FDA update
FDA update
7/27/20264 min read


FDA Medical Device Update 2026: What EU Manufacturers Should Know
QMSR, cybersecurity, human factors, clinical decision support and software assurance
For many European medical device and IVD manufacturers, the United States may not be the primary market. FDA requirements may nevertheless become relevant when entering the US market, supporting an American partner or developing products and quality processes for several regulatory regions.
FDA publications may also provide useful supporting state-of-the-art references for EU MDR and IVDR documentation, particularly where they describe current technical or regulatory expectations in detail. They do not, however, replace EU legislation, standards, Common Specifications or MDCG guidance.
Please note that FDA Class I is not equivalent to MDR Class I, and IVDR Class A does not directly translate into an FDA classification or exemption.
1. QMSR is now in force
The Quality Management System Regulation, QMSR, became effective on 2 February 2026. It incorporates ISO 13485:2016 and terminology from ISO 9000:2015 into 21 CFR Part 820.
This brings the FDA quality-system framework closer to the system already used by most European manufacturers. However, ISO 13485 certification alone does not demonstrate full FDA compliance. FDA-specific statutory, reporting, recordkeeping and inspection requirements remain applicable.
QMSR does not formally incorporate ISO 14971:2019, Medical devices, Application of risk management to medical devices, but FDA recognises it as a consensus standard. An established ISO 14971 process therefore provides a strong basis for risk management, provided that it is properly integrated into design, production, supplier control, CAPA, complaints and post-market activities.
What about MDSAP?
FDA accepts audit reports from an MDSAP-recognised Auditing Organization as a substitute for routine FDA quality-system inspections, provided that the applicable US requirements are included in the audit scope.
FDA receives the MDSAP audit reports through the programme. A satisfactory MDSAP audit can therefore significantly reduce the likelihood of a separate routine FDA inspection.
MDSAP does not remove FDA’s inspection authority. FDA may still perform for-cause, compliance follow-up, PMA-related or other special inspections.
What should an EU manufacturer do?
Perform a documented QMSR gap assessment.
Confirm that ISO 14971-based risk management is integrated throughout the QMS.
Check that current MDSAP scope includes the applicable US requirements.
Prepare relevant quality records for possible FDA review.
Source:
Quality Management System Regulation – FDA
Medical Device Single Audit Program – FDA
2. Updated cybersecurity guidance
FDA issued the final guidance:
Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions
The guidance covers cybersecurity design, risk management, testing, labelling, vulnerability management, software updates, third-party components and Software Bills of Materials. It also addresses the statutory requirements for products meeting the definition of a cyber device under section 524B of the FD&C Act.
The guidance is not limited to internet-connected devices. It may apply to devices containing software, firmware or programmable logic, including some products exempt from 510(k).
For European manufacturers, IEC 81001-5-1, Security, Activities in the product life cycle, provides a useful foundation, but FDA-specific submission and statutory requirements must still be assessed.
What should manufacturers do?
Confirm the product’s cybersecurity and cyber-device status, and verify that cybersecurity is integrated into development, risk management, architecture, verification, component management and post-market maintenance.
Source:
Cybersecurity in Medical Devices – FDA
3. Human factors and IEC 62366-1
FDA published the updated final guidance:
Applying Human Factors and Usability Engineering to Medical Devices
FDA recognises IEC 62366-1, Medical devices, Application of usability engineering to medical devices. An IEC 62366-1-compliant usability engineering file therefore provides a strong foundation for a US submission.
However, it may not automatically cover every FDA expectation. FDA provides more detailed recommendations concerning:
identification and validation of critical tasks
representative US user populations and use environments
participant numbers
realistic training and training decay
use errors, close calls and repeated attempts
qualitative root-cause analysis
human factors information included in the marketing submission
FDA generally recommends at least 15 participants from each distinct user population in human factors validation unless another approach is justified.
What should an EU manufacturer do?
Perform an FDA gap assessment rather than rebuilding the IEC 62366-1 file. Confirm that critical tasks, participants, environments, training, validation methods and submission content meet FDA expectations.
Source:
Applying Human Factors and Usability Engineering to Medical Devices
Content of Human Factors Information in Medical Device Marketing Submissions
4. Clinical Decision Support Software
The updated final guidance Clinical Decision Support Software explains when a CDS function may fall outside the medical-device definition and when it remains an FDA-regulated device software function.
To qualify as Non-Device CDS, all applicable statutory criteria must be met. In particular, a healthcare professional must be able to independently review the basis for the recommendation and must not rely primarily on the software output.
Opaque, highly automated or time-critical recommendations require particular caution. An EU software qualification or classification assessment does not automatically determine the US regulatory status.
Source:
Clinical Decision Support Software – FDA
5. Computer Software Assurance
FDA’s final guidance: Computer Software Assurance for Production and Quality Management System Software concerns software used in production or the quality system, such as eQMS applications, spreadsheets, CAPA systems, production software and automated test systems. It does not primarily concern software embedded in the medical device itself.
Computer Software Assurance, CSA, means selecting assurance and testing activities according to the consequences of a software failure.
This does not mean abandoning scripted testing. It means that every feature does not need the same test method or amount of documentation:
High-process-risk functions may require detailed scripted or automated testing.
Lower-risk functions may be adequately assessed through supplier evidence, scenario testing, exploratory testing, user acceptance testing or monitoring.
The manufacturer must define the intended use, identify foreseeable failures, assess their impact, select suitable assurance activities and retain objective evidence that the software is fit for use.
Source:
Computer Software Assurance for Production and Quality Management System Software
What should EU manufacturers prioritise?
A European manufacturer entering or operating in the US market should:
Complete a QMSR gap assessment and review its MDSAP scope.
Assess cybersecurity and section 524B applicability.
Compare the IEC 62366-1 usability file with FDA human factors expectations.
Reassess the US status of clinical decision support functions.
Apply the CSA risk-based approach to production and QMS software.
International standards, MDSAP and EU documentation provide a valuable starting point. None of them removes the need for a US-specific regulatory assessment.
Need help assessing how the latest FDA requirements affect your quality system, software or medical device documentation?
Quality and Regulatory Consulting
Expert services in medical device regulation and quality compliance.
contact information
Karkinen Consulting Oy, Helsinki, Finland
Business ID: 3103786-9
info@karkinen.com
© 2026. All rights reserved.


