Certification and Regulatory Audits
ISO 13485 Certification Audit (Stage 1 and Stage 2)
Initial ISO 13485 certification happens in two steps. A certification body reviews your documentation and readiness in Stage 1, then checks in Stage 2 that the system is implemented and working. If the certification body grants certification, the certificate runs on a three-year cycle.
At a Glance
- Conducted by
- A certification body you engage
- Structure
- Stage 1 (documentation and readiness) and Stage 2 (implementation)
- Standard
- ISO 13485:2016
- Certificate cycle
- Three years, with surveillance audits at least annually
- Decision
- Made by the certification body after the audit
What It Is
ISO 13485:2016 sets out requirements for a quality management system for organizations involved with medical devices. Certification is a third-party statement, by a certification body, that your system meets them. Customers and distributors often ask for it, and it's a common foundation for market access outside the US.
Stage 1 is a readiness review. The auditor examines your documented system, scope, sites and planning, and judges whether you're ready for Stage 2. Stage 2 is the implementation audit: the auditor samples records, interviews staff and observes processes to confirm the system works as documented across the scope you've applied for.
ISO 13485 certification isn't an FDA requirement, and FDA doesn't issue certificates. The QMSR incorporates the same standard by reference, so the work overlaps heavily, but a certificate doesn't exempt a firm from FDA inspection.
Who Conducts It
A certification body you choose and contract with performs both stages. Auditors are assigned based on your scope and device technologies, and the certification decision is made by the certification body after the audit.
Choose a certification body whose accreditations and recognitions suit your markets and customers, and check before you sign.
What Triggers It
- Customer or distributor requirements for ISO 13485 certification
- Market access plans in countries that look for an ISO 13485 based quality system
- A new company or new site building its first quality system to certification
- Contract manufacturers seeking certification to win device work
- Plans for MDSAP or EU market entry, where the same quality system will be assessed
What They Look At
Scope and Exclusions
Whether the scope statement fits what you actually do and whether any exclusions or non-applications are justified.
Documented System
The quality manual, procedures and records the standard requires, checked for adequacy at Stage 1 and for use at Stage 2.
Risk-Based Decisions
How risk management, including ISO 14971 for product risk, shapes design, production and supplier decisions.
Design and Development
Planning, inputs, outputs, reviews, verification, validation, transfer and changes, where design is in scope.
Production and Process Control
Process validation, identification, traceability, cleanliness and work environment, as they apply to your products.
Internal Audit and Management Review
Evidence that both are running and producing actions, which certification bodies generally expect to see before Stage 2.
Feedback, Complaints and CAPA
Whether the system collects feedback, handles complaints and drives corrective action, even with limited production history.
How to Prepare
- 01
Settle the Scope First
Agree a scope that covers what you actually do and the sites involved, and resolve exclusions before Stage 1.
- 02
Run the System Before You Audit It
Generate real records: training, supplier evaluations, production records, an internal audit cycle and a management review.
- 03
Close Stage 1 Concerns Promptly
Resolve every Stage 1 concern before Stage 2. Open items have a way of becoming Stage 2 nonconformities.
- 04
Commission an Independent Internal Audit
Have someone outside the process audit the full system against ISO 13485:2016 before Stage 2.
- 05
Prepare People, Not Just Paper
Auditors interview staff at every level. Make sure people know the procedures that govern their work and where the records live.
Common Pitfalls
- Booking Stage 2 before the system has produced enough records to show it works.
- Procedures copied from a template that describe processes the company doesn't actually run.
- An internal audit performed by the person who wrote the procedures being audited.
- Management review held as a formality, with no decisions or actions recorded.
- Supplier controls that list suppliers but show no evaluation or monitoring.
How QMSAdvisor Helps
- An AI-assisted gap analysis of your documents against ISO 13485:2016, with every finding reviewed and confirmed by an advisor.
- A Stage 1 readiness view: missing procedures, inadequate procedures and missing evidence, each with an owner and a list of what to submit.
- Evidence review between Stage 1 and Stage 2, so open items are closed with records rather than intentions.
- Internal audit support that gives you an independent full-system audit before Stage 2.
ISO 13485 Certification Readiness
Prepare your QMS, records and people for a certification body's Stage 1 and Stage 2 audits.
QMS Build for Startups (Phased)
A QMS built in phases for a device startup: design controls and risk first, the rest before you need it.
Internal Audit Program
A risk-based internal audit program, run by your team or our advisors, with reports written for FDA to read.
AI-Assisted QMS Gap Assessment
An AI-assisted first pass over the QMS documents you already have, with every result reviewed by an advisor.
Standards and Regulations Involved
Questions About the ISO 13485 Certification Audit
What's the difference between Stage 1 and Stage 2?
Stage 1 checks documentation and readiness: whether your system is defined and you're prepared for the implementation audit. Stage 2 checks implementation: whether the system is actually working across your scope.
How long does an ISO 13485 certificate last?
Certificates run on a three-year cycle. Surveillance audits happen at least annually, and a recertification audit takes place before the certificate expires.
Does ISO 13485 certification satisfy FDA?
No. The QMSR incorporates ISO 13485:2016 by reference, so a certificate is a strong foundation, but FDA inspects independently and adds its own requirements, such as MDR, UDI and the records and labeling provisions in 820.35 and 820.45.
How many records do we need before Stage 2?
There's no fixed number, but auditors need enough evidence to see each process operating. Ask your certification body about its expectations, and don't book Stage 2 until internal audit and management review have both produced real outputs.
Related Audits and Inspections
ISO 13485 Surveillance Audit
The periodic audits, at least annually, that support continued ISO 13485 certification between renewals.
ISO 13485 Recertification Audit
The pre-expiry audit that reviews the whole ISO 13485 system and how it performed over the three-year cycle.
MDSAP Audit
One audit by a recognized auditing organization that covers several participating regulators, including FDA.
Internal Audit
Audits your own team runs of your quality system, now open to FDA inspection under the QMSR.
Request an Assessment
Prepare for Your ISO 13485 Certification Audit With an Advisor
Tell us what's coming and when, and an advisor will scope readiness work around it. Please don't send confidential documents yet: secure upload is set up after onboarding.


