resources
How ISO 13485 Contract Manufacturers Support FDA QMSR Compliance in 2026
/)
/)
Published on 29th Sept 2026
On 2 February 2026, the FDA's Quality Management System Regulation (QMSR) came into force, replacing the 1996 Quality System Regulation (QSR) under 21 CFR Part 820. The change is not cosmetic. By incorporating ISO 13485:2016 by reference as the legal foundation for US medical device manufacturing, the FDA has fundamentally restructured how compliance is demonstrated, how inspections are conducted, and, critically, how the quality of outsourced manufacturing is evaluated.
For finished device manufacturers who rely on contract manufacturing partners, the implications are immediate. Supplier audit reports and quality agreements with contract manufacturers are no longer shielded from FDA review. Under the previous QSR, records such as internal audits and supplier audit reports were categorically exempt from inspection under §820.180(c). That exemption no longer exists under QMSR.
The practical consequence: if your contract manufacturer's quality system cannot withstand FDA scrutiny, that exposure now sits directly on your establishment's inspection record.
This guide explains what QMSR requires of outsourced manufacturing relationships, what an ISO 13485-certified contract manufacturer provides in that context, and what device OEMs should verify before and during a manufacturing partnership.
The QMSR final rule was published on 31 January 2024 and took effect on 2 February 2026, giving manufacturers a two-year transition period. The core structural change is that the FDA incorporated ISO 13485:2016 by reference into 21 CFR Part 820, making compliance with the international standard a legal requirement rather than a voluntary benchmark.
For most finished device manufacturers, the clause-level requirements of ISO 13485 were already familiar. The more significant operational shift is in how those requirements are now enforced, particularly regarding outsourced processes.
Under the old QSR, the FDA could not inspect certain categories of records during an establishment inspection. That protection is gone. As confirmed in the FDA's QMSR FAQ, the agency now has authority to review:
Internal audit reports and findings
Supplier audit reports
Management review minutes and records
Quality agreements with contract manufacturers
Supplier qualification records and approved supplier lists
Receiving inspection documentation and supplier corrective action records
This is a material change. Previously, a device manufacturer could maintain documented supplier controls without those controls being directly testable by an FDA investigator. Under QMSR, the investigator can review supplier audit reports to verify that purchasing controls stated in a PMA application are actually being executed.
Alongside the rule change, the FDA retired the Quality System Inspection Technique (QSIT) and replaced it with Compliance Program 7382.850. Where QSIT organised inspections around four major subsystems, CP 7382.850 uses six QMS areas mapped directly to ISO 13485:2016 clauses.
One of those six areas is Outsourcing and Purchasing, which maps to ISO 13485 Clauses 4.1.5 and 7.4. Under this area, FDA investigators evaluate:
Supplier qualification criteria and the approved supplier list
Purchasing process controls and purchasing information adequacy
Verification of purchased product
Quality agreements with contract manufacturers
Supplier performance metrics and corrective action records
The inspection standard has shifted from "do you have procedures?" to "does your quality system function as an integrated, risk-driven whole?" A contract manufacturer that holds ISO 13485 certification provides documented evidence of exactly that, reducing the burden of proof on the finished device manufacturer.
QMSR and ISO 13485 both require that supplier oversight be proportionate to risk. Critical component suppliers and contract manufacturers performing complex assembly operations require more rigorous controls than commodity suppliers. This means the quality agreement, qualification evidence, and ongoing monitoring records for a contract manufacturer producing Class II or Class IIb device assemblies will receive close scrutiny during an FDA inspection.
ISO 13485:2016 is the international standard for quality management systems specific to medical device manufacturing. Certification means a third-party notified body has audited the manufacturer's QMS against the standard's requirements and confirmed conformance. Under QMSR, ISO 13485 is no longer merely a useful credential; it is the regulatory framework itself.
It is important to understand what certification does and does not provide under QMSR:
ISO 13485 certification does not exempt a contract manufacturer from FDA inspections, and the FDA will not issue certificates of conformance to ISO 13485 as a result of an inspection. However, a certified contract manufacturer provides the finished device manufacturer with structured, auditable evidence of QMS conformance that directly supports the supplier qualification and ongoing monitoring requirements of QMSR.
An ISO 13485-certified contract manufacturer operates documented controls across the following areas, all of which are directly relevant to a finished device manufacturer's QMSR obligations:
ISO 13485 Clause | Requirement | Relevance to OEM's QMSR Position |
|---|---|---|
4.1 | General QMS requirements including outsourced process controls | Demonstrates the CM manages its own supply chain under a documented QMS |
6.4 | Work environment and contamination control | Critical for cleanroom-dependent assemblies; directly auditable under CP 7382.850 |
7.4 | Purchasing controls including supplier evaluation and re-assessment | Reduces the OEM's need to audit the CM's sub-tier suppliers independently |
7.5 | Production and service provision including process validation | Confirms manufacturing processes are validated, not just documented |
7.6 | Control of monitoring and measurement equipment | Calibration traceability required for medical device production |
8.2.4 | Internal audit programme | Audit records now inspectable by FDA; a functioning programme is evidence of a live QMS |
8.5 | CAPA and continual improvement | Demonstrates systematic defect resolution rather than reactive firefighting |
Under QMSR and ISO 13485 Clause 7.4, the quality agreement between a finished device manufacturer and a contract manufacturer is the primary document defining the division of regulatory responsibilities. FDA investigators reviewing outsourcing and purchasing controls will examine this agreement directly.
A well-structured quality agreement with an ISO 13485-certified contract manufacturer should specify:
Scope of manufacturing activities covered and applicable device classifications
Responsibility for process validation and validation record retention
Change notification requirements and change control procedures
Traceability requirements for components and sub-assemblies
Nonconformance reporting obligations and CAPA responsibilities
Record retention periods and FDA access provisions
Right-to-audit clauses and frequency of scheduled audits
A contract manufacturer that operates under a certified QMS will typically have standard quality agreement templates that address these elements, reducing the legal and administrative burden on the OEM.
For device assemblies requiring controlled environments, ISO 13485 Clause 6.4 requires documented work environment controls, including contamination control measures. Under CP 7382.850, FDA investigators evaluate infrastructure appropriateness and contamination control as part of the Resource Management inspection area.
Contract manufacturers operating certified cleanrooms to ISO 14644 standards provide the OEM with documented environmental classification data, particle count records, and gowning and access controls that directly satisfy this requirement. This is particularly relevant for Class II and Class IIb device assemblies where particulate contamination can constitute a product safety risk.
Given that supplier audit reports and quality agreements are now directly inspectable by the FDA, the due diligence a finished device manufacturer conducts before and during a contract manufacturing relationship carries real regulatory weight. The following checklist reflects the records and evidence an FDA investigator may request under CP 7382.850's Outsourcing and Purchasing area.
Conduct a structured supplier qualification process before placing production orders. The approved supplier list must document the criteria used to qualify each supplier, and those criteria must be proportionate to the risk profile of the outsourced activity.
Obtain a copy of the contract manufacturer's current ISO 13485 certificate and scope of certification; confirm the scope covers the specific manufacturing activities being outsourced
Review the contract manufacturer's quality manual or QMS overview to confirm documented procedures for the relevant clauses
Conduct an on-site or remote audit against ISO 13485 Clauses 4.1, 7.4, 7.5, and 8.5 as a minimum; document findings and any corrective actions required before qualification
Execute a quality agreement that addresses all elements listed in the previous section
Verify process validation status for any special processes (soldering, overmoulding, cleanroom assembly, sterilisation) relevant to the device
Ongoing monitoring is a QMSR requirement, not a one-time qualification event. FDA investigators will look for evidence that supplier performance is actively tracked and that the oversight intensity is appropriate for the risk level.
Monitoring Activity | Minimum Frequency | Documentation Required |
|---|---|---|
Supplier performance review | Quarterly or per batch depending on volume | Metrics summary, trend analysis |
Re-audit against ISO 13485 | Annually for critical suppliers | Audit report, CAPA log if findings raised |
Quality agreement review | Upon any scope change or regulatory update | Revised agreement, change record |
Nonconformance review | Per occurrence | NCR log, root cause analysis, CAPA closure |
Management review inclusion | Annually | Management review minutes referencing supplier performance |
Under QMSR, the following records may be requested by an FDA investigator during an establishment inspection. They must be factual, complete, and free of characterisations that could be misread as admissions of systemic failure:
Approved supplier list with qualification criteria and dates
Supplier qualification audit reports, including findings and CAPA responses
Quality agreements with all active contract manufacturers
Receiving inspection records and acceptance criteria
Supplier corrective action records and closure evidence
Supplier performance metrics and trend data
The key operational point: these records need to exist and be current before an inspection, not assembled in response to one. A contract manufacturer operating under ISO 13485 will maintain most of these records within its own QMS; the OEM's responsibility is to ensure the quality agreement requires disclosure and that regular audits confirm the records reflect actual practice.
Several misunderstandings about the relationship between ISO 13485 certification and QMSR compliance persist in the industry. These are worth addressing directly because acting on incorrect assumptions creates measurable compliance risk.
Misconception 1: An ISO 13485 certificate is sufficient proof of QMSR compliance.
It is not. The FDA has been explicit that it will not accept an ISO 13485 certificate as a proxy for QMSR compliance and will not exempt certified manufacturers from FDA inspections. Certification demonstrates that a third-party auditor found the QMS conformant at the time of audit. The FDA conducts its own independent assessment.
Misconception 2: If the contract manufacturer holds ISO 13485, the OEM has no further compliance obligation for outsourced activities.
This is incorrect and potentially the most consequential misunderstanding. Under QMSR and ISO 13485 Clause 4.1, the finished device manufacturer retains responsibility for outsourced processes. The OEM cannot transfer regulatory accountability to the contract manufacturer. The quality agreement defines the division of responsibilities, but the OEM remains the regulated entity accountable for the finished device.
Misconception 3: The old QSR supplier control requirements were essentially the same, so nothing has changed operationally.
The clause-level requirements are substantially similar. What changed is enforceability. Records that were previously shielded from FDA review are now inspectable. A supplier control programme that existed on paper but was not actively executed was a lower-risk position under the QSR. Under QMSR, the same programme is directly testable. The FDA has stated that investigators will evaluate whether the quality system functions as an integrated whole, not whether procedures exist.
Misconception 4: MDSAP certification is equivalent to or required for QMSR compliance.
The Medical Device Single Audit Programme (MDSAP) is a separate initiative covering multiple regulatory bodies. The FDA has confirmed that QMSR inspections will not follow the MDSAP audit plan or procedures. MDSAP participation is not required for QMSR compliance, and MDSAP certification does not exempt a manufacturer from QMSR inspections.
The regulatory landscape under QMSR makes the selection of a contract manufacturing partner a compliance decision, not only a commercial one. The quality of the partner's QMS directly affects the OEM's inspection readiness. The following criteria reflect what matters under the new enforcement framework.
Current ISO 13485:2016 certification with a scope that covers the intended manufacturing activities. Confirm the certificate is current, issued by an accredited notified body, and that the scope statement explicitly includes the relevant processes (e.g. SMT assembly, injection moulding, cleanroom assembly, box build integration).
Documented process validation for all special processes. Under ISO 13485 Clause 7.5.6, processes whose output cannot be fully verified by subsequent inspection must be validated. This includes reflow soldering profiles, overmoulding parameters, and any process where defects may only become apparent in use.
Active CAPA system with closed-loop evidence. A CAPA log that shows only open actions is not evidence of a functioning system. Look for completed root cause investigations and verifiable effectiveness checks.
Calibrated measurement and test equipment. ISO 13485 Clause 7.6 requires a documented calibration programme. For device assemblies involving dimensional, electrical, or functional testing, out-of-calibration equipment creates a product release risk that is directly traceable back to the OEM.
Beyond the non-negotiables, certain capabilities in a contract manufacturer reduce the ongoing compliance management workload for the OEM:
Integrated traceability systems that link component lot numbers to finished assembly serial numbers, supporting the OEM's device history record requirements under QMSR
Established change notification procedures that trigger formal review before any material, process, or supplier change is implemented, protecting the OEM from undisclosed changes that could affect device performance or regulatory status
Experience with Class II or Class IIb device programmes, which indicates familiarity with the documentation depth, risk management integration, and design transfer requirements that apply to higher-risk classifications
Cleanroom capability to ISO 14644 where the device assembly requires a controlled particulate environment, providing the OEM with the environmental monitoring data needed to satisfy Clause 6.4
For multinational device programmes, a contract manufacturer operating in Asia with ISO 13485 certification and established quality agreements can provide US-destined device assemblies that satisfy QMSR supplier control requirements. The QMSR applies to finished device manufacturers distributing in the US; it does not require that contract manufacturers be located in the US. What it does require is that the OEM's supplier controls, quality agreements, and audit records are maintained and inspection-ready regardless of where manufacturing occurs.
QMSR enforcement is active. The following points summarise the practical implications for device OEMs managing contract manufacturing relationships:
The §820.180(c) exemption is gone. Supplier audit reports, quality agreements, internal audit records, and management review minutes are all inspectable by FDA investigators as of 2 February 2026.
ISO 13485 certification in a contract manufacturer is necessary but not sufficient. It provides structured evidence of QMS conformance and reduces the OEM's qualification burden. It does not transfer regulatory accountability or exempt either party from FDA inspection.
The quality agreement is the compliance instrument. It must clearly define responsibilities for process validation, change control, traceability, CAPA, and record access. A contract manufacturer operating under ISO 13485 should be able to support a robust quality agreement.
Ongoing monitoring is a regulatory requirement, not a commercial courtesy. Annual re-audits, quarterly performance reviews, and documented nonconformance management are all expected under CP 7382.850's Outsourcing and Purchasing inspection area.
Geographic location of the contract manufacturer is not a compliance barrier. QMSR requires that the OEM's supplier controls are documented and executed; it does not require domestic manufacturing.
For device programmes requiring precision assembly, cleanroom manufacturing, or high-mix low-to-medium volume production, working with an ISO 13485-certified contract manufacturer with documented processes across SMT assembly, injection moulding, and full box build integration provides a defensible and inspection-ready supply chain foundation.
To discuss how FVG's ISO 13485-certified manufacturing operations support QMSR compliance requirements for your device programme, contact our engineering team.