El 2 de febrero de 2026, la Food and Drug Administration (FDA) de EE. UU. implementó la nueva Quality Management System Regulation (QMSR), sustituyendo formalmente a la anterior Quality System Regulation (21 CFR Part 820). Con esta transición, la FDA incorporó por referencia la ISO 13485:2016 a la legislación estadounidense e introdujo un nuevo modelo de inspección en el marco del Compliance Program 7382.850.
This article focuses on that second question. It explains how to structure a QMSR gap analysis, which areas almost always reveal gaps in practice, particularly for IVD and companion diagnostic manufacturers, and what FDA inspectors are finding in the first wave of QMSR inspections.
The insights below draw directly on MDx CRO’s quality and regulatory affairs experience supporting IVD manufacturers through QMSR readiness assessments.
Key point: ISO 13485 certification does not equal QMSR compliance. FDA-specific requirements remain fully enforceable, and under QMSR, inspectors now access records they previously could not.
Why the FDA QMSR Matters Beyond the February 2026 Deadline
The February deadline was the starting point, not the finish line. FDA’s Compliance Program 7382.850 is now the active inspection model. Manufacturers operating under the assumption that QMSR readiness was a one-time transition exercise are exposed to a different enforcement environment than the one they prepared for.
Under the former QSR model, inspections used QSIT subsystem checklists. Under QMSR, investigators evaluate how quality processes function as an integrated lifecycle framework, not whether each subsystem satisfies an individual checklist. That structural shift changes what inspectors look for and what they find.
Inspection change: FDA inspectors can now access internal audit reports, management reviews, and supplier audits. Under the previous QSR model, these records were largely outside inspection scope. Many manufacturers are unaware of this shift and have not reviewed the quality or completeness of these documents with inspection readiness in mind.
MDSAP Audit Approach 2026: How It Differs from FDA Inspections Under QMSR
MDSAP audits and FDA inspections serve fundamentally different regulatory functions and must not be conflated.
An MDSAP audit is conducted by an FDA-recognized Auditing Organization. It assesses conformity with harmonized quality management system requirements — ISO 13485 and the regulatory requirements of participating authorities including FDA. It is scheduled, structured, and conformity-focused. Participation remains voluntary.
An FDA inspection is a statutory enforcement activity conducted directly by FDA investigators. Its objective is not certification — it is the evaluation of compliance with US legal requirements and the identification of potential violations, systemic weaknesses, or public health risks.
| MDSAP audit | FDA inspection (CP 7382.850) |
|---|---|
| Conformity-focused | Compliance-driven and enforceable |
| Scheduled and structured | Risk-based, for-cause, or routine |
| Bound by MDSAP task structure | Not limited by MDSAP scope or sampling |
| Outcome: certification report | Outcome: Form 483 / warning letter / no action |
| Internal records may not be reviewed | Internal audits, supplier audits, management reviews now in scope |
Strong MDSAP performance may influence FDA surveillance planning. It does not eliminate the possibility of inspection, nor does it guarantee a favourable outcome when one occurs.
Common Assumptions That Increase Inspection Risk
Several structural misconceptions remain widespread. Under QMSR, these assumptions translate directly into inspection exposure.
- «MDSAP replaces FDA inspections.» It informs surveillance planning. It does not limit FDA’s statutory authority.
- «If the MDSAP auditor didn’t find it, FDA won’t pursue it.» FDA investigators are not constrained by MDSAP audit depth or task sequencing.
- «ISO 13485 certification ensures FDA compliance.» ISO 13485 is incorporated by reference into QMSR, but FDA-specific requirements — UDI, MDR, device listing, labeling controls — remain fully enforceable and are not covered by ISO 13485 alone.
- «QMSR was a documentation update.» For ISO-certified manufacturers, many gaps are substantive — missing FDA-required record content, incomplete UDI integration, absent MDR linkage — not cosmetic.
QMSR vs QSR vs ISO 13485: What Actually Changed
QMSR incorporates ISO 13485:2016 by reference into US law. That is a structural alignment, not a reduction in FDA enforcement authority. Obligations related to UDI, MDR, device listing, and labeling controls continue to apply in full.
| Element | Former QSR (21 CFR 820) | FDA QMSR (2026) | ISO 13485:2016 |
|---|---|---|---|
| Legal status | US regulation | US regulation (ISO 13485 incorporated by reference) | International standard |
| Inspection model | QSIT subsystem checklists | CP 7382.850 — lifecycle, risk-based | Certification audit |
| Internal audit access | Limited under §820.180(c) | Internal audits and management reviews reviewable | Auditor access at certification |
| CAPA focus | Cumplimiento procedimental | Demonstrated effectiveness + root cause verification | Effectiveness required |
| FDA-specific requirements | Totalmente integrados | UDI, MDR, labeling still fully enforceable | No incluidos |
Takeaway: ISO 13485 alignment does not eliminate FDA-specific compliance obligations. A manufacturer can hold ISO 13485 certification and still have substantive QMSR gaps.
FDA Compliance Program 7382.850: How Inspections Work
As of 2 February 2026, FDA retired QSIT and implemented Compliance Program 7382.850. Inspections are now organised around six integrated QMS areas and four Other Applicable FDA Requirements (OAFRs).
| Six QMS areas | Four OAFRs |
| Change Control | Unique Device Identification (UDI) |
| Design & Development | Medical Device Reporting (MDR) |
| Management Oversight | Corrections & Removals |
| Outsourcing & Purchasing | Tracking |
| Production & Service Provision | |
| Measurement, Analysis & Improvement |
Under this model, FDA evaluates how quality subsystems operate as an interconnected framework — not as isolated elements. Inspectors assess whether risk information, design decisions, post-market data, and management oversight are aligned throughout the product lifecycle.
The Four Areas That Almost Always Reveal Gaps
Across QMSR gap assessments conducted on IVD and medical device manufacturers, four areas surface as gaps with consistent regularity — even in organisations that have maintained ISO 13485 certification for years.
1. Complaint handling and servicing records
Many companies aligned with ISO 13485 underestimate the level of record detail FDA expects. Under QMSR, complaint and servicing records must include specific, enumerated data fields that ISO 13485 does not explicitly define. Records are often incomplete from an FDA perspective even when they satisfy the certification standard.
2. UDI traceability and record integration
UDI compliance is not simply a matter of having a UDI assigned and registered in GUDID. QMSR requires the UDI to be consistently recorded across multiple record types: complaints, servicing records, and batch or device history records. That level of cross-system integration is frequently missing — particularly in manufacturers who completed UDI registration without reviewing how UDI flows through their quality records.
3. Labeling and packaging controls
FDA maintains specific requirements for label content — including UDI, expiry dates, and handling instructions — and expects documented procedures designed to ensure accuracy and prevent mix-ups. These requirements are often handled informally or through processes that do not meet FDA’s explicit documentation expectations, even when the labels themselves are technically correct.
4. Linkage between ISO processes and FDA regulatory requirements
This is the gap that most consistently surprises ISO-certified organisations. A company may have complaint handling aligned with ISO 13485 clause 8.2.2 and consider that requirement closed — but fail to explicitly connect that process to Medical Device Reporting obligations under 21 CFR Part 803. FDA does not treat ISO conformity as a substitute for regulatory linkage. Each process must demonstrably connect to the applicable FDA requirement in the documentation.
«Companies often assume that having a robust ISO-aligned procedure is sufficient. What we find in practice is that the procedure exists — but there is no explicit documented connection between that procedure and the FDA-specific obligation it is meant to fulfil. That gap is invisible until an inspector asks for it.»
Joana Martins, QA/RA Specialist, MDx CRO
Why QMSR Gap Analysis Is More Complex for IVD and CDx Manufacturers
ISO 13485 and QMSR do not formally distinguish between device types. However, the nature of IVDs fundamentally changes which gaps are most consequential and how difficult they are to close.

A QMSR gap analysis for an IVD manufacturer must extend beyond traditional quality system elements. It needs to integrate scientific validity, analytical performance, and clinical evidence into the assessment framework. Where a general medical device gap analysis evaluates whether a product is designed, manufactured, and controlled to ensure safety and functional performance, an IVD-focused analysis must additionally verify that the product generates clinically reliable results under real-world biological variability.
| Area | General medical device | IVD / CDx — additional complexity |
|---|---|---|
| Design controls | User needs, design inputs, outputs, V&V | Intended use, specimen type, analyte definition, performance claims must link to analytical and clinical data |
| Risk management | Device failure modes | Must also cover false positive and false negative results, diagnostic decision risks, interfering substances, matrix effects |
| Production controls | Process validation, specifications | Lot-to-lot variability of biological materials must be validated against clinically relevant performance criteria |
| Post-market surveillance | Complaint handling, MDR | Must detect performance drift — shifts in sensitivity or specificity — not just product failures |
| Purchasing controls | Supplier qualification | Supplier variability can directly affect assay performance outcomes |
«For IVDs, failures may not manifest as product defects — they manifest as clinically incorrect results. That is a more insidious form of non-compliance, and it means the risk management and design control documentation needs to work harder than it does for a general medical device.»
Joana Martins, QA/RA Specialist, MDx CRO
What FDA Is Finding in QMSR Inspections: Warning Letter Patterns
Recent warning letters issued by CDRH following QMSR inspections show a consistent pattern. Deficiencies are not isolated — they are interconnected, reflecting a failure to operate an effective integrated quality system rather than individual documentation gaps.
| Finding category | Most common deficiency pattern |
| CAPA | Procedures not defined or inadequate; failure to investigate root causes; CAPAs not verified for effectiveness |
| Complaint handling | Complaints not properly documented or evaluated; failure to assess whether complaints are reportable under MDR; no complaint trending or statistical analysis |
| Design controls | Lack of design verification and validation; poor documentation of design changes and their impact; no design and development plan or procedure |
| Supplier controls | Lack of defined quality requirements that suppliers must meet; no risk-based audit justification |
| Process validation | Manufacturing processes not validated; no revalidation after changes; validation protocols incomplete or not scientifically justified |
| Management responsibility | Management not actively involved in QMS; no effective management review with documented decisions and follow-up |
Important: The FDA has clarified that if previous inspections were conducted under the QS Regulation (prior to 2 February 2026), any corrective actions proposed or implemented must now be pursued pursuant to QMSR requirements — not the former QSR standard.
What FDA Inspectors Scrutinize Most
Based on regulatory inspection support experience, three documentation areas present heightened exposure under QMSR.
1. Internal audits, supplier audits, and management review records
Under QMSR, FDA inspectors may review internal audit reports, supplier audit outcomes, and management review records. Investigators evaluate whether quality processes function effectively in practice — not merely whether procedures formally exist. Records must clearly demonstrate identified issues, root cause analysis, corrective actions, and documented closure. Incomplete or draft audit records increase inspection risk.
2. Design controls and traceability (ISO 13485 clause 7.3)
Manufacturers must demonstrate full traceability across user needs, design inputs, design outputs, verification and validation, and residual risks. Traceability weaknesses frequently arise at the interfaces between risk management files, labeling claims, UDI triggers, and MDR criteria. For companion diagnostics, this alignment is especially critical because intended use, biomarker claims, and clinical evidence directly impact regulatory risk classification.
3. CAPA and effectiveness verification
CAPA remains one of the most enforcement-sensitive areas under QMSR. The most common weakness is the absence of documented effectiveness verification following corrective actions. Closing a CAPA administratively — marking it complete without objective evidence that the root cause was eliminated — is insufficient. Investigators expect evidence demonstrating that actions prevented recurrence.
Inspection Risk Indicators
| Risk area | Typical vulnerability |
| CAPA | Problemas repetidos sin verificación de eficacia documentada |
| Design controls | Trazabilidad incompleta entre el análisis de riesgos y las entradas de diseño |
| Management review | Actas sin decisiones, métricas o acciones de seguimiento documentadas |
| Supplier oversight | No risk-based justification for audit scope; missing quality requirements for suppliers |
| Post-market surveillance | Tendencias de quejas no vinculadas a CAPA ni a actualizaciones de diseño |
| UDI | Not consistently recorded across complaints, servicing records, and device history records |
| MDR linkage | Complaint handling procedures not explicitly connected to MDR reporting obligations |
How to Conduct a QMSR Gap Analysis: Process and Timeline
ISO 13485 certification does not automatically confirm FDA QMSR compliance. A structured gap analysis identifies the regulatory overlays and inspection exposure points that ISO conformity alone leaves unaddressed.
What a QMSR gap analysis covers
A thorough assessment works through four stages:
- Clause mapping: Map ISO 13485 clauses to QMSR references. Confirm terminology alignment. Identify where the QMSR adds FDA-specific requirements beyond the ISO standard.
- FDA-specific overlay identification: Verify explicit incorporation of UDI requirements across all applicable record types, MDR reporting triggers and their linkage to complaint handling, labeling obligations under 21 CFR Part 801, and device listing and registration controls.
- Documentation exposure review: Assess internal audit completeness and whether records are inspection-ready, CAPA effectiveness evidence, management review decision traceability, and supplier risk classification and audit justification.
- Risk prioritisation and remediation planning: Each gap is assessed for potential impact on quality, business continuity, and regulatory standing. Higher-risk gaps — those most likely to generate Form 483 observations or warning letters — are prioritised for remediation with assigned ownership and timelines.
How long does it take?
A gap analysis typically takes 4–6 weeks, provided documentation is made available at the outset. Implementation of corrective actions depends on the number and severity of findings and on the responsiveness of the internal team.
For manufacturers with both QMSR and ISO 13485 gaps, implementation may take 4–5 months. Where gaps are limited to QMSR-specific requirements in an otherwise ISO-aligned system, the timeline is typically shorter.
The ISO 13485 certification gap — what ‘compliant’ actually means
A persistent scenario in QMSR readiness work: a manufacturer holds ISO 13485 certification, has documented procedures that appear robust, and believes ISO alignment is sufficient. Gaps emerge in missing FDA-required data fields in records, incomplete UDI implementation, and failure to link ISO processes to FDA regulatory requirements.
They are structurally compliant with ISO but not fully aligned with FDA expectations. The distinction matters: an FDA inspector is not evaluating conformity to a certification standard. The inspector is evaluating compliance with US law and assessing whether the quality system actually functions as an integrated framework.

Download
QMSR Gap Assessment Checklist for IVD and CDx Manufacturers — A structured reference document developed by the MDx CRO quality team.
Practical Implications for Manufacturers
Inspection scope may be data-driven. FDA may use pre-inspection data reviews to target areas of concern, increasing scrutiny where trends or inconsistencies are identified.
FDA inspectors are evaluating how quality processes work together in practice — not whether each subsystem satisfies a checklist in isolation.
Previously internal records are now fair game. Internal audit reports, supplier audit outcomes, and management review records may be reviewed. These documents must reflect issues identified, decisions made, and actions taken.
Risk management must be continuous and demonstrable. FDA expects risk to be actively monitored and linked to CAPA, design changes, supplier controls, and post-market surveillance — not treated as a static exercise.
Post-market data is a primary inspection focus. Complaint trends, MDR, recalls, UDI, and tracking data are increasingly used to assess whether the quality system is effective and responsive.
Cómo MDx apoya la preparación para la FDA QMSR: visión experta
La transición de QSR a FDA QMSR requiere más que actualizar la terminología. Exige alineación estructural y preparación orientada a inspecciones.
Basándose en la experiencia de campo apoyando a fabricantes en la preparación para inspecciones y en proyectos de alineación regulatoria, Joana Martins, especialista en QA/RA en MDx, destaca que las vulnerabilidades más frecuentes no provienen de procedimientos ausentes, sino de una eficacia del sistema insuficientemente demostrada.
Según la experiencia de Joana en preparación para inspecciones, las organizaciones suelen subestimar tres puntos de exposición durante la preparación para inspecciones de la FDA:
- La profundidad de la revisión de documentación ahora permitida bajo la QMSR
- La necesidad de trazabilidad entre la gestión de riesgos, los controles de diseño y los datos poscomercialización
- La importancia de la verificación documentada de la eficacia dentro de los sistemas CAPA
Para abordar estos puntos de exposición, MDx apoya a los fabricantes de productos sanitarios mediante:
- Evaluaciones independientes de preparación alineadas con QMSR, centradas en la exposición durante inspecciones
- Análisis estructurados de brechas de la QMSR que incorporan añadidos regulatorios específicos de la FDA
- Inspecciones simuladas de la FDA alineadas con el Compliance Program 7382.850
- Apoyo estratégico para empresas que desarrollan diagnósticos complementarios de la FDA, donde la trazabilidad del diseño, los controles de etiquetado y la integración de datos del ciclo de vida requieren una coherencia regulatoria reforzada
En lugar de abordar la FDA QMSR como una actualización documental, MDx trabaja con las organizaciones para garantizar que sus sistemas de calidad demuestren integridad operativa, toma de decisiones basada en riesgo y resiliencia ante inspecciones.
Las organizaciones que se preparan para una inspección de la FDA o evalúan su alineación con la QMSR pueden beneficiarse de una evaluación temprana y estructurada. La evaluación proactiva reduce los plazos de remediación, minimiza la interrupción por inspecciones y refuerza la confianza regulatoria.
Preguntas frecuentes sobre la FDA QMSR, MDSAP y las inspecciones
La principal diferencia es la alineación estructural. Bajo QSR, los requisitos de la FDA estaban redactados directamente en 21 CFR Part 820. Bajo QMSR, la FDA incorpora ISO 13485:2016 por referencia a la legislación estadounidense, manteniendo vigentes las obligaciones específicas de la FDA. En resumen, la QMSR armoniza la estructura con la ISO 13485. Sin embargo, no reduce la autoridad de aplicación de la FDA ni elimina requisitos específicos de EE. UU. como MDR, UDI o el registro/listado de dispositivos.
No. Aunque la ISO 13485 constituye la base de la QMSR, los requisitos legales específicos de la FDA siguen aplicándose. Los fabricantes deben cumplir con MDR, correcciones y retiradas, UDI y otras obligaciones de EE. UU. Según la experiencia regulatoria, las empresas suelen asumir que la certificación ISO cierra todas las brechas. En la práctica, es necesaria una evaluación de brechas de la QMSR específica para confirmar la alineación completa con la FDA.
La FDA sustituyó QSIT por el Compliance Program 7382.850, con efecto el 2 de febrero de 2026. Este nuevo programa alinea las inspecciones con el marco de la QMSR. En lugar de listas de verificación por subsistemas, la FDA ahora organiza las inspecciones en torno a seis áreas del QMS y cuatro Other Applicable FDA Requirements (OAFR). Como resultado, las inspecciones siguen un enfoque más integrado, basado en riesgo y centrado en el ciclo de vida.
Sí. Bajo la QMSR, los investigadores de la FDA pueden revisar informes de auditoría interna, auditorías de proveedores y registros de revisión por la dirección.
En la práctica, los inspectores ahora verifican si las incidencias se identificaron, documentaron y cerraron de forma efectiva. Ya no se centran solo en si existen procedimientos; evalúan si el sistema funciona según lo previsto.
Las acciones de auditoría incompletas o no verificadas pueden aumentar el riesgo de inspección.
La FDA ahora pone mayor escrutinio en:
– Informes de auditoría interna y de proveedores
– Documentación de revisión por la dirección
– Registros de trazabilidad de controles de diseño
– Procedimientos CAPA y comprobaciones de eficacia
Según la experiencia en inspecciones, la verificación de eficacia de CAPA es un punto débil frecuente. Las empresas suelen implementar acciones correctivas, pero no documentan evidencia objetiva de que la acción resolvió la causa raíz.
Bajo la QMSR, la eficacia importa tanto como la documentación.
Porque MDSAP y las inspecciones de la FDA tienen finalidades distintas. MDSAP evalúa la conformidad. Las inspecciones de la FDA evalúan el cumplimiento legal y el riesgo para la salud pública. Los investigadores de la FDA no están sujetos a los métodos de muestreo ni al alcance de auditoría de MDSAP. Si los inspectores identifican CAPA ineficaz, trazabilidad débil o brechas entre los procedimientos y la práctica real, pueden emitir observaciones en el Formulario 483, incluso tras una auditoría MDSAP satisfactoria.
Empiece pronto. La preparación suele llevar más tiempo del esperado. Después, realice una evaluación estructurada de brechas de la QMSR. El cumplimiento con ISO 13485 por sí solo no confirma la alineación completa con la FDA. Por último, forme a los equipos en el Compliance Program 7382.850. Las entrevistas simuladas y las simulaciones de inspección ayudan a identificar debilidades. Incluso una remediación documentada en curso demuestra control del sistema y reduce el riesgo de inspección.
La aplicación de la FDA QMSR comenzó el 2 de febrero de 2026, cuando la nueva Quality Management System Regulation sustituyó oficialmente a la anterior Quality System Regulation (21 CFR Part 820). A partir de esa fecha, las inspecciones de la FDA operan bajo el Compliance Program 7382.850.
Bajo la QMSR de 2026, la ISO 13485:2016 se incorpora por referencia a la legislación estadounidense. Esto significa que los fabricantes deben cumplir los requisitos de la ISO 13485 como parte del cumplimiento con la FDA. Sin embargo, la armonización no es una equivalencia completa: las obligaciones específicas de la FDA, como UDI, notificación MDR, registro/listado de dispositivos y controles de etiquetado, siguen siendo plenamente exigibles y no están cubiertas únicamente por la ISO 13485. Consulte la tabla comparativa QSR vs QMSR vs ISO 13485 anterior para un desglose detallado.