Skip to main content
Matrix One>Blog>How to do a gap analysis for MDSAP requirements

How to do a gap analysis for MDSAP requirements

An MDSAP gap analysis compares your existing quality management system against the requirements of all five MDSAP regulatory authorities at once, so you find out where one process satisfies four jurisdictions and where it satisfies none. The work is a mapping exercise: list the requirements, link each one to the process that meets it, and the requirements left with nothing linked to them are your gaps. This guide sets out how to run it, what the five authorities each add on top of ISO 13485:2016, and the traps that make a gap analysis look complete when it is not.

What is MDSAP, and which regulators accept it?

The Medical Device Single Audit Program lets one audit, performed by an authorised auditing organisation, satisfy the quality system requirements of five regulators at the same time. The audit model is built on ISO 13485:2016 and then extended with the country specific requirements each authority adds.

AuthorityCountryStatus of MDSAP
Health CanadaCanadaMandatory for Class II, III and IV devices. MDSAP certification replaced the previous CMDCAS scheme on 1 January 2019.
FDAUnited StatesVoluntary. The FDA accepts an MDSAP audit report in place of a routine surveillance inspection, though not in place of for-cause or pre-approval inspections.
TGAAustraliaVoluntary. Accepted as evidence toward conformity assessment.
ANVISABrazilVoluntary, and widely used to support Good Manufacturing Practice certification.
MHLW and PMDAJapanVoluntary. Accepted as part of the QMS conformity assessment.

The EU is not a member. An MDSAP certificate does not satisfy Regulation (EU) 2017/745, so a manufacturer selling in Europe still needs its notified body assessment separately. That is the single most common misunderstanding we hear about the programme.

Why run a gap analysis before an MDSAP audit?

Because the alternative is discovering the gaps during the audit. Most manufacturers arrive at MDSAP with a quality system already certified to ISO 13485:2016, which covers the majority of the audit model but not the country specific additions. A gap analysis tells you how much of the remaining work is genuinely new and how much is documentation of things you already do.

It also stops you building five parallel quality systems. Run properly, the analysis usually shows that one procedure can satisfy several jurisdictions with a small addition, which is the entire point of the programme.

What does the MDSAP audit model actually cover?

The audit model is organised into seven processes rather than into clause numbers, and your gap analysis should follow the same structure so the output maps onto how you will be audited.

ProcessWhat the auditor examines
ManagementQuality policy, objectives, planning, management review, and the resources committed to the quality system.
Device marketing authorisation and facility registrationThat the devices you are auditing are actually registered in each market, and that the registrations are current.
Measurement, analysis and improvementData analysis, internal audit, nonconformity handling and corrective action.
Medical device adverse events and advisory notices reportingComplaint handling, reportability decisions, and each country's reporting timelines and formats.
Design and developmentDesign controls, design transfer and design changes. Not applicable if you do not design.
Production and service controlsProcess validation, product identification and traceability, and servicing.
PurchasingSupplier evaluation, purchasing information and verification of purchased product.

Where do the five jurisdictions add requirements beyond ISO 13485?

These are the areas where an ISO 13485:2016 certified system most often falls short, and therefore where a gap analysis earns its keep.

AreaWhat changes by jurisdiction
Adverse event reportingTimelines and thresholds differ. Each authority has its own reportability criteria, forms and clocks, and a single generic complaint procedure will not satisfy all five.
Recalls and advisory noticesEach country defines what triggers a field action and who must be told, within what period.
Registration and licensingEvidence that the specific device is authorised in the specific market, kept current, including changes that require notification.
Brazil Good Manufacturing PracticeANVISA adds GMP requirements under RDC 665/2022, which go beyond ISO 13485:2016 in several production and record keeping areas.
JapanMHLW Ministerial Ordinance 169 adds requirements including the roles of the marketing authorisation holder and specific Japanese language documentation.
CanadaCanadian Medical Devices Regulations obligations sit alongside the standard, including licence conditions and specific record retention.

How do you run the gap analysis, step by step?

  1. Fix the scope. Which devices, which sites and which of the five markets. A gap analysis for markets you do not sell into is wasted effort, and scope creep is the most common reason these stall.

  2. Build the requirement list as discrete items. Break each regulation into individually identifiable requirements rather than working from whole documents. One requirement, one row, one identifier.

  3. Map your processes to those requirements. Link each requirement to the procedure, work instruction or record that satisfies it. A link is a claim you have to be able to defend.

  4. Find the unlinked requirements. Anything with nothing linked to it is a gap. This is the actual output and it should take minutes to produce once the links exist.

  5. Classify each gap. Missing entirely, partially covered, or covered in practice but not documented. The three need very different amounts of work and conflating them ruins the plan.

  6. Assign and schedule. Each gap needs an owner and a date, and the plan needs to fit inside your audit timeline rather than alongside it.

  7. Re-run it after the changes. A gap analysis is a live view, not a one-off document. If re-running it is expensive, that is a sign the links live in a spreadsheet rather than in a system.

Why do gap analyses fail?

Four patterns, and all four produce an analysis that looks complete. The first is mapping at document level: claiming a whole procedure covers a whole regulation, which hides every specific requirement inside it. The second is treating a link as evidence, when a link is only a claim until someone checks the linked process actually does what the requirement asks.

The third is doing it once. Regulations change, and a static spreadsheet is out of date the first time a procedure is revised. The fourth is scoping to ISO 13485:2016 alone and assuming the country specific additions are minor, which is exactly where the findings come from.

How does this work in Matrix Quality?

Requirements from standards and regulations are held as individual linked items rather than as attached documents, so each one can be traced to the process that satisfies it. Linking the requirements to your processes produces the gap view as a live query rather than a document somebody assembles, which is what makes step seven above cheap enough to actually do.

The same trace matrix is what you show an auditor. Because it is generated from live links rather than maintained by hand, it cannot drift out of step with the processes it describes. If you also hold design controls in Matrix Req, the design and development process in the audit model traces to the same dataset. Our rankings for the two halves are in the best eQMS software and best requirements management software posts.

For the programme itself, including certification and maintenance, see our guide to MDSAP certification. For the standard underneath the audit model, see what ISO 13485 requires. And because internal audit is one of the seven processes and a frequent source of findings, the internal audit checklist is worth working through before the auditor arrives.

Last updated: 13 September 2026.

Common questions about MDSAP gap analysis

01Is MDSAP mandatory?

Only in Canada, where MDSAP certification has been required for Class II, III and IV devices since 1 January 2019 and replaced the earlier CMDCAS scheme. For the United States, Australia, Brazil and Japan the programme is voluntary, although each authority accepts MDSAP audit results in its own way. The EU is not part of the programme at all.

02Does an MDSAP certificate cover the EU MDR?

No. Regulation (EU) 2017/745 is outside the programme, so a manufacturer selling in Europe still needs a notified body conformity assessment separately. Treating MDSAP as covering Europe is the most common misunderstanding we see, and it is an expensive one to discover late.

03How long does an MDSAP gap analysis take?

For a manufacturer already certified to ISO 13485:2016, the mapping itself is usually a few weeks of focused work. What takes longer is closing the gaps, particularly adverse event reporting procedures that have to handle five different sets of timelines and thresholds. Scope the analysis narrowly and the mapping goes quickly.

04Can you use one procedure for all five jurisdictions?

For most processes, yes, and that is the point of the programme. The exceptions are the areas where the authorities genuinely differ, principally adverse event reporting, field actions and registration evidence. There the usual answer is one procedure with country specific sections rather than five separate procedures.

05What is the difference between a gap analysis and an internal audit?

A gap analysis asks whether your system is designed to meet the requirements. An internal audit asks whether the system as designed is actually being followed. You need both, and in that order: auditing against a system with known design gaps tells you very little.

06Do you need software to run a gap analysis?

No, and plenty of manufacturers do the first one in a spreadsheet. The difficulty is the seventh step, re-running it after changes. A spreadsheet map is accurate on the day it is written and decays from then on, so the question is less whether you can produce one and more whether you can keep it current.

Written by
Eva Kautenburger
CCO

Eva Kautenburger is Chief Customer Officer at Matrix One, where she leads Customer Success & Supp across the full portfolio of regulatory and quality management solutions for the medical device industry. A certified I. and II. Party Auditor with deep expertise in ISO 13485, EU MDR/IVDR, IEC 62304, and 21 CFR Part 820, she brings both the technical fluency and regulatory grounding that MedTech customers need to navigate complex compliance landscapes. In her role, Eva oversees a cross-functional team of Solution Consultants, Solution Engineers and Account Managers, driving onboarding, retention, support and strategic growth for customers ranging from emerging device companies to global enterprises as well as consulting intiatives to support customers in their regulatory journey.

View profile →

Request a demo and get started today.

See how Matrix One connects your requirements, risks, tests, and documentation in one platform.

Request A Demo Today

Thank you

A member of our team will be in contact within 48 hours.