Start a free trial
Menu

Standards · Pharma and medical devices

Which pharma and medical device rules apply to you?

EU GMP and its annexes, the ICH guidelines, 21 CFR, the MDR and the IVDR, ISO 13485 and ISO 14971, and the IEC standards for software as a medical device. Explained in plain words, in one catalogue, with every entry linked to its source.

Overview

Law, guidance, standard: three layers in both worlds

Medicinal products and medical devices are regulated differently, but the requirement reaches a manufacturer the same way in both.

  1. The law binds the manufacturer

    EU GMP as a condition of your licence, the MDR and the IVDR for a device, 21 CFR in the United States. An authority or a notified body checks that you meet it.

  2. Guidance says how inspectors read it

    The GMP annexes, the PIC/S guide, the ICH guidelines and the MDCG documents are what an inspector or an assessor expects to see, chapter by chapter.

  3. Standards are how you build the system

    ISO 13485 and ISO 14971 for a device, ICH Q10 for a pharmaceutical quality system, IEC 62304 for software, GAMP 5 for the computerised systems underneath.

  4. Data integrity runs through all of it

    Annex 11 and 21 CFR Part 11 put validation, audit trails and electronic signatures on every system that holds a regulated record. It is where most findings are written.

  5. Find yours below

    Search the catalogue by name, browse it by family, or answer five questions about what you make. Each entry links to its source and can be requested in ComplyTrain.

The law: EU GMP and the MDR, or 21 CFR in the United States binds you as a manufacturer. The standards and guidance below are how inspectors expect you to meet it. MEDICINAL PRODUCTS EU GMP Part I · Part II the manufacturing practice a licence requires Annex 1 · 11 · 15 · 16 sterile · computerised · validation · release + ICH Q7 · Q9 risk · Q10 quality system · PIC/S Inspected. Your authority licenses you. MEDICAL DEVICES MDR · IVDR classification, conformity, the technical file ISO 13485 · ISO 14971 the quality system · the risk process + IEC 62304 software · 62366-1 · 60601-1 · ISO 10993 CE-marked. A notified body assesses you. COMPUTERISED SYSTEMS AND DATA Annex 11 · 21 CFR Part 11 electronic records and signatures, audit trails GAMP 5 · PIC/S PI 041 the validation practice · data integrity + MDCG 2019-11 · IMDRF for software as a device The same expectations on both sides. shares the QMS validated by ISO 9001 is the shape underneath both quality systems; ISO 13485 and ICH Q10 add what a regulator expects on top of it. The FDA's Part 820 aligns with ISO 13485 from February 2026, so one device quality system now serves the EU and the US. HOW A PHARMA OR DEVICE REQUIREMENT REACHES A MANUFACTURER · COMPLYTRAIN BY SKYLEN
How a pharma or device requirement reaches a manufacturer: the law binds you; EU GMP with its annexes, ICH and PIC/S cover medicinal products; the MDR and IVDR with ISO 13485, ISO 14971 and the IEC standards cover devices; Annex 11, Part 11, GAMP 5 and PI 041 cover the systems and the data.

The rules a pharma or medical-device company works under

Two regulated worlds sit on this page, medicinal products and medical devices, and they share one shape. A law binds the manufacturer: you cannot make or sell without meeting it, and an authority or a notified body checks that you do. Guidance says how the inspectors expect the law to be met. And standards, mostly ISO and IEC, are how the industry builds the system that meets both. This page explains the three layers for each world, the computerised systems and the data that run through both, and where the documents come from. The explorer below then finds the ones that match what you make.

Medicinal products: good manufacturing practice

A manufacturing authorisation for a medicinal product in the EU is conditional on good manufacturing practice, and EudraLex Volume 4 is the guide every inspector uses. Part I covers finished products in nine chapters: the pharmaceutical quality system, personnel, premises and equipment, documentation, production, quality control, outsourced activities, complaints and recalls, and self-inspection. Part II covers active substances and is the EU's adoption of ICH Q7. The annexes carry the specifics: Annex 1, revised in 2022, for sterile products and the contamination control strategy behind them; Annex 11 for computerised systems; Annex 15 for qualification and validation; Annex 16 for what the Qualified Person certifies before a batch is released. The PIC/S guide is the same text harmonised for the fifty-plus authorities in the scheme, and the one an inspector from outside the EU works from.

In the United States, 21 CFR Parts 210 and 211 are the current good manufacturing practice regulations, and 21 CFR Part 11 sets the rules for electronic records and electronic signatures. The FDA takes part in PIC/S and the expectations are the same on both sides; what differs is the letter of the regulation an inspector cites.

ICH: the guidelines behind the quality system

The International Council for Harmonisation brings the regulators and industry of Europe, the United States, Japan and a growing list of others together to write one guideline that each region then adopts. Q7 is GMP for active substances. Q8 is pharmaceutical development, the origin of quality by design, the design space and the control strategy. Q9, revised in 2023, is quality risk management: the process, its tools and how formal to be. Q10 is the pharmaceutical quality system: management responsibility, process performance monitoring, corrective and preventive action, change management and management review, built on ISO quality concepts and on GMP. Q12 covers post-approval change through established conditions. E6, revised in 2025, is good clinical practice for trials. Q8, Q9 and Q10 together are the design of a modern quality system, and Q10 is what a pharmaceutical quality system audit measures you against. ISO 9001 is the shape underneath; see ISO 9001 and, for the risk process Q9 asks for, the risk management page.

Computerised systems and data integrity

Any system that creates, stores or signs a GMP record is in scope, from a laboratory information system and a manufacturing execution system to the quality software itself and a validated spreadsheet. Annex 11 and 21 CFR Part 11 say what such a system must do: be validated for its intended use, keep an audit trail, control access, and make an electronic signature as binding as a handwritten one. GAMP 5, in its 2022 second edition, is the industry's guide to doing that with a risk-based approach and without validating what does not need it. PIC/S PI 041 is the inspectors' guidance on data integrity, the ALCOA+ principles that a record must be attributable, legible, contemporaneous, original and accurate, and complete, consistent, enduring and available. Data integrity is where most GMP findings of the last decade have been written.

Medical devices: the MDR, the IVDR and the standards under them

Regulation (EU) 2017/745, the MDR, applies since May 2021 and Regulation (EU) 2017/746, the IVDR, since May 2022, with transition periods for devices certified under the old directives. Both work the same way: the intended purpose and the classification rules put a device in a class, everything above class I is assessed by a notified body, the general safety and performance requirements in Annex I must be met and the technical documentation in Annexes II and III must show it, a clinical evaluation must support every claim, and post-market surveillance, vigilance and the unique device identifier run for the life of the product. In the United States, 21 CFR Part 820 is the quality system regulation, and from February 2026 it incorporates ISO 13485, so one device quality system now serves both markets.

Harmonised standards give a presumption of conformity with the regulation, and they are the standards a notified body audits. ISO 13485 is the quality management system, ISO 9001 in shape with what a regulator expects on top. ISO 14971 is risk management for devices, the file every design decision traces back to, with ISO/TR 24971 as its worked guidance. IEC 60601-1 covers electrical safety, IEC 62366-1 usability engineering, ISO 10993 the biological evaluation of anything in contact with the body, ISO 14155 clinical investigations, ISO 15223-1 and ISO 20417 the symbols and the information supplied with a device, and ISO 11607 the sterile barrier.

Software as a medical device

Software is a medical device when its intended purpose is medical, and since the MDR that includes a great deal of decision-support and monitoring software that was class I under the directives and is class IIa or higher now. MDCG 2019-11 is the guidance on when software qualifies and how it classifies; the IMDRF documents on software as a medical device define the term, categorise the risk and describe the clinical evaluation regulators in every major market use. The standards then follow the life cycle. IEC 62304 sets the software life-cycle processes by safety class, from planning and requirements through architecture, verification, release and maintenance. IEC 82304-1 covers health software sold as a product on general-purpose hardware. IEC 62366-1 covers the usability engineering the interface needs, ISO 14971 the risk file, and IEC 81001-5-1 with MDCG 2019-16 the cybersecurity a connected device must design in. Software in a device, embedded firmware, follows IEC 62304 too.

Where the documents come from

EudraLex, the MDCG guidance and the EU regulations are free from the European Commission and EUR-Lex; PIC/S and ICH publish their guidelines free of charge; the Code of Federal Regulations is free on the eCFR. The ISO and IEC standards are bought from ISO, IEC or your national standards body, GAMP 5 from ISPE, and the IMDRF documents are free. Every entry in the explorer below links to its source.

Who decides what applies to you

Not this page, and not us. For a medicinal product it is the marketing authorisation and your manufacturing licence; for a device it is the intended purpose you declare and the class it puts you in; and in both worlds the inspector, the notified body and your customers' supplier audits decide what evidence they expect to see. What the explorer can do is show you the whole map: search it by name, browse it by family, or answer five questions about what you make and see which areas manufacturers like you are commonly asked about. Each entry links to its source, to its ComplyTrain page where one exists, and otherwise to a request. ComplyTrain holds a standard as a requirement tree with the evidence against each requirement. The licence and the certificate stay yours to earn.

Standards explorer

Find your pharma and medical device standards

Search EU GMP and its annexes, the ICH guidelines, 21 CFR, the MDR and IVDR and the ISO and IEC device standards together, browse them by family, or answer five questions about what you make.

62 standards in the catalogue

Not sure where to start?

Five questions, pick everything that applies. Nothing is stored.

Question 1 of 5What do you make or do?
Question 2 of 5Which markets?
Question 3 of 5Who inspects or assesses you?
Question 4 of 5Where in the life cycle is your work?
Question 5 of 5What are you asked to show?
ISO management systems14 standards
  1. EN 9100AS9100 and EN 9100: the aerospace quality standardRead moreOne aerospace quality standard published under three names: AS9100 in the Americas, EN 9100 in Europe, JISQ 9100 in Asia-Pacific. It contains ISO 9001 in full and adds the requirements aviation, space and defence put on top.↗
  2. ISO 10007Quality management - Guidelines for configuration managementRead moreQuality management - Guidelines for configuration management↗
  3. ISO 14001Environmental management systems - Requirements with guidance for useRead moreEnvironmental management systems - Requirements with guidance for use↗
  4. ISO 19443Quality management systems - Specific requirements for the application of ISO 9001:2015 by organizations in the supply chain of the nuclear energy sector supplying products and services important to nuclear safety (ITNS)Read moreQuality management systems - Specific requirements for the application of ISO 9001:2015 by organizations in the supply chain of the nuclear energy sector supplying products and services important to nuclear safety (ITNS)↗
  5. ISO 28000Security and resilience - Security management systems - RequirementsRead moreSecurity and resilience - Security management systems - Requirements↗
  6. ISO 37001Anti-bribery management systems - Requirements with guidance for useRead moreAnti-bribery management systems - Requirements with guidance for use↗
  7. ISO 37301Compliance management systems - Requirements with guidance for useRead moreCompliance management systems - Requirements with guidance for use↗
  8. ISO 45001Occupational health and safety management systems - Requirements with guidance for useRead moreOccupational health and safety management systems - Requirements with guidance for use↗
  9. ISO 50001Energy management systems - Requirements with guidance for useRead moreEnergy management systems - Requirements with guidance for use↗
  10. ISO 55001Asset management - Management systems - RequirementsRead moreAsset management - Management systems - Requirements↗
  11. ISO 9001ISO 9001 quality managementRead moreISO 9001 is the international standard for quality management systems. ComplyTrain is structured around its clause structure, so your QMS is audit-ready by design.↗
  12. ISO/IEC 17025General requirements for the competence of testing and calibration laboratoriesRead moreGeneral requirements for the competence of testing and calibration laboratories↗
  13. ISO/IEC 20000-1Information technology - Service management - Part 1: Service management system requirementsRead moreInformation technology - Service management - Part 1: Service management system requirements↗
  14. ISO/IEC 42001Information technology - Artificial intelligence - Management systemRead moreInformation technology - Artificial intelligence - Management system↗
Good manufacturing practice11 standards
  1. 21 CFR Part 11Electronic Records; Electronic SignaturesRead moreElectronic Records; Electronic Signatures↗
  2. 21 CFR Part 211Current Good Manufacturing Practice for Finished PharmaceuticalsRead moreCurrent Good Manufacturing Practice for Finished Pharmaceuticals↗
  3. EU GMP Annex 1EudraLex Volume 4, Annex 1: Manufacture of sterile medicinal productsRead moreEudraLex Volume 4, Annex 1: Manufacture of sterile medicinal products↗
  4. EU GMP Annex 11EudraLex Volume 4, Annex 11: Computerised systemsRead moreEudraLex Volume 4, Annex 11: Computerised systems↗
  5. EU GMP Annex 15EudraLex Volume 4, Annex 15: Qualification and validationRead moreEudraLex Volume 4, Annex 15: Qualification and validation↗
  6. EU GMP Annex 16EudraLex Volume 4, Annex 16: Certification by a Qualified Person and batch releaseRead moreEudraLex Volume 4, Annex 16: Certification by a Qualified Person and batch release↗
  7. EU GMP Part IEudraLex Volume 4, Part I: Basic requirements for medicinal productsRead moreEudraLex Volume 4, Part I: Basic requirements for medicinal products↗
  8. EU GMP Part IIEudraLex Volume 4, Part II: Basic requirements for active substances used as starting materialsRead moreEudraLex Volume 4, Part II: Basic requirements for active substances used as starting materials↗
  9. GAMP 5GAMP 5, second edition: A Risk-Based Approach to Compliant GxP Computerized SystemsRead moreGAMP 5, second edition: A Risk-Based Approach to Compliant GxP Computerized Systems↗
  10. PIC/S PE 009PIC/S Guide to Good Manufacturing Practice for Medicinal ProductsRead morePIC/S Guide to Good Manufacturing Practice for Medicinal Products↗
  11. PIC/S PI 041PIC/S Good Practices for Data Management and Integrity in Regulated GMP/GDP EnvironmentsRead morePIC/S Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments↗
ICH guidelines6 standards
  1. ICH E6ICH E6(R3): Good Clinical PracticeRead moreICH E6(R3): Good Clinical Practice↗
  2. ICH Q10ICH Q10: Pharmaceutical Quality SystemRead moreICH Q10: Pharmaceutical Quality System↗
  3. ICH Q12ICH Q12: Technical and Regulatory Considerations for Pharmaceutical Product Lifecycle ManagementRead moreICH Q12: Technical and Regulatory Considerations for Pharmaceutical Product Lifecycle Management↗
  4. ICH Q7ICH Q7: Good Manufacturing Practice Guide for Active Pharmaceutical IngredientsRead moreICH Q7: Good Manufacturing Practice Guide for Active Pharmaceutical Ingredients↗
  5. ICH Q8ICH Q8(R2): Pharmaceutical DevelopmentRead moreICH Q8(R2): Pharmaceutical Development↗
  6. ICH Q9ICH Q9(R1): Quality Risk ManagementRead moreICH Q9(R1): Quality Risk Management↗
Medical devices and health software19 standards
  1. ISO 10993-1Biological evaluation of medical devices - Part 1: Evaluation and testing within a risk management processRead moreBiological evaluation of medical devices - Part 1: Evaluation and testing within a risk management process↗
  2. ISO 11607-1Packaging for terminally sterilized medical devices - Part 1: Requirements for materials, sterile barrier systems and packaging systemsRead morePackaging for terminally sterilized medical devices - Part 1: Requirements for materials, sterile barrier systems and packaging systems↗
  3. ISO 13485Medical devices - Quality management systems - Requirements for regulatory purposesRead moreMedical devices - Quality management systems - Requirements for regulatory purposes↗
  4. ISO 14155Clinical investigation of medical devices for human subjects - Good clinical practiceRead moreClinical investigation of medical devices for human subjects - Good clinical practice↗
  5. ISO 14971Medical devices - Application of risk management to medical devicesRead moreMedical devices - Application of risk management to medical devices↗
  6. ISO 15223-1Medical devices - Symbols to be used with information to be supplied by the manufacturer - Part 1: General requirementsRead moreMedical devices - Symbols to be used with information to be supplied by the manufacturer - Part 1: General requirements↗
  7. ISO 20417Medical devices - Information to be supplied by the manufacturerRead moreMedical devices - Information to be supplied by the manufacturer↗
  8. IEC 60601-1Medical electrical equipment - Part 1: General requirements for basic safety and essential performanceRead moreMedical electrical equipment - Part 1: General requirements for basic safety and essential performance↗
  9. IEC 62304Medical device software - Software life cycle processesRead moreMedical device software - Software life cycle processes↗
  10. IEC 62366-1Medical devices - Part 1: Application of usability engineering to medical devicesRead moreMedical devices - Part 1: Application of usability engineering to medical devices↗
  11. IEC 81001-5-1Health software and health IT systems safety, effectiveness and security - Part 5-1: Security - Activities in the product life cycleRead moreHealth software and health IT systems safety, effectiveness and security - Part 5-1: Security - Activities in the product life cycle↗
  12. IEC 82304-1Health software - Part 1: General requirements for product safetyRead moreHealth software - Part 1: General requirements for product safety↗
  13. 21 CFR Part 820Quality Management System Regulation (QMSR)Read moreQuality Management System Regulation (QMSR)↗
  14. IVDRRegulation (EU) 2017/746 on in vitro diagnostic medical devicesRead moreRegulation (EU) 2017/746 on in vitro diagnostic medical devices↗
  15. MDRRegulation (EU) 2017/745 on medical devicesRead moreRegulation (EU) 2017/745 on medical devices↗
  16. IMDRF SaMD N41Software as a Medical Device (SaMD): Clinical EvaluationRead moreSoftware as a Medical Device (SaMD): Clinical Evaluation↗
  17. ISO/TR 24971Medical devices - Guidance on the application of ISO 14971Read moreMedical devices - Guidance on the application of ISO 14971↗
  18. MDCG 2019-11Guidance on qualification and classification of software in Regulation (EU) 2017/745 and 2017/746Read moreGuidance on qualification and classification of software in Regulation (EU) 2017/745 and 2017/746↗
  19. MDCG 2019-16Guidance on Cybersecurity for medical devicesRead moreGuidance on Cybersecurity for medical devices↗
Risk management standards and methods12 standards
  1. ISO 22301Security and resilience - Business continuity management systems - RequirementsRead moreSecurity and resilience - Business continuity management systems - Requirements↗
  2. ISO 31000ISO 31000 risk managementRead moreISO 31000 is the international guidance for managing risk. ComplyTrain’s risk management is structured around its process, so risk is a living framework across the organisation, not a spreadsheet reviewed once a year.↗
  3. ISO/IEC 23894Information technology - Artificial intelligence - Guidance on risk managementRead moreInformation technology - Artificial intelligence - Guidance on risk management↗
  4. FAIROpen FAIR Risk Analysis Standard (O-RA)Read moreOpen FAIR Risk Analysis Standard (O-RA)↗
  5. IEC 31010Risk management - Risk assessment techniquesRead moreRisk management - Risk assessment techniques↗
  6. IEC 60812Failure modes and effects analysis (FMEA and FMECA)Read moreFailure modes and effects analysis (FMEA and FMECA)↗
  7. IEC 61508Functional safety of electrical/electronic/programmable electronic safety-related systemsRead moreFunctional safety of electrical/electronic/programmable electronic safety-related systems↗
  8. IEC 61882Hazard and operability studies (HAZOP studies) - Application guideRead moreHazard and operability studies (HAZOP studies) - Application guide↗
  9. NIST AI RMFNIST AI RMF, a framework for managing AI system riskEd. 1.0Read moreA voluntary US framework of four functions, Govern, Map, Measure and Manage, for organizations to manage AI system risk, with no certification scheme.↗
  10. NIST SP 800-30NIST SP 800-30 information security risk assessmentsEd. Rev. 1Read moreNIST's guide to running an information security risk assessment, from threat sources and vulnerabilities through to a level of risk.↗
  11. NIST SP 800-37NIST SP 800-37 risk management framework for information systemsEd. Rev. 2Read moreNIST's seven-step Risk Management Framework for categorizing federal information systems, selecting and implementing security and privacy controls, and having an authorizing official decide whether the residual risk is acceptable.↗
  12. COSO ERMEnterprise Risk Management - Integrating with Strategy and PerformanceRead moreEnterprise Risk Management - Integrating with Strategy and Performance↗

Titles belong to their publishers. The one-line summaries are ours.

Request access to work with this standard in ComplyTrain

Shortlist

Standards with their own page

Each page sets out what the standard asks of you and how a ComplyTrain workspace is organised around it. The catalogue above holds far more than these, and any entry in it can be requested. Adding a standard to a workspace is usually a matter of days, not a project.

  • ISO 9001

    ISO 9001 quality management

    ISO 9001 is the international standard for quality management systems. ComplyTrain is structured around its clause structure, so your QMS is audit-ready by design.

If you need to get there and have no quality function

A standard usually arrives as a contract condition or a regulator's letter rather than a project anyone planned for, and often at a company with no quality manager. Software is half the answer. Skylen's consultants are the other half, and because they build on ComplyTrain from day one you keep a live system your team owns rather than a binder and a departed consultant.

  • Gap assessment

    A clause-by-clause read of where you stand against the standard your contract or your regulator cites, turned into a prioritised plan you could act on with us or alone.

    What an assessment covers
  • Guided implementation

    Our consultants build the system with your team - procedures, document control, the records you need to keep and the review cadence - and prepare you for the audit or the inspection.

    How an engagement works
  • Full-service quality function

    We run and maintain the system for you, so a small team can reach and hold a standard without hiring a quality manager.

    What full-service means

Questions people ask about pharma and device rules

Is ISO 13485 mandatory for a medical device?

Not by name. The MDR requires a quality management system and lists what it must cover; ISO 13485 is the harmonised standard that gives a presumption of conformity with that requirement, and it is what a notified body audits. In practice every manufacturer above class I holds it. In the United States, 21 CFR Part 820 incorporates ISO 13485 from February 2026, so the same system serves both markets.

What is the difference between GMP and ISO 9001?

ISO 9001 is a voluntary standard for a quality management system that a certification body audits. GMP is law: a condition of your manufacturing licence, inspected by your medicines authority, with detailed rules for premises, batch records, release and the rest. ICH Q10 describes a pharmaceutical quality system built on ISO quality concepts and on GMP, which is how the two fit together. See ISO 9001.

Is our software a medical device?

It depends on its intended purpose, not on its technology. Software intended to provide information used for a medical decision, or to monitor a physiological process, is a device under the MDR, and MDCG 2019-11 walks through the qualification step by step. Software that only stores, communicates or searches data is not. A wrong answer here is expensive in both directions, so it is a question for regulatory counsel before development starts.

What does data integrity actually require?

That every GMP record can be trusted: it is attributable to who made it, legible, made at the time, the original or a true copy, and accurate, and that it is complete, consistent, enduring and available for its retention period. Annex 11 and 21 CFR Part 11 put that on computerised systems as validation, audit trails, access control and electronic signatures. PIC/S PI 041 is the inspectors' own guidance on what they look for.

Which annexes of EU GMP apply to us?

Part I and, if you handle active substances, Part II apply to everyone with a manufacturing authorisation. Annex 11 applies to anyone with a computerised system in GMP, which is everyone; Annex 15 to anyone qualifying equipment or validating a process; Annex 16 to batch certification. The rest depend on what you make: Annex 1 for sterile products, Annex 2 for biologicals, Annex 3 for radiopharmaceuticals, and so on. Your licence and your product list say which.

Does ComplyTrain certify us against a standard?

No. Certification is issued by an accredited certification body, a licence by your authority, and government quality assurance is exercised by the acquisition authority. ComplyTrain is the system you build, run and evidence your compliance in, and Skylen's consultants can take you through the work. The certificate stays yours to earn.

Can I get a standard added to ComplyTrain?

Yes, and that is what the Request access button on every entry is for. Tell us which standard and where the requirement comes from, and we come back to you on what holding it in your workspace involves, usually within one business day. Adding a standard to a workspace is usually a matter of days, not a project. ComplyTrain holds a standard as a requirement tree with your evidence against each requirement, and the tree is what we build.

Request access to work with a standard, a guideline or a regulation

Some of these documents are sold by the bodies that publish them, and some are law or guidance you can read for free. We write a page only where we have read the document, so one is missing from this site either because we have not written it up yet, or because it is licensed and not ours to republish. Name the document and where the requirement comes from, and we come back to you on what holding it in your workspace involves.

See ComplyTrain on your own quality system

Book a 30-minute demo with your quality or regulatory lead - the product organised around the rules you answer to.