The short answer. Since February 2, 2026, FDA’s Quality Management System Regulation (QMSR, 21 CFR Part 820) replaces the old Quality System Regulation. It incorporates ISO 13485:2016 by reference, keeps a few FDA-specific requirements, opens management review and audit records to inspection, and comes with a new inspection program that replaced QSIT. An ISO 13485 certificate does not exempt a manufacturer from FDA inspection.

What changed

TopicOld QSRQMSR since February 2, 2026
BasisFDA’s own text, 21 CFR 820.1 to 820.250ISO 13485:2016 incorporated by reference, plus Clause 3 of ISO 9000:2015 for definitions
RecordsDevice master record, design history file, device history recordNo separate record types; content moves to the Medical Device File (ISO 13485 clause 4.2.3) and the design and development file (7.3.10)
Risk managementExplicit only in design validation, 820.30(g)Risk management throughout the requirements; ISO 14971 itself is not incorporated
Management review, internal and supplier auditsExcluded from routine FDA inspection, 820.180(c)FDA can inspect management review, quality audit and supplier audit reports
TermsManagement with executive responsibilityTop management, as defined in ISO 9000
Approval signaturesSignature for each individual who approved a recordRequirement removed
InspectionsQSIT, compliance program 7382.845Compliance Program 7382.850, issued February 2, 2026
Sources: final rule 89 FR 7496 (February 2, 2024); FDA QMSR page and FAQ.

Requirements FDA kept on top of ISO 13485

How FDA now inspects

Compliance Program 7382.850 organizes the QMSR into six QMS areas: change control; design and development; management oversight; measurement, analysis and improvement; production and service provision; outsourcing and purchasing. Four other FDA requirements are checked alongside: reporting, corrections and removals, tracking and UDI. Investigators review risk management documentation throughout the inspection. Baseline inspections must cover management review and internal audits. Sites actively enrolled in MDSAP do not get routine surveillance inspections.

The program also tells investigators to consider cyber devices, as defined in section 524B(c) of the FD&C Act, for review. See FDA cybersecurity requirements for medical devices.

Related FDA actions

What this means during development

Sources

What OVA does here, and where our responsibility ends

OVA Solutions is a medical device engineering group working under an ISO 13485:2016 certified quality system: 62 engineers, 220 devices developed, $125 per hour, offices in New York, Florida, the United Kingdom, Estonia and Ukraine. We design electronics, firmware and mechanics and take a device from concept to design for manufacturing. We are not a regulatory consultancy and not a contract manufacturer: the regulatory strategy and the submission stay with you or your regulatory consultant.

More from OVA: what medical device development costs, how to choose a development firm, answers from Lisa Voronkova, our quality system.

Updated on October 8, 2026.