QMSR Compliance in 2026: What FDA Inspectors Are Checking First

The grace period never existed. On 2 February 2026, the Quality Management System Regulation replaced the Quality System Regulation, and FDA began inspecting against it the same day.

Seven months on, a pattern has emerged from early inspections. The firms struggling are not the ones with thin procedures. They are the ones who treated QMSR compliance as a renaming exercise, swapped a few terms, and filed the project as done.

This article covers what actually changed, what investigators are pulling on first, the gaps teams keep hitting, and what to do about them this quarter.

What QMSR Compliance Actually Means Now

The QMSR amends 21 CFR Part 820 by incorporating ISO 13485:2016 by reference. It also brings in Clause 3 of ISO 9000:2015 for vocabulary. In total, FDA amended 179 sections across 18 parts of Title 21.

However, the bigger change is not the text. It is the inspection model. FDA retired the Quality System Inspection Technique and replaced it with Compliance Program 7382.850, a risk-based, total product lifecycle approach. You can read the agency’s own summary on the FDA QMSR page.

The change most teams underestimated

Under the old rule, section 820.180(c) shielded three record types from routine FDA review: management review, internal quality audits, and supplier audit reports.

That exemption is gone. As FDA states plainly in its QMSR frequently asked questions, the agency now has authority to inspect all three.

So records written on the assumption that no investigator would ever read them are now discoverable. For many quality teams, that single change has more practical impact than the ISO alignment itself.

What Inspectors Are Checking First

Consultants who have sat through QMSR inspections this year report a consistent theme. The opening focus is not your quality manual, your SOP structure, or whether you renamed the Device Master Record to a Medical Device File.

It is whether risk-based thinking is genuinely embedded across the system. If risk analysis still lives as a standalone activity inside the design history file, investigators tend to find that gap inside the first hour.

The thread test

CP 7382.850 encourages investigators to follow a single issue across the whole system. In practice, that looks like this.

An investigator picks one complaint. Then they ask whether it triggered a CAPA. Next, whether the Risk Management File was updated to reflect a new hazard or a wrong risk estimate. Then whether purchasing records show the supplier reclassified. Finally, whether the design documentation moved.

Under QSIT, those four areas were often examined separately. Now they are examined as one chain. A break anywhere in that chain reads as a system that does not function, rather than an isolated paperwork miss.

No sampling tables

QSIT gave investigators fixed sampling tables. CP 7382.850 does not. Instead, records are selected based on product risk and professional judgment.

The practical effect is that inspections are less predictable. Teams that prepared for a known sample size now face a reviewer who follows the evidence wherever it leads.

The Real Problems Quality Teams Are Facing

These are the gaps showing up repeatedly across the industry. Some may look familiar.

Problem 1: The transition was treated as a rename

Swapping terminology is the visible part of the work. Many organisations did that, updated a quality manual, and closed the project. Under a process-based inspection, those systems look correct on paper and fail in practice.

Problem 2: Risk management sits in a silo

Risk files are often written at design stage and never revisited. Yet QMSR expects risk to flow into CAPA prioritisation, complaint handling, process validation, labelling and supplier controls. If the Risk Management File has not been touched since product release, that is the finding.

Problem 3: Suppliers are classified by spend, not by risk

Many supplier programmes still grade vendors by purchasing category or contract value. Investigators are asking whether a supplier’s risk classification is proportionate to the risk that component poses to the finished device, and whether purchasing documents reflect it.

Problem 4: Design traceability has holes

The expectation is a clean line from user need through design inputs, outputs, verification, validation and transfer. Gaps slow inspections down and can complicate premarket review later.

Problem 5: CAPA is still reactive

Under the old model, investigations often started once a complaint threshold was crossed. Proactive trending and early risk mitigation are now baseline expectations rather than signs of maturity.

Problem 6: Audit records were never written to be read

This follows directly from the 820.180(c) change. Internal audit reports and management review minutes written in shorthand, or written defensively, now sit in front of an investigator.

Problem 7: Small and mid-size firms are stretched thinnest

Larger organisations absorbed this with dedicated regulatory teams. Companies without that bench are carrying the same obligation with a fraction of the resource. That gap in capacity, not in intent, is where most of the risk now sits.

Is Anyone Solving This Well?

Yes, though unevenly. The firms handling it best share a few habits.

·       They re-ran the gap assessment on behaviour, not documents. The first pass compared old clauses to new ones. The second pass asked whether the system actually connects.

·       They rehearsed the thread. Picking a real complaint and tracing it end to end exposes breaks faster than any checklist.

·       They rewrote audit and management review records for disclosure. Not sanitised, but complete, clear and defensible.

·       They ran mock inspections under the new programme. Practising QSIT habits for a CP 7382.850 inspection prepares you for the wrong conversation.

Firms already certified to ISO 13485 had a head start on structure. Even so, certification is not a shield. FDA has been clear that a certificate does not exempt anyone from inspection, and ISO-certified firms have still been caught out on risk integration.

How RxCloud approaches this

We audit and validate quality systems in regulated environments, so this transition is not theoretical for us. It shows up in the findings we write and the remediation we support.

·       Audits that test the thread, not the binder. With over 1500 GxP audits completed across 27+ countries, we look for the same breaks investigators look for, before they do.

·       Risk-based CSV and CSA. We concentrate validation effort on the systems that genuinely affect data integrity and patient safety, which is the same logic CP 7382.850 applies. More on our Computer System Validation services.

·       Remediation that closes root causes. Deviation patterns across clients tell us which gaps recur, so fixes hold rather than reappear at the next inspection.

We would rather understate this than oversell it. QMSR readiness is built on quality fundamentals. If risk management is not connected to the rest of the system, no amount of documentation will carry an inspection.

QMSR vs QSR: What Actually Differs

AspectQSR (before Feb 2026)QMSR (now)
BasisStandalone US requirementsISO 13485:2016 incorporated by reference
Inspection methodQSIT, four subsystemsCP 7382.850, lifecycle and process based
SamplingFixed sampling tablesRisk and investigator judgment
Management review recordsExempt under 820.180(c)Open to inspection
Internal audit reportsExemptOpen to inspection
Supplier audit reportsExemptOpen to inspection
Risk managementConcentrated in design controlsExpected across the full system
FocusDo the procedures exist?Does the system function?

Six Steps to Close the Gap

If your last gap assessment was a document mapping exercise, this is the follow-up work.

1.       Re-assess against behaviour. Ask whether each process connects to the next, not whether a procedure exists.

2.       Integrate risk management. Build the links from the Risk Management File into CAPA, complaints, supplier controls and design change.

3.       Re-classify suppliers by patient risk. Then make sure purchasing records and agreements reflect the new classification.

4.       Rehearse the thread. Take a real complaint from the last year and trace it through every connected system.

5.       Prepare audit and management review records for disclosure. Assume an investigator will read them, because now one can.

6.       Run a mock inspection under CP 7382.850. Test the system the way it will actually be tested.

One further point worth planning for. FDA has confirmed that investigators may review records created before 2 February 2026. A comparative analysis showing that older records meet QMSR requirements is a sensible piece of preparation.

Frequently Asked Questions

Is QMSR compliance mandatory now?

Yes. The QMSR took effect on 2 February 2026 with no phase-in and no grace period. FDA began inspecting under Compliance Program 7382.850 on the same date, and the older inspection programmes were withdrawn.

Does ISO 13485 certification make us QMSR compliant?

No. ISO 13485:2016 is incorporated by reference, so meeting it is necessary, but a certificate does not exempt any firm from FDA inspection. FDA does not issue certificates of conformance, and certified firms are still inspected under CP 7382.850.

Can FDA now inspect our internal audit and management review records?

Yes. The exemptions that existed under section 820.180(c) of the old Quality System Regulation were not carried into the QMSR. Management review records, internal quality audit reports and supplier audit reports are all now open to inspection.

What is the biggest difference between QMSR and QSR?

The inspection philosophy. QSR inspections asked whether procedures existed and followed fixed subsystems with sampling tables. QMSR inspections under CP 7382.850 test whether the quality system functions as a connected, risk-driven whole, with records selected by risk and investigator judgment.

Will FDA look at records created before February 2026?

Yes. FDA has said investigators may review records that predate the effective date, because the requirements of the two regulations are substantially similar. Many firms are preparing a comparative analysis to show that older records still meet QMSR expectations.

Where should a small quality team start?

Start with risk integration, because that is what inspectors probe first. Take one real complaint and trace it through CAPA, the Risk Management File, purchasing and design. Wherever the thread breaks, you have found your first gap.