The short answer
ISO 13485 is the quality management system standard for medical devices. It applies to businesses that design, make, sterilise, import, distribute or service medical devices or their components. It’s built on the same foundations as ISO 9001, but it adds requirements for risk management, design control, traceability, complaint handling and reporting to regulators.
In Australia, a manufacturer’s QMS that complies with ISO 13485:2016 is treated, under a TGA Order, as meeting the relevant parts of the quality management system conformity assessment procedures. For sponsors and distributors, certification is usually a customer or supplier requirement rather than a legal one.
The 2016 edition was reviewed and confirmed by ISO in October 2025, so there is no new version to transition to.
Reviewed October 2026. Checked against the TGA, the Federal Register of Legislation, the FDA and ISO.
Talk to an ISO Lead Auditor →If you make, import or supply medical devices, ISO 13485 has probably already come up. A hospital or health service asks for it in a tender. An overseas manufacturer wants it before appointing you as their Australian distributor. A customer you make components for sends you a supplier questionnaire with it on page one.
It’s the right standard for the job, and it’s a more demanding one than ISO 9001. Streamline audits, gap-assesses and mentors ISO 13485 systems for Australian medical device businesses, often alongside an existing ISO 9001 system.
What ISO 13485 is
ISO 13485:2016 is titled Medical devices. Quality management systems. Requirements for regulatory purposes. The last three words are the important ones. Where ISO 9001 is built around customer satisfaction and continual improvement, ISO 13485 is built around safe, effective devices and meeting the regulatory requirements of the markets you sell into.
Australia adopted it unchanged as AS ISO 13485:2017. It underpins the TGA’s quality system assessment, the international Medical Device Single Audit Program (MDSAP), and the US FDA’s Quality Management System Regulation (QMSR), which has incorporated ISO 13485:2016 by reference since 2 February 2026.
There is no new edition coming. ISO reviewed the standard in 2025 and confirmed the 2016 edition on 31 October 2025. If you have been following the ISO 9001:2026 transition, none of that applies here.

Who needs ISO 13485
- Manufacturers of medical devices, including in vitro diagnostics, whether you design the device or make it to someone else’s design.
- Contract manufacturers and component suppliers whose customers are device manufacturers. It usually arrives as a supplier requirement.
- Sterilisation, packaging and calibration service providers working on devices.
- Australian sponsors, importers and distributors. You hold the ARTG entry or move the product, so the law gives you post-market duties: distribution records, passing on complaints, adverse event reporting and recalls. ISO 13485 gives that work a structure an overseas manufacturer, a hospital or an auditor will recognise.
- Businesses that service or install devices, where traceability and records follow the device into the field.
Where it sits with the TGA
This is where most of the confusion lives, so it’s worth being precise.
For manufacturers, the Medical Devices Regulations 2002 set out conformity assessment procedures, including quality management system procedures. The Therapeutic Goods (Conformity Assessment Standard for Quality Management Systems) Order 2019 names ISO 13485:2016. A quality management system that complies with it is treated as having had the relevant parts of those procedures applied. The Order is a deeming provision rather than a mandate, but in practice ISO 13485 is how manufacturers show the TGA their quality system works.
For evidence, the TGA accepts MDSAP certificates as manufacturing evidence and can use MDSAP audit reports to shorten its own assessment. It accepts MDSAP certificates and audit reports only where the audit covered the Australian requirements and the certificate includes Australia in scope.
What the TGA finds. In its own audit programme the TGA reports averages of 2.9 major and 8.3 minor nonconformities per audit across domestic and overseas audits (financial years 2021 to 2023). The most frequent areas are:
- general QMS requirements and documentation (clauses 4.1 and 4.2.1)
- purchasing (7.4.1)
- production and service provision (7.5.1)
- corrective action (8.5.2)
- internal audit (8.2.4)
One of the corrective action examples it gives is “corrections instead of corrective action”. We find the same pattern at internal audit, and it is cheaper to find it there.
For sponsors and distributors, the Act and Regulations put obligations on you directly: being able to provide the manufacturer’s evidence, keeping distribution records, passing complaints to the manufacturer and assisting investigations, reporting adverse events and running recalls. ISO 13485 certification is not a legal requirement for a sponsor. It is very often a commercial one, and the post-market clauses of the standard line up closely with what the TGA expects of you anyway.
ISO 13485 certification is not market approval. It does not put a device on the ARTG, and it does not replace TGA conformity assessment. Which regulatory pathway applies depends on the device’s classification and where it is made, and that sits with your regulatory affairs adviser or the TGA. We work on the quality system that sits underneath.
What it adds to ISO 9001
| Area | ISO 13485:2016 | Why it matters |
|---|---|---|
| Risk management | Risk-based approach across the QMS (4.1.2) and documented risk management in product realisation (7.1) | Risk is about patient and user safety, not only business risk. Most manufacturers work to ISO 14971 for this |
| Medical device file | A file for each device type or family (4.2.3) | Holds the specifications, labelling, manufacturing and servicing requirements in one place |
| Records | Kept for at least the lifetime of the device, and never less than two years from release (4.2.5) | Often much longer than businesses expect |
| QMS software | Software used in the QMS has to be validated (4.1.6) | Includes inventory, ERP and complaint systems, not just production software |
| Work environment | Requirements for work environment and contamination control (6.4) | Cleanrooms, health and clothing of personnel, and control of contaminated product |
| Design and development | Detailed controls through to design transfer, design changes and a design file (7.3) | Can be excluded only where regulations allow, for example a distributor that designs nothing |
| Purchasing | Supplier criteria proportionate to the risk of what you buy (7.4) | A common finding in TGA audits |
| Validation | Process validation (7.5.6), plus sterilisation and sterile barrier validation where relevant (7.5.7) | Where you can’t fully verify the output, you validate the process |
| Identification and traceability | Product identification including UDI where required (7.5.8), traceability, and extra requirements for implantable devices (7.5.9) | You need to know where every batch went |
| Feedback and complaints | Feedback (8.2.1), complaint handling (8.2.2), reporting to regulatory authorities (8.2.3) | The post-market link to the regulator |
| Nonconforming product | Covers product found nonconforming after delivery, and advisory notices (8.3.3) | This is where recalls and field actions live |
| Improvement | Maintain the effectiveness of the QMS, rather than continually improve it | A deliberate difference: the regulatory goal is a stable, controlled system |
The structure is different too. ISO 13485:2016 follows the older ISO 9001:2008 clause layout, not the harmonised structure ISO 9001, ISO 14001 and ISO 45001 now share. It asks for more documented procedures than ISO 9001 does. That matters most when you run the two together.
Running ISO 13485 alongside ISO 9001
Many medical device businesses hold both: ISO 13485 for the devices, ISO 9001 for the wider business or for customers who ask for it by name. The clause numbers don’t line up, so a combined system needs a map.
In a recent combined ISO 9001 and ISO 13485 internal audit for an Australian surgical supplies business, we tested traceability the way a recall would test it. We pulled batch numbers from the inventory system and followed a mock recall through to the customer list. We also built the business a conformity matrix: each clause of both standards against a plain English summary of the requirement and the evidence that meets it.
That matrix outlasts any one audit. When the person who looks after the system is away, or leaves, whoever picks it up can still show a certification auditor how every requirement is met.
Two practical points for a combined system:
- One manual, two maps. Write the system around how the business works, then map it to each standard. Don’t run two parallel sets of procedures.
- Two certificates. ISO 13485 certification is not ISO 9001 certification. If customers ask for both, both have to be in your certification body’s scope.
How we help
- Gap analysis. An independent assessment of where your system stands against ISO 13485, with a prioritised action list. For a business with ISO 9001 already, it is usually the fastest way to scope the extra work.
- Independent internal audits. Clause 8.2.4 requires them, and they’re one of the TGA’s most common findings. We audit against ISO 13485, ISO 9001 or both in one visit, on site or remotely, and test traceability, complaints and supplier control on real records.
- ISO mentoring. For a capable quality or regulatory person building or extending the system themselves, with an experienced auditor checking the work as it goes.
- Conformity matrices and combined systems. Mapping ISO 13485 and ISO 9001 to one set of processes, so the system is run once and audited twice.
- Management system maintenance. Keeping internal audits, management reviews and corrective actions on schedule between certification audits.
Getting certified
Certification is through an accredited certification body, with the usual Stage 1 and Stage 2 audits followed by surveillance. Check that the body’s accreditation actually covers ISO 13485 and the technical area your devices fall into. Then decide early whether you also want MDSAP, which audits to ISO 13485 plus the requirements of the participating regulators (Australia, Brazil, Canada, Japan and the US) in one programme. Our guide to choosing an ISO certification body in Australia covers the checks.
How long it takes: three to six months for most organisations, longer for larger, multi-site or multinational ones. The variable that matters most is design control and validation. A distributor with a working ISO 9001 system is extending what it has. A manufacturer that designs its own devices, starting from scratch, has far more to build and evidence.
We don’t publish a cost range for ISO 13485. Whether you design devices, sterilise them or only distribute them moves the number too much for a range to be honest. Tell us your scope and we’ll give you a real figure.
Been asked for ISO 13485 in a tender or supplier questionnaire?
Send us the clause or questionnaire and we’ll tell you what it does and does not require, and whether your existing system is closer than you think. No obligation and no sales pitch.
Book a free consultation →Common questions
Is ISO 13485 mandatory in Australia?
Not as a blanket legal requirement. For manufacturers, a quality system complying with ISO 13485:2016 is treated as meeting the relevant parts of the TGA’s quality management system conformity assessment procedures, which makes it the practical route. For sponsors and distributors it isn’t a legal requirement, though health customers and overseas manufacturers often ask for it.
What is the difference between ISO 9001 and ISO 13485?
ISO 13485 is a quality management system standard for medical devices. It adds risk management, design control, validation, traceability, complaint handling and regulatory reporting to ISO 9001’s foundations. It asks you to maintain the effectiveness of the system rather than continually improve it. It also follows the older ISO 9001:2008 clause structure, so the two don’t line up clause by clause.
Does ISO 13485 certification mean my device is approved by the TGA?
No. Certification shows your quality management system meets the standard. Putting a device on the Australian Register of Therapeutic Goods is a separate regulatory process that depends on the device’s classification and evidence.
Is there a new version of ISO 13485 coming?
Not at present. ISO completed its review in 2025 and confirmed the 2016 edition on 31 October 2025, so ISO 13485:2016 remains current.
Do distributors need ISO 13485?
They don’t need it by law, but it is common. The parts of the standard covering traceability, complaints, adverse event reporting and recalls describe work an Australian sponsor or distributor has to do anyway, and certification is how many overseas manufacturers and health customers check it is done.
Can design and development be excluded from ISO 13485?
Yes, where the applicable regulatory requirements allow it, for example a distributor that designs nothing. The exclusion and the reason for it have to be recorded in the quality manual.
What is MDSAP?
The Medical Device Single Audit Program lets one audit satisfy the quality system requirements of several regulators: Australia’s TGA, Brazil’s ANVISA, Health Canada, Japan’s regulators and the US FDA. The TGA accepts MDSAP certificates as manufacturing evidence.
Do you need an ISO 13485 internal audit before certification?
Yes. Clause 8.2.4 requires planned internal audits, and certification bodies normally expect to see internal audits and a management review completed, with findings followed through, before Stage 2.
How long does ISO 13485 take?
Three to six months for most organisations, longer for larger, multi-site or multinational ones. It depends mostly on how much design and validation work is in scope, and whether a working ISO 9001 system already exists.
Where Streamline fits
Streamline is run by a practising ISO Lead Auditor who audits quality management systems across manufacturing, healthcare and technical businesses, and has recently audited a combined ISO 9001 and ISO 13485 system. You deal with the auditor from the first conversation.
The honest first step is usually not certification. It’s finding out how far your current system is from the standard, and whether the clause someone has asked for applies to you at all. A gap analysis answers both. If you already hold ISO 9001, you’re extending it, not starting again.
Sources
- ISO, ISO 13485:2016 Medical devices. Quality management systems. Requirements for regulatory purposes, confirmed 31 October 2025
- Standards Australia, AS ISO 13485:2017
- Federal Register of Legislation, Therapeutic Goods (Conformity Assessment Standard for Quality Management Systems) Order 2019
- Therapeutic Goods Administration, Medical device TGA update: audit program and compliance trends
- US Food and Drug Administration, Quality Management System Regulation (QMSR)
- US Food and Drug Administration, Medical Device Single Audit Program (MDSAP)
Talk to an ISO Lead Auditor
If you have been asked for ISO 13485, or you need an internal audit before your next surveillance visit, email hello@streamline.business or book a free consultation.
Book a free consultation →










