On this page
Published: October 20, 2024 · Last reviewed: May 1, 2026
Key Takeaways
- The QMSR replaced most of Part 820's original text with an incorporation of ISO 13485:2016, not a new quality standard invented by the FDA.
- Many former QSR subparts are now reserved; citing them as active requirements is a compliance and credibility error.
- Design controls remain the anchor for generating cybersecurity evidence, they just map to ISO 13485 clause 7.3 rather than a standalone Part 820 subpart.
- CAPA and complaint handling must treat cybersecurity vulnerabilities as nonconformities with the same rigor as any other quality escape.
- Supplier controls now carry more weight because third-party software and components are a documented source of risk under both QMSR and Section 524B.
- QSIT is retired; FDA investigators now use CP 7382.850, which changes how inspections probe cybersecurity records.
21 CFR Part 820 is the FDA's Quality System Regulation for medical devices. As of February 2, 2026, it operates as the Quality Management System Regulation (QMSR), which incorporates ISO 13485:2016 by reference and reserves many of the old QSR subparts rather than replacing FDA oversight. Cybersecurity artifacts required under Section 524B, threat models, SBOMs, CAPA records, and design history files, must be generated and controlled inside this QMS, not produced separately for a submission.
Reviewed September 17, 2026
Medical device manufacturers are now operating under a rewritten quality regulation, and the transition has direct consequences for how cybersecurity evidence gets built and defended. The QMSR did not soften the FDA's expectations; it changed where those expectations live in the text and tied them more tightly to ISO 13485:2016. Teams that keep citing the old QSR subpart numbers for design controls or document requirements risk citing sections that are now reserved. Getting the mapping wrong in an audit or a submission response is more than a paperwork problem, it signals that the QMS itself has not been updated. This matters most for cybersecurity because Section 524B premarket artifacts, SBOMs, threat models, vulnerability management plans, are only credible if they trace back to controlled QMS records rather than one-off documents assembled for the FDA.
Why This Matters
The FDA's "Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions" final guidance, dated February 3, 2026, is explicit that cybersecurity risk management is not a separate deliverable bolted onto a submission. It has to be an output of the manufacturer's quality management system, from design input through postmarket surveillance. The QMSR transition landed one day before that guidance took effect, which is not a coincidence, both reflect the FDA's move toward international harmonization while keeping device-specific enforcement authority.
Manufacturers that treat the QMSR as a documentation reshuffle will miss the substance: ISO 13485:2016 uses different terminology and a different clause structure than the old QSR, and inspectors trained under CP 7382.850 will ask for records mapped to that structure. Cybersecurity documentation, SBOMs, threat models, penetration test reports, coordinated vulnerability disclosure records, has to sit inside the same document control and record retention scheme as every other design and production record. If it does not, the FDA can treat it as unverified, which undermines a Section 524B submission regardless of the technical work behind it.
What Is 21 CFR Part 820?
21 CFR Part 820 is the FDA's regulation establishing the Quality System Regulation for medical device manufacturers, first issued to require design, production, and postmarket controls that keep devices safe and effective. Before the 2026 amendment, Part 820 contained the FDA's own subpart structure covering design controls, document controls, production and process controls, and CAPA. It applied to any entity engaged in the design, manufacture, packaging, labeling, storage, installation, or servicing of finished devices intended for the U.S. market.
[KEY REQUIREMENT] Part 820 compliance is not optional for a device to be legally marketed in the United States; it is a condition of maintaining a valid establishment registration and device listing, and failure to comply can result in warning letters, import holds, or consent decrees regardless of premarket clearance status.
What Changed Under the QMSR Amendment?
The QMSR amendment, effective February 2, 2026, replaced most of Part 820's original FDA-authored text with an incorporation by reference of ISO 13485:2016, plus a smaller set of FDA-specific additions. This is a harmonization move, not a deregulation. The FDA retains full enforcement authority over device manufacturers; it did not hand oversight to ISO or to a third party.
Several concrete changes matter for cybersecurity programs:
- Many former QSR subparts are now reserved because their content is superseded by the corresponding ISO 13485:2016 clause. Do not cite a reserved subpart as an active requirement in an SOP or a submission.
- Terminology shifted to align with ISO 13485 language, for example "quality management system" replaces "quality system" and clause-based cross references replace some of the old subpart numbering.
- Section 820.35 is now a records requirement, distinct from its prior scope, and manufacturers should confirm their document control procedures reference the current text rather than a legacy interpretation.
- Section 820.45 addresses device labeling and packaging controls and remains a distinct FDA-specific provision layered on top of ISO 13485.
- The FDA's Quality System Inspection Technique (QSIT) program was retired on February 2, 2026, and replaced by inspection program CP 7382.850, which investigators now use to structure QMS inspections including cybersecurity-relevant records.
Old QSR Subsystem vs. Where the Requirement Lives Now
| Legacy QSR Subsystem | Prior Subpart | Current Location Under QMSR/ISO 13485 |
|---|---|---|
| Design controls | Subpart C, 820.30 | ISO 13485:2016 clause 7.3, referenced through QMSR |
| Document controls | Subpart D, 820.40 | ISO 13485:2016 clause 4.2, plus FDA record provisions |
| Records | Subpart M, 820.180-820.198 | Largely reserved; core content now in ISO 13485 clause 4.2.5 and retained FDA-specific record rules including 820.35 |
| Production and process controls | Subpart G, 820.70-820.75 | ISO 13485:2016 clause 7.5 |
| CAPA | Subpart J, 820.100 | ISO 13485:2016 clause 8.5.2-8.5.3, with FDA CAPA expectations preserved |
| Labeling and packaging | Subpart H, 820.120-820.130 | Retained in part as 820.45, an FDA-specific addition alongside ISO 13485 |
| Management responsibility | Subpart B, 820.20 | ISO 13485:2016 clause 5 |
Manufacturers should update internal SOPs to cite the current clause structure, since an SOP that still points exclusively to a reserved subpart will not hold up under a CP 7382.850 inspection.
Who Does Part 820 Apply To, and What Is Exempt?
Part 820, now operating as the QMSR, applies to any manufacturer, specification developer, contract manufacturer, or repackager involved in producing finished devices for the U.S. market, domestic or foreign. The scope has not narrowed under the QMSR amendment. Certain lower-risk Class I devices remain exempt from the design control requirements under the same criteria the FDA used before the amendment, and some Class I devices are exempt from the QMSR entirely unless they are implantable, life-sustaining, or life-supporting. Manufacturers should not assume an exemption carries over automatically; the exemption list is device-specific and should be verified against the current device classification regulation rather than assumed from legacy practice.
Why Do Design Controls Matter for Cybersecurity Evidence?
Design controls are where cybersecurity risk management has to originate, because the FDA expects the threat model, architecture views, and risk analysis to be design inputs, not retrofits. Under ISO 13485:2016 clause 7.3, incorporated through the QMSR, design input, verification, and validation records must capture the security requirements a device was built to meet. A threat model produced after the design is frozen cannot satisfy this, because it cannot demonstrate that security requirements shaped design decisions.
[KEY REQUIREMENT] Cybersecurity risk assessments, secure design decisions, and verification test results must be captured as design control records inside the QMS, with the same revision control and approval signatures as any other design output, so they can be traced from a Section 524B submission back to a specific design review.
How Do CAPA and Complaint Handling Cover Vulnerabilities?
See also: CAPA in Medical Device Cybersecurity, The Importance of a Medical Device QMS, and Conducting a Medical Device Security Audit.
CAPA and complaint handling processes must treat a discovered vulnerability the same way they treat any other nonconformity, with root cause analysis, corrective action, and effectiveness checks. A vulnerability report, whether from internal testing, a coordinated disclosure researcher, or a customer complaint, should enter the same complaint handling system that captures a mechanical failure. Under ISO 13485:2016 clause 8.5, incorporated through the QMSR, that record has to show the investigation was completed and the corrective action addressed the root cause, not just the specific instance reported.
What Do Supplier Controls Require for Third-Party Software?
Supplier controls require manufacturers to qualify and monitor any supplier providing components that affect device safety or performance, and third-party software components fall squarely in that scope. An SBOM identifies what third-party and open-source components are present, but supplier controls under ISO 13485:2016 clause 7.4 require a documented basis for trusting that supplier's development and update practices. Manufacturers should maintain purchasing controls that require component suppliers to disclose known vulnerabilities and support end-of-life timelines, since that information feeds directly into the SBOM and postmarket vulnerability management obligations under Section 524B.
How Do Document and Record Controls Apply to Threat Models and SBOMs?
Document and record controls require that threat models, SBOMs, and related cybersecurity artifacts be maintained as controlled documents with version history, approval records, and defined retention periods. ISO 13485:2016 clause 4.2, incorporated through the QMSR, sets the baseline for this, and 820.35's current record requirement adds an FDA-specific layer on top. An SBOM that is regenerated informally for each submission without version control does not meet this standard, because there is no traceable record of what changed between versions or why.
How Do Section 524B Premarket Artifacts Trace Back to QMS Records?
Section 524B premarket cybersecurity artifacts, the SBOM, the threat model, the vulnerability management plan, and the SPDF description, all have to trace back to specific QMS records rather than exist as submission-only documents. The FDA's February 3, 2026 final guidance expects reviewers to be able to follow a threat identified in the threat model to a design control record showing how it was mitigated, and from there to a verification or validation record showing the mitigation was tested. If a submission's cybersecurity narrative cannot be reconciled with the underlying design history file and CAPA records, it signals that the documentation was assembled outside the QMS, which the FDA can flag as a quality system deficiency independent of the technical merits.
How Blue Goat Cyber Approaches This
Blue Goat Cyber works with manufacturers to align cybersecurity evidence, threat models, SBOMs, and penetration test results, with the QMS records that have to support a Section 524B submission under the QMSR. We review existing design history files and CAPA procedures to identify where cybersecurity documentation is disconnected from controlled records, and we help rebuild that traceability before a submission goes in. Our team includes CISSP and OSCP-certified engineers with backgrounds spanning red team operations and quality systems. If the FDA raises cybersecurity deficiencies after our engagement, we resolve them at no additional cost. Manufacturers preparing a design history file for a new submission can start with our FDA premarket cybersecurity services.
Frequently Asked Questions
Does the QMSR replace 21 CFR Part 820?
The QMSR did not replace the FDA's authority over medical device quality systems; it amended Part 820 to incorporate ISO 13485:2016 by reference and add FDA-specific provisions. The FDA still enforces the regulation, inspects manufacturers, and can take action for nonconformance. Manufacturers are still operating under Part 820, just with different underlying text.
Are all the old QSR subparts still in effect?
No, many former subparts are now reserved because ISO 13485:2016 covers the same content through its own clause structure. Citing a reserved subpart as if it is a current, standalone requirement is inaccurate and can undermine an SOP or a submission response. Manufacturers should verify current citations against the amended regulation text.
What replaced QSIT for FDA inspections?
The FDA retired the Quality System Inspection Technique program on February 2, 2026, and replaced it with inspection program CP 7382.850. Investigators use CP 7382.850 to structure inspections against the QMSR and ISO 13485:2016 clause structure, which affects how cybersecurity-relevant records get requested and reviewed during an inspection.
Does Part 820 explicitly require cybersecurity controls?
Part 820 and the QMSR do not name cybersecurity as a standalone subpart, but design controls, CAPA, supplier controls, and document controls all apply to cybersecurity activities the same way they apply to any other design or quality function. Section 524B and the FDA's premarket cybersecurity guidance layer specific cybersecurity content requirements on top of this general QMS framework.
Who is exempt from Part 820 or the QMSR?
Certain Class I devices are exempt from design control requirements or from the QMSR entirely, unless they are implantable, life-sustaining, or life-supporting. Exemptions are device-specific and tied to classification regulations, not a blanket exemption for a product category. Manufacturers should confirm exemption status against the current device classification rather than legacy assumptions.
How does an SBOM connect to Part 820 record requirements?
An SBOM has to be maintained as a controlled document under the same document and record control requirements that apply to other design outputs, including version history and defined retention. This lets the SBOM submitted for a Section 524B review be traced to a specific design record and update history rather than standing alone as an unverified list.
CTA
If your design history files, CAPA records, and cybersecurity documentation are not telling the same story, that gap will surface in an FDA review or an inspection under CP 7382.850. Blue Goat Cyber can review your QMS structure against the current QMSR text and help close the traceability gap before it becomes a deficiency. Contact us to schedule a QMS and cybersecurity documentation review.
About the author
Christian Espinosa, MBA, CISSP · Founder & CEO, Blue Goat Cyber
U.S. Air Force Academy graduate and veteran with 30+ years in cybersecurity. Founded Alpine Security in 2014 (acquired 2020), then Blue Goat Cyber in 2022. Has supported 275+ FDA medical device submissions; no client has failed to clear due to cybersecurity. Author of three books including The Smartest Person in the Room. Ironman triathlete and mountaineer.
