The Quality Management System Regulation officially took effect on February 2, 2026, replacing the Quality System Regulation that governed medical device manufacturers for decades. The QMSR incorporates ISO 13485:2016 by reference, aligning the FDA’s manufacturing requirements with the international standard used by regulators around the world. Alongside that shift, the FDA replaced its long-standing Quality System Inspection Technique with a new inspection process described in Compliance Program 7382.850, retiring the older compliance program documents that governed device and premarket approval inspections.

Several months into enforcement, a clearer picture is emerging of how these inspections actually run. For manufacturers holding ISO 13485 certification, or working toward it, the changes carry real implications for how audit-ready they need to be at all times, not just before a scheduled inspection.

The Inspection Framework Has Been Restructured

Under the old system, FDA investigators worked through four QSIT subsystems: management controls, design controls, corrective and preventive actions, and production and process controls. The new compliance program replaces that structure with a risk-based strategy that organizes requirements into six Quality Management System Areas and four Other Applicable FDA Requirements, with each area built from individual elements tied to specific regulatory requirements.

In practice, this means investigators are no longer sampling one subsystem at a time. They are now expected to evaluate how an organization’s entire quality system manages risk across the full product lifecycle, from design through post-market activity, which brings FDA inspection logic closer to how Notified Body and MDSAP audits already operate.

Manufacturers preparing for ISO 13485 audits should treat this as a meaningful shift in scope, not a cosmetic rename of the old framework.

Risk Documentation Is Now the Starting Point

One of the more notable changes reported since enforcement began is where investigators start. Rather than moving through fixed subsystems, investigators are now expected to begin with a company’s risk management file, using it to determine the intended use of the device, the risks tied to patients and users, and how well those risks are addressed consistently across design, production, suppliers, and post-market processes. That file effectively becomes the roadmap for the rest of the inspection.

This places added weight on how well a company’s risk management documentation connects to the rest of its quality system. A risk file that exists on its own, disconnected from design records, supplier files, and CAPA data, is likely to draw more scrutiny than one that clearly ties those pieces together.

Internal Audits and Management Reviews Are Getting a Closer Look

Under the old regulation, certain internal records, including some management review and internal audit discussions, carried a degree of practical insulation from routine FDA review. Under the new compliance program, the FDA has clarified that internal quality audits and management reviews are explicitly listed as elements within the QMS Areas being evaluated, and supplier audit reports are also subject to review during inspections.

This is a meaningful shift from how many organizations previously treated these activities, since management review and internal audit records had often been viewed as somewhat separate from direct FDA scrutiny. Companies should assume that findings, escalation decisions, and how leadership engaged with those findings are all now fair game during an inspection, not just the fact that the review or audit took place.

For organizations that haven’t reassessed how thoroughly they document these activities, this is a good area to revisit before the next inspection cycle, particularly with support from ISO 13485 internal auditor training that reflects the current expectations.

Historical Records Are Fair Game Too

Investigators are not limited to reviewing records created after the QMSR took effect. FDA investigators may review records that are part of a manufacturer’s quality management system, including those created before February 2, 2026, when determining compliance with the new regulation. Manufacturers should treat older documentation as something that still needs to hold up under current expectations, rather than something that’s effectively grandfathered in.

Cybersecurity Is Now Part of the Inspection Scope

Software-enabled and connected devices are drawing additional attention during inspections. Consistent with cybersecurity provisions from the Food and Drug Omnibus Reform Act of 2022, the updated compliance program directs investigators to review cyber devices and other software-enabled products for conformity with FDA’s cybersecurity requirements, with failures in this area capable of leading to significant findings and enforcement action.

Manufacturers of connected or software-driven devices should expect this to be a standing part of future inspections rather than a one-time area of focus.

ISO 13485 Alignment Doesn’t Cover Everything

A recurring theme in early QMSR enforcement is that ISO 13485 conformance, on its own, isn’t the full picture. While ISO 13485:2016 is incorporated by reference into U.S. law, FDA-specific statutory and regulatory requirements remain fully enforceable, meaning obligations tied to unique device identification, medical device reporting, device listing, and labeling controls all continue to apply on top of the standard.

Because QMSR aligns so closely with ISO 13485:2016, some organizations have assumed their existing ISO certification carries them through an FDA inspection without additional work, an assumption that can create blind spots, particularly around FDA-specific obligations layered into the new framework. The gap for most manufacturers isn’t a missing process. Document control, CAPA, supplier management, complaints, training, and internal audits are usually already in place. The question is whether those existing processes fully account for the FDA-specific requirements that sit alongside ISO 13485.

This is a useful checkpoint for any organization that has treated its ISO 13485 certification as the finish line rather than one part of a broader compliance picture.

What This Means for Your Next Inspection

A few practical takeaways stand out from the first several months of QMSR enforcement:

  • Your risk management file needs to tell a coherent story. Since it’s the likely starting point for an inspection, it should connect clearly to design, production, supplier, and post-market records rather than standing alone.
  • Internal audits and management reviews need to reflect real substance. Investigators are now expected to look at whether these activities identify genuine issues and drive follow-through, not just whether they occurred on schedule.
  • Older records still matter. Documentation created before February 2, 2026 can still be reviewed, so it needs to hold up against current expectations.
  • Software and connected devices carry added scrutiny. Cybersecurity documentation should be treated as a standing inspection topic.
  • ISO 13485 conformance is necessary but not sufficient. FDA-specific requirements around labeling, UDI, and medical device reporting still need dedicated attention.

How Cavendish Scott Can Help

Cavendish Scott has spent more than 40 years helping organizations build quality management systems that hold up to scrutiny, not just pass a single audit. Our team supports medical device manufacturers through ISO 13485 consulting, ISO 13485 internal auditing, and ISO 13485 internal auditor training built around how inspections and audits are actually conducted today.

If your organization hasn’t reassessed its risk management documentation, internal audit depth, or FDA-specific obligations since QMSR took effect, now is a good time to do so. Reach out to Cavendish Scott to discuss where your quality system stands.

Sources

Scroll to Top