Logo

Assuric

Quality Management

ISO 13485

The quality management standard for medical device software

FRAMEWORK

ISO 13485
compliance

ISO 13485 is the internationally recognised quality management system (QMS) standard for medical devices. If you are building software as a medical device, it is the backbone of your route to a UKCA or CE mark, and the QMS that notified bodies and NHS buyers will expect to see. Assuric gives you a ready-to-use electronic QMS so you can build it properly the first time and keep it audit-ready.

Request a demo

ISO 13485

Medical Device Quality Management System

70%71 tasks
Not started (16)
In progress (5)
Completed (50)

We are trusted by

  • Infix
  • Coreline
  • Suvera
  • Nursebuddy
  • Accurx
  • Cleo
  • Sanome
  • Heidi
  • Eolas
  • Tandem
  • Circle Health Group
  • Heim
  • Hippo Labs
  • Delfa
  • Guardant
  • Medcurrent
  • Surgery AI
  • Welby Innovate
  • Hesta Health
  • Kanjo
  • Rosenfield
  • VitVio
  • Megi Your Health Assistant
  • Chequp
  • Rhades
  • Joy
  • ONION AI
  • Think Divergent
  • Theta
  • Healthnix
  • Infix
  • Coreline
  • Suvera
  • Nursebuddy
  • Accurx
  • Cleo
  • Sanome
  • Heidi
  • Eolas
  • Tandem
  • Circle Health Group
  • Heim
  • Hippo Labs
  • Delfa
  • Guardant
  • Medcurrent
  • Surgery AI
  • Welby Innovate
  • Hesta Health
  • Kanjo
  • Rosenfield
  • VitVio
  • Megi Your Health Assistant
  • Chequp
  • Rhades
  • Joy
  • ONION AI
  • Think Divergent
  • Theta
  • Healthnix
Product

How Assuric can help

We can assist you with all aspects of ISO 13485, including:

Electronic QMS

Manage your controlled documents, procedures and records in one place. Version control, review workflows and locked approved versions keep you audit-ready, without the folder sprawl and lost sign-offs.

Document control and e-signatures

Approval workflows, full version history and FDA 21 CFR Part 11 compliant e-signatures. Every document has a clear owner, a review date and an audit trail.

Risk management (ISO 14971)

Run your medical device risk management alongside your QMS. Record hazards, causes and controls, and link them to your technical documentation so your risk file and your quality system stay in step.

Lean, startup-ready templates

Customisable procedures and policies written to pass audit, without the twenty-page design control documents you get elsewhere. Start from a sensible baseline and make it yours.

Map to other frameworks

Reuse controls and evidence across ISO 13485, ISO 27001, IEC 62304 and your clinical safety work. Do the work once and meet several requirements at the same time.

Migrate your existing QMS

Moving off a manual, audit-unfriendly tool? Bring your documents across with their version history and metadata intact, and pick up where you left off.

Audit management

Manage internal audits, corrective actions and supplier records in one place, so you walk into your notified body audit prepared rather than scrambling.

Expert regulatory support

Work with our team for ad-hoc advice or hands-on help building your technical file and clinical evaluation. You are not left to work out the standard on your own.

How it fits together

One quality system, several standards

ISO 13485 is the quality system the other standards plug into. Do the work once on Assuric and reuse it across all of them.

ISO 13485

Your quality management system

ISO 14971

Risk management for your device

IEC 62304

Your software development lifecycle

DCB0129

Clinical safety for the NHS

FAQS

Frequently Asked Questions

Get in touch if we haven’t answered your question below, we are always happy to help!

What is ISO 13485?

ISO 13485 is the international standard for a quality management system (QMS) specific to medical devices. It sets out how you design, build, document and maintain a device to a consistent, safe and traceable standard. For medical device software it is the foundation most regulators and buyers expect to see.

Do I need ISO 13485 for a medical device?

It is not a legal requirement in its own right, but in practice it is close to essential. A notified or approved body will expect a compliant QMS before granting a UKCA or CE mark for anything above the lowest risk class, and NHS and enterprise buyers increasingly ask for it during procurement. Even for a Class I self-certified device, an ISO 13485 QMS is the cleanest way to evidence that you build safely.

What is the difference between ISO 13485 and ISO 9001?

ISO 9001 is a general quality management standard for any organisation. ISO 13485 is built on the same foundations but tailored to medical devices, with far more emphasis on regulatory requirements, risk management, traceability and documentation. If you make a medical device, ISO 13485 is the one that matters.

If you want the background, see our guide to ISO 9001 for digital health teams.

How does ISO 13485 relate to IEC 62304 and ISO 14971?

They work together. ISO 13485 is your overall quality system, ISO 14971 is how you manage risk, and IEC 62304 covers your software development lifecycle. Assuric lets you manage all three in one place and reuse evidence across them.

How long does ISO 13485 certification take?

It depends on your product and where you are starting from, but the documentation is usually the bottleneck. Assuric shortens that part significantly with ready-to-use templates and a structured QMS, so most teams move faster than they expect. We also work with excellent notified and certification bodies, so when your documentation is ready your audit is with people we know and trust. Book a demo and we will give you a realistic timeline for your device.

testimonials

What our customers say

Compliance is complex, but our AI tools simplify it. Discover features to stay ahead of regulations.

Kelly Klifa
Heim

Kelly Klifa

CEO at Heim

Assuric has been transformative for Heim as we looked to achieve DCB0129 and DTAC compliance. The platform is easy to use, and the AI tools and automated reminders make previously dreaded compliance tasks a breeze. Paul and Matt supported us every step of the way.

Katie Baker
Tandem

Katie Baker

Director UK & Ireland at Tandem

Assuric has been fantastic in helping us quickly and safely navigate regulatory compliance in the UK. From completing Cybersecurity requirements to DSPT, DCB0129, and DTAC, the team was supportive, extremely knowledgeable, and the platform made everything quick and straightforward. A separate regulatory company we consulted at the beginning even remarked on how quickly we achieved compliance!

Maks Kozarzewski
VitVio

Maks Kozarzewski

COO at VitVio

We couldn't speak highly enough of both the Assuric team and the platform itself, which is incredibly easy to use, and with the skill and hardworking nature of the Assuric team. They've been a key component in accelerating our progress and deployments!

Maja Mazur
Healthnix

Maja Mazur

CEO at Healthnix

Assuric has been such a blessing in getting our DTAC and GDPR compliance done - completing all the documentation and deciding what needs to be done whilst running the business is very hard, but the team really helped us through that. The platform is easy to use, helps keep track of things and it even allows us to coordinate all the team training easily. Highly recommend them!

Dean Mawson
DPM

Dean Mawson

Clinical Director at DPM

Assuric streamlines the process of achieving and maintaining compliance with DCB0129 standards for digital health technologies. The user-friendly interface simplifies collaboration across multidisciplinary teams, while the built-in templates and workflows save significant time and effort during compliance projects. Assuric’s ability to centralise documentation and provide real-time visibility into project progress is particularly beneficial for Clinical Safety Officers and digital project teams, enhancing both efficiency and assurance.

Blog

Latest articles from the team

View all

Make your life easier
and talk to us to simplify compliance

Goodbye manual processes, hello automation. Let Assuric manage compliance and security, so you can focus on growth.

CTA Image