Skip to main content
Matrix One>Blog>The Best Design Controls Software for Medical Devices Under the QMSR

The Best Design Controls Software for Medical Devices Under the QMSR

Design controls software for medical devices is the tool that holds your design inputs, outputs, reviews, verification, validation and changes as linked, signed records, so the design and development file required by ISO 13485:2016 clause 7.3.10 builds itself. Short answer: for 2026, under the FDA QMSR, the ranking is Matrix Req first, then Greenlight Guru, Jama Connect, Ketryx, Siemens Polarion ALM, PTC Codebeamer, Orcanos and IBM DOORS Next. Matrix Req is first because it puts configurable required traces, change impact warnings, Part 11 signatures and a frozen, generated design history file in one tool built only for regulated device teams.

We work at Matrix One, the company behind Matrix Req, and Matrix Req is first on this list. We have said so up front so you can weigh the ranking accordingly. Every competitor fact below was read on that vendor's own website in October 2026, every regulatory statement is tied to a numbered clause or section, and we quote no pricing a vendor does not publish and no review-site scores.

Matrix Req is a design controls and requirements management tool for medical device and regulated product teams. It has been built for that one job since 2014, and Matrix One says more than 500 life sciences and medical device companies use its products.

Why can you trust this list?

  • Matrix One has built requirements and design controls tooling for medical device teams since 2014.

  • We disclose our interest: we make Matrix Req, and it is ranked first.

  • Every regulatory claim is tied to a numbered clause or section, read in the current eCFR text on 8 October 2026.

  • Every competitor statement was read on that vendor's own website in October 2026 and is attributed to it.

  • No invented pricing and no review-site data.

  • Signed by the author and dated, and reviewed in line with our editorial policy.

8 best design controls software shortlist

ToolBest for
Matrix ReqDevice teams that want design controls, risk and a generated design history file in one configurable tool
Greenlight GuruSmall and mid-size device companies that want design controls and an eQMS from one vendor
Jama ConnectLarger organisations running complex systems requirements across many teams
KetryxSoftware-heavy teams that want design controls generated from Jira and Git
Siemens Polarion ALMEnterprises standardised on Siemens engineering tools and ReqIF exchange
PTC CodebeamerMulti-standard ALM programmes spanning medical, automotive and industrial
OrcanosTeams that want ALM and QMS modules from one smaller vendor
IBM DOORS NextOrganisations with an established DOORS estate and an IBM toolchain

How do the 8 design controls tools compare at a glance?

ToolBuilt forStrongest on
Matrix ReqMedical device design controls end to endRequired traces, impact warnings, Part 11 signed and frozen documents
Greenlight GuruDevice companies wanting QMS and design in one productDesign controls and quality processes from one vendor
Jama ConnectLarge multi-team systems engineeringLive traceability and review at scale
KetryxSoftware as a medical device built in Jira and GitDeveloper-native evidence and release gating
Siemens Polarion ALMSiemens-centred enterprise ALMBuilt-in ReqIF and rule-based import
PTC CodebeamerRegulated ALM across several industriesPreconfigured templates for IEC 62304 and automotive standards
OrcanosCombined ALM and QMS for smaller firmsFMEA variants and Part 11 signatures in one suite
IBM DOORS NextLong-running DOORS programmesLarge requirement sets and round-trip import and export

The rest of this page explains why the ranking falls this way. The regulatory change comes first because it decides what the software has to hold.

What changed for design controls when the QMSR took effect on 2 February 2026?

The FDA's Quality Management System Regulation took effect on 2 February 2026, and 21 CFR 820.30, the old design controls section, is now marked [Reserved]. Sections 820.20 to 820.30 are all reserved in the current eCFR text.

Design controls did not go away. Under 21 CFR 820.10(a), a manufacturer must document a quality management system that complies with ISO 13485, which 21 CFR 820.7(b) incorporates by reference as ISO 13485:2016. Under 21 CFR 820.10(c), manufacturers of class II and class III devices must comply with Design and Development, clause 7.3 and its subclauses in ISO 13485.

So the requirement you are buying software for is now ISO 13485:2016 clause 7.3, read through 21 CFR 820.10(c).

Any vendor page that still describes its design controls only against 21 CFR 820.30 is describing the legacy rule. When we read the eight vendors' own pages on 8 October 2026, Greenlight Guru and Orcanos named the QMSR on their own sites, Jama Connect and Visure still listed 820.30 on their medical device pages, and none stated the 2 February 2026 date. Read every vendor's wording, ours included, with that date in mind.

The phrase "design history file" no longer appears in 21 CFR Part 820. The record ISO 13485 asks for is the design and development file in clause 7.3.10, which must include or reference the records that show conformity to the design and development requirements, plus records of design changes. Most teams still call it the DHF, and the tooling question is the same: can the tool produce that file from the records it already holds?

Which ISO 13485 clause 7.3 records does design controls software have to hold?

Each subclause of 7.3 produces records. A design controls tool earns its place if it holds those records as linked items rather than as separate documents someone has to keep in step by hand.

ClauseWhat the software has to hold
7.3.2 PlanningThe plan, its stages, reviews and responsibilities, and under 7.3.2 e) the method for tracing outputs to inputs
7.3.3 InputsFunctional, performance, usability and safety requirements, regulatory requirements and risk management outputs, reviewed and approved
7.3.4 OutputsOutputs that meet inputs, with acceptance criteria, approved before release
7.3.5 ReviewReview records with participants and date
7.3.6 VerificationPlans with methods, acceptance criteria and sample size rationale, and results that show outputs meet inputs
7.3.7 ValidationValidation on representative product against user needs and intended use, with results
7.3.8 TransferEvidence that outputs were verified as suitable for manufacturing before becoming production specifications
7.3.9 ChangesEach change identified, its significance assessed, reviewed, verified or validated as appropriate, and approved before implementation
7.3.10 FileA design and development file per device type or family, including or referencing all of the above

Clause 7.3.2 e) is the one most tools get judged on in practice. It requires the plan to state how outputs will be traced to inputs, which is why a tool that lets you declare which links are mandatory is doing compliance work rather than just drawing diagrams.

Clause 7.3.9 is the one most teams fail on. It asks you to evaluate a change's effect on constituent parts, on product already delivered, and on the inputs and outputs of risk management. A tool that cannot show what sits downstream of a changed requirement leaves that evaluation to memory.

Which class I devices still need design controls under 21 CFR 820.10(c)?

Most class I devices are outside clause 7.3 in the US, but not all. 21 CFR 820.10(c)(1) keeps every class I device automated with computer software inside design controls.

Table 1 to paragraph (c)(2) then lists five more by regulation: tracheobronchial suction catheters (868.6810), non-powdered surgeon's gloves (878.4460), protective restraints (880.6760), manual radionuclide applicator systems (892.5650) and radionuclide teletherapy sources (892.5740).

If your class I product runs software, budget for design controls tooling exactly as a class II team would. The software clause is the one that catches most early stage companies by surprise.

What does 21 CFR Part 11 add to a design review sign-off?

Design reviews, output approvals and change approvals are all signatures. If you sign them electronically, 21 CFR Part 11 applies to the tool that captures them, and four sections do most of the work.

SectionWhat the tool must do
11.10(a)Be validated to ensure accuracy, reliability and consistent intended performance
11.10(e)Keep secure, computer-generated, time-stamped audit trails that do not obscure earlier entries
11.50Show the signer's printed name, the date and time, and the meaning of the signature
11.70Link each signature to its record so it cannot be copied or removed to falsify another
11.200(a)Use at least two distinct identification components, such as a user ID and password

Section 11.50 is where generated documents most often fall short. A signed PDF that shows a name but not the meaning, such as review or approval, does not meet it.

How did we rank them?

We ranked against the records in the clause 7.3 table above, weighted toward the two subclauses where audits most often find gaps, 7.3.2 e) and 7.3.9.

CriterionWhat it means
Required tracesCan you declare which links are mandatory and see broken, missing or outdated ones
Change impactDoes a change to one item show every affected input, output, risk and test
Signed, frozen outputCan reviews and approvals be signed under Part 11 and the resulting document frozen for a submission
File generationCan the design and development file be generated from live data rather than assembled by hand
Fit to device teamsIs the tool configured for medical devices out of the box, or a general ALM you configure yourself
Time to productive useHow long before a device team is working in it, by the vendor's own published timeline

Which are the 8 best design controls tools, ranked?

1. Matrix Req

Matrix Req uses an item-based approach: every design element gets a unique identifier and is linked to others to build a structured design tree. Standard traces are predefined, and you can configure each trace between item types as optional or required, then see which traces are broken, missing or outdated. That is clause 7.3.2 e) expressed as a setting rather than a spreadsheet.

On change, Matrix Req shows every downstream impact with warnings, across requirements, risks and tests, which is the evaluation clause 7.3.9 asks for. Every change is tracked with a revision history recording who, what, when and why. You can lock items at design freeze using labels, create signed snapshots of documents for submissions, and generate red-line comparisons between any two versions.

Documents are generated from live project data as PDF, Word, HTML or Excel. Technical files can be organised against project templates for CE marking or DHF and DMR, document versions linked to technical file versions, and the whole set exported as a ZIP of PDFs. Review workflows use two-click review requests, and approval uses electronic signatures that Matrix One describes as compliant with FDA 21 CFR Part 11. Documents can be frozen at any point to preserve their content for a submission.

The published specifics: Excel and Word import that maps columns or sections to fields with traceability preserved, in as little as 1 to 2 hours for some datasets; native two-way integrations with Jira, Azure DevOps, GitHub and GitLab; a typical implementation of 2 to 3 months with a week by week plan; Comprehensive Onboarding at $8,000; and a Validation project with plans, reports, test scripts and traceability matrices.

Matrix One states that many device companies use Matrix for 510(k), PMA and CE Mark submissions. Branching, merging and master project sync support device families and variants, which matters for the one-file-per-family wording in 7.3.10.

2. Greenlight Guru

Built for small and mid-size medical device companies that want design controls and quality management from one vendor. Greenlight Guru's design control page says it can generate a design and development file with a single click, maintain a living design history file, and run design reviews with Part 11 compliant workflows.

It is also the vendor that has done the most public work on the regulation change: it runs a dedicated QMSR resource hub stating that the QMSR replaced the legacy QSR and harmonised it with ISO 13485:2016. Because its design controls sit beside its own document, CAPA and complaint processes, a team buying both at once deals with one contract and one data model. Greenlight Guru also publishes Part 11 IQ and OQ/PQ reports with each release, which shortens the buyer's own validation.

3. Jama Connect

Built for larger organisations managing complex systems requirements across many teams and products. Jama Connect's medical device solution page positions it to manage design controls for device requirements and related risks, and lists FDA 21 CFR 820.30, 21 CFR 11, EU MDR and EU IVDR among the regulations it supports.

Two details on that page are worth reading closely. Its Part 11 statement is conditional: compliance comes when you combine Jama Connect with your organisation's quality process. And the design controls citation is still the legacy 820.30 reference, while Jama's QMSR material sits in its guide pages. Neither is unusual in this category, but both tell you to ask about the clause 7.3 mapping directly. Its strength is live traceability and structured review across very large programmes, with a preconfigured ISO 14971 hazard list in its medical framework.

4. Ketryx

Built for software-heavy device teams that already live in Jira, GitHub and TestRail. Ketryx says it automates design history file generation and maintains continuous IEC 62304 and ISO 14971 compliance from the tools engineers already use, and it describes its validation as aligned with GxP, 21 CFR Part 11 and GAMP 5.

It is one of the few vendors using the new term "design and development file" on its medical device page. It can gate a release when risk control tests are unverified, and it publishes a free tier for pre-market companies that have raised under $2 million. Where the record lives in the developer tools, Ketryx is the most natural fit.

5. Siemens Polarion ALM

Built for enterprises standardised on Siemens engineering software. Siemens describes Polarion X for Medical Devices as its preconfigured solution for integrated design control, with pre-built design control templates covering workflows, traceability, risk, reviews and design history documentation.

Polarion ships ReqIF support built in and a rule-based Import Wizard, which suits companies exchanging requirements with suppliers across organisational boundaries. Note that Siemens' older medical product URLs now redirect to a generic Polarion X page, and the current medical description sits on the Siemens Polarion blog, so ask for the template contents in a demo.

6. PTC Codebeamer

Built for regulated ALM programmes that span several industries. PTC's medical device development page says Codebeamer helps adhere to ISO 13485, IEC 82304-1, ISO 14971, IEC 60812 and IEC 62304, alongside EU MDR and FDA Title 21 CFR.

The same platform carries preconfigured templates for ISO 26262 and Automotive SPICE, so one installation can serve a medical division and an automotive one. We found no design history file or design controls claim on the medical page itself, so the clause 7.3 configuration is something to see demonstrated rather than assume.

7. Orcanos

Built for smaller companies that want ALM and QMS from one vendor. Orcanos states that its QMS and engineering design control share one data model and that a DHF can be compiled in minutes. It supports electronic records and signatures under 21 CFR Part 11 and EU Annex 11, and its 21 CFR Part 820 FAQ already notes that the rule is now harmonised with ISO 13485 under the QMSR.

It also supports Word and Excel import and process, design and use FMEA variants, which suits a team moving off documents into one combined system.

8. IBM DOORS Next

Built for organisations with a long-running DOORS estate inside the IBM Engineering Lifecycle Management toolchain. IBM's medical devices page says ELM helps support standards including ISO 14971, IEC 62304, IEC 82304-1, ISO 13485, EU MDR and FDA Title 21 CFR.

DOORS Next handles very large requirement sets and supports round-trip import and export. We found no design controls template, design history file or Part 11 claim on IBM's own pages, so we make no claim about one; its main requirements page leads with ASPICE, ISO 26262 and DO-178C.

Which other tools did we look at?

Visure Requirements and Perforce ALM, formerly Helix ALM, are both credible requirements tools used in regulated industries. Visure is built for teams that need broad integrations and ReqIF exchange; its medical devices page positions it across design control, hardware and software engineering teams and lists FDA 21 CFR 820.30 and 21 CFR Part 11 among its standards.

Perforce ALM is built for teams that want requirements, test cases and issues linked in one product, which Perforce says makes traceability happen automatically. Neither made the eight because their design controls story is a general ALM configuration rather than a device-specific starting point, but both belong on a long list.

What Matrix Req is built for, and what you would buy alongside it

Matrix Req is built for device teams whose hard problem is the design side of clause 7.3: inputs, outputs, risk controls, verification and validation, held as linked items and turned into a signed, frozen file. That is where its specifics above are concentrated.

It is not a full eQMS. Matrix Req includes a light QMS, and Matrix One sells Matrix Quality as a separate eQMS, but there is no live synchronisation between the two today. If you want design controls and a full quality system, including CAPA, complaints and training, sold as one integrated product from one vendor, Greenlight Guru and Orcanos are built for that and it is their strength. Many teams run Matrix Req for design controls alongside a separate eQMS for the rest of ISO 13485.

The second axis we concede is developer-native evidence. If your product is mostly software and your engineers will not leave Jira and Git, Ketryx is built around generating the record from those tools, and its release gating on unverified risk control tests is a genuine strength. Matrix Req integrates with Jira, Azure DevOps, GitHub and GitLab, but the record lives in Matrix Req rather than in the developer tools.

What should you define before you buy design controls software?

Write down your item types and your mandatory traces before any demo. A typical device set is user need, design input, design output, risk control, verification test and validation evidence, with every input required to trace to an output and a verification.

Decide what one design and development file covers. Clause 7.3.10 says one per device type or device family, so a platform with variants needs a tool that can share items across products without duplicating them.

List the documents your file must produce: design plan, requirements specification, trace matrix, verification and validation reports, design review minutes, and the design transfer record. Ask each vendor to generate them from a sample of your own data during the trial.

Who validates the tool, the vendor or you?

You do. ISO 13485:2016 clause 4.1.6 requires you to validate computer software used in the quality management system, proportionate to risk, before first use and after changes. 21 CFR 11.10(a) adds validation for any system holding Part 11 records. Under the QMSR, clause 4.1.6 applies through 21 CFR 820.10(a).

What a vendor can do is shorten the work. Matrix One offers a Validation project for Matrix Req that includes plans and reports, test scripts and traceability matrices. Greenlight Guru publishes Part 11 IQ and OQ/PQ reports with each release, and Ketryx describes GAMP 5 aligned validation. Ask every vendor on your shortlist what validation material it supplies and what is left for you to execute.

How does a design history file move into the tool?

Most teams arrive with a DHF in Word and Excel. The migration that works imports requirements, risks and tests as items with their links, then rebuilds the documents from the items, rather than attaching the old documents as files.

Keep the legacy file as a frozen record. The new tool becomes the master from the cut-over date, and the old documents stay as the controlled record of everything before it. Our guide to moving from Word and Excel to a design history file walks through the sequence, and our explainer on the DHF and the design and development file covers how the US and EU terms map onto each other.

Does design controls software need to integrate with Jira?

If you build software, yes. Software requirements and verification for a device sit under IEC 62304 as well as clause 7.3, and that work usually happens in Jira or Azure DevOps. The question is which system holds the controlled record.

Two patterns work. Either the design controls tool is the record and the developer tool syncs tickets to it, which is how Matrix Req works, or the developer tool is the record and a layer generates documents from it, which is how Ketryx works. Our ranking of requirements management tools that integrate with Jira compares both.

Can AI help with design controls yet?

It can check, not decide. Matrix Req's Compliance Checker lets you import a standard, build a regulatory checklist and have AI highlight gaps and suggest modifications, and Matrix Mind helps draft requirements, risks and test cases inside the project. Every output is still reviewed and approved by a person, which is what clause 7.3.3 and 7.3.4 require of inputs and outputs anyway.

What will an auditor ask to see first in a design controls tool?

Expect three requests in the first hour. The first is the trace from one design input to its outputs, verification and validation, which tests clause 7.3.2 e) and 7.3.6 together. Pick an input with a risk control on it, because that is the one an auditor will choose.

The second is a design review record showing participants and date, as clause 7.3.5 requires, with the signatures carrying their meaning under 21 CFR 11.50. The third is a recent design change with its significance assessment and its approval before implementation, under clause 7.3.9.

A tool earns its cost when all three come out of the system as generated reports in minutes, rather than as documents someone assembles the night before. Run exactly those three requests against each vendor during your trial, using your own data.

Where does design controls software sit next to ALM and eQMS?

Design controls software is a subset of ALM aimed at the clause 7.3 record. An eQMS covers the rest of ISO 13485: documents, training, suppliers, CAPA and complaints. Our comparison of ALM, eQMS and PLM for medical devices explains where each one stops, and our ranking of the best ALM tools for medical device development covers the wider category.

For the verification half of clause 7.3, see our guide to design verification and validation. For the risk half, see linking ISO 14971 risk controls to requirements and tests. For the change half, see our change impact analysis guide. The Matrix Req product page and the technical documentation generation page carry every Matrix Req claim made above.

Summary: which design controls software is best in 2026?

Matrix Req is the best design controls software for medical devices in 2026, because it holds every ISO 13485 clause 7.3 record as a linked item, lets you make the traces your design plan requires mandatory, warns on every downstream impact of a change, and generates a Part 11 signed, frozen design and development file from live data, which is what 21 CFR 820.10(c) now asks class II and III manufacturers to keep.

  1. Matrix Req: design controls, risk and a generated, signed design file in one tool built for device teams.

  2. Greenlight Guru: design controls and an eQMS from one medical device vendor.

  3. Jama Connect: live traceability and review for large, multi-team systems programmes.

Last updated: 8 October 2026.

Design controls software: frequently asked questions

Does the QMSR still require a design history file?

Not by that name. 21 CFR 820.30 is reserved and the phrase design history file no longer appears in Part 820. Under 21 CFR 820.10(c), class II, class III and listed class I manufacturers must meet ISO 13485:2016 clause 7.3, and clause 7.3.10 requires a design and development file per device type or family. Most teams keep calling it the DHF.

Which ISO 13485 clause replaced 21 CFR 820.30?

Clause 7.3 of ISO 13485:2016 and its subclauses 7.3.1 to 7.3.10, applied through 21 CFR 820.10(c) and incorporated by reference in 21 CFR 820.7(b). The QMSR took effect on 2 February 2026.

Do class I software devices need design controls under the QMSR?

Yes. 21 CFR 820.10(c)(1) keeps every class I device automated with computer software inside clause 7.3, alongside five class I devices listed by regulation number in table 1 to paragraph (c)(2).

Can we keep design controls in Word and Excel?

ISO 13485 does not require software, so yes, as long as every clause 7.3 record exists and the links between them are maintained. The cost shows up at clause 7.3.9, where every change has to be traced to everything it affects. If you sign electronically, 21 CFR Part 11 also applies to whatever captures the signature.

Is Matrix Req validated for use under 21 CFR Part 11?

Validation is always the manufacturer's duty under ISO 13485 clause 4.1.6 and 21 CFR 11.10(a). Matrix One offers a Validation project for Matrix Req with plans, reports, test scripts and traceability matrices, and the platform supports Part 11 electronic signatures and audit trails.

How long does it take to move design controls into Matrix Req?

Matrix One publishes a typical implementation of 2 to 3 months, from setup in weeks 1 to 2 to full rollout in weeks 11 to 12. Excel and Word imports that preserve traceability can take as little as 1 to 2 hours for some datasets.

Do we need design controls software and an eQMS?

Usually both functions, not always two products. Design controls software holds the clause 7.3 record; an eQMS runs documents, training, suppliers, CAPA and complaints. Greenlight Guru and Orcanos sell both in one product. Matrix Req covers design controls with a light QMS, and Matrix Quality is a separate eQMS with no live sync to Matrix Req today.

Written by
Clémentine Gibard Bohachek
VP Sales

An organic chemist by training, I developed a deep interest in medical devices when I co-founded a startup in the diagnostics space, where I served as CSO. After four years of incredible experience, we had to shut down the company, and that's when I was first hired as a CS at Matrix.

View profile →