Where the Program Stands in September 2026

Start with what is verifiable, because QMM attracts a lot of confident secondhand commentary. The February 11, 2026 Federal Register notice (Docket No. FDA-2023-N-5706) announces “the third year of the voluntary Quality Management Maturity (QMM) Prototype Assessment Protocol Evaluation Program.” CDER intended to accept requests through April 13, 2026, to notify each establishment of a decision within 60 days of receipt, and to “select up to nine volunteer participants.”1,22 The same notice states that in 2024 CDER evaluated nine establishments in the initial year, and that the second year, announced in April 2025 with a June 9, 2025 request deadline, “is ongoing.”1,2

Three things follow from that wording. First, FDA has published a participant count only for year one. Anyone quoting a year-two number is not quoting FDA. Second, the year-three notice describes the assessment tool as having been refined after year one, not after year two, which means the 2026 cohort is being assessed with the same streamlined protocol and rubric the 2025 cohort received.1 Third, the word “prototype” is still in the program’s name. FDA is running the program to “gain additional experience with the assessment tool and process,” and the notice says continuation “is needed to assure that these assessments enable consistent and meaningful evaluations.”1 This is a tool still being validated on volunteers, not a launched regulatory program.

Program timeline from the primary record

October 2020 to March 2022: two contractor-run pilots, seven domestic finished dosage form sites and eight foreign API sites, all conducted virtually.6 April 2022: OPQ white paper on QMM and supply chains.10 November 2, 2022: advisory committee votes 9 to 0 in favor of establishing a CDER QMM program.6 2023: practice areas white paper and a Federal Register request for comments (88 FR 63587).5,3 January 25, 2024: year one notice, nine establishments assessed that year.3,1 April 23, 2025: year two notice with a refined tool.2 February 11, 2026: year three notice, requests through April 13, 2026.1 April 2026: CDER presents lessons from the 2024 cohort at the Generic Drugs Forum.7,21

What has been published about results

FDA has not published site-level results, and it does not name participants in its notices. What it has released is aggregate. The 2025 notice says the 2024 cohort “reasonably reflected the diversity of the industry,” that the rubric “effectively differentiated the maturity of quality management practices across the nine establishments,” and that participants found the engagement and reports valuable but “also indicated that certain aspects of the prototype assessment protocol were repetitive.”2 The 2026 notice adds that the nine sites included generic drug manufacturers, a contract testing laboratory, and brand drug manufacturers, and that the protocol “distinguished differences in maturity levels between practice areas at a single establishment” as well as between establishments.1

The most specific public data came on April 22, 2026, when Eric Twum of CDER’s Office of Quality Surveillance presented “An Update on CDER’s Quality Management Maturity (QMM) Program” at the Generic Drugs Forum, a session the agenda describes as sharing “lessons learned from the 2024 QMM Prototype Assessment Protocol Evaluation Program.”21 RAPS reported that the nine participating companies generally scored high, often 4 out of 5, on management commitment to quality and employee engagement, and lower, averaging around 3 out of 5, on the advanced pharmaceutical quality system and technical excellence practice areas.7 We return to what that pattern means below.

Why FDA Built QMM: The Drug Shortage Root Cause

QMM did not begin as a quality initiative. It began as a drug shortage initiative. In 2019, the FDA-led interagency Drug Shortages Task Force analyzed 163 drugs that went into shortage between 2013 and 2017 and found that 62 percent “went into shortage after supply disruptions occurred that were associated with manufacturing or product quality problems.”9 The task force named three root causes. The second was that the “market does not recognize and reward manufacturers for mature quality management systems.” Because purchasers have limited information about the quality management of any specific facility, the market does not pay a premium for mature systems, backup capacity, or risk management plans, and manufacturers “are more likely to keep costs down by minimizing investments in manufacturing quality, which eventually leads to quality problems, triggering supply disruptions and shortages.”9

The task force’s second recommendation was to “create a rating system to incentivize drug manufacturers to invest in achieving quality management system maturity,” so that purchasers and group purchasing organizations could see, and reward, the maturity of the facility making the drugs they buy.9 That recommendation is the origin of everything that followed, and it explains why CDER’s stated goals for the program end with “minimize risks to product availability to assure reliable market supply.”4,5

62%Of 163 drugs in shortage 2013-2017 followed manufacturing or product quality problems (FDA task force)9
9Establishments assessed in year one (2024); up to nine sought again for year three1
~100 hrsParticipant time estimated by pilot sites, varying with staff involved6

A note on the shortage numbers

Leaders should hold the 62 percent figure carefully. It comes from FDA’s own root-cause analysis of a defined set of 163 drugs. A January 2025 data brief prepared for HHS/ASPE, covering 2018 to 2023, worked from manufacturer-reported reasons instead and found a different distribution: where a reason was given, the most common was increased demand (37.3 percent), followed by an API shortage (11.1 percent), with “other” accounting for 39.1 percent of cases.16 The two studies measure different things (FDA’s analysis of underlying disruption versus the reason a manufacturer chose to report), so they are not contradictory, but they are a reminder that the quality share of shortages depends on who is classifying. The ASPE brief also confirmed the structural facts that make QMM relevant: injectables made up half of all shortages, and shortages of injectables lasted a median of 4.6 years against 1.6 years for oral products.16 Those are the sterile, low-margin, few-supplier products where a single site’s quality performance decides whether patients get the drug.

What the Prototype Protocol Measures

CDER defines QMM as “the extent to which drug manufacturing establishments implement quality management practices that prioritize patients, drive continual improvement, and enhance supply chain reliability through the strategic integration of business decisions and manufacturing operations with quality practices and technological advancements.”1 The prototype protocol turns that definition into questions in five practice areas, each explored through key elements. The 2023 white paper describes the areas and what less mature and more mature establishments look like in each.5

Practice area 1

Management commitment to quality

How management sets quality goals and policy, aligns them with business objectives and the strategic plan, resources them, and communicates them at all levels. Assessment may cover the frequency and depth of management review and whether its outputs start improvements. Example topics: management review, resource management.5,2

Practice area 2

Business continuity

How the site sustains operations through expected and unexpected disruption: supply chain redundancy, understanding and mitigating supply risks, preventive maintenance effectiveness, frequency of unplanned production disruption and speed of recovery. Mature sites forecast demand, qualify backup suppliers, and manage inventory levels. Example topics: supply planning, demand forecasting.5,2

Practice area 3

Advanced pharmaceutical quality system

The site’s approach to quality risk management, the rationale behind its process performance and product quality monitoring, how CAPA and monitoring data are used to improve operations, how CAPA effectiveness is judged, and whether change management evaluates and implements changes properly. Less mature sites fund corrective actions after failures and not preventive ones. Example topic: continual improvement.5,2

Practice area 4

Technical excellence

Managing information and data so it is attributable, legible, contemporaneous, original, accurate, complete, consistent, enduring, and available regardless of format; synthesizing information from different sources; judging whether a technical solution is fit for purpose and implementing it well. Less mature sites struggle with data integration and resist unfamiliar change even when funds exist. Example topics: data governance, process optimization.5,2

Practice area 5: Employee engagement and empowerment

Whether employees are willing to suggest improvements and whether leadership creates an environment that invites them; whether staff understand how their role affects product quality and patient safety; whether people have access to development and clear career paths. Mature establishments “foster a culture of active participation without fear of reprisal.” Example topic: rewards and recognition.5,2

Two details of the naming matter for anyone reading across the three notices. The 2024 notice called the first practice area “leadership.” The 2025 notice renamed it “management commitment to quality” to match the 2023 white paper, and it replaced the example topic “corrective action and preventive action process” under the advanced PQS area with “continual improvement,” to align with modifications made to the protocol.2 That second change is a signal about direction: FDA wants to assess whether CAPA feeds a working improvement loop, not whether a CAPA procedure exists.

The maturity scale and the rubric

FDA has not published the prototype rubric. What it has said is that assessors use “a standardized prototype assessment protocol and rubric to evaluate each establishment’s practices, behaviors, and responses to specific questions,” and that after year one CDER “streamlined the QMM assessment tool to make the prototype protocol and rubric clearer and more concise.”1 The pilot programs used ordinal scales of levels one through five, with each practice area scored and an aggregated establishment score produced; the names for levels four and five differed between the two contractors.6 The RAPS reporting of 4 out of 5 and 3 out of 5 scores from the 2024 cohort indicates the five-level structure carried into the prototype.7 The 2023 white paper also says the report “may benchmark the participant’s maturity against similar establishments” without disclosing identities, depending on the number and demographics of participants.5

How an assessment runs

The 2026 notice lays out the process in more operational detail than either earlier notice. Selected establishments receive orientation materials and a pre-assessment questionnaire that identifies the topic areas to be covered and helps the site line up subject matter experts. The assessment “may take up to five days” and is conducted by a team of three assessors drawn from CDER staff, explicitly excluding “FDA personnel from the Office of Inspections and Investigations charged with the responsibility of ensuring CGMP compliance.” The site receives an agenda in advance, the full leadership team does not need to be present throughout, and personnel may join remotely.1

Afterward the site receives a QMM assessment report giving its score in each practice area and underlying topic, with context for how the score was determined, and highlighting “2-3 areas of strength and 2-3 actionable opportunities for improvement in each practice area.” Participants are encouraged to pick at least one opportunity and build an improvement plan, share it with CDER, meet about three months after the assessment to discuss it, and meet again at about six months to review progress.1 That six-month arc, with two structured conversations with the agency about a plan the site chose, is the actual deliverable of the program. There is no certificate and no rating.

ElementYear one (2024 notice)Year three (2026 notice)
Inspection history requiredAt least one human drug surveillance inspection in the prior 5 yearsAt least one human drug surveillance inspection (5-year window removed in 2025 to widen eligibility)
Current classificationNAI or VAINAI or VAI
Assessment teamThree assessors; CDER staff or CDER staff plus contractorsThree assessors; CDER staff, no Office of Inspections and Investigations personnel
DurationUp to five business days, onsite or hybridUp to five days, onsite or hybrid
ReportSummary of strengths and growth opportunitiesScore per practice area and topic, 2-3 strengths and 2-3 opportunities per area
Follow-upVirtual feedback meeting at about six monthsImprovement plan shared with CDER, meetings at about three and six months
Decision timelineWithin 90 days of receiptWithin 60 days of receipt

Sources: the January 2024, April 2025, and February 2026 Federal Register notices.3,2,1

How a QMM Assessment Differs From a CGMP Inspection

FDA has been unusually direct about this distinction, because confusion about it is the main reason sites hesitate to volunteer. The 2023 white paper has a section titled “Addressing Possible Misconceptions About the QMM Program.” Its first point: “QMM assessments are not used to evaluate compliance with CGMP.” Inspections are conducted under section 704(a) of the Federal Food, Drug, and Cosmetic Act, are mandatory, and refusal is prohibited under section 301(f). By contrast, “QMM assessments are not part of FDA’s inspection authority and participation in the QMM program is voluntary. The QMM assessment cannot be used to determine compliance with CGMP.”5 Information gathered in an assessment “is not intended to evaluate compliance with CGMP or support regulatory actions.”5

The practical differences go deeper than the legal basis. An inspection looks for deficiencies against a minimum standard. As the 2022 white paper put it, FDA investigators “look for deficiencies in meeting CGMP, but these evaluations do not measure how far a site’s pharmaceutical quality system (PQS) rises above the minimum requirements. Simple adherence to CGMP standards does not indicate, for example, that a firm is investing in improvements to prevent supply disruptions.”10 A QMM assessment starts from the assumption that the site is compliant (the NAI/VAI entry criterion enforces that) and asks a different question: how much of the site’s quality effort is prevention, prediction, and improvement rather than detection and correction.

DimensionCGMP surveillance inspectionQMM prototype assessment
Legal basisMandatory under FD&C Act section 704(a)Voluntary; not part of inspection authority5
Question askedDoes the site meet minimum CGMP requirements?How far do practices, behaviors, and culture rise above the minimum?10
Who conducts itCredentialed investigators, Office of Inspections and InvestigationsThree CDER assessors, no inspection personnel1
Unit of evaluationProducts, processes, records, facilitiesThe establishment; QMM does not evaluate product quality5
OutputForm FDA 483, classification, possible enforcementScored report, strengths and opportunities, follow-up meetings1
Data typeObjective evidence of conformanceQualitative; focuses on approach and why the site chose its metrics5
Consequence of a low resultRegulatory actionNone from FDA; the report is the site’s to act on5

Three further clarifications from FDA’s own material are worth repeating to executive teams. QMM “does not evaluate product quality”; every drug on the U.S. market is expected to meet standards regardless of the maturity of the site that made it.5,10 Maturity “is independent of establishment size or age, and the types or number of products produced”; a well-funded site with new equipment is not mature if the technology is not fit for purpose and controlled.5 And QMM is distinct from the Quality Metrics program: metrics are quantitative data a site collects, while a QMM assessment is qualitative and asks why the site chose those metrics and how it uses them.5 The pilot paper records that stakeholders repeatedly confused the two, and also confused “maturity” with the age of a facility.6

What Participants and FDA Say They Learned

The public record on lessons comes in three layers: the 2020 to 2022 pilots, documented in a peer-reviewed commentary by twelve CDER authors; the 2024 cohort, described in the 2025 and 2026 notices and the April 2026 Generic Drugs Forum presentation; and commentary from participants and advisors published in the trade press. Only the first two are FDA’s words, and the attributions below keep that boundary.

Lessons from the pilots (2020-2022)

The pilots were run by two contractors using different methods, which limited comparison but multiplied learning.6 The domestic finished dosage form pilot used a two-stage design: a 24-question self-assessment against a five-level rubric, followed by a facilitated discussion focused on areas needing clarification. It covered six practice areas: leadership and governance, continual improvement, stakeholder engagement and satisfaction, knowledge management, workforce engagement, and operations. The foreign API pilot skipped self-assessment, used 66 questions in direct engagement, and covered four areas: sustainability, risk management, compliance (defined as exceeding requirements and adopting best practices), and quality culture.6

The headline participant finding is the one CDER keeps quoting: “Many of the participating establishments reported that the QMM pilot assessments helped to identify their strengths, weaknesses, and new areas for improvement which they had not previously identified through internal audits or CGMP inspections.”6 The paper reproduces participant comments about using results to set goals and objectives, to target improvement areas in the quality plan, and to communicate within the corporate organization, and separately about wanting QMM scores for API suppliers and contract facilities as an input to supplier qualification.6

FDA’s own lessons were about the mechanics of assessing culture, and they are directly transferable to any internal self-assessment:

  • Orientation matters. Sites benefited from an introduction packet or pre-meeting, and from preparatory materials at least two weeks in advance, because “the QMM assessments are significantly different from regulatory inspections with which establishments are familiar.”6
  • Self-assessment gives the site a voice. Assessors and participants “found value in using the self-assessments,” which also directed the facilitated discussion to the areas that needed elaboration.6
  • Evidence examples help. Sites found it useful to see concrete examples of documents that could substantiate a rating, and FDA concluded that maturity determinations need to be supported by documentation.6
  • Rigid time limits fail. Both pilots started with 15 minutes per question; some conversations were rushed and did not yield what was needed.6
  • Redundancy distorts scores. Quality risk management, knowledge management, innovation, and continual improvement were covered by questions in multiple practice areas, and “redundant topics within or between practice areas may reduce the accuracy of scoring if these topics are accounted for more than once.”6 This is the lesson that resurfaced in 2024 when participants called the prototype repetitive.2
  • Assessor behavior decides the quality of the data. Assessors sometimes departed from planned questions, missed follow-ups, or asked leading or yes/no questions. FDA concluded it would need to train assessors in interview technique, neutrality, plain language, and in distinguishing behaviors that meet CGMP from those that exceed it.6
  • Interviewing across levels needs to be independent. Because the pilots were virtual, assessors could not interview management and staff separately, and the paper notes that “independently interviewing different levels of staff within the organization may be important to gauge the culture.”6
  • Visual scoring communicates better. Assessors, participants, and FDA “generally preferred data presented visually in radar/spider plots rather than in tabulated scores.”6

Lessons from the 2024 cohort

FDA’s published account of year one is short but consistent. Trained assessors ran five-day assessments using the prototype protocol and an objective rubric, and “the rubric effectively differentiated the maturity of quality management practices across the nine establishments.”2 Participants valued “the QMM report, engagement with the assessment team, and the ability to have open discussions,” and they were able “to share challenges and successes related to their manufacturing sectors.”1 Their main criticism was repetition, and CDER responded by streamlining the protocol, updating the rubric, and reframing some questions for clarity.2 An FDA international bulletin in October 2024 confirmed CDER planned to complete all nine assessments that year, and Jennifer Maguire of the Office of Quality Surveillance told the ISPE Annual Meeting in October 2024 that six of the nine had been completed by then.19,8

The scoring pattern reported from the April 2026 presentation is the finding executives should spend time on. Sites scored well on management commitment and employee engagement and lower on advanced PQS and technical excellence.7 Recall who these sites are: volunteers with clean inspection histories, self-selected for confidence in their quality systems. Even among them, the practice areas that ask about the use of quality risk management to prevent failures, the rationale behind monitoring, CAPA effectiveness logic, data integration across systems, and adoption of fit-for-purpose technology were the weakest. Leadership was saying the right things and staff were engaged; the systems that turn that commitment into predictive, data-driven prevention were not yet at the same level. That is a description of the compliance-to-maturity gap that would fit a great many pharma and biotech sites that have never heard of QMM.

What the strong scores tell you

High marks on management commitment and employee engagement among well-inspected volunteers suggest those two areas are the ones a compliant site is most likely to already have in reasonable shape, and the ones an internal self-assessment is most likely to overrate. The discriminating areas are advanced PQS and technical excellence. If you have time to look at only two practice areas before year-end planning, look at those two.7

What participants and advisors have said outside FDA

Three sources add practitioner perspective, and each should be read as commentary rather than as FDA findings. Writing in Pharmaceutical Executive in August 2025, Somnath Mishra, William Hauck, and Sarah Akers reported that pilot participants found assessments gave “a comprehensive understanding of site operations and identified opportunities for improvement not previously considered by site management,” while also noting that comments to FDA’s 2023 docket showed the industry “has not yet achieved consensus on the value of QMM assessments.” Their executive advice was that most organizations are far less ready for a QMM assessment than for a compliance audit, that scores are site-specific and do not transfer between facilities, and that remediation can take months to years depending on scope.15

Arnold & Porter’s February 2026 advisory on the year-three notice summarized the process and offered a caution most enthusiasts skip: companies should weigh whether “potential release of a negative assessment under the Freedom of Information Act could paint the company in an unrepresentative light or trigger more intensive FDA scrutiny,” against the value of “voluntary cooperation with the agency in a setting in which the agency can provide guidance for improvement.”14 FDA’s own 2023 presentation had already flagged the public-disclosure question as an open design decision, noting that publicizing ratings for a voluntary program might discourage participation, and that the supply chain benefits most “if the least mature sites are incentivized to participate.”18

Finally, the Duke-Margolis Center for Health Policy argued in December 2023 that FDA should advance QMM with a narrowed initial scope focused on vulnerable, essential, multisource generic drugs, that it “may be more effective if it remains a voluntary program,” and that a separate product-level supply chain reliability program would be needed because QMM does not cover factors such as backup raw material suppliers, inventory buffers, and manufacturing redundancy.17 That last point is important for the “what QMM will not do” section below.

QMM, ICH Q10, and Supply Chain Resilience

ICH Q10 is the reference model

The clearest statement of the relationship is in the 2022 white paper: “Gauging QMM requires, in part, determining how well and how thoroughly a manufacturer has implemented the concepts of ICH Q10.” The paper’s Figure 1 shows three steps: CGMP defines the minimum to market drugs legally, ICH Q10 augments CGMP with an effective pharmaceutical quality system over the product lifecycle, and QMM “requires, in part, thoroughly implementing the concepts of ICH Q10 to promote continual improvement.”10 The 2023 practice areas paper says CDER reviewed case studies based on ICH Q9(R1), Q10, and Q12, along with the ISO 9000 series, when defining the five areas.5

Read the practice areas against ICH Q10 and the mapping is close. Q10 section 2 (management responsibility) requires senior management to participate in the PQS, demonstrate visible support, ensure escalation processes exist, conduct management reviews, advocate continual improvement, and commit resources.11 That is practice area one. Q10 section 3.2 names the four PQS elements: the process performance and product quality monitoring system, CAPA, change management, and management review of process performance and product quality.11 Those are the elements practice area three examines, with the emphasis on whether they drive improvement. Q10 section 1.6 names two enablers, knowledge management and quality risk management.11 Knowledge management is most of practice area four, and quality risk management runs through areas two and three. Employee engagement has no dedicated Q10 section but supports Q10’s requirement that the quality policy be “communicated to and understood by personnel at all levels.”11

One sentence in ICH Q10 explains why a QMM program is needed at all. Q10 states that it “is not intended to create any new expectations beyond current regulatory requirements. Consequently, the content of ICH Q10 that is additional to current regional GMP requirements is optional.”11 The optional content is precisely the material that distinguishes a mature site: management review of the PQS itself (Q10 section 4.1), monitoring of internal and external factors, and the lifecycle use of knowledge and risk management. A CGMP inspection cannot demand what a guideline calls optional. QMM is FDA’s attempt to measure and reward it instead.

Regulatory flexibility: promised in principle, not delivered in practice

ICH Q10 Annex 1 describes “potential opportunities to enhance science and risk based regulatory approaches,” including increased use of risk-based approaches for regulatory inspections and optimized post-approval change processes for sites that demonstrate an effective PQS and product and process understanding, with the note that “the actual regulatory process will be determined by region.”11 The 2022 white paper picks this up, listing possible incentives that “could include reduced inspection frequency, increased regulatory flexibility in making postapproval changes, and improved supply chain insight,” and connecting QMM to the PQS effectiveness needed to use ICH Q12 tools.10 The 2023 presentation listed “incentives for participation” among operational decisions still to be made and planned a guidance to address “eligibility criteria for voluntary participation, components of the program, incentives.”18

As of the February 2026 notice, none of that has arrived. The notice describes no incentive beyond the report and follow-up meetings, no rating, and no guidance; the CDER QMM page lists white papers, notices, and journal articles but no guidance document.1,4 The 2022 white paper was explicit that “an evaluation of QMM is not currently part of the FDA’s assessment, inspection, or surveillance processes; the responsibility for QMM falls solely on the manufacturer,” and nothing published since has changed that status.10

The supply chain argument, and its evidence

FDA’s case that maturity produces resilience rests on benchmarking research, much of it CDER-funded. The 2022 white paper cites a University of St. Gallen analysis showing high-performing production sites displayed higher quality system maturity and quality culture than low-performing sites, a Dun & Bradstreet study of more than 200 establishments finding mature practices correlated with performance (reported as unpublished data), and CDER-funded work finding firms with positive workplace culture were less likely to experience shortages (also unpublished).10 The pilot paper adds that research on global manufacturers “found a significant positive correlation between delivery performance and the application of QMM principles associated with production.”6

In July 2025, OPQ published a second white paper, “Quality Management Initiatives in the Pharmaceutical Industry: An Economic Perspective,” which models four investment scenarios (minimal, suboptimal, optimal, and overinvestment) on a cost curve and argues that incremental investment in quality management is “not an all-or-nothing proposition.” It cites a case study in which a biopharmaceutical site with intermediate practices reduced defects by more than 50 percent and waste by 75 percent and redirected 25 percent of staff to other activities.12 The paper is persuasive as a framing document. Attorneys at Hyman, Phelps & McNamara pointed out its limits the following month: the model “relies heavily on case studies and anecdotal evidence rather than rigorous econometric analysis,” the paper itself concedes it leaves out the “external complexities of the pharmaceutical market,” and as a white paper rather than guidance “it’s not clear how or if this analysis might impact enforcement decisions going forward.”13 Leaders who want to fund a maturity program should cite the correlational research honestly, as correlation, and build the business case on their own cost of poor quality data.

The broader policy context still favors the program. FDA’s FY2025 Report on the State of Pharmaceutical Quality describes the agency’s “proactive approach to quality management” that “encourages a strong quality culture and supply chain reliability,” pointing to the QMM page as the example.20 The 2022 white paper noted that the White House’s 100-day supply chain review recommended FDA “lead the development of a framework to measure and provide transparency regarding a facility’s quality management maturity.”10 The direction is consistent across administrations. The timeline is not.

Running a Self-Assessment Without Joining the Program

Most mid-size pharma and biotech sites will not apply. Nine slots a year across the entire CDER-regulated industry, an NAI/VAI requirement, and an open question about FOIA exposure make that a rational choice. But the protocol’s structure is public, the pilot lessons on how to assess culture are public, and the 2024 scoring pattern tells you where to look. A site can run a credible internal assessment against the five practice areas in a quarter. Here is an approach that borrows the parts of FDA’s method that its own pilots validated.

1

Set the scope and the sponsor

Pick one establishment, not the company. QMM is site-level and FDA is explicit that maturity is independent of size, age, and product mix.5 Name a sponsor outside the quality unit (site head or head of operations), because three of the five practice areas are about business integration, supply planning, and technology, not about QA. Decide up front whether corporate functions will be interviewed; the pilots found some questions are best answered by corporate leaders with responsibility across sites and others by site personnel.6

2

Build the question set from the published elements

Use the five practice areas and the example elements from the 2023 white paper and the 2025 notice (management review and resource management; supply planning and demand forecasting; continual improvement, QRM, monitoring rationale, CAPA effectiveness, change management; data governance and process optimization; understanding of patient impact, rewards and recognition).5,2 Write open questions, not yes/no ones, and de-duplicate deliberately: assign quality risk management, knowledge management, and continual improvement each to one area so they are not scored twice.6 Twenty to thirty questions is enough; the FDF pilot used 24.6

3

Define a five-level working scale with evidence examples

FDA has not published its rubric, so write your own five-level ordinal scale and label it as a working scale. For each level in each area, list two or three documents or records that would substantiate it; sites in the pilots specifically asked for this.6 Keep the level descriptions short. FDA found that “unnecessary complexity in the level descriptions and the rubric may lead to subjectivity in scoring.”6

4

Self-assess first, then interview independently

Follow the two-stage FDF pilot design: the site leadership team scores itself, then a small assessment team (three people, at least one from outside the site) holds facilitated discussions focused on the areas where the self-score and the evidence diverge.6 Interview operators, supervisors, and managers separately; FDA concluded that independent interviews across levels may be important to gauge culture, something its virtual pilots could not do.6 Do not put a fixed time limit on questions.6

5

Score by consensus and report visually

Have assessors score independently and resolve differences by a documented consensus process, as the pilot assessors did.6 Present the result as a radar plot of the five areas with self-score and assessor score overlaid, which is the format both assessors and sites preferred.6 Write two to three strengths and two to three opportunities per area, matching the structure of FDA’s report.1

6

Pick one improvement per weak area and run FDA’s follow-up cadence

Choose at least one opportunity, write a plan with a defined goal, review it at three months and progress at six months, exactly as the program asks of participants.1 Put the review on the agenda of the management review of the PQS required by ICH Q10 section 4.1, so the maturity work becomes part of the quality system rather than a project beside it.11

Where to look hardest

Given the 2024 cohort pattern, weight the effort toward practice areas three and four.7 In the advanced PQS area, the test questions are the ones the white paper lists: what is the rationale for the metrics you monitor, how do you decide a CAPA was effective, does the deviation and CAPA data ever change how you run the process, and how often does risk review happen when nothing has gone wrong.5 In technical excellence, the test is data integration: can the site bring together deviation, batch, maintenance, complaint, and supplier data into one review without a week of manual extraction, and when a technology upgrade was proposed, how was fit for purpose decided.5 These are the questions where a compliant site with a competent quality unit is most likely to score a three.

For business continuity, the questions are ones many quality organizations have never been asked in an audit: how many unplanned production disruptions occurred in the last year because of maintenance, how quickly did the site recover, which single-source materials have no qualified backup, and how demand forecasts reach the site.5 Those answers usually live in supply chain and engineering, which is why the sponsor should not be QA.

What an internal assessment can borrow from the pilots, in one list
  • Orientation packet two weeks ahead, with example evidence per question.6
  • Self-assessment before facilitated discussion.6
  • Three assessors, independent scoring, consensus resolution.6
  • Open questions, no leading questions, no jargon, no time cap per question.6
  • Separate interviews by level of the organization.6
  • One topic scored in one place only.6
  • Radar plot output, two to three strengths and opportunities per area, three- and six-month follow-up.6,1

If you do decide to apply

The request is short. The 2026 notice asks for a contact, the establishment address, FEI and DUNS numbers, a brief description of operations including whether the site makes APIs, generics, innovator drugs, OTC drugs, or biological products and whether it is a contract manufacturer or testing organization, and confirmation of the eligibility characteristics.1 CDER selects “participants that reasonably reflect the diversity of the industry,” so a site that fills a gap in that diversity (a biologics drug substance site, for example) may have a better chance than a tenth oral solid dose plant.1 The year-three window closed on April 13, 2026; if the pattern of the last three years holds, a fourth-year notice would be the next opportunity, but FDA has not announced one and nothing in the 2026 notice commits to it.1 Run the internal assessment first regardless. Pilot participants estimated about 100 hours of their own time for an assessment, and the PharmExec authors’ advice to do a readiness assessment before enrolling is sound.6,15

What QMM Will and Will Not Do for Your Company

Here is the candid version, drawn only from what FDA has published and what the record shows.

What QMM will not do today

It will not reduce your inspection frequency, speed a post-approval change, or change how an investigator treats your site. The program is voluntary, the 2026 notice attaches no incentive, and the 2022 white paper’s list of possible incentives remains a list of possibilities.1,10 It will not give you a rating you can show a purchaser; there is no rating, and FDA has not decided whether ratings would ever be public.18 It will not certify product quality, because it does not evaluate products.5 It will not assess factors like backup raw material suppliers, inventory buffers, or redundant capacity in the way a product-level reliability program would.17 And it will not protect an assessment report from a records request; that risk is the applicant’s to weigh.14

What it will do is narrower and, for the right site, still valuable. Participants have consistently said the assessment surfaces improvement opportunities that internal audits and inspections did not, because it asks different questions.6 It gives a site a structured, outside view of five areas that no other regulator-designed instrument covers together, and it gives the improvement plan two scheduled conversations with CDER staff who are not inspectors.1 For a site that has decided to invest in maturity anyway, that is a useful forcing function, and participation in a prototype is a chance to shape a tool the industry will eventually meet in some form.

There is also a longer-term reading. FDA’s stated intent since 2019 has been a rating system that purchasers use, and its 2022 white paper openly describes the program as “a move toward performance-based regulation.”9,10 Stakeholders polled at the 2022 workshop overwhelmingly agreed purchasers should consider QMM (99 percent of more than 400 respondents), and when asked about the biggest benefit of participation, 52 percent chose identification of continual improvement opportunities, 25 percent improved supply chain insight, and only 17 percent regulatory incentives.6 The industry, in other words, already values what the assessment reveals more than what FDA might give for it. The pilot paper’s participant quotes about wanting QMM scores for API suppliers and contract labs point to where commercial pressure will come from first: not from FDA, but from customers who start asking their CDMOs and API suppliers the five practice-area questions in audits and contracts.6

What no one should do is treat QMM as a burden to be prepared for like an inspection. FDA’s own white paper says it plainly: “QMM is NOT an additional burden or requirement. It is, in fact, integral to an establishment’s quality system. Most establishments already have processes and practices aligned with QMM.”5 The right response to year three of the program is not to build a QMM readiness function. It is to ask, honestly and with evidence, how much of your site’s quality effort prevents problems and how much of it documents them after the fact, and then to move one practice area up one level in the next six months.

Conclusion

Three years in, FDA’s QMM program is exactly what its name says: a prototype. Nine sites were assessed in 2024, a second cohort was in progress when the third was announced, the tool has been streamlined once, and the agency has published no rating, no guidance, and no incentive. What it has published is more useful than any of those would be right now: a clear definition, five practice areas with the elements behind them, an honest account of what it learned about assessing culture, and a first look at how well-inspected volunteers scored. The scores say that management commitment and engaged employees are common among good sites, and that the advanced quality system and technical excellence that turn commitment into prevention are not. That gap is the drug shortage root cause the 2019 task force named, and it is the gap most sites can measure themselves without waiting for FDA.

Sakara Digital works with pharma and biotech organizations that want to move from a compliant quality system to a mature one, with particular depth in the data governance, monitoring rationale, and CAPA effectiveness questions where the 2024 cohort scored lowest. If you are weighing a QMM self-assessment, considering a future application, or simply want an independent read on which of the five practice areas would move first at your site, we are happy to have that conversation.

For Further Reading