ISO 13485 vs GDPMD: two systems, one wrong choice to avoid.
They are not competitors — they cover different halves of the device supply chain. The expensive mistake is implementing the wrong one, or both, badly. Here is the clean split, the grey zones, and what each actually costs.
Manufacturer → ISO 13485. Importer, distributor or AR → GDPMD.
ISO 13485 is the international quality management standard for organisations that design and manufacture medical devices. It underpins conformity assessment for MDA registration, and it is the audit basis for MDSAP, CE marking and FDA QMSR compliance.
GDPMD — Good Distribution Practice for Medical Devices — is Malaysia's own requirement for organisations that import, distribute or represent devices. It is a condition of the MDA establishment licence for those roles: no GDPMD certificate, no licence, no market.
If you only read one line: the standard follows the activity, not the company. One legal entity that manufactures and imports needs both, under one integrated system. Two companies that both call themselves “suppliers” can need completely different certificates.
Settle it in five questions
Answer these about what your company physically does with the device. Any single “yes” in the first three puts you in manufacturer territory for that activity.
- Does the device carry your name or brand when it reaches the customer? If yes, you are likely its manufacturer regardless of who built it.
- Do you assemble, kit, sterilise, refurbish or modify it? If yes, that process is yours to control and validate.
- Do you design or specify it, even if production is outsourced? Owning the design owns the design controls.
- Do you import, store, transport or sell devices made by others under their name? If yes, you need GDPMD for those activities.
- Do you act as the local presence for a foreign manufacturer? That is authorised representative scope — GDPMD, plus AR obligations on the licence.
Yes to both halves is normal and not a problem. It means one integrated system with a scope statement covering both — see below.
Side by side
| ISO 13485 | GDPMD | |
|---|---|---|
| Who needs it | Manufacturers (incl. local assembly/relabelling) | Importers, distributors, authorised representatives |
| Nature | International standard (ISO 13485:2016) | Malaysian regulatory requirement |
| Legal hook | Quality-system basis for manufacturer conformity assessment | Condition of the establishment licence under Act 737 |
| Core scope | Design, production, risk management, traceability | Storage, transport, traceability, installation/servicing, recall |
| Audited by | Certification bodies (and MDSAP AOs) | CABs registered with MDA |
| Recognised outside Malaysia | Yes — the global baseline | No — Malaysia-specific |
| Export value | High — basis of MDSAP, CE, FDA QMSR | Malaysia-specific |
| Surveillance | Annual | Annual |
| Our fee, year 1 | RM7,500 + certification-body and MDA licence fees, paid direct | RM5,500 + certification-body audit, paid direct |
What ISO 13485 actually demands
ISO 13485:2016 is a quality management system standard written specifically for medical devices. It shares its skeleton with ISO 9001 but diverges everywhere that patient safety is involved: where ISO 9001 asks you to satisfy customers, ISO 13485 asks you to demonstrate regulatory compliance and control risk. Certification is granted against the whole system, not against a product.
The clauses that generate the real work:
- Clause 4 — quality management system. A quality manual, a defined scope with justified exclusions, and — the one people underestimate — a medical device file for each device or family, holding the specification, manufacturing and measurement records in one traceable place.
- Clause 5 — management responsibility. A named management representative with real authority, a quality policy that is more than a poster, and management reviews with recorded inputs and outputs. Auditors read the minutes.
- Clause 6 — resources. Competence records for everyone whose work affects product quality, plus controlled infrastructure and work environment — cleanliness, contamination control, and controlled conditions where the device demands them.
- Clause 7 — product realisation. The largest clause: design and development controls with verification and validation, purchasing controls over your suppliers, production and process validation, and identification and traceability throughout. Sterile devices carry additional obligations.
- Clause 8 — measurement, analysis and improvement. Complaint handling, reporting to regulators, internal audit, control of nonconforming product, and corrective and preventive action that actually closes.
Risk management runs through all of it, and in practice a CAB will expect to see ISO 14971 applied properly rather than a risk table assembled the week before the audit.
What GDPMD actually demands
GDPMD governs everything that happens to a device after it leaves the manufacturer and before it reaches the user. The premise is simple: a perfectly manufactured device can still injure someone if it is stored at the wrong temperature, shipped without protection, installed by an untrained technician, or cannot be traced when a recall is issued.
The system therefore has to control:
- Storage and handling — segregated areas, controlled temperature and humidity where the device requires it, and quarantine for returned, damaged, expired or recalled stock so it cannot re-enter supply.
- Traceability — the ability to identify what you received, from whom, and every customer it went to, by batch or serial number. This is the single most common failure point, and the thing a recall exposes instantly.
- Transport and delivery — protecting the device in transit, and validating cold-chain conditions where they apply.
- Installation and servicing — where you install, commission or service devices, with competent, trained personnel and records to prove it.
- Complaints, recall and vigilance — a documented mechanism for handling complaints, escalating adverse events to MDA, and executing a field corrective action. Most CABs will ask you to demonstrate a mock recall.
The grey zone: when a “distributor” is really a manufacturer
This is where companies lose the most money, because they certify the wrong system and discover it during an assessment. Under the Malaysian framework, you are pushed toward manufacturer obligations when you do any of the following:
- Relabel under your own name. Putting your brand on a device made by someone else generally makes you its manufacturer for regulatory purposes.
- Assemble or kit. Combining components or bundling devices into a procedure pack that you place on the market under your own name is manufacturing, not distribution.
- Sterilise. If sterilisation happens under your control, that process is yours to validate.
- Modify or refurbish. Changing a device’s intended purpose or performance takes you well past distribution.
Simple repackaging for transport, or translating an instruction leaflet without touching the device, usually does not. But the line is drawn by what you actually do on your floor — not by the words on your business card, and not by which certificate is cheaper.
How certification actually runs
Both certificates follow the same shape, and both are issued by a Conformity Assessment Body — for GDPMD, one registered with MDA for that scope.
- Gap analysis. We walk the site and compare what you do against what the standard requires. You get the shortfall in writing before any money goes to a certification body.
- Documentation. The quality manual, procedures, work instructions and forms — written around your operation rather than pulled off a template shelf, because auditors can tell the difference immediately.
- Implementation. The step companies try to skip. The system has to run long enough to generate genuine records; certifying an empty system is how you fail Stage 2.
- Internal audit and management review. Both are mandatory inputs, and both must be complete before the CAB arrives.
- Stage 1 assessment. A documentation and readiness review. The CAB confirms the system exists and is capable of being audited.
- Stage 2 assessment. The full on-site audit against the standard, looking for evidence that the system is genuinely operating.
- Nonconformity closure, then certification. Findings are closed with corrective action and evidence; the certificate follows.
- Establishment licence. With the certificate in hand, the licence application is filed through MeDC@St — and only then can you begin registering products.
Realistic timelines: three to five months for GDPMD in a distribution business that engages properly, and four to eight months for ISO 13485 in a manufacturer starting without a formal system. An existing ISO 9001 system shortens both, because document control, internal audit and management review already exist in some form.
What it costs
Our fees are published, and so are the certification-body and MDA fees you pay direct — we list them beside our fee, never inside it. See the full fee table. Prices below are current as of .
| Engagement | Our fee | Paid direct by you |
|---|---|---|
| GDPMD certification only | RM5,500 (year 1) | RM4,785 certification-body audit, per warehouse |
| GDPMD + MDA establishment licence | RM5,500 (year 1) | RM4,785 certification-body audit, per warehouse · MDA licence fee per role: distributor RM2,250, importer RM2,250, authorised representative RM4,250 |
| ISO 13485 + MDA manufacturer licence | RM7,500 (year 1) | RM7,500 certification-body audit · RM4,250 MDA manufacturer licence (RM250 application + RM4,000 licence) |
| GDPMD surveillance | RM2,500 / year | RM2,585 certification-body audit, per warehouse (years 2 and 3) |
| ISO 13485 surveillance | RM4,000 / year | RM5,000 certification-body audit (years 2 and 3) |
One thing no consultant can quote for you: the cost of physically meeting the requirement. If GDPMD says your cold chain must be controlled and you have no temperature monitoring, that equipment is a real cost and it is yours. We tell you about it at gap analysis rather than at the audit.
When you need both
A Malaysian manufacturer that also imports complementary products, or a distributor that assembles, kits, relabels or services devices, can hold both obligations at once. The wasteful answer is two separate paper systems with two manuals, two audit calendars and contradictory procedures. The right answer is one integrated quality system whose scope statement covers both sets of activities.
That is how we build it — one manual, one document-control system, one internal audit programme, one management review, one audit calendar, two certificates. The overlap is genuinely large: document control, training records, corrective action, complaint handling and traceability are common to both. Duplicating them doubles your maintenance cost forever and gives an auditor two versions of the truth to find.
And where does ISO 9001 fit?
This is the third standard companies get tangled in, usually because they already hold ISO 9001 and assume it counts. It helps, but it does not substitute.
ISO 9001 is a general quality management standard built around customer satisfaction and continual improvement. ISO 13485 borrows its structure but rewrites the priorities: the objective is not a happier customer, it is a safe device and a demonstrable regulatory position. That produces concrete differences an auditor will look for — the medical device file, design controls with formal verification and validation, process validation where output cannot be fully verified, risk management applied across the entire product lifecycle, complaint handling wired to regulatory reporting, and record retention tied to the lifetime of the device. Notably, ISO 13485 does not require the continual-improvement machinery ISO 9001 does; it requires you to keep the system effective and compliant.
The practical upshot: an existing ISO 9001 system is a genuine head start, because document control, internal audit, management review, training records and corrective action already exist and can be extended rather than invented. Expect a shorter implementation — not a certificate by default.
Choosing a Conformity Assessment Body
You cannot certify yourself, and the body you pick has more effect on the experience than most companies expect. Four things worth checking before you sign:
- Registered scope. The CAB must be registered with MDA for the scope you need, and scopes change. Confirm current registration rather than relying on a certificate someone was shown two years ago.
- Both scopes under one roof. If you need GDPMD and ISO 13485, a body holding both means one audit team, one schedule and one set of corrective actions instead of two of everything.
- Sector familiarity. An assessor who has audited your device category asks sharper questions and wastes far less of your time on misunderstandings about what your product does.
- Realistic lead time. Assessor availability, not your readiness, is frequently the binding constraint on your certification date. Book the slot early; it is the single easiest month to lose.
The certification body's fee is paid by you directly to the body, and we publish the figure we budget with beside our own fee — so choose the body on scope and competence, then check its quotation against the fee table.
Five mistakes that cost real money
- Certifying the wrong system. A relabeller certifying GDPMD alone, then being told at assessment that manufacturer obligations apply.
- Buying a template manual. Documentation that describes a company you are not. Auditors open the records, not the manual, and the gap shows in minutes.
- Certifying an empty system. Going to Stage 2 with no real records because the system was written last month and never run.
- Treating traceability as paperwork. It is the one control a recall tests in public, and the most common major nonconformity in distribution audits.
- Losing the renewal calendar. Three clocks — QMS annually, licence every three years, registration every five — and none of them align. A lapsed certificate can suspend a licence that is holding up every product you sell.
Apa beza ISO 13485 dengan GDPMD?
ISO 13485 ialah sistem kualiti untuk pengilang peranti perubatan; GDPMD pula wajib untuk pengimport, pengedar dan wakil sah sebagai syarat lesen establishmen MDA. Pengilang yang turut mengimport mungkin perlukan kedua-duanya — dan ia sepatutnya dibina sebagai satu sistem bersepadu, bukan dua set dokumen berasingan. Kami boleh sahkan keperluan sebenar syarikat anda secara percuma melalui WhatsApp.
Frequently asked questions
Can GDPMD replace ISO 13485?
Is ISO 13485 mandatory in Malaysia?
We import AND assemble — which applies?
How long does ISO 13485 certification take in Malaysia?
How much does ISO 13485 certification cost in Malaysia?
Is ISO 13485 recognised in place of GDPMD for licensing?
Which is cheaper to get?
Do we need to recertify every year?
Can one CAB certify both?
Still unsure which applies to you?
Describe what your company actually does with devices — import, store, assemble, relabel, service — and we will tell you which system the law expects. Free, and in writing.