Healthcare and medical device organizations must comply with stringent quality and safety standards. ISO 13485 is the primary standard for medical device quality management, while ISO 15189 addresses medical laboratory requirements.

These standards ensure patient safety, product effectiveness, and regulatory compliance with bodies like FDA, MDR, and other regional regulators.

Key Standards for Healthcare & Medical Devices

Benefits

  • Patient safety enhanced
  • Regulatory compliance globally
  • Market access worldwide
  • Risk management improved
  • Product quality assured
  • Liability protection

Industry Challenges

  • Strict regulatory requirements
  • Post-market surveillance
  • Clinical evidence needs
  • Recall management
  • Biocompatibility testing

All Standards for Healthcare & Medical Devices

ISO 9000:2026 Quality Management - Fundamentals and Vocabulary The reference document for quality management concepts, principles and terminology. ISO 9000:2026 is the fifth edition and replaces ISO 9000:2015; it supplies the definitions that ISO 9001 and the rest of the ISO/TC 176 portfolio rely on. Management Systems ISO 9001:2026 Quality Management Systems The requirements standard for a quality management system, and the most widely used certification standard in the world. ISO 9001:2026, the sixth edition, was published on 16 September 2026 and replaces ISO 9001:2015; certified organizations have a transition period to move to it. Management Systems Certifiable ISO 9004:2018 Quality Management - Guidance for Sustained Success Guidance for organizations that want to go beyond conformity with ISO 9001 and improve their overall ability to achieve sustained success, including a self-assessment tool for judging maturity. Management Systems ISO 10001:2018 Customer Satisfaction - Codes of Conduct Guidance on planning, designing, implementing and improving customer satisfaction codes of conduct — the promises an organization makes to its customers about how it will behave — as the first line of defence against complaints and disputes. Management Systems ISO 10002:2018 Complaints Handling in Organizations Guidance on handling complaints about products and services inside an organization — from receipt and acknowledgement through investigation, resolution and follow-up, to using complaint data for improvement. Management Systems ISO 10003:2018 External Dispute Resolution for Customer Satisfaction Guidance on resolving product- and service-related complaints that an organization has been unable to settle internally, by using dispute resolution providers external to the organization. Management Systems ISO 10004:2018 Monitoring and Measuring Customer Satisfaction Guidance on defining and implementing processes to monitor and measure customer satisfaction, covering what to measure, how to gather direct and indirect data, and how to analyse and act on the results. Management Systems ISO 45001:2018 Occupational Health and Safety Management Systems The international standard for occupational health and safety management systems, replacing OHSAS 18001. Current edition is ISO 45001:2018 with Amendment 1:2024 (climate action); a revision is at Draft International Standard stage. Management Systems Certifiable ISO 27000:2018 Information Security Management Systems - Overview and Vocabulary The overview and vocabulary document for the ISO/IEC 27000 family. It explains how the ISMS standards fit together and defines the terms they use, and is available free of charge from ISO. Management Systems ISO 31010:2019 Risk Assessment Techniques A catalogue of risk assessment techniques with guidance on selecting and applying them. The second edition, IEC 31010:2019, replaces the 2009 edition and complements ISO 31000. Management Systems ISO 27001:2022 Information Security Management Systems The certifiable requirements standard for an information security management system. Current edition is ISO/IEC 27001:2022 with Amendment 1:2024 (climate action); Annex A lists 93 controls organised into four themes. Management Systems Certifiable ISO 27002:2022 Information Security, Cybersecurity and Privacy Protection - Security Controls The implementation guidance companion to ISO/IEC 27001. It describes 93 information security controls in four themes, each with purpose, guidance and attributes, and is not itself a certifiable standard. Management Systems ISO 17025:2017 Testing and Calibration Laboratories - Competence Requirements The international standard against which testing and calibration laboratories are accredited. The third edition, ISO/IEC 17025:2017, was reviewed and confirmed in 2023 and remains current. Industry-Specific Certifiable ISO 13485:2016 Medical Devices - Quality Management Systems The quality management system standard for organizations involved in the medical device life cycle, written for regulatory purposes. ISO 13485:2016 is the third edition; a systematic review confirmed it and it remains current. Management Systems Certifiable ISO 14971:2019 Medical Device Risk Management The risk management standard for medical devices, specifying the process manufacturers use to identify hazards, estimate and evaluate risks, control them and monitor the effectiveness of controls across the device life cycle. Third edition, published 2019. Industry-Specific ISO 10993:2025 Biological Evaluation of Medical Devices The multi-part series governing biological evaluation (biocompatibility) of medical devices. Part 1, the framework document, was revised in 2025 as its sixth edition, reorganised to align with ISO 14971 and replacing ISO 10993-1:2018. Industry-Specific ISO 62304:2015 Medical Device Software - Software Life Cycle Processes The software life cycle standard for medical device software. It defines development, maintenance, risk management, configuration management and problem resolution processes, scaled by software safety class A, B or C. A second edition is in development. Industry-Specific ISO 15189:2022 Medical Laboratories - Quality and Competence Requirements The accreditation standard for medical laboratories. The fourth edition, ISO 15189:2022, replaces ISO 15189:2012 and also replaces ISO 22870:2016, bringing point-of-care testing into the main standard and aligning its structure with ISO/IEC 17025:2017. Industry-Specific Certifiable ISO 62366:2020 Medical Devices - Usability Engineering / Human Factors The usability engineering standard for medical devices. It specifies a process for analysing, specifying, developing and evaluating the usability of a device as it relates to safety, addressing use errors and use-related hazards. Current text is the 2015 edition with Amendment 1:2020. Industry-Specific ISO 22301:2019 Business Continuity Management Systems The certifiable business continuity management system standard. Current edition is ISO 22301:2019 with Amendment 1:2024 (climate action); a revision is in preparation at committee draft stage. Management Systems Certifiable ISO 37301:2021 Compliance Management Systems Certifiable requirements for a compliance management system, replacing the guidance-only ISO 19600:2014 Governance & Social Certifiable ISO 42001:2023 Artificial Intelligence Management Systems The first certifiable AI management system standard (AIMS), specifying requirements for the responsible development, provision and use of AI systems Technology & Innovation Certifiable ISO 27005:2022 Information Security Risk Management Guidance on managing information security risks in support of an ISO/IEC 27001 information security management system; guidance only, not certifiable Management Systems ISO 27701:2025 Privacy Information Management Systems Certifiable requirements for a privacy information management system (PIMS); the 2025 second edition is a standalone standard, no longer an extension to ISO/IEC 27001 Management Systems Certifiable ISO 27032:2023 Cybersecurity Guidelines for Cyberspace Guidelines for Internet security, explaining how Internet security relates to network, web and cybersecurity; second edition published 2023, replacing the 2012 cyberspace-focused edition Management Systems ISO 23894:2023 Artificial Intelligence - Risk Management Guidance on managing risk specific to artificial intelligence, applying the ISO 31000 risk management model to AI development and use; guidance only, not certifiable Technology & Innovation ISO 30141:2024 Internet of Things - Reference Architecture Reference architecture for Internet of Things systems, providing a conceptual model, architectural views and design patterns; second edition published 2024 Technology & Innovation ISO 24028:2020 Artificial Intelligence - Overview of Trustworthiness in AI A technical report surveying the factors that affect the trustworthiness of systems providing or using AI, including transparency, explainability, controllability, robustness, safety, security and privacy. Technology & Innovation ISO 27030:2022 IoT Security and Privacy - Guidelines (published as ISO/IEC 27400) ISO/IEC 27030 was the working project number for IoT security and privacy guidelines; the work was renumbered and published as ISO/IEC 27400:2022, which is the standard to reference. Technology & Innovation ISO 30409:2016 Human Resource Management - Workforce Planning Guidelines and a framework for strategic and operational workforce planning, scalable to organizations of any size, industry or sector. Reviewed and confirmed in 2022. Management Systems ISO 15223:2021 Medical Devices - Symbols to be Used with Information Supplied by the Manufacturer Specifies the symbols used to convey information supplied with medical devices, on the device, its packaging or accompanying documentation. The fourth edition (2021) is amended by Amendment 1:2025. Industry-Specific ISO 14155:2026 Clinical Investigation of Medical Devices for Human Subjects - Good Clinical Practice Specifies good clinical practice for the design, conduct, recording and reporting of clinical investigations of medical devices in human subjects. The 2026 edition supersedes ISO 14155:2020. Industry-Specific