The QMSR Era: What Changed for OEMs and Their CMs
The regulation you built your quality system around no longer reads the way it did a year ago. As of February 2, 2026, FDA's Quality System Regulation is gone in the form most quality directors memorized. In its place sits the Quality Management System Regulation, the QMSR, which amends 21 CFR Part 820 by incorporating ISO 13485:2016 by reference and layering a small set of FDA-specific requirements on top.
If your procedures still point to design controls at 820.30 and purchasing controls at 820.50, they now cite prose that has been removed from the regulation. The requirements did not vanish. They moved. Design controls now live in ISO 13485:2016 Clause 7.3, purchasing in Clause 7.4, CAPA in Clause 8.5. The obligation is the same; the address changed.
That sounds like a documentation exercise, and for a mature quality system a good part of it is. But the transition also changed how FDA inspects, how premarket submissions describe your quality system, and, for any OEM that outsources manufacturing, how you are expected to prove control over work you do not perform yourself. This article walks the whole chain: what the QMSR is, what moved where, what investigators now expect, and how contract manufacturer qualification fits into a QMSR-compliant quality system.
What the QMSR actually is
Start with the mechanics, because the phrase "incorporates ISO 13485:2016 by reference" carries more weight than it first appears.
FDA published the QMSR final rule in February 2024 with a two-year transition period before the February 2, 2026 compliance date. Incorporation by reference means the text of ISO 13485:2016 now carries the force of federal regulation. You do not comply with ISO 13485 as an optional certification and Part 820 as the real requirement. Under the QMSR, the standard is the requirement for most of the quality system, and it is enforceable as such.
The rule also pulls in ISO 9000:2015 Clause 3 for terminology. That matters more than it sounds, because a large share of the transition work is vocabulary. The old subpart language and the ISO clause language describe overlapping concepts with different words, and the words are now the legally operative ones.
Here is the part that trips people up. ISO 13485:2016 compliance alone does not satisfy the QMSR. FDA retained a set of supplemental requirements that clarify or add to concepts in the standard, covering areas like device labeling and packaging control, unique device identification, and specific records provisions. An organization holding a clean ISO 13485:2016 certificate is well positioned, but a certificate is not a compliance pass. The FDA-specific provisions still apply, and an investigator will still check them.
So the accurate mental model is not "FDA adopted ISO 13485." It is "FDA built its device quality regulation on top of ISO 13485:2016 and kept the pieces the standard does not cover."
The map: where the requirements moved
Most of the practical transition is a remapping problem. The functions you already run map to ISO 13485 clauses, and your job is to preserve traceability across the move so an auditor pulling a thread in 2027 can still follow it back through work performed under the old structure.
AAMI, analyzing the shift, characterized it as structural rather than substantive: the move from Part 820's subpart organization to ISO 13485's clause-based organization introduces more than 100 terminology updates across the total product lifecycle, and preserving documentation traceability requires deliberate mapping. Read that carefully. AAMI is saying the underlying expectations did not change much, but the labels did, and if you do not manage the relabeling your records stop lining up with the regulation that governs them.
The headline moves for an OEM quality system:
Design controls are now addressed under ISO 13485:2016 Clause 7.3, Design and development, in place of the former design-controls subpart. The design and development planning, inputs, outputs, review, verification, validation, and transfer activities you already run all sit here. Clause 7.3 also carries an explicit design and development files requirement, which formalizes something the old subpart implied.
Control of outsourced processes is the one to slow down on, because it is not in the purchasing clause where instinct sends you. It sits in Clause 4.1, the general quality management system requirements. Clause 4.1 requires that when you outsource a process that affects product conformity, you retain control over it and document that control within your quality system. For an OEM that manufactures through a contract manufacturer, that single clause is the spine of the whole relationship. More on that below.
CAPA maps to ISO 13485:2016, split across Clause 8.5.2 for corrective action and Clause 8.5.3 for preventive action. The single CAPA subpart most quality systems were built around is now two distinct clauses. If your procedure bundles corrective and preventive action into one workflow with one label, this is a good moment to check that both halves are visibly satisfied.
The records vocabulary changed too, and this one catches people off guard during inspections. The Device Master Record concept is replaced by the Medical Device File under Clause 4.2.3, and the Device History Record maps to the records requirements under Clause 4.2.5. If your document control system still indexes everything as DMR and DHR, it will function, but an investigator asking for the Medical Device File and getting handed something labeled DMR is one more small friction in an inspection where friction reads as disorganization.
None of these moves changes what a good quality system does. They change what it is called and where it is filed. The risk is not that the requirement disappeared. The risk is that your procedures, work instructions, and training records still speak the old dialect, and the gap between what your documents say and what the regulation now says is exactly the kind of thing an inspection surfaces.
What changed for FDA inspections
The change that will show up first in most quality directors' lives is the inspection.
FDA discontinued the Quality System Inspection Technique, the QSIT that structured device inspections for two decades, and now inspects under the updated Compliance Program 7382.850 aligned to the QMSR framework. If your internal audit program, your mock inspections, and your inspection-readiness training were all built around the four QSIT subsystems, that scaffolding no longer matches how the agency approaches your facility.
The deeper shift is one the industry press has framed well. With the compliance date now behind us, the operative question changed from "are we ready?" to "can we demonstrate it?" Readiness was a project with a deadline. Demonstrability is a permanent condition. An investigator is not asking whether you updated your procedures before February 2026. They are asking you to show, from records, that the system operates the way the documents claim.
That is a subtle but real change in burden. Under the old prescriptive framework, an inspection often turned on whether a required procedure existed and named the required elements. ISO 13485:2016 is built around a risk-based, process-effectiveness logic, which means "we have a procedure" is table stakes and "here is the objective evidence that the procedure produced the intended result" is the actual bar. MD+DI, comparing the two frameworks, noted this move from a prescriptive to a risk-based philosophy directly, and flagged that ISO 13485 compliance alone does not close residual FDA-specific provisions.
For a quality director, the practical translation is this. Rewrite the internal audit program against the clause structure and Compliance Program 7382.850 rather than QSIT. Make sure every claim your quality manual makes is backed by retrievable records. And treat the risk basis of each control as something you can articulate, because a risk-based framework invites the investigator to ask why a control is calibrated the way it is, not just whether it exists.
The premarket-submission wrinkle
There is a piece of this transition that affects regulatory leads more than quality directors, and it is still moving.
FDA issued draft guidance in October 2025 recommending that PMA and HDE premarket submissions include quality system information mapped to ISO 13485, with early cross-functional gap analyses to support it. As of that analysis, FDA had not issued parallel guidance for 510(k) or de novo submissions, which is where most Class II devices clear.
So if you are preparing a PMA or HDE, the expectation to present ISO 13485-mapped quality system documentation is now explicit in draft form. If you are on a 510(k) or de novo pathway, the equivalent guidance had not landed at the time of that analysis, and the status may have shifted since. Verify the current guidance state before you build your submission strategy around it. This is a genuinely fluid corner of the transition, and getting it wrong means either over-documenting a submission or, worse, under-documenting one.
Where the contract manufacturer relationship changes
Everything above applies whether you manufacture in-house or outsource. This section is why the outsourcing OEM should read the QMSR transition differently from a fully vertically integrated one.
When you outsource manufacturing, the QMSR does not outsource your responsibility. Clause 4.1's control-of-outsourced-processes requirement means the process your contract manufacturer runs is still your process for regulatory purposes, and you must retain and document control over it within your own quality management system. The CM performs the work. You own the conformity. That has always been broadly true, but the QMSR framework makes the demonstrability of that control an explicit, inspectable element of your system.
Think about the demonstrability burden from the last section and extend it across the organizational boundary. When an investigator asks you to show that a manufacturing control produced the intended result, and that control physically runs at a contract manufacturer three time zones away, you are the one who has to produce the evidence. Not your CM. You. Your quality system has to hold the objective evidence that the outsourced process is controlled, monitored, and producing conforming product, or that it can be retrieved on demand through the CM under your agreement.
That reframes contract manufacturer qualification from a purchasing formality into a load-bearing part of your QMSR compliance. Three things carry that weight:
Supplier evaluation and selection under Clause 7.4. Your qualification of a contract manufacturer has to be a documented, risk-based evaluation, not a certificate check. A CM's own ISO 13485:2016 certification is meaningful evidence, and it is the right starting screen, but under the same logic that a certificate does not make you QMSR-compliant, a supplier's certificate does not discharge your evaluation obligation. You still have to assess whether their controls fit your device, your risk profile, and your specifications.
Outsourced-process control under Clause 4.1. This is where the quality agreement earns its place. The agreement is the instrument that documents which party controls what, how deviations and nonconformances flow back to you, who owns CAPA when a manufacturing problem originates at the CM, what change control notification you receive before the CM alters a validated process, and what records the CM holds on your behalf and makes available for inspection. If those mechanics are not written down and operating, your Clause 4.1 control is a claim without evidence.
CAPA coordination across the boundary under Clause 8.5. When a nonconformance at the CM triggers corrective action, both quality systems are involved, and the interfaces have to be defined. Whose CAPA system is the system of record? How does a preventive action identified at the CM reach your risk file? Under Clause 8.5.2 and 8.5.3, the corrective and preventive halves are distinct, and across an outsourced relationship the coordination of both halves is something an investigator can reasonably ask you to demonstrate.
There is a consolidation angle here that operations executives will recognize. Every contract manufacturer in your supply base is a separate outsourced-process control problem, a separate quality agreement, a separate qualification file, a separate CAPA interface, and a separate line on your inspection-readiness burden. The more CMs, the more surfaces where the demonstrability gap can open. Reducing the number of manufacturing partners, or concentrating multiple services with a single partner whose quality system you have qualified once and monitor continuously, is not only a cost-of-quality argument. Under the QMSR's demonstrability logic, it is a compliance-surface argument.
When an OEM evaluates a contract manufacturer under the QMSR, the questions worth asking cut in a specific direction. Is the CM's quality system genuinely built to ISO 13485:2016, with the clause structure reflected in how they actually operate rather than a certificate on the wall? Can they produce the objective evidence you will need to demonstrate outsourced-process control, on your timeline, in an inspection? Do they understand that the FDA-specific supplemental requirements ride along with the standard, so that labeling, UDI, and records controls at their facility support your obligations, not just their certificate? Is their CAPA system mature enough to interface cleanly with yours? A CM that treats these as routine is a CM whose quality system reduces your compliance surface instead of adding to it.
For the startup building its first quality system
A note for the smaller audience here, because the QMSR transition lands differently on a company that never operated under the old QSR.
If you are a startup building your first quality system in 2026, you have an advantage the incumbents do not. You are not remapping a decade of procedures written in the old subpart dialect. You get to build directly on ISO 13485:2016's clause structure, which is the structure the QMSR now enforces and the structure most of the rest of the regulated world already uses. Build design controls into Clause 7.3 from the first design review. Structure your records as the Medical Device File under Clause 4.2.3 rather than learning DMR terminology you will only have to unlearn.
MD+DI flagged that the transition costs fall hardest on small and mid-sized manufacturers without established ISO systems. That is true for companies retrofitting. For a company starting clean, the opposite can hold: you skip the retrofit entirely if you build native to the standard.
The one thing not to skip, even early, is the outsourced-process logic. If you are a startup, you are almost certainly outsourcing manufacturing, packaging, sterilization, or all three. Clause 4.1 makes you responsible for controlling those processes inside your quality system from day one. A contract manufacturer whose quality system is already QMSR-aligned, and whose test data comes from accredited labs, does a lot of that heavy lifting for you and strengthens your submission file at the same time. Packaging validation test data from an ISO/IEC 17025:2017-accredited lab, for instance, holds up in an FDA submission without triggering re-testing questions, because the data comes from an independently assessed lab. That is one fewer gap for you to close before clearance.
What to do now
The transition date has passed, so the work is no longer a project with an end. It is the operating condition of a QMSR quality system. A short punch list for a mature OEM:
- Confirm every procedure, work instruction, and training record speaks the ISO 13485:2016 clause vocabulary, not removed subpart language, and that the terminology mapping is documented so records created under the old structure still trace cleanly.
- Rebuild internal audits and mock inspections around the clause structure and Compliance Program 7382.850 rather than the retired QSIT subsystems.
- Verify that every claim your quality manual makes is backed by retrievable objective evidence, because the inspection question is now demonstrability, not existence.
- Re-examine each contract manufacturer relationship as a Clause 4.1 outsourced-process control problem: is the quality agreement current, is control documented, do CAPA and change-control interfaces actually operate?
- For any active PMA or HDE submission, incorporate ISO 13485-mapped quality system documentation per the October 2025 draft guidance, and verify the current guidance status for 510(k) and de novo pathways before assuming it does or does not apply.
This pillar anchors LSO's Quality and Regulatory Systems hub. Companion articles go deeper on the pieces that matter most to an outsourcing OEM: what investigators now expect from a contract manufacturer's quality system during a QMSR inspection, what a quality agreement needs to cover under the new framework, how CAPA practice shifts moving from the QSR playbook to Clause 8.5, a supplier-qualification and CM-audit checklist for quality directors, and the practical implications of running design controls through Clause 7.3.
The QMSR did not make quality systems harder in principle. It harmonized the U.S. framework with the standard most of the world already runs on, which over time makes multi-market compliance simpler. What it did was raise the bar on proof, and for OEMs that outsource, it extended that proof burden across every manufacturing partner in the supply base. The companies that come through the first inspection cycle cleanly will be the ones whose quality systems, and whose contract manufacturers' quality systems, were built to be demonstrated, not just described.
