Who We Serve: Business Model
Specification Developers
A specification developer designs the device, owns the label and answers for it in the market, while another company builds it. Outsourcing production does not outsource responsibility, and auditors look hardest at the points where the two companies meet. We help specification developers build a quality system that shows they are in control of a product they do not physically make.
Standards and Regulations to Know
- 21 CFR Part 807Establishment Registration, Device Listing and Premarket Notification (510(k))
- 21 CFR Part 820 (QMSR)Quality Management System Regulation
- ISO 13485Quality Management Systems for Medical Devices
- 21 CFR Part 803Medical Device Reporting
- 21 CFR Part 806Reports of Corrections and Removals
- ISO 14971Risk Management for Medical Devices
- MDSAPMedical Device Single Audit Program
Typical Regulatory Exposure
Under 21 CFR 807.20(a)(1), a firm that initiates or develops specifications for a device made by a second party registers and lists, and the QMSR names specification development among the functions of a manufacturer. Under 21 CFR 803, a firm that initiates specifications for devices made by a second party is a manufacturer for medical device reporting. Design controls, complaint handling, reporting decisions and corrections and removals stay with you, even when your contract manufacturer performs parts of the work under agreement.
Purchasing controls are where specification developers are tested most. ISO 13485 expects supplier evaluation and monitoring in proportion to risk, purchasing information that includes, where applicable, the supplier's agreement to notify you of changes before they are made, and verification of purchased product. Outsourcing and Purchasing is one of the six QMS areas in Compliance Program 7382.850, and a quality agreement should say who owns process validation, nonconformance disposition, complaint investigation, records and change approval.
Design transfer is the handoff that most often goes wrong. ISO 13485 Clause 7.3.8 expects design outputs to be verified as suitable for manufacturing before they become final production specifications, and when production sits at another company, the evidence of that transfer has to live in your design records as well as theirs. Later changes need the same care, because a change at the contract manufacturer can be a design change for you.
Where Audits Find Gaps
- 01
Quality Agreement Left Generic
The agreement copies a template and does not assign complaint investigation, reporting decisions, validation ownership or change approval for this specific product.
- 02
Design Records Held by the Manufacturer
Drawings, specifications and validation reports live only at the contract manufacturer, so the specification developer cannot produce its own design history on request.
- 03
Changes Discovered After the Fact
The contract manufacturer changed a material, process or sub-tier supplier, and the specification developer found out later through a complaint or an audit.
- 04
Complaints Forwarded but Not Owned
Complaints are passed to the contract manufacturer for investigation, and the specification developer never reviews the result or decides on reportability itself.
- 05
Transfer Without Evidence of Manufacturability
Production started before process validation and transfer reviews were complete, with no record showing the specifications were verified as suitable for manufacturing.
- 06
Supplier Monitoring by Certificate Only
The contract manufacturer's ISO 13485 certificate is the only evidence of control, with no audits, performance data or periodic reevaluation.
Relevant Standards and Regulations
- 21 CFR Part 807Establishment Registration, Device Listing and Premarket Notification (510(k))
- 21 CFR Part 820 (QMSR)Quality Management System Regulation
- ISO 13485Quality Management Systems for Medical Devices
- 21 CFR Part 803Medical Device Reporting
- 21 CFR Part 806Reports of Corrections and Removals
- ISO 14971Risk Management for Medical Devices
- MDSAPMedical Device Single Audit Program
Relevant Services
Supplier Audits and Supplier Controls
Risk-based supplier selection, quality agreements, monitoring and supplier audits that hold up under QMSR.
QMS Build for Startups (Phased)
A QMS built in phases for a device startup: design controls and risk first, the rest before you need it.
AI-Assisted QMS Gap Assessment
An AI-assisted first pass over the QMS documents you already have, with every result reviewed by an advisor.
FDA Inspection Readiness (CP 7382.850)
FDA device inspection preparation built around Compliance Program 7382.850 and its risk-based approach.
Submission Readiness (510(k), De Novo, PMA, Pre-Sub, 513(g))
The design, risk and V&V evidence behind a 510(k), De Novo or PMA, organized and gap-checked.
Audits and Inspections You May Face
FDA Baseline Surveillance Inspection
FDA's comprehensive surveillance inspection of your quality system under Compliance Program 7382.850.
Supplier Audit
Audits you perform of your own suppliers and contract manufacturers as part of purchasing controls.
ISO 13485 Certification Audit (Stage 1 and Stage 2)
The Stage 1 and Stage 2 audits a certification body runs before granting ISO 13485 certification.
Questions
We outsource all manufacturing. What do we still have to do ourselves?
You keep responsibility for the device: design controls, risk management, purchasing controls over the manufacturer, complaint handling, reporting decisions and corrections and removals. Your contract manufacturer can perform some tasks under a quality agreement, but the decisions and the records showing you made them stay with you.
Do specification developers have to register with FDA?
Yes. Under 21 CFR 807.20(a)(1), a firm that initiates or develops specifications for a device manufactured by a second party registers and lists. Your contract manufacturer has its own registration obligations for the activities it performs.
How do we make sure our contract manufacturer tells us about changes?
Write it into the purchasing and quality agreements: which changes need notice, how far in advance and who approves them. ISO 13485 expects purchasing information to include, where applicable, the supplier's agreement to notify you of changes before they are made. Then check it during supplier audits.
Specification Developers
Get an Advisor's View of Your Quality System
Tell us about your devices and the audit or inspection ahead, and an advisor will scope an assessment for your kind of product. Please don't send confidential documents yet: secure upload is set up after onboarding.


