A Class 2 or Class 3 medical device application arrives at Thai FDA with hundreds of pages of technical data, and it can still be returned at the document completeness check for one reason: the ISO 13485 certificate attached doesn't cover what the applicant thinks it covers. This is one of the more preventable stalls we see in a CSDT submission, and it happens because manufacturers treat the certificate as a checkbox rather than a document whose scope, issuing body, and validity period all have to line up precisely with the product being registered.
Why Thai FDA asks for it
ISO 13485:2016 is the international quality management standard written specifically for the medical device industry, and it exists to demonstrate that a manufacturer's processes consistently produce devices meeting both customer expectations and regulatory requirements. Under the Medical Device Act B.E. 2562 (2019), Thai FDA treats a current, appropriately scoped ISO 13485 certificate as required evidence in the Common Submission Dossier Template (CSDT) for Class 2 and Class 3 devices. An application that arrives without one doesn't make it to technical review; it gets returned at the completeness screen before a reviewer even looks at the clinical or technical sections.
Class 1 devices follow a notification pathway rather than full registration, and Thai FDA does not require ISO 13485 certification as part of that notification. That said, we still recommend Class 1 manufacturers maintain a compliant quality system voluntarily, since the post-market surveillance and incident reporting obligations that apply across all device classes are far easier to satisfy when a real QMS is already in place.
Getting the scope right
The most common way a certificate fails to satisfy Thai FDA isn't that it's missing, it's that its scope doesn't match the product. Three elements matter here. First, product scope: the certificate has to name the category of device being registered in terms consistent with its intended use and classification. A certificate scoped to surgical instruments doesn't automatically extend to active implantable devices, even when the same company manufactures both at the same site. Second, activity scope: if design work happens at one facility and manufacturing at another, both sites' certificates may need to demonstrate coverage of the specific activities relevant to the Thai submission. Third, site coverage: a group or multi-site certificate only satisfies the requirement for the specific facilities named in its scope, not for every plant the parent company operates.
Manufacturers who assume a broad corporate ISO 13485 certificate automatically covers every product line and every facility are the ones most likely to get a scope query back from Thai FDA mid-review. Checking the scope language against the actual device and site before submission avoids that entirely.
Certification bodies Thai FDA will accept
Thai FDA accepts ISO 13485 certificates issued by certification bodies holding accreditation from a national accreditation body that participates in the International Accreditation Forum (IAF) multilateral recognition arrangement. In practice, certificates issued under accreditation from bodies such as UKAS in the UK, DAkkS in Germany, COFRAC in France, A2LA in the US, JAB in Japan, and their equivalents in other IAF member countries are all accepted. The certifying body's name and accreditation number appear on the certificate itself and can be cross-checked against the IAF member database if there's any doubt.
European Notified Bodies also produce acceptable certificates in most cases, since they're accredited for medical device QMS audits under national bodies that are themselves IAF members. One detail worth flagging: the certificate needs to reference ISO 13485:2016 specifically. A certificate that only cites "EN ISO 13485" without the year designation may prompt Thai FDA to ask which version was actually audited against, adding an avoidable delay.
Validity, surveillance audits, and dossier timing
ISO 13485 certificates are typically issued for a three-year period, but that validity is conditional on annual surveillance audits conducted by the certification body. A certificate whose surveillance audit has lapsed isn't in good standing, regardless of whether the formal expiry date has technically passed, and Thai FDA will not treat it as satisfying the requirement. At the three-year mark, a full recertification audit resets the clock; manufacturers need to plan that recertification well in advance, because even a brief gap in certificate validity creates a compliance problem in the Thai registration record and can trigger a variation application just to update it.
The certificate submitted with the CSDT dossier must also stay valid throughout Thai FDA's entire review period, not just at the moment of submission. If it expires while the application is under review, an updated certificate has to be provided before registration will be issued. This makes certificate expiry a project management consideration as much as a regulatory one: submitting a dossier six months before a certificate lapses, when the review itself typically takes several months, is a common and entirely avoidable way to create a mid-review scramble.
Beyond the certificate itself, the CSDT needs supporting evidence that the manufacturer's QMS procedures actually address the device's specific lifecycle: design and development controls, risk management, production controls, non-conformance and CAPA handling, and post-market surveillance. How much detail Thai FDA expects scales with the device's risk classification. A straightforward Class 2 device might only need a summary of the relevant QMS elements, while a complex Class 3 device with significant software components will draw scrutiny on software lifecycle documentation, validation records, and change management procedures. The post-market surveillance plan specifically needs to describe how post-market data gets collected and evaluated, what vigilance procedures exist for incident reporting, and how feedback from the Thai market feeds back into the manufacturer's ongoing risk management process.
What this means for your registration timeline
Every ISO 13485 problem described above is discoverable before submission, not after. A scope gap, an overdue surveillance audit, or a certification body that doesn't meet IAF accreditation are all things that can be checked against the actual certificate weeks before a dossier goes anywhere near Thai FDA. Manufacturers who build that check into their CSDT preparation timeline avoid the far more expensive version of this problem, which is a returned application and a restarted submission clock. DeeMED Consulting reviews ISO 13485 certificates and supporting QMS documentation as part of building out the CSDT dossier for foreign manufacturers registering medical devices in Thailand, catching certificate scope and validity issues before they become a Thai FDA query.
Sources & Further Reading
- Thai FDA, Medical Device Act B.E. 2562 (2019) and CSDT requirements — www.fda.moph.go.th
- ISO 13485:2016, Medical devices — Quality management systems — Requirements for regulatory purposes
