FDA QMSR Final Rule Transition

Introduction

For nearly 30 years, 21 CFR Part 820 was the bedrock of FDA device quality oversight. That changed on February 2, 2026, when the Quality Management System Regulation (QMSR) officially replaced it, incorporating ISO 13485:2016 by reference.

Many manufacturers are treating this as a documentation refresh — swap some section numbers, update a few templates, call it done. That approach misses the point entirely.

FDA inspectors are no longer checking whether your quality manual mentions the right clause numbers. They're evaluating whether your quality system actually functions as an integrated, risk-based whole.

This article breaks down what QMSR really changes, how FDA inspections work now under Compliance Program 7382.850, and what your team needs to do differently to stay audit-ready.

Key Takeaways

  • QMSR took effect February 2, 2026, folding ISO 13485:2016 and ISO 9000:2015 Clause 3 into Part 820
  • ISO 13485 alignment is not enough — FDA added U.S.-specific requirements, and the FD&C Act controls any conflict
  • Prepare for risk-adaptive inspections under Compliance Program 7382.850; QSIT is retired
  • Extend risk management across the full product lifecycle, not design controls alone
  • Expect FDA inspectors to request management reviews, internal audits, and supplier audit reports

What Is the FDA QMSR?

The device quality regulation has a long history. The original CGMP rule was codified in 1978. It got a major revision in 1996-1997, creating the Quality System Regulation most of the industry grew up with. QMSR is the next chapter, finalized January 31, 2024, and enforceable as of February 2, 2026.

Timeline of FDA device quality regulation history from 1978 to 2026

Incorporation by reference is the mechanism doing the heavy lifting here. Instead of FDA rewriting ISO 13485:2016 into agency language, the standard's text now functions as if it were printed directly inside Part 820. Clause 3 of ISO 9000:2015 gets the same treatment for terminology.

Why FDA Made This Change

FDA's own reasoning is straightforward. According to the Federal Register final rule, the legacy QS Regulation and ISO 13485 contain "substantially similar requirements," and aligning the two reduces redundant systems for companies already selling into international markets.

"Substantially similar" is not the same as identical. QMSR still carries FDA-specific supplements ISO 13485 alone does not cover:

  • Management responsibility expectations beyond ISO's baseline
  • Complaint handling specifics tied to U.S. reporting obligations
  • UDI and traceability rules unique to FDA's framework

Other legacy QSR details shifted rather than carried over. The old rule that design reviews include someone with no direct responsibility for that design stage did not survive intact. ISO 13485 Clause 7.3.5 instead requires representatives of the functions concerned: a less rigid standard.

Who Has to Comply

QMSR applies to finished-device manufacturers intending commercial distribution in the U.S., including certain accessory manufacturers. Blood tubing and diagnostic X-ray components, for example, count as finished devices under FDA's definition because they function as accessories.

Even CGMP-exempt device categories aren't fully off the hook. They still have to maintain complaint files and meet the general recordkeeping requirements under 820.35.

QSR vs QMSR: What Has Actually Changed

The most visible shift is structural. Legacy Part 820 organized requirements into subparts: design controls here, purchasing controls there, each in its own silo. ISO 13485 organizes around integrated, numbered clauses that emphasize how processes interact, not just what each one requires in isolation.

Industry analysis from AAMI describes this as a structural rather than purely substantive change, but flags more than 100 material terminology updates manufacturers need to track across their documentation.

Practical implications:

  • Quality manuals built around old QSR section numbers will need re-indexing to ISO clause language
  • Legacy terminology maps (old term → QMSR equivalent) should live somewhere your team can actually reference them
  • "Purchasing controls" as a narrow concept is gone. It is replaced by ongoing, risk-informed supplier oversight across qualification, monitoring, and reevaluation

The Records Exemption Is Gone

Here's the change that catches manufacturers off guard: the old §820.180(c) exemption protected certain records from routine FDA copying and review. That protection did not carry into QMSR.

Management review reports, internal audit records, and supplier audit reports are now inspectable. If your management review minutes have been a two-paragraph rubber stamp for the last five years, that's about to become visible to an investigator.

Risk-Based Quality System Expectations

The word "risk" appeared exactly once in the old Quality System Regulation. AAMI's review of ISO 13485:2016 counts the term appearing more than 25 times (a rough proxy for how much more rigor the standard expects around risk thinking).

That rigor isn't confined to design controls anymore. Risk-based thinking now needs to show up across:

  1. Design and development: hazard identification tied to actual design decisions
  2. Supplier oversight: risk-proportionate qualification and monitoring
  3. Manufacturing and process controls: ongoing verification tied to product risk
  4. Complaint handling and post-market monitoring: trending that feeds back into risk files

Four areas requiring risk-based thinking under QMSR quality systems

This typically means closer alignment with ISO 14971 for the underlying risk-management methodology. FDA and industry guidance both stress the same distinction: risk rationale must show up in documented decisions. A policy that says "we consider risk" is not enough without evidence of what that consideration changed.

How FDA Inspections Have Changed Under QMSR

If you've been inspected under the old system, you know QSIT, the Quality System Inspection Technique that walked investigators through subsystems one at a time: CAPA, design controls, production and process controls, management controls. That checklist retired on February 2, 2026, and was replaced by Compliance Program 7382.850.

The new program is risk-adaptive rather than subsystem-based. Inspection scope and depth now depend on:

  • Patient and user risk associated with the device
  • Product complexity and novel manufacturing processes
  • Prior inspection history and unresolved deficiencies
  • Emerging signals: recall frequency, adverse event trends, complaint volume

Investigators Now Follow Issues Across the System

Under QSIT, a complaint got reviewed inside the complaint-handling subsystem, largely in isolation. Under CP 7382.850, investigators select relevant elements across six QMS areas and expand their review whenever evidence links one requirement to another.

Practically, that means a single complaint can now pull an investigator through CAPA records, into risk management documentation, and on through production records, following the thread wherever it leads.

Management review has become a genuine focus point in this model. Investigators are looking for evidence of leadership decisions, resource allocation, and follow-through, not meeting minutes that only say "reviewed and approved."

Paper compliance and real process capability are no longer interchangeable. Under QMSR, performance is measured by whether your system holds up when someone pulls a thread, not by how many binders you can produce.

Preparing Your Organization for the QMSR Transition

The most commonly reported hurdles aren't exotic. They're the unglamorous work of:

  • Updating documentation and terminology to match ISO clause language
  • Restructuring quality manuals around integrated processes instead of legacy subparts
  • Requalifying suppliers under broader, ongoing oversight expectations
  • Training staff to think in risk-based, ISO-style terms rather than checklist compliance

Internal audits and mock inspections deserve a rebuild too. If your mock audits still walk the QSIT subsystem checklist, they're rehearsing for an inspection format that no longer exists. Model internal audits on the issue-tracing approach CP 7382.850 actually uses: pick a complaint or nonconformity and trace it across CAPA, risk records, and production data, the way an investigator now would.

Training is where a lot of teams stall out. Building genuine capability, not just course completion, takes real infrastructure.

QMS Learning's Medical Device & Life Sciences QMS pathway (pilot enrollment opens Q3 2026) covers ISO 13485:2016 clause by clause, a subpart-by-subpart review of FDA 21 CFR Part 820, and ISO 14971 risk management from hazard identification through post-market surveillance. The AI Workbench built into the pathway is trained on those same standards and helps engineers:

  • Diagnose whether an issue is a process gap, isolated incident, or design problem
  • Select the right method (CAPA, FMEA, gap analysis, or root-cause investigation)
  • Generate audit-ready artifacts on the spot, including design history file entries and risk management plans

QMSR inspections demand objective evidence of functioning processes, not just updated SOPs in a binder. The platform's Manager Dashboard exports training records, completed scenarios, and time-stamped Workbench activity into a single evidence package.

QMS Learning platform dashboard displaying training records and audit evidence exports

That package lets a team show readiness when an investigator is in the room, instead of scrambling to assemble proof after the fact.

QMSR vs MDSAP: Are They the Same Thing?

Short answer: no, and confusing the two creates real exposure.

FDA inspections under QMSR do not follow the MDSAP audit plan or procedures. FDA will neither require nor issue certificates of conformance to ISO 13485. Those two facts alone should end the assumption that a clean MDSAP audit protects you from an FDA inspection.

Aspect QMSR (FDA Inspection) MDSAP
Nature Mandatory regulatory enforcement Voluntary third-party audit program
Scheduling Risk-based, triggered by signals like recalls and product complexity Fixed annual audits on a three-year certification cycle
Outcome Inspection findings, Form 483, warning letters Certificate covering multiple participating regulators
Substitutes for FDA inspection? N/A No

A valid ISO 13485 or MDSAP certificate doesn't exempt a manufacturer from FDA inspection. The programs run on different clocks and serve different purposes. MDSAP is still useful: one audit cycle can satisfy multiple participating regulators. It is not a substitute for QMSR compliance.

Frequently Asked Questions

What is the FDA QMSR?

QMSR is FDA's revised device quality regulation, effective February 2, 2026, which incorporates ISO 13485:2016 by reference in place of the former Quality System Regulation (21 CFR Part 820).

What is the difference between the MDSAP and QMSR programs?

QMSR is FDA's mandatory regulatory framework enforced through direct inspection. MDSAP is a voluntary third-party audit program that does not exempt manufacturers from FDA inspection.

What U.S.-specific requirements does QMSR add beyond ISO 13485?

QMSR adds FDA-specific expectations on top of ISO 13485, including device labeling and packaging controls, unique device identification (UDI) linkages, and certain record and reporting obligations tied to 21 CFR requirements.

When did the QMSR officially take effect?

The rule was finalized January 31, 2024, published in the Federal Register on February 2, 2024, and became enforceable on February 2, 2026.

If my company is already ISO 13485 certified, does QMSR still require changes?

Yes, though typically a lighter lift. Certified companies still need to confirm alignment with FDA's added U.S.-specific requirements that sit on top of the base ISO 13485 clauses.

Will FDA review records created before the QMSR effective date?

Yes. FDA may review pre-QMSR records during inspections. A comparative gap analysis helps confirm older documentation still meets current QMSR requirements.