ISO 13485 Clauses Explained: A Complete Clause-by-Clause Breakdown (2026)

ISO 13485:2016 has eight clauses, but only five carry auditable requirements. This ISO 13485 clauses explained guide breaks down Clauses 4 through 8 in practical terms, corrects the common DHF-to-Medical-Device-File mapping error, and explains how FDA’s Compliance Program 7382.850 — which replaced QSIT on February 2, 2026 — reorganizes inspections around six QMS Areas and four Other Applicable FDA Requirements.

What every section of ISO 13485:2016 actually requires — and where auditors dig deepest

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Standard Reads Like a Checklist. It Isn’t One.

ISO 13485:2016 has eight clauses. Five of them carry actual requirements. That structure looks simple on the page — and it’s exactly why so many quality teams underestimate how much interpretation each clause demands once an auditor starts asking “show me.” This ISO 13485 clauses explained guide breaks down what each section requires, where the requirements overlap, and what auditors and FDA investigators may look for.

The FDA’s Quality Management System Regulation (QMSR) took effect February 2, 2026, incorporating ISO 13485:2016 by reference into 21 CFR Part 820. That changes what this clause structure means in practice. FDA also replaced its inspection methodology the same day — the Quality System Inspection Technique (QSIT) is gone, replaced by Compliance Program 7382.850. Getting the clause boundaries right now has a direct line to how an FDA investigator scopes an inspection, not just how a certification body audits.

Regulatory affairs and quality professionals reading this already know ISO 13485 exists. What’s harder to find is a breakdown that goes past the clause titles and into what each section demands in practice — where the audit findings cluster, where risk management threads through clauses that don’t mention risk in their title, and where the standard’s lack of an Annex SL high-level structure changes how it should be read compared to ISO 9001.

My perspective on this comes from 25+ years in operations leadership, an ISO 9001 Internal Auditor certification, and a Six Sigma Green Belt — a lot of that time spent on both sides of the table, building QMS documentation and sitting in CAPA reviews when a gap in that documentation turned into a finding. The pattern holds across every regulated QMS I’ve worked with: teams don’t fail because they misread a clause. They fail because they treated clause boundaries as more rigid than the standard actually intends, and missed how much cross-referencing an auditor expects between clauses 4 through 8.

If you haven’t run a structured gap check against the current clause set, that’s the place to start — not a full documentation rewrite.

👉 Run the ISO 13485 Gap Assessment Checklist before you touch your quality manual — a free, structured way to see exactly which clauses your QMS already satisfies and which ones need real work before an auditor finds the gap for you.


In This Guide

  • How ISO 13485:2016 is structured, and why it doesn’t follow ISO’s Annex SL format
  • A clause-by-clause breakdown of Clauses 4 through 8
  • How FDA’s current inspection program, Compliance Program 7382.850, reorganizes inspections around six QMS Areas
  • The most common audit findings tied to specific sub-clauses
  • Where risk management actually appears throughout the standard
  • How ISO 13485 clause numbering compares to ISO 9001
  • FAQs on structure, exclusions, and transition timing


👉 Start Here (Top Resources)


ISO 13485 Clauses Explained: How the Standard Is Structured

ISO 13485 clauses explained with an eight-clause map covering the standard’s foundational and QMS requirement clauses
ISO 13485 clauses explained through an eight-clause map showing the foundational clauses and the five clauses containing QMS requirements.

ISO 13485:2016 is built around eight clauses. The first three are introductory — they define scope, point to normative references, and set terminology. They carry no auditable requirements on their own, but skipping them is a mistake most teams make once and then correct the hard way.

Clauses 4 through 8 are where the requirements live. This is the part of the standard your certification body actually audits against, clause by clause, sub-clause by sub-clause.

Here’s something worth knowing before you go further: ISO 13485 does not follow the Annex SL high-level structure that ISO 9001:2015, ISO 14001, and ISO 45001 all share. Those three standards align clause-for-clause at the top level, which is why integrated management systems work so cleanly across them. ISO 13485 kept its own structure when it was revised in 2016, specifically so it could stay independent of ISO 9001 revision cycles — a deliberate choice by the technical committee to protect regulatory stability for device manufacturers. If you’re coming from an ISO 9001 background, this is the first adjustment to make: don’t assume clause 7 means the same thing in both standards. It doesn’t.


Clauses 1 Through 3: No Requirements, But Don’t Skip Them

Clause 1 (Scope) defines what the standard covers and, critically, how exclusion and non-application work. ISO 13485 doesn’t let an organization simply skip a requirement that seems inconvenient — where a clause is excluded or considered non-applicable (say, you don’t perform installation), the scope and justification have to be documented in the quality manual under Clause 4.2.2, and be prepared to defend that justification during an audit.

Clause 2 (Normative References) points to ISO 9000:2015 for terms and definitions. You don’t need to buy ISO 9000 to comply, but auditors do expect your team to be using its vocabulary consistently — “nonconformity,” “corrective action,” and “verification” all carry specific meanings your documentation should match.

Clause 3 (Terms and Definitions) establishes the vocabulary used throughout the standard, including specific definitions for concepts like medical device, complaint, risk, and post-market surveillance. Getting comfortable with this terminology matters more than it looks like it should — auditors expect your documentation to use these terms precisely, not colloquially.

📥 Before diving into clauses 4-8: if your QMS documentation predates 2020, run it against the current ISO 13485 Documentation Requirements breakdown first. Most gaps trace back to documentation structure, not missing procedures.


Clause 4: Quality Management System

Clause 4 sets the general requirements for the QMS itself — and it’s where most audit programs start, because everything downstream depends on it.

4.1 General Requirements requires you to identify your QMS processes, map their sequence and interaction, and — this is the part that trips up contract manufacturers — maintain control over any process you outsource. Most common finding: outsourced processes (contract sterilization, contract testing, third-party calibration) that exist operationally but were never formally brought into QMS scope. If a supplier touches your product or your data, your QMS has to account for it.

4.2 Documentation Requirements covers the quality manual, the Medical Device File (Clause 4.2.3), document control, and record control. This requirement is specific to this standard — it’s not something ISO 9001 asks for. It’s a defined set of documents and references demonstrating a device meets its requirements throughout its lifecycle, and auditors will ask to see it assembled, not scattered across a dozen disconnected folders.

If your documentation still uses FDA’s old terminology, this is worth getting precise about. As of February 2, 2026, the terms Device Master Record, Device History Record, and Design History File no longer appear in 21 CFR Part 820. Those legacy record concepts weren’t simply eliminated; their applicable requirements are now addressed through the QMSR framework and ISO 13485’s own structure. Most of what a Device Master Record covered lives in the Medical Device File at Clause 4.2.3, while the Design History File corresponds to the Design and Development File at Clause 7.3.10. These aren’t simple one-for-one renamings: the Medical Device File in particular is a broader requirement than the DMR it replaced, so a straight terminology swap in your documentation will likely leave gaps a crosswalk exercise would catch.

Sub-clause 4.2.4 (control of documentation) and 4.2.5 (control of records) get their own scrutiny. Auditors typically check three things here: are documents reviewed and approved before use, is there a mechanism to prevent use of outdated versions, and are records retained for a defined, justified period. If you’re preparing for your first audit under this clause → build your document control procedure before you build anything else. Everything else in the QMS references it.


Clause 5: Management Responsibility

Clause 5 puts specific, named accountability on top management — not “the quality department,” but leadership itself.

This clause requires a documented quality policy, measurable quality objectives, evidence of planning for QMS changes, and a sub-clause I’ve seen come up repeatedly in audit findings — management review. Clause 5.6.2 is unusually prescriptive for an ISO standard: it names twelve required inputs, and a compliant management review record has to address all of them or document why one doesn’t apply — feedback, complaint handling, reporting to regulatory authorities, audits, monitoring and measurement of processes, monitoring and measurement of product, corrective action, preventive action, follow-up actions from previous reviews, changes that could affect the QMS, recommendations for improvement, and applicable new or revised regulatory requirements. A management review that skips several of these, or that doesn’t produce documented outputs and action items, is a finding waiting to happen — and under the current FDA inspection framework, it’s no longer just a certification-audit concern (more on that below).

If you are already ISO 9001 certified, this clause will feel familiar structurally — but ISO 13485 expects a tighter link between management review and regulatory requirements specifically, not just general business objectives.


Clause 6: Resource Management

Clause 6 covers human resources, infrastructure, and work environment — including contamination-control requirements under 6.4.2 that go considerably further than ISO 9001’s general treatment of work environment.

6.2 Human Resources requires documented competence for anyone whose work affects product quality — not just “trained,” but competence tied to education, skills, and experience, with evidence. 6.3 Infrastructure requires maintenance records for equipment critical to product conformity. 6.4 Work Environment and Contamination Control is where device manufacturers doing anything sterile, implantable, or otherwise contamination-sensitive get the most detailed scrutiny — cleanroom classifications, gowning procedures, and environmental monitoring data all trace back here.


Clause 7: Product Realization

Clause 7 is the largest clause in the standard, and it’s where design controls, purchasing, production, and servicing all live.

7.1 Planning of Product Realization is where ISO 13485 explicitly requires documented risk management processes within product realization, with records maintained throughout. The clause’s note points readers to ISO 14971 for further guidance on structuring that risk management activity — it’s a reference, not a formal incorporation, though in practice most organizations end up using ISO 14971’s framework to satisfy this requirement.

7.3 Design and Development is one of the sub-clauses most commonly identified as non-applicable by contract manufacturers who don’t design product — but where it applies, it can’t be excluded lightly, and the justification has to hold up to the same Clause 4.2.2 scrutiny as any other exclusion. If it applies to you, this is the densest technical section of the standard: design inputs, outputs, review, verification, validation, transfer, and change control, each with its own documented evidence trail. Most common finding: design changes made without running them back through the full verification/validation cycle, especially late in development when schedule pressure is highest.

7.4 Purchasing requires supplier evaluation criteria proportionate to risk, and re-evaluation triggers when supplier performance changes. 7.5 Production and Service Provision covers process validation for anything that can’t be fully verified by downstream inspection — sterilization is the textbook example, which is why it gets its own dedicated body of standards. 7.6 Control of Monitoring and Measuring Equipment ties directly into your calibration program.

If you are under customer or FDA pressure to show design control maturity quickly → prioritize closing out 7.3 documentation gaps before anything else in this clause. In my experience, it’s one of the first sections a regulatory reviewer or auditor asks to see in depth.


Clause 8: Measurement, Analysis and Improvement

Clause 8 is where the QMS proves it’s actually working — and where CAPA lives.

8.2 Monitoring and Measurement covers feedback, complaint handling, and internal audit. Complaint handling under this clause has to interface with FDA’s separate adverse-event reporting requirements — a complaint that may represent a reportable event under Medical Device Reporting (21 CFR Part 803) can’t remain solely an internal QMS record; it has to be evaluated independently against those reporting obligations.

8.3 Control of Nonconforming Product requires documented procedures for identifying, segregating, and dispositioning nonconforming product, including for product discovered nonconforming after delivery — which is where recall-adjacent procedures connect back into the standard.

8.5 Improvement is where corrective and preventive action requirements sit. CAPA under ISO 13485 requires root cause investigation, verification that the action taken was effective, and — a detail I’ve seen auditors check for specifically — evidence that you evaluated whether the same nonconformity could exist elsewhere in the organization before closing the CAPA. A CAPA record that fixes one instance without documenting that broader check is incomplete by this clause’s own standard, regardless of whether the immediate fix worked.

For a deeper breakdown of this clause specifically, see our full guide to CAPA requirements in ISO 13485.


Where ISO 13485 and FDA’s QMSR Overlap by Clause

FDA’s Quality Management System Regulation took effect February 2, 2026, incorporating ISO 13485:2016 by reference into 21 CFR Part 820. That’s the headline most coverage stopped at. What matters more for how you prepare is what happened on the inspection side the same day: FDA retired the Quality System Inspection Technique (QSIT), the inspection methodology it had used since 1999, and replaced it with a new compliance program manual — CP 7382.850, Inspection of Medical Device Manufacturers.

ISO 13485 clauses explained through the 2026 FDA QMSR inspection framework, including six QMS Areas and four OAFRs
ISO 13485 clauses explained in the context of the FDA QMSR and CP 7382.850 inspection framework effective February 2, 2026.

QSIT organized inspections around four subsystems. CP 7382.850 reorganizes them around six QMS Areas, each mapped to ISO 13485 clauses with FDA-specific requirements layered in:

  • Management Oversight — the QMS itself, management review, the medical device file, and product realization planning
  • Design and Development — design inputs, outputs, review, verification, validation, software validation, and transfer
  • Production and Service Provision — production planning, process validation, and servicing
  • Measurement, Analysis, and Improvement — complaint handling, feedback, internal audits, corrective and preventive action, and control of nonconforming product
  • Outsourcing and Purchasing — supplier evaluation and control
  • Change Control — how changes to product or process are managed and documented

Alongside the six QMS Areas, inspections also evaluate four Other Applicable FDA Requirements (OAFRs) that sit outside ISO 13485’s text entirely: Medical Device Reporting (21 CFR Part 803), Corrections and Removals reporting (21 CFR Part 806), Medical Device Tracking (21 CFR Part 821), and Unique Device Identification (21 CFR Part 830). This is where the clause structure above stops covering everything — these four areas are FDA-specific regulatory obligations, not ISO 13485 requirements. They’re evaluated during routine surveillance, compliance follow-up, and PMA postmarket inspections; a narrow exception can apply to certain PMA preapproval inspections when the manufacturer hasn’t yet introduced the device to the U.S. market.

The change that affects Clause 5 most directly: under the prior QSR, management review records were categorically exempt from FDA review under §820.180(c). Under CP 7382.850, that exemption is gone. Management review now sits squarely inside the Management Oversight QMS Area, and an investigator can ask to see it — which means the twelve required Clause 5.6.2 inputs covered above aren’t just a certification-audit concern anymore.

One caution worth stating plainly: ISO 13485 certification and FDA QMSR compliance are related but not identical. A QMS built cleanly against Clauses 4 through 8 covers the ISO 13485 core that QMSR incorporates, but it doesn’t automatically satisfy the four OAFRs — those require their own documented processes regardless of how strong your clause-by-clause QMS is.

If you’re not sure whether your current documentation satisfies both frameworks → our FDA QSR vs ISO 13485 comparison and MDSAP vs ISO 13485 breakdown both walk through this in more detail than fits here.

ISO 13485 vs ISO 9001: Same Numbers, Different Weight

ElementISO 13485:2016ISO 9001:2015
Structure8 clauses, own structure (not Annex SL)10 clauses, Annex SL high-level structure
Risk managementDocumented risk management required in product realization (7.1); note references ISO 14971Risk-based thinking, less prescriptive
Customer satisfaction monitoringNo direct ISO 9001-style requirement; feedback/complaints addressed via Clause 8.2Explicit requirement (Clause 9.1.2)
DocumentationMedical device file required (Clause 4.2)No equivalent requirement
Design controlsDetailed, mandatory unless justified exclusionLess detailed by comparison
Regulatory linkDirectly referenced in FDA QMSR (21 CFR 820)Not tied to a specific regulation

The clause numbers look similar enough to cause real confusion — both standards use “Clause 7” for a large operational section, but the content underneath diverges substantially. If your organization holds both certifications, don’t assume a clause 7 audit finding under one standard tells you anything about your standing under the other. For the full comparison, see ISO 9001 vs ISO 13485.

The objection I hear most on this topic: “We’re already ISO 9001 certified — how much of this is actually new work?” Realistically, expect Clauses 5 and 6 to require the least rework, since management responsibility and resource management overlap heavily in intent. Clauses 4, 7, and 8 are where the medical device-specific requirements add real documentation and process work — the medical device file, design control rigor, and CAPA’s broader-impact evaluation aren’t things a general ISO 9001 QMS already has built in.


Most teams don’t fail an ISO 13485 audit because they misunderstood a clause. They fail because they assumed a documented procedure was enough without checking whether it actually produces the evidence an auditor will ask to see.

👉 Run a structured check before that assumption gets tested in front of an auditor → ISO 13485 Gap Assessment Checklist


Quick Clause Reference Checklist

A clause tells you what’s required. It doesn’t tell you what to hand an auditor when they ask for proof. Below is a quick translation — clause by clause, requirement to evidence.

ISO 13485 clauses explained through an audit evidence checklist showing objective evidence for Clauses 4, 5, 7, and 8
ISO 13485 clauses explained through the objective evidence auditors may review for Clauses 4, 5, 7, and 8.

✅ Clause 4 — QMS scope defined, outsourced processes controlled, medical device file assembled
✅ Clause 5 — Quality policy documented, management review covering all required inputs
✅ Clause 6 — Competence records current, contamination controls documented where applicable
✅ Clause 7 — Risk management documented within product realization; ISO 14971 provides further guidance; design control records complete, supplier evaluation criteria defined
✅ Clause 8 — Complaint handling tied to regulatory reporting, CAPA records show broader-impact evaluation

⚠️ Clauses 1–3 — Exclusions and non-applicability justified in the quality manual, not just left blank

For implementation sequencing beyond the checklist above, our ISO 13485 Implementation Roadmap and ISO 13485 Gap Assessment: Step-by-Step Guide walk through the order to tackle these in.


FAQ

How many clauses does ISO 13485:2016 have?

Eight. Clauses 1 through 3 are introductory and carry no auditable requirements. Clauses 4 through 8 contain the substantive quality management system requirements that certification bodies audit against — and since February 2026, FDA investigators evaluate the same core requirements under Compliance Program 7382.850.

Does ISO 13485 follow the same structure as ISO 9001?

No. ISO 13485 does not use ISO’s Annex SL high-level structure, which ISO 9001, ISO 14001, and ISO 45001 all share. The technical committee kept ISO 13485 independent specifically to protect regulatory stability for device manufacturers, so clause numbers that look similar between the two standards often cover different scope.

Can I exclude clauses from ISO 13485?

Only with documented justification. Under Clause 4.2.2, the scope and justification for any exclusion or non-application have to be recorded in the quality manual, and you need to be prepared to defend that justification during an audit.

Which ISO 13485 clause covers risk management?

Clause 7.1 (Planning of Product Realization) is where documented risk management is explicitly required, and its note points to ISO 14971 for further guidance. But risk-related requirements aren’t confined to one clause — they surface throughout Clauses 4 through 8 rather than sitting in a single isolated section.

What’s the difference between ISO 13485 and the FDA’s QMSR?

As of February 2, 2026, FDA’s QMSR incorporates ISO 13485:2016 by reference into 21 CFR Part 820, and FDA’s inspection methodology changed to match — Compliance Program 7382.850 replaced QSIT the same day. The two frameworks are far more tightly aligned than before, but they’re not identical: four Other Applicable FDA Requirements (Medical Device Reporting, Corrections and Removals, Medical Device Tracking, and UDI) sit outside ISO 13485’s text and are evaluated in applicable inspection types, with a limited exception for certain PMA preapproval inspections when the device has not yet been introduced to the U.S. market.

What is CP 7382.850?

CP 7382.850 (Inspection of Medical Device Manufacturers) is FDA’s current compliance program manual for device inspections, effective February 2, 2026 alongside the QMSR. It replaced the Quality System Inspection Technique (QSIT) and reorganizes inspections around six QMS Areas — Management Oversight, Design and Development, Production and Service Provision, Measurement/Analysis/Improvement, Outsourcing and Purchasing, and Change Control — plus four Other Applicable FDA Requirements evaluated in most inspection types.

Do I need to buy ISO 9001 to understand ISO 13485’s terminology?

You don’t need to purchase it, but ISO 13485 does reference ISO 9000:2015 for its terms and definitions, and auditors expect consistent use of that vocabulary in your documentation.

Which clauses deserve the closest audit preparation?

In practice, Clause 4.2 (documentation control), Clause 7.3 where applicable (design and development), and Clause 8.5 (CAPA effectiveness) tend to draw sustained attention, largely because each requires ongoing documented evidence rather than a one-time procedure. The exact focus varies by organization, device type, and regulatory scope — under the current FDA inspection framework, Management Oversight and Measurement, Analysis, and Improvement are evaluated on every inspection regardless of device type.

Is a documentation kit enough to get ISO 13485 clause requirements right?

A kit gives you a starting structure, but clause-by-clause compliance depends on evidence specific to your processes — training records, design and development records, CAPA effectiveness checks. Our ISO Documentation Kits for Manufacturers page breaks down what a kit does and doesn’t cover.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching how the clauses fit together? Start with What Is ISO 13485? for the foundational overview before working through this clause breakdown a second time.

🔹 Ready to assess where your QMS actually stands? Run the ISO 13485 Gap Assessment Checklist against the clause list above — it’s built to map directly to Clauses 4 through 8.

🔹 Need the official standard text to cite exact clause language? Purchase ISO 13485:2016 through ANSI Webstore — use code CC2026 for 5% off through December 31, 2026. International-language editions are available for teams managing documentation across multiple regulatory regions.

🔹 Need your internal auditors trained on this clause structure before your next surveillance audit? ISO 13485 training through BSI Group covers the structure clause by clause with a certification body’s own instructors.

The Standards Navigator breaks down what these clauses actually demand — not just what they’re titled — so your team can walk into an audit knowing which sub-clause the finding will land on before it does.


Stay Ahead of Clause-Level Changes

Most QMS documentation doesn’t fail because a team ignored ISO 13485. It fails because someone mapped a procedure to the wrong clause once, early on, and every review since has confirmed the wrong thing.

Organizations that treat the clause structure above as a living reference — checked against actual audit findings, updated as FDA’s QMSR enforcement approach becomes clearer — walk into surveillance audits with far fewer surprises than organizations treating their quality manual as a document they wrote once and filed away.

The Standards Navigator tracks ISO 13485, QMSR, and the surrounding medical device standards landscape as they develop, not just at certification time.

👉 Get updates on ISO 13485 and medical device QMS requirements
👉 Be first to access new gap assessment tools and clause-mapping resources

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

FDA QSR vs ISO 13485: The Complete QMSR Transition Guide (2026)

The FDA replaced the legacy Quality System Regulation on February 2, 2026. The new QMSR incorporates ISO 13485:2016 by reference — making the international medical device quality standard the structural backbone of U.S. federal regulation. This guide covers exactly what changed, what FDA-specific requirements remain in force beyond ISO 13485, and what your quality system needs to address now that the QMSR is in full effect.

What changed on February 2, 2026, what stayed, and exactly what your quality system needs to address now that the FDA’s QMSR is in full force.

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The FDA Replaced the QSR. Here’s What That Actually Means.

On February 2, 2026, the FDA’s legacy Quality System Regulation — the QSR under 21 CFR Part 820 — was replaced.

Not updated. Not revised. Replaced.

The new Quality Management System Regulation (QMSR) restructured 21 CFR Part 820 around a single foundational document: ISO 13485:2016. The FDA incorporated the international medical device quality standard by reference — meaning ISO 13485 is now the structural backbone of U.S. medical device quality regulation. It is no longer a voluntary international standard that sophisticated manufacturers pursue for global market access. It is what the FDA expects your quality system to be built on.

If your quality system was built against the old QSR framework — DMRs, DHFs, QSIT audit language — you are now operating against a framework that has been retired. The FDA’s inspectors are using a new compliance program. The terminology has changed. The inspection scope has changed. The risk management expectations have changed.

This guide covers exactly what the QSR was, what the QMSR replaced it with, where ISO 13485 fits into the new regulatory structure, what FDA-specific requirements remain in force beyond ISO 13485, and what your quality system needs to address right now.


In This Guide

  • What the FDA QSR was and why it was replaced
  • What the QMSR actually is — and what it is not
  • How FDA QSR, ISO 13485, and QMSR relate to each other
  • The four FDA-specific requirements that ISO 13485 does not cover
  • Key changes under the QMSR manufacturers need to act on
  • Does ISO 13485 certification satisfy QMSR?
  • The role of ISO 14971 in QMSR compliance
  • QMSR gap assessment — where to start
  • From the Shop Floor — what this transition actually looks like
  • Getting ISO 13485 certified under the QMSR framework


✅ Start Here (Top Resources)

📋 Start with a structured gap assessment before engaging a certification body. The free ISO 13485 Gap Assessment Checklist covers every clause area plus all four QMSR bridge requirements — so you know exactly where you stand before you spend money on implementation. Download Free Checklist

📋 Purchase the official ISO 13485:2016 standard → ISO 13485:2016 — ANSI Webstore — use coupon CC2026 for 5% off through December 31, 2026

📋 Purchase the required companion standard → ISO 14971:2019 Risk Management — ANSI Webstore — use coupon CC2026 for 5% off

📋 Get ISO 13485 training for your team → BSI Group ISO 13485 Training

📋 Get ISO 13485 certified with an accredited certification body → ISOQAR ISO 13485 Certification

📋 Save up to 50% buying ISO standards as a bundle → ISO Standards Packages — ANSI Webstore


What Was the FDA QSR?

Professional infographic explaining the FDA Quality System Regulation under 21 CFR Part 820, featuring medical device manufacturing, CGMP requirements, and regulatory compliance history.
The FDA Quality System Regulation under 21 CFR Part 820 established the foundational CGMP requirements governing medical device manufacturing quality systems in the United States.

The FDA’s Quality System Regulation was codified under 21 CFR Part 820. First authorized in July 1978 and significantly revised in 1996, the QSR established the current good manufacturing practice (CGMP) requirements for finished medical device manufacturers distributing products in the United States.

The QSR covered the core pillars of a medical device quality management system: management responsibility, design controls, document and record controls, purchasing controls, production and process controls, corrective and preventive action (CAPA), labeling, and complaint handling. It was written in FDA-specific language and structured around FDA-specific documentation concepts:

  • Device Master Record (DMR) — the compiled documentation defining how a device is manufactured
  • Design History File (DHF) — records demonstrating the device was designed in accordance with an approved plan
  • Device History Record (DHR) — production records for each manufactured unit or lot
  • Quality System Inspection Technique (QSIT) — the FDA’s subsystem-by-subsystem inspection approach

For decades, the FDA QSR and ISO 13485 ran in parallel. They covered similar ground but used different terminology, different structural frameworks, and different documentation concepts. Manufacturers selling devices in both the U.S. and international markets often maintained two parallel compliance frameworks — one for the FDA, one for ISO 13485 or MDSAP. That dual-track approach created overhead, redundancy, and audit complexity that manufacturers had been managing for years.

That parallel structure is over.


What Is the QMSR?

The Quality Management System Regulation (QMSR) is the amended version of 21 CFR Part 820, effective February 2, 2026. The FDA issued the final rule in February 2024, providing a two-year implementation window before the regulation took effect.

The core structural change: instead of writing QMS requirements directly into the regulation, the FDA incorporated ISO 13485:2016 by reference. Part 820 now points to ISO 13485 as the source document for quality system requirements. The regulation itself became significantly shorter — most of its text now simply directs manufacturers to the relevant ISO 13485 clause.

What this means in practice: ISO 13485:2016 compliance is now a regulatory expectation under 21 CFR Part 820 — not a voluntary international best practice. Manufacturers who have never engaged with ISO 13485 are now operating under a framework built on it.

The QMSR also updated the FDA’s inspection program. As of February 2, 2026, the FDA retired the Quality System Inspection Technique (QSIT) and implemented Compliance Program 7382.850 — a revised inspection approach built around the ISO 13485 process-based structure rather than the subsystem-by-subsystem approach of the old QSR.


FDA QSR vs ISO 13485 vs QMSR — How They Relate

This is where manufacturers get confused, so it is worth being precise.

The old QSR was a standalone FDA regulation with its own requirements, its own terminology, and its own documentation structure. It has been retired.

ISO 13485:2016 is the international standard for medical device quality management systems, published by the International Organization for Standardization. It has always been used by regulatory authorities globally — including Health Canada, the EU MDR framework, and MDSAP participating countries — as the baseline for QMS requirements.

The QMSR is the new version of 21 CFR Part 820. It uses ISO 13485:2016 as its foundation by incorporating it by reference, while layering on U.S.-specific regulatory requirements that ISO 13485 does not fully address on its own.

Think of it this way: the QMSR is ISO 13485 plus the FDA-specific additions the agency determined were necessary to cover U.S. statutory obligations that go beyond what the international standard requires.

ISO 13485 does most of the heavy lifting. But QMSR is not simply “ISO 13485 with a new name.” Several FDA-specific obligations remain fully in force and cannot be satisfied by ISO 13485 conformance alone.


What the QMSR Kept — The Four FDA Bridge Requirements

The QMSR retained four categories of U.S.-specific requirements that remain unchanged and fully enforceable. These are sometimes called the QMSR “bridge requirements” — the FDA-specific obligations that ISO 13485 does not cover:

1. Medical Device Reporting (MDR)

Manufacturers must continue to report adverse events, malfunctions, and deaths or serious injuries involving their devices to the FDA under 21 CFR Part 803. ISO 13485 addresses post-market surveillance at a high level but does not specify MDR reporting timelines or mechanisms. The QMSR cross-references MDR explicitly in §820.10.

2. Unique Device Identification (UDI)

The UDI system — requiring device labeling to carry a unique identifier traceable in the FDA’s Global Unique Device Identification Database (GUDID) — continues unchanged under QMSR. ISO 13485 does not address UDI requirements. §820.10 explicitly cross-references UDI compliance.

3. Corrections and Removals

Reporting obligations for corrections and removals under 21 CFR Part 806 remain in force. Manufacturers must report corrections or removals initiated to reduce a risk to health or remedy a violation.

4. Device Tracking

Tracking requirements for certain high-risk device categories under 21 CFR Part 821 continue to apply.

A manufacturer whose QMS is fully ISO 13485 compliant but has not addressed these four areas is not QMSR compliant. This is the most important distinction in the entire QMSR framework.


What Changed Under the QMSR

Infographic explaining the major operational and regulatory changes introduced under the FDA QMSR, including terminology alignment, expanded risk management, inspection changes, and ISO 13485 document control requirements.
The FDA’s QMSR transition introduced major changes beyond terminology — expanding risk management expectations, changing inspection structure, and aligning medical device quality systems directly with ISO 13485.

Beyond the structural shift to ISO 13485, several specific changes affect how manufacturers need to operate:

Terminology Alignment

The QMSR adopts ISO 13485 and ISO 9000 vocabulary, replacing legacy QSR-specific terms:

Old QSR TermQMSR / ISO 13485 Term
Device Master Record (DMR)Medical Device File (MDF)
Design History File (DHF)Design and Development File (DDF)
Device History Record (DHR)Manufacturing Records
Quality System RecordDistributed across QMS documentation

Manufacturers are not required to rename every document immediately — but QMS documentation, training materials, and internal audit programs should be progressively aligned to ISO 13485 terminology to avoid confusion during inspections.

Risk Management Extends Across the Entire QMS

Under the old QSR, risk management was concentrated primarily in design controls. Under QMSR — consistent with ISO 13485 and its companion standard ISO 14971 — risk-based thinking now extends across the entire quality system, including supplier controls, manufacturing processes, CAPA, complaint handling, and post-market activities. This is a substantive operational shift, not a documentation update.

Internal Audits and Management Reviews Are Now Inspection Territory

Under QSR, internal audits were required but the FDA’s QSIT inspection process did not focus on them directly. Under QMSR and Compliance Program 7382.850, internal audits and management reviews are within the FDA’s inspection scope. Investigators will evaluate whether your internal audit program functions as a process-based system consistent with ISO 13485 Clause 8.2.4 requirements.

Inspection Structure Changed

The FDA’s inspection approach under CP 7382.850 evaluates how quality subsystems function as an interconnected framework rather than auditing them in isolation. Inspectors follow issues across processes — a finding in complaint handling may lead directly into CAPA, risk management, and design controls in the same inspection.

ISO 13485 Must Be Controlled as an External Document

Because QMSR incorporates ISO 13485 by reference, manufacturers are required to control the standard as an external document within their QMS under ISO 13485 Clause 4.2.4. This means purchasing the official standard and maintaining version control — a detail many manufacturers miss entirely.

📋 Buy the Official ISO 13485:2016 — ANSI Webstore — use coupon CC2026 for 5% off


Does ISO 13485 Certification Satisfy QMSR?

Corporate infographic explaining whether ISO 13485 certification satisfies FDA QMSR requirements, including compliance gaps, FDA bridge requirements, inspection readiness, and the path to full QMSR compliance.
ISO 13485 certification provides the foundation for QMSR compliance — but manufacturers must still address FDA-specific bridge requirements, inspection readiness, and process-based audit expectations.

This is the most common question manufacturers ask after the QMSR took effect, and the answer requires precision.

ISO 13485 certification helps significantly — but does not automatically guarantee QMSR compliance.

ISO 13485 certification from an accredited certification body demonstrates that your QMS meets the international standard’s requirements. Under QMSR, that foundation now aligns with what the FDA expects at the structural level. If your organization is already ISO 13485 certified, the gap between your current QMS and QMSR compliance is substantially smaller than it was under the old QSR.

However, ISO 13485 certification does not cover the four FDA bridge requirements — MDR, UDI, corrections and removals, and device tracking. It also does not replace FDA inspections. The FDA retains full enforcement authority under U.S. law regardless of third-party certification status. An ISO 13485 certificate is not a substitute for FDA inspection readiness.

The practical position: ISO 13485 certification gets you approximately 80–85% of the way to QMSR compliance. The remaining work is ensuring the FDA bridge requirements are explicitly addressed in QMS documentation, records and labeling controls map to both ISO 13485 and FDA expectations, and your internal audit program is prepared for the process-based inspection approach under CP 7382.850.

If you are not yet ISO 13485 certified and are subject to QMSR, pursuing certification is the most efficient path to demonstrating compliance with the regulation’s foundation.

📋 Buy ISO 13485:2016 — ANSI Webstore — use coupon CC2026 for 5% off


The Role of ISO 14971 Under QMSR

ISO 14971 — Risk Management for Medical Devices — plays a critical role in QMSR compliance that is consistently underestimated.

Under the old QSR, risk management was primarily concentrated in design controls. Under QMSR, risk-based thinking is expected throughout the entire quality system. ISO 14971 provides the formal risk management framework — hazard identification, risk estimation, risk evaluation, risk control, and residual risk evaluation — that ISO 13485 requires manufacturers to implement but does not itself specify in detail.

ISO 13485 explicitly requires compliance with ISO 14971. Under QMSR, that requirement carries federal regulatory weight. FDA investigators under CP 7382.850 are expected to start inspections with the risk management file as their roadmap — following risk documentation into design controls, production controls, CAPA, and post-market surveillance.

If your QMS does not have a well-documented, lifecycle-integrated risk management program built on ISO 14971, this is your highest-priority gap under QMSR.

📋 ISO 14971:2019 — ANSI Webstore — use coupon CC2026 for 5% off

For the complete relationship between ISO 13485 and ISO 14971, see ISO 9001 vs ISO 13485 — Key Differences.


QMSR Gap Assessment — Where to Start

📋 Start with a structured gap assessment before engaging a certification body. The free ISO 13485 Gap Assessment Checklist covers every clause area plus all four QMSR bridge requirements — so you know exactly where you stand before you spend money on implementation. Download Free Checklist

Manufacturing compliance gap assessment scale showing audit readiness levels with 0–2 gaps as audit ready, 3–5 gaps as moderate risk, and 6+ gaps as high risk
A simple gap assessment can quickly show whether your operation is audit-ready — or at risk of failure.

For manufacturers currently operating under the old QSR framework, a structured gap assessment is the most efficient starting point. Key areas to evaluate:

Documentation and terminology. Map your existing QMS documents to ISO 13485 clause requirements. Identify where legacy QSR terminology (DMR, DHF, DHR) appears and plan progressive alignment to ISO 13485 vocabulary. Your team and your auditors need to understand the mapping.

Risk management integration. Assess whether your risk management program is limited to design controls or extends across supplier qualification, production processes, CAPA, complaint handling, and post-market surveillance as ISO 14971 and QMSR require.

FDA bridge requirements. Confirm that MDR, UDI, corrections and removals, and device tracking obligations are explicitly addressed in QMS procedures and cross-referenced in §820.10 documentation.

Internal audit program. Update your internal audit program to reflect process-based auditing across interconnected QMS elements rather than subsystem-by-subsystem evaluation. Ensure auditors understand the QMSR inspection approach under CP 7382.850.

Supplier controls. ISO 13485 Clause 7.4 has more prescriptive supplier control requirements than the old QSR. Review supplier qualification procedures, quality agreements, and monitoring programs against ISO 13485 requirements.

External document control. Confirm that ISO 13485:2016 and ISO 14971 are registered as external documents in your QMS with version control — this is now a regulatory requirement, not optional housekeeping.


From the Shop Floor

Professional manufacturing team conducting a QMS transition planning meeting focused on gap assessments, operational involvement, and ISO 13485 documentation remediation.
Successful QMSR transitions are driven by honest gap assessments, operational team involvement, and proactive cleanup of long-standing documentation and compliance weaknesses.

After 25 years managing quality systems in heavy industrial manufacturing, I have watched more regulatory transitions than I care to count. Most follow the same pattern: the announcement creates anxiety, the implementation period creates confusion, and the actual change — once you get to it — turns out to be more manageable than the noise suggested.

The QMSR transition is no different, with one important caveat.

The manufacturers who are struggling right now are the ones who treated the QSR as a compliance exercise rather than an operational system. If your QMS was built as a documentation binder rather than a living process framework, QMSR is going to expose that gap — not because the regulation is fundamentally harder, but because the ISO 13485 process-based approach assumes your quality system actually runs your operations, not the other way around.

The manufacturers I have seen navigate transitions like this most effectively do three things. They conduct an honest gap assessment before anyone from the outside asks them to. They involve their operations team — not just regulatory affairs — in the remediation. And they treat the transition as an opportunity to clean up years of accumulated documentation debt rather than a compliance burden to minimize.

QMSR gives you a cleaner, more internationally aligned framework. The manufacturers who approach it that way will come out of this transition with stronger systems and less audit friction. The ones who treat it as a box-checking exercise will find the new inspection approach under CP 7382.850 less forgiving than the old QSIT was.


Getting ISO 13485 Certified Under the QMSR Framework

If your organization is not yet ISO 13485 certified, QMSR provides a clear incentive to pursue it. An accredited ISO 13485 certificate demonstrates to customers, regulators, and trading partners that your QMS meets the international standard that now forms the foundation of U.S. medical device regulation.

For certification: ISOQAR is a UKAS-accredited certification body with experience in medical device quality management system assessments.

📋 ISO 13485 Certification — ISOQAR

For training: BSI Group offers ISO 13485 training covering requirements interpretation, internal auditing, and implementation — suitable for quality managers, regulatory affairs professionals, and internal auditors preparing for the QMSR inspection environment.

📋 ISO 13485 Training — BSI Group


Quick Reference Comparison Table

ElementOld FDA QSRISO 13485:2016QMSR (Current)
Effective date1996 (revised)2016February 2, 2026
Regulatory basisU.S. federal regulationInternational standardU.S. federal regulation
StructureFDA-specific requirementsISO Harmonized StructureISO 13485 by reference + FDA additions
TerminologyDMR, DHF, DHRMDF, DDF, manufacturing recordsISO 13485 terms (progressive alignment)
Risk management scopePrimarily design controlsFull lifecycle (ISO 14971)Full QMS — ISO 14971 expected
MDR requirementsYesNoYes (§820.10 cross-reference)
UDI requirementsYesNoYes (§820.10 cross-reference)
Inspection programQSITThird-party certification auditCP 7382.850 (process-based)
ISO 13485 certificationNot requiredThird-party certificationStrongly recommended, not sufficient alone

Frequently Asked Questions

What is the QMSR and when did it take effect?

The Quality Management System Regulation (QMSR) is the amended version of 21 CFR Part 820, effective February 2, 2026. It replaced the legacy FDA Quality System Regulation (QSR) by incorporating ISO 13485:2016 by reference as the foundational quality system framework for U.S. medical device manufacturers.

What is the difference between the FDA QSR and the QMSR?

The old QSR was a standalone FDA regulation with its own requirements and terminology — DMRs, DHFs, DHRs, and the QSIT inspection approach. The QMSR replaced it with a framework built on ISO 13485:2016, adopted by reference, while retaining four U.S.-specific bridge requirements: Medical Device Reporting, UDI, corrections and removals, and device tracking.

Does ISO 13485 certification satisfy QMSR requirements?

ISO 13485 certification provides approximately 80–85% of the foundation for QMSR compliance. However, it does not cover the four FDA-specific bridge requirements and does not replace FDA inspections. A targeted QMSR gap assessment is necessary even for fully ISO 13485 certified organizations.

Is ISO 14971 required under QMSR?

Yes. ISO 13485 explicitly requires risk management per ISO 14971, and under QMSR that requirement carries federal regulatory weight. Risk-based thinking under QMSR extends across the entire quality system — not just design controls as under the old QSR. ISO 14971 is the expected framework.

What are the four QMSR bridge requirements that ISO 13485 does not cover?

Medical Device Reporting (MDR) under 21 CFR Part 803, Unique Device Identification (UDI), Corrections and Removals under 21 CFR Part 806, and Device Tracking under 21 CFR Part 821. These remain fully enforceable under QMSR regardless of ISO 13485 certification status.

What happened to the old QSR terminology — DMR, DHF, DHR?

The QMSR adopts ISO 13485 terminology. Device Master Record (DMR) becomes Medical Device File (MDF), Design History File (DHF) becomes Design and Development File (DDF), and Device History Record (DHR) maps to Manufacturing Records. Manufacturers are not required to rename documents immediately but should plan progressive alignment to ISO 13485 terminology.

What is FDA Compliance Program 7382.850?

CP 7382.850 is the FDA’s new inspection program implemented February 2, 2026, replacing the retired Quality System Inspection Technique (QSIT). It uses a process-based inspection approach aligned with ISO 13485 structure, evaluating how quality subsystems function as an interconnected framework rather than auditing them in isolation.

Does ISO 9001 certification satisfy QMSR?

No. ISO 9001 and ISO 13485 share a structural framework but serve different regulatory purposes. ISO 9001 certification does not satisfy ISO 13485 requirements and is not accepted by the FDA under QMSR. See ISO 9001 vs ISO 13485 for the complete comparison.


📥 Free Resources

Not Sure What to Do Next?

Start with a structured gap assessment before engaging a certification body. The free ISO 13485 Gap Assessment Checklist covers every clause area plus all four QMSR bridge requirements — so you know exactly where you stand before you spend money on implementation. Download Free Checklist

✅ You need the official ISO 13485:2016 standard 📋 ISO 13485:2016 — ANSI Webstore — use coupon CC2026 for 5% off through December 31, 2026

✅ You need the required ISO 14971 risk management companion 📋 ISO 14971:2019 — ANSI Webstore — use coupon CC2026 for 5% off

✅ You want to save buying both standards together 📋 ISO Standards Packages — Save up to 50% — ANSI Webstore

✅ You need ISO 13485 training before your gap assessment or implementation 📋 BSI Group ISO 13485 Training

✅ You are ready to pursue ISO 13485 certification 📋 ISOQAR ISO 13485 Certification

✅ You want to understand what ISO 13485 requires 📋 What Is ISO 13485? — Complete Guide

✅ You want to understand how ISO 9001 and ISO 13485 differ 📋 ISO 9001 vs ISO 13485 — Key Differences

✅ You want to understand ISO 13485 purchase options and cost 📋 Buy ISO 13485 — Complete Purchasing Guide 📋 How Much Does ISO 13485 Cost?

✅ You want to understand certification costs and timelines 📋 ISO Certification Cost Calculator 📋 How Long Does ISO Certification Take? 📋 Best ISO Certification Bodies


The QSR Is Gone. The QMSR Is What the FDA Expects Now.

The FDA replaced 21 CFR Part 820 on February 2, 2026. ISO 13485:2016 is now the structural backbone of U.S. medical device quality regulation. That is not an update to a voluntary standard — it is a fundamental shift in what federal regulation requires from every manufacturer in the U.S. medical device supply chain.

For manufacturers previously operating only under the QSR framework: your system needs to be restructured around ISO 13485. For ISO 13485 certified organizations: your certification provides a strong foundation, but the four FDA bridge requirements and the updated inspection approach under CP 7382.850 require targeted attention. For ISO 9001 certified manufacturers in the medical device supply chain: the supply chain pressure is coming. The pattern that played out in automotive and aerospace — sector-specific quality standards flowing down the supply chain — is now playing out in medical devices.

At The Standards Navigator, complex standards are translated into practical, real-world guidance you can act on.

✅ Get updates on new standards, implementation strategies, and compliance insights ✅ Be first to access new guides, tools, and checklists

Subscribe below to stay ahead.

Subscribe

* indicates required