ISO 13485 Training Guide: Courses, Requirements & Career
Everything you need to know about ISO 13485:2016, from its requirements and differences with ISO 9001 to Foundation, Internal Auditor and Lead Auditor training, salaries, and 25 frequently asked questions.
Every syringe, pacemaker, diagnostic kit and surgical instrument carries a silent promise: it will work safely, every single time. ISO 13485 is the international standard that helps manufacturers keep that promise. If you work in, or want to enter, the medical device, diagnostics, healthcare packaging or life-sciences sector, understanding ISO 13485 is no longer optional. It is the language regulators, customers and auditors speak.
This guide is written for quality professionals, engineers, regulatory specialists, students and business owners who want clear answers. By the end you will know what ISO 13485 requires, how it differs from ISO 9001, how organisations implement and certify it, and which training course is right for you.
In this guide
What is ISO 13485?
The ISO 13485 family and related standards
Why ISO 13485 matters
Which industries implement ISO 13485
Key requirements, clause by clause
ISO 13485 vs ISO 9001
Documentation and records: paper, electronic or hybrid
How certification works and how it helps
Building your knowledge: Foundation, Internal Auditor and Lead Auditor
Which course should you choose?
How EAS online courses help you succeed
Career benefits, roles and salaries
25 frequently asked questions
Free download: ISO 13485 internal audit checklist
What is ISO 13485?
ISO 13485:2016, Medical devices – Quality management systems – Requirements for regulatory purposes, is the internationally recognised standard for a quality management system (QMS) in organisations involved in the design, production, installation, servicing, storage, distribution or supply of medical devices and related services.
Unlike general quality standards, ISO 13485 has one overriding purpose: to show that an organisation can consistently provide safe, effective medical devices that meet customer and regulatory requirements. That is why the words "for regulatory purposes" appear in its title.
Current edition: ISO 13485:2016 (third edition). ISO's technical committee ISO/TC 210 reconfirmed it after its most recent systematic review, so it remains the current version.
Europe: In the European Union, EN ISO 13485:2016 + A11:2021 is the harmonised standard used to demonstrate QMS conformity under the Medical Device Regulation (EU MDR) and In-Vitro Diagnostic Regulation (IVDR).
United States: Since 2 February 2026, the US FDA's Quality Management System Regulation (21 CFR Part 820, QMSR) incorporates ISO 13485:2016 by reference, with some additional FDA requirements.
Global: The Medical Device Single Audit Program (MDSAP) uses ISO 13485 as its backbone, allowing one audit to satisfy regulators in Australia, Brazil, Canada, Japan and the USA.
India: India's Medical Devices Rules, 2017 set QMS requirements for manufacturers (Fifth Schedule) that are closely aligned with ISO 13485.
The ISO 13485 Family and Related Standards
ISO 13485 is a stand-alone requirements standard, but it never works alone. A medical device QMS draws on a family of supporting standards, each covering a specialised topic. Knowing how they fit together is one of the most valuable skills an ISO 13485 professional can have.
| Standard | Topic | How it links to ISO 13485 |
| ISO 14971:2019 (+ ISO/TR 24971) | Application of risk management to medical devices | The accepted method for the risk management required throughout product realization (clause 7.1) |
| IEC 62304 | Medical device software life-cycle processes | Design and development of software in, or as, a medical device |
| IEC 62366-1 | Usability engineering | Design inputs, verification and validation for use-related risk |
| ISO 10993 series | Biological evaluation of medical devices | Biocompatibility evidence for design validation |
| ISO 11135 / 11137 / 17665 | Sterilization by ethylene oxide, radiation and moist heat | Validation of sterilization processes (clause 7.5.7) |
| ISO 11607-1 / -2 | Packaging for terminally sterilized medical devices | Sterile barrier system design and validation |
| ISO 14644 series | Cleanrooms and controlled environments | Work environment and contamination control (clause 6.4) |
| ISO 15223-1 / ISO 20417 | Symbols and information supplied by the manufacturer | Labelling and instructions for use |
| IEC 60601 series | Safety of medical electrical equipment | Design inputs and verification for electrical devices |
| ISO 15378 | Primary packaging materials for medicinal products (GMP) | Relevant to pharmaceutical packaging and combination-product suppliers |
| ISO 19011:2018 | Guidelines for auditing management systems | The basis for planning and conducting ISO 13485 audits |
| ISO 9001 | Generic quality management systems | The original basis of ISO 13485; often held alongside it |
Why ISO 13485 Matters
In most industries a quality failure costs money. In medical devices it can cost lives. ISO 13485 matters because it builds safety, traceability and regulatory compliance into every process:
Market access: Most major markets expect or require an ISO 13485-based QMS before a device can be sold.
Patient safety: Risk management, design controls and process validation reduce the chance of a device failing in use.
Recall readiness: Complaint handling, vigilance reporting and traceability allow fast, controlled responses when something goes wrong.
Customer confidence: OEMs and hospitals increasingly buy only from ISO 13485 certified suppliers.
Operational efficiency: Consistent processes reduce scrap, rework, complaints and audit findings.
Which Industries Implement ISO 13485?
A common misconception is that ISO 13485 is only for companies that put their own name on a medical device. In reality, it applies to any organisation in the device supply chain, including suppliers of components, packaging, software and services.
| Sector | Typical scope examples | Why they adopt ISO 13485 |
| Medical device manufacturers | Implants, surgical instruments, catheters, syringes, hospital equipment | Regulatory approval (CDSCO, CE, FDA) and customer requirements |
| In-vitro diagnostics (IVD) | Reagents, rapid test kits, analysers | IVDR, CDSCO and export requirements |
| Pharma and drug-device combination products | Prefilled syringes, inhalers, auto-injectors, drug-coated devices | Device constituent parts must meet device QMS requirements alongside GMP |
| Medical electronics | PCB assembly, sensors, wearables, patient monitors, imaging subsystems | OEM customers require certified electronics manufacturing services |
| Packaging | Sterile barrier pouches, trays, blister packs, labels | Packaging directly affects sterility and shelf life |
| Software and digital health | Software as a medical device (SaMD), AI diagnostics, firmware | Regulators treat qualifying software as a medical device |
| Contract and component manufacturers | Moulding, machining, extrusion, assembly, coating | Supplier approval by device OEMs |
| Sterilization, calibration and service providers | EO or gamma sterilization, servicing, refurbishment | Outsourced processes must be controlled by the manufacturer |
| Distributors and importers | Warehousing, logistics, installation | Traceability, storage conditions and recall support |
Good to know: A pharmaceutical manufacturer making only medicines normally follows GMP rather than ISO 13485. ISO 13485 becomes relevant when a company makes the device part of a combination product, supplies device components, or wants to enter the device market.
Key Requirements of ISO 13485: Clause by Clause
ISO 13485:2016 has eight clauses. Clauses 1 to 3 explain scope, references and definitions. Clauses 4 to 8 contain the requirements an auditor will check.
| Clause | Title | What it requires in practice |
| 4 | Quality management system | Define the organisation's role (manufacturer, supplier, distributor, etc.); apply a risk-based approach to QMS processes; control outsourced processes; validate software used in the QMS; maintain a quality manual and a medical device file for each device type; control documents and records |
| 5 | Management responsibility | Top management commitment; customer focus including regulatory requirements; quality policy and measurable objectives; defined responsibilities; a management representative; planned management reviews with defined inputs and outputs |
| 6 | Resource management | Competent, trained personnel with documented training effectiveness; maintained infrastructure; controlled work environment; contamination control, especially for sterile devices |
| 7 | Product realization | Planning with risk management; customer and regulatory requirements; full design and development controls (planning, inputs, outputs, review, verification, validation, transfer, changes, design file); supplier evaluation and purchasing controls; production controls; cleanliness; installation and servicing; sterile device requirements; process and sterilization validation; identification, UDI and traceability; preservation; calibration of monitoring equipment |
| 8 | Measurement, analysis and improvement | Feedback system; complaint handling; reporting to regulatory authorities; internal audits; process and product monitoring; nonconforming product control before and after delivery; data analysis; corrective and preventive action |
ISO 13485 vs ISO 9001: What's the Difference?
ISO 13485 began as an adaptation of ISO 9001, and the two share many concepts. They have since grown apart. ISO 9001 aims for customer satisfaction and continual improvement across any industry. ISO 13485 aims for safe, effective devices and regulatory compliance. The table below summarises the differences auditors and implementers meet most often.
| Aspect | ISO 9001:2026 | ISO 13485:2016 |
| Purpose | Consistent quality and enhanced customer satisfaction in any sector | Safe and effective medical devices that meet regulatory requirements |
| Structure | Harmonized Structure (clauses 4–10), shared with ISO 14001, ISO 45001 and others | Its own structure (clauses 4–8), based on ISO 9001:2008 |
| Regulatory focus | Statutory and regulatory requirements considered generally | Regulatory requirements embedded throughout the standard |
| Improvement | Continual improvement required | Maintaining QMS effectiveness; improvement is needed to keep devices safe and effective |
| Risk | Risk-based thinking; risks and opportunities | Formal product risk management through the life cycle (normally ISO 14971) plus a risk-based approach to QMS processes |
| Documentation | Documented information as the organisation needs | Quality manual, many documented procedures, and a medical device file for each device type |
| Customer satisfaction | Monitored as a key performance measure | Replaced by feedback and complaint handling linked to post-market surveillance |
| Design and development | Required where applicable | Detailed requirements including design transfer and a design and development file |
| Work environment | Environment for operation of processes | Contamination control and specific requirements for sterile devices |
| Software validation | Not specifically required | Validation of software used in the QMS, production and servicing |
| Traceability | Where required | Mandatory, with extra requirements for implantable devices; supports UDI |
| Complaints and vigilance | General customer feedback | Documented complaint handling and reporting of adverse events to regulators |
| Preventive action | Replaced by risk-based thinking | Retained as a separate requirement (clause 8.5.3) |
| Management representative | No longer required | Still required |
| Exclusions | Requirements not applicable must be justified | Clauses 6, 7 and 8 may be marked not applicable with justification; design controls may be excluded only where regulations allow |
| Record retention | As defined by the organisation | At least the lifetime of the device, and no less than two years from release |
Can you hold both? Yes. Many organisations hold ISO 9001 and ISO 13485 together, often in an integrated system. ISO 13485 certification, however, does not automatically mean ISO 9001 conformity, and the reverse is also true.
Implementation: Documentation and Records, Paper or Electronic?
ISO 13485 is documentation-heavy for a good reason: if something goes wrong with a device, the organisation must be able to show exactly how it was designed, made, tested and released. The standard does not say whether documents and records must be paper or electronic. It says they must be controlled, legible, identifiable, retrievable and protected.
What you will need to document
QMS documents: quality policy, quality objectives, quality manual (including scope and justification for non-applicable clauses), and procedures required by the standard.
Medical device file: device description, intended use, labelling, specifications, manufacturing, packaging, storage, installation and servicing procedures, and measurement procedures for each device type.
Design and development file: design plans, inputs, outputs, reviews, verification, validation, transfer and change records.
Records: training, maintenance, supplier evaluation, batch or device history, process validation, sterilization, traceability, calibration, complaints, internal audits, nonconformities, CAPA and management review.
| Aspect | Paper-based system | Electronic system (eQMS) | What ISO 13485 expects |
| Document control | Signed masters, controlled copies, distribution lists | Workflow approval, automatic versioning, controlled access | Review and approval before issue; current versions at point of use; obsolete documents prevented from use (4.2.4) |
| Records | Forms, logbooks, batch records in files | Electronic forms, database entries, audit trails | Legible, identifiable, retrievable, protected from loss or unauthorised change (4.2.5) |
| Signatures | Handwritten | Electronic signatures | Identifies who approved; FDA Part 11 applies for US submissions |
| Software | Minimal | eQMS, ERP, MES, LIMS, calibration software | Validation of QMS software before use and after changes, proportionate to risk (4.1.6) |
| Retention | Physical storage, fire and pest protection | Backup, disaster recovery, readable formats | Lifetime of the device, and at least two years from release |
| Confidential data | Locked cabinets | Access rights, encryption | Protect confidential health information (4.2.5) |
| Best suited for | Small companies and early-stage start-ups | Growing and multi-site organisations | Either approach is acceptable if controls are effective |
Consultant's tip: Many organisations run a hybrid system: electronic document control with paper records on the shop floor. This works well, provided the interface between the two is controlled and electronic systems are validated. Apply the ALCOA+ principles (attributable, legible, contemporaneous, original, accurate, complete, consistent, enduring and available) to every record.
How ISO 13485 Certification Works and How It Helps
The certification journey
Gap analysis against ISO 13485 and applicable regulations
Implementation of processes, documents, risk management and records
Training of internal auditors, process owners and management
Internal audit and management review covering the full QMS
Stage 1 audit by an accredited certification body (readiness and documentation review)
Stage 2 audit (on-site assessment of implementation and effectiveness)
Certification valid for three years, with annual surveillance audits and recertification in year three
| Who benefits | How certification helps |
| The organisation | Market access, fewer recalls and complaints, efficient processes, readiness for regulatory inspections, and a basis for CE marking, CDSCO licensing, FDA QMSR and MDSAP |
| Customers and OEMs | Confidence in suppliers, fewer supplier audits, reliable traceability |
| Patients and users | Safer, more reliable devices |
| Regulators | Evidence of a systematic QMS, supporting reliance programmes such as MDSAP |
| Employees | Clear responsibilities, better training, a culture of quality |
Choose wisely: Always choose a certification body that is accredited for ISO 13485 by a recognised accreditation body. For EU MDR, a Notified Body is required for most device classes; ISO 13485 certification alone does not grant CE marking.
Building Your Knowledge: Foundation, Internal Auditor and Lead Auditor Courses
Reading a standard is one thing. Understanding how to apply and audit it is another. Structured courses give you a guided path from awareness to audit leadership.
| ISO 13485 Foundation | ISO 13485 Internal Auditor | ISO 13485 Lead Auditor | |
| Purpose | Understand the standard, its terms and requirements | Plan, conduct, report and follow up internal and supplier audits | Lead audit teams for first, second and third-party audits |
| Who can do it | Anyone: students, freshers, production, R&D, regulatory, sales and management staff | QA/QC, production, R&D and regulatory staff; ideally 6–12 months' work experience and basic ISO 13485 knowledge | Quality professionals, consultants and aspiring certification auditors; ideally 1–2 years' relevant experience and prior ISO 13485 knowledge |
| Key content | Medical device regulations; ISO 13485 structure and clauses; links to ISO 14971; documentation | All of Foundation, plus ISO 19011 audit principles; audit planning; checklists; interviewing; evidence; nonconformity reporting; follow-up | All of Internal Auditor, plus audit programme management; leading teams; opening and closing meetings; certification process; role plays and case studies |
| Format at EAS | Self-paced online | Self-learning or live virtual | Live virtual or classroom, 5 days / 40 hours |
| Assessment | Online quiz and final exam | Exercises, quizzes and final exam | Continuous assessment and written examination |
| Certificate | EAS certificate of completion | EAS Internal Auditor certificate | Lead Auditor certificate (CQI-IRCA certified where applicable) |
| What you can do next | Contribute to QMS implementation; move on to Internal Auditor | Audit your organisation's QMS and suppliers; support certification and CAPA | Lead supplier and internal audits; apply to certification bodies as a trainee auditor; register with CQI-IRCA (subject to their criteria) |
Which ISO 13485 Course Should You Choose?
Choosing a course is a career decision, so it deserves a little thought. Use this quick guide:
| If you are… | Start with | Why |
| A student or fresher interested in medical devices | Foundation | Builds the vocabulary and regulatory context employers look for |
| Working in production, R&D, stores or sales at a device company | Foundation, then Internal Auditor | Helps you understand why procedures exist and contribute to audits |
| A QA/QC or regulatory professional | Internal Auditor | The most practical, job-ready credential for day-to-day QMS work |
| Responsible for supplier quality or vendor development | Internal Auditor, then Lead Auditor | Supplier audits are second-party audits; Lead Auditor skills add authority |
| A QA/RA manager or management representative | Lead Auditor | Complete view of audit programmes, certification and regulatory expectations |
| A consultant or aspiring certification body auditor | Lead Auditor | The recognised entry qualification for third-party auditing |
| Already an ISO 9001 auditor moving into medical devices | ISO 13485 Internal Auditor or Lead Auditor | Focuses on the device-specific differences you will be audited on |
Counsellor's advice: If you are unsure, begin with the level you can apply immediately at work. Knowledge sticks when it is used. Bundles combining all three levels are available if you want to plan your full pathway in one step.
How EAS Online Courses Help You Succeed
EAS (Empowering Assurance Systems) is a JAS-ANZ accredited certification body and a CQI-IRCA Approved Training Partner since 2016. Our platform, onlinecourse.eascertification.com, was built to give learners the depth of a classroom course with the flexibility of online study.
| Platform feature | How it helps you |
| Presentation slides for every module | Structured learning, clause by clause |
| Each clause explained with 2–3 scenarios | See how requirements work in real device companies |
| Clause notes | Fast revision before exams and audits |
| Audit perspective for each clause (Internal Auditor) | Know what evidence to look for and what questions to ask |
| In-built exercises and quizzes | Practise and check understanding as you go |
| Standard references | Learn to read and interpret the actual clause text |
| Downloadable materials | Keep templates and notes for use at work |
| Online final exam and soft-copy certificate | Certify on your schedule, from anywhere |
| Module videos (coming soon) | An extra way to learn each topic |
Explore the courses:
Career Benefits of Accredited ISO 13485 Training
The medical device sector is one of the fastest-growing areas of manufacturing, in India and worldwide. Regulators are tightening requirements, and companies need people who understand them. An accredited ISO 13485 qualification signals exactly that.
Better shortlisting: Recruiters often search for "ISO 13485" and "internal auditor" or "lead auditor" as keywords.
Recognised credibility: Accredited training follows defined learning outcomes and assessment, so employers trust it.
A move up the ladder: Audit skills move you from carrying out procedures to evaluating and improving them.
Global mobility: ISO 13485 is recognised in almost every market, from India and the Middle East to Europe and the USA.
Flexible career paths: Lead auditors can work in industry, with certification bodies, or as independent consultants.
Positions and salaries: an indicative comparison
Salaries depend on company size, city, sector, experience and negotiation. The figures below are indicative ranges drawn from job-market observations, meant to show direction rather than guarantee pay.
| Role | Typical experience | Typical qualification | Indicative annual CTC (India) |
| QA / QC Executive | 0–3 years | Degree + ISO 13485 Foundation | ₹2.5 – 5 lakh |
| QMS / Compliance Engineer | 2–5 years | ISO 13485 Internal Auditor | ₹4 – 8 lakh |
| Supplier Quality Engineer / Internal Audit Lead | 4–8 years | Internal Auditor + Lead Auditor | ₹7 – 14 lakh |
| QA / RA Manager, Management Representative | 7–12 years | Lead Auditor + ISO 14971 knowledge | ₹12 – 25 lakh |
| Head of Quality & Regulatory Affairs | 12+ years | Lead Auditor + regulatory expertise | ₹25 – 50 lakh+ |
| Certification body auditor (full-time) | 5+ years of sector experience | Lead Auditor + CB qualification | ₹8 – 20 lakh |
| Angle | Without ISO 13485 training | With accredited ISO 13485 training |
| Job search | Generic quality roles | Shortlisted for medical device, IVD and supplier-quality roles |
| Responsibilities | Following procedures, inspection | Auditing, CAPA, supplier approval, audit readiness |
| Promotion | Slower; experience alone must prove competence | Faster route to lead, supervisory and management roles |
| Pay band | Entry band for the grade | Often considered for the next band or role with audit responsibility |
| Mobility | Limited to local, general manufacturing | Recognised by multinational OEMs and overseas employers |
| Independent work | Not usually possible | Freelance internal and supplier audits, consulting and training |
| Work model / region | Indicative earnings | Notes |
| India – in-house employment | ₹4 – 25 lakh per year | Depends on role, city and company size |
| India – freelance auditor / consultant | ₹8,000 – 20,000 per audit day | Experienced lead auditors with sector expertise command the upper end |
| Middle East | Higher tax-free packages for experienced QA/RA roles | Demand driven by healthcare manufacturing and distribution |
| USA | About US$80,000 – 132,000 per year for ISO 13485 lead auditor roles | Based on job listings in 2026 |
| Europe | Strong demand linked to EU MDR and IVDR | Notified Body and QA/RA roles are particularly sought after |
25 Frequently Asked Questions about ISO 13485
What is ISO 13485 in simple words?
What is the latest version of ISO 13485?
Is ISO 13485 mandatory?
Who needs ISO 13485 certification?
What is the difference between ISO 9001 and ISO 13485?
Can a company hold both ISO 9001 and ISO 13485?
How long does ISO 13485 certification take?
How long is an ISO 13485 certificate valid?
What is a medical device file?
Does ISO 13485 require risk management?
Can records be kept electronically?
How long must records be kept?
Can design and development be excluded?
What is the difference between an internal auditor and a lead auditor?
Who can join an ISO 13485 Foundation course?
Do I need Foundation before Internal Auditor?
Can I take the Lead Auditor course directly?
Is an online ISO 13485 course valid?
What is CQI-IRCA?
Does the certificate expire?
How is the online final exam conducted at EAS?
What jobs can I get after ISO 13485 training?
Will ISO 13485 training increase my salary?
Can non-medical industries benefit from ISO 13485?
How do I get started with EAS?
Free Download: ISO 13485:2016 Internal Audit Checklist
To help you put this guide into practice, we have prepared a clause-by-clause ISO 13485:2016 internal audit checklist. It lists the key requirements to verify, the evidence to look for, and space to record your findings.
Download the ISO 13485 Internal Audit Checklist
Final Thoughts
ISO 13485 is more than a certificate on the wall. It is the discipline that keeps medical devices safe, regulators confident and patients protected. For professionals, it opens doors to one of the most stable and rewarding sectors in manufacturing.
Whether you are taking your first step or preparing to lead audits, start with the level that fits your goals. Explore ISO 13485 courses at EAS Online and build expertise the medical device industry values.
Need help choosing? Write to training@eascertification.com or WhatsApp +91 82206 66148.
This article is for general information. Always refer to the current edition of ISO 13485 and applicable regulations for your market.