Qhubio
    Industry Requirements

    Medical Device Cpk Requirements

    4 min read Last updated

    Medical-device validation criteria must be justified from product risk, process knowledge, specifications, and the approved validation protocol. ISO 13485 and FDA requirements do not prescribe one universal Cpk value.

    The engineering question this page answers

    How does capability evidence fit into IQ/OQ/PQ validation and risk-based acceptance without inventing a universal FDA or ISO 13485 Cpk threshold?

    Decision logic

    Define characteristic risk class from ISO 14971 risk analysis ↓ Set acceptance criterion in the validation protocol — approved before execution ↓ Confirm measurement system is qualified with uncertainty analysis, not only MSA ↓ OQ: challenge process at worst-case within specification ↓ PQ: capability under normal production, sampling justified by risk ↓ If criterion missed → CAPA, not silent re-run

    Capability study readiness

    Typical industry requirements

    • Predefine the index, sigma estimator, sample plan, and acceptance criterion.
    • Demonstrate stability and measurement adequacy before interpreting capability.
    • Use risk-based criteria and alternative methods for non-normal or attribute outputs.

    Industry context — why these targets exist

    Neither ISO 13485 nor 21 CFR Part 820 specifies a numeric Cpk. Capability is one input to process validation (IQ / OQ / PQ) and to risk-based acceptance under ISO 14971. Acceptance criteria are set in the validation protocol, justified by risk and by measurement uncertainty, and approved before execution. Any "medical device requires Cpk 1.33" claim is a customer or internal convention, not a regulation.

    Evidence and requirement scope

    Governing and program requirements

    Contractual requirement

    Validation and acceptance are risk-based and controlled by the approved validation protocol and quality system.

    Limitation: These sources provide regulatory and QMS context, not a universal fixed Cpk clause.

    Verify: Approved validation protocol, risk file and product acceptance specification.

    Quality Management System Regulation — U.S. Food and Drug AdministrationISO 13485 — Medical devices — Quality management systems — ISO

    Industry practice

    Industry practice

    Use capability evidence as one input to process validation rather than a substitute for validation.

    Engineering recommendations and risks

    Engineering recommendation

    Confirm measurement-system suitability and risk-based sampling before interpreting an index.

    Program confirmation

    • Verify the approved validation protocol and product-specific acceptance criteria.

    Engineering procedure

    1. Reference the risk file — capability target must trace to a hazard and harm severity, not to a copy-paste 1.33.
    2. Author the validation protocol with pre-approved acceptance criteria and sampling rationale.
    3. Qualify the measurement system with traceable calibration and documented uncertainty.
    4. Execute OQ at process window edges to demonstrate capability across worst-case operating conditions.
    5. Execute PQ under representative production, with statistically justified sample size.
    6. Log every deviation; a failed criterion is a CAPA input, not a study to re-run.
    7. Re-validate on defined triggers: design change, process change, supplier change, drift observed in monitoring.

    Typical failure modes

    • Cpk target set by copy-paste from another product, not from risk analysis.
    • Sampling plan without documented rationale.
    • Measurement uncertainty not quantified; Cpk reported to two decimals inside gauge noise.
    • OQ executed inside a narrow, comfortable window rather than the validated worst case.
    • Traceability gap between measured lot, calibration record and DHR.
    • Re-validation triggers not defined; drift in monitoring never escalates.

    Engineering insight

    • Capability numbers without measurement uncertainty are unauditable — Cpk within measurement noise is not capability.
    • Sampling "n = 30" without a risk-based rationale is the most common validation audit finding.
    • OQ that only tests nominal conditions is not OQ; it is PQ mislabeled.
    • A "successful" PQ that hides an OQ excursion will surface as a field complaint months later.

    When NOT to use this metric

    • Do not use capability alone as validation evidence — IQ, OQ and PQ together form validation.
    • Do not report Cpk without stating measurement uncertainty.
    • Do not rely on a single PQ result for the life of the product; define re-validation triggers.

    Relationship to other capability metrics

    • Cpk vs measurement uncertainty: Cpk is only meaningful when the ratio of uncertainty to tolerance is documented and acceptable.
    • Capability vs sampling: Sample size traces to risk, not to statistical convenience.
    • PQ Cpk vs monitoring: Ongoing monitoring must be able to detect drift within the validated window.

    Engineering notes

    • Never claim regulatory compliance from a numeric Cpk alone — validation is a documented process, not a number.
    • Never approve a protocol without pre-defined acceptance criteria.
    • Never close a deviation without a CAPA linkage.

    Continue the investigation

    Use the Process Capability Calculator to prepare OQ/PQ evidence, and cross-read Process Capability Study and Process Capability Analysis. For non-conformance route to 8D / CAPA and update the Process FMEA.

    Verification checklist

    • Acceptance criterion traced to risk analysis
    • Validation protocol approved before execution
    • Measurement uncertainty quantified and documented
    • Sampling rationale documented, not defaulted
    • OQ executed at worst-case within specification
    • PQ executed under representative production conditions
    • Re-validation triggers defined and monitored

    Assumptions and applicability

    • Process condition: statistical stability is required.
    • Distribution assumption: use a distribution model justified for the data.
    • Confirm process stability and measurement-system adequacy before interpreting a capability index.
    • Use a justified distribution model or non-normal method when the normal model is unsuitable.
    • Numerical targets shown on industry pages are common examples, not universal requirements. The contract, drawing, customer-specific requirement, Control Plan, and validation protocol take precedence.

    Sources and engineering references

    External engineering references used for this page. Qhubio applies these references to the practical guidance above.

    Frequently asked questions