Certification and Market Access
MDSAP Readiness
The Medical Device Single Audit Program lets one audit by a recognized auditing organization cover the requirements of several regulators at once. We help you prepare the ISO 13485 base and the country-specific layers each participating regulator adds, so a single audit can do the work of several.
What You Receive
- 01Market Requirements Matrix
- 02Consultant-Reviewed Gap Findings
- 03Updated Reporting and Registration Procedures
- 04Readiness Review Report
Every finding is reviewed and approved by a qualified QMS advisor before it reaches you.
What It Is
MDSAP brings together the participating regulators: Australia's TGA, Brazil's ANVISA, Health Canada, Japan's MHLW and PMDA, and the US FDA. An auditing organization recognized under the program audits your QMS against ISO 13485:2016 and against the specific requirements of the regulators in whose markets you sell. The cycle has an initial certification audit, annual surveillance audits and a recertification audit.
The country-specific layer is where most firms are thin. Each regulator has its own expectations for market authorization and registration, adverse event and advisory notice reporting, and notifying the authority of changes. An MDSAP auditor follows a structured audit model and checks these requirements inside the processes they belong to, so a gap in one country's reporting rules surfaces in your complaint handling or change control, not in a separate chapter.
MDSAP nonconformities are graded, and the grade shapes what happens next, including whether the participating regulators are notified. For US firms there's another reason to care: FDA accepts MDSAP audit reports in place of routine surveillance inspections. That substitution doesn't cover for-cause inspections or pre-approval inspections, which FDA still conducts itself.
When You Need It
- You sell, or plan to sell, in more than one participating market and want one audit instead of several
- A regulator in a market you sell into expects an MDSAP certificate as part of market access
- You want an MDSAP audit report to stand in for routine FDA surveillance inspections
- You hold ISO 13485 certification and are adding MDSAP to your audit program
- A previous MDSAP audit produced graded nonconformities you need to close properly
- You've added a market and need its reporting and registration requirements built into your procedures
What We Do
- 01
Map Your Markets to Requirements
We start from where you sell and plan to sell, then list the regulator-specific requirements that apply to your devices. That list becomes the checklist the rest of the work is measured against.
- 02
Assess the ISO 13485 Base
An AI-assisted first pass over your documents checks the ISO 13485:2016 foundation, and an advisor reviews every result. Weak core processes produce findings in every jurisdiction at once, so they get fixed first.
- 03
Layer In Country-Specific Requirements
We check that complaint handling, adverse event reporting, advisory notices, registration and change notification procedures name each relevant authority, its reporting rules and the person in your organization who owns them.
- 04
Prepare Process Owners for the Audit Model
MDSAP auditors work through processes in a defined sequence and follow the links between them. We prepare process owners to explain their process, produce records and trace a complaint or a change across the system.
- 05
Run a Readiness Review
An advisor audits the system the way an MDSAP auditor would. Findings land in your action plan with severity, owners and due dates.
- 06
Support the Nonconformity Response
After the audit, we help you write corrections, root cause and corrective actions that answer each graded nonconformity with the evidence the auditing organization asked for.
Deliverables
Market Requirements Matrix
Each participating regulator relevant to you, its requirements, and the procedure or record that meets each one.
Consultant-Reviewed Gap Findings
Findings against ISO 13485:2016 and the country-specific requirements, with sources, severity and owners.
Updated Reporting and Registration Procedures
Redlines or new procedures for adverse event reporting, advisory notices and change notifications, organized by market.
Readiness Review Report
Readiness by process, with open items and what each needs to close.
How the Platform Helps
Findings Classified by Gap Type
Each finding is classified, for example missing procedure, procedure inadequate or insufficient evidence, so you can see whether a country gap is a writing problem or an execution problem.
One Action Plan Across Jurisdictions
Owners, due dates and evidence requirements in one plan sorted by severity, instead of a separate tracker per market.
CAPA Records for Graded Nonconformities
Correction, root cause, corrective action and effectiveness verification in one record, with an immutable activity history behind it.
Audits and Inspections It Prepares You For
MDSAP Audit
One audit by a recognized auditing organization that covers several participating regulators, including FDA.
ISO 13485 Certification Audit (Stage 1 and Stage 2)
The Stage 1 and Stage 2 audits a certification body runs before granting ISO 13485 certification.
ISO 13485 Surveillance Audit
The periodic audits, at least annually, that support continued ISO 13485 certification between renewals.
FDA Foreign Facility Inspection
FDA inspection of a manufacturer outside the US that makes devices for the US market.
Standards and Regulations in Scope
Questions About This Service
Which regulators participate in MDSAP?
The participating regulators are Australia's TGA, Brazil's ANVISA, Health Canada, Japan's MHLW and PMDA, and the US FDA. Your audit covers ISO 13485:2016 plus the specific requirements of the regulators in the markets where you sell.
Does an MDSAP audit replace FDA inspections?
FDA accepts MDSAP audit reports in place of routine surveillance inspections. It doesn't replace for-cause inspections or pre-approval inspections, which FDA can still conduct. Build your QMS to hold up to an FDA investigator regardless.
How is MDSAP different from an ISO 13485 certification audit?
The ISO 13485 requirements are the same base, but MDSAP adds each participating regulator's requirements, follows a structured audit model and grades nonconformities. A higher grade can lead to the regulators being notified. That makes country-specific reporting and registration procedures far more visible than in a standard certification audit.
What does the MDSAP audit cycle look like?
An initial certification audit, annual surveillance audits and a recertification audit. The country-specific scope changes as you enter or leave markets, so keep your requirements matrix current between audits.
We only sell in the US. Is MDSAP worth it?
It depends on your plans. With no other participating markets in view, the main benefit is the substitution for routine FDA surveillance inspections, in exchange for supporting an annual audit program. We can walk through the trade-off on an assessment call.
Request an Assessment
Discuss MDSAP Readiness With an Advisor
Tell us about your devices, your documents and your timeline, and an advisor will scope the work with you. Please don't send confidential documents yet: secure upload is set up after onboarding.


