CAPA for pre-market: you need less than you think

August 14, 2026 ░░░░░░

CAPA for pre-market: you need less than you think

Ask a pre-market team where corrective and preventive action (CAPA) sits on the priority list and it usually lands below design controls, risk management, and the submission itself. The reasoning is easy to follow. Nothing has shipped, so there are no complaints to investigate, no returned product to analyze, and no field failures to trend. Standing up a full CAPA program before there is anything to correct looks like paying for a process nobody will touch for a year.

That instinct is half right. A development-stage company does not need the CAPA program a commercial manufacturer runs, with trending dashboards, escalation tiers, and a monthly review board. What it does need is a CAPA process that works, sized to the volume of quality events a company actually generates before launch. Those two things get confused constantly, and the confusion is expensive in both directions: teams that skip CAPA entirely, and teams that copy a 40-page procedure from a consultant and then drown in it.

BONUS RESOURCE: CAPA Report Template

What an auditor checks first

Look at what FDA actually cites. In fiscal year 2025, the agency recorded roughly 2,660 device-related Form 483 citations, and the single most frequent one was inadequate CAPA procedures under 21 CFR 820.100(a), accounting for 279 observations, or about one in 10 of all device citations. Complaint handling came second.

Read the citation language carefully. Inspectors write up procedures, not volume. No manufacturer has ever been cited for having too few CAPAs. They get cited because the procedure is missing a required element, because the procedure exists but the records show it was not followed, or because actions were closed without anyone verifying they worked.

That distinction is the whole argument for pre-market teams. The bar an auditor applies is qualitative. Does a documented procedure exist, does it define its inputs, and can you show one example of the loop closing from problem to root cause to action to verification? A company with four well-run CAPA records clears that bar. A company with 60 sloppy ones does not.

ISO 13485:2016 makes the documented procedure explicit in clause 8.5.2, one of the few places in the standard where a procedure is mandated by name. As of Feb. 2, 2026, that clause is FDA's requirement too. The Quality Management System Regulation (QMSR) amended 21 CFR Part 820 to incorporate ISO 13485:2016 by reference, FDA retired the Quality System Inspection Technique on the same date, and inspections now run under compliance program 7382.850. Early post-QMSR observations cite ISO clauses directly rather than legacy Part 820 sections. Your corrective action procedure is now a regulatory document in both jurisdictions, which is an argument for writing it once, correctly, rather than twice.

The clock starts earlier than most teams assume

For a 510(k) device, FDA is clear that facility inspections are not part of the clearance process. The agency's own guidance states there is no pre-approval inspection as a prerequisite to 510(k) clearance, followed immediately by the warning that a manufacturer should be prepared for a quality system inspection at any time after clearance is granted.

Read that sentence again and the timeline problem should become obvious. Nobody checks your CAPA process before clearance, but an inspector can check it the day after. There is no grace period written into the regulation, no ramp-up window, and no allowance for a company that was busy launching. The system has to exist on day one of commercial distribution, which means it has to be built during the phase when it feels least necessary.

Europe removes even that ambiguity. A notified body audits the quality management system before the CE certificate is issued, and CAPA is a standard part of that assessment. The same holds for ISO 13485 certification anywhere in the world. Stage 1 of a certification audit almost always produces findings, each one has to be answered with a documented corrective action, and the Stage 2 auditor will pull those records specifically to see how the process performed. If any of them carry a completed effectiveness check, that is the strongest evidence available that the system functions.

The quality events are already happening

Pre-market work generates plenty of material for a CAPA system. For example:

  • A supplier ships components outside the agreed specification.
  • A verification protocol fails because the acceptance criteria were written against the wrong requirement.
  • Someone discovers that three design reviews were held without recorded attendees.
  • An internal audit turns up document control gaps ahead of certification.

Every one of those is a legitimate CAPA input under 8.5.2, and every one of them is happening right now inside companies that describe themselves as not having any quality events yet. The events are real. The capture mechanism is missing, so they get resolved over Slack, in a design review, or in someone's head, and the evidence of resolution vanishes with the conversation.

The cost of that gap arrives later, when an auditor asks how the supplier issue was handled, and the honest answer is that the team fixed it and moved on, with no record of the investigation, the root cause, or the check that confirmed the fix held. Reconstructing that history from memory and email threads, 18 months after the fact, takes far longer than logging it would have taken at the time. Cleanup always costs more than setup.

What minimal but real actually looks like

The standard itself supports scaling. Clause 8.5.2 requires that corrective actions be taken without undue delay and be proportionate to the effects of the nonconformities encountered. Proportionate cuts both ways. A minor documentation error does not warrant a formal eight-discipline investigation, and a supplier defect with patient-safety implications warrants considerably more than a one-line note.

A defensible pre-market CAPA process comes down to six things, and none of them require a large team:

  • One documented procedure that names its data sources: supplier nonconformances, internal audit findings, verification and validation failures, design review actions, and, once you are commercial, complaints and service records.
  • A written decision rule that separates a correction from a corrective action, so the team knows what gets logged and what gets escalated.
  • Investigation depth scaled to risk, with the reasoning for the depth recorded rather than assumed.
  • Documented action, including verification that the action does not adversely affect the ability to meet regulatory requirements.
  • An effectiveness check with a defined method and a defined date, which is the element auditors find missing most often.
  • Records that feed management review, so quality events are visible to leadership rather than buried in a folder.

Six elements, one procedure, and a place to store the records. That is a week of setup work if the templates already exist, and several weeks of drafting and internal review if they do not.

The opposite failure is just as costly

Overcorrection is the other trap. A team that takes CAPA seriously for the first time often responds by routing every typo, every meeting that ran long, and every misfiled document into a formal CAPA. Twelve months later there are 40 open records, none closed and none verified.

An auditor reading 40 open CAPAs with no effectiveness checks reaches a conclusion faster than one reading four closed ones, because an unmanaged backlog is direct evidence that the documented process is not being followed. The volume becomes the finding. Getting the trigger right matters more than getting the coverage broad, which is why what should actually trigger a CAPA is the first question to answer before writing the procedure, not after.

The same logic governs everything else in a pre-market quality system. Teams do not need more QMS. They need a right-sized QMS to stop paying the hidden tax on engineering and regulatory time, and CAPA is one of the clearest places where that principle applies.

BONUS RESOURCE: CAPA Report Template

Build a right-sized CAPA program with Greenlight Guru

Two things make lightweight CAPA hold up under audit: a procedure written to the standard, and a system that connects quality events to the records they affect.

Writing compliant templates and procedures from scratch is where most of the time goes. Manually drafting and validating the full set of SOPs a pre-market team needs for regulatory readiness runs to roughly 400 hours of work, which is the real reason CAPA gets deferred. It is rarely a philosophical objection to the process. It is a calculation about where a small team spends its next 40 hours.

Greenlight Guru removes that first cost. The CAPA workflow ships pre-configured with root cause analysis, effectiveness checks, and approvals built into the record, and it arrives alongside more than 80 audit-tested templates written by medtech professionals rather than adapted from a generic quality platform. Each quality event links to the design controls, risk records, and supplier records it touches, so an auditor tracing a supplier nonconformance to its resolution follows a connected path instead of a manual reconstruction. Companies running the full system see a 3.5x reduction in the likelihood of major audit findings.

To see how that looks inside the system, schedule your free demo of Greenlight Guru today.

Etienne Nichols is the Head of Industry Insights & Education at Greenlight Guru. As a Mechanical Engineer and Medical Device Guru, he specializes in simplifying complex ideas, teaching system integration, and connecting industry leaders. While hosting the Global Medical Device Podcast, Etienne has led over 200...

CAPA Report Template
Download For Free
CAPA Report Template - slide-in cover
Search Results for:
    Load More Results