Key Summary

A professional FAQ guide on handling inconsistent quality system certificates (ISO 13485, MDSAP, NMPA, CE) during overseas registration of home-use medical devices. Covers decision logic, required evidence, common mistakes, a preparation checklist, AIMEILI regulatory insights, and key follow-up questions.

When registering a home-use medical device overseas, if the quality system certificates (e.g., ISO 13485, MDSAP, NMPA system inspection, or CE system audit) are inconsistent, companies should first clarify which quality system documents are accepted by the target country’s regulatory authority and review the coverage, validity, and certificate holder of existing certificates. The decision logic is: first confirm whether the product falls under the country’s medical device regulatory scope; then determine the registration pathway and applicant according to risk class; next assess whether existing NMPA, CE, FDA, or ISO 13485 documentation can be reused; and finally complete the localization conversion of technical files, risk management, clinical evidence, labeling, and local agent arrangements. Common risks include the certificate scope not covering the product, mismatch between the certificate holder and the registration applicant, differences in audit standards, incomplete translation, and untimely renewal or version updates. Companies should prepare the system certificate, audit reports, nonconformity closure records, the quality manual, and a cross-reference table of procedure documents, and verify acceptance through a local agent. For multi-country registration, using the GHWP member state framework and a document matrix can reduce duplicate work, but the evidence chain must remain complete and changes must be controlled.

Compiled based on the AIMEILI Registration Practice Question Bank, the International Medical Device Registration Knowledge Base, and public regulatory information; specific projects should be based on the latest requirements of the target country’s regulatory authorities and the product documentation basis.

Published: August 2, 2026, 10:23 | Updated: August 2, 2026, 10:23

Applicable Scenarios and Core Issues

Home-use medical devices include blood pressure monitors, blood glucose meters, thermometers, nebulizers, massagers, low-frequency therapy devices, and the like. Companies often already have an NMPA registration certificate or CE certificate in China and also hold an ISO 13485 system certificate. However, during overseas registration applications in Southeast Asia, the Middle East, Latin America, and other regions, the submitted quality system certificates often show inconsistencies.

Inconsistencies may appear in the following forms: the address on the system certificate differs from the address in the registration application; the certificate scope does not cover the product submitted; the certificate holder is the parent company while the registration applicant is a subsidiary; the system audit is based on ISO 13485:2016, but the target country requires equivalent adoption or additionally requires MDSAP; or the certificate is due to expire, but the target country requires the most recent surveillance audit report.

The core issue is not simply submitting an extra certificate. Rather, it is necessary to understand how the target country’s regulatory authority accepts quality system proof. Acceptance varies significantly from country to country: some accept ISO 13485 alone, others require a factory inspection report, others require an on-site audit by the local regulatory authority, and still others accept only certificates issued by specific bodies.

Therefore, the company should first map the entire chain of existing quality system proof, including the certificate body, annexes, audit reports, nonconformity closure records, and the date of the last audit. It should then compare these against the target country’s official registration guidance or consult a local agent to identify which documents are directly acceptable and which need to be supplemented.

Registration Decision Logic

Companies should make judgments in the following sequence to avoid falling into a passive state of merely supplying documents.

Step 1: Determine whether the product falls within the target country’s medical device regulatory scope. Some home-use products may be regulated as general consumer goods in certain countries, for example simple massagers or certain low-power physiotherapy devices. If the product is not a medical device, a quality system certificate is not a mandatory condition.

Step 2: Determine the product’s risk class and registration pathway. Home-use medical devices are usually low or medium-low risk, such as Class A, Class B, or Class I, Class II, but classification differs between countries. The risk class decides whether a quality system audit is required or a declaration is sufficient.

Step 3: Determine the applicant entity. Most countries require the local registration applicant to hold the quality system certificate, or the manufacturer to hold the certificate and submit it as part of the registration. If the certificate holder is different from the registration applicant, proof of the authorization relationship must be provided.

Step 4: Assess whether existing documents can be reused. The ISO 13485 certificate is the most commonly used system proof globally. The MDSAP certificate can reduce audits in some countries. The CE system certificate can be used as a reference in technical review. However, an NMPA system inspection report generally cannot serve directly as overseas registration proof and can only be used as supplementary evidence.

Step 5: Confirm localization requirements. A quality system certificate is only one link in the registration chain. Technical files, performance verification, risk management, clinical evaluation, labeling and instructions for use, and local agent responsibilities must all be checked one by one. A consistent system certificate alone is not enough for approval.

Documentation and Evidence

What a company needs to prepare is not a single certificate but a complete evidence chain. Required documents include:

  • A copy of the quality system certificate and any supporting documents recognized by the issuing body.
  • Certificate annex or scope attachment clearly defining the covered product categories and models.
  • The most recent audit report and nonconformity closure records.
  • A cross-reference table between the quality manual and procedure documents to help the regulatory authority understand the system elements.
  • Basic qualification documents such as factory address, contact person, and production license.
  • An authorization letter explaining the relationship between the certificate holder and the registration applicant.
  • For multi-country registration, a system document gap analysis table.
  • A certified translation of the certificate, performed by a professional agency, with a translator’s declaration.

For technical files, a clear mapping between the quality system and product documents should be established. For example, every risk management report, verification report, and clinical evaluation document should be traceable to the corresponding procedures and records in the quality system.

If the target country requires MDSAP, the company must verify whether the existing ISO 13485 audit covers MDSAP’s additional requirements, such as vigilance reporting, regulatory communication, and data integrity. If not, a gap assessment should be arranged in advance.

If the certificate scope does not include the product being submitted, the issuing body should be contacted to extend the scope. This process may require additional product audits or production record audits and is time-consuming, so it should be started as early as possible.

Common Mistakes

  • Submitting only the first page of the certificate without the scope attachment and audit reports.
  • Ignoring the certificate’s validity period and failing to calculate whether it will expire during the registration review.
  • Using the NMPA system inspection report directly for overseas registration without localization explanation.
  • Submitting a certificate held by a different entity than the applicant without providing authorization or change records.
  • Providing a direct translation of the certificate without a verification link on the issuing body’s official website or notarized documents.
  • Assuming ISO 13485 is globally accepted and overlooking the target country’s additional on-site audit requirements.
  • Using different versions of the quality manual for multi-country registration, causing confusion in document numbering.
  • Failing to synchronize updated system documents into the technical documentation, leading to version mismatches.

Company Preparation Checklist

  • Establish a quality system certificate register recording certificate type, issuing body, validity period, scope, and remarks.
  • Check each country’s registration guidelines for specific quality system certificate requirements.
  • Confirm whether the existing certificate scope covers the applied product; if not, start a scope extension immediately.
  • Organize the most recent three audit reports, nonconformity closure records, and internal audit plans.
  • Map the correspondence between product technical documents and quality system procedures.
  • Prepare a system gap analysis report explaining the conformity between ISO 13485 and the target country’s requirements.
  • Communicate with the local agent or authorized representative about certificate acceptance and, if necessary, ask for written confirmation from the regulatory authority.
  • Develop a certificate renewal and version update plan to keep the certificate valid throughout the registration review period.

AIMEILI Perspectives

The most common misjudgment is treating the quality system certificate as a static piece of paper, ignoring the audit records and scope behind it. What regulators actually evaluate is whether the system can continuously ensure product safety and effectiveness, not the certificate copy itself.

At the beginning of a project, a quality system gap analysis should be performed before entering electronic submission. The gap analysis should cover target country regulations, recognized issuing body lists, certificate scope, factory inspection, and language requirements. A small investment of time upfront can significantly reduce the risk of deficiencies.

ISO 13485 certificates, audit reports, and internal audit records can be reused, but MDSAP certificates, factory inspection reports, and locally language versions of the quality manual must be localized. The NMPA system inspection report cannot be used directly as overseas registration proof; it can only act as supporting material.

A local agent is not simply a submission window. The agent should be responsible for confirming the regulator’s actual acceptance of quality system certificates and for advising on certificate translation and notarization. In principle, the manufacturer should retain control of the certificates to avoid disruption if the agent changes.

Change and renewal are long-term risk points. Changes in the certificate address, legal representative, or issuing body can affect overseas registration. Companies must establish a change notification mechanism. For multi-country registration, a document matrix and unified version management are recommended, using ISO 13485 as the base and adding incremental explanations according to each country’s requirements, rather than starting from scratch every time.

Frequently Asked Follow-up Questions

What should be done if the ISO 13485 certificate is about to expire while overseas registration is under review?

It is recommended to arrange a system renewal audit at least six months before expiration and submit proof that the renewal application has been accepted to the target country’s regulatory authority. Some countries allow a grace period for transitional documents after the old certificate expires, but this should be communicated in advance. If transitional documents are not accepted, it may be necessary to resubmit supplementary information after the new certificate is issued.

Can a parent company’s certificate cover home-use medical devices produced by a subsidiary?

Generally, no. If the subsidiary is not a certificate holder and is not within the audit scope, the regulator will require additional explanations of production and quality system responsibility. Two solutions are possible: integrate the subsidiary into the parent company’s certificate scope, or apply for a separate system certificate in the subsidiary’s name. The former usually involves shorter audit time.

In which countries is the MDSAP certificate more recognized, and is it necessary for home-use medical devices?

The MDSAP certificate is more recognized in member countries such as Australia, Brazil, Canada, Japan, and the United States, but not all home-use medical devices require MDSAP. If the target country explicitly requires MDSAP, it must be obtained; if it is optional, the company can decide based on cost. Most home-use medical devices are not high-risk, and an ISO 13485 certificate in combination with confirmation from a local agent is usually sufficient.

Content Review and Applicability Boundary

Author: AIMEILI Regulatory Editorial Department

Professional Review: AIMEILI Medical Device International Registration Project Team

Source Principle: Priority is given to official regulatory bodies, international organizations, standards organizations, and public regulatory information; industry media and project experience are used only as supplementary judgment.

Applicability Boundary: This article is provided for preliminary understanding, document preparation, and project planning. It does not replace the formal requirements of a target country’s regulatory authority, testing conclusions, or legal advice.

Source and Language Notice

View Chinese original page

Related Reading

Need a registration pathway assessment?

Send product type, intended use, target countries and existing certificates. AIMEILI can help evaluate registration pathway, documentation gaps and compliance risks.

Contact AIMEILI