Your ISO 13485 Certificate Does Not Prove MDR 2017 Compliance— Here Is What Does

What Notified Bodies Actually Check When They Say They Are Auditing ISO 13485 — The MDR 2017 Reality

By Ankur Khare — Biomedical Engineer | Regulatory Affairs Specialist | Founder, MedReg Intel


There is a conversation that happens in almost every ISO 13485 certification project in India.

The consultant tells the manufacturer — get your ISO 13485 certificate and your MDR 2017 compliance is sorted.

The manufacturer spends six to twelve months and significant budget getting certified.

Then the Notified Body audit happens. And three major non-compliances are raised — none of which were covered by the ISO 13485 certification process.

This happens because ISO 13485 and MDR 2017 Fifth Schedule compliance are not the same thing. They are substantially aligned. But they are not identical. And the gaps between them are exactly where manufacturers get caught.

This article goes deeper than the question of whether ISO 13485 is mandatory. It tells you precisely where ISO 13485 ends and MDR 2017 begins — and what that means for your audit preparation.


The Previous Article — A Quick Recap

In an earlier article on MedReg Intel, I established that MDR 2017 does not mandate ISO 13485 certification explicitly. What it mandates is compliance with the Fifth Schedule — the QMS requirements embedded directly in the Indian regulatory framework.

The distinction matters for commercial and legal reasons. But it raises a deeper question.

If ISO 13485 and the Fifth Schedule are substantially aligned — where exactly do they diverge? And which divergences matter in practice?

Those are the questions this article answers.


What ISO 13485:2016 Actually Covers

ISO 13485:2016 is a quality management system standard published by the International Organisation for Standardisation. It specifies requirements for organisations involved in the design, production, installation, and servicing of medical devices and related services.

Its core structure follows eight clauses:

Clause 4 — Quality Management System. General requirements and documentation requirements including quality manual, medical device file, and control of documents and records.

Clause 5 — Management Responsibility. Management commitment, customer focus, quality policy, planning, responsibility and authority, and management review.

Clause 6 — Resource Management. Provision of resources, human resources, infrastructure, and work environment and contamination control.

Clause 7 — Product Realisation. Planning, customer-related processes, design and development, purchasing, production and service provision, and control of monitoring and measuring equipment.

Clause 8 — Measurement, Analysis and Improvement. Monitoring and measurement, control of nonconforming product, analysis of data, and improvement including corrective and preventive action.

ISO 13485 is an internationally recognised framework. Certification against it is issued by accredited certification bodies — third parties that are independent of the manufacturer and the regulatory authority.


What the Fifth Schedule of MDR 2017 Actually Covers

The Fifth Schedule of MDR 2017 is titled Quality Management System for Medical Devices and In Vitro Diagnostic Medical Devices.

Its structure mirrors ISO 13485 closely. The same functional areas appear — general requirements, management responsibility, resource management, product realisation, and measurement and improvement.

The language in many sections is directly drawn from ISO 13485:2016.

But the Fifth Schedule is not ISO 13485. It is a Schedule embedded in an Indian statutory instrument — the Medical Devices Rules 2017 notified under the Drugs and Cosmetics Act 1940. This creates three important distinctions.


Three Critical Distinctions Between ISO 13485 and the Fifth Schedule

Distinction One — Legal Standing

ISO 13485 is a voluntary international standard. Compliance with it is not a legal obligation in any jurisdiction unless a specific law or regulation references it as mandatory.

The Fifth Schedule is part of Indian law. Non-compliance with the Fifth Schedule is non-compliance with MDR 2017 — a statutory instrument. The consequences are not a failed audit and a corrective action plan. They are licence refusal, suspension, or cancellation.

A manufacturer who has ISO 13485 certification but whose QMS does not actually meet Fifth Schedule requirements is compliant with an international standard and non-compliant with Indian law. These are not the same thing.

Distinction Two — Applicability Scope

ISO 13485 applies to any organisation involved in the medical device lifecycle — manufacturers, importers, distributors, suppliers of components and services.

The Fifth Schedule under MDR 2017 applies specifically to manufacturers of finished devices, in vitro diagnostic medical devices, mechanical contraceptives, surgical dressings, surgical bandages, surgical staplers, surgical sutures and ligatures, and blood collection bags — as defined in Section 2 of the Fifth Schedule.

The scope is more defined under Indian law than under the international standard. This affects which entities are required to comply and to what extent.

Distinction Three — The Indian Regulatory Context Requirements

The Fifth Schedule references Indian regulatory instruments throughout — the Medical Devices Rules 2017, the Drugs and Cosmetics Act, CDSCO notifications, and the classification system under the First Schedule.

ISO 13485 normatively references ISO 14971 for risk management. Product-specific standards such as IEC 62304 for software lifecycle and IEC 60601 for electrical safety are complementary requirements depending on device type — but they are not embedded in ISO 13485 itself.

A manufacturer whose QMS is built entirely on ISO 13485 and its referenced international standards — without specific reference to Indian regulatory requirements — has a QMS that is internationally compliant but potentially incomplete under Indian law.

The practical consequence: your QMS procedures must reference MDR 2017 provisions directly. Your corrective action procedures must cite the applicable Indian regulatory requirements. Your management review agenda must address Indian regulatory compliance specifically — not only international standard compliance.


Where ISO 13485 Certification Falls Short in an MDR 2017 Context

Based on the Third Schedule audit requirements and the Fifth Schedule QMS requirements, here are the specific areas where ISO 13485 certification alone is insufficient for MDR 2017 compliance.

Area One — Fourth Schedule Document Requirements

An ISO 13485 audit does not verify your Fourth Schedule documentation. The Fourth Schedule specifies the exact documents required for manufacturing licence applications in India — device master file, plant master file, substantial equivalence documentation, essential principles checklist, and others.

Your ISO 13485 certificate says nothing about whether your Fourth Schedule documents are complete, correctly structured, or CDSCO-compliant. A Notified Body conducting your MDR 2017 audit will check Fourth Schedule documents explicitly. This is outside the scope of ISO 13485 certification.

Area Two — Essential Principles Conformity

MDR 2017 requires manufacturers to demonstrate conformity with essential principles of safety and performance as laid down by the Central Government. These essential principles are India-specific regulatory requirements.

ISO 13485 does not require demonstration of essential principles conformity. It requires a quality management system that supports regulatory compliance — but the specific regulatory requirements are defined by the applicable jurisdiction, not by the standard itself.

Your essential principles checklist — a specific document required in your Fourth Schedule technical file — is outside the scope of what ISO 13485 certification verifies.

Area Three — Post-Approval Change Management Under the Sixth Schedule

MDR 2017's Sixth Schedule classifies changes to licensed devices and manufacturing processes into major changes requiring prior CLA or SLA approval and minor changes requiring intimation within specified timelines.

ISO 13485 requires a change control procedure. But it does not define which changes are major and which are minor under Indian law. It does not specify the 45-day intimation timeline. It does not reference Rule 26(iii) deemed approval provisions.

A manufacturer whose change control procedure is built only on ISO 13485 requirements — without specific reference to the Sixth Schedule categories and timelines — has a change control system that is ISO 13485 compliant but potentially MDR 2017 non-compliant.

Area Four — Materiovigilance and Adverse Event Reporting

MDR 2017 specifies adverse event reporting requirements — including the 15-day reporting timeline for serious adverse events under Rule 26(ii) and the broader Materiovigilance reporting requirements under Rule 76. These are India-specific requirements with specific timelines and reporting authorities.

ISO 13485 requires post-market surveillance and complaint handling procedures. But the specific timelines, reporting formats, and regulatory authorities are defined by national law — not by the standard.

Your MDR 2017 compliance requires that your vigilance procedures reference Rule 76 timelines, CDSCO reporting requirements, and the Materiovigilance Programme of India specifically.


What a Complete MDR 2017 QMS Looks Like

A QMS that genuinely meets MDR 2017 Fifth Schedule requirements — and will withstand a Notified Body audit — has the following characteristics.

It is built on ISO 13485:2016 as the structural foundation.

It references the Fifth Schedule provisions directly in its quality manual and procedures — not only ISO 13485 clause numbers.

It includes procedures specifically addressing Fourth Schedule documentation requirements — with document templates, review checklists, and version control aligned to CDSCO submission requirements.

It includes an essential principles compliance procedure — mapping each essential principle to the technical documentation that demonstrates conformity.

Its change control procedure references the Sixth Schedule major versus minor change classification explicitly — with defined timelines for CLA approval applications and intimation submissions.

Its vigilance and complaint handling procedures reference Rule 76 timelines and CDSCO reporting requirements specifically.

Its management review agenda includes a standing item on Indian regulatory compliance status — not only international standard compliance.


The Audit Conversation That Determines Your Licence

When a Notified Body auditor sits across from you for your MDR 2017 audit — whether post-grant for Class A or pre-grant for Class B — the conversation that matters is not whether you have an ISO 13485 certificate.

The conversation that matters is whether your QMS actually addresses the six mandatory audit items in the Third Schedule. Whether your Fourth Schedule documents are complete and cross-referenced. Whether your essential principles checklist maps to your technical file. Whether your change control procedure references the Sixth Schedule correctly.

ISO 13485 certification is evidence of QMS competence. It is not evidence of MDR 2017 compliance.

The manufacturers who walk into NB audits with ISO 13485 certificates and MDR 2017-integrated QMS documentation walk out with licences.

The manufacturers who walk in with ISO 13485 certificates and QMS documentation that only references international standards walk out with non-conformance reports.

Know the difference before your auditor does.


The "ISO 13485 Doesn't Fit India" Argument — And Why It Misses the Point

A recurring argument in Indian MedTech circles is that ISO 13485 is a Western standard designed for Western manufacturing conditions — and that India should develop its own QMS standard that accounts for Indian climate conditions, Indian genetic diversity, and Indian healthcare infrastructure realities.

This argument deserves a direct response because it affects how manufacturers approach their QMS investment.

ISO 13485 is a quality management system standard. It governs how you document, control, review, and improve your manufacturing and design processes. It does not specify what temperature your device must withstand, what patient population data your clinical evidence must cover, or what environmental conditions your device must be validated against.

Those questions are answered by product performance standards — the BIS standards under Rule 7, the IEC 60601 series for electrical safety, the ISO 11135 series for sterilization. These are the standards where India's specific climate conditions, infrastructure realities, and population characteristics are genuinely relevant.

Calling for a replacement of ISO 13485 conflates two separate questions — how should quality be managed, and what should the product do. ISO 13485 answers the first. Product standards answer the second.

The genuine infrastructure gap in India is not in the QMS standard. It is in the ecosystem that supports its implementation — the number of qualified Notified Bodies, the availability of NABL-accredited laboratories certified to test against BIS standards, and the published guidance that translates international QMS principles into India-specific operational requirements.

MDR 2017's Fifth Schedule is already India's adaptation of ISO 13485 — not a wholesale adoption of the international standard but a statutory instrument that draws from it while embedding Indian regulatory requirements directly.

The answer to India's QMS implementation challenges is better infrastructure supporting the existing framework. Not a new standard that would require years to develop, internationally validate, and build an accreditation ecosystem around — while manufacturers wait.


The One-Sentence Summary

ISO 13485 gives you the structure. MDR 2017 Fifth Schedule gives you the legal obligation. A compliant QMS requires both — explicitly integrated, not assumed to be equivalent.


MedReg Intel tracks regulatory developments, compliance strategy, and policy analysis relevant to India's medical device sector at medregintel.com

Ankur Khare is a Biomedical Engineer and Regulatory Affairs Specialist and the founder of MedReg Intel. This article is for informational purposes and does not constitute formal regulatory or legal advice.

Comments

Popular posts from this blog

The ₹50 Lakh Mistake Killing Indian MedTech Startups — And How to Avoid It

A Practical Roadmap for Developing Medical Devices in India

Make in India for Medical Devices — The Reality No One Is Talking About