Blog Article

FDA Is Rewriting How You Respond to a 483. Are Your CAPAs Ready?

QMSR came into force February 2, 2026. FDA Compliance Program 7382.850 replaced QSIT. The 483 response window is still 15 working days, but the citation language, the records FDA can request, and the format of an acceptable response have all shifted. Here's what changed and what your CAPA workflow has to produce.

QMSR came into force February 2, 2026. FDA Compliance Program 7382.850 replaced QSIT. The 483 response window is still 15 working days, but the citation language, the records FDA can request, and the format of an acceptable response have all shifted. Here's what changed and what your CAPA workflow has to produce.

FDA Form 483 document on the left with citation changing from 21 CFR §820.X to ISO 13485 clause notation, response timeline arrow showing 15 working days, and a CAPA record on the right with linked evidence

The 483 that doesn't look like the one you rehearsed for

A device manufacturer closes out its first inspection under the new rules. The investigator hands over a Form 483 — seven observations on the familiar form. But the top citation doesn't read the way the QA team's response template expects. It says "failure to establish and maintain procedures for corrective action per ISO 13485:2016 clause 8.5.2," not the §820.100 language every SOP on file is written against.

The 15-working-day clock starts on receipt, the same as it always has. What's different is nearly everything the response has to contain:

  • the citation points at an ISO 13485 clause, so the response template's §820 header fields are already wrong;
  • the investigator has asked to read the internal audit that surfaced the gap — a record FDA couldn't compel a year ago;
  • a narrative letter promising to "implement corrective actions" won't clear the bar — the reviewer expects the CAPA record itself, attached.

That's the shift this post is about: not the deadline, but what a defensible 483 response now has to produce — and the CAPA workflow that has to produce it inside the window.

What changed on February 2, 2026

The QMSR Final Rule replaced the operational requirements of the 1996 21 CFR Part 820 with ISO 13485:2016, incorporated by reference, plus a thin layer of FDA-specific retained clauses. Effective date February 2, 2026. On the same day, FDA Compliance Program 7382.850 replaced the Quality System Inspection Technique (QSIT) as the inspection manual investigators work from.

QSIT had been the inspection framework for medical devices since 1999. It structured inspections around six subsystems (Management, Design Controls, CAPA, Production and Process Controls, Material Controls, Records/Documents/Change Controls) and gave investigators a known progression through a manufacturer's QMS. Sponsors prepared for QSIT inspections for two and a half decades.

CP 7382.850 keeps the subsystem framing but updates how investigators move through it: ISO 13485 vocabulary, the new Medical Device File construct, and access to records that the old §820.180(c) exemption used to shield. The first post-QMSR inspections began Feb 2; by mid-2026 the pattern in 483 citations had become clear enough for response procedures to need updating.

This article is about what's actually different in the 483 response process under CP 7382.850, where the response templates most companies have on file fall short, and what your CAPA workflow has to produce inside the 15-working-day window to make the response defensible. In one table:

In your 483 response Pre-QMSR (Part 820 / QSIT) Post-QMSR (ISO 13485 / CP 7382.850)
Citation language "…per 21 CFR §820.100(a)" "…per ISO 13485:2016 clause 8.5.2, as incorporated by reference"
Records FDA can request Management review, internal audit, supplier audit shielded by §820.180(c) All three fully inspectable
Acceptable response Narrative letter + commitments; evidence to follow Structured, per-citation, with the CAPA records attached
Evidence expectation Summary of intended actions Root cause + CAPA + effectiveness plan as linked records
Response window 15 working days 15 working days (unchanged)

The new citation language in 483s

Pre-QMSR 483 citations read in a familiar shape: "Failure to establish and maintain procedures for corrective and preventive action per 21 CFR §820.100(a)." The structure was a regulatory citation with a brief description of the observed gap, written against the Part 820 framework that had been the operational reference since 1996.

Post-QMSR 483 citations read differently: "Failure to establish and maintain procedures for corrective action per ISO 13485:2016 clause 8.5.2, as incorporated by reference under 21 CFR Part 820." The citation now names the ISO 13485 clause directly, references QMSR's incorporation by reference, and (where applicable) cites the FDA-retained §820 clauses alongside the ISO clause.

The shift sounds cosmetic. It isn't, for three operational reasons:

  • Response procedures need updating. Any pre-2024 SOP that says "the response shall address each cited §820 clause" no longer describes the response your team has to produce. Update the language to "each cited ISO 13485:2016 clause and the corresponding retained §820 clauses where applicable."
  • Response templates need updating. Form templates with §820.X header fields have to become ISO 13485 clause fields — same structure, different labels. A template still on §820 vocabulary reads to a CDER or CDRH reviewer as a sponsor who hasn't updated their post-QMSR practices.
  • Cross-reference tables matter again. The §820-to-ISO-13485 mapping tables many QA teams built during 2024–2025 transition planning are now operational reference documents, not transition artefacts. Cite the cross-reference when you cite a legacy §820 clause — it proves the response is coherent across both citation systems.

Records FDA can now request during inspection

The §820.180(c) exemption under the old Part 820 protected three categories of records from FDA review: management review minutes, internal audit reports, and supplier audit records. The exemption was specific — the records had to exist (they were required by §820.20, §820.22, and §820.50) but FDA couldn't compel their production during an inspection.

QMSR removes the exemption. The three record types now sit in the same inspection-accessible category as every other QMS record, and CP 7382.850 tells investigators exactly when to ask for each:

  • Management review records — requested during the Management subsystem portion of the inspection.
  • Internal audit reports — requested during the Records subsystem portion.
  • Supplier audit records — requested during the Material Controls subsystem portion.

The practical implication for your 483 response: if your response cites a management review where the issue was discussed, or an internal audit where the gap was identified, or a supplier audit where the deficiency was flagged, FDA can now request the underlying record. Citing the record means producing the record. The response procedure has to anticipate this.

It also changes how your CAPA workflow runs. Pre-QMSR, a finding from internal audit could be addressed through a focused CAPA without the internal audit report itself becoming part of the inspection record. Post-QMSR, the internal audit that found the gap, the CAPA that addressed it, and the management review that surfaced the trend are all linked records FDA can request together. The CAPA workflow has to keep those linkages clean.

The 15-working-day window hasn't moved

FDA's expectation that the response arrive within 15 working days of receipt of the 483 hasn't changed. What changed is what the response has to contain.

Pre-QMSR, a strong response sent to the FDA district office within 15 days could be a narrative letter committing to corrective actions, with implementation evidence to follow over the next 30-60 days. The narrative format was acceptable as long as the commitments were specific and the timeline was reasonable.

Post-QMSR, the strong response is more structured. Each citation needs a numbered response section containing: the root cause analysis with documented data behind it, the corrective action with implementation evidence (where the implementation has happened in the 15-day window), the preventive action with the risk-based justification, and the effectiveness verification plan with the monitoring metrics that will close the loop. Where implementation evidence isn't yet available, the response cites the implementation plan with named owners and dates.

The pattern is essentially what a strong response always was, expressed in CAPA-system terms. The difference is that CP 7382.850 investigators expect to see the CAPA records themselves attached to the response, not just summarised in narrative. A response that says "we have opened CAPA #198 to address this finding" without producing CAPA #198 reads as incomplete to the post-QMSR reviewer.

What an acceptable response looks like under CP 7382.850

The post-QMSR acceptable 483 response has a structural shape that pre-QMSR responses didn't always have. Each citation gets its own response section. Each response section contains:

Root cause analysis with documented data. Not "the team failed to follow the procedure." The specific failure mode, traced through process data, deviation history, and supporting investigation records. Where the root cause analysis used a structured methodology (5-Why, fishbone, fault tree), the methodology is named and the analysis attached.

Corrective action with implementation evidence. The action taken or planned to address the immediate failure. Where implementation has happened within the response window, the implementation evidence is attached (updated procedure version, training-completion records, equipment qualification record, etc.). Where implementation hasn't happened yet, the implementation plan is named with owners and dates.

Preventive action with risk basis. The systemic action to prevent recurrence, with the risk-based justification for why this action addresses the cause rather than the symptom. ICH Q9(R1) risk methodology is acceptable framing; ISO 14971 framing is acceptable for device-specific risk; the framework named doesn't matter as long as the justification is documented.

Effectiveness verification plan with monitoring metrics. The specific data the firm will collect to demonstrate the action worked. Frequency, owner, threshold for escalation if the data shows the action didn't close the gap. The effectiveness verification record gets linked to the CAPA so the closure of the verification feeds back to the CAPA closure.

Linked records. The CAPA record, the change-control record (where applicable), the training assignment record (where applicable), the procedure revision record. All attached or referenced with retrievable identifiers.

This is the format CP 7382.850 reviewers are looking for. It's also exactly what a working CAPA workflow produces as a matter of routine. The response is the CAPA record set, formatted for FDA submission.

The CAPA workflow your response depends on

The 15-working-day response window forces a particular operational discipline on the CAPA system. The CAPA has to be opened within 24 hours of the 483, the root cause analysis has to be substantive within 5-7 working days, the corrective and preventive actions have to be defined within 10 working days, and the response package has to be assembled and reviewed by 15. None of that scales without a CAPA workflow that runs as one connected record set rather than as separate documents.

The connected record set is:

  • the originating 483 citation, and the CAPA opened against it;
  • the root cause analysis with its linked investigation evidence;
  • the action plan, with linked change-control records where the action is a procedure or process change;
  • the linked training where the action is a competency change;
  • the linked effectiveness verification plan with its monitoring schedule;
  • and the response cover letter your QA team assembles from those records for submission.

The architectural discipline is the same one a strong CAPA workflow always needs: a workflow that owns the state of the CAPA end to end, clean links between the records an action touches — the change-control record a procedure fix drives, the training a competency action depends on, the effectiveness verification that has to close before the CAPA does — and an audit trail, kept separate for each customer, that captures every change with a timestamp and the sign-off recorded at each gate. See the slow-CAPA architecture post for why these primitives matter outside the 483 response context too.

The firms that handle 483 responses smoothly under CP 7382.850 aren't doing anything novel. They're running CAPA workflows that produce the structured records as a matter of routine, then assembling those records into the response inside the 15-day window. Firms still running on form-and-email CAPAs spend the 15 days reconstructing what a connected workflow would already have captured.

Common 483 response mistakes that surface as repeat findings

Post-QMSR inspection pattern is showing a small number of recurring response mistakes that produce repeat findings in the next inspection cycle.

Symptom-level corrective action without preventive action. The response addresses the immediate failure (retrain the operator, revise the procedure) without addressing why the gap existed in the first place (the SOP was outdated, the training programme didn't catch it, the management review didn't surface it). The next inspection finds the same gap because the cause wasn't addressed.

Effectiveness verification that's a date in the future without a metric. "Effectiveness will be verified at the next quarterly management review." A management review without a defined metric isn't effectiveness verification — it's a calendar reminder. The post-QMSR expectation is a named metric with a numeric threshold and a documented data source.

Response that doesn't address all citations on the form. A 483 with seven citations needs seven response sections. Responses that cluster citations under common themes ("citations 1-3 all relate to documentation gaps...") leave specific citations without explicit response and produce follow-up correspondence asking for the missing pieces.

Implementation evidence that doesn't actually demonstrate implementation. A response that says "the procedure has been revised" needs to attach the new revision with the approval signature timestamps, the training records for everyone trained on the new revision, and the date the old revision was retired. The narrative "we've updated the procedure" without the supporting evidence reads as a commitment, not a closure.

Cross-citation linkages missed. When multiple citations share a root cause (e.g., several findings tracing back to a single training-management gap), the response should explicitly note the linkage and address the shared root cause once with cross-references. Responses that address each citation separately as if it had a unique cause read as superficial and risk repeat findings on the linked items.

How Complere supports a defensible 483 response

A post-QMSR 483 response runs on the same corrective-action work your team does every day: the response is that record, put together by your QA team for submission. Complere keeps its pieces connected from the moment you open it.

  • Each citation gets its own thread. You can open a separate corrective-action record for every item on the 483, and everything that item needs stays attached to it as it moves.
  • It can't close before it's actually done. The record walks from root cause, through the corrective and preventive actions, to a check that the fix worked, and it isn't allowed to close until it gets there, so the analysis, the actions, and the proof sit in one place instead of scattered across documents.
  • Actions stay tied to what they set in motion. When an action is a procedure change, it stays linked to that change; when it's a training need, the training is assigned and its completion tracked.
  • Nothing changes without leaving a mark. Every step keeps its own history, who did what and when, so a change becomes part of the record. Your files sit in a space of your own, apart from every other customer's.

The quality judgement stays yours: the root cause analysis, the action plan, the effectiveness criteria, and the review of what you send. What Complere gives it is a connected place to live, so producing the response inside the 15-working-day window isn't a hunt for last quarter's template or last year's training records.

Frequently asked questions

Questions readers commonly ask about FDA Is Rewriting How You Respond to a 483. Are Your CAPAs Ready?.

Does QMSR change how I should handle a 483 issued before February 2, 2026?

A 483 issued before February 2, 2026 cites §820 clauses under the pre-QMSR framework, and your response should follow the pre-QMSR citation conventions. The response is judged against the regulations in force at the time of inspection, not at the time of response. Where the underlying CAPA work overlaps post-QMSR practices (which it usually does), your response can reference the cross-reference table for context, but the primary citation framework is the one the 483 was written against.

Can I send a partial response within 15 days and finish later?

A partial response within 15 days is acceptable when implementation evidence isn't yet available, as long as the partial response is structured and committed. State explicitly which sections are complete with evidence, which sections have implementation underway with named owners and dates, and the date the complete response will arrive. A response that arrives within 15 days with even partial structure reads materially better to the FDA reviewer than a complete response arriving on day 25.

What happens if my CAPA isn't fully closed by the time the response is due?

That's the normal case — the 15-day window rarely allows full CAPA closure, especially when effectiveness verification requires a 30-90 day monitoring period. The acceptable response submits the CAPA record at its current state with the effectiveness verification plan documented, then follows up with the verification evidence when the monitoring period closes. The follow-up is an extension of the response, not a separate submission. Schedule the follow-up at submission time so it doesn't slip when the team gets pulled into the next inspection cycle.

Disclaimer: This article is a practical interpretation of the QMSR Final Rule (89 FR 7496), 21 CFR Part 820 as amended, FDA Compliance Program 7382.850, and ISO 13485:2016. It is not legal advice. Teams should confirm specific requirements against their predicate rules, intended use, validated quality system documentation, and the contractual provisions of their eQMS vendor.

About the author

Co-founder, Validation & Engineering, DevOps Lead

Compliance and quality-systems specialist writing for regulated SaaS buyers in pharma, medical device, biotech, and CDMO. All posts reviewed against current FDA, MHRA, EMA, ICH, and PIC/S guidance before publication.

Continue Exploring

Explore related topics, modules, and compliance resources for a deeper understanding of your quality system.

QMSR 12-clause map companion post
Related

QMSR is live — the 12-clause map to your eQMS

Explore this topic in more depth to build a complete picture of your quality and compliance operations.

Explore
Slow-CAPA architecture companion post
Related

If your CAPAs are slow, your QMS architecture is wrong

Explore this topic in more depth to build a complete picture of your quality and compliance operations.

Explore

Related from the blog

More from the Complere editorial team on quality, validation, and inspection readiness.

AI in Regulated Industries

GAMP 5 Second Edition and AI: What 'Category 5' Means When the Model Retrains Itself

GAMP 5 Category 5 assumed software was static at release. AI retrains itself. What Appendix D11 adds, and why validation evidence is a stream, not a binder.

Read the article
eQMS Architecture & Selection

If Your CAPAs Are Slow, Your QMS Architecture Is Wrong (Not Your Team)

Slow CAPAs get blamed on overworked QA, but the cycle-time data says otherwise: the wasted days sit at the seams between your eQMS modules, not your team.

Read the article
CDMO & Multi-Tenant Architecture

Why CDMO Quality Systems Break at the Seams — and What 'Tenant of One' Should Mean

CDMOs serve dozens of sponsors, but every sponsor audits the CDMO as an extension of their own facility. 'Tenant of one' is the architecture that resolves it.

Read the article

See the CAPA and evidence trail your 483 response runs on

Walk through how Complere keeps CAPAs, evidence linkages, training assignments, and effectiveness checks connected so your QA team can assemble the response within the 15-working-day window.