This framework outlines key compliance requirements based on common areas of FDA regulation, including Quality System (QS) elements like management responsibility, design controls, production/process controls, and CAPA, as well as requirements for document/record control, electronic records/signatures (21 CFR Part 11), and medical device cybersecurity. It provides a structured overview of these critical areas for maintaining compliance with applicable FDA regulations.
Establishes requirements for a quality system for medical device manufacturers.
Policies and procedures are established; documented; and maintained for the overall quality system.
Management with executive responsibility establishes and maintains an adequate quality system.
Adequacy of Quality Policy and Objectives.
Effectiveness of Management Review.
The quality system is established; implemented; and maintained in accordance with FDA requirements.
Establishes requirements for controlling the design of medical devices.
Policies and procedures are established; documented; and maintained for design control activities.
Design and development planning activities are conducted and documented.
Design inputs are established; documented; and meet user needs and intended use.
Design outputs are documented; meet design input requirements; and are verified.
Planned and systematic reviews of the design are conducted and documented.
Design verification activities are conducted and documented.
Design validation activities are conducted and documented.
The design is correctly translated into production specifications.
Establishes requirements for controlling production and processes.
Policies and procedures are established; documented; and maintained for production and process controls.
Processes are controlled to ensure that a device conforms to its specifications.
Requirements for production and installation are established and maintained.
Establishes requirements for corrective and preventive actions.
Policies and procedures are established; documented; and maintained for corrective and preventive actions.
A system is established and maintained for implementing corrective and preventive actions.
Data Analysis for Identifying Nonconformities.
Investigation of Nonconformities.
Implementation and Verification of Corrective and Preventive Actions.
Establishes requirements for controlling documents and records.
Policies and procedures are established; documented; and maintained for document and record control.
Documents are controlled to ensure that necessary documents are available and obsolete documents are removed.
Records are maintained to demonstrate compliance with quality system requirements.
Establishes requirements for electronic records and electronic signatures (21 CFR Part 11).
Policies and procedures are established; documented; and maintained for electronic records and electronic signatures.
Systems that create; modify; maintain; or transmit electronic records are validated.
Audit trails are generated for systems that manage electronic records.
Requirements for electronic signatures are established and maintained.
Establishes requirements and guidance for medical device cybersecurity.
Policies and procedures are established; documented; and maintained for medical device cybersecurity.
Cybersecurity risks are identified; analyzed; evaluated; controlled; and monitored throughout the device lifecycle.
Cybersecurity requirements are verified and validated through testing.
A process is established for identifying; assessing; and mitigating postmarket cybersecurity vulnerabilities.