- Trigger
- Scheduled quarterly review (see How content is reviewed). This is the first quarterly spot-check, the one the editorial policy commits to completing in the third quarter of 2026.
- Scope
- 30 of the 167 published requirements, sampled across all six published regimes. Selection basis: within each regime the requirements were sorted by identifier and sampled at even intervals, so the sample spans each standard's clause range rather than clustering; per-regime counts were set in proportion to regime size — ISO 13485 9, IEC 81001-5-1 8, IEC 62304 5, FDA cybersecurity guidance 4, IEC 62366-1 2, ISO 14971 2. The sample is recorded in full below and the selection is reproducible.
- Method
- Each sampled requirement was compared against the current text of its source standard or regulation, retrieved at review time. 21 CFR Part 820 was fetched live from the eCFR. The consensus standards and the FDA cybersecurity guidance were read from our licensed corpus copies, which are the authoritative text for sources that publish no machine-readable current version. Each check asked three questions: does every cited clause number exist in the current edition, does our wording carry the same obligation level and scope as the clause, and does the clause say what we claim it says. Working papers for all three review partitions are at data/review-ledger-evidence/2026-Q3/.
- Findings
- 10 of the 30 sampled requirements carried a finding; 20 required no change. 1 was critical: our coordinated vulnerability disclosure requirement described a plan that §524B(b)(1) of the FD&C Act obliges manufacturers of cyber devices to submit as though it were a discretionary FDA recommendation. 2 were high: our internal-audit requirement narrowed ISO 13485 §8.2.4 from four conformance targets to one, and our security-update requirement extended a manufacturer-only verification duty to suppliers. 5 were medium and 2 were low, all of them dropped qualifiers, omitted a second required element, or attributed a passage to the wrong section of the FDA guidance. No sampled requirement cited a clause number that does not exist, and none was left unverified. The IEC 62304, IEC 62366-1 and ISO 14971 requirements were clean throughout.
- Disposition
- the critical finding was corrected on 2026-08-12; the remaining 9 were corrected on 2026-08-14.