In its 2026 guidance, the U.S. Food and Drug Administration (FDA) treats human factors and usability engineering as part of the complete safety case for a medical device, not merely as a separate test added at the end of the development process. These requirements have been incorporated into the eSTAR v7.0 electronic submission form, raising the documentation standard expected of companies when submitting medical device marketing applications.
This interpretation is based on guidance material sponsored by IQVIA MedTech and written by Di Lu, Associate Director of Regulatory Affairs for Human Factors and Usability Engineering at IQVIA MedTech. It therefore explains how to understand and document the requirements and is not a substitute for the FDA’s regulatory text itself.
Testing Is Not the Starting Point
The basic regulatory question, according to the material, is not whether the company conducted a human factors validation study, but whether the risks resulting from use of the device can be considered acceptable. A validation study remains one possible outcome of the usability engineering process, not the entire process.
If foreseeable misuse of a device could lead to serious harm to the user or patient, testing data are generally required to verify that risk controls are effective. If testing is not necessary, the company must document the rationale for that determination in the usability engineering file. In both cases, the FDA expects to see the complete process, including risk analysis, classification decisions, and supporting evidence, rather than a standalone test report.
Three Categories Determine the Amount of Evidence Required
The FDA framework divides devices or modifications into three categories associated with use-related risks and the effect of user interaction on device safety and effectiveness:
- Category 1: Typically includes modifications that do not affect the user interface, intended users, intended use, use environment, training, or labeling. Examples include updating an algorithm in radiological image-processing software without changing its user interface, tasks, or workflow.
- Category 2: Includes new devices that do not contain critical tasks, modifications that do not affect critical tasks, and situations in which critical tasks exist but the company can justify that new validation data are unnecessary based on the interface’s history and complexity and the existing risk controls.
- Category 3: Includes new devices with critical tasks and modifications that affect those tasks. A critical task is one whose improper performance could result in serious harm to the user or patient; in such cases, human factors validation testing data should be submitted.
The importance of distinguishing between Categories 2 and 3 lies in the fact that the same modification may move a device from one category to another. A home test for laboratory diagnosis may not require new validation if misreading the result would lead only to prolonged inconvenience. However, changing the intended user from a home patient to a clinical user may raise the potential consequences of misinterpretation to the level of misdiagnosis or an impact on patient care, particularly if the result is displayed differently from the customary standard.
What Must the Company Demonstrate?
It is not sufficient for a company to state that the modification did not materially change the risks. For a Category 2 claim, the FDA expects a detailed use specification defining the intended use, intended user, use environment, and required training for each device category.
Use-related risk analysis, known by the abbreviation URRA, is also now expected for nearly every new device, including types that historically did not need to submit human factors materials. The company also needs a report on known or foreseeable use problems, known as KUPS, based on public databases for similar devices. Formative data or physician statements may support an argument that the device’s use is consistent with the existing standard of care, particularly for surgical, radiological, and cardiac devices.
For modified devices, the most persuasive evidence may include a comparison of user tasks and the user interface, changes to the use specification, and risk controls, rather than simply stating that the changes are insignificant.
When Can a Clinical Study Replace Usability Testing?
The FDA may accept human factors validation incorporated into a clinical study instead of conducting a separate usability study, but under specific conditions. A usability protocol must be designed in advance as part of the clinical study and must reflect user interaction under real-world conditions of use. Training participants beyond what the typical user receives may also reduce the value of the data.
The evaluation process requires observing users during use. If the clinical study does not permit direct observation, additional monitoring data may be needed to supplement use errors and adverse events self-reported by participants. This pathway is more suitable when real-world use cannot be simulated, such as electrosurgical devices that rely on immediate tissue color changes or surgical instruments used on a beating heart.
What Changes in Practice Before Submission?
If the submission date is 30 to 90 days away, the material considers the priority to be not relying on a single validation report, but reviewing the design and development file to ensure that it reflects a coherent usability engineering process. The URRA should be completed, FDA adverse-event data for similar devices should be reviewed, and the rationale for a Category 2 classification should be reassessed if similar devices have shown serious use-related incidents.
For files prepared under the previous approach, it may be necessary to conduct a gap analysis before submission, including a comparative analysis of the user interface for modified devices. The material emphasizes that addressing these points during regulatory review is possible, but may lead to delays that could have been avoided.
Editorial reading: The most important practical change is not that the FDA has imposed a uniform test for every device, but that it requires companies to show their reasoning and evidence when assessing use-related risks. This increases the importance of classification decisions, analysis of prior incidents, and linking the design to risk controls from the early stages. The original regulatory source still needs to be reviewed for each device and situation, because the material is sponsored by IQVIA MedTech and does not present a complete official FDA text.