Sourcing Medical Device Components from India: What ISO 13485, FDA's QMSR and CDSCO Actually Require

A buyer needed a small batch of machined titanium components for a surgical instrument. The Indian shop they found had ISO 9001 certification, clean audit history and had made parts for orthopedic device customers before.
The buyer assumed that covered them. It did not. ISO 9001 says nothing about biocompatibility and the shop's certificate said nothing about ISO 13485 either. The parts were dimensionally perfect and still could not go into a device filing without a separate round of material testing nobody had scoped or paid for. The order slipped by ten weeks while that gap got fixed.
Nothing here was a quality failure. It was a framework mix-up. Medical device sourcing runs on four separate systems and each one checks something different. Knowing which one covers what is the actual first step, before any RFQ goes out.
Four frameworks, four different questions
Most buyers treat "medical grade" as one bar to clear. It is really four separate questions and a supplier can pass one and fail another without anyone noticing until late in the order.
ISO 13485 asks: does this organization run a quality system built for medical devices specifically? It is the standard for a quality management system in the design and manufacture of medical devices. It is a standalone standard, not a medical-flavored version of ISO 9001: it kept its own eight-clause structure when ISO 9001 moved to a different structure in its 2015 revision and it places an explicit, added focus on risk management running through the whole system, not just the finished part. A shop can be a strong general precision manufacturer, even ISO 9001 certified and simply never have built this separate layer. Risk management for the device itself sits in a related but separate standard, ISO 14971. A component supplier does not usually own that file, but the buyer needs to know what component-level evidence has to feed back into it.
FDA's QMSR asks: does this quality system meet the United States' own device rule? As of February 2, 2026, the FDA folded its old Quality System Regulation into a new Quality Management System Regulation that incorporates ISO 13485:2016 directly by reference, on top of a short list of FDA-specific additions. In plain terms, meeting ISO 13485 is now most of the way to meeting the US requirement, but not automatically the whole way. The FDA does not certify to ISO 13485 itself and does not treat an ISO 13485 certificate as a substitute for its own inspection.
QMSR itself directly binds finished-device manufacturers, not automatically every supplier in the chain. A shop making an ordinary machined component that goes inside someone else's device is not automatically a QMSR-regulated entity in its own right. A shop making something FDA treats as an accessory or finished device on its own terms or contract-manufacturing the complete device, is. Either way, the buyer's own QMSR/ISO 13485 purchasing controls still have to manage that supplier, which is why the practical bar for a serious component supplier ends up close to ISO 13485 regardless of whether QMSR technically reaches them directly.
| What the Indian supplier makes | Does QMSR directly apply to them? | What the buyer still verifies |
|---|---|---|
| Raw material or an ordinary machined component | Usually not | Material spec, traceability, process control |
| A component or accessory FDA treats as a finished device in its own right | Potentially yes | Their own QMS status, not just the buyer's |
| Contract manufacturing the complete finished device | Yes | Full QMSR/ISO 13485 alignment |
| Finished device built and sold only in India | CDSCO governs instead, not QMSR | Applicable CDSCO class and licence |
ISO 10993 asks: is the actual material and finish on this part safe in contact with the human body? This is not a management-system standard at all. It is a family of biological test methods, chosen based on what the device touches, for how long and how. A titanium implant component and a reusable external instrument handle can trigger a completely different test panel under the same family of standards. Passing ISO 13485 says a company runs its processes well. It says nothing about whether a specific material and manufacturing process leaves behind a residue or coating that reacts badly with tissue.
One current wrinkle worth checking directly rather than assuming: ISO published a revised ISO 10993-1 in November 2025 and FDA partially recognized it in May 2026, but "partial" is doing real work in that sentence. FDA excluded two specific pieces of the new edition, including its clause on biological risk estimation, which conflicts with the separate ISO 14971 risk-management standard FDA already recognizes. Declarations built on the 2018 edition are still accepted, but only through a transition window ending mid-2029. If the device is headed for the US, do not just write "ISO 10993" into the RFQ. Confirm which edition, which exclusions and which specific endpoints the actual submission needs.
CDSCO's Medical Devices Rules ask: what does India's own regulator require for this specific device class? India classifies devices into four risk classes, A through D, low to high. Class A and B both go through a CDSCO-registered Notified Body audit of the manufacturing site, then the State Licensing Authority issues the manufacturing licence. Class C and D go through CDSCO's own Central Licensing Authority instead, a more involved process. None of that is self-certification: an independent audit sits somewhere in the path for every class. One current wrinkle worth checking directly rather than assuming: a 2025 CDSCO directive moved certain Class A non-sterile, non-measuring devices out of the licensing system entirely and into a lighter registration path, so the class letter alone does not always tell you which pathway actually applies. This framework governs devices sold or distributed in India. It matters most directly to a buyer building or selling a finished device that will reach the Indian market and matters indirectly to a component supplier if their customer's finished-device filing depends on documentation the component maker has to provide.
The distinction that actually matters: component versus finished device
Most of the confusion in medical device sourcing traces back to one mixed-up idea. A company that machines a component is not automatically the same thing, in regulatory terms, as the company that holds legal responsibility for the finished device.
The finished-device manufacturer, usually the buyer's own company or their OEM customer, is normally the one who registers the device with the FDA or CDSCO and holds the actual regulatory clearance. A contract manufacturer making one component inside that device does not usually hold that clearance itself.
There is a real exception worth knowing. A component that changes the device's performance, safety characteristics or intended purpose can itself cross the line into being treated as a device in its own regulatory right, not just a passive input feeding someone else's filing. A supplier making a part like that is not automatically off the hook just because someone else's name is on the final filing. Ask directly whether anything the supplier makes has ever been classified this way for a comparable customer.
That does not let the component maker off the hook. The finished-device manufacturer's own quality system has to control every outside supplier feeding into the device, the same extension ISO 9001's own purchasing clause requires for any externally provided process. Many medical device buyers prefer or require ISO 13485 certification for suppliers of critical components, since auditing every supplier's general manufacturing quality system from scratch does not scale. The exact requirement still depends on the component, the buyer's own QMS, the device's risk level and the target market, but for a component maker with no ISO 13485, being ISO 13485 certified is often the practical difference between getting seriously considered for medical device work and not.
Signs your current sourcing process is not ready for this
Before the how-to below, a quick self-check. If most of these are true for how a component search is currently running, the gap in the opening story is likely to repeat.
- Nobody on the buying side can say, plainly, whether the part being sourced counts as a component or a finished device under the relevant regulator.
- "ISO certified" has been treated as one bar, without checking whether the certificate is ISO 9001, ISO 13485 or both.
- No one has asked which ISO 10993 test panel actually applies to this part's material, patient contact type and contact duration.
- The RFQ never states whether biocompatibility testing is the supplier's responsibility, the buyer's or a third-party lab's.
- Nobody has checked whether the finished device is aimed at the US market, the Indian market, both or neither, since that changes which rules apply at all.
- The supplier has never been asked to show a real ISO 13485 audit report, only a certificate.
How to actually verify a supplier for medical device work
Step 1: Confirm what is actually being sourced. A raw machined component, a sub-assembly or a labeled finished device are three different regulatory situations. Get this straight before anything else, since it decides which of the four frameworks even apply to the supplier directly.
Step 2: Ask for the ISO 13485 certificate, then check four things on it, not just that it exists. The site: is the actual factory making your parts the one covered? The scope: does it cover the exact process and product type you need, not just "machining" in general? The validity: is it current? The certification body: can its accreditation be independently checked? A shop certified for general machining is not the same as one certified for medical device component manufacturing specifically and a certificate for a different site than the one making your parts is not evidence of anything.
Step 3: Ask who is responsible for ISO 10993 testing,and get that answer in writing before the order starts. Biocompatibility testing is usually commissioned by the finished-device manufacturer, tied to the specific material and use case and run by an accredited third-party lab, not performed by the component shop itself. What the shop controls is consistency: using the qualified material, following a validated cleaning process and not introducing an unapproved coating or process change that would invalidate testing already done on an earlier batch.
Step 4: If the finished device targets the US market, ask how the supplier's QMS lines up with the new QMSR. A supplier already certified to ISO 13485:2016 is most of the way there. Ask directly whether they are also familiar with FDA's specific additional requirements layered on top, since a straight ISO 13485 certificate does not automatically cover every FDA-specific point.
Step 5: If the finished device will be sold in India, confirm the classification and who holds the CDSCO license. Class A and B go through a Notified Body audit and a State Licensing Authority. Class C and D go through CDSCO's own Central Licensing Authority, a more involved process. Check the current classification for the specific device rather than assuming from the letter alone, since some Class A devices have been moved to a lighter registration path that skips full licensing entirely. This is usually the finished-device manufacturer's responsibility, not the component supplier's, but a buyer should still know which class applies, since it shapes how much documentation the whole supply chain needs to produce.
Step 6: Ask what happens when something changes. A supplier that changes a material source, a heat-treatment vendor, a cleaning chemistry, a coating, a subcontractor or an inspection method without telling you can quietly invalidate testing or documentation already on file. Get a straight answer, in writing, on when and how they notify you of a change like that before it happens, not after.
Step 7: For anything beyond a low-risk component, put a quality agreement in place, not just a purchase order. A quality agreement is the document that actually spells out acceptance criteria, change notification, nonconformance handling, CAPA, audit rights and record retention, the specifics a PO never covers. For a critical or patient-contact component, this is worth having signed before the first order, not after a problem.
Not every component needs the same depth of qualification
A non-patient-contact bracket and a blood-contact component are not the same qualification project and treating them identically wastes effort on the low-risk part while under-checking the high-risk one.
For a low-criticality component, a certificate review, sample approval and material documentation is often a reasonable bar. For a component that affects device performance or has repeated patient contact, add process traceability, change control and a documented process review. For an implant, sterile or blood-contact component, add a real supplier audit, a signed quality agreement, validated processes and full traceability before it ships.
Match the qualification effort to what the component actually touches and does, not to a single fixed checklist applied the same way every time.
Where AI actually helps in supplier qualification and where it does not
AI tools can genuinely help with the paperwork side of this: pulling scope and expiry dates off a certificate, comparing three suppliers' evidence side by side, flagging a document a checklist calls for that is missing or summarizing a long audit report into what actually changed.
What it cannot do is decide that a supplier is compliant. Whether a certificate is genuine, whether a process is actually validated and whether a specific supplier meets a specific regulator's bar are judgment calls that still need a person or the regulator itself, to make. Use it to find the gaps faster. Don't let it be the one that says the gap is closed.
What this does not mean
This is not a reason to assume every Indian precision shop is unsuited to medical device work. A shop that already runs ISO 13485 for other customers, understands cleaning validation and can produce real batch traceability records is doing the hard part already. The gap in the opening story was never about capability. It was about nobody checking which framework actually applied before the order started.
It is also not a reason to treat CDSCO and FDA requirements as interchangeable. A device cleared for the Indian market under CDSCO is not automatically cleared for the US market under FDA's QMSR and the reverse is also true. Each is its own filing, even when both ultimately lean on the same underlying ISO 13485 quality system.
Where this leaves you
Four frameworks, four different questions. ISO 13485 asks about the quality system. FDA's QMSR asks whether that system also meets the US-specific bar. ISO 10993 asks about the material itself. CDSCO asks what India's own regulator requires for that device class. A supplier can answer one of these well and never have been asked the other three.
The same discipline that applies to AS9100 in aerospace sourcing applies here: know which certification actually unlocks the work in front of you and verify the scope, not just the certificate. If the supplier's general quality system is still in question, the broader ISO 9001 guide is the right starting point before any of the four frameworks above come into play.
Related reading
Frequently asked questions
Does a component supplier need ISO 13485 to make medical device parts?
Not by law, in most cases, since the finished-device manufacturer usually holds the regulatory clearance. In practice, many medical device buyers prefer or require it for suppliers of critical components, because it is the standard proof that the supplier's quality system is built for this kind of work. The exact bar depends on the component's risk, the buyer's own QMS and the target market.
What is the difference between ISO 13485 and ISO 9001?
ISO 9001 is a general quality management standard for any industry. ISO 13485 is a standalone standard built specifically for medical devices, not a medical-flavored version of ISO 9001. The two no longer even share the same structure, since ISO 9001 moved to a different one in its 2015 revision, and ISO 13485 places an explicit risk-management focus running through the whole system rather than only the finished product.
What changed with FDA's QMSR in 2026?
As of February 2, 2026, the FDA replaced its old Quality System Regulation with a new Quality Management System Regulation that incorporates ISO 13485:2016 directly, on top of a short list of FDA-specific additional requirements. A manufacturer already certified to ISO 13485 is most of the way to meeting the new US rule, but not automatically certified to it.
What does ISO 10993 actually test?
It is a family of biological test methods that check whether a device's actual materials and manufacturing process are safe in contact with the human body, based on what the device touches, for how long, and how. It is not a management-system standard and does not get "passed" the way a certification audit does.
What is CDSCO and when does it apply?
CDSCO is India's medical device regulator, operating under the Medical Devices Rules, 2017. It classifies devices into four risk classes, A through D, and the licensing path gets more demanding as the class rises: Class A and B go through a Notified Body audit and a State Licensing Authority, Class C and D go through CDSCO's own Central Licensing Authority. It applies most directly to whoever holds the finished device's regulatory filing, not usually to a component supplier alone.
Can an Indian manufacturer without ISO 13485 still make medical device components?
Sometimes, for lower-risk components or with a buyer willing to extend their own oversight further into the supplier's process. It is a harder sell for most serious buyers, since ISO 13485 is the standard evidence a component supplier's quality system is actually built for this kind of work.
Is an ISO 13485 certified supplier automatically compliant with both FDA and CDSCO rules?
No. Both regulators lean on ISO 13485 as a foundation, but each layers its own specific requirements and its own filing process on top. Certification to ISO 13485 is a strong starting point, not a substitute for either agency's own requirements.
Ready for fewer, better conversations?
Augmino connects verified Indian manufacturers with buyers who mean business.
Apply to Join