Stage 1Gap assessment — know what you owe
Before any software or SOP, write down three things: which regulations apply to you (for a US-market device company that usually starts with FDA QMSR / 21 CFR 820 and ISO 13485, with ISO 14971 for risk), which of their requirements you already satisfy informally, and which you satisfy not at all. At 30 people the honest answer is usually "we do most of this in email, spreadsheets, and one senior engineer's memory" — which is a gap, because a QMS requirement you can't evidence is a requirement you don't meet.
Turn the gap list into an owned plan: every gap gets an owner, a target date, and a definition of done that names the evidence an auditor would ask for. Resist the urge to write forty SOPs in a weekend — sequence them in the order the rest of this playbook follows, because each stage depends on the one before it.
- Map each applicable clause to: evidence exists / evidence is informal / no evidence.
- Decide your regulatory strategy now (US only? MDSAP jurisdictions later?) — it changes the scope of Stages 5 and 6.
- Set a management-review cadence from day one, even while the QMS is a skeleton.
Stage 2Document control + e-sign — the foundation
Everything else in a QMS is written down somewhere, so the document system comes first. You need controlled documents with versions, an approval workflow, a way to know who has read what, and a periodic-review cadence — and, if you intend to keep records electronically for FDA purposes, signatures designed around 21 CFR Part 11: re-authentication at the moment of signing, a rendered manifestation of who signed, when, and why, and an append-only history behind the record.
Start with a small, real document set: a quality manual, the document-control SOP itself, and the SOPs for the processes in Stages 3–5. Every SOP you approve through the controlled workflow is simultaneously content and evidence — it demonstrates the document system works.
- Approve the document-control SOP through the document-control workflow. Auditors notice.
- Decide signature meanings (author / reviewer / approver) before the first signature, not after.
- Keep obsolete revisions retrievable but unmistakably superseded.
Stage 3CAPA, NCR, and complaints — the correction loop
The heart of an FDA-ready QMS is the loop that notices problems, contains them, fixes root causes, and proves the fix worked. That is three linked record types, and the links are the point: a complaint from the field, the nonconformance report that confirms and contains it, and the CAPA that carries root-cause analysis, corrective actions, and an effectiveness check. When these live in disconnected tools, the audit question "show me the CAPA this complaint led to" becomes a scavenger hunt.
Write the SOPs so that thresholds are explicit — not every NCR deserves a CAPA, and a CAPA system flooded with trivia is as non-functional as no CAPA system. Define what escalates, who decides, and what evidence closes each record.
- Every CAPA should point at the record that triggered it — complaint, NCR, audit finding, or internal signal.
- Effectiveness checks get a due date and an owner at CAPA creation, not at closure.
- Complaint intake needs a path from support conversations into the quality system, or signals will die in an inbox.
Stage 4Training & competence — prove people are ready
A QMS the team hasn't been trained on is a liability with a table of contents. Regulators expect you to define competence requirements per role, train people on the procedures that apply to them, keep records of that training, and re-train when documents change. At 30 people this is genuinely manageable — if it's wired to the document system, so that a revised SOP automatically raises the question "who needs re-training?"
- Define a role-to-procedure matrix: which roles must be trained on which SOPs.
- Record training with a date, a trainee, the document version trained on, and an attestation.
- Treat read-receipts as awareness, not competence — some procedures need demonstrated proficiency.
Stage 5Audits & supplier controls — inspect yourself first
Internal audits are how you find your gaps before an auditor does; supplier controls are how you extend the QMS beyond your own walls. Build an internal-audit program that covers the whole QMS on a defined cycle, feed findings into the CAPA loop from Stage 3, and qualify your critical suppliers: risk-tier them, define what qualification requires per tier, and keep the evaluations current.
- Auditor independence matters even in a small company — no one audits their own process.
- Findings without CAPA linkage are observations, not a functioning audit program.
- Purchasing controls only work if the approved-supplier list is enforced where POs are actually raised.
Stage 6MDSAP readiness — one audit, five jurisdictions
If your market strategy includes Canada, Brazil, Japan, or Australia alongside the US, MDSAP lets one audit cycle cover multiple regulators — but it audits your QMS as a set of linked processes, following chains across management, measurement, design, production, and purchasing. A QMS built as the previous five stages describe is largely MDSAP-shaped already; readiness work is mostly about rehearsing the linkages and closing the residual gaps for each jurisdiction in scope.
- Run a mock audit against the MDSAP companion-document structure before the real cycle.
- Rehearse process linkages: pick a complaint and walk it to a CAPA, a design change, training, and a release, on demand.
- Track jurisdiction-specific requirements (registrations, reporting clocks) explicitly rather than assuming ISO 13485 coverage is enough.
After stage 6Keep it boring
An FDA-ready QMS is not a project you finish; it's an operating rhythm. Management review on cadence, internal audits on cycle, CAPAs closed with effectiveness evidence, training current against document versions. The goal of all six stages is that the next audit — internal, FDA, or MDSAP — is boring, because the evidence was accumulating as the work happened rather than being reconstructed for the occasion.
Want to see the modules in this playbook with realistic seeded data? Explore the live demo, browse the organized QMS hub, or email us — we'll walk your own gap list through the platform with you.