QMSR Inspection Readiness: Mapping What Auditors Want
The planning window closed on February 2, 2026. That was the day the FDA's Quality Management System Regulation (QMSR) took effect, amending 21 CFR Part 820 to incorporate ISO 13485:2016 by reference (FDA, Quality Management System Regulation (QMSR)). Two years of transition runway are behind us. What matters now is whether your quality system, and every outsourced process feeding it, produces the records an investigator asks for on the day they walk in.
Here is the part a lot of teams underestimated. QMSR did not just swap terminology. It retired the inspection playbook. As of the effective date, FDA no longer uses the Quality System Inspection Technique (QSIT) and instead inspects under Compliance Program 7382.850 (FDA, QMSR Final Rule FAQ). If your internal audit program, your mock-inspection scripts, and your CM's evidence packages were all built around the four QSIT subsystems, they were built for a framework that no longer governs the visit.
This piece is for QA/RA directors who own inspection readiness across a supply chain, not just inside their own four walls. LSO's quality system was already aligned to ISO 13485:2016 before the transition, which means the mapping work below is not theoretical for us. It is how we operate.
ISO 13485 certification does not buy you an exemption
Start with the misconception that keeps surfacing. Holding an ISO 13485 certificate does not exempt a firm from FDA inspection, and it does not stand in for the records you have to produce during one. FDA states this plainly in its QMSR FAQ: firms must be prepared to demonstrate QMSR compliance with records during an inspection, certificate or not (FDA, QMSR Final Rule FAQ).
That distinction matters most at the OEM-CM boundary. Your contract manufacturer may hold a clean ISO 13485 certificate and pass MDSAP audits. Good. But when an FDA investigator inspecting your finished device follows a process into an outsourced operation, the question is not "does your CM have a certificate." The question is whether the objective evidence exists, is retrievable, and ties back to the specific lots and design inputs under review. Certification is a starting position. Records are the finish line.
The records moved. Did your document structure follow?
QMSR eliminated the QSR-era Device Master Record and Device History Record concepts. Documentation now organizes as a Medical Device File under ISO 13485:2016 Clause 4.2.3, with device-specific records maintained under Clause 4.2.5 (ISO 13485:2016 Clauses 4.2.3 and 4.2.5, incorporated by reference under QMSR).
The risk here is quiet. Many firms mapped old terms to new ones on a spreadsheet and called it done. The DMR became "the Medical Device File," the DHR became "device records," and the actual filing structure, index, and retrieval logic never changed. An investigator working under 7382.850 is not going to ask for your DMR by name. They are going to ask to see the documentation that defines the device and the records that show it was built to that definition. If your CM still hands over a folder labeled "DHR" while your procedures reference a Medical Device File that lives somewhere else, you have a traceability seam that shows up as an observation.
It is also exactly the work that determines whether an inspection goes smoothly.
Where the outsourced-process evidence lives
The subsystems most exposed at an OEM inspection are the ones you do not run yourself. Sterilization validation. Packaging validation. Cleaning and environmental controls in assembly. These are the areas where the finished-device manufacturer carries the regulatory obligation but the actual work, and the actual records, sit at a contract facility.
A few examples of what an investigator can reasonably follow into an outsourced operation:
- Packaging and sterile barrier validation. Seal strength, integrity, and accelerated aging records tied to your specific configuration, under the ISO 11607-1:2019 and ISO 11607-2:2019 framework. If those studies were run at a testing lab, the data has to be retrievable and defensible without a re-test scramble.
- Sterilization validation. Cycle development, dose-setting, and bioburden records for the method your device uses, with the documentation trail intact from protocol through report.
- Environmental and contamination control. Work-environment controls now flow through ISO 13485:2016 Clause 6.4 rather than the removed QSR production-and-process-controls prose. Monitoring records for the cleanroom your device was assembled in are part of that evidence.
The common failure is not that the work was done badly. It is that the evidence is scattered across vendors, formatted inconsistently, and never assembled into a package that survives a records request in real time.
One practical advantage worth naming: LSO's packaging test lab in Brea is accredited to ISO/IEC 17025:2017 by Perry Johnson Laboratory Accreditation (PJLA-accredited, certificate L26-623). Test data from an independently assessed lab holds up in FDA submissions and audits without re-testing questions, because the competence of the lab that generated it has already been assessed against an international standard. The accredited scope covers specific methods, including seal strength by ASTM F88, integrity testing by ASTM F2096, F1929, and F3039, and accelerated aging by ASTM F1980. When the investigator follows your packaging validation into our lab, the accreditation is part of why the data does not become a discussion.
Map readiness to how you will actually be inspected
The 7382.850 compliance program is the framework now. That tracks with what we see. The transition was treated as a documentation exercise when it is really an integration exercise: design inputs, risk management, supplier controls, and postmarket data all have to connect.
A workable readiness approach for an OEM managing contract manufacturers:
First, rebuild your mock inspections around the current compliance program, not the retired QSIT subsystems. If your internal audit checklist still says "management controls, design controls, CAPA, production and process controls" as four QSIT pillars, it is auditing to a framework FDA no longer uses.
Second, run a records-retrieval drill at the supplier boundary. Pick a lot. Ask your CM to produce the Medical Device File elements and device records for it, in the format and timeframe an investigator would expect. Time it. The gap between "we have it somewhere" and "here it is" is the gap that becomes an observation.
Third, confirm your quality agreements name the current framework. Agreements that still reference the DMR, the DHR, or 21 CFR 820 subpart language need updating to reflect the Medical Device File structure and the ISO 13485:2016 clauses the requirements now flow through. This is its own topic, and one worth a dedicated review before your next audit cycle.
FDA has continued to refine the rule since it took effect, including technical amendments published in a December 4, 2025 Federal Register notice that clarify provisions layered atop the ISO 13485 incorporation (Federal Register, Medical Devices; Quality Management System Regulation Technical Amendments). For premarket-stage teams, FDA also issued October 2025 draft guidance on the QMS information expected in PMA and HDE submissions (RAPS, FDA issues draft guidance on QMSR information for premarket submissions). Startups building a first quality system have an advantage here: you are not remapping a QSR-era architecture, you are building to ISO 13485:2016 from the start. Build the Medical Device File structure correctly the first time and you skip the retrofit entirely.
What LSO brings to the inspection
When an FDA investigator follows a process from your finished device into our facility, the evidence is already structured to the QMSR framework. Our quality system was aligned to ISO 13485:2016 before February 2, 2026, our packaging test data comes from an ISO/IEC 17025-accredited lab, and our documentation is organized as Medical Device File and device records rather than legacy DMR and DHR folders. That means the outsourced-process portion of your inspection is a controlled handoff, not a scramble.
We can also map, subsystem by subsystem, what an investigator is likely to request in the areas we handle for you, and show you the records that answer each request before the inspection ever happens. That is the difference between hoping the supply chain holds up and knowing it will.
