Skip to main content
    MedTech Cyber Tips
    The Ultimate Guide
    Updates
    FDA

    QMSR replaces 21 CFR 820 — what changes for cybersecurity

    FDA's Quality Management System Regulation harmonizes Part 820 with ISO 13485. Cyber design controls and CAPA expectations carry over with subtle scoping changes.

    The Quality Management System Regulation (QMSR) is now in effect, replacing the legacy QSR. For cybersecurity programs, the most material shifts are scoped record requirements and tighter alignment with ISO 13485 design and risk processes.

    What to update now: your design history file index, security risk management plan references, and CAPA templates that previously pointed at 21 CFR 820 sub-parts. Most controls (design inputs/outputs, V&V, supplier controls) map cleanly — only the citation language and a few records change.