverse events and issue advisory notices where regulations require.
- Internal audit — audit the QMS at planned intervals to confirm it conforms to ISO 13485 and is effectively maintained.
- Monitoring and measurement of processes and product — verify that product requirements are met before release.
- Control of nonconforming product — identify and control product that does not conform, with documented procedures.
- Analysis of data — determine, collect, and analyze data to demonstrate suitability and effectiveness of the QMS.
- Corrective and preventive action (CAPA) — take documented action to eliminate causes of nonconformities and prevent recurrence. CAPA is central to ISO 13485 and a frequent focus during audits.
Documentation and Records: The Backbone of Compliance
More than most standards, ISO 13485 is documentation- and records-driven. Auditors verify conformity largely through evidence, so the QMS must generate and retain the right records at each step — competence records, design files, calibration logs, complaint files, CAPA records, and management review minutes.
Two documented essentials sit at the center:
- The quality manual, defining scope, exclusions, and procedures.
- The medical device file, tying together product specifications, manufacturing, installation, and servicing information for each device family.
Retention periods must be defined and must satisfy applicable regulatory requirements. A common failing is having procedures on paper that day-to-day practice does not follow — records are what prove the two are aligned.
Risk Management and Regulatory Alignment
The ISO 13485 requirements are risk-based throughout. Risk management is not confined to one clause; a risk-based approach is applied across product realization and the wider QMS, and organizations typically link their processes to a recognized risk management framework for medical devices.
The standard is also written to support regulatory compliance — its full title ends with “Requirements for regulatory purposes.” For US organizations, this matters more than ever: the FDA’s Quality Management System Regulation (QMSR) took effect on 2 February 2026 and incorporates ISO 13485:2016 by reference, replacing the former 21 CFR Part 820 Quality System Regulation. For a fuller explanation of the US regulatory context and how it connects to certification, see our ISO 13485 for medical devices article and our FDA certification page.
How IAS Helps You Meet the ISO 13485 Requirements
Integrated Assessment Services (IAS) supports organizations across the United States in achieving and maintaining conformity with ISO 13485:2016. Our services are designed around the clause requirements described above:
- ISO 13485 certification — independent assessment of your medical device QMS against the standard, following a clear certification process.
- ISO 13485 lead auditor training — for professionals who need to plan and lead audits against ISO 13485.
- ISO 13485 internal auditor training — build the in-house competence Clause 8 expects for effective internal audits. See upcoming dates on our training schedule.
Both courses form part of our wider ISO 13485 training program. Understanding how an audit is conducted helps you prepare the right evidence — our ISO audit procedure guide walks through what assessors review. If you are weighing several standards at once, the ISO certification hub gives an overview of the wider family. IAS provides certification under its applicable UQAS accreditation scope, and its group company Empowering Assurance Systems (EAS) maintains its own applicable accreditation arrangements.
Ready to begin? Contact us to discuss your organization’s path to ISO 13485 certification.


