Add Your Heading Text Here
Reference guide for quality and regulatory teams
QMSR inspections: how FDA inspects medical device manufacturers now.
On February 2, 2026, Part 820 became the Quality Management System Regulation (QMSR) and the inspection technique FDA had used for decades was withdrawn on the same day. The requirements barely moved. The way they get evaluated moved a long way. This guide covers what an inspection now looks like in practice: the map investigators work from, both coverage models, what officials say they are citing so far, and where teams are getting caught.
- Effective
- Feb 2, 2026No grace period beyond the two-year transition
- Inspection program
- CP 7382.850QSIT withdrawn the same day
- Structure
- 6 areas, 4 OAFRsOrganised around patient risk
- Top cited area
- Risk managementPer CDRH, early 2026 observations
At a glance
What changed, in one page
FDA's own final rule describes the old and new requirements as substantially similar. That is accurate, and it is exactly why some teams under-prepared. The substance held. Almost everything about how an investigator arrives at it did not.
What Part 820 looks like now
Physically, the regulation got much shorter. Most of it is now a pointer to the standard. What remains in the CFR text is worth knowing, because it is the part ISO 13485 does not cover and the part an investigator will check separately.
| Section | What it does | Worth knowing |
|---|---|---|
| Subpart A820.1, 820.3, 820.7, 820.10 | Scope, definitions, the formal incorporation by reference, and the general QMS requirement. | 820.10(d) requires manufacturers of life-supporting and life-sustaining devices to meet clause 7.5.9.2, traceability for implantable devices. 820.10(e) states that failure to comply with any applicable requirement renders a device adulterated. |
| Subpart B820.35, 820.45 | Supplemental provisions. FDA-specific requirements added where the agency judged the standard insufficiently explicit. | This is the short list that is easy to miss because it is not in the standard. |
| 820.35Control of records | Sits on top of ISO 13485 clause 4.2.5. Specifies complaint record content and when complaints must be investigated, service records, UDI documentation under Part 830, and confidentiality of records sent to and received from FDA. | More explicit than the old QSR text on complaints. Practitioners consistently flag this as the section companies underestimate. |
| 820.45Device labeling and packaging controls |
Sits on top of ISO 13485 clause 7.5.1, control of production and service provision. FDA did not consider the standard's labeling and packaging controls adequate. Requires documented procedures covering integrity, inspection, storage and operations for labeling and packaging. | Labeling must be examined for accuracy before release or storage, covering the correct UDI or UPC, expiry date, storage instructions, handling instructions and any additional processing instructions. Release of labeling and the results of labeling inspection must both be documented. |
| Subparts C to OReserved | The old prescriptive text is gone. Readers are directed to ISO 13485:2016. | If your SOPs cite 820.30 or 820.100, the citation no longer resolves to anything. |
Words that do not mean what the standard says they mean
820.3 is short and easy to skip, and skipping it is how teams misread the standard. FDA definitions and the definitions in section 201 of the Federal Food, Drug, and Cosmetic Act supersede the correlating ISO terms. Four worth knowing:
| Term in ISO 13485 | What it means under Part 820 |
|---|---|
| Organization | Read as manufacturer, as defined in Part 820. Every ISO obligation on the organisation is an obligation on the manufacturer, including contract sterilizers, installers, relabelers, remanufacturers, repackers, specification developers, and initial distributors of foreign entities performing those functions. |
| Safety and performance | Read as safety and effectiveness, per clause 0.1 of ISO 13485. The change in wording does not relieve you of any obligation to provide reasonable assurance of safety and effectiveness. |
| Medical device, labelling | Superseded by the statutory definitions in section 201(h) and 201(m) of the Act. |
| Implantable medical device | Takes the meaning of implant as defined in 21 CFR 860.3. |
Who has to follow design controls
820.10(c) is specific about this, and it is worth checking against your own portfolio. Clause 7.3 and all its subclauses apply to class II and class III devices, and to two categories of class I device: any class I device automated with computer software, and five named device types, being tracheobronchial suction catheters, non-powdered surgeon's gloves, protective restraints, manual radionuclide applicator systems, and radionuclide teletherapy sources.
820.35(a) names the fields, so this one is checkable in advance
For complaints reportable under Part 803, complaints you determine must be investigated, and complaints you investigate anyway, seven items must be recorded: device name, date the complaint was received, any UDI or UPC and other device identification, the complainant's name, address and phone number, the nature and details of the complaint, any correction or corrective action taken, and any reply to the complainant. If a similar complaint was already investigated, a further investigation is not required, but you must keep records justifying that decision.
The map investigators work from
The clearest way to understand a 7382.850 inspection is its central structure. Patients and users sit at the middle. A ring of risk management surrounds them, because your own risk documentation is what the investigator uses to navigate. The six QMS areas sit around that, with FDA-specific requirements outside.
Our rendering of the inspection structure described in Compliance Program 7382.850, Part III. Not a reproduction of FDA's diagram.
Outside the six areas sit four other applicable FDA requirements. These are US statutory obligations that ISO 13485 does not address, so they get verified separately no matter how strong your certification position is. What is less well known is that the regulation tells you exactly where each one attaches to the standard. 820.10(b) does the mapping, and it is the most practical paragraph in Part 820 for anyone rewriting procedures.
| Requisito | Attaches to this ISO clause | Per 820.10(b) |
|---|---|---|
| Unique Device Identification21 CFR Part 830 | Clause 7.5.8 Identification |
Document a system to assign unique device identification in accordance with Part 830. |
| Device tracking21 CFR Part 821 | Clause 7.5.9.1 Traceability, general |
Document traceability procedures in accordance with Part 821, where applicable. |
| Medical Device Reporting21 CFR Part 803 | Clause 8.2.3 Reporting to regulatory authorities |
Notify FDA of complaints meeting the reporting criteria of Part 803. |
| Corrections and removals21 CFR Part 806 | Clauses 7.2.3, 8.2.3, 8.3.3 Advisory notices |
Handle advisory notices in accordance with Part 806. |
The six QMS areas, and what sits inside each
Each area breaks into elements, and each element ties to specific requirements, mostly ISO 13485 clauses with the QMSR additions layered in. Attachment A of the compliance program maps all of it, and it is the single most useful thing a quality team can read before an inspection.
| Área | Elements it covers |
|---|---|
| Change control | Changes to the quality system, to software, to products and processes, and to purchasing. |
| Design and development | Design inputs and outputs, review, verification, validation, software validation, and design transfer. |
| Management oversight | The quality management system itself, management review, the medical device file, planning of product realisation, and the risk-based approach required by clause 4.1.2(b). |
| Measurement, analysis and improvement | Complaint handling, feedback, internal audits, analysis of data, control of nonconforming product, corrective action, and preventive action. |
| Outsourcing and purchasing | Outsourced processes and the purchasing process. |
| Production and service provision | Process validation, identification and traceability, and for sterile products, sterilisation and sterile barrier systems. |
Risk applies to processes you would not think to assess
This is a detail from FDA's own town hall that saves teams a lot of unnecessary work, and it is worth reading twice.
Clause 4.1.2(b) requires a risk-based approach across all quality system processes, including administrative ones like document control and training. That sounds like an invitation to build a separate formal risk assessment for every internal function. FDA has said it is not. Decisions about an administrative process should reference the existing risk documentation for the related product or process instead.
The worked example FDA gave
How often you retrain staff on a manufacturing procedure should be informed by the documented risk of that procedure. It does not require a standalone training risk assessment. The same proportionality applies to training effectiveness checks: higher-risk work may warrant supervisor evaluation, skill assessment or performance monitoring, while simpler verification can be enough for lower-risk work.
Two coverage models, and which one you get
Every inspection follows one of two models. The model sets the minimum amount of your quality system that gets examined. Knowing which one applies to your next inspection tells you how deep to prepare.
| Model | Minimum coverage | When it applies |
|---|---|---|
| Model 1Broad | At least one element from each of the six QMS areas, plus the applicable OAFRs and general items. Every main part of the system is touched, even if only at one element. | Non-baseline surveillance, compliance follow-up, for-cause, specific product risk assignments, and PMA postmarket inspections. |
| Model 2Deep | Named minimum elements across all six areas. Design and development alone expands to inputs, outputs, review, verification, validation, software validation and transfer. Measurement, analysis and improvement expands to seven elements. | Baseline surveillance inspections and PMA pre-approval inspections, where FDA has no inspection history to rely on or an application pending. |
In both models the investigator can add elements whenever conditions warrant. The model is a floor, not a ceiling. If something surfaces, the inspection widens.
How an inspection unfolds
The mechanics will feel familiar to anyone who has been through a QSIT inspection. The order of operations is what changed.
- Form 482 issuedA domestic inspection still opens with the notice of inspection.
- OrientationFacility tour, how products and processes work, roles and responsibilities.
- Product risks identifiedThe investigator determines which risks the device could pose to patients or users. This step now drives everything after it.
- Your risk documentation is readUsed throughout to understand those risks and how they are controlled. It is the navigation instrument, not a file to be checked off.
- An element is selected and evaluatedWithin a QMS area or an OAFR. There is no set order, and areas are not worked through in sequence.
- Scope adjustsIf objectionable conditions surface, the investigator adds elements. Documents are reviewed, staff interviewed, processes observed.
- Form 483 if warrantedObservations listed. You can annotate the form or respond in writing afterwards.
What FDA is citing so far
Early data, presented by CDRH officials at three separate events in the spring of 2026. Read it as directional. The ordering has not settled, and we have flagged that below rather than picking the version that reads best.
At the Food and Drug Law Institute annual conference in May, Keisha Thomas, associate director in CDRH's Office of Product Evaluation and Quality, said the agency had completed just over 100 inspections under the QMSR. For Form 483 observations issued between February and mid-April, she ranked the top areas as follows.
| Rank | Área | What auditors report finding underneath |
|---|---|---|
| 01 | Gestión de riesgos | The file looks complete but cannot show the connective work: how complaints, nonconformances, service data, field failures and supplier issues feed back into the analysis, who owns those updates, and how control effectiveness is verified over time. |
| 02 | Outsourcing and purchasing | Rarely an empty supplier file. Usually a generic one, with a low-risk packaging vendor and a critical contract sterilizer governed by the same template and the same review cadence. |
| 03 | Complaint handling and feedback | Fails at the handoffs rather than in the procedure. The signal arrives but does not travel upstream. |
| 04 | UDI | One of the four OAFRs, verified separately from anything your certification covers. |
| 05 | Corrective action | Existence of a procedure is not the question. Evidence the action worked is. |
Risk, risk, risk, risk. That is the fundamental change to QMSR. Keisha Thomas, associate director, CDRH Office of Product Evaluation and Quality, 2026, as reported by The FDA Group
One thing is stable, the rest is not
Risk management came first at all three events, and that is the finding to act on. Everything below it moves. At MedCon in late April, officials put outsourcing and purchasing second for the February to March window. At the RAPS Quality Conference around four months in, Thomas listed risk management, then corrective action, then risk-based approach, complaint handling and purchasing. She added the caveat that matters most: it is early, and the agency is largely seeing the same citations it saw before the QMSR, in a different order. The categories are old. What changed is how an inspection arrives at them.
Terminology that changed, and what you can ignore
Three terms that have organised US device documentation for decades do not appear in the QMSR. The obligations survived. The vocabulary did not.
| Retired term | Where the content lives now | Clause |
|---|---|---|
| Design history file | Design and development file. Contains or references the records establishing compliance with design and development requirements, including the plan, the procedures, and design changes. | ISO 13485 7.3.10 |
| Device master record | Medical device file, plus referenced production specifications. The file is a single hub for a device type or family rather than a fixed record category. | ISO 13485 4.2.3 |
| Device history record | Production and service provision records with acceptance evidence. The single combined file concept goes away; the underlying batch and production records do not. | ISO 13485 7.5.1 and related |
You do not need to retrofit your history
FDA states in its own QMSR FAQ that manufacturers do not need to revise or recreate records created before February 2, 2026, and officials confirmed at the April town hall that older documents do not need ISO 13485 references added, and that terms like design history file do not need scrubbing from historical records. What is expected is that you identify where processes need to change and plan those changes. Old records do not need new labels. Old gaps still need closing.
Outcomes, thresholds and the response clock
| Classification | Meaning |
|---|---|
| NAI | No action indicated. No objectionable conditions observed. |
| VAI | Voluntary action indicated. Objectionable conditions documented but below the threshold for regulatory action. |
| OAI | Official action indicated. Conditions supported by evidence, and regulatory action is recommended. |
Findings that point toward OAI
The compliance program guides the classification decision with two situations. Situation 1 lists examples pointing toward an initial OAI, and two of them are worth committing to memory because they are both risk failures rather than documentation failures:
- No risk management process in product realisationFailure to establish or maintain one.
- Postmarket feedback that never reaches risk managementThe loop from the field back into the analysis is open.
Situation 2 lists examples that typically result in VAI, where deficiencies suggest a low probability of nonconforming product reaching patients. Both situations existed under prior versions of the program and were updated for the QMSR. The threshold for action has not moved.
The response window
The practical expectation is a written response with corrections and corrective action plans within roughly 15 business days of the Form 483, which is the window in which a response is normally considered before the agency moves. Prompt voluntary correction remains the outcome FDA prefers. From there the ladder runs through advisory measures, then administrative actions, then judicial ones. Confirm the exact window against the Form 483 you receive rather than against this page.
Five things teams get wrong
We are ISO 13485 certified, so we are covered.
Certification and notified body audits are useful evidence of a working system. They do not replace QMSR readiness or your own internal audit obligations, and there is no certification against Part 820. The four OAFRs and the Subpart B supplements sit entirely outside what a certificate speaks to.
Sampling is gone, so everything gets examined.
Statistical sampling plans are out. Sampling itself is not. It is now risk-based, driven by your own risk documentation and your real-time data. What did change is that under Model 1 every QMS area gets touched at least once, so no area is skipped outright.
Our internal audits come back clean, which proves we are in good shape.
Those reports are now inspectable, and an absence of findings can as easily mean the audits are not looking hard enough. FDA has encouraged firms to run internal audits more like an inspection, aimed at finding real problems first.
Records from before February 2026 are a liability now.
They are inspectable, but they do not need retrofitting or relabelling. What matters is whether a gap analysis surfaces a real deficiency, such as feedback that never fed into risk management, and whether you have a plan to close it.
Producing a complete FMEA satisfies the risk requirement.
The test is no longer whether the FMEA exists. It is whether the FMEA reflects current product performance, and whether you can show the connective work that keeps it current after launch.
The preparation exercise FDA suggested
Asked at the town hall how to prepare, officials pointed at one specific rehearsal. It is the most useful paragraph in this guide, so it is worth doing rather than reading.
Start with a single identified patient risk. Follow its controls forward through every process they touch: into design inputs, through process validation and production controls, out into complaint handling and postmarket feedback, and back into risk management. Then be ready to show that the risk-based decisions along the way were justified, documented and acted on.
A team that can walk one patient risk end to end is demonstrating the connected, risk-driven system the program was built to evaluate. Our reading, not a quotation
Try it on your own system and one of two things happens. Either the walk completes, and you have your inspection rehearsal. Or it stalls, and where it stalls is diagnostic. In our experience the stall is almost never a missing document. It is a missing link between two documents that live in different systems, maintained by hand, and last reconciled at some point nobody can name.
Where we can help
Modern Requirements is a comprehensive requirements management platform, and the backbone of requirements work inside Azure DevOps, where your engineering team already works. When requirements, risk controls, tests and results are work items in the same project, the trace is a by-product of doing the work rather than something reassembled before an inspection.
Author requirements in Azure DevOps and walk the trace in either direction. Coverage views surface the risk control with no requirement and the requirement with no test. Review and approval carry electronic sign-off, and every baseline is versioned and audited, so you can show what the design looked like at any freeze point and what changed since.
Ambiguity, missing acceptance criteria and untestable phrasing flagged as the requirement is written, because an input written in a form no test can satisfy is the upstream cause of a lot of design control findings. Every suggestion is accepted, edited or rejected by a person.
Gaps surface the day they appear, not the week before an inspection. Every finding arrives with its reasoning attached, and a person accepts or rejects it before anything touches a controlled record.
Your evidence, mapped to the clauses it answers. Observations arrive in clause language now. Your proof should speak the same language.
See the chain hold together.
See requirements, risk controls, tests and results working as one traceable chain, with the evidence ready whenever an investigator asks for it.
Scheduling Pick a time that suits your team
Cost Free
Schedule a demo
We reply within one business day with times.
We use your details to arrange the demo and nothing else. Unsubscribe any time.
















