How to Write Medical Device SOPs People Actually Follow
A practical guide for building clear usable procedures within a right sized MedTech QMS.
Article Overview
Effective medical device SOPs translate regulatory and quality requirements into a process your team can perform consistently. The best procedures reflect the company, product, risk, and people involved. They also make responsibilities, decisions, records, and approvals clear without adding unnecessary complexity.
Start with the process: Define how work should happen before drafting the document.
Apply the requirements: Identify the regulatory, quality, and risk controls the process must satisfy.
Write for the user: Make the procedure easy to understand at the point of work.
Right size the controls: Use the approvals, handoffs, and evidence your company actually needs.
Keep it current: Control revisions, train affected employees, and update the SOP when the process changes.
A medical device SOP is a controlled document that explains how a quality or operational process is performed. An effective SOP gives people enough direction to complete the process correctly and consistently, while also producing the evidence the quality management system needs.
That sounds simple, but many MedTech startups begin in a very different place. They learn that they need a quality management system, hire a consultant, and receive a Quality Manual, SOPs, templates, forms, and training records. The documents exist, but the team has not necessarily implemented a system it understands or uses.
The gap appears quickly. Employees work around procedures that do not fit the business. Records are completed after the fact. An SOP assigns work to departments that do not exist. As an audit, submission, financing milestone, or commercial launch approaches, those mismatches become harder to correct.
The practical test is straightforward. If an employee needs to perform the process tomorrow, does the SOP make the work easier to understand and complete? If the procedure routinely requires someone from Quality to translate it, the SOP probably needs improvement.
How SOPs Fit Into a Medical Device QMS
Medical device regulations and standards establish requirements, but each manufacturer must translate those requirements into its own processes. In the United States, the FDA Quality Management System Regulation became effective on February 2, 2026 and incorporates ISO 13485:2016 by reference. These frameworks set expectations for the quality system. Your procedures define how your organization meets the applicable expectations in practice.
Two companies can have compliant design and development processes while implementing them differently. A five-person startup developing its first device should not automatically adopt the same approval structure, handoffs, and controls as a multinational manufacturer.
Every requirement written into an SOP becomes something the company is expected to follow. Extra committees, reviews, forms, or deadlines do not automatically make a procedure more compliant. They can create more opportunities for the company to depart from its own process.
This is why SOP development should begin with the business, the device, and the applicable requirements. For more background, see QuickVault’s guides to SOP management, ISO 13485, and the current 21 CFR Part 820 and QMSR framework.
Seven Steps to Write SOPs Teams Can Follow
1. Define the Purpose and Applicable Requirements
Begin by defining why the process exists and what it must accomplish. Identify the regulatory requirements, standards, quality objectives, and internal policies that apply. Then consider what could happen if the process fails and which controls are needed to manage that risk.
This keeps the procedure focused. It also prevents the team from copying requirements that are not relevant to the device, market, or stage of the company.
2. Map How the Process Should Work
Before writing the SOP, map the process from trigger to completion. Ask who initiates it, what information is needed, what activities occur, where decisions are made, what approvals have a clear purpose, and what evidence must be retained.
Document the intended operating reality, not the process you think an auditor wants to see. If the current workflow has gaps, resolve those gaps before turning it into a controlled procedure.
Trigger: What event or input starts the process
Owner: Who is accountable for completing it
Participants: Who performs, reviews, or approves specific work
Decision points: What decisions must be made and by whom
Outputs and records: What the process produces and what evidence must be retained
Interfaces: Which other QMS processes, documents, suppliers, or systems are affected
3. Assign Work to Real People and Roles
Startups often have people wearing several hats rather than fully staffed departments. Avoid adopting language such as “Quality shall review” or “Manufacturing shall approve” unless those roles clearly exist and the responsibility is understood.
For each major activity, identify who performs the work, who reviews it, who makes the final decision, and whether any responsibility is outsourced. The company can rely on outside expertise, but it still needs an internal owner who understands the process and can explain how it works.
4. Match the Controls to the Device and Risk
The QMS should reflect the product the company is developing. Software, sterile single-use products, implantable devices, IVDs, and complex electromechanical systems create different operational needs.
Supplier controls provide a useful example. If a contract manufacturer produces a critical component whose failure could affect safety or performance, the oversight should reflect that risk. Applying the same controls to an office supply vendor would add work without meaningfully improving product quality.
Use the same principle when defining reviews, approvals, records, escalation paths, and training. Control should be proportionate to the applicable risk and requirement.
5. Write for the Person Performing the Work
Use direct language, clear sequence, and terms your team understands. State the responsible role and required action. Define unfamiliar terms, link or reference the forms and records the user needs, and make decision points easy to find.
Keep the SOP at the right level. The procedure should explain the process, responsibilities, controls, and required evidence. A separate work instruction can provide detailed task steps when the activity requires screen-level, equipment-specific, or highly technical direction.
Remove approvals, handoffs, and documentation that have no clear regulatory, quality, or operational purpose. Simplicity is useful only when the procedure still provides enough control and direction to produce a consistent result.
6. Test the SOP Before Approval
Ask someone who performs the process to walk through the draft using a realistic scenario. Watch for unclear responsibilities, missing inputs, vague decisions, unavailable forms, and steps that do not match the actual workflow.
This review should test whether the procedure works, not only whether the wording sounds formal. Resolve the gaps before approval and training so employees are not forced to invent workarounds later.
7. Control, Train, and Improve
Once approved, the SOP must remain controlled and accessible. Employees should use the current version and complete any required training before performing affected work. Obsolete versions should be removed from use while the required history is retained.
Review the SOP when the process, product, organization, supplier relationship, system, or applicable requirement changes. Complaints, audit findings, deviations, nonconformances, and CAPAs may also reveal that a procedure no longer provides enough direction or control.
A connected document and change control process helps teams manage revisions, approvals, effective dates, training impact, and the evidence associated with each change.
How to Use SOP Templates and Consultants
Templates and consultants can accelerate SOP development, but they should provide a starting structure rather than a finished quality system. A template cannot know your device, team, suppliers, tools, risk profile, or regulatory strategy.
Review every role, approval, handoff, timeline, form, and record before adopting it. Remove what does not apply, add what the process requires, and confirm that the people responsible can perform the procedure as written.
External consultants can help interpret requirements, identify gaps, and bring experience from other companies. The startup still needs to understand and own the resulting system. If nobody inside the company can explain the process without calling the consultant who drafted it, implementation is incomplete.
How Detailed a Medical Device SOP Should Be
A medical device SOP should contain enough detail for a trained employee to perform the process consistently and generate the required evidence. The appropriate level depends on the complexity of the activity, the user’s experience, the consequences of error, and whether a separate work instruction provides more detailed steps.
A practical SOP commonly identifies the purpose, scope, responsible roles, required inputs, process steps, decision points, approvals, outputs, records, references, and related training. The exact format can vary, but the content should make the process understandable and auditable.
Signs an SOP Needs Improvement
Employees rely on workarounds: The documented process does not match how the work is actually completed.
Quality must translate the procedure: The language, responsibilities, or decision points are unclear.
Records are created after the fact: The workflow does not make documentation part of the work.
Approvals have no clear purpose: The process contains inherited steps that do not add control or evidence.
The SOP names departments that do not exist: The procedure was copied from a company with a different structure.
Changes in one system do not reach the SOP: Document control, training, risk, and change processes are disconnected.
How an eQMS Supports Better SOP Management
A well-written SOP still becomes difficult to follow when employees cannot find the current version, approvals move through email, training is tracked separately, or changes are disconnected from risk and related records.
An electronic quality management system can support the procedure throughout its lifecycle by managing review and approval workflows, revision history, effective dates, access, training assignments, and change impact. QuickVault connects SOP management and document control with the broader quality system so teams can maintain clear responsibilities and traceable evidence as the company grows.
What Is the Difference Between an SOP and a Work Instruction?
An SOP describes how a process is controlled, including its purpose, scope, responsibilities, activities, decisions, approvals, and records. A work instruction usually provides more detailed directions for completing a specific task within that process. Companies can use both when separate levels of detail make the work clearer.
Is There One Required Format for a Medical Device SOP?
There is no single universal layout that every medical device SOP must follow. The format should comply with your document control process and make the applicable responsibilities, activities, controls, and records clear. Consistency across the QMS helps employees use procedures and helps reviewers understand them.
Can a MedTech Startup Use an SOP Template?
Yes. A template can provide a useful structure and help a startup avoid beginning with a blank page. Every section still needs to be evaluated against the company’s device, regulatory pathway, organization, suppliers, tools, and risks. Delete requirements that do not apply and add the controls the actual process needs.
Who Should Write and Approve an SOP?
The process owner and people who understand the work should help develop the SOP. Quality and Regulatory can help interpret requirements and confirm that the process fits the QMS. Approval roles should be defined by the company’s document control process and should reflect meaningful accountability rather than inherited titles.
When Should a Medical Device SOP Be Updated?
Update an SOP when a change affects the process, responsibilities, systems, suppliers, product, risk controls, records, or applicable requirements. Audit findings, complaints, deviations, nonconformances, and CAPAs may also identify a needed revision. Planned reviews should follow the interval and criteria defined in the company’s QMS.
Build the SOPs Your Medical Device Team Can Use
The strongest SOP is not the longest or most complicated. It is the one that helps your team perform the process consistently, manage the relevant risk, retain objective evidence, and meet applicable requirements.
Before drafting, ask one question: What is the simplest effective process our company can follow that appropriately manages the risks of our device and meets our regulatory obligations?
The answer should shape the workflow first and the SOP second.
Want to see how QuickVault helps MedTech teams manage controlled documents, training, change, risk, and quality records in one connected platform? Book a demo of QuickVault.