Skip to content
Menu

Regulation explainer

Selling Into Medical Devices: What Buyers Expect Under ISO 13485:2016

suppliers selling to buyers in regulated markets. Drafted with AI assistance from the regulation dataset and approved by a person before publication; see the editorial policy.

Guide

When a medical device company evaluates you as a supplier, ISO 13485:2016 compliance is usually one of the first things their procurement or quality team checks. It is not a formality. Buyers in this market carry their own regulatory obligations, and they need to show that everyone in their supply chain, including you, meets the same bar.

Here is what that means in practice: before a contract is signed, expect a request for documentation proving your quality management system meets [ISO 13485:2016](/regulations/iso-13485). This applies globally, regardless of where you or your buyer are based.

What buyers will ask for

Buyers typically request a specific set of documents, and having them ready before you're asked saves time and signals that you understand the market:

  • Your ISO 13485 QMS Certificate, issued by a Notified Body
  • A Technical File or Design Dossier for the product in question
  • A Risk Management File, built around ISO 14971
  • A Clinical Evaluation Report (CER)
  • A Post-Market Surveillance Plan
  • Unique Device Identification (UDI) registration details
  • If you're missing any of these, it will come up in due diligence, and it may stall or end the conversation before pricing is even discussed.

    Why this matters for suppliers

    Buyers in regulated markets are not just checking a box. They are required to demonstrate that their suppliers operate under a controlled, documented quality system, because any gap in your documentation becomes a gap in theirs. If you can't produce a current ISO 13485 QMS Certificate or a complete Risk Management File, you're asking your buyer to take on risk they are not able to absorb.

    This is particularly true for anything involving design changes, new components, or new manufacturing sites. Each of those can require updates to your Technical File or Risk Management File, and buyers will often ask when those documents were last revised.

    Getting ready before you're asked

    The suppliers who move fastest through buyer evaluations are the ones who treat these six documents as standing deliverables, not paperwork assembled at the last minute. Keep your certificate current, your Technical File aligned with what you actually manufacture, and your Post-Market Surveillance Plan active rather than archived.

    If you're preparing your documentation set for buyers in this space, Complyra's [supplier compliance](/supplier-compliance) tools can help you organize and keep track of what's current and what needs attention.

    Complyra checks product and supplier information against regulatory requirements to support procurement decisions. It does not issue certifications or guarantee legal compliance; final responsibility for compliance remains with the buyer and supplier.

    Related