Medical Device Validation Requirements Under QMSR

The Quality Management System Regulation (QMSR) establishes the current U.S. quality-system requirements for medical device manufacturers. Effective February 2, 2026, the QMSR amended 21 CFR Part 820 and incorporated ISO 13485:2016 by reference as the principal quality-management framework for medical devices.

The former Quality System Regulation sections commonly cited for design controls, production controls, process validation, labeling, and packaging are no longer the current regulatory structure. Medical device validation requirements now arise primarily through the ISO 13485 clauses incorporated into Part 820, together with FDA-specific requirements retained in §§ 820.1, 820.3, 820.10, 820.35, and 820.45.

The regulatory structure changed, but the fundamental expectation did not: manufacturers must establish objective evidence that device designs, manufacturing processes, software, sterilization processes, packaging systems, and lifecycle controls consistently achieve their intended results.

Medical device validation controls under QMSR and ISO 13485:2016
QMSR integrates design, process, software, sterilization, packaging, risk-management, and lifecycle validation controls under 21 CFR Part 820 and ISO 13485:2016.

Current Regulatory Framework

The QMSR requires manufacturers to document a quality management system that complies with applicable ISO 13485:2016 requirements and the supplemental requirements of Part 820.

The principal validation requirements are distributed across the following areas:

Validation areaCurrent regulatory basis
Quality management system21 CFR 820.10(a) and ISO 13485 Clause 4
Design and development21 CFR 820.10(c) and ISO 13485 Clause 7.3
QMS software validationISO 13485 Clause 4.1.6
Production and service process validationISO 13485 Clause 7.5.6
Sterilization and sterile-barrier process validationISO 13485 Clauses 7.5.5 and 7.5.7
Monitoring and measuring softwareISO 13485 Clause 7.6
Risk managementISO 13485 Clauses 4.1.2, 7.1, and related lifecycle requirements
Packaging and labeling controls21 CFR 820.45 and applicable ISO 13485 production and preservation requirements
Records and lifecycle evidence21 CFR 820.35 and ISO 13485 Clauses 4.2, 7, and 8

The incorporated ISO 13485 requirements are legally enforceable under the QMSR. However, the QMSR does not require a manufacturer to obtain ISO 13485 certification. Certification also does not exempt a manufacturer from FDA inspection or enforcement.

Where an ISO 13485 provision conflicts with the Federal Food, Drug, and Cosmetic Act or another applicable FDA regulation, the U.S. statutory or regulatory requirement controls.


Validation Principles Under QMSR

Validation under the QMSR is not limited to protocol execution. It is a controlled lifecycle process that begins with intended use, requirements, risk assessment, and design and continues through verification, validation, transfer, routine production, monitoring, change control, and postmarket feedback.

A defensible validation program should establish:

  • The intended use of the device, process, system, or software
  • Clear and measurable requirements
  • Applicable regulatory and consensus-standard requirements
  • Risk-based validation scope and rigor
  • Defined responsibilities and qualified personnel
  • Approved protocols or equivalent controlled plans
  • Scientifically and technically justified acceptance criteria
  • Objective evidence that requirements were met
  • Traceability among requirements, risks, tests, deviations, and conclusions
  • Review and approval of validation results
  • Controls for changes, revalidation, and maintenance of the validated state

Validation activities should be proportionate to device risk, process complexity, degree of automation, potential failure consequences, and the ability to detect nonconforming output before release.


Design Verification and Design Validation

Under § 820.10(c), ISO 13485 Clause 7.3 design and development requirements apply to manufacturers of:

  • All Class II devices
  • All Class III devices
  • Class I devices automated with computer software
  • The additional Class I devices specifically listed in § 820.10(c)

Design verification and design validation are related but distinct activities.

ActivityFundamental question
Design verificationDid the design outputs satisfy the specified design inputs?
Design validationDoes the resulting device satisfy user needs, intended uses, and applicable safety and performance requirements?

Design and Development Planning

The manufacturer must plan and control design and development activities. The plan should define:

  • Design stages and deliverables
  • Responsibilities and authorities
  • Required design reviews
  • Verification and validation activities
  • Risk-management activities
  • Traceability methods
  • Design-transfer activities
  • Interfaces among technical, clinical, manufacturing, quality, and regulatory functions
  • Required resources and competent personnel

The design plan should be reviewed and updated as development progresses.

Design Inputs and Risk Controls

Design inputs should translate intended use, user needs, regulatory requirements, applicable standards, risk controls, functional requirements, performance requirements, usability needs, and safety requirements into complete and testable specifications.

Design inputs should be:

  • Unambiguous
  • Internally consistent
  • Measurable where practicable
  • Verifiable or validatable
  • Traceable to their sources
  • Reviewed and approved

Risk-control measures identified during risk analysis must be translated into design requirements and verified for effective implementation.

Design Verification

Design verification may include:

  • Engineering analysis
  • Dimensional and functional testing
  • Electrical safety and electromagnetic compatibility testing
  • Bench performance testing
  • Software verification
  • Biocompatibility testing
  • Packaging design testing
  • Review of drawings, specifications, and calculations
  • Comparison of outputs against approved design inputs

Verification methods, sample sizes, acceptance criteria, results, and deviations must be documented.

Design Validation

Design validation must demonstrate that the device meets user needs and intended uses under defined operating conditions. Validation should be performed using representative product, such as initial production units, batches, or appropriately justified equivalents.

Depending on the device, design validation may include:

  • Simulated-use studies
  • Usability or human-factors validation
  • Clinical evaluation or clinical investigation
  • Device software validation
  • Performance testing under anticipated use conditions
  • Testing across intended users, patient populations, and use environments
  • Validation of cleaning or reprocessing instructions
  • Transportation and storage evaluation
  • Packaging and shelf-life studies
  • Confirmation that implemented risk controls remain effective

Validation must be completed before release of the design for commercial distribution. Results must demonstrate conformity to predefined acceptance criteria rather than merely record that testing was performed.

Medical-device design validation is not the same as equipment Design Qualification. Design validation evaluates whether the medical device meets user needs and intended use. Equipment DQ evaluates whether a proposed facility, utility, equipment item, or computerized system design is suitable for its intended operational purpose.

Design Transfer and Design Changes

Design transfer must ensure that approved design outputs are correctly translated into production specifications, manufacturing instructions, inspection requirements, software configurations, acceptance criteria, and other controlled production information.

Design changes must be:

  • Identified and documented
  • Reviewed for technical and regulatory significance
  • Evaluated for effects on components, work in process, released devices, risk controls, and manufacturing processes
  • Verified or validated as appropriate
  • Approved before implementation
  • Assessed for possible premarket-submission requirements

The design and development file must include or reference records demonstrating conformity with applicable design requirements, including controlled design changes.


Manufacturing Process Validation

ISO 13485 Clause 7.5.6 requires validation of production and service processes when the resulting output cannot be, or is not, verified by subsequent monitoring or measurement.

Examples may include:

  • Molding and forming processes
  • Welding, soldering, brazing, or bonding
  • Coating and surface-treatment processes
  • Heat treatment
  • Automated assembly
  • Software-controlled manufacturing operations
  • Cleaning processes
  • Aseptic processing
  • Sterilization
  • Sterile-barrier forming and sealing
  • Processes in which destructive testing would be required to verify every unit

A process should not be classified as requiring validation merely because it is important. The manufacturer should first determine whether subsequent inspection or testing can adequately verify the output. Where complete verification is technically possible but is not performed, validation may still be required.

Process Validation Strategy

The validation strategy should define:

  • Process purpose and boundaries
  • Product families and configurations covered
  • Critical quality characteristics
  • Critical process parameters
  • Equipment, tooling, utilities, and software used
  • Material and component requirements
  • Operator qualifications
  • Sampling and statistical rationale
  • Worst-case and challenge conditions
  • Acceptance criteria
  • Monitoring and control requirements
  • Required records
  • Conditions requiring revalidation

A traditional IQ, OQ, and PQ structure can provide an effective framework:

  • Installation Qualification verifies that equipment, utilities, software, and supporting components are installed according to approved requirements.
  • Operational Qualification challenges operating ranges, parameters, alarms, controls, and anticipated failure conditions.
  • Performance Qualification demonstrates that the integrated process consistently produces acceptable output under routine or simulated production conditions.

The QMSR does not require manufacturers to use the specific terms IQ, OQ, and PQ. It requires documented evidence that the process is capable of achieving its planned results. The selected validation structure must be technically appropriate and clearly defined.

Continued Process Control

Initial validation does not eliminate the need for routine process controls. Validated processes must be monitored using established parameters, in-process controls, inspection results, maintenance status, calibration status, environmental conditions, and other relevant data.

Adverse trends, repeated nonconformities, process excursions, equipment failures, or changes may require investigation, corrective action, or revalidation.


Software Assurance and Validation

The QMSR addresses two fundamentally different software categories:

Software categoryPrimary control framework
Software that is part of, or is itself, a medical deviceDesign and development controls under ISO 13485 Clause 7.3 and applicable device-software requirements
Software used in production or the quality management systemISO 13485 Clauses 4.1.6, 7.5.6, and 7.6, as applicable

These categories should not be combined into one generic software-validation procedure without recognizing their different intended uses and risks.

Production and QMS Software

Software used in production or the quality management system must be validated for its intended use before initial use and, as appropriate, after changes.

Examples include:

  • Manufacturing execution systems
  • Automated production or inspection systems
  • Electronic quality management systems
  • Complaint and CAPA systems
  • Document-management systems
  • Laboratory or test-data systems
  • Production-data collection and analysis applications
  • Software embedded in manufacturing equipment
  • Cloud services used to maintain required quality records
  • Software used to control monitoring and measuring equipment

FDA’s February 2026 Computer Software Assurance for Production and Quality Management System Software guidance describes a risk-based approach for establishing confidence that this software is fit for its intended use.

A software-assurance strategy should:

  • Define the software’s intended use
  • Identify functions affecting device quality, patient safety, or quality records
  • Evaluate process risk associated with software failure
  • Determine the appropriate assurance activities
  • Assess supplier and configuration information
  • Use scripted or unscripted testing methods appropriate to the risk
  • Document objective evidence sufficient to support the assurance conclusion
  • Control configuration, access, data, interfaces, and changes
  • Determine whether regression testing or revalidation is required after changes

Computer software assurance does not eliminate the validation requirement. It permits the validation effort and documentation to be focused on intended use, process risk, critical functionality, and meaningful objective evidence rather than unnecessary test-script volume.

Device Software

Software that is part of a medical device must be controlled through the device design and development lifecycle. Controls should address:

  • Software requirements
  • Architecture and detailed design
  • Software risk analysis
  • Traceability
  • Verification and validation
  • Anomaly management
  • Configuration management
  • Cybersecurity where applicable
  • Release approval
  • Change control and regression testing
  • Postmarket monitoring

The production and QMS software assurance guidance does not replace the design-control and premarket requirements applicable to device software functions.


Sterilization Validation

Sterilization processes require specific control under ISO 13485 Clauses 7.5.5 and 7.5.7. Processes for sterilization and sterile-barrier systems must be validated before implementation and reviewed or revalidated following changes that could affect process effectiveness.

Sterilization validation should address:

  • Product and packaging configuration
  • Product families and processing categories
  • Load configuration and worst-case locations
  • Sterilization modality
  • Cycle or dose development
  • Bioburden and microbiological characteristics
  • Process challenge devices and biological indicators where applicable
  • Physical and microbiological acceptance criteria
  • Sterility assurance requirements
  • Product functionality and material compatibility
  • Sterilant residuals where applicable
  • Routine monitoring and release requirements
  • Equipment calibration and maintenance
  • Deviations, excursions, and nonconforming cycles
  • Periodic review and requalification

Applicable FDA-recognized standards may include method-specific requirements for ethylene oxide, radiation, moist heat, dry heat, vaporized hydrogen peroxide, and other sterilization processes.

Records must permit each sterilization batch or lot to be traceable to the sterilization-process parameters used.

Outsourcing sterilization does not transfer the finished-device manufacturer’s responsibility for the safety and effectiveness of the device. The manufacturer must qualify and control the contract sterilizer, define responsibilities, review validation evidence, approve applicable changes, and maintain adequate records. Contract sterilizers are also subject to the QMSR requirements applicable to the operations they perform.

See Sterilization Methods Overview for the principal sterilization technologies and their validation considerations.


Packaging and Sterile-Barrier Validation

Medical-device packaging controls arise from § 820.45 and applicable ISO 13485 requirements for production, sterile-barrier systems, product preservation, storage, handling, and distribution.

Section 820.45 requires documented procedures addressing packaging and labeling integrity, inspection, storage, and operations under customary processing, storage, handling, distribution, and use conditions.

Packaging validation should distinguish among three related activities:

  1. Packaging design verification confirms that packaging materials and the packaging-system design satisfy specified requirements.
  2. Packaging-process validation demonstrates that forming, sealing, and assembly processes consistently produce acceptable packaging.
  3. Package performance testing evaluates whether the completed packaging system protects the device through sterilization, storage, handling, distribution, and intended use.

A packaging-validation program may include:

  • Material and component qualification
  • Package configuration and design verification
  • Sealing or closure process validation
  • Seal strength and integrity testing
  • Visual inspection criteria
  • Sterilization compatibility
  • Distribution simulation
  • Environmental conditioning
  • Accelerated and real-time aging
  • Shelf-life justification
  • Package-opening and aseptic-presentation evaluation
  • Label durability and legibility
  • Verification of storage and handling requirements

For terminally sterilized devices, FDA-recognized ISO 11607-1 and ISO 11607-2 provide established frameworks for sterile-barrier systems and validation of forming, sealing, and assembly processes.

Packaging validation must represent the actual device, packaging configuration, sterilization exposure, manufacturing process, and distribution environment. Testing empty packages or unrepresentative configurations does not establish that the marketed packaging system is acceptable.

See Packaging Qualification Strategy and Packaging Integrity Testing for detailed packaging-validation approaches.


Risk Management

Risk management is integrated throughout ISO 13485 and therefore throughout the QMSR. It is not confined to a single risk-analysis report completed during product development.

Risk-based controls apply to:

  • Quality-management-system processes
  • Design inputs and outputs
  • Design verification and validation
  • Supplier qualification and purchased-product verification
  • Production and process validation
  • Software validation and assurance
  • Monitoring and measuring equipment
  • Nonconforming product
  • Corrective and preventive action
  • Design and production changes
  • Postmarket feedback

ISO 14971 is an FDA-recognized consensus standard that provides a structured medical-device risk-management framework. It supports hazard identification, risk estimation, risk evaluation, risk control, evaluation of residual risk, production and post-production monitoring, and maintenance of the risk-management file.

Risk-management outputs should be traceable to:

  • Design requirements
  • Risk-control measures
  • Verification and validation activities
  • Labeling and instructions for use
  • Production controls
  • Supplier controls
  • Acceptance criteria
  • Postmarket monitoring

Feedback, complaints, nonconformities, service data, CAPA, and other postmarket information must be evaluated for their effect on existing risk conclusions and validation controls.


Supplier and Outsourced-Process Controls

Manufacturers remain responsible for processes, products, and services provided by external parties.

The type and extent of supplier controls should be proportionate to:

  • The risk associated with the supplied product or service
  • The supplier’s ability to meet specified requirements
  • The effect of supplier failure on device safety and effectiveness
  • The extent to which incoming or subsequent verification can detect nonconformity

For outsourced validated processes, supplier controls may include:

  • Technical and quality agreements
  • Supplier qualification and audits
  • Review of process-validation protocols and reports
  • Approval of product families and worst-case configurations
  • Review of equipment and software qualifications
  • Defined routine monitoring and release responsibilities
  • Deviation and nonconformance notification
  • Change-notification and approval requirements
  • Access to validation and production records
  • Periodic supplier-performance review

A vendor certificate or summary report is not automatically sufficient. The manufacturer must determine whether the available evidence adequately supports its product, intended use, process configuration, and regulatory responsibilities.


Change Control and Revalidation

Validated designs, processes, software, sterilization cycles, and packaging systems must remain under controlled change management.

A validation-impact assessment should determine whether a proposed change affects:

  • Intended use or user needs
  • Design inputs or outputs
  • Risk-management conclusions
  • Product materials or components
  • Manufacturing methods or process parameters
  • Equipment, tooling, utilities, or facilities
  • Software, firmware, configuration, or interfaces
  • Sterilization cycle, load, or product family
  • Packaging materials, dimensions, or sealing parameters
  • Test methods or acceptance criteria
  • Suppliers or outsourced processes
  • Labeling, storage, distribution, or shelf life
  • Previously completed verification or validation

Depending on significance and risk, the required action may range from documented review to targeted verification, regression testing, partial revalidation, or complete revalidation.

Changes must be reviewed, verified or validated as appropriate, and approved before implementation. Changes affecting a marketed device must also be assessed for possible regulatory-submission or reporting requirements.

See Change Control Impact on Validation for a structured validation-impact assessment approach.


Validation Documentation and Records

Validation conclusions must be supported by controlled, reviewable, and traceable records.

Depending on the activity, validation documentation may include:

  • Validation plans
  • Intended-use statements
  • Design and process requirements
  • Risk assessments
  • Design-review records
  • Traceability matrices
  • Equipment and utility qualification records
  • Process-validation protocols and reports
  • Software-assurance assessments
  • Sterilization-validation records
  • Packaging-validation records
  • Approved test methods and acceptance criteria
  • Raw data and supporting calculations
  • Deviations, investigations, and corrective actions
  • Supplier and outsourced-process evidence
  • Change assessments and revalidation decisions
  • Final approval and release records

A Validation Protocol and Final Report should clearly identify what was evaluated, the acceptance criteria applied, the results obtained, deviations encountered, and the basis for the final conclusion.

Under the current QMSR inspection framework, FDA investigators may review QMS records—including management-review, quality-audit, and supplier-audit records that were previously exempt from routine FDA review under the former QSR. Validation records should therefore be complete, internally consistent, and readily retrievable.


Common Validation Deficiencies

Common QMSR validation deficiencies include:

  • Continuing to cite obsolete QSR sections as current requirements
  • Treating design verification as a substitute for design validation
  • Performing design validation with nonrepresentative prototypes without justification
  • Using vague or nonmeasurable acceptance criteria
  • Failing to trace risk controls to verification and validation evidence
  • Validating processes without first defining which outputs cannot be adequately verified
  • Assuming that the terms IQ, OQ, and PQ are themselves regulatory requirements
  • Treating computer software assurance as permission to eliminate validation evidence
  • Combining device-software validation and QMS software assurance without distinguishing their scopes
  • Accepting supplier or vendor validation documents without documented assessment
  • Assuming that outsourced sterilization transfers regulatory responsibility
  • Performing package integrity tests without validating the packaging process
  • Implementing changes without assessing previously completed validation
  • Failing to use complaints, nonconformities, CAPA, and trend data to reassess risk and validation status

Summary

The QMSR changed the structure and citation basis of U.S. medical-device quality-system requirements, but it did not reduce validation expectations.

Manufacturers must use the ISO 13485 framework incorporated into Part 820, together with FDA-specific requirements, to establish that:

  • Device designs meet user needs and intended uses
  • Production processes consistently achieve planned results
  • Production and QMS software is fit for intended use
  • Device software is controlled through the design lifecycle
  • Sterilization and sterile-barrier processes remain effective
  • Packaging protects the device through its claimed shelf life and distribution conditions
  • Risk management drives validation and lifecycle decisions
  • Changes are assessed and validated before implementation
  • Objective evidence remains complete, traceable, and available for FDA inspection

Effective medical-device validation is therefore not a collection of isolated protocols. It is a risk-based system of design, process, software, supplier, documentation, and postmarket controls maintained throughout the total product lifecycle.


Regulatory and Technical References