ISO 13485 certification: a realistic timeline and cost breakdown

ISO 13485:2016 is the international standard for quality management systems in the medical device industry. Certification means an accredited certification body has audited a company's quality management system (QMS) against ISO 13485, the international standard for medical device quality systems, and issued a certificate confirming the system conforms.
However, the timeline to achieve certification can vary widely and depends on a number of factors. Most medical device companies can become certified in six to 18 months, depending on the state of their quality system and the availability of certification bodies.
Certification is a three-year commitment, not a one-time event
The ISO certification audit happens in two stages. Stage 1 is a readiness review centered on the documented system, checking whether the QMS is written to meet the standard and whether the company is prepared for a deeper look. It can often be conducted remotely, although IAF MD 9, the mandatory document governing how accredited bodies certify to ISO 13485, calls for Stage 1 to be performed on site where higher-risk devices are involved. Stage 2 is the full audit and it happens at the site, where the auditor samples actual records and tests whether the documented system is the one the company actually runs.
After the certificate: surveillance and recertification
Companies that clear both stages and close any major findings will be issued a certificate stating their conformity with ISO 13485:2016. It is valid for three years. The rhythm of those three years is set by ISO/IEC 17021-1, the standard governing how certification bodies operate, which calls for surveillance audits in the first and second years following the certification decision and a recertification audit in the third year before the certificate expires. The first surveillance audit has to happen within 12 months of the certification decision date.
Surveillance audits are shorter than the initial audit. IAF MD 5 puts the annual surveillance time at roughly a third of the initial certification audit, and each one has to cover internal audits and management review, complaints handling, and progress on findings from the previous audit, with adverse events, advisory notices and recalls added for medical devices specifically. Recertification in year three is calculated at about two thirds of what a fresh initial audit would take at that point rather than two thirds of the original, so a company that has grown since certification pays for the growth.
Where certification is actually required
Founders tend to assume a certificate is legally mandatory. No regulation anywhere states that a manufacturer must hold an ISO 13485 certificate. What regulations require is a quality system, and the three markets a pre-market team usually cares about handle that differently.
| Market | What is actually required |
|---|---|
| European Union | A QMS meeting Article 10 of the EU Medical Device Regulation. EN ISO 13485 is a harmonized standard, so conformity with it carries a presumption of conformity with those QMS requirements. A notified body assesses the system for all but the lowest-risk devices. |
| Canada | A valid certificate under the Medical Device Single Audit Program (MDSAP) for Class II, III and IV devices. MDSAP is an ISO 13485 audit with Canadian regulatory requirements layered on top. An ordinary ISO 13485 certificate from a regular registrar will not support a medical device licence. |
| United States | Compliance with the FDA Quality Management System Regulation, which aligned with ISO 13485 as of Feb. 2, 2026. No certificate is required. |
The shorthand "required for CE marking" persists because certification is how nearly everyone demonstrates the system, not because any regulation names it.
The credibility case
Market access is only half the reason companies certify. On the Global Medical Device Podcast, Weronika Michaluk of HTD Health described certification as a badge her company pursued partly because clients needed proof that processes were checked and approved rather than merely claimed, a story covered in more depth in our post on achieving ISO 13485 certification.
Where the months actually go
Six phases account for nearly all of the elapsed time.
1. Gap analysis: two to four weeks
An honest inventory of what already exists against what the standard requires, and the result sets expectations for everything that follows. Teams with an ISO 9001 system or a disciplined development process usually find they are further along than they assumed, while teams starting from shared drives find the opposite.
2. Building the QMS: three to 12 months
Writing the quality manual, the procedures, the forms and templates, then training people to them. The quality manual is required by Clause 4.2.2 of ISO 13485:2016, and because it is the document auditors and investors use to find everything else, it is worth writing well rather than writing long. Our guide to creating a quality manual covers what belongs in one.
3. Operating the QMS: three months minimum
This is the phase founders often leave out of the plan. Auditors sample records, and records only exist if the system has been used. Evaluating whether internal audits and management reviews are being planned and performed is a stated objective of Stage 1 under ISO/IEC 17021-1, so a company that shows up with an empty audit log has given the auditor nothing to evaluate. Certification bodies commonly expect at least three months of live operation before Stage 1, which is roughly the time it takes to complete an internal audit cycle covering the full scope of the QMS and hold at least one management review with documented inputs and outputs.
4. Stage 1 audit and remediation
Findings at this stage concern how the system is written, and fixing them is usually a matter of weeks, though a company that arrives badly prepared can lose a quarter here.
5. Stage 2 audit
The auditor follows threads end to end, tracing a complaint to its investigation to the corrective action to the effectiveness check. Major nonconformities must be corrected and verified before certification is recommended.
6. The certification decision
The audit report goes to a decision maker at the certification body who was not part of the audit team, which adds weeks rather than months.
Registrar lead time: one to three months
One item sits outside those phases and derails schedules anyway. Certification bodies book up, and popular registrars are often scheduling initial certifications several months out, which lands hardest on a company that waits until its QMS is ready before making the call. Engaging a registrar during the gap analysis phase costs little and protects the date.
What drives the cost
The certification body's fee is largely a function of audit days, and audit days are not negotiable in the way most founders assume. IAF MD 9 sets the starting point in Annex D, based on the effective number of personnel within the certification scope:
| Effective number of personnel | Stage 1 + Stage 2 audit time |
|---|---|
| 1 to 5 | 3 days |
| 6 to 10 | 4 days |
| 11 to 15 | 4.5 days |
| 16 to 25 | 5 days |
| 26 to 45 | 6 days |
| 46 to 65 | 7 days |
| 66 to 85 | 8 days |
| 86 to 125 | 10 days |
What moves the number up or down
Those numbers are a floor to adjust from, not a quote. IAF MD 9 lists factors that increase audit time, including covering more than one main technical area, device complexity, reliance on suppliers for processes critical to device function or user safety, and a poor regulatory compliance history. Reductions are allowed for organizations whose scope excludes manufacturing, capped at 20 percent of the table value, with a larger reduction of up to 50 percent available where the scope covers only distribution or transportation services. Certifying to ISO 9001 and ISO 13485 together adds a minimum of 25 percent to the calculated days.
Three levers matter for a founder budgeting this. Headcount inside scope drives the base, and effective number of personnel is not the same as the payroll number, since part-time staff convert to full-time equivalents and contractors count when they fall inside the scope. Scope breadth drives the adjustments, so a certification covering two main technical areas carries the additional audit time each one requires. And the three-year cycle means the initial audit is roughly half the story, with two surveillance audits and a recertification audit still to come.
Make certification easier with an eQMS built for medical device standards and regulations
The gap between a documented QMS and an operating one is where certification timelines are won or lost. A system that generates records as the team does its normal work arrives at Stage 2 with a story auditors can follow.
Greenlight Guru is built to be that system for medical device companies. Pre-market teams get more than 80 audit-tested procedure and form templates aligned to ISO 13485, design controls and risk records that link to each other as engineers work, and training assignments that trigger when a procedure changes so the training record exists without anyone maintaining a spreadsheet. Most teams are running on it in five to eight weeks, which puts the three-month operating clock in motion months earlier than a from-scratch build would.
To see how Greenlight Guru can help your team achieve ISO 13485 certification faster, get a free demo of our software today.
Greenlight Guru is the leading cloud-based platform purpose-built for MedTech companies. The end-to-end solution streamlines product development, quality management, and clinical data management by integrating cross-functional teams, processes, and data throughout the entire product lifecycle. Greenlight Guru’s...
Related Posts
FDA inspections under QMSR: a guide to Compliance Program 7382.850
ISO 13485: The Ultimate Guide to Medical Device QMS Requirements
Supplier management after clearance: what breaks first as your supplier list grows
Get your free eBook
Ultimate Guide to ISO 13485:2016 Quality Management System for Medical Devices




