Who We Serve: Business Model
Contract Manufacturers and Component Suppliers
A contract manufacturer answers to many parties: each customer's quality agreement, each customer's auditors, a certification body and, for some activities, FDA. The quality system has to satisfy all of them without becoming a different system for each. We help contract manufacturers and component suppliers get there.
Standards and Regulations to Know
- ISO 13485Quality Management Systems for Medical Devices
- 21 CFR Part 820 (QMSR)Quality Management System Regulation
- 21 CFR Part 807Establishment Registration, Device Listing and Premarket Notification (510(k))
- ISO 9001General Quality Management Systems
- ISO 19011Guidelines for Auditing Management Systems
- MDSAPMedical Device Single Audit Program
Typical Regulatory Exposure
Device manufacturers are responsible for the products they place on the market, including the parts others make for them. Under the QMSR, purchasing controls expect customers to evaluate and control suppliers in proportion to risk, and Outsourcing and Purchasing is one of the six QMS areas in Compliance Program 7382.850. In practice, that responsibility reaches the supplier as audits, questionnaires, quality agreements and requests for records.
Registration and inspection obligations depend on what you do. A contract manufacturer of finished devices generally registers with FDA and is subject to the QMSR for the activities it performs, while a supplier of components generally does not register and is controlled through its customers. Contract sterilizers, packagers and other specific activities have their own considerations, so confirm your position against your actual operations.
Many device customers expect ISO 13485 certification from critical suppliers, and for firms subject to the QMSR, internal audit, management review and supplier audit records are now open to FDA inspection. The records customers, certification bodies and investigators see should tell one consistent story.
Where Audits Find Gaps
- 01
Quality Agreements That Leave Gaps
Agreements do not say who handles complaints, who approves changes, who owns process validation or when nonconformances must be reported, so each side assumes the other does it.
- 02
Changes Made Without Customer Notification
Process, material or sub-tier supplier changes went through internal change control without notifying the customers whose agreements require it.
- 03
Customer Requirements Lost in Translation
Customer specifications and special requirements are captured at contract review but never carried into work instructions, inspection plans and production records.
- 04
Sub-Tier Suppliers Approved but Not Monitored
Your own suppliers of materials and services were approved on paper but are not monitored, a question customer auditors ask more and more often.
- 05
Disposition Authority Unclear
Use-as-is and rework decisions are made without the customer approval the agreement requires, or without a record of who authorized them.
- 06
Audit Findings Answered Customer by Customer
Similar findings from different customer audits get separate responses, with no single CAPA addressing the shared root cause.
Relevant Standards and Regulations
- ISO 13485Quality Management Systems for Medical Devices
- 21 CFR Part 820 (QMSR)Quality Management System Regulation
- 21 CFR Part 807Establishment Registration, Device Listing and Premarket Notification (510(k))
- ISO 9001General Quality Management Systems
- ISO 19011Guidelines for Auditing Management Systems
- MDSAPMedical Device Single Audit Program
Relevant Services
Supplier Audits and Supplier Controls
Risk-based supplier selection, quality agreements, monitoring and supplier audits that hold up under QMSR.
ISO 13485 Certification Readiness
Prepare your QMS, records and people for a certification body's Stage 1 and Stage 2 audits.
Internal Audit Program
A risk-based internal audit program, run by your team or our advisors, with reports written for FDA to read.
CAPA System Remediation
Fixing a CAPA system auditors keep citing: the procedure, the records, root cause, effectiveness and backlog.
MDSAP Readiness
Prepare for one audit covering ISO 13485 and the country-specific requirements of participating regulators.
Audits and Inspections You May Face
Customer Audit
A customer's audit of your quality system, often a device maker auditing a supplier or contract manufacturer.
Supplier Audit
Audits you perform of your own suppliers and contract manufacturers as part of purchasing controls.
ISO 13485 Surveillance Audit
The periodic audits, at least annually, that support continued ISO 13485 certification between renewals.
FDA Baseline Surveillance Inspection
FDA's comprehensive surveillance inspection of your quality system under Compliance Program 7382.850.
Questions
Do we need to register with FDA as a contract manufacturer?
It depends on your activities. Contract manufacturers of finished devices generally register and list, component suppliers generally do not, and activities such as contract sterilization have their own considerations. Confirm your position with your regulatory team or counsel against what you actually do.
How can we prepare for customer audits without starting over each time?
Build one evidence base around the topics customers ask about most: quality agreements, change notification, process validation, supplier controls and CAPA. Keep it current in one place, and each customer audit becomes retrieval rather than reconstruction.
Is ISO 9001 enough for a component supplier?
It depends on what you supply and what your customers require. Some device customers accept ISO 9001 for lower-risk components and expect ISO 13485 for critical ones, so check your quality agreements and ask your key customers directly.
Contract Manufacturers and Component Suppliers
Get an Advisor's View of Your Quality System
Tell us about your devices and the audit or inspection ahead, and an advisor will scope an assessment for your kind of product. Please don't send confidential documents yet: secure upload is set up after onboarding.


