• newsletter passarini

FDA 2026: The Complete Guide to New Medical Device Regulatory Requirements in the US

If you work in the medical device industry and believe your FDA clearance process is under control for 2026, it is time to raise the alarm. The recent US regulatory updates were not merely routine revisions—they have completely rewritten the rules of the game. From the mandatory enforcement of the new QMSR (which officially retired the old QSR) to the new stringent Cybersecurity requirements and the critical revision of ISO 10993-1 for biocompatibility, minor oversights in your technical documentation can result in months of delay or complete market rejection. Is your company truly prepared to meet the FDA’s new standards? Discover what has changed and what you must adjust immediately.

  1. Biocompatibility 

ISO 10993-1:2025 (6th edition): The FDA recognized the standard with partial recognition as of May 25, 2026. The biological risk assessment must be integrated into the risk management process under ISO 14971, considering chemical characterization, including extractables and leachables (E&L), when applicable.

Exception and transition period: The FDA expressly excluded the application of Clause 6.9 / Annex A, Table A.1 due to differences from the FDA’s risk management approach. Compliance with the ISO 10993-1:2018 version remains accepted during the transition period, through July 1, 2029.

ClarkeModet Acquires Passarini Group to Expand Regulatory Affairs
  1. Human Factors and Usability 

Final Guidance – May 29, 2026: The FDA published the final version of Content of Human Factors Information in Medical Device Marketing Submissions.

The document establishes categories for determining the level of human factors information to be presented in submissions, considering aspects such as critical tasks, user interface, use-related risks, and device modifications.

Implementation: Effective as of August 3, 2026.

  1. Cybersecurity

Final Guidance – February 3, 2026: The FDA published the final version of Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions, replacing the previous 2025 version.

The guidance reinforces the need to integrate cybersecurity into the quality management system and the device lifecycle.

Key elements

  • Threat modeling;
  • Cybersecurity risk management;
  • Software Bill of Materials (SBOM);
  • vulnerability identification and handling processes;
  • controls for vulnerability updates and remediation;
  • architecture and security documentation;
  • monitoring and risk management throughout the lifecycle.

eSTAR: Cybersecurity documentation continues to be incorporated into the FDA’s electronic submission processes. The eSTAR structure and specific fields should be verified according to the submission type and the current version of the form.

Enforcement: The Compliance Program 7382.850 now incorporates the QMSR-related inspection approach, including cybersecurity aspects when applicable to the device and quality system.

  1. Medical Software – SaMD / AI / ML 

AI/ML Lifecycle Management

The FDA maintains the Artificial Intelligence-Enabled Device Software Functions: Lifecycle Management and Marketing Submission Recommendations guidance as Draft Guidance, originally published in January 2025.

It presents the FDA’s regulatory expectations for lifecycle management of AI-enabled software functions. 

Predetermined Change Control Plan – PCCP

The final guidance on Predetermined Change Control Plans for Medical Devices establishes a framework allowing certain pre-specified modifications to devices, including software and AI/ML-related changes, without necessarily requiring a new submission for each change, provided the established criteria are met. 

Clinical Decision Support Software

The FDA published the final guidance on Clinical Decision Support Software (CDS) in January 2026, clarifying the regulatory boundaries applicable to clinical decision support software and the criteria used to determine when certain functions fall outside the medical device definition.

 

  1. Quality Management System – QMSR 

Effective date: February 2, 2026

The Quality Management System Regulation (QMSR) officially took effect, replacing the former Quality System Regulation (QSR) model and incorporating ISO 13485:2016 by reference, with additional FDA requirements and particularities.

Key impacts

  • alignment of the quality system with ISO 13485:2016;
  • updated expectations for procedures and records;
  • greater integration between risk management and the quality system;
  • updated FDA inspection practices.

End of QSIT

The FDA discontinued the Quality System Inspection Technique (QSIT) as an inspection methodology and adopted the approach established under Compliance Program 7382.850, aligned with the QMSR.

 

  1. Regulatory Submissions and Inspections 

eSTAR and eCopy

The FDA continues to expand the use of eSTAR for electronic submissions. Whether it is mandatory should be assessed according to the specific submission type and applicable regulatory program, and should not be generalized to all submissions.

Guidance under the eCopy Program remains applicable according to the submission type and current electronic requirements.

  1. Post-Market and Real-World Evidence 

Real-World Evidence – RWE

The FDA published the final guidance on Use of Real-World Evidence to Support Regulatory Decision-Making for Medical Devices, consolidating the use of real-world data to support certain regulatory decisions. RWE may be used, as applicable, at different stages of the device lifecycle. 

Post-market cybersecurity

Post-market cybersecurity management remains a critical element, including:

  • vulnerability monitoring;
  • threat identification and assessment;
  • vulnerability management;
  • updates and patches;
  • risk communication when applicable. 

Patient Preference Information

The FDA also reinforced the use of Patient Preference Information (PPI) as a supporting element for regulatory evaluation and patient-centered decision-making.

 

  1. Products and Specific Guidances 

The 2026 regulatory agenda includes the development and updating of specific guidances for certain categories of devices and technologies.

Topics of interest include:

  • devices intended for weight loss;
  • assessment of thermal effects on tissue;
  • digital technologies and software-driven devices;
  • devices with artificial intelligence components;
  • cybersecurity-related technologies.

Key Points of Attention for 2026

For regulatory impact assessment purposes, the topics that deserve the most attention are:

  1. QMSR: final adaptation of the quality system to the new regime in effect since February 2, 2026.
  2. ISO 10993-1:2025: adoption of the new edition and transition planning through July 1, 2029.
  3. Cybersecurity: integration of Section 524B requirements into development, submission, and post-market activities.
  4. Human Factors: application of the new final guidance from May 2026.
  5. AI/ML: monitoring the development of the Lifecycle Management guidance, keeping in mind it remains in draft.
  6. RWE/PPI: growing use of real-world evidence and patient preference information.
  7. Post-market: strengthening of continuous risk management, including cybersecurity and vulnerabilities.

References: 

  1. FDA – Recognized Consensus Standards: ISO 10993-1:2025
  2. Content of Human Factors Information in Medical Device Marketing Submissions
  3. Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions
  4. Artificial Intelligence-Enabled Device Software Functions: Lifecycle Management and Marketing Submission Recommendations
  5. Quality Management System Regulation (QMSR)
  6. eCopy Program for Medical Device Submissions
  7. Use of Real-World Evidence to Support Regulatory Decision-Making for Medical Devices

Share