This FAQ provides a comprehensive guide on the use of ISO 13485 certificates in FDA registration processes, including 510(k), PMA, and De Novo submissions. It covers applicable scenarios, registration logic, required materials, common errors, preparation checklists, regulatory interpretation, and practical business imp
How to Use ISO 13485 Certificate for FDA Registration in the United States
When applying for FDA 510(k), PMA, or De Novo registration, the ISO 13485 certificate is not a mandatory requirement by the FDA. However, it serves as critical evidence that the quality management system (QMS) meets international standards and plays a substantial role in premarket review, establishment registration, and quality system inspections. The FDA accepts ISO 13485 as one form of evidence for QMS compliance, particularly for export-oriented companies, as holding an ISO 13485 certificate can simplify the burden of demonstrating QSR 820 compliance. Companies need to submit copies of the certificate, a list of QMS documents, internal audit and management review records, and explain the consistency between the certificate scope and the product. Common risks include the certificate scope not covering the target product, non-compliance with MDSAP requirements, and system documents not updated to the latest version.
Applicable Scenarios and Core Issues
The ISO 13485 certificate is proof that an enterprise's QMS complies with international standards. In FDA registration, it is mainly applied in the following scenarios: (1) as supporting material for 510(k) or PMA submissions, demonstrating that design control and risk management processes are controlled; (2) as evidence of system compliance for FDA establishment registration and device listing, especially if the company does not have a separate QSR 820 certification; (3) as proof of system compliance for U.S. customers or importers conducting audits. Core issues include: whether the certificate covers the intended product, which certification body issued the certificate, whether MDSAP requirements are included, and how system changes during the certificate validity period impact registration. Companies should first determine product classification and registration pathway, then assess the applicability of the existing ISO 13485 certificate.
Registration Decision Logic
Determining how to use the ISO 13485 certificate in FDA registration requires the following steps: First, determine whether the product is regulated as a medical device by the FDA. Second, based on product classification (Class I/II/III), determine the registration pathway (510(k), PMA, De Novo, exempt). Third, assess the current QMS status: whether the company has obtained ISO 13485 certification, whether the certificate scope includes the product, and whether the system also meets MDSAP requirements. Fourth, if holding an ISO 13485 certificate, check the differences from QSR 820 (such as design control, CAPA, complaint handling, label control) and prepare a gap analysis report. Fifth, confirm whether a U.S. Agent needs to be designated and authorization documents submitted. Sixth, check the connection between technical documents (e.g., risk management report, clinical evaluation data, software validation report) and ISO 13485 system documents. For companies targeting multiple countries, priority should be given to ISO 13485 certificates issued by MDSAP-recognized certification bodies, as MDSAP is recognized by the FDA and reduces duplicate audits. If the certificate covers only ISO 13485 without MDSAP, separate QSR 820 compliance documents are required. The registration pathway determines the type of documents to submit: 510(k) requires a system declaration and certificate copy; PMA requires complete system documents (including design history, risk management, clinical results); exempt products only require establishment registration and device listing, but the system certificate still demonstrates production capability.
Materials and Evidence
When using an ISO 13485 certificate for FDA registration, the following core materials should be prepared: original ISO 13485 certificate and Chinese/English translation (with company seal); explanation of the certificate scope (whether it covers the intended product); QMS document list (including quality manual, procedures, work instructions); design control documents (design plan, design inputs/outputs, design review records); risk management documents (ISO 14971 report); internal audit and management review records; corrective and preventive action (CAPA) procedures and examples; gap analysis matrix against QSR 820; U.S. Agent authorization letter (if applicable); and the most recent certification body audit report. All documents should be translated into English and maintain version consistency. The evidence chain must demonstrate the connection between the ISO 13485 system and FDA requirements, such as incorporating FDA special guidelines in risk management and citing FDA-recognized consensus standards in clinical evaluation. For software medical devices, additional software verification and validation reports are required. Companies are advised to retain system operating records for at least five years and establish document control procedures to ensure the latest versions.
Common Errors
- Error 1: The ISO 13485 certificate scope does not cover the registration product, leading the FDA to require additional system audits.
- Error 2: Confusing ISO 13485 with QSR 820 requirements, directly substituting the certificate for a system declaration without submitting a gap analysis.
- Error 3: Using an expired or soon-to-expire certificate without completing renewal before registration.
- Error 4: The certificate is issued by a non-MDSAP recognized body, and no rapid remediation plan is prepared.
- Error 5: Major design changes have occurred but the system documents are not updated, causing inconsistency between the submitted certificate and technical documents.
- Error 6: No U.S. Agent appointed or agent information is inaccurate, preventing the certificate from being linked to the registration.
- Error 7: System documents (e.g., CAPA, complaint handling) are not translated into English or the translation is unprofessional.
- Error 8: When submitting multiple product registrations simultaneously, the certificate scope is not verified for each product.
Company Preparation Checklist
- Verify the ISO 13485 certificate validity, certification body, and scope.
- Create a mapping list between the certificate and products, ensuring each registered product is within the certificate scope.
- Prepare a Quality Management System (QMS) Statement, signed and stamped.
- Develop a QSR 820 gap analysis table, comparing each requirement of 21 CFR Part 820 with ISO 13485.
- Collect design history documents: design plans, design reviews, design verification and validation, design transfer records.
- Update the risk management report (ISO 14971) and add FDA special controls (if applicable).
- Organize clinical evaluation data: literature reviews, clinical study data, equivalent device references.
- Confirm that the U.S. Agent has signed the authorization letter and submitted it to the FDA.
- Check that labels and instructions for use comply with 21 CFR Part 801.
- Establish post-market surveillance procedures: complaint handling, adverse event reporting, annual reports (for PMA).
AIMEILI Regulatory Interpretation and Business Impact
From a regulatory consulting perspective, the most common misjudgment by companies is believing that ISO 13485 directly equates to FDA QSR 820, thus neglecting gap analysis and supplemental documentation. Practical experience shows that FDA auditors have very high expectations for system document consistency, especially design control and CAPA records. Companies should initiate system gap assessment at least six months before registration. Priority tasks in the early stages include: confirming that the certificate scope covers the target product, selecting an MDSAP-recognized certification body, and preparing English versions of system documents. Most system documents can be reused, but verification and validation records need adjustments for U.S. market requirements, e.g., clinical evaluation should include U.S. population data. A U.S. Agent is mandatory and must have a physical address; companies often mistakenly believe the agent can be virtual or use mail forwarding. It is recommended to assign certificate control to a dedicated person, start renewal audits 12 months in advance, and avoid registration application rejections due to certificate expiration. For multi-country registration, establish a unified system document library based on ISO 13485 + MDSAP to reduce the risk of supplemental submissions per country.
In practice, companies should break down this issue into five tasks: regulatory judgment, material preparation, evidence reuse, localization conversion, and post-market maintenance, rather than having only one department temporarily compile documents. This allows earlier identification of gaps and ensures a consistent understanding of target country requirements across sales, R&D, quality, and regulatory teams.
Common Questions
Q: Can an expired ISO 13485 certificate be used for an FDA application?
A: No. The FDA does not accept expired certificates as proof of a quality system. Companies should initiate renewal at least six months before expiration and ensure the renewal audit covers all registered products. If the certificate has expired, a new certification must be obtained and a valid certificate submitted.
Q: Can a small company without an ISO 13485 certificate apply directly to the FDA?
A: Yes, but it must demonstrate that the quality system complies with QSR 820. Small companies can establish a simplified system (e.g., based on GB/T 19001) but must pay special attention to design control and CAPA. Lack of a system certificate increases the risk of FDA on-site inspections; it is recommended to at least obtain ISO 13485 certification to reduce barriers.
Q: What is the difference between an ISO 13485 certificate and an MDSAP certificate for FDA registration?
A: An ISO 13485 certificate only demonstrates compliance with the international QMS standard. An MDSAP certificate shows that the system simultaneously meets the requirements of FDA QSR 820, Canada, Brazil, Japan, and Australia. Holding an MDSAP certificate directly satisfies FDA system requirements without additional gap analysis, and audit frequency is reduced to once every two years. Export-oriented companies targeting multiple countries are advised to prioritize the MDSAP certificate.
Execution Recommendations: When handling the question “How to use ISO 13485 certificate for FDA registration,” companies should place regulatory judgment, evidence, applicant identity, market entry timing, and post-market responsibilities on the same project timeline. This prevents regulatory departments from focusing only on documents, sales only on launch dates, and quality departments from being unaware of target market requirements, which can lead to disconnects between registration pathways and material preparation. If the target market is a GHWP member state or highly aligned with international regulations (IMDRF, ISO 13485, ISO 14971, UDI), companies should first identify reusable materials, then decide which content requires localization translation, additional declarations, retesting, or signature by a local agent. This sequence is more stable and cost-controllable than simply collecting documents per country. At the project execution level, it is advisable to retain at least: product classification basis, technical document version, label/IFU version, test report coverage models, clinical evidence source, local agent communication records, and supplement opinion records. These records directly affect the company's ability to quickly explain the product's compliance status during subsequent renewal, change, unannounced audit, or post-market event handling.
Need a registration pathway assessment?
Send product type, intended use, target countries and existing certificates. AIMEILI can help evaluate registration pathway, documentation gaps and compliance risks.
Contact AIMEILI