QMSR vs ISO 13485 for Medical Device Manufacturers

The Quality Management System Regulation (QMSR) and ISO 13485:2016 are now directly connected, but they are not interchangeable. Effective February 2, 2026, the QMSR amended 21 CFR Part 820 and incorporated ISO 13485:2016 by reference. Applicable ISO 13485 requirements therefore have the force and effect of U.S. federal law for medical device manufacturers subject to Part 820.

This harmonization removed many differences between the former Quality System Regulation and ISO 13485. It did not replace FDA regulation with voluntary ISO certification. Medical device manufacturers supplying the U.S. market must comply with:

  • Applicable ISO 13485:2016 requirements incorporated into Part 820
  • FDA-specific requirements in 21 CFR Part 820
  • Applicable provisions of the Federal Food, Drug, and Cosmetic Act
  • Other applicable FDA regulations governing medical devices

ISO 13485 certification may support a manufacturer’s quality system, but it does not establish QMSR compliance, prevent an FDA inspection, or limit FDA enforcement authority.

Relationship between QMSR, ISO 13485, and FDA-specific medical device requirements
QMSR incorporates ISO 13485:2016 as its quality-system framework while FDA definitions, supplemental requirements, inspections, and enforcement remain controlling.

QMSR and ISO 13485 at a Glance

Comparison areaQMSRISO 13485:2016
Type of requirementU.S. federal regulationInternational quality-management-system standard
Legal status in the United StatesMandatory for manufacturers subject to 21 CFR Part 820Applicable requirements are legally enforceable because they are incorporated into Part 820
Governing authorityU.S. Food and Drug AdministrationInternational Organization for Standardization
Primary purposeEstablishes U.S. medical-device CGMP requirementsProvides a medical-device quality-management-system framework for regulatory purposes
Applicable editionISO 13485:2016 incorporated by referenceCurrent published edition of the standard
Certification requiredNoCertification is optional under the standard, although particular markets or customers may require it
Compliance assessmentFDA inspection and regulatory reviewInternal, customer, certification-body, or regulatory audit
Result of successful assessmentNo FDA certificate is issuedA third-party certification body may issue an ISO 13485 certificate
Governing terminologyFDA and FD&C Act definitions control where specifiedISO 13485 and incorporated ISO 9000 terminology
Supplemental requirementsIncludes FDA-specific provisions for records, complaints, servicing, UDI, labeling, packaging, reporting, and enforcementDoes not independently contain all U.S.-specific statutory and regulatory requirements
EnforcementFDA regulatory and judicial actionCertification findings may affect certification status but are not FDA enforcement actions
Geographic applicationDevices manufactured, imported, or offered for import into the United StatesUsed internationally and may support multiple regulatory jurisdictions

The central distinction is straightforward:

ISO 13485 supplies the principal quality-system framework used by the QMSR, while FDA law determines how that framework applies to medical devices regulated in the United States.


How ISO 13485 Became Part of the QMSR

The QMSR incorporates ISO 13485:2016 by reference under 21 CFR 820.7. Incorporation by reference gives the incorporated material the same legal effect as if its applicable requirements were printed directly in the Code of Federal Regulations.

Section 820.10 requires a manufacturer subject to Part 820 to document a quality management system that complies with:

  1. Applicable requirements of ISO 13485:2016
  2. Other applicable requirements of Part 820
  3. Other applicable FDA regulatory requirements

The QMSR also incorporates Clause 3 of ISO 9000:2015 for quality-management terminology, subject to the definition hierarchy established in § 820.3.

This approach substantially reduces duplication between Part 820 and ISO 13485. The current Part 820 is consequently much shorter than the former Quality System Regulation. Requirements formerly written directly into numerous QSR sections are now addressed primarily through incorporated ISO 13485 clauses.

Reserved sections in Part 820 do not indicate that the underlying quality-system requirements were eliminated. In most cases, the operative requirements are now found in ISO 13485.

A Future ISO Revision Does Not Automatically Change the QMSR

Part 820 incorporates a specific edition: ISO 13485:2016.

If ISO publishes a revised edition, that new edition will not automatically replace the 2016 edition incorporated into U.S. law. FDA must evaluate the revision and determine whether Part 820 should be amended through the federal rulemaking process.

A manufacturer may choose to adopt a newer ISO edition for certification or international purposes, but it must still demonstrate compliance with the edition legally incorporated into Part 820 until FDA formally changes the regulation.

Referenced Standards Are Not Automatically Incorporated

ISO 13485 refers to or discusses other standards, including standards related to medical-device risk management. Those references do not automatically make every cited standard part of the QMSR.

For example, ISO 14971 provides an FDA-recognized medical-device risk-management framework, but the QMSR final rule incorporated only:

  • ISO 13485:2016
  • Clause 3 of ISO 9000:2015

Other standards remain voluntary consensus standards unless another law or regulation makes them mandatory. They may nevertheless provide an accepted method of demonstrating conformity with applicable regulatory requirements.


What ISO 13485 Provides

ISO 13485 provides the primary organizational structure for a medical-device quality management system.

Its requirements address:

  • Quality-management-system processes
  • Management responsibility
  • Resource management
  • Product realization
  • Design and development
  • Purchasing and outsourced processes
  • Production and service provision
  • Process validation
  • Sterilization and sterile-barrier controls
  • Monitoring and measuring equipment
  • Complaint handling
  • Regulatory reporting
  • Internal audits
  • Control of nonconforming product
  • Data analysis
  • Corrective and preventive action
  • Risk-based decision-making
  • Document and record control

ISO 13485 is designed for organizations involved in one or more stages of the medical-device lifecycle, including design, manufacturing, storage, distribution, installation, servicing, and related activities.

An organization may implement ISO 13485 without obtaining certification. ISO does not conduct certification or issue certificates. Independent certification bodies perform certification audits and issue certificates when the organization demonstrates conformity within the defined certification scope.

Under the QMSR, however, applicable ISO 13485 requirements are not voluntary for manufacturers subject to Part 820. They form part of the legally enforceable U.S. CGMP framework.


What the QMSR Adds to ISO 13485

The QMSR does more than direct manufacturers to follow ISO 13485. It establishes FDA-specific scope, definitions, supplemental provisions, regulatory connections, and enforcement consequences.

The principal FDA-specific provisions are found in:

QMSR sectionFDA-specific function
§ 820.1Defines applicability, scope, conflicts, foreign-manufacturer obligations, and exemptions or variances
§ 820.3Establishes FDA definitions and the hierarchy between FDA and ISO terminology
§ 820.7Incorporates ISO 13485:2016 and ISO 9000:2015 Clause 3 by reference
§ 820.10Requires the QMS, connects ISO clauses to other FDA regulations, defines design-control applicability, and establishes enforcement consequences
§ 820.35Adds complaint, servicing, UDI, and confidentiality record requirements
§ 820.45Adds detailed device-labeling and packaging controls

These provisions must be applied together with the incorporated ISO clauses.


Scope and Applicability

ISO 13485 may be used by a broad range of organizations throughout the medical-device supply chain. The QMSR applies according to the statutory and regulatory scope established by FDA.

Under § 820.1, Part 820 governs the methods, facilities, and controls used for the:

  • Design
  • Manufacture
  • Packaging
  • Labeling
  • Storage
  • Installation
  • Servicing

of finished devices intended for human use.

Manufacturers subject to the QMSR include organizations performing functions such as:

  • Finished-device manufacturing
  • Specification development
  • Contract manufacturing
  • Contract sterilization
  • Installation
  • Relabeling
  • Repacking
  • Remanufacturing
  • Initial distribution of devices manufactured by foreign establishments performing covered functions

A manufacturer performing only certain covered operations must comply with the requirements applicable to those operations.

Manufacturers of components or parts that are not finished devices are generally outside the direct scope of Part 820, although FDA encourages them to consider applicable quality-system provisions. A component supplier may still maintain ISO 13485 certification because of customer, contractual, or international-market requirements.

Foreign manufacturers offering devices for import into the United States are subject to the QMSR. Devices may be refused admission if they appear to be adulterated or otherwise violate the FD&C Act and applicable FDA regulations.


FDA Definitions Control

ISO 13485 and ISO 9000 provide much of the terminology used in the QMSR, but FDA terminology remains controlling where § 820.3, the FD&C Act, or another FDA regulation provides a different definition.

Section 820.3 establishes the following hierarchy:

  1. Definitions in the FD&C Act apply and supersede correlating ISO definitions.
  2. Definitions specified in § 820.3 supersede correlating definitions in ISO 13485 or ISO 9000.
  3. ISO 13485 and ISO 9000 definitions apply where FDA has not established a controlling definition.

Examples include:

  • The FD&C Act definition of device controls over the ISO definition of medical device.
  • The FD&C Act definition of labeling controls over the correlating ISO terminology.
  • Manufacturer includes specification developers, contract sterilizers, installers, relabelers, remanufacturers, repackers, and certain initial distributors.
  • Organization is interpreted as manufacturer for purposes of Part 820.
  • Finished device includes a device or accessory suitable for use or capable of functioning, whether or not it is packaged, labeled, or sterilized.
  • Safety and performance in ISO 13485 does not replace FDA’s statutory standard of reasonable assurance of safety and effectiveness.

A manufacturer should not mechanically substitute ISO terminology for FDA terminology in procedures, regulatory assessments, or inspection responses where the FDA definition affects the legal meaning.


FDA Requirements Outside ISO 13485

ISO 13485 repeatedly refers to “applicable regulatory requirements.” For a manufacturer supplying the U.S. market, this includes requirements outside Part 820.

Section 820.10 expressly connects particular ISO clauses to FDA regulations governing:

FDA requirementRegulatory locationQMS connection
Unique Device Identification21 CFR Part 830Device identification and production records
Medical-device tracking21 CFR Part 821Traceability where tracking requirements apply
Medical Device Reporting21 CFR Part 803Complaint evaluation and reporting to FDA
Corrections and removals21 CFR Part 806Advisory notices, corrections, removals, and reporting

Other potentially applicable FDA requirements include:

  • Establishment registration and device listing under Part 807
  • Premarket notification requirements under Part 807
  • Premarket approval requirements under Part 814
  • Investigational device requirements under Part 812
  • Medical-device labeling requirements under Part 801
  • Electronic records and electronic signatures under Part 11
  • Electronic-product radiation-control requirements
  • Device-specific special controls and classification regulations
  • Postmarket surveillance requirements
  • Import and export requirements

Compliance with ISO 13485 alone does not demonstrate compliance with these requirements.

The QMS must contain a method for identifying, implementing, and maintaining all regulatory requirements applicable to the manufacturer’s devices, activities, and markets.


Design and Development Applicability

ISO 13485 contains design and development requirements in Clause 7.3. The QMSR defines which U.S. device manufacturers must apply those requirements.

Under § 820.10(c), the ISO 13485 design and development requirements apply to manufacturers of:

  • All Class II devices
  • All Class III devices
  • Class I devices automated with computer software
  • The additional Class I devices specifically listed in § 820.10(c)

This FDA-specific applicability provision remains important. A manufacturer should not determine U.S. design-control applicability solely from the wording or certification scope of ISO 13485.

Devices manufactured under an Investigational Device Exemption are not automatically exempt from applicable design and development requirements.

For a detailed treatment of design verification, design validation, process validation, software assurance, sterilization, packaging, and lifecycle controls, see Medical Device Validation Requirements Under QMSR.


FDA-Specific Record Requirements

ISO 13485 establishes general record-control requirements. Section 820.35 adds information that manufacturers must include in particular records.

Complaint Records

Complaint records must document the review, evaluation, and investigation of complaints involving possible failure of a device, labeling, or packaging to meet specifications.

For complaints subject to reporting, requiring investigation, or actually investigated, the records must include specified information such as:

  • Device name
  • Date the complaint was received
  • UDI, UPC, or other device identification
  • Complainant information
  • Nature and details of the complaint
  • Corrections or corrective actions taken
  • Reply to the complainant

When a complaint is not investigated because a similar complaint has already been investigated, the manufacturer must document the justification.

Servicing Records

Servicing records must include, at minimum:

  • Device identification
  • UDI, UPC, or other applicable identifier
  • Date of service
  • Individuals performing the service
  • Service performed
  • Test and inspection data

UDI Records

The UDI must be recorded for each medical device or batch of medical devices as required by applicable QMSR and UDI provisions.

These requirements supplement ISO 13485. An ISO-based procedure that does not capture the information required by § 820.35 is not fully compliant with the QMSR.


FDA Labeling and Packaging Provisions

ISO 13485 addresses production, packaging, labeling, product preservation, and controlled operations. FDA determined that additional provisions were necessary because labeling and packaging errors remain significant causes of medical-device recalls.

Section 820.45 requires documented procedures covering labeling and packaging:

  • Integrity
  • Inspection
  • Storage
  • Processing
  • Handling
  • Distribution
  • Use, where appropriate

Before release or storage, as applicable, manufacturers must examine labeling and packaging for accuracy, including:

  • Correct UDI, UPC, or other device identification
  • Expiration date
  • Storage instructions
  • Handling instructions
  • Additional processing instructions

Manufacturers must document labeling release and establish controls that prevent labeling and packaging mix-ups. Inspection results must be recorded.

These requirements supplement ISO 13485 Clause 7.5.1. An ISO 13485 certificate does not demonstrate that the manufacturer has correctly implemented the specific controls required by § 820.45.


ISO 13485 Certification Is Not QMSR Compliance

A manufacturer may maintain a well-designed ISO 13485-certified quality system and still violate the QMSR.

Possible causes include:

  • Failure to apply FDA definitions
  • Inadequate U.S. regulatory-reporting procedures
  • Missing UDI or device-tracking controls
  • Incomplete complaint or servicing records
  • Inadequate labeling and packaging controls
  • Failure to meet FDA design-control applicability requirements
  • Noncompliance with device-specific special controls
  • Failure to meet registration, listing, premarket, or postmarket requirements
  • Procedures written for non-U.S. regulatory terminology without an adequate U.S. regulatory supplement

The opposite distinction also applies: an FDA inspection does not result in ISO 13485 certification.

QuestionAnswer
Does ISO 13485 certification prove QMSR compliance?No
Does the QMSR require an ISO 13485 certificate?No
Will FDA accept an ISO certificate instead of evaluating compliance?No
Does a successful FDA inspection produce an ISO certificate?No
Can an ISO 13485-certified manufacturer still receive an FDA Form 483 or Warning Letter?Yes
Can one integrated QMS support both QMSR compliance and ISO certification?Yes
Must the integrated QMS include FDA-specific requirements?Yes

Certification can provide useful independent evidence that the quality system conforms to the certification scope. It does not transfer regulatory responsibility from the manufacturer to the certification body.


Certification Audits vs FDA Inspections

An ISO 13485 certification audit and an FDA inspection differ in authority, purpose, scope, methodology, and consequences.

AreaISO 13485 certification auditFDA QMSR inspection
Conducted byIndependent certification bodyFDA investigators
Primary objectiveDetermine conformity with ISO 13485 within the certification scopeDetermine compliance with the QMSR, FD&C Act, and applicable FDA regulations
Legal authorityCertification agreementFederal statutory inspection authority
ResultCertification, continuation, suspension, withdrawal, or audit findingsInspection classification and possible regulatory action
Certificate issuedYes, when certification requirements are metNo
FDA-specific regulationsOnly when included within the audit criteriaEvaluated as applicable
Enforcement authorityNone under the FD&C ActFDA retains statutory and regulatory enforcement authority
Records reviewedBased on audit scope and certification rulesRecords FDA considers relevant to QMSR compliance
Device focusMay be based on certification scopeMay focus on device and patient risks, violations, complaints, recalls, or regulatory history

On February 2, 2026, FDA discontinued the Quality System Inspection Technique and implemented the risk-based inspection process described in Compliance Program 7382.850.

The current inspection model evaluates interconnected quality-system areas such as:

  • Management oversight
  • Design and development
  • Change control
  • Outsourcing and purchasing
  • Production and service provision
  • Measurement, analysis, and improvement

FDA may also evaluate other applicable requirements, including:

  • Medical Device Reporting
  • Corrections and removals
  • Device tracking
  • Unique Device Identification
  • Registration and listing
  • Marketing authorization
  • Previous inspection and compliance issues

FDA investigators may expand the inspection when findings indicate additional risk or when the minimum inspection coverage is insufficient to assess compliance.


Access to Management Review and Audit Records

Under the former Quality System Regulation, certain management-review, quality-audit, and supplier-audit reports were generally exempt from routine FDA review under former § 820.180(c).

That exemption was not retained in the QMSR.

During inspections conducted under the current QMSR, FDA investigators may review:

  • Management-review records
  • Internal quality-audit reports
  • Supplier-audit reports
  • Supporting records and corrective actions
  • Records created before February 2, 2026, when relevant to current compliance

Manufacturers should ensure these records are complete, objective, internally consistent, and supported by evidence.

Audit procedures and management-review procedures should no longer state that FDA is categorically prohibited from reviewing these records.

See FDA Inspection Readiness for inspection preparation, documentation, and response considerations.


ISO Audits, MDSAP, and FDA Inspections

A conventional ISO 13485 certification audit does not exempt a manufacturer from FDA inspection.

MDSAP must be treated separately. Under the Medical Device Single Audit Program, an audit is performed by an MDSAP-recognized Auditing Organization against ISO 13485 and applicable requirements of participating regulatory authorities.

FDA may use qualifying MDSAP audit reports as a substitute for certain agency surveillance inspections. This does not eliminate FDA’s authority to conduct:

  • For-cause inspections
  • Compliance follow-up inspections
  • Specific product-risk assignments
  • PMA preapproval inspections
  • PMA postmarket inspections
  • Other inspections or investigations considered necessary

MDSAP participation therefore may affect FDA’s surveillance approach, but it does not eliminate QMSR obligations or FDA enforcement authority.


Enforcement Remains an FDA Function

The principal practical difference between ISO certification and the QMSR is enforcement.

Under § 820.10(e), failure to comply with an applicable Part 820 requirement renders a device adulterated under section 501(h) of the FD&C Act. The device and persons responsible for the failure may be subject to regulatory action.

Depending on the nature, significance, and persistence of the violations, FDA action may include:

  • Form FDA 483 inspection observations
  • Warning Letters
  • Import detention or refusal of admission
  • Seizure
  • Injunction
  • Civil money penalties
  • Criminal prosecution
  • Compliance follow-up inspections
  • Delays or restrictions affecting premarket submissions
  • Action involving devices already in distribution

An ISO certification body may issue a nonconformity, suspend a certificate, or withdraw certification. It cannot determine whether a device is adulterated under the FD&C Act or initiate FDA enforcement action.

An ISO 13485 certificate is therefore not a regulatory shield.


Building One Integrated Quality System

Manufacturers do not need separate quality systems for ISO 13485 and the QMSR. A single integrated system is generally more effective, provided that it incorporates all applicable U.S. requirements.

A practical structure includes:

ISO 13485 Core

Use the ISO 13485 process structure for:

  • Quality-system governance
  • Management responsibility
  • Resource management
  • Product realization
  • Design and development
  • Purchasing
  • Production and service provision
  • Monitoring and measurement
  • Complaint handling
  • Internal audits
  • CAPA
  • Document and record control

FDA Regulatory Overlay

Add documented controls for:

  • QMSR scope and FDA definitions
  • Device classification
  • Design-control applicability
  • Registration and listing
  • Premarket authorization
  • UDI
  • Device tracking
  • Medical Device Reporting
  • Corrections and removals
  • FDA complaint-record requirements
  • FDA servicing-record requirements
  • Labeling and packaging controls
  • Device-specific special controls
  • Electronic records and signatures
  • FDA inspections and regulatory communications

Regulatory Traceability

Maintain a regulatory matrix mapping:

  • Applicable ISO 13485 clauses
  • Applicable Part 820 requirements
  • Other applicable FDA regulations
  • Internal procedures
  • Responsible functions
  • Required records
  • Relevant products and sites

This structure makes the relationship between ISO conformity and FDA compliance visible and reduces the likelihood that a requirement will be overlooked because it appears outside the main QMS procedure set.


Transitioning Former QSR Documentation

Manufacturers should remove the assumption that former QSR section numbers remain the current regulatory basis.

Documents requiring review may include:

  • Quality manuals
  • Standard operating procedures
  • Work instructions
  • Validation plans and protocols
  • Design and development procedures
  • Complaint and CAPA procedures
  • Supplier-control procedures
  • Audit checklists
  • Management-review procedures
  • Training materials
  • Regulatory matrices
  • Electronic workflow configurations
  • Templates and forms

Former citations such as §§ 820.30, 820.70, 820.75, 820.120, and 820.130 should not continue to be presented as current Part 820 sections.

The underlying requirements may remain applicable through ISO 13485 or current FDA supplemental provisions. Citations should therefore be replaced based on the actual regulatory basis rather than deleted without assessment.

For example:

Former citationCurrent regulatory basis
Former § 820.30 — Design controls§ 820.10(c) and ISO 13485 Clause 7.3
Former § 820.70 — Production and process controlsISO 13485 production and service provisions
Former § 820.75 — Process validationISO 13485 Clause 7.5.6 and, where applicable, Clause 7.5.7
Former § 820.120 — Device labeling control§ 820.45 and applicable ISO 13485 provisions
Former § 820.130 — Device packaging§ 820.45 and applicable ISO 13485 provisions
Former § 820.180 — General records§ 820.35 and ISO 13485 record-control requirements
Former § 820.198 — Complaint files§ 820.35, ISO 13485 Clause 8.2.2, and Part 803

The transition should preserve traceability to the current requirements and demonstrate that the manufacturer evaluated—not merely renamed—its existing controls.


Common Misunderstandings

“QMSR and ISO 13485 are now identical.”

Incorrect. ISO 13485 supplies the principal framework, but the QMSR includes FDA-specific scope, terminology, records, labeling, packaging, reporting, design-applicability, and enforcement provisions.

“An ISO 13485 certificate proves FDA compliance.”

Incorrect. FDA expressly states that ISO certification alone does not demonstrate QMSR compliance.

“FDA adopted every standard referenced by ISO 13485.”

Incorrect. Only ISO 13485:2016 and Clause 3 of ISO 9000:2015 were incorporated through the QMSR final rule.

“Future ISO 13485 revisions automatically become FDA requirements.”

Incorrect. FDA must evaluate a revision and amend the QMSR through rulemaking before a different edition becomes incorporated into Part 820.

“FDA will certify manufacturers to ISO 13485.”

Incorrect. FDA inspections do not produce ISO certificates.

“The shorter Part 820 eliminated the former requirements.”

Incorrect. Most requirements were relocated to the incorporated ISO 13485 framework rather than eliminated.

“ISO terminology can always replace FDA terminology.”

Incorrect. FD&C Act and FDA definitions supersede correlating ISO definitions where specified.

“FDA cannot review internal-audit or management-review records.”

Incorrect under the QMSR. The former record-review exemption was not retained.

“MDSAP participation prevents FDA inspections.”

Incorrect. FDA may use qualifying MDSAP reports instead of certain surveillance inspections but retains authority to conduct other inspections.


Summary

The QMSR harmonizes the U.S. medical-device quality-system framework with ISO 13485, but it does not surrender FDA authority or convert U.S. compliance into a certification exercise.

For manufacturers supplying the United States:

  • Applicable ISO 13485:2016 requirements are legally enforceable through Part 820.
  • The FD&C Act and FDA regulations remain controlling.
  • FDA definitions supersede conflicting ISO terminology.
  • Sections 820.35 and 820.45 establish supplemental records, labeling, and packaging requirements.
  • Other FDA requirements for reporting, UDI, tracking, registration, listing, premarket authorization, and postmarket controls remain applicable.
  • ISO 13485 certification is not required by the QMSR and does not establish FDA compliance.
  • FDA may inspect records beyond those typically reviewed during a certification audit.
  • Failure to comply may render a device adulterated and expose the manufacturer and responsible persons to regulatory action.

The correct compliance model is therefore:

ISO 13485:2016 requirements incorporated into Part 820, plus FDA-specific QMSR provisions, plus all other applicable U.S. statutory and regulatory requirements.


Regulatory References