ISO 15189 and ISO/IEC 17025 are accreditation, not certification
Medical laboratory and testing/calibration laboratory competence is classified as accreditation, and is not described as an ordinary business ISO certificate.
05
The most common mistake in healthcare is treating three entirely separate activities as one: delivering healthcare, manufacturing medical devices and operating a laboratory. All three fall into different record classes.
Medical laboratory and testing/calibration laboratory competence is classified as accreditation, and is not described as an ordinary business ISO certificate.
The medical device quality management system is one thing and product conformity another. Device class, target market and economic operator role are mandatory questions.
It is product conformity for placing on the EU market, with a notified body involved where required. It is not shown in the same class as an ISO certificate.
For organisations in any sector seeking to standardise processes and manage customer expectations systematically.
For organisations that demonstrate product or service conformity on the basis of measurement results.
For organisations where service interruption is critical, or that are multi-site or critical suppliers.
For organisations that process data, access customer systems or provide cloud services.
For organisations processing personally identifiable information within an ISO 27001 scope.
For organisations and groups of organisations establishing corporate governance over records.
For organisations carrying a broad inventory of regulatory obligations.
For organisations providing facility services or managing large property portfolios.
For organisations that develop, provide or use artificial intelligence in high-impact contexts.
For businesses seeking to address employee, site and operational risks systematically.
For organisations with measurable energy consumption and energy performance targets.
A quality management system for organisations delivering healthcare services.
For organisations that design, manufacture, install or service medical devices.
For businesses producing and supplying primary packaging materials for medicinal products.
For organisations managing air quality in building and facility interiors.
For laboratories and organisations working with hazardous biological materials.
These are not ISO standards; each has its own scheme owner, issuing body and rules. Whether they are candidates is decided by activity and buyer requirement.
HDS is a French statutory certification for anyone hosting personal health data as a GDPR-article-28 processor, issued by COFRAC-accredited bodies.
C5 is the BSI's cloud security criteria catalogue for Germany — auditors examine against it and the output is an attestation (Testat), not a certificate.
MARS-E is CMS's security and privacy standard for ACA Administering Entities, built on the CMS Acceptable Risk Safeguards and NIST SP 800-53 Rev 4.
The Cyber Assessment Framework is the NCSC's outcome-based framework for assessing cyber resilience, structured around 4 objectives and 41 assessments.
The DSPT is NHS England's mandatory self-assessment toolkit for organisations with access to NHS patient data — the output is a status, not a certificate.
EPCS is the DEA rule under 21 CFR 1311.300: providers of electronic prescription or pharmacy applications must obtain a third-party audit.
Last verified:
This page is for information only; it is not legal advice. A record appearing here does not mean it is required for your business. This library does not issue certificates.
Attributing this record helps other researchers verify it independently.
"Healthcare." Certifidex, FutureTechnologies. Last verified 4 August 2026. https://certifidex.com/sectors/healthcare