QMSR vs ISO 13485 for Medical Device Manufacturers
The Quality Management System Regulation (QMSR) and ISO 13485:2016 are now directly connected, but they are not interchangeable. Effective February 2, 2026, the QMSR amended 21 CFR Part 820 and incorporated ISO 13485:2016 by reference. Applicable ISO 13485 requirements therefore have the force and effect of U.S. federal law for medical device manufacturers subject to Part 820.
This harmonization removed many differences between the former Quality System Regulation and ISO 13485. It did not replace FDA regulation with voluntary ISO certification. Medical device manufacturers supplying the U.S. market must comply with:
- Applicable ISO 13485:2016 requirements incorporated into Part 820
- FDA-specific requirements in 21 CFR Part 820
- Applicable provisions of the Federal Food, Drug, and Cosmetic Act
- Other applicable FDA regulations governing medical devices
ISO 13485 certification may support a manufacturer’s quality system, but it does not establish QMSR compliance, prevent an FDA inspection, or limit FDA enforcement authority.

QMSR and ISO 13485 at a Glance
| Comparison area | QMSR | ISO 13485:2016 |
|---|---|---|
| Type of requirement | U.S. federal regulation | International quality-management-system standard |
| Legal status in the United States | Mandatory for manufacturers subject to 21 CFR Part 820 | Applicable requirements are legally enforceable because they are incorporated into Part 820 |
| Governing authority | U.S. Food and Drug Administration | International Organization for Standardization |
| Primary purpose | Establishes U.S. medical-device CGMP requirements | Provides a medical-device quality-management-system framework for regulatory purposes |
| Applicable edition | ISO 13485:2016 incorporated by reference | Current published edition of the standard |
| Certification required | No | Certification is optional under the standard, although particular markets or customers may require it |
| Compliance assessment | FDA inspection and regulatory review | Internal, customer, certification-body, or regulatory audit |
| Result of successful assessment | No FDA certificate is issued | A third-party certification body may issue an ISO 13485 certificate |
| Governing terminology | FDA and FD&C Act definitions control where specified | ISO 13485 and incorporated ISO 9000 terminology |
| Supplemental requirements | Includes FDA-specific provisions for records, complaints, servicing, UDI, labeling, packaging, reporting, and enforcement | Does not independently contain all U.S.-specific statutory and regulatory requirements |
| Enforcement | FDA regulatory and judicial action | Certification findings may affect certification status but are not FDA enforcement actions |
| Geographic application | Devices manufactured, imported, or offered for import into the United States | Used internationally and may support multiple regulatory jurisdictions |
The central distinction is straightforward:
ISO 13485 supplies the principal quality-system framework used by the QMSR, while FDA law determines how that framework applies to medical devices regulated in the United States.
How ISO 13485 Became Part of the QMSR
The QMSR incorporates ISO 13485:2016 by reference under 21 CFR 820.7. Incorporation by reference gives the incorporated material the same legal effect as if its applicable requirements were printed directly in the Code of Federal Regulations.
Section 820.10 requires a manufacturer subject to Part 820 to document a quality management system that complies with:
- Applicable requirements of ISO 13485:2016
- Other applicable requirements of Part 820
- Other applicable FDA regulatory requirements
The QMSR also incorporates Clause 3 of ISO 9000:2015 for quality-management terminology, subject to the definition hierarchy established in § 820.3.
This approach substantially reduces duplication between Part 820 and ISO 13485. The current Part 820 is consequently much shorter than the former Quality System Regulation. Requirements formerly written directly into numerous QSR sections are now addressed primarily through incorporated ISO 13485 clauses.
Reserved sections in Part 820 do not indicate that the underlying quality-system requirements were eliminated. In most cases, the operative requirements are now found in ISO 13485.
A Future ISO Revision Does Not Automatically Change the QMSR
Part 820 incorporates a specific edition: ISO 13485:2016.
If ISO publishes a revised edition, that new edition will not automatically replace the 2016 edition incorporated into U.S. law. FDA must evaluate the revision and determine whether Part 820 should be amended through the federal rulemaking process.
A manufacturer may choose to adopt a newer ISO edition for certification or international purposes, but it must still demonstrate compliance with the edition legally incorporated into Part 820 until FDA formally changes the regulation.
Referenced Standards Are Not Automatically Incorporated
ISO 13485 refers to or discusses other standards, including standards related to medical-device risk management. Those references do not automatically make every cited standard part of the QMSR.
For example, ISO 14971 provides an FDA-recognized medical-device risk-management framework, but the QMSR final rule incorporated only:
- ISO 13485:2016
- Clause 3 of ISO 9000:2015
Other standards remain voluntary consensus standards unless another law or regulation makes them mandatory. They may nevertheless provide an accepted method of demonstrating conformity with applicable regulatory requirements.
What ISO 13485 Provides
ISO 13485 provides the primary organizational structure for a medical-device quality management system.
Its requirements address:
- Quality-management-system processes
- Management responsibility
- Resource management
- Product realization
- Design and development
- Purchasing and outsourced processes
- Production and service provision
- Process validation
- Sterilization and sterile-barrier controls
- Monitoring and measuring equipment
- Complaint handling
- Regulatory reporting
- Internal audits
- Control of nonconforming product
- Data analysis
- Corrective and preventive action
- Risk-based decision-making
- Document and record control
ISO 13485 is designed for organizations involved in one or more stages of the medical-device lifecycle, including design, manufacturing, storage, distribution, installation, servicing, and related activities.
An organization may implement ISO 13485 without obtaining certification. ISO does not conduct certification or issue certificates. Independent certification bodies perform certification audits and issue certificates when the organization demonstrates conformity within the defined certification scope.
Under the QMSR, however, applicable ISO 13485 requirements are not voluntary for manufacturers subject to Part 820. They form part of the legally enforceable U.S. CGMP framework.
What the QMSR Adds to ISO 13485
The QMSR does more than direct manufacturers to follow ISO 13485. It establishes FDA-specific scope, definitions, supplemental provisions, regulatory connections, and enforcement consequences.
The principal FDA-specific provisions are found in:
| QMSR section | FDA-specific function |
|---|---|
| § 820.1 | Defines applicability, scope, conflicts, foreign-manufacturer obligations, and exemptions or variances |
| § 820.3 | Establishes FDA definitions and the hierarchy between FDA and ISO terminology |
| § 820.7 | Incorporates ISO 13485:2016 and ISO 9000:2015 Clause 3 by reference |
| § 820.10 | Requires the QMS, connects ISO clauses to other FDA regulations, defines design-control applicability, and establishes enforcement consequences |
| § 820.35 | Adds complaint, servicing, UDI, and confidentiality record requirements |
| § 820.45 | Adds detailed device-labeling and packaging controls |
These provisions must be applied together with the incorporated ISO clauses.
Scope and Applicability
ISO 13485 may be used by a broad range of organizations throughout the medical-device supply chain. The QMSR applies according to the statutory and regulatory scope established by FDA.
Under § 820.1, Part 820 governs the methods, facilities, and controls used for the:
- Design
- Manufacture
- Packaging
- Labeling
- Storage
- Installation
- Servicing
of finished devices intended for human use.
Manufacturers subject to the QMSR include organizations performing functions such as:
- Finished-device manufacturing
- Specification development
- Contract manufacturing
- Contract sterilization
- Installation
- Relabeling
- Repacking
- Remanufacturing
- Initial distribution of devices manufactured by foreign establishments performing covered functions
A manufacturer performing only certain covered operations must comply with the requirements applicable to those operations.
Manufacturers of components or parts that are not finished devices are generally outside the direct scope of Part 820, although FDA encourages them to consider applicable quality-system provisions. A component supplier may still maintain ISO 13485 certification because of customer, contractual, or international-market requirements.
Foreign manufacturers offering devices for import into the United States are subject to the QMSR. Devices may be refused admission if they appear to be adulterated or otherwise violate the FD&C Act and applicable FDA regulations.
FDA Definitions Control
ISO 13485 and ISO 9000 provide much of the terminology used in the QMSR, but FDA terminology remains controlling where § 820.3, the FD&C Act, or another FDA regulation provides a different definition.
Section 820.3 establishes the following hierarchy:
- Definitions in the FD&C Act apply and supersede correlating ISO definitions.
- Definitions specified in § 820.3 supersede correlating definitions in ISO 13485 or ISO 9000.
- ISO 13485 and ISO 9000 definitions apply where FDA has not established a controlling definition.
Examples include:
- The FD&C Act definition of device controls over the ISO definition of medical device.
- The FD&C Act definition of labeling controls over the correlating ISO terminology.
- Manufacturer includes specification developers, contract sterilizers, installers, relabelers, remanufacturers, repackers, and certain initial distributors.
- Organization is interpreted as manufacturer for purposes of Part 820.
- Finished device includes a device or accessory suitable for use or capable of functioning, whether or not it is packaged, labeled, or sterilized.
- Safety and performance in ISO 13485 does not replace FDA’s statutory standard of reasonable assurance of safety and effectiveness.
A manufacturer should not mechanically substitute ISO terminology for FDA terminology in procedures, regulatory assessments, or inspection responses where the FDA definition affects the legal meaning.
FDA Requirements Outside ISO 13485
ISO 13485 repeatedly refers to “applicable regulatory requirements.” For a manufacturer supplying the U.S. market, this includes requirements outside Part 820.
Section 820.10 expressly connects particular ISO clauses to FDA regulations governing:
| FDA requirement | Regulatory location | QMS connection |
|---|---|---|
| Unique Device Identification | 21 CFR Part 830 | Device identification and production records |
| Medical-device tracking | 21 CFR Part 821 | Traceability where tracking requirements apply |
| Medical Device Reporting | 21 CFR Part 803 | Complaint evaluation and reporting to FDA |
| Corrections and removals | 21 CFR Part 806 | Advisory notices, corrections, removals, and reporting |
Other potentially applicable FDA requirements include:
- Establishment registration and device listing under Part 807
- Premarket notification requirements under Part 807
- Premarket approval requirements under Part 814
- Investigational device requirements under Part 812
- Medical-device labeling requirements under Part 801
- Electronic records and electronic signatures under Part 11
- Electronic-product radiation-control requirements
- Device-specific special controls and classification regulations
- Postmarket surveillance requirements
- Import and export requirements
Compliance with ISO 13485 alone does not demonstrate compliance with these requirements.
The QMS must contain a method for identifying, implementing, and maintaining all regulatory requirements applicable to the manufacturer’s devices, activities, and markets.
Design and Development Applicability
ISO 13485 contains design and development requirements in Clause 7.3. The QMSR defines which U.S. device manufacturers must apply those requirements.
Under § 820.10(c), the ISO 13485 design and development requirements apply to manufacturers of:
- All Class II devices
- All Class III devices
- Class I devices automated with computer software
- The additional Class I devices specifically listed in § 820.10(c)
This FDA-specific applicability provision remains important. A manufacturer should not determine U.S. design-control applicability solely from the wording or certification scope of ISO 13485.
Devices manufactured under an Investigational Device Exemption are not automatically exempt from applicable design and development requirements.
For a detailed treatment of design verification, design validation, process validation, software assurance, sterilization, packaging, and lifecycle controls, see Medical Device Validation Requirements Under QMSR.
FDA-Specific Record Requirements
ISO 13485 establishes general record-control requirements. Section 820.35 adds information that manufacturers must include in particular records.
Complaint Records
Complaint records must document the review, evaluation, and investigation of complaints involving possible failure of a device, labeling, or packaging to meet specifications.
For complaints subject to reporting, requiring investigation, or actually investigated, the records must include specified information such as:
- Device name
- Date the complaint was received
- UDI, UPC, or other device identification
- Complainant information
- Nature and details of the complaint
- Corrections or corrective actions taken
- Reply to the complainant
When a complaint is not investigated because a similar complaint has already been investigated, the manufacturer must document the justification.
Servicing Records
Servicing records must include, at minimum:
- Device identification
- UDI, UPC, or other applicable identifier
- Date of service
- Individuals performing the service
- Service performed
- Test and inspection data
UDI Records
The UDI must be recorded for each medical device or batch of medical devices as required by applicable QMSR and UDI provisions.
These requirements supplement ISO 13485. An ISO-based procedure that does not capture the information required by § 820.35 is not fully compliant with the QMSR.
FDA Labeling and Packaging Provisions
ISO 13485 addresses production, packaging, labeling, product preservation, and controlled operations. FDA determined that additional provisions were necessary because labeling and packaging errors remain significant causes of medical-device recalls.
Section 820.45 requires documented procedures covering labeling and packaging:
- Integrity
- Inspection
- Storage
- Processing
- Handling
- Distribution
- Use, where appropriate
Before release or storage, as applicable, manufacturers must examine labeling and packaging for accuracy, including:
- Correct UDI, UPC, or other device identification
- Expiration date
- Storage instructions
- Handling instructions
- Additional processing instructions
Manufacturers must document labeling release and establish controls that prevent labeling and packaging mix-ups. Inspection results must be recorded.
These requirements supplement ISO 13485 Clause 7.5.1. An ISO 13485 certificate does not demonstrate that the manufacturer has correctly implemented the specific controls required by § 820.45.
ISO 13485 Certification Is Not QMSR Compliance
A manufacturer may maintain a well-designed ISO 13485-certified quality system and still violate the QMSR.
Possible causes include:
- Failure to apply FDA definitions
- Inadequate U.S. regulatory-reporting procedures
- Missing UDI or device-tracking controls
- Incomplete complaint or servicing records
- Inadequate labeling and packaging controls
- Failure to meet FDA design-control applicability requirements
- Noncompliance with device-specific special controls
- Failure to meet registration, listing, premarket, or postmarket requirements
- Procedures written for non-U.S. regulatory terminology without an adequate U.S. regulatory supplement
The opposite distinction also applies: an FDA inspection does not result in ISO 13485 certification.
| Question | Answer |
|---|---|
| Does ISO 13485 certification prove QMSR compliance? | No |
| Does the QMSR require an ISO 13485 certificate? | No |
| Will FDA accept an ISO certificate instead of evaluating compliance? | No |
| Does a successful FDA inspection produce an ISO certificate? | No |
| Can an ISO 13485-certified manufacturer still receive an FDA Form 483 or Warning Letter? | Yes |
| Can one integrated QMS support both QMSR compliance and ISO certification? | Yes |
| Must the integrated QMS include FDA-specific requirements? | Yes |
Certification can provide useful independent evidence that the quality system conforms to the certification scope. It does not transfer regulatory responsibility from the manufacturer to the certification body.
Certification Audits vs FDA Inspections
An ISO 13485 certification audit and an FDA inspection differ in authority, purpose, scope, methodology, and consequences.
| Area | ISO 13485 certification audit | FDA QMSR inspection |
|---|---|---|
| Conducted by | Independent certification body | FDA investigators |
| Primary objective | Determine conformity with ISO 13485 within the certification scope | Determine compliance with the QMSR, FD&C Act, and applicable FDA regulations |
| Legal authority | Certification agreement | Federal statutory inspection authority |
| Result | Certification, continuation, suspension, withdrawal, or audit findings | Inspection classification and possible regulatory action |
| Certificate issued | Yes, when certification requirements are met | No |
| FDA-specific regulations | Only when included within the audit criteria | Evaluated as applicable |
| Enforcement authority | None under the FD&C Act | FDA retains statutory and regulatory enforcement authority |
| Records reviewed | Based on audit scope and certification rules | Records FDA considers relevant to QMSR compliance |
| Device focus | May be based on certification scope | May focus on device and patient risks, violations, complaints, recalls, or regulatory history |
On February 2, 2026, FDA discontinued the Quality System Inspection Technique and implemented the risk-based inspection process described in Compliance Program 7382.850.
The current inspection model evaluates interconnected quality-system areas such as:
- Management oversight
- Design and development
- Change control
- Outsourcing and purchasing
- Production and service provision
- Measurement, analysis, and improvement
FDA may also evaluate other applicable requirements, including:
- Medical Device Reporting
- Corrections and removals
- Device tracking
- Unique Device Identification
- Registration and listing
- Marketing authorization
- Previous inspection and compliance issues
FDA investigators may expand the inspection when findings indicate additional risk or when the minimum inspection coverage is insufficient to assess compliance.
Access to Management Review and Audit Records
Under the former Quality System Regulation, certain management-review, quality-audit, and supplier-audit reports were generally exempt from routine FDA review under former § 820.180(c).
That exemption was not retained in the QMSR.
During inspections conducted under the current QMSR, FDA investigators may review:
- Management-review records
- Internal quality-audit reports
- Supplier-audit reports
- Supporting records and corrective actions
- Records created before February 2, 2026, when relevant to current compliance
Manufacturers should ensure these records are complete, objective, internally consistent, and supported by evidence.
Audit procedures and management-review procedures should no longer state that FDA is categorically prohibited from reviewing these records.
See FDA Inspection Readiness for inspection preparation, documentation, and response considerations.
ISO Audits, MDSAP, and FDA Inspections
A conventional ISO 13485 certification audit does not exempt a manufacturer from FDA inspection.
MDSAP must be treated separately. Under the Medical Device Single Audit Program, an audit is performed by an MDSAP-recognized Auditing Organization against ISO 13485 and applicable requirements of participating regulatory authorities.
FDA may use qualifying MDSAP audit reports as a substitute for certain agency surveillance inspections. This does not eliminate FDA’s authority to conduct:
- For-cause inspections
- Compliance follow-up inspections
- Specific product-risk assignments
- PMA preapproval inspections
- PMA postmarket inspections
- Other inspections or investigations considered necessary
MDSAP participation therefore may affect FDA’s surveillance approach, but it does not eliminate QMSR obligations or FDA enforcement authority.
Enforcement Remains an FDA Function
The principal practical difference between ISO certification and the QMSR is enforcement.
Under § 820.10(e), failure to comply with an applicable Part 820 requirement renders a device adulterated under section 501(h) of the FD&C Act. The device and persons responsible for the failure may be subject to regulatory action.
Depending on the nature, significance, and persistence of the violations, FDA action may include:
- Form FDA 483 inspection observations
- Warning Letters
- Import detention or refusal of admission
- Seizure
- Injunction
- Civil money penalties
- Criminal prosecution
- Compliance follow-up inspections
- Delays or restrictions affecting premarket submissions
- Action involving devices already in distribution
An ISO certification body may issue a nonconformity, suspend a certificate, or withdraw certification. It cannot determine whether a device is adulterated under the FD&C Act or initiate FDA enforcement action.
An ISO 13485 certificate is therefore not a regulatory shield.
Building One Integrated Quality System
Manufacturers do not need separate quality systems for ISO 13485 and the QMSR. A single integrated system is generally more effective, provided that it incorporates all applicable U.S. requirements.
A practical structure includes:
ISO 13485 Core
Use the ISO 13485 process structure for:
- Quality-system governance
- Management responsibility
- Resource management
- Product realization
- Design and development
- Purchasing
- Production and service provision
- Monitoring and measurement
- Complaint handling
- Internal audits
- CAPA
- Document and record control
FDA Regulatory Overlay
Add documented controls for:
- QMSR scope and FDA definitions
- Device classification
- Design-control applicability
- Registration and listing
- Premarket authorization
- UDI
- Device tracking
- Medical Device Reporting
- Corrections and removals
- FDA complaint-record requirements
- FDA servicing-record requirements
- Labeling and packaging controls
- Device-specific special controls
- Electronic records and signatures
- FDA inspections and regulatory communications
Regulatory Traceability
Maintain a regulatory matrix mapping:
- Applicable ISO 13485 clauses
- Applicable Part 820 requirements
- Other applicable FDA regulations
- Internal procedures
- Responsible functions
- Required records
- Relevant products and sites
This structure makes the relationship between ISO conformity and FDA compliance visible and reduces the likelihood that a requirement will be overlooked because it appears outside the main QMS procedure set.
Transitioning Former QSR Documentation
Manufacturers should remove the assumption that former QSR section numbers remain the current regulatory basis.
Documents requiring review may include:
- Quality manuals
- Standard operating procedures
- Work instructions
- Validation plans and protocols
- Design and development procedures
- Complaint and CAPA procedures
- Supplier-control procedures
- Audit checklists
- Management-review procedures
- Training materials
- Regulatory matrices
- Electronic workflow configurations
- Templates and forms
Former citations such as §§ 820.30, 820.70, 820.75, 820.120, and 820.130 should not continue to be presented as current Part 820 sections.
The underlying requirements may remain applicable through ISO 13485 or current FDA supplemental provisions. Citations should therefore be replaced based on the actual regulatory basis rather than deleted without assessment.
For example:
| Former citation | Current regulatory basis |
|---|---|
| Former § 820.30 — Design controls | § 820.10(c) and ISO 13485 Clause 7.3 |
| Former § 820.70 — Production and process controls | ISO 13485 production and service provisions |
| Former § 820.75 — Process validation | ISO 13485 Clause 7.5.6 and, where applicable, Clause 7.5.7 |
| Former § 820.120 — Device labeling control | § 820.45 and applicable ISO 13485 provisions |
| Former § 820.130 — Device packaging | § 820.45 and applicable ISO 13485 provisions |
| Former § 820.180 — General records | § 820.35 and ISO 13485 record-control requirements |
| Former § 820.198 — Complaint files | § 820.35, ISO 13485 Clause 8.2.2, and Part 803 |
The transition should preserve traceability to the current requirements and demonstrate that the manufacturer evaluated—not merely renamed—its existing controls.
Common Misunderstandings
“QMSR and ISO 13485 are now identical.”
Incorrect. ISO 13485 supplies the principal framework, but the QMSR includes FDA-specific scope, terminology, records, labeling, packaging, reporting, design-applicability, and enforcement provisions.
“An ISO 13485 certificate proves FDA compliance.”
Incorrect. FDA expressly states that ISO certification alone does not demonstrate QMSR compliance.
“FDA adopted every standard referenced by ISO 13485.”
Incorrect. Only ISO 13485:2016 and Clause 3 of ISO 9000:2015 were incorporated through the QMSR final rule.
“Future ISO 13485 revisions automatically become FDA requirements.”
Incorrect. FDA must evaluate a revision and amend the QMSR through rulemaking before a different edition becomes incorporated into Part 820.
“FDA will certify manufacturers to ISO 13485.”
Incorrect. FDA inspections do not produce ISO certificates.
“The shorter Part 820 eliminated the former requirements.”
Incorrect. Most requirements were relocated to the incorporated ISO 13485 framework rather than eliminated.
“ISO terminology can always replace FDA terminology.”
Incorrect. FD&C Act and FDA definitions supersede correlating ISO definitions where specified.
“FDA cannot review internal-audit or management-review records.”
Incorrect under the QMSR. The former record-review exemption was not retained.
“MDSAP participation prevents FDA inspections.”
Incorrect. FDA may use qualifying MDSAP reports instead of certain surveillance inspections but retains authority to conduct other inspections.
Summary
The QMSR harmonizes the U.S. medical-device quality-system framework with ISO 13485, but it does not surrender FDA authority or convert U.S. compliance into a certification exercise.
For manufacturers supplying the United States:
- Applicable ISO 13485:2016 requirements are legally enforceable through Part 820.
- The FD&C Act and FDA regulations remain controlling.
- FDA definitions supersede conflicting ISO terminology.
- Sections 820.35 and 820.45 establish supplemental records, labeling, and packaging requirements.
- Other FDA requirements for reporting, UDI, tracking, registration, listing, premarket authorization, and postmarket controls remain applicable.
- ISO 13485 certification is not required by the QMSR and does not establish FDA compliance.
- FDA may inspect records beyond those typically reviewed during a certification audit.
- Failure to comply may render a device adulterated and expose the manufacturer and responsible persons to regulatory action.
The correct compliance model is therefore:
ISO 13485:2016 requirements incorporated into Part 820, plus FDA-specific QMSR provisions, plus all other applicable U.S. statutory and regulatory requirements.
Regulatory References
- 21 CFR Part 820 — Quality Management System Regulation
- FDA Quality Management System Regulation
- FDA QMSR Frequently Asked Questions
- QMSR Final Rule — Medical Devices; Quality System Regulation Amendments
- FDA Inspection of Medical Device Manufacturers — Compliance Program 7382.850
- FDA Medical Device Risk-Based Inspections
- FDA Medical Device Single Audit Program
- ISO 13485 — Quality Management for Medical Devices
- ISO Certification

