How it works
How a packaging validation program runs, and where the judgment sits.
You get a packaging file a reviewer can follow: the right evidence for your device, split into two clean streams, with a filed document at the end of every stage. Most of a program is machine time, fixed in length by physics. The decisions that make your submission read well happen before any sample is built, and making them is our work.
In short
How the packaging validation process is structured
Packaging validation has one decision in it that carries the weight. Stability evidence and performance evidence are separate branches rather than stages of one sequence: ASTM F1980 section 1.5 places distribution, handling and shipping events outside the scope of the aging guide. No order between them is mandated. What a reviewer reads is which arms you ran, in what combination, and why. We author that reasoning, you approve it, and an accredited laboratory runs the testing.
The decision
A laboratory will run whatever protocol you specify.
It is not engaged to tell you the protocol is wrong, because that is not what you bought. You bought machine time on a chamber, a shake table and a tensile frame. The quote prices the tests. It does not price the reasoning for why those tests and not others.
The reasoning is the deliverable. A reviewer opening your packaging section is likely to be looking for one line of reasoning: from your risk file to the conditions you tested, and from those conditions to the numbers you accepted. Where that line is missing, the tests can be entirely sound and the submission still comes back with questions.
So our work sits upstream of the laboratory. We decide which evidence your device needs, we write down why, and you approve it before a single sample is built.
One decision, two independent evidence streams.
You are paying us for the node, the branch decision in the middle. The two limbs are machine time you can buy from any accredited laboratory. The decision is what reaches your submission as written reasoning instead of raw data, and it is the part a reviewer actually reads.
The real-time lane leaves the frame on purpose. It starts from the same lots at the same time as the accelerated set, and it is still running long after the report is filed.
The two streams
Two separate branches, not stages of one thing.
ASTM F1980 section 1.5 places distribution, handling and shipping events outside the scope of the aging guide, so the aging arm and the distribution arm are answering different questions and neither can answer the other one. Our reading, labeled as ours: they are separate branches off the sterilized product rather than stages of one sequence, and anyone who tells you an order is mandated should be able to give you the clause that mandates it.
Performance, stability, the conditional combined arm, and what each one cannot tell you.
| Stream | The question it answers | Method | What it cannot tell you |
|---|---|---|---|
| StreamPerformance | The question it answersDoes the sterile barrier survive the events of shipping? | MethodASTM D4169 distribution simulation, or an ISTA procedure where the profile fits it better | What it cannot tell youAnything about time on a shelf. It is an event, not a duration. |
| StreamStability | The question it answersDoes the sterile barrier survive time on a shelf? | MethodASTM F1980 accelerated aging, with real-time aging started from the same lots at the same time | What it cannot tell youAnything about handling and shipping. F1980 section 1.5 puts those events outside its scope. |
| StreamCombined, conditional | The question it answersIs the honest worst case both at once? | MethodBoth arms applied to one condition set, in the order the distribution and storage profile justifies | What it cannot tell youWhich stress caused a defect. Combining costs you the ability to separate an event-related failure from a time-related one. |
Run the combined arm where your product's real route and storage make both stresses land on the same unit. Do not run it because it looks more thorough on paper. The cost is in the last column, and you carry it whether or not anything fails.
The order question
There is no mandated order, and that is the whole point.
Transit before aging is defensible: it challenges the barrier in the state it is actually shipped in. Aging before transit is also defensible, on the reasoning that aged material can be more brittle, so shipping an already-aged package is the harsher test. Both are sound. Neither is required.
The work is not picking the clever one. It is choosing deliberately for your distribution and storage profile, recording the reasoning where a reviewer can read it, and linking that decision to your risk management file. That is what your justification states: which branches ran, in what combination, and why.
A justification that names the alternative and explains the choice is harder to challenge than one that presents a single answer as the only one. If a reviewer prefers the other order, the document has already answered them.
Amendment 1:2023 applies a defined risk management process to packaging. A documented, risk-based choice of which arms run is precisely what the amendment asks for. The transition and the branch structure are the same point.
Dated notice
FDA accepts declarations of conformity to recognition 14-530, the un-amended ISO 11607-1:2019, until 20 December 2026. Recognition 14-594 covers the amended standard. This is a documentation gap rather than a testing gap, and it applies to premarket submissions only.
What the 2026 transition actually requiresWhere both streams converge
Integrity and strength, read against criteria fixed beforehand.
The evaluation methods, what each detects, and the data type each produces.
| Method | What it detects | Data type |
|---|---|---|
| MethodASTM F88 | What it detectsSeal strength, as the force required to separate the seal | Data typeVariables |
| MethodASTM F1929 | What it detectsChannel leaks in the seal, by dye penetration | Data typeAttribute |
| MethodASTM F2096 | What it detectsGross leaks in the whole package, by internal pressurization | Data typeAttribute |
- The two attribute methods are not duplication. They interrogate different failure modes: one looks at the seal, one looks at the whole package. Running both is defensible, and it has to be defended in writing rather than left standing as a coincidence.
- Data type decides how sample size is argued. Attribute results take a zero-failure reliability case stated as confidence and reliability. Seal strength is variables data and takes a tolerance interval, which is a different calculation with different assumptions to declare.
- All three are destructive. Condition sets are independent, and a unit used for dye penetration is not available for seal strength. That arithmetic decides how many units you build, and it is settled before the build rather than during it.
- Designations are bare on this page because that is the plain way to name a method. The recognized edition and FDA recognition number behind each one is published on our methodology page with the date the database entry was read, and your report carries the edition recorded on our standards register at the time of the work, which is not always the latest edition published.
The sterile barrier every one of these tests protects.
The vertical exaggeration is stated on the drawing and both scale bars are true. An undeclared exaggeration is the kind of thing this audience is trained to catch, so we declare it.
The program
Ten stages, and what each one produces.
You approve one plan at the start and receive one evidence package at the end. Every stage in between hands you a named document for your file, never a progress update: if a stage cannot name what it produces, it does not count as one.
- 01Intake and scope
The device and its class, the sterile barrier system and who makes it, the sterilization method and the maximum number of cycles the packaging must withstand, the distribution profile, the shelf life claim, and the submission date. Nothing is assumed from a template.
Discovery and intake record
- 02Packaging Validation Plan
What is covered and what is not. The packaging system layer by layer, sterile barrier system through to unitization. The sterilization state the packaging is presented in. The stated basis for the assurance level and the distribution cycle selected. The traceability spine opens here.
Packaging Validation Plan, with the traceability spine opened
- 03Test matrix and rationale
The branch decision, written down. Which arms run, whether they combine, in what order, and the reasoning for each, linked to your risk file. The rationale column is the whole game, and it is the one column a test plan can look finished without.
Test matrix with a rationale entry against every row
- 04Sample size justification
Sample size follows from the risk rating, and the risk rating is yours. We take the ratings out of your ISO 14971 file, state the confidence and reliability they support, name the method used for each data type, and state where a number is a practical optimum rather than a statistical requirement.
Sample size justification, with assumptions and limitations declared
- 05Sample build and chain of custody
Untraceable sample provenance is a failure mode this work is exposed to. Every unit is traceable to its lot, its build date, its sterilization load and the condition set it belongs to. Contingency units follow the same route as the set they support: a spare kept on a shelf has not been through transit and aging, and cannot substitute for one that has.
Build record and chain of custody log
- 06Protocols and the laboratory statement of work
One protocol per method, with acceptance criteria written before any sample is tested. Publication of a method by a standards body does not by itself make it validated in the laboratory that will run it, so a test report naming a method is not on its own evidence that the method was validated for your material and your seal configuration. That record normally sits with the laboratory performing the test, so we ask for it method by method, against that laboratory's actual scope of accreditation, before samples ship.
Test protocols and the laboratory statement of work
- 07Testing and deviation handling
The laboratory runs the testing. Deviations and nonconformances are raised when they happen and dispositioned in writing, not reconciled afterwards when the results are already known.
Deviation and nonconformance records
- 08Data review
Results read against criteria that were fixed before the test. A failing result is a valid outcome of a correctly specified test, and we report it as one. Acceptance criteria written after results are the most serious integrity failure there is in this work.
Test data review
- 09Validation Summary Report
The connected story, with clause traceability. Every row of the spine opened in the plan resolves here to a protocol, a result and a report section. Standards are cited with the edition on our register at the time of the work rather than the latest edition published, and with the FDA recognition number where the method is recognized.
Validation Summary Report, submission-ready
- 10Change control and revalidation guidance
What would invalidate this package: a material change, a supplier change, a sterilization cycle change, a new distribution route. Written down now, while it is cheap. The note also fixes the real-time arrangement in writing: who pulls the remaining points, when, who is told if real-time data disagrees with the accelerated result, and that the real-time data governs when it does. That conversation can land years after delivery, which is exactly why it is settled on paper before it does.
Change control and revalidation note
TEMPLATE
The traceability spine
It turns a folder of loose test results into a packaging section a reviewer can read straight through, opened in your validation plan and closed in the summary report.
| Requirement | Plan section | Protocol | Result | Report section |
|---|
Every row must resolve. A row that does not resolve is a finding against us, not against you.
This is the blank structure from our own template, shown as it stands before a program starts. The rows fill with your requirements, your protocols and your results. Every example on this site is drawn from our own templates.
How long
The paperwork can be compressed. The aging cannot.
A full program runs three to six months, which assumes an accelerated arm of roughly one to three months. A longer shelf life claim, or a lower chamber temperature, puts a program outside that range. The floor is arithmetic rather than effort. ASTM F1980 sets the oven time from the Q10 relationship. A Q10 of 2 is the common convention, higher values are less conservative and have to be justified, and we round the result up, because rounding down under-ages the samples.
The numbers on the drawing are there to be checked. Three years is 1095 days. At 60 C against a 23 C ambient with a Q10 of 2, the acceleration factor is 12.996, so the accelerated duration is 84.26 days, and the drawing says 85.
Everything either side of the chamber can be compressed. Protocols, sample planning, laboratory booking and the report package are document work, and document work moves at the speed it is resourced rather than at the speed of a chamber.
The one scheduling decision that matters is when the samples get built. Everything downstream waits on that, so it is settled at the plan stage rather than discovered later.
When to run it in house
Three questions. If you answer yes to all three, run it in house.
- Do you have a written sampling rationale you would defend in an Additional Information response?
- Do you have a documented, risk-based decision on which test arms run and in what combination?
- Do you have a test method validation position for every method in the plan?
Three yeses mean you already have what we sell, and you should go straight to a laboratory. If one of the three is missing, now is the cheap place to find that out. Mid-review and mid-audit are the expensive ones.
Where we stop
The edges of the engagement, stated plainly.
- We do not operate a laboratory
We hold no ISO/IEC 17025 accreditation and we do not claim it. We select the laboratory that fits the method, the accreditation scope and the schedule. A laboratory can hold ISO/IEC 17025 and still not be accredited for the specific method your device needs, because accreditation is scope-specific, so we check the scope rather than the certificate.
- We do not own the validation
You are the manufacturer. You approve the plan, you own the validation, and our name is never in your approval block. Deliverables and protocols are your property from the first day of the engagement. Your risk file is yours: we take its ratings as given and do not author the risk analysis.
- We do not promise a regulatory outcome
Nobody can. A consultant who promises one is telling you something they are not in a position to know. What we commit to is scope, schedule, the rationale in writing, and authorship of the packaging section you file.
- We hold no interest in any laboratory or packaging supplier
Laboratory charges are passed through at cost with the laboratory's own charge shown against them, and the handling charge is a disclosed line item rather than a claim about independence. It is on the invoice, as its own line.
After delivery
If someone asks about our work, we answer.
For 24 months after delivery we remain available to help you answer questions from a regulator, notified body or certification body about our work. Four hours are included per validation program, one hour for gap assessments. Beyond that, support is chargeable at the rate in your statement of work.
Project records are retained for seven years.
Questions
Questions this work raises.
- Do we have to do distribution simulation before aging?
No. ASTM F1980 section 1.5 puts shipping and handling events outside the aging guide's scope, so the two arms are asking different questions of the same package. No order is mandated, and we have never been shown the clause that would mandate one. What is required is that you chose deliberately and wrote down why.
- Can you make it faster?
The paperwork, yes. The aging, no. The Q10 arithmetic sets the oven time, and we round it up rather than down. Real-time aging starts alongside the accelerated set and continues past the report, which is the point of starting it early rather than the flaw in it.
- Who validates the test method, us or the laboratory?
Both, in different places. The validation record for a method normally sits with the laboratory performing the test, because publication of a method by a standards body does not by itself make it validated there. What sits with you is the supplier evaluation that chose that laboratory, and the file that records it. That is why we ask each laboratory for its position method by method, against its accredited scope, and put the answer in your file rather than leaving it as an assumption.
- What happens if a test fails?
It is reported as a failure. A failing result is a valid outcome of a correctly specified test, and it is a far cheaper thing to learn in a protocol than in an Additional Information response. What happens next is an investigation with a documented disposition, not a quiet re-run.
- Can you guarantee we clear?
No. Nobody can and nobody should say otherwise. We commit to the scope, the schedule, the sampling rationale in writing, and the packaging section you file.
- Do we have to run the full program to start?
No. The Gap Assessment is the smaller starting point. It reads your existing package against ISO 11607-1 and -2 including Amendment 1:2023 and grades every finding as a documentation gap, an evidence gap or a testing gap. A possible finding is that you have no gap and need nothing.
What you leave with
An honest read on where you stand.
On the call we work through where your evidence actually stands and what is missing from it. If a program makes sense, you get a one-page outline of what it would involve, what it would cost and how long it would take. If it does not make sense yet, that is the answer you get, and it is a useful one.
Thirty minutes, your device, this diagram.
Bring the device description, the sterilization method and the packaging format, and we will walk your product through the decision above. It is a working conversation, not a pitch.
- Thirty minutes. No slides.
- A personal reply the same business day, from the founder, not a queue.
- Device details are held in confidence. Mutual NDA available on request before you send anything.