AsteronAsteron

    ISO 13485 quality management for European medical software

    Asteron builds the quality management system needed to develop, maintain and support medical device and IVD software under controlled processes. ISO 13485 connects regulatory responsibilities, product development, risk management, suppliers, complaints, corrective actions and post-market activities within one operating system. The service is designed for European healthtech manufacturers preparing medical software for the Netherlands, Germany and wider EU markets.

    View Medical Device Track pricing
    • Medical-device QMS built around the real product
    • MDR or IVDR responsibilities connected
    • Product lifecycle and risk processes integrated
    • Audit and notified-body evidence prepared

    Medical Device Track from €30,000

    What is ISO 13485?

    ISO 13485:2016 is the international quality-management-system standard for medical devices and related services. It defines how an organisation controls the processes used to design, develop, deliver and maintain products that must consistently meet customer and applicable regulatory requirements.

    For a medical software company, the QMS is not simply a collection of corporate policies. It connects product decisions, design and development records, risk management, software lifecycle activities, supplier controls, complaints, corrective actions and post-market information.

    ISO 13485 can provide a recognised structure for a manufacturer’s quality system, but it does not replace the applicable MDR or IVDR requirements. The regulatory pathway still depends on the product’s intended use, qualification, classification and conformity-assessment route.

    ISO 13485 establishes the medical-device quality system. It is not a CE mark, a product approval or automatic proof of MDR or IVDR conformity.

    Who needs ISO 13485?

    The QMS scope depends on the legal manufacturer, products, activities, locations, outsourced processes and target markets.

    Medical device software manufacturers

    Companies developing software with an intended medical purpose need controlled design, development, risk, release and post-market processes appropriate to their regulatory role and device classification.

    IVD software manufacturers

    Software used for examination of specimens, diagnostic interpretation or other IVD purposes may require an IVDR-aligned quality system and evidence appropriate to the product’s intended purpose.

    Suppliers and service providers

    Organisations providing development, infrastructure, components or other services to medical-device manufacturers may implement ISO 13485 when their role, customers or contracts require controlled medical-device quality processes.

    Healthtech companies determining their regulatory route

    Not every health application is a medical device. If qualification or classification remains unclear, the intended use and regulatory position should be assessed before building a full ISO 13485 system.

    The correct QMS scope should not be copied from another company’s certification scope. It follows the manufacturer’s own products, activities and regulatory position.

    What an ISO 13485 QMS covers

    The management system must reflect how the manufacturer actually builds and supports the product. Asteron integrates the required controls into existing product, engineering and regulatory workflows instead of creating a parallel documentation layer.

    Quality governance and regulatory responsibilities

    Define the QMS scope, quality policy, objectives, management responsibilities, regulatory roles and the processes needed to keep the system effective and current.

    Product planning and design control

    Establish how requirements, design inputs, outputs, reviews, verification, validation, transfer and product changes are planned, approved and documented.

    Risk and software lifecycle integration

    Connect ISO 14971 risk management, IEC 62304 software lifecycle activities and IEC 81001-5-1 cybersecurity work to the relevant quality processes and product evidence.

    Suppliers and outsourced processes

    Define how critical suppliers, cloud services, software components and outsourced development activities are selected, controlled, monitored and changed.

    Complaints, nonconformity and corrective action

    Create controlled processes for complaints, product issues, nonconforming outputs, root-cause analysis, corrective and preventive action and effectiveness review.

    Post-market and lifecycle feedback

    Connect information from customers, incidents, vigilance, post-market surveillance, security vulnerabilities and product performance back into risk, product and quality decisions.

    The precise processes depend on the product and regulatory pathway. A software-only manufacturer should not receive irrelevant manufacturing templates, but it must still control every ISO 13485 requirement applicable to its activities.

    Relevance for the Netherlands and Germany

    Netherlands

    Medical software manufacturers entering the Dutch market may need to demonstrate both product-regulatory controls and healthcare information-security practices. ISO 13485 addresses the medical-device quality system, while standards such as NEN 7510 address the Dutch healthcare information-security context.

    Dutch market access still depends on the applicable MDR or IVDR route, product classification and any required notified-body assessment.

    Germany

    German medical software and DiGA companies may need an ISO 13485-based quality system when the product qualifies as a medical device. The QMS can support product development, risk, complaint and post-market evidence, but it does not by itself establish DiGA eligibility or approval.

    German requirements involving BfArM, BSI or national healthcare pathways remain explicit additions to the European medical-device foundation.

    For multi-market healthtech companies, Asteron builds one European product and quality core, then connects Dutch, German and other national requirements without duplicating the entire system.

    How Asteron builds the QMS

    1. Confirm the manufacturer and product scope

      Asteron reviews the intended use, regulatory role, product qualification and classification, development model, locations, suppliers and target markets.

      If the regulatory position is unresolved, classification or specialist regulatory work is scoped separately before the QMS design is finalised.

    2. Map existing processes and evidence

      Current product, engineering, quality, security and regulatory activities are mapped against ISO 13485 and the applicable MDR or IVDR requirements.

      Useful processes and records are retained. Missing ownership, controls and evidence are documented in one implementation plan.

    3. Design the integrated operating system

      Asteron defines the required quality processes, responsibilities, records, review points and connections to ISO 14971, IEC 62304, IEC 81001-5-1 and other included requirements.

      The objective is one operable QMS rather than separate documentation projects for each standard.

    4. Implement the processes with the team

      Policies, procedures, registers and product records are introduced through practical workshops. Client actions are tracked with named owners and deadlines.

      The manufacturer’s team begins using the system before assessment so that the QMS can be supported by real operating evidence.

    5. Verify readiness

      Asteron prepares the internal audit, management review, evidence set and team for the intended certification-body or notified-body assessment.

      The external assessment and regulatory decision remain with the independent body.

    Asteron designs and implements the agreed QMS processes, prepares the included evidence structure, facilitates workshops and coordinates readiness activities.

    The manufacturer approves intended use, regulatory and product decisions; provides the product records and stakeholders; assigns process owners; implements technical actions; and remains legally accountable for the device and its regulatory obligations.

    What Asteron delivers

    The final deliverable set depends on the products, classification, regulatory route and existing documentation. A standard ISO 13485 scope may include:

    Quality-system foundation

    • Confirmed QMS and certification scope
    • Quality policy, objectives and governance
    • Regulatory roles and responsibilities
    • Controlled document and record structure
    • Management review and internal audit processes
    • Training and competence controls
    • Supplier and outsourced-process controls

    Product and lifecycle processes

    • Design and development controls
    • Risk-management integration
    • Software-lifecycle integration
    • Product and software change control
    • Complaint and nonconformity handling
    • CAPA process
    • Post-market and vigilance interfaces
    • Audit-readiness and prioritised action plan

    Product-specific technical documentation, clinical or performance evaluation and broader regulatory submissions are included only when explicitly stated in the Medical Device Track scope.

    ISO 13485 is scoped through the Medical Device Track

    Asteron does not publish a misleading standalone ISO 13485 package price because the work depends on the intended use, device or IVD classification, number of products, development model, existing documentation and required regulatory pathway.

    The approved starting point is Medical Device Track from €30,000.

    Possible scope
    • ISO 13485
    • ISO 14971
    • IEC 62304
    • IEC 81001-5-1
    • MDR or IVDR pathway support
    • Specialist coordination and co-delivery

    Larger, multi-product, higher-class or more complex engagements are scoped individually.

    Payment terms (fixed-scope)
    • 40% at signing
    • 40% when audit-ready
    • 20% after certification

    Prices exclude VAT where applicable.

    View full pricing

    External certification and notified-body assessment

    Asteron builds the QMS, prepares the evidence and team and can coordinate the agreed assessment process. Asteron cannot act as both implementer and independent certifier.

    Depending on the product and chosen route, the external review may involve:

    • An accredited ISO 13485 certification body
    • An MDR or IVDR notified body
    • A customer or specialist independent assessor
    • More than one assessment route

    External certification-body, notified-body and other assessment fees are not included in Asteron’s project price. The client contracts and pays each independent body directly.

    Notified-body fees depend on product classification, number of devices, technical-documentation scope, audit duration and assessment route. Standard ISO 27001 external-audit ranges are not applicable as notified-body medical-device fees.

    The external decision remains independent. Asteron’s contracted outcome guarantee applies to Asteron deliverables within the agreed scope: if the agreed outcome is not reached because of those deliverables, Asteron corrects the work at no additional cost within that scope.

    What remains separate

    Unless explicitly included in the Medical Device Track proposal, the following remain separate:

    • Formal legal or regulatory opinions
    • Final qualification and classification decisions
    • Clinical evaluation or performance evaluation
    • Laboratory, usability or clinical testing
    • Full product technical-documentation production
    • Engineering and source-code remediation
    • Penetration testing
    • Hosting or infrastructure implementation
    • Notified-body and certification-body fees
    • Regulatory authority fees

    Frequently asked questions

    What is ISO 13485?

    ISO 13485:2016 is the international quality-management-system standard for medical devices and related services.

    Is ISO 13485 required under MDR or IVDR?

    MDR and IVDR require manufacturers to maintain an appropriate quality management system. ISO 13485 is a recognised way to structure that system, but the complete legal requirements and conformity route must still be addressed.

    Is ISO 13485 relevant to medical device software?

    Yes. Software manufacturers use the QMS to control design, development, risk, suppliers, product changes, complaints and post-market activities.

    Does every health application need ISO 13485?

    No. The need depends on intended use, regulatory qualification, the organisation’s role and customer or market requirements.

    Is ISO 13485 certification the same as CE marking?

    No. ISO 13485 certification concerns the quality management system. CE marking depends on conformity with the complete applicable MDR or IVDR requirements and the correct assessment route.

    How does ISO 13485 relate to IEC 62304?

    ISO 13485 provides the quality-system environment. IEC 62304 defines medical-device software development and maintenance lifecycle processes within that environment.

    How does it relate to ISO 14971?

    ISO 14971 provides the medical-device risk-management process, which must connect to product development, changes, complaints and post-market information within the QMS.

    Is ISO 13485 relevant in the Netherlands and Germany?

    Yes, when the company manufactures medical devices or IVDs for those markets. National healthcare requirements may apply in addition to the shared European medical-device framework.

    How much does ISO 13485 implementation cost?

    Asteron delivers ISO 13485 through the Medical Device Track, starting from €30,000. The final scope depends on the product, classification, existing processes and related standards.

    Are notified-body fees included?

    No. Independent certification and notified-body fees are contracted and paid directly by the client to the relevant organisation.

    Official references

    • – ISO — ISO 13485:2016
    • – European Commission — MDR and IVDR
    • – European Commission — MDCG guidance for medical devices
    • – ISO — ISO 14971 medical-device risk management
    • – IEC — IEC 62304 medical-device software lifecycle
    • – IEC — IEC 81001-5-1 health-software security lifecycle

    Last reviewed: July 2026

    Asteron is not endorsed by or partnered with ISO, IEC, the European Commission, any competent authority or notified body.

    Build the quality system around the real product

    Share the intended use, product architecture, regulatory position and existing documentation. Asteron will define the QMS, lifecycle and assessment scope needed for the Medical Device Track.

    View Medical Device Track pricing