ISO 13485 Gap Analysis: The Proven Path to QMSR Ready

Medical Devices

Score. Prioritize. Close.

An ISO 13485 gap analysis is no longer a certification exercise. As of February 2, 2026, the FDA's Quality Management System Regulation incorporates ISO 13485:2016 by reference into 21 CFR Part 820 — which means the distance between your quality system and the standard is now the distance between your quality system and United States federal law. The gaps did not change. The consequences did.

Direct Answer: An ISO 13485 gap analysis is a clause-by-clause comparison of your existing quality management system against every requirement of ISO 13485:2016 — scoring each requirement twice, once for whether it is documented and once for whether it is actually implemented. The output is a prioritized work list showing which gaps are housekeeping, which threaten certification, and which now carry regulatory exposure under the FDA QMSR.

Most device organizations arrive at an ISO 13485 gap analysis from one of three places. They are ISO 9001 certified and assume the jump is small. They are a startup that has built a product and now discovers the system was supposed to come first. Or they have held ISO 13485 for years and have just realized that the FDA investigator walking through the door in 2026 is going to frame every question in the language of the standard rather than the old Quality System Regulation.

All three need the same thing first: an honest picture of where the system actually stands. Not where the binder says it stands. Where an auditor, opening a drawer at random, would find it.

This guide covers how to run an ISO 13485 gap analysis properly — why an ISO 9001 checklist will actively mislead you, which clauses generate the most findings, how to score honestly, how to prioritize what you find, and what the QMSR changed about the stakes. MSI publishes a free ISO 13485 gap analysis tool you can use to run one yourself.


What Changed

Why an ISO 13485 Gap Analysis Now Carries Regulatory Weight

QMSR. Part 820. One System.

For decades, U.S. device manufacturers ran two vocabularies. The FDA's Quality System Regulation governed what the agency inspected. ISO 13485 governed what a notified body or registrar certified. The two overlapped heavily but used different words, different structures, and different emphases — so organizations maintained a translation layer, and the translation layer was where things got lost.

That ended on February 2, 2026. The FDA's Quality Management System Regulation replaced the old QSR and incorporated ISO 13485:2016 by reference. The regulation is codified in 21 CFR Part 820, and it now points at the standard rather than restating it. MSI covers the mechanics of that shift in its analysis of the QMSR and ISO 13485 alignment.

Direct Answer: An ISO 13485 gap analysis now serves two masters at once. Because the FDA QMSR incorporates ISO 13485:2016 by reference, a nonconformity against the standard is simultaneously a potential regulatory finding. The same scoring exercise that used to prepare you for a registrar audit now also prepares you for an FDA inspection.

The practical consequence is a change in how you should read your own results. Before, a gap in complaint handling meant a possible nonconformity at your next surveillance audit. Now it means the same thing, plus exposure during an FDA inspection where the investigator is reading from the standard. The scoring is identical. The weight attached to a low score is not.

This is why an ISO 13485 gap analysis run in 2026 should be a deeper exercise than one run in 2022. Organizations that have held the certificate for years are not exempt — a system that passed a registrar audit is not automatically a system that satisfies a federal investigator asking the same questions with subpoena power behind them. MSI's work on the FDA Voluntary Improvement Program explores what maturity beyond bare compliance actually looks like.


The Structural Trap

Why an ISO 9001 Checklist Will Wreck Your ISO 13485 Gap Analysis

Different Architecture. Entirely.

This is the single most expensive mistake in medical-device readiness work, and it is made constantly by teams who assume the standards are cousins.

ISO 9001:2015 uses the Harmonized Structure — the ten-clause Annex SL architecture shared across most modern ISO management system standards. ISO 13485:2016 does not. It retains the pre-Annex SL architecture deliberately, because the medical device community concluded that regulatory stability mattered more than structural harmony. Clause 4 is Quality Management System. Clause 5 is Management Responsibility. Clause 6 is Resource Management. Clause 7 is Product Realization. Clause 8 is Measurement, Analysis and Improvement.

If you map an ISO 9001 checklist onto ISO 13485, the clause numbers will not line up — and the requirements that have no ISO 9001 equivalent will simply not appear on your list. You will finish the exercise with a comfortable score and a system that fails Stage 2.

Direct Answer: An ISO 13485 gap analysis cannot be run from an ISO 9001 checklist. ISO 13485:2016 keeps the pre-Annex SL clause structure rather than the harmonized ten-clause format, and it carries device-specific requirements — the Medical Device File, design controls, sterilization validation, traceability, regulatory reporting — that have no ISO 9001 counterpart and would be omitted entirely from a 9001-derived scoring sheet.

Beyond structure, the emphasis differs. ISO 9001 is built around customer satisfaction and continual improvement. ISO 13485 is built around regulatory compliance and risk to the patient. Where ISO 9001 asks whether the customer is happy, ISO 13485 asks whether the device is safe and whether you can prove it. That difference is not cosmetic — it changes what “adequate” looks like for every single record.

Organizations already certified to ISO 9001 do start from a real advantage: document control, internal audit, management review, corrective action, and competence are all live processes rather than blank pages. But the advantage is narrower than it feels. MSI's guide to building a medical-device quality management system maps what carries over and what genuinely has to be built from nothing.


Where the Findings Come From

The Clauses Your ISO 13485 Gap Analysis Must Score Hardest

Design. Risk. Evidence.

Every clause counts. But across 200+ certification audits, MSI has watched a consistent set of requirements produce the majority of findings. Score these with extra suspicion.

Clause 4.2.3 — The Medical Device File

This has no ISO 9001 equivalent whatsoever, and it is where 9001-derived checklists fail first. For each device type or family, ISO 13485 requires a file containing the general device description, intended use, labeling, specifications, manufacturing and monitoring procedures, installation and servicing requirements. In practice, most organizations have all of this — scattered across seven systems, owned by four departments, and assembled fresh every time someone asks. A file that exists only when reconstructed is not a file. Score it honestly.

Clause 7.3 — Design and Development Controls

Design controls are the heart of device regulation, and design history is where an FDA investigator will go first. Your ISO 13485 gap analysis should score planning, inputs, outputs, review, verification, validation, transfer to production, and change control as separate line items — not as one lump called “we do design.” Subclause 7.3.9 on design changes is a frequent finding source; MSI's work on change management automation and its design and development guide both go deep on the record discipline auditors expect.

Risk Management Across the Whole System

ISO 13485 requires a risk-based approach to the entire quality system, applied throughout product realization and referencing ISO 14971 for medical device risk management. The gap most organizations have here is not the absence of a risk file — it is the disconnection of the risk file from everything else. If your risk analysis does not visibly drive your design inputs, your process validation decisions, your supplier controls, and your post-market surveillance, the linkage is a gap even if every individual document exists.

Clause 7.5.6 — Process Validation

Where the output of a process cannot be verified by subsequent inspection, the process must be validated. Sterilization, sealing, welding, molding, coating, software. The failure mode is almost never “we did not validate” — it is “we validated once, three years ago, and have since changed the equipment, the operator training, or the supplier.” Score revalidation triggers as a separate item.

Clause 8.2 — Complaint Handling and Regulatory Reporting

Feedback, complaint handling, and reporting to regulatory authorities are explicit, separate requirements. The most common gap is a complaint process that captures and closes complaints but never asks the escalation question: does this event meet a reporting threshold, who decides, and where is that decision recorded? Under the QMSR, that decision record is federal evidence.

Clause 5.6 — Management Review

ISO 13485 specifies management review inputs and outputs more prescriptively than ISO 9001 does, and Clause 5.6.3 requires documented decisions in four defined areas. Management review is required by ISO 13485, ISO 9001, ISO 14001, and ISO 45001 alike — but the device version is the least forgiving. MSI's ISO 13485 management review playbook covers what a compliant review actually has to contain.

Direct Answer: The clauses that generate the most findings in an ISO 13485 gap analysis are the Medical Device File (4.2.3), design and development controls (7.3), risk management integration per ISO 14971, process validation (7.5.6), complaint handling and regulatory reporting (8.2), and management review (5.6). Score each as multiple line items rather than one, because that is how an auditor will examine them.


Method

How to Run an ISO 13485 Gap Analysis in Four Passes

Documented. Implemented. Prioritized. Owned.

The mechanics are simple. The discipline is not. Two-axis scoring — separating what is written from what is done — is the whole method, because the space between those two answers is where every serious finding lives.

Pass 1 — Score what is documented. Clause by clause, does a controlled procedure exist that addresses this requirement? Not a draft. Not a slide deck. Not a shared folder someone maintains informally. A controlled document, under revision control, that the people doing the work can find.

Pass 2 — Score what is implemented. Do people actually follow it, and could you show an investigator the evidence? This pass is where honest organizations get uncomfortable, and where an ISO 13485 gap analysis earns its keep. A perfect procedure nobody follows scores worse than an imperfect one everybody does.

Pass 3 — Prioritize by consequence, not by effort. Sort by patient risk and regulatory exposure first, certification risk second, housekeeping last. A missing signature on a training record and a missing design validation are not the same finding, and treating them as one queue is how organizations spend three months closing trivia.

Pass 4 — Assign owners and dates. Every gap gets a name and a deadline. A gap analysis that produces a beautiful heat map and no assignments has changed nothing about your regulatory position.

Direct Answer: Run an ISO 13485 gap analysis in four passes: score what is documented, score what is actually implemented, prioritize by patient risk and regulatory exposure rather than by ease of fixing, then assign every gap an owner and a date. The two-axis scoring is essential — a documented-but-unimplemented requirement is the finding auditors and investigators find fastest.

Run it with the people who own each process, not about them. An ISO 13485 gap analysis conducted by the quality manager alone, in a room, from memory, will be optimistic by roughly the margin you would expect. Conducted with the design engineer, the production supervisor, and the regulatory affairs lead in the room, it will be accurate — and the corrective actions will land faster, because the people who have to change something helped find the problem.

MSI's free ISO 13485 gap analysis tool is a self-scoring spreadsheet built exactly this way: each requirement scored for documentation and implementation separately, with a readiness dashboard by clause and a recommended next step attached to every row. Most teams complete a first pass in a day or two.


Reading the Results

What Your ISO 13485 Gap Analysis Results Actually Mean

Read. Rank. Respond.

A readiness percentage is a starting point, not a verdict. What matters is the shape of the scores, and there are three patterns worth learning to recognize.

High documented, low implemented. The classic. You have a well-written system that people work around. This is the most dangerous profile, because it feels like readiness and audits like negligence. It is also the profile that most often follows a consultant engagement where templates were delivered but never operationalized.

Low documented, high implemented. Common in engineering-led startups. People do the right things by instinct and experience, and nothing is written down. Easier to fix than it looks — you are capturing reality, not changing it — but it will fail an audit outright, because ISO 13485 requires documented evidence, not competent improvisation.

Evenly moderate across the board. Often means the scoring was not honest. A real system has strengths and weaknesses. A row of 3s across forty clauses usually means someone was scoring the procedure titles rather than the practice.

Direct Answer: The most dangerous result in an ISO 13485 gap analysis is a high documentation score paired with a low implementation score. It reads as readiness and audits as failure. A well-written procedure that nobody follows is a worse position than a thin procedure that everyone follows, because it demonstrates to an auditor that the system exists on paper only.

Once the results are ranked, the work is ordinary quality management: corrective actions with owners, dates, and verification of effectiveness. Fold them into your existing improvement cycle rather than running them as a separate project — a parallel “gap closure project” tends to end when the enthusiasm does. Build internal audit capability so the next check is your own rather than a registrar's; MSI's ISO Internal Auditor training and internal audit services both exist for that reason.


Beyond the U.S.

How an ISO 13485 Gap Analysis Serves Every Market at Once

One System. Many Regulators.

ISO 13485 is the closest thing the device world has to a common currency. The FDA now incorporates it. The European Union's Medical Device Regulation expects a quality system that ISO 13485 satisfies. Health Canada requires it through the international regulatory convergence work and the Medical Device Single Audit Program, which lets a single audit satisfy multiple national regulators.

This is the strategic argument for doing an ISO 13485 gap analysis thoroughly rather than minimally. Every gap you close serves several regulators simultaneously. Every gap you leave open is exposure in every market you sell into. The economics of a rigorous scoring exercise are unusually favorable in devices, because the work is not duplicated across jurisdictions the way it is in most regulated industries.

Direct Answer: A thorough ISO 13485 gap analysis pays across every market at once. The FDA QMSR, the EU MDR, Health Canada, and the MDSAP participating regulators all build on or accept ISO 13485:2016, so a gap closed once is a gap closed everywhere. Certification itself is issued by a registrar accredited under the global accreditation framework, not by ISO.

One note on the certificate itself. ISO does not certify anyone — an accredited registrar does, and that registrar is accredited by a body such as ANAB, which is peer-evaluated under Global ACI, the body that unified IAF and ILAC on 1 January 2026. That chain is what makes the certificate mean something to a regulator who has never met you.


Scope and Timing

When to Run an ISO 13485 Gap Analysis, and How Often

Early. Honestly. Repeatedly.

The most costly timing error in medical devices is running the exercise too late. Startups routinely build a product, raise a round, book a Stage 1 audit, and only then discover that design controls were supposed to be operating during development rather than reconstructed afterward. A design history file assembled retroactively is not a design history file — it is a narrative, and registrars recognize the difference immediately.

Run the first one before you think you need it. A device company at the prototype stage that scores itself honestly against ISO 13485 will find the exercise cheap and the corrections easy, because there is very little history to unwind. The same company eighteen months later, with three products in the field and a submission pending, will find both expensive.

Direct Answer: Run an ISO 13485 gap analysis before certification is imminent, then annually as a self-check. Device organizations that score themselves early — while the product is still in development — close gaps at a fraction of the cost, because design controls can be built into the work rather than reconstructed from it afterward.

For organizations that already hold the certificate, an annual ISO 13485 gap analysis is the cheapest surveillance insurance available. Systems drift. People leave, processes get shortcuts, a supplier changes, software is updated, and the procedure that described reality two years ago now describes an aspiration. Organizations typically report that an annual self-scoring pass catches that drift long before a surveillance audit does — and catching it yourself is a corrective action, while catching it at audit is a finding.

Scope the exercise across the whole standard rather than the parts you suspect are weak. The clauses organizations skip are almost always the ones they have never been asked about — which is precisely why they have not been maintained. An ISO 13485 gap analysis that scores only the areas you already worry about is a confirmation exercise, not an assessment.


Working With MSI

After the ISO 13485 Gap Analysis: Turning Findings Into a Plan

Write. Train. Attend.

Scoring the system is something your team can and should do itself. Sequencing the response is where most organizations stall — because the findings arrive as a list, and a list is not a plan.

Management Systems International (MSI) has spent 28 years building management systems in regulated environments where the evidence has to survive contact with an investigator. MSI's track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries.

Three things distinguish MSI's ISO consulting approach for device organizations. MSI writes the procedures alongside your engineers rather than handing over templates for you to reverse-engineer — which matters enormously in design controls, where a generic procedure is worse than none. MSI trains your staff to run internal audits, because a device company that depends permanently on an external auditor has not built a quality system, it has rented one. And MSI attends the certification audit. Being in the room on audit day is a commitment most consultants will not make.

A planning session takes the output of your ISO 13485 gap analysis and turns it into a sequence — what to fix first, what can wait, what needs outside help, and what a realistic certification timeline looks like given your actual staffing. For organizations that would rather have the whole path run for them, SurePath is MSI's turnkey route from decision to certificate, and SureResults keeps the system audit-ready year-round once you hold it.


Next Steps

Start Your ISO 13485 Gap Analysis This Week

Score. Sequence. Certify.

Download the Free ISO 13485 Gap Analysis Tool

A self-scoring spreadsheet covering every ISO 13485:2016 requirement — including design controls, sterilization, and servicing. Score each clause as documented and implemented, get an instant readiness percentage, and receive a recommended next step for every gap. No consultant required, no obligation, and yours to re-run every year.

Get the ISO 13485 Tool →

Turn Your Findings Into a Sequence — One Planning Session

Bring your scored results. Leave with a plan: what to fix first, what can wait until after Stage 1, and a realistic certification timeline based on the staff you actually have. MSI has attended 200+ certification audits and knows which controls a registrar tests hardest in a device company.

Call 760-434-9141 to Plan a Session →

Have MSI Run the Whole Certification

SurePath is MSI's turnkey path to ISO 13485: procedures written with your engineers, staff trained, internal audit program built from day one, and MSI in the room on audit day. For device companies with thin quality bandwidth and a regulatory deadline, this is the shortest defensible route to a certificate.

Explore SurePath →


Frequently Asked Questions

ISO 13485 Gap Analysis: Common Questions Answered

Ask. Answer. Act.

Can I use my ISO 9001 gap analysis for ISO 13485?

No. An ISO 13485 gap analysis requires its own scoring sheet, because ISO 13485:2016 keeps the pre-Annex SL clause structure rather than the harmonized ten-clause format. Device-specific requirements — the Medical Device File, design controls, sterilization validation, regulatory reporting — have no ISO 9001 equivalent and would simply be missing from a 9001-derived list.

Do I still need an ISO 13485 gap analysis if I am already certified?

Yes, and 2026 is the year to run one. Because the FDA QMSR now incorporates ISO 13485:2016 by reference, an ISO 13485 gap analysis is no longer only about certification — it maps your exposure during an FDA inspection. A system that satisfied a registrar is not automatically a system that satisfies a federal investigator asking the same questions.

How long does an ISO 13485 gap analysis take?

Most teams complete a first pass of an ISO 13485 gap analysis in a day or two using a self-scoring tool. What takes longer is the honest version — the one run with the design engineer, production supervisor, and regulatory lead in the room, where each score gets challenged. That version takes about a week and is worth several times the difference.

Which clause causes the most findings?

Design and development controls under Clause 7.3, with the Medical Device File under Clause 4.2.3 close behind. In MSI's experience across 200+ certification audits, the design history file and the linkage between risk management and design decisions are where registrars and FDA investigators both go first. Score them as multiple separate line items in your ISO 13485 gap analysis, not as one.

Do I need a consultant to run one?

No. An ISO 13485 gap analysis is designed to be run by the team that owns the processes, and MSI publishes a free self-scoring tool for exactly that purpose. Where outside help earns its cost is afterward — turning a list of findings into a sequenced plan, and knowing from audit experience which gaps a registrar will actually test hardest.

Does an ISO 13485 gap analysis help with the EU MDR or MDSAP?

Yes. Because the FDA QMSR, the EU Medical Device Regulation, and the MDSAP participating regulators all build on or accept ISO 13485:2016, a gap closed once is a gap closed across markets. That convergence is what makes a thorough ISO 13485 gap analysis unusually good value compared with regulated industries where each jurisdiction demands separate work.


Related Reading

References and Authoritative Sources

International Organization for Standardization — ISO 13485:2016, Medical Devices — Quality Management Systems
International Organization for Standardization — ISO 14971:2019, Application of Risk Management to Medical Devices
International Organization for Standardization — ISO 9001 Quality Management
International Organization for Standardization — Certification and Conformity
U.S. Food and Drug Administration — Quality Management System Regulation (QMSR) FAQ
U.S. Food and Drug Administration — Medical Device Single Audit Program (MDSAP)
National Archives — 21 CFR Part 820, Quality Management System Regulation
International Medical Device Regulators Forum — IMDRF
Association for the Advancement of Medical Instrumentation — AAMI
Global Accreditation Cooperation Incorporated — Global ACI (successor to IAF and ILAC, operational 1 January 2026)
ANSI National Accreditation Board — ANAB
American Society for Quality — ASQ Quality Resources

About Management Systems International (MSI)

Diana Lynn is President and Principal ISO Consultant at Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she co-founded in 1998. With 28 years of experience including extensive AS9100 work in MSI's early years, MSI's track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.

msi-international.com  ·  760-434-9141

Share this post:
post by:
Picture of Diana Lynn

Diana Lynn

Founder and Principal of Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she founded in 1998. Diana implements management systems, conducts audits, and develops MSI's entire training curriculum — 80+ organizations certified, 200+ audits, and 600+ professionals trained across manufacturing, technology, aerospace, medical device, government, healthcare, defense, and other regulated industries.
In This Guide
Stay Informed

Join our early-access list for ISO 14001:2026 briefings.

Trusted by Global Leaders

Don't miss our latest news!

Get on our Email list. MSI emails new offers, training dates, and ISO updates to our list before anyone else.

Twenty-eight years of practice, written down.
New: complete ISO procedure templates and guides. 13 procedure topics, five standards and combos, editable Word — with the judgment calls already made.
See the templates →

Buy any Template Packages and the price is credited 100% to ISO Consulting Projects, SurePath or SureResults Online or Traditional. Terms apply