Skip to main content
v2026.11,772 entries · CC-BY 4.0

MDSAP: The Medical Device Single Audit Program, Explained

How MDSAP actually works: the three membership tiers and what each one really accepts, the seven-process audit model auditors follow in sequence, and the 1-5 nonconformity grading scale (with its separate escalation step) that decides how serious a finding becomes.

Ask CASRAI · included with Regulatory Radar

Ask about MDSAP: The Medical Device Single Audit Program, Explained

Ask CASRAI answers research-administration questions and cites the passages behind every claim — and says so when the corpus does not cover something, instead of guessing. It comes with a Regulatory Radar subscription at $29 a month, alongside the daily digest of regulatory changes and the dashboard of what changed.

150 questions a day, on this site, over the API, or inside your own tools through the CASRAI MCP server.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Written and maintained by CASRAI Editorial Board

Last updated

The Medical Device Single Audit Program (MDSAP) lets a manufacturer undergo one audit, from one MDSAP-recognized auditing organization, and have the resulting report accepted by multiple regulators instead of hosting a separate inspection for each one. It is a regulatory audit against a published process model — not a certification, and not a stronger version of ISO 13485 certification.

Who actually accepts an MDSAP report

Per FDA’s own MDSAP page, membership sits in three tiers, and the tier matters — only the first accepts an MDSAP report as a direct substitute for its own routine inspection today.

Tier Authorities What it means in practice
Regulatory Authority Members Australia’s Therapeutic Goods Administration (TGA), Brazil’s ANVISA, Health Canada, Japan’s MHLW and PMDA, and the U.S. FDA These are the audit’s actual sponsors. FDA’s own wording is that it “may continue to accept MDSAP audit reports as a substitute for routine Agency inspections.”
Official Observers The European Union, Singapore’s Health Sciences Authority (HSA), the UK’s MHRA, and the WHO Prequalification of IVDs Programme Observing the program, not accepting reports in place of their own routine oversight — an MDSAP report does not substitute for a notified-body audit under EU MDR/IVDR.
Affiliate Members Argentina’s ANMAT, Israel’s Ministry of Health, Kenya’s Pharmacy and Poisons Board, South Korea’s MFDS, Mexico’s COFEPRIS, South Africa’s SAHPRA, and Taiwan’s TFDA A lighter engagement tier, short of full member acceptance.

Two caveats worth stating plainly rather than assuming: firms with Electronic Product Radiation Control (EPRC) activities remain subject to separate FDA inspection for those activities regardless of MDSAP status, and this page does not assert a date on which Health Canada made MDSAP mandatory for device licensing — check Health Canada’s own current guidance directly before relying on a specific date, since FDA’s page (the primary source used here) does not state one.

The audit is process-based, not clause-based

A standard ISO 13485 surveillance audit typically samples clauses of the standard. MDSAP instead audits seven defined processes, in a fixed sequence, using a shared audit approach document (MDSAP AU P0002) that every recognized auditing organization applies the same way. That consistency — not just the shared report — is what lets five regulators rely on one audit.

The primary sequence is:

  1. Management — top management’s oversight of the QMS: quality planning, defined responsibilities, resource allocation, and management review.
  2. Measurement, Analysis and Improvement — how nonconformities are investigated, CAPAs run, and QMS performance data is analyzed.
  3. Design and Development — design controls and the design history file for products in scope.
  4. Production and Service Controls — process validation, environmental controls, equipment calibration and maintenance, and in-process/final inspection.

Purchasing is audited alongside whichever of those three process areas it touches, rather than as a separate stop on the sequence. Two further processes run as supporting audits: Device Marketing Authorization and Facility Registration, and Medical Device Adverse Events and Advisory Notices Reporting — the process area that covers complaint handling, reportability decisions and field safety actions (see CASRAI’s complaint handling for medical devices guide for the intake-to-reportability mechanics that feed this audit area).

The 1-5 nonconformity grading scale

MDSAP does not grade findings simply “minor” or “major” the way a typical ISO 13485 surveillance audit does. Auditors assign a numeric grade from 1 to 5: grades 1 through 3 are treated as minor, grades 4 and 5 as more serious. Grading runs in two steps — an initial point score is assigned against the specific ISO 13485:2016 requirement the finding is written against, using a defined grading matrix, and then a separate set of escalation rules is applied on top of that initial score. Escalation is what makes the final grade higher than the starting point: commonly cited escalation drivers include whether the same nonconformity has recurred from a prior audit, whether it spans multiple manufacturing sites, and whether it carries direct product-safety or regulatory-reporting consequences rather than a purely procedural gap. Because escalation is a distinct step from the initial score, two nonconformities written against the same clause can close at different final grades depending on context the clause number alone doesn’t capture — read the auditing organization’s finding write-up for the escalation reasoning, not just the grade number, before scoping a response.

This is a materially different consequence model than the generic NCR/NCAR process most quality systems already run (see CASRAI’s nonconformity: major vs. minor guide for that general mechanism) — treat an MDSAP grade as its own scale, not a relabeling of a major/minor call your QMS already made.

MDSAP vs. ISO 13485 certification: not the same audit

MDSAP is not an ISO 13485 certification audit conducted to a higher standard; it is a distinct assessment with a distinct purpose, though certification bodies commonly schedule the two together to save audit days. FDA does not certify anyone to ISO 13485 and does not require a certificate at all — under the Quality Management System Regulation (QMSR) it requires compliance with 21 CFR Part 820 and verifies that through inspection, not certification. If you’re scoping a combined visit, CASRAI’s ISO 13485 certification guide covers the certification-body side of that conversation: the audit-day table, the stage 1/stage 2 split, and how a combined MDSAP-plus-ISO-13485 visit is typically sequenced.

Where MDSAP fits alongside other market-access routes

MDSAP participation doesn’t replace jurisdiction-specific submissions. A device still needs its own regulatory pathway determination in each market — see CASRAI’s FDA medical device classification and 510(k)/PMA guide for the U.S. side, and the EU MDR guide for why an MDSAP report is not a substitute for a notified-body conformity assessment in the EU, where MDSAP participates only as an official observer. For manufacturers also navigating Mexico’s COFEPRIS pathway (an MDSAP affiliate member, not a full member), CASRAI’s COFEPRIS guide covers that jurisdiction’s own authorization mechanics.

Frequently asked questions

Is MDSAP mandatory?

Not universally. It is voluntary for manufacturers, but individual member regulators can and do make it a practical requirement for market access in their own jurisdiction — check the specific regulator’s current guidance rather than assuming MDSAP’s own participant list settles the question for every member.

Does an MDSAP audit replace a notified body audit under EU MDR?

No. The EU participates in MDSAP only as an official observer, not as a full member accepting the report in place of its own oversight — a notified-body conformity assessment under MDR/IVDR is still required separately.

Who conducts an MDSAP audit?

An MDSAP-recognized auditing organization, applying the shared MDSAP Audit Approach and Companion Document so that every recognized auditing organization assesses the same seven processes the same way, regardless of which organization runs the audit.

What happens if a nonconformity grades at 4 or 5?

Grades 4 and 5 are treated as more serious than grades 1 through 3, typically driving a shorter required closure timeline and closer regulator attention than a lower-grade finding — confirm the specific consequence and deadline with your auditing organization’s own grading guidance, since escalation reasoning is written per finding, not fixed by grade number alone.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 72,264 indexed passages, and every answer cites the ones it drew on.