Safety compliance for medical devices in 2026 under FDA QMSR and EU MDR

man, mask, covid, covid-19, face mask, surgical mask, pandemic, young man, portrait, coronavirus, mask, covid, covid, covid, covid, covid, face mask, pandemic

Why safety compliance now means lifecycle evidence

Safety compliance for medical devices in 2026 is not a checklist completed just before launch. It is an evidence system that connects intended use, risk management, design controls, supplier controls, usability, cybersecurity, production monitoring, complaint handling and field action decisions. Regulators expect manufacturers to show how safety decisions were made, how they were verified, and how those decisions remain valid after the device is in use.

This shift affects manufacturers, importers, distributors, hospital buyers and technical teams because the same device may face tighter expectations in several areas at the same time. In the United States, FDA’s Quality Management System Regulation became effective on February 2, 2026. In Europe, MDR transition dates continue to apply only under defined conditions. For more coverage of device risk, quality and regulatory updates, see our safety and compliance section.

wash, hands, soap, hygiene, clean, handwash, coronavirus, covid-19, wash, wash, soap, soap, soap, hygiene, hygiene, hygiene, hygiene, clean, clean, clean, handwash, handwash, handwash, coronavirus, coronavirus, coronavirus, coronavirus, coronavirus, covid-19, covid-19, covid-19

What changed for medical device safety compliance in 2026

The main 2026 compliance theme is convergence. FDA has moved its device quality regulation closer to ISO 13485:2016, while EU MDR already requires a risk-based quality management system and technical documentation that supports general safety and performance requirements. Global requirements are not identical, but manufacturers now need fewer isolated compliance files and more consistent lifecycle evidence.

FDA QMSR is now effective

FDA published the QMSR final rule on February 2, 2024, with an effective date of February 2, 2026. The rule amends 21 CFR Part 820 and incorporates ISO 13485:2016 by reference as the foundation for medical device quality management system requirements. FDA also incorporates Clause 3 of ISO 9000:2015 for terminology. The agency has stated that the federal Food, Drug, and Cosmetic Act and FDA implementing regulations control if there is any conflict with the incorporated standard.

For industry teams, the bigger operational issue is inspection readiness. FDA’s QMSR FAQ explains that, during inspections on or after February 2, 2026, investigators may review records that are part of the manufacturer’s quality management system, including records created before the QMSR effective date. FDA also states that management review, quality audit and supplier audit reports are no longer excluded in the same way they were under the prior QS regulation record-review exception. That raises the importance of document consistency, audit trails and meaningful management review.

Cybersecurity and human factors are part of safety evidence

FDA’s February 2026 final cybersecurity guidance addresses quality management system considerations and premarket submission content for devices with cybersecurity risk. It describes expectations for cybersecurity device design, labeling and documentation, and it supersedes FDA’s June 27, 2025 cybersecurity guidance. For connected devices, the point is direct: cybersecurity becomes a safety issue when a vulnerability could affect clinical performance, data integrity, availability or user trust.

FDA’s August 2026 final guidance on applying human factors and usability engineering to medical devices reinforces another core point: use-related risk must be managed through design, not only through warnings. Usability evidence should connect intended users, use environments, known hazards, critical tasks, formative evaluations and validation activities. For devices used by patients at home, emergency clinicians, older adults or multiple professional roles, this evidence can be central to the safety case.

EU MDR transition remains conditional

In the European Union, Regulation (EU) 2017/745 has applied since May 26, 2021. Regulation (EU) 2023/607 extended certain MDR transition periods to address device shortage risks, but it did not create a blanket delay. For many legacy devices, the extension runs to December 31, 2027 for class III devices and specified class IIb implantable devices, and to December 31, 2028 for other listed class IIb, class IIa and certain class I sterile or measuring devices. Devices that previously did not require a notified body under the old directive but do under MDR may also have a December 31, 2028 date in defined circumstances.

The conditions matter as much as the dates. The device must continue to comply with the applicable previous directive, must not have significant changes in design or intended purpose, must not present an unacceptable health or safety risk, and the manufacturer needed an MDR quality management system and notified body application milestones by the 2024 deadlines specified in the regulation. In practice, transition status should be treated as a controlled regulatory claim, not an assumption.

A practical compliance map for device teams

The following map shows how a modern safety compliance file can connect regulatory expectations to daily work. It is not a substitute for a device-specific regulatory plan, but it helps teams avoid scattered documentation and unsupported claims.

Compliance area Core safety question Typical evidence to maintain
Intended use and claims Who uses the device, for what clinical purpose, and in what environment? Intended use statement, indications, user profiles, labeling rationale and claim traceability.
Risk management Have hazards been identified, evaluated, controlled and monitored across the lifecycle? Risk management plan, hazard analysis, benefit-risk rationale, risk controls, residual risk evaluation and production or post-production updates.
Design and development Do design outputs meet design inputs and user needs? Design plans, input-output traceability, verification, validation, design reviews and change records.
Usability Could foreseeable use errors cause harm? Use-related risk analysis, critical task analysis, formative study records, validation study protocol and results.
Cybersecurity Could security threats affect safety, effectiveness or availability? Threat modeling, secure design controls, software bill of materials where applicable, vulnerability handling process, update strategy and labeling.
Supplier and production controls Can the device be made consistently within specifications? Supplier qualification, purchasing controls, process validation, acceptance criteria, nonconformance handling and corrective actions.
Postmarket surveillance Are field signals being captured, evaluated and acted on? Complaint files, adverse event evaluations, trend reviews, UDI records, vigilance reports, recall or correction decisions and CAPA links.

Risk management is the backbone, not a separate document

ISO 14971:2019 remains a central international reference for medical device risk management. ISO describes it as a standard that specifies terminology, principles and a process for identifying hazards, estimating and evaluating associated risks, controlling those risks and monitoring control effectiveness throughout the device lifecycle. The standard was published in 2019 and, according to ISO’s public information, was reviewed and confirmed in 2025.

Risk management is weak when it is treated as a file assembled near the end of development. It is useful when it drives early design decisions. For example, if a home-use infusion device has a foreseeable risk of incorrect setup, the safety compliance response should not stop at a warning statement. The team should consider design simplification, physical constraints, software prompts, alarm behavior, training assumptions, labeling and validation with representative users. The final risk file should show why the selected controls are appropriate and how their effectiveness was verified.

The same principle applies to software and connected equipment. If a cybersecurity threat could interrupt therapy, corrupt a measurement or delay an alarm, it belongs in the safety discussion. If a supplier component affects essential performance, supplier controls belong in the safety discussion. If production data shows a drift in a critical dimension, the risk file should be updated when that drift affects risk estimates or controls.

Inspection readiness after QMSR

QMSR inspection readiness is not just a matter of replacing old procedure titles. It requires manufacturers to show how the quality system works as a system. FDA has indicated that its post-February 2, 2026 inspection process aligns with QMSR and that the older Quality System Inspection Technique is no longer used. Teams should therefore expect broader questions about process interaction, risk-based decision making and management oversight. See also: clinical equipment.

A practical internal step is to perform a structured crosswalk between legacy 21 CFR Part 820 procedures, ISO 13485:2016 clauses and current FDA-specific requirements. The crosswalk should identify where procedures changed, where old records still demonstrate compliance, and where additional rationale is needed. It should also show how complaint handling, CAPA, purchasing controls, production controls and design changes feed back into risk management.

Companies should pay special attention to records that may have been less visible under the prior inspection model. Management review minutes should show meaningful review of safety, quality and compliance trends. Internal audit records should be objective and complete enough to support corrective action. Supplier audit records should explain why supplier risk is acceptable, especially when outsourced processes affect sterile barriers, software, electronics, calibration, biocompatibility or critical performance.

Postmarket duties can change the safety case

Safety compliance does not end at release. FDA’s Medical Device Reporting regulation under 21 CFR Part 803 requires manufacturers to report deaths, serious injuries and certain malfunctions within 30 calendar days after becoming aware of a reportable event. FDA also describes five-workday reports for events designated by FDA or events that require remedial action to prevent an unreasonable risk of substantial harm to public health. Importers and user facilities have their own reporting duties and timelines.

Corrections and removals are another critical postmarket area. Under 21 CFR Part 806, manufacturers and importers must report certain corrections or removals to FDA when the action is initiated to reduce a risk to health or remedy a violation that may present a risk to health. FDA describes a 10-working-day reporting timeline from the initiation of the correction or removal. Even when a correction or removal is not reportable, records must be maintained.

UDI also supports postmarket safety by helping identify devices through distribution and use. FDA’s UDI system generally requires labelers to place a unique device identifier on device labels and packages, subject to exceptions and alternatives, and to submit device information to the Global Unique Device Identification Database. In a recall, complaint trend review or hospital investigation, weak identification can delay risk assessment and field action.

Checklist for a stronger 2026 safety compliance program

  • Confirm which regulations, guidance documents and standards apply to each device family and market.
  • Update the quality system crosswalk for FDA QMSR, ISO 13485:2016 and applicable local requirements.
  • Recheck whether management review, internal audit and supplier audit records would withstand regulatory review.
  • Connect risk management to design inputs, verification, validation, usability, cybersecurity, production controls and postmarket data.
  • Review EU legacy device transition status with evidence for each condition, not only the transition date.
  • Ensure cybersecurity risk management is integrated for connected, software-driven or data-dependent devices.
  • Validate critical user tasks with representative users, uses and environments where use error could cause harm.
  • Test complaint handling procedures against FDA Medical Device Reporting, EU vigilance, and correction or removal decision timelines.
  • Use UDI, lot, serial and distribution records to support rapid traceability in field safety actions.
  • Document benefit-risk reasoning when residual risk remains after controls are implemented.

Frequently asked questions

What is safety compliance for medical devices?

Safety compliance is the documented ability to show that a device is designed, manufactured, labeled, monitored and corrected in ways that meet applicable regulatory requirements and protect patients, users and others. It includes quality management, risk management, usability, cybersecurity, production controls and postmarket surveillance.

Does FDA QMSR make ISO 13485 certification mandatory?

No. FDA has incorporated ISO 13485:2016 into QMSR, but FDA’s public FAQ states that it will not require certificates of conformance to ISO 13485 and will not issue such certificates. FDA inspections assess compliance with FDA regulations.

Are EU MDR transition extensions automatic?

No. The extensions under Regulation (EU) 2023/607 are conditional. Manufacturers need evidence that the device falls within the covered categories and meets conditions such as no significant change in design or intended purpose, no unacceptable risk, and required quality system and notified body milestones.

Why are cybersecurity and usability treated as safety issues?

Cybersecurity can affect safety when a threat changes device performance, data integrity, availability or clinical decision support. Usability can affect safety when foreseeable use errors cause or contribute to harm. Both areas should be connected to the risk management file and validated through appropriate evidence.

What is the main takeaway for 2026?

The main takeaway is that safety compliance should be managed as a lifecycle evidence system. A manufacturer should be able to explain what risks were known, what controls were chosen, why those controls were acceptable, how they were verified, and how postmarket signals are used to keep the safety case current.