FDA QSR (21 CFR Part 820) & Part 11 Compliance
The FDA Quality System Regulation (21 CFR Part 820) and Electronic Records rule (21 CFR Part 11) establish how medical software must be built to ensure clinical safety and efficacy. In software engineering, these rules require that every user requirement is linked to an automated test (Design Verification), changes are tracked in a Design History File (DHF), and releases are signed with tamper-proof electronic signatures.
Plain-Language Executive Summary
FDA Quality System regulations govern how medical software must be designed, tested, and validated to ensure it never harms a patient. It mandates a complete paper trail proving every clinical feature was deliberately planned (Design Inputs), verified with automated tests (Design Outputs), and signed with tamper-proof electronic signatures.
Patient Safety & Clinical Device Efficacy — Ensuring software algorithms do not misdiagnose patients, corrupt medical imagery, or fail during real-time physiological monitoring.
Who It Applies To & Penalties for Non-Compliance
Applicability & Covered Scope
Any software functioning as a medical device (diagnosing, monitoring, treating disease) or embedded in physical clinical equipment. Covers Software as a Medical Device (SaMD), clinical decision support algorithms, electronic health record (EHR) modules, and companion diagnostics.
Inspection Observations & Recalls
FDA Form 483 inspection observations, Warning Letters, import alerts, mandatory product recalls, and federal consent decrees halting commercial distribution. Inadequate software validation is one of the most frequent causes of FDA 483 inspection citations and mandatory medical device recalls.
FDA Design Controls (21 CFR § 820.30) & NUP Fulfillment
FDA design controls enforce a structured, verified progression from user needs to production code:
1. Design Controls & Design History File (DHF)
21 CFR § 820.302. Software Verification & Validation (V&V)
21 CFR § 820.30(f) & (g)3. Electronic Records & Electronic Signatures (Part 11)
21 CFR Part 114. CAPA: Corrective and Preventive Action
21 CFR § 820.100Auditable Artifacts & Design History File (DHF) Evidence
The deterministic pipeline automatically compiles and seals these auditable DHF artifacts upon release:
- Design History File (DHF) Index & Traceability Matrix (`traceability-matrix.json`)
- Software Verification Protocol & Summary Report (Vitest CI execution artifacts)
- Software Hazard Analysis & ISO 14971 Risk Management File
- 21 CFR Part 11 Electronic Signature Validation Package
Copy this prompt into your AI coding assistant to automatically generate requirement-to-test traceability matrices.
Related Quality Gate: Compliance Checklist: FDA DHF Release Gate
Validate DHF completeness and electronic signatures with Checklists.
FDA 820.30 Document Templates
Get copyable markdown boilerplates for SRS, SDD, and Master Test Plans.
Community Discussion & Feedback
Attributed peer feedback and official Netspective architecture notes.