Quality
An ISO 13485 gap analysis tells you exactly where your quality management system falls short of the standard, clause by clause, before an auditor does. Taylored runs fixed-scope gap analyses for medical device companies of every size, and hands back a findings report with a prioritised plan to close every gap.
Independent, practical and audit-focused. You get a clear picture of your QMS, a realistic route to certification and no surprises on audit day.

A gap analysis is a structured comparison of your current quality management system (QMS) against every requirement of ISO 13485:2016. We work through the standard clause by clause: management responsibility, resource management, product realisation, design and development controls, purchasing and supplier control, production and service provision, measurement, analysis and improvement, and the documentation and record-keeping that ties it all together.
For each clause we look at three things. Does a process exist? Is it documented in a way an auditor can follow? And is there evidence it is actually being followed in practice? A QMS can look complete on paper and still fail an audit because the records do not back it up, so we test the reality, not just the manual.
We also check the regulatory overlay that applies to your devices. ISO 13485 is the backbone, but UK MDR, EU MDR or IVDR, and the FDA's Quality Management System Regulation each add specific expectations. Where your markets need more than the standard itself, the gap analysis says so.
The output is not a pass or fail. It is a map: what is in place, what is partly there, what is missing, and which gaps matter most for the audit you are preparing for.
You are building or finishing a QMS and want to know whether it is ready for a certification body. A gap analysis at this stage stops you booking a Stage 1 audit too early, or paying for documents you already have.
A new device class, a new site, outsourced manufacturing, software added to a hardware device, or a move into new markets. Each changes what the standard and your regulators expect of your QMS, and a gap analysis shows what needs to catch up.
Due diligence teams and Notified Bodies ask the same questions. An independent gap analysis gives you the answers first, so findings are fixed on your timetable rather than raised in someone else's report.
Already certified? A gap analysis also works as a QMS health check ahead of surveillance or recertification audits, particularly if your system has drifted since the last visit or key quality staff have moved on.
Every gap analysis ends with three deliverables, written so that your team can act on them without needing us in the room.
A clause-by-clause record of what we found: conforming, partially conforming or missing, with the evidence we reviewed and the specific requirement each gap relates to. This is the document your certification body will want to see you have acted on.
Gaps ranked by audit risk and effort, sequenced into a plan. Critical gaps that would block certification come first, quick wins next and the polish last, so you spend effort where it changes the outcome.
An honest estimate of the internal hours, any external support and the elapsed time needed to close the gaps, so you can plan resource and set a realistic certification date.
If you want help closing the gaps, we can carry on into QMS implementation, remediation and internal audits. If you would rather do it in-house, the roadmap is written for exactly that.
A typical gap analysis follows six steps. The scope, the clauses in play and the site arrangements are agreed in writing before we start, so the fee is fixed.
Scoping call: your devices, markets, sites and where you think the weak spots are
Document review: quality manual, procedures, work instructions and records, shared securely
Interviews and walkthrough: remote or on-site, with the people who run each process
Clause-by-clause assessment against ISO 13485:2016 and your applicable regulations
Findings report and remediation roadmap, reviewed with you in a closing meeting
Optional next steps: remediation support, QMS implementation or internal audits
Most gap analyses run over two to four weeks from scoping call to closing meeting, depending on the size of the QMS and how quickly documents and people are available. Remote reviews are standard; on-site walkthroughs are added where production or sterilisation processes need to be seen.
Taylored is not a certification body. ISO 13485 certificates are issued by accredited certification bodies after a Stage 1 and Stage 2 audit. What we do is get you through that audit with as few findings as possible, and the gap analysis is the first step of that route.
After the gap analysis comes remediation, where the missing processes and records are put in place, then an internal audit to prove the system works before an external auditor looks at it. Only then do you book the certification body. Skipping steps is how companies end up paying for a failed Stage 2.
If your QMS is already mature, the gap analysis may confirm you are ready and the route is short. If it is not, you will know what it takes before you commit budget to an audit.
Certification-body fees, consultancy support and internal effort: our guide explains what actually drives the price of ISO 13485 certification, how long each stage takes and how to keep the cost down.
A gap analysis is priced as a fixed fee, agreed in writing after the scoping call. What moves the price is the size of your QMS: the number of sites and processes, how many device families and markets are in scope, and whether the review is remote or needs time on site.
We do not publish a rate card, because a two-person software start-up and a multi-site manufacturer with sterile products are not the same job. What we can promise is a fixed scope and a fixed fee before any work starts, with no surprises at the closing meeting.
Plenty of device companies come to us with a QMS that was built for ISO 9001, inherited from a parent company, or written by a consultant who has since moved on. You do not need to start again. The gap analysis tells you what to keep, what to adapt and what to add.
The same applies if you are already certified and want an independent view before a surveillance or recertification audit. We treat it as a mock audit with a roadmap attached.
You can, and a checklist is a reasonable first pass. What a template cannot do is judge whether your evidence would satisfy an auditor, spot the regulatory requirements that sit on top of the standard for your markets, or tell you which gaps actually matter. An independent review by someone who has sat on both sides of the audit table finds the things a self-assessment tends to miss.
Either. Document review and interviews are usually done remotely, which keeps the fee down and works well for design-led and software companies. Where production, sterilisation or warehousing processes need to be seen, we add on-site time and agree it in the scope.
Typically two to four weeks from scoping call to closing meeting. The main variables are how large your QMS is and how quickly your team can share documents and make people available for interviews.
Not always, but it is worth it before a recertification audit, after a significant change to your devices or organisation, or when a new regulation such as the FDA's QMSR changes what your QMS has to demonstrate. It is much cheaper to find a gap yourself than to have a certification body raise it as a major nonconformity.
You decide. Some clients take the roadmap and close the gaps in-house. Others ask us to run the remediation, build out the QMS or carry out the internal audit that comes before certification. Both routes are fine; the report is written so that either works.
Our quality team has built, audited and rescued ISO 13485 systems for start-ups and established manufacturers, and includes experienced lead auditors who know what a certification body will actually look for. You get a straight answer on where you stand and a plan you can run with.