An independent overview from DQS, a recognized MDSAP Auditing Organization.
The Medical Device Single Audit Program (MDSAP) is an international audit program that allows a single audit of a medical device manufacturer's quality management system to satisfy the regulatory requirements of multiple participating jurisdictions. It is based on ISO 13485 and supplemented by jurisdiction-specific regulatory requirements from the participating regulators. The MDSAP program is governed by the Regulatory Authority Council (RAC), the body representing the participating regulatory authorities. MDSAP audits are performed by recognized Auditing Organizations (AOs), such as DQS MED, which are authorized to audit medical device manufacturers under the MDSAP framework and issue MDSAP certificates following a positive certification decision.
MDSAP is relevant to medical device manufacturers that operate, or intend to operate, in at least one of the participating markets. Instead of undergoing separate inspections or audits by each regulator, a manufacturer hosts one MDSAP audit that produces an audit report accepted by each participating authority within its respective regulatory framework. The program is widely used by manufacturers seeking efficient, consistent quality-system oversight across multiple jurisdictions.
Five Regulatory Authorities currently participate as full members: the U.S. Food and Drug Administration (FDA), Health Canada, Brazil's ANVISA, Australia's Therapeutic Goods Administration (TGA), and Japan's MHLW/PMDA. Additional regulators engage as Official Observers (including the European Commission, the United Kingdom's MHRA, Singapore's HSA, and the WHO IVD Prequalification Programme) or as Affiliate Members. The audit model is defined by the MDSAP Audit Approach and a companion set of audit procedures and forms, all of which are maintained on an ongoing basis by the Regulatory Authority Council.
Terminology note: Throughout this article, the term Auditing Organization (AO) is used in accordance with the official MDSAP terminology and refers to organizations formally recognized under the MDSAP program to perform MDSAP audits and issue MDSAP certificates. The term certification body is used in its broader industry sense to describe organizations, such as DQS, that provide certification and conformity assessment services. Where MDSAP-specific activities are discussed, Auditing Organization should be regarded as the authoritative term.
Already have a quality management system based on ISO 13485?
If your organization is preparing for an MDSAP audit and is looking for a recognized Auditing Organization, our dedicated certification page has everything you need — from audit scope to a personalized quote.
What is MDSAP, from a certification body's perspective?
From a certification body's perspective, MDSAP is the international single-audit program through which an authorized Auditing Organization assesses a medical device manufacturer's quality management system against ISO 13485 and the specific regulatory requirements of up to five participating jurisdictions in one integrated audit. The audit is structured according to the MDSAP Audit Approach, associated audit tasks, and a non-conformity grading model, and it produces a final audit report and a non-conformity report (if applicable) that participating regulators may use within their own respective regulatory frameworks.
MDSAP certificates are issued with a three-year validity. Each certification cycle consists of a certification audit (initial audit for first-time certification), followed by two annual surveillance audits and a recertification audit that initiates the next three-year certification cycle. The Auditing Organization must itself be recognized by the Regulatory Authority Council on the basis of demonstrated competence and continuing oversight. The MDSAP audit report and related nonconformity documentation serve as independent third-party evidence that participating Regulatory Authorities may utilize within their respective regulatory frameworks for pre-market and post-market oversight.
As a certification body, DQS assesses and certifies conformity, it does not design or implement your quality management system. That independence is what gives an MDSAP audit its value: the manufacturer builds and runs the system, and an authorized Auditing Organization verifies it against ISO 13485 and the participating regulators' requirements.
Key Facts at a Glance
| Full Title | Medical Device Single Audit Program (MDSAP) |
| Published by | MDSAP Regulatory Authority Council, comprising the participating regulators; the program is also referenced within the International Medical Device Regulators Forum (IMDRF). |
| First Published | Pilot phase 2014–2016; operational phase commenced on 1 January 2017 . |
| Current Version | Operational program defined by the MDSAP Audit Approach and associated audit procedures, updated periodically by the Regulatory Authority Council. The audit is based on ISO 13485:2016 plus current jurisdiction-specific requirements. |
| Applicable to | Medical device manufacturers seeking market access in at least one of the participating jurisdictions: Australia, Brazil, Canada, Japan, and the United States. |
| Certifiable | Yes. Following successful completion of an MDSAP audit, a recognized Auditing Organization may issue an MDSAP certificate covering the audited scope. |
| Structure | The MDSAP audit is organized around seven primary processes: Management; Device Marketing Authorization and Facility Registration; Measurement, Analysis and Improvement; Medical Device Adverse Events and Advisory Notices Reporting; Design and Development (where applicable); Production and Service Controls; and Purchasing. The MDSAP Audit Approach defines the objectives, links, and interactions between these processes. Unlike a traditional clause-based audit, MDSAP audits follow a defined process sequence established by the MDSAP Audit Approach. This process-based approach allows auditors to evaluate interactions between processes and assess both ISO 13485 and applicable jurisdiction-specific regulatory requirements in a consistent manner. |
| Related Standards and Regulations | ISO 13485:2016 and the applicable regulatory requirements of the participating MDSAP jurisdictions (United States, Canada, Brazil, Australia, and Japan). |
Context and Drivers
Regulatory Convergence and Efficient Oversight
MDSAP emerged from a coordinated effort by regulators to reduce duplicative inspections of medical device manufacturers while preserving the rigor of jurisdiction-specific requirements. For each participating regulator, MDSAP audit outputs feed into national regulatory processes — for the FDA, MDSAP audits are generally accepted in lieu of routine inspections under its compliance program, while retaining the authority to conduct for-cause, compliance, or other inspections when necessary; for Health Canada, MDSAP certification is mandatory for manufacturers seeking or maintaining Medical Device Licenses for Class II, III and IV medical devices; for ANVISA, TGA, and MHLW/PMDA, MDSAP outputs are used within their respective frameworks.
Single Audit, Multiple Markets
For manufacturers, MDSAP reduces the cumulative audit and inspection burden across multiple jurisdictions. A single MDSAP audit produces evidence that can be used by each participating regulator without a separate, additional audit. For organizations operating internationally, this supports planning predictability for audit days, site availability, and document preparation.
Wider Recognition by Observers and Affiliates
In addition to the five participating Regulatory Authorities, several organizations currently participate in MDSAP as Official Observers. These include the European Union (EU), the Medicines and Healthcare products Regulatory Agency (MHRA, United Kingdom), the Health Sciences Authority (HSA, Singapore), and the World Health Organization (WHO) Prequalification for In Vitro Diagnostics (IVDs) Programme.
While Official Observers do not formally recognize MDSAP as an alternative regulatory pathway, they participate in the program to monitor its implementation, contribute to its development, and explore opportunities for future regulatory convergence.
An up-to-date list of participating Regulatory Authorities, Official Observers, and Affiliate Members is available on the official MDSAP website maintained by the Regulatory Authority Council.
Core Requirements
ISO 13485 as the QMS Reference
The MDSAP audit is built on ISO 13485. The standard's requirements for management responsibility, resource management, product realization, and measurement, analysis, and improvement provide the structural backbone of the audit.
Jurisdiction-Specific Regulatory Requirements
On top of ISO 13485, the MDSAP Audit Approach and associated audit tasks incorporate additional requirements from each participating regulator: 21 CFR Part 820 and related FDA requirements for the United States; Canadian Medical Devices Regulations (CMDR) for Canada; RDC 665/2022 and related ANVISA requirements for Brazil; the Therapeutic Goods (Medical Devices) Regulations 2002 for Australia; and Japanese MHLW Ministerial Ordinance 169 and related requirements for Japan. The auditor verifies conformance with each set of jurisdiction-specific requirements that applies to the manufacturer's declared markets.
MDSAP Audit Approach and Seven Primary Processes
The MDSAP audit is organized around seven primary processes: Management; Device Marketing Authorization and Facility Registration; Measurement, Analysis and Improvement; Medical Device Adverse Events and Advisory Notices Reporting; Design and Development (where applicable); Production and Service Controls; and Purchasing. The MDSAP Audit Approach defines the audit sequence, objectives, linkages, and interactions between these processes, enabling auditors to assess conformity with ISO 13485 and applicable jurisdiction-specific regulatory requirements in a consistent and process-based manner.
Three-Year Audit Cycle
MDSAP certificates are issued with a three-year validity. Each certification cycle consists of a certification audit (initial audit for first-time certification), followed by two annual surveillance audits and a recertification audit that initiates the next three-year certification cycle. Special audits may be triggered by significant changes, complaints, or regulatory referrals.
Non-Conformity Grading and Reporting
Non-conformities raised during an MDSAP audit are graded on a defined five-level scale, taking into account the affected QMS process and any escalation factors. Certain Grade 4 and all Grade 5 nonconformities may trigger expedited notification requirements to the affected participating Regulatory Authorities in accordance with MDSAP procedures. The audit report is provided to the participating regulators for use within their respective oversight processes.
Target Groups and Application Areas
MDSAP is intended for medical device manufacturers that intend to place devices on the market in two or more participating jurisdictions. The program is used by manufacturers of a wide range of devices — including diagnostic imaging equipment, implants, in vitro diagnostic devices, surgical instruments, dental devices, software as a medical device, and combination products, provided that the device type and registration status are recognized by the relevant Regulatory Authority.
Manufacturers of all sizes participate in MDSAP, from contract manufacturers and small enterprises to multinational organizations with multiple manufacturing sites. For organizations that already operate an ISO 13485 quality management system, MDSAP provides the basis for evidence-based access to multiple markets through a single coordinated audit, supporting informed regulatory and commercial decision-making.
Manufacturers that operate only in the EU and have no current or planned presence in MDSAP jurisdictions typically rely on EU MDR or IVDR conformity assessment rather than MDSAP. Manufacturers should consider the markets they serve, the volume of audits and inspections they otherwise undergo, and the alignment of their existing QMS with ISO 13485 when evaluating MDSAP participation.
Related Standards and Regulations
ISO 13485 as the QMS Backbone
ISO 13485 specifies requirements for a quality management system for medical device manufacturers. It is the technical basis of the MDSAP audit. Many manufacturers maintain ISO 13485 certification alongside MDSAP, either through the same certification body or through a coordinated audit arrangement.
Differentiation from EU MDR and EU IVDR
EU MDR 2017/745 and EU IVDR 2017/746 are EU regulations governing market access to the European Union. The European Commission participates in MDSAP as an Official Observer, but MDSAP audit outputs do not by themselves satisfy the conformity assessment requirements of EU MDR or EU IVDR. EU MDR and IVDR conformity assessments must be carried out by a Notified Body designated under those regulations. However, MDCG guidance recognizes that MDSAP audit reports may be taken into account during MDR/IVDR surveillance audits where equivalent requirements have been assessed. The MDR and IVDR remain fully applicable, and Notified Bodies must ensure that all MDR/IVDR-specific requirements are adequately evaluated. The Notified Body retains full authority and responsibility for its assessment, conclusions, and certification decisions. For manufacturers active in both EU and MDSAP jurisdictions, audit activities may often be coordinated or combined where the certification provider is both a recognized MDSAP Auditing Organization and an MDR/IVDR Notified Body. Such integrated audit programs can reduce disruption and increase efficiency while maintaining compliance with the distinct requirements and decision-making processes applicable to each scheme.
Other Regulatory References
MDSAP audits incorporate the jurisdiction-specific requirements listed above. As the MDSAP program continues to evolve, additional regulatory requirements may be incorporated if new Regulatory Authorities join the MDSAP Regulatory Authority Council and become full participating members of the program.
Your organization operates a quality management system for medical devices and is preparing for an MDSAP audit by a recognized Auditing Organization? Learn more on our dedicated MDSAP Certification page.
About DQS as a certification body
This article is part of the DQS Knowledge Center, a resource on management system standards and certification processes. For context on who produced it:
- One of Germany's first management system certifiers — DQS issued its first certificate in 1986 and has audited and certified management systems for over 40 years.
- Operates from more than 80 offices in 60 countries with a worldwide network of more than 3,000 auditors.
- DQS Medizinprodukte GmbH is a recognized MDSAP Auditing Organization and a designated Notified Body (NB 0297) under the European Medical Device Regulation (EU MDR 2017/745). In addition, DQS offers accredited ISO 13485 certification services. This allows manufacturers to work with one experienced certification partner for multiple regulatory and certification activities, while each assessment remains independent and follows the applicable regulatory requirements.
- Member of IQNet, the international certification network, supporting cross-border recognition of DQS certificates.
The articles in this Knowledge Center are written and reviewed by DQS specialists working with these standards in audit practice. Where applicable, content is verified against the current version of the standard, the issuing body's official publications, and recent regulatory or accreditation guidance. This article was last reviewed on 25 June 2026.
Frequently Asked Questions about MDSAP
Is MDSAP mandatory?
MDSAP is generally voluntary, with one important exception: manufacturers of Class II, III, and IV medical devices that wish to market their products in Canada must maintain a valid MDSAP certificate as a condition of holding a Canadian Medical Device Licence (MDL).
Which countries participate in MDSAP?
Five regulators currently participate as full members: the FDA (United States), Health Canada (Canada), ANVISA (Brazil), TGA (Australia), and MHLW/PMDA (Japan). Additional regulators engage as Official Observers, including the European Commission, the UK MHRA, Singapore's HSA, and the WHO IVD Prequalification programme. Several other regulators are recognized as Affiliate Members.
How Often Are MDSAP Audits Conducted and How Long Do They Take?
MDSAP certification follows a three-year audit cycle consisting of an initial certification audit, two annual surveillance audits, and a re-certification audit. Manufacturers therefore normally undergo one scheduled MDSAP audit each year. Additional special audits may be conducted when necessary, such as to assess significant organizational or regulatory changes.
Audit duration is determined according to MDSAP audit time calculation requirements and depends on the audit cycle stage, the applicable MDSAP audit tasks, the jurisdictions included within the audit scope, and other factors such as organizational complexity and site structure.
Does MDSAP replace EU MDR conformity assessment?
No. EU MDR 2017/745 requires conformity assessment by a Notified Body designated under the regulation. MDSAP audit outputs do not by themselves satisfy this requirement. The European Commission participates in MDSAP as an Official Observer, but MDSAP is not formally recognized as equivalent to EU MDR conformity assessment.
How is MDSAP different from ISO 13485 certification?
ISO 13485 certification focuses on conformity with the requirements of ISO 13485. MDSAP uses ISO 13485 as its foundation but also incorporates regulatory requirements from the participating jurisdictions. In addition, MDSAP audits follow a standardized Audit Approach and a defined audit sequence that evaluates interactions between key quality management system processes. As a result, an MDSAP audit assesses both ISO 13485 compliance and applicable regulatory requirements for FDA, Health Canada, ANVISA, TGA, and MHLW/PMDA within a single audit framework. This process-based methodology promotes consistency between audits and enables regulators to rely on a single audit outcome across multiple jurisdictions.
What happens if a non-conformity is identified?
MDSAP non-conformities are graded on a five-level scale that takes into account the affected process and escalation factors. Certain Grade 4 and all Grade 5 nonconformities may trigger expedited notification requirements to the affected participating Regulatory Authorities in accordance with MDSAP procedures.. Manufacturers respond through a documented corrective action process, and the Auditing Organization verifies the effectiveness of corrective actions in line with the MDSAP audit approach.