Five months after FDA's Quality Management System Regulation (QMSR) took effect on February 2, 2026, the shift is no longer theoretical. FDA retired the Quality System Inspection Technique (QSIT) in favor of the risk-informed Compliance Program 7382.850, and investigators have moved with it: the question in an inspection is no longer “does this procedure exist,” it's “does your quality system actually control real-world product and patient risk across the total product lifecycle.” If your organization is still treating QMSR as a documentation update, the first five months of enforcement suggest that's a costly read of the room.
This shift didn't happen in isolation. It lines up directly with other recent FDA guidance, including draft recommendations on AI-enabled device software, Predetermined Change Control Plans (PCCPs), and Form 483 response strategy. Read together, the message is consistent: FDA wants continuous lifecycle risk management, controlled change, and transparent oversight, not a static, checklist-driven QMS.
Early inspections show FDA investigators expect documented, risk-based decision making across the entire quality system, and they're evaluating whether your quality processes themselves were designed with a proportionate, risk-based approach. In practice, that means being ready to explain:
The bar has moved. It's no longer enough for these processes to exist. Their design and execution now need to be demonstrably commensurate with the risks they're meant to control.
Under QMSR, FDA investigators have explicit authority to inspect records that were previously off-limits, including management review minutes, internal quality audits, supplier audit reports, and legacy QMS files created before the regulation's effective date. There's no grandfather clause protecting older documentation from this level of scrutiny.
Public enforcement data is already telling a clear story:
Investigators aren't treating deficiencies as isolated administrative errors. They're tracing risk threads across QMS boundaries, from purchasing to complaints to CAPA to risk files, to see whether the whole system holds together.
The practical impact of this risk-based enforcement model isn't uniform. It plays out differently depending on the device category.
Vascular surgical devices and implants. As Class III devices, these draw elevated scrutiny on purchasing controls and complaint handling. Firms need closed-loop traceability and rigorous supplier oversight: a raw material nonconformity or a postmarket vascular failure signal has to instantly update design risk files, trigger CAPA, and drive supplier audit actions.
Sterilization and infection-control equipment. Because validation directly impacts sterility assurance, FDA is focused on process monitoring and equipment failure modes. Software changes or sterilization process deviations need to show verified risk-control execution tied directly back to management review oversight.
Aesthetic, pain-management, and regenerative medicine devices. Rapid iteration cycles and heavy reliance on contract manufacturing put purchasing and complaint feedback risk in focus here. User feedback, including off-label use trends or adverse event signals, must immediately update risk evaluations and alter incoming lot control parameters.
Surviving a QMSR inspection was never a document-renaming exercise, and it's not solved by an ISO 13485 certificate either. FDA has explicitly clarified that certification does not exempt a firm from inspection. Organizations should expect every significant quality decision, whether it involves a product, a process, a supplier, or a quality system activity, to answer one question: what is the risk-based rationale for doing it this way? Firms need to be ready to show that the level of control matches the risk involved, backed by objective evidence.
Under QMSR, risk-based thinking has moved from a product engineering discipline to an operating principle that runs through the entire quality management system.
This is where a lot of organizations need a second set of eyes. Medicept's quality and regulatory teams help you translate QMSR's risk-based expectations into a defensible, evidence-backed quality system, from supplier oversight and CAPA design to management review metrics and mock inspection readiness. If your QMS can still explain “why” behind every major decision, we can help you build that case before FDA asks for it.
Clarity. Not complications. If QMSR has you reassessing your inspection readiness, we're glad to talk it through.
Talk to a Medicept quality strategist →
Melissa has over 25 years of medical device quality system and regulatory compliance experience. Although her focused area of expertise is in medical device regulatory affairs she has worked across the full product lifecycle, from development to post-market activities. Melissa excels in cross-functional collaboration, using her expertise to support new product development and assess design changes. With significant experience in Quality Management System (QMS) development and improvement, Melissa has also guided companies through ISO certification, demonstrating a comprehensive understanding of regulatory compliance and quality assurance. As a certified lead auditor, she has successfully prepared clients for and conducted internal and supplier audits, as well as hosted FDA and notified body inspections.
As a Director, Regulatory Affairs, Melissa is an integral part of the Medicept executive management team, focused on the day to day operations within regulatory affairs as well as the development and cultivation of long-term client relationships. In addition, she provides strategic client consulting and education services and leads the Medicept Regulatory Affairs Team.
Before joining Medicept in 2025, she was a quality and regulatory consultant at RQM+. She also held various Quality and Regulatory positions in industry at Peregrine Surgical, Tiercel Surgical, HR Pharmaceuticals, DENTSPLY, Unilife Medical Solutions and Lonza Biologics.
Melissa holds a B.S. degree in Biology and MBA from Mount Saint Mary's College and a graduate certificate in Regulatory Affairs from Hood College. She is a member of RAPS and holds various community volunteer positions.
Ryan has over 15 years of medical device R&D, quality system, quality engineering, and regulatory compliance experience. He has successfully designed and implemented quality management systems and regulatory approaches for companies, which have been reviewed and accepted by global regulatory agencies. He has performed many Quality Management System audits and has educated numerous medical device companies on US and international standards. His areas of expertise include all aspects of QMS remediation, QMS development and implementation, CAPA programs, document management systems, and integration of risk management and cybersecurity throughout the product development lifecycle. Ryan has familiarity with the new U.S. FDA 21 CFR Part 820 Quality Management System Regulation (QMSR), working knowledge of 21 CFR Part 820 Quality System Regulation (QSR), EU Medical Device Regulation (MDR) 2017/745 and the Medical Device Single Audit Program (MDSAP).
As Manager of Quality Systems, Ryan is responsible for leading the Quality Systems team, collaborating with other leaders, and creating strong relationships with clients, to provide proven solutions in quality systems, quality engineering, regulatory affairs, risk management, human factors, cybersecurity, and clinical trials. This includes developing and implementing design controls, design change management, customer complaint programs, non-conformance and CAPA management, and associated training programs.
Before joining Medicept in 2023, Ryan served in Quality & Regulatory leadership roles at medical device and biotechnology companies, as well as organizations which provide products and services to the medical device and biotechnology industries. He has successfully led the submission and approval of two 510(k) packages, including pre-submission meetings, review & creation and submission and has held positions as primary contact for regulatory inspections and inquiries.
Ryan achieved the certification for CQI and IRCA-certified QMS Lead Auditor based on ISO 13485:2016 and MDSAP requirements, issued by NSF in November 2023.
Ryan holds a master's degree in engineering management from Case Western Reserve University. He is a member of Regulatory Affairs Professional Society (RAPS).
Medicept is your integrated lifecycle partner, bringing regulatory, quality, clinical, and commercialization expertise together in one team to move medical technologies from concept to patients, faster and with confidence. With 30+ years supporting medical devices, 600+ regulatory submissions, and a clinical leadership bench with 125+ years of combined oncology and device experience across 25+ countries, we help reduce risk and keep critical programs moving. Because patients are waiting.
What is QMSR and when did it take effect?
QMSR is FDA's Quality Management System Regulation, which took effect February 2, 2026. It aligns FDA's quality system requirements more closely with ISO 13485:2016 and replaces the older Quality System Inspection Technique (QSIT) with the risk-informed Compliance Program 7382.850.
Does an ISO 13485 certificate exempt a company from FDA inspection under QMSR?
No. FDA has explicitly clarified that ISO 13485 certification does not exempt a firm from inspection. Investigators still assess whether a company's quality system demonstrably controls risk, certificate or not.
What records can FDA inspect under QMSR that it couldn't before?
FDA investigators now have explicit authority to inspect records such as management review minutes, internal quality audits, supplier audit reports, and legacy QMS files created before QMSR's effective date.
What's the difference between QSIT and Compliance Program 7382.850?
QSIT was a procedural, checklist-based inspection technique. CP 7382.850 is risk-informed, meaning investigators evaluate whether a quality system's design and execution are commensurate with the risks it's meant to control, not just whether procedures exist on paper.
Which quality system areas are drawing the most Form 483 observations under QMSR?
Early CDRH reporting identifies risk management as the top observation category, followed by outsourcing and purchasing controls, complaint handling and feedback, UDI tracking, and CAPA.