V5 Ultimate
Compliance · The complete guide

QMSR vs ISO 13485FDA Quality Management System Regulation vs ISO 13485:2016

TL;DR

FDA’s Quality Management System Regulation (QMSR) replaces the legacy QSR by incorporating ISO 13485:2016, aligning U.S. medical device QMS expectations to the international standard while retaining targeted FDA-specific obligations and terminology linkages important for inspections and enforcement.

Reviewed · By V5 Ultimate compliance team· 2,355 words · ~11 min read
AI · Explain it for MY operation

How does QMSR vs ISO 13485 apply to your shop floor?

Pick your industry and scale — Ask V5 rewrites the definition in your context, gives a worked example, and shows what V5 does on day one.

Your scale

01QMSR vs ISO 13485: What Changed and What Did Not

On February 2, 2024, FDA published the final rule (89 FR 7496) amending 21 CFR Part 820 to incorporate ISO 13485:2016 by reference as the Quality Management System Regulation (QMSR). The effective date is February 2, 2026, replacing the legacy Quality System Regulation (QSR) and formally aligning U.S. device quality expectations to the globally used ISO 13485 framework. FDA’s objective is regulatory convergence that reduces duplicative requirements without lowering the bar for safety and effectiveness.

QMSR means that, for most sections of Part 820, ISO 13485 clauses are now the controlling text. However, incorporation by reference does not erase FDA’s statutory authorities or cross-parts obligations. Certain U.S.-specific elements remain, including device reporting and records retention tied to federal statutes, as well as expectations around terminology familiar to FDA field investigators.

Practically, manufacturers with mature ISO 13485 systems will experience fewer structural changes and more emphasis on verifying FDA overlays and evidence linkages. Legacy QSR-only firms must modernize to ISO 13485’s risk-based process controls, supplier management, and postmarket integration, ensuring comprehensive documentation supports each lifecycle stage from design to complaint handling.

03FDA Overlays that Remain, and the Evidence FDA Expects

QMSR aligns core QMS expectations to ISO 13485, yet targeted U.S. overlays persist. Manufacturers must maintain device adverse event reporting under 21 CFR Part 803, and they should be prepared to demonstrate robust complaint handling, medical device reporting triage, and decision rationales. Unique Device Identification rules continue to govern device identification and traceability in labelling and records. Combination product pathways in 21 CFR Part 4 still define QMS expectations for drug-device and biologic-device products.

Electronic records and signatures used to meet QMSR obligations must satisfy 21 CFR Part 11 when applicable. This affects eDHF, eDHR, eDMR, CAPA workflows, and complaint handling systems. FDA will assess data integrity controls, access management, audit trails, and validated state of systems supporting quality records.

Inspection evidence should clearly show how risk management informs design inputs, verification and validation, process validations, supplier controls, and postmarket activities. Traceability matrices that link design inputs to outputs, verification, validation, and risk controls remain central. Device history records should demonstrate that each lot or unit met specified acceptance criteria and that UDI information is captured where applicable.

Maintain clear cross-references to retained FDA-specific requirements to avoid confusion under the new structure. Practical crosswalks in procedures can cite the relevant ISO 13485 clause alongside the applicable U.S. regulation. See 21 CFR 803, UDI DI vs UDI PI, and 21 CFR Part 11 for the most common overlays, and consult 21 CFR Part 4 for combination products as needed.

04Terminology Mapping: DMR, DHF, and DHR Under QMSR and ISO 13485

While QMSR incorporates ISO 13485 terminology, FDA continues to reference legacy QSR constructs such as the Device Master Record (DMR), Device History Record (DHR), and Design History File (DHF). ISO 13485 organizes equivalent evidence within documented information for design and development, production, and traceability records. Establish clear internal mappings so staff and auditors can navigate both vocabularies during inspections and supplier audits.

A practical approach is to maintain a controlled crosswalk in your document hierarchy. Quality plans should specify where ISO 13485 clauses are satisfied and which repositories hold the corresponding U.S.-recognized artifacts. Many firms implement an electronic DMS and eDHR solution to keep DHF, DMR, and DHR elements linked and searchable, with change control, training records, and audit trails in scope. See the eBMR/eDHR capability for examples of structured recordkeeping.

FDA QSR/QMSR termISO 13485 conceptTypical contents/evidenceInspection tip
Design History File (DHF)Design and development files (clause 7.3)Design plan, inputs/outputs, risk files, V&V, transfer, reviews, change recordsShow traceability from inputs to outputs, risk controls, and V&V evidence.
Device Master Record (DMR)Documented information for production and service (7.5), purchasing (7.4), validation (7.5.6)Specifications, drawings, BOM, assembly/packaging, work instructions, QC tests, labelingProve current revision control and alignment to released design outputs.
Device History Record (DHR)Records of production and traceability (7.5.1, 7.5.3, 7.5.9)Batch/unit history, dates, quantities, equipment, test results, UDI, release authorizationDemonstrate each lot/unit met acceptance criteria and is uniquely traceable.
Quality RecordsDocumented information and records (4.2.4, 4.2.5)CAPA, complaints, audits, calibrations, training, supplier performance, management reviewCorrelate trending to CAPA effectiveness and management review inputs.

Your procedures should define who curates each file, retention times, and the electronic systems of record. Consistent metadata, part numbers, and UDI linkages make retrieval faster, reduce audit friction, and strengthen evidence credibility during FDA and notified body audits.

05Risk Management, Design Controls, and Postmarket Integration

QMSR expects ISO 13485’s risk-based thinking to be operational, not rhetorical. Risk management per ISO 14971 must inform design inputs, verification and validation strategies, process validations, and acceptance activities. Complaint handling feeds the risk file with field data, creating a closed loop where postmarket insights recalibrate premarket controls. This is especially critical for software, diagnostics, and connected devices where updates and anomaly patterns evolve quickly.

Design control rigor remains unchanged in spirit: plans must define reviews, responsibilities, and interfaces. Inputs must be complete, unambiguous, and testable; outputs must be verifiable and suitable for production. Transfer requires demonstrable readiness of processes, training, equipment, and quality controls. Postmarket surveillance outcomes should be visible in management review, with measurable indicators that drive CAPA prioritization and effectiveness checks.

Clinical evaluation and usability engineering interact with risk management where applicable. For investigational devices, ISO 14155 provides a study governance baseline that supports design validation evidence. Ensure that residual risks and benefit-risk conclusions align with labeling and IFU claims, and that V&V traceability accounts for software versions, cybersecurity controls, and interface risks for connected systems.

Review your procedures to verify that the risk file is a living document, updated after significant nonconformities, CAPAs, or field actions. See ISO 14971 and its 2019/Amd1:2024 update for current expectations on benefit-risk, information for safety, and production/postproduction monitoring inputs.

06Software, Electronic Records, and 21 CFR Part 11 Under QMSR

QMSR does not independently redefine electronic records and signatures; it expects compliance with 21 CFR Part 11 where electronic systems fulfill regulatory recordkeeping. Consequently, system validation, data integrity controls, and audit trails must be proportionate to record criticality. This applies to eDHF/eDHR, CAPA, complaint handling, training, calibration, and supplier quality platforms used to meet QMSR clauses.

Define intended use, risk, and validation depth for each GxP-relevant system. Include security roles, identity controls, versioning, back-up and restore testing, and change management. For hybrid approaches where paper and electronic coexist, clarify the record of truth and reconcile signatures, timestamps, and attachments. Poorly defined hybrid records can create gaps in traceability and data integrity during inspections.

Link record metadata to product, lot, and UDI attributes to enable fast retrieval and trending. Design user interfaces that lower error rates in production data capture and ensure real-time status for release decisions. Routine audit trail reviews should be risk-based and supported by documented procedures and training records. A clean chain of custody for data makes FDA and notified body audits faster and more predictable.

If you operate with mixed media, consult the hybrid record system entry for governance considerations, and align your Part 11 approach with your policies and infrastructure. Maintain a change record showing how updates to applications, infrastructure, and configurations preserve validated state. For cyber-physical systems, map device software versions to released configurations and production controls for traceability.

07Global Alignment: EU MDR/IVDR, ISO 9001, and Related Frameworks

By anchoring Part 820 to ISO 13485, FDA has narrowed divergence with major jurisdictions that already rely on ISO 13485 for device QMS expectations. While EU MDR and IVDR impose additional regulatory requirements beyond the QMS, their quality foundation harmonizes with ISO 13485, streamlining multi-market compliance strategies. Manufacturers can now operate a single, global QMS core with targeted regional overlays.

ISO 9001 remains relevant for enterprise-level quality culture and process methods, but it is not device-specific and lacks several controls critical to medical technology. Device makers should treat ISO 13485 as the governing standard for design and manufacturing controls, and, where applicable, integrate clinical, vigilance, and economic operator requirements per EU MDR and IVDR. Over time, QMSR’s alignment should reduce redundant audits, documentation, and training complexity.

Firms preparing for EU submissions should note data and traceability expectations for EUDAMED, UDI-DI and UDI-PI, and postmarket surveillance system linkages. Those same datasets reinforce FDA inspections when structured consistently. Document your jurisdictional overlays, and make your evidence portable across notified body and FDA reviews to accelerate remediation and reduce variability.

For orientation on quality frameworks and organizational maturity, see ISO 9001. Planning for the EUDAMED device database and UDI requirements relates to U.S. UDI concepts, including UDI DI vs UDI PI. For timing considerations around EU infrastructure, monitor entries such as MDR EUDAMED mandatory 2026 and IVDR-related transitions.

08Common Pitfalls, Misinterpretations, and FDA Inspection Focus

Early QMSR inspections will test whether firms simply re-labeled procedures or truly implemented risk-based integration. Investigators will follow the thread from design inputs to verification and validation, process validation, supplier controls, acceptance activities, and complaint handling, verifying that each linkage is traceable in records. They will also assess whether electronic systems meet Part 11 expectations and whether data integrity and change control are robust.

Misinterpretations tend to arise in three areas: assuming ISO certification is sufficient for FDA compliance, underestimating supplier quality responsibilities, and failing to update risk files with postmarket signals. Additionally, mapping confusion between DMR/DHF/DHR and ISO documented information can cause retrieval delays and incomplete evidence during inspections.

  • Treating ISO 13485 certification as a substitute for QMSR compliance evidence.
  • Risk files that are static and do not absorb complaints, service data, and CAPA outcomes.
  • Process validation protocols that do not reflect worst-case materials, software versions, or equipment states.
  • Supplier controls that lack risk-based qualification, monitoring, and incoming acceptance tied to critical characteristics.
  • Hybrid records without a declared record of truth, leading to signature and version mismatches.
  • Management reviews that summarize metrics but do not drive resourcing or CAPA effectiveness decisions.

To mitigate these risks, strengthen your supplier quality plan and align it to product and process risk; see supplier risk management. Make management review a closed-loop governance forum that allocates resources to the highest risks and tracks action effectiveness to completion. Ensure your document map explains where FDA-recognized artifacts reside and test retrieval drills before an inspection begins.

Finally, rehearse end-to-end data trails for two or three representative products and lots, including UDI capture, acceptance results, nonconformance handling, and release authorization. This reveals systemic gaps before investigators do.

09How QMSR Interacts with Neighboring Frameworks and Cross-References

QMSR’s incorporation of ISO 13485 does not stand alone. It must be read with the device statutory framework and neighboring regulations and standards. Device reporting obligations under Part 803, corrections and removals, registration and listing, UDI and labeling, and combination product rules continue to operate. Standards like ISO 14971 for risk management and ISO 14155 for clinical investigation provide the technical underpinnings for design control evidence and benefit–risk justifications.

For organizations that previously followed only QSR, adopting ISO 13485’s structure changes how procedures and forms are grouped and where responsibilities are assigned. For those long aligned to ISO 13485, the principal task is to evidence FDA overlays with precise cross-references. A written crosswalk maintained under change control is invaluable during inspections and helps new staff navigate requirements efficiently.

Consider your inspection-readiness posture by validating the end-to-end path from design planning through supplier qualification, production acceptance, and complaint handling. A risk-based internal audit program should prioritize the highest patient and product risks, then drill into the associated process controls and records. When electronic systems support these controls, Part 11 validation and data integrity reviews are part of your readiness story.

As you tune policies and SOPs, monitor updates to the ISO 13485 corpus and related guidance like the 2024 amendment; see ISO 13485 2024 amendment. Also ensure your strategic quality plan aligns with organizational frameworks such as ISO 9001 where appropriate, while keeping the device-specific ISO 13485 controls primary.

10Transition Planning, Milestones, and How V5 Supports QMSR Implementation

A structured transition plan prevents late-stage surprises. Begin with a clause-by-clause gap assessment from ISO 13485 to your current procedures, then identify FDA overlays and record evidence needed to satisfy QMSR. Prioritize changes that affect patient risk or release decisions, and implement governance to manage training, change control, and communication. Build a crosswalk mapping DMR, DHF, and DHR constructs to ISO documented information and declare repositories and owners.

Translate the plan into measurable milestones, such as completing supplier risk reclassification, validating critical electronic systems, and proving traceability matrices on representative products. Schedule mock inspections to verify retrieval speed, completeness of evidence, and leadership fluency on management review outputs. Align your CAPA backlog with transition risks so remediation improves both compliance and product performance signals.

  1. Perform a documented ISO 13485 gap assessment against current procedures and records.
  2. Define an FDA overlay map for 21 CFR Parts 803, 11, UDI, and combination products as applicable.
  3. Validate and lock down electronic systems supporting QMSR records with risk-based Part 11 controls.
  4. Requalify critical suppliers and update incoming acceptance to match risk and design outputs.
  5. Prove DMR/DHF/DHR to ISO mapping with end-to-end retrieval drills and UDI traceability.

Use platform capabilities that reduce administrative load while preserving data integrity and inspection readiness. Leverage dashboards to monitor progress to the 2026 milestone, and ensure role-based access promotes accountability for each workstream. Embed risk, design, production, and postmarket linkages into everyday workflows rather than sidecar trackers.

Frequently asked questions

Q.What is the effective date for FDA’s QMSR and what happens until then?+

QMSR takes effect on February 2, 2026. Until then, firms should complete gap assessments, implement ISO 13485–aligned procedures, validate electronic systems, and retain compliance with existing obligations such as MDR reporting.

Q.Does ISO 13485 certification alone prove compliance with QMSR?+

No. FDA evaluates processes and records under U.S. law. A certificate can indicate maturity, but you must demonstrate compliance with FDA-specific overlays and produce objective evidence at inspection.

Q.How do DMR, DHF, and DHR map to ISO 13485 terms?+

DHF aligns with design and development files under clause 7.3, DMR aligns with documented information for production and service, and DHR aligns with production and traceability records. Maintain a controlled crosswalk and clear repositories.

Q.What FDA requirements remain outside ISO 13485 under QMSR?+

Medical device reporting under 21 CFR Part 803, UDI and labeling obligations, combination product rules, and 21 CFR Part 11 for electronic records remain applicable. Corrections and removals and registration rules also continue.

Q.How should we handle electronic records for QMSR compliance?+

Apply risk-based 21 CFR Part 11 controls: define intended use, validate systems, manage access and audit trails, and declare the record of truth in hybrid environments. Keep change control and data integrity central.

Q.What inspection evidence will FDA expect under QMSR?+

Risk-based traceability from design inputs to V&V and production, validated processes, supplier controls, complete DHRs with UDI where applicable, and robust complaint handling with MDR triage and rationales. Rapid retrieval is essential.

Q.How does QMSR relate to EU MDR/IVDR requirements?+

EU MDR/IVDR build on ISO 13485 but add regulatory elements such as economic operator responsibilities and PMS reporting. A single ISO 13485–based core with regional overlays supports both FDA and EU pathways.

Primary sources

Further reading

See QMSR vs ISO 13485 working on a real shop floor

V5 Ultimate ships with the QMSR vs ISO 13485 controls already wired in — audit trail, e-signatures, validation evidence. Free trial, no credit card, onboard in days, not months.