What Is the Quality Management System Regulation (QMSR)?
The Essential Guide to Requirements Management and Traceability
Chapters
- 1. Requirements Management
- Overview
- 1 What is Requirements Management? A Complete Guide
- 2 Why do you need Requirements Management?
- 3 Four Stages of Requirements Management Processes
- 4 Adopting Agile Requirements Management Tools
- 5 Status Request Changes
- 6 Conquering the 5 Biggest Challenges of Requirements Management
- 7 Three Reasons You Need a Requirements Management Solution
- 8 Guide to Poor Requirements: Identify Causes, Repercussions, and How to Fix Them
- 9 What Is a Requirements Management Plan? A Practical Guide
- 10 Enterprise Requirements Management: Keeping Traceability Current
- 2. Writing Requirements
- Overview
- 1 Functional requirements examples and templates
- 2 What Is a Product Requirements Document? A Complete PRD Guide
- 3 What Is a User Requirement Specification (URS)? How to Write and Manage One
- 4 Identifying and Measuring Requirements Quality
- 5 How to Write a System Requirements Specification (SRS) Document
- 6 The Fundamentals of Business Requirements: Examples of Business Requirements and the Importance of Excellence
- 7 Adopting the EARS Notation to Improve Requirements Engineering
- 8 What Is a Compliance Risk Assessment? Steps, Framework, and Examples
- 9 Jama Connect Advisor™
- 10 Frequently Asked Questions about the EARS Notation and Jama Connect Advisor™
- 11 How to Write an Effective Product Requirements Document (PRD)
- 12 Functional vs. Non-Functional Requirements
- 13 What Are Nonfunctional Requirements and How Do They Impact Product Development?
- 14 What Is a Software Design Specification? Key Components + Template
- 15 Characteristics of Effective Software Requirements and Software Requirements Specifications (SRS)
- 16 8 Do’s and Don’ts for Writing Requirements
- 17 Project Requirements: Types, Process, and Best Practices
- 18 INCOSE Guide to Writing Requirements
- 3. Requirements Gathering and Management Processes
- Overview
- 1 Requirements Engineering
- 2 Requirements Analysis
- 3 A Guide to Requirements Elicitation for Product Teams
- 4 Requirements Gathering Techniques for Agile Product Teams
- 5 Requirements Gathering in Software Engineering: Process, Techniques, and Best Practices
- 6 Defining and Implementing a Requirements Baseline
- 7 Managing Project Scope — Why It Matters and Best Practices
- 8 Requirements Decomposition and How AI Supports It
- 9 How Long Do Requirements Take?
- 10 How to Reuse Requirements Across Multiple Products
- 11 Requirements Prioritization Techniques: 7 Methods for Engineers
- 12 How to Run a Requirements Gathering Workshop
- 4. Requirements Traceability
- Overview
- 1 What Is Traceability in Product Development? A Guide for Regulated Teams
- 2 Tracing Your Way to Success: The Crucial Role of Traceability in Modern Product and Systems Development
- 3 Bidirectional Traceability: What It Is and How to Implement It
- 4 Change Impact Analysis (CIA): A Short Guide for Effective Implementation
- 5 What is Engineering Change Management (ECM)? A Complete Guide
- 6 What is Meant by Version Control?
- 7 Key Traceability Challenges and Tips for Ensuring Accountability and Efficiency
- 8 The Role of a Data Thread in Product and Software Development
- 9 Unraveling the Digital Thread: Enhancing Connectivity and Efficiency
- 10 What is a Traceability Matrix? A Guide to Requirements Traceability
- 11 How to Create and Use a Requirements Traceability Matrix (RTM)
- 12 Requirements Traceability Matrix Pros and Cons: A Practical Guide
- 13 Live Traceability vs. After-the-Fact Traceability
- 14 Overcoming Barriers to Live Requirements Traceability™
- 15 Requirements Traceability, What Are You Missing?
- 16 Requirements Traceability: Links in the Chain
- 17 What Are the Benefits of End-to-End Traceability During Product Development?
- 18 Requirements Volatility: 7 Essential Management Strategies
- 19 FAQs About Requirements Traceability
- 20 What Is AI Traceability? How to Implement It
- 21 Product Traceability for Regulated Industries: A Complete Guide to Audit-Ready Compliance
- 22 What Is the Traceability Information Model?
- 5. Requirements Management Tools and Software
- Overview
- 1 Selecting the Right Requirements Management Tools and Software
- 2 Why Investing in Requirements Management Software Makes Business Sense During an Economic Downturn
- 3 Why Word and Excel Alone is Not Enough for Product, Software, and Systems Development
- 4 Can You Track Requirements in Excel?
- 5 What Is Application Lifecycle Management (ALM)?
- 6 Is There Life After DOORS®?
- 7 Requirements Management Tools Jira
- 8 Checklist: Selecting a Requirements Management Tool
- 6. Requirements Validation and Verification
- 7. Meeting Regulatory Compliance and Industry Standards
- Overview
- 1 Understanding ISO Standards
- 2 Understanding ISO/IEC 27001: A Guide to Information Security Management
- 3 What is DevSecOps? A Guide to Building Secure Software
- 4 Compliance Management
- 5 What Is Functional Safety (FuSa)? Standards, Lifecycle, and Where Programs Fail
- 6 Failure Mode and Effects Analysis (FMEA) Explained
- 7 TÜV SÜD: Ensuring Safety, Quality, and Sustainability Worldwide
- 8 What is IEC 62443? A Guide to Industrial Cybersecurity
- 9 DFARS Compliance: A Guide for Defense Contractors
- 10 CMMC vs FedRAMP: What’s Different and Which One Applies to You
- 11 Automotive SPICE (ASPICE) 4.0: A Complete Guide
- 12 Restriction of Hazardous Substances (RoHS) Compliance Guide
- 13 MISRA C and MISRA C++ Explained: Rules for Safer Embedded Code
- 14 REACH Compliance for Product Engineering Teams
- 8. Systems Engineering
- Overview
- 1 What is Systems Engineering? A Guide for Modern Engineering Teams
- 2 How Do Engineers Collaborate? A Guide to Streamlined Teamwork and Innovation
- 3 The Systems Engineering Body of Knowledge (SEBoK)
- 4 What Is MBSE? Model-Based Systems Engineering Explained
- 5 Digital Engineering Between Government and Contractors
- 6 Digital Engineering Tools: The Key to Driving Innovation and Efficiency in Complex Systems
- 7 What Is Bill of Materials (BOM) Management? A Guide to Controlling Product Data
- 9. Automotive Development
- Overview
- 1 Understanding IATF 16949: A Quick Guide to Automotive Quality Management
- 2 What Is ISO 21434? Automotive Cybersecurity Engineering Explained
- 3 What Is ISO 26262? A Guide to Functional Safety in Automotive
- 4 What Is ASIL? A Guide to Automotive Safety Integrity Levels in ISO 26262
- 5 What Is SOTIF? A Guide to ISO 21448 for ADAS Safety
- 10. Medical Device & Life Sciences Development
- Overview
- 1 The Importance of Benefit-Risk Analysis in Medical Device Development
- 2 Software as a Medical Device: Revolutionizing Healthcare
- 3 What’s a Design History File, and How Are DHFs Used by Product Teams?
- 4 Navigating the Risks of Software of Unknown Pedigree (SOUP) in the Medical Device & Life Sciences Industry
- 5 What Is ISO 13485? A Guide to Medical Device Quality Management Systems
- 6 What Is a Device Master Record (DMR)? Definition and FDA Requirements
- 7 What Is IEC 62304? Medical Software Guide
- 8 ISO 13485 vs ISO 9001: Understanding the Differences and Synergies
- 9 What You Need to Know: ANSI/AAMI SW96:2023 — Medical Device Security
- 10 Failure Modes, Effects, and Diagnostic Analysis (FMEDA) for Medical Devices: What You Need to Know
- 11 Embracing the Future of Healthcare: Exploring the Internet of Medical Things (IoMT)
- 12 What Is General Safety and Performance Requirements (GSPR)? What You Need To Know
- 13 What Is IEC 62366? A Guide to Medical Device Usability Engineering
- 14 What Is the Quality Management System Regulation (QMSR)?
- 15 510(k) vs PMA: Differences in FDA Device Approval and Clearance
- 16 EU MDR Compliance Requirements and Timeline
- 17 Essential Performance Requirements and How to Identify Them
- 18 DHF vs DMR vs DHR: What Changed Under the FDA QMSR
- 19 Computer Software Assurance for Production and Quality Systems
- 20 IVDR Compliance: What Manufacturers Need to Know
- 21 IEC 60601-1 Guide for Medical Devices
- 22 A Guide to Medical Device Requirements Management
- 11. Aerospace & Defense Development
- Overview
- 1 What is ITAR Compliance? What Engineering Teams Need to Know
- 2 What Is DO-278A? A Guide for Compliance Teams
- 3 What Is a Safety Integrity Level (SIL)? How to Calculate and Apply It
- 4 A Guide to Aerospace Requirements Management
- 5 What Is ARP4754A? A Complete Guide to Civil Aircraft and Systems Development Assurance
- 6 Understanding ARP4761A: Guidelines for System Safety Assessment in Aerospace
- 7 What Is DO-254? A Complete Guide to Airborne Hardware Design Assurance
- 8 What Is DO-178C? A Guide to Airborne Software Certification
- 12. Architecture, Engineering, and Construction (AEC industry) Development
- 13. Industrial Manufacturing & Machinery, Automation & Robotics, Consumer Electronics, and Energy
- 14. Semiconductor Development
- 15. AI in Product Development
- Overview
- 1 What Is AI in Product Development? A Complete 2026 Guide
- 2 AI Test Case Generation: A Complete Guide for Regulated QA Teams
- 3 Using AI to Write Software Requirements: What Works and What Doesn’t
- 4 What Is the Model Context Protocol (MCP) for Requirements Management?
- 5 AI for Systems Engineering: Benefits, Risks, and How to Start
- 6 How to Automate Requirements Management
- 7 Artificial Intelligence in Requirements Management
- 16. Risk Management
- 17. Product Development Terms and Definitions
Chapter 10: What Is the Quality Management System Regulation (QMSR)?
Chapters
- 1. Requirements Management
- Overview
- 1 What is Requirements Management? A Complete Guide
- 2 Why do you need Requirements Management?
- 3 Four Stages of Requirements Management Processes
- 4 Adopting Agile Requirements Management Tools
- 5 Status Request Changes
- 6 Conquering the 5 Biggest Challenges of Requirements Management
- 7 Three Reasons You Need a Requirements Management Solution
- 8 Guide to Poor Requirements: Identify Causes, Repercussions, and How to Fix Them
- 9 What Is a Requirements Management Plan? A Practical Guide
- 10 Enterprise Requirements Management: Keeping Traceability Current
- 2. Writing Requirements
- Overview
- 1 Functional requirements examples and templates
- 2 What Is a Product Requirements Document? A Complete PRD Guide
- 3 What Is a User Requirement Specification (URS)? How to Write and Manage One
- 4 Identifying and Measuring Requirements Quality
- 5 How to Write a System Requirements Specification (SRS) Document
- 6 The Fundamentals of Business Requirements: Examples of Business Requirements and the Importance of Excellence
- 7 Adopting the EARS Notation to Improve Requirements Engineering
- 8 What Is a Compliance Risk Assessment? Steps, Framework, and Examples
- 9 Jama Connect Advisor™
- 10 Frequently Asked Questions about the EARS Notation and Jama Connect Advisor™
- 11 How to Write an Effective Product Requirements Document (PRD)
- 12 Functional vs. Non-Functional Requirements
- 13 What Are Nonfunctional Requirements and How Do They Impact Product Development?
- 14 What Is a Software Design Specification? Key Components + Template
- 15 Characteristics of Effective Software Requirements and Software Requirements Specifications (SRS)
- 16 8 Do’s and Don’ts for Writing Requirements
- 17 Project Requirements: Types, Process, and Best Practices
- 18 INCOSE Guide to Writing Requirements
- 3. Requirements Gathering and Management Processes
- Overview
- 1 Requirements Engineering
- 2 Requirements Analysis
- 3 A Guide to Requirements Elicitation for Product Teams
- 4 Requirements Gathering Techniques for Agile Product Teams
- 5 Requirements Gathering in Software Engineering: Process, Techniques, and Best Practices
- 6 Defining and Implementing a Requirements Baseline
- 7 Managing Project Scope — Why It Matters and Best Practices
- 8 Requirements Decomposition and How AI Supports It
- 9 How Long Do Requirements Take?
- 10 How to Reuse Requirements Across Multiple Products
- 11 Requirements Prioritization Techniques: 7 Methods for Engineers
- 12 How to Run a Requirements Gathering Workshop
- 4. Requirements Traceability
- Overview
- 1 What Is Traceability in Product Development? A Guide for Regulated Teams
- 2 Tracing Your Way to Success: The Crucial Role of Traceability in Modern Product and Systems Development
- 3 Bidirectional Traceability: What It Is and How to Implement It
- 4 Change Impact Analysis (CIA): A Short Guide for Effective Implementation
- 5 What is Engineering Change Management (ECM)? A Complete Guide
- 6 What is Meant by Version Control?
- 7 Key Traceability Challenges and Tips for Ensuring Accountability and Efficiency
- 8 The Role of a Data Thread in Product and Software Development
- 9 Unraveling the Digital Thread: Enhancing Connectivity and Efficiency
- 10 What is a Traceability Matrix? A Guide to Requirements Traceability
- 11 How to Create and Use a Requirements Traceability Matrix (RTM)
- 12 Requirements Traceability Matrix Pros and Cons: A Practical Guide
- 13 Live Traceability vs. After-the-Fact Traceability
- 14 Overcoming Barriers to Live Requirements Traceability™
- 15 Requirements Traceability, What Are You Missing?
- 16 Requirements Traceability: Links in the Chain
- 17 What Are the Benefits of End-to-End Traceability During Product Development?
- 18 Requirements Volatility: 7 Essential Management Strategies
- 19 FAQs About Requirements Traceability
- 20 What Is AI Traceability? How to Implement It
- 21 Product Traceability for Regulated Industries: A Complete Guide to Audit-Ready Compliance
- 22 What Is the Traceability Information Model?
- 5. Requirements Management Tools and Software
- Overview
- 1 Selecting the Right Requirements Management Tools and Software
- 2 Why Investing in Requirements Management Software Makes Business Sense During an Economic Downturn
- 3 Why Word and Excel Alone is Not Enough for Product, Software, and Systems Development
- 4 Can You Track Requirements in Excel?
- 5 What Is Application Lifecycle Management (ALM)?
- 6 Is There Life After DOORS®?
- 7 Requirements Management Tools Jira
- 8 Checklist: Selecting a Requirements Management Tool
- 6. Requirements Validation and Verification
- 7. Meeting Regulatory Compliance and Industry Standards
- Overview
- 1 Understanding ISO Standards
- 2 Understanding ISO/IEC 27001: A Guide to Information Security Management
- 3 What is DevSecOps? A Guide to Building Secure Software
- 4 Compliance Management
- 5 What Is Functional Safety (FuSa)? Standards, Lifecycle, and Where Programs Fail
- 6 Failure Mode and Effects Analysis (FMEA) Explained
- 7 TÜV SÜD: Ensuring Safety, Quality, and Sustainability Worldwide
- 8 What is IEC 62443? A Guide to Industrial Cybersecurity
- 9 DFARS Compliance: A Guide for Defense Contractors
- 10 CMMC vs FedRAMP: What’s Different and Which One Applies to You
- 11 Automotive SPICE (ASPICE) 4.0: A Complete Guide
- 12 Restriction of Hazardous Substances (RoHS) Compliance Guide
- 13 MISRA C and MISRA C++ Explained: Rules for Safer Embedded Code
- 14 REACH Compliance for Product Engineering Teams
- 8. Systems Engineering
- Overview
- 1 What is Systems Engineering? A Guide for Modern Engineering Teams
- 2 How Do Engineers Collaborate? A Guide to Streamlined Teamwork and Innovation
- 3 The Systems Engineering Body of Knowledge (SEBoK)
- 4 What Is MBSE? Model-Based Systems Engineering Explained
- 5 Digital Engineering Between Government and Contractors
- 6 Digital Engineering Tools: The Key to Driving Innovation and Efficiency in Complex Systems
- 7 What Is Bill of Materials (BOM) Management? A Guide to Controlling Product Data
- 9. Automotive Development
- Overview
- 1 Understanding IATF 16949: A Quick Guide to Automotive Quality Management
- 2 What Is ISO 21434? Automotive Cybersecurity Engineering Explained
- 3 What Is ISO 26262? A Guide to Functional Safety in Automotive
- 4 What Is ASIL? A Guide to Automotive Safety Integrity Levels in ISO 26262
- 5 What Is SOTIF? A Guide to ISO 21448 for ADAS Safety
- 10. Medical Device & Life Sciences Development
- Overview
- 1 The Importance of Benefit-Risk Analysis in Medical Device Development
- 2 Software as a Medical Device: Revolutionizing Healthcare
- 3 What’s a Design History File, and How Are DHFs Used by Product Teams?
- 4 Navigating the Risks of Software of Unknown Pedigree (SOUP) in the Medical Device & Life Sciences Industry
- 5 What Is ISO 13485? A Guide to Medical Device Quality Management Systems
- 6 What Is a Device Master Record (DMR)? Definition and FDA Requirements
- 7 What Is IEC 62304? Medical Software Guide
- 8 ISO 13485 vs ISO 9001: Understanding the Differences and Synergies
- 9 What You Need to Know: ANSI/AAMI SW96:2023 — Medical Device Security
- 10 Failure Modes, Effects, and Diagnostic Analysis (FMEDA) for Medical Devices: What You Need to Know
- 11 Embracing the Future of Healthcare: Exploring the Internet of Medical Things (IoMT)
- 12 What Is General Safety and Performance Requirements (GSPR)? What You Need To Know
- 13 What Is IEC 62366? A Guide to Medical Device Usability Engineering
- 14 What Is the Quality Management System Regulation (QMSR)?
- 15 510(k) vs PMA: Differences in FDA Device Approval and Clearance
- 16 EU MDR Compliance Requirements and Timeline
- 17 Essential Performance Requirements and How to Identify Them
- 18 DHF vs DMR vs DHR: What Changed Under the FDA QMSR
- 19 Computer Software Assurance for Production and Quality Systems
- 20 IVDR Compliance: What Manufacturers Need to Know
- 21 IEC 60601-1 Guide for Medical Devices
- 22 A Guide to Medical Device Requirements Management
- 11. Aerospace & Defense Development
- Overview
- 1 What is ITAR Compliance? What Engineering Teams Need to Know
- 2 What Is DO-278A? A Guide for Compliance Teams
- 3 What Is a Safety Integrity Level (SIL)? How to Calculate and Apply It
- 4 A Guide to Aerospace Requirements Management
- 5 What Is ARP4754A? A Complete Guide to Civil Aircraft and Systems Development Assurance
- 6 Understanding ARP4761A: Guidelines for System Safety Assessment in Aerospace
- 7 What Is DO-254? A Complete Guide to Airborne Hardware Design Assurance
- 8 What Is DO-178C? A Guide to Airborne Software Certification
- 12. Architecture, Engineering, and Construction (AEC industry) Development
- 13. Industrial Manufacturing & Machinery, Automation & Robotics, Consumer Electronics, and Energy
- 14. Semiconductor Development
- 15. AI in Product Development
- Overview
- 1 What Is AI in Product Development? A Complete 2026 Guide
- 2 AI Test Case Generation: A Complete Guide for Regulated QA Teams
- 3 Using AI to Write Software Requirements: What Works and What Doesn’t
- 4 What Is the Model Context Protocol (MCP) for Requirements Management?
- 5 AI for Systems Engineering: Benefits, Risks, and How to Start
- 6 How to Automate Requirements Management
- 7 Artificial Intelligence in Requirements Management
- 16. Risk Management
- 17. Product Development Terms and Definitions
What Is the Quality Management System Regulation (QMSR)?
On February 2, 2026, the Food and Drug Administration (FDA) retired the Quality System Inspection Technique (QSIT), which was built around the legacy Quality System Regulation (QSR), and began inspecting medical device manufacturers under Compliance Program 7382.850 (CP 7382.850). Early QMSR inspections had been reported by May 2026, and FDA investigators may now request records once shielded from review, including management review and internal and supplier audit reports.
Manufacturers that treated the change as a naming update are already finding gaps. A design file that cleared years of QSR-era spot checks can still fail a records request that now reaches into management review minutes, supplier audit reports, or a risk file no one has touched since launch.
This guide covers what changed between the QSR and the QMSR, the core requirements now enforced under ISO 13485:2016, who the rule reaches, and the steps device teams are taking to close gaps before their next inspection.
What Is the QMSR?
The QMSR is the FDA’s amended current good manufacturing practice (CGMP) framework for medical devices, codified at Title 21 of the Code of Federal Regulations (CFR) Part 820. It incorporates by reference the International Organization for Standardization (ISO) medical device quality management system standard, ISO 13485:2016, and Clause 3 of ISO 9000:2015 for vocabulary. The incorporated text carries the force and effect of law, as though printed in the Code of Federal Regulations. FDA issued the final rule, published on February 2, 2024 (89 FR 7496), and it took effect two years later.
Under section 501(h) of the Federal Food, Drug, and Cosmetic Act (FD&C Act), the FDA treats a device that a manufacturer produces outside a compliant quality management system (QMS) as adulterated. Only Subparts A and B of Part 820 survive, six sections covering scope, definitions, incorporation by reference, QMS requirements, control of records, and labeling and packaging controls. The remaining subparts are reserved.
Why the FDA Replaced 21 CFR Part 820 With the QMSR
The amended rule harmonizes United States (US) device quality system requirements with international regulators. Regulatory authorities already use ISO 13485 as the foundation for their quality system requirements, including in harmonization programs such as the Medical Device Single Audit Program (MDSAP). The standard’s requirements are substantially similar to the QSR requirements FDA enforced for decades.
Enforcement began at the end of the two-year transition, and investigators may review QMS records created before the effective date when assessing compliance. That incorporation changes how Part 820 is inspected. Where the FD&C Act defines a term, the statutory definition supersedes the ISO definition.
What Changed Between the QMSR and the Legacy QSR
The QSR spanned 12 subparts. The QMSR keeps two and reserves the rest. Those renamed artifacts map one-to-one as follows.QMSR eliminates several legacy QSR record-type definitions, but the underlying documentation requirements remain largely captured within ISO 13485. The closest corresponding record concepts include:
| Legacy QSR Term | QMSR / ISO 13485 Equivalent |
| QSR | QMSR |
| Design History File (DHF) | Design and Development File |
| Device Master Record (DMR) | Medical Device File |
| Device History Record (DHR) | Batch or lot record |
The FDA also layered device-specific requirements onto the standard. Section 820.35 requires complaint records to capture, among other items, device name, date received, any Unique Device Identification (UDI) or other device identifier, complainant contact details, the nature and details of the complaint, corrective action taken, and any reply to the complainant. Complaint intake should be re-verified against those elements. A UDI record is also required for each device or batch.
Regarding labeling, the FDA retained its FDA-specific labeling and packaging controls beyond ISO 13485 and now requires that labeling and packaging be verified for accuracy before release, including the correct UDI or Universal Product Code (UPC) and expiration date. The removal of the old management-review and audit-report exemption opened management-review records, internal quality-audit reports, and supplier-audit reports to FDA review. Notified bodies and MDSAP auditors had already seen those records, so the FDA followed suit.
Core Requirements Under the QMSR
With ISO 13485:2016 as the operative text, the weight shifts to several connected quality system areas. Records must show a working QMS with updated terminology across these connected requirements:
- Management responsibility: Quality policy, measurable objectives, and management review must be documented.
- Design and development: Design controls, design files, verification, and validation must remain linked.
- Document and record control: Quality manual content, procedures, complaint records, and servicing records must be controlled.
- Corrective and Preventive Action (CAPA): CAPA initiation, prioritization, and evidence must be risk-based.
Risk-based thinking now runs through all of them rather than sitting in design validation alone. That shift changes how teams justify decisions regarding suppliers, production, post-market, and quality during inspections.
Management Responsibility and Quality Policy
Top management must establish a quality policy with measurable objectives and conduct management reviews fed by quality data and risk management activities. A management representative must remain in place, a role ISO 9001 dropped, and ISO 13485 kept. Inspection readiness now depends on showing how leadership reviews data, acts on risk signals, and keeps the QMS aligned with device and process performance.
Design and Development Controls
Medical device design controls now sit in ISO 13485’s design and development requirements. They still apply only to Class II and Class III devices, plus Class I devices automated with computer software and those listed in § 820.10(c). Each device type or family needs a Design and Development File, and manufacturers can continue using records built under the old requirements if they demonstrate compliance.
Document and Record Control
A quality manual must describe the QMS scope, documented procedures, and process interactions, with documents and records controlled in accordance with ISO 13485. Section 820.35 sits on top, so complaint and servicing records need the ISO controls plus the added federal detail.
Risk Management Expectations
Under the legacy QSR, risk management appeared only in § 820.30(g), within design validation. ISO 13485 spreads risk-based requirements across the quality system. Those requirements reach supplier controls, production processes, CAPA prioritization, and post-market surveillance.
Any appropriately validated risk-management process qualifies under the QMSR. ISO 14971 is not mandatory. Manufacturers must document risk-based decisions. Risk management still applies to Class I devices that are exempt from design controls. QMSR does not require manufacturers to use ISO 14971 specifically. Manufacturers must meet the risk-management and risk-based requirements incorporated through ISO 13485, and ISO 14971 remains an established framework that organizations can use to support those activities.
CAPA Provisions
CAPA obligations now come from ISO 13485’s CAPA provisions, which replace the legacy CAPA section. Corrective actions must be proportionate to the effects of the nonconformity and taken without undue delay, and manufacturers must demonstrate risk-based reasoning in initiating and prioritizing CAPAs.
Who Needs to Comply With the QMSR
Manufacturers marketing a finished device for human use in the United States generally must comply, unless the device’s FDA product code is listed as Good Manufacturing Practice (GMP)-exempt. A finished device is any device or accessory suitable for use or capable of functioning, whether or not it is packaged, labeled, or sterilized. The rule reaches beyond traditional manufacturers:
- Domestic and foreign finished device manufacturers: Foreign manufacturers account for a major share of the affected population, according to the FDA’s regulatory impact analysis.
- Contract manufacturers: Foreign contract manufacturers are included within that affected population, according to the FDA’s analysis, and each is responsible for the operations it performs.
- Specification developers, relabelers, and repackers: Firms that design devices without building them, or that repackage or relabel them, carry obligations for those functions.
- Initial distributors of foreign entities: Importers performing covered functions on behalf of foreign manufacturers must comply.
Component and part suppliers are excluded, though the FDA encourages voluntary compliance. Firms performing only covered operations comply only with the applicable requirements. Class I devices exempt from design controls still owe complaint file and record obligations.
Steps to Prepare for QMSR Compliance
Enforcement beganwill begin on February 2, 2026, so teams shouldcan use the transition sequence belowko as a remediation plan. Teams should check whether their evidence matches how investigators now inspect the QMS:
- Gap analysis scoped to QMS maturity: Teams without ISO 13485 certification need clause-by-clause mapping against the full standard, while certified teams can focus on FDA additions in §§ 820.35 and 820.45, along with related reporting and UDI regulations. For legacy designs, a documented gap analysis is a recommended way to assess alignment with QMSR. Retroactive changes are not clearly required by the available FDA-related guidance.
- Documentation updates with a terminology crosswalk: Internal naming conventions may remain, but manufacturers must comply with applicable ISO 13485:2016 requirements under QMSR, and mapping documentation to the ISO clause structure is a common preparation practice to demonstrate alignment.
- Training on the expanded inspection scope: Training should cover terminology mapping and the risk-based inspection approach.
- Internal audit against the new framework: The audit should confirm the content of complaint and servicing records and the completeness of UDI recordings.
- Design file and end-to-end traceability alignment: Verification and validation records should show that risk controls were tested and confirmed.
Paper-era files often fail at design file and traceability alignment. A file can be complete under the old checklist and still leave an inspector unable to trace a design output back through verification to its input and risk control. Teams should confirm that requirement changes, risk controls, design outputs, and test evidence stay connected as the device record evolves.
Common Challenges Manufacturers Face During the Transition
Early QMSR inspection focus areas include:
- Risk management: Teams must show documented reasoning behind quality system decisions.
- Outsourcing and purchasing: Supplier controls need evidence that matches the risk of the outsourced process or purchased product.
- Complaint handling: Complaint records need the added federal detail.
Some smaller manufacturers that sold only in the US market lack an established ISO 13485 system and face a steep learning curve in risk management. For teams that have never formally documented risk assessment, risk analysis, failure conditions, impact, and likelihood, the new emphasis can require more than terminology training. It changes how design, supplier, production, and post-market decisions are justified.
Maintaining separate quality systems for design and production complicates traceability and audit readiness. The strain grows when design sits with one site while manufacturing or a contract manufacturer holds the production records. A risk management file that hasn’t been updated since device release signals that risk management is disconnected from post-market quality functions.
Turning QMSR Compliance Into a Connected Workflow
Inspection readiness suffers when audit evidence lives in separate files. Jama Connect® from Jama Software® supports that workflow by keeping design, verification, and risk records connected. As requirements change, teams can keep audit-ready documentation available when an inspection starts. Its medical device framework aligns to ISO 13485:2016 and FDA design controls, and Live Traceability™ keeps linked records visible together. Review Center’s electronic signatures and audit-trail records support compliance with atisfy 21 CFR Part 11.
Keep QMSR Evidence Ready Before Inspection
The QMSR incorporates the 2016 edition of ISO 13485 as a static reference, so any future revision would require new FDA rulemaking to apply in the US. QMSR readiness is now an operating discipline for medical device teams. Teams need to know how Part 820 maps to ISO 13485:2016 and keep risk-based decisions documented. Inspection evidence should be available before an investigator asks for it.
If your team needs a more reliable way to keep QMSR records organized, Jama Connect supports that workflow in one place. A 30-day free trial shows how connected traceability supports QMSR readiness.
Frequently Asked Questions About QMSR
What is the difference between QMSR and QSR?
The QSR was a standalone FDA regulation written in the agency’s own language. QMSR uses ISO 13485:2016 as the operative quality system text and adds FDA-specific requirements for complaint records, servicing records, UDI, and labeling inspection. A rename-only approach is insufficient. A terminology crosswalk for SOPs and records helps teams test end-to-end traceability against the ISO clause an investigator will use.
When did the QMSR go into effect?
The QMSR became effective on February 2, 2026, two years after the final rule was published on February 2, 2024. Teams updating evidence after that date should keep requirements management and linked records organized for inspections. Inspection planning should also cover pre-effective-date records when those records help assess current compliance, including legacy gap analyses, management review records, audit reports, complaint records, and risk-based decisions.
Is ISO 13485 certification required under the QMSR?
No, certification isn’t required. The FDA won’t require or issue ISO 13485 certificates, and a certificate doesn’t exempt a manufacturer from inspection. MDSAP is the exception, since the FDA may accept MDSAP audit reports in place of routine surveillance inspections, but not for cause or premarket approval inspections. Certified medical device teams should still check FDA-specific additions in complaint, servicing, UDI, and labeling records before inspection.
How does the QMSR affect existing 510(k) submissions?
Existing clearances remain valid. Design documentation for new submissions must meet substantially the same requirements as under the QSR, since the QMSR realigned the framework around ISO 13485:2016 rather than changing the evidence a submission must contain. Before a new submission, teams should check that submission files and inspection records tell the same story. Jama Connect can help teams maintain that consistency across the Design and Development File. Existing 510(k) clearances remain valid. QMSR primarily changes the quality-system requirements manufacturers must follow and the framework FDA uses during inspection; it does not generally require a complete design and development file to be submitted as part of a standard 510(k). Manufacturers should maintain applicable design and development records under QMSR and provide specific QMS-related information when required by the submission type or applicable FDA guidance.
This article was authored by Mario Maldari and published on August 20, 2026.
Book a Demo
See Jama Connect in Action!
Our Jama Connect experts are ready to guide you through a personalized demo, answer your questions, and show you how Jama Connect can help you identify risks, improve cross-team collaboration, and drive faster time to market.