MDSAP Certification Consultants for Medical Device Manufacturers

MDSAP certification allows a medical device manufacturer to undergo a single quality management system audit that is accepted by several major regulators. Medfins International helps manufacturers extend an existing ISO 13485 system to meet the country-specific requirements of each participating authority, prepare the MDSAP audit model evidence and respond confidently to findings from a recognised Auditing Organisation.

What is the Medical Device Single Audit Program (MDSAP)?

The Medical Device Single Audit Program lets an MDSAP-recognised Auditing Organisation conduct one regulatory audit of a manufacturer’s QMS that satisfies the relevant requirements of multiple regulatory authorities. The audit is based on ISO 13485:2016 plus the additional national requirements of each participating jurisdiction the manufacturer sells into.

MDSAP is not a product approval. It covers the quality system; product registrations, licences and clearances in each country are still required separately.

Participating regulators

According to the US FDA’s MDSAP information, the regulatory authority members are:

  • Therapeutic Goods Administration (TGA), Australia
  • Agência Nacional de Vigilância Sanitária (ANVISA), Brazil
  • Health Canada
  • Ministry of Health, Labour and Welfare (MHLW) and Pharmaceuticals and Medical Devices Agency (PMDA), Japan
  • US Food and Drug Administration (FDA)

Official observers include the European Union, Singapore’s HSA, the UK MHRA and the WHO Prequalification of IVDs Programme. Affiliate members currently include regulators in Argentina, Israel, Kenya, the Republic of Korea, Mexico, South Africa and Taiwan. Membership changes over time, so we confirm the current list at the start of each project.

How each regulator uses MDSAP

  • Health Canada: an MDSAP certificate is the accepted way to demonstrate QMS compliance for Class II to IV medical device licences.
  • US FDA: MDSAP audit reports can be used in place of routine FDA surveillance inspections; for-cause and pre-approval inspections may still take place. Audits address the QMSR in 21 CFR Part 820.
  • TGA, ANVISA and MHLW/PMDA: MDSAP reports and certificates are used as evidence of QMS compliance in their conformity assessment and registration processes, reducing the need for separate inspections in many cases.

Who should consider MDSAP?

  • Manufacturers selling, or planning to sell, in Canada, where MDSAP is effectively required
  • Exporters targeting two or more participating markets who want to reduce the number of regulatory audits
  • Indian and overseas manufacturers already certified to ISO 13485 who are expanding to the USA, Brazil, Australia or Japan

Scope of the MDSAP audit

The MDSAP audit model follows a defined sequence of processes:

  1. Management
  2. Device marketing authorisation and facility registration
  3. Measurement, analysis and improvement
  4. Medical device adverse events and advisory notices reporting
  5. Design and development
  6. Production and service controls
  7. Purchasing

Findings are graded on a 1 to 5 scale, and higher-graded nonconformities must be reported to the regulators within short, fixed timeframes. This makes preparation more important than in a typical ISO 13485 audit.

Documents typically required

  • ISO 13485 quality manual and procedures updated for each selected jurisdiction
  • Procedures for adverse event reporting, recalls and advisory notices for each country
  • Records of market authorisations, establishment registrations and licences held
  • Design history, risk management (ISO 14971:2019) and software life-cycle records (IEC 62304) where applicable
  • Supplier controls, including critical suppliers and outsourced processes
  • Complaint, CAPA, internal audit and management review records

MDSAP certification process

  1. Market selection: confirm which participating jurisdictions will be in scope.
  2. Gap analysis: assess your ISO 13485 system against MDSAP audit model tasks and each country’s regulatory requirements.
  3. QMS update: add the country-specific procedures, reporting routes and records.
  4. Auditing Organisation selection: choose an MDSAP-recognised Auditing Organisation and agree the audit plan.
  5. Mock MDSAP audit: an internal audit following the MDSAP audit model and grading approach.
  6. Initial certification audit: Stage 1 and Stage 2 audits by the Auditing Organisation.
  7. Nonconformity response: root cause, correction and corrective action plans within the required deadlines.
  8. Ongoing cycle: annual surveillance audits and recertification on a three-year cycle.

Timelines and what affects them

MDSAP preparation time depends on the maturity of your existing ISO 13485 system, the number of jurisdictions selected, device risk classes, whether design is in scope, and Auditing Organisation availability. Organisations without a functioning ISO 13485 QMS should first build that foundation.

Common reasons for findings

  • Adverse event and recall reporting procedures that do not reflect each country’s rules
  • Records of market authorisations and registration changes not maintained
  • Weak links between complaints, risk management and CAPA
  • Insufficient control of critical suppliers and contract manufacturers

Benefits of MDSAP for manufacturers

  • Fewer audits: one audit programme can replace several separate regulatory inspections and QMS audits.
  • Predictable schedule: audits follow a planned three-year cycle rather than unannounced routine inspections in many cases.
  • Market access: it supports licensing in Canada and QMS evidence for registrations in the other member markets.
  • Stronger QMS: the structured audit model encourages consistent processes for complaints, reporting and changes across all markets.

MDSAP also has trade-offs. Audits usually take longer than ISO 13485 audits, the requirements of every selected market must be met, and nonconformity responses have strict deadlines. For a company supplying only India and a small number of non-member markets, ISO 13485 certification may be enough.

Keeping MDSAP certification

After certification, the QMS must keep pace with each jurisdiction. New product authorisations, changes to adverse event reporting rules, updates to the FDA QMSR and changes in Health Canada or ANVISA requirements must all be reflected in procedures before the next surveillance audit.

How Medfins International supports you

Led by a CQI and IRCA certified ISO 13485 Lead Auditor, our team maps your QMS against the MDSAP audit model and prepares the country-specific procedures auditors look for. If your QMS needs strengthening first, we start with ISO 13485:2016 certification support. We also connect MDSAP with product submissions such as US FDA 510(k), and offer supplier audit support for critical suppliers. Contact us to plan your MDSAP route.

Frequently asked questions

Does MDSAP replace product registration in each country?
No. MDSAP covers the quality management system audit only. You still need the relevant product authorisation in each market, such as a Health Canada medical device licence, US FDA clearance or approval, ANVISA registration, TGA inclusion or Japanese approval or certification. The MDSAP report and certificate support those processes.
Do I need ISO 13485 certification before MDSAP?
MDSAP audits are built on ISO 13485:2016, so a functioning ISO 13485 system is the essential starting point. Many Auditing Organisations can issue an ISO 13485 certificate alongside the MDSAP certificate, and manufacturers often move to MDSAP from an existing certificate at recertification or through a transfer to an MDSAP-recognised Auditing Organisation.
Which countries accept MDSAP?
The regulatory authority members are Australia (TGA), Brazil (ANVISA), Canada (Health Canada), Japan (MHLW and PMDA) and the USA (FDA). Several other regulators participate as observers or affiliate members. We check the current list published by the FDA and the MDSAP programme before scoping your audit.
Can Indian manufacturers get MDSAP certified?
Yes. MDSAP is open to manufacturers worldwide, including Indian manufacturers. Any manufacturer that sells or plans to sell in at least one participating market can be audited by an MDSAP-recognised Auditing Organisation, and the audit covers the requirements of the jurisdictions you select. Indian licensing under the Medical Devices Rules, 2017 remains separate.
How is MDSAP different from a normal ISO 13485 audit?
MDSAP follows a structured audit model, includes country-specific regulatory requirements, uses a graded nonconformity system and shares results with the participating regulators. Audit durations are typically longer, and responses to nonconformities have strict deadlines. Preparation therefore needs to go beyond a standard ISO 13485 readiness review.