FDA Quality Management System Regulation (QMSR)
QMSR: Device Labelling and Packaging Controls (§820.45)

FDA Quality Management System Regulation (QMSR) QMSR-820.45: Device labelling and packaging controls (§820.45)

Section 820.45 establishes FDA-specific DEVICE LABELLING + PACKAGING controls supplementing ISO 13485:2016 Section 7.5.11 (preservation of product). REQUIREMENTS: (a) LABELLING - the manufacturer must establish + maintain procedures to control labelling activities to ensure that LABELLING IS LEGIBLE + DURABLE + AFFIXED OR ATTACHED to the device + APPROPRIATE LABELLING IS RELEASED FOR COMMERCIAL USE - including device identification + manufacturer name + intended use + warnings + cautions + instructions for use (IFU). (b) UDI ON LABEL - the UDI must appear on the LABEL OF THE DEVICE + on each higher level of packaging in human-readable + AIDC (Automatic Identification and Data Capture) format per 21 CFR Part 830. (c) LABELLING INSPECTION + STORAGE - procedures for inspection of labelling for accuracy including identification number + lot number + expiration date + control number + similar information; secure storage of labelling + control of access. (d) LABELLING OPERATIONS - control of labelling operations to prevent mix-ups; controlled environment where labelling is performed; supervision of labelling operations; documentation of labelling operations. (e) PACKAGING - packaging must be designed + constructed to protect the device from alteration + damage during processing + storage + handling + distribution + use. (f) PACKAGING VALIDATION - validation of packaging design per ISO 11607-1 + 11607-2 (Packaging for Terminally Sterilized Medical Devices) where applicable.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 61 controls across 48 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CFR211-G-122 Section 211.122 - Materials Examination and Usage Criteria
  • CFR211-G-125 Section 211.125 - Labeling Issuance
  • CFR211-G-130 Section 211.130 - Packaging and Labeling Operations

API 1164 · 1 control

  • API1164-02 Risk Management Framework

BSI IT-Grundschutz · 1 control

  • BSI-15 Security categorization

FISMA · 1 control

  • FISMA-NIST-800-53-RMF-800-171-FIPS Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200
  • GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics
  • 60601-1.7.1 Equipment identification and marking

IEC 62443 · 1 control

  • IEC62443-02 System security categorization

IEEE 1686 · 1 control

  • IEEE1686-Scope-IED-Substation-Automation-2022-IEC-NERC-NIST-Coord IEEE 1686 - Scope + Intelligent Electronic Devices (IEDs) + Substation Automation + 2022 Edition + Coordination with IEC 62351 + IEC 62443 + NERC CIP + NIST SP 800-82

IEEE 7000 · 1 control

  • IEEE7000-EthicalRisk-Identification-Analysis-Treatment-ValidationOutcomes IEEE 7000 Clauses 8 + 8.1 + 8.2 - Ethical Risk Identification + Analysis + Treatment + Validation of Ethical Outcomes + AI Safety + Robustness + Adversarial Protection

ISMAP (Japan) · 1 control

  • ISO-14064-1-5.4 Categorization of indirect GHG emissions

ISO/IEC 27010:2015 · 1 control

  • 27010-8.2 Membership Termination

ISO/IEC 27019:2024 · 1 control

  • ISO27019-02 System security categorization

ISO/IEC 27043:2015 · 1 control

  • ISO27043-08 Information classification and labeling

ISO/SAE 21434 · 1 control

  • ISO21434-08 Information classification and labeling

Japan AI Guidelines · 1 control

  • JP-AIG-Risk-Based-AI-System-Categorisation-Tiered-Approach-EU-AI-Act-Aligned-Generative-Foundation-Models Japan AI Guidelines Risk-Based AI System Categorisation + Tiered Approach + EU AI Act Aligned + Generative AI + Foundation Models + High-Risk + Limited-Risk + Minimal-Risk + AISI Capability-Based Thresholds

MITRE ATT&CK · 1 control

MITRE D3FEND · 1 control

MTCS (Singapore) · 1 control

  • MTCS-Acquisition-Development-Maintenance-Supplier-Vulnerability-DevSecOps-SBOM-SDLC-SCA-API-Container MTCS Acquisition + Development + Maintenance + Supplier + Vulnerability + DevSecOps + SBOM + SDLC + SCA
  • NAIC-2 Information Security Program (ISP) - Section 4

NIST SP 1800-32 · 1 control

  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-123 · 1 control

NIST SP 800-137 · 1 control

  • NISTSP137-1 ISCM Strategy, Governance, and Volatility Assessment

NIST SP 800-144 · 1 control

  • NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access

NIST SP 800-145 · 1 control

  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 1 control

NIST SP 800-190 · 1 control

  • NISTSP61-4 Detection and Analysis: Sources, Triage, Categorisation, Prioritisation

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-7 Privacy, Records Retention, and User-Controlled Wallets

NIST SP 800-88 · 1 control

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework

NIST SP 800-92 · 1 control

  • NISTSP92-7 Privacy in Logs, Sensitive Content Handling, Cloud and SaaS Log Considerations
  • QRCM-1.3 Data Classification for Migration

OECD AI Principles · 1 control

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection

OWASP ASVS · 1 control

OWASP MASVS · 1 control

OWASP SAMM · 1 control

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment

OpenSSF Scorecard · 1 control

  • OSSFSC-2 Dependency Management, Pinning, Updates, Vulnerability Tracking
  • PASONE-1 Security Triage Process, Asset Sensitivity Classification, and Threat Assessment

PTES · 1 control

  • PTESPHASE-1 Pre-Engagement Interactions and Scoping
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight

SASB Standards · 1 control

  • SASB-SOC-7 Selling Practices and Product Labeling
  • SHAREASSESS-2 Access Control, Identity, Authentication

SLSA · 1 control

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance
  • UKAI-1 Risk-Based Approach and Pro-Innovation Principles

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 61 it maps to, and the evidence behind each claim, over MCP and REST.