← to the overview of all articles

Does My Software Vendor Need ISO 13485 & ISO 27001 Certification?

September 23, 2026Contact Person: Malte BuckschMalte Bucksch
Scale with certification seal and question mark: Does my software vendor need ISO 13485 & ISO 27001 certification?

Successfully developing regulated medical software or an app (e.g. a digital health application under §33a SGB V) is a complex undertaking.

In addition to the MDR, ISO 13485 and ISO 27001, there are numerous other standards and laws you have to comply with (e.g. IEC 62304, IEC 62366, IEC 82304, ISO 14971, DiGAV, GDPR, …)

Many manufacturers therefore outsource product development to a software vendor with the relevant expertise in order to get to market quickly and safely.

This raises a central question:

Should you choose a certified software vendor? (according to ISO 13485 and ISO 27001)

… or can you also succeed with a non-certified software vendor?

The answer is not always clear-cut and depends on several factors. This guide is intended to help you make the decision.

In short:

There is no legal requirement for the software vendor itself to be certified according to ISO 13485. However, the MDR obliges the manufacturer to maintain a quality management system (Article 10(9) MDR). This includes selecting, evaluating and monitoring its suppliers (ISO 13485, clause 7.4 Purchasing). A software vendor certified according to ISO 13485 and ISO 27001 already meets these requirements in a verifiable way. For a medical device under the MDR or a DiGA, it is therefore the safer choice. For software without a medical purpose, no certificate is needed.

Table of Contents

1. Relevant Certificates for Software Vendors

In the context of digital health applications (DiGA), medical apps and Software as a Medical Device (SaMD), exactly two certificates are particularly relevant when choosing a vendor:

The relevant certificates for medical software: ISO 13485 and ISO 27001

Figure 1: The relevant certificates for developing medical software and apps: ISO 13485 (quality management system) and ISO 27001 (information security management system)

1.1 ISO 13485 Certificate for Quality Management of Medical Devices

ISO 13485 is an internationally recognized standard that defines the requirements for a comprehensive quality management system for the design and manufacture of medical devices. It ensures that the vendor has implemented processes that guarantee the safety and effectiveness of the medical device software.

An ISO 13485 certified software vendor not only brings the necessary expertise in medical device development, but has also established a regulatory-compliant quality management system for developing medical software.

Notified bodies even require an ISO 13485 certificate for a successful medical device approval.

1.2 ISO 27001 Certificate for Information Security

ISO 27001 is a global standard for information security management systems (ISMS).

An ISO 27001 certified vendor demonstrates the ability to protect confidential data, including the sensitive health data processed in digital health applications and medical software. The certification means that the vendor has established a comprehensive information security management system. The certified company has thus demonstrably implemented suitable security controls and processes to minimize risks such as data loss, theft or alteration.

DiGA manufacturers, for example, are obliged to be certified according to ISO 27001. The obligation for information security management therefore also extends to critical suppliers.

Note:

Did you know that a certified vendor is audited for several days every year?

An accredited auditor ensures that the company works in compliance with the standards. You can therefore rely on the competence of your vendor.

2. Non-Certified vs. Certified Software Vendor

2.1 When Does a Non-Certified Vendor Work?

If you are developing health software that is not intended to become a medical device under the MDR or a DiGA, a non-certified vendor can also be a good option.

Health lifestyle software that has no medical purpose is not regulated as a medical device by the MDR. A good example would be a classic fitness app.

In this case, your software vendor does not need any knowledge of medical device development and therefore no certified quality management system according to ISO 13485 either.

Note:

Your software product may process personal health data.

In that case, expect increased data protection requirements under the General Data Protection Regulation (GDPR). Look for software vendors with an ISO 27001 certificate to reduce the risk of data security incidents.

2.2 When Should You Choose a Certified Vendor?

The situation is different if you want to develop software or an app that qualifies as a medical device under the MDR. This includes in particular digital health applications (DiGA). Legal responsibility always remains with the manufacturer. The manufacturer must demonstrate that it has selected and monitors its suppliers, including the software vendor, according to its quality management system.

The likelihood of successful market approval, product success and business success increases significantly if you work with a certified software vendor for medical device software and DiGA.

The certification of the software vendor ensures that all regulatory requirements are met and significantly reduces the risk of compliance problems. For medical, regulated applications, a certified partner can make the decisive difference between the success and failure of the project.

You can find detailed information on this in chapter 3 “Risks: Certified vs. Non-Certified Vendor”.

2.3 Conclusion: Certified vs. Non-Certified

Our recommendation:

Work with a certified vendor if you …

  • … want to develop software or an app as a regulated medical device.
  • … want to get into the DiGA directory quickly and safely.

Certified software vendors do not have to laboriously build up quality management and information security processes first, and they bring a lot of practical experience in medical device development.

If your software is not a medical device and not a DiGA, you can work with a non-certified vendor without any problems.

If you want to develop a medical device or a DiGA with a non-certified vendor, keep the risks and problems below in mind with the highest priority (see chapter 3).

3. Risks: Certified Vendor vs. Non-Certified Vendor

The following table provides an overview of the most important risks and problems that can arise from non-certified vendors.

If you plan to implement medical software with a non-certified vendor, keep these risks in mind at all times during the project.

AspectNon-certified vendor: risksCertified vendor (according to ISO 13485 & 27001): benefits
Risks for product, company and managing directors
Medical device under the MDR: legal consequencesRisk of violations of medical device law (high financial damage, loss of reputation and criminal consequences for individuals)Protection of the company and the managing directors through proven regulatory compliance according to ISO 13485
Data protection & data security: legal consequencesRisk of data protection violations involving health data (high financial damage, loss of reputation and criminal consequences for individuals)Guaranteed data security and data protection according to ISO 27001 and GDPR
Compliance & project successRisk that the product does not reach the market due to non-compliance or has to be withdrawn from the market laterCertainty about compliance and a safe market launch of the product
Harm to healthRisk of harm to patientsMaximum patient safety
Problems in company auditsMissing proof of the vendor's competence in the BfArM application for the DiGA or towards the notified body under the MDRSmooth processing with proof of competence through ISO certificates
Internal costs and need for specialists
Costs and timeHigh internal costs and time spent on onboarding, training, monitoring and auditing the vendor teamEfficient way of working without additional onboarding or auditing of the vendor team
Need for specialistsNeed to build up internal specialists for quality management and data securityReliance on the vendor's expertise without the need for internal specialists
Market entry and market success
Cooperation opportunitiesLow trust and therefore limited cooperation and funding opportunities, e.g. with health insurers or public fundingHigh trust and therefore diverse cooperation opportunities and access to funding through a quality seal
Time of product market entryDelayed market entry due to an untrained vendor team and lengthy iteration loopsFast market entry thanks to an experienced and trained vendor team
← to the overview of all articles

Are you planning to implement medical software or a DiGA?

Contact us for a free initial consultation. We will give you an estimate of the effort and timeframe required to implement your project. We will also examine the regulatory and strategic framework conditions for your product.