QMS gap analysis against ISO 13485, mapped to your device classification and regulatory pathway
Medical Devices
ISO 13485 Certification
Medical Devices
ISO 13485 Certification
Get Your Medical Device QMS Ready for Auditors and Regulators, Not Just the Next Milestone
ISO 13485 certification is the baseline your notified body, the FDA, and your customers expect before they'll trust a device you make. We build the quality management system underneath that certificate, so it holds up under regulatory scrutiny and doesn't slow down the product roadmap you're actually trying to ship.
The challenge
The Problem We're Usually Called In For
Most device companies don't fail an ISO 13485 audit because their product is unsafe. They fail because design controls weren't documented as they happened, a CAPA was closed without real root cause analysis, or supplier controls existed on paper but were never actually followed. None of that surfaces until a notified body auditor pulls the thread, or a regulatory submission stalls on a documentation gap.
We work with Quality Directors, Regulatory Affairs leads, VPs of Engineering, and founders at medical device companies, from pre-revenue startups preparing their first submission to established manufacturers expanding into new markets. Some of you need certification for a CE mark or FDA pathway. Some already have a QMS that's grown unwieldy. Others are inheriting a system from a previous quality lead and need it stress-tested before an auditor does it for you.
Scope
What the Certification Process Covers
Design control review, including design history files, risk management per ISO 14971, and design transfer
Document and record control review, so your QMS produces evidence instead of just paperwork
Supplier and purchasing controls, including how supplier qualification and monitoring actually get evidenced
CAPA process review, focused on root cause analysis that would satisfy an auditor, not just a closed ticket
Production and process controls, including validation, traceability, and device history records
Internal audit program setup or review, and support through your first internal audit cycle
Certification body liaison, including readiness for Stage 1 and Stage 2 audits
Engagement
How the Engagement Works
A proven 7-step consulting process from discovery to sustained process excellence.
Step 01
Discovery & Scoping
Step 02
Gap Assessment
Step 03
Build & Remediation
Step 04
Internal Audit & Management Review
Step 05
Certification Support
A short call to understand your device classification, regulatory pathway, and current QMS maturity. We agree on scope before assessment begins.
We review your existing QMS, or design one if you're starting from scratch, against ISO 13485's requirements and flag exactly what needs to change.
We work with your quality and engineering teams to close the gaps, from design control documentation to supplier qualification records, without freezing your development timeline.
We run or support the internal audit ISO 13485 requires and prepare the management review that certification depends on.
We prepare you for the certification body's audits, sit in on request, and help close findings fast so a documentation gap doesn't delay your market access.
Outcomes
Proof, Not Promises
Early-stage device startup preparing for their first CE mark submission
the gap assessment found design history files that existed but weren't traceable back to design inputs, a common Stage 2 finding. Rebuilding the traceability matrix closed the gap before the certification body ever raised it.
Client outcome
Established manufacturer expanding into a new product line
supplier controls for a new critical component supplier hadn't been formally qualified. We closed the gap within the audit window, avoiding a nonconformity that would have delayed the certification decision.
Client outcome
FAQ
Questions We Get Asked Before Signing
For a company with an existing QMS, typically four to six months. Companies building a QMS from scratch usually need six to twelve months, depending on device complexity and how many product lines are in scope.
Yes. Risk management is deeply integrated into ISO 13485's design controls, so we address both together rather than treating them as separate workstreams.
It builds a strong foundation. ISO 13485 and FDA's Quality System Regulation overlap significantly, though FDA submissions have additional requirements we can scope separately if needed.
We build the QMS around your existing development process wherever possible rather than forcing a rebuild, and we flag early if any planned milestone is at risk from a documentation gap.
Yes, and we help determine how to scope your QMS efficiently across product lines without duplicating documentation unnecessarily.
Certification is valid for three years with annual surveillance audits. We can support those ongoing or transition full ownership to your internal quality team.
Ready to Get Your QMS Audit-Ready?
A device is only as trustworthy as the system that produced it. ISO 13485 certification proves that system holds up, and we make sure it does before a notified body, a regulator, or a customer finds the gap first.
Schedule a 30-minute QMS readiness call and find out where your gaps are. When you reach out, we'll ask for your name, work email, company, role, and a brief note on your regulatory pathway. That's enough for us to come prepared.
