Subcontractors & critical suppliers

ISO 13485 supplier audit: what your client manufacturer will verify

Article 10 MDR requires manufacturers to control their critical suppliers; ISO 13485 §7.4 defines the practical requirements. If you manufacture a component, provide sterilisation services, supply primary packaging, or integrate embedded software into a medical device, your client is required to audit you. In some cases, the manufacturer's notified body may audit your premises directly.

ISO 13485 MDR Art. 10 Supplier Audit ISO 19011
Talk to us →
Qualification

Are you a critical supplier under the MDR?

The term "critical" supplier is not explicitly defined by the MDR. It is the manufacturer who determines each supplier's criticality level by assessing the impact of their activity on the conformity and safety of the final device, in accordance with ISO 13485 §7.4.1. In practice, notified bodies review this classification during certification audits: a supplier that is poorly evaluated or unsupervised constitutes a direct non-conformity.

You are most likely a critical supplier if you manufacture or provide:

  • A component that is incorporated into the finished product and contributes to its performance or safety
  • A sterilisation service, primary or terminal
  • An assembly or sub-manufacturing service for the device or a significant part of it
  • Embedded software or an integrated SaMD module
  • Primary packaging (in direct contact with the sterile MD)
  • A calibration or validation service for critical equipment
  • A transport or cold-chain storage service for a temperature-sensitive MD

Three requirement levels based on your criticality

Level Profile Expected requirements
Low criticalityStandard raw material supplier, non-specialist transportDocumented initial evaluation, supplier questionnaire, batch traceability. Periodic re-evaluation recorded in the QMS (ISO 13485 §7.4.1).
Medium criticalityIntegrated components, non-primary packaging, standard servicesISO 9001 still accepted by some manufacturers. ISO 13485 increasingly required. Documented process control, on-site supplier audit.
High criticalitySterilisation, assembly, critical components, primary packaging, embedded software (IEC 62304)ISO 13485 required in practice. Certification recommended before any contractual relationship with a Class IIa manufacturer or above. Direct NB audit possible.

Source: practice of French notified bodies (LNE-GMED, AFNOR Cert.), MDR Article 10, ISO 13485:2016 §7.4, AFNOR (ISO 13485 supplier audit).

Five services tailored to your maturity level

Maturity diagnostic

Flash audit of your current organisation against ISO 13485 and MDR Article 10 requirements. Gap identification, criticality assessment of your activity, roadmap toward certification or contractual compliance required by your client manufacturers.

Durée 1 to 3 days on-site
Preparation for a client audit

Your client is auditing you in 4 to 12 weeks. We structure your documentation, identify likely questions, run a mock audit, and coach your team on audit posture.

Durée 2 to 6 weeks depending on initial gap
ISO 13485 QMS implementation

Full build of an ISO 13485:2016-compliant QMS, calibrated for your subcontracting activity (some design requirements do not apply; others are reinforced).

Durée 6 to 12 months depending on size and existing systems
ISO 13485 certification preparation

Full mock audit, identification of residual gaps, remediation plan, support during the certification audit.

Durée 8 to 12 weeks
Annual monitoring and surveillance audit preparation

Annual internal audit, QMS update, preparation for NB surveillance audit. For certified subcontractors who wish to outsource their monitoring and internal audit function.

Durée 5 to 10 days per year
Field experience

Five mistakes we commonly see in subcontractors new to medical devices

# Mistake Consequence
1"We're ISO 9001 — that's enough"ISO 9001 is a solid foundation. For a medium-criticality subcontractor, it may be sufficient depending on the manufacturer's requirements. For high-criticality suppliers, ISO 13485 has become the standard expected by notified bodies and the majority of Class IIa and above manufacturers. Verify contractual requirements before assuming your current certification covers the scope.
2Underestimating traceabilityISO 13485 requires documented product traceability, by batch or serial number depending on device class and the manufacturer's requirements. The specific modalities depend on your activity but are systematically checked in supplier audits. Factor in the impact on your information systems from the QMS implementation phase.
3Confusing equipment qualification and process validationISO 13485 §7.5.6 requires equipment qualification (IQ/OQ/PQ) and validation of special processes whose results cannot be fully verified after the fact. A subcontractor may have mastered a process for years without holding the documented proof required under MD standards. This is a consistent friction point in audits: know-how is not enough — reproducibility must be demonstrated through records.
4Failing to anticipate a direct NB auditFor high-criticality subcontractors, the notified body may audit you directly. If you are unprepared, your client risks losing their certificate.
5Treating certification as the end goalThe certificate is a starting point, not an end. Real control is visible in supplier audits, particularly in change management and supplier oversight.

A real case: machining subcontractor, first ISO 13485 certification

3

days · diagnostic

9

months · QMS build

12

months · contractual deadline

A 25-person company, ISO 9001 certified, supplying machined parts to a Class IIb medical device manufacturer. During an audit, the manufacturer's notified body flagged inadequate supplier control over the machining subcontractor. The manufacturer required ISO 13485 certification within 12 months.

Our intervention: 3-day diagnostic, gap identification (document management, machining process validation, batch traceability, operator training on MD requirements). QMS built over 9 months, certification obtained on schedule. Annual maintenance in place since.

Frequently asked questions

The MDR does not require subcontractors to be certified. It is your client — the manufacturer — who imposes certification or an equivalent level of control, based on their documented risk analysis under Article 10 and ISO 13485 §7.4. In practice, for a high-criticality subcontractor, certification has become the market standard.
The cost depends on two main variables: preparation fees (consulting, QMS implementation, mock audit) and the certification body's fees. The latter are calculated according to IAF MD 9, which determines audit durations based on headcount and the complexity of outsourced activities. A 10-person company does not require the same audit time as an 80-person one. We provide a precise estimate at the initial scoping stage, once your activity scope and headcount are known.
Yes. We prepare the audit with you (document review, mock audit, team coaching on audit posture), and we can be present as technical support on audit day, at your request.
A subcontractor performing activities that affect the conformity of the final device is subject to the requirements of ISO 13485 clause 7.4. The manufacturer must evaluate, qualify, and monitor them against defined criteria. Depending on the criticality of the outsourced activity, the manufacturer may require ISO 13485 certification from the subcontractor, or may accept a qualification audit. The subcontractor must also maintain documented procedures, ensure traceability, and notify any changes that may affect product conformity. The scope of obligations varies by the nature of the service.

Subcontractor ISO 13485 consulting
ISO 13485 clause 7.4.1 requires the manufacturer to define criteria for selecting, evaluating, and re-evaluating suppliers. The initial evaluation can take several forms: on-site audit, self-assessment questionnaire, technical file review, certificate review. Supplier criticality determines the rigour of the process: a supplier of critical components or high-impact outsourced activities will be audited periodically. Monitoring results must be recorded in the QMS and re-evaluated at defined intervals. An unevaluated or unsupervised supplier is a direct non-conformity in a certification audit.

See our ISO 13485 supplier audit service
ISO 13485 certification is not a legal obligation for a subcontractor. The manufacturer remains responsible for the final conformity of the device. However, in practice, many manufacturers and notified bodies require it contractually for critical suppliers, as it simplifies evaluation and monitoring. For less critical activities, a qualification audit or questionnaire may suffice. Market expectations are moving toward increasing certification requirements, particularly for sterilisation providers, component manufacturers, and embedded software suppliers (IEC 62304).

Prepare your ISO 13485 certification
A supplier quality agreement (Quality Agreement) is a contractual document that formalises the respective responsibilities of the manufacturer and subcontractor regarding quality and regulatory compliance. It specifies applicable requirements, control arrangements, change notification conditions, and traceability obligations. ISO 13485 does not make this agreement mandatory in this exact form, but clause 7.4.3 requires purchasing information to clearly specify requirements. In practice, for any critical outsourced activity, the quality agreement is the documented proof that the manufacturer has controlled its supply chain.

Manage your subcontractor relationships

Client audit approaching, certification to prepare?

The earlier we understand the brief, the stronger the plan.

Talk to us →