
That's changing. The FDA's Quality Management System Regulation (QMSR) final rule took effect February 2, 2026, formally incorporating ISO 13485:2016 into U.S. federal regulation. The two frameworks that quality teams have treated as separate systems for 30 years are now, legally, mostly the same system.
This guide breaks down what each framework actually requires, where meaningful differences remain, and what your quality team needs to do now that harmonization is law.
Key Takeaways
- ISO 13485 is a voluntary global standard; the QMSR (formerly 21 CFR 820) is binding U.S. law that now incorporates ISO 13485:2016 by reference
- Since February 2, 2026, FDA and ISO 13485 requirements overlap substantially, plus a few U.S.-specific additions
- QMSR is closing historical gaps in risk management, documentation, and supplier oversight
- International sellers still need standalone third-party ISO 13485 certification — QMSR compliance doesn't grant one
- One risk-based QMS built on ISO 13485:2016 is the most efficient path to satisfy both U.S. and global regulators
ISO 13485 vs 21 CFR 820 (QMSR): Quick Comparison
Both frameworks share the same goal: safe, effective medical devices. They differ in legal status, how prescriptive they are, and who checks your work.
Legal Status
- ISO 13485: Voluntary standard verified through third-party certification bodies or notified bodies. Required for market access in the EU, Canada, Australia, and most other regulated markets.
- 21 CFR 820 (QMSR): Legally enforceable U.S. federal regulation. Noncompliance can trigger FDA 483 observations, warning letters, or import bans.
Documentation & Prescriptiveness
- ISO 13485: Spells out required procedures, a quality manual, and specific supporting records for nearly every process.
- QMSR: Historically more performance-based, judging whether a process worked rather than dictating its exact form. Now adopting ISO's documentation structure.
Risk Management Integration
- ISO 13485: Applies risk-based thinking through design, purchasing, and complaint handling, tied directly to ISO 14971.
- QMSR: Lacked an explicit system-wide risk mandate under old Part 820. The 2024 Federal Register final rule closes that gap by adopting ISO 13485's risk-based structure.
Supplier Oversight
- ISO 13485: Requires formal supplier qualification criteria, ongoing performance monitoring, and documented re-evaluation.
- QMSR: Brings this rigor into U.S. law more explicitly, moving past a narrower focus on incoming inspection alone.
Regulatory Enforcement & Audit Access
- ISO 13485: Assessed through periodic third-party certification audits; auditors can review internal audit and management review records.
- QMSR: Eliminates the old exemption that kept FDA inspectors out of those same internal records — a significant shift covered below.

What Is ISO 13485?
ISO 13485:2016 is the international quality management system standard built specifically for medical devices. It borrows its process model from ISO 9001 but tailors every clause to the realities of device design, production, and servicing under regulatory scrutiny.
Each requirement maps to an operational outcome:
- Risk-based lifecycle management reduces recall risk by catching problems before they reach patients
- Structured design controls speed up regulatory submissions because traceability already exists
- Documented supplier oversight cuts down on incoming quality escapes from vendors
The 2016 edition replaced the 2003 version with material QMS changes, not cosmetic edits:
- Risk management required across the full QMS, not only the product
- Stronger complaint-handling procedures
- A dedicated design-transfer section
- Clearer regulatory reporting obligations
Those updates were written to align more closely with global regulators, including the FDA.
Use Cases of ISO 13485
For most companies selling outside the U.S., ISO 13485 certification isn't optional. It's the entry ticket.
- EU market access under MDR/IVDR generally requires a certified QMS aligned to ISO 13485
- Canada and Australia have built ISO 13485 into their regulatory frameworks as baseline expectations
- Contract manufacturers, Class II/III device makers, and IVD companies pursuing multi-country distribution commonly hold certification before they can bid on business
ISO doesn't issue certificates itself. Organizations work with independent certification bodies to get audited and certified, per ISO's own guidance on the standard. That third-party layer is precisely why ISO 13485 conformance and FDA compliance, even under the new QMSR, aren't automatically interchangeable.
What Is 21 CFR Part 820 (Now the QMSR)?
21 CFR Part 820 has governed the design, production, labeling, and distribution of medical devices sold in the U.S. since it was substantially revised in 1996. As of February 2, 2026, it has a new name: the Quality Management System Regulation (QMSR).
FDA published the final rule on January 31, 2024 (with Federal Register publication on February 2, 2024), giving manufacturers a two-year transition window before the QMSR became enforceable.
The regulation still rests on the same core requirements:
- **Design controls and a Design History File** create traceability from initial concept through production
- CAPA and complaint-handling requirements drive continuous improvement rather than one-off fixes
- Document, purchasing, and production controls keep records, suppliers, and manufacturing under defined procedures
What's new is a set of U.S.-specific requirements layered on top of the ISO 13485 base:
- Complaint file documentation requirements beyond ISO's baseline
- Unique Device Identification (UDI) recordkeeping
- Labeling and packaging inspection procedures
- Retention of FDA's statutory "safety and effectiveness" language, distinct from ISO's "safety and performance" phrasing
Who Must Comply with the QMSR
Compliance is mandatory for anyone manufacturing or distributing devices in the U.S., regardless of whether they also hold ISO certification.
- Domestic device manufacturers with no international ambitions still must meet the QMSR in full
- U.S.-only contract manufacturers face the same inspection standards as global players
- First-time post-QMSR inspectees are learning FDA's Compliance Program 7382.850, which replaced the old QSIT model
Design controls, CAPA, and complaint files have historically been among FDA's most cited Quality System deficiencies during inspections. That pattern is unlikely to shift just because the regulation changed names.
ISO 13485 vs 21 CFR 820: Key Differences and Which Applies to You
The historical gaps between these two frameworks (documentation style, risk integration, supplier rigor, audit transparency) are narrowing fast. But "mostly the same" isn't identical. Here's how to know what you actually need.
If you sell only in the U.S.: You must meet the QMSR. Full stop. ISO 13485 certification is not required, though building your system to ISO's structure now makes QMSR compliance easier.
If you sell internationally: You still need standalone ISO 13485 certification from a notified body or registrar. QMSR compliance, even though it now incorporates ISO 13485:2016, doesn't produce a certificate you can hand to a European regulator.
Per FDA's own QMSR FAQ, FDA does not issue ISO certifications, and an ISO certificate doesn't exempt you from FDA inspection either. These remain two separate verification paths that now share one underlying rulebook.
If you're already ISO 13485-certified: You're most of the way to QMSR-ready, but not entirely there. You'll still need to layer on:
- UDI recordkeeping practices
- Complaint file documentation beyond ISO's Clause 8.2.2 baseline
- MDR (medical device reporting) obligations specific to FDA
If your system was built narrowly around the old Part 820: This is where the real exposure sits. FDA inspectors can now review internal audit and management review records that were previously off-limits under the old Section 820.180(c) exemption. Teams that treated those records as internal-only documents now need to write them with the same rigor they'd apply to anything auditor-facing.

That shift means quality teams need to read both frameworks fluently and turn requirements into evidence an inspector or notified body will accept. For a lot of teams, that dual fluency is still a real gap.
QMS Learning's Medical Device & Life Sciences pathway (pilot cohort Q3 2026) is built around that problem: ISO 13485 and 21 CFR Part 820 side by side, with practice producing the records auditors and FDA investigators actually review.
Conclusion
ISO 13485 remains the passport for global market access. The QMSR—21 CFR 820 under its new name—is the non-negotiable floor for selling in the U.S. As of 2026, one QMS aligned to ISO 13485:2016 covers the bulk of both requirements for most teams.
The practical payoff shows up in three places:
- Less duplicate documentation across standards
- Fewer parallel audit cycles to plan and host
- Stronger inspection posture when FDA reviewers can see records (internal audits, management reviews) that used to stay internal
Frequently Asked Questions
Does the FDA recognize ISO 13485?
As of the QMSR final rule, effective February 2, 2026, FDA formally incorporates ISO 13485:2016 by reference into its regulations. ISO certification itself, however, doesn't replace an FDA inspection.
What is the difference between the FDA QMSR and ISO 13485?
FDA's regulation (the QMSR, formerly 21 CFR 820) is legally binding U.S. law enforced through direct inspections. ISO 13485 is a voluntary international standard verified through third-party certification audits.
When was 21 CFR Part 820 introduced?
The regulation dates to a major 1996 revision, effective in 1997. It was substantially revised again into the Quality Management System Regulation via a final rule published February 2, 2024, effective February 2, 2026.
What is the QMSR and how does it affect 21 CFR 820?
The QMSR is the renamed, revised version of 21 CFR Part 820. It incorporates ISO 13485:2016 requirements directly while retaining a handful of FDA-specific additions like UDI recordkeeping and complaint file documentation.
Do I still need separate ISO 13485 certification if I comply with the QMSR?
Yes, if you sell internationally. QMSR compliance alone doesn't grant ISO 13485 certification. Companies selling outside the U.S. still need a separate audit from a notified body or registrar.
What happens during an FDA inspection under the QMSR?
FDA inspectors can now review previously exempt records, including internal audits and management reviews. FDA also moved to a new inspection process, Compliance Program 7382.850, replacing the older QSIT model.


