MedDeviceGuideMedDeviceGuide
Back

QMSR Supplier Quality Agreements for Cloud, AI, Cybersecurity, and Test Vendors

Draft QMSR supplier quality agreements for cloud, AI, cybersecurity, testing, and sterilization vendors with audit, CAPA, change notice, and evidence clauses.

Ran Chen
Ran Chen
Global MedTech Expert | 10× MedTech Global Access
Published 2026-05-05Last reviewed 2026-05-0518 min read

What This Article Covers / Does Not Cover

This article covers one document: the supplier quality agreement (SQA) that a medical device manufacturer must execute with critical outsourced vendors under FDA QMSR (21 CFR Part 820, effective 2 February 2026, incorporating ISO 13485:2016 by reference) and ISO 13485 Clause 7.4. It provides clause-by-clause construction guidance for five vendor categories that are increasingly critical in 2026: cloud hosting providers, AI model/data vendors, penetration testing firms, ASCA/non-ASCA test laboratories, and sterilization vendors.

It includes a vendor-type-to-clause matrix, sample clause language (clearly labeled as illustrative), a change notification decision tree, common auditor objections with responses, and a pre-audit evidence checklist.

This article does not cover general supplier evaluation, selection, or ranking methodology. For supplier audit checklists, see Supplier Audit Checklist. For third-party vendor cybersecurity risk management, see Medical Device Third-Party Vendor Cybersecurity Risk Management. For QMSR transition details, see QSR to QMSR Transition. For general QMS gap analysis, see QMSR Gap Analysis ISO 13485 Checklist.


Regulatory Basis

QMSR (effective 2 February 2026) incorporates ISO 13485:2016 by reference into 21 CFR Part 820. The purchasing control requirements in ISO 13485 Clause 7.4 now have the force of US federal law. Key provisions:

ISO 13485 ClauseRequirementSQA Relevance
4.1.5Control of outsourced processes — retain responsibilityDefines scope of outsourced activities in SQA
7.4.1Purchasing process — evaluate, select, monitor suppliersBasis for vendor qualification and ongoing monitoring
7.4.2Purchasing information — describe product, requirementsSQA must describe requirements for approval, procedures, processes, equipment
7.4.3Verification of purchased productDefines acceptance criteria and verification activities
7.5.9TraceabilitySQA must ensure traceability of components/services
8.2.3Feedback / complaint handlingSQA must include complaint cooperation clauses
8.5.2Corrective actionSQA must include CAPA cooperation clauses
8.5.3Preventive actionSQA should include proactive risk communication

Additionally, FDA Section 524B (cyber devices) and the updated FDA cybersecurity guidance (February 2026) require manufacturers to extend cybersecurity oversight to third-party software, cloud, and service components. MITRE's April 2026 publication on cybersecurity risk analysis for medical devices explicitly addresses shared security responsibilities for cloud and AI/ML vendors.


Vendor Classification and SQA Requirement Matrix

Not every vendor needs a full quality agreement. Use this classification to determine SQA depth:

Vendor TypeRisk LevelQMS Certificate RequiredQuality Agreement RequiredAudit FrequencyISO 13485 Clause Basis
Cloud hosting (IaaS/PaaS/SaaS for device data, AI inference)Critical (A)ISO 27001, SOC 2 Type IIFull SQAAnnual (remote or on-site)7.4.1, 7.4.2, 4.1.5
AI model/data vendor (training data, annotation, model hosting)Critical (A)ISO 27001 desirableFull SQAAnnual7.4.1, 7.4.2
Penetration testing firmCritical (A)N/A (competency-based)Scoped SQAPer engagement7.4.1, 7.4.2
ASCA-accredited test labCritical (A)ISO/IEC 17025 + ASCAScoped SQAPer engagement + accreditation monitoring7.4.1, 7.4.2, 7.4.3
Non-ASCA test labHigh (B)ISO/IEC 17025Scoped SQAPer engagement7.4.1, 7.4.2, 7.4.3
Contract sterilization vendorCritical (A)ISO 13485, ISO 11135/11137/17665Full SQAAnnual on-site7.4.1, 7.4.2, 7.4.3, 4.1.5
Raw material supplierHigh (B)ISO 9001 or ISO 13485Abbreviated SQA or PO termsBiennial7.4.2
General office supplies, non-critical servicesLow (D)N/APurchase order termsN/A7.4.2 (minimal)

Recommended Reading
OEM vs Independent Ultrasound Service Provider: A Due Diligence Decision Tool
ISO 13485Quality Systems2026-08-05 · 15 min read

Clause-by-Clause Construction Guide

The following sections provide the specific clauses to include in an SQA for each critical vendor type. Language is illustrative — adapt to your organization's templates.

Clause 1: Scope and Outsourced Activities

Purpose: Define exactly what the vendor does that affects device quality, safety, or cybersecurity. Per ISO 13485 Clause 4.1.5, the manufacturer retains full regulatory responsibility for outsourced processes.

Vendor TypeWhat to Specify
Cloud hostingHosting environment for [device data / AI inference / QMS software]; uptime SLA; data residency; encryption at rest and in transit; backup and disaster recovery; network segmentation
AI model/data vendorTraining data curation, labeling/annotation services, model training and validation, model hosting/API access, data provenance tracking
Penetration testingScope of testing (device firmware, companion app, cloud APIs, network protocols); testing methodology; deliverables (report format, vulnerability classification); safety constraints during testing
Test lab (ASCA/non-ASCA)Standards to be tested against; test plan approval process; sample handling; report format (ASCA Summary Test Report if applicable); timeline
Sterilization vendorSterilization method; cycle parameters; biological indicator specifications; load configuration; release criteria; residue testing

Illustrative language:

"This Quality Agreement applies to the following outsourced activities performed by [Vendor Name] on behalf of [Manufacturer Name]: [specific activities]. [Manufacturer Name] retains full regulatory responsibility for these outsourced activities as required by ISO 13485:2016 Clause 4.1.5 and 21 CFR Part 820 (QMSR)."

Clause 2: Regulatory Compliance and Certifications

Purpose: Document the vendor's applicable certifications and regulatory status.

Vendor TypeRequired CertificationsVerification Method
Cloud hostingISO 27001, SOC 2 Type II, HIPAA BAA (if PHI involved)Certificate copies; annual renewal monitoring
AI model/data vendorISO 27001 desirable; GDPR compliance (if EU data)Attestation; DPA (Data Processing Agreement)
Penetration testingIndustry certifications (CREST, OSCP, CEH for testers); no ISO requirementResume/CV of assigned testers; methodology statement
ASCA labISO/IEC 17025:2017 with ASCA-specific scope addendum; FDA ASCA accreditation letterVerify on FDA ASCA accreditation list before each submission; monitor for status changes
Non-ASCA labISO/IEC 17025:2017Certificate copy; accreditation body verification
Sterilization vendorISO 13485:2016; applicable sterilization standard certificationCertificate copies; annual renewal monitoring

Illustrative language:

"[Vendor Name] shall maintain the following certifications and accreditations: [list]. [Vendor Name] shall notify [Manufacturer Name] within [5 business days] of any change in certification status, scope, or accreditation, including suspension, withdrawal, or voluntary relinquishment."

Clause 3: Change Notification

Purpose: Ensure the vendor notifies the manufacturer before implementing changes that could affect product quality, safety, cybersecurity, or regulatory status.

Decision tree for change notification:

VENDOR PROPOSED CHANGE
│
├─► Does the change affect product quality, safety, or cybersecurity?
│    ├─ YES → Requires written notification [X days] before implementation
│    │    ├─ Does the change affect device specifications or intended use?
│    │    │    ├─ YES → Requires manufacturer written approval before implementation
│    │    │    └─ NO → Notification only; manufacturer has [X days] to object
│    │    └─ Does the change affect the vendor's certification/accreditation?
│    │         ├─ YES → Immediate notification; manufacturer re-evaluates vendor
│    │         └─ NO → Proceed with standard change notification
│    └─ NO → No notification required; document in vendor's internal change log

Vendor-specific change triggers:

Vendor TypeChanges Requiring NotificationNotification Timeline
Cloud hostingData center relocation; infrastructure platform upgrade; security control changes; sub-processor changes; encryption protocol changes; SLA changes; data residency changes30 days prior
AI model/data vendorTraining data source changes; labeling methodology changes; model architecture changes; API changes; sub-contracting of data processing30 days prior
Penetration testingPersonnel changes (lead tester); methodology changes; tool changesPer engagement
ASCA/non-ASCA labAccreditation status changes; scope changes; equipment relocation; key personnel changes; test method modificationsImmediate for accreditation; 30 days for others
Sterilization vendorProcess parameter changes; equipment changes; biological indicator supplier changes; facility relocation; cycle modifications30 days prior; immediate for any parameter OOS

Illustrative language:

"[Vendor Name] shall not implement any change that could affect the quality, safety, efficacy, or regulatory compliance of the outsourced services without prior written notification to [Manufacturer Name]. Changes requiring notification include but are not limited to: [list from table above]. [Manufacturer Name] shall have [15 business days] from receipt of notification to provide written approval, objection, or request for additional information."

Clause 4: Vulnerability and Security Incident Notification

Purpose: For cloud, AI, and cybersecurity vendors, define how and when security vulnerabilities and incidents are reported.

Notification TypeTimelineContent RequiredEscalation
Critical vulnerability (CVSS 9.0+) affecting the device24 hours of discoveryCVE ID (if available); affected components; exploitability assessment; interim mitigations; estimated remediation timelineImmediate — manufacturer PSIRT activated
High vulnerability (CVSS 7.0-8.9)72 hoursSame as aboveManufacturer risk assessment within 5 business days
Security incident involving device data or systems24 hours of detectionIncident description; data affected; containment measures; root cause (when known)Manufacturer incident response team activated
Sub-processor security event5 business daysDescription; impact assessment; remediationManufacturer re-evaluates vendor risk

Illustrative language:

"[Vendor Name] shall notify [Manufacturer Name] within [24 hours] of becoming aware of any security vulnerability rated CVSS 7.0 or above that affects the services provided under this Agreement, or any security incident involving [Manufacturer Name]'s data or systems. Notification shall include: vulnerability description and CVSS score, affected components, known exploitability, interim compensating controls, and estimated remediation timeline. [Manufacturer Name] reserves the right to invoke its Product Security Incident Response Team (PSIRT) process and to coordinate public disclosure timing in accordance with its coordinated vulnerability disclosure policy."

For more on vulnerability triage, see SBOM-to-VEX Vulnerability Triage Workflow.

Clause 5: Audit Rights

Purpose: Reserve the manufacturer's right to audit the vendor's facilities, processes, and records.

Vendor TypeAudit TypeFrequencyScope
Cloud hostingRemote audit (SOC 2 report review + questionnaire)AnnualSecurity controls, data handling, access management, encryption, incident response
AI model/data vendorRemote or on-siteAnnualData handling, labeling quality, model version control, access management
Penetration testingReport review + methodology assessmentPer engagementTester qualifications, methodology compliance, report quality
ASCA/non-ASCA labOn-site (for critical tests) or remoteAs neededCalibration records, test procedures, personnel qualifications, sample handling
Sterilization vendorOn-siteAnnualCycle parameters, validation records, biological indicators, environmental monitoring

Illustrative language:

"[Manufacturer Name] reserves the right to audit [Vendor Name]'s facilities, processes, records, and sub-contractors relevant to the outsourced activities described in this Agreement. Audits may be conducted with [30 days] prior written notice for scheduled audits, or without prior notice in the event of a quality or safety concern. [Vendor Name] shall provide reasonable access to relevant personnel, documentation, and systems during audits. Audit findings shall be addressed through [Vendor Name]'s corrective action process, with responses provided to [Manufacturer Name] within [15 business days] of audit report issuance."

Clause 6: CAPA Cooperation

Purpose: Define how the vendor participates in the manufacturer's corrective and preventive action process.

CAPA TriggerVendor ResponsibilityTimeline
Nonconformance in vendor-supplied service/productParticipate in root cause analysis; implement corrective actions; provide effectiveness evidenceRCA within 15 business days; CA within 30 business days
Complaint traceable to vendor component/serviceProvide relevant records (batch records, test data, access logs, change logs); participate in investigationResponse within 10 business days
Audit finding at vendorImplement corrective actions per agreed timeline; provide objective evidence of closurePer audit report
Recalls or field safety corrective actions involving vendor componentProvide traceability data; support investigation; cooperate with regulatory submissionsImmediate

Illustrative language:

"In the event that a nonconformance, complaint, or adverse event is attributable to or involves the services provided by [Vendor Name], [Vendor Name] shall cooperate fully with [Manufacturer Name]'s investigation and CAPA process. This includes providing relevant records, participating in root cause analysis, implementing agreed corrective actions, and providing objective evidence of effectiveness. [Vendor Name] shall respond to SCARs (Supplier Corrective Action Requests) within [15 business days]."

Clause 7: Records and Documentation

Purpose: Define what records the vendor must maintain and make available.

Vendor TypeRecords to MaintainRetention Period
Cloud hostingUptime logs, access logs, security incident logs, change logs, backup verification records, SOC 2 reportsMinimum 10 years (aligned with MDR Art. 10(15))
AI model/data vendorTraining data provenance records, labeling quality metrics, model version history, data processing logsMinimum 10 years
Penetration testingTest plans, test reports, vulnerability findings, remediation verificationMinimum 10 years
Test labTest plans, raw data, test reports, calibration records, equipment logs, personnel qualification recordsMinimum 10 years or per regulatory requirement
Sterilization vendorCycle records, biological indicator results, environmental monitoring, equipment calibration, validation recordsMinimum 10 years or per regulatory requirement

Clause 8: Sub-Contracting and Sub-Processing

Purpose: Control the vendor's use of sub-contractors who may affect product quality.

Illustrative language:

"[Vendor Name] shall not sub-contract any portion of the outsourced activities described in this Agreement without prior written approval from [Manufacturer Name]. Where sub-contracting is approved, [Vendor Name] shall: (a) ensure the sub-contractor meets equivalent quality and regulatory requirements, (b) maintain a quality agreement or equivalent controls with the sub-contractor, (c) remain fully responsible for the sub-contractor's performance, and (d) notify [Manufacturer Name] of any sub-contractor changes. For cloud hosting services, [Vendor Name] shall maintain a current list of sub-processors and notify [Manufacturer Name] of additions or changes at least [30 days] before they take effect."


Common Auditor Objections and How to Address Them

#Auditor ObjectionWhy It's RaisedHow to AddressEvidence to Provide
1"No quality agreement with cloud hosting vendor"Cloud vendors often resist SQAs; manufacturer relied on standard terms of serviceExecute SQA even if vendor pushes back. Use SOC 2 Type II report + manufacturer risk assessment as bridge documentation if vendor refuses formal SQA. Escalate to vendor's compliance team — major cloud providers (AWS, Azure, GCP) have established SQA frameworks for regulated industries.SQA; SOC 2 Type II report; manufacturer risk assessment; correspondence documenting SQA negotiation
2"Quality agreement does not address cybersecurity/vulnerability notification"Legacy SQAs were written for physical component suppliersAdd Clause 4 (vulnerability notification) per above. Include CVSS thresholds, notification timelines, and PSIRT coordination.Updated SQA; PSIRT procedure reference; SBOM linkage documentation
3"No audit rights clause for AI data vendor"Manufacturer assumed standard PO terms were sufficient for data vendorsAdd audit rights clause. If vendor refuses on-site, negotiate remote audit rights plus annual questionnaire + SOC 2 report review.SQA with audit clause; annual vendor questionnaire; risk assessment
4"Change notification clause is too vague — 'material changes' is undefined"Generic language does not meet ISO 13485 Clause 7.4.2 specificityEnumerate specific change triggers per vendor type (see Clause 3 table above). Avoid undefined terms like "material."Updated SQA with enumerated change triggers
5"No evidence of monitoring ASCA lab accreditation status"Manufacturer assumed ASCA accreditation was permanentAdd clause requiring vendor to notify of accreditation changes. Independently verify on FDA ASCA list before each submission. For ASCA-specific evidence package guidance, see FDA ASCA Test Report Acceptance Package.SQA with accreditation notification clause; FDA ASCA list verification records (screenshots with dates)
6"Sterilization vendor SQA does not reference current validation status"SQA was written before initial validation; never updated to reference revalidationInclude clause requiring vendor to maintain current validation status and notify manufacturer of revalidation schedule and results.Updated SQA; validation report references; revalidation schedule
7"CAPA cooperation clause missing from pen-test firm SQA"Pen-test firms viewed as one-time service providersEven per-engagement vendors need CAPA cooperation clauses. Findings from pen-test may require re-testing after remediation.SQA with CAPA clause; pen-test report remediation verification records
8"Records retention period in SQA shorter than regulatory requirement"Vendor's standard retention policy (e.g., 3-5 years) conflicts with medical device requirements (minimum 10 years under MDR)Specify minimum 10-year retention. For US-only devices, specify per 21 CFR 820 requirements.Updated SQA; vendor record retention policy; gap analysis if vendor cannot meet requirement

Pre-Audit Evidence Checklist

Before your next FDA inspection or ISO 13485 surveillance audit, verify the following for each critical vendor:

  • SQA executed: Quality agreement signed by both parties, current version

  • Scope defined: Outsourced activities clearly enumerated per ISO 13485 Clause 4.1.5

  • Certifications current: Vendor certification copies on file; expiration dates tracked; renewal monitoring in place

  • Change notification clause: Specific change triggers enumerated per vendor type; notification timeline defined

  • Vulnerability notification clause (cloud/AI/cybersecurity vendors): CVSS thresholds, timelines, PSIRT coordination defined

  • Audit rights clause: Reserved in SQA; audit schedule defined; last audit report on file

  • CAPA cooperation clause: SCAR process defined; response timelines specified; last SCAR on file with closure evidence

  • Records clause: Retention period specified (minimum 10 years); record types enumerated; access guaranteed

  • Sub-contracting clause: Prior approval required; sub-contractor list maintained; quality controls specified

  • ASCA accreditation verification (test labs): Verified on FDA ASCA list within last 30 days; status change notification clause in SQA

  • Annual vendor review: Vendor performance review completed per ISO 13485 Clause 7.4.1; documented in QMS

  • Risk assessment: Vendor risk classification documented; controls commensurate with risk level


Recommended Reading
MedDeviceRepair: Keeping Loaner Exchanges Traceable When Serial Numbers Change
Post-Market SurveillanceLabeling & UDI2026-09-10 · 22 min read

Sample SQA Template Structure

For those building from scratch, use this section order:

  1. Parties and Effective Date

  2. Scope of Outsourced Activities (Clause 4.1.5 reference)

  3. Regulatory Framework (ISO 13485, QMSR, FDA Section 524B where applicable)

  4. Vendor Certifications and Qualifications

  5. Requirements and Specifications (product/service specifications per Clause 7.4.2)

  6. Change Notification (enumerated triggers, timelines, approval requirements)

  7. Vulnerability and Security Incident Notification (for cloud/AI/cybersecurity vendors)

  8. Verification and Acceptance (Clause 7.4.3 — how manufacturer verifies purchased product/service)

  9. Audit Rights (scheduled, unscheduled, remote, on-site)

  10. CAPA Cooperation and Complaint Handling

  11. Records and Documentation (types, retention, access)

  12. Sub-Contracting and Sub-Processing Controls

  13. Confidentiality and Data Protection

  14. Term, Termination, and Transition (data return/destruction upon termination)

  15. Dispute Resolution

  16. Signatures and Date


Key Regulatory References

ReferenceDescription
21 CFR Part 820 (QMSR)FDA Quality Management System Regulation, effective 2 February 2026
ISO 13485:2016 Clause 7.4Purchasing controls — evaluation, purchasing information, verification
ISO 13485:2016 Clause 4.1.5Control of outsourced processes
FDA Section 524BCybersecurity requirements for cyber devices
FDA Cybersecurity Guidance (February 2026)Premarket cybersecurity, aligned with QMSR/ISO 13485
MITRE (April 2026)Cybersecurity Risk Analysis for Medical Devices in the Era of Evolving Technologies
ISO/IEC 17025:2017General requirements for competence of testing and calibration laboratories
FDA ASCA ProgramAccreditation Scheme for Conformity Assessment
ISO 11135:2014Ethylene oxide sterilization
ISO 11137 seriesRadiation sterilization
ISO 17665:2006Moist heat sterilization
MDR Article 10(15)Record retention requirements (minimum 10 years)