The best way to explain what a good design control plan actually looks like is to build one, end to end, for a real device category rather than talk about design controls in the abstract. What follows is an illustrative concept package for a Class II knee soft tissue anchor, a suture-based fixation device used to reattach ligament or tendon tissue to bone during arthroscopic knee repair. No client, no real product, no real data. It's a walkthrough of the ISO 13485 Clause 7.3 structure, the standards battery an anchor like this actually needs, and the distinction that matters most in this kind of device: acceptance criteria derived from a standard, versus acceptance criteria copied from a predicate's marketing claim.
Why this device is a good teaching example
Suture anchors are a mature, well-regulated device category with an FDA guidance document specifically written for them (Bone Anchors, Premarket Notification (510(k)) Submissions, issued March 2020), an active consensus standard purpose-built for the category (ASTM F3690, covering suture anchor insertion and pull displacement resistance), and a predicate landscape clean enough that walking through it doesn't implicate any real product or company. That combination, FDA guidance plus a device-specific ASTM standard plus an established 510(k) pathway, is exactly the situation design controls are supposed to make efficient. You're not inventing a regulatory strategy from nothing. You're building a documented, traceable case that your specific anchor meets the performance the standard and the predicate landscape already define, and understanding why that's still real engineering work, not paperwork, is the point of this walkthrough.
Design and development planning
Clause 7.3.2 requires a documented plan before design activity starts, covering the design stages, review points, verification and validation activities, and responsibilities. For this device, the plan sets four stages: concept and requirements definition, detailed design and prototype fabrication, verification testing, and design validation, with a formal design review gate at the end of each stage, per Clause 7.3.5, staffed with at least one reviewer independent of the stage under review. That independent-reviewer requirement is technically optional under the newer QMSR structure since ISO 13485 doesn't carry it forward the way the old 21 CFR 820.30 did, but it's cheap insurance and standard practice, so it stays in the plan regardless. The plan also names the traceability tool that will link every requirement to its verification method, because for a device with mechanical, material, and biocompatibility requirements running in parallel, an untracked spreadsheet is where design control programs quietly fall apart.
User needs and design inputs
The user need starts simply: a surgeon needs a device that securely reattaches soft tissue to bone during arthroscopic repair, with fixation strength and durability sufficient to withstand physiological loading throughout the tissue-to-bone healing period, without loosening, migrating, or failing before healing is complete.
Translating that into design inputs is where the real engineering judgment happens, and it's also where the standards-versus-predicate distinction shows up for the first time. The design inputs aren't set by asking what a competitor's cleared anchor achieves and matching it. They're set by asking what load the fixation actually needs to survive. That means pulling in the biomechanics literature on in vivo tendon and ligament loading during the relevant healing window, typically citing peak forces reported for the specific anatomic repair the anchor targets, and setting a pullout strength requirement with margin above that physiological load, not just above whatever number shows up in a competitor's 510(k) summary. A predicate's cleared performance is a useful sanity check and a required part of the eventual substantial equivalence argument. It is not, on its own, a design input, for the same reason I flagged in a recent piece on reviewing a grant proposal that made this exact substitution: a verification threshold copied from a predicate, with no independent clinical or biomechanical rationale behind it, is not a documented design input. It's a number with no lineage.
Design inputs for this device include: static pullout strength above a stated physiological load with defined margin, cyclic fatigue performance without loosening or failure across a specified cycle count representing the healing timeline, insertion torque and driving characteristics within a range that avoids bone damage or anchor failure during placement, suture-eyelet or suture-channel abrasion resistance sufficient to avoid premature suture failure, material biocompatibility appropriate for permanent bone and soft tissue contact, and, if the anchor body is bioabsorbable rather than permanent metal or PEEK, a degradation profile that maintains fixation strength through the healing window before resorbing.
Design outputs and the verification battery
Each input maps to a defined test method, and this is where the device-specific ASTM standard earns its place. ASTM F3690 is the primary reference for suture anchor insertion and pull displacement resistance testing, and it's written to be selective rather than prescriptive: the standard offers multiple test methods for different anchor designs, all-suture anchors versus multi-component anchors with a separate bone-implanted body, and expects the manufacturer to select and justify which methods actually apply to their specific design rather than running every test in the document by default. ASTM F543, originally written for metallic bone screws, supplies the insertion and torsional testing methodology, driving torque and torsional strength per its Annex sections, adapted for anchor insertion where relevant to the device's fixation mechanism. Cyclic fatigue testing follows the general approach FDA's bone anchor guidance describes: insertion into a simulated bone substrate representative of the intended implantation site, cyclic loading to a target cycle count, and a post-fatigue static pullout test on anchors that survive fatigue without failure, to characterize any strength degradation from cyclic loading before final pullout.
Biocompatibility follows ISO 10993-1:2018's risk-based framework for a permanent, bone- and tissue-contacting implant: cytotoxicity and sensitization per ISO 10993-5 and -10 at minimum, with the full endpoint matrix, irritation, systemic toxicity, genotoxicity, implantation, and material-mediated pyrogenicity where applicable, scoped against the specific contact duration and tissue type per the ISO 10993-1 decision framework, not assumed from a similar-sounding predicate's biocompatibility summary. If the anchor body uses a bioabsorbable polymer, degradation products and their systemic handling need their own evaluation, since resorbable materials carry biocompatibility considerations a permanent metal or PEEK anchor doesn't.
Design validation and the predicate comparison
Verification confirms the anchor meets its design outputs under controlled bench conditions. Validation, under Clause 7.3.7, confirms the device meets user needs and intended use under actual or simulated use conditions, and conflating the two is a documentation error I've seen cause real problems: a mechanistic bench study in simulated bone substrate is verification. It is not validation, no matter how realistic the substrate is, because it doesn't confirm anything about actual surgical use, and a proposal or submission that describes one as if it were the other invites exactly the kind of scrutiny nobody wants during review.
The predicate comparison belongs in a specific, bounded place in this structure: the substantial equivalence argument for the eventual 510(k), built after design inputs, outputs, and verification are already defined against the standard and the clinical literature, not before. At that stage, the predicate comparison answers a narrower question than "does our device work," it answers "is our device's technology, intended use, and performance close enough to a legally marketed device that FDA can rely on that device's safety and effectiveness history instead of requiring a full PMA." That's a real and useful comparison. It's also a downstream check against an independently derived requirement set, not the source of the requirement set itself. Getting that order backwards, letting the predicate's cleared numbers define what "good enough" means before you've asked what the physiology actually demands, is how a design control program ends up defensible on paper and quietly under-engineered in practice.
Traceability, start to finish
Every one of these inputs, outputs, verification results, and the validation activity ties back to the original user need through a single traceability matrix, maintained as design work happens rather than reconstructed at the end. Under the QMSR's incorporation of ISO 13485, that traceability is now an explicit requirement rather than a best practice, and for a device with this many interacting requirements, mechanical, material, biological, and usability, a matrix built after the fact almost always has gaps that only surface during an audit or, worse, during an actual field complaint investigation trying to trace a failure mode back to its design origin.
Done this way, design controls for a device like this aren't a compliance exercise layered on top of the engineering. They're the structure that makes sure the engineering answer, does this anchor actually hold under the loads it will see, gets asked and answered before the regulatory argument, does this compare well enough to what's already cleared, gets built on top of it.
FDA, Bone Anchors – Premarket Notification (510(k)) Submissions, issued March 3, 2020; ASTM F3690, Standard Test Method for Evaluating Suture Anchor Insertion and Pull Displacement Resistance; ASTM F543, Standard Specification and Test Methods for Metallic Medical Bone Screws; ISO 13485:2016 Clause 7.3, Design and Development; ISO 10993-1:2018, Biological Evaluation of Medical Devices, Part 1.
