Gap analysis is a structured QARA method that compares a medical device organization’s current quality system, technical documentation, or processes against the requirements of a target standard or regulation, such as ISO 13485, EU MDR 2017/745, or the FDA QMSR, to identify deficiencies that must be closed before compliance is achieved.
What is gap analysis?
In medical device work, a gap analysis is a systematic assessment that measures where you are against where a regulation or standard says you need to be. The “gap” is the difference between your documented and implemented state and the required state. The output is not just a list of problems. It is a prioritized set of actions, owners, and evidence needed to reach conformity.
Gap analysis sits at several points in the device lifecycle: before a new market submission, when a standard is revised, during quality system implementation, and after an acquisition. It applies to a full quality management system (QMS), a single technical file, a design history file (DHF), or a discrete process such as complaint handling or supplier control.
Why gap analysis matters in medical device development
Regulated device work leaves little room for guesswork. A missed requirement can surface as an FDA Form 483 observation, a notified body nonconformity, a delayed CE certificate, or a blocked market entry. Each of those carries cost, lost revenue, and patient-safety exposure.
Two recent shifts make the technique especially active. The FDA QMSR took effect on February 2, 2026, and it incorporates ISO 13485:2016 by reference into 21 CFR Part 820, with the legacy subparts reserved. Manufacturers that built their systems around the old Quality System Regulation now have to confirm coverage against ISO clauses plus the FDA overlay. In Europe, EU MDR 2017/745 remains the governing law, and mandatory EUDAMED registration is phasing in during 2026. Both transitions start with the same first step: a documented gap analysis.
Catching a gap early is far cheaper than remediating it under a nonconformity clock or a warning letter. It also gives leadership a defensible, evidence-based view of readiness rather than a hopeful one.
How gap analysis works
A sound gap analysis follows a repeatable sequence. The exact steps scale with scope, but the structure holds.
- Define the scope and baseline. State the target requirement set (for example, ISO 13485:2016, EU MDR Annex I, or IEC 62304) and what you are assessing against it: a QMS, a technical file, or a single process.
- Build the requirement map. Break the standard into discrete, testable requirements. A clause-by-clause crosswalk works well, and for the QMSR transition, a QSR-to-ISO 13485 crosswalk is common.
- Gather objective evidence. Review procedures, records, design outputs, and risk files. Interview process owners. Confirmation comes from evidence, not from assurances that something is handled.
- Score each requirement. Mark each as met, partially met, or not met, with a note on what proof exists or is missing.
- Rate and prioritize the gaps. Weight findings by risk and regulatory consequence so critical items rise to the top.
- Build the remediation plan. Assign actions, owners, due dates, and the evidence that will close each gap.
Common frameworks referenced during this work include ISO 13485 for the QMS, ISO 14971 for risk management, IEC 62304 for the software lifecycle, IEC 62366-1 for usability, and EU MDR 2017/745 or IVDR 2017/746 for the applicable European requirements. Naming the exact clause behind every finding keeps the analysis auditable.
Common challenges and best practices
Teams often treat gap analysis as a documentation exercise and stop at whether a procedure exists. Auditors under the QMSR now look at how consistently procedures are implemented, so a paper-only review misses the real gaps. Check implementation and records, not just wording.
A second failure is vague findings. “Improve supplier controls” gives no one a way to act. A good finding names the clause, states the deficiency, and defines the evidence that will close it.
Scope creep is another trap. An unbounded review stalls. Fix the target requirement set and the assessed object up front, then hold that line.
Good practice looks like this: a single owner for the analysis, a clause-level requirement map, evidence attached to each score, risk-based prioritization, and a remediation plan with dates that feed directly into CAPA where appropriate. Reassess after major changes, whether that is a new standard edition, a new market, or a merger.
How SJML helps with gap analysis
Syrma Johari MedTech (SJML) runs gap analysis as part of its Compliance-as-a-Service offering. The QARA team assesses quality systems and technical documentation against ISO 13485, EU MDR and IVDR, the FDA QMSR, and MDSAP, then maps each finding to a clause and a remediation action. Support extends to DHF and technical file remediation, ISO 14971 risk files, and QMS build-out, with capabilities across Class I, II, and III devices. The aim is a clear, evidence-based path from the current state to conformity.
Frequently asked questions
Its purpose is to compare a manufacturer’s current quality system, technical file, or process against a target standard or regulation and identify what is missing before an audit or submission. The result is a prioritized, evidence-based remediation plan, which reduces the risk of nonconformities, FDA observations, and delayed market access.
Run one before a new regulatory submission, when a standard or regulation is revised, during QMS implementation, and after a merger or acquisition. The 2026 transitions to the FDA QMSR and EU MDR EUDAMED registration are common triggers, since each requires manufacturers to confirm coverage against updated requirements.
A gap analysis measures your system against a target requirement set to plan for a future state, often before you claim conformity. An internal audit checks an established system against its own procedures and applicable standards on a scheduled basis. Gap analysis is forward-looking and project-based, while internal audit is a recurring QMS control.
The reference set depends on the scope. Common anchors include ISO 13485 for the quality system, ISO 14971 for risk management, IEC 62304 for software, IEC 62366-1 for usability, and EU MDR 2017/745 or the FDA QMSR for jurisdiction-specific requirements. The chosen requirement set defines the baseline the assessment measures against.
Related terms
- ISO 13485
- FDA QMSR
- EU MDR
- CAPA
- Design History File (DHF)