A professional FAQ explaining how to handle quality system certificate inconsistencies (ISO 13485, MDSAP, NMPA, CE) during overseas registration of POCT products, including gap analysis, documentation preparation, common mistakes, and AIMEILI regulatory interpretation.
When quality system certificates—such as ISO 13485, MDSAP, NMPA certificates, or CE technical files—are inconsistent with target-country requirements during overseas registration of POCT products, the manufacturer must first determine whether the target country accepts the existing certificates and whether the certificate scope covers the POCT product category. Next, perform a gap analysis, supplement missing evidence, and align technical documentation and post-market obligations accordingly. Below is a practical, professional guide.
Key Summary
When registering POCT products overseas, manufacturers often encounter inconsistencies in quality system certificates—for instance, their ISO 13485, MDSAP, NMPA system certificates, or CE technical documentation may differ from target country requirements. The first step is to determine whether the target country accepts the existing certificates and whether the certificate scope covers the POCT product category. For GHWP member countries such as Saudi Arabia, Thailand, and Brazil, MDSAP or ISO 13485 is generally recognized, but additional requirements (e.g., local audits) may apply. If only an NMPA certificate is held, manufacturers must evaluate whether it satisfies fundamental QMS principles in the target country and, if needed, conduct a gap analysis or apply for MDSAP certification. For technical documentation, performance verification, risk management, and clinical evaluation must be adjusted based on intended use and local epidemiological data. Labels and instructions for use must be modified to meet local language and formatting requirements, and a local agent or authorized representative must be appointed to assume regulatory responsibility. Post-market maintenance includes adverse event reporting, change notifications, and certificate renewals; inconsistent system certificates may lead to rejection or ongoing regulatory risk. Manufacturers should plan multi-country registration early, reuse core documents, and localize differences to avoid redundant recompilation and correction costs.
Applicable Scenarios and Core Issue
POCT overseas registration often faces the challenge of inconsistent quality system certificates. This typically occurs when a manufacturer holds certificates from different regulators, such as NMPA QMS compliance, ISO 13485, MDSAP, CE MDD/MDR audit, or target-country-specific audits (e.g., ANVISA in Brazil, QMS in Japan). Inconsistencies may appear as: the certificate scope does not include POCT products, the audit standard version differs, specific clauses are missing (e.g., software validation, cold chain management), or the certificate has expired without renewal. The core question is: what are the target country’s quality system requirements, does it recognize equivalent systems, and how can the manufacturer provide sufficient evidence of continuous compliance?
A common misconception is that an ISO 13485 certificate is globally universal. In practice, ISO 13485 is a baseline, but many countries impose additional requirements—Japan requires QMS compliance with MHLW Ministerial Ordinance, Brazil requires INMETRO audits, and Saudi Arabia has SFDA-specific requirements. For POCT products, because they involve self-testing by patients, point-of-care detection, and remote data transmission, the QMS should also cover software verification, user training, and after-sales service. Inconsistent system certificates may render the registration file inadequate, leading to deficiency letters or outright rejection.
Registration Decision Logic
Step 1: Determine Regulatory Classification
Confirm whether the product falls within the target country’s medical device regulatory scope. POCT products are usually regulated as medical devices, but classification may differ. For example, the FDA may classify some POCT products as Class II exempt or non-exempt; the EU under IVDR classifies them into A, B, C, or D; GHWP members such as Thailand and Malaysia follow similar frameworks. If the product is not a medical device, no quality system certificate is needed.
Step 2: Determine Risk Class and Registration Path
High-risk POCT products (e.g., infectious pathogen detection) generally require stricter audits (e.g., MDSAP or third-party audits). Low-risk products may accept a self-declaration or manufacturer’s declaration of conformity. Selection by target country: the U.S. requires QSR 820; the EU requires ISO 13485 plus CE audit; Canada accepts MDSAP; Brazil requires INMETRO certification; Japan requires foreign manufacturer certification.
Step 3: Assess Reusability of Existing Files
If you hold an NMPA certificate, confirm whether it covers POCT design, development, production, and service. The NMPA QMS is similar to ISO 13485 in core processes (CAPA, change management, design control) but may lack some international requirements (e.g., MDR post-market surveillance). MDSAP is the most efficient certificate, covering the U.S., Canada, Brazil, Japan, and Australia, and is recognized by many GHWP members. CE technical documentation system assessments (by notified bodies) can also serve as partial evidence.
Step 4: Confirm Technical File, Performance Verification, Risk Management, Clinical Evaluation, and Labeling Requirements
System inconsistencies often appear in technical files. Ensure the risk management report complies with the latest ISO 14971; clinical evaluation is based on target-population data; performance verification considers local reference ranges and interfering substances; labels and instructions reflect local language and regulatory format. Appoint a local agent or authorized representative with clear responsibility for registration holding and post-market surveillance. Align the post-market surveillance plan—including adverse event reporting, change notification, and ongoing stability data—with the system files.
Documentation and Evidence
To address certificate inconsistencies, prepare the following:
- Copies of existing system certificates (ISO 13485, MDSAP, CE, NMPA) with a statement confirming whether the scope includes POCT products.
- Gap analysis report comparing your existing system with target-country requirements (clause differences, audit cycles, document language). For GHWP members, reference IMDRF guidelines.
- Supplementary or revised system documents, e.g., software verification records (if the POCT product includes software), user training materials, and transport stability verification.
- Risk management documentation demonstrating compliance with ISO 14971 and specific country requirements (e.g., SFDA checks on photosensitive components).
- Performance verification data: precision, accuracy, linearity, interference, and clinical sample testing per local registration guidance.
- Clinical evaluation report: literature review or clinical studies proving safety and effectiveness in the target population.
- Labels and instructions for use (IFU) samples in the local language and format, including relevant warnings (e.g., self-test risks).
- Local agent authorization and quality agreement designating the local registration agent and defining responsibilities.
- Post-market surveillance plan: complaint handling, adverse event reporting, and periodic safety and performance updates (PSUR).
All materials must provide valid evidence of QMS audits, such as internal audit records, management review minutes, CAPA examples, and supplier audits, to demonstrate ongoing system operation.
Common Mistakes
- Submitting existing certificates without addressing differences: Merely uploading ISO 13485 without explaining scope leads to incomplete registration files.
- Ignoring expired certificates: Certificates must be valid; expired certificates result in immediate registration failure.
- Mismatch between technical documents and system description: E.g., the risk management report references a different standard version than the system file, or design control documents lack change history.
- Choosing an inappropriate local agent: An agent lacking regulatory capability or submitting incorrect materials leads to errors and unclear accountability.
- Careless translation of labels/IFU: Machine translation can be inaccurate and may not comply with local formatting rules (font, units, warning placement).
- Missing post-market surveillance plan: Failing to provide specific adverse event reporting procedures and update mechanisms undermines the credibility of the quality system.
- Ignoring multi-country synergy: Preparing separate system files for each country without reusing core documents doubles time and cost.
Preparation Checklist
- Identify all target registration countries and check each country’s QMS requirements for POCT products (e.g., acceptance of MDSAP, need for local audits).
- Review existing system certificates: collect copies, confirm validity, scope, and auditing body. If gaps exist, prioritize applying for MDSAP or CB audit.
- Perform a gap analysis against each target country’s requirements, document the findings, and develop a corrective plan.
- Update system documents to address missing clauses (e.g., software validation, cold chain, traceability) and revise the quality manual accordingly.
- Prepare technical files ensuring performance verification, risk management, and clinical evaluation align with both the system files and target-country guidelines.
- Prepare labels and IFU with professional translation and legal review to ensure language accuracy and regulatory compliance.
- Appoint a local agent or authorized representative by signing a formal agreement that clearly states responsibilities (submissions, communication, post-market oversight).
- Conduct a pre-submission mock audit, either internal or third-party, following target-country requirements to identify and resolve issues early.
- For multi-country registration, use MDSAP for broad coverage and then supplement each country’s specific requirements.
AIMEILI Regulatory Interpretation and Business Impact
Manufacturers often mistakenly assume that identical certificate names are sufficient, overlooking differences in certificate version, audit scope, and validity. Many POCT companies have received deficiency letters because the certificate scope did not explicitly state “POCT,” causing months of additional review. Therefore, early in the project, perform a comprehensive investigation of target-country system requirements and create a gap analysis matrix that clearly identifies which documents can be reused (e.g., general ISO 13485 sections) and which must be localized (e.g., language, local regulatory clauses).
Close collaboration with the local agent is vital. The agent is not just a document submitter but an extension of the manufacturer’s compliance. Its understanding of local regulations directly affects registration success. Control of certificates (e.g., MDSAP annual audits) and change management (design changes, label changes) must be integrated into the manufacturer’s quality system; otherwise, certificates may be invalidated or registration revoked. For multi-country registration, adopt a “core system + local annex” model: share one set of base system documents (quality manual, CAPA procedures) across all countries, then create annexes for specific requirements (e.g., ANVISA special clauses in Brazil, J-QMS supplemental requirements in Japan). This significantly reduces redundant compilation and correction risk.
Frequently Asked Questions
Q1: I only have an NMPA system certificate, not ISO 13485. Can I register in Saudi Arabia?
The Saudi FDA (SFDA) generally requires ISO 13485 or an equivalent system certificate. An NMPA certificate can serve as part of the equivalence evidence, but you will typically need to supplement it with a gap analysis report demonstrating the degree of alignment between the NMPA system and ISO 13485 quality management system elements. Additionally, SFDA may require a local audit or a third-party audit. We recommend consulting your Saudi authorized representative first to determine the exact acceptance criteria.
Q2: Which countries does MDSAP cover? Are there additional requirements for POCT products?
MDSAP currently covers five countries: the United States, Canada, Brazil, Japan, and Australia. For POCT products, each country has special requirements—for example, the FDA’s QSR 820 provisions on software verification and labeling; Canada requires equivalency to CMDCAS; Brazil requires supplemental ANVISA audits. An MDSAP certificate indicates conformity to a unified audit model, but national regulators may still impose additional requirements. When using MDSAP, confirm that your POCT product is within the certificate scope and supplement each country’s specific technical documents.
Q3: Do POCT products require notified-body audit of the quality system for EU registration?
Under the EU IVDR, POCT products are generally Class C or D, requiring notified-body audit of the quality management system. This audit is typically combined with the CE technical documentation review. If you already hold an MDSAP certificate, some duplication in system documentation review may be reduced, but the notified body will still audit according to IVDR Annex IX. Therefore, you must ensure your system documents address IVDR-specific requirements for POCT, such as clinical performance studies, suitability evaluation, and software verification.
Source: AIMEILI Medical Device International Registration Knowledge Base. Published: July 30, 2026. This article is for preliminary understanding and project planning and does not replace official requirements from target-country regulators, testing conclusions, or legal advice.
Need a registration pathway assessment?
Send product type, intended use, target countries and existing certificates. AIMEILI can help evaluate registration pathway, documentation gaps and compliance risks.
Contact AIMEILI