If you skimmed the QMSR announcement in early 2024 and filed it under "find and replace the word 'QSR' with 'QMSR' sometime before 2026," you are not alone, and you are also not done. The Quality Management System Regulation took effect February 2, 2026, and six months into enforcement I'm still fielding the same question from clients: "so what actually changed?" The honest answer is that FDA's own framing invites the confusion. The agency's stated position is that ISO 13485 requirements are, "taken in totality, substantially similar" to the old Quality System Regulation. That phrase is true and it is also doing a lot of quiet work. The deltas hiding inside "substantially similar" are exactly where I've seen SOPs break during this transition, so let's walk through them.
What actually happened, structurally
The QMSR amends 21 CFR Part 820, and it does it by incorporation, not by rewrite. FDA didn't draft a new set of American design control requirements. It adopted ISO 13485:2016 by reference, along with Clause 3 of ISO 9000:2015 for terms and definitions, and then kept a small set of FDA-specific provisions bolted on where the agency felt ISO 13485 didn't go far enough or where it needed to stay compatible with other parts of the FD&C Act.
The structural result is dramatic even if the substance is "substantially similar." The old QSR ran fifteen subparts, A through O, each one spelling out a quality system element directly in regulatory text: design controls in 820.30, document controls in 820.40, corrective and preventive action in 820.100, and so on. The new QMSR collapses that down to two subparts. Subpart A covers general provisions. Subpart B covers supplemental provisions. Everything else, including the old standalone 820.30 Design Controls section that every device engineer in this industry has memorized, is now marked "Reserved." Design controls live in ISO 13485 Clause 7.3 now, full stop. (This structural collapse is worth a visual: fifteen subparts on one side, two on the other, side by side.)
Six FDA-specific sections survived the consolidation: 820.1 (Scope), 820.3 (Definitions), 820.7 (Incorporation by Reference), 820.10 (QMS Requirements), 820.35 (Control of Records), and 820.45 (Device Labeling and Packaging Controls). I'll come back to 820.35 and 820.45, because that's where FDA added back QSR-style specificity that ISO 13485 alone doesn't cover, and it's a common gap in transition plans that treat the QMSR as pure incorporation.
The five deltas that actually matter
Risk management stopped being a design-controls thing and became a everything thing. In the old QSR, the word "risk" appears exactly once, in 820.30(g), design validation. In ISO 13485:2016, "risk" shows up more than 25 times. Clause 4.1.2 requires a risk-based approach to controlling the QMS processes themselves, which means risk-based thinking now formally extends to supplier controls, software validation, change control, and training, not just the product risk file your risk management SOP already covers. ISO 14971 itself is not incorporated by reference, so you don't have a direct regulatory obligation to conform to it by name. But ISO 13485 pulls in 14971's terms and principles throughout, which makes conformance to 14971 the practical, de facto route to demonstrating 13485 conformance on the risk side. If your QMS still treats risk management as something that happens in one procedure and one file, you have a gap, even if your product risk management process itself is airtight.
Design traceability moved from best practice to requirement. Under the QSR, documented traceability between design inputs, design outputs, verification, and validation was smart engineering discipline, not a regulatory mandate. ISO 13485:2016 requires, as part of design and development planning, that this traceability be established and maintained. If your team has been running design controls off a set of linked documents and institutional memory instead of a formal Design Requirements Traceability Matrix, that used to be a style choice. It is now a regulatory gap. This is also the most direct bridge between this article and the next one I'm publishing, on populating a design FMEA: traceability and hazard analysis increasingly have to talk to each other in a documented, defensible way, and doing that by hand at scale is exactly the kind of structured, high-volume drafting work where I've started using AI as a first-pass tool, with an engineer still owning every judgment call.
The records shield is gone, and this is the one that surprises clients most. Under the old 820.180(c), FDA investigators were explicitly barred from reviewing management review reports and minutes, internal quality audit reports, and supplier audit reports and reports of supplier audits. That exception is gone in the QMSR. FDA removed it specifically to align US practice with how other regulators and MDSAP auditing organizations already operate, where those records are fair game. Practically, this means your management review minutes need to read like a document you'd defend in front of an investigator, not an internal conversation. If your reviews have historically been light on documented rationale for decisions, or your internal audit reports read more like checklists than substantive findings, this is the change to fix first.
Terminology shifted, and mixed vocabulary is now an audit-finding magnet. DHF (Design History File), DMR (Device Master Record), and DHR (Device History Record) do not appear in ISO 13485 and are not separately defined in the QMSR. The operative ISO concept is the Medical Device File, MDF. "Top Management" replaces "Management with Executive Responsibility" as the standard term. None of this means you have to purge DHF and DMR from your vocabulary; legacy terminology isn't prohibited, and plenty of well-run QMSs will keep using it because it's familiar and it maps cleanly to FDA's historical expectations. What will get flagged is inconsistency: a controlled document set that calls the same thing an MDF in one SOP and a DHF in another is exactly the kind of loose-thread finding an investigator pulls on.
FDA added back specificity in two places where it decided ISO 13485 wasn't detailed enough. Section 820.35, Control of Records, spells out signature and date requirements, and ties complaint and servicing record content to 21 CFR Part 803 and UDI documentation to Part 830. For any complaint that's reportable under Part 803 or that warrants investigation, the record has to capture the device name, date received, UDI or UPC, complainant name and contact information, the nature and details of the complaint, corrective action taken, and any reply to the complainant, plus detailed servicing records where applicable. That's actually more prescriptive than the old QSR complaint file requirements were. Section 820.45, Labeling and Packaging, exists because FDA found that ISO 13485 doesn't include a labeling inspection requirement, so the agency retained the old 820.120(b)-style label accuracy inspection prior to release, stacked on top of ISO 13485 Clause 7.5.1(e). If your transition plan was "map our SOPs to ISO clauses and call it done," these two sections are where that plan falls short, because there's no ISO clause to map to. You have to procedurize them directly against the regulation text.
One more structural detail worth knowing: 820.10(b) explicitly cross-wires certain ISO 13485 clauses to other CFR parts. Clause 7.5.8, Identification, for example, requires a documented UDI system that has to satisfy Part 830. Similar linkages exist for Part 803 (medical device reporting), Part 806 (corrections and removals), and Part 821 (tracking). And where ISO 13485 conflicts with the FD&C Act or its implementing regulations, the Act and the regulations control, not the standard. Worth knowing that one relaxation exists too: ISO 13485 Clause 7.3.5 doesn't carry forward the QSR's requirement for an independent reviewer on design reviews, someone without direct responsibility for the design stage under review. FDA addressed this directly in its response to comment 46 of the final rule preamble. My advice to clients has been to keep the independent reviewer requirement in your own procedure anyway. It's cheap insurance, notified bodies still like seeing it, and there's no version of "we removed our independent review step because the regulation technically allows it" that plays well in an audit finding response.
Inspections changed too, and not just cosmetically
QSIT, the Quality System Inspection Technique that's defined how FDA investigators approached device inspections for decades, retired on February 2, 2026, the same day the QMSR took effect. It's been replaced by Inspection of Medical Device Manufacturers Compliance Program 7382.850, with the older programs 7382.845 and 7383.001 withdrawn. FDA inspections will not follow MDSAP audit plans, the agency will not require or issue ISO 13485 certificates of conformance, and holding a 13485 certificate from a notified body does not exempt a manufacturer from FDA inspection. I've had this conversation with more than one startup client who assumed a fresh BSI or TÜV certificate meant they were largely covered. They are not off the hook, because FDA assesses against the regulation directly, including the Subpart B specifics that a certification audit never actually touches, like the 820.35 complaint record content requirements.
The enforcement posture shift matters as much as the document shift. Investigators under 7382.850 are evaluating how well your system actually works: whether complaint data gets analyzed and acted on, whether vigilance reporting is happening the way it should, not just whether procedures exist on paper describing how it's supposed to work. And because the records shield in 820.180(c) is gone, investigators can now pull your management review minutes and internal audit reports and follow the threads they find there, which they literally could not do before this February.
What this means for your SOPs, practically
If your company is already ISO 13485 certified, which describes most device startups selling into EU or MDSAP markets, the lift here is moderate but not zero. You need to update your Quality Manual and SOP citations from "21 CFR 820 Subpart X" references to QMSR and ISO clause references, reconcile terminology so you're not mixing DHF and MDF language across your controlled document set, verify that the Subpart B specifics (complaint record content, label inspection, signature and date requirements, UDI hooks) are explicitly procedurized rather than assumed to be covered by your 13485 certification, and revise your supplier and quality agreements to remove references to the old QSR.
If you're a US-only shop that built your QMS strictly against the 1996 QSR text and never pursued 13485 certification, the gap is bigger: you need risk-based process controls per Clause 4.1.2 built into places they've never lived before, formal input-output-verification-validation traceability, management review and audit records written to withstand inspection rather than internal-only scrutiny, and the broader ISO documentation architecture underneath all of it.
One last housekeeping item, easy to miss: FDA also issued a technical amendments rule, effective the same date, updating 179 sections across 18 CFR parts to conform old QSR references to the new QMSR structure. If any of your controlled documents cite specific old section numbers, like 820.198 for complaint files, check them against the current text. Those citations may now point at reserved or renumbered sections that no longer say what your SOP thinks they say.
"Substantially similar" was never a promise that nothing changed. It was FDA telling you where to look hardest.
Federal Register final rule, Feb. 2, 2024; 21 CFR Part 820, current text via eCFR; FDA QMSR page; FDA QMSR FAQ; CDRH compliance programs, incl. 7382.850; Technical amendments final rule, Federal Register; ISO 13485:2016, available read-only via the ANSI IBR Portal (free registration required).
