When an international distributor, private-label brand owner, or hospital procurement committee screens a new sterile medical device partner—whether sourcing single-use circumcision staplers, radial endovenous laser fibers, negative pressure wound therapy (NPWT) dressings, or sterile injection needles—the commercial conversation almost always opens with a quality claim: 'Our factory is ISO 13485 certified.' Accompanying the quote is a color PDF certificate stamped with embossed seals, gold ribbons, and accreditation logos.
For many commercial teams, receiving this PDF marks the end of quality due diligence. In reality, it should be the opening question. In the global medical device trade, quality management system (QMS) certificates represent one of the most frequently misunderstood, misrepresented, and manipulated document classes. Certificates may be expired, suspended, issued by unaccredited 'certificate mills', limited to non-sterile assembly, or restricted to a corporate trading office while excluding the actual contract manufacturing plant.
This guide provides a comprehensive, field-by-field verification methodology for international medical device buyers. It explains how to decode certificate scopes against the international standard for certification bodies (ISO/IEC 17021-1), how to execute public database lookups via IAF CertSearch and national accreditation bodies, how to navigate the 2026 Global ACI institutional transition, how to spot fatal fake certificate patterns, and how to structure binding QMS evidence terms in distribution and OEM agreements.
What fields does a conforming ISO 13485 certificate actually carry — and why does the scope line decide the deal?
A valid ISO 13485 certificate is not an arbitrary artistic document. Under ISO/IEC 17021-1:2015 (Conformity assessment — Requirements for bodies providing audit and certification of management systems), Clause 8.6.2 defines the mandatory information that must appear on every certification document issued by an accredited certification body (CB)5. If a presented certificate lacks any of these core fields, it fails baseline conformity assessment standards:
- Name and Geographic Location: The full legal entity name and physical street address of the certified client, including all operational sites covered under a multi-site certification.
- Dates of Certification: The effective date of granting, extending, or renewing certification, alongside the explicit expiry date or recertification due date (standard audit cycles run on a 3-year validity window with mandatory annual surveillance audits).
- Unique Identification Code: A distinct certificate tracking number issued by the certification body for registry cross-referencing.
- Normative Standard & Version: Explicit citation of the audited standard, namely
ISO 13485:2016(or regional adoptions such asEN ISO 13485:2016/A11:2021in the European Union orYY/T 0287-2017in China). - Scope of Certification: The unambiguous definition of activities, product types, and services audited at each named physical site.
- Issuing Certification Body Details: The legal name, official address, and certification mark/logo of the issuing registrar, accompanied by the accreditation symbol of the recognized Accreditation Body (AB).
The table below outlines the field-by-field verification checklist that procurement teams should apply to every supplier certificate before advancing commercial negotiations:
| Certificate Field | Normative Requirement | Verification Significance | Pass Criteria | Investigation Trigger / Red Flag |
|---|---|---|---|---|
| Certified Entity Name | Full registered legal name of the organization | Confirms whether the audited entity is the company signing the commercial agreement | Exact match with supplier's business license, bank account, and commercial quotation | Name belongs to an offshore trading shell or unrelated corporate parent; 'trading company' listed as manufacturer |
| Physical Site Address | Specific physical location(s) audited | Ensures the physical factory manufacturing the quoted SKUs was inspected, not just an office | Matches the physical factory address, cleanroom location, and packaging site | Only commercial office address listed; factory address absent or located in a different jurisdiction |
| Scope Statement | Precise description of audited activities and product families | Defines exactly which lifecycle stages (design, manufacturing, sterile packaging) and device types are covered | Explicitly lists 'Design & Development' (if applicable), 'Production', and the specific quoted device family (e.g., circumcision staplers) | Generic 'sales of medical devices' only; quoted product family omitted; 'production' omitted for manufacturing claims |
| Standard & Edition | Full title and year of the normative standard | Verifies compliance with the current medical device quality management standard | Explicitly states 'ISO 13485:2016' (or EN ISO 13485:2016/A11:2021) | Cites obsolete 'ISO 13485:2003' or generic 'ISO 9001:2015' as medical device evidence |
| Validity Dates | Initial certification date, issue date, and expiry date | Confirms the certificate is currently active and within its 3-year recertification lifecycle | Expiry date is in the future; issue date aligns with standard 3-year recertification intervals | Expired certificate; date interval exceeds 3 years; handwritten or visibly edited date fields |
| Certificate Number | Unique alphanumeric tracking identifier | Enables independent verification in database registries and directly with the issuing registrar | Resolves successfully in IAF CertSearch or the issuing CB's online verification portal | Number not found in CB database; number format deviates from the issuing CB's published syntax |
| Accreditation Mark | Symbol of the national accreditation body (e.g., ANAB, UKAS, CNAS, DAkkS) | Proves the certification body is independently audited and recognized under international multilateral arrangements | Contains legitimate AB logo alongside the CB's logo, often with an IAF MLA endorsement mark | AB mark absent (unaccredited certificate); fictitious AB logo; forbidden ISO logo printed on certificate |
Source: Synthesized from ISO/IEC 17021-1:2015 Clause 8.6.2 and medical device distributor due diligence standards.
Decoding the Scope Line: Design & Development vs. Production Only
In medical device procurement, the scope statement is where deals succeed or fail. Under ISO 13485:2016 Clause 1.2, if a manufacturer excludes design and development controls (Clause 7.3), this exclusion must be justified and explicitly reflected in the QMS scope4.
Consider the operational difference between two common scope formulations for a single-use surgical device:
- Scope A: 'Design and development, production, and distribution of sterile disposable circumcision staplers and endovenous laser fibers.'
- Scope B: 'Production and distribution of disposable circumcision staplers.'
If a distributor is purchasing finished branded goods from the supplier, Scope A proves that the supplier maintains complete Design History Files (DHF), design verification and validation data, risk management files (ISO 14971), and clinical evaluation reports. Conversely, Scope B indicates a contract manufacturing / build-to-print operation. The supplier has been audited for manufacturing processes, cleanroom environmental controls, and batch release, but does not own the design controls. If a buyer seeks an OEM/ODM partner to design a custom device under a private label, a supplier holding only Scope B cannot legally provide design authority support without an external design partner.
Multi-Site Operations and Outsourced Sterilization
For sterile single-use devices, buyers must scrutinize how sterilization is handled in the certificate scope. Many device assemblers outsource ethylene oxide (EO) or gamma radiation sterilization to specialized contract sterilizers. When sterilization is outsourced, the manufacturer's ISO 13485 scope must cover the control of outsourced processes (Clause 4.1.5), and the manufacturer must maintain validated sterilization protocols (per ISO 11135 for EO or ISO 11137 for radiation).
Furthermore, if a supplier operates multiple facilities—for example, corporate headquarters in Shanghai, injection molding in Jiangsu, and cleanroom assembly in Weihai—the certificate must either be a multi-site certificate explicitly listing all site addresses and their specific sub-scopes in an attached annex (per IAF Mandatory Document MD 1), or the supplier must present separate, valid certificates for each operational site5.
How do you verify the certificate itself: IAF CertSearch, the certification body, or both?
When verifying an accredited certification, the International Organization for Standardization (ISO) officially establishes two primary routes1:
When seeking to verify a certification issued by an accredited certification body, you can either: Use the International Accreditation Forum's global database, IAF CertSearch. CertSearch consolidates data from the IAF, accreditation bodies, and certification bodies, allowing you to confirm certification and accreditation status in one place. Certificates can be verified individually, in bulk, or via API; or contact the relevant certification body, accreditation body, or IAF directly to confirm the respective statuses.— ISO, 'Certification' Guidance (retrieved 20 August 2026)
International buyers should execute both routes in sequence to achieve definitive verification.
Route 1: IAF CertSearch Database Verification
IAF CertSearch (iafcertsearch.org) is the official global database established by the International Accreditation Forum to validate accredited management system certifications2. The platform operates on a three-tier data hierarchy: national Accreditation Bodies (ABs) upload accredited Certification Bodies (CBs); CBs upload certified client organizations, active certificate numbers, standard versions, and scope details; and the central registry validates the entire accreditation chain.
To verify a certificate on IAF CertSearch:
- Navigate to
iafcertsearch.organd select 'Search by Company / Organisation' or 'Search by Certificate Number'. - Enter the exact legal entity name or the unique certificate number from the supplier's document.
- Inspect the returned profile: verify that the status is displayed as Active (green), the standard indicates
ISO 13485:2016, the issuing CB is listed, and the associated Accreditation Body is recognized. - Check the physical address and certified scope displayed in the registry against the PDF presented by the supplier.
Route 2: Direct Certification Body Verification
While IAF CertSearch is an indispensable global aggregator, the issuing Certification Body is the definitive legal authority for its own certificates. Reputable international registrars (such as TÜV SÜD, BSI, SGS, DNV, DEKRA, TÜV Rheinland, CQC, and CMD) maintain proprietary online client directories. If an online tool is unavailable or if a certificate is pending database synchronization, buyers should email the CB's compliance department with the certificate number, company name, and attached PDF requesting formal written status confirmation.
In specific jurisdictions, dedicated national verification portals provide streamlined checking. For example, in the United Kingdom, UKAS CertCheck (certcheck.ukas.com) enables instant validation of all accredited certificates issued by UKAS-accredited certification bodies8.
| Verification Channel | Operator / Authority | Coverage Scope | Primary Function | Operational Limitation |
|---|---|---|---|---|
| IAF CertSearch | Global ACI / IAF | Worldwide accredited CBs and certified entities | Validates complete accreditation chain (Entity → CB → AB) | Contains only accredited certifications; data upload depends on CB synchronization schedules |
| UKAS CertCheck | United Kingdom Accreditation Service (UKAS) | All UKAS-accredited management system certifications | Real-time validation of UKAS-accredited certificates and scopes | Limited to UKAS-accredited certification bodies only |
| CB Online Portals | Individual Registrars (e.g., TÜV, BSI, SGS, CQC, CMD) | Certificates issued exclusively by that specific registrar | Authoritative, real-time record of certificate status, suspensions, and scope | Fragmented across hundreds of individual registrar websites |
| AB Directories (ANAB, CNAS, DAkkS) | National Accreditation Bodies | Accredited Certification Bodies and their approved scopes | Confirms whether the CB holds valid accreditation for ISO 13485 (medical devices) | Confirms the competence of the CB; generally does not index individual end-client certificates |
Source: Synthesized from ISO, IAF CertSearch, UKAS, ANAB, and CNAS documentation.
What does 'accredited' mean after January 2026 — Global ACI, the former IAF MLA and marks in transition?
A critical development in international conformity assessment took place on 1 January 2026: the formal launch of the Global Accreditation Cooperation Incorporated (Global ACI)6. Global ACI unified the International Accreditation Forum (IAF) and the International Laboratory Accreditation Cooperation (ILAC) into a single, comprehensive international organization representing accreditation bodies across management systems, testing, calibration, and inspection.
For medical device distributors and regulatory auditors reviewing supplier certificates in 2026 and beyond, understanding this institutional transition prevents costly misinterpretations:
- Continuity of Multilateral Arrangements: As documented by accreditation bodies including the ANSI National Accreditation Board (ANAB), all existing IAF Multilateral Recognition Arrangements (MLA) and ILAC Mutual Recognition Arrangements (MRA) continue to be fully recognized without interruption under Global ACI7.
- Accreditation Mark Validity During Transition: Certificates issued prior to or during 2026 that display the familiar IAF MLA mark alongside the national accreditation body logo remain entirely valid. International rules provide for a multi-year transition overlap period. A distributor must not reject a supplier certificate simply because it displays the legacy IAF MLA symbol rather than newly developed Global ACI branding.
- Verifying the Accreditation Body Layer: Accreditation is the process by which an authoritative national body (such as ANAB in the United States, UKAS in the United Kingdom, CNAS in China, DAkkS in Germany, or ACCREDIA in Italy) audits the Certification Body against ISO/IEC 17021-1 to confirm its technical competence to audit medical device manufacturers. Buyers can search the AB's public register—such as the ANAB Accredited Directory9 or the CNAS English Directory10—to verify that the CB's accredited program specifically includes ISO 13485.
Why doesn't my supplier appear in IAF CertSearch — unaccredited, not uploaded, or fake?
When a supplier's company name or certificate number returns 'No results found' in IAF CertSearch, procurement managers frequently wonder whether they are facing a fraudulent supplier. While fraud is a distinct possibility, jumping immediately to a fraud verdict is a technical mistake.
According to the official IAF CertSearch FAQ documentation3:
- Accredited-Only Coverage: 'No, the database only contains accredited certifications.' If a certificate was issued by an unaccredited body, it will never appear in CertSearch.
- Exact Entity Requirement: 'It is only possible to validate a certification if the Certified Entity is a known entity to the user.' Searching vague keywords or misspelled English trade names will return zero results.
- Privacy Controls: 'No user is able to download or view a list of certifications issued by a Certification Body.' Searches must query specific known entities or certificate IDs.
Furthermore, ISO's official guidance emphasizes that 'accreditation is not compulsory, and non-accreditation does not necessarily mean the certification body is not reputable'1. However, in the highly regulated medical device sector, an unaccredited ISO 13485 certificate is almost universally rejected by hospital tenders, notified bodies, and national health authorities because it lacks independent oversight.
When a record is absent from CertSearch, execute this structured three-step diagnostic triage:
- Step 1: Check Data Latency & Entity Spelling. Cross-check the exact registered legal entity name (including local language characters, such as Chinese company registration names) and check the issuing CB's proprietary online portal. If the CB's portal confirms the certificate is active, the absence in CertSearch is simply a data sync delay.
- Step 2: Check Certification Body Accreditation Status. Search the national Accreditation Body's directory (e.g., CNAS, ANAB, UKAS) to verify if the issuing CB is accredited for ISO 13485. If the CB is not listed, the certificate is unaccredited.
- Step 3: Direct Registrar Verification. Contact the CB directly. If the CB states that it has no record of issuing the certificate, the document is confirmed counterfeit.
What does an ISO 13485 certificate NOT prove — product approval, site capability or sterile processing?
One of the most consequential errors an international distributor can make is assuming that an ISO 13485 certificate represents product-level authorization. An ISO 13485 certificate attests that an organization has established, documented, and implemented a quality management system compliant with the standard. It provides no standalone proof regarding the following critical domains:
- Not a Product Regulatory Approval: ISO 13485 certification does not grant legal marketing authorization in any sovereign jurisdiction. It is not an FDA premarket clearance, not an EU CE mark, and not a Chinese NMPA medical device registration. Distinguish supplier QMS evidence from product marketing authorizations by reviewing the companion guides in this series: the FDA 510(k) clearance verification guide, the CE certificate & notified body verification guide, and the NMPA registration certificate verification guide.
- Not Proof of Specific Batch Quality or Sterility: An ISO 13485 audit evaluates system-level procedures (document control, CAPA, management review, supplier evaluation). Auditors sample records; they do not perform lot-release testing, sterility testing (per ISO 11737), or mechanical endurance testing on individual shipments.
- Not Proof of Facility Scale or Dedicated Capacity: A company with ten employees working in a shared facility can achieve ISO 13485 certification just as a multinational manufacturer with ten thousand workers can. The certificate does not verify automated production capacity, cleanroom square footage, or financial stability.
- Not Proof of Design Ownership: As established in the scope analysis, a certificate with a production-only scope confirms manufacturing controls but provides zero evidence of design ownership or clinical evaluation files.
For comprehensive supplier qualification across contract manufacturing and private-label programs, distributors should review our in-depth analysis on how to qualify a sterile medical device contract manufacturer beyond basic QMS documentation.
MDSAP, FDA QMSR and the EU harmonized standard: when does one audit count somewhere else?
While ISO 13485:2016 is a voluntary, non-governmental international standard, global regulatory authorities increasingly incorporate or reference it within their mandatory statutory frameworks. Understanding where and how ISO 13485 audits satisfy local legal requirements allows distributors to leverage supplier audit evidence efficiently across multiple target markets.
The Medical Device Single Audit Program (MDSAP)
The Medical Device Single Audit Program (MDSAP) allows a single regulatory audit conducted by an authorized Auditing Organization (AO) to satisfy the quality management system requirements of up to five participating international regulatory authorities11. However, the legal weight and reliance placed on an MDSAP audit varies significantly by jurisdiction:
- Health Canada: Mandatory. Health Canada requires all manufacturers of Class II, III, and IV medical devices sold in Canada to hold a valid MDSAP certificate (which replaced the legacy CMDCAS system in 2019) as a condition of medical device licensing.
- U.S. Food and Drug Administration (FDA): Routine Inspection Substitution. The FDA accepts MDSAP audit reports in lieu of routine FDA surveillance inspections. However, MDSAP does not substitute for FDA premarket approval (PMA), 510(k) clearance, or for-cause compliance inspections.
- Australia Therapeutic Goods Administration (TGA): TGA uses MDSAP audit reports as primary evidence when evaluating manufacturer conformity for Australian medical device inclusion.
- Brazil ANVISA: ANVISA utilizes MDSAP audit results to grant its mandatory Brazilian Good Manufacturing Practice (BGMP) certification, substantially accelerating market entry.
- Japan MHLW / PMDA: Japan's Ministry of Health, Labour and Welfare uses MDSAP audit reports to waive on-site QMS inspections for marketing authorization holders.
The U.S. FDA Quality Management System Regulation (QMSR)
On 2 February 2026, the U.S. FDA's landmark Quality Management System Regulation (QMSR) final rule officially took effect, amending 21 CFR Part 82012. The QMSR explicitly incorporates ISO 13485:2016 by reference into U.S. federal regulations, replacing the legacy 1996 Quality System Regulation (QSR).
While this harmonization aligns FDA inspection expectations with international ISO 13485 audits, buyers targeting the U.S. market must note two essential boundaries: the FDA does not issue ISO 13485 certificates, and holding an ISO 13485 certificate does not exempt a foreign facility from FDA establishment registration, device listing, or direct FDA inspection authority. For operational details on how QMSR impacts design controls and change notifications, see our guide on design transfer and change control under QMSR and ISO 13485.
European Union Harmonized Standard: EN ISO 13485
In the European Union, the European Commission officially cited EN ISO 13485:2016 and its amendment A11:2021 in the Official Journal of the European Union via Commission Implementing Decision (EU) 2022/757 of 11 May 2022 (amending Implementing Decision (EU) 2021/1182)13. Compliance with EN ISO 13485 provides a legal presumption of conformity with the corresponding quality management system requirements of the EU Medical Device Regulation (Regulation (EU) 2017/745, MDR).
| Jurisdiction / Framework | Normative Basis | Statutory Status | Regulatory Reliance Model | What It Proves to the Buyer |
|---|---|---|---|---|
| ISO 13485:2016 (Standard) | ISO/IEC 17021-1 accredited audit | Voluntary international standard | Commercial baseline; required by tenders and supply contracts | Audited management system exists; scope defines covered activities |
| MDSAP (Single Audit) | ISO 13485 + country-specific requirements | Mandatory in Canada (Class II-IV); recognized in US, BR, AU, JP | Health Canada licence condition; FDA routine inspection substitution; ANVISA BGMP waiver | QMS meets specific statutory requirements of 5 participating sovereign regulators |
| U.S. FDA QMSR (21 CFR 820) | ISO 13485:2016 incorporated by reference | Mandatory federal regulation (in force 2 Feb 2026) | Federal inspection baseline for all device facilities supplying the US | QMS aligns with FDA statutory design, document, and post-market controls |
| European Union (MDR / IVDR) | EN ISO 13485:2016/A11:2021 (Decision 2022/757) | Harmonized standard under Regulation (EU) 2017/745 | Presumption of conformity with MDR Annex IX / XI QMS requirements | QMS satisfies notified body baseline for EU CE mark technical assessment |
Source: Synthesized from FDA, Health Canada, EUR-Lex, and ANVISA regulatory publications.
Which fake, expired and out-of-scope patterns are deal-enders — and which need one clarifying question?
When screening supplier paperwork, procurement and regulatory teams must distinguish between fatal integrity failures (which require terminating the vendor relationship immediately) and administrative discrepancies (which can be resolved through formal clarification). According to the ISO Survey 2024 (published in 2025 in collaboration with the IAF), 31,215 valid ISO 13485:2016 certificates covering 43,957 certified sites were recorded worldwide14. In such a vast global market, rogue operators exploit buyer inexperience through recognizable deceptive patterns.
The matrix below classifies common certificate defects by severity and prescribes the appropriate due diligence response:
| Severity Level | Observed Certificate Anomaly | Root Cause / Diagnostic Meaning | Recommended Commercial Action |
|---|---|---|---|
| CRITICAL (Deal-Ender) | ISO logo printed directly on the certificate | Instant tell for fraud. ISO explicitly forbids anyone from using the ISO logo in connection with certification1. | Hard stop. Terminate vendor discussions; report false certification claim to the issuing body or ISO. |
| CRITICAL (Deal-Ender) | Certificate states 'Certified by ISO' or 'ISO Approved' | ISO does not perform certification or issue certificates. Statement is legally false on its face1. | Hard stop. Disqualify vendor immediately for intentional regulatory deception. |
| CRITICAL (Deal-Ender) | Certification Body is unaccredited or non-existent ('Certificate Mill') | Certificate was purchased from a paper mill without independent audit or AB oversight. | Hard stop. Reject certificate; supplier fails baseline regulatory qualification. |
| CRITICAL (Deal-Ender) | CB confirms certificate is Suspended, Withdrawn, or Falsified | Supplier failed surveillance audits, committed major non-conformities, or forged the PDF. | Hard stop. Notify procurement leadership and quarantine any pending orders. |
| MAJOR (Hold / Block) | Quoted product family completely missing from the scope statement | Scope creep. The manufacturer is certified for other product lines, but not the device being quoted. | Commercial hold. Demand an amended certificate scope or evidence of audited design/manufacturing transfer. |
| MAJOR (Hold / Block) | Actual manufacturing factory address omitted from certificate sites | The certificate covers a corporate headquarters or sales office, while the production plant is uninspected. | Commercial hold. Demand the multi-site annex (IAF MD 1) covering the physical production facility. |
| MINOR (Clarification) | English company name on quote differs slightly from certificate name | Common in cross-border trade (e.g., transliterated Chinese pinyin names vs. registered international trade names). | Request official business license and legal confirmation linking the commercial brand to the certified entity. |
| MINOR (Clarification) | Scope specifies 'Production' but omits 'Design & Development' | Supplier operates as a contract manufacturer / build-to-print plant rather than design authority. | Clarify design responsibility. If private-labeling, ensure buyer holds the complete Design History File (DHF). |
Source: Synthesized from ISO complaints guidance, IAF advisories, and distributor audit findings.
Reporting False Certifications and Logo Misuse
When a buyer encounters an outright fraudulent certificate or unauthorized use of certification marks, ISO provides clear escalation channels1. Complaints should be directed first to the identified Certification Body to confirm whether the document was forged. If an organization falsely claims accredited certification or misuses accreditation symbols, complaints can be lodged directly with the relevant national Accreditation Body or the Global ACI Secretariat.
What certificate evidence and re-verification terms belong in a distribution or OEM agreement?
Verifying an ISO 13485 certificate during initial supplier onboarding is necessary, but insufficient. Quality management system status is dynamic: a manufacturer in good standing today may face major audit non-conformities, scope reductions, or certificate suspension during annual surveillance audits next year. International buyers must convert verification findings into binding contractual covenants within their commercial Distribution Agreement or Quality Agreement (QA).
Ensure your supply contracts incorporate these five mandatory quality evidence clauses:
- Mandatory Quality Exhibit: The agreement must attach as an integral schedule a full, unredacted copy of the supplier's current ISO 13485 certificate, including all multi-site annexes, site addresses, and exact scope wording.
- 15-Day Change Notification Covenant: The supplier must be contractually obligated to notify the distributor in writing within fifteen (15) calendar days of: (a) any written notice from its Certification Body regarding major audit non-conformities, certificate suspension, cancellation, or scope reduction; (b) any change in the issuing Certification Body; or (c) any relocation or structural modification of named manufacturing cleanroom sites.
- Annual Status Confirmation Protocol: The distributor retains the right to demand written confirmation of successful annual surveillance audit completion and an updated certificate upon recertification at least thirty (30) days prior to document expiry.
- Right to Audit & Regulatory Access: For private-label and OEM partnerships, the agreement must guarantee the buyer (and its regulatory auditors / notified body) the right to conduct on-site or virtual quality audits upon reasonable notice and access relevant technical files.
- Breach & Termination Remedies: Explicitly stipulate that failure to maintain active, accredited ISO 13485 certification covering the quoted SKUs constitutes a material breach of contract, entitling the buyer to immediate contract termination, order cancellation without penalty, and indemnification for regulatory recall costs.
Where VEMERIX fits — and where due diligence still begins
VEMERIX operates as the international brand of Weihai Medison Medical Equipment Co., Ltd., positioned as a Minimally Invasive Surgery Total Solution Platform serving urology, vascular surgery, and perioperative care. In international trade, we advocate that manufacturers should be held to the exact verification standards they teach.
Weihai Medison Medical Equipment Co., Ltd. holds a fully active, accredited ISO 13485:2016 Certificate (No. 10425YQ00012R0S), issued on 29 September 2025 and valid through 28 September 202815. The audited scope explicitly covers both design and development and production for our core product families at our Qujiahe Industrial Park manufacturing facility in Weihai, Shandong, China, including:
- Automatic circumcision rings and disposable circumcision staplers / kits (such as our CE-marked Auto-Circumcision Ring and surgical stapler lines);
- Single-use medical laser fibers (such as our 1470 nm radial vascular fibers used in endovenous laser ablation);
- Medical vacuum negative-pressure machines and NPWT perioperative care consumables;
- Topical scar care gels and sterile syringe-assisted propulsion devices.
We encourage international distributors, private-label partners, and procurement committees to apply every check described in this guide to our documentation: verify our certificate number in public registries, review our full scope wording, inspect our cleanroom environmental validation data, and request complete technical files through our Quality & Compliance Portal or by connecting directly with our regulatory team via VEMERIX International Contact. In medical device partnerships, transparent verification is the foundation of patient safety and long-term commercial trust.
Frequently Asked Questions
Does ISO itself issue ISO 13485 certificates?
No. The International Organization for Standardization (ISO) develops and publishes international standards, but it does not perform conformity audits, does not issue certificates, and strictly prohibits the use of the ISO logo on certification documents1. All valid ISO 13485 certificates are issued exclusively by independent third-party Certification Bodies (registrars). Any document claiming to be 'issued by ISO' or bearing the ISO logo is fraudulent.
Can I verify an ISO 13485 certificate online for free?
Yes. Buyers can verify accredited certificates for free through IAF CertSearch (iafcertsearch.org) by searching the certified organization's legal name or certificate number2. Additionally, most accredited Certification Bodies (such as TÜV, BSI, SGS, DNV, CQC, and CMD) and national accreditation bodies (such as UKAS CertCheck in the UK8 or the CNAS directory in China10) provide free public verification portals.
My supplier is not in IAF CertSearch — is the certificate fake?
Not necessarily. As noted in the IAF CertSearch FAQ, the database contains only accredited certifications, and some accredited Certification Bodies experience data synchronization lags when uploading newly issued certificates3. Furthermore, if you searched an informal trading name rather than the registered legal entity name, no result will appear. If a certificate is missing from CertSearch, check the issuing CB's own online directory or contact the CB directly before drawing a definitive conclusion.
The certificate shows an IAF MLA mark — is that still valid in 2026?
Yes. Although the Global Accreditation Cooperation Incorporated (Global ACI) officially launched on 1 January 2026 to assume the former roles of the IAF and ILAC6, all existing IAF Multilateral Recognition Arrangements (MLA) remain fully recognized7. Transition policies provide for an extended multi-year overlap period during which certificates displaying the legacy IAF MLA mark remain completely valid.
Is ISO 13485 certification legally required for medical devices?
ISO 13485 is a voluntary international standard, but compliance is frequently made mandatory through national regulations or commercial contracts. For example, Health Canada mandates MDSAP certification (which incorporates ISO 13485) for Class II–IV medical device licences11. In the U.S., the FDA's QMSR incorporates ISO 13485:2016 by reference into 21 CFR 82012. In the EU, EN ISO 13485:2016/A11:2021 provides a legal presumption of conformity with the EU MDR13.
Does an ISO 13485 certificate mean the device itself is approved?
No. An ISO 13485 certificate proves that an audited quality management system exists. It does not constitute product marketing clearance or approval. A manufacturer must still obtain market-specific product authorizations, such as an FDA 510(k) clearance in the United States, a CE certificate from a notified body in Europe, or an NMPA registration certificate in China.
The scope says 'production' but not 'design and development' — does that matter?
Yes. A scope that specifies 'production' while omitting 'design and development' indicates that the supplier has excluded design controls under ISO 13485 Clause 7.34. This is standard for a contract manufacturer assembling devices according to customer-provided drawings, but it means the supplier cannot serve as the legal design authority for private-label or ODM products. The buyer must hold and maintain the complete Design History File (DHF).
How long is an ISO 13485 certificate valid, and what can happen between audits?
ISO 13485 certificates are typically issued for a three-year validity cycle, subject to mandatory annual surveillance audits in Year 1 and Year 2. If a manufacturer fails a surveillance audit, commits unresolved major non-conformities, or fails to pay certification fees, the Certification Body can suspend or withdraw the certificate prior to its stated expiry date. This is why commercial contracts must require 15-day change notifications.