ISO 13485 certification of the quality management system for medical devices
We certify quality management systems to ISO 13485 in Bulgaria under the established certification procedures of CERTIND S.A. The standard is for organizations across the medical device chain — manufacturers, suppliers of components and services, importers and distributors. The audit is conducted in Bulgarian, and you will receive a tailored quote within two hours.
- Certification bodyCERTIND S.A.
- Who it is formanufacturers and suppliers
- Quotewithin 2 hours during business hours
The standard at a glance
What is ISO 13485?
ISO 13485 is the international standard setting out the requirements for a quality management system for medical devices. Unlike the general quality standard, everything here serves one goal: the device must be safe and meet regulatory requirements throughout its entire life cycle.
The current edition is ISO 13485:2016. The standard applies to organizations along the entire chain — design and development, production, storage and distribution, installation and servicing — as well as to suppliers of components, materials and services for these activities.
The main difference from ISO 9001 lies in the emphasis. ISO 9001 aims for customer satisfaction and continual improvement. ISO 13485 requires, above all, maintaining effectiveness — documented processes, traceability, risk management throughout the life cycle and records that stand up to scrutiny years later.
The standard is used as the basis of the quality system that the European medical device regulations expect from manufacturers. It is important to know, however, that ISO 13485 certification is not a conformity assessment under the regulations and does not replace a certificate from a notified body. It demonstrates that your quality management system meets the standard.
Who ISO 13485 is for
- Device manufacturers From consumables and instruments to equipment and software as a medical device.
- Suppliers in the chain Components, materials, sterilization, packaging and other services for manufacturers.
- Importers and distributors Storage, transport under controlled conditions, batch traceability.
- Installation and servicing Organizations that install and maintain medical equipment.
ISO 13485 · the documentation
What the standard requires on paper
For medical devices, documented information is not bureaucracy but evidence. Here is how it is structured — from the general to the specific.
The top level: what the system covers, which processes make it up and how they relate to each other.
- Scope of the system and justification for excluded requirements
- Description of the processes and their interaction
- References to the procedures
- The organization’s role — manufacturer, distributor, service provider
The procedures the standard explicitly requires, and those without which your operations cannot be managed.
- Control of documents and records
- Internal audit, nonconforming product, corrective and preventive actions
- Risk management throughout the life cycle
- Feedback, complaints and incident reporting
The level at which a requirement becomes action: parameters, steps, checks and acceptance criteria.
- Device and production process specifications
- Requirements for cleanliness, contamination control and sterility, where applicable
- Validation of processes whose output cannot be verified
- Installation and servicing requirements
The bottom level matters most for the audit: it shows what actually happened to a specific batch.
- Medical device file with all related information
- Production, inspection and testing records by batch
- Traceability to components and to the recipient, where required
- Retention periods aligned with the lifetime of the device
The auditor works backwards from the device: selects a batch and traces the records back to the raw material and forward to the customer. A missing record is a nonconformity, however well the system is described.
ISO 13485 · the differences
What the auditor looks for in addition
If you have an ISO 9001 system, the foundation is in place. These are the requirements that ISO 13485 adds on top of it, and where nonconformities arise most often.
- Risk management throughout the device life cycle, not only during development
- Design and development: inputs and outputs, review, verification, validation
- Design transfer to production with confirmed suitability
- Device file — a single place where everything about the device can be seen
Risk management is the common thread: it explains why the processes look exactly the way they do.
- Requirements for the work environment, cleanliness and contamination control
- Validation of processes whose output cannot be verified by subsequent inspection
- Records of the parameters of each sterilization cycle, where applicable
- Traceability to component and to recipient, depending on the type of device
Validation and traceability are the two areas where the audit spends the most time.
- Collecting and analysing market feedback as an input for improvement
- A documented procedure for handling and evaluating complaints
- A procedure for notifying the competent authorities where regulatory requirements call for it
- Corrective actions, including recalls or advisory notices where necessary
The standard allows requirements that do not apply to your activity to be excluded — the exclusion is justified in writing.
How ISO 13485 certification works
The process is the same for every organization and follows ISO/IEC 17021-1, the international standard for certification bodies. Only the audit duration differs — it depends on the number of employees, the sites and the complexity of the activity.
The process in detail- 01 Enquiry and quoteYou describe your activity, number of employees and sites. You receive a quote with the scope, audit duration and price.within 2 hours during business hours
- 02 Contract and audit planOnce the contract is signed, we agree the dates, the scope and the audit team.dates that suit you
- 03 Stage 1 — readiness reviewThe auditor reviews the scope, the manual, the procedures, the device file and risk management, and assesses whether the system is ready.documents, scope, readiness
- 04 Stage 2 — on-site auditThe audit checks production on site — validated processes, environmental control, batch records, traceability in both directions and complaint handling.in Bulgarian, at your premises
- 05 Corrective actionsIf nonconformities are found, you are given a deadline to correct them and submit evidence.only if needed
- 06 Decision and certificateAn independent certification decision and issue of the certificate by CERTIND S.A.under CERTIND S.A. procedures
What the price of ISO 13485 certification depends on
The price of the certificate is not fixed, because it is calculated from several factors, including the audit days your organization requires, which are determined under the mandatory document IAF MD 5.
ISO certification pricingComplexity and sector
The type of device and its risk class, and whether sterile processes and design are involved.
Number of sites
Production sites, warehouses and service bases in scope.
Number of employees
Full-time and part-time staff.
Number and type of standards
When the system is integrated with ISO 9001, the audit is usually shorter.
A consultant to implement the system is a separate cost. A certification body cannot provide consultancy to the organizations it certifies — this is an impartiality requirement under ISO/IEC 17021-1.
Describe your activity, number of employees and sites — within two hours during business hours you will receive a quote with scope and price.
Exact quote within 2 hoursQuestions and answers
Frequently asked questions about ISO 13485
Answers to the questions our clients ask most often before certification.
Does ISO 13485 replace the requirements of the European regulations?
No. ISO 13485 certification demonstrates that your quality management system meets the standard. Conformity assessment under the European medical device regulations is carried out by a notified body and is a separate procedure.
Is ISO 13485 certification accredited?
No. The scheme is outside the scope of CERTIND S.A.’s RENAR accreditation. The certificate is issued under the body’s established procedures after an actual audit. The accredited quality standard is ISO 9001.
How does it differ from ISO 9001?
ISO 9001 is about customer satisfaction and continual improvement. ISO 13485 requires maintaining effectiveness and compliance with regulatory requirements — with more documented procedures, traceability, risk management and records with long retention periods.
Can the two standards be combined?
Yes. Many organizations maintain a common system and are certified to both standards — the common part is audited once, and the specific requirements of ISO 13485 are checked separately.
How long is the certificate valid?
Three years. Surveillance audits are carried out in the second and third years, and after the end of the cycle comes recertification, which keeps the certificate valid.
Standards that combine with ISO 13485
The standards that go hand in hand with a medical device quality system.
All standards
ISO 9001Quality managementThe accredited foundation — the general quality system on which ISO 13485 builds.To the standard
ISO/IEC 27001Information securityFor manufacturers of software as a medical device and for protecting test data.To the standard
ISO 14001Environmental managementFor production sites — waste, chemicals and permits.To the standard
ISO 13485 · Free quote
ISO 13485 certification
Describe your activity, the organization’s locations, number of employees and types of standards — within two hours during business hours you will receive a quote with the scope, audit duration and an all-inclusive price.
- Certification bodyCERTIND S.A.
- Auditin Bulgarian, at your premises
- Quotewithin 2 hours during business hours