QMSdesk

RegulationsRegulations / Medical devices

FDA QMSR: what it asks for, and the records that answer it

The FDA QMSR (Quality Management System Regulation, 21 CFR Part 820) is the FDA's quality system rule for manufacturers of finished medical devices made in, or imported into, the US. It has applied since February 2, 2026. It incorporates ISO 13485:2016 by reference and adds a short list of FDA-specific requirements for records, labeling and packaging. FDA now inspects under compliance program 7382.850, and an ISO 13485 certificate does not exempt a site from inspection.

Bring one workflow. We'll show you QMSdesk running it. or download the QMSR requirements checklist

FDA QMSR in one page

The regulation itself is short. Its weight sits in the standard it brings in.

What it replaced

The 1996 Quality System Regulation (QSR). The final rule was published on February 2, 2024 (89 FR 7496), with a two-year transition.

What it incorporates

ISO 13485:2016, the 2016 edition specifically, and Clause 3 of ISO 9000:2015 for vocabulary (§820.7).

What it adds

§820.10 ties ISO 13485 to other FDA rules: UDI (Part 830), tracking (Part 821), medical device reporting (Part 803) and corrections and removals (Part 806). §820.35 sets what certain records must contain. §820.45 covers labeling and packaging.

What wins a conflict

Where ISO 13485 conflicts with the FD&C Act or its regulations, the Act and its regulations control (§820.1(b)).

QMSdesk™ is built to support organizations working to ISO 13485:2016. Under the medical device profile, it keeps your complaints, CAPAs, suppliers, audits and management reviews as linked, signed records, so your evidence tells one story.

QMSR vs QSR: what moved where

The QSR's familiar section numbers are gone. Most requirements now live in an ISO 13485 clause.

QSR section (before February 2, 2026) Where it lives under the QMSR
§820.20 Management responsibility ISO 13485 §5, including management review (§5.6)
§820.22 Quality audit ISO 13485 §8.2.4
§820.25 Personnel ISO 13485 §6.2
§820.30 Design controls ISO 13485 §7.3, applied by §820.10(c)
§820.40 Document controls ISO 13485 §4.2.4
§820.50 Purchasing controls ISO 13485 §7.4
§820.90 Nonconforming product ISO 13485 §8.3
§820.100 Corrective and preventive action ISO 13485 §8.5.2 and §8.5.3
§820.120 and §820.130 Labeling and packaging §820.45, with ISO 13485 §7.5.1
§820.180 to §820.186 Records ISO 13485 §4.2.3 (medical device file), §4.2.5 and §7.5.1, plus §820.35
§820.180(c) Exception for audit and review reports Removed. FDA can now inspect these records
§820.198 Complaint files ISO 13485 §8.2.2, plus §820.35(a)

QMSR complaint handling: 820.198 no longer exists

You'll still see "21 CFR 820.198" cited. Under the QMSR, complaint handling sits in ISO 13485 §8.2.2. §820.35(a) adds record requirements. You keep records of the review, evaluation and investigation of any complaint about a possible failure to meet specifications. For complaints that must be reported to FDA under Part 803, and complaints you investigate, you record the device name, date received, any UDI or UPC and other device identification, the complainant's name, address and phone number, the nature and details, any correction or corrective action, and any reply. If you skip an investigation because a similar complaint was already investigated, you record why.

The clause-to-control map

The map covers key QMSR requirements, including some QMSdesk leaves to you. It isn't a full list of every requirement in the QMSR or ISO 13485.

Requirement (clause, paraphrased) How QMSdesk supports it Evidence the system produces What you still own
§820.10(a). Document a QMS that complies with the applicable requirements of ISO 13485 and of this part. The medical device profile carries ISO 13485 and the FDA QMSR. Procedures run through a signed document lifecycle. Signed, effective procedures. Your profile record. Your quality manual, procedures and medical device files.
§820.35(a), ISO §8.2.2. Handle complaints, and keep the records §820.35(a) requires, including why any investigation was not done. Complaint workflow: acknowledgment tracked against a 3-business-day target, investigation and root cause, a signed reportability review, a signed CAPA decision, and the reply. The complaint record, its signatures and a closure-record PDF. Deciding which complaints you investigate, and capturing every §820.35(a) element, including UDI, under your procedure.
§820.10(b)(3), ISO §8.2.3. Report complaints that meet Part 803. The reportability review is a signed decision with its justification. A reportable complaint records the authority and the reporting deadline. The signed decision, the authority and the deadline. Setting the deadline (30 calendar days from awareness under §803.50, or 5 work days under §803.53) and filing the report with FDA.
§820.10(b)(1), (2), (4); §820.35(c). UDI, tracking, corrections and removals. Nonconformances carry UDI and serial number under the medical device profile. Nonconformance records with device identification. Your UDI system and production records, tracking, and Part 806 reports. Outside QMSdesk's scope.
§820.10(c), ISO §7.3. Design and development for class II, class III and listed class I devices. Outside QMSdesk's scope. Under the medical device profile, each CAPA records whether it affects the design. The CAPA's design-impact field. Your design and development records.
§820.10(d), ISO §7.5.9.2. Traceability for devices that support or sustain life. Outside QMSdesk's scope. — Your traceability records.
ISO §7.1. Risk management throughout product realization. A risk register on a 5×5 matrix, with FMEA scoring available. Assessments and residual-risk acceptance are signed, and risk controls are verified separately from their implementation. Signed risk records and their linked CAPAs. Your risk management process and file, and your risk acceptability criteria.
ISO §8.5.2, §8.5.3. Corrective and preventive action. CAPA as its own record: signed action-plan review, verification, and an effectiveness check that can't be skipped. A failed check raises a new linked CAPA. Signed CAPA records, action evidence and effectiveness results. Investigation methods, and actions proportionate to the effects of the nonconformity.
ISO §8.3. Control of nonconforming product. Nonconformance workflow with a signed disposition (reject, rework, use as is or return). Use as is needs a technical rationale. Signed nonconformance records. Your disposition criteria, rework instructions and any concessions.
ISO §7.4. Supplier evaluation, monitoring and re-evaluation. Risk tiers set qualification gates and 6, 12 or 24-month reviews. Signed status decisions. SCARs answered through a single-use link. The Approved Supplier List, signed decisions and SCAR records. Supplier audits, purchasing data and incoming acceptance.
ISO §5.6. Management review, now open to FDA inspection. A frozen, signed snapshot of the quality system as of the period end. Minutes and decisions signed at closure. The snapshot, signed minutes and tracked follow-up actions. Running the review and making its decisions.
ISO §8.2.4. Internal audit, now open to FDA inspection. Audit program and calendar. Auditors can't audit their own department. Critical findings raise a nonconformance and a risk. Signed audit reports and a register of every finding. Your audit program and the audits themselves.
ISO §4.2.4. Document control. Author, reviewer and approver are different people. Training is assigned on approval. External standards are controlled as reference documents. Signed versions, controlled copies with logged downloads, periodic review tasks. Document content.
ISO §6.2. Competence and training. Training assigned on approval, change and CAPA. Quizzes, practical assessments and competency assessments. Completion records (signed acknowledgments and practical assessments, auto-graded quiz results) and training transcripts. Competence criteria and training content.
§820.35, ISO §4.2.5. Control of records, including retention. A SHA-256 hash-chained, insert-only audit trail, verified daily. Records raised in error are cancelled with a signed reason, never hard-deleted. Under the medical device profile, records are kept for at least 15 years after they reach a final state, and you can set a longer period. The audit trail, verification results and retention clock. Defining device lifetime and any longer retention it needs (ISO §4.2.5), and marking confidential records for FDA (§820.35(d)).
§820.35(b). Servicing records. Outside QMSdesk's scope. — Your servicing records.
§820.45. Labeling and packaging controls. Your labeling procedure can run as a controlled document. The approved procedure. Label inspection and release records on your line.
ISO §4.1.6. Validate software used in the QMS before first use and after changes, in proportion to risk, and keep records. QMSdesk's core platform is validated under a QA-approved Validation Summary Report. We'll walk you through the full record under a mutual NDA. Validating QMSdesk for your intended use, and revalidating after changes.
21 CFR Part 11. Electronic records and signatures. Re-authentication at every signature, a recorded meaning, and the signature committed with its change. The signature manifest on closure records and controlled copies. Your Part 11 procedures (including §11.10(i), (j) and (k), and §11.300) and the §11.100(c) letter to FDA.

See how QMSdesk handles it: complaint management, CAPA and the medical device profile

7382.850: how FDA inspects under the QMSR

On February 2, 2026, FDA withdrew the Quality System Inspection Technique (QSIT). Investigators now follow compliance program 7382.850. It groups QMSR requirements into six QMS areas and four other applicable FDA requirements:

  • QMS areas: Management Oversight; Design and Development; Change Control; Measurement, Analysis, and Improvement; Production and Service Provision; and Outsourcing and Purchasing.
  • Other FDA requirements: Medical Device Reporting, Reports of Corrections and Removals, Medical Device Tracking Requirements, and Unique Device Identification.

Investigators review your risk management documentation throughout the inspection and follow risk across areas, in no fixed order. Management review, internal audit and supplier audit reports are now within reach, because the QMSR dropped the old §820.180(c) exception.

In QMSdesk, those records link to each other. A critical complaint prompts a linked risk, and a signed CAPA decision raises its CAPA. The CAPA raises its change control and training where they're needed. The management review snapshot shows them all as of the period end. Inspection View gives an inspector a time-boxed, read-only account that can see and export records but can't change or sign them.

Kept current

What changed recently

  1. February 2, 2024

    FDA published the final rule, "Medical Devices; Quality System Regulation Amendments" (89 FR 7496). Federal Register

  2. December 4, 2025

    FDA published technical amendments (90 FR 55978) that update other device rules to refer to the QMSR, effective February 2, 2026. FDA calls them editorial, with no new requirements. Federal Register

  3. February 2, 2026

    The QMSR took effect, and 21 CFR Part 820 now incorporates ISO 13485:2016. FDA QMSR page

  4. February 2, 2026

    FDA withdrew QSIT and began inspecting under compliance program 7382.850. It retired compliance programs 7382.845 and 7383.001. FDA QMSR page

Download the checklist

Take the requirements checklist with you: every row of the clause-to-control map, with space to note your own procedure and evidence.

PDF and Excel

Regulation checklist

The tables from this page, with a column for your own evidence. No form to fill in.

FDA QMSR FAQ

When did the FDA QMSR take effect?

On February 2, 2026. FDA published the final rule on February 2, 2024 and gave manufacturers two years to transition.

What happened to 21 CFR 820.198?

It no longer exists. Complaint handling now sits in ISO 13485 §8.2.2, and §820.35(a) sets what certain complaint records must contain.

Does an ISO 13485 certificate exempt us from FDA inspection?

No. FDA doesn't require or issue ISO 13485 certificates, and a certificate doesn't exempt a manufacturer from FDA inspection.

Can FDA now see our management review and internal audit records?

Yes. The QMSR dropped the §820.180(c) exception, so FDA can inspect management review, quality audit and supplier audit reports.

Does 21 CFR Part 11 still apply under the QMSR?

Yes. Part 11 applies to electronic records kept under any FDA records requirement, including the QMSR's. QMSdesk is designed to support Part 11, and the §11.100(c) letter to FDA stays yours.

Will QMSdesk meet the QMSR for us?

No software can. Your quality system meets the QMSR, in your environment and under your procedures. QMSdesk is built to support organizations working to ISO 13485:2016, and it gives you the controls and records this page maps.

Reviewed by a practitioner

Abdul Azam, Founder & CEO, 25 years in regulated life-sciences quality. Last reviewed September 26, 2026. Next review December 2026. This guide is general information, not legal or regulatory advice.

From complaint to proven fix, ready for your investigator

Bring a real complaint. We'll run it from receipt to CAPA, and show you each record it leaves along the way.

Download the QMSR requirements checklist, or see complaint management.