← Back to blog

FDA QMSR 2026: ISO 13485 Alignment, Inspections & What Changed

Written by Sarah Jennings · FDA Compliance Specialist

FDA Quality Management System Regulation (QMSR) took effect Feb 2, 2026. How Part 820 now incorporates ISO 13485:2016, CP 7382.850 replaces QSIT, and what RA/QA teams must do.

FDAQMSRISO-1348521-CFR-820QUALITY-SYSTEMINSPECTIONSMEDICAL-DEVICES

§ KEY TAKEAWAYS

  • QMSR took effect February 2, 2026: 21 CFR Part 820 is retitled QMSR and incorporates ISO 13485:2016 by reference.
  • QSIT is withdrawn; FDA inspects under Compliance Program 7382.850 with six QMS areas plus four OAFRs.
  • ISO 13485 certification is not required and does not exempt a firm from FDA inspection.
  • Management reviews, internal audits, and supplier audit reports are now in-scope for FDA review.

FDA QMSR Explained: What Changed When the Quality Management System Regulation Took Effect

On February 2, 2026, the U.S. Food and Drug Administration’s Quality Management System Regulation (QMSR) became effective. The rule amends the device current good manufacturing practice (CGMP) requirements in 21 CFR Part 820, retitles that part as the QMSR, and incorporates by reference ISO 13485:2016 — the international consensus standard for medical device quality management systems.

For quality, regulatory, and operations teams, this is not a cosmetic renumbering exercise. It changes how Part 820 is structured, how FDA prepares and conducts inspections, which records investigators may request, and how U.S. requirements relate to systems you may already run for CE Marking, MDSAP, or other markets.

This guide is written for manufacturers of finished devices and related establishments subject to Part 820. It summarizes what the final rule and FDA’s public QMSR materials say, what Compliance Program 7382.850 changes about inspections, and a practical readiness checklist. It is not legal advice; always verify against the current regulation text and FDA primary sources before changing SOPs.

What Is the QMSR?

The QMSR is the revised 21 CFR Part 820 framework that:

  1. Incorporates ISO 13485:2016 by reference as the core quality management system requirements for device CGMP (with FDA-specific additional provisions retained where needed).
  2. Aligns U.S. device quality system terminology and structure more closely with the ISO standard used by many other regulators.
  3. Replaces the legacy Quality System Regulation (QSR) architecture that industry associated with the long-standing QSIT inspection playbook.

The final rule was published in the Federal Register on February 2, 2024, with a two-year delayed effective date of February 2, 2026. That lag was intentional: FDA expected manufacturers to gap-assess existing QS procedures against ISO 13485:2016 and implement changes before enforcement under the new part.

What “incorporates by reference” means in practice

Incorporation by reference means the ISO 13485:2016 requirements FDA designated become enforceable U.S. regulatory requirements through Part 820 — not optional guidance. Manufacturers must establish and maintain a quality management system that meets those incorporated requirements and the additional FDA requirements that remain in Part 820 (and other applicable device regulations).

Critical clarifications FDA has stated publicly:

  • ISO 13485 certification is not required for QMSR compliance.
  • FDA will not issue certificates of conformance to ISO 13485.
  • Holding an ISO 13485 certificate does not exempt a manufacturer from FDA inspection.
  • FDA inspections assess compliance with FDA regulations, not third-party certification schemes. FDA has also stated that QMSR inspections do not follow the MDSAP audit plan or procedures.

In short: ISO alignment reduces dual-system friction for global firms, but it is not “one ISO certificate replaces FDA oversight.”

Timeline at a Glance

DateEvent
February 2, 2024QMSR final rule published (Federal Register)
February 2, 2026FDA Compliance Program 7382.850 (Inspection of Medical Device Manufacturers) — issuance/implementation date per FDA CP materials
February 2, 2026QMSR effective; enforcement under revised Part 820 begins
February 2, 2026QSIT withdrawn; CP 7382.845 and PMA inspection CP 7383.001 no longer used for these inspections

If your SOPs, training decks, or supplier quality agreements still say “QSIT subsystems” as the way FDA inspects, they are out of date as of the effective date.

How Inspections Changed: CP 7382.850 Replaces QSIT

Under the old Quality System Regulation, many inspections were organized around the Quality System Inspection Technique (QSIT) and its familiar subsystems (commonly discussed as management controls, Design Controls, CAPA, and production and process controls).

On the QMSR effective date, FDA stated that it stopped using QSIT and began using the process in Compliance Program 7382.850. After February 2, 2026, FDA no longer uses:

  • Inspection of Medical Device Manufacturers (7382.845)
  • Medical Device PMA Preapproval and PMA Postmarket Inspections (7383.001)

for the inspection approach those documents previously governed.

Six QMS areas + four “other applicable FDA requirements” (OAFRs)

FDA’s public QMSR materials and Compliance Program 7382.850 describe a risk-based inspection process. The current CP (FDA CDRH compliance program pages / media download for 7382.850) organizes coverage around six Quality Management System (QMS) areas and four Other Applicable FDA Requirements (OAFRs) in the risk-based process description and Attachment A. Always use the current FDA PDF if labels or figures are updated.

QMS areas (per CP 7382.850 risk-based process):

  1. Change control
  2. Design and development
  3. Management oversight
  4. Measurement, analysis, and improvement
  5. Outsourcing and purchasing
  6. Production and service provision

OAFRs (per CP 7382.850):

  1. Medical Device Reporting (MDR)
  2. Reports of corrections and removals
  3. Medical device tracking
  4. Unique Device Identification (UDI)

Each area/OAFR contains elements corresponding to regulatory requirements. Investigators are expected to prioritize risk to patients and users, not a fixed "tick every QSIT subsystem checkbox" routine.

Two inspection models (not the old QSIT "levels")

CP 7382.850 describes two inspection models (confirm exact figures/triggers in the current FDA PDF):

  1. Most inspections: Cover a minimum of one element in each QMS area and OAFR, choosing elements based on potential adverse impact to patients/users.
  2. Baseline / certain preapproval-style coverage: For establishments with no prior FDA device inspection or MDSAP audit and not enrolled in MDSAP (baseline surveillance), and for PMA preapproval inspections, the program specifies particular elements that should be covered in each area/OAFR.

Across models, investigators also review general items such as Establishment Registration and Device Listing, marketing authorizations, prior Form FDA-483 / compliance history, and assignment-specific instructions.

Greater emphasis on Risk Management across the product lifecycle

A recurring theme in the new inspection program is risk management integrated through product realization — not treated as a separate design-only exercise. Investigators are expected to use risk-related documentation (for example MDRs, corrections/removals, complaints and feedback, postMarket Surveillance and servicing data) to understand product risk and to test whether the firm’s controls match that risk.

CP 7382.850 also elevates certain risk-management failures as examples of serious inspection outcomes (including classifications that can support Official Action Indicated pathways). Treat risk files, CAPA linkages, and change-control impact assessments as inspection-facing evidence, not only internal ISO paperwork.

Records that were historically off-limits are now in play

Under the prior QS regulation, certain quality assurance records — notably management reviews, internal quality audits, and related exclusions under old § 820.180(c) — were generally outside routine FDA review practice. ISO 13485 does not contain those U.S.-specific exemptions.

FDA’s QMSR FAQ states that under the QMSR, FDA has authority to inspect management review, quality audits, and supplier audit reports, and that the QS-era exceptions are not maintained. Firms should expect investigators to request these records under the QMSR inspection framework.

Practical implication: Write management reviews and internal audits assuming an investigator may read them. Vague findings, closed CAPAs without effectiveness checks, or “paper-only” supplier audits are now more dangerous, not less.

Other shifts called out in the new inspection program

CP 7382.850 also addresses (confirm details in the current PDF):

  • Remote regulatory assessments (RRAs) are more formally integrated into the device oversight toolkit (FDA may use remote review of establishments and records in lieu of or ahead of on-site inspection).
  • Cybersecurity / cyber devices receive explicit attention for software-enabled products, consistent with broader FDA device cybersecurity policy and statutory reforms.

Firms with connected devices should ensure quality system evidence for secure design, update processes, and vulnerability handling is inspection-ready — not only premarket submission-ready.

What Did Not Magically Disappear

QMSR does not erase FDA-specific postmarket and identification regimes. OAFRs exist precisely because ISO 13485 alone does not fully replace:

  • 21 CFR Part 803 — Medical Device Reporting
  • 21 CFR Part 806 — Corrections and removals
  • Device tracking requirements where applicable
  • UDI labeling and GUDID obligations

Complaint handling, CAPA, design controls, production controls, and process validation remain central — now framed through the ISO-aligned QMS structure and evaluated with a stronger risk lens.

Also unchanged in spirit: FDA still expects a quality system that actually works for the devices you ship. Harmonization with ISO is about structure and global consistency, not a lower bar.

QMSR vs ISO 13485 vs MDSAP (Quick Comparison)

TopicPractical takeaway under QMSR
ISO 13485:2016Core QMS requirements incorporated by reference into Part 820
ISO certificateOptional commercially; not a substitute for FDA compliance or inspection
MDSAPUseful multipurpose audit program; FDA has stated QMSR inspections do not follow MDSAP procedures
EU MDR / other marketsCloser QMS language reduces dual documentation pain, but market-specific technical docs and PMS/vigilance still differ
Inspection evidenceExpect deeper review of risk, change control, supplier control, and audit/management review records

Readiness Checklist for RA / QA Teams

Use this as an operational gap list (adapt to your firm size and device risk):

1. Map procedures to QMSR / ISO structure

  • Gap-assess each SOP against ISO 13485:2016 clauses plus remaining FDA-specific Part 820 and OAFR requirements.
  • Retire or rewrite QSIT-centric inspection readiness binders that organize only by old subsystems without a risk-based story.
  • Align document control so the “current” QMS package is unambiguous during inspection.

2. Make risk management inspection-facing

  • Demonstrate risk management across design, production, purchasing, change control, and postmarket feedback — not only a design-stage FMEA archive.
  • Link complaints, MDRs, corrections/removals, and service data into risk file updates with dated decisions.
  • Train CAPA owners to show how residual risk and risk acceptability criteria drive actions.

3. Prepare management review and audit packages

  • Ensure management reviews include required inputs/outputs, resource decisions, and follow-up of previous actions.
  • Treat internal audit reports as discoverable: findings, scope, independence, CAPA, effectiveness.
  • Supplier audits: ensure schedules, criticality, and follow-up SCAR evidence match purchasing controls.

4. Rehearse the new inspection models

  • Walk through “one element per QMS area + OAFR” coverage with your most risk-relevant products.
  • For new sites or PMA preapproval situations, prepare for the more prescribed element list in model 2.
  • Update front-room / back-room scripts so staff do not refuse lawful requests for management review or audit reports based on obsolete QS-era assumptions.

5. Connect quality system change to Regulatory Intelligence

QMSR did not freeze the rest of the FDA environment. Guidance updates, inspection classification trends, cybersecurity expectations, and postmarket databases still move. Quality leadership needs a feed of regulator-published changes that might force SOP or risk file updates — not only a one-time 2026 conversion project.

MedFlux monitors FDA publications and 26 other device regulators so quality and regulatory teams see inspection-relevant policy changes in one workflow — alongside postmarket signals from tools such as FDA recall lookup and adverse-event intelligence in our MAUDE and AEMS guides.

Frequently Asked Questions

When did the FDA QMSR take effect?

February 2, 2026. The final rule published February 2, 2024, with a two-year delayed effective date.

Does QMSR replace 21 CFR Part 820?

It amends and retitles Part 820 as the Quality Management System Regulation and incorporates ISO 13485:2016 by reference, with additional FDA requirements retained. Practitioners still talk about “Part 820,” but the content and inspection approach are the QMSR regime.

Is ISO 13485 certification required under QMSR?

No. FDA does not require ISO 13485 certificates and does not issue them. A certificate does not exempt you from FDA inspection.

What replaced QSIT?

FDA stopped using QSIT on February 2, 2026, and inspects under Compliance Program 7382.850 (Inspection of Medical Device Manufacturers). Prior CPs 7382.845 and 7383.001 are no longer used for the approaches they previously covered.

Can FDA review internal audit and management review records?

Yes. FDA’s QMSR FAQ states the agency may inspect management review, quality audits, and supplier audit reports; the prior QS exceptions are not maintained in the QMSR.

Does MDSAP participation change how FDA inspects under QMSR?

MDSAP enrollment and audit history can affect inspection planning context (including baseline vs non-baseline model selection described in industry analyses of CP 7382.850). FDA has stated that QMSR inspections do not follow MDSAP audit procedures, and ISO/MDSAP certificates do not replace FDA regulatory assessment.

Primary Sources and Further Reading

Always prefer primary materials when updating SOPs:

  • FDA — Quality Management System Regulation (QMSR) overview and FAQ pages on fda.gov
  • Federal Register final rule (February 2, 2024): Medical Devices; Quality System Regulation Amendments
  • FDA Compliance Program 7382.850Inspection of Medical Device Manufacturers (FDA materials list issuance/implementation with the February 2, 2026 effective date; confirm you hold the current PDF from FDA)
  • ISO 13485:2016 — Medical devices — Quality management systems — Requirements for regulatory purposes (copyrighted standard; obtain via authorized channels)

Related Resources

Sarah Jennings
AUTHOR

Sarah Jennings

FDA Compliance Specialist

Specializes in FDA 510(k) submissions, De Novo pathways, and Quality System Regulation (21 CFR 820) remediation.

LINKEDIN ↗

Editorial policy · About MedFlux · Updated 2026-08-06