Aller au contenu

Add Your Heading Text Here

Free field guide · PDF

How FDA inspects medical device manufacturers now.

On February 2, 2026, Part 820 became the QMSR and the inspection technique FDA had used for decades was withdrawn the same day. The requirements barely moved. The way they get evaluated moved a long way.

Thirteen sections written to be used during a readiness review, not skimmed once — including the reference tables you will actually go back to.

Sections

13

Reference tables

7

Reviewed

July 2026

Cost

Gratuit

Get the field guide

We'll email you the PDF so it's in your inbox, not just your downloads folder.

We use your details to send the guide and occasional MedTech updates. Unsubscribe any time.

No sales call attached·Sources cited throughout

Check your inbox

The QMSR Field Guide is on its way to the address you gave us. If it has not arrived in a few minutes, look in spam or quarantine before you assume it did not send.

See how this works inside Azure DevOps →

What's in it

Thirteen sections, and what each one covers.

This is a reference guide, not an overview. It assumes you know what QMSR is and goes straight to how an inspection under Compliance Program 7382.850 actually runs.

01

What changed, in one page

The seven shifts that matter: the regulation, the inspection program, the navigation, sampling basis, finding language, records access, and what genuinely did not move.

02

What Part 820 looks like now

Subpart A and Subpart B section by section, the four ISO terms FDA definitions supersede, who design controls actually apply to, and the seven fields 820.35(a) requires on a complaint record.

03

The map investigators work from

The inspection structure diagrammed, plus the table showing where each of the four OAFRs attaches to a specific ISO 13485 clause under 820.10(b).

04

The six QMS areas

Every area broken into the elements it covers, drawn from Attachment A of the compliance program.

05

Risk beyond the obvious

Why clause 4.1.2(b) does not mean a standalone risk assessment for every administrative process, with the worked example FDA gave at the town hall.

06

Two coverage models

Model 1 and Model 2 compared, with the minimum coverage each sets and which inspection types trigger which. Knowing yours tells you how deep to prepare.

07

How an inspection unfolds

The seven-step order of operations from Form 482 through to Form 483, and the step that now drives everything after it.

08

What FDA is citing so far

The top five cited areas ranked, what auditors report finding underneath each, and how the ordering differed across three separate CDRH appearances this spring.

09

Terminology that changed

DHF, DMR and DHR — where the content lives now and under which clause. Plus what FDA has said about not retrofitting historical records.

10

Outcomes and timelines

NAI, VAI and OAI explained, the two findings the program names as pointing toward an initial OAI, and the practical response window after a Form 483.

11

Five things teams get wrong

The assumptions that show up most often in readiness conversations, each with what is actually true — starting with certification.

12

The exercise FDA suggests

The single-patient-risk walk officials pointed at as a rehearsal. Probably the most useful page in the guide, and the shortest.

13

Where we can help

How the traceability chain holds together inside Azure DevOps, and where each Modern Requirements product fits. One section, clearly marked.

Reference material

The tables and diagrams you'll come back to.

The prose is worth reading once. These are the parts teams tell us they keep open during a gap analysis.

Patients RISK MGMT Change control Design & dev Production Measurement Purchasing Management

Section 03 · Diagram

The inspection structure

Patients at the centre, ringed by risk management, ringed by the six QMS areas, with the OAFRs outside. The shape of a 7382.850 inspection on one page.

Section 03 · Table

Where each OAFR attaches

UDI, device tracking, MDR and corrections and removals, each mapped to the exact ISO 13485 clause it sits on per 820.10(b). The most practical paragraph in Part 820 for anyone rewriting procedures.

Section 09 · Crosswalk

DHF, DMR, DHR — where they went

Each retired term matched to where its content lives now and under which clause, so you can update procedure references without guessing.

Section 06 · Comparison

Model 1 against Model 2

Minimum coverage for each, side by side, with the inspection types that trigger them. Baseline surveillance and PMA pre-approval get the deep model — worth knowing before you plan your prep.

Section 02 · Checklist

The seven fields on a complaint record

820.35(a) names them explicitly, which makes this one checkable against your own records this afternoon rather than during an inspection.

Section 04 · Table

Six areas, every element

What sits inside change control, design and development, management oversight, measurement, outsourcing and purchasing, and production and service provision.

Section 10 · Reference

Classification and the response clock

NAI, VAI and OAI, plus the two findings the compliance program names as pointing toward an initial OAI. Both are risk failures, not documentation failures.

A sample · from section 08

What you're actually getting, rather than a description of it.

This is one table from one section, reproduced as it appears in the guide. The other twelve sections are built the same way — sourced, dated, and honest about where the evidence is still thin.

Top cited areas · Feb–mid-Apr 2026 Section 08
01
Risk managementThe file looks complete but cannot show the connective work: how complaints, nonconformances, service data, field failures and supplier issues feed back into the analysis.
02
Outsourcing and purchasingRarely an empty supplier file. Usually a generic one, with a low-risk packaging vendor and a critical contract sterilizer on the same template.
03
Complaint handling and feedbackFails at the handoffs rather than in the procedure. The signal arrives but does not travel upstream.
04
UDIOne of the four OAFRs, verified separately from anything your certification covers.
05
Corrective actionExistence of a procedure is not the question. Evidence the action worked is.
Per Keisha Thomas, CDRH Office of Product Evaluation and Quality, at the Food and Drug Law Institute annual conference, May 2026. Just over 100 inspections completed at that point.
Risk, risk, risk, risk. That is the fundamental change to QMSR. Keisha Thomas, associate director, CDRH Office of Product Evaluation and Quality, 2026, as reported by The FDA Group

The guide then does something most vendor content will not: it shows where this data disagrees with itself. Risk management came first at all three spring events, but below that the ordering moves — MedCon put outsourcing and purchasing second, while the RAPS Quality Conference list ran risk management, corrective action, risk-based approach, complaint handling and purchasing.

We flagged the inconsistency rather than picking the version that reads best, because a quality director presenting this internally needs to know which parts are firm.

Who it's for

Written for the people who sit in the room with the investigator.

It assumes US market exposure and a Class II or Class III portfolio, and it goes past what QMSR is into how an inspection under it actually runs.

Section 13 covers where Modern Requirements fits, and it is clearly marked so you can skip it. The other twelve sections stand on their own regardless of what you use for requirements today.

  • VP / Head of Quality
  • Director of Regulatory Affairs
  • QA Managers & Quality Engineers
  • Design Assurance leads
  • Engineering leaders owning design control content

Get the field guide.

Thirteen sections, seven reference tables, in your inbox in a minute. No sales call attached.

Send me the guide
Modern Requirements logo mark