Biocompatibility Standards Explained: ISO 10993 Requirements for Medical Devices in 2026

This guide breaks down the ISO 10993 series and the sixth edition of ISO 10993-1, published in November 2025. It covers FDA’s partial recognition of the new edition in May 2026, the two clauses the agency excluded, and whether manufacturers need to revisit biological evaluation plans for devices already cleared.

What ISO 10993-1:2025 and FDA’s Partial Recognition Mean for Your Biological Evaluation Plan

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Standard Behind Your Biocompatibility Testing Just Changed — Is Your Documentation Still Defensible?

Biocompatibility standards for medical devices just changed in a way regulatory affairs teams can’t ignore. If your device has any contact with the human body, your biological evaluation plan rests on one standard: ISO 10993-1. For years, that meant the 2018 edition. That’s no longer the whole story.

ISO published a sixth edition, ISO 10993-1:2025, in November 2025. The FDA followed with recognition of that edition on May 25, 2026 — but only partial recognition. Two specific clauses were excluded outright. If your technical documentation, supplier certificates, or biological evaluation reports still cite the 2018 edition without addressing what changed, that’s a gap a reviewer or auditor will find.

This isn’t a cosmetic update. The reorganization ties biocompatibility more tightly to ISO 14971 risk management, and the FDA’s exclusions tell you exactly where the agency still wants you to lean on its own biocompatibility guidance instead of the standard’s language. This guide covers the current medical device biocompatibility testing requirements under both editions, what changed, and what FDA’s recognition decision actually means for your Biological Evaluation Plan (BEP).

I’ve been on the reviewing side of this problem before, just from the documentation control angle. As an ISO 9001 internal auditor, I’ve flagged design history files where a supplier’s certificate of conformance still referenced an outdated edition of a cited standard — the technical content hadn’t changed, but the paper trail no longer matched what the standard actually required. That’s the kind of finding that stalls a submission or an audit closeout, and it’s entirely avoidable if someone catches the edition mismatch before a reviewer does.

Before you touch a single test report, run a gap check on where your current documentation stands against the 2025 edition.

👉 Most teams don’t fail because their biocompatibility data is wrong — they fail because their documentation still points to the wrong edition of the standard. Run the ISO 13485 Gap Assessment Checklist before your next submission or audit →


In This Guide

  • What ISO 10993-1 covers and why it sits at the center of biocompatibility evaluation
  • The full ISO 10993 series, part by part
  • What actually changed in the 2025 edition
  • FDA’s partial recognition — and exactly what it excluded
  • Whether you need to retest devices already cleared under the 2018 edition
  • How biocompatibility documentation fits into your ISO 13485 QMS
  • A quick audit checklist for your next document review


👉 Start Here (Top Resources)


What Is Biocompatibility, and Why ISO 10993 Matters

Biocompatibility is the assessment of whether a device’s materials — and the way those materials contact the body — create an unacceptable biological risk. ISO 10993-1 is the standard that governs how you plan, justify, and document that biocompatibility risk assessment. It doesn’t hand you a checklist of tests to run blindly; it requires you to build a risk-based Biological Evaluation Plan (BEP) that considers the device’s materials, manufacturing processes, intended anatomical contact, and exposure duration.

That risk-based framing matters because it’s the same language FDA reviewers and notified bodies expect to see. A BEP that reads like a 2009-era test list, rather than a risk justification tied to ISO 14971, is a common source of review questions and additional information requests.

If you’re still building out your risk management process, our guide on risk management in medical devices under ISO 14971 covers the foundation ISO 10993-1 now leans on even more heavily than before.


The ISO 10993 Series at a Glance

Infographic showing the ISO 10993 series for biological evaluation of medical devices, including ISO 10993-1, -5, -6, -7, -10, -12, -17, and -18.
The ISO 10993 series consists of multiple standards that together form a complete biological evaluation framework for medical devices.

ISO 10993-1 doesn’t stand alone — it’s the framework document for a series that covers specific test methods and evaluation categories.

PartCoversStatus Note
ISO 10993-1Overall evaluation and testing within a risk management processSixth edition (2025) now partially recognized by FDA
ISO 10993-5In vitro cytotoxicity2009 edition, still current
ISO 10993-6Local effects after implantationUpdated 2026 edition
ISO 10993-7Ethylene oxide sterilization residualsUpdated 2026 edition
ISO 10993-10Irritation and skin sensitization2021 edition
ISO 10993-12Sample preparation and reference materials2021 edition, amended 2025
ISO 10993-17Toxicological risk assessment of device constituents2023 edition, amended 2025
ISO 10993-18Chemical characterization of materials2020 edition, amended 2022

Most common finding: Manufacturers cite ISO 10993-5 or -10 correctly but leave the ISO 10993-1 reference in their design history file pointing to the 2018 edition without any documented rationale for why. If your BEP hasn’t been revisited since the 2025 edition published, that’s the first thing to check.

If your device is sterilized and you haven’t looked at how the 2026 edition of ISO 10993-7 interacts with your sterilization validation, our sterilization standards overview walks through ISO 11135, 11137, 17665, and 11607 alongside it.


What Changed in ISO 10993-1:2025

The sixth edition isn’t a light refresh. ISO’s technical committee reorganized the standard and changed its title to explicitly align with the ISO 14971 risk management framework. The practical changes:

  • More detailed guidance on calculating exposure duration — including how to treat foreseeable misuse, such as a device used longer than its labeled duration.
  • Expanded guidance on device characterization and biological hazard identification, intended to reduce reliance on generic test batteries.
  • Terminology aligned with ISO 14971, so if your team already knows that standard, the 2025 edition should read more consistently — though NAMSA and other industry commentators note there isn’t yet a technical report equivalent to ISO/TR 24971 to guide interpretation of the new edition.

Here’s how the two editions compare on the points that matter most for your Biological Evaluation Plan:

Topic2018 Edition2025 Edition
Risk Management IntegrationReferenced ISO 14971More explicitly aligned throughout
Exposure DurationLimited guidanceExpanded methodology for calculating duration, including foreseeable misuse
Biological Hazard IdentificationLess detailedExpanded guidance on device characterization and hazard identification
Risk EstimationDifferent treatmentNew Clause 6.9 (excluded by FDA)

If you are preparing a Biological Evaluation Plan for a new device → start by confirming which edition your FDA reviewer or notified body expects to see referenced, since adoption isn’t uniform across regions. The EU has generally moved faster toward treating the 2025 edition as state of the art. Manufacturers should verify current adoption expectations directly with their notified body and applicable competent authorities, since implementation timing varies and is subject to change.

One shift worth flagging for regulatory teams building out a modern BEP: chemical characterization under ISO 10993-18 is playing a larger role than it used to. Rather than defaulting to a blanket biological test matrix for every device, more manufacturers are leaning on thorough chemical characterization data — extractables and leachables profiles, material composition analysis — to justify a narrower, risk-based testing strategy. ISO 10993-1:2025’s expanded hazard identification guidance reinforces this shift. A well-documented ISO 10993-18 characterization can reduce redundant biological testing, but only if the chemistry-driven rationale is documented clearly enough to withstand a reviewer’s scrutiny.

Comparison graphic showing the major differences between ISO 10993-1:2018 and ISO 10993-1:2025 for biological evaluation of medical devices.
The 2025 edition places greater emphasis on risk management integration, biological hazard identification, and exposure assessment.

ISO 10993 FDA Recognition: What’s Excluded and Why

🔑 Key FDA Takeaway FDA recognizes ISO 10993-1:2025, but excludes:

  • The “consumer products” language in Clause 6.5.11.3
  • Clause 6.9 on biological risk estimation

Manufacturers should document alternative justification using FDA guidance and ISO 14971.

On May 25, 2026, FDA updated its Recognized Consensus Standards database (Recognition No. 2-313) to include ISO 10993-1:2025 — but not in full. Two specific exclusions matter for your submissions:

  1. The phrase “consumer products or” in Clause 6.5.11.3. This clause addresses low-risk, intact-skin-contacting devices. The standard allows manufacturers to point to a material’s history of safe use in consumer products as justification for reduced testing. FDA excluded this because it conflicts with Attachment G of its 2023 biocompatibility guidance, which defines specific materials with an accepted history of use — a consumer product history alone doesn’t automatically satisfy FDA’s expectations.
  2. Clause 6.9 on biological risk estimation. FDA determined this clause conflicts with the risk estimation approach already established in the FDA-recognized ISO 14971:2019. Sponsors can’t rely on Clause 6.9 to claim conformity in a submission.

If you are under customer or notified body pressure to update your BEP quickly → prioritize reviewing these two clauses first. They’re the specific areas where citing the 2025 edition alone won’t satisfy FDA, and you’ll need to document your justification through existing FDA guidance instead.

Partial recognition means you cannot submit a clean Declaration of Conformity to the full 2025 edition. Your submission documentation needs to call out the partial recognition explicitly and show how you’re addressing the excluded clauses — silence on this point is what generates additional information requests.

Workflow illustrating FDA partial recognition of ISO 10993-1:2025 and the documentation required for excluded clauses during medical device submissions.
FDA recognizes ISO 10993-1:2025 with specific exclusions, requiring manufacturers to document alternative regulatory justifications.

Do You Need to Retest Already-Cleared Devices?

This is the objection I hear most from teams looking at this update: does a new edition mean I have to redo my biocompatibility testing on devices that already have clearance?

No — not automatically. FDA’s recognition of a newer edition doesn’t retroactively invalidate data or clearances based on the 2018 edition. If you already hold clearance under the 2018 edition → you don’t need to retest existing devices. What you do need is a documented rationale, at your next design change or periodic review, for why your BEP still reflects sound risk management even though a newer edition exists. That’s a documentation and justification exercise, not a lab exercise.

Where this becomes a live issue is new submissions and significant design changes going forward — those are where reviewers will expect to see the current edition addressed.


Where Biocompatibility Fits Into Your ISO 13485 QMS

Biocompatibility data doesn’t live in isolation — it’s part of your design and development file under ISO 13485, and it feeds directly into your risk management file under ISO 14971. If your ISO 13485 documentation structure doesn’t have a clear place for biological evaluation plans, reports, and the rationale behind edition changes, that’s a gap worth closing before your next internal audit — not after a nonconformance is written.

This also connects to supplier controls. If a component supplier’s certificate of conformance references ISO 10993-1 by edition, your incoming inspection and supplier qualification process needs a mechanism to catch when that reference goes stale — the same principle covered in our guide on common mistakes in ISO 13485 QMS implementation.

And if you’re managing devices sold in both the US and EU, the edition-adoption gap between FDA and the EU regulatory framework is one more reason to keep your MDR vs ISO 13485 documentation aligned rather than treating them as separate tracks.

👉 If your biological evaluation documentation hasn’t been reviewed since the 2025 edition published, don’t wait for a finding to tell you. Check where your QMS documentation actually stands →


Quick Audit Checklist

✅ Confirm which edition of ISO 10993-1 your current BEP references, and whether that matches what your reviewer or notified body expects
✅ Check whether your device’s biocompatibility justification relies on Clause 6.5.11.3 (consumer product history) or Clause 6.9 (risk estimation) — both need alternative justification for FDA submissions
✅ Verify supplier certificates of conformance cite current standard editions, not stale references
✅ Confirm your risk management file cross-references your BEP consistently ✅ If your device is sterilized, check the 2026 editions of ISO 10993-6 and -7 against your current validation data ⚠️ Don’t assume “FDA recognized” means “fully accepted” — verify the Supplementary Information Sheet for any standard before citing it as a full Declaration of Conformity


FAQ

What is biocompatibility testing for medical devices?

Biocompatibility testing evaluates whether the materials in a medical device, and the way those materials contact the body, could cause an unacceptable biological response. It covers areas like cytotoxicity, sensitization, irritation, and systemic toxicity, selected based on the device’s contact type and duration.

What is ISO 10993-1, and do I need to comply with it?

ISO 10993-1 is the framework standard that governs how you plan and justify a biological evaluation within a risk management process. If your device contacts the body directly or indirectly, FDA and most global regulators expect your biocompatibility strategy to follow its structure, even where full conformity isn’t feasible.

What changed between ISO 10993-1:2018 and ISO 10993-1:2025?

The 2025 edition reorganized the standard to align more closely with ISO 14971, added detailed guidance on calculating exposure duration and identifying biological hazards, and updated terminology throughout.

Has the FDA recognized ISO 10993-1:2025?

Yes, as of May 25, 2026, but only partially. FDA excluded the “consumer products” language in Clause 6.5.11.3 and all of Clause 6.9 on biological risk estimation, both of which conflict with existing FDA guidance and the FDA-recognized ISO 14971:2019.

Do I need to retest devices already cleared under the 2018 edition?

No. Existing clearances aren’t invalidated by a newer edition. You do need a documented rationale for your current approach at your next design change or periodic review.

Which parts of the ISO 10993 series apply to my device?

That depends on your device’s contact type (surface, external communicating, or implant) and contact duration (limited, prolonged, or permanent). ISO 10993-1 provides the matrix for selecting relevant parts of the series based on those two factors. We’ll be covering that contact-duration matrix in detail in an upcoming guide.

Is ISO 10993 the same as ISO 13485?

No. ISO 13485 governs your overall quality management system for medical devices. ISO 10993 is a series specifically about biological evaluation, and its outputs — your BEP and test reports — become part of the design and development records your ISO 13485 QMS requires you to maintain.

Where do I purchase ISO 10993 standards?

Individual parts and bundled packages are available through the ANSI Webstore, which also serves international buyers and offers documents in multiple languages. The ISO.org catalog describes each part but is not the recommended purchase channel.


📥 Free Resources

  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.
  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements, including where biocompatibility documentation fits.
  • AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification.

Not Sure What to Do Next?

🔹 Still researching how the 2025 edition affects your device category? Start with our breakdown of risk management under ISO 14971 — biocompatibility evaluation doesn’t stand apart from it anymore.

🔹 Ready to check where your documentation actually stands? Run the ISO 13485 Gap Assessment Checklist before your next audit or submission, not after.

🔹 Need to purchase the current standard? ISO 10993-1:2025 — ANSI Webstore, or get the full biological evaluation package bundled at roughly 45% off individual pricing if you’re assembling multiple parts of the series. Use code CC2026 for an additional 5% off through December 31, 2026.

The Standards Navigator will keep tracking how FDA recognition evolves on this standard as updates are published.


Documentation Gaps Don’t Show Up Until Someone’s Looking For Them

Teams that treat biocompatibility as a one-time lab exercise are the ones caught off guard when a standard’s edition changes underneath them. Teams that treat it as a living part of their design and risk management file catch the mismatch at their next internal review, not during an FDA question round — and it’s usually a citation that didn’t keep up, not the underlying science, that stalls a submission.

The Standards Navigator tracks these regulatory shifts as they happen — not months later when the transition deadline is already close. If ISO 10993-1:2025 affects your device, this is a good window to revisit your documentation rationale while the timeline is still in your control.

👉 Get updates on medical device compliance and biocompatibility standard changes
👉 Be first to access new gap assessment checklists and documentation tools for ISO 13485 and ISO 14971

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

Validation & Verification Requirements: What ISO 13485 and the New FDA QMSR Actually Demand (2026 Guide)

ISO 13485 Clause 7.3 requires distinct verification and validation evidence — and the FDA’s new QMSR, effective February 2, 2026, makes the distinction matter more than ever. This guide breaks down design verification, design validation, process validation, and software validation requirements, and shows manufacturers how to build a traceability matrix that survives an audit or inspection.

ISO 13485 verification and validation requirements explained for medical device manufacturers navigating the QMSR transition

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Documentation Gap That Fails Design History Files

A design verification report that confirms the device meets its own specifications is not the same thing as a validation report that confirms the device meets the user’s actual needs. Auditors know the difference. Regulatory affairs teams sometimes don’t find out until an FDA inspector or notified body assessor pulls the Design History File and asks for both — and only one exists.

That gap has gotten more consequential, not less. The FDA’s Quality Management System Regulation took effect February 2, 2026, formally incorporating ISO 13485:2016 into 21 CFR Part 820 by reference. Verification and validation records that used to satisfy QSR expectations are now being evaluated against ISO 13485 Clause 7.3 directly — and the two frameworks don’t document V&V identically.

From the Floor: As a certified ISO 9001 Internal Auditor, I’ve sat across the table from teams who could produce a stack of test reports but couldn’t answer a simple question: which of these prove the design meets the specification, and which prove it meets the user’s need? Verification and validation get treated as interchangeable paperwork until an auditor separates them — and by then it’s a finding, not a conversation. The QMS documentation discipline that catches this before an audit is the same discipline that catches it before a submission.

If your last internal audit didn’t clearly separate verification evidence from validation evidence, that’s the gap worth closing first.

Run a clause-by-clause gap check before your next surveillance audit or FDA inspection — the ISO 13485 Gap Assessment Checklist below is built for exactly this kind of documentation review. Most teams miss the verification/validation split until it’s flagged.

👉 ISO 13485 Gap Assessment Checklist


In This Guide

  • What verification and validation mean under ISO 13485 Clause 7.3, and why they are not interchangeable
  • How process validation (Clause 7.5.6) differs from design validation
  • Software validation requirements for devices and manufacturing/QMS software
  • What changed under the FDA QMSR effective February 2, 2026
  • The most common V&V documentation failures found in audits and inspections
  • How to structure a verification and validation plan that survives scrutiny


👉 Start Here (Top Resources)

If you’re building or auditing a verification and validation process, these are the two resources worth starting with:


Verification vs. Validation: The Core Distinction

Comparison infographic explaining the differences between ISO 13485 verification and validation requirements under ISO 13485:2016, including design inputs, intended use, testing methods, timing, applicable clauses, and common audit findings.
This comparison illustrates how verification and validation serve different purposes under ISO 13485 and why both are required for compliant medical device design controls.

Verification confirms that design outputs meet design inputs. Validation confirms that the finished device meets user needs and intended use. That one-sentence distinction is where most documentation failures start, because the two activities can look procedurally similar — testing, measuring, comparing results against criteria — while answering completely different questions.

ElementDesign VerificationDesign Validation
Question answeredDid we build the design correctly?Did we build the correct design?
Compared againstDesign inputs / specificationsUser needs / intended use
Typical methodsBench testing, inspection, analysis, comparison to similar designsClinical evaluation, simulated use testing, human factors studies
TimingThroughout design and developmentUnder defined operating conditions, on initial production units or equivalent
ISO 13485 clause7.3.67.3.7
Common failureTesting against internal spec only, no traceability to inputValidating on prototypes instead of production-equivalent units

Most common finding: auditors and FDA investigators repeatedly cite validation performed on non-representative units — bench prototypes, early builds, or units built on equipment that doesn’t match production. ISO 13485 Clause 7.3.7 specifically requires validation on production or production-equivalent units, under defined operating conditions.


Verification and Validation in Practice: An Infusion Pump Example

Take a manufacturer developing an infusion pump. Design verification confirms the device meets its own engineering specifications:

  • ✅ Flow rate accuracy within the specified tolerance
  • ✅ Battery life meets the stated runtime under load
  • ✅ Alarm volume meets the decibel specification

Design validation confirms something different — that the device works safely in the hands of the people who will actually use it:

  • ✅ Nurses can operate the pump correctly and safely during simulated or actual clinical use
  • ✅ The alarm is audible and distinguishable in a realistic hospital environment, not a quiet test lab
  • ✅ Labeling and instructions for use are understood by the intended users without additional training

A pump can pass every verification test and still fail validation — accurate flow rate and long battery life mean nothing if a nurse under time pressure misreads the alarm or misinterprets the instructions. That’s the gap Clause 7.3.7 is built to catch, and it’s why validation has to happen on production-equivalent units under conditions that resemble actual use.


Design Verification Requirements

Clause 7.3.6 requires that design verification confirms outputs meet input requirements, with results and conclusions recorded, including the methods, dates, and individuals performing the verification. In practice, that means every design input needs a traceable verification activity — not a general statement that “the device was tested.”

If you are building a Design History File from scratch → start with a traceability matrix that maps every design input to its verification method and result before writing a single test protocol. Retrofitting traceability after testing is where most rework happens.

If you are already ISO 9001 certified and adding ISO 13485 → your existing design control process likely covers verification structurally, but it almost certainly lacks the input-to-output traceability rigor ISO 13485 auditors expect. That’s the gap to close first, not the documentation format.

👉 Before You Build Another Test Protocol

Most verification failures aren’t testing failures — they’re traceability failures. Run your design inputs against your current verification records now and find the gaps before an assessor does. →


Design Validation Requirements

Design validation under Clause 7.3.7 must be performed on production or production-equivalent units, under defined operating conditions, and must include risk analysis where applicable — which is where ISO 14971 risk management intersects directly with design controls. Validation isn’t complete until it addresses actual clinical or user-environment conditions, not lab conditions that approximate them.

Objection: “Our device is low-risk — do we really need formal simulated-use validation?” Even Class I and low-risk Class II devices need validation evidence proportional to risk, and “proportional” still means documented, traceable, and tied to intended use. A shorter validation plan is defensible. No validation plan is not.

Clinical evaluation, when required, and human factors/usability testing both fall under validation, not verification — a distinction that matters for regulatory submissions referencing FDA guidance on human factors engineering.


Process Validation Under Clause 7.5.6

Infographic explaining the three phases of process validation under ISO 13485, including Installation Qualification (IQ), Operational Qualification (OQ), and Performance Qualification (PQ), with key activities, outputs, and compliance requirements.
This infographic explains the roles of IQ, OQ, and PQ in process validation, helping manufacturers understand how each qualification stage supports ISO 13485 and FDA QMSR compliance.

Separate from design validation, ISO 13485 Clause 7.5.6 requires validation of processes where the resulting output cannot be verified by subsequent monitoring or measurement — sterilization, certain sealing and bonding processes, injection molding parameters, and software used in production are the classic examples.

Process validation requires:

  • ✅ Defined criteria for review and approval of the process
  • ✅ Approval of equipment and qualification of personnel
  • ✅ Use of specific methods, procedures, and acceptance criteria
  • ✅ Requirements for records (Clause 4.2.5)
  • ✅ Revalidation criteria, including criteria for triggering revalidation

Most auditors and FDA investigators expect this evidence structured around three stages: Installation Qualification (IQ), Operational Qualification (OQ), and Performance Qualification (PQ).

Installation Qualification (IQ) confirms that equipment and supporting systems are installed correctly, according to the manufacturer’s specifications and the site’s own installation requirements — including verified utilities, calibration status, and documentation of the as-installed configuration, not just a checklist that the equipment arrived and was plugged in.

Operational Qualification (OQ) confirms that the equipment operates as intended across its full specified operating range, not just at a single nominal setting. For a sterilization process, that means testing at the upper and lower bounds of temperature, time, and pressure defined in the process specification — not only the target parameters.

Performance Qualification (PQ) confirms that the process consistently produces conforming output under actual production conditions, typically across multiple runs and, where risk warrants it, multiple operators, shifts, or lots. PQ is where most revalidation triggers get defined, since it establishes the baseline the process must continue to meet.

If you are validating a sterilization or bonding process for the first time → build your IQ/OQ/PQ protocol before ordering test units. Retrofitting an IQ after OQ testing has already started is a common finding, and it undermines the traceability an assessor is looking for.

If your process hasn’t changed but your equipment or facility has → IQ typically needs to be repeated even when OQ and PQ parameters stay the same, since IQ is tied to the specific installation, not the process design.

Skipping straight to PQ — running production and calling the passing output “validation” — is one of the most common shortcuts auditors flag, because it skips the evidence that the equipment itself is capable of consistently meeting the operating range the process depends on.

If you are outsourcing sterilization or bonding processes → your supplier controls documentation needs to show that you’ve verified the supplier’s process validation, not just received a certificate of conformance.


Software Validation Requirements

Software validation shows up in two places under ISO 13485, and conflating them is a recurring audit finding: software that is part of the device (or used in its production) versus software used for quality management purposes, such as electronic QMS platforms or CAPA tracking tools. Both require validation appropriate to their use, application, and risk — but the depth and method differ substantially, and design-control software validation should be traceable back to the same input/output structure as hardware verification.


What the FDA QMSR Changed for U.S. Manufacturers

The FDA’s Quality Management System Regulation replaced the legacy Quality System Regulation under 21 CFR Part 820, effective February 2, 2026, incorporating ISO 13485:2016 by reference rather than maintaining a separately worded U.S. regulation. For manufacturers who were already ISO 13485 certified, the operational impact on verification and validation practices is smaller than the documentation-mapping impact: DHF, DMR, and DHR content doesn’t necessarily need renaming, but it does need a clear mapping showing where ISO 13485 Clause 7.3 requirements are satisfied within existing U.S. records.

If you were operating under legacy QSR language only → this is the trigger to formally adopt ISO 13485 Clause 7.3 verification/validation terminology and structure, since FDA inspectors are now trained against the ISO clause structure, not the old Part 820 subparts.


Common V&V Documentation Failures

The same handful of gaps show up repeatedly in ISO 13485 QMS audits:

  • No traceability matrix linking design inputs to verification methods and results
  • Validation performed on prototypes rather than production-equivalent units
  • Missing revalidation criteria for processes that later change equipment, materials, or parameters
  • Software validation treated as one-size-fits-all instead of scaled to risk and application
  • Verification and validation dates, methods, and personnel not fully recorded, leaving conclusions without traceable support

👉 Before Your Next Notified Body Assessment

If you’re not confident your traceability matrix would hold up under document review, that’s the exact gap the ISO 13485 Gap Assessment Checklist was built to catch — in under 45 minutes. →


Building a Verification & Validation Plan That Holds Up

A defensible V&V plan starts with the traceability matrix, not the test protocols. Build it in this order:

  1. List every design input and requirement
  2. Map each input to a specific verification method and acceptance criterion
  3. Identify which requirements also require validation evidence, and under what conditions
  4. Define production-equivalent unit criteria before validation begins
  5. Build revalidation triggers into the plan up front — not as an afterthought after a process change

This structure is what turns a stack of individual test reports into a Design History File that answers an assessor’s questions instead of prompting more of them.

Workflow infographic illustrating how verification and validation fit into the ISO 13485 design control process, from user needs and design inputs through production-equivalent units, validation, and Design History File documentation.
This workflow shows how verification and validation integrate into ISO 13485 design controls to produce a complete, traceable Design History File for regulatory compliance.

Quick Audit Checklist

  • ✅ Every design input has a documented verification method and result
  • ✅ Validation was performed on production or production-equivalent units
  • ✅ Risk analysis is referenced in the validation rationale
  • ✅ Process validation records include revalidation criteria
  • ✅ Software validation is scaled to intended use and risk
  • ✅ Verification and validation records include dates, methods, and personnel
  • ⚠️ Watch for validation evidence copied from an earlier device without device-specific justification

FAQ

What is the difference between verification and validation in ISO 13485?

Verification confirms design outputs meet design inputs — did we build it correctly. Validation confirms the finished device meets user needs and intended use — did we build the correct thing. They require separate evidence and cannot substitute for each other.

Does ISO 13485 require validation on production units?

Yes. Clause 7.3.7 requires design validation on production or production-equivalent units under defined operating conditions, not on early prototypes or bench models that don’t reflect final manufacturing.

What processes require process validation under Clause 7.5.6?

Any process where output cannot be fully verified by later inspection or testing — common examples include sterilization, certain welding and bonding processes, injection molding, and adhesive curing.

How did the FDA QMSR affect verification and validation requirements?

The QMSR, effective February 2, 2026, incorporates ISO 13485:2016 into 21 CFR Part 820 by reference. Manufacturers now need documentation that maps clearly to ISO 13485 Clause 7.3, even if internal DHF/DMR/DHR naming stays the same.

Do low-risk devices still need design validation?

Yes, though the depth can scale with risk. A shorter, risk-justified validation plan is acceptable; skipping validation entirely is not.

Does software need separate validation from the device it’s part of?

Software validation is required both for software that’s part of or used in producing the device, and for software used for quality management purposes — but the required depth and method differ by application and risk.

What’s the most common finding auditors cite for validation?

Validation conducted on non-representative units — prototypes or early builds that don’t match production configuration or manufacturing conditions.

Where does risk management fit into verification and validation?

ISO 14971 risk management activities feed directly into what needs validation and how rigorously, particularly for design validation rationale and process revalidation triggers.


📥 Free Resources

  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements, including design control and V&V documentation gaps
  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts
  • AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification

Not Sure What to Do Next?

🔹 Still researching your V&V documentation gaps? Start with the ISO 13485 Gap Assessment Checklist — it maps directly to Clause 7.3 verification and validation requirements.

🔹 Ready to build a compliant V&V process? BSI Group’s ISO 13485 training covers Clause 7.3 requirements in the depth a design control rebuild needs.

🔹 Need the standard itself to build your traceability matrix against? Get ISO 13485:2016 from ANSI Webstore — code CC2026 takes 5% off, and international formats are available.


Verification proves your engineers met the specification. Validation proves your customers can safely use the product. Auditors expect both. Regulators require both. A complete Design History File demonstrates both through traceable evidence — not one comprehensive-sounding report that tries to do both jobs at once.


Stay Ahead of the Next V&V Finding

Design History File gaps rarely surface during routine work — they surface during an audit or inspection, when there’s no time left to fix them. Manufacturers who catch the verification/validation split early walk into assessments with a traceability matrix that answers questions before they’re asked. Manufacturers who don’t spend the assessment explaining why validation was performed on a prototype.

The Standards Navigator tracks ISO 13485, QMSR, and medical device compliance requirements as they develop — including changes that affect how verification and validation get documented.

👉 Get updates on ISO 13485 and QMSR compliance changes
👉 Be first to access new medical device gap assessment tools and checklists

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.