If you've spent any real time inside a medical device quality system, you already know 21 CFR 820.100 by number, not just by name. It's the section that shows up in nearly every device-related FDA Form 483, and it's the section most quality teams get partway right: they have a CAPA procedure, they open CAPA records on schedule, and they still get cited anyway.
Here's the part most explainers of this topic skip: as of February 2, 2026, the compliance date FDA set in its final rule at 89 FR 7496, § 820.100 is no longer the citation an investigator will actually write on a new inspection. FDA folded the Quality System Regulation into ISO 13485:2016 under the new Quality Management System Regulation (QMSR), and the corrective and preventive action requirements that used to live at § 820.100 now sit in ISO 13485:2016 clause 8.5, referenced through the new § 820.10. The substance barely moved. The address it lives at did.
This guide covers what § 820.100 required, where that requirement lives now, how FDA investigators actually work through a CAPA system during an inspection, and what a CAPA program needs to hold up under both the old citation and the new one.
A Short History: What 21 CFR 820.100 Said
FDA finalized the original Quality System Regulation in 1996 (61 FR 52602), effective June 1, 1997, and § 820.100 was its corrective and preventive action requirement. The text was short, but it packed in seven distinct obligations. Under § 820.100(a), manufacturers had to establish procedures covering:
- Analysis of data sources — processes, work operations, concessions, quality audit reports, quality records, service records, complaints, returned product, and other sources — to identify existing and potential causes of nonconforming product, using statistical methodology where necessary to catch recurring problems.
- Investigation of the cause of nonconformities related to product, processes, and the quality system itself.
- Identification of the actions needed to correct the nonconformity and prevent it from recurring.
- Verification or validation that the corrective and preventive action taken is actually effective and doesn't create a new problem in the finished device.
- Implementation and documentation of the changes in methods and procedures needed to fix the problem.
- Dissemination of information about the quality problem to the people responsible for product quality or for preventing the problem.
- Submission of the information, including the corrective and preventive actions taken, for management review.
Section 820.100(b) then added a plain requirement that's easy to skate past: all of that activity, and its results, had to be documented. Not implied by good practice. Written down.
That seven-part structure is worth knowing even now, because it's the skeleton every FDA-facing CAPA procedure has been built on for almost thirty years, and it maps almost element-for-element onto the standard that replaced it.
Corrective Action vs. Preventive Action
Corrective action addresses a nonconformity that already happened. Preventive action addresses one that hasn't happened yet but that your data, trend, near-miss, or risk analysis suggests it could. That distinction sounds obvious in a training slide and disappears constantly in practice. The most common structural weakness I see in a CAPA system isn't a missing corrective action. It's a preventive action field that exists on the form and is functionally never used, because nobody built a process for surfacing potential problems before they become actual ones.
Under ISO 13485:2016, the two are split into separate clauses on purpose: 8.5.2 for corrective action, 8.5.3 for preventive action, each with its own cycle of cause determination, action, implementation, and effectiveness review. A CAPA log full of records that are all reactive, all triggered by something that already went wrong, is a system that's only using half its own clause structure. That's exactly the kind of thing an investigator notices on a records pull.
How This Changed Under the QMSR
FDA's final rule amending Part 820, published February 2, 2024 (89 FR 7496), replaced the standalone U.S. requirements with a direct incorporation of ISO 13485:2016 by reference. The compliance date was February 2, 2026, two years out, and as of that date manufacturers are expected to run a quality management system that satisfies ISO 13485:2016 in full, cross-referenced through the new § 820.10.
ISO 13485:2016 addresses CAPA under clause 8.5, titled "Improvement," broken into three parts: 8.5.1 (General, the QMS-wide obligation to maintain suitability and effectiveness), 8.5.2 (Corrective action), and 8.5.3 (Preventive action). The old § 820.100 elements map onto that structure closely enough that most companies' actual CAPA work product doesn't need to change. What needs to change is the citation in your SOPs, your training records, and your CAPA form headers, plus one genuine addition: 8.5.1's broader mandate to review the suitability and effectiveness of the quality management system as a whole, not just each individual nonconformity in isolation.
| § 820.100(a) Element (1996 QSR) | Where It Lives Now (ISO 13485:2016) |
|---|---|
| (1) Analyze data sources for causes | Clause 8.4 (Analysis of data) feeding 8.5.2(a) |
| (2) Investigate cause of nonconformities | Clause 8.5.2(b) |
| (3) Identify needed corrective/preventive actions | Clauses 8.5.2(c) and 8.5.3(b) |
| (4) Verify/validate effectiveness | Clauses 8.5.2(f) and 8.5.3(e) |
| (5) Implement and record changes | Clauses 8.5.2(d) and 8.5.3(c) |
| (6) Disseminate info to responsible parties | Clause 5.5 (Responsibility, authority, and communication) |
| (7) Submit for management review | Clause 5.6 (Management review) |
One more practical wrinkle: ISO 13485:2016 clause 8.5.3 ties preventive action explicitly back to risk management, which most manufacturers already handle under ISO 14971. If your preventive action process and your risk management file don't talk to each other, the QMSR transition is a good forcing function to connect them.
How FDA Evaluates CAPA During an Inspection
FDA's Quality System Inspection Technique guide, known throughout the industry as QSIT and first issued in August 1999, was withdrawn on February 2, 2026, the same compliance date that retired § 820.100 as a standalone citation, and replaced by Compliance Program 7382.850. The replacement changed more than the document's name — it changed the structure underneath it. QSIT organized an inspection around four subsystems: management controls, design controls, corrective and preventive action, and production and process controls. CP 7382.850 replaces that with six QMS Areas — Management Oversight; Design and Development; Production and Service Provision; Outsourcing and Purchasing; Change Control; and Measurement, Analysis, and Improvement — plus four OAFRs. CAPA is no longer a standalone subsystem. It now sits nested inside Measurement, Analysis, and Improvement, alongside complaint handling and data analysis. That doesn't make it a lighter review: a weak CAPA system still tends to expose weaknesses everywhere else in the quality system, and if the quality data isn't being analyzed, root causes aren't being investigated, and effectiveness isn't being verified, that same gap usually runs through design controls, production controls, and complaint handling too.
In practice, an investigator working the Measurement, Analysis, and Improvement area will pull your CAPA log, select a sample of records, and trace each one backward and forward:
- Where did the input come from? Complaint, internal audit, nonconforming product, field servicing, a supplier issue.
- Was the root cause investigation documented, and does it actually explain the failure?
- Does the corrective or preventive action logically follow from that root cause?
- Was the action verified or validated as effective after implementation?
- Was the whole thing documented well enough that someone outside the room could follow it?
That last piece, the documentation, is where § 820.100(b) and its downstream ISO 13485:2016 requirements do the most damage to companies that treat CAPA as tribal knowledge instead of a written record.
Common Ways CAPA Systems Fail Inspection
A few patterns show up over and over in the CAPA systems that draw observations:
- Containment gets recorded as correction. The unit gets fixed, the shipment gets quarantined, and the CAPA gets closed without anyone asking what caused the failure in the first place. That's a correction, not a corrective action, and the distinction matters to an investigator even when it doesn't matter to the person who closed the record.
- Root cause stops at the first plausible answer. "Operator error" closes the investigation instead of opening the next question: why did the process allow that error to reach the product?
- Effectiveness verification never happens, or happens too early. A CAPA gets marked effective before there's been enough production volume or enough time to know whether the fix actually worked.
- Preventive action is copy-pasted or left blank. The field exists on the form because the SOP requires it, not because anyone is using trend data, near-misses, or risk analysis to open genuinely preventive records.
- Required inputs get ignored. Complaint trends and internal audit findings are supposed to feed the CAPA system under § 820.100(a)(1) and its successor at clause 8.4. A system that only reacts to nonconformances on the production floor and never touches complaint or audit data is missing a required input, not just being incomplete.
- CAPAs run past their own internal deadlines with no documented justification. Neither § 820.100 nor ISO 13485:2016 sets a specific day count for closing a CAPA. The 30-day or 90-day target in your quality manual is your own commitment, not a regulatory one, but an unexplained pattern of blowing past it is its own finding.
Building a CAPA System That Holds Up
A CAPA program that survives inspection needs a handful of things working together, not just a form:
- Clear intake criteria. A defined threshold for when a nonconformance, complaint, or audit finding must become a CAPA record, so opening a CAPA isn't a judgment call made differently by every reviewer.
- A real root cause methodology. 5-Why, fishbone, fault tree, whatever fits the complexity of the problem, applied consistently and documented, not just referenced in the SOP.
- Risk-based prioritization. Not every CAPA needs the same rigor. Tie the depth of investigation to the severity and likelihood of harm.
- A defined effectiveness check. A specific metric, a specific re-check interval, and a decision point for what happens if the metric shows the action didn't work.
- Documented closure approval, with the record itself showing who reviewed it and on what basis it was closed.
- Trend analysis feeding management review, so CAPA data isn't just closed and filed but actually informs whether the quality system as a whole is improving, which is the whole point of ISO 13485:2016 clause 8.5.1.
- A live connection to complaint handling, internal audit, and design controls. CAPA doesn't function as an island. It's the mechanism that turns everything else your quality system observes into an actual change.
CAPA and the Form 483 Connection
CAPA weaknesses are one of the most reliable drivers of FDA Form 483 observations in the device industry, and the two are connected in both directions: a poorly run CAPA system generates observations, and a well-documented CAPA response is often the strongest tool a company has for closing out an inspection finding credibly. If you're in the middle of drafting a response to an observation that touches corrective or preventive action, the structure and timeline discipline matter as much as the technical fix. Our walkthrough on responding to an FDA Form 483 covers how to sequence that response so it holds up.
The better long-term investment, though, is building the CAPA discipline before an investigator ever walks in the door. That's the core of what FDA inspection preparation actually means in practice: not a mock inspection the week before, but a quality system where the CAPA subsystem can withstand a records pull on any given day.
Frequently Asked Questions
Does 21 CFR 820.100 still apply after the QMSR compliance date? Not as a standalone citation. As of February 2, 2026, it's incorporated by reference through 21 CFR 820.10 into ISO 13485:2016 clause 8.5. Full clause-by-clause mapping: "How This Changed Under the QMSR" above.
What's the difference between corrective action and preventive action? Corrective action responds to a nonconformity that already happened; preventive action responds to one your data, trends, or risk analysis says could happen. Full clause breakdown and why investigators expect to see both in use: "Corrective Action vs. Preventive Action" above.
How long does a company have to close a CAPA under FDA regulations? Neither the original § 820.100 nor its ISO 13485:2016 successor sets a specific day count for closure — the 30-day or 90-day target in most quality manuals is a self-imposed commitment, not a regulatory one. What an investigator actually checks is whether a CAPA that runs past that internal target carries a documented, risk-based justification for the extension, tied to the same closure-approval record described in "Building a CAPA System That Holds Up" above. A missed date with a reasoned, recorded rationale reads very differently on a records pull than the same missed date with nothing written down.
What does FDA look for in a CAPA system during an inspection? An investigator working the Measurement, Analysis, and Improvement area pulls a sample of CAPA records and traces each one for a documented root cause, an action that logically follows from that cause, and verification that the fix actually worked after implementation — not just that the record was opened and closed on schedule. See "How FDA Evaluates CAPA During an Inspection" above for the full walkthrough, including where CAPA now sits in FDA's post-QSIT inspection structure.
Do design controls or complaint handling feed into CAPA? Yes. Section 820.100(a)(1), and its ISO 13485:2016 successor at clause 8.4 (Analysis of data), required manufacturers to analyze complaints, returned product, servicing records, audit reports, and quality records as CAPA inputs. A CAPA system that only reacts to nonconformances on the floor and never touches complaint or audit trends is missing a required input, not just being less thorough than it could be.
Last updated: 2026-09-16
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.