Back to the main site

ISO 13485 vs FDA 21 CFR 820

What they share

Both standards require document control, design controls, process validation, CAPA, supplier qualification, calibration, complaint handling, post-market surveillance and management review. A supplier that complies with one will look 80% compliant with the other on the day-to-day shop floor. The audit cycle is one year. The certificate is valid for three years, with surveillance audits in years two and three.

Where they differ

What a buyer should ask the supplier

Three questions that catch most of the cases where a supplier looks certified on paper but is not: 1. Which audit body issued your certificate, and what is the scope statement? 2. When was your most recent surveillance audit, and how many major non-conformities were raised? 3. For a U.S. sale: do you also hold an MDSAP audit, or do you have a separate 21 CFR 820 audit report?

Practical differences a buyer or supplier QA needs to know.
TopicISO 13485FDA 21 CFR 820
JurisdictionInternational (adopted by EU MDR)United States (FDA)
TerminologyManagement, work environmentManagement, manufacturing, controls
Risk management linkISO 14971 (referenced)Risk-based approach (referenced, not mandatory)
Design controls scopeDesign and developmentDesign controls
Complaint handlingComplaint handlingComplaint files (separate from CAPA)
Audit bodyNotified Body (TÜV SÜD, BSI, DNV)FDA inspector or 3rd party (MDSAP)
Acceptance by FDARecognised (alternative to 820)Recognised
Acceptance by EU MDRRequired (via MDR Article 10(9))Not recognised directly
Documentation languageLocal language acceptedEnglish required

FAQ — ISO 13485 vs FDA 21 CFR 820

Is ISO 13485 accepted by the FDA?

Yes, as an alternative pathway to 21 CFR 820. The FDA runs the CDRH Acceptable Quality System audit program.

Does 21 CFR 820 satisfy EU MDR?

No. EU MDR requires ISO 13485 specifically.

How long is an ISO 13485 certificate valid?

Three years for the certification cycle, with annual surveillance audits.

What is MDSAP?

MDSAP is a single audit that satisfies the regulatory authorities of the US, Canada, Japan, Australia and Brazil.

Request our audit package