On August 3, 2026, the MDSAP officially released AU P0002.011, MDSAP Audit Approach, which immediately replaced the previous Version 010 issued in February.

This is more than a minor version update. Version 011 brings cybersecurity, UDI, personnel competence, and other requirements directly into audit tasks, signaling a shift in the MDSAP audit approach from checking whether a quality system is merely documented to assessing whether it is effectively implemented and demonstrably compliant.
So, what exactly has changed—and where will MDSAP auditors be looking more closely?
Eight Key Changes in MDSAP AU P0002.011
1. Risk-Based Thinking Moves Upfront — Task 1
The requirement to use a risk-based approach to control QMS processes has been moved forward to Task 1.
During audits, auditors may no longer focus solely on design-related risks. They may also examine whether the company:
- Regularly reviews and maintains its risk register;
- Updates risk control measures throughout the product and process lifecycle; and
- Applies risk-based thinking consistently across the entire quality management system.
In other words, auditors will be looking at whether risk management is embedded throughout the QMS, rather than being treated as an isolated design activity.
2. Personnel Competence: From “Training” to “Competence”
Under Task 6, the focus is shifting away from simply verifying training records.
Training attendance sheets and records of completed training alone may no longer be sufficient to demonstrate that personnel are qualified for their roles.
Companies should establish a formal personnel competence assessment process and maintain objective evidence such as:
- Practical skills assessments;
- Competency evaluations;
- Qualification or authorization records; and
- Other evidence demonstrating that employees can effectively perform their assigned responsibilities.
During an audit, auditors may also select personnel for practical demonstrations or competency assessments.
The key distinction is simple: completing training does not necessarily mean being competent.
3. More Detailed UDI Oversight
The updated approach further clarifies responsibilities related to Unique Device Identification (UDI).
1. Clearer allocation of responsibilities
The Manufacturer is responsible for ensuring that UDI requirements are properly implemented on the production and labeling side.
The Sponsor, as the holder of the market authorization, is responsible for submitting and maintaining UDI information in the applicable database.
The respective responsibilities of the Manufacturer and Sponsor should be clearly defined through a written agreement.
2. FDA change-control requirements
Under FDA requirements, when a design or packaging change affects device identification, the manufacturer must assess whether a new UDI-DI needs to be assigned.
UDI considerations should therefore be incorporated into the company’s design change and change-control processes.
4. Changes to the Design and Development Process
Version 011 introduces several notable changes to design and development requirements.
1. Independent design review requirement removed
The previous requirement that design reviews must be conducted by an independent reviewer has been removed, bringing the approach closer to the principles of ISO 13485.
2. New FDA cybersecurity requirements
The updated approach introduces FDA-related requirements concerning cybersecurity design inputs and cybersecurity design verification.
Cybersecurity considerations therefore need to be incorporated into the design and development process from the appropriate stages.
3. UDI updates must be traceable following design changes
When a design change is implemented, manufacturers must also assess whether corresponding UDI data needs to be updated and reported to the FDA.
This further connects design change control with UDI management.
5. Expanded Production and Service Requirements
Several requirements relating to production and service activities have also been expanded.
1. Australia TGA UDI requirements added to Task 1
Task 1 now includes requirements related to UDI under Australia’s Therapeutic Goods Administration (TGA) framework.
2. Greater traceability for life-supporting and life-sustaining devices
Task 18 incorporates the FDA definitions of “life-supporting” and “life-sustaining” devices, increasing traceability expectations for these types of products.
3. Software-enabled devices covered under installation activities
Task 26 expands the conformity assessment requirements for installation activities to address devices that incorporate software functionality.
This means companies should pay closer attention to installation, verification, and related compliance activities for software-enabled medical devices.
6. Cybersecurity: From Design Through Post-Market Surveillance
Cybersecurity requirements are no longer limited to the product design stage.
The updated MDSAP audit approach introduces requirements for a cybersecurity feedback loop and incorporates additional FDA cybersecurity expectations for medical devices.
It also adds requirements related to measurement, analysis, and improvement.
This effectively extends cybersecurity oversight across the device lifecycle—from design and development through production, post-market feedback, monitoring, and continual improvement.
For manufacturers, cybersecurity should therefore be managed as an ongoing lifecycle process rather than a one-time design exercise.
7. Marketing Authorization and Establishment Registration
The requirements concerning Predetermined Change Control Plans (PCCP) have been significantly revised.
The previous restriction that limited PCCP provisions to AI-enabled devices has been removed.
This represents a broader application of the PCCP concept and means that manufacturers should reassess their change-control strategies and determine whether the revised requirements may apply to their products.
8. Terminology Updated in Annex 2
Annex 2 has also been updated to improve the precision of its terminology.
The previous term “critical supplier” has been replaced with the more specific term “sterilization and laboratory service supplier.”
This terminology change provides greater clarity regarding the types of external providers covered by the relevant requirements.
Conclusion
The release of MDSAP AU P0002.011 sends a clear message: MDSAP audits are increasingly focused not simply on whether a company’s documentation looks complete, but on whether its processes are effectively implemented, objectively evidenced, and consistently maintained.
The latest revision places greater emphasis on areas such as risk-based thinking, personnel competence, UDI management, cybersecurity, design changes, software-related activities, and post-market processes.
For medical device manufacturers preparing for an upcoming MDSAP audit, it is advisable to conduct a gap assessment against Version 011 as soon as possible, identify differences between the current QMS and the updated audit approach, and implement the necessary system and process updates in advance.
A well-written procedure is no longer enough. Manufacturers need to be able to demonstrate that their processes actually work in practice.