Major Revisions to MDSAP 2026: Full End-to-End System Upgrade
Views:100
Time:2026-08-10 13:45:34

On August 3, 2026, MDSAP officially issued MDSAP AU P0002.011 MDSAP Audit Approach, a major revision released only half a year after the previous version. This update goes far beyond minor textual and formatting tweaks; it delivers structural overhauls covering the full scope of the quality management system (QMS), including administrative controls, design and development, production and service provision, purchasing controls, cybersecurity, plus jurisdiction-specific regulatory requirements from the FDA, TGA, ANVISA and other authorities. For medical device manufacturers relying on MDSAP certificates to maintain market access across multiple global territories, this document directly defines audit priorities and compliance red lines for the next audit cycle.




https://www.mdsap.global/sites/default/files/2026-07/MDSAP%20AU%20P0002.011%20MDSAP%20Audit%20Approach.pdf

一、Overhaul of Top-Level Management System



The revision redefines responsibilities and shifts core focus for key management processes, with a core philosophy of embedding risk-based thinking, full product lifecycle oversight and personnel competency requirements at the initial QMS planning stage.


(一)Process Risk Control Mandates Moved Forward to System Planning Stage
Requirements mandating risk-based approaches for QMS process controls, previously located under Management Task 7, have been formally relocated to Management Task 1. Under this adjustment, auditors will no longer solely review post-hoc risk control activities implemented by manufacturers. Instead, they will prioritize verifying whether process risk principles are built into QMS design during top-level planning, including upfront identification of process risks and allocation of corresponding control resources.
(二)Official Clarification of TGA UDI Responsibility Boundaries
Within Management Task 5, MDSAP has formally clarified the statutory UDI compliance responsibilities split between medical device Manufacturers and Australian Sponsors under Australian TGA regulations:
  • Australian Sponsors, who hold market entry approvals, bear primary accountability for UDI declaration and data maintenance related to ARTG registration.
  • Manufacturers must ensure UDI implementation aligns with requirements at production and labeling stages, and notify certification bodies of major system or product changes.This clear division resolves widespread ambiguity over accountability previously faced by manufacturers exporting to Australia.

(三)Audit Focus Shift from Training Records to Personnel Competency Evidence
Management Task 6 introduces a critical pivot in audit evaluation: audit teams will no longer center reviews on training sign-in sheets or hour logs. Instead, verification will focus entirely on the assessment and confirmation of role-specific staff competence, fully aligning with core ISO 13485 human resource requirements. Moving forward, manufacturers who only submit training records without supporting proof of staff practical proficiency will receive nonconformities.

(四)Strengthened Senior Management Oversight of Full Lifecycle Risk Management
Management Task 7 is redefined to formalize senior management’s oversight of risk management across the complete product lifecycle. Top management is required to deeply engage in end-to-end risk controls spanning R&D, manufacturing and post-market surveillance, rather than merely providing perfunctory signature approvals.
二、Upgraded Cybersecurity and Software Compliance Rules



Amid the rising prevalence of software-enabled and connected medical devices, Release 011 systematically embeds cybersecurity mandates into every stage of the MDSAP audit workflow, covering design inputs, verification and validation, through to post-market surveillance.
New Specialized Cybersecurity Audit Scope Added to Post-Market Surveillance:Within Measurement, Analysis & Improvement (MA&I) Task 12, dedicated audit criteria for medical device cybersecurity and post-market feedback assessment have been introduced. Manufacturers must demonstrate established processes to proactively collect cybersecurity vulnerabilities, security incident data and threat intelligence released by regulators, and integrate this data into internal data analysis and corrective improvement workflows.
FDA Cybersecurity Mandates Made Mandatory Design Inputs in Design & Development:Design & Development Task 12 adds audit checks for FDA cybersecurity validation, alongside formalized cross-process audit linkage with measurement, analysis and improvement activities. Auditors will trace whether cybersecurity vulnerabilities and threat intelligence collected post-market are fed back into design changes, risk management and continuous improvement to form a closed-loop system.
PCCP Change Mechanism Unrestricted – No Longer Limited to AI/ML Devices:Medical Device Marketing Authorization & Facility Registration Task 3 revises rules for the Predetermined Change Control Plan (PCCP), removing the prior restriction that limited PCCP usage solely to artificial intelligence-enabled devices. This means the FDA’s flexible PCCP change pathway is now available via MDSAP audits for conventional medical device change management, allowing manufacturers to streamline filing procedures for many routine product modifications.
Software Installation Activities Included in Production Audit Scope:Production and Service Controls Task 26 adds dedicated audit clauses for installation activities of software-based medical devices, covering verification and validation of software installation on target hardware and within intended clinical environments, closing compliance gaps for software devices at the manufacturing stage.
Audit Linkage Established Between Cybersecurity Verification and MA&I ProcessesDesign & Development Task 12 adds audit checks for FDA cybersecurity validation, alongside formalized cross-process audit linkage with measurement, analysis and improvement activities. Auditors will trace whether cybersecurity vulnerabilities and threat intelligence collected post-market are fed back into design changes, risk management and continuous improvement to form a closed-loop system.
三、Deepened UDI Regulatory Oversight



Release 011 embeds UDI compliance requirements across design, production, purchasing and management modules, with clearer audit pathways and earlier inspection checkpoints, forming a full-lifecycle UDI audit framework.
(一)FDA UDI Change Triggers Integrated into R&D Stage Reviews
Design & Development Task 13 adds new audit criteria covering FDA UDI change triggers: any modification to a device or its packaging that creates a new version or model mandates reallocation of a UDI-DI in accordance with 21 CFR 830.50. Design change reviews will now include direct verification of UDI-DI reassignment obligations, removing UDI compliance as an isolated task solely for production and labeling teams.
(二) TGA UDI Mandates Fully Integrated into Production and Technical File Audits
  • Production Task 1 incorporates Australia-specific TGA UDI compliance requirements, verifying manufacturers’ selection of issuing agencies, UDI assignment and proper label implementation. All FDA UDI conformity assessments are consolidated within jurisdiction-specific audit sections for streamlined review logic.
  • Production Task 16 embeds TGA UDI rules into technical file audits: manufacturers shipping products to Australia must retain complete supporting evidence of UDI implementation within technical documentation.

(三)Cross-Linkage Between Purchasing and Management Processes for UDI Accountability
Purchasing Controls Task 5 adds formal guidance requiring auditors to cross-reference Management Task 5 records to verify that written agreements clearly define UDI responsibilities between manufacturers and Australian Sponsors, and that Sponsors are incorporated into the supplier control system.
四、Minor Jurisdiction-Specific Regulatory Adjustments



This revision updates region-specific regulatory provisions, including both process simplifications and incorporation of newly enacted regulatory standards.
(一) FDA Reforms
  • Removal of Mandatory Independent Reviewer Rule for Design ReviewsDesign & Development Task 14 deletes the former FDA requirement mandating one independent reviewer with no direct design responsibility participate in every design review. Manufacturers may now tailor design review mechanisms based on organizational scale and product risk class, boosting flexibility and shortening review timelines.
  • Official Definition of Life-Support and Life-Sustaining Devices IntegratedProduction Task 18 adopts the official FDA definition of life-support and life-sustaining devices outlined in 21 CFR 860.3, establishing clear judgment criteria for traceability audits.

(二)Brazil ANVISA: RDC 848/2024 Incorporated into Audit Standards
Brazil-specific requirements under Design & Development Task 7 now include compliance with Clause 1 of ANVISA RDC 848/2024. Manufacturers exporting to Brazil must update their design control processes to align with this latest regulation.

(三)Precise Terminology Refinement in Annexes: Sterilization Supplier Wording Revised
Annex 2 revises the general term “key suppliers” to specifically “sterilization and laboratory service suppliers”. This update clarifies audit grading rules and nonconformity judgment criteria for these high-risk suppliers, eliminating interpretive ambiguity.
五、Compliance Upgrade Action Roadmap for Medical Device Manufacturers



In response to sweeping adjustments in Release 011, quality and regulatory teams are advised to launch system gap assessments and internal audit self-inspections across four core workstreams immediately:
(一) Upgrade Human Resource Procedures and Establish Formal Competency Assessment Frameworks
Shift internal audit focus from training completion rates to proof of staff competence. Revise your Human Resources & Training Control Procedure to build a multi-dimensional competency evaluation system including theoretical examinations, on-site practical observations and mentorship assessments, and retain full formal records of competency confirmation.

(二)Build a Closed-Loop Full Lifecycle Cybersecurity Management System
  • R&D Phase: Formalize cybersecurity defense standards and vulnerability mitigation controls within design input checklists; complete supporting cybersecurity risk assessments and threat modeling documentation.
  • Post-Market Phase: Revise post-market feedback SOPs to include regular monitoring of cybersecurity vulnerabilities and regulatory safety alerts.
  • Cross-Process Linkage: Document formal workflows to escalate cybersecurity incidents into risk management, design change and corrective/preventive action (CAPA) processes to achieve closed-loop control.

(三)Establish Dual-Track FDA & TGA UDI Compliance Frameworks
  • Revise your Design Change Control Procedure to mandate a mandatory UDI-DI reassignment review item for every design modification, complying with 21 CFR 830.50.
  • Revise written agreements with Australian Sponsors to clearly split responsibilities for UDI declaration, data maintenance and change notifications; include Sponsors within your supplier management program.

(四)Optimize Design Control Workflows to Improve Compliance Efficiency
Leverage the FDA’s removal of the mandatory independent design reviewer rule to update design review protocols within your Design & Development Control Procedure, streamlining review cycles while maintaining robust risk management controls. Simultaneously map cross-trigger linkages between design changes, UDI updates and cross-border registration modifications to avoid compliance gaps.
    六、Conclusion



    The release of MDSAP Release 011 signals a sustained shift in global medical device audit priorities toward upfront risk mitigation, competency-based evaluation and full product lifecycle governance. All manufacturers are recommended to integrate the new revision requirements into internal audit schedules, complete QMS document revisions and conduct company-wide staff training to ensure seamless transition during upcoming surveillance audits. For further professional consultation, contact Wiselink!

    Contact Us
    Fill Form
    Whether you need more information or wish to cooperate with us, we will guide you through every step of the regulatory process. Subscribe to our newsletter for the latest global regulatory updates.