Design Control Process for Medical Devices

Blog |

The design control process for medical devices is a documented, risk-based system for translating user needs into a device that can be shown to meet its requirements, intended use, and applicable regulatory obligations. It connects product development with the quality management system (QMS) so that important decisions, tests, risks, and changes remain controlled and traceable.

For startups and medical device manufacturers, design controls are more than a compliance exercise. Applied early, they reduce ambiguity, expose technical problems, and organize evidence for submissions and inspections. The same principles apply to hardware, Software as a Medical Device (SaMD), AI/ML-enabled products, and connected devices—although the evidence needed for each product will differ.

Why Design Controls Matter

Design controls create a disciplined path from a clinical or user problem to a validated product. They help teams define what the device must do, identify risks, evaluate design choices, and demonstrate that the finished device is suitable for its intended users and environment.

Clear requirements reduce rework, planned reviews catch gaps, and traceability makes regulatory questions easier to answer. Controlled transfer and change control reduce the chance that manufacturing decisions or product updates will introduce new problems. Reviewers should be able to follow the development story without reconstructing it from scattered records.

What Are the FDA Guidelines for Design Control?

FDA's Quality Management System Regulation (QMSR) became effective on February 2, 2026. Under 21 CFR 820.10(c), manufacturers of Class II and Class III devices, and certain Class I devices, must comply with the design and development requirements in ISO 13485:2016, Clause 7.3 and its subclauses. The covered Class I products include devices automated with computer software and specific device types listed in the regulation.

The former Quality System Regulation placed design controls in 21 CFR 820.30, but that section was removed entirely when the QMSR took effect and is now reserved. FDA's 1997 design-control guidance was also archived. Current procedures should therefore be mapped to the QMSR and incorporated ISO 13485 requirements.

Does ISO 13485 Cover Design Controls?

Yes. ISO 13485:2016 Clause 7.3 covers design and development planning, inputs, outputs, review, verification, validation, transfer, changes, and files. It sits within the broader QMS alongside document control, supplier controls, production, corrective action, and other processes.

ISO 13485 uses “design and development file.” Many U.S. teams still say Design History File (DHF), the term used in former 21 CFR 820.30. Device Master Record (DMR) is also legacy FDA terminology; ISO 13485 Clause 4.2.3 requires a medical device file containing or referencing the specifications and procedures needed to produce and control the device.

Step-by-Step Design Control Process

Design control is iterative. Risk analysis, reviews, and traceability should be updated as the design matures.

  1. Plan the Work and Assign Responsibility

    Create a design and development plan defining phases, deliverables, responsibilities, interfaces, review points, and approval authority. Explain how contributing functions will coordinate and update the plan when the scope or evidence needs change.

    For a lean organization, the plan can be brief, but it must identify the evidence required, its owner, and its review point.

  2. Define User Needs and Intended Use

    Document the clinical problem, intended users, patient population, use environment, and essential tasks. Align intended use and indications for use with the proposed regulatory pathway and labeling.

    Translate user needs into measurable requirements. A vague need such as “easy to use” requires defined usability criteria before it can be verified or validated.

  3. Establish Design Inputs

    Design inputs convert user, safety, performance, regulatory, cybersecurity, and manufacturing needs into clear requirements. Each input should be testable, approved, and traceable.

    Resolve conflicting or ambiguous requirements before downstream testing and document the resulting decisions.

  4. Integrate Risk Management

    Risk management should begin while inputs and architecture are being developed, not after the design is complete. ISO 14971 provides the principal framework for medical device risk management. Identified hazards, foreseeable sequences of events, hazardous situations, and risk controls should inform design requirements and test plans.

    Link risks and controls to inputs, outputs, verification, and residual-risk conclusions. For software-enabled devices, connect safety analysis with threat modeling when a cyber event could affect safety or essential performance.

  5. Produce Controlled Design Outputs

    Design outputs define the device and enable production and acceptance. Examples include drawings, bills of materials, software requirements, architecture specifications, labeling, manufacturing instructions, and test methods.

    Review and approve outputs before release and include or reference objective acceptance criteria.

  6. Verify the Design

    Design verification asks whether outputs meet inputs. Define the method, samples, acceptance criteria, responsibilities, and statistical rationale before testing. Record results, deviations, conclusions, and approvals.

    Methods may include inspection, analysis, code review, bench testing, or comparison with a recognized standard. A traceability matrix should connect each applicable input with objective evidence.

  7. Validate the Finished Device

    Design validation asks whether the device meets user needs and intended use. Perform it under defined conditions using production units, lots, batches, or their equivalents, as appropriate.

    Evidence may include usability validation, clinical evaluation, clinical investigation, simulated-use studies, or software validation. The plan should reflect actual users, environments, workflows, and foreseeable misuse. Passing a specification test does not by itself show that users can safely achieve the intended outcome.

  8. Conduct Formal Design Reviews

    Hold documented, cross-functional reviews at appropriate stages. Each review should evaluate results, identify issues, assign actions, and record decisions. Include the functions and specialists needed for that stage.

    Independence should be meaningful, but it can be scaled to the organization. A startup may use a qualified adviser or a team member who does not directly own the work under review.

  9. Transfer and Control the Design

    Design transfer ensures that approved specifications are correctly translated into production. Confirm supplier readiness, inspection methods, software build controls, process validation, and release criteria.

    After transfer, control design changes through documented review, verification or validation as appropriate, risk analysis, regulatory assessment, and approval. Keep the design and development file current and searchable throughout the device lifecycle.

SaMD, AI/ML, and Software-Enabled Device Considerations

Software records should cover requirements, architecture, versioning, configuration management, anomalies, testing, and release. SaMD teams should connect lifecycle activities to intended use, clinical evaluation, risk management, and postmarket monitoring.

For AI/ML functions, document dataset provenance, selection criteria, labeling methods, population characteristics, training and test separation, subgroup performance, and model version. Planned modifications need defined controls, acceptance criteria, monitoring, and rollback. A Predetermined Change Control Plan may be appropriate for certain FDA submissions, but it must be specific and bounded.

Connected devices also need cybersecurity integrated into design. Begin threat modeling early, establish security requirements, maintain a Software Bill of Materials (SBOM), and verify controls through risk-appropriate testing. Component provenance, vulnerability monitoring, secure updates, and postmarket response should connect to the overall risk file and design-change process. QCC's cybersecurity compliance services help manufacturers organize this evidence for review.

Regulatory Pathways: 510(k), PMA, EU MDR, International Submissions

A 510(k) generally demonstrates that a device is substantially equivalent to a legally marketed predicate. Design control records help support the performance, software, risk, cybersecurity, and labeling evidence used in that comparison.

A Premarket Approval Application (PMA) is the most stringent FDA marketing application and is generally required for Class III devices. Unlike a 510(k), it requires valid scientific evidence providing a reasonable assurance of safety and effectiveness. The development program and clinical evidence are therefore typically more extensive.

Under the EU Medical Device Regulation, technical documentation must be clear, organized, searchable, and cover design and manufacturing information, risk management, verification, validation, and other conformity evidence. A common core can support multiple markets, but teams must still map jurisdiction-specific requirements.

Common Design Control Gaps

Frequent gaps include unclear requirements, missing review approvals, tests that do not map to inputs, incomplete risk-control verification, validation with unrepresentative users, uncontrolled software versions, and changes implemented without adequate impact analysis.

Remediation starts with an evidence map. Identify missing links, determine whether existing records provide objective evidence, and complete justified supplemental work. A focused mock audit or submission-readiness review can reveal gaps while there is still time to correct them.

Design Control Checklist

Before a major review or submission, confirm that the team has:

  • A current design and development plan
  • Approved user needs, intended use, and design inputs
  • Integrated safety and cybersecurity risk records
  • Controlled design outputs with acceptance criteria
  • Complete verification and validation plans and reports
  • Documented design reviews and closed action items
  • Transfer, supplier, and production-readiness evidence
  • Traceability from user needs through validation
  • Controlled change records and regulatory assessments
  • An indexed design and development file

Start controls early, use an eQMS or connected tools where practical, align product and quality teams frequently, plan verification and validation around regulatory evidence needs, integrate risk throughout development, and maintain a concise file that reviewers can navigate.

How Quality Commercial Consultants Can Help

Quality Commercial Consultants helps medical device and health-technology companies convert technical work into clear, submission-ready evidence. Support may include QMS compliance planning, gap analysis, traceability and documentation planning, compliance-risk identification, design and development file reviews, audit preparation, and integration of evidence into FDA submissions.

Effective design controls protect patients, strengthen product quality, and reduce review delays. Contact our experts to discuss your device, regulatory pathway, and evidence needs.

Contact Us Today

We provide clear regulatory guidance that meets you where you are today.