Back to Frameworks

FDA Quality Management System Regulation (QMSR)

United States
v2026 (Final Rule 2024)
7 domains
13 controls

The new 21 CFR Part 820 (Quality Management System Regulation, QMSR) was published as a Final Rule on 31 January 2024 (89 FR 7496) and applies from 2 FEBRUARY 2026. It HARMONISES the FDA medical device quality system requirements with ISO 13485:2016 by INCORPORATING THAT STANDARD BY REFERENCE under §820.7 + retaining a small number of FDA-specific additions (§820.15 clarifications + §820.35 record controls including audit trail + UDI + reporting + §820.45 device labelling + packaging controls). The QMSR replaces the prior Quality System Regulation (QSR) which had its own elaborate structure (former §820.20 through §820.250 covering management responsibility + design controls + document control + purchasing + production + acceptance + CAPA + labelling + handling + records + servicing + statistical techniques). The QMSR applies to FINISHED MEDICAL DEVICES that are intended for human use + are subject to FDA registration + listing under section 510 of the Federal Food, Drug, and Cosmetic Act. STRUCTURE - the QMSR Final Rule has 7 substantive sections: §820.1 scope; §820.3 definitions; §820.7 incorporation by reference; §820.10 requirements for a quality management system (incorporating ISO 13485:2016 Sections 4-8); §820.15 clarification of concepts (FDA-specific clarifications + glossary harmonisation); §820.35 control of records (record retention + audit trail + UDI + medical-device reporting + corrections and removals records); §820.45 device labelling and packaging controls (FDA-specific). RELATED FRAMEWORKS: ISO 13485:2016 (incorporated by reference + COPYRIGHTED + NEEDS LICENSED COPY); EU MDR (Regulation (EU) 2017/745) + IVDR (Regulation (EU) 2017/746) parallel medical device + IVD regulations; FDA Part 11 (Electronic Records + Electronic Signatures) for computer system validation + audit trail records under §820.35; FDA Cybersecurity Premarket Guidance + Cures Act 524B for medical device software. The 2-YEAR TRANSITION PERIOD requires FDA-regulated medical device manufacturers to fully implement the harmonised QMSR by 2 February 2026 + the FDA has clarified that the transition does not require re-certification - existing QSR-compliant systems will be evaluated against QMSR during routine inspections after the application date.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

QMSR: Clarification of Concepts and Definitions (§820.15)

1 controls
Controls in the QMSR: Clarification of Concepts and Definitions (§820.15) domain of FDA Quality Management System Regulation (QMSR)1 controls
CodeTitle
QMSR-820.15Clarification of concepts (§820.15)

QMSR: Control of Records (§820.35) - Audit Trail, UDI, Reporting

1 controls
Controls in the QMSR: Control of Records (§820.35) - Audit Trail, UDI, Reporting domain of FDA Quality Management System Regulation (QMSR)1 controls
CodeTitle
QMSR-820.35Control of records - record retention, audit trail, UDI, medical-device reporting (§820.35)

QMSR: Coordination with ISO 13485:2016, EU MDR/IVDR, FDA Part 11

1 controls
Controls in the QMSR: Coordination with ISO 13485:2016, EU MDR/IVDR, FDA Part 11 domain of FDA Quality Management System Regulation (QMSR)1 controls
CodeTitle
QMSR-Coord-ISO13485-MDR-IVDR-Part11Coordination with ISO 13485:2016, EU MDR/IVDR, FDA Part 11, Cybersecurity Guidance

QMSR: Device Labelling and Packaging Controls (§820.45)

1 controls
Controls in the QMSR: Device Labelling and Packaging Controls (§820.45) domain of FDA Quality Management System Regulation (QMSR)1 controls
CodeTitle
QMSR-820.45Device labelling and packaging controls (§820.45)

QMSR: Quality Management System Requirements (§820.10 incorporating ISO 13485:2016 Sec. 4-8)

6 controls
Controls in the QMSR: Quality Management System Requirements (§820.10 incorporating ISO 13485:2016 Sec. 4-8) domain of FDA Quality Management System Regulation (QMSR)6 controls
CodeTitle
QMSR-820.10Requirements for a Quality Management System - ISO 13485:2016 Sections 4-8 incorporation (§820.10)
QMSR-ISO13485-Sec5Management responsibility (ISO 13485:2016 Section 5 - incorporated via §820.10)
QMSR-ISO13485-Sec6Resource management (ISO 13485:2016 Section 6 - incorporated via §820.10)
QMSR-ISO13485-Sec7_DesignControlsProduct realization - Design and Development controls (ISO 13485:2016 Section 7.3)
QMSR-ISO13485-Sec7_PurchasingPurchasing controls + supplier management (ISO 13485:2016 Section 7.4)
QMSR-ISO13485-Sec8Measurement, analysis and improvement (ISO 13485:2016 Section 8)

QMSR: Scope, Definitions, Incorporation by Reference (§§820.1-820.7)

1 controls
Controls in the QMSR: Scope, Definitions, Incorporation by Reference (§§820.1-820.7) domain of FDA Quality Management System Regulation (QMSR)1 controls
CodeTitle
QMSR-820.1_3_7Scope, definitions and incorporation by reference (§§820.1, 820.3, 820.7)

QMSR: Transition Plan from Prior QSR, FDA Inspection Approach, Status

2 controls
Controls in the QMSR: Transition Plan from Prior QSR, FDA Inspection Approach, Status domain of FDA Quality Management System Regulation (QMSR)2 controls
CodeTitle
QMSR-StatusFDA QMSR - corpus status, enforcement landscape, future evolution
QMSR-TransitionTransition from prior QSR + 2 February 2026 application + FDA inspection approach

Your Compliance Coverage

If you comply with FDA Quality Management System Regulation (QMSR), you already cover:

Maps to 160 other frameworks

13 total controls
ICH E6(R3) - Good Clinical Practice
6 source controls mapped|5 target controls covered
46%
SWIFT CSCF
5 source controls mapped|4 target controls covered
38%
ISO 45001:2018
5 source controls mapped|6 target controls covered
38%
ISO 20000-1
5 source controls mapped|6 target controls covered
38%
ISO 14001
5 source controls mapped|4 target controls covered
38%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
5 source controls mapped|9 target controls covered
38%
BRCGS Global Standard for Food Safety Issue 9
5 source controls mapped|12 target controls covered
38%
ISO 9001:2015
5 source controls mapped|7 target controls covered
38%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
5 source controls mapped|9 target controls covered
38%
IEC 62304:2015 Medical Device Software Lifecycle Processes
5 source controls mapped|6 target controls covered
38%
21 CFR Part 211 - Current Good Manufacturing Practice
4 source controls mapped|8 target controls covered
31%
IEC 60601-1 - Medical Electrical Equipment Safety
4 source controls mapped|4 target controls covered
31%
GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6
4 source controls mapped|2 target controls covered
31%
31%
ISO 14001:2015
4 source controls mapped|5 target controls covered
31%
ISO 27005
4 source controls mapped|3 target controls covered
31%
AS9100D - Aerospace Quality Management System
4 source controls mapped|5 target controls covered
31%
ISO/IEC 27003:2017
4 source controls mapped|5 target controls covered
31%
IATF 16949:2016 - Quality Management System for Automotive Production
4 source controls mapped|4 target controls covered
31%
GAMP 5 - Good Automated Manufacturing Practice
4 source controls mapped|3 target controls covered
31%
FDA 21 CFR Part 11
3 source controls mapped|4 target controls covered
23%
ISO 13485
3 source controls mapped|5 target controls covered
23%
ASIS SPC.1-2009 - Organizational Resilience Standard
3 source controls mapped|3 target controls covered
23%
ISO 13485:2016
3 source controls mapped|4 target controls covered
23%
ISO 19011
3 source controls mapped|4 target controls covered
23%
ISO 31000:2018
3 source controls mapped|2 target controls covered
23%
21 CFR Part 58 - Good Laboratory Practice (GLP)
3 source controls mapped|3 target controls covered
23%
TEFCA - Trusted Exchange Framework and Common Agreement
3 source controls mapped|2 target controls covered
23%
Regulation on the European Health Data Space (EHDS)
3 source controls mapped|3 target controls covered
23%
IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2)
3 source controls mapped|2 target controls covered
23%
ICAO Annex 17 - Aviation Security (AVSEC)
3 source controls mapped|2 target controls covered
23%
Florida Digital Bill of Rights (FDBR)
3 source controls mapped|1 target controls covered
23%
Aged Care Quality Standards (Australia)
3 source controls mapped|4 target controls covered
23%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
3 source controls mapped|2 target controls covered
23%
ISO/IEC 27014:2020
3 source controls mapped|4 target controls covered
23%
EU In Vitro Diagnostic Medical Devices Regulation (IVDR)
3 source controls mapped|3 target controls covered
23%
EU Medical Devices Regulation (MDR 2017/745)
3 source controls mapped|3 target controls covered
23%
Protective Security Policy Framework (PSPF) Release 2024
2 source controls mapped|2 target controls covered
15%
OWASP ASVS
2 source controls mapped|2 target controls covered
15%
NAIC Insurance Data Security Model Law (MDL-668)
2 source controls mapped|2 target controls covered
15%
MITRE D3FEND
2 source controls mapped|2 target controls covered
15%
ISMAP (Japan)
2 source controls mapped|2 target controls covered
15%
IEEE 1686
2 source controls mapped|4 target controls covered
15%
IEC 62443
2 source controls mapped|4 target controls covered
15%
AWS Well-Architected Security Pillar
2 source controls mapped|2 target controls covered
15%
Azure Security Benchmark
2 source controls mapped|2 target controls covered
15%
API 1164
2 source controls mapped|4 target controls covered
15%
ISO/IEC 27010:2015
2 source controls mapped|2 target controls covered
15%
GS1 Global Standards - Supply Chain Traceability and Data Security
2 source controls mapped|3 target controls covered
15%
FSSC 22000 - Food Safety System Certification
2 source controls mapped|1 target controls covered
15%
ISO/IEC 27701:2019
2 source controls mapped|1 target controls covered
15%
Voluntary Principles on Security and Human Rights (VPs)
2 source controls mapped|1 target controls covered
15%
15%
HITECH Act
2 source controls mapped|3 target controls covered
15%
EASA Part-IS - Information Security in Aviation
2 source controls mapped|1 target controls covered
15%
COSO Internal Control - Integrated Framework (2013)
2 source controls mapped|2 target controls covered
15%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
2 source controls mapped|2 target controls covered
15%
OWASP Top 10:2025
2 source controls mapped|2 target controls covered
15%
OWASP DevSecOps Maturity Model (DSOMM)
2 source controls mapped|4 target controls covered
15%
FedRAMP Rev 5
2 source controls mapped|3 target controls covered
15%
Annex 11 to EU GMP - Computerised Systems
2 source controls mapped|3 target controls covered
15%
ISO/IEC 27011:2024
2 source controls mapped|4 target controls covered
15%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
2 source controls mapped|2 target controls covered
15%
SLSA
1 source controls mapped|1 target controls covered
8%
UK AI Regulation Framework
1 source controls mapped|1 target controls covered
8%
SIG (Shared Assessments)
1 source controls mapped|1 target controls covered
8%
PTES
1 source controls mapped|1 target controls covered
8%
OWASP SAMM
1 source controls mapped|1 target controls covered
8%
OWASP MASVS
1 source controls mapped|1 target controls covered
8%
OpenSSF Scorecard
1 source controls mapped|1 target controls covered
8%
Oman National Cybersecurity Framework
1 source controls mapped|1 target controls covered
8%
OECD AI Principles
1 source controls mapped|1 target controls covered
8%
NIST SP 800-92
1 source controls mapped|1 target controls covered
8%
NIST SP 800-88
1 source controls mapped|1 target controls covered
8%
NIST SP 800-63-4
1 source controls mapped|1 target controls covered
8%
NIST SP 800-61
1 source controls mapped|1 target controls covered
8%
NIST SP 800-146
1 source controls mapped|1 target controls covered
8%
NIST SP 800-145
1 source controls mapped|1 target controls covered
8%
NIST SP 800-144
1 source controls mapped|1 target controls covered
8%
NIST SP 800-137
1 source controls mapped|1 target controls covered
8%
NIST SP 800-123
1 source controls mapped|1 target controls covered
8%
NIS2 Directive
1 source controls mapped|1 target controls covered
8%
MTCS (Singapore)
1 source controls mapped|1 target controls covered
8%
MITRE ATT&CK
1 source controls mapped|1 target controls covered
8%
Japan AI Guidelines
1 source controls mapped|1 target controls covered
8%
IEEE 7000
1 source controls mapped|1 target controls covered
8%
Ghana Cybersecurity Act
1 source controls mapped|1 target controls covered
8%
FISMA
1 source controls mapped|1 target controls covered
8%
NIST SP 1800-32
1 source controls mapped|1 target controls covered
8%
NSA Guidance for Transition to Quantum-Resistant Cryptography
1 source controls mapped|1 target controls covered
8%
ISO 27043
1 source controls mapped|1 target controls covered
8%
ISO 27018
1 source controls mapped|1 target controls covered
8%
ISO 27019
1 source controls mapped|1 target controls covered
8%
NIST SP 800-53 Rev 5
1 source controls mapped|1 target controls covered
8%
ISO 27001:2022
1 source controls mapped|1 target controls covered
8%
ISO 14064 - Greenhouse Gas Accounting and Verification (Parts 1-3)
1 source controls mapped|1 target controls covered
8%
BSI IT-Grundschutz
1 source controls mapped|1 target controls covered
8%
ISO 27017
1 source controls mapped|1 target controls covered
8%
ISO/SAE 21434
1 source controls mapped|1 target controls covered
8%
NIST SP 800-190
1 source controls mapped|1 target controls covered
8%
PIC/S Guide to Good Manufacturing Practice for Medicinal Products
1 source controls mapped|1 target controls covered
8%
MDS2 (Medical Device)
1 source controls mapped|3 target controls covered
8%
ICH Q10 - Pharmaceutical Quality System
1 source controls mapped|3 target controls covered
8%
W3C Verifiable Credentials (VC) Data Model 2.0
1 source controls mapped|1 target controls covered
8%
Vietnam Law on Cybersecurity (No. 24/2018/QH14)
1 source controls mapped|1 target controls covered
8%
PCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR)
1 source controls mapped|2 target controls covered
8%
Pakistan Personal Data Protection Bill 2023
1 source controls mapped|2 target controls covered
8%
OCC Heightened Standards (12 CFR Part 30, Appendix D)
1 source controls mapped|1 target controls covered
8%
NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205)
1 source controls mapped|1 target controls covered
8%
India Account Aggregator Framework (RBI)
1 source controls mapped|1 target controls covered
8%
HKMA SPM
1 source controls mapped|1 target controls covered
8%
HKMA Cyber Resilience Assessment Framework (C-RAF)
1 source controls mapped|1 target controls covered
8%
GLI-33 - Gaming Laboratories International Event Wagering Systems
1 source controls mapped|1 target controls covered
8%
GLBA
1 source controls mapped|1 target controls covered
8%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
1 source controls mapped|4 target controls covered
8%
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution
1 source controls mapped|3 target controls covered
8%
IEC 62351 - Power Systems Communication Security
1 source controls mapped|1 target controls covered
8%
ISO/IEC 38500:2024 - Governance of IT
1 source controls mapped|3 target controls covered
8%
8%
ISO/IEC 27400:2022
1 source controls mapped|3 target controls covered
8%
ISO/IEC 29115:2023 - Entity Authentication Assurance Framework
1 source controls mapped|1 target controls covered
8%
NIST AI Risk Management Framework (AI RMF 1.0)
1 source controls mapped|2 target controls covered
8%
ISO/IEC 29134:2023
1 source controls mapped|3 target controls covered
8%
ISO/IEC 27050 - Electronic Discovery (Parts 1-4)
1 source controls mapped|1 target controls covered
8%
Illinois Biometric Information Privacy Act (BIPA)
1 source controls mapped|3 target controls covered
8%
Barbados Data Protection Act 2019
1 source controls mapped|1 target controls covered
8%
ISO/IEC 30111:2019
1 source controls mapped|3 target controls covered
8%
ISO/IEC 29147:2018
1 source controls mapped|3 target controls covered
8%
COBIT 2019
1 source controls mapped|1 target controls covered
8%
ISO/IEC 29100:2024
1 source controls mapped|3 target controls covered
8%
APRA CPS 234
1 source controls mapped|1 target controls covered
8%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
1 source controls mapped|2 target controls covered
8%
Azerbaijan Law on Personal Data (2010)
1 source controls mapped|1 target controls covered
8%
FedRAMP High
1 source controls mapped|1 target controls covered
8%
NIST SP 800-53 Revision 5.1 HIGH
1 source controls mapped|1 target controls covered
8%
FedRAMP Moderate
1 source controls mapped|1 target controls covered
8%
NIST SP 800-53 Rev 5 MODERATE
1 source controls mapped|1 target controls covered
8%
NIST SP 800-53 Rev 5 LOW
1 source controls mapped|1 target controls covered
8%
ISO/IEC 27004:2016
1 source controls mapped|3 target controls covered
8%
ISO/IEC 27031:2011
1 source controls mapped|1 target controls covered
8%
FFIEC IT Examination Handbook
1 source controls mapped|1 target controls covered
8%
IAIS Insurance Core Principles (ICPs)
1 source controls mapped|1 target controls covered
8%
ISO/IEC 27007:2020
1 source controls mapped|1 target controls covered
8%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
1 source controls mapped|1 target controls covered
8%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
1 source controls mapped|1 target controls covered
8%
IRM Enterprise Risk Management Framework (Institute of Risk Management)
1 source controls mapped|1 target controls covered
8%
Authorised Economic Operator (AEO) Programmes - Global Standards
1 source controls mapped|2 target controls covered
8%
Space ISAC (Information Sharing and Analysis Center) - Threat Framework
1 source controls mapped|1 target controls covered
8%
APRA CPS 230 Operational Risk Management
1 source controls mapped|2 target controls covered
8%
Automotive SPICE (ASPICE) v4.0 - Process Assessment Model
1 source controls mapped|1 target controls covered
8%
FBI CJIS Security Policy
1 source controls mapped|1 target controls covered
8%

Frequently Asked Questions

What is FDA Quality Management System Regulation (QMSR)?

FDA Quality Management System Regulation (QMSR) is a compliance framework from United States with 7 domains and 13 controls. The new 21 CFR Part 820 (Quality Management System Regulation, QMSR) was published as a Final Rule on 31 January 2024 (89 FR 7496) and applies from 2 FEBRUARY 2026. It HARMONISES the FDA medical device quality system requirements with ISO 13485:2016 by INCORPORATING THAT STANDARD BY REFERENCE under §820.7 + retaining a small number of FDA-specific additions (§820.15 clarifications + §820.35 record controls including audit trail + UDI + reporting + §820.45 device labelling + packaging controls). The QMSR replaces the prior Quality System Regulation (QSR) which had its own elaborate structure (former §820.20 through §820.250 covering management responsibility + design controls + document control + purchasing + production + acceptance + CAPA + labelling + handling + records + servicing + statistical techniques). The QMSR applies to FINISHED MEDICAL DEVICES that are intended for human use + are subject to FDA registration + listing under section 510 of the Federal Food, Drug, and Cosmetic Act. STRUCTURE - the QMSR Final Rule has 7 substantive sections: §820.1 scope; §820.3 definitions; §820.7 incorporation by reference; §820.10 requirements for a quality management system (incorporating ISO 13485:2016 Sections 4-8); §820.15 clarification of concepts (FDA-specific clarifications + glossary harmonisation); §820.35 control of records (record retention + audit trail + UDI + medical-device reporting + corrections and removals records); §820.45 device labelling and packaging controls (FDA-specific). RELATED FRAMEWORKS: ISO 13485:2016 (incorporated by reference + COPYRIGHTED + NEEDS LICENSED COPY); EU MDR (Regulation (EU) 2017/745) + IVDR (Regulation (EU) 2017/746) parallel medical device + IVD regulations; FDA Part 11 (Electronic Records + Electronic Signatures) for computer system validation + audit trail records under §820.35; FDA Cybersecurity Premarket Guidance + Cures Act 524B for medical device software. The 2-YEAR TRANSITION PERIOD requires FDA-regulated medical device manufacturers to fully implement the harmonised QMSR by 2 February 2026 + the FDA has clarified that the transition does not require re-certification - existing QSR-compliant systems will be evaluated against QMSR during routine inspections after the application date. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does FDA Quality Management System Regulation (QMSR) have?

FDA Quality Management System Regulation (QMSR) has 13 controls organised across 7 domains. The largest domains are QMSR: Quality Management System Requirements (§820.10 incorporating ISO 13485:2016 Sec. 4-8) (6 controls), QMSR: Transition Plan from Prior QSR, FDA Inspection Approach, Status (2 controls), QMSR: Clarification of Concepts and Definitions (§820.15) (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does FDA Quality Management System Regulation (QMSR) map to?

FDA Quality Management System Regulation (QMSR) maps to 160 other compliance frameworks. The top mapping partners are ICH E6(R3) - Good Clinical Practice (46% coverage), SWIFT CSCF (38% coverage), ISO 45001:2018 (38% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with FDA Quality Management System Regulation (QMSR) compliance?

Start your FDA Quality Management System Regulation (QMSR) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about FDA Quality Management System Regulation (QMSR) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 13 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required