MDSAP is the closest thing the medical device industry has to a single global quality audit. One audit, conducted by one Auditing Organisation, accepted by five regulators. For a manufacturer that would otherwise host five separate inspections, the arithmetic is compelling.
But MDSAP is frequently misunderstood — particularly on what it does not cover, and on how it relates to ISO 13485 and its European variant, EN ISO 13485. This guide covers both.

What MDSAP is
The Medical Device Single Audit Program allows a recognised third-party Auditing Organisation to conduct one audit of a manufacturer’s quality management system that satisfies the regulatory requirements of multiple participating authorities simultaneously.
The five full participants:
| Country | Authority | Status |
|---|---|---|
| Canada | Health Canada | Mandatory for Class II, III and IV devices |
| United States | FDA | Voluntary — substitutes for routine surveillance inspections |
| Australia | TGA | Voluntary — accepted for market inclusion |
| Brazil | ANVISA | Voluntary — accepted in place of BGMP inspection |
| Japan | MHLW / PMDA | Voluntary — reduces document submission burden |
The UK MHRA holds observer status and has signalled interest in fuller participation.
The limitation nobody should discover late
MDSAP is not accepted in the European Union. EU notified bodies conduct their own audits under MDR and IVDR. An MDSAP certificate does not shorten, replace or influence a notified body assessment.
If your markets are the EU and India, MDSAP delivers you nothing directly. If your markets include Canada, it is not optional.
Where Canada makes it compulsory
Health Canada requires a valid MDSAP certificate for a medical device licence covering Class II, III and IV devices, under section 32 of the Canadian Medical Devices Regulations. There is no alternative route. For manufacturers selling into Canada, MDSAP is a licensing precondition, not a strategic option.
ISO 13485 and EN ISO 13485: not the same document
This distinction causes real confusion, and it matters commercially.
ISO 13485:2016 is the international standard for medical device quality management systems. It is the baseline for MDSAP, and since 2 February 2026 it is incorporated by reference into the FDA’s Quality Management System Regulation, which replaced the old Quality System Regulation in 21 CFR Part 820.
EN ISO 13485:2016 is the European adoption of that standard. It contains the identical technical text plus European annexes — the Z annexes — which map the standard’s clauses against the QMS requirements of EU MDR and IVDR. The A11:2021 amendment updated those annexes.
The practical consequence: certification to EN ISO 13485:2016 with A11:2021 gives presumption of conformity for the specific requirements identified in the Z annexes only. It does not make you MDR or IVDR compliant. Clinical evaluation, post-market surveillance, PSUR, vigilance, UDI and the PRRC role all sit outside it.
If your certificate does not cite the A11:2021 amendment, that is worth raising with your certification body.
How an MDSAP audit is structured
MDSAP uses a seven-process model rather than walking the ISO 13485 clauses in order:
- Management — the entry process, and the one that sets the auditor’s impression
- Device Marketing Authorisation and Facility Registration — country-specific licensing and registration
- Measurement, Analysis and Improvement — CAPA, complaints, internal audit, data analysis
- Medical Device Adverse Events and Advisory Notices Reporting — the most country-divergent process, with five different reporting regimes
- Design and Development
- Production and Service Controls
- Purchasing — supplier controls
Certification follows a three-year cycle: an initial Stage 1 and Stage 2 audit, surveillance audits in years one and two, and recertification in year three.
Nonconformity grading is what makes MDSAP different
MDSAP does not simply classify findings as major or minor. Each nonconformity is scored using a defined system, starting from the clause involved and escalating where the finding relates to a process the programme treats as higher risk, or where there is a documented history of the same failure.
Findings at or above a defined threshold are reported directly to the participating regulatory authorities. In other words, your audit findings reach the regulators, not just your certification body.
What changed in 2026
Two developments are worth knowing:
The audit approach was revised. References to the old 21 CFR Part 820 Quality System Regulation were removed from the audit task checklists. US compliance is now evaluated through the QMSR, which incorporates ISO 13485:2016. Criteria addressing Predetermined Change Control Plans for AI and machine-learning enabled devices were also added.
Programme governance moved. Australia’s TGA now hosts MDSAP governance and the official document repository, at mdsap.global. If your team still works from bookmarked FDA-hosted MDSAP documents, they should be re-sourced.
How MDSAP and the FDA QMSR interact
The QMSR took effect on 2 February 2026, aligning US quality system requirements with ISO 13485:2016 while retaining US-specific supplemental requirements. Because MDSAP was already built on ISO 13485, the alignment works in manufacturers’ favour: a well-run MDSAP programme now maps closely onto FDA’s baseline.
It does not, however, make QMSR compliance automatic. The US-specific supplemental requirements still need to be demonstrably addressed in your system.
Is MDSAP worth it for your organisation?
Clear yes: you sell, or intend to sell, Class II or above in Canada. It is mandatory.
Usually yes: you sell into three or more of the five participating markets, or into Brazil where MDSAP acceptance avoids extended ANVISA inspection queues.
Probably not yet: your markets are the EU, India and the Middle East. MDSAP adds audit cost without removing an audit you currently face.
The honest framing is that MDSAP is a consolidation tool. It pays back where you have multiple participating markets. It is an added expense where you do not.
Preparing properly
- Gap assessment against the seven-process model, not against ISO 13485 clause order. Teams that prepare clause by clause are repeatedly caught out by the country-specific tasks.
- Country-specific requirements first. Adverse event reporting timelines differ across all five jurisdictions. This is the most common source of findings.
- Get management engagement genuine. Management is the entry process and sets the tone for everything after.
- CAPA must be demonstrably effective, with closure evidence, not just open and closed dates.
- Internal audits should mirror the MDSAP model in the cycle before your first audit.
How Medfins International supports MDSAP and ISO 13485
We support manufacturers with ISO 13485:2016 implementation and certification, EN ISO 13485:2016 with A11:2021 alignment for EU market access, MDSAP gap assessment against the seven-process model, country-specific requirement mapping across all five jurisdictions, mock audits and internal audit programme design, Auditing Organisation selection and coordination, nonconformity response and CAPA closure, and FDA QMSR readiness.
Frequently asked questions
Which countries accept MDSAP?
Five regulatory authorities participate: Health Canada, the US FDA, Australia’s TGA, Brazil’s ANVISA and Japan’s MHLW/PMDA. Canada requires MDSAP for Class II, III and IV device licences. The others accept it voluntarily. The UK MHRA holds observer status.
Is MDSAP accepted in the European Union?
No. The EU does not participate in MDSAP. Notified bodies conduct their own audits under EU MDR and IVDR, and an MDSAP certificate does not replace or reduce that assessment.
Is MDSAP mandatory?
Only in Canada, where a valid MDSAP certificate is required for a medical device licence covering Class II, III and IV devices under the Canadian Medical Devices Regulations. In the United States, Australia, Brazil and Japan it is voluntary.
What is the difference between ISO 13485 and EN ISO 13485?
The technical requirements are identical. EN ISO 13485:2016 is the European adoption and adds the Z annexes, which map the standard’s clauses to the quality management system requirements of EU MDR and IVDR. With the A11:2021 amendment, it supports presumption of conformity for the specific requirements listed in those annexes only.
Does ISO 13485 certification satisfy the FDA QMSR?
Not on its own. The QMSR, effective 2 February 2026, incorporates ISO 13485:2016 by reference but retains US-specific supplemental requirements. Certification is the foundation; a gap assessment against the QMSR-specific additions is still needed.
How long does MDSAP certification take?
Typically nine to eighteen months from initial gap assessment to certificate, depending on the maturity of your existing quality system and Auditing Organisation availability. Certification then runs on a three-year cycle with annual surveillance audits.
Considering MDSAP?
If you are weighing whether MDSAP is worth it for your market mix, preparing for a first audit, or responding to findings from one, we can give you a straight assessment of where you stand.
Write to sales@medfinsinternational.com or call +91 8527048221.
