A medical device quality management system is the written way you design, make, watch, and fix a device: ISO 13485, 21 CFR 820, and — from February 2026 — the FDA’s QMSR that pulls 13485 into U.S. law. It is the architecture. It is not a 510(k), and it is not a PYCAD product.
If you meant ISO 14971 → medical device risk management. If you meant PMS → medical device post-market surveillance. If you meant process validation → medical device validation process. If you meant design V&V → medical device verification and validation. If you meant FDA 510(k) / PMA → FDA medical device approval process. If you meant software validation → medical device software validation.
If the device is imaging software, PYCAD is the imaging stack (viewer / model), not the regulatory agent / QMS vendor / GTM shop.
The frameworks
| Framework | Who | What it actually asks |
|---|---|---|
| ISO 13485:2016 | International | A process QMS. Risk in every process. Design controls, purchasing, production, CAPA, records |
| 21 CFR 820 / QMSR | FDA | U.S. quality rule. QMSR (2 Feb 2026) incorporates 13485, plus FDA-specific pieces (e.g. reporting, labelling) |
| EU MDR | Europe | Lifecycle: clinical evidence, PMS / PSUR, UDI / EUDAMED. The QMS has to carry that weight |
QMSR is the reason a dual-market company can stop keeping two slightly different quality manuals. It is not a reason to ignore FDA-only duties (MDRs, certain labelling, inspections). The approval path that sits on top of this system is FDA medical device approval process.
Pillars
Design controls. You cannot inspect quality in at the end. Inputs (user needs) → outputs (specs) → review → verification → validation → transfer. The V&V how-to is design V&V. The records live here.
Risk. Parallel track, not a chapter you paste in at submission. Hazard → estimate → control → residual. Method: ISO 14971.
Document and record control. One current procedure. Versioned. Approved. The file an auditor asks for is this week’s, not a shared drive of drafts.
Suppliers. Vet, write a quality agreement, watch them. A device is the weakest purchased part.
CAPA. Corrective: the fire. Preventive: the wiring. Root cause, action, check it held. A CAPA that only closes the ticket is theatre.
Complaints and PMS. Field data in; design or process change out. The PMS how-to is post-market surveillance. Process validation of the line is IQ / OQ / PQ.
A lean roadmap
1. Policy and scope. What you make, where, which sites. A quality policy that a floor lead can repeat without a poster.
2. Process map and SOPs. Only the processes you actually run. Design, purchasing, production, CAPA, complaints, document control. Do not write a 13485-shaped novel for a five-person team.
3. Records that match the SOPs. If the SOP says a design review has a checklist, the last review has that checklist. Auditors read the gap, not the prose.
4. Internal audit, management review, then the registrar or FDA. Fix what you find. Software in the device does not get a separate fantasy QMS — software validation sits on 700 and still lives under this one system.
FAQ
Is ISO 13485 certification required in the U.S.?
Not as a certificate on the wall. FDA will inspect you against QSR today and QMSR after 2 February 2026, which is 13485 plus FDA extras. A 13485 certificate helps Europe and a lot of other markets. It is not a 510(k).
Do we need eQMS software?
You need control, not a brand. A small team can run procedures and records on a locked, versioned system. Buy software when the volume of change and audit trail makes paper or a shared drive a risk, not because a vendor said “QMS platform.”
If the device is imaging software, PYCAD is the imaging stack (viewer / model), not the QMS vendor. Case studies.