Start a free trial
Menu

Standards · Pharma and medical devices

Which pharma and medical device rules apply to you?

EU GMP and its annexes, the ICH guidelines, 21 CFR, the MDR and the IVDR, ISO 13485 and ISO 14971, and the IEC standards for software as a medical device. Explained in plain words, in one catalogue, with every entry linked to its source.

Overview

Law, guidance, standard: three layers in both worlds

Medicinal products and medical devices are regulated differently, but the requirement reaches a manufacturer the same way in both.

  1. The law binds the manufacturer

    EU GMP as a condition of your licence, the MDR and the IVDR for a device, 21 CFR in the United States. An authority or a notified body checks that you meet it.

  2. Guidance says how inspectors read it

    The GMP annexes, the PIC/S guide, the ICH guidelines and the MDCG documents are what an inspector or an assessor expects to see, chapter by chapter.

  3. Standards are how you build the system

    ISO 13485 and ISO 14971 for a device, ICH Q10 for a pharmaceutical quality system, IEC 62304 for software, GAMP 5 for the computerised systems underneath.

  4. Data integrity runs through all of it

    Annex 11 and 21 CFR Part 11 put validation, audit trails and electronic signatures on every system that holds a regulated record. It is where most findings are written.

  5. Find yours below

    Search the catalogue by name, browse it by family, or answer five questions about what you make. Each entry links to its source and can be requested in ComplyTrain.

The law: EU GMP and the MDR, or 21 CFR in the United States binds you as a manufacturer. The standards and guidance below are how inspectors expect you to meet it. MEDICINAL PRODUCTS EU GMP Part I · Part II the manufacturing practice a licence requires Annex 1 · 11 · 15 · 16 sterile · computerised · validation · release + ICH Q7 · Q9 risk · Q10 quality system · PIC/S Inspected. Your authority licenses you. MEDICAL DEVICES MDR · IVDR classification, conformity, the technical file ISO 13485 · ISO 14971 the quality system · the risk process + IEC 62304 software · 62366-1 · 60601-1 · ISO 10993 CE-marked. A notified body assesses you. COMPUTERISED SYSTEMS AND DATA Annex 11 · 21 CFR Part 11 electronic records and signatures, audit trails GAMP 5 · PIC/S PI 041 the validation practice · data integrity + MDCG 2019-11 · IMDRF for software as a device The same expectations on both sides. shares the QMS validated by ISO 9001 is the shape underneath both quality systems; ISO 13485 and ICH Q10 add what a regulator expects on top of it. The FDA's Part 820 aligns with ISO 13485 from February 2026, so one device quality system now serves the EU and the US. HOW A PHARMA OR DEVICE REQUIREMENT REACHES A MANUFACTURER · COMPLYTRAIN BY SKYLEN
How a pharma or device requirement reaches a manufacturer: the law binds you; EU GMP with its annexes, ICH and PIC/S cover medicinal products; the MDR and IVDR with ISO 13485, ISO 14971 and the IEC standards cover devices; Annex 11, Part 11, GAMP 5 and PI 041 cover the systems and the data.

The rules a pharma or medical-device company works under

Two regulated worlds sit on this page, medicinal products and medical devices, and they share one shape. A law binds the manufacturer: you cannot make or sell without meeting it, and an authority or a notified body checks that you do. Guidance says how the inspectors expect the law to be met. And standards, mostly ISO and IEC, are how the industry builds the system that meets both. This page explains the three layers for each world, the computerised systems and the data that run through both, and where the documents come from. The explorer below then finds the ones that match what you make.

Medicinal products: good manufacturing practice

A manufacturing authorisation for a medicinal product in the EU is conditional on good manufacturing practice, and EudraLex Volume 4 is the guide every inspector uses. Part I covers finished products in nine chapters: the pharmaceutical quality system, personnel, premises and equipment, documentation, production, quality control, outsourced activities, complaints and recalls, and self-inspection. Part II covers active substances and is the EU's adoption of ICH Q7. The annexes carry the specifics: Annex 1, revised in 2022, for sterile products and the contamination control strategy behind them; Annex 11 for computerised systems; Annex 15 for qualification and validation; Annex 16 for what the Qualified Person certifies before a batch is released. The PIC/S guide is the same text harmonised for the fifty-plus authorities in the scheme, and the one an inspector from outside the EU works from.

In the United States, 21 CFR Parts 210 and 211 are the current good manufacturing practice regulations, and 21 CFR Part 11 sets the rules for electronic records and electronic signatures. The FDA takes part in PIC/S and the expectations are the same on both sides; what differs is the letter of the regulation an inspector cites.

ICH: the guidelines behind the quality system

The International Council for Harmonisation brings the regulators and industry of Europe, the United States, Japan and a growing list of others together to write one guideline that each region then adopts. Q7 is GMP for active substances. Q8 is pharmaceutical development, the origin of quality by design, the design space and the control strategy. Q9, revised in 2023, is quality risk management: the process, its tools and how formal to be. Q10 is the pharmaceutical quality system: management responsibility, process performance monitoring, corrective and preventive action, change management and management review, built on ISO quality concepts and on GMP. Q12 covers post-approval change through established conditions. E6, revised in 2025, is good clinical practice for trials. Q8, Q9 and Q10 together are the design of a modern quality system, and Q10 is what a pharmaceutical quality system audit measures you against. ISO 9001 is the shape underneath; see ISO 9001 and, for the risk process Q9 asks for, the risk management page.

Computerised systems and data integrity

Any system that creates, stores or signs a GMP record is in scope, from a laboratory information system and a manufacturing execution system to the quality software itself and a validated spreadsheet. Annex 11 and 21 CFR Part 11 say what such a system must do: be validated for its intended use, keep an audit trail, control access, and make an electronic signature as binding as a handwritten one. GAMP 5, in its 2022 second edition, is the industry's guide to doing that with a risk-based approach and without validating what does not need it. PIC/S PI 041 is the inspectors' guidance on data integrity, the ALCOA+ principles that a record must be attributable, legible, contemporaneous, original and accurate, and complete, consistent, enduring and available. Data integrity is where most GMP findings of the last decade have been written.

Medical devices: the MDR, the IVDR and the standards under them

Regulation (EU) 2017/745, the MDR, applies since May 2021 and Regulation (EU) 2017/746, the IVDR, since May 2022, with transition periods for devices certified under the old directives. Both work the same way: the intended purpose and the classification rules put a device in a class, everything above class I is assessed by a notified body, the general safety and performance requirements in Annex I must be met and the technical documentation in Annexes II and III must show it, a clinical evaluation must support every claim, and post-market surveillance, vigilance and the unique device identifier run for the life of the product. In the United States, 21 CFR Part 820 is the quality system regulation, and from February 2026 it incorporates ISO 13485, so one device quality system now serves both markets.

Harmonised standards give a presumption of conformity with the regulation, and they are the standards a notified body audits. ISO 13485 is the quality management system, ISO 9001 in shape with what a regulator expects on top. ISO 14971 is risk management for devices, the file every design decision traces back to, with ISO/TR 24971 as its worked guidance. IEC 60601-1 covers electrical safety, IEC 62366-1 usability engineering, ISO 10993 the biological evaluation of anything in contact with the body, ISO 14155 clinical investigations, ISO 15223-1 and ISO 20417 the symbols and the information supplied with a device, and ISO 11607 the sterile barrier.

Software as a medical device

Software is a medical device when its intended purpose is medical, and since the MDR that includes a great deal of decision-support and monitoring software that was class I under the directives and is class IIa or higher now. MDCG 2019-11 is the guidance on when software qualifies and how it classifies; the IMDRF documents on software as a medical device define the term, categorise the risk and describe the clinical evaluation regulators in every major market use. The standards then follow the life cycle. IEC 62304 sets the software life-cycle processes by safety class, from planning and requirements through architecture, verification, release and maintenance. IEC 82304-1 covers health software sold as a product on general-purpose hardware. IEC 62366-1 covers the usability engineering the interface needs, ISO 14971 the risk file, and IEC 81001-5-1 with MDCG 2019-16 the cybersecurity a connected device must design in. Software in a device, embedded firmware, follows IEC 62304 too.

Where the documents come from

EudraLex, the MDCG guidance and the EU regulations are free from the European Commission and EUR-Lex; PIC/S and ICH publish their guidelines free of charge; the Code of Federal Regulations is free on the eCFR. The ISO and IEC standards are bought from ISO, IEC or your national standards body, GAMP 5 from ISPE, and the IMDRF documents are free. Every entry in the explorer below links to its source.

Who decides what applies to you

Not this page, and not us. For a medicinal product it is the marketing authorisation and your manufacturing licence; for a device it is the intended purpose you declare and the class it puts you in; and in both worlds the inspector, the notified body and your customers' supplier audits decide what evidence they expect to see. What the explorer can do is show you the whole map: search it by name, browse it by family, or answer five questions about what you make and see which areas manufacturers like you are commonly asked about. Each entry links to its source, to its ComplyTrain page where one exists, and otherwise to a request. ComplyTrain holds a standard as a requirement tree with the evidence against each requirement. The licence and the certificate stay yours to earn.

Standards explorer

Find your pharma and medical device standards

Search EU GMP and its annexes, the ICH guidelines, 21 CFR, the MDR and IVDR and the ISO and IEC device standards together, browse them by family, or answer five questions about what you make.

62 standards in the catalogue

Not sure where to start?

Five questions, pick everything that applies. Nothing is stored.

Question 1 of 5What do you make or do?
Question 2 of 5Which markets?
Question 3 of 5Who inspects or assesses you?
Question 4 of 5Where in the life cycle is your work?
Question 5 of 5What are you asked to show?
ISO management systems14 standards
  1. EN 9100Quality Management Systems - Requirements for Aviation, Space and Defence OrganizationsEd. 2018How ComplyTrain supports itISO 9001 plus the aerospace and defence supply chain's additional requirements (AS9100 in the Americas).
  2. ISO 10007Quality management - Guidelines for configuration managementEd. 2017Configuration management guidance, the civil counterpart to ACMP-2000 series.
  3. ISO 14001Environmental management systems - Requirements with guidance for useEd. 2015Environmental management: how an organisation controls its environmental impact and obligations.
  4. ISO 19443Quality management systems - Specific requirements for the application of ISO 9001:2015 by organizations in the supply chain of the nuclear energy sector supplying products and services important to nuclear safety (ITNS)Ed. 2018ISO 9001 with the additional requirements of the nuclear supply chain.
  5. ISO 28000Security and resilience - Security management systems - RequirementsEd. 2022Security management across the supply chain.
  6. ISO 37001Anti-bribery management systems - Requirements with guidance for useEd. 2016Anti-bribery controls, often asked for in public procurement and export markets.
  7. ISO 37301Compliance management systems - Requirements with guidance for useEd. 2021A management system for meeting legal and contractual compliance obligations.
  8. ISO 45001Occupational health and safety management systems - Requirements with guidance for useEd. 2018Occupational health and safety management, the successor to OHSAS 18001.
  9. ISO 50001Energy management systems - Requirements with guidance for useEd. 2018Energy management: measuring and improving energy performance.
  10. ISO 55001Asset management - Management systems - RequirementsEd. 2014Managing physical assets over their life cycle.
  11. ISO 9001Quality management systems - RequirementsEd. 2015How ComplyTrain supports itThe general-purpose quality management system standard most defence and industrial contracts start from.
  12. ISO/IEC 17025General requirements for the competence of testing and calibration laboratoriesEd. 2017Competence requirements for test and calibration laboratories.
  13. ISO/IEC 20000-1Information technology - Service management - Part 1: Service management system requirementsEd. 2018IT service management, the certifiable counterpart to ITIL.
  14. ISO/IEC 42001Information technology - Artificial intelligence - Management systemEd. 2023The first management system standard for organisations that build or use AI.
Good manufacturing practice11 standards
  1. 21 CFR Part 11Electronic Records; Electronic SignaturesEd. 2024When an electronic record or signature is trustworthy and equivalent to paper: audit trails, controls, validation.
  2. 21 CFR Part 211Current Good Manufacturing Practice for Finished PharmaceuticalsEd. 2024The US cGMP regulation for finished drug products; Part 210 sets the general provisions.
  3. EU GMP Annex 1EudraLex Volume 4, Annex 1: Manufacture of sterile medicinal productsEd. 2022The 2022 revision: contamination control strategy, cleanroom design, aseptic processing and monitoring.
  4. EU GMP Annex 11EudraLex Volume 4, Annex 11: Computerised systemsEd. 2011Validation, data integrity, audit trails, electronic signatures and supplier control for computerised systems in GMP.
  5. EU GMP Annex 15EudraLex Volume 4, Annex 15: Qualification and validationEd. 2015The life-cycle approach to qualification of equipment and validation of processes, cleaning and transport.
  6. EU GMP Annex 16EudraLex Volume 4, Annex 16: Certification by a Qualified Person and batch releaseEd. 2015What the Qualified Person certifies before a batch is released, and what they rely on.
  7. EU GMP Part IEudraLex Volume 4, Part I: Basic requirements for medicinal productsEd. 2022The good manufacturing practice guide for medicinal products in the EU: quality management, personnel, premises, documentation, production, quality control.
  8. EU GMP Part IIEudraLex Volume 4, Part II: Basic requirements for active substances used as starting materialsEd. 2014GMP for active pharmaceutical ingredients, the EU adoption of ICH Q7.
  9. GAMP 5GAMP 5, second edition: A Risk-Based Approach to Compliant GxP Computerized SystemsEd. 2022The industry guide to validating computerised systems in GxP, the practice behind Annex 11 and Part 11.
  10. PIC/S PE 009PIC/S Guide to Good Manufacturing Practice for Medicinal ProductsEd. 2023The GMP guide the 50-plus PIC/S authorities inspect against, harmonised with EU GMP.
  11. PIC/S PI 041PIC/S Good Practices for Data Management and Integrity in Regulated GMP/GDP EnvironmentsEd. 2021The inspectors' guidance on data integrity: ALCOA+, audit trails, data governance.
ICH guidelines6 standards
  1. ICH E6ICH E6(R3): Good Clinical PracticeEd. 2025The standard for designing, conducting and reporting clinical trials that involve human participants.
  2. ICH Q10ICH Q10: Pharmaceutical Quality SystemEd. 2008The pharmaceutical quality system model across the product life cycle, built on ISO quality concepts and GMP.
  3. ICH Q12ICH Q12: Technical and Regulatory Considerations for Pharmaceutical Product Lifecycle ManagementEd. 2019Managing post-approval changes through established conditions and a product lifecycle management document.
  4. ICH Q7ICH Q7: Good Manufacturing Practice Guide for Active Pharmaceutical IngredientsEd. 2000GMP for active substances, adopted in the EU as GMP Part II and by the FDA as guidance.
  5. ICH Q8ICH Q8(R2): Pharmaceutical DevelopmentEd. 2009Quality by design: the design space, critical quality attributes and the control strategy.
  6. ICH Q9ICH Q9(R1): Quality Risk ManagementEd. 2023The pharmaceutical quality risk management process and its tools, revised in 2023 for formality and subjectivity.
Medical devices and health software19 standards
  1. ISO 10993-1Biological evaluation of medical devices - Part 1: Evaluation and testing within a risk management processEd. 2018Biocompatibility: which biological endpoints to evaluate for a device in contact with the body.
  2. ISO 11607-1Packaging for terminally sterilized medical devices - Part 1: Requirements for materials, sterile barrier systems and packaging systemsEd. 2019The sterile barrier: materials, design and validation of packaging for sterile devices.
  3. ISO 13485Medical devices - Quality management systems - Requirements for regulatory purposesEd. 2016Quality management for medical device manufacturers and their suppliers.
  4. ISO 14155Clinical investigation of medical devices for human subjects - Good clinical practiceEd. 2020Good clinical practice for clinical investigations of medical devices.
  5. ISO 14971Medical devices - Application of risk management to medical devicesEd. 2019The risk management process every medical device file is built on: hazard identification, estimation, control and residual risk.
  6. ISO 15223-1Medical devices - Symbols to be used with information to be supplied by the manufacturer - Part 1: General requirementsEd. 2021The symbols on device labels and their meaning.
  7. ISO 20417Medical devices - Information to be supplied by the manufacturerEd. 2021What the label, the instructions for use and the packaging must say.
  8. IEC 60601-1Medical electrical equipment - Part 1: General requirements for basic safety and essential performanceEd. 2020The electrical safety standard for medical equipment, with its collateral and particular standards.
  9. IEC 62304Medical device software - Software life cycle processesEd. 2015The life-cycle processes for software that is or is part of a medical device, by safety class A, B or C.
  10. IEC 62366-1Medical devices - Part 1: Application of usability engineering to medical devicesEd. 2020Usability engineering for medical devices: use errors, formative and summative evaluation.
  11. IEC 81001-5-1Health software and health IT systems safety, effectiveness and security - Part 5-1: Security - Activities in the product life cycleEd. 2021The secure development life cycle for health software and connected devices, the standard notified bodies read for cybersecurity.
  12. IEC 82304-1Health software - Part 1: General requirements for product safetyEd. 2016Safety and security requirements for health software products that run on general-purpose IT, including software as a medical device.
  13. 21 CFR Part 820Quality Management System Regulation (QMSR)Ed. 2024The US medical device quality system regulation, aligned with ISO 13485 from February 2026.
  14. IVDRRegulation (EU) 2017/746 on in vitro diagnostic medical devicesEd. 2017The EU regulation for in vitro diagnostics, with its own classification and performance evaluation.
  15. MDRRegulation (EU) 2017/745 on medical devicesEd. 2017The EU medical device regulation: classification, conformity assessment, the technical documentation, post-market surveillance and UDI.
  16. IMDRF SaMD N41Software as a Medical Device (SaMD): Clinical EvaluationEd. 2017The international regulators' framework for software as a medical device: definitions, risk categorisation and clinical evaluation.
  17. ISO/TR 24971Medical devices - Guidance on the application of ISO 14971Ed. 2020How to apply ISO 14971 in practice, with the worked examples the standard itself leaves out.
  18. MDCG 2019-11Guidance on qualification and classification of software in Regulation (EU) 2017/745 and 2017/746Ed. 2019When software is a medical device under the MDR and IVDR, and how it is classified.
  19. MDCG 2019-16Guidance on Cybersecurity for medical devicesEd. 2020How the MDR's general safety and performance requirements apply to the cybersecurity of a device, pre-market and post-market.
Risk management standards and methods12 standards
  1. ISO 22301Security and resilience - Business continuity management systems - RequirementsEd. 2019Business continuity management: keeping the organisation running through disruption.
  2. ISO 31000Risk management - GuidelinesEd. 2018How ComplyTrain supports itPrinciples and a framework for managing risk. Guidance, not a certifiable requirement set.
  3. ISO/IEC 23894Information technology - Artificial intelligence - Guidance on risk managementEd. 2023ISO 31000 applied to AI systems: the sources of risk particular to them and how to manage them across the life cycle.
  4. FAIROpen FAIR Risk Analysis Standard (O-RA)Ed. 2021Factor Analysis of Information Risk: quantifying cyber risk in loss event frequency and magnitude rather than colours.
  5. IEC 31010Risk management - Risk assessment techniquesEd. 2019The catalogue of risk assessment techniques, from brainstorming and checklists to FMEA, HAZOP, bow-tie and Monte Carlo, and when each fits.
  6. IEC 60812Failure modes and effects analysis (FMEA and FMECA)Ed. 2018The method standard for FMEA and FMECA, used in reliability, safety and process risk work.
  7. IEC 61508Functional safety of electrical/electronic/programmable electronic safety-related systemsEd. 2010The umbrella functional safety standard: safety integrity levels and the safety life cycle that sector standards derive from.
  8. IEC 61882Hazard and operability studies (HAZOP studies) - Application guideEd. 2016The structured team study that finds deviations in a process design and their consequences.
  9. NIST AI RMFArtificial Intelligence Risk Management Framework (AI RMF 1.0)Ed. 2023Four functions, Govern, Map, Measure and Manage, for the risks of AI systems, voluntary and sector-neutral.
  10. NIST SP 800-30Guide for Conducting Risk Assessments (Rev. 1)Ed. 2012How to run an information security risk assessment: threat sources, events, vulnerabilities, likelihood and impact.
  11. NIST SP 800-37Risk Management Framework for Information Systems and Organizations (Rev. 2)Ed. 2018The seven-step framework, Prepare to Monitor, that ties categorisation, control selection, assessment and authorisation together.
  12. COSO ERMEnterprise Risk Management - Integrating with Strategy and PerformanceEd. 2017The enterprise risk management framework used in corporate governance and financial reporting.

Titles belong to their publishers. The one-line summaries are ours.

Request access to work with this standard in ComplyTrain

Shortlist

Standards with their own page

Each page sets out what the standard asks of you and how a ComplyTrain workspace is organised around it. The catalogue above holds far more than these, and any entry in it can be requested. Adding a standard to a workspace is usually a matter of days, not a project.

  • ISO 9001

    ISO 9001 quality management

    ISO 9001 is the international standard for quality management systems. ComplyTrain is structured around its clause structure, so your QMS is audit-ready by design.

If you need to get there and have no quality function

A standard usually arrives as a contract condition or a regulator's letter rather than a project anyone planned for, and often at a company with no quality manager. Software is half the answer. Skylen's consultants are the other half, and because they build on ComplyTrain from day one you keep a live system your team owns rather than a binder and a departed consultant.

  • Gap assessment

    A clause-by-clause read of where you stand against the standard your contract or your regulator cites, turned into a prioritised plan you could act on with us or alone.

    What an assessment covers
  • Guided implementation

    Our consultants build the system with your team - procedures, document control, the records you need to keep and the review cadence - and prepare you for the audit or the inspection.

    How an engagement works
  • Full-service quality function

    We run and maintain the system for you, so a small team can reach and hold a standard without hiring a quality manager.

    What full-service means

Questions people ask about pharma and device rules

Is ISO 13485 mandatory for a medical device?

Not by name. The MDR requires a quality management system and lists what it must cover; ISO 13485 is the harmonised standard that gives a presumption of conformity with that requirement, and it is what a notified body audits. In practice every manufacturer above class I holds it. In the United States, 21 CFR Part 820 incorporates ISO 13485 from February 2026, so the same system serves both markets.

What is the difference between GMP and ISO 9001?

ISO 9001 is a voluntary standard for a quality management system that a certification body audits. GMP is law: a condition of your manufacturing licence, inspected by your medicines authority, with detailed rules for premises, batch records, release and the rest. ICH Q10 describes a pharmaceutical quality system built on ISO quality concepts and on GMP, which is how the two fit together. See ISO 9001.

Is our software a medical device?

It depends on its intended purpose, not on its technology. Software intended to provide information used for a medical decision, or to monitor a physiological process, is a device under the MDR, and MDCG 2019-11 walks through the qualification step by step. Software that only stores, communicates or searches data is not. A wrong answer here is expensive in both directions, so it is a question for regulatory counsel before development starts.

What does data integrity actually require?

That every GMP record can be trusted: it is attributable to who made it, legible, made at the time, the original or a true copy, and accurate, and that it is complete, consistent, enduring and available for its retention period. Annex 11 and 21 CFR Part 11 put that on computerised systems as validation, audit trails, access control and electronic signatures. PIC/S PI 041 is the inspectors' own guidance on what they look for.

Which annexes of EU GMP apply to us?

Part I and, if you handle active substances, Part II apply to everyone with a manufacturing authorisation. Annex 11 applies to anyone with a computerised system in GMP, which is everyone; Annex 15 to anyone qualifying equipment or validating a process; Annex 16 to batch certification. The rest depend on what you make: Annex 1 for sterile products, Annex 2 for biologicals, Annex 3 for radiopharmaceuticals, and so on. Your licence and your product list say which.

Does ComplyTrain certify us against a standard?

No. Certification is issued by an accredited certification body, a licence by your authority, and government quality assurance is exercised by the acquisition authority. ComplyTrain is the system you build, run and evidence your compliance in, and Skylen's consultants can take you through the work. The certificate stays yours to earn.

Can I get a standard added to ComplyTrain?

Yes, and that is what the Request access button on every entry is for. Tell us which standard and where the requirement comes from, and we come back to you on what holding it in your workspace involves, usually within one business day. Adding a standard to a workspace is usually a matter of days, not a project. ComplyTrain holds a standard as a requirement tree with your evidence against each requirement, and the tree is what we build.

Request access to work with a standard, a guideline or a regulation

Name the document and where the requirement comes from, and we come back to you on what holding it in your workspace involves.

See ComplyTrain on your own quality system

Book a 30-minute demo with your quality or regulatory lead - the product organised around the rules you answer to.