ISO 13485 is the quality management system standard for medical devices, and a growing number of fulfillment operations pursue certification so they can legally and safely handle regulated devices. Here is what the certification actually covers, what a certified 3PL must maintain day to day, how to tell a real certificate from a marketing claim, and how it connects to FDA rules, so you can shortlist the right partner with confidence.
What ISO 13485 certification means for a fulfillment operation
ISO 13485 is an international standard that specifies requirements for a quality management system, or QMS, covering any organization involved in the medical device lifecycle, including design, manufacturing, and distribution. When a 3PL holds ISO 13485 certification, it means an accredited, independent registrar audited its documented processes, such as receiving, storage, order fulfillment, and shipping, and confirmed they meet the standard well enough to issue a certificate. This is a meaningfully different claim than a brand simply listing hazmat or medical devices as a specialty. A genuine certificate has three parts that matter: a certificate number you can look up, the name of the accredited registrar that issued it, such as NQA, BSI, or SGS, and a scope statement spelling out exactly which activities and locations are covered. Critically, ISO 13485 certification is never issued or approved by the FDA. The FDA registers device facilities and enforces its own quality regulation, but certification to the ISO standard comes only from an accredited third-party registrar, so any claim that a warehouse is FDA-approved for ISO 13485 is a red flag worth questioning directly.
What a certified 3PL must maintain: UDI, traceability, recalls, and CAPA
Holding the certificate is the start, not the end. A 3PL operating a real ISO 13485 quality system maintains several things every day. First, Unique Device Identification, or UDI, verification at receiving, tying each device's UDI barcode to lot and serial records in the warehouse management system so any unit can be traced forward or backward through the supply chain. Second, full lot and serial traceability through picking and packing, not just at intake, so a single defective batch can be isolated without pulling unrelated inventory. Third, a documented recall procedure that defines how affected units are quarantined, how the manufacturer and downstream accounts are notified, and how the response is closed out. Fourth, corrective and preventive action, or CAPA, records that show the operation investigates errors and fixes root causes rather than just logging incidents. Fifth, controlled documentation and complaint handling, meaning SOPs are version-controlled and any customer or patient complaint related to a device is logged and routed for review. Ask any certified 3PL to walk through these five processes specifically, since they are what separates a working quality system from a certificate on a wall.
Certified vs compliant: how to verify the certificate and its scope
Marketing language blurs the line between ISO 13485 certified, FDA compliant, FDA registered, and GMP compliant, and these are not interchangeable. FDA registration simply means a facility is listed in the FDA's establishment registration database, which is a low bar with no independent audit behind it. GMP compliance and HIPAA compliance are separate claims entirely. Only ISO 13485 certified means an accredited registrar has audited the operation's quality management system against the actual standard. To verify a claim, ask for the certificate number and registrar name, then confirm the registrar itself is accredited, typically through a national accreditation body such as ANAB in the US, since an ISO 13485 certificate from an unaccredited registrar carries no real weight. Most important, read the scope statement. Certificates are scope-limited, so a facility certified for design and manufacturing is not automatically certified for distribution and warehousing, and vice versa. A device brand should confirm the scope statement explicitly names the activities it needs, such as storage, order fulfillment, or light kitting, at the exact facility that will handle its inventory, not just at the parent company level.
How ISO 13485 relates to FDA QSR and QMSR
For decades the FDA enforced its own Quality System Regulation, under 21 CFR Part 820, which overlapped with but was not identical to ISO 13485. That changed with the FDA's Quality Management System Regulation, or QMSR, which was finalized in February 2024 and took effect on February 2, 2026, formally replacing the old device-specific regulation and incorporating ISO 13485:2016 by reference as the baseline US requirement. In practice, this means device manufacturers now need their own quality systems, and by extension their logistics partners' systems, to align with the international standard rather than a separate US-only rulebook. It does not change who issues certification. FDA registration and QMSR compliance are verified through FDA inspection and enforcement, while ISO 13485 certification still comes only from an accredited registrar. A 3PL can be FDA-registered without being ISO 13485 certified, and in principle could be ISO 13485 certified without being the specific facility named on a manufacturer's FDA registration, so device brands should confirm both pieces separately rather than assuming one implies the other.
When device classes require it, costs, and how to choose
Not every device program needs a certified 3PL by law, but the higher the risk class, the more it matters in practice. Class I devices, such as bandages or simple exam gloves, carry the lightest quality-system expectations. Class II devices, the largest ecommerce category and including things like glucose monitors and many diagnostic tools, typically require a manufacturer's full quality system, which increasingly flows down to its logistics partner's traceability and documentation. Class III devices, such as implants, carry the strictest requirements, and most manufacturers at that tier will only work with a 3PL that holds its own ISO 13485 certificate with a scope matching the work. Certified fulfillment typically costs more than standard fulfillment, driven by the labor of maintaining controlled documentation, lot-level scanning at every touch, and periodic surveillance audits the 3PL itself must pass to keep its certificate active. Using Fulfill.com pricing benchmarks as a baseline, expect standard receiving and pick-and-pack rates plus a premium for regulated handling and audit-ready documentation. To choose well, confirm the certificate, registrar, and scope match your device class and facility, then run a smaller trial shipment before committing full volume.