Selecting a supplier for a medical device component involves more than confirming whether they hold an ISO 13485 certificate.
Medical device manufacturers need objective evidence that an external supplier can consistently meet defined technical, quality and regulatory requirements. The level of control should reflect the component’s intended use, its criticality and the potential consequences of a process or component failure.
This guide explains what to consider when qualifying an ISO 13485 component supplier, what a typical supplier audit may cover and which records can support your supplier approval process.
What does ISO 13485 require when using external suppliers?
ISO 13485 provides an internationally recognized quality-management framework for organizations involved in the medical-device supply chain. Its purchasing controls require manufacturers to evaluate and select suppliers based on their ability to meet specified requirements.
The type and extent of supplier control should be proportionate to:
- The potential effect of the supplied component on the finished medical device
- The risks associated with the component or outsourced process
- The supplier’s demonstrated capability and performance
- The controls that can subsequently be applied by the manufacturer
Supplier qualification is therefore not a one-time certification check. It should establish that the supplier understands the requirements, has suitable controls in place and can provide evidence that delivered components conform to the agreed specification.
In the United States, the FDA Quality Management System Regulation, effective from 2 February 2026, incorporates ISO 13485:2016 by reference. This has further aligned US quality-system expectations with the internationally recognised ISO 13485 framework.
Is ISO 13485 certification enough to approve a supplier?
ISO 13485 certification is valuable evidence that a supplier operates within an independently assessed medical-device quality management system. However, certification should form one part of a wider, risk-based supplier evaluation.
Quality teams should also assess:
- Whether the certificate’s scope covers the supplied process
- Technical and manufacturing capability
- Process control and validation
- Inspection and measurement capability
- Traceability arrangements
- Change-control procedures
- Nonconformance and corrective-action processes
- Capacity and continuity of supply
- Previous experience within the medical-device industry
Laser Wire Solutions is certified to ISO 13485:2016 for the laser processing of medical device wires and components using stripping, cutting and drilling methods.
View our ISO 13485 certificate
How the LWS quality system supports OEM supplier controls
Laser Wire Solutions provides precision laser-processed components for medical-device manufacturers, including spool-to-spool and pre-cut wire components.
Our ISO 13485-certified Medical Device Component Supply operation supports controlled production from initial process development through pilot builds and ongoing component supply.
Depending on the application and agreed quality requirements, this can include:
Defined component requirements
Customer drawings, wire specifications, strip dimensions, tolerances, inspection requirements and acceptance criteria are reviewed before production requirements are finalised.
Controlled laser processes
Application-specific laser settings, handling methods and inspection requirements are defined to support consistent, repeatable processing.
Process development and validation support
Development work can be used to establish a suitable process before moving into production. Validation requirements, evidence and responsibilities are agreed with the customer according to the application and project scope.
Inspection and measurement
Available inspection capabilities include in-house SEM imaging, optical measurement, linear-encoder wire inspection and pull-force testing, where applicable to the component and agreed inspection plan.
Batch and process traceability
Production and inspection records support traceability between supplied components, the applicable process and the associated manufacturing batch or lot.
Control of nonconforming product
Components that do not meet agreed acceptance criteria are identified, controlled and investigated through the applicable quality processes.
Change control
Requirements for notification, review and approval of relevant process, material or specification changes can be defined through the purchasing documentation or quality agreement.
The precise controls and records required should be agreed during supplier qualification and before production begins.
Process. Inspect. Measure. Verify.
Risk-classifying outsourced medical components
There is no single universal classification system for labelling every supplied component as “critical” or “non-critical.” Each medical-device manufacturer should determine the appropriate classification using its own risk-management process and the component’s role within the finished device.
Factors to consider include:
| Assessment area | Questions to consider |
|---|---|
| Intended use | Where and how is the component used in the finished device? |
| Failure effect | What could happen if the component or processed feature failed? |
| Detectability | Can a defect be reliably detected before the device reaches the user? |
| Process complexity | Is the component custom-made or difficult to manufacture consistently? |
| Downstream verification | Can the result of the outsourced process be fully verified later? |
| Patient contact | Does the component have direct or indirect patient contact? |
| Design risk | Is the component linked to a hazard or control identified in the device risk analysis? |
| Supply risk | Is the supplier single-source, capacity-constrained or dependent on specialist equipment? |
Higher-criticality components or processes
A higher level of supplier control may be appropriate where failure could affect device safety or performance, where defects are difficult to detect or where the outsourced process cannot be fully verified through subsequent inspection.
Controls may include:
- Detailed supplier evaluation
- An on-site or remote quality audit
- An approved quality agreement
- Formal process validation
- Defined inspection and acceptance plans
- First article or pilot-lot approval
- Enhanced traceability
- Agreed change-notification requirements
- Regular performance monitoring and re-evaluation
Lower-criticality components
A lower-risk component may require fewer controls, but the rationale should still be documented. Certification review, a supplier questionnaire, specification approval and routine incoming inspection may provide sufficient evidence where the associated risks are low and conformity can be readily verified.
Risk classification should determine the controls applied. It should not be used to remove supplier oversight entirely.
What should a medical device supplier audit cover?
A supplier audit should assess whether documented procedures are being implemented effectively and whether the supplier can consistently meet the OEM’s specific requirements.
A typical audit agenda may include:
1. Audit scope and introductions
- Supplied components and processes
- Intended application
- Applicable specifications and quality requirements
- Responsibilities and key contacts
2. Quality management system
- ISO 13485 certificate and certification scope
- Quality policy and QMS structure
- Document and record control
- Internal audit and management-review arrangements
- Personnel responsibilities and training
3. Contract and specification review
- Review of customer drawings and specifications
- Acceptance criteria
- Feasibility and capacity assessment
- Control of revised requirements
4. Supplier and material controls
- Qualification of raw-material and service suppliers
- Incoming material verification
- Material identification and traceability
- Control of subcontracted processes
5. Production and process control
- Approved work instructions
- Equipment qualification
- Process settings and recipe control
- Operator training
- In-process checks
- Process validation, where required
6. Inspection and measuring equipment
- Inspection methods
- Calibration status
- Measurement-system suitability
- Sampling plans
- Recording and review of results
7. Identification and traceability
- Batch or lot identification
- Links between material, production and inspection records
- Status identification throughout production
- Record retention
8. Nonconformance and corrective action
- Identification and segregation of nonconforming product
- Investigation and disposition
- Customer notification
- Corrective-action processes
- Effectiveness checks
9. Change control
- Assessment of proposed changes
- Customer notification and approval
- Revalidation requirements
- Control of documents and production settings
10. Capacity and business continuity
- Available capacity
- Equipment maintenance
- Contingency arrangements
- Critical suppliers and single-source dependencies
- Production and delivery monitoring
Which records should you request from a component supplier?
The documentation required should be based on component risk, regulatory requirements and the agreements established between the manufacturer and supplier.
A customer-agreed quality documentation pack may include:
- Current ISO 13485 certificate
- Completed supplier questionnaire
- Approved drawings and component specifications
- Quality or supplier agreement
- First Article Inspection report
- Process flow and inspection plan
- Process-validation plan or summary
- Equipment qualification or calibration evidence
- Defined acceptance criteria
- Inspection and measurement results
- Batch or lot traceability records
- Certificate of Conformity
- Raw-material certificates or Certificates of Analysis, where LWS is responsible for material supply and these are available from the material manufacturer
- Nonconformance or deviation records
- Approved change records
- Packaging and identification requirements
Some organizations refer to this collection as a PPAP-style documentation pack. PPAP is not a universal ISO 13485 requirement, so the required documents and approval stages should be defined specifically for the medical-device project.
Not every record will be appropriate or available for every component. Documentation, confidentiality, retention and access requirements should be agreed during project and quality planning.
A practical supplier-qualification process
Step 1: Define the component and process
Document the technical specification, intended use, required processing, acceptance criteria and applicable regulatory or customer requirements.
Step 2: Assess component and supply risk
Consider component criticality, failure severity, detectability, process complexity, downstream verification and continuity-of-supply risks.
Step 3: Establish supplier-selection criteria
Define the certifications, capabilities, capacity, records and quality controls the supplier must demonstrate.
Step 4: Evaluate the supplier
Review the supplier’s certification scope, questionnaire responses, technical capability, sample results and available quality evidence. Conduct an audit where justified by risk.
Step 5: Confirm requirements and controls
Agree specifications, inspection requirements, validation responsibilities, documentation, change notification and nonconformance communication.
Step 6: Approve initial production
Use feasibility samples, first articles, pilot batches or validation lots to confirm that the process can meet the agreed requirements.
Step 7: Monitor ongoing performance
Review delivery, conformity, complaints, deviations, corrective actions and other agreed supplier-performance measures.
Step 8: Re-evaluate according to risk
Supplier approval should be reviewed periodically and when significant changes, quality issues or new requirements arise.
Qualifying Laser Wire Solutions as a component supplier
Laser Wire Solutions supports medical-device manufacturers with ISO 13485-certified laser processing for medical wires and components.
Our capabilities include:
- Precision insulation removal
- Fine-wire and micro-coax processing
- Laser cutting and drilling
- Spool-to-spool processing
- Pre-cut component supply
- Application-specific process development
- Inspection and measurement
- Pilot and production-volume supply
We can support the technical and quality discussions needed to determine whether our process is suitable for your component, from initial feasibility through validated, scalable production.
Frequently asked questions
What are the main ISO 13485 supplier requirements?
Medical-device manufacturers should evaluate and select suppliers according to their ability to meet specified requirements. The extent of control should reflect the risks associated with the supplied component or service and the supplier’s performance.
How do you qualify an ISO 13485 component supplier?
Qualification normally includes defining requirements, assessing component risk, reviewing the supplier’s certification and capabilities, evaluating objective evidence, agreeing controls and approving initial production. Higher-risk components may also require an audit and formal process validation.
Does an ISO 13485 certificate remove the need for a supplier audit?
No. Certification is useful evidence, but it does not automatically demonstrate that a supplier can meet every application-specific requirement. The need for an audit should be determined through the manufacturer’s risk-based supplier-control process.
What is a critical medical-device component?
A component may be considered critical when its failure could affect the safety, essential performance or regulatory conformity of the finished device. Classification should be based on the manufacturer’s risk analysis and the component’s intended use.
What is the difference between a Certificate of Conformity and a Certificate of Analysis?
A Certificate of Conformity confirms that the supplied product meets specified requirements. A Certificate of Analysis reports specific test or measurement results for a material or batch. The appropriate document depends on the product, specification and agreed purchasing requirements.
What should be included in a medical-device supplier quality agreement?
A quality agreement may define responsibilities for specifications, documentation, traceability, validation, inspection, nonconformance reporting, change notification, record retention, audits and corrective action.
This resource provides general supplier-quality information and does not replace an organization’s own regulatory, legal or quality-system assessment.


