At CLEIO, we have spent two decades developing regulated products, and we have watched this play out enough times to say it plainly: you have to design compliance in from the start.
What is Medical Device Compliance?
Medical Device Compliance Is an Ongoing State
Medical device compliance means you can demonstrate, at any moment across the entire product lifecycle, that your device is safe, effective, and meets the regulatory requirements of the markets you sell into. At its core, it comes down to patient safety. It is an ongoing state you have to maintain, and staying compliant means maintaining that proof continuously.
Device Risk Class Determines Your Compliance Requirements
Your class determines your regulatory pathway, the evidence regulators require, and frankly how much of your budget compliance will consume. A Class I device may only need to comply with general controls, whereas a Class III device requires full premarket approval supported by clinical data. Knowing your class early changes everything about how you plan.
Which Medical Device Regulations Apply to You?
United States: FDA Compliance and the New QMSR
One thing worth flagging, because a lot of older content online still gets it wrong: the FDA no longer runs on the old Quality System Regulation. As of February 2026, the Quality Management System Regulation (QMSR) is in force. It rewrites 21 CFR Part 820 to align directly with ISO 13485. In practice, that is good news, because it means the American and international quality systems now speak nearly the same language.
Canada: Health Canada Licensing and MDSAP
The Medical Device Single Audit Program (MDSAP) provides a single audit that helps manufacturers satisfy several regulators at once. Build your quality system to ISO 13485, and you have already done most of the heavy lifting for Health Canada.
European Union: EU MDR and IVDR Compliance
Fair warning: the MDR asks for a lot of clinical evidence, and the review timelines run longer than most teams hope. Build them into your plan early, so they do not catch you off guard.
ISO 13485 and ISO 14971: The Standards that Cross Every Border
Two standards keep showing up no matter which market you target. ISO 13485:2016 shapes your entire quality management system for medical devices, while ISO 14971:2019 is the one that governs how you handle risk from start to finish. Master these two key standards for global market access, and you have a foundation that serves the US, the EU, and Canada at once.
Why Late Medical Device Compliance Is So Expensive
This is the heart of it. When a team treats compliance as documentation to produce at the finish line, they are quietly setting up a very expensive problem.
Here is what actually happens. Regulators want more than a device that simply works. They want proof that you designed it deliberately, that you assessed the risks, and that every requirement traces from the original intended use all the way through to testing. That proof is called design controls, and you cannot fake it after the fact.
The teams that struggle are rarely the ones that lack talent. They are the ones that treated a design requirement as paperwork instead of a controlled engineering input.
“A design control you build in real time costs you a bit of discipline. A design control you reconstruct after the fact costs you a redesign, a delayed submission, and a lot of very tense meetings. I have never seen the retroactive route come out cheaper.”
David Dupuis
Director of PMO at CLEIO
How to Build Compliance Into Product Development from Day One
Start With Design Controls and the Design and Development (D&D) File
Everything begins with the Design and Development File (formerly Design History File). From the very first definition of what the device is supposed to do, you trace each requirement forward: intended use leads to design inputs, inputs lead to outputs, outputs get verified and validated.
And yes, verification and validation are two different things, which trips people up constantly. Verification asks “did we build the device right, against the specs?” Validation asks “did we build the right device, one that actually meets the user’s needs?” You need both, and you need them planned from day one.
Treat Risk Management (ISO 14971) as a Design Input
Under ISO 14971, risk management works as a live input that shapes your design decisions. When you identify a hazard early, you can design it out. When you find it late, you can only warn against it or add a safeguard on top. Tackle risk early, and the device comes out safer and less expensive to build.
Design Cybersecurity In From the Start
Software has quietly become the part of a device most likely to compromise an audit. Since the FDA’s 2025 guidance, any device that contains software, or that is software, counts as a cyber device under Section 524B. That means including a cybersecurity management plan, a Software Bill of Materials, and much more in your premarket submission.
The FDA’s February 2026 update, aligned with the QMSR, is explicit that security belongs in your design from the outset. Treat it as one more design input, right next to safety and risk.
Build Your Quality Management System Around the Product
Document control, records, procedures, and continuous improvement all work best when they map to how your team really develops. Do this well, and audit readiness stops being a fire drill.
Jean-Yves Pairet
Director of Quality Assurance at CLEIO
Common Medical Device Compliance Mistakes that Fail Audits
Writing Compliance Documentation After the Fact
Auditors spot a design history reconstructed at the end almost instantly, because the dates, the logic, and the decisions do not line up.
Build the record as you go, so it tells the true story of how the device came together.
Keeping Risk Management (ISO 14971) Disconnected From Design
Feed your ISO 14971 work back into the design, so identified hazards actually change what you build. Then feed your design back into risk management, and demonstrate that the risk control measures you implemented do manage the associated risks.
Confusing Design Verification With Validation
These get blurred constantly. Verification checks the device against its specifications, while validation checks it against real user needs. Plan and run both, and keep them clearly separate in your records.
Relying on a Generic Quality Management System
A QMS copied from a template rarely matches how your team actually develops, which leaves gaps an auditor will find. Shape the system around your real process, your products, and your development team
Overlooking Regulatory Changes
Assuming the old QSR still governs your submission when the QMSR has been in force since February 2026 is exactly the kind of blind spot that derails a filing. Keep a habit of tracking changes in every market you sell into.
Caroline Lau
Quality Assurance Coordinator at CLEIO
That is the whole point of an integrated model: the regulatory strategy and the engineering decisions are made in the same room, by people who talk to each other every day. That is how we help bring new devices to market that are safe and effective, ensuring nothing slips through the cracks before an audit.
Frequently Asked Questions about Medical Device Compliance
What is medical device compliance?
What are the medical device classes?
What is the difference between FDA compliance and ISO 13485?
How does device classification affect design and development?
What is the difference between a 510(k), a DeNovo and a PMA?
How early should compliance be considered in product development?
Is ISO 13485 mandatory for the US market?
ISO 13485 certification itself is voluntary in the US, but building your quality system to ISO 13485 is mandatory since the adoption of the QMSR. It also gives you a head start in Canada and Europe.
Our experts always got your back
With extensive cross-industry experience, we’re always ready to tackle medical device development complexities and propel your success.
Main Author
Caroline Graver
Writer & Content Specialist
Caroline is a content specialist with deep expertise in medtech and product development, translating complex technical concepts into clear, compelling narratives for healthcare and innovation audiences.
Collaborator &
Reviewer
Jean-Yves Pairet
Director of Quality
Jean-Yves leads the Quality Team, overseeing the QMS and maintaining our ISO 13485 certification.