Quality Management

ISO 13485 QMS Implementation for Medical Software

A quality management system built for how software companies actually work — Agile-compatible, IEC 62304 integrated, audit-ready from day one. Not a generic manufacturing template with your logo on it.

ISO 13485:2016 IEC 62304 ISO 14971 IEC 62366 Agile Compatible EU MDR Ready
3–6
Months to certification readiness
50+
QMS documents delivered
100%
Audit success rate

Why medical software companies get QMS wrong

Most QMS implementations for software companies fail because they copy-paste frameworks designed for hardware manufacturers. The result is documentation that looks compliant but breaks during audits — because the processes don't match how software is actually built.

The most common QMS mistakes for SaMD

  • Generic templates that don't fit software — design controls written for physical prototypes, not sprint-based development. Auditors notice immediately when the QMS doesn't match real workflows.
  • Missing IEC 62304 integration — ISO 13485 design and development controls must map to your Software Development Lifecycle. Without this mapping, you can't demonstrate software process traceability.
  • No change control for software updates — every version release is technically a design change. Without a documented change control process, each update is an uncontrolled modification — a critical non-conformity.
  • Infrastructure not addressed — ISO 13485 requires controlled infrastructure. For software companies, this means your development environment, CI/CD pipeline, cloud hosting, and backup processes must all be covered.
  • Supplier controls not tailored to SaaS — your QMS must address suppliers of critical software components, cloud providers (AWS, Azure, GCP), and outsourced development. Generic supplier controls miss these.
What we do differently: We build every QMS process around your actual development workflow. Before writing a single SOP, we spend two weeks documenting how your team works — your tools, your release cadence, your team structure — and design processes that your team will actually follow.
Who needs ISO 13485 implementation
  • Medical software startups preparing for CE marking or UKCA
  • SaMD companies entering EU, UK, Singapore, or Australian markets
  • Software companies whose enterprise customers require ISO 13485 certification
  • Teams that have outgrown ad hoc processes and need structured quality management
  • Companies transitioning from MDD to EU MDR (QMS update required)
  • AI/ML medical device developers needing compliant change management

Not sure if your current processes are QMS-ready? We'll tell you in a free call.

Book free assessment →

Complete ISO 13485 QMS implementation

Every component your QMS needs — from documented processes to internal audit training — delivered in a structured 3–6 month engagement.

Core QMS Processes

  • ISO 13485 gap analysis — comprehensive assessment of your current processes against all standard requirements, with a written remediation plan and timeline
  • Quality Manual — top-level QMS document defining your quality policy, scope, and process map
  • Document & Record Control — procedures for creating, reviewing, approving, and archiving controlled documents and quality records
  • Design & Development Controls (IEC 62304 mapped) — complete SDLC procedures for planning, inputs, outputs, review, verification, validation, and transfer
  • Risk Management Integration (ISO 14971) — risk management procedures integrated into your development and change control processes
  • Management Review — procedure and templates for annual management review meetings, inputs, outputs, and action tracking
  • CAPA (Corrective & Preventive Actions) — non-conformance reporting, root cause analysis, and effectiveness verification procedures
  • Internal Audit programme — audit schedule, procedure, checklists, and report templates — plus internal auditor training

Software-Specific Processes

  • Software Development Lifecycle (IEC 62304) — class B and C software development procedures, unit/integration/system testing protocols
  • Configuration & Change Management — version control procedures, change request process, release authorisation
  • Verification & Validation — V&V planning, test protocols, traceability matrices linking requirements to tests
  • Cybersecurity Management — vulnerability management, penetration testing procedures, incident response (MDCG 2019-16 aligned)
  • Infrastructure & Environment Control — development, test, and production environment procedures; cloud infrastructure controls
  • Supplier & Purchasing Controls — supplier evaluation, approved supplier list, outsourced process controls (including critical SaaS and cloud providers)
  • Post-Market Surveillance Processes — complaint handling, PMS, vigilance reporting, PSUR procedures
  • Certification audit preparation — stage 1 and stage 2 audit preparation, mock audit, non-conformity response support

ISO 13485 that works with Agile development

You do not need to give up sprints, CI/CD, or fast releases to be ISO 13485 compliant. We've implemented QMS processes for Scrum, Kanban, and full DevOps teams.

01
Sprint-level design controls
Design inputs and outputs mapped to user stories and features. Design reviews embedded in sprint ceremonies — no separate waterfall-style design review meetings required.
02
CI/CD-compatible change control
Change control gates at release level, not commit level. Automated test evidence captured from your pipeline. Release authorisation process that fits your deployment cadence.
03
Traceability in your existing tools
Requirements-to-tests traceability maintained in Jira, GitHub Issues, or Azure DevOps — not a separate spreadsheet. We configure your existing tools to capture the evidence ISO 13485 requires.
04
Risk management in your backlog
Risk assessment integrated into feature development — not a separate annual exercise. ISO 14971 risk analysis triggered by design inputs, updated through the sprint.
05
Lightweight record-keeping
Quality records captured automatically where possible — Git commits, test run reports, review comments. Manual records kept to the minimum required by the standard.
06
Your team can actually follow it
We run workshops with your developers and product team to ensure processes are understood and workable. QMS compliance that only lives in a document folder fails at the first surveillance audit.

How ISO 13485 QMS implementation works in practice

1
Week 1–3 · Assessment
Current state gap analysis
Document your existing processes, development workflow, tools, and team structure. Assess against ISO 13485 requirements. Deliver a written gap analysis report with remediation priorities.
2
Month 1–2 · Foundation
Quality Manual and core procedures
Draft the Quality Manual, Document Control SOP, and Management Responsibilities procedures. Establish the QMS document structure and controlled document numbering system.
3
Month 2–4 · Development
All process documentation
Build all 30–50 controlled documents: SOPs, work instructions, forms, and templates. Iterative review with your team to ensure processes are workable and accurate.
4
Month 4–5 · Go-live
Implementation and team training
Roll out the QMS to your team. Train staff on new procedures. Begin generating quality records. Conduct the first management review. Embed CAPA and internal audit processes.
5
Month 5–6 · Audit Ready
Internal audit and certification preparation
Conduct the first full internal audit cycle. Address findings. Prepare for Stage 1 and Stage 2 certification body audit. Support during the certification audit itself.
Service details
StandardISO 13485:2016
Timeline3–6 months
Documents delivered30–50+ controlled docs
Delivery modeRemote (with on-site option)
PricingFixed-price project
Certification bodyYour choice — we support all major CBs
What's not included — but we can add
  • ISO 13485 certification body fees (external cost, ~€4–10K)
  • EU MDR technical documentation development
  • Post-certification surveillance audit support

Ready to build your QMS? Let's map out the project in a free call.

Start QMS setup →

ISO 13485 QMS — common questions

Does my medical software company need ISO 13485 certification? +
ISO 13485 certification is not legally mandated by EU MDR itself — however, a functioning ISO 13485-compliant QMS is required to demonstrate conformity under MDR Annex IX. In practice, all medical software companies pursuing CE marking under EU MDR, UKCA, or entry into Asian markets need a QMS that meets ISO 13485 requirements. Many enterprise customers and hospital systems also require ISO 13485 certification as a contractual condition for procurement.
How long does ISO 13485 implementation take? +
A complete ISO 13485 QMS implementation for a software company typically takes 3–6 months from kick-off to certification audit readiness. If you already have some documented processes, it may be closer to 3 months. Starting from zero typically takes 5–6 months. Add 2–4 months for the external certification body to schedule and conduct the Stage 1 and Stage 2 audits.
Can ISO 13485 work with Agile/DevOps development? +
Yes — ISO 13485 and IEC 62304 compliance does not require waterfall development. We have implemented QMS processes for teams using Scrum, Kanban, and CI/CD pipelines. The key is defining compliant design controls that fit your sprint cadence: design input/output at the feature level, change control that gates releases rather than blocking development, and traceability that maps requirements to tests in tools your team already uses (Jira, GitHub, Azure DevOps).
What is the cost of ISO 13485 certification? +
Our consulting fee for ISO 13485 QMS implementation ranges from €8,000 to €18,000 depending on company size and existing process maturity. External certification body fees (BSI, SGS, TÜV, Intertek, etc.) typically range from €4,000–€10,000 for the initial certification audit plus annual surveillance audits. We provide a fixed-price proposal after the free discovery call.
What is the difference between ISO 13485 certification and EU MDR CE marking? +
ISO 13485 is a quality management system standard — it certifies your organisation's processes, not your specific product. CE marking under EU MDR certifies a specific medical device (your software) as conforming to EU MDR requirements. To get CE marking for a Class IIa+ device, you typically need both: a certified ISO 13485 QMS (or equivalent MDR Annex IX assessment) AND product-specific technical documentation and clinical evaluation reviewed by a Notified Body. We handle both workstreams.
Do you provide ongoing support after QMS implementation? +
Yes. We offer retainer-based ongoing regulatory support to keep your QMS maintained between surveillance audits — management review support, CAPA consultation, regulatory change updates (new MDCG guidance, standard revisions), and preparation for annual surveillance audits. This ensures your QMS stays current as regulations evolve and your product changes.

What companies combine with QMS implementation

Ready to build your ISO 13485 QMS?

Book a free 30-minute call. We'll assess your current processes and tell you exactly what your QMS needs — and how long it will take to get there.

Book free consultation →
No commitment · Fixed-price projects · Agile-compatible implementations