FDA’s Data Integrity Warning for Device Submissions: What Manufacturers Should Learn About Third-Party Testing
FDA’s 2026 medical device data integrity notification highlights the risk of unreliable third-party testing data. Learn how manufacturers can strengthen supplier qualification, evidence review, and submission readiness.
By Melita Ball

Medical device manufacturers often rely on third-party testing laboratories to generate critical evidence for premarket submissions. That reliance can be appropriate and necessary. It can also create a serious compliance risk if the manufacturer treats the test report as the starting point and ending point of evidence review.
FDA's June 2026 medical device data integrity notification puts that risk in clear terms. The agency has noted an increase in unreliable testing data generated by third-party testing facilities on behalf of device manufacturers and sponsors. FDA reminded sponsors and manufacturers to carefully evaluate third parties and independently verify testing results before submitting data to the agency.
For manufacturers, the message is direct: outsourcing the test does not outsource responsibility for the evidence.
Third-party evidence is still manufacturer evidence
A test laboratory may perform the work, but the manufacturer is the party that uses the data to support safety, performance, cybersecurity, substantial equivalence, or benefit-risk arguments. If the data is unreliable, incomplete, copied, falsified, or poorly controlled, the manufacturer's submission can be delayed or undermined.
This is not just a supplier quality issue. It is a submission readiness issue. It is also a design control issue, because verification and validation evidence must support the design inputs, risk controls, claims, and intended use of the device.
Manufacturers should resist the temptation to manage third-party testing as a procurement transaction. The better model is a controlled evidence lifecycle:
- Define what evidence is needed and why.
- Qualify the provider for the specific test type and regulatory purpose.
- Confirm the protocol, standards, samples, acceptance criteria, and data expectations before testing begins.
- Review raw data, deviations, anomalies, and calculations before relying on the final report.
- Connect the results back to design inputs, risk controls, cybersecurity requirements, and submission sections.
A final report without that surrounding control may not be enough.
Why this matters more now
Several trends make third-party data integrity especially important in 2026.
First, device submissions are more evidence-intensive. Software, cybersecurity, usability, biological safety, electrical safety, performance testing, and AI-enabled functionality can all require specialized technical evidence.
Second, manufacturers are under pressure to move quickly. Lean teams, investor timelines, limited internal test capacity, and global launch plans can lead to compressed review cycles. When speed becomes the dominant priority, evidence quality can suffer.
Third, supply chains are more distributed. Manufacturers may work with laboratories, engineering partners, contract manufacturers, cybersecurity testers, and consultants across multiple jurisdictions. Each handoff introduces the possibility of unclear ownership.
Fourth, FDA is paying attention. When the agency states that unreliable data from certain third-party testing facilities may be rejected, manufacturers should treat that as a signal to review their own controls.
Supplier qualification needs to be specific
A generic approved supplier list is not enough for high-impact testing. A laboratory may be qualified for one test method but not another. A provider may have appropriate equipment but weak data controls. A cybersecurity testing partner may be technically capable but unfamiliar with medical device submission expectations.
Supplier qualification should consider:
- Accreditation, scope, and test method relevance
- Experience with medical device or IVD submissions
- Data integrity controls and raw data availability
- Personnel competence and independence
- Equipment calibration and software validation controls
- Subcontracting practices
- Deviation handling and retest policies
- Cybersecurity and confidentiality controls
- Prior regulatory concerns, when known
The qualification should be documented, risk-based, and periodically refreshed. For critical evidence, manufacturers should also define what records must be provided with the final report.
Protocol control prevents downstream surprises
Many evidence problems begin before the test starts. If the protocol is vague, the wrong sample is used, the acceptance criteria are unclear, or the test method does not match the regulatory question, the final report may be difficult to defend.
Before testing begins, manufacturers should confirm:
- The device configuration and software version
- The sample selection and traceability
- The applicable standards or internal methods
- The intended regulatory use of the test
- The acceptance criteria and rationale
- Environmental or use-condition assumptions
- Required raw data and data format
- Deviation reporting expectations
- The review and approval path for protocol changes
This discipline is especially important for SaMD, AI-enabled devices, cybersecurity testing, and devices with frequent software or design updates. A small configuration mismatch can create a large submission problem.
Independent verification should be built into the process
FDA's reminder to independently verify testing results should not be interpreted as a last-minute review of the PDF report. Manufacturers need a process that confirms whether the data can be relied upon.
That review may include checking raw data against summary tables, confirming sample traceability, reviewing deviations, comparing results against acceptance criteria, verifying calculations, and ensuring that conclusions are supported by the evidence.
For high-risk testing, manufacturers may also perform technical peer review, require access to raw data, conduct supplier audits, or use an independent expert to evaluate anomalies.
The point is not to duplicate every test. The point is to maintain enough control to know whether the evidence is credible, complete, and submission-ready.
Data integrity belongs in management review
When third-party testing evidence affects submission timing, market access, or patient safety, leadership should understand the risk. Management review should include trends in supplier performance, test failures, retesting, data anomalies, submission delays, and recurring issues with external providers.
This is where quality, regulatory, engineering, clinical, cybersecurity, and operations need a shared view. If testing issues are treated as isolated project setbacks, the organization may miss systemic weaknesses in supplier qualification, protocol control, or evidence review.
What manufacturers should do now
Manufacturers should start with a targeted review of high-impact third-party evidence used in pending or planned submissions. Focus first on tests that support safety, performance, cybersecurity, risk controls, substantial equivalence, or essential requirements.
Ask these questions:
- Do we know exactly which third parties generated each critical evidence package?
- Were they qualified for that specific test and regulatory use?
- Do we have approved protocols, sample traceability, and acceptance criteria?
- Did we review raw data, deviations, and calculations before relying on the report?
- Are test results linked to design inputs, risk controls, and submission claims?
- Would we be able to explain our review process during an FDA interaction?
If the answer is uncertain, the company should strengthen the process before the next submission deadline forces a rushed decision.
How IntelaSolve helps
IntelaSolve gives manufacturers a connected way to manage the evidence behind regulated products. Supplier qualification, design verification, risk management, cybersecurity documentation, quality records, document control, and submission readiness should not live in separate systems that require manual reconstruction.
With IntelaSolve, the goal is to help teams maintain traceability from evidence planning through supplier control, test execution, review, approval, and submission use. That kind of connected compliance infrastructure is especially valuable when manufacturers rely on outside laboratories and technical partners.
FDA's 2026 data integrity message should not make manufacturers afraid of third-party testing. It should make them more disciplined. The right partners, governed by the right quality system controls, can still support efficient product development and strong submissions.
Relying on third-party laboratories for your next FDA submission? Request an IntelaSolve Compliance Readiness Analysis to evaluate whether your supplier qualification, test evidence review, and submission traceability are ready for regulatory scrutiny.
