Skip to content

Cleveland, Ohio

ISO 13485 consulting for Northeast Ohio device makers.

QMSR took effect on 2 February 2026 and made ISO 13485 the substance of US device regulation. For companies coming out of Cleveland's clinical research pipeline, that changes when a quality system has to exist.

We work in the Kansas City metro. Engagements here run remotely, with on-site visits at the points where being in the building changes the outcome — gap analysis, internal audit, and the certification audits themselves. We do not maintain an office in this market and would rather say so than imply otherwise.

Why the deadline has already passed

On 2 February 2026, FDA's Quality Management System Regulation took effect. It amends 21 CFR Part 820 to incorporate ISO 13485:2016 by reference. The practical meaning is easy to miss: for quality system purposes, ISO 13485 conformance is no longer something you align to the US regulation — it substantially is the US regulation.

That reframes a conversation device companies have been having for years. It used to be reasonable to run a QSR-shaped system and treat ISO 13485 as a separate commercial requirement for European or customer purposes. As of six months ago, that separation stopped making sense.

One point worth stating clearly, because it gets muddled in both directions: FDA requires compliance with the incorporated requirements. It does not require an ISO 13485 certificate. Many manufacturers certify anyway — for notified bodies, for customers, for markets outside the US — but that is a commercial decision and deserves to be made as one.

Industry in Cleveland

  • Cleveland Clinic Innovations 107 startups, 2,800+ issued patents and 900 active licences over 25 years — a continuous source of new device companies needing a first QMS
  • STERIS US operational headquarters in Mentor, Ohio, where the company was founded in 1985
  • Cleveland Innovation District Five anchor institutions including Cleveland Clinic, Case Western Reserve and University Hospitals
  • Northeast Ohio contract manufacturing base 2,664 manufacturers under 100 employees — the supplier tier device companies actually buy from

A metro that keeps producing new device companies

Cleveland's device sector has an unusual shape. Rather than one or two large manufacturers surrounded by suppliers, it is fed by a continuous clinical research pipeline. Cleveland Clinic Innovations has produced 107 startups over roughly 25 years, alongside more than 2,800 issued patents and 900 active licences.

That shapes what the work looks like here. A large share of engagements in this metro are first quality systems — companies with a technology, a clinical champion and a funding round, who have just discovered that design controls were supposed to start earlier than they thought.

The Cleveland Innovation District, anchored by Cleveland Clinic, Case Western Reserve, Cleveland State, MetroHealth and University Hospitals, keeps that pipeline fed. STERIS, founded in Mentor in 1985 and still running its US operational headquarters there, anchors the established end of the same market.

Design controls start earlier than most founders expect

The most expensive misunderstanding in early-stage device companies is when design controls begin. They apply from the start of commercial design and development — not at submission.

A company that designs for two years without design controls and then reconstructs the record retrospectively produces a document set that reviewers and auditors are experienced at recognising. Contemporaneous records cannot be manufactured afterwards, and the attempt is usually visible.

The workable pattern is a lean quality system at company formation that genuinely satisfies design controls, expanded toward full ISO 13485 scope as commercialisation approaches. It costs materially less than a retrospective build, and it produces a design history file that is evidence rather than reconstruction.

The supplier tier is the other half of the problem

Northeast Ohio has 2,664 manufacturing establishments with fewer than 100 employees (US Census County Business Patterns, 2023) — the largest such base of any Ohio metro, and one of the largest in any market we cover. Many supply device companies without being device companies themselves.

For a contract machinist, moulder or coater, the question is rarely whether to certify to ISO 13485. It is whether an existing ISO 9001 system can carry the controls a device customer will flow down: process validation, traceability to the batch, controlled changes, and a corrective action process that produces evidence rather than a note.

That is usually a smaller job than a second certification. Getting an honest read on which of the two you actually need is worth doing before anyone quotes you for either.

How we work with companies here

We are based in the Kansas City metro. Cleveland engagements run remotely, with on-site visits at the points where being present changes the result — the initial gap analysis walkthrough, the first internal audit, and the certification audits themselves.

For device work that split tends to suit clients anyway. Design history file review, procedure drafting, risk file construction and CAPA design are better done asynchronously, with your regulatory lead reviewing on their own schedule rather than across a conference table.

The consultant who scopes the engagement does the work. There is no handoff to a junior implementer after the sale — which, for a company whose design history file will be read by a reviewer, matters more than it does in most quality work.

What an engagement covers

  • QMSR gap assessment Where your current system sits against ISO 13485:2016 as incorporated into 21 CFR Part 820, and what actually has to change. Fixed scope, fixed price.
  • Design controls and the design history file Built as design happens rather than reconstructed before submission — planning, inputs, outputs, review, verification, validation, transfer and change control.
  • Risk management integration ISO 14971 alignment treated as a living file connected to CAPA and design change, not a document refreshed once a year.
  • CAPA a reviewer will accept Drawing on complaints, service records, returns, nonconforming product and audit findings, with trending rather than only individual investigations.
  • Supplier controls Evaluation, selection, monitoring and re-evaluation criteria proportionate to risk. The clause where findings cluster most reliably.
  • Internal audit and management review Conducted to auditor-grade standards, with an action register that closes findings before a certification body or an investigator sees them.
  • Certification and notified body liaison If you are heading to the EU as well as the US. We hold no commercial relationship with any certification body.

Questions we get from companies in this market

Do we need ISO 13485 certification, or just QMSR compliance?

Legally, FDA requires compliance with the requirements incorporated into 21 CFR Part 820 — it does not require a certificate. Commercially the answer usually changes: notified bodies expect ISO 13485 in practice for EU market access, and a growing number of customers ask for it directly. The honest sequence is to build a compliant system first and then decide whether certifying it is worth the audit cost for your specific markets. We will tell you if we think it isn't.

We're a Cleveland Clinic spin-out with no quality system yet. Where do we start?

With scope and design controls, in that order, and earlier than feels comfortable. Design controls apply from the start of commercial design and development, so the practical question is not whether to build a system but how small it can be while genuinely satisfying them. A lean formation-stage QMS that expands as you approach commercialisation is considerably cheaper than a retrospective build before a submission.

We machine parts for a device manufacturer. Do we need ISO 13485 too?

Often not. What your customer usually needs is evidence that specific controls exist in your process — validation of any special process, traceability, controlled changes, and a corrective action loop that produces records. That can frequently sit inside an existing ISO 9001 system rather than requiring a second certification. Get it assessed before anyone sells you a full 13485 implementation, because the cost difference is substantial.

Does Ohio have its own safety or device regulator we need to satisfy?

No, and it is worth being precise because sites in this industry frequently get it wrong. Ohio has no OSHA-approved State Plan; private-sector workplaces fall under federal OSHA. The Ohio BWC's PERRP programme covers public employees only. For device manufacturers here the regulatory driver is federal, through FDA, not state.

How long does ISO 13485 take from a standing start?

For a small device company with reasonable engineering discipline, six to twelve months to a certifiable system is realistic — longer than ISO 9001, because design control and risk management requirements are more demanding and because the evidence has to be contemporaneous. Companies with an existing ISO 9001 system move faster on the management-system clauses and slower on design controls.

Can you help with FDA submissions as well?

We build and remediate the quality system a submission relies on. We are not a regulatory affairs firm and do not write 510(k)s. If you need both, that is a normal split and we work alongside RA consultants regularly — we would rather say where our work ends than take on something outside it.

Other standards in Cleveland

This page is about ISO 13485, which is what this metro's industry asks for most often. We cover these here too.

  • ISO 9001 in Cleveland Northeast Ohio has the largest small-manufacturer base of any Ohio metro. Most of those shops are not device companies — they are who device companies buy from.