Medical Device M&A Data Room: The Regulatory Evidence Room (2026 Guide)
Co-founder at Peony. Former M&A at Nomura, early-stage VC at Backed VC, and growth-equity / secondaries investor at Target Global. I write about investors, fundraising, and deal advisors from the deal-side perspective I spent years in.

Last updated: July 2026
I'm Sean Yu, co-founder of Peony. I have spent a lot of time on the deal side of medical device transactions, and the pattern is always the same: the founder thinks the diligence room is a formality, a place to dump PDFs so the lawyers can tick boxes. It is not. In a device deal the regulatory file is the asset. The buyer is not really buying your revenue — they can model that from the outside. They are buying your right to keep selling the product, and that right lives in your quality system, your 510(k) clearances, and your inspection history. The seller who understands this stages the room to the buyer's regulatory checklist and pre-answers the hard questions before they are asked. The one who dumps files loses the multiple.
Quick answer. A medical device M&A data room is a controlled, permissioned repository that stages a device company's regulatory evidence — 510(k)/PMA clearances, the quality-system file, CAPA and complaint logs, inspection history, and recall records — alongside the usual corporate, commercial, and financial diligence documents, organized to the buyer's regulatory due-diligence checklist. In device deals it is not a filing cabinet; it is the room where regulatory diligence either defends the price or triggers a re-trade, because the buyer inherits your quality system and FDA holds new owners responsible for the prior owner's problems.
There is a timing reason this guide exists now. As of February 2, 2026, FDA's Quality Management System Regulation (QMSR) is live. The final rule was published in the Federal Register on February 2, 2024 (citation 89 FR 7496) with a two-year runway, and that runway is over. The QMSR rewrites 21 CFR Part 820 to incorporate ISO 13485:2016 by reference, which means compliance with the international standard is now a US legal requirement rather than a voluntary bonus. It also retires the vocabulary every device founder grew up on: the terms Design History File (DHF), Device Master Record (DMR), and Device History Record (DHR) do not appear in the QMSR — ISO 13485 folds that content into a single concept called the "Medical Device File." The records did not go away; the labels did. And here is the problem: every seller's data room is still labeled the old way. The seller who labels both, and who pre-answers the 483/CAPA question, defends price. The one who does not, does not.
If you are selling a drug or a therapeutic asset rather than a device, this is the wrong guide — read the biotech M&A data room playbook, which owns IND/CMC/BLA and CVR structures. This post is for the device side: 510(k)/PMA, QMSR, and the Medical Device File.
What is a medical device M&A data room, and how is it different?
A medical device M&A data room is a permissioned virtual data room built to stage a device company's regulatory evidence for buyer diligence, not just its corporate paperwork. What makes it different from a generic M&A room is that the regulatory layer is load-bearing: the buyer's first move is to confirm every marketed product maps to a valid 510(k) or PMA, then to sweep your recalls, Warning Letters, inspection history, and adverse-event reports — most of which they can pull from public FDA databases before they ever open your room. The room's job is to pre-empt that sweep by staging the same evidence, organized and closed out, so the buyer reads "in control" instead of "unknown risk."
The distinction matters because of where the money moves. In a SaaS or services deal, diligence findings adjust price at the margin. In a device deal, regulatory findings are deal-shaping: as advisors put it, problems discovered during diligence can lead to price adjustments, changes in deal structure, or in extreme cases termination. The reason is inheritance. FDA increasingly scrutinizes legacy records from prior owners and cites new owners for inadequate processes — ownership transfer does not absolve responsibility. So the buyer is not diligencing a risk they can walk away from at close; they are diligencing a liability they will own. That asymmetry is why the QMS file is the asset, and why the room is worth staging deliberately.
Here is the device M&A landscape at a glance, current to mid-2026:
| Dimension | Where it stands in 2026 |
|---|---|
| Market context | US medtech M&A hit ~$97.6B in 2025, a decade high; H1 2026 tracked ~$36.5B as reported by trade press, running above H1 2025 |
| The QMSR shift | Live as of February 2, 2026 — 21 CFR 820 now incorporates ISO 13485:2016; DHF/DMR/DHR retired into the "Medical Device File" |
| What buyers check first | That every marketed product maps to a valid 510(k) or PMA in FDA's public databases; then recalls, Warning Letters, 483s, and adverse events |
| Dominant pathway | ~99% of US devices reach market via 510(k), not PMA; FDA cleared ~3,238 510(k)s in 2025 (~99% of the year's device authorizations) |
| Typical process length | Roughly 3–6 months from data room open to close for a founder-led sale; strategics run the deepest regulatory diligence |
| What the data room costs | A founder-led room runs a few hundred dollars a month (Peony Data Room, $52/user/month); enterprise auctions sit in platforms averaging ~$68K/year |
Why is regulatory diligence deal-shaping instead of a formality?
Regulatory diligence is deal-shaping because the buyer inherits your quality system and cannot escape it after close, so every unresolved regulatory issue is a liability they price today. This is the single mental shift that separates founders who defend their multiple from founders who get re-traded. You are not handing over a set of documents for the lawyers to review; you are handing over the operating license for the product, and the buyer's counsel treats it that way.
Start from what the buyer knows before they call you. Almost everything material about your regulatory standing is public. Your clearances are in FDA's 510(k) and PMA databases. Your recalls are in the Medical Device Recalls database, each one tagged Class I, II, or III. Your Warning Letters are searchable by company on FDA's site. Your adverse-event reports sit in MAUDE, which FDA began transitioning to the new Adverse Event Monitoring System (AEMS) in 2026. Your surgeon and KOL payments are in CMS Open Payments. A competent buyer runs all of these against your name before diligence formally opens, builds a red-flag list, and then opens your data room to see whether your version of reality matches the public record. When it does, you look disciplined. When it does not — a marketed product with no clearance you can point to, a recall with no root-cause closure, a KOL payment that appears in Open Payments but not in your consulting file — the gap itself becomes the finding, and the finding becomes a discount or a structure change.
The QMSR raises the stakes here in a specific, under-appreciated way. Under the old Quality System Regulation, FDA investigators were barred from reviewing your management-review reports, internal-audit reports, and supplier-audit reports during a routine inspection. The QMSR eliminated that protection. As of February 2, 2026, those internal quality records are inspectable — which means a buyer's regulatory counsel, thinking ahead to how FDA will treat the company post-close, now wants to see them too. Records you could once keep internal are now part of the diligence surface. If your internal audits have been finding the same nonconformity for three years running with no durable fix, that is now a visible problem.
How to run M&A due diligence without employees finding out
Run it as a need-to-know process with a tiny deal team and a data room that enforces access at the document level, because in device M&A the leak risk is internal and commercial, not the buyer. The people who can blow up your process are your own reps, your distributors, and your surgeon KOLs — the moment they suspect a sale, reps start hedging their pipeline, distributors slow their orders, and a KOL mentions it at a conference. Your job is to keep the circle small and the evidence trail clean.
Practically, that means a few disciplines. Keep the internal deal team to the smallest set of people who can actually produce the documents — usually the CEO, the CFO or head of finance, and one quality or regulatory lead, plus outside counsel. Use a data room with per-person access rather than shared links, so that nothing can be forwarded to someone outside the circle; a shared Dropbox link, once created, is a permanent uncontrolled door. Watermark every page with the viewer's name and email so that if anything leaks, it traces to exactly one recipient. Stage the room so the most sensitive commercial files — customer lists, rep territories, KOL contracts — are not loaded until a bidder is serious and under an NDA that names them. And prepare an honest, boring internal cover story for the diligence activity, such as a financing round or an audit, that explains why finance is pulling contracts without naming an acquisition. The cover story helps, but the real protection is structural: most of the room was never visible to anyone who could tip off the field.
This is a place where tooling matters more than willpower. I run Peony, a data room company used by 5,900+ customers, and the reason document-level permissioning exists is exactly this scenario — a founder who needs to show a buyer everything while showing the organization nothing.
How do you stage disclosure to competing bidders without leaking your edge?
Stage disclosure in tiers, releasing the most sensitive regulatory and commercial IP last and only to bidders who have proven they are serious, because a competing bidder is also a competitor who can keep whatever they see. This is the core tension of a competitive device process: the same competition that gets you a premium also puts your crown-jewel know-how in front of the exact people who would benefit most from it if the deal dies.
The workable pattern is a disclosure ladder. The first tier — open to any qualified bidder under a signed NDA — is the teaser-level regulatory picture: your clearance list, your product portfolio, high-level QMS structure, audited financials, and the shape of your commercial footprint without customer names. The second tier, opened once a bidder submits a credible indication of interest, adds the detail that lets them build a real model: 510(k) summaries, the inspection and recall history with CAPAs, reimbursement analysis, and redacted commercial contracts. The third tier — the Medical Device File itself, the design inputs and outputs, the verification and validation protocols, the manufacturing process, the unredacted KOL and distribution contracts — opens only after price and structure are largely agreed, and for a strategic competitor, only behind a clean team. At each step the documents stay view-only with download disabled and per-viewer watermarks on. The ladder does two things at once: it gives you a read on who is serious (a bidder unwilling to earn their way up the tiers is not a real buyer), and it limits how much a tire-kicker or a competitive-intelligence mission can extract.
Do I need a clean team before opening the data room to a competitor?
Yes — if a bidder is a direct competitor, put your crown-jewel regulatory and manufacturing IP behind a clean team before it ever renders on their screen. A clean team is a named, walled-off group — outside counsel, an independent consultant, or a ring-fenced diligence unit — that is contractually barred from sharing what it sees with the acquirer's competing product line or commercial teams. It reviews your most sensitive Medical Device File content, your 510(k) strategy, and your manufacturing process, and reports conclusions (not the underlying documents) back to the deal principals. This matters because a strategic buyer's R&D engineers cannot un-see your design inputs, validation approach, or process parameters if the deal collapses, and antitrust law separately constrains how much competitively sensitive information two competitors can exchange before a deal closes. Pair the clean team with document-level access, disabled downloads, and per-viewer watermarks so the review is both legally clean and forensically traceable.
What red flags do buyers actually pull from public databases?
Buyers build their red-flag list from public FDA and CMS databases before diligence opens, so the smart seller pulls the same records first and pre-empts every one of them. The point of staging the room this way is not paranoia; it is that the buyer will find these things regardless, and the only variable you control is whether they find them from you (framed and closed) or from a database (raw and unexplained). Here is where they look and what they find:
- 510(k) and PMA databases. Every marketed product must map to a valid clearance or approval. A product on your price list with no clearance you can point to is the fastest way to turn a diligence call into a re-trade conversation. Pull your own clearance list and reconcile it to what you actually sell.
- Medical Device Recalls database. Recalls are public back to 2002 and tagged Class I (reasonable probability of serious harm or death), Class II (temporary or reversible harm), or Class III (unlikely to cause harm). A recall is survivable; a recall with no documented root-cause and no evidence the corrective action stuck is not.
- Warning Letters. Searchable by company. A Warning Letter is a materially different signal than a 483 — it means FDA escalated, and the buyer will want the full response-and-closeout trail.
- Inspection history and 483s. There is no single clean database of every 483, but FDA's inspection and compliance-action dashboards, the FOIA reading room, and the CDRH inspections database (2008 to present) let a buyer reconstruct your inspection record. Stage your own 483s with their CAPAs so the buyer never has to FOIA them.
- MAUDE adverse events. MAUDE holds the adverse-event reports filed under 21 CFR Part 803 — millions of reports, useful for spotting a signal cluster on your product family. Remember MAUDE's own caveat: reports are published as submitted, FDA does not verify them, and causation cannot be inferred. A buyer who understands that will not over-weight a noisy report, but they will ask about a genuine cluster.
- CMS Open Payments. This is the classic device-M&A trap. Every payment your company makes to a physician or teaching hospital is reported to CMS and published, searchable by anyone. A buyer can pull your KOL and surgeon payment history and check it against the consulting contracts in your data room. A payment in Open Payments with no matching, fair-market-value contract in the room is an anti-kickback and Sunshine Act exposure the buyer will price — or walk from.
The takeaway is simple: run your own diligence from the outside before the buyer does, and stage the answers in the room.
What happens to my 510(k) clearances and quality system when I sell?
Your 510(k) clearances stay attached to the product and its legal manufacturer, so what happens depends on deal structure and on keeping FDA registration and listing current through the change of control. This is one of the most misunderstood mechanics in a device sale, and getting it wrong is a diligence red flag in itself.
In a stock sale, the legal entity that holds the clearances survives and simply changes ownership, so the 510(k)s and PMAs ride along with the company — but the buyer inherits the entire regulatory history too, including every past 483, recall, and open CAPA. In an asset sale, the picture is more involved: clearances are tied to the manufacturer of record, so the buyer needs to update FDA establishment registration and device listing to reflect the new owner, and the parties have to confirm that the clearance and its associated regulatory obligations transfer cleanly with the assets. Either way, establishment registration and listing (governed by 21 CFR Part 807, updated in FDA's public registration database, usually weekly) must reflect the new ownership after close, and the buyer's counsel will check that the transition is documented in the room. The other thing that transfers, unavoidably, is responsibility: FDA holds the new owner accountable for the quality system it acquires, which is exactly why the buyer diligences your QMS as hard as your revenue. Stage a short regulatory-transition memo in the room that lays out, product by product, how each clearance and registration moves in your proposed structure. It signals you have thought about the mechanics the buyer is worried about.
How do you organize the Medical Device File so a QMSR-era buyer can read it?
Organize the room product-by-product around each product's Medical Device File, and label every folder under both the QMSR term and the retired DHF/DMR/DHR terms so no reviewer stalls. The QMSR went live February 2, 2026, but the transition is uneven in practice: a buyer's regulatory counsel who trained on the new rule asks for the "Medical Device File," while a seasoned reviewer who spent twenty years under the Quality System Regulation still asks for the "DHF." If your room is labeled only one way, half your reviewers hunt for documents that are sitting right there under a name they are not searching for. Dual-labeling is a five-minute discipline that removes a real source of diligence friction.
Concretely, build one top-level folder per marketed product. Inside each, stage the Medical Device File content: the design history (user needs, design inputs, design outputs, design reviews, verification, validation, design transfer, and the design-change record), the device master record content (product specifications, production process, quality-assurance procedures, packaging and labeling), and the device history record content (production records, acceptance records, and lot traceability). Even though the QMSR no longer uses those three headings, group the content that way and note the mapping, because that is how the documents were created and how an experienced reviewer navigates them. Then, at the QMS level (not per product), stage your quality manual and ISO 13485:2016 certificate, your management-review and internal-audit records — now inspectable under the QMSR, so expect the buyer to want them — your CAPA log, your complaint and MDR files, your supplier and purchasing controls, and your training and competency records. The seller who maps the room to how the buyer checks it looks in control; the one who dumps a flat folder of PDFs makes the buyer do the organizing, and a buyer doing your organizing is a buyer finding your gaps.
What are the most common first-time seller mistakes in a device deal?
The most common first-time-seller mistake is treating the data room as a storage dump instead of an argument, followed closely by under-preparing the regulatory file the buyer inherits. First-time founders consistently underestimate how much of the deal outcome is decided in the room, and the errors cluster in predictable ways.
The recurring mistakes I see:
- Dumping files instead of staging them. A flat folder of five hundred PDFs forces the buyer to organize your company for you, and every hour they spend hunting is an hour they spend finding gaps. Stage to the checklist.
- Hiding the old 483. Founders sit on a closed 483 hoping it stays buried. It does not — the buyer reconstructs your inspection history from public sources, and a concealed observation reads as a control failure far worse than the observation itself.
- Leaving CAPAs open or undocumented. An open CAPA is the single item most likely to escalate a buyer's concern, because industry sources report CAPA deficiencies are the tipping point FDA uses to escalate to a Warning Letter. Close them, document effectiveness, or explain the plan.
- Ignoring change-of-control clauses. Distribution, GPO, and sales-rep agreements frequently require written consent before a merger or assignment, and closing without those consents can breach the contract and cost you the distribution the buyer is paying for. Inventory these early; buyers price the risk of lost access.
- Mismatched Open Payments and consulting files. A KOL payment history that does not reconcile to fair-market-value contracts in the room is a self-inflicted anti-kickback flag.
- Opening the whole room to everyone at once. Competitors get your crown jewels for free and you lose all read on who is serious. Stage disclosure in tiers behind a clean team.
- Buying more data room than the deal needs. A founder-led sale under $100M does not need a five-figure enterprise auction platform. Overpaying for the brand on the login page is not the same as protecting the deal.
- Letting the EU MDR cliffs sneak up. If you sell in Europe, legacy certificates face hard deadlines of December 31, 2027 and December 31, 2028; a buyer will price the risk of a product falling off the market.
Every one of these is preventable with a room that is staged, not stuffed.
How does the QMSR change what belongs in a 2026 device data room?
The QMSR changes the vocabulary you label with and expands the internal quality records a buyer expects to see, so a 2026 device room needs dual DHF/Medical Device File labeling and clean, inspection-ready audit and management-review files. The underlying documentation obligations did not shrink — FDA considers the old DHF/DMR/DHR content adequately covered by ISO 13485:2016 — but two shifts matter for how you stage the room.
First, the terminology. Because the QMSR incorporates ISO 13485:2016 by reference and that standard uses the "Medical Device File" concept rather than DHF/DMR/DHR, the modern buyer's regulatory checklist is written in ISO language. Your room, almost certainly built up over years under the Quality System Regulation, is written in FDA-QSR language. Bridge the two: label folders "Medical Device File (DHF/DMR/DHR)" so both generations of reviewer land on the right content. Second, the inspection surface. The QMSR eliminated the old rule's protection that shielded management-review, internal-audit, and supplier-audit reports from FDA inspection, and it added an explicit requirement to document traceability between design inputs, outputs, verification, and validation. Both of those now belong in a diligence-ready room — the buyer's counsel is modeling how FDA will treat the combined company after close, and they want to see that your internal quality records are clean and your design traceability is documented. A note for freshness: FDA published technical amendments to the QMSR in December 2025, so confirm you are working from the current text. The practical upshot is that the 2026 room is slightly more exposed than the 2025 room would have been, and the seller who cleaned up their internal audit findings before opening the room is the seller who benefits from that exposure rather than getting hurt by it. Across the 5,900+ customers who run deal and diligence rooms on Peony, the ones who defend their price are almost always the ones who staged the regulatory evidence deliberately rather than uploading it in a hurry the week diligence opened.
Frequently asked questions
Should I disclose an old FDA 483 to acquirers before or during diligence?
Disclose it early, on your terms, with the CAPA record attached — do not wait to be caught. A buyer's regulatory counsel can pull your inspection history from FDA's public dashboards, and finding an undisclosed 483 mid-diligence reads as a control failure even when the observation was minor. Stage the 483, your written response, the CAPA, and the effectiveness evidence (verification, closure, any follow-up inspection) as one clean packet, gated to the buyer's regulatory reviewer. The story you want the buyer telling their investment committee is "they found it, fixed it, proved it stuck" — not "what else are they hiding?" A documented closed 483 is a QMS that works; a hidden one is a re-trade.
Will an FDA 483 with completed CAPAs kill my medical device acquisition?
No — a 483 with completed, effectiveness-verified CAPAs rarely kills a device deal on its own; a Warning Letter or an unresolved CAPA is the real escalation risk. Inspectors issue Form 483 observations constantly, and industry sources report that CAPA deficiencies are the tipping point that escalates an observation into a Warning Letter. What buyers price is not the existence of the 483 but the state of the response: closed and durable, or open and drifting. Note that under the QMSR, effective February 2, 2026, FDA can now inspect your management-review and internal-audit records, which the old Quality System Regulation shielded. Stage the observation, response, CAPA, and closure evidence together and the 483 becomes proof your system self-corrects.
What red flags do buyers look for in medical device regulatory diligence?
Buyers hunt for gaps between what you market and what FDA cleared, and for quality-system decay they will inherit. The public-database sweep comes first: every marketed product must map to a valid 510(k) or PMA, and the buyer cross-checks recalls, Warning Letters, inspection history, and adverse-event reports against your room. The top red flags are marketed products with no clean regulatory pedigree, an open or poorly documented CAPA, a Class I or II recall without root-cause closure, a Warning Letter, KOL payments in CMS Open Payments but not your contracts, distribution or GPO agreements with unsecured change-of-control consents, and EU MDR legacy certificates nearing the December 2027 and December 2028 cliffs. FDA holds new owners responsible for inherited problems.
How do I keep a sale invisible to surgeon KOLs, distributors, and employees?
Run the process on a need-to-know basis and let the data room enforce it, because leaks in device M&A come through your commercial edges — surgeon KOLs, distributors, and reps — not through the buyer. Keep the deal team tiny, use per-person access instead of shared links so nothing forwards, and watermark every page with the viewer's identity so a leak traces to one recipient. Do not stage customer-identifying files, KOL consulting contracts, or rep territory data until a bidder is serious and under an NDA that names them. I run Peony, a data room company, and the pattern that works is document-level permissions plus dynamic watermarking plus a clean index that reveals structure without revealing counterparties.
How do I stop a strategic acquirer from mining my regulatory know-how if the deal dies?
Stage the crown-jewel regulatory IP last, behind a clean team, and never let a competitor's product engineers into your Medical Device File on first look. Your 510(k) strategy, design inputs and outputs, verification and validation protocols, and manufacturing process are the know-how a strategic buyer's R&D group would most like to see — and cannot un-see if the deal collapses. Gate those documents to a named clean team that is contractually barred from sharing with the acquirer's competing product line, keep them view-only with download disabled and watermarks on, and release them only after price and structure are largely agreed. A strong NDA is the legal backstop; document-level access control plus per-viewer watermarking keeps the process forensically defensible.
What's the best virtual data room for a medical device M&A deal?
The best data room for a device deal is the one that matches your process size, so segment by who is running it. A $14 billion strategic process run by a bulge-bracket bank will sit in an enterprise platform like Datasite, which averages roughly $68,000 in annual contract value and is built for banker-led auctions. A founder-led sale under $100M does not need that — it needs document-level permissions, dynamic watermarking, a clean index, and pricing that does not punish a six-month process. That is the lane Peony is built for, at $52 per user per month with unlimited free viewers. iDeals sits in between, typically $500 to $1,000 per month for mid-market. Match the tool to the deal.
Can I just use Dropbox or Google Drive for medtech due diligence?
You can, and I would not, because Dropbox and Google Drive give you shared links and folder permissions but none of the controls a regulated device sale needs. A device data room has to enforce document-level access (so a competing bidder's R&D team never reaches your Medical Device File), per-viewer watermarks (so a leaked 510(k) traces to one recipient), download control, and an audit trail of who opened what — the record you rely on in reps-and-warranties disputes. Shared-link storage attributes every leak to you, the seller, not the leaker, and cannot stage disclosure across bidders or run a clean team. Where the QMS file is the asset, a purpose-built room defends your price instead of re-trading it.
Should I sell to a strategic acquirer or a PE platform in 2026's medtech M&A wave?
It depends on whether you want maximum price with integration risk (strategic) or a partnership with a second bite (PE), and 2026's market supports both. Medtech M&A hit roughly $97.6 billion in 2025, a decade high, and momentum carried into 2026 — Boston Scientific agreed to acquire Penumbra for about $14.5 billion enterprise value, announced January 15, 2026, and Danaher closed its roughly $9.9 billion acquisition of Masimo on June 10, 2026. Strategics pay for synergy and usually pay the highest headline, but absorb your team and run the deepest regulatory diligence because they inherit your quality system. PE keeps management and offers a second exit. A competitive process with both reveals who values your asset most.
What multiple does a commercial-stage 510(k) device company sell for in 2026?
There is no single multiple, but the 2026 anchors point to a wide, growth-and-margin-driven range for commercial-stage device companies. The cleanest public benchmark is Danaher's acquisition of Masimo at roughly 18x estimated 2027 EBITDA (about 15x including full run-rate synergies) — a large, profitable, commercial-stage platform. Smaller 510(k)-cleared companies trade well below that, and industry rules of thumb suggest companies clearing roughly $10 million in annual EBITDA see a meaningful step-up over sub-scale peers. What moves your number is revenue growth, gross margin, reimbursement clarity, the durability of your 510(k) portfolio, and how clean your regulatory file is. Treat any comp-aggregator range as directional and the in-deal Masimo multiple as the hard anchor.
How do I organize the design history file and QMS records for buyer diligence?
Organize by the buyer's regulatory checklist and label your files under both the old and new vocabulary, because as of February 2, 2026 the QMSR replaced the DHF/DMR/DHR terms with the ISO 13485 "Medical Device File." Build one folder per product containing its Medical Device File — the design history (inputs, outputs, reviews, verification, validation), the device master record content (specifications, process, QA procedures), and the device history record content (production and lot records) — even though the QMSR retired those labels. Counsel on the new rule asks for the "Medical Device File"; a QSR-era reviewer still asks for the "DHF." Label both. Alongside, stage QMS masters, management-review and internal-audit records (now inspectable), the CAPA log, complaints, and supplier controls.
What documents go in a medical device M&A data room?
A device M&A data room holds the corporate deal file plus a regulatory evidence layer that is the real asset. The regulatory core: per-product 510(k) clearances or PMA approvals (with clearance letters and the FDA database link), the Medical Device File for each product, the QMS and ISO 13485 certificate, CAPA and complaint logs, MDR adverse-event records, recall and field-action history, and the full inspection history including any 483s with their CAPAs. The commercial and legal layer: distribution, GPO, and sales-rep agreements with change-of-control clauses; KOL consulting contracts mapped against CMS Open Payments; IP; supplier agreements; and EU MDR or other international certificates with transition status. The financial layer: audited statements, revenue by product and channel, and reimbursement analysis.
How much does a data room cost for a 3-6 month medical device sale process?
For a founder-led device sale, budget a few hundred dollars a month, not the five-figure enterprise contracts you will read about. Peony's Data Room plan is $52 per user per month with unlimited free viewers, so a three-to-six-month process costs a small, predictable monthly fee no matter how many bidders or advisors view it. Enterprise platforms like Datasite average around $68,000 in annual contract value; iDeals typically runs $500 to $1,000 per month for mid-market deals. Watch out for per-page pricing on a regulatory-heavy file — a device room full of validation protocols and inspection history runs to thousands of pages, and per-page models can turn a routine upload into a big bill. A flat per-user model is usually cheaper.
Related resources
- Biotech M&A Data Room 2026 — the sibling for drug and therapeutic deals: IND/CMC/BLA, eCTD modules, and CVR structures, where this guide owns the device side (510(k)/PMA and QMSR)
- Best Healthcare M&A Advisors — how to pick a banker for a medtech or healthcare sale, and what a device-specialist advisor adds to a regulated process
- M&A Due Diligence Process Guide — the end-to-end diligence workflow that the regulatory layer in this guide plugs into
- Virtual Data Room Cost Guide — pricing models compared, including why per-page pricing punishes a document-heavy regulatory file
- Imaging Center M&A Data Room — the sibling for diagnostic-imaging and outpatient-center deals, where reimbursement and accreditation lead diligence
- Medical Equipment Sale Data Room — the sibling for capital-equipment and device-distribution sales, with its own service-contract and installed-base diligence
- Dynamic Watermarking Guide — how per-viewer watermarking makes a leak traceable to one recipient, the control that underpins a confidential process
Sources
- Medical Devices; Quality System Regulation Amendments (89 FR 7496) — QMSR final rule, published Feb 2, 2024, effective Feb 2, 2026
- Medical Devices; Quality Management System Regulation Technical Amendments (Dec 4, 2025) — confirms the QMSR text was amended in Dec 2025
- FDA Quality Management System Regulation (QMSR) — FDA landing page for the ISO 13485:2016 incorporation
- Boston Scientific to acquire Penumbra — announced Jan 15, 2026; ~$14.5B EV, $374.00/share
- Danaher completes acquisition of Masimo — closed June 10, 2026 (~$9.9B EV, ~18x est. 2027 EBITDA)
- FDA 510(k) Premarket Notification database — public clearance lookup buyers use to verify marketed products
- FDA PMA database — public premarket-approval lookup
- FDA Medical Device Recalls database — recall history tagged Class I/II/III, public since 2002
- FDA Warning Letters — searchable by company, date, and issuing office
- CMS Open Payments — public database of manufacturer payments to physicians and teaching hospitals
- FDA Establishment Registration & Listing search — 21 CFR Part 807, updated weekly, checked at change of control
- Amending Regulation (EU) 2023/607 — EU MDR legacy transition deadlines of Dec 31, 2027 and Dec 31, 2028

