On February 2, 2026, the FDA’s Quality Management System Regulation took effect, revising 21 CFR Part 820 to incorporate ISO 13485:2016 as its foundational framework. For companies that already operated an ISO 13485 quality system, far less changed than the headlines suggested. For companies that did not, the change is more significant.
This guide covers what 21 CFR Part 820 is, what the QMSR revision actually changed, and a question most coverage skips entirely: what the regulation means for a company that develops software for a medical device rather than manufacturing the device itself.
Note: This guide provides general educational information, not legal or regulatory advice. Requirements vary by company role, device, and market. Confirm the requirements that apply to your organization and products.
What Is 21 CFR Part 820?
21 CFR Part 820 is the section of the US Code of Federal Regulations that sets quality system requirements for medical device manufacturers. It is the regulation behind what the industry long called the Quality System Regulation, or QSR, and it is enforced by the FDA through inspection.
Its scope is the organization, not the product. Part 820 governs how a manufacturer controls design, production, documents, records, purchasing, corrective action, and the other processes that together make device quality repeatable rather than accidental. A device is cleared or approved through a separate pathway; Part 820 governs the system that produces it.
That classification question is governed by separate regulations depending on the product, such as the rule defining Medical Device Data Systems.
The regulation applies to finished-device manufacturers that intend to commercially distribute medical devices in the United States. That phrase does a lot of work and is key to understanding who actually bears the obligation, as the later sections of this guide explain.
What the QMSR Changed
The Quality Management System Regulation, effective February 2, 2026, revises Part 820 to incorporate ISO 13485:2016 by reference, while retaining certain FDA-specific requirements in U.S. regulations. In practical terms, FDA moved its quality system framework toward the international standard rather than maintaining a parallel one.
This was a convergence, not a reinvention. FDA itself has characterized ISO 13485 and the prior quality system regulation as substantially similar as a whole. The two frameworks already required the same fundamental things: management responsibility, design controls, document and record control, purchasing controls, corrective and preventive action, and the rest. What differed was terminology, structure, and a number of specifics.
What it means in practice, by starting position
If your organization | The QMSR transition is |
Already operated a certified ISO 13485:2016 quality system | Largely a records- and terminology-mapping exercise rather than a process redesign. The architecture you built to is now the architecture FDA points to. |
Operated only to the prior US quality system regulation | A more substantial alignment effort is needed, since the structure, vocabulary, and some requirements follow ISO 13485 rather than the former Part 820 layout. |
Is not a finished device manufacturer | Largely indirect. Obligations reach you through the manufacturer’s quality system and your contract, not through the regulation applying to you directly. |
It is worth being precise about one thing, because it is widely misunderstood: QMSR is not a new software quality regulation, and it contains no software-specific carve-out. It is a quality system regulation for finished device manufacturers. There is no requirement that an ISO 13485-certified software development organization rewrite its quality management system because QMSR took effect.
Who Part 820 Actually Applies To
This is where most teams get their footing wrong, in both directions. Some assume the regulation binds everyone who touches a device. Others assume that because they are not the manufacturer, none of it reaches them. Neither is right.
If you are the legal manufacturer
If your company is the finished device manufacturer intending to commercially distribute the device, Part 820, as revised by QMSR, applies to you directly across the entire quality system. That includes design controls, purchasing controls, and the obligation to evaluate and control your suppliers. It is not limited to the parts of the device you build in-house.
If you are a supplier
If your company develops software, components, or services for a device that another company manufactures and distributes, the regulation does not apply to you directly. The manufacturer holds the obligation. But it reaches you all the same, through two routes.
The first is supplier controls. The manufacturer is required to evaluate and control its suppliers, which means that your processes, records, and outputs fall under its quality system. In practice, that can mean qualification, audits, quality agreements, and defined acceptance criteria for what you deliver.
The second is allocation. Whatever the manufacturer contractually allocates to you becomes your obligation to meet: design controls for your portion of the work, risk management activities, software lifecycle processes, documentation, traceability, and records that will be included in their design history file. You are not carrying the regulation; you are carrying what the manufacturer’s system assigns to you under it.
A manufacturer choosing a software supplier has to be able to demonstrate that the supplier is controlled. A supplier operating its own certified ISO 13485 quality system removes most of that burden because its processes are already auditable and its records are already in a usable form. A supplier without one shifts that work onto the manufacturer, which is cost, time, and risk the manufacturer has to absorb.
21 CFR Part 820 and ISO 13485: How They Relate Now
Before QMSR, a company selling into both the US and international markets often maintained one quality system mapped to two frameworks, tracking where the prior Part 820 and ISO 13485 diverged. The QMSR revision reduces that divergence considerably by incorporating ISO 13485:2016 into the US regulation.
ISO 13485:2016 | 21 CFR Part 820 as revised by QMSR | |
Nature | Voluntary international standard, certifiable by an accredited body | US federal regulation, enforced by FDA inspection |
Scope | Quality management system for medical devices | Quality management system for finished device manufacturers distributing in the US |
Relationship | Incorporated by reference into the revised US regulation | Incorporates ISO 13485:2016 plus certain FDA-specific requirements |
How you demonstrate it | Certification audit by a notified or certification body | FDA inspection |
Certification to ISO 13485 is not the same as regulatory compliance, nor is it a substitute for it. What certification demonstrates is that an organization operates an audited quality system. Our guide to developing SaMD in conformance with ISO 13485 provides a more in-depth overview of the standard.
What This Means for Medical Device Software
Part 820 and QMSR govern the quality system. They do not describe how to build software. That is the role of other standards, and the distinction matters when planning work.
The quality system provides the framework: design controls, document and record control, supplier controls, change control, and corrective action. IEC 62304 provides the software lifecycle processes that run inside that framework, and ISO 14971 provides the risk management spine running through both. A team that has one without the others has a gap.
For software specifically, the design control expectations are where the quality system and the software lifecycle meet most directly. Design inputs, design outputs, design review, verification, validation, design transfer, and design changes all have software equivalents, and the records that satisfy them are largely the same as those required by IEC 62304. Built well, one set of evidence serves both.
Frequently Asked Questions
What is 21 CFR Part 820?
21 CFR Part 820 is the US federal regulation setting quality system requirements for medical device manufacturers. It governs how a manufacturer controls design, production, records, purchasing, and corrective action. As of February 2, 2026, it was revised by the Quality Management System Regulation to incorporate ISO 13485:2016.
What is the FDA QMSR?
The Quality Management System Regulation is FDA’s revision of 21 CFR Part 820, effective February 2, 2026, which incorporates ISO 13485:2016 as the foundational quality system framework along with certain FDA-specific requirements. It replaced the prior Quality System Regulation approach rather than adding a separate regulation.
Does 21 CFR Part 820 apply to software companies?
Not directly, unless the company is the manufacturer of the finished device. A software supplier developing under a manufacturer’s quality system is subject to supplier controls and to the obligations the manufacturer allocates to it by contract, including design controls, risk management, software lifecycle processes, and documentation.
What is the difference between 21 CFR Part 820 and ISO 13485?
ISO 13485 is a voluntary international standard to which an organization can be certified. 21 CFR Part 820 is a U.S. federal regulation enforced by FDA inspection. Since the QMSR revision, Part 820 incorporates ISO 13485:2016 by reference along with certain FDA-specific requirements, so the two are now closely aligned rather than parallel.
Did QMSR require companies to rewrite their quality systems?
For organizations already operating a certified ISO 13485:2016 quality system, generally no. The transition is largely a records- and terminology-mapping exercise because QMSR moved the US framework toward the standard those organizations already followed. Organizations operating only to the prior US regulation face a more substantial alignment effort.
Is QMSR a software regulation?
No. QMSR is a quality system regulation for finished device manufacturers. It is not software-specific and contains no software carve-out. Software lifecycle expectations come from IEC 62304, and risk management from ISO 14971, both of which operate within the applicable quality system.
Building Software Inside Someone Else’s Quality System
Most software suppliers in this industry work under a manufacturer’s quality system rather than holding the regulatory obligation themselves. Doing that well means producing records the manufacturer can actually use: design outputs traceable to inputs, verification evidence tied to requirements, risk controls implemented and documented, and a change history that holds up under inspection.
Sequenex develops medical device software under its own ISO 13485-certified quality management system, with lifecycle practices aligned to IEC 62304, so the evidence integrates into the manufacturer’s design history file rather than needing reconstruction. The legal manufacturer retains responsibility for regulatory strategy, submissions, and postmarket obligations. To discuss how this works for your program, explore our medical device software development services or get in touch with us.

