QMSAdvisor

Certification and Market Access

ISO 13485 Certification Readiness

ISO 13485 certification starts with a Stage 1 review of your documentation and readiness, then a Stage 2 audit of how the system actually runs. We help you arrive at Stage 1 with a defensible scope, the required procedures in place, and a full internal audit and management review already on record.

What You Receive

  1. 01Scope Statement and Justifications
  2. 02Gap Report Against ISO 13485
  3. 03Procedure and Records Checklist
  4. 04Internal Audit and Management Review Records
  5. 05Stage 1 Readiness Summary

Every finding is reviewed and approved by a qualified QMS advisor before it reaches you.

What It Is

A certification body audits your quality management system against ISO 13485:2016 in two stages. Stage 1 looks at your documentation, your scope and whether you're ready for the full audit. Stage 2 tests implementation: auditors sample records, interview staff and follow processes where the work happens. A certificate then runs on a three-year cycle, with surveillance audits at least annually and a recertification audit before it expires.

Most Stage 1 trouble traces back to a few early decisions. The scope statement has to match the devices and activities you actually perform. Excluding design and development needs a justification that applicable regulatory requirements permit it, and any requirement you don't apply needs a reason tied to the nature of your device or your activities. The procedures and records the standard requires to be documented have to exist, be controlled and be in use, not just drafted.

Since FDA's QMSR took effect on February 2, 2026 and incorporates ISO 13485:2016 by reference, the same system now has to hold up for a certification body and for an FDA investigator. Certification readiness is a good moment to build it once for both, while keeping the FDA-specific additions visible in your quality manual and procedures, such as the records requirements in 820.35 and the labeling and packaging controls in 820.45.

When You Need It

  • A customer, distributor or partner requires an ISO 13485 certificate before they'll buy from you or qualify you as a supplier
  • You plan to sell into a market whose regulator relies on ISO 13485 certification or an MDSAP certificate
  • Your certification body has proposed Stage 1 dates and your internal audit or management review hasn't happened yet
  • You're moving from ISO 9001 to ISO 13485 and need to close the device-specific gaps
  • You changed scope, added a site or brought a process in-house and need to extend your certificate
  • A previous Stage 1 or Stage 2 audit raised nonconformities you need to close before the next visit

What We Do

  1. 01

    Confirm Scope and Exclusions

    We map your devices, sites and activities against the standard and write a scope statement the certification body can verify. Where design and development or another requirement doesn't apply, we draft the justification and check that it holds for every market you sell into.

  2. 02

    Run an AI-Assisted Gap Analysis

    You upload the quality documents you already have. The AI does a first pass against ISO 13485:2016 and the QMSR additions, and an advisor reviews every result before it becomes a finding with a source, a severity and an owner.

  3. 03

    Close the Documented Procedure Gaps

    We work through the procedures and records the standard requires to be documented, such as document and record control, internal audit, nonconforming product, CAPA, complaint handling and purchasing, and check each one against how your team actually works.

  4. 04

    Complete Internal Audit and Management Review

    A certification body expects to see the system running before Stage 1. We run, or support your team in running, a full internal audit, and help you hold a management review with the inputs the standard calls for and outputs you can act on.

  5. 05

    Hold a Readiness Review Before Stage 1

    An advisor walks the system the way a Stage 1 auditor would: scope, quality manual, procedure set, records of implementation and open actions. You get a plain list of what's ready, what isn't, and what can reasonably carry into Stage 2.

  6. 06

    Support Stage 2 and the Findings Response

    During Stage 2 we help with document retrieval and interview preparation. Afterward, we help you write corrections and corrective actions for any nonconformities in a form the certification body can verify and close.

Deliverables

  • Scope Statement and Justifications

    A scope written to your actual devices, sites and activities, with documented justification for any exclusion or non-application.

  • Gap Report Against ISO 13485

    Advisor-reviewed findings sorted by severity, each tied to the document and location it came from.

  • Procedure and Records Checklist

    The documented procedures and records the standard requires, cross-referenced to the controlled document that meets each one.

  • Internal Audit and Management Review Records

    A completed internal audit report and management review record, written so a Stage 1 auditor can follow them.

  • Stage 1 Readiness Summary

    A short, candid read on readiness, with remaining items, owners and due dates.

How the Platform Helps

  • One Library for the Whole Procedure Set

    Upload documents in any format, including exports from the eQMS you already use. Originals are preserved with a SHA-256 fingerprint and duplicates are flagged, so you can see exactly which version the gap analysis read.

  • Findings That Point to the Source

    Every finding names the document and location it came from, its gap type and a what-to-submit checklist, so your team knows what evidence closes it.

  • An Action Plan Built Around the Audit Date

    Owners, due dates and evidence requirements, sorted by severity, so the items that would hold up Stage 1 get done first.

  • Evidence Review Before the Auditor Sees It

    Your team submits evidence and an advisor accepts it or requests a revision with a note. The activity history records every decision.

See the full platform

Audits and Inspections It Prepares You For

Standards and Regulations in Scope

Questions About This Service

What is the difference between Stage 1 and Stage 2?

Stage 1 is mostly a documentation and readiness review: the auditor checks your scope, quality manual and procedures, and whether the system is ready to be audited in full. Stage 2 tests implementation by sampling records, interviewing staff and following processes. Problems found at Stage 1 can delay Stage 2, so it pays to close them early.

Do we need a full internal audit and management review before Stage 1?

Certification bodies generally expect evidence that the system has been operating, and a completed internal audit and management review are the usual proof. Ask your certification body what it expects to see, but plan on having both complete and on record before Stage 1.

Can we exclude design and development?

Only where applicable regulatory requirements allow it, and the justification belongs in your quality manual. If you sell in the US, check this carefully, because FDA's design requirements apply depending on your device and classification. We help you write a justification that holds for every market you sell into.

How long does it take to get ready for certification?

It depends on how much of the system already exists and runs. A firm with procedures in place but thin records needs a different plan from a firm starting from scratch. The gap analysis gives you a realistic plan, and engagements are scoped after an assessment call.

Does an ISO 13485 certificate satisfy FDA?

No. FDA doesn't issue or require ISO 13485 certificates, and a certificate doesn't replace an FDA inspection. Because the QMSR incorporates ISO 13485:2016 by reference, a well-built system is a strong foundation, but FDA's own additions and its inspection approach still apply.

Request an Assessment

Discuss ISO 13485 Certification Readiness With an Advisor

Tell us about your devices, your documents and your timeline, and an advisor will scope the work with you. Please don't send confidential documents yet: secure upload is set up after onboarding.