ISO 13485 Training Guide: Courses, Requirements & Career

Everything you need to know about ISO 13485:2016, from its requirements and differences with ISO 9001 to Foundation, Internal Auditor and Lead Auditor training, salaries, and 25 frequently asked questions.

Every syringe, pacemaker, diagnostic kit and surgical instrument carries a silent promise: it will work safely, every single time. ISO 13485 is the international standard that helps manufacturers keep that promise. If you work in, or want to enter, the medical device, diagnostics, healthcare packaging or life-sciences sector, understanding ISO 13485 is no longer optional. It is the language regulators, customers and auditors speak.

This guide is written for quality professionals, engineers, regulatory specialists, students and business owners who want clear answers. By the end you will know what ISO 13485 requires, how it differs from ISO 9001, how organisations implement and certify it, and which training course is right for you.

In this guide

  1. What is ISO 13485?

  2. The ISO 13485 family and related standards

  3. Why ISO 13485 matters

  4. Which industries implement ISO 13485

  5. Key requirements, clause by clause

  6. ISO 13485 vs ISO 9001

  7. Documentation and records: paper, electronic or hybrid

  8. How certification works and how it helps

  9. Building your knowledge: Foundation, Internal Auditor and Lead Auditor

  10. Which course should you choose?

  11. How EAS online courses help you succeed

  12. Career benefits, roles and salaries

  13. 25 frequently asked questions

  14. Free download: ISO 13485 internal audit checklist

What is ISO 13485?

ISO 13485:2016, Medical devices – Quality management systems – Requirements for regulatory purposes, is the internationally recognised standard for a quality management system (QMS) in organisations involved in the design, production, installation, servicing, storage, distribution or supply of medical devices and related services.

Unlike general quality standards, ISO 13485 has one overriding purpose: to show that an organisation can consistently provide safe, effective medical devices that meet customer and regulatory requirements. That is why the words "for regulatory purposes" appear in its title.

  • Current edition: ISO 13485:2016 (third edition). ISO's technical committee ISO/TC 210 reconfirmed it after its most recent systematic review, so it remains the current version.

  • Europe: In the European Union, EN ISO 13485:2016 + A11:2021 is the harmonised standard used to demonstrate QMS conformity under the Medical Device Regulation (EU MDR) and In-Vitro Diagnostic Regulation (IVDR).

  • United States: Since 2 February 2026, the US FDA's Quality Management System Regulation (21 CFR Part 820, QMSR) incorporates ISO 13485:2016 by reference, with some additional FDA requirements.

  • Global: The Medical Device Single Audit Program (MDSAP) uses ISO 13485 as its backbone, allowing one audit to satisfy regulators in Australia, Brazil, Canada, Japan and the USA.

  • India: India's Medical Devices Rules, 2017 set QMS requirements for manufacturers (Fifth Schedule) that are closely aligned with ISO 13485.

ISO 13485 is a stand-alone requirements standard, but it never works alone. A medical device QMS draws on a family of supporting standards, each covering a specialised topic. Knowing how they fit together is one of the most valuable skills an ISO 13485 professional can have.

StandardTopicHow it links to ISO 13485
ISO 14971:2019 (+ ISO/TR 24971)Application of risk management to medical devicesThe accepted method for the risk management required throughout product realization (clause 7.1)
IEC 62304Medical device software life-cycle processesDesign and development of software in, or as, a medical device
IEC 62366-1Usability engineeringDesign inputs, verification and validation for use-related risk
ISO 10993 seriesBiological evaluation of medical devicesBiocompatibility evidence for design validation
ISO 11135 / 11137 / 17665Sterilization by ethylene oxide, radiation and moist heatValidation of sterilization processes (clause 7.5.7)
ISO 11607-1 / -2Packaging for terminally sterilized medical devicesSterile barrier system design and validation
ISO 14644 seriesCleanrooms and controlled environmentsWork environment and contamination control (clause 6.4)
ISO 15223-1 / ISO 20417Symbols and information supplied by the manufacturerLabelling and instructions for use
IEC 60601 seriesSafety of medical electrical equipmentDesign inputs and verification for electrical devices
ISO 15378Primary packaging materials for medicinal products (GMP)Relevant to pharmaceutical packaging and combination-product suppliers
ISO 19011:2018Guidelines for auditing management systemsThe basis for planning and conducting ISO 13485 audits
ISO 9001Generic quality management systemsThe original basis of ISO 13485; often held alongside it

Why ISO 13485 Matters

In most industries a quality failure costs money. In medical devices it can cost lives. ISO 13485 matters because it builds safety, traceability and regulatory compliance into every process:

  • Market access: Most major markets expect or require an ISO 13485-based QMS before a device can be sold.

  • Patient safety: Risk management, design controls and process validation reduce the chance of a device failing in use.

  • Recall readiness: Complaint handling, vigilance reporting and traceability allow fast, controlled responses when something goes wrong.

  • Customer confidence: OEMs and hospitals increasingly buy only from ISO 13485 certified suppliers.

  • Operational efficiency: Consistent processes reduce scrap, rework, complaints and audit findings.

Which Industries Implement ISO 13485?

A common misconception is that ISO 13485 is only for companies that put their own name on a medical device. In reality, it applies to any organisation in the device supply chain, including suppliers of components, packaging, software and services.

SectorTypical scope examplesWhy they adopt ISO 13485
Medical device manufacturersImplants, surgical instruments, catheters, syringes, hospital equipmentRegulatory approval (CDSCO, CE, FDA) and customer requirements
In-vitro diagnostics (IVD)Reagents, rapid test kits, analysersIVDR, CDSCO and export requirements
Pharma and drug-device combination productsPrefilled syringes, inhalers, auto-injectors, drug-coated devicesDevice constituent parts must meet device QMS requirements alongside GMP
Medical electronicsPCB assembly, sensors, wearables, patient monitors, imaging subsystemsOEM customers require certified electronics manufacturing services
PackagingSterile barrier pouches, trays, blister packs, labelsPackaging directly affects sterility and shelf life
Software and digital healthSoftware as a medical device (SaMD), AI diagnostics, firmwareRegulators treat qualifying software as a medical device
Contract and component manufacturersMoulding, machining, extrusion, assembly, coatingSupplier approval by device OEMs
Sterilization, calibration and service providersEO or gamma sterilization, servicing, refurbishmentOutsourced processes must be controlled by the manufacturer
Distributors and importersWarehousing, logistics, installationTraceability, storage conditions and recall support

Good to know: A pharmaceutical manufacturer making only medicines normally follows GMP rather than ISO 13485. ISO 13485 becomes relevant when a company makes the device part of a combination product, supplies device components, or wants to enter the device market.

Key Requirements of ISO 13485: Clause by Clause

ISO 13485:2016 has eight clauses. Clauses 1 to 3 explain scope, references and definitions. Clauses 4 to 8 contain the requirements an auditor will check.

ClauseTitleWhat it requires in practice
4Quality management systemDefine the organisation's role (manufacturer, supplier, distributor, etc.); apply a risk-based approach to QMS processes; control outsourced processes; validate software used in the QMS; maintain a quality manual and a medical device file for each device type; control documents and records
5Management responsibilityTop management commitment; customer focus including regulatory requirements; quality policy and measurable objectives; defined responsibilities; a management representative; planned management reviews with defined inputs and outputs
6Resource managementCompetent, trained personnel with documented training effectiveness; maintained infrastructure; controlled work environment; contamination control, especially for sterile devices
7Product realizationPlanning with risk management; customer and regulatory requirements; full design and development controls (planning, inputs, outputs, review, verification, validation, transfer, changes, design file); supplier evaluation and purchasing controls; production controls; cleanliness; installation and servicing; sterile device requirements; process and sterilization validation; identification, UDI and traceability; preservation; calibration of monitoring equipment
8Measurement, analysis and improvementFeedback system; complaint handling; reporting to regulatory authorities; internal audits; process and product monitoring; nonconforming product control before and after delivery; data analysis; corrective and preventive action

ISO 13485 vs ISO 9001: What's the Difference?

ISO 13485 began as an adaptation of ISO 9001, and the two share many concepts. They have since grown apart. ISO 9001 aims for customer satisfaction and continual improvement across any industry. ISO 13485 aims for safe, effective devices and regulatory compliance. The table below summarises the differences auditors and implementers meet most often.

AspectISO 9001:2026ISO 13485:2016
PurposeConsistent quality and enhanced customer satisfaction in any sectorSafe and effective medical devices that meet regulatory requirements
StructureHarmonized Structure (clauses 4–10), shared with ISO 14001, ISO 45001 and othersIts own structure (clauses 4–8), based on ISO 9001:2008
Regulatory focusStatutory and regulatory requirements considered generallyRegulatory requirements embedded throughout the standard
ImprovementContinual improvement requiredMaintaining QMS effectiveness; improvement is needed to keep devices safe and effective
RiskRisk-based thinking; risks and opportunitiesFormal product risk management through the life cycle (normally ISO 14971) plus a risk-based approach to QMS processes
DocumentationDocumented information as the organisation needsQuality manual, many documented procedures, and a medical device file for each device type
Customer satisfactionMonitored as a key performance measureReplaced by feedback and complaint handling linked to post-market surveillance
Design and developmentRequired where applicableDetailed requirements including design transfer and a design and development file
Work environmentEnvironment for operation of processesContamination control and specific requirements for sterile devices
Software validationNot specifically requiredValidation of software used in the QMS, production and servicing
TraceabilityWhere requiredMandatory, with extra requirements for implantable devices; supports UDI
Complaints and vigilanceGeneral customer feedbackDocumented complaint handling and reporting of adverse events to regulators
Preventive actionReplaced by risk-based thinkingRetained as a separate requirement (clause 8.5.3)
Management representativeNo longer requiredStill required
ExclusionsRequirements not applicable must be justifiedClauses 6, 7 and 8 may be marked not applicable with justification; design controls may be excluded only where regulations allow
Record retentionAs defined by the organisationAt least the lifetime of the device, and no less than two years from release

Can you hold both? Yes. Many organisations hold ISO 9001 and ISO 13485 together, often in an integrated system. ISO 13485 certification, however, does not automatically mean ISO 9001 conformity, and the reverse is also true.

Implementation: Documentation and Records, Paper or Electronic?

ISO 13485 is documentation-heavy for a good reason: if something goes wrong with a device, the organisation must be able to show exactly how it was designed, made, tested and released. The standard does not say whether documents and records must be paper or electronic. It says they must be controlled, legible, identifiable, retrievable and protected.

What you will need to document

  • QMS documents: quality policy, quality objectives, quality manual (including scope and justification for non-applicable clauses), and procedures required by the standard.

  • Medical device file: device description, intended use, labelling, specifications, manufacturing, packaging, storage, installation and servicing procedures, and measurement procedures for each device type.

  • Design and development file: design plans, inputs, outputs, reviews, verification, validation, transfer and change records.

  • Records: training, maintenance, supplier evaluation, batch or device history, process validation, sterilization, traceability, calibration, complaints, internal audits, nonconformities, CAPA and management review.

AspectPaper-based systemElectronic system (eQMS)What ISO 13485 expects
Document controlSigned masters, controlled copies, distribution listsWorkflow approval, automatic versioning, controlled accessReview and approval before issue; current versions at point of use; obsolete documents prevented from use (4.2.4)
RecordsForms, logbooks, batch records in filesElectronic forms, database entries, audit trailsLegible, identifiable, retrievable, protected from loss or unauthorised change (4.2.5)
SignaturesHandwrittenElectronic signaturesIdentifies who approved; FDA Part 11 applies for US submissions
SoftwareMinimaleQMS, ERP, MES, LIMS, calibration softwareValidation of QMS software before use and after changes, proportionate to risk (4.1.6)
RetentionPhysical storage, fire and pest protectionBackup, disaster recovery, readable formatsLifetime of the device, and at least two years from release
Confidential dataLocked cabinetsAccess rights, encryptionProtect confidential health information (4.2.5)
Best suited forSmall companies and early-stage start-upsGrowing and multi-site organisationsEither approach is acceptable if controls are effective

Consultant's tip: Many organisations run a hybrid system: electronic document control with paper records on the shop floor. This works well, provided the interface between the two is controlled and electronic systems are validated. Apply the ALCOA+ principles (attributable, legible, contemporaneous, original, accurate, complete, consistent, enduring and available) to every record.

How ISO 13485 Certification Works and How It Helps

The certification journey

  1. Gap analysis against ISO 13485 and applicable regulations

  2. Implementation of processes, documents, risk management and records

  3. Training of internal auditors, process owners and management

  4. Internal audit and management review covering the full QMS

  5. Stage 1 audit by an accredited certification body (readiness and documentation review)

  6. Stage 2 audit (on-site assessment of implementation and effectiveness)

  7. Certification valid for three years, with annual surveillance audits and recertification in year three

Who benefitsHow certification helps
The organisationMarket access, fewer recalls and complaints, efficient processes, readiness for regulatory inspections, and a basis for CE marking, CDSCO licensing, FDA QMSR and MDSAP
Customers and OEMsConfidence in suppliers, fewer supplier audits, reliable traceability
Patients and usersSafer, more reliable devices
RegulatorsEvidence of a systematic QMS, supporting reliance programmes such as MDSAP
EmployeesClear responsibilities, better training, a culture of quality

Choose wisely: Always choose a certification body that is accredited for ISO 13485 by a recognised accreditation body. For EU MDR, a Notified Body is required for most device classes; ISO 13485 certification alone does not grant CE marking.

Building Your Knowledge: Foundation, Internal Auditor and Lead Auditor Courses

Reading a standard is one thing. Understanding how to apply and audit it is another. Structured courses give you a guided path from awareness to audit leadership.

ISO 13485 FoundationISO 13485 Internal AuditorISO 13485 Lead Auditor
PurposeUnderstand the standard, its terms and requirementsPlan, conduct, report and follow up internal and supplier auditsLead audit teams for first, second and third-party audits
Who can do itAnyone: students, freshers, production, R&D, regulatory, sales and management staffQA/QC, production, R&D and regulatory staff; ideally 6–12 months' work experience and basic ISO 13485 knowledgeQuality professionals, consultants and aspiring certification auditors; ideally 1–2 years' relevant experience and prior ISO 13485 knowledge
Key contentMedical device regulations; ISO 13485 structure and clauses; links to ISO 14971; documentationAll of Foundation, plus ISO 19011 audit principles; audit planning; checklists; interviewing; evidence; nonconformity reporting; follow-upAll of Internal Auditor, plus audit programme management; leading teams; opening and closing meetings; certification process; role plays and case studies
Format at EASSelf-paced onlineSelf-learning or live virtualLive virtual or classroom, 5 days / 40 hours
AssessmentOnline quiz and final examExercises, quizzes and final examContinuous assessment and written examination
CertificateEAS certificate of completionEAS Internal Auditor certificateLead Auditor certificate (CQI-IRCA certified where applicable)
What you can do nextContribute to QMS implementation; move on to Internal AuditorAudit your organisation's QMS and suppliers; support certification and CAPALead supplier and internal audits; apply to certification bodies as a trainee auditor; register with CQI-IRCA (subject to their criteria)

Which ISO 13485 Course Should You Choose?

Choosing a course is a career decision, so it deserves a little thought. Use this quick guide:

If you are…Start withWhy
A student or fresher interested in medical devicesFoundationBuilds the vocabulary and regulatory context employers look for
Working in production, R&D, stores or sales at a device companyFoundation, then Internal AuditorHelps you understand why procedures exist and contribute to audits
A QA/QC or regulatory professionalInternal AuditorThe most practical, job-ready credential for day-to-day QMS work
Responsible for supplier quality or vendor developmentInternal Auditor, then Lead AuditorSupplier audits are second-party audits; Lead Auditor skills add authority
A QA/RA manager or management representativeLead AuditorComplete view of audit programmes, certification and regulatory expectations
A consultant or aspiring certification body auditorLead AuditorThe recognised entry qualification for third-party auditing
Already an ISO 9001 auditor moving into medical devicesISO 13485 Internal Auditor or Lead AuditorFocuses on the device-specific differences you will be audited on

Counsellor's advice: If you are unsure, begin with the level you can apply immediately at work. Knowledge sticks when it is used. Bundles combining all three levels are available if you want to plan your full pathway in one step.

How EAS Online Courses Help You Succeed

EAS (Empowering Assurance Systems) is a JAS-ANZ accredited certification body and a CQI-IRCA Approved Training Partner since 2016. Our platform, onlinecourse.eascertification.com, was built to give learners the depth of a classroom course with the flexibility of online study.

Platform featureHow it helps you
Presentation slides for every moduleStructured learning, clause by clause
Each clause explained with 2–3 scenariosSee how requirements work in real device companies
Clause notesFast revision before exams and audits
Audit perspective for each clause (Internal Auditor)Know what evidence to look for and what questions to ask
In-built exercises and quizzesPractise and check understanding as you go
Standard referencesLearn to read and interpret the actual clause text
Downloadable materialsKeep templates and notes for use at work
Online final exam and soft-copy certificateCertify on your schedule, from anywhere
Module videos (coming soon)An extra way to learn each topic

Explore the courses:

Career Benefits of Accredited ISO 13485 Training

The medical device sector is one of the fastest-growing areas of manufacturing, in India and worldwide. Regulators are tightening requirements, and companies need people who understand them. An accredited ISO 13485 qualification signals exactly that.

  • Better shortlisting: Recruiters often search for "ISO 13485" and "internal auditor" or "lead auditor" as keywords.

  • Recognised credibility: Accredited training follows defined learning outcomes and assessment, so employers trust it.

  • A move up the ladder: Audit skills move you from carrying out procedures to evaluating and improving them.

  • Global mobility: ISO 13485 is recognised in almost every market, from India and the Middle East to Europe and the USA.

  • Flexible career paths: Lead auditors can work in industry, with certification bodies, or as independent consultants.

Positions and salaries: an indicative comparison

Salaries depend on company size, city, sector, experience and negotiation. The figures below are indicative ranges drawn from job-market observations, meant to show direction rather than guarantee pay.

RoleTypical experienceTypical qualificationIndicative annual CTC (India)
QA / QC Executive0–3 yearsDegree + ISO 13485 Foundation₹2.5 – 5 lakh
QMS / Compliance Engineer2–5 yearsISO 13485 Internal Auditor₹4 – 8 lakh
Supplier Quality Engineer / Internal Audit Lead4–8 yearsInternal Auditor + Lead Auditor₹7 – 14 lakh
QA / RA Manager, Management Representative7–12 yearsLead Auditor + ISO 14971 knowledge₹12 – 25 lakh
Head of Quality & Regulatory Affairs12+ yearsLead Auditor + regulatory expertise₹25 – 50 lakh+
Certification body auditor (full-time)5+ years of sector experienceLead Auditor + CB qualification₹8 – 20 lakh
AngleWithout ISO 13485 trainingWith accredited ISO 13485 training
Job searchGeneric quality rolesShortlisted for medical device, IVD and supplier-quality roles
ResponsibilitiesFollowing procedures, inspectionAuditing, CAPA, supplier approval, audit readiness
PromotionSlower; experience alone must prove competenceFaster route to lead, supervisory and management roles
Pay bandEntry band for the gradeOften considered for the next band or role with audit responsibility
MobilityLimited to local, general manufacturingRecognised by multinational OEMs and overseas employers
Independent workNot usually possibleFreelance internal and supplier audits, consulting and training
Work model / regionIndicative earningsNotes
India – in-house employment₹4 – 25 lakh per yearDepends on role, city and company size
India – freelance auditor / consultant₹8,000 – 20,000 per audit dayExperienced lead auditors with sector expertise command the upper end
Middle EastHigher tax-free packages for experienced QA/RA rolesDemand driven by healthcare manufacturing and distribution
USAAbout US$80,000 – 132,000 per year for ISO 13485 lead auditor rolesBased on job listings in 2026
EuropeStrong demand linked to EU MDR and IVDRNotified Body and QA/RA roles are particularly sought after

25 Frequently Asked Questions about ISO 13485

What is ISO 13485 in simple words?
It is the international standard for a quality management system for organisations involved with medical devices. It helps them make safe, effective devices and meet regulatory requirements.
What is the latest version of ISO 13485?
ISO 13485:2016 is the current edition. It was reconfirmed after its most recent systematic review and remains in force.
Is ISO 13485 mandatory?
ISO 13485 itself is voluntary, but many regulators require an equivalent QMS. In practice it is essential for CE marking in Europe, is incorporated into the US FDA QMSR, supports MDSAP, and aligns with India's Medical Devices Rules.
Who needs ISO 13485 certification?
Medical device and IVD manufacturers, and the suppliers, contract manufacturers, packaging and sterilization providers, software developers, distributors and service companies that support them.
What is the difference between ISO 9001 and ISO 13485?
ISO 9001 focuses on customer satisfaction and continual improvement in any industry. ISO 13485 focuses on device safety, risk management and regulatory compliance, with more detailed documentation, traceability and design control requirements.
Can a company hold both ISO 9001 and ISO 13485?
Yes. Many do, often through an integrated management system audited in one visit.
How long does ISO 13485 certification take?
Typically six to twelve months from gap analysis to certification, depending on company size, device complexity and existing systems.
How long is an ISO 13485 certificate valid?
Three years, with surveillance audits every year and a recertification audit before expiry.
What is a medical device file?
A file for each device type or family that contains or references the information needed to show conformity: description, intended use, labelling, specifications, manufacturing, servicing and measurement procedures.
Does ISO 13485 require risk management?
Yes. It requires a documented risk management process across product realization, and ISO 14971 is the accepted method for meeting it.
Can records be kept electronically?
Yes. Records may be paper or electronic, provided they are controlled, protected and retrievable, and any software used is validated.
How long must records be kept?
At least for the lifetime of the device as defined by the organisation, and not less than two years from product release, or longer if regulations require.
Can design and development be excluded?
Only where regulations allow it, for example for a contract manufacturer that does not design products. Any exclusion must be justified in the quality manual.
What is the difference between an internal auditor and a lead auditor?
An internal auditor audits their own organisation (first-party audits). A lead auditor is trained to lead audit teams, including supplier (second-party) and certification (third-party) audits.
Who can join an ISO 13485 Foundation course?
Anyone. No prior experience is needed, making it ideal for students, freshers and staff new to medical devices.
Do I need Foundation before Internal Auditor?
It is recommended but not always mandatory. If you have no background in ISO 13485, Foundation makes the Internal Auditor course much easier.
Can I take the Lead Auditor course directly?
Yes, if you already understand ISO 13485 requirements and have relevant work experience. Otherwise, start with Foundation or Internal Auditor.
Is an online ISO 13485 course valid?
Yes. Online courses from accredited or approved training providers carry the same certificate as classroom courses. What matters is the provider's recognition and the course assessment.
What is CQI-IRCA?
The Chartered Quality Institute's International Register of Certificated Auditors. It certifies auditor training courses and registers auditors worldwide. A CQI-IRCA certified course follows defined learning outcomes and examination rules.
Does the certificate expire?
Training certificates do not expire, but refresher training is recommended when the standard or regulations change.
How is the online final exam conducted at EAS?
After completing the modules, you take the final exam online. A minimum score of 70% is needed to pass, and one free retake is available.
What jobs can I get after ISO 13485 training?
QA/QC executive, QMS or compliance engineer, internal auditor, supplier quality engineer, regulatory affairs associate, QA/RA manager and, with experience, certification body auditor or consultant.
Will ISO 13485 training increase my salary?
Training alone does not guarantee a raise, but it makes you eligible for audit, supplier-quality and management roles that usually carry higher pay bands.
Can non-medical industries benefit from ISO 13485?
Yes. Electronics, plastics, packaging, precision engineering and software companies use it to become approved suppliers to the medical device industry.
How do I get started with EAS?
Choose your course on onlinecourse.eascertification.com, enrol online, receive your login details by email and start learning at your own pace.

Free Download: ISO 13485:2016 Internal Audit Checklist

To help you put this guide into practice, we have prepared a clause-by-clause ISO 13485:2016 internal audit checklist. It lists the key requirements to verify, the evidence to look for, and space to record your findings.

Download the ISO 13485 Internal Audit Checklist

Final Thoughts

ISO 13485 is more than a certificate on the wall. It is the discipline that keeps medical devices safe, regulators confident and patients protected. For professionals, it opens doors to one of the most stable and rewarding sectors in manufacturing.

Whether you are taking your first step or preparing to lead audits, start with the level that fits your goals. Explore ISO 13485 courses at EAS Online and build expertise the medical device industry values.

Need help choosing? Write to training@eascertification.com or WhatsApp +91 82206 66148.

This article is for general information. Always refer to the current edition of ISO 13485 and applicable regulations for your market.