MedTech Terms
    The authoritative reference
    All terms

    Supplier Controls

    Procedures to ensure purchased products and services conform to requirements.

    Reviewed by Christian Espinosa, Founder, Blue Goat CyberLast reviewed May 5, 2026

    Definition

    Per 21 CFR 820.50 and ISO 13485 Section 7.4, manufacturers must evaluate, select, and monitor suppliers based on the supplier's ability to meet specified requirements.

    What this means in practice

    Supplier audits, agreements, and incoming inspection comprise the typical control set. Supply chain risk now includes cybersecurity concerns for software suppliers.

    Cross-references

    Part of

    A larger framework or document this term belongs to.

    Primary references

    3 sources
    Link health: 2 verified 1 needs review· last checked 2026-05-09
    eCFR·1IMDRF/GHTF·1FDA·1
    1. 1
      21 CFR 820.50
      Needs review
      eCFRecfr.gov
    2. 2
      GHTF/IMDRF Process Validation Guidance
      Verified
      IMDRF/GHTFimdrf.org
    3. 3
      FDA - Device Manufacturing
      Verified
      FDAfda.gov

    Inline markers like [1] jump to the matching reference above.