Quality plans are project-specific documents that state which procedures, resources, records, and acceptance criteria apply to a particular device, process, or contract, and who is accountable for each. In medical device work, a quality plan connects one program’s activities to the manufacturer’s wider quality management system and to the planning requirements in ISO 13485:2016.
What is a quality plan?
A quality plan takes the general rules of a quality management system (QMS) and applies them to one specific case: a device program, a production line, a site transfer, or a customer contract. The QMS says how the organization works. The quality plan says how those rules get met for this thing, on this timeline, by these people.
ISO 10005:2018 is the international guidance document for establishing, reviewing, applying, and revising quality plans. It gives structure but sets no requirements. The binding hook sits in ISO 13485:2016 clause 7.1, planning of product realization, which requires manufacturers to document how product realization requirements are met and notes that this documentation may take the form of a quality plan. Clause 5.4.2 covers planning of the QMS itself, a separate activity.
Why a quality plan matters in medical device development
Device programs fail in the seams. Design hands off to manufacturing, a supplier changes a resin grade, a contract manufacturer runs a process the OEM never validated. A quality plan is where those handoffs get named, sequenced, and assigned before anyone starts building.
The regulatory stakes are direct. FDA’s Quality Management System Regulation, 21 CFR Part 820, took effect on February 2, 2026, and now incorporates ISO 13485:2016 by reference, so the clause 7.1 planning expectation carries US enforcement weight. EU MDR 2017/745 Article 10(9) requires a QMS covering product realization, including planning. Notified bodies and FDA investigators read planning records early, because a thin plan predicts thin execution downstream.
Cost follows. Teams that skip planning discover missing verification evidence during design transfer, when tooling is cut, and the schedule has no slack.
Key components of a medical device quality plan
Content varies by scope. A workable device quality plan usually addresses:
- Scope and objectives. Which device, process, or site the plan covers.
- Responsibilities. Named roles across design, quality, regulatory, and manufacturing, including who releases the device.
- Applicable procedures and records. Which SOPs and forms apply, and where deviations are allowed.
- Design and development controls. Phases, reviews, and design outputs, tied to ISO 13485:2016 clause 7.3.
- Risk management interface. How the plan links to the ISO 14971:2019 risk management file, and who updates it after design changes.
- Verification and validation. Test protocols, sample sizes, and the standards each test runs to, such as IEC 60601-1 for electrical safety or IEC 62366-1 for usability engineering.
- Supplier controls. Qualification status, incoming inspection, and change notification terms.
- Process validation. IQ, OQ, and PQ scope for processes whose output cannot be fully verified by inspection, plus PFMEA linkage.
- Inspection and acceptance criteria. In-process checks, release testing, and the criteria that trigger a nonconformance.
- Change control and CAPA routes. How changes are assessed for revalidation impact after baselining.
Software pulls in a parallel document. IEC 62304:2006+A1:2015 calls for a software development plan, which the quality plan should reference rather than duplicate. Same for the risk management and clinical evaluation plans: point to them, keep single sources of truth.
Common challenges and best practices
The most frequent failure is writing the plan for the auditor instead of the team. Plans that restate the quality manual in different words add no control. Plans that name a specific test, an acceptance limit, and an owner do.
Version drift is the second problem. A plan written at the concept phase and never revised through design transfer becomes evidence against the manufacturer: the record shows planned activities that visibly did not happen. Put it under document control and revise it at each phase gate.
Ownership is the third. Plans authored entirely by QA get ignored by engineering. Joint authorship works better, with QA owning approval rather than drafting.
Two habits separate teams that use their plans from teams that file them. Baseline before the first verification protocol executes. And when a supplier or CDMO performs part of the scope, state which organization holds each record. DHF completeness gaps trace back to that ambiguity.
How SJML helps with quality plans
Syrma Johari MedTech (SJML) works as an end-to-end medical device CDMO, operating under a certified ISO 13485 quality management system and aligned to FDA 21 CFR Part 820, EU MDR and IVDR, and MDSAP. Programs run through phase-gate management with structured change control, so planning documents stay current as a design moves from feasibility to design transfer. On the manufacturing side, SJML supports process validation (IQ, OQ, PQ), PFMEA, PPAP, supplier qualification, and NPI readiness reviews, with MES-based traceability across build records. QARA teams support DHF and technical file construction alongside the engineering work.
Frequently asked questions
ISO 13485:2016 clause 7.1 requires manufacturers to plan and document product realization processes, and a note in the clause states that this documentation can take the form of a quality plan. The standard does not mandate that exact title or format. What it mandates is documented planning covering objectives, requirements, verification activities, and acceptance criteria for the specific product.
A quality manual describes the quality management system as a whole: its scope, documented procedures, and process interactions. A quality plan applies that system to one specific case, such as a single device program or production line, and adds project-specific detail like schedules, owners, and acceptance limits. One is organizational and lasting; the other is scoped and time-bound.
Since February 2, 2026, 21 CFR Part 820 incorporates ISO 13485:2016 by reference, so the clause 7.1 planning requirement applies to finished device manufacturers distributing in the United States. FDA investigators can review planning records during inspection. The legacy quality planning language of the former Quality System Regulation no longer appears as separate regulatory text.
Joint authorship works best. Design, manufacturing, and regulatory contributors define the activities they will actually perform, while QA reviews the plan for QMS alignment and approves it. Plans written by QA alone describe generic controls rather than the program’s real verification and validation sequence, which weakens both the document and its value during audit.
Related terms
- Quality Management System (QMS)
- Design Controls
- Process Validation
- Change Control
- Acceptance Criteria