Let us work together to bring your vision to life with quality. Contact our team to get started.
North American Medical Device Quality Control Recommendations: Part 1
Developing a medical device is rarely a straight line from idea to finished product. A concept that looks straightforward on paper can quickly become complicated once safety, reliability, regulatory requirements, usability, manufacturing, cybersecurity, and risk management enter the picture.
One of the most effective ways to manage that complexity is to adopt a proven and structured development process from the very beginning and not when the product is almost ready for certification or production.
In North America, medical device manufacturers rely on a combination of regulatory requirements, guidance documents, and recognized or consensus standards. FDA and Health Canada do not publish medical device standards; they publish an updated online database of consensus standards (FDA) by medical specialty topic or a recognized standard (Health Canada) by medical speciality topic. They have created online downloadable digital documents, that are not always up to date.
Most medical device standards are published by organizations such as IEC/AAMI, ASTM, CSA, ISO, or UL (or ANSI/UL).
Understanding and applying the applicable medical device consensus and recognized standards, and knowledge of the specific essential requirements of the Medical Device Quality Management System (QMS) at the initial conception stage will help to create all subsequent design project/manufacturing risks that should be considered.
In other words, quality control starts well before the first prototype is built.
The following resources provide useful starting points for manufacturers and product development teams:
1. FDA sub-group CDRH (Center for Devices and Radiological Health) online Guidance documents for Industry (legal manufacturers) and FDA staff online: Search for FDA Guidance Documents | FDA
2. Health Canada publishes online guidance documents covering regulatory requirements and expectations for medical device manufacturers for industry and their staff as well: Guidance Documents
3. FDA Cybersecurity in Medical Devices: Quality System Considerations & Content of Premarket Submissions: Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions | FDA
4. Health Canada Guidance Document: Pre-Market Requirements for Medical Device Cybersecurity: Guidance Document: Pre-market Requirements for Medical Device Cybersecurity - Canada.ca
5. UL standards (one page at time, requires login & password): https://www.shopulstandards.com/Catalog.aspx
6. CSA Store (review of Standard Preface & Scope only; requires purchase for full version as .pdf file or online viewing): https://www.csagroup.org/store/
7. ISO 13485:2016, Medical Device Quality Management System
8. ISO 14971:2019, Medical Device Risk Management (reference standard in ISO 13485)
9. FDA: 21 CFR 820 (updated 2026-04-03) Quality Management System Regulation: eCFR: 21 CFR Part 820 -- Quality Management System Regulation
Medical Device design and Quality Management standards
Once the intended use, markets, and product requirements are understood, the next question is: Which standards apply to the device, or to the cloud-based and/or mobile device software application?
That question should be answered early. Waiting until the end of development to determine certification requirements can result in expensive redesigns, especially when a standard affects the product's electrical architecture, mechanical design, software, enclosure, power supply, or user interface.
Depending on the type of device, relevant standards may include:
1. IEC EN 60601-1:2005+AMD1:2012+ADM2:2020: Medical electrical equipment - Part 1: General requirements for basic safety and essential performance
2. Comprehensive list of IEC 60601-1-x collateral and IEC 60601-2-X particular standards: IEC 60601 - Wikipedia
3. IEC 80001-1:2021: Application of risk management for IT-Networks for medical devices – Part 1: Effectiveness and security in the implementation and use of connected devices or connected health software.
4. IEC 81001-1:2021: Health software and health IT systems safety, effectiveness and security – Part 1: Principles and concepts
5. IEC 81001-5-1:2021; Health software and health IT systems safety, effectiveness and security – Part 5-1: Security – Activities in the product life cycle
6. IEC EN 62304-1:2006+AMD1:2015: Lifecycle requirements for medical device software
7. IEC EN 62366-1: 2015+AMD1:2020: Application of usability engineering for medical devices
Note: Some of the following published standards are not free to download, but must be purchased in either digital file or hardcopy versions
The exact standards required will depend on the device, its intended use, where it will be sold, how it connects to other systems, and the risks associated with its use.
Summary
Introducing a new electronic medical device (Class I or Class II) to the medical professional setting or home healthcare markets involves a series of development stages as part of a detailed process which includes market research and validation, product definition, requirements generation, concept, detailed design and engineering, review, prototyping, verification & validation testing, pre-certification review and testing, final equipment certification / regulatory compliance, labelling, instructions for use before heading into full production manufacturing and distribution.
Each of these stages comes with its own planned and budgeted costs. However, risk management activities such as analysis, evaluation, control, benefit/residual risk and overall residual risk of identified hazards to operator/patient safety must be performed at every major milestone/gateway stage and recorded.
These principles provide the foundation for an effective quality control process. The next step is putting them into practice through preventative, verification, and validation activities throughout the product lifecycle. In Part 2, we look at how these requirements translate into practical quality control activities across design, verification, validation, manufacturing, and post-market support.