FDA QMSR 2026: What Medical Device Founders Should Change Before the Next Prototype

For founders and product teams building Class I/II hardware: what actually changed when FDA's QMSR replaced the old QS framework, and how to keep early prototypes from becoming regulatory debt.

September 7, 20266 min read

Konstantin Dolgan

Written by Konstantin Dolgan, Ph.D., NPDP

Founder & CEO, Product Development Engineer

Published September 7, 2026

Key takeaways

  • FDA's Quality Management System Regulation (QMSR) took effect February 2, 2026, amending 21 CFR Part 820 and incorporating ISO 13485:2016 by reference.
  • FDA stopped using QSIT and Compliance Programs 7382.845 and 7383.001 on that date. Device inspections now follow Compliance Program 7382.850.
  • ISO 13485 certification on its own is not QMSR compliance. Where the standard conflicts with the FD&C Act or its regulations, the Act and its regulations control.
  • Devices under an Investigational Device Exemption are not exempt from design and development requirements (21 CFR 820.10(c), ISO 13485 Clause 7).
  • The practical change for founders is timing. Decide before a build whether it is an exploratory model or evidence, because only one of those needs a controlled record.

What changed on February 2, 2026

FDA's Quality Management System Regulation (QMSR) amends 21 CFR Part 820, the current good manufacturing practice requirements for devices, and incorporates ISO 13485:2016 by reference. It took effect on February 2, 2026. The final rule, Medical Devices; Quality System Regulation Amendments, was published in the Federal Register on February 2, 2024, with a two year runway to that effective date.

In plain English, the quality system expectations you meet are now written mostly in ISO 13485 language, with FDA specific additions layered on top. QMSR also incorporates Clause 3 of ISO 9000:2015 for vocabulary, so terms mean what the standard says they mean. Where ISO 13485 and the Federal Food, Drug, and Cosmetic Act (or its regulations) conflict, the Act and its regulations control.

Inspections changed too. As of February 2, 2026, FDA stopped using the Quality System Inspection Technique (QSIT) and Compliance Programs 7382.845 and 7383.001. Inspections now follow the updated Compliance Program 7382.850, Inspection of Medical Device Manufacturers. The practical effect for a small team is that an investigator walks your quality system the way the standard is structured, not the way the old four subsystem model was structured.

Why this matters before you freeze a prototype design

QMSR applies to finished device manufacturers who intend to commercially distribute their devices. Accessories that are treated as finished devices can pull a manufacturer into scope as well. So the question is not whether you have a quality system on the day you build your first bench model. The question is whether the builds you intend to lean on later were produced and documented in a way that survives review.

One point catches founders off guard. Devices under an Investigational Device Exemption are not exempt from design and development requirements. 21 CFR 820.10(c) keeps those obligations in place, and they map to the Design and Development requirements in Clause 7 of ISO 13485. If your clinical or human factors work runs under an IDE, the design record has to exist.

Old QS-era habit versus QMSR-era expectation

Topic
Old QS-era habit
QMSR-era expectation
Quality system basis
Part 820 subsystems read on their own terms
Part 820 as amended, built on ISO 13485:2016 with ISO 9000:2015 Clause 3 vocabulary
Design and development records
Design history file assembled toward the end of the program
Design and development records maintained as the work happens, per ISO 13485 Clause 7
Risk management emphasis
Risk treated mostly as a design input document
Risk woven through design, process, and supplier decisions and updated as builds teach you more
Inspection approach
QSIT and Compliance Programs 7382.845 and 7383.001
Compliance Program 7382.850, Inspection of Medical Device Manufacturers
When design controls start
After the concept felt settled
Before the first build you intend to use as evidence for a claim

Checklist: before your next evidence-grade prototype

  • Write one sentence naming the purpose of the build: learning, or evidence for a specific claim.
  • Freeze and label a configuration identifier for the unit, and keep it on the physical part.
  • Capture a reproducible bill of materials, including supplier, part number, and revision for purchased items.
  • Record materials and process details that could affect the result: resin grade, print material and machine, post processing, sterilization if any.
  • Keep a build record naming who built the unit, when, and any deviation from the plan.
  • Link each evidence build to the requirement or design input it is meant to exercise.
  • Write the test protocol before the test, including acceptance criteria, not after seeing the data.
  • Start a risk file early and update it when a build teaches you a new failure mode.
  • Confirm whether your device or accessory is a finished device intended for commercial distribution, since that determines scope.
  • Agree with your contract manufacturer, in writing, on which records they keep and which they hand to you.
  • Check ISO 13485 Clause 7 design and development expectations against what your team already produces, and close the smallest gaps first.
  • Set a review point where exploratory work formally transitions into design controls, and put a date on it.

When a shop prototype becomes regulatory evidence

Not every build needs a controlled record. Exploratory models exist to answer a question: does this mechanism work, does the enclosure feel right in a gloved hand, can the sensor read through this wall thickness. Learn fast, keep an engineering notebook, move on. Nobody expects a design history file behind a foam mockup.

An evidence build is different. The moment a unit is used to support a claim, it is evidence. Usability and human factors sessions, bench performance testing, biocompatibility sample articles, and design verification runs all fall here. For those, the build needs a known configuration, a bill of materials you can reproduce, a build record naming who built what and when, materials and process traceability, and a link back to the requirement being tested.

The cheapest moment to draw that line is before the build, not after. Retroactively reconstructing a configuration is where teams lose weeks and sometimes have to rebuild and retest. This is the part of the work we spend the most time on with founders moving from idea to functional prototype in medical device prototyping, and it is why we treat documentation as an engineering deliverable rather than paperwork that happens later.

How this relates to ISO 13485, and what stays FDA specific

QMSR moves the baseline onto ISO 13485:2016, which is good news if your contract manufacturer or your European plans already run on that standard. It is not the same as saying an ISO 13485 certificate makes you QMSR compliant. Certification is a third party audit outcome against the standard. QMSR is a US regulation that incorporates the standard and then adds and modifies requirements, and FDA inspects against the regulation, not against your certificate.

Areas that remain distinctly FDA include labeling and packaging controls written into Part 820, device specific record expectations, and reporting obligations that live outside the quality system regulation entirely. Broader program discipline still helps, and if you are building that muscle for the first time, our note on quality management systems in new product development covers the groundwork.

What this article is not

  • Not legal or regulatory advice. Your regulatory consultant or counsel owns the determination for your specific device.
  • Not a claim that QMSR removed FDA specific requirements. It did not.
  • Not a claim that every bench model needs a full quality system on day one.
  • Not a substitute for reading the FDA QMSR page and the Federal Register final rule, both linked below.

Where to go next

If you are early and trying to decide how much structure your next build actually needs, that is a short conversation, not a project. You can compare approaches in our overview of medical device design companies, read how we scope engagements in product development consulting, or tell us what you are building and we will tell you plainly where the documentation line should fall for your device.

Sources

Frequently asked questions

Does QMSR replace 21 CFR Part 820?

No. QMSR amends Part 820. The regulation still exists, and it now incorporates ISO 13485:2016 by reference along with Clause 3 of ISO 9000:2015 for vocabulary. Where the standard conflicts with the FD&C Act or its regulations, the Act and its regulations control.

Do I need a full quality system before my first prototype?

Not for exploratory learning models. You do need design and development records in place before builds that support claims, and you need them earlier than most teams expect if you plan to use those builds for usability, bench testing, biocompatibility, or design verification.

Are IDE devices exempt from design controls?

No. Under 21 CFR 820.10(c), devices under an Investigational Device Exemption are not exempt from design and development requirements, which correspond to Clause 7 of ISO 13485. Plan the design record alongside the study, not after it.

Will FDA still inspect using QSIT?

No. As of February 2, 2026, FDA stopped using QSIT and Compliance Programs 7382.845 and 7383.001. Inspections of device manufacturers follow the updated Compliance Program 7382.850.

Does an ISO 13485 certificate mean we are QMSR compliant?

It does not. Certification is a third party audit against the standard. QMSR is a US regulation that incorporates the standard and adds FDA specific requirements, and FDA inspects against the regulation. A certificate is useful evidence of maturity, not a substitute for compliance.

Related articles

All articles

Get in touch

Tell us what this is about

Share a few details about your question, partnership, or idea — a member of the LA NPDT team will reply within one business day.

Optional context

What are you looking to accomplish? (optional)

What do you already have? (optional — tick any)

Your information stays confidential and is never shared.