Supplier Qualification

Supplier qualification is the documented process a medical device manufacturer uses to evaluate, approve, and monitor suppliers of components, materials, and outsourced services. It applies risk-based criteria, objective evidence of capability, and ongoing performance monitoring so that the purchased product consistently meets specified requirements under ISO 13485:2016 clause 7.4 and the FDA Quality Management System Regulation.


What is supplier qualification?

Supplier qualification sits inside purchasing controls, the part of a quality management system (QMS) that governs anything a manufacturer buys rather than makes. It covers raw materials, machined parts, printed circuit board assemblies, sterile packaging, contract sterilization, calibration services, and software of unknown provenance (SOUP) used inside device firmware.

The manufacturer stays legally responsible for the finished device no matter how much work is outsourced. GHTF/SG3/N17:2008, the harmonized guidance on control of products and services obtained from suppliers, states that the entity holding QMS responsibility cannot contract it away.


Why supplier qualification matters in medical device development

Complaint investigations often end at a purchased item: a resin lot with a different additive package, a connector bought from a broker, a molder who quietly moved tooling. None of these show up in the final inspection. They show up in the field.

Regulators treat this as a first-order control. Since February 2, 2026, the purchasing controls that sat in 21 CFR 820.50 come from ISO 13485 clause 7.4, incorporated by reference into 21 CFR Part 820 under the FDA Quality Management System Regulation (QMSR). The QMSR also gives FDA authority to inspect supplier audit reports, which the old QS regulation exempted. In Europe, Article 10(9) of EU MDR 2017/745 requires the QMS to cover resource management, including selection and control of suppliers and subcontractors, and notified bodies’ audit that controls during Annex IX assessment.

A supplier that fails qualification late in a program forces requalification, revalidation, and a delayed submission, at a cost that early diligence never carries.


The supplier qualification process

Qualification is a sequence, not a single event. A workable process usually runs like this:

  • Define what is purchased and how it affects the device. Link each item to design outputs and to the ISO 14971:2019 risk file.
  • Tier suppliers by risk. Suppliers whose parts influence safety or essential performance get the deepest scrutiny. Write down the tier rationale.
  • Set evaluation criteria before evaluating. ISO 13485 clause 7.4.1 requires documented criteria for selection, evaluation, and re-evaluation, based on the supplier’s effect on product quality and on device risk.
  • Gather objective evidence. Certifications, a quality questionnaire, capacity data, regulatory history, and, for critical suppliers, an on-site audit.
  • Qualify the output, not just the company. First article inspection, material verification, sample lots, PPAP, and process validation (IQ/OQ/PQ) where the supplier runs a special process, per ISO 13485 clause 7.5.6.
  • Execute a quality agreement. Scope, specifications, change notification duties, subtier control, record retention, and right of audit.
  • Add the supplier to the approved supplier list (ASL) with an explicit scope. Approved for one part number is not approved for all.
  • Verify incoming product. Clause 7.4.3 requires verification proportionate to risk: inspection, certificate of analysis review, or a validated skip-lot scheme.
  • Monitor and re-evaluate on a defined cycle. Score on-time delivery, nonconformance rate, and change-notification compliance. Feed issues into supplier corrective action requests (SCARs) and into CAPA where warranted.

Software supply chains follow the same logic through different clauses. IEC 62304:2006+A1:2015 requires SOUP components to be identified and their anomaly lists reviewed. IEC 81001-5-1 extends cybersecurity duties to third-party software.


Common challenges and best practices

The most common finding is not a missing qualification file. It is a missing monitoring record. Teams onboard a supplier, file a thick approval package, then produce nothing afterward. Re-evaluation under clause 7.4.1 is a standing obligation.

Second failure: certificate substitution. An ISO 13485 certificate tells you a supplier holds a QMS. It says nothing about whether that supplier can hold a tolerance on your part or whether your part sits inside their certified scope. Read the scope statement, then verify.

Third: unmanaged subtier risk. Your molder’s resin distributor is your problem. Quality agreements should require notification of subtier changes, and critical material sources should be named.

Good practice is boring and consistent. Tier on risk. Audit the tier that matters. Keep the ASL current. Treat a supplier change notification as a change control input, because a supplier-initiated change can invalidate a validation the manufacturer owns.


How SJML helps with supplier qualification

Syrma Johari MedTech runs supplier qualification across its manufacturing and QARA practice. On the manufacturing side, that covers supply-chain resilience, dual sourcing, obsolescence management, and qualification tied into process validation (IQ/OQ/PQ), PPAP, PFMEA, and BOM review, with SAP-integrated MES supporting traceability. On the compliance side, SJML supports supplier audits, ISO 13485 and MDSAP quality system work, and ISO 14971 risk files as part of regulatory sustenance. Teams building or remediating a purchasing-control program can use these together rather than across separate vendors.

Talk to SJML’s QARA team →


Frequently asked questions

What is the difference between supplier qualification and supplier approval?

Qualification is the evaluation activity: assessing capability, auditing, verifying samples, and confirming a supplier can meet requirements. Approval is the decision that follows, recorded by adding the supplier to the approved supplier list with a defined scope. A supplier may be qualified for one component and approved only for that component, not a broader category.

Does a supplier need ISO 13485 certification to be qualified?

No. ISO 13485 certification is useful evidence but is not required by ISO 13485 clause 7.4 or the FDA QMSR. Many machining, molding, and electronics suppliers hold only ISO 9001. What matters is that the manufacturer sets risk-based criteria, gathers evidence against them, and applies controls sufficient for the risk the purchased item carries.

How often should suppliers be re-evaluated?

There is no fixed regulatory interval. ISO 13485 clause 7.4.1 requires re-evaluation on documented criteria, so the cycle follows risk. Critical suppliers are commonly reviewed annually with periodic on-site audits, while low-risk commodity suppliers may be reviewed less often. What auditors check is that the stated cycle exists, is justified, and has actually been followed.

What changed for supplier controls under the FDA QMSR?

The QMSR took effect on February 2, 2026, and amended 21 CFR Part 820 to incorporate ISO 13485:2016 by reference. Purchasing controls formerly written in 21 CFR 820.50 now come from ISO 13485 clause 7.4. Procedures citing the old section numbers need updating, and ongoing supplier monitoring is now an explicit rather than implied obligation.


Related terms

  • Purchasing Controls
  • Quality Agreement
  • Process Validation
  • Change Control
  • Corrective and Preventive Action (CAPA)

Table of Contents

Free EU MDR Technical Documentation Compliance Checklist

Understand documentation gaps and use our single-window worksheet to prepare for Notified Body review.

Related Glossaries

Ask Sygma AI

AI-Powered Assistant

SJ Assistant