Guide

ISO 13485, QMSR and MDSAP: how to build a single QMS for Europe and the United States?

Illustration: ISO 13485 QMS, QMSR alignment and MDSAP audits.

In brief

A European ISO 13485 QMS is not automatically FDA compliant. Since February 2026, QMSR incorporates ISO 13485:2016 by reference, but US-specific requirements remain. Aim for a common foundation that can integrate each market (including through MDSAP), rather than a duplicated quality system.

Your ISO 13485 QMS is ready. Then the United States arrives on the roadmap

This is a frequent situation for a European MedTech: the quality management system is already structured around ISO 13485, processes are in place, then the company decides to target the US market.

With that ambition, three acronyms quickly arrive: ISO 13485, QMSR and MDSAP. Do you rebuild the QMS? Create FDA-specific procedures? Keep a European system and a US system in parallel?

Since 2 February 2026, FDA’s Quality Management System Regulation (QMSR) incorporates ISO 13485:2016 by reference into 21 CFR Part 820 (Federal Register, 2 February 2024). The alignment is real, but it would be a mistake to conclude: “We are ISO 13485, therefore we are FDA compliant.”

ISO 13485, QMSR and MDSAP: three different roles

Before changing a procedure, separate the three notions. ISO 13485 is the international reference standard for medical-device QMS. QMSR is the US regulation for manufacturers under FDA quality-system requirements: since February 2026 it relies directly on ISO 13485:2016 while keeping US-specific requirements. MDSAP is a regulatory audit programme that lets a recognised auditing organisation run one audit covering applicable requirements of several participating authorities (including the United States, Canada, Australia, Brazil and Japan).

QMSR: what actually changes for a European MedTech

The main change is simple: an organisation already structured around ISO 13485 now sits much closer to what FDA expects. That strongly reduces the case for two parallel quality architectures. But harmonisation is not equivalence.

QMSR remains US law. FDA-specific requirements continue to apply, as do other obligations depending on product and situation: vigilance, corrections and removals, establishment registration, listing, UDI or market-placement requirements. An ISO 13485 certificate alone is therefore not enough to demonstrate FDA conformity.

Another important point: since QMSR entered into force, FDA has also evolved its inspection approach. Companies must show that the system actually works, beyond the existence of procedures. Management reviews, internal audits, supplier audits, CAPA, complaints or design records must be coherent, controlled and defensible. The question shifts from “do we have the right SOP?” to “can we show that our system produces the right decisions and the right evidence?”

MDSAP: useful, not magical

MDSAP answers another problem: avoiding repeated regulatory audits when several markets are in scope. The audit is built around processes such as management, design and development, purchasing, production, CAPA and monitoring.

For an international MedTech, this approach can be valuable because it pushes teams to show links between processes, applicable requirements and evidence. But MDSAP does not replace everything. It does not replace FDA regulation, does not remove FDA’s inspection authority, and does not replace European MDR or IVDR obligations. The European Union is currently an observer of the programme, not a member. Treat MDSAP as a regulatory-efficiency lever, not a universal passport.

One QMS, but not a generic one

Facing multiple markets, two bad strategies appear often. The first duplicates procedures (EU, US, then variants for complaints, changes, vigilance or suppliers): the QMS becomes hard to maintain. The second assumes one common ISO 13485 procedure is enough everywhere: simpler, but it can hide jurisdiction-specific requirements.

The better model sits between the two: a common process, completed by local regulatory rules when needed. Complaints example: intake, qualification, investigation and closure can stay unique; reportability assessment, timelines, authorities to notify or expected records depend on the market. Same logic for product change: common change control, separate EU / US regulatory impact analysis.

In other words: one common process → applicable requirements identified → decision rules by jurisdiction → traceable evidence.

How to build this architecture in practice

Keep ISO 13485 as the common base

Management, competence, design, purchasing, production, monitoring, CAPA or audits do not need to be rebuilt market by market.

Map complementary requirements

Link QMSR and other applicable FDA obligations to existing processes. Every identified gap should drive a real action: decision, ownership, workflow field, validation, control or record.

Place local rules where decisions happen

A US requirement should appear when the team makes a US decision, not in an annex nobody opens. Keep evidence alive in the tools teams actually use.

When the product evolves quickly, the main risk is disconnection between requirements, risks, tests, changes and quality records. An eQMS integrated with team tools reduces that break. Qapsule can strengthen orchestration and evidence traceability across tools.

Medical software and AI: watch change control

For SaMD manufacturers, this architecture is even more critical. One release can change a feature, a risk, a test, a performance claim, user information or a regulatory decision. Change control cannot be a quality procedure disconnected from product development.

For some AI-enabled devices, a Predetermined Change Control Plan (PCCP) further increases the need for coherence between design, validation, risk management and regulatory strategy. We cover that in our article on the PCCP for AI medical software. The logic stays the same: a new regulatory requirement should not create a parallel system. It should enrich the existing compliance infrastructure.

Action plan

  • Define the US scope: devices, classification, activities, sites and roles concerned.
  • Map your existing QMS to identify what is already covered.
  • Run a QMSR gap analysis and identify applicable complementary FDA requirements.
  • Attach each gap to an existing process before creating a new procedure.
  • Formalise decision rules by jurisdiction when requirements diverge.
  • Check evidence that actually exists: audits, CAPA, design, complaints, validation, suppliers, management reviews.
  • Assess MDSAP value against your international strategy.
  • Test the system with an internal audit before an inspection or regulatory audit.

Conclusion

QMSR brings the FDA frame closer to ISO 13485 without erasing US specifics. The useful indicator is not how many procedures you create, but how quickly you can show which requirement applies, how it is executed and where the evidence sits. That is also the logic of the PULSE programme; an internal audit remains one of the most effective ways to check alignment between procedures, practices and evidence.

FAQ

What is the difference between ISO 13485 and QMSR?

ISO 13485:2016 is an international QMS standard for medical-device organisations. QMSR is FDA’s quality-system regulation. Since 2 February 2026 it incorporates ISO 13485:2016 by reference into 21 CFR Part 820, while keeping US-specific regulatory requirements.

Is an ISO 13485 certificate enough for FDA conformity?

No. ISO 13485 certification is an excellent foundation, but it does not alone demonstrate conformity to all applicable FDA requirements. Manufacturers must identify and integrate complementary US requirements for their activities and devices.

Do we need two different QMS systems for Europe and the US?

Not necessarily, and full duplication is rarely the most effective option. Keep common processes where possible, then explicitly integrate jurisdiction-specific rules at the steps where they matter.

Is MDSAP mandatory in the United States?

No. MDSAP participation is voluntary for a manufacturer placing devices on the US market. Its value should be assessed against the markets in scope and the international regulatory strategy.

Does MDSAP avoid an FDA inspection?

Not systematically. FDA may use some MDSAP results in lieu of certain routine inspections, but it retains inspection authority. An MDSAP audit is not a guarantee that an FDA inspection will not occur.

Does MDSAP replace CE marking?

No. MDSAP replaces neither MDR/IVDR obligations nor notified-body involvement when required. The EU is an observer of MDSAP, not a member.

Where should we start if we are already ISO 13485 and want to enter the US?

Start with a gap analysis between your current QMS and the FDA requirements that actually apply. First determine what already exists, what must be adapted and which complementary requirements must be integrated. Rewrite procedures only when necessary.

QARA PULSE article based on ISO 13485:2016, FDA’s Quality Management System Regulation (QMSR) and the Medical Device Single Audit Program (MDSAP). Regulatory information checked in April 2026, content refreshed in August 2026. Not personalised regulatory or legal advice for a specific device. Always verify official texts and guidance in force.

Related: eQMS deployment · Internal audit · Qapsule · PCCP · Contact

← All resources