Life Science Outsourcing
spoke

ISO 13485 Certified Is Not QMSR Compliant

g

geannina

ISO 13485 Certified Is Not QMSR Compliant

A current ISO 13485:2016 certificate proves one thing: a registrar found your quality system conformed to the standard on the days it assessed you. It does not prove you comply with FDA's Quality Management System Regulation. FDA says so plainly. The agency will neither require nor issue ISO 13485 certificates of conformance, and holding one does not exempt a manufacturer from inspection (FDA, QMSR Frequently Asked Questions).

For years that gap was mostly academic for U.S. manufacturers, who ran the old regulation and treated the certificate as a separate export credential. It isn't academic anymore. The framework changed, the inspection model changed, and early enforcement data suggest FDA is looking hard at the parts a registrar audit never touches.

What the QMSR actually adopted

On February 2, 2026, the QMSR replaced the prior Quality System Regulation and incorporated ISO 13485:2016 by reference into 21 CFR Part 820. It applies to finished device manufacturers who intend to commercially distribute devices in the United States (FDA, Quality Management System Regulation).

Here is the part that trips people up. The QMSR is the standard, but not only the standard. It requires compliance with ISO 13485:2016 plus additional FDA-specific requirements under the Federal Food, Drug, and Cosmetic Act (Covington & Burling, analysis of the QMSR final rule). Your certificate covers the ISO layer. It says nothing about the FDA layer sitting on top of it.

And where the two conflict, U.S. statutory law wins. ISO 13485 supplies the quality-system framework; U.S. statutory definitions and FDA-specific requirements determine compliance. The differing statutory definitions of the word "device" are a clean illustration of why the standard alone cannot settle a compliance question (Naveen Agarwal, QMSR QuickTake #15).

The overlays a registrar audit never tests

A registrar assesses conformance to ISO 13485:2016. That is the whole scope of the engagement. It does not assess the FDA-specific obligations the QMSR layers on, and those obligations are exactly where certified-but-noncompliant firms get caught.

Unique device identification, U.S. labeling requirements, and medical device reporting and complaint-handling tied to the FD&C Act all live outside the ISO scope a certificate confirms. A registrar can find your complaint-handling procedure fully conformant to the standard and never once check whether your reportable-event decisions meet FDA's timelines. Both statements can be true on the same day.

There is a second, quieter gap: evidence depth. Under the QMSR, design controls flow through ISO 13485:2016 Clause 7.3, corrective and preventive action through Clause 8.5.2 and 8.5.3, and document control through Clause 4.2. A certificate tells you a registrar sampled those clauses and found them satisfied on an audit day. An FDA investigator does not sample the certificate. They pull the design history records, the CAPA files, the process validation reports, and they ask you to walk the evidence. The certificate is a snapshot. The inspection is a proof.

The inspection model changed too

FDA retired the Quality System Inspection Technique on February 2, 2026 and moved to a risk-based inspection model governed by Compliance Program 7382.850 (Gardner Law, on the QMSR transition). The old QSIT gave firms a predictable, four-subsystem map to prepare against. That map is gone. Risk-based inspection means the investigator follows the evidence and the risk, not a fixed checklist you can rehearse.

Early post-QMSR enforcement data point in a consistent direction. cloudtheapp.com/fda-enforcement-trends-q1-2026-what-warning-letters-and-483s-tell-quality-teams/)). Treat that as a first-quarter signal, not a settled trend. The sample is small and the window is narrow. But the direction is worth noticing, because management responsibility and risk-management integration are precisely the areas a document-focused certification audit is weakest at probing. A registrar can confirm you have a management review procedure. An investigator asks whether management actually acted on what the reviews surfaced.

What this means if you're qualifying or consolidating contract manufacturers

For an OEM building a supplier base, the lesson is direct: a contract manufacturer's ISO 13485 certificate is a screening signal, not a compliance guarantee. It gets a vendor onto your shortlist. It does not tell you whether that vendor's design records, supplier controls, and process validation evidence will hold up when an investigator walks them, and under the QMSR your CM's records become part of your regulatory exposure.

So qualify substance, not the badge. When you audit a CM, go past the certificate to the evidence behind the clauses that matter most for your product: the design history under Clause 7.3, the CAPA records under Clause 8.5, the validation files for the processes you're outsourcing. Ask how the CM handles the FDA-specific overlays the certificate does not cover, particularly complaint handling, reporting decisions, and UDI. Ask to see a recent management review and what changed because of it. A mature CM will have those records ready and legible. A vendor that treats the certificate as the finish line will not.

The same discipline applies to your own house. If your QMS was built to pass a registrar audit, it is optimized for conformance on an announced day, not for surviving an unannounced, risk-based FDA inspection. Those are related goals. They are not the same goal.

The certificate still matters. It is real evidence that a competent third party assessed your system against a rigorous standard. Just do not mistake it for the thing FDA is actually going to measure. Certification proves your framework conforms. Compliance proves your records do the work the framework promises. Under the QMSR, the second one is what gets inspected.

If you're consolidating contract manufacturing partners or requalifying an existing one under the QMSR, our quality team can walk through your supplier-qualification criteria and evidence expectations in a 30-minute technical review.

Request a Quote

Ship faster with fewer vendors

LSO consolidates assembly, packaging, validation, and sterilization under one roof — FDA-registered, ISO 13485-certified, across three facilities. Tell us about your device and we'll map the fastest path to production.

Or call us directly: (714) 672-1090