For manufacturers & authorised representatives
ISO 13485 Consulting & Certification Support
ISO 13485:2016 is the backbone standard for medical device manufacturers and the entry ticket to most markets. We design a QMS that is genuinely yours — proportionate, risk-driven, and ready for certification and every surveillance audit that follows.
- Primary outcomeCertification-ready QMS aligned to ISO 13485:2016
- Integrated withISO 14971 risk management throughout the lifecycle
- Best fitManufacturers, OEM/ODM suppliers and authorised representatives
ISO 13485:2016 is the most widely recognised quality management standard for medical devices worldwide. In Malaysia it is the route by which manufacturers demonstrate conformity for Establishment Licensing, and internationally it is the credential that opens conversations with distributors and regulators in other markets.
What ISO 13485 Consulting covers
Deliverables are adjusted to your device class, facility type and audit timeline — this is the full menu.
-
Comprehensive QMS design
Process architecture, quality policy and objectives, documented information structure and management responsibility framework built around how your business actually runs.
-
Risk management (ISO 14971)
Risk management file, hazard identification, risk-benefit analysis, risk control verification and production feedback loops fully integrated into design and process controls.
-
Technical documentation
Design and development files, design history, essential principles conformity checklists and technical files structured for both ISO certification and MDA submission reuse.
-
Surveillance audit support
Annual surveillance and recertification preparation, evidence packs, on-site audit hosting, finding responses and root-cause-driven CAPA closure.
-
Supplier & outsourced controls
Supplier evaluation criteria, quality agreements, incoming verification strategy and monitoring of outsourced processes such as sterilisation and contract manufacture.
-
Post-market surveillance
Complaint handling, adverse event decision trees, vigilance reporting timelines, trend analysis and feedback into design and risk files.
Who this is for
- Medical device manufacturers seeking first-time ISO 13485 certification
- OEM and ODM suppliers whose customers require certified quality systems
- Authorised representatives needing a conforming QMS for licensing
- Certified organisations preparing for surveillance or recertification audits
- Companies transitioning an ISO 9001 system to meet ISO 13485 requirements
What you walk away with
- ISO 13485 Quality Manual
- Process & procedure suite
- Risk management file
- Design history file structure
- Internal audit programme
- Certification readiness report
Every engagement follows our four-stage pathway
Initial assessment → QMS & dossier preparation → CAB/MDA audit → approval and renewal.
See the full pathwayISO 13485 — frequently asked
01
We hold ISO 9001. How much extra work is ISO 13485?
ISO 9001 gives you a real head start — management commitment, document control, internal audit, corrective action and management review all carry across. The additions that matter are regulatory-requirement traceability throughout the QMS, formal risk management integrated with ISO 14971, controlled design and development files, stricter traceability and record retention, and mandatory post-market surveillance and vigilance reporting. Most ISO 9001-certified organisations need a focused gap-closure programme rather than a rebuild.
02
How long does ISO 13485 certification take?
For an organisation starting from no formal system, six to twelve months from kick-off to certification audit is a realistic planning range. You need the system documented, implemented, running long enough to generate records, and put through a full internal audit and management review cycle before a certification body will assess you. Certification bodies want evidence of a system in operation, not a system on paper.
03
Do we need ISO 13485 if we only sell in Malaysia?
If you manufacture, it is the standard route to demonstrating conformity for your Establishment Licence. If you only import or distribute, GDPMD is usually the applicable system instead. Where you do both, the scope needs deliberate structuring — we will map which system applies to which part of your operation.
Disclaimer: The content above is general information, not regulatory or legal advice. Requirements, fees and validity periods are set by the Medical Device Authority and may change. Always verify current requirements against the applicable MDA guidance documents, or engage us for a formal assessment of your specific case.
Ready to start your ISO 13485 project?
A 30-minute call with Maya establishes what applies to your business, what it will take, and how long it should realistically run.