← All articles

What FDA’s 2026 Human Factors Guidances Actually Change

Updated: 9 September 2026By HFhub

2026 has turned into a particularly important year for Human Factors in medical devices. In May, FDA published the final Content of Human Factors Information in Medical Device Marketing Submissions guidance after several years in draft. Then, in August, FDA revised Applying Human Factors and Usability Engineering to Medical Devices for the first time since 2016.

I have spent quite a bit of time comparing both documents with their previous versions. I went through more than 700 textual differences between the 2016 and 2026 versions of the revised Applying Human Factors guidance and almost 800 differences between the 2022 draft and the final 2026 Content guidance.

Most of those changes are editorial, reference updates, formatting changes, or wording that does not affect how a Human Factors program is actually run. A smaller number, however, have real implications for how Human Factors connects with device development, risk management, lifecycle management and regulatory submissions. Those are the changes I have focused on here.

Looking at the two guidances together is particularly interesting because their roles are now much more clearly separated. The revised Applying Human Factors guidance describes how Human Factors should be integrated into medical device development and risk management, while the Content of Human Factors Information in Medical Device Marketing Submissions guidance addresses how the resulting Human Factors evidence should be assessed and communicated to FDA.

In a way, this separation reflects how Human Factors is already managed in many organizations. The people responsible for the operational Human Factors process are often not the same people responsible for regulatory strategy and submission content. FDA has now created a similar distinction between the guidance governing the underlying HF process and the guidance governing what FDA expects to see in a marketing submission.

I’ve always believed, however, that a competent Human Factors professional working in medical devices must also have solid knowledge of the regulatory aspects. It is difficult to make good decisions about the URRA, validation strategy, evidence generation or residual risk if you do not understand how those decisions will eventually be assessed in a submission. The same applies in the opposite direction. It is difficult to build a strong regulatory argument if you do not understand how the Human Factors evidence was generated and what its limitations are. Those responsibilities may be separated organizationally, but I do not think they should be separated intellectually.

Anyway, regardless of how your organization divides these responsibilities, whether you work in Human Factors, Regulatory Affairs, Quality, Risk Management or device development, these are the changes I would pay attention to.

Decision Point D makes lifecycle evidence much more important

Of all the changes across the two guidances, I think Decision Point D is the most consequential. In the 2022 draft of the Content guidance, the logic was relatively direct. If a new device had critical tasks, or a modified device introduced new critical tasks or impacted existing ones, the device moved to Category 3. The final guidance inserts another decision. Even when critical tasks exist or have been impacted, FDA now asks whether Human Factors validation test data actually need to be submitted.

Decision Point D considers the history of use of the user interface for the intended use, users and environments, the complexity of the interface, and the adequacy of existing risk controls. This means that a new device can have critical tasks, or a modified device can have impacted existing critical tasks, and still remain Category 2 when the available evidence supports the conclusion. It is essentially formalizing something that seasoned Human Factors professionals have been doing for quite some time: building an evidence-based rationale for not submitting new Human Factors validation data.

In my experience, this is quite a significant point. FDA says that when critical tasks are impacted but existing risk controls remain effective, the rationale should include objective evidence that the risk controls remain effective. Decision Point D is therefore not a shortcut or a presumption against validation. FDA also identifies circumstances in which validation data are more likely to be needed, including complex user interfaces, device types with a history of known use errors, significant differences affecting use, new safety signals attributed to use error, or increases in the severity of potential harm. The decision ultimately depends on whether the available evidence is strong enough to demonstrate that the existing risk controls remain effective under the new conditions.

I have mentioned this before in some of my posts, but I think the impact on traditional lifecycle management activities could be significant. If manufacturers want to use post-market history as objective evidence to support a Category 2 rationale, they will need to understand use problems from a Human Factors perspective rather than relying only on the technical categories commonly used in complaint systems. More importantly, root-cause investigation methods may need to capture enough information to understand whether a reported problem was related to the user interface, what use error occurred, and whether the relevant risk controls actually performed as intended. Without that level of information, years of post-market data may be much less useful when trying to justify why a device with critical or impacted critical tasks does not require new Human Factors validation data in the submission.

For me, this is one of the most important consequences of Decision Point D. The flexibility to keep a device with critical or impacted critical tasks in Category 2 depends on the quality of the evidence accumulated throughout the product lifecycle. If post-market information has not been collected and investigated in a way that allows use-related problems and the performance of risk controls to be understood, that historical data may have limited value when it is later needed to support a regulatory justification. The final guidance also makes this lifecycle perspective more explicit for modified devices by asking manufacturers to consider multiple modifications collectively and assess the potential impact of cumulative changes, rather than evaluating each change in isolation. Decision Point D therefore has implications well beyond submission strategy. It changes the value of how Human Factors evidence is generated, maintained and connected with post-market activities throughout the life of the device.

Human Factors is being connected more directly to design inputs and formal risk management

Another operationally important change in the revised Applying Human Factors guidance appears very early in the document. The 2016 guidance said that, as part of design controls, manufacturers conduct a risk analysis that includes risks associated with device use and measures implemented to reduce those risks. The 2026 wording is more specific. When determining design and development inputs, manufacturers must include applicable outputs of the risk management process and usability requirements according to the intended use of the device.

That sentence has implications well beyond Human Factors documentation. If usability requirements are developed by the Human Factors team but do not formally enter the design and development input process, that approach is no longer aligned with FDA’s description of how usability requirements should be incorporated into device development. The same applies if important outputs from use-related risk analysis remain isolated in an HF document rather than connecting to the engineering requirements that actually drive the design.

For me, this is one of the changes that should involve Systems Engineering and Quality just as much as Human Factors and Risk Management. I would look at how usability requirements are generated, where they live, how they trace to user needs and risk controls, and whether design reviews evaluate them as design inputs rather than treating them as supporting documentation.

The language around risk management has also become much more consistent. The revised guidance repeatedly moves away from broader terms such as “risk management strategies” and “risk management options” toward risk control measures and risk control options. The underlying hierarchy has not changed, but FDA now describes Human Factors activities using terminology that is much closer to the language of formal medical device risk management. The Content guidance follows the same direction, including in its example URRA, where the applicable risk control measure and the method used to evaluate its effectiveness are explicitly identified.

The submission architecture is now much more flexible

The separation between the two guidances has some very practical consequences for how Human Factors information is prepared for FDA submissions.

The clearest example is Appendix A of the 2016 Applying Human Factors guidance. That appendix described the structure FDA recommended for the HFE/UE Report and, for many organizations, effectively became the default template for communicating Human Factors work in a submission. In the revised Applying Human Factors guidance, Appendix A is gone, and recommendations about what Human Factors information should be included in a marketing submission now sit in the Content of Human Factors Information in Medical Device Marketing Submissions guidance instead.

Interestingly, the old HFE/UE report structure has not really disappeared. Section V of the Content guidance still follows a very familiar eight-section architecture covering the conclusion, users and use environments, user interface, known use problems, preliminary HFE/UE activities, use-related risk analysis, critical tasks and Human Factors validation. For Category 3 submissions, Appendix C essentially preserves that complete HFE/UE report structure, although there are some changes in the content and organization.

The category-based reporting model itself is not new in the 2026 final guidance. Categories 1, 2 and 3, with different levels of recommended Human Factors information, were already present in the 2022 draft. What changes substantially in the final guidance is the boundary between Categories 2 and 3 through Decision Point D.

In general, the overall submission model is much more proportional than the architecture many organizations built around the 2016 guidance. Category 1 can be supported primarily by a conclusion and high-level summary. Category 2 adds information about the intended users, uses, use environments and training, the user interface and known use problems, together with the rationale supporting the Category 2 determination. Category 3 is where FDA recommends the complete HFE/UE report, including preliminary analyses and evaluations, the URRA, critical-task information and Human Factors validation evidence.

For me, this is one of the most useful aspects in the new guidance. I have never thought that every submission should require the same Human Factors report simply because the underlying development process was comprehensive. The amount of Human Factors work performed during development and the amount of Human Factors information FDA needs to review in a particular submission are two different questions.

That distinction is also why I would be careful about interpreting Category 1 or Category 2 as doing less Human Factors. A Category 2 submission may contain considerably less Human Factors information than a Category 3 submission, but supporting that category may still depend on a substantial amount of underlying evidence. The Content guidance explicitly recommends maintaining Human Factors information regardless of whether that information is ultimately submitted.

There are also some useful changes within the familiar report structure. The conclusion now includes the HF Submission Category and the rationale supporting the level of information being submitted. For modified devices, FDA adds explicit comparisons with the existing device across users, uses, use environments, training and the user interface. For Category 3 submissions, the old risk-analysis section is now more explicitly centered on the URRA and, for modified devices, the comparative URRA. These changes make the report more closely connected to the submission decision rather than simply documenting the Human Factors process that was performed.

One related change is worth highlighting. The final guidance now explicitly states that the URRA should include all user tasks and identify those considered critical. This should already follow naturally from a complete use-related risk analysis, but I am glad FDA has made it explicit because I still encounter companies that preselect a list of critical tasks for the URRA rather than presenting the complete task structure from which criticality was determined. That does not mean every task requires the same depth of analysis, but the URRA needs to provide enough of the overall picture to show how use-related risk and criticality were assessed.

There are practical efficiencies as well. Information already available elsewhere in the submission can be cross-referenced rather than duplicated, and previously reviewed Human Factors information does not need to be resubmitted. This can make the HFE/UE report substantially more efficient, particularly when device description, labeling, intended users and other relevant information already exist elsewhere in the submission.

Some documentation language has also moved with this restructuring. The revised Applying Human Factors guidance replaces references to the design history file with design and development file. It also removes the 2016 statements saying that all HFE/UE documentation should be retained in manufacturer files and that submissions do not need to contain all raw Human Factors validation data. I would not interpret those deletions as changes in FDA’s expectations. Those topics are now addressed in the Content guidance, which recommends maintaining Human Factors information regardless of whether it is submitted and explains that submitted Human Factors information does not typically include all raw validation data.

From an implementation perspective, I think the important change is therefore not simply that Appendix A has disappeared from Applying Human Factors. If an SOP or submission template still treats the 2016 Appendix A as FDA’s universal HFE/UE report structure, it needs to be updated. The current model is much more proportional: the underlying Human Factors evidence can remain comprehensive, while the information actually submitted to FDA can be adapted to what is needed for the specific HF Submission Category.

Revalidation and residual risk are more explicitly connected to risk management

The revised Applying Human Factors guidance is also clearer about what happens when problems identified during validation lead to additional design changes. The 2016 guidance said that, depending on the risk-management strategies implemented, retesting might be necessary. The revised guidance refers specifically to Human Factors revalidation and links that decision to the extent of the additional risk control measures and modification of the user interface.

That distinction is quite important inside a Quality system. “Retesting” can describe anything from an informal confirmation activity to a focused study, while “revalidation” has a clearer relationship with formal design validation and change control. At the same time, I would be careful not to interpret revalidation as automatically meaning that the complete original Human Factors validation study needs to be repeated. For modified devices, FDA continues to allow validation to be focused on the user interactions and tasks affected by the modification.

There is another terminology point that becomes relevant here. FDA acknowledges that Human Factors validation testing is sometimes referred to as “summative testing,” but also notes that some definitions of summative testing omit elements FDA considers essential to Human Factors validation. In my experience, this matters particularly for companies trying to operate a single global usability engineering process under IEC 62366 while also supporting FDA submissions.

I do not think the answer is to create artificial distinctions between a “summative study” and an “FDA validation study.” The important question is whether the evaluation being used for validation, or revalidation, contains the elements FDA expects and adequately evaluates the affected interactions and risk controls. Calling an activity “summative” does not by itself demonstrate that it satisfies FDA’s expectations for Human Factors validation, just as calling something “retesting” does not establish that the design has been appropriately revalidated.

While we are on the subject of validation, it is also worth noting that FDA has cleaned up the way residual risk is discussed after validation, bringing the language closer to conventional risk-management logic. The 2016 concept of “true residual risk,” described as risk beyond practicable means of elimination or reduction, has disappeared. The revised guidance instead describes a sequence in which remaining risks are considered for further control and the resulting residual risk is then evaluated for acceptability, with benefit-risk reasoning where necessary.

I prefer this structure because it removes a Human Factors-specific concept that could be difficult to reconcile with the wider risk-management process. FDA also changes the expectation for persistent serious use errors from being “analyzed well” to being “thoroughly analyzed,” reinforcing the level of investigation expected before accepting the remaining risk.

There is some new flexibility in formative methods

The definition of formative evaluation has been modified. The old definition described assessment at one or more stages of development and specifically referred to identifying interface strengths and weaknesses and potential use errors that could result in harm. The revised definition is shorter and more intent-based, describing an evaluation conducted with the intent intent to explore user-interface strengths, weaknesses and unanticipated use errors.

I think there is one potential problem with how this wording could be interpreted.. In medical-device Human Factors, formative evaluation is often associated with relatively small samples, commonly five to eight participants per user group. But that sample-size rationale was developed for a much more specific purpose: discovering usability problems, not for every question that might now fit within a formative evaluation. HE75:2025 makes this distinction explicitly, stating that sample size depends on the goal of the test and recommending five to eight participants when the objective is to uncover issues that cause frequent usability problems.

If the objective is to explore how users interact with an interface and identify problems that need to be addressed, a small iterative sample can be entirely appropriate. If the objective is instead to estimate the prevalence of a preference, quantitatively compare design alternatives, support a product claim, characterize population performance or answer another question requiring statistical inference, calling the activity a “formative evaluation” does not make five to eight participants an appropriate sample. The sample size needs to follow the question being asked and the strength of the conclusion the study is expected to support.

I would therefore be careful not to let the revised definition of formative evaluation create a broader interpretation of the traditional formative sample-size rationale. “Formative” describes the role of the evaluation in development. It does not determine the appropriate sample size.

There are also smaller terminology updates. “Heuristic Analysis” becomes “Heuristic Evaluation,” and the fault-tree-analysis section refers to a multidisciplinary rather than simply “diverse” team. The cognitive walkthrough section now says that the activity can involve users and/or Human Factors specialists making it explicit that an expert-based cognitive walkthrough can also fit within the method. The actual set of formative methods described by FDA has otherwise changed very little, so I would not redesign a process around these updates. They are mainly terminology changes worth correcting when procedures, templates or training materials are revised.

I have always thought, however, that FDA’s guidance could go much further in representing the breadth of methods available within Human Factors and ergonomics. The revised guidance still relies largely on the same familiar approaches such as task analysis, heuristic evaluation, expert review, contextual inquiry, interviews, cognitive walkthroughs and simulated-use testing. All of these are useful, but they represent only part of the methodological toolbox available to a Human Factors professional. Medical device development may also require methods that help understand workload, cognition, physical interaction, environmental constraints, workflow, situation awareness, anthropometric fit, biomechanics and other factors relevant to use-related risk.

I have never seen FDA’s list as defining what Human Factors work should look like. I see it simply as a set of examples, in practice, the Human Factors method should be selected based on the question that needs to be answered and the evidence needed to support design and risk-management decisions, rather than being limited to the methods that happen to be named in the guidance.

A few last terminology changes and clarifications are worth noting

The revised Applying Human Factors guidance adds or formalizes several definitions that were not present in the 2016 version, including harm, normal use, residual risk, serious harm, serious injury, use environment and use-related risk analysis. The addition of URRA is particularly relevant because the term is now formally embedded across FDA’s two Human Factors guidances. I would treat most of these changes as terminology alignment rather than a new process, but they are still worth cleaning up in SOPs, templates and training material.

One definition worth looking at more closely is abnormal use. The 2016 guidance described it as an intentional act or omission reflecting violative or reckless use or sabotage. The revised definition instead describes a conscious or deliberate act or omission that is counter to or violates normal use and is beyond further reasonable user-interface-related risk control by the manufacturer. I see this mainly as a clarification of the boundary between use error and abnormal use. Intentional behavior alone is not enough to classify something as abnormal use. The behavior also needs to fall outside normal use and beyond further reasonable UI-related risk control. For organizations that use “the user did it intentionally” as the basis for excluding a behavior from use-related risk analysis, the revised wording provides a more precise test.

There are also two smaller wording changes around validation that are worth knowing but should not be overinterpreted. The 2016 guidance said that labeling and training used in validation should “correspond exactly” to what would be used with the marketed US device. The revised guidance removes “exactly.” I would not read this as permission to test materially different labeling or training, but it does provide slightly more room to justify representativeness rather than literal identity.

Similarly, the language around a learning curve changes from one that “requires repeated use” to one “where repeated use is relevant.” Again, I do not see this as a major change in validation expectations. It simply makes the need for repeated use somewhat more dependent on the actual use context and the rationale for the study design.

A short note for combination products

One scope point is worth highlighting for anyone working with combination products. The final Content guidance is explicit that combination products can involve additional risks and considerations and are not addressed by the guidance, with sponsors directed to the appropriate Center and review division for combination-product-specific Human Factors questions.

I would therefore be careful about incorporating the Category 1, 2 and 3 framework directly into a combination-product procedure as though FDA had formally applied it to those products. Many of the concepts may remain useful, but the regulatory pathway still needs to be part of the Human Factors strategy.

Where I would update company procedures first

If I were updating a company Human Factors process around these guidances, I would prioritize four areas: the connection between Human Factors outputs and design and development inputs, lifecycle and cumulative change assessment, maintenance of the evidence needed to support Decision Point D, and replacement of the old Appendix A submission model with the Category 1, 2 and 3 reporting structure.

I would then address the more specific updates around abnormal use, revalidation, terminology, formative methods and validation-study wording. Those changes are worth incorporating, but I would consider them secondary to the process interfaces that determine whether Human Factors evidence can actually be generated, maintained and reused effectively across the product lifecycle.

My main takeaway from the two guidances

After comparing both documents, I would describe the 2026 changes as an operational realignment of Human Factors rather than a redesign of the Human Factors process. The fundamentals of understanding users, tasks and use-related risk, developing the interface, conducting formative work and validating the final design remain largely familiar.

The more significant change is what happens around that process. Decision Point D gives manufacturers greater flexibility over when new Human Factors validation data need to be submitted, but that flexibility depends on being able to demonstrate that existing risk controls remain effective. That makes complete URRAs, cumulative change assessment, comparative analysis, post-market information and the ability to maintain and reuse existing Human Factors evidence much more important throughout the product lifecycle.

To me, that is the main direction of these two guidances. FDA has made the submission framework more flexible while making the quality and continuity of the underlying Human Factors and risk-management evidence much more visible.