
Short answer: ISO 13485 is the quality-management-system standard for medical devices. When a PCB assembly supplier holds it, an auditor from an accredited certification body has verified that the factory runs controlled, documented, validated processes with batch-level traceability — the system a medical build depends on. What the certificate does not do: approve your device, guarantee that your product type is in its audited scope, or replace your own design controls and regulatory submissions. The certificate is a starting point you verify, not a conclusion you accept.
ISO 13485 for PCBA buyers at a glance
| Question | What the certificate tells you | What you still have to check |
|---|---|---|
| Is there a real quality system? | Yes — a certification body audits it on a recurring cycle | That the certificate is current and the registrar is accredited |
| Does it cover my product? | Only what the scope statement says | Scope wording: does it name assembly of the kind you are buying? |
| Does it cover the site quoting my job? | Certificates list specific legal entities and addresses | That your boards will be built at a listed site |
| Will I get traceability records? | The system requires batch/lot record-keeping | Format and retention period — put both in the contract |
| Is my device now compliant? | No — never | Market authorization — FDA clearance/approval, CE marking, NMPA registration — is a separate path you own |
What ISO 13485 actually is
ISO 13485:2016 — Medical devices — Quality management systems — Requirements for regulatory purposes — defines how an organization in the medical-device supply chain must manage quality. It grew out of ISO 9001 and shares its process-based DNA, but the two standards have diverged in intent, and the differences are exactly the things a medical buyer cares about:
| Dimension | ISO 9001:2015 | ISO 13485:2016 |
|---|---|---|
| Purpose | General quality management, any industry | Medical-device quality, written to line up with regulators' expectations |
| Driving philosophy | Continual improvement and customer satisfaction | Consistency and maintained effectiveness — a validated process should keep doing exactly what it did |
| Risk | Risk-based thinking, loosely specified | Risk management applied through product realization, expected to be documented |
| Documentation | Lighter — "documented information" where needed | Heavier and explicit: procedures, records, and a file for the device type |
| Process validation | Required where output cannot be verified downstream | Same principle, taken further — validation evidence is a routine audit item |
| Who holds it in electronics | Nearly every serious factory | The subset that runs medical builds — it is a meaningful filter |
One structural note that surprises people: ISO 13485:2016 did not adopt the new clause structure ISO 9001 took in 2015. It deliberately stayed close to the older ISO 9001:2008 layout, because regulators had already built their frameworks around it. The two certificates on a factory wall are cousins, not versions of each other.
What it changes on the assembly floor
For a PCB assembly line, the practical difference between "we have ISO 9001" and "we also run ISO 13485" shows up in five places:
- Process validation. Where a process result cannot be fully verified by later inspection — reflow soldering is the classic case — the process itself must be validated and then locked: documented parameters, qualified equipment, revalidation when anything material changes.
- Traceability. Batch and lot records tie finished assemblies back through assembly runs to incoming material. If a component lot is recalled, the system should answer "which shipped boards contain it?" from records, not memory. One caveat the standard hides in plain sight: each factory defines the extent of its traceability — so specify component-lot-to-batch traceability in the contract, alongside record format and retention, rather than assuming the certificate delivers it.
- Change control. No silent substitutions. A changed component, solder paste, or process parameter goes through documented review before it touches a medical build.
- Supplier control. The factory must qualify and monitor its own suppliers — which is why component sourcing channels and their records are part of the audit, not a private matter.
- Records that outlive the order. Inspection results, test data and process records are retained on a defined schedule, because a device maker may need them years later for a regulatory question.

What an ISO 13485 certificate does not mean
The certificate is a system audit, not a product judgment. Three boundaries matter:
- It is not device approval. Regulatory clearance — an FDA submission, CE marking under the EU MDR, NMPA registration — belongs to the device manufacturer and is a separate process. A contract assembler's certificate supports your file; it does not substitute for it.
- It does not transfer design responsibility. Design controls, risk files, verification and validation of the device itself stay with you. The assembler's system governs how your design is built, not whether the design is right.
- It is entity-, site- and scope-specific. A certificate naming one factory does not cover a sister plant, a subcontractor, or work outside the scope statement.
Worth knowing in 2026: the US FDA's Quality Management System Regulation now incorporates ISO 13485:2016 by reference — the harmonization took effect in February 2026. That has made the standard more, not less, central: a supplier fluent in ISO 13485 is speaking the same language your US regulatory consultant is.
Does ISO 13485 apply to cable and wire harness assembly?
Yes — the standard is not board-specific. A patient-connected cable or an internal harness in a medical device flows through the same quality-system logic: validated crimp processes, lot traceability on wire and connectors, controlled changes, retained records. Two things to look for on the harness side:
- Workmanship standard: cable and harness builds are inspected against IPC/WHMA-A-620, the harness counterpart to IPC-A-610 for board assembly. The acceptance class is set by your specification.
- Crimp validation: a crimped termination is the harness world's "cannot fully verify by inspection" case — pull-force and crimp-height validation records are the evidence that matters.

How to verify a supplier's ISO 13485 claim
Verification takes ten minutes and is entirely reasonable to ask for. Nobody with a real certificate refuses.
- Ask for the certificate PDF. Marketing pages say "ISO 13485 certified"; the document says who, where, what and until when.
- Match the legal entity and address to the company quoting your job — and to the site that will actually build it.
- Read the scope statement. It should plainly cover the work you are buying — assembly of printed circuit boards, cable assemblies, or both.
- Check the dates. Certificates run on a three-year cycle with surveillance audits between; an expired certificate is a conversation, not a technicality.
- Check the registrar. The issuing certification body should be accredited (ANAB, UKAS, CNAS and peers). Registrar databases and the IAF CertSearch directory can help: a certificate that appears there is genuine. Absence is not proof of a fake — not every certification body uploads its data — so in that case verify directly with the issuing registrar.
Where BELI fits
BELI manufactures under ISO 9001:2015, ISO 14001 and ISO 13485:2016 quality systems, and certificates are available on request as part of any RFQ — we would rather you verify than assume, which is the point of this article. Assemblies are inspected to IPC-A-610 and harnesses to IPC/WHMA-A-620, with the acceptance class set by your specification. Components are sourced through authorized distributors with traceability kept through the build. For what this looks like on a medical project — which manufacturing records travel with your boards and which parts of the regulatory file remain yours — see our medical device PCB assembly page.
The bottom line
Treat ISO 13485 as a filter, then a checklist. As a filter, it separates factories that have submitted to medical-grade process discipline from those that describe themselves that way. As a checklist, the certificate hands you exactly five things to confirm: entity, site, scope, dates, registrar. Do that once per supplier and the phrase "ISO 13485 certified" stops being marketing language and starts being information.
