Skip to content
QMSR GUIDE

QMSR is now in enforcement — what it means for a small device, IVD, or biotech company

The transition period is over. Here's what changed, what FDA can now review during an inspection that it could not review before, and what to have documented today.

UPDATED AUGUST 2026 · 8 MIN READ
WHAT CHANGED

The QMSR compliance date (February 2, 2026) passed. The pre-QMSR 820.180(c) exception that shielded internal audit, supplier audit, and management review records from routine FDA inspection is gone from the current text.

WHAT STILL QUALIFIES IT

FDA's Compliance Policy Guide 130.300 is still published and un-withdrawn — a separate, non-regulatory limit on how that authority gets exercised in practice, distinct from the removed regulatory exemption.

WHAT TO DO NOW

Write internal audit and management review records assuming they can be requested and read; update any procedure still citing an old Part 820 section number to the current QMSR clause structure.

FDA's Quality Management System Regulation (QMSR) became the enforced quality-system standard for medical device manufacturers on February 2, 2026. The transition period is over. This guide covers what changed, what FDA can now review during an inspection that it could not review before, and what a small device, IVD, or biotech company needs to have documented today.

Why the compliance date matters now

QMSR is FDA's regulation replacing the prior Quality System Regulation (QSR) at 21 CFR Part 820. Rather than restate device-specific quality-system requirements in FDA's own regulatory text, QMSR incorporates ISO 13485:2016, the international quality management system standard for medical devices, directly by reference. A small number of FDA-specific additions remain in Part 820 itself: records of complaints, servicing records, and unique device identification requirements at 21 CFR 820.35, plus device labeling and packaging controls at 21 CFR 820.45.

The rule was finalized February 2, 2024 (89 FR 7523). Manufacturers had a two-year transition period to align their quality management systems with ISO 13485:2016 and the QMSR structure. That transition period ended February 2, 2026. QMSR is the operative, enforced regulation now, not a future requirement to prepare for.

Is QMSR still something to prepare for, or is it already enforced?

It's already enforced, not a future requirement. That distinction matters for how a company should be thinking about this. The question that matters now: is your quality management system, as it exists today, something FDA can walk in and inspect against QMSR requirements — including records that used to be off-limits.

The records exemption is gone

Internal audit, supplier audit, and management review records are no longer categorically off-limits to FDA during an inspection. The pre-QMSR regulation, at 21 CFR 820.180, required manufacturers to keep quality-system records "reasonably accessible" and make them "readily available for review and copying by FDA employee(s)" during an inspection. But subsection (c) of that same, now-retired section carved out a specific exception.

What did the old 820.180(c) exception shield?

The exact text of the pre-QMSR provision:

(c) Exceptions. This section does not apply to the reports required by § 820.20(c) Management review, § 820.22 Quality audits, and supplier audit reports used to meet the requirements of § 820.50(a) Evaluation of suppliers, contractors, and consultants, but does apply to procedures established under these provisions. Upon request of a designated employee of FDA, an employee in management with executive responsibility shall certify in writing that the management reviews and quality audits required under this part, and supplier audits where applicable, have been performed and documented, the dates on which they were performed, and that any required corrective action has been undertaken.

Under the old QSR, FDA could not routinely pull the substance of your internal audit reports, your supplier audit reports, or your management review records during an inspection. The most an investigator could ask for was a signed certification from an executive-responsibility-level employee, confirming that those activities happened, when, and that any resulting corrective action was undertaken. The content of those reports stayed internal: findings, gaps identified, disagreements among reviewers, severity assessments.

Does that exception still exist anywhere in the current QMSR text?

No. We checked the full current text of Part 820 for any surviving version of this exception: in the control-of-records section at 820.35, in the general quality-management-system requirements at 820.10, and everywhere else in the regulation. There is no equivalent exception anywhere in the current text. (The current regulation does contain a subsection titled "Confidentiality" at 820.35(d), but it governs whether manufacturer-marked records are withheld from public disclosure under FOIA, not whether FDA may review them during an inspection. It is not a successor to the former 820.180(c) inspection carve-out.) Internal audit is now governed by ISO 13485's internal-audit clause at Clause 8.2.4 and management review by its management-review clause at Clause 5.6, both incorporated into the QMSR through 820.10, the same way every other quality-system requirement is.

Does FDA's Compliance Policy Guide 130.300 still protect these records?

One nuance worth stating plainly, because your auditors will know it: separate from the regulation, FDA has a long-standing compliance policy — Compliance Policy Guide Sec. 130.300 — under which, during routine inspections, it "will not review or copy reports and records that result from audits and inspections of the written quality assurance program." FDA has not formally withdrawn that policy. The page is still posted, and is marked current as of February 3, 2026 — the day after the QMSR compliance date.

Read the rest of that page, though. It carries a notice that the document "was issued prior to the final rule issued on February 2, 2024," and that FDA "encourages manufacturers to review the current QMSR to ensure compliance with the relevant regulatory requirements." It states that compliance policy guides "do not establish legally enforceable responsibilities and thus are not binding on FDA or the public." And the policy's operative text still cites 21 CFR 820.22, the pre-QMSR "Quality audit" section QMSR retired, so it points to a requirement that no longer exists under that number.

So the instrument is still posted, and FDA says on that same page that it is not binding. The regulatory exemption that used to bar these requests is gone, and FDA has clear authority to make them. Whether an investigator asks for a full report on any given day is a question of practice, not of protection. The safe posture for a small company is to assume these records can be requested and to write them accordingly. Note too that a management review is not a "quality audit," so it was never covered by that policy in the first place — of the three record types, management-review records are the most squarely inspectable today.

Your internal audit reports, your supplier audit reports, and your management review records are now the kind of record FDA can ask to see and copy during an inspection, not just a signed certification that they occurred. If those documents contain a finding your team flagged and didn't fully close, an unresolved disagreement between reviewers, or language you wouldn't want read verbatim in an FDA observation, that's no longer something you can assume stays internal.

For a small company, this changes the calculus on how internal audits and management reviews get written, not just whether they get performed. A finding logged informally in a meeting note, in a tone that assumed only internal readers, is now potentially inspection-facing text.

Clause-level changes that matter for a small company

QMSR touches nearly every part of the pre-QMSR regulation. This is not an exhaustive list — it's the handful of changes most likely to catch a small, resource-constrained team unprepared.

  • Design controls consolidate under ISO 13485, and the DHF concept shifts. The pre-QMSR Design History File requirement at 820.30(j) is now expressed through ISO 13485's design and development file concept, incorporated at 820.10(c). The recordkeeping obligation is substantively similar, but the language your design controls procedure references should point to the ISO 13485 clause structure, not the old 820.30 subsection lettering. An auditor working from the current regulation will expect that alignment.
  • Document control moves out of Part 820 and into ISO 13485 Clause 4.2.4. The old standalone document-control section at 820.40 is retired; document control is now governed by ISO 13485 Clause 4.2.4, incorporated at 820.10. If your document-control SOP still cites "820.40" as its regulatory basis, that citation is stale.
  • Supplier and purchasing controls move to ISO 13485 Clause 7.4. The old purchasing-controls section at 820.50 is retired in favor of ISO 13485 Clause 7.4, incorporated at 820.10. Supplier evaluation and re-evaluation criteria should be traceable to that clause.
  • Internal audit records are now inspectable: the change with the most direct consequence for a small company. That follows directly from the removal of the 820.180(c) exception above. The underlying clause moved too: the old 820.22 "Quality audit" section is retired; internal audit is governed by ISO 13485 Clause 8.2.4, incorporated at 820.10.
  • Management review carries the same inspection exposure as internal audit. Its records are no longer shielded by the former 820.180(c) certification-only carve-out. The old 820.20 "Management responsibility" section is retired in favor of ISO 13485 Clause 5.6, incorporated at 820.10.
  • Complaint records now explicitly require UDI/UPC identification. The old complaint-files section at 820.198 is now 820.35(a), with the unique device identifier or universal product code added as an explicit required field.
  • DMR and DHR remain, but sit under a different structural home. The Device Master Record (formerly 820.181) and Device History Record (formerly 820.184) concepts persist under the general control-of-records requirement at 820.35, alongside ISO 13485's "medical device file" concept. Update the citation if a procedure still references the old 820.181 or 820.184 numbers; the substance doesn't change.

Does the design-controls change apply to every device class?

No — check applicability before you act on the design-controls item above. 820.10(c) applies the design and development requirements — ISO 13485 Clause 7.3 and its subclauses — to manufacturers of Class II and Class III devices, plus the Class I devices the subsection specifically lists: devices automated with computer software, and a table of named device types. If your device is Class I and not on that list, Clause 7.3 does not apply to you, and design controls did not apply to you under the old 820.30 either. This is the only clause in this guide whose applicability turns on device class. Everything else here applies regardless of class.

Does the complaint UDI/UPC requirement apply to every complaint I log?

No — that field is scoped rather than universal. 820.35(a) requires it for complaints you must report to FDA under Part 803, complaints you determine must be investigated, and complaints you investigate regardless of those requirements — not for every complaint you log.

What inspection-ready means now

Being inspection-ready under QMSR today, not as a future goal, means:

  • Your internal audit reports and management review records are written knowing they can be read by an FDA investigator, not just certified as having occurred. A gap your team flagged and didn't fully close, or a disagreement between reviewers, should be documented the way you'd want an inspector to see it: honestly, with corrective action tracked to closure.
  • Your supplier audit reports carry the same expectation. If a supplier audit surfaced a finding that never got resolved, that's now visible, not just the fact that the audit happened.
  • If any of your quality documentation (procedures, SOPs, training records) still cites an old Part 820 section number — 820.20, 820.22, 820.30, 820.40, 820.50, 820.181, 820.184, 820.198, or 820.200 — update it to the current clause structure: 820.10, 820.35, and 820.45, plus the specific ISO 13485 clause each requirement now lives under.
  • Complaint-handling records for reportable and investigated complaints include UDI/UPC identification per 820.35(a), not just the narrative fields that satisfied the old 820.198.
  • Someone in the organization can trace every quality-system requirement back to its current clause, not the clause it used to sit at three years ago.

Finding your gaps

Most of the changes above are structural: a requirement moved from one clause number to another, or a records-confidentiality exemption disappeared. Neither type of change is easy to catch by re-reading your existing procedures once and assuming they still line up. The old citations are usually still sitting in the document; they just no longer point at anything current.

An automated gap analysis compares your existing quality management system documentation against the current QMSR requirement text — clause by clause — and shows you where a requirement changed structural position, where a citation is stale, and where a record type (like internal audit or management review) now carries inspection exposure it didn't carry before. Each finding shows the source clause it's checked against, so you can verify it yourself rather than take a tool's word for it.

Frequently asked questions

Is FDA's Compliance Policy Guide 130.300 the same protection as the old 820.180(c) exemption?
No. The former 820.180(c) exemption was a pre-QMSR regulatory carve-out — a rule that no longer exists in the current QMSR text. CPG 130.300 is a separate, still-published FDA compliance policy under which investigators “will not review or copy reports and records that result from audits and inspections of the written quality assurance program” during routine inspections. FDA has not formally withdrawn CPG 130.300, but its page carries a notice encouraging manufacturers to review the current QMSR, and states that compliance policy guides “do not establish legally enforceable responsibilities and thus are not binding on FDA or the public.” And the policy only ever covered quality-assurance-program audits — a management review was never an “audit,” so it was never covered by that policy in the first place.
Do old Part 820 section numbers still work if my procedures cite them?
No. If your quality documentation still cites an old Part 820 section number — 820.20, 820.22, 820.30, 820.40, 820.50, 820.181, 820.184, or 820.198 — update it to the current QMSR structure (820.10, 820.35, 820.45) and the specific ISO 13485 clause each requirement now lives under. The old citations are usually still sitting in the documents; they just no longer point at anything current.
Does the design-controls change apply to every device class?
No. 21 CFR 820.10(c) applies ISO 13485 Clause 7.3 (design and development) to manufacturers of Class II and Class III devices, plus the Class I devices the subsection specifically lists. If your device is Class I and not on that list, Clause 7.3 does not apply to you — the same as under the old 820.30. It's the only clause in this guide whose applicability turns on device class.
Does the complaint UDI/UPC requirement apply to every complaint I log?
No. 21 CFR 820.35(a) requires the unique device identifier or universal product code field for complaints you must report to FDA under Part 803, complaints you determine require investigation, and complaints you investigate regardless of those requirements — not for every complaint you log.

A free structural scan is coming.

No credit card. No sales call.

Join the waitlist →

We'll email you when the scanner launches.