
Medical Device Single Audit Program (MDSAP) Consulting Services
A single nonconformity in an MDSAP audit can trigger a “for cause” inspection from any of the five participating authorities. Our consultants close the gaps in advance, so your quality management system holds up.
What is MDSAP, and why does one audit cover five markets?
What is MDSAP, and why does one audit cover five markets?
The Medical Device Single Audit Program (MDSAP) allows one audit, performed by an MDSAP-recognized Auditing Organization, to satisfy the quality management system requirements of five regulatory authorities at once: the US FDA, Health Canada, Brazil's ANVISA, Japan's PMDA, and Australia's TGA. One report, reviewed once, can support registrations in all five jurisdictions instead of five separate audit cycles.
Health Canada has required MDSAP certification for most Class II–IV devices since January 2019. For manufacturers selling into Canada, it isn't an efficiency option. It's the audit.
Why manufacturers underestimate MDSAP preparation
An MDSAP audit runs deeper than a standard ISO 13485 surveillance visit. It is typically conducted by two auditors, sometimes with observers from the FDA or Health Canada attending, and the scope extends into country-specific regulatory requirements that ISO 13485:2016 alone does not cover. Manufacturers who prepare only against the standard, not the audit model, are routinely caught out.
In the US, that gap has widened since the FDA's Quality Management System Regulation (QMSR) took effect on February 2, 2026, replacing the former Quality System Regulation and incorporating ISO 13485:2016 directly into 21 CFR Part 820. A QMS aligned only to the legacy structure needs a fresh review against the QMSR text, not a relabeling exercise.
How an MDSAP audit differs from an ISO 13485 audit or a single-country inspection
An ISO 13485 certification audit confirms your quality management system meets the standard. An MDSAP audit confirms that, and layers on the specific statutory requirements of up to five regulatory authorities, assessed against one defined audit model rather than five separate inspection formats. It replaces the audit. It doesn't replace the underlying QMS work.
When you need MDSAP support
- You're entering the Canadian market, where MDSAP has been mandatory since 2019
- You're running separate audits across the US, Japan, Brazil, and Australia, and want to consolidate them into one program
- You've received a negative or “for cause” report from a previous MDSAP audit and need a corrective path
- Your QMS is ISO 13485 certified but has never been assessed against the country-specific requirements MDSAP layers on top
Satisfied Clients
Our MDSAP Consulting Services:
MDSAP Readiness Assessment
In a desktop review, we evaluate your existing QMS against MDSAP requirements, identify compliance gaps, define areas of improvement, and provide a clear roadmap toward audit readiness.
MDSAP training
We train your teams on the MDSAP approach and country specific requirements based on your training needs. This can be instructor led or e-learning and ensure the training effectiveness is evaluated.
Mock MDSAP Audits
We simulate the structure, rigor, and documentation flow of an actual MDSAP audit, ensuring your team gets familiar with the MDSAP audit approach, audit your processes, and ensure full preparedness.
QMS Integration Support
We help harmonize your existing ISO 13485 QMS framework with MDSAP’s country-specific expectations (FDA QSR, Health Canada, TGA, PMDA, ANVISA) for seamless alignment.
Audit Follow-Up and CAPA Management
We assist in interpreting findings, creating a corrective action plan and implementing corrective actions.
How we sequence your MDSAP preparation
Qserve's approach moves in a fixed order: readiness assessment first, so the gaps are known before anything else starts; targeted QMS integration and training next; a mock audit before the real one, run within Qserve's wider Audits & Inspections practice; and CAPA support if findings do surface. Each stage is a decision point, not a fixed package. MDSAP sits alongside MDR/IVDR, FDA, and NMPA mock audits under Qserve's Audits & Assessments service line.
How we sequence your MDSAP preparation
Qserve's approach moves in a fixed order: readiness assessment first, so the gaps are known before anything else starts; targeted QMS integration and training next; a mock audit before the real one, run within Qserve's wider Audits & Inspections practice; and CAPA support if findings do surface. Each stage is a decision point, not a fixed package. MDSAP sits alongside MDR/IVDR, FDA, and NMPA mock audits under Qserve's Audits & Assessments service line.
Couldn't find your question?
How long does MDSAP preparation typically take?
Timelines track QMS maturity. Organizations already ISO 13485 certified with strong documentation can be ready in a few weeks. Those building a QMS from scratch, or addressing findings from a previous “for cause” report, should plan for several months.
Is MDSAP mandatory, or can we rely on ISO 13485 certification alone?
It depends on the market. Health Canada has required MDSAP certification for most Class II–IV devices since January 2019, making it effectively mandatory there. The FDA, ANVISA, PMDA, and TGA currently accept MDSAP audit reports as part of, though not a full replacement for, their own oversight, so outside Canada the case is efficiency rather than legal requirement.
Do all five MDSAP countries apply identical requirements?
No. MDSAP audits assess a shared core process model, but each participating authority retains supplementary requirements the others don't, from FDA QMSR provisions to Health Canada's device licensing rules. A QMS built only to the shared core will still miss country-specific gaps.
What happens if we receive a negative or “for cause” MDSAP report?
A negative report can prompt one or more participating authorities to schedule their own follow-up inspection, independent of the MDSAP cycle. Qserve helps you interpret the findings, build a defensible corrective action plan, and engage with the auditing organization to close the report before that follow-up scrutiny arrives.
Latest blogs

These are the 5 most common Notified Body findings during CER reviews under MDR — and what you need to address to avoid them.
.png)
ISO 13485 doesn't cover AI-specific risks. See why medical device and IVD manufacturers need a dedicated AI audit to meet EU AI Act and Notified Body expectations.
.png)
What ISO 14155 requires for medical device clinical investigations: history, roles, phases, and participant protections, plus how Qserve trains teams on it.
