QMSAdvisor

Certification and Regulatory Audits

ISO 13485 Certification Audit (Stage 1 and Stage 2)

Initial ISO 13485 certification happens in two steps. A certification body reviews your documentation and readiness in Stage 1, then checks in Stage 2 that the system is implemented and working. If the certification body grants certification, the certificate runs on a three-year cycle.

At a Glance

Conducted by
A certification body you engage
Structure
Stage 1 (documentation and readiness) and Stage 2 (implementation)
Standard
ISO 13485:2016
Certificate cycle
Three years, with surveillance audits at least annually
Decision
Made by the certification body after the audit

What It Is

ISO 13485:2016 sets out requirements for a quality management system for organizations involved with medical devices. Certification is a third-party statement, by a certification body, that your system meets them. Customers and distributors often ask for it, and it's a common foundation for market access outside the US.

Stage 1 is a readiness review. The auditor examines your documented system, scope, sites and planning, and judges whether you're ready for Stage 2. Stage 2 is the implementation audit: the auditor samples records, interviews staff and observes processes to confirm the system works as documented across the scope you've applied for.

ISO 13485 certification isn't an FDA requirement, and FDA doesn't issue certificates. The QMSR incorporates the same standard by reference, so the work overlaps heavily, but a certificate doesn't exempt a firm from FDA inspection.

Who Conducts It

A certification body you choose and contract with performs both stages. Auditors are assigned based on your scope and device technologies, and the certification decision is made by the certification body after the audit.

Choose a certification body whose accreditations and recognitions suit your markets and customers, and check before you sign.

What Triggers It

  • Customer or distributor requirements for ISO 13485 certification
  • Market access plans in countries that look for an ISO 13485 based quality system
  • A new company or new site building its first quality system to certification
  • Contract manufacturers seeking certification to win device work
  • Plans for MDSAP or EU market entry, where the same quality system will be assessed

What They Look At

  • Scope and Exclusions

    Whether the scope statement fits what you actually do and whether any exclusions or non-applications are justified.

  • Documented System

    The quality manual, procedures and records the standard requires, checked for adequacy at Stage 1 and for use at Stage 2.

  • Risk-Based Decisions

    How risk management, including ISO 14971 for product risk, shapes design, production and supplier decisions.

  • Design and Development

    Planning, inputs, outputs, reviews, verification, validation, transfer and changes, where design is in scope.

  • Production and Process Control

    Process validation, identification, traceability, cleanliness and work environment, as they apply to your products.

  • Internal Audit and Management Review

    Evidence that both are running and producing actions, which certification bodies generally expect to see before Stage 2.

  • Feedback, Complaints and CAPA

    Whether the system collects feedback, handles complaints and drives corrective action, even with limited production history.

How to Prepare

  1. 01

    Settle the Scope First

    Agree a scope that covers what you actually do and the sites involved, and resolve exclusions before Stage 1.

  2. 02

    Run the System Before You Audit It

    Generate real records: training, supplier evaluations, production records, an internal audit cycle and a management review.

  3. 03

    Close Stage 1 Concerns Promptly

    Resolve every Stage 1 concern before Stage 2. Open items have a way of becoming Stage 2 nonconformities.

  4. 04

    Commission an Independent Internal Audit

    Have someone outside the process audit the full system against ISO 13485:2016 before Stage 2.

  5. 05

    Prepare People, Not Just Paper

    Auditors interview staff at every level. Make sure people know the procedures that govern their work and where the records live.

Common Pitfalls

  • Booking Stage 2 before the system has produced enough records to show it works.
  • Procedures copied from a template that describe processes the company doesn't actually run.
  • An internal audit performed by the person who wrote the procedures being audited.
  • Management review held as a formality, with no decisions or actions recorded.
  • Supplier controls that list suppliers but show no evaluation or monitoring.

How QMSAdvisor Helps

  • An AI-assisted gap analysis of your documents against ISO 13485:2016, with every finding reviewed and confirmed by an advisor.
  • A Stage 1 readiness view: missing procedures, inadequate procedures and missing evidence, each with an owner and a list of what to submit.
  • Evidence review between Stage 1 and Stage 2, so open items are closed with records rather than intentions.
  • Internal audit support that gives you an independent full-system audit before Stage 2.

Standards and Regulations Involved

Questions About the ISO 13485 Certification Audit

What's the difference between Stage 1 and Stage 2?

Stage 1 checks documentation and readiness: whether your system is defined and you're prepared for the implementation audit. Stage 2 checks implementation: whether the system is actually working across your scope.

How long does an ISO 13485 certificate last?

Certificates run on a three-year cycle. Surveillance audits happen at least annually, and a recertification audit takes place before the certificate expires.

Does ISO 13485 certification satisfy FDA?

No. The QMSR incorporates ISO 13485:2016 by reference, so a certificate is a strong foundation, but FDA inspects independently and adds its own requirements, such as MDR, UDI and the records and labeling provisions in 820.35 and 820.45.

How many records do we need before Stage 2?

There's no fixed number, but auditors need enough evidence to see each process operating. Ask your certification body about its expectations, and don't book Stage 2 until internal audit and management review have both produced real outputs.

Request an Assessment

Prepare for Your ISO 13485 Certification Audit With an Advisor

Tell us what's coming and when, and an advisor will scope readiness work around it. Please don't send confidential documents yet: secure upload is set up after onboarding.