FDA Quality Management System Regulation (QMSR)
QMSR: Coordination with ISO 13485:2016, EU MDR/IVDR, FDA Part 11

FDA Quality Management System Regulation (QMSR) QMSR-Coord-ISO13485-MDR-IVDR-Part11: Coordination with ISO 13485:2016, EU MDR/IVDR, FDA Part 11, Cybersecurity Guidance

QMSR coordinates with multiple regimes. (a) ISO 13485:2016 - incorporated by reference + the substantive QMS content lives in this copyrighted ISO standard. (b) EU MDR (Regulation (EU) 2017/745) + EU IVDR (Regulation (EU) 2017/746) parallel medical-device + IVD regulations - dual-validated manufacturers face MDR Article 10 + IVDR Article 10 manufacturer obligations alongside QMSR + ISO 13485:2016; the EU regulatory pathway typically requires ISO 13485:2016 certification from a Notified Body (NB) as the primary QMS evidence + the QMSR maps similar requirements to FDA QMS evidence. (c) FDA Part 11 - electronic records + electronic signatures used in QMSR record-keeping per §820.35. (d) FDA Premarket Cybersecurity Guidance (2014 + 2018 + 2023 + 2024 updates) + Cures Act Section 524B - cybersecurity built into design controls + risk management for medical device software (SaMD + Software in a Medical Device); Software Bill of Materials (SBOM) for medical device software premarket submissions per 2024 FDA premarket cybersecurity guidance. (e) ISO 14971 (medical-device risk management) + ISO 14155 (clinical investigation) + ISO 11607 (packaging for terminally sterilized devices) + IEC 62366-1 (usability engineering) + IEC 62304 (medical device software lifecycle) + IEC 80001 (medical IT network risk management) - companion standards routinely incorporated by reference into QMSR-aligned QMS.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 4 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FDA 21 CFR Part 11 · 2 controls

  • Part11.AuditTrail Audit trail requirements - secure computer-generated time-stamped (21 CFR §11.10(e))
  • Part11.CSV Computer system validation + risk-based approach (21 CFR §11.10(a) + 2003 FDA Scope and Application Guidance + 2023 CSA draft)
  • IVDR-Art.10 General obligations of manufacturers (Article 10)
  • MDR-Art.10 General obligations of manufacturers (Article 10)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.