The grace period never existed. On 2 February 2026, the Quality Management System Regulation replaced the Quality System Regulation, and FDA began inspecting against it the same day.
Seven months on, a pattern has emerged from early inspections. The firms struggling are not the ones with thin procedures. They are the ones who treated QMSR compliance as a renaming exercise, swapped a few terms, and filed the project as done.
This article covers what actually changed, what investigators are pulling on first, the gaps teams keep hitting, and what to do about them this quarter.
The QMSR amends 21 CFR Part 820 by incorporating ISO 13485:2016 by reference. It also brings in Clause 3 of ISO 9000:2015 for vocabulary. In total, FDA amended 179 sections across 18 parts of Title 21.
However, the bigger change is not the text. It is the inspection model. FDA retired the Quality System Inspection Technique and replaced it with Compliance Program 7382.850, a risk-based, total product lifecycle approach. You can read the agency’s own summary on the FDA QMSR page.
Under the old rule, section 820.180(c) shielded three record types from routine FDA review: management review, internal quality audits, and supplier audit reports.
That exemption is gone. As FDA states plainly in its QMSR frequently asked questions, the agency now has authority to inspect all three.
So records written on the assumption that no investigator would ever read them are now discoverable. For many quality teams, that single change has more practical impact than the ISO alignment itself.
Consultants who have sat through QMSR inspections this year report a consistent theme. The opening focus is not your quality manual, your SOP structure, or whether you renamed the Device Master Record to a Medical Device File.
It is whether risk-based thinking is genuinely embedded across the system. If risk analysis still lives as a standalone activity inside the design history file, investigators tend to find that gap inside the first hour.
CP 7382.850 encourages investigators to follow a single issue across the whole system. In practice, that looks like this.
An investigator picks one complaint. Then they ask whether it triggered a CAPA. Next, whether the Risk Management File was updated to reflect a new hazard or a wrong risk estimate. Then whether purchasing records show the supplier reclassified. Finally, whether the design documentation moved.
Under QSIT, those four areas were often examined separately. Now they are examined as one chain. A break anywhere in that chain reads as a system that does not function, rather than an isolated paperwork miss.
QSIT gave investigators fixed sampling tables. CP 7382.850 does not. Instead, records are selected based on product risk and professional judgment.
The practical effect is that inspections are less predictable. Teams that prepared for a known sample size now face a reviewer who follows the evidence wherever it leads.
These are the gaps showing up repeatedly across the industry. Some may look familiar.
Swapping terminology is the visible part of the work. Many organisations did that, updated a quality manual, and closed the project. Under a process-based inspection, those systems look correct on paper and fail in practice.
Risk files are often written at design stage and never revisited. Yet QMSR expects risk to flow into CAPA prioritisation, complaint handling, process validation, labelling and supplier controls. If the Risk Management File has not been touched since product release, that is the finding.
Many supplier programmes still grade vendors by purchasing category or contract value. Investigators are asking whether a supplier’s risk classification is proportionate to the risk that component poses to the finished device, and whether purchasing documents reflect it.
The expectation is a clean line from user need through design inputs, outputs, verification, validation and transfer. Gaps slow inspections down and can complicate premarket review later.
Under the old model, investigations often started once a complaint threshold was crossed. Proactive trending and early risk mitigation are now baseline expectations rather than signs of maturity.
This follows directly from the 820.180(c) change. Internal audit reports and management review minutes written in shorthand, or written defensively, now sit in front of an investigator.
Larger organisations absorbed this with dedicated regulatory teams. Companies without that bench are carrying the same obligation with a fraction of the resource. That gap in capacity, not in intent, is where most of the risk now sits.
Yes, though unevenly. The firms handling it best share a few habits.
· They re-ran the gap assessment on behaviour, not documents. The first pass compared old clauses to new ones. The second pass asked whether the system actually connects.
· They rehearsed the thread. Picking a real complaint and tracing it end to end exposes breaks faster than any checklist.
· They rewrote audit and management review records for disclosure. Not sanitised, but complete, clear and defensible.
· They ran mock inspections under the new programme. Practising QSIT habits for a CP 7382.850 inspection prepares you for the wrong conversation.
Firms already certified to ISO 13485 had a head start on structure. Even so, certification is not a shield. FDA has been clear that a certificate does not exempt anyone from inspection, and ISO-certified firms have still been caught out on risk integration.
We audit and validate quality systems in regulated environments, so this transition is not theoretical for us. It shows up in the findings we write and the remediation we support.
· Audits that test the thread, not the binder. With over 1500 GxP audits completed across 27+ countries, we look for the same breaks investigators look for, before they do.
· Risk-based CSV and CSA. We concentrate validation effort on the systems that genuinely affect data integrity and patient safety, which is the same logic CP 7382.850 applies. More on our Computer System Validation services.
· Remediation that closes root causes. Deviation patterns across clients tell us which gaps recur, so fixes hold rather than reappear at the next inspection.
We would rather understate this than oversell it. QMSR readiness is built on quality fundamentals. If risk management is not connected to the rest of the system, no amount of documentation will carry an inspection.
| Aspect | QSR (before Feb 2026) | QMSR (now) |
| Basis | Standalone US requirements | ISO 13485:2016 incorporated by reference |
| Inspection method | QSIT, four subsystems | CP 7382.850, lifecycle and process based |
| Sampling | Fixed sampling tables | Risk and investigator judgment |
| Management review records | Exempt under 820.180(c) | Open to inspection |
| Internal audit reports | Exempt | Open to inspection |
| Supplier audit reports | Exempt | Open to inspection |
| Risk management | Concentrated in design controls | Expected across the full system |
| Focus | Do the procedures exist? | Does the system function? |
If your last gap assessment was a document mapping exercise, this is the follow-up work.
1. Re-assess against behaviour. Ask whether each process connects to the next, not whether a procedure exists.
2. Integrate risk management. Build the links from the Risk Management File into CAPA, complaints, supplier controls and design change.
3. Re-classify suppliers by patient risk. Then make sure purchasing records and agreements reflect the new classification.
4. Rehearse the thread. Take a real complaint from the last year and trace it through every connected system.
5. Prepare audit and management review records for disclosure. Assume an investigator will read them, because now one can.
6. Run a mock inspection under CP 7382.850. Test the system the way it will actually be tested.
One further point worth planning for. FDA has confirmed that investigators may review records created before 2 February 2026. A comparative analysis showing that older records meet QMSR requirements is a sensible piece of preparation.
Yes. The QMSR took effect on 2 February 2026 with no phase-in and no grace period. FDA began inspecting under Compliance Program 7382.850 on the same date, and the older inspection programmes were withdrawn.
No. ISO 13485:2016 is incorporated by reference, so meeting it is necessary, but a certificate does not exempt any firm from FDA inspection. FDA does not issue certificates of conformance, and certified firms are still inspected under CP 7382.850.
Yes. The exemptions that existed under section 820.180(c) of the old Quality System Regulation were not carried into the QMSR. Management review records, internal quality audit reports and supplier audit reports are all now open to inspection.
The inspection philosophy. QSR inspections asked whether procedures existed and followed fixed subsystems with sampling tables. QMSR inspections under CP 7382.850 test whether the quality system functions as a connected, risk-driven whole, with records selected by risk and investigator judgment.
Yes. FDA has said investigators may review records that predate the effective date, because the requirements of the two regulations are substantially similar. Many firms are preparing a comparative analysis to show that older records still meet QMSR expectations.
Start with risk integration, because that is what inspectors probe first. Take one real complaint and trace it through CAPA, the Risk Management File, purchasing and design. Wherever the thread breaks, you have found your first gap.