What FDA Actually Proposed, and What It Did Not

Start with the text, because the details matter more than the headlines. The proposed rule appeared in the Federal Register on Monday, July 13, 2026, at 91 FR 42888 through 42906, under Docket No. FDA-2025-N-6075 and RIN 0910-AI94.1 FDA’s press announcement went out on July 10, 2026, three days before publication.3 The comment period closes at 11:59 p.m. Eastern Time on September 11, 2026, and FDA states that late comments will not be considered.1

The rule does two separate things. The first part creates a registration pathway for distributed manufacturing. The second part aligns the registration and listing regulations for foreign establishments with section 2511 of the PREVENT Pandemics Act, so that a foreign establishment whose drug is further processed at another foreign establishment before import still has to register and list.1 FDA estimates that about 1,625 currently unregistered foreign establishments would newly register under that second part.1 This article is about the first part, but quality leaders should read the second, because the same supply-chain visibility logic runs through both. FDA says the rule is issued in part under CDER’s Framework for Regulatory Advanced Manufacturing Evaluation (FRAME) initiative, which names distributed manufacturing as one of its priority technologies alongside end-to-end continuous manufacturing and artificial intelligence.6

Several law firm advisories and trade press summaries have already covered the legal mechanics in detail, including the eligibility criteria, the single-legal-entity requirement, and the advice to assess current operations and upstream foreign suppliers against the proposal.17181920 They are worth reading. What follows draws on the Federal Register text directly and then turns to the operational question those summaries leave open.

The three new definitions

FDA proposes to amend 21 CFR 207.1 by revising the definition of “establishment” and adding three new terms. The proposed regulatory text is worth reading in the original, because the eligibility conditions are written into the definitions themselves rather than into a separate qualification section.2

A distributed manufacturing establishment (DME) means the distributed manufacturing hub together with one or more distributed manufacturing units that are, in the proposed text, “(1) demonstrated to be and that remain equivalent in design and operation at any location, (2) that engage in the manufacture, preparation, propagation, compounding, or processing of the same drug(s) at one or more physical location(s), and (3) under the oversight and control of a single quality unit, which has a management structure located at the distributed manufacturing hub and has implemented a unified pharmaceutical quality system.”2 On top of that, the hub and all units collectively must operate under one management pursuant to a manufacturing strategy designed to be decentralized, and must have been subject to a preapproval inspection in connection with an approved application that describes the decentralized strategy for at least one drug in each profile class the DME manufactures.2 A DME must include either at least one unit capable of moving or at least two stationary units.2

A distributed manufacturing hub means “the place of business at one general physical location that is the primary location of the quality unit responsible for implementing the unified pharmaceutical quality system to direct, monitor, and control the manufacture of drugs to ensure product quality at the distributed manufacturing establishment, including ensuring that all distributed manufacturing units within the distributed manufacturing establishment at any location are and remain equivalent in design and operation.”2

A distributed manufacturing unit (DMU) means “a physical unit engaged in the manufacture, preparation, propagation, compounding, or processing of a drug(s) that is generally deployed, or put into effect, at a separate location from the distributed manufacturing hub and that may further move from one general physical location to another if the unit is capable of mobility.”2

Notice what is missing. The proposed rule uses the phrase “unified pharmaceutical quality system” (UPQS) in every definition and throughout the preamble, but it does not define the term in the regulatory text. The preamble describes it functionally: under a UPQS, the quality unit’s personnel “develop the policies and procedures that govern manufacturing operations for the entire DME; determine appropriate staffing and the personnel reporting structure for the entire DME; and conduct the overall lifecycle management for all DMUs.”1 FDA also states it intends to provide separate guidance on CGMP compliance as applied to distributed manufacturing.1 That guidance has been on CDER’s list since 2023 under the working title “Approaches to Meeting CGMP Requirements for Distributed Manufacturing,” and as of this writing it has not been issued.424 FDA explicitly asks whether there are other terms it should define, which is one of the most useful openings for comment.1

The registration mechanics in brief

5 daysCalendar days after the first domestic hub or unit begins commercial manufacture to register the DME, or to confirm a new or relocated unit has started (proposed 207.21(b), 207.29(b))2
30 / 120Calendar days of advance notice before relocating a mobile unit within or to the United States (30) or within or to a foreign country (120) (proposed 207.29(b)(4))2
Sept 11, 2026Comment deadline, 11:59 p.m. Eastern, Docket No. FDA-2025-N-6075. FDA says late comments will not be considered1

FDA proposes to assign the Unique Facility Identifier and the FDA Establishment Identifier (FEI) to the hub, and to assign each DMU its own unit identifier (the preamble suggests something like a sub-FEI) that both distinguishes the unit and ties it to its hub.1 Registration information for a DME would include the location of each unit, which may be a physical address or GPS coordinates.2 Adding a unit is an expedited update due within five calendar days of the domestic unit starting commercial manufacture, or before a foreign unit’s product is imported. Removing a unit, changing the hub’s address, or changing the DME’s name is an expedited update due within 30 calendar days.2

Mobile units get their own timeline. Before a mobile unit moves, the registrant must notify FDA at least 30 calendar days in advance for a move within or to the United States, or at least 120 calendar days for a move within or to a foreign country. The notice must include the unit identifier, departure and destination locations, anticipated dates, and the anticipated date manufacturing will start at the new location. After arrival, the registrant must confirm within five calendar days that manufacturing has begun.2 FDA says the two periods reflect how long it takes to prepare a domestic versus a foreign inspection, and specifically asks for comment on whether they are appropriate.1

This is a proposed rule. None of the definitions, timelines, or identifiers above are in effect. FDA proposes that any final rule take effect 30 calendar days after publication and asks for comment on that date too.1 Companies should treat everything in this article as preparation for a framework that may change, not as a description of current law. Today, each location that manufactures a drug still registers separately under the existing definition of “establishment” in 21 CFR 207.1 as a place of business under one management at one general physical location.14

What is deliberately excluded

Two exclusions tell you what FDA is really testing for. First, the pathway is not available to a network of unaffiliated contract manufacturers making the same drug at different sites. FDA’s reasoning is that unaffiliated entities “would operate under different management that would not have the direct authority to manage another entity’s quality system,” and that “potentially competing quality systems” make it difficult to ensure equivalence is maintained.1 Second, third-party relabelers, repackers, and salvagers cannot be part of a DME because they would not meet the requirement of having a UPQS.1 FDA does note the registrant must be a single legal entity and asks for comment on whether other distributed models should be covered.1

The preamble also draws a line between a genuine hub and a company that has merely centralized a few quality functions. A firm that makes the same drug at several existing plants and consolidates complaint coordination or global procedures at headquarters has not, in FDA’s view, implemented a UPQS.1 That distinction is the whole point of this article. Centralizing a function is not the same as running one quality system.

The consequence of losing equivalence. Under proposed 207.29(b)(3)(i), a registrant must remove a unit from the DME when it stops manufacturing there, or when the unit “no longer remains equivalent in design and operations” and the registrant has not taken steps to restore equivalence.2 The preamble goes further: an establishment registered as a DME that no longer meets the definition “would not be duly registered, and any drugs manufactured at such an establishment would be deemed to be misbranded” under section 502(o) of the FD&C Act.1 Equivalence is not a one-time qualification claim. It is a continuing condition of the registration, and losing it has a product-level consequence.

One Registration Means One Quality System: The Operational Test

Read the definitions again with an operations lens and a pattern appears. FDA is not asking whether a company has a quality unit. Every CGMP manufacturer has one; 21 CFR 211.22 requires a quality control unit with “the responsibility and authority to approve or reject all components, drug product containers, closures, in-process materials, packaging material, labeling, and drug products, and the authority to review production records.”10 FDA is asking whether one quality unit, located at one hub, exercises that authority over every unit in the network, and whether the company can show it.

The word that carries the weight is “demonstrated.” Units must be “demonstrated to be and that remain equivalent in design and operation at any location.”2 A demonstration is a body of records. The preamble makes clear that FDA expects to look at those records during the preapproval inspection that is itself a condition of eligibility: “For DM, the opportunity during a preapproval inspection to review the effectiveness of the UPQS is especially important to confirm that the UPQS is capable of managing changes in manufacturing operations to ensure equivalency in design and operation across DMUs.”1

This connects to ICH Q10, which FDA adopted as guidance in 2009. Q10 describes a pharmaceutical quality system that spans the product lifecycle and names management responsibility, knowledge management, and quality risk management as its foundations. It also expects management review of performance indicators such as deviations, CAPA, and change management.9 A hub that cannot produce a management review covering every unit does not have a Q10-style system across the network, whatever the org chart says.

The stakeholder feedback FDA gathered through its October 2022 discussion paper and public workshop, and summarized in November 2023, anticipated this.5 Stakeholders “supported the reasoning that a centralized PQS model is essential to DM for CDER-regulated products,” and several suggested that “existing tools, such as cloud-based data management systems and digital connections, could be applied to permit a centralized PQS site to oversee and ensure consistent drug product quality across all manufacturing locations under its control.”4 Stakeholders also proposed that a centralized PQS could “provide oversight and consistency in document management and training, deviation identification and handling, investigations, change controls, corrective actions and preventive actions (CAPA), and batch releases.”4 That list is, in effect, the outline of a readiness review. The rest of this article takes each item in turn.

The registration system and the quality system have to agree

One more framing point before the detail. Under this proposal, the registration record becomes a mirror of the quality system’s own view of the network. The unit identifier FDA assigns has to match something inside the company: an equipment record, a system instance, a validated configuration. The proposed relocation notice requires departure and arrival dates and the date manufacturing starts. Those are also change control fields. If the quality system and the registration system disagree about which units exist, where they are, and when they started producing, one of them is wrong, and an investigator can find the discrepancy by comparing two documents.

Registration event (proposed)Quality system record that must already existWhere it usually breaks
Add a unit (update within 5 days of commercial manufacture)Qualification package showing equivalence to the reference unit; system instance added to the validated inventory; operator qualification at the host siteThe unit starts commercial batches on a “temporary” configuration before the equivalence package is closed
Relocate a mobile unit (30 or 120 days advance notice)Change control opened well before the notice, with requalification plan for the destination (utilities, environment, connectivity)Change control is opened after the move is scheduled, so the notice window is already too short
Confirm manufacturing started at new location (within 5 days)Requalification approved; batch record template released for the new location; audit trail confirmed activeThe first batch runs while requalification is “in review”
Remove a unit for loss of equivalence (within 30 days)Deviation or change control that declares the unit non-equivalent and quarantines or evaluates affected batchesNobody owns the decision that a unit has crossed from “deviating” to “no longer equivalent”
Annual review of registration (October through December)Annual product review and management review that reconcile the unit list against the live inventoryThe annual registration update is done by regulatory affairs from last year’s list

The Computerized System Inventory: Every Unit, Every Instance, Every Version

The first thing an investigator asks about computerized systems is what they are. 21 CFR 211.68 permits “automatic, mechanical, or electronic equipment or other types of equipment, including computers, or related systems” in manufacturing, provided the equipment is “routinely calibrated, inspected, or checked according to a written program designed to assure proper performance,” with written records maintained.11 21 CFR 11.10(a) requires “validation of systems to ensure accuracy, reliability, consistent intended performance, and the ability to discern invalid or altered records.”15 Neither obligation can be met for a system that is not on the inventory.

In a traditional plant, the inventory is a list of systems at one address. In a distributed establishment, a single “system” often exists as many instances: one manufacturing execution or control layer per unit, one set of instrument firmware per unit, one connectivity stack per unit, and one central platform at the hub that aggregates them. Equivalence “in design and operation” has to be shown at the level of those instances, because that is the level at which the units can drift apart.

What a distributed inventory needs to record

The practical fix is to extend the inventory so that every entry is keyed to a unit and a location, not just to a system name. At a minimum, each unit’s entry should carry:

  • The unit identifier that will appear in the registration, so the quality system and the registration use the same key. The proposed rule says the identifier is “important for traceability.”1 Traceability is only real if the identifier appears in internal records too.
  • The current location and the location history, including the dates each relocation started and ended. For a mobile unit, location is a controlled attribute, not a note.
  • Every software and firmware version on the unit, and the reference configuration it must match. Equivalence at the design level means the same validated configuration, and any divergence should be visible as a diff rather than discovered during an investigation.
  • The connectivity state: whether the unit is online to the hub, on a store-and-forward mode, or fully disconnected, and the validated behavior in each state.
  • The qualification status at the current location. FDA’s preamble is explicit that relocation “introduces multiple, independent factors (e.g., climate, utilities) that could impact its ability to have equivalent design and operations at the new location,” and that equivalence “would need to be evaluated and confirmed prior to manufacturing at the new location and through continued validation and monitoring, even though it is the same DMU.”1 The inventory should therefore show qualification as a property of the unit at a location, not of the unit alone.
  • The hub-side platform components that the unit depends on for release, review, and record retention, so that a change at the hub can be traced to every unit it touches.

Mobile and modular units are systems too

A modular unit that ships as a container with its own control system, sensors, and local data store is one physical object but several computerized systems. Companies sometimes qualify it as “equipment” and never register the software layers as systems in their own right. That creates a gap the moment the unit moves: the equipment requalification covers utilities and environment, but nobody re-verifies that the local time source, user directory, and data transfer to the hub still work at the new site. The MHRA, which brought its own point of care and modular manufacture framework into force on July 23, 2025, has said that for decentralized manufacturing “not all products and processes will be suitable” and that developers must ensure “manufacturing and testing procedures are suitable” for the deployment environment.21 The same logic applies to the computerized layer of a unit: suitability at the destination has to be checked, not assumed.

A useful test. Pick one unit at random and ask for the list of every computerized system on it, every version, its current location, its qualification status at that location, and the hub systems it depends on. If the answer takes more than an hour to assemble, the inventory is not ready to support a single registration.

Batch Records That Reconcile Across Nodes

21 CFR 211.188 requires batch production and control records for each batch, including “complete information relating to the production and control of each batch,” and identification of the persons performing and checking each significant step, or, where a step is performed by automated equipment under 211.68, the person checking the automated step.12 21 CFR 211.192 then requires that all production and control records “be reviewed and approved by the quality control unit to determine compliance with all established, approved written procedures before a batch is released or distributed.”13

In a distributed model, a batch record has at least three homes. Part of it is generated at the unit, where the process runs. Part of it is generated at the hub, where materials are released, procedures are issued, and the disposition decision is made. Part of it may be generated at neither, for example at a testing laboratory or a materials kitting operation that supplies several units. The record the quality unit reviews under 211.192 has to be the whole record, assembled from all of those sources, and it has to be internally consistent.

What “reconcile across nodes” means in practice

The unit identifier has to be inside the batch record. A batch record that says “Line 2” is meaningless when there are twelve equivalent units. Every batch should carry the unit identifier and the location at which it was produced, the same identifier used in the registration and the system inventory. The preamble’s traceability point depends on this: FDA cannot connect a lot to a unit if the batch record does not name the unit.1

Material genealogy must survive the hub-to-unit handoff. Stakeholders told FDA in 2022 that a central inventory might distribute “appropriately sourced, qualified, and released starting materials” to host sites, and that “electronic safeguards, such as kitting and barcoding, could help ensure that only qualified and released raw/starting materials and validated standard operating procedures (SOPs) are used with the manufacturing unit.”4 That is a sound design, but it only works if the hub’s release record for a kit and the unit’s consumption record for that kit share a lot number and reconcile. A unit that can accept an unreleased kit, or a hub that cannot tell which unit consumed which kit, breaks the chain.

Time has to mean the same thing everywhere. A distributed establishment can span time zones and network conditions. Batch records should record timestamps in a single reference time with the local offset preserved, and the time source at each unit should be a controlled, synchronized service. Otherwise a hub reviewer comparing a unit’s process log against the hub’s material release time cannot tell whether a material was used before it was released.

Review at the hub has to be timely and complete. The stakeholder summary records a debate on this point: some stakeholders proposed time-zone-specific review teams so the centralized PQS could “perform timely batch review and approval” for all units, while others suggested that “sufficiently robust and appropriately validated automated systems might be able to ensure proper batch decisions.”4 Either path is defensible. What is not defensible is a hub that approves batches from a unit it cannot see in near real time, or a unit that releases locally because the hub is too slow. Review by exception, where the system flags only deviations from the master record for human review, is often the practical answer at scale, but it has prerequisites, and they are stricter across a network than inside one plant: a fully validated master record, complete electronic capture, and a proven exception logic.

Small batches change the review math. FDA’s stakeholder summary notes that self-contained units “might be designed to produce small batch sizes (even single doses)” and that “destructive end-product testing of such batches may not be feasible.”4 The 2025 draft guidance on 21 CFR 211.110 addresses part of this: process monitoring adjustments within preestablished, quality-approved limits do not typically need additional quality unit approval, provided the production data is reviewed by the quality unit before the batch is approved or rejected.7 Note the last condition. Automation can reduce what the quality unit approves in the moment. It does not remove the quality unit’s review before disposition, and in a distributed model that review happens at the hub.

Audit Trail Coverage That Does Not Stop at a Site Boundary

FDA’s 2018 guidance on data integrity defines an audit trail as a secure, computer-generated, time-stamped electronic record that allows reconstruction of the events relating to the creation, modification, or deletion of an electronic record, and it expects audit trails to be reviewed as part of the record review under 211.192.8 21 CFR 11.10(e) requires “secure, computer-generated, time-stamped audit trails to independently record the date and time of operator entries and actions that create, modify, or delete electronic records.”15

Nothing in either text says the audit trail may end at the edge of the building. Yet that is exactly where audit trail coverage tends to stop in a distributed design, for three reasons.

Three places an audit trail breaks across a network

Identity. An audit trail records who did what. If each unit has its own local user accounts, a hub reviewer sees “operator01” at Unit 7 and “operator01” at Unit 9 with no way to know whether they are the same person, whether that person was qualified for that unit, or whether the account was shared. The fix is one identity source across the establishment, with per-unit authorization. 11.10(d) requires “limiting system access to authorized individuals,”15 and FDA’s stakeholder summary records the industry’s own proposal that a centralized PQS “could manage operator access, limiting operation to those who are appropriately qualified.”4 That proposal is only workable if identity is central.

Time and sequence. Audit trail entries from a unit that was offline for six hours and then synchronized arrive at the hub with a synchronization time, not the original event time, unless the system is designed to preserve both. A reviewer at the hub needs to see the original event time, the unit’s clock source, and the time the entry reached the hub. Without that, the audit trail cannot answer the one question it exists to answer: what happened, in what order.

Custody during transfer and relocation. When a mobile unit is shut down, moved, and restarted, the records it holds locally pass through a period in which they are not under the hub’s live control. The audit trail of that period should show who closed the unit’s systems, that no records were changed in transit, and who reopened them. The relocation itself is an event in the establishment’s history, and the proposed registration rule already treats it as one requiring dated notice.2 The quality system should record it with at least the same precision.

Audit trail review as a network activity

The data integrity guidance expects audit trail review to be part of routine record review by the quality unit, with a frequency and depth based on risk.8 In a distributed establishment, that review has to be possible from the hub without traveling to the unit. That means the audit trails from every unit are either replicated to the hub or accessible from it, that the hub reviewer can filter by unit identifier and batch, and that the review itself is recorded. A procedure that says “the site reviews its own audit trails” does not describe a unified quality system. It describes twelve of them.

What good looks like. A hub quality reviewer opens one batch, sees every audit trail entry from the unit and from the hub-side systems in one time-ordered view, can identify each actor against a single identity source and that actor’s qualification for that unit, can see any offline period and how it was closed, and signs one review record. The site boundary is invisible in the record because the record was designed for the establishment, not the site.

One Document Control System and One Training System

The preamble’s functional description of a UPQS begins with procedures: the quality unit’s personnel “develop the policies and procedures that govern manufacturing operations for the entire DME.”1 21 CFR 11.10(k) requires “appropriate controls over systems documentation including… adequate controls over the distribution of, access to, and use of documentation for system operation and maintenance.”15 And 21 CFR 211.25(a) requires that CGMP training “be conducted by qualified individuals on a continuing basis and with sufficient frequency to assure that employees remain familiar with CGMP requirements applicable to them.”25

The failure mode here is familiar to anyone who has run a multi-site quality system: the global procedure is issued from the center, each site adopts it with “local adjustments,” and within two years the sites are running materially different processes under the same document number. In a traditional company that is a harmonization problem. In a DME it is a loss of equivalence in operation, and the proposed rule says a unit that is no longer equivalent must be removed from the registration.2

Document control

One document control system for the establishment means one effective version of every procedure, master batch record, and specification, issued from the hub, with a single controlled mechanism for any location-specific variation. Where a variation is genuinely necessary (a utility connection differs, a host site has its own access rules), it should be a controlled addendum linked to the parent document and to the unit identifier, approved by the hub quality unit, and visible in a report that lists every active addendum across the network. If that report cannot be produced, the company cannot demonstrate that operations remain equivalent, because it cannot say what each unit is actually following.

The MHRA’s framework offers a parallel worth noting. Under the UK regulations, the control site is the only named manufacturing site on the license and holds responsibility for product quality across all manufacturing sites, and the MHRA Inspectorate has said that a decentralised manufacturing master file must be included within any submission.21 A master file of that kind, one place that describes every unit, its location, its configuration, and its approved variations, is a sensible artifact for a US DME to maintain whether or not FDA ever asks for one by that name.

Training and operator qualification

Stakeholders told FDA that a “standardized training strategy” developed and maintained by the centralized PQS “can contribute to consistent drug product quality and process performance across all manufacturing locations,” and that training “could be communicated electronically to individual operators at host sites.”4 They also flagged the hard case: units that “move frequently and/or over large geographical distances” may require “new personnel” to be “trained and qualified to operate DM units at each new location.”4

One training system means the hub owns the curriculum, the qualification criteria, and the records for every operator at every unit, including host-site personnel who are not employees of the manufacturer. It means the training record is linked to the unit identifier, so the hub can show which operators are qualified on which unit at which location and, when a unit relocates, which operators have been qualified at the destination. It also means that 11.10(i), which requires a determination that persons who use electronic record systems “have the education, training, and experience to perform their assigned tasks,”15 is satisfied by a record the hub can produce, not by a host-site manager’s assurance.

A 2025 paper in Frontiers in Medicine on quality management for decentralized cell and gene therapy manufacturing describes the same structure from the sponsor’s side: a control site as “the primary focus point for interaction with regulatory agencies,” a central QMS setting global standards, and a training program that includes GxP training, refresher courses, and “job-specific SOPs and working instructions as appropriate” to minimize variability across centers.23 The paper is about a different product class and a different regulatory context, but the design principle carries: the center owns training because the center owns equivalence.

Deviations, CAPA, and Change Control That Can See Every Unit

21 CFR 211.192 requires that any unexplained discrepancy or specification failure “be thoroughly investigated,” that the investigation “extend to other batches of the same drug product and other drug products that may have been associated with the specific failure or discrepancy,” and that a written record include conclusions and follow-up.13 In a distributed establishment, “other batches that may have been associated” means batches from other units. A deviation at Unit 3 caused by a firmware setting is potentially a deviation at every unit running that firmware. An investigation that stops at the unit boundary has not met the regulation.

Deviations and trending

The hub needs one deviation system in which every event, from every unit, is recorded with the unit identifier, classified with a common taxonomy, and trended across the network. That is what lets the quality unit spot that three units in different states are logging the same minor event, which is a process signal rather than three local incidents. Stakeholders anticipated this in 2022, noting that “specific mechanisms may be necessary to contemporaneously manage deviations, failure investigations, corrective actions, and changes across a network of host sites.”4 “Contemporaneously” is the right word. A weekly upload of site deviation logs to a central spreadsheet is not a unified system; it is a reporting line.

Two design choices matter. First, who can open, escalate, and close a deviation at a unit, and whether host-site personnel who are not employees have any role in that workflow. The stakeholder summary records that “some operators may not be traditional manufacturing personnel and the extent of their quality responsibilities might be limited by their organization.”4 The procedure should say so explicitly. Second, how nonconforming material at a remote unit is physically detained. FDA’s own 2022 discussion paper5 raised the concern that applicants “who are not present at host sites will face challenges with ensuring that any rejected manufacturing components are quarantined, disposed of, and investigated,” and the stakeholder summary notes that stakeholders “did not generally address” how a unit would physically detain or destroy nonconforming product.4 That gap is still open, and a company’s procedures should close it before an investigator asks.

Change control with a registration clock inside it

Change control in a DME has an unusual feature: some changes carry a regulatory notice period that starts before the change, not after. Under the proposal, a mobile unit cannot move without 30 or 120 days of advance notice, and a unit cannot stay in the registration if it loses equivalence.2 That means the change control procedure has to classify changes by their effect on equivalence and on registration, and route them accordingly:

  • Changes that affect equivalence in design (a control system upgrade, a component substitution, a configuration change) must be applied to every unit or justified for none, and the justification must show the units remain equivalent afterward. The preamble’s expectation that the UPQS is “capable of managing changes in manufacturing operations to ensure equivalency in design and operation across DMUs”1 is aimed squarely at this.
  • Changes that affect equivalence in operation (a procedure revision, a training requirement, a new host-site constraint) need the same network-wide application and the addendum control described above.
  • Relocations need a change control opened early enough to complete the destination assessment, the requalification plan, and the regulatory notice before the earliest permitted move date. If the quality system learns of a planned move 20 days out, the registration timeline has already been missed.
  • Unit additions and removals need a change control that produces the information the registration update requires (identifier, location, operations) and that records the equivalence decision.

FDA also asks for comment on situations “where providing such advance notice would not be feasible,” and when a registrant “would first be able to notify the Agency” in those cases.1 A company that has already mapped its emergency relocation scenarios through change control will have something concrete to say.

How a Quality Unit Demonstrates Oversight of a Unit It Does Not Sit In

The hub is defined as “the primary location of the quality unit.”2 Primary, not only. Quality personnel may be present at units. But the definition assumes that the quality unit exercises oversight and control over units where it is not physically present, and the preamble contrasts this with a traditional site where the quality unit is “typically being entirely present at that same location.”1 The question a quality leader has to be able to answer is: how do I show an investigator that I control a unit I visit twice a year?

The 2023 stakeholder summary records that feedback “suggested that information to support that the centralized PQS has adequate oversight of multiple DM units across multiple geographical locations could be provided in a regulatory submission and assessed through facility evaluation.”4 In other words, the company writes it down and FDA checks it. Four kinds of evidence make that demonstration credible.

EVIDENCE 1

Authority in writing

A quality manual and organizational description showing that the hub quality unit approves procedures, specifications, batch disposition, deviations, and changes for every unit, that no unit can release product locally, and that host-site personnel act under the hub’s delegated instructions. The preamble expects the quality unit to determine “staffing and the personnel reporting structure for the entire DME.”

EVIDENCE 2

Data the hub can see now

Live or near-live access from the hub to each unit’s process data, environmental monitoring, batch records, audit trails, and system status, with the review of that data recorded. Oversight that depends on a site emailing a report is not oversight; it is trust.

EVIDENCE 3

Management review by unit

A periodic management review, in the ICH Q10 sense, that reports deviations, CAPA, changes, training status, and process performance for each unit side by side, with actions where units diverge. This is the single most persuasive document that equivalence “remains” rather than “was once demonstrated.”

EVIDENCE 4

Verification on site

A risk-based program of on-site verification at each unit, with a defined frequency, a defined scope (equipment, environment, personnel, records), and a written outcome. Stakeholders proposed that after FDA’s initial inspection, the centralized PQS “would perform future host site evaluations that FDA could review when inspecting the centralized PQS site.” That only works if the evaluations exist.

One caution on remote oversight. Stakeholders encouraged FDA to use “alternative tools (e.g., remote regulatory assessments)” for host-site assessments.4 Whether FDA does so is FDA’s choice. The manufacturer’s oversight is a separate obligation and should not be designed on the assumption that FDA will never visit a unit. The proposed 30- and 120-day relocation windows exist, in FDA’s own words, to allow time “to prepare for a domestic versus foreign inspection, if needed.”1 FDA is telling companies it may inspect units.

Regulatory Focus reported in August 2026 on an editorial by Amalia Issa in Clinical Pharmacology in Drug Development, which made a related point from the clinical pharmacology side: because units need only be equivalent in design and operation rather than identical, sponsors will need to be able to show that a unit that relocated recently still produces product that behaves the same as a unit that never moved, and comparability planning should be built into development from the start rather than added later.16 That is the same “remains equivalent” test seen from the product rather than the facility.

A Practical Readiness Checklist

The following sequence is written for a pharma or biotech company that either intends to pursue DME registration if the rule is finalized, or that already runs a hub-and-unit model under separate registrations and wants to know how far it is from a single quality system. Each step produces a record that the next step depends on.

1

Decide whether the model even fits the definition

Single legal entity as registrant. One management structure. Units that make the same drugs. At least one mobile unit or at least two stationary ones. No unaffiliated contract manufacturers operating units. An approved application (or a planned submission) that describes the decentralized strategy for each profile class. If any of these is missing, the pathway does not apply, and the rest of this list is still good practice but not a registration prerequisite.

2

Name the reference unit and write the equivalence standard

Define, in a controlled document, what “equivalent in design and operation” means for this establishment: the reference configuration, the allowed variations, the tests that prove equivalence for a new or relocated unit, and the ongoing monitoring that shows it persists. Without a written standard, “equivalent” is an opinion.

3

Rebuild the computerized system inventory around units and locations

Every system instance on every unit, with version, location, connectivity mode, qualification status at the current location, and hub dependencies. Key every entry to the unit identifier you expect to use in the registration.

4

Put the unit identifier into the batch record, the deviation record, the training record, and the change record

One key, used everywhere. This is the single change that makes cross-node reconciliation possible and that lets the registration and the quality system be compared line by line.

5

Centralize identity, time, and audit trail access

One identity source with per-unit authorization. One synchronized time reference with local offsets preserved. Audit trails from every unit reviewable from the hub, filtered by unit and batch, with offline periods and relocations visible as events.

6

Collapse document control and training into one system with controlled local addenda

One effective version of every document, issued from the hub. Local variations only as linked, approved addenda. A report of all active addenda by unit. Training and qualification records owned by the hub and linked to unit and location, including host-site personnel.

7

Add equivalence and registration triggers to change control

Classify every change by its effect on equivalence in design, equivalence in operation, unit location, and unit membership in the DME. Attach the regulatory notice timeline to relocation changes so the change control system, not a calendar reminder, enforces the 30- and 120-day windows if they survive into a final rule.

8

Write the procedure for a unit that stops being equivalent

Who decides, on what evidence, what happens to batches made while the unit was drifting, how the unit is either restored or removed, and who files the registration update. The proposed rule makes this a registration event with a misbranding consequence. Most companies have no procedure for it.

9

Run a management review by unit and an on-site verification program

Produce the first side-by-side review of deviations, CAPA, changes, training, and process performance across units, and schedule risk-based on-site verifications with written outcomes. These two documents are the core of the oversight demonstration.

10

Rehearse the preapproval inspection of the hub

FDA says the preapproval inspection is where it will assess whether the UPQS can manage change and maintain equivalence. Walk an internal auditor through a relocation, a network-wide deviation, and a batch release from a unit in another time zone, using only records available at the hub.

Commenting on the Docket Before September 11

Comments are due by 11:59 p.m. Eastern on September 11, 2026, through regulations.gov under Docket No. FDA-2025-N-6075, or by mail or hand delivery received by that date. FDA warns that comments posted electronically are public and unchanged, and that anyone who wants to include confidential business information (it gives “a manufacturing process” as an example) should follow the written submission process for confidential material rather than posting it.1 For a quality or IT leader, that warning matters: a comment that describes your network architecture in detail is a public document.

The questions FDA has actually asked

A comment is most useful when it answers something the agency has asked. In the preamble, FDA specifically requests comment on:

  • Whether the 30-day (domestic) and 120-day (foreign) advance notice periods for relocating a mobile unit are appropriate.1
  • The specific circumstances in which advance notice of a relocation would not be feasible, and when a registrant would first be able to notify the agency in those situations.1
  • Whether there are other terms, including terms used in the proposed rule, that FDA should define or clarify in Part 207, and how.1
  • The benefits and burdens of extending the approach to other distributed manufacturing models beyond the single-entity hub-and-unit model.1
  • The proposed effective date of 30 calendar days after publication of a final rule.1
  • The severability of the rule’s provisions.1
  • The information collection burden estimates under the Paperwork Reduction Act.1

What an operations-minded comment might say

On defining the unified pharmaceutical quality system. The rule’s central eligibility condition is undefined in regulatory text. A comment could ask FDA either to define UPQS in 207.1 or to state plainly that the term is to be read through the forthcoming CGMP guidance, and could propose the functional elements FDA already lists in the preamble (network-wide procedures, staffing and reporting structure, lifecycle management of all units) as a starting point. Companies that already run a hub-and-unit model are the best placed to say what the definition should and should not require.

On the unit identifier. A comment could support FDA’s proposal to assign a unit identifier and ask the agency to confirm whether it expects the identifier to appear in batch records, labeling, or listing submissions, since the answer determines how companies design their record systems. The preamble calls the identifier “important for traceability,” and it would help to know what FDA intends to trace with it.

On the relocation timelines. Rather than arguing that 30 or 120 days is too long or too short in the abstract, a comment could describe the sequence of activities a relocation actually involves (destination assessment, requalification, operator qualification, connectivity verification, regulatory notice) and where the notice period falls in that sequence. FDA has said the periods are about its own inspection logistics; a comment can add the manufacturer’s logistics to the record.

On loss of equivalence. The proposal requires removal of a unit that no longer remains equivalent and the registrant “has not taken steps” to restore it. A comment could ask FDA to clarify what counts as taking steps, how long a unit may remain in the registration while under remediation, and whether product made during that period is affected. These are the questions a quality unit will face first, and the preamble does not answer them.

On computerized systems and data. The proposed rule is a registration rule and says almost nothing about data. That is appropriate for its scope, but the CGMP guidance FDA has promised will have to. A comment could ask that the guidance address the topics this article has covered: system inventories that account for every unit and location, cross-node batch record reconciliation, audit trail review from the hub, identity and time synchronization, and the evidence expected for remote oversight. Putting those topics on the record now increases the chance they are addressed when the guidance is drafted.

On harmonization. Stakeholders asked FDA in 2022 for international alignment on terminology and principles,4 and the UK has since brought a hub-and-spoke framework with a control site into force.22 A comment from a company operating in both jurisdictions could point to specific places where the two frameworks use different terms for the same thing, so that a single quality system can serve both.

Practical notes on submitting. Reference the docket number in the comment. Organize it by the preamble section you are responding to. State facts about your own operations only to the extent you are comfortable making them public, and route anything sensitive through the confidential submission process. FDA reads comments for information it does not already have; a comment that repeats the preamble back to the agency adds nothing.

Conclusion

The proposed rule is modest in what it changes on paper: a few definitions in Part 207, some registration timelines, an identifier scheme. It is not modest in what it assumes. It assumes that a company can point to one quality unit, at one hub, and show with records that the unit directs, monitors, and controls production at every location in the network, and that the units are equivalent today and will be tomorrow. Registration is the reward for having built that. It is not a substitute for it. A company that reads this proposal as a regulatory affairs project will be surprised at the preapproval inspection, where FDA has said it intends to test whether the unified quality system can actually manage change across units.

The systems that carry that demonstration are the ones quality and IT leaders already own: the computerized system inventory, the batch record, the audit trail, document control, training, deviation management, and change control. None of them needs to be reinvented. Each of them needs to be extended so that the unit and its location are first-class attributes, so that the hub can see and act on every unit’s records in something close to real time, and so that the registration record and the quality record describe the same establishment. Whether or not this rule is finalized in its current form, that work has a value of its own, because it is the same work any company running production at more than one location should already have done.

Sakara Digital works with pharma and biotech organizations on the quality system and data architecture questions behind decisions like this one: which records need to reconcile across sites, how audit trail review and document control should be structured when production is distributed, and what evidence a quality unit needs to show oversight it cannot exercise in person. If you are evaluating a hub-and-unit model, preparing a comment to the docket, or trying to find out how far your current systems are from supporting a single quality system across many locations, and you want an independent perspective on where to start, we are happy to have that conversation.

For Further Reading