In the world of regulatory audits, it is not always the major issues that trigger non-conformities. Often it is the seemingly minor gaps, a reference to an outdated ISO standard, an untracked update to a guidance document, or the lack of documented rationale behind a deviation, that lead to the most significant audit findings.
In 2026, that risk has intensified. ISO 13485, the foundational quality management standard for medical devices, is currently designated as “under review”: with potential changes related to the new ISO Harmonized Structure and AI integration expected to be considered at the next review cycle. IEC 62304, the key standard for medical device software lifecycle processes, is undergoing a major revision to Edition 2, introducing a simplified two-level safety classification system, an expanded scope covering all health software and AI/ML systems, and new provisions for AI development lifecycle governance. And as of February 2, 2026, the FDA’s QMSR formally aligned U.S. quality system requirements with ISO 13485:2016: creating a direct regulatory dependency between standard version currency and FDA compliance.
For MedTech companies juggling regulatory requirements across the U.S., EU, and Asia, maintaining visibility over evolving standards is both essential and more complex than ever. Without a proactive system, teams risk falling out of compliance, facing audit delays, and damaging trust with regulators.
Download our free checklist to see if your tracking system is putting your company at risk.
What Is Standards Management in Regulatory Affairs?
Standards management refers to the structured process of tracking and applying technical standards, harmonized guidelines, and regulatory references across the medical device lifecycle. A strong standards management system ensures consistent tracking of international standards, integration into technical documentation and clinical evaluation reports, ongoing monitoring of new or revised standards post-approval, and a documented, traceable rationale for selecting or deviating from any given standard.
In 2026, the key standards landscape looks like this:
ISO 13485 (QMS): Last confirmed in 2020, currently under review. The next revision may incorporate the ISO Harmonized Structure and AI-related amendments. Manufacturers should monitor closely; a new edition would trigger documentation updates across every product’s quality system.
ISO 14971 (Risk Management): Reviewed and confirmed in March 2025 with no changes. Expected to be reviewed again in five years, providing a stable baseline for risk management documentation through approximately 2030.
IEC 62304 (Medical Device Software): Edition 2 is actively under development, introducing a two-level safety classification system, expanded scope covering all health software, and new AI/ML lifecycle provisions. Companies developing software-driven or AI-enabled devices should begin gap-assessing against Edition 2 requirements now.
IEC 62304 and ISO 14971 integration: The two standards work closely together to create a complete medical device risk management framework for software: cybersecurity and AI-driven software introduce additional complexity that manufacturers using either standard should actively monitor.
FDA QMSR: Effective February 2, 2026, the FDA’s QMSR formally aligns U.S. quality system requirements with ISO 13485:2016: creating a direct dependency between ISO 13485 currency and U.S. regulatory compliance that did not previously exist in the same explicit form.
Why Poor Standards Management Leads to Audit Non-Conformities
Without proactive oversight, standards can become outdated, misapplied, or inconsistently referenced. Common pitfalls include: referencing withdrawn or superseded standards in regulatory filings; failing to update documentation in response to revised standards; no clear justification for why a particular standard was used or excluded; inconsistent application across regions or product lines; and lack of awareness about how updates impact already-approved devices.
In 2026, three specific emerging risks elevate these pitfalls for companies developing digital or AI-enabled products:
IEC 62304 Edition 2 transition risk: Edition 2 expands IEC 62304’s scope to cover all health software; meaning products that were previously outside the standard’s formal scope may now fall under it. Companies that have not assessed whether their software portfolio is affected by Edition 2’s expanded definition may face unexpected compliance gaps at their next notified body or FDA inspection.
EU AI Act intersection with harmonized standards: Cybersecurity has become a critical regulatory focus area, with cybersecurity standards now directly impacting market approvals for software-driven and AI-enabled devices across all major markets. The EU AI Act, with high-risk AI obligations applying from August 2026, adds a new layer of standards obligations that must be tracked alongside traditional medical device standards. Companies whose standards management systems do not cover AI Act-relevant standards risk an undetected compliance gap.
QMSR and ISO 13485 version currency: With the FDA’s QMSR now formally aligned to ISO 13485:2016, any manufacturer referencing an earlier version of ISO 13485 in their quality system documentation is at risk of a QMSR non-conformity at FDA inspection. Version currency tracking is no longer a quality best practice; it is a regulatory requirement.
What Auditors Look For
Regulators today are focused not just on whether standards are cited, but on how well they are managed throughout a product’s lifecycle. During an audit, reviewers want to see traceability (a clear line connecting each applied standard to product files, risk assessments, test reports, and design documentation), impact assessments, evidence of monitoring, internal SOPs, and regional consistency.
A growing expectation in 2026 audits, particularly under EU MDR notified body reviews and FDA QMSR inspections, is what auditors increasingly call “connected documents”: a single traceable chain that ties requirements to design, risk, verification, labeling, suppliers, and post-market data. Auditors expect one coherent story, not a collection of independently managed documents. The solution is not more documents; it is connected documents.
For software-driven devices specifically, IEC 62304 compliance now requires integration across ISO 13485 (QMS), ISO 14971 (risk management), and IEC 62304 itself, the IEC 62304 Software Development Plan becomes part of the ISO 13485 Design and Development Plan, and every risk identified in IEC 62304 should tie back to the ISO 14971 risk file. Auditors reviewing software technical files expect this integration to be visible and traceable; not maintained in separate silos.
The Risks of Getting It Wrong
The consequences of poor standards management can be severe and go far beyond documentation errors. Audit findings may require follow-up inspections or lead to suspended certifications. Outdated or non-recognized standards delay regulatory approvals. Resource-intensive CAPAs fix avoidable errors. Loss of market access is a real consequence under MDR/IVDR, which have strict harmonized standards rules. And erosion of trust with regulators and notified bodies leads to more frequent or detailed inspections.
Two 2026-specific risks add urgency:
QMSR non-conformity risk: With the FDA’s QMSR explicitly aligned to ISO 13485:2016, any manufacturer whose quality system documentation references an earlier ISO 13485 version, or whose supplier audit records do not reflect the new QMSR scope, faces a specific, named non-conformity risk at FDA inspection. This is a direct consequence of standard version currency that did not exist in the same form before February 2026.
IEC 62304 Edition 2 portfolio risk: Edition 2’s expanded scope, covering all health software and introducing new AI/ML lifecycle provisions means some products previously considered outside IEC 62304’s scope may now fall within it. Companies that do not proactively assess this scope change risk discovering the gap during an audit or submission review rather than in a controlled internal assessment.
How Proactive Standards Management Helps
A proactive standards management approach shifts companies from reactive problem-solving to forward-looking compliance control. With the right tools and processes in place, teams can reduce audit stress, respond quickly to changes, ensure consistency across global portfolios, align RA, QA, engineering, and R&D teams, and stay ahead of evolving regulations.
In 2026, “staying ahead” requires tracking not just traditional medical device standards but an expanding set of intersecting frameworks: standards like ISO 13485, ISO 14971, IEC 62304, IEC 62366-1 (usability), ISO 10993 (biocompatibility), and ISO 15223-1 (symbols) each touch a different phase of the device lifecycle; but auditors expect one traceable chain connecting all of them. For software and AI-enabled devices, that chain now also includes IEC 81001-5-1 (cybersecurity for health software), ISO/IEC 27001 (information security), and the emerging AI Act-related standards framework.
The most effective standards management systems automate key processes: auto-enrolling training when an SOP updates, auto-creating a CAPA from repeat non-conformity trends, auto-notifying owners when a standard changes, and auto-revoking outdated templates to prevent “old” forms from being used in active submissions. These automation capabilities are what separate proactive compliance infrastructure from manual tracking that inevitably falls behind.
How RegDesk Supports Standards Management
Managing standards manually through spreadsheets, shared drives, or disparate systems is a recipe for confusion and error and in 2026, with ISO 13485 under review, IEC 62304 Edition 2 in active development, and the FDA’s QMSR creating explicit ISO version dependencies, the cost of manual tracking failure has never been higher.
RegDesk streamlines the process with intelligent automation, global coverage, and built-in traceability:
Real-Time Standards Alerts: Get automatic notifications when FDA, ISO, IMDRF, or EU standards are updated, withdrawn, or replaced; including emerging developments like IEC 62304 Edition 2 progression and ISO 13485 review outcomes.
Centralized Repository: Manage all standards in one place, tied directly to product records, documentation, and regions; enabling the “connected documents” traceability that auditors increasingly expect.
Change Impact Analysis: Quickly identify which products are affected by a standard change, including scope expansions like IEC 62304 Edition 2’s coverage of all health software, with built-in workflows to notify relevant teams.
Audit-Ready Traceability: Maintain clean, version-controlled records for each standard, complete with history and rationale; the documented trail that regulators and notified bodies expect to see during inspections.
AI-Powered Automation: Eliminate manual monitoring with AI that flags changes, suggests actions, and reduces review time, so standards compliance is built into your quality system, not bolted on at audit time.
Conclusion
In 2026, standards management has moved from a quality best practice to a strategic regulatory necessity. With ISO 13485 under review, IEC 62304 Edition 2 in active development, ISO 14971 stable but requiring monitoring of its interactions with evolving software and AI standards, and the FDA’s QMSR creating explicit version currency dependencies, the standards landscape demands proactive, automated, and integrated tracking more than ever before.
The more complex your product portfolio and global footprint, the more critical it becomes to proactively monitor, assess, and document your standards strategy. Companies that build connected, traceable standards management infrastructure, rather than managing standards reactively through spreadsheets and manual reviews, will be best positioned for audit readiness, faster submissions, and stronger regulatory relationships in 2026 and beyond.
With tools like RegDesk, that shift from reactive to proactive is achievable; turning standards compliance from a source of audit anxiety into a built-in competitive advantage.
Q&A
Q: Why is medical device standards management more complex in 2026 than in previous years?
A: Several simultaneous standards developments have created an unusually demanding monitoring environment in 2026. ISO 13485 is currently under review, with changes related to the ISO Harmonized Structure and AI integration expected to be considered at the next review cycle. IEC 62304 Edition 2 is actively under development, introducing a simplified safety classification system, expanded scope covering all health software and AI/ML systems, and new AI development lifecycle provisions. ISO 14971 was reviewed and confirmed stable in March 2025 with no changes; providing a stable baseline, but manufacturers still need to monitor its interaction with the evolving IEC 62304 framework. And the FDA’s QMSR, effective February 2, 2026, creates an explicit regulatory dependency between ISO 13485 version currency and U.S. QMS compliance. Managing all of these simultaneously across multiple product lines and global markets: requires structured, automated standards tracking.
Q: What is IEC 62304 Edition 2 and how will it affect my medical device software compliance?
A: IEC 62304 Edition 2 is a major revision to the medical device software lifecycle standard, currently under active development. Key changes include a simplified two-level safety classification system (replacing the existing three-class system), an expanded scope that covers all health software; not just formally regulated medical devices and new provisions for AI/ML development including a defined AI development lifecycle. The revision also emphasizes “harm” in a broader sense aligned with ISO 14971:2020, separates development versus maintenance activities more clearly, and removes redundant QMS clauses, shifting general QMS obligations to ISO 13485. Companies developing SaMD, digital health tools, or AI-enabled devices should begin gap-assessing their software lifecycle documentation against Edition 2 requirements now; particularly regarding the expanded scope, which may bring previously out-of-scope products into the standard’s formal requirements.
Q: What do auditors specifically look for in a standards management system?
A: Auditors expect one coherent traceable story; not a collection of independently managed documents. They want to see a live matrix that connects requirement to risk, design input, verification, labeling, and complaint; training auto-enrolled when SOPs update; CAPAs auto-created from repeat non-conformity trends; owners notified when standards change; and outdated templates revoked so “old” forms cannot be used in active submissions. Specific audit expectations include traceability linking each applied standard to relevant product files and test reports; formal impact assessments for standard revisions or withdrawals; evidence of ongoing monitoring (not last-minute updates); internal SOPs for standard evaluation and approval; and regional consistency documentation where global submissions apply different standards. For software devices, auditors expect the IEC 62304 Software Development Plan to be visibly integrated into the ISO 13485 Design and Development Plan, with every software risk tied back to the ISO 14971 risk file.
Q: How does the FDA’s QMSR affect standards management obligations?
A: The FDA’s Quality Management System Regulation (QMSR), effective February 2, 2026, formally aligns U.S. quality system requirements with ISO 13485:2016. This creates a direct, explicit dependency between ISO 13485 version currency and FDA compliance that did not previously exist in the same form. Manufacturers whose quality system documentation references an earlier version of ISO 13485, or whose supplier audit records do not reflect QMSR scope requirements, face a specific non-conformity risk at FDA inspection. Practically, this means standards version tracking, previously a quality best practice, is now a regulatory requirement. Any standards management system that does not explicitly track ISO 13485 version currency and its interaction with QMSR is leaving a compliance gap.
Q: How many standards does a typical medical device company need to track, and how should they prioritize?
A: The core medical device standards framework spans at least seven major areas: quality management (ISO 13485); risk management (ISO 14971); clinical and performance evidence (ISO 14155); usability and human factors (IEC 62366-1); information and symbols (ISO 15223-1, ISO 20417); safety and performance (IEC 60601 series, IEC 62304); and sterilization and biocompatibility (ISO 11135/11137, ISO 10993 series). For software and AI-enabled devices, cybersecurity standards (IEC 81001-5-1, ISO/IEC 27001) and the emerging EU AI Act-related standards framework add additional layers. Prioritization should be driven by risk; start with standards directly referenced in regulatory submissions, those flagged as “under revision” (currently ISO 13485 and IEC 62304 Edition 2), and those with explicit regulatory dependencies (ISO 13485 to QMSR). A centralized standards management platform that automatically flags status changes eliminates the need for manual prioritization and ensures nothing is missed across a complex portfolio.