ISO 13485 vs. MDSAP: Which Quality System Do You Actually Need?

Many medical-device executives ask the same question:

“Should we become ISO 13485 certified, or should we pursue MDSAP?”

The problem is that the question creates a false choice.

ISO 13485 and MDSAP are not two competing quality systems. ISO 13485 defines the foundation of the quality management system. MDSAP determines how that system is audited against the requirements of multiple regulatory authorities.

A better question is:

“Which markets are we entering, and what level of regulatory audit coverage will those markets require?”

The answer can affect certification costs, audit duration, procedures, supplier controls, post-market reporting, regulatory staffing, and even the structure of the company’s operations.

ISO 13485 Is the Foundation

ISO 13485:2016 is the internationally recognized quality-management-system standard for organizations involved in the design, manufacture, installation, and servicing of medical devices. It establishes requirements for areas such as document control, management responsibility, risk management, design controls, purchasing, production, validation, complaint handling, corrective action, and post-market activities. (ISO)

In practical terms, ISO 13485 tells a medical-device company what a compliant quality system should contain.

It creates a framework for consistently controlling the device throughout its lifecycle—from early product development and supplier selection through manufacturing, distribution, complaint investigation, and corrective action.

An ISO 13485 certificate is also widely requested by:

  • International distributors

  • Strategic partners

  • Contract manufacturers

  • Institutional investors

  • Potential acquirers

  • Notified bodies and regulatory authorities

  • Hospitals and purchasing organizations

But an ISO 13485 certificate is not, by itself, a medical-device approval. It does not automatically authorize a product for sale in the United States, Canada, Europe, Australia, Japan, Brazil, or any other jurisdiction.

It demonstrates that the company’s quality system has been independently assessed against the standard within the certificate’s defined scope.

That distinction matters.

MDSAP Is an Audit Program, Not a Separate Standard

The Medical Device Single Audit Program allows a recognized Auditing Organization to conduct one regulatory audit intended to satisfy the relevant quality-system requirements of its participating regulatory authorities.

The five full MDSAP regulatory members are:

  • Australia’s Therapeutic Goods Administration

  • Brazil’s ANVISA

  • Health Canada

  • Japan’s MHLW and PMDA

  • The U.S. Food and Drug Administration

The European Union, United Kingdom, Singapore, and the World Health Organization participate as official observers, while several additional regulators participate as affiliate members. (U.S. Food and Drug Administration)

MDSAP is based on ISO 13485, but it adds the applicable regulatory requirements of the countries included in the audit.

A company is therefore not choosing MDSAP instead of ISO 13485. It is being audited to ISO 13485 plus the relevant national requirements for the MDSAP jurisdictions within its scope.

The official MDSAP audit approach is process-based and built around risk management. It examines interconnected processes including management, measurement and improvement, design and development, production and service controls, purchasing, device registration, adverse-event reporting, and advisory notices. (U.S. Food and Drug Administration)

That makes an MDSAP audit more than a general review of whether procedures exist. Auditors examine whether the company has correctly integrated country-specific requirements into the way those procedures actually operate.

The Difference at a Glance

QuestionISO 13485 CertificationMDSAP CertificationWhat is it?Certification to an international QMS standardA multi-jurisdiction regulatory audit programCore foundationISO 13485 requirementsISO 13485 plus participating-country requirementsWho performs the audit?An accredited certification bodyAn MDSAP-recognized Auditing OrganizationPrimary purposeDemonstrate conformity to the QMS standardProvide one regulatory audit covering multiple participating authoritiesCountry-specific requirementsIncluded only when added to the audit or certification scopeBuilt directly into the applicable MDSAP audit tasksCanadaA general ISO certificate alone is insufficient for applicable device licensingRequired for manufacturers of Class II, III, and IV devicesUnited StatesFDA does not require an ISO 13485 certificateVoluntary, although FDA may use an MDSAP report in place of certain routine inspectionsAudit structureStandard-based certification auditPrescribed, process-based regulatory audit approachMarket authorizationDoes not grant product approvalDoes not replace device registration or product authorization

What Do You Need for the United States?

The U.S. answer changed significantly on February 2, 2026, when FDA’s Quality Management System Regulation became effective.

The QMSR incorporates ISO 13485:2016 by reference while retaining additional FDA-specific requirements. This brings the U.S. quality-system framework into much closer alignment with the international standard. (U.S. Food and Drug Administration)

However, alignment with ISO 13485 does not mean FDA now requires every manufacturer to hold an ISO 13485 certificate.

FDA has expressly stated that:

  • It does not require certificates of conformance to ISO 13485.

  • It does not issue ISO 13485 certificates.

  • An ISO 13485 certificate does not exempt a manufacturer from FDA inspection.

  • FDA inspections follow FDA’s QMSR inspection process rather than the MDSAP audit plan.

  • MDSAP remains voluntary for manufacturers participating in the U.S. market. (U.S. Food and Drug Administration)

For a company selling only in the United States, the legal requirement is compliance with applicable FDA regulations, including the QMSR—not necessarily third-party certification.

Nevertheless, ISO 13485 certification may still make business sense. It can strengthen investor confidence, support supplier and distributor relationships, improve acquisition readiness, and create a foundation for future international expansion.

MDSAP may be unnecessary for a U.S.-only startup unless international expansion is already part of the near-term strategy.

What Do You Need for Canada?

Canada is where the decision becomes much clearer.

Manufacturers of Class II, III, and IV medical devices must maintain an appropriate ISO 13485 quality-system certificate issued through an MDSAP-recognized Auditing Organization to support Canadian medical-device licensing. Health Canada completed its mandatory transition to MDSAP in 2019. (Canada)

A conventional ISO 13485 certificate issued outside the MDSAP framework is therefore not enough for a manufacturer seeking to license applicable devices in Canada.

Companies planning Canadian entry frequently make the mistake of obtaining standard ISO 13485 certification first, only to discover that they must later transition to an MDSAP-recognized Auditing Organization.

That can mean:

  • Another gap assessment

  • Revised procedures

  • Additional regulatory training

  • Expanded internal-audit coverage

  • New post-market reporting controls

  • A broader external audit

  • Additional certification expense

A company with Canada in its near-term commercial plan should normally build MDSAP requirements into the quality system from the beginning.

What About Australia, Brazil, and Japan?

Australia, Brazil, and Japan all participate as full MDSAP regulatory members, but their use of MDSAP is not identical.

Australia, for example, assesses MDSAP audit reports and certificates as part of the evidence supporting compliance with Australian medical-device requirements. Brazil uses MDSAP within its regulatory and good-manufacturing-practice oversight framework. (Therapeutic Goods Administration (TGA))

The important point is that MDSAP is not a universal market-access passport.

Each regulator decides how it will use the audit report and certificate. A manufacturer must still satisfy product-registration, technical-documentation, labeling, clinical, local-representation, vigilance, and other requirements applicable to each country.

MDSAP can reduce duplicative quality-system audits. It does not eliminate the remaining regulatory work.

Does MDSAP Cover Europe?

Not in the same way that it covers the five full participating regulatory authorities.

The European Union is an official MDSAP observer, not a full member of the MDSAP Regulatory Authority Council. As a result, an MDSAP audit is not a substitute for EU MDR or IVDR conformity-assessment requirements. (MDSAP)

An ISO 13485-based quality system remains highly relevant to European market access, and an MDSAP-certified system may provide a strong operational foundation. But the company must still address applicable European requirements through its notified body, authorized representative, technical documentation, post-market surveillance, vigilance, and conformity-assessment strategy.

A company targeting both Canada and Europe may therefore need an MDSAP certificate and separate EU certification or notified-body oversight.

When Standard ISO 13485 Certification May Be Enough

A standard ISO 13485 certification path may be appropriate when:

  • The company is initially focused on the United States.

  • Canada is not part of the foreseeable commercial plan.

  • The company is a component supplier rather than the legal manufacturer.

  • Customers require ISO 13485 but not MDSAP.

  • The business wants to establish a credible QMS before taking on broader international obligations.

  • Available capital and internal regulatory resources are limited.

The quality system should still be designed with expansion in mind. Adding country-specific requirements later is easier when the original system has clear process ownership, regulatory matrices, scalable procedures, strong supplier controls, and disciplined recordkeeping.

When MDSAP Is the Better Path

MDSAP is generally the stronger strategic choice when:

  • Canadian market entry is planned.

  • The company expects to commercialize in several MDSAP countries.

  • International distributors are already being evaluated.

  • Management wants one coordinated audit program rather than multiple separate regulatory audits.

  • The company has mature design, manufacturing, supplier, complaint, and post-market processes.

  • Leadership is prepared to maintain country-specific regulatory requirements continuously—not just during audit season.

MDSAP can improve audit efficiency across markets, but it also creates a broader compliance commitment. Adding a country to the certificate means accepting the applicable regulatory tasks, reporting requirements, records, and auditor scrutiny associated with that jurisdiction.

Companies should not casually include every possible market “just in case.”

The certification scope should follow a realistic commercial strategy.

The Most Common Implementation Mistakes

Treating MDSAP as an ISO Audit With a Few Extra Questions

MDSAP is structured around linked regulatory processes. Auditors may follow a complaint into adverse-event reporting, CAPA, risk management, design controls, supplier controls, and production records.

A quality system built as disconnected procedures may struggle even when every required SOP technically exists.

Adding Country Requirements Immediately Before the Audit

A regulatory procedure is not effective merely because it has been approved.

The company needs evidence that personnel were trained, regulatory decisions were made correctly, records were generated, reporting timelines were monitored, and the process was included in internal audits and management review.

Ignoring Outsourced Processes

Outsourcing design, machining, sterilization, packaging, testing, or distribution does not outsource the manufacturer’s ultimate responsibility.

The MDSAP audit approach specifically emphasizes controls over outsourced activities and suppliers performing important or validated processes. (U.S. Food and Drug Administration)

Selecting the Wrong Certification Scope

The certificate must accurately reflect the company’s devices, activities, sites, and responsibilities.

A vague or overly narrow scope may not support the intended regulatory application. An unnecessarily broad scope may create additional audit time and compliance obligations.

Assuming Certification Prevents Regulatory Inspections

Certification is not immunity.

FDA may accept MDSAP audit reports as a substitute for certain routine inspections, but it retains its regulatory authority and may still inspect a manufacturer based on risk, compliance history, product concerns, or other factors. (U.S. Food and Drug Administration)

A Smarter Way to Choose

The right decision begins with a three-to-five-year market-access plan—not with a quotation from a certification body.

Before selecting the certification path, leadership should answer:

  1. Which countries will the company realistically enter?

  2. What device classes will be marketed in those countries?

  3. Is Canada part of the plan?

  4. Is the company the legal manufacturer or a supplier?

  5. Which design and production activities are outsourced?

  6. How many locations must be included?

  7. Are complaint, vigilance, recall, and regulatory-reporting processes already operational?

  8. Can the organization support the continuing audit and recordkeeping burden?

The answers should determine the audit strategy.

Build One Quality System—Then Choose the Right Audit Path

For most medical-device companies, the best approach is not to create separate “ISO,” “FDA,” and “MDSAP” quality systems.

Build one integrated, risk-based quality system grounded in ISO 13485. Incorporate the regulatory requirements of each market through controlled procedures, jurisdictional matrices, reporting workflows, training, internal audits, and management review.

Then select the certification and audit pathway that supports the company’s actual commercialization plan.

ISO 13485 establishes the foundation. MDSAP expands the regulatory audit coverage. Your target markets determine how far you need to go.

Planning an ISO 13485 or MDSAP Certification Strategy?

Texas BioVentures helps medical-device companies design, implement, remediate, and integrate quality systems for ISO 13485, MDSAP, FDA QMSR, design controls, supplier management, post-market surveillance, and international expansion.

A well-designed certification strategy can prevent unnecessary audits, duplicate procedures, avoidable remediation, and costly delays in market entry.

This article is provided for general informational purposes and does not constitute legal, certification, or regulatory advice.

Previous
Previous

When to Bring in an Interim VP of Regulatory Affairs

Next
Next

Setting Up an eQMS: A Founder’s Checklist