FDA 21 CFR Part 820 Quality System Regulation Compliance Checklist: Design Controls & Corrective Action Requirements for Medical Device Manufacturers
Master FDA 21 CFR Part 820 compliance with our detailed checklist covering design controls, CAPA, and audit requirements for medical device manufacturers. Updated 2025.
---
Introduction: Why FDA 21 CFR Part 820 Compliance Is Non-Negotiable for Medical Device Manufacturers
In the intricate world of medical device manufacturing, precision, reliability, and above all, patient safety, are paramount. These foundational principles are codified by the U.S. Food and Drug Administration (FDA) through its Quality System Regulation (QSR), specifically 21 CFR Part 820. For medical device companies, compliance with this regulation isn't merely a suggestion; it's a legal and ethical imperative. Failure to adhere carries severe consequences, extending far beyond monetary penalties.
Consider the stark reality revealed by FDA enforcement actions. Year after year, FDA Form 483 inspection observations and Warning Letters frequently cite deficiencies in manufacturers' Quality Management Systems (QMS), with specific sections of Part 820 often highlighted. For instance, data consistently shows that Design Controls (§820.30) and Corrective and Preventive Actions (CAPA) (§820.100) are among the most common areas of non-compliance, leading to significant scrutiny. These observations are not just paperwork; they are precursors to product recalls, import alerts, consent decrees that impose strict oversight, and in egregious cases, even criminal liability for individuals. The reputational damage alone can be catastrophic, eroding patient and physician trust built over years.
This article provides a structured compliance framework designed to help medical device manufacturers navigate the complexities of Part 820. It focuses on the two highest-cited deficiency areas—Design Controls (§820.30) and CAPA (§820.100)—offering actionable checklists derived directly from the regulatory text.
It's also critical to acknowledge a monumental shift: the FDA's transition from the legacy QSR (21 CFR Part 820) to the new Quality Management System Regulation (QMSR). This final rule, published in 2024 and effective February 2, 2026, harmonizes the FDA's requirements with the international standard ISO 13485:2016. This shift necessitates a re-evaluation of existing QMS processes. Proactive manufacturers are already beginning to assess their readiness. To get a comprehensive understanding of your current standing and areas for improvement across your entire quality system, we recommend you explore our full FDA 21 CFR 820 Medical Device Internal Audit Readiness Checklist.
What Is FDA 21 CFR Part 820 and Who Must Comply?
The Quality System Regulation (QSR), outlined in 21 CFR Part 820, lays down the federal requirements governing the methods, facilities, and controls used in the design, manufacture, packaging, labeling, storage, installation, and servicing of finished medical devices. Its overarching goal is to ensure that medical devices are safe and effective for their intended use. Essentially, it dictates what a medical device manufacturer’s Quality Management System must entail to produce compliant products.
The applicability of Part 820 is broad, encompassing any firm that manufactures, prepares, propagates, compounds, assembles, or processes a medical device for commercial distribution in the U.S. This includes:
- Class II and Class III device manufacturers: These are the primary focus, though certain Class I devices are also covered.
- Specification developers: Companies that design devices but outsource manufacturing.
- Repackagers and relabelers: Firms that alter medical device packaging or labels.
- Contract manufacturers and sterilizers: Companies performing specific processes on behalf of a device manufacturer.
- Software-only device developers: Manufacturers of Software as a Medical Device (SaMD) are also subject to QSR requirements, adapting traditional hardware-centric controls to software development lifecycles.
To truly understand Part 820, it’s essential to view it within the broader regulatory ecosystem:
- 21 CFR Part 820 (QSR / QMSR): This is the foundational quality system framework itself, setting the operational standards.
- 21 CFR Part 803 (Medical Device Reporting - MDR): This regulation requires manufacturers to report adverse events, which often serve as critical data inputs for a robust CAPA system.
- 21 CFR Part 806 (Reports of Corrections and Removals): This governs the reporting of recalls and field actions, which are direct outputs or consequences of CAPA and other quality processes.
- ISO 13485:2016 (Medical devices — Quality management systems — Requirements for regulatory purposes): This international standard has long served as a globally recognized benchmark for medical device QMS. With the QMSR transition, it will now be incorporated by reference into U.S. law, creating significant harmonization. The principles of effective purchasing controls and supplier audits are also explicitly integrated within both Part 820 and ISO 13485, recognizing the critical role of the supply chain in overall product quality and safety.
The QMSR transition timeline is a critical consideration. While the final rule was published in 2024, the effective date is February 2, 2026. This means manufacturers have a grace period to update their Quality Management Systems. During this period, compliance with either the legacy 21 CFR Part 820 or the new QMSR (which effectively means ISO 13485:2016) is acceptable. However, by February 2026, all manufacturers must be fully compliant with the QMSR. Proactive manufacturers should use this time to perform a thorough gap analysis between their current QMS and the new QMSR requirements, initiating the necessary procedural updates, training, and system modifications. Assessing your QMS against the new standard now is crucial for a smooth transition.
QMSR vs. Legacy QSR: Key Differences Manufacturers Must Track
The QMSR doesn't replace the QSR entirely; rather, it modernizes and harmonizes it by adopting the structure and many of the requirements of ISO 13485:2016. While the core intent of ensuring safe and effective devices remains, the approach and certain explicit requirements have evolved. Manufacturers need to track these differences meticulously.
Here’s a high-level comparison highlighting the shift:
| Feature/Requirement | Legacy 21 CFR Part 820 (QSR) | New QMSR (incorporating ISO 13485:2016) | Implications for Manufacturers |
| :------------------------------- | :---------------------------------------------------------------------- | :----------------------------------------------------------------------------- | :---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Structure | Prescriptive, section-by-section requirements | Process-based approach, aligned with ISO 13485:2016 clauses | Requires a remapping of existing QMS procedures to the new structure; emphasis on process interaction and effectiveness. |
| Risk Management | Implied in design controls, CAPA, etc. | Explicit and integrated throughout the entire QMS (aligned with ISO 14971) | Mandates formal risk management activities at all stages of the product lifecycle, from design to post-market surveillance. Manufacturers must have robust risk management files. |
| Documentation | Required for various processes (e.g., DHF, DMR, DHR) | Focus on "documented information," more flexible in format but requires control | Emphasis on controlled processes and records rather than specific document titles. Digital transformation for documentation management becomes even more critical. |
| Design Controls | Detailed under §820.30 | Covered in Clause 7.3 of ISO 13485, with emphasis on risk and usability | While conceptually similar, the integration of risk management (ISO 14971) and human factors/usability engineering is more explicit and stringent. |
| CAPA | Detailed under §820.100 | Covered in Clause 8.5.2 and 8.5.3 of ISO 13485 | The core requirements remain similar, but the process-oriented nature of ISO 13485 may lead to more integrated and less siloed CAPA systems, with stronger links to other QMS elements. |
| Supplier Controls | Covered under §820.50 Purchasing Controls | Covered in Clause 7.4 of ISO 13485, with risk-based supplier evaluation | Stronger emphasis on a risk-based approach to supplier selection, evaluation, and monitoring, proportionate to the risk posed by the supplied product or service. |
| Software Validation | Addressed implicitly, or through FDA guidance documents (e.g., General Principles of Software Validation) | Explicitly required for software used in the QMS and for SaMD | Manufacturers must ensure all software used in production, quality management, or as a medical device itself is validated according to its intended use and risk level. |
| Post-Market Surveillance | Addressed through MDR, complaints, etc. | More explicit links between post-market data and design/risk management processes | Requires a closed-loop system where post-market data feeds directly back into design and risk management, driving continuous improvement and potential CAPA. |
Action Item for Manufacturers: It is imperative that medical device manufacturers run a dual-compliance gap audit now. This involves assessing their existing QMS against both the legacy Part 820 and the impending QMSR (ISO 13485:2016). Identifying gaps early allows for a structured remediation plan, training initiatives, and system adjustments well before the February 2026 deadline, preventing last-minute rushes and potential non-compliance findings.
FDA 21 CFR Part 820.30 Design Controls Compliance Checklist
Design Controls, as stipulated in §820.30, are consistently among the most frequently cited sections in FDA Form 483 observations and Warning Letters. This is largely because deficiencies in design controls can have direct and severe implications for device safety and effectiveness. A poorly designed device, or one whose design is not adequately documented and controlled, is inherently risky. Design controls ensure that the device developed meets user needs and its intended use, reducing the likelihood of product failures, recalls, and patient harm.
Here's a breakdown of the seven core design control elements, presented as a practical checklist:
Design and Development Planning (§820.30(b))
The foundation of any successful medical device development lies in comprehensive planning. A clear plan ensures that all activities are organized, resourced, and executed effectively.
- [ ] Design plan exists and is version-controlled: A written design and development plan is established for each new device or significant modification, outlining the design stages, milestones, and deliverables. This plan should be a living document, updated as the project evolves.
- [ ] Responsibilities and authorities documented: The responsibilities of all personnel involved in the design and development activities are clearly defined, including those responsible for verification, validation, and design review.
- [ ] Plan is reviewed and updated at each phase gate: The design plan is reviewed, approved, and updated as appropriate as the design and development activities progress through defined stages or "phase gates."
- [ ] Interface with other groups defined: The plan clearly identifies and defines the interfaces with different groups or departments responsible for different segments of the design and development.
- Common deficiency: Many plans are created at the project's inception but are never revisited or updated, rendering them obsolete and ineffective as the design inevitably changes.
Design Input (§820.30(c))
Design inputs are the requirements that form the basis for the design. They must be accurate, unambiguous, and documented to ensure the final device meets user needs.
- [ ] Intended use and user needs captured in writing: The device's intended use and the needs of the user (e.g., patients, clinicians) are clearly documented and serve as primary design drivers.
- [ ] Performance, safety, and regulatory requirements defined: All functional, performance, safety (e.g., electrical, biocompatibility), and applicable regulatory requirements (e.g., IEC 60601-1, specific FDA guidance) are documented and specified.
- [ ] Incomplete/ambiguous requirements resolved before design proceeds: Any vague, conflicting, or incomplete design input requirements are identified and resolved with relevant stakeholders before being approved and used as the basis for design.
- [ ] Design inputs reviewed and approved by designated individual: All design input requirements are formally reviewed and approved by an authorized individual(s), ensuring they are adequate and appropriate.
Design Output (§820.30(d))
Design outputs are the results of the design efforts at each stage of the design process, leading to the device specifications.
- [ ] Outputs defined in terms that allow adequate evaluation: Design outputs are expressed in terms that allow for objective verification against design inputs, such as specifications, drawings, and manufacturing procedures.
- [ ] Essential device functions identified: Those design outputs that are essential for the proper functioning and safety of the device are clearly identified.
- [ ] Outputs reviewed, approved, and released per documented procedure: All design outputs are formally reviewed, approved, and controlled before release to ensure they are complete and accurate.
- [ ] Acceptance criteria established: Acceptance criteria are established for all design outputs, which will be used during design verification and validation activities.
Design Review (§820.30(e))
Design reviews are formal, documented meetings that evaluate the design at various stages to identify problems and ensure design outputs meet inputs.
- [ ] Formal design reviews conducted at planned stages: Design reviews are conducted at appropriate stages of the design and development process, as outlined in the design plan.
- [ ] Attendees include independent reviewer not responsible for design stage: Each design review includes representatives of all functions concerned with the design stage being reviewed and an individual(s) who does not have direct responsibility for the design stage being reviewed (i.e., an independent reviewer).
- [ ] Results recorded including date, individuals, and design reviewed: The results of the design review, including identified deficiencies, required actions, and attendees, are documented in a formal record.
- [ ] Action items assigned and tracked: Any identified deficiencies or action items from the review are assigned to specific individuals and tracked to closure.
Design Verification (§820.30(f))
Design verification confirms that the design output meets the design input requirements. It answers the question: "Did we design the device right?"
- [ ] Verification methods defined in plan: The methods and acceptance criteria for design verification are established and documented in the design plan or a separate verification plan.
- [ ] Test protocols and acceptance criteria documented before testing: Protocols for all verification activities (e.g., testing, inspection, analysis) are documented and approved before execution, along with clear acceptance criteria.
- [ ] Verification results reviewed and approved: The results of all verification activities are thoroughly reviewed, documented, and approved by designated individuals.
- [ ] Verification records link specific outputs to inputs tested: Records clearly demonstrate how each design output was verified against its corresponding design input, providing objective evidence of compliance.
Design Validation (§820.30(g))
Design validation confirms that the finished device meets user needs and its intended use when used under actual or simulated use conditions. It answers the question: "Did we design the right device?"
- [ ] Validation performed on initial production units or equivalents: Design validation is performed on units produced using specified production methods, ensuring the validation reflects the actual manufactured product.
- [ ] Software validation included where applicable: If the device includes software (including SaMD), software validation is performed according to established procedures and relevant FDA guidance (e.g., General Principles of Software Validation, cybersecurity guidance). This is distinct from 21 CFR Part 11, which applies to electronic records/signatures.
- [ ] Clinical evaluation or usability testing records available: Where appropriate, design validation includes clinical evaluations, usability studies, or other methods to demonstrate the device meets user needs in real-world or simulated environments.
- [ ] Validation includes testing under extreme conditions where relevant: Validation activities consider potential use errors and misuse, and, where relevant, include testing under extreme but foreseeable conditions.
- [ ] Validation results reviewed and approved: All validation results are documented, reviewed, and approved, confirming the device meets its intended use and user needs.
Design Transfer (§820.30(h)) and Design Changes (§820.30(i))
Design transfer ensures that the device design is correctly translated into production specifications. Design changes ensure any modifications are controlled and documented.
- [ ] Transfer procedure documented and followed: A documented procedure for design transfer ensures that the device design is accurately translated into production specifications and manufacturing processes.
- [ ] Design changes captured in design history file (DHF): All design changes, regardless of their magnitude, are documented, reviewed, verified, validated (where appropriate), and approved.
- [ ] Impact assessment performed for each change: Before implementing a change, an assessment of its impact on the device, its components, manufacturing processes, and regulatory requirements is performed.
- [ ] Changes approved before implementation: No design change is implemented until it has undergone the required reviews, approvals, and any necessary re-verification or re-validation.
Design History File (DHF) (§820.30(j))
The DHF is the compilation of records that describes the design history of a finished device. It serves as objective evidence that the design was developed in accordance with the approved design plan and the requirements of Part 820.
- [ ] DHF index maintained and current: A comprehensive index or table of contents for the DHF is maintained, ensuring all relevant documents are accounted for and easily locatable.
- [ ] All design control records traceable and retrievable: The DHF contains or references all records necessary to demonstrate that the design was developed in accordance with the design plan and the QSR. This includes all design inputs, outputs, reviews, verification, validation, and transfer activities.
- [ ] DHF reviewed during internal audits and management review: The completeness and accuracy of the DHF are regularly assessed as part of internal audits and management review processes.
- [ ] DHF demonstrates compliance with §820.30: The DHF as a whole provides clear, objective evidence that all design control requirements of 21 CFR Part 820.30 have been met.
For a deeper dive into ensuring your design documentation is impeccable, download our Design History File audit checklist.
FDA 21 CFR Part 820.100 CAPA Requirements Compliance Checklist
Corrective and Preventive Actions (CAPA) is arguably the most critical system within a medical device manufacturer’s QMS, often referred to as the "connective tissue" that links various quality processes. It's consistently the second most-cited deficiency area in FDA observations because an ineffective CAPA system indicates a fundamental breakdown in a company's ability to identify, address, and prevent recurrence of quality issues.
It's vital to distinguish between corrective action (eliminating the cause of an existing nonconformity) and preventive action (eliminating the cause of a potential nonconformity). Both are crucial for continuous improvement and maintaining device safety and effectiveness.
Here’s a walk-through of the six required CAPA procedures under §820.100(a):
Data Analysis and Problem Identification (§820.100(a)(1))
An effective CAPA system begins with the robust collection and analysis of quality data from various sources to identify existing and potential nonconformities.
- [ ] Sources of quality data defined and regularly analyzed: Procedures identify internal (e.g., in-process nonconformances, audit findings, trend analysis of production data) and external (e.g., customer complaints, MDRs, service reports, returned product analysis, post-market surveillance) sources of quality data.
- [ ] Statistical methods used where appropriate: Appropriate statistical methodologies are employed to detect recurring quality problems and trends, especially for high-volume data.
- [ ] Trends identified and escalated per procedure: Procedures define how adverse quality trends are identified, evaluated, and escalated to initiate a CAPA investigation, even if individual events do not trigger one.
- [ ] Nonconforming products handled per procedure: Identified nonconforming products are controlled and segregated according to established procedures, and their disposition feeds into the CAPA system if root cause investigation is required.
Root Cause Investigation (§820.100(a)(2)-(3))
Once a problem is identified, a thorough investigation is paramount to determine its true root cause, not just its symptoms. This often includes examining the scope and extent of the problem.
- [ ] Root cause investigation initiated within defined timeframe: Procedures establish criteria and timelines for initiating a root cause investigation once a nonconformity or potential nonconformity is identified.
- [ ] Investigation methodology documented: The chosen investigation methodology (e.g., 5-Why analysis, Fishbone/Ishikawa diagrams, Fault Tree Analysis, Failure Mode and Effects Analysis (FMEA)) is documented and followed.
- [ ] Root cause conclusion supported by objective evidence (not assumption): The investigation provides objective evidence to support the identified root cause(s), moving beyond superficial symptoms to underlying systemic issues.
- [ ] Extent of problem (scope/impact) determined: The investigation includes an assessment of the scope, impact, and potential for recurrence of the nonconformity, including similar products or processes.
Action Plan Development and Implementation (§820.100(a)(4)-(5))
Developing and implementing actions that genuinely address the identified root cause(s) is crucial to preventing recurrence.
- [ ] Corrective/preventive actions address root cause (not just symptom): The action plan specifies actions (e.g., process changes, design modifications, equipment adjustments, training) designed to eliminate the identified root cause(s) and prevent recurrence or occurrence.
- [ ] Actions assigned to responsible owner with due date: Each action item within the plan is assigned to a specific individual or department with clear responsibilities and target completion dates.
- [ ] Changes to procedures, specifications, or training documented: Any changes resulting from the CAPA (e.g., revised work instructions, updated specifications, new training modules) are formally documented and controlled.
- [ ] Affected regulatory submissions assessed for changes requiring FDA notification: An assessment is performed to determine if any CAPA-driven changes require notification or submission to regulatory authorities (e.g., PMA supplements, 510(k) updates) as per 21 CFR Part 806 or other guidance.
Verification of Effectiveness (§820.100(a)(6))
This is arguably the most critical and most commonly missed step in FDA observations. Without verifying effectiveness, a CAPA is incomplete and risks recurrence of the problem.
- [ ] Effectiveness criteria defined before CAPA closure: Specific, measurable effectiveness criteria are established and documented before the CAPA actions are implemented. These criteria define what success looks like.
- [ ] Effectiveness check performed after implementation (with defined time horizon): A planned effectiveness check is performed after the CAPA actions have been implemented, over a sufficient period to demonstrate sustained improvement.
- [ ] CAPA not closed until effectiveness is confirmed with objective evidence: The CAPA record remains open until objective evidence demonstrates that the implemented actions have effectively eliminated the root cause and prevented recurrence or occurrence.
- [ ] Ineffective CAPAs escalated and re-investigated: If the effectiveness check reveals that the CAPA was not effective, the issue is re-escalated, and a new investigation (or a continuation of the previous one) is initiated.
CAPA Record and Management Review Integration
A robust CAPA system is not a standalone process but an integral part of the broader QMS, feeding into continuous improvement and management oversight.
- [ ] All CAPA activities are documented: A comprehensive record of all CAPA activities, from initial problem identification to effectiveness verification, is maintained and easily retrievable.
- [ ] CAPA status is regularly reviewed by management: Information regarding CAPA status, trends, and effectiveness is regularly presented to and reviewed by management with executive responsibility, as part of the management review process.
- [ ] CAPA data informs other QMS processes: Learnings from CAPA investigations (e.g., new risks identified, process improvements) are fed back into other QMS processes such as risk management, design controls, training, and internal auditing.
- [ ] CAPA procedures are periodically reviewed and updated: The CAPA procedure itself is periodically reviewed and updated to ensure its continued effectiveness and alignment with regulatory requirements and best practices.
To streamline your CAPA process and ensure robust compliance, leverage our dedicated FDA 21 CFR 820.100 Corrective & Preventive Action CAPA Audit checklist.
Frequently Asked Questions (FAQs)
Q1: What is the primary difference between the legacy 21 CFR Part 820 and the new QMSR?
A1: The primary difference is the structure and explicit integration of ISO 13485:2016. While the core objectives remain the same, the QMSR adopts the internationally recognized process-based approach of ISO 13485, explicitly requiring risk management throughout the QMS and providing greater alignment with global regulatory standards. It’s less prescriptive on how you implement certain requirements and more focused on what needs to be achieved through a risk-based QMS.
Q2: How does the QMSR transition impact small medical device manufacturers?
A2: The QMSR transition impacts all medical device manufacturers regardless of size. While larger companies may have more resources for QMS updates, smaller manufacturers should also proactively conduct a gap analysis. The shift towards ISO 13485 may streamline compliance for companies already operating internationally, but for those solely focused on the U.S. market, it requires a significant update to their QMS documentation and processes. The FDA aims for increased clarity and flexibility, which could ultimately benefit smaller entities by encouraging a more efficient, risk-based approach rather than strict adherence to outdated prescriptive requirements.
Q3: What is the most critical aspect of Design Controls (§820.30)?
A3: While all elements of Design Controls are crucial, the most critical aspect is arguably ensuring robust Design Inputs that accurately capture user needs, intended use, and regulatory requirements, and then verifying that Design Outputs meet these inputs, followed by Design Validation to ensure the