The QMSR took effect on February 2, 2026, two years to the day after FDA published the final rule. Part 820 now incorporates ISO 13485:2016 by reference, plus Clause 3 of ISO 9000:2015 for definitions. A technical amendments rule published December 4, 2025 under Docket FDA-2025-N-4635 made 179 editorial conforming changes across 18 CFR parts, repointing references from sections such as 820.30 and 820.198 to their QMSR equivalents.

There is no transition period. FDA said it would begin enforcing the QMSR on the effective date. On January 30 the agency released compliance program 7382.850, Inspection of Medical Device Manufacturers, which retired QSIT along with programs 7382.845 and 7383.001. Instead of QSIT's four subsystems, investigators now work through six quality management system areas and four other applicable FDA requirements under a risk-based strategy, with Model 1 covering most inspections and Model 2 for baseline surveillance and PMA preapproval work.

The record change is the one that surprises people. The exemptions at old 820.180(c) did not survive, so management review minutes, internal audit reports and supplier audit reports are now fair game. FDA's Karen Masley-Joseph put it plainly at a February 5 implementation webinar: "we can look at records that were prior to February 2." Cybersecurity for software-enabled devices is also named as an inspection priority.

None of this requires ISO 13485 certification. FDA will not ask for a certificate and will not issue one, and holding one does not buy an exemption from inspection. What it does require is that procedures use the regulation's language and that the risk management file be real, since the new program treats risk management failures with heightened severity. A startup that mapped its QSR procedures to ISO clauses in 2025 is fine. One still citing design history file and device master record language in its SOPs will spend the first hour of its next inspection explaining the gap.