Medical Device Compliance: What It Takes to Get to Market

Written By Caroline

Published on September 16, 2026

Last Edit on October 01, 2026

Here is a question we get a lot: at what point should a team start worrying about medical device compliance?
Most people assume the answer is “when approaching submission”. Plenty of companies across the medical device industry work exactly this way: build the product first, then bring in the regulatory people to document everything and get the paperwork in order. We understand the instinct. It feels efficient. It is also the single most expensive assumption you can make, and it gets riskier as your device grows more complex.

At CLEIO, we have spent two decades developing regulated products, and we have watched this play out enough times to say it plainly: you have to design compliance in from the start.

What is Medical Device Compliance?

Let’s start here, because “compliance” is one of those words everyone uses without really knowing what it implies.

Medical Device Compliance Is an Ongoing State

Medical device compliance means you can demonstrate, at any moment across the entire product lifecycle, that your device is safe, effective, and meets the regulatory requirements of the markets you sell into. At its core, it comes down to patient safety. It is an ongoing state you have to maintain, and staying compliant means maintaining that proof continuously.

That distinction matters. People often confuse compliance with approval. Approval, like an FDA clearance, is a milestone you cross once. Compliance is the thing you build and maintain, through your quality management system, your records, and your procedures, long before and after the device is on the market.

Device Risk Class Determines Your Compliance Requirements

Not every device faces the same requirements, and the reason comes down to risk. It makes sense when you think about it: a device that could seriously harm someone must clear far tougher, more specific rules than a low-risk one. That is why regulators sort devices into classes based on the harm they could cause if something goes wrong.
In the US, it breaks down into three categories. Class I covers low-risk devices, like a tongue depressor. Class II is the moderate-risk group, like an infusion pump. Class III is where the high-risk devices live, like an implantable pacemaker.

Your class determines your regulatory pathway, the evidence regulators require, and frankly how much of your budget compliance will consume. A Class I device may only need to comply with general controls, whereas a Class III device requires full premarket approval supported by clinical data. Knowing your class early changes everything about how you plan.

Which Medical Device Regulations Apply to You?

This is usually where teams start to feel lost, and we get it. The global regulatory landscape spans several rulebooks, and they overlap in ways that are easy to trip over.

United States: FDA Compliance and the New QMSR

If you are selling in the US, the FDA is your regulatory authority. Manufacturers must meet its requirements before a device ever reaches patients. Most Class II devices reach the market through a 510(k) premarket notification, while higher-risk devices go through premarket approval (PMA).

One thing worth flagging, because a lot of older content online still gets it wrong: the FDA no longer runs on the old Quality System Regulation. As of February 2026, the Quality Management System Regulation (QMSR) is in force. It rewrites 21 CFR Part 820 to align directly with ISO 13485. In practice, that is good news, because it means the American and international quality systems now speak nearly the same language.

Canada: Health Canada Licensing and MDSAP

Health Canada licenses medical devices under a four-class system, from Class I (lowest risk) to Class IV (highest). Class II and up require a Medical Device Licence, and since 2019 that application requires MDSAP certification.

The Medical Device Single Audit Program (MDSAP) provides a single audit that helps manufacturers satisfy several regulators at once. Build your quality system to ISO 13485, and you have already done most of the heavy lifting for Health Canada.

European Union: EU MDR and IVDR Compliance

Selling in Europe means complying with the EU Medical Device Regulation (MDR), or the In Vitro Diagnostic Regulation (IVDR) if your product is a diagnostic. Here, a notified body reviews your technical documentation and quality system before you can apply the CE mark, ensuring the device meets EU requirements. Several regulatory bodies may be involved, including notified bodies and national competent authorities.

Fair warning: the MDR asks for a lot of clinical evidence, and the review timelines run longer than most teams hope. Build them into your plan early, so they do not catch you off guard.

ISO 13485 and ISO 14971: The Standards that Cross Every Border

Two standards keep showing up no matter which market you target. ISO 13485:2016 shapes your entire quality management system for medical devices, while ISO 14971:2019 is the one that governs how you handle risk from start to finish. Master these two key standards for global market access, and you have a foundation that serves the US, the EU, and Canada at once.

Why Late Medical Device Compliance Is So Expensive

This is the heart of it. When a team treats compliance as documentation to produce at the finish line, they are quietly setting up a very expensive problem.

Here is what actually happens. Regulators want more than a device that simply works. They want proof that you designed it deliberately, that you assessed the risks, and that every requirement traces from the original intended use all the way through to testing. That proof is called design controls, and you cannot fake it after the fact.

So when compliance arrives late, teams face an ugly choice. They either try to reconstruct a design history that should have been built along the way, which auditors see through immediately, or they go back, redesign, and retest parts of the product to make it defensible. Both cost time, both cost money, both delay your entry to market at exactly the moment your runway is thinnest.

The teams that struggle are rarely the ones that lack talent. They are the ones that treated a design requirement as paperwork instead of a controlled engineering input.

“A design control you build in real time costs you a bit of discipline. A design control you reconstruct after the fact costs you a redesign, a delayed submission, and a lot of very tense meetings. I have never seen the retroactive route come out cheaper.”

David Dupuis
Director of PMO at CLEIO

How to Build Compliance Into Product Development from Day One

Good news: the fix comes down to sequence. These best practices bring compliance in as a design input, right alongside performance and cost, rather than as a review at the end.

Start With Design Controls and the Design and Development (D&D) File

Everything begins with the Design and Development File (formerly Design History File). From the very first definition of what the device is supposed to do, you trace each requirement forward: intended use leads to design inputs, inputs lead to outputs, outputs get verified and validated.

And yes, verification and validation are two different things, which trips people up constantly. Verification asks “did we build the device right, against the specs?” Validation asks “did we build the right device, one that actually meets the user’s needs?” You need both, and you need them planned from day one.

Treat Risk Management (ISO 14971) as a Design Input

Under ISO 14971, risk management works as a live input that shapes your design decisions. When you identify a hazard early, you can design it out. When you find it late, you can only warn against it or add a safeguard on top. Tackle risk early, and the device comes out safer and less expensive to build.

Design Cybersecurity In From the Start

Software has quietly become the part of a device most likely to compromise an audit. Since the FDA’s 2025 guidance, any device that contains software, or that is software, counts as a cyber device under Section 524B. That means including a cybersecurity management plan, a Software Bill of Materials, and much more in your premarket submission.

The FDA’s February 2026 update, aligned with the QMSR, is explicit that security belongs in your design from the outset. Treat it as one more design input, right next to safety and risk.

Build Your Quality Management System Around the Product

A quality management system should fit the product you are actually building, from early design through manufacturing, and reflect the real work rather than a generic template. It starts with a clear understanding of your own processes.

Document control, records, procedures, and continuous improvement all work best when they map to how your team really develops. Do this well, and audit readiness stops being a fire drill.

“When the quality system is built around the product from the start, an audit is a simple checkbox to fill. Everything is traceable, everything is where it should be, readily available and we are not scrambling to reconstruct anything. Audit readiness is a result of doing the work properly.”

Jean-Yves Pairet
Director of Quality Assurance at CLEIO

Common Medical Device Compliance Mistakes that Fail Audits

A handful of patterns fail submissions and audits again and again. The encouraging part is that every one of them is avoidable when compliance rides along with development instead of chasing it. Here are the ones we see most often, and what to do instead.

Writing Compliance Documentation After the Fact

Auditors spot a design history reconstructed at the end almost instantly, because the dates, the logic, and the decisions do not line up.

Build the record as you go, so it tells the true story of how the device came together.

Keeping Risk Management (ISO 14971) Disconnected From Design

A risk analysis that sits in its own document and never touches a real design decision amounts to box-ticking. It looks thorough on paper, but it never makes the device any safer.

Feed your ISO 14971 work back into the design, so identified hazards actually change what you build. Then feed your design back into risk management, and demonstrate that the risk control measures you implemented do manage the associated risks.

Confusing Design Verification With Validation

These get blurred constantly. Verification checks the device against its specifications, while validation checks it against real user needs. Plan and run both, and keep them clearly separate in your records.

Relying on a Generic Quality Management System

A QMS copied from a template rarely matches how your team actually develops, which leaves gaps an auditor will find. Shape the system around your real process, your products, and your development team

Overlooking Regulatory Changes

Assuming the old QSR still governs your submission when the QMSR has been in force since February 2026 is exactly the kind of blind spot that derails a filing. Keep a habit of tracking changes in every market you sell into.

“Most people will think about device compliance and focus on device requirements, but compliance also requires planned processes that are managed in a QMS.
The mistake many teams make is to postpone QMS activities, and when they want to submit for device approval, realise that QMS implementation cannot be executed overnight.”

Caroline Lau
Quality Assurance Coordinator at CLEIO

Our Quality Assurance Team
We will be direct about why this matters to us. CLEIO brings regulatory and engineering teams under one roof, a shared QMS, which means compliance does not get handed off and lost in the gaps between them. It travels with the product from the first sketch to the final submission.

That is the whole point of an integrated model: the regulatory strategy and the engineering decisions are made in the same room, by people who talk to each other every day. That is how we help bring new devices to market that are safe and effective, ensuring nothing slips through the cracks before an audit.

Compliance built in from the start pays off in every direction. It protects your timeline, keeps your budget under control, turns audits into calm formalities, and gets a safe, effective device to patients faster.

Frequently Asked Questions about Medical Device Compliance

It is the ongoing state of being able to demonstrate that your device is safe, effective, and meets the regulatory requirements of every market you sell into, across its entire lifecycle. It is maintained through your quality management system, not achieved once and forgotten.
Devices are classified by risk. In the US, these are Class I (low risk), Class II (moderate risk), and Class III (high risk). Your device class determines your regulatory pathway, the clinical evidence you need, and the overall compliance effort.
FDA compliance means meeting US regulatory requirements to legally market a device in the United States. ISO 13485 is an international standard for medical device quality management systems. Since the FDA’s QMSR took effect in February 2026, compliance now requires a QMS based on ISO 13485, so the two overlap far more than they used to.
Regulatory requirements and device classification have a significant impact on the intensity of the controls and records applied during design and development. A higher class means more rigorous controls and more documentation. To ensure an efficient pathway to market, align your activities with the regulatory strategy from the very beginning.
A 510(k) is a premarket notification showing your device is substantially equivalent to one already on the market, and it is the common route for Class II devices. A DeNovo is a pathway for low to moderate risk devices that have no substantially equivalent devices already on the market. A premarket approval (PMA) is a more rigorous review backed by clinical data, required for high-risk Class III devices.
From day one. Compliance works best as a design input alongside performance and cost, built into the design and development file from the first requirement. Bringing it in late forces reconstruction or redesign, which costs time and money you rarely have to spare.

ISO 13485 certification itself is voluntary in the US, but building your quality system to ISO 13485 is mandatory since the adoption of the QMSR. It also gives you a head start in Canada and Europe.

Our experts always got your back

With extensive cross-industry experience, we’re always ready to tackle medical device development complexities and propel your success.

Main Author

Caroline Graver

Writer & Content Specialist

Caroline is a content specialist with deep expertise in medtech and product development, translating complex technical concepts into clear, compelling narratives for healthcare and innovation audiences.

Collaborator &
Reviewer

Subscribe to get our insights delivered to your email inbox