For organizations in the medical device industry, regulatory compliance is a critical component for success. In this article, we will break down the EU Medical Device Regulation (MDR), including the key changes in EU regulation for medical devices.
We will also cover compliance strategies for manufacturers as well as Software as a Medical Device (SaMD) companies and how a Quality Management System (QMS) can help businesses comply with regulatory requirements.
Understanding the EU MDR
The EU MDR, short for European Union Medical Device Regulation, is a regulatory framework governing the production and distribution of medical devices in the EU. MDR was introduced to bring EU legislation up to speed with both medical and technical advances in the health sector.
In short, MDR seeks to ensure the safety and performance of medical devices, ultimately providing a more patient-friendly environment where transparency and patient safety are key and patients can benefit from new, innovative medical devices. We will go into more detail on the specific changes and requirements in a later section.
The MDR framework aims to boost clinical safety and establish fair market access for medical device organizations by providing a transparent, straightforward, and sustainable regulatory framework. MDR also provides regulatory oversight and ensures post-market surveillance of medical devices.
The MDR also seeks to decrease ambiguity by providing clear definitions and classifications, to facilitate a common understanding at the EU level.
MDR Timeline & Deadlines
MDR (2017/745/EU) came into effect on May 26, 2021; it replaces the previously existing medical devices Directive (93/42/EEC) (MDD) and the active implantable medical devices Directive (90/385/EEC) (AIMDD).
The MDD and the AIMDD are considered “Directives”, whereas MDR is a “Regulation”. What is the difference between a directive and a regulation? According to the European Commission, regulations are not required to be transposed into national legislation (in contrast to directives). This means that the MDR should help reduce the chance of discrepancies in the interpretation of the legislation across the EU.
The MDR was initially published in May 2017. This marked the start of a four-year transition window, during which the MDR came into force gradually until the regulation’s “Date of Application”, May 26, 2021.
To facilitate a smooth transition to MDR, a few transitional conditions were set forth (Article 120). For example, some devices with MDD certificates were allowed to be on the market until May 26, 2024, and may be kept available until May 26, 2025.
Key Changes in EU Medical Device Regulation
In this section, we’ll summarize the key changes in EU medical device regulation established by the MDR, modernizing the previous system. While not an exhaustive list, these changes reflect the most critical changes to the legislation. For full details, please refer to the European Commission’s official website.
It is important to note that although the MDR introduces some new requirements for manufacturers, the MDR and the previous Directives generally have the same fundamental regulatory obligations regarding the responsibility of manufacturers and products.
Many of the essential requirements have been retained, and the MDR essentially adds to the requirements outlined in the Directives.
Let’s dive into the main changes and improvements brought forth by the MDR.

Broader scope & device reclassifications
Compared to the MDD, the MDR has a broader scope and reclassifies certain types of devices. Manufacturers of medical devices are encouraged to review their product portfolios to determine whether some of their devices that weren’t covered under the MDD now fall into the scope of the MDR. Manufacturers should also check whether specific devices will be reclassified and whether they will require examination from a Notified Body.
In addition, the EU MDR now explicitly includes software within the definition of a medical device if it is intended to be used for a medical purpose. This means that many more software applications are now covered by the regulation. As a result, SaMD companies should also review their software applications to determine if they need to comply with the new regulation.
Reinforced clinical evaluation requirements
The MDR also strengthens the requirements for clinical evaluation; these changes represent some of the biggest revisions to the previous Directives.
Similar to the MDD, the MDR incorporates the collection of clinical data available in the existing literature and the need to set up any needed clinical studies.
The Regulation also includes a procedure for the approval of multi-center clinical investigations on an EU level. These strengthened clinical evaluation requirements illustrate the MDR’s emphasis on a “life-cycle approach to safety”, supported by clinical data.
For SaMD organizations in particular, this means conducting clinical evaluations that go beyond demonstrating technical functionality. They must demonstrate actual clinical benefit and safety in the intended user population
Increased traceability & transparency
One new feature of the Regulation is the system of “unique device identifiers” (UDIs). This new system enables simplified traceability of medical devices and software with a medical purpose.
This requirement also seeks to aid in the quick and efficient product recall of medical devices found to pose safety risks.
Another new addition is a comprehensive European database on medical devices, EUDAMED. EUDAMED integrates various data points and systems to aggregate and analyze information about both the medical devices themselves and their manufacturers.
The database includes information such as the UDI, notified bodies, clinical investigations, vigilance, and market surveillance.
With the creation of EUDAMED, the MDR increases the traceability of medical devices and provides enhanced transparency, including easier access to information for both the public and healthcare professionals.
Increased oversight & surveillance
Notified bodies
In the context of EU medical device regulation, notified bodies play an important role. They are independent organizations that evaluate and certify medical devices. Under the MDR, notified bodies are bound by stricter oversight and designation requirements, for example in terms of clinical competence. The database of notified bodies can be found here.
Manufacturers of medical devices need to verify whether their notified body is designated under the MDR and whether the designation’s scope covers all of their products. This also applies to software as a medical device applications.
Working with the notified body is crucial to accurately estimating and planning the timing of certification. It is advisable to consult with a notified body early on in the development process. This helps ensure that companies are aware of the necessary steps to achieve timely compliance with MDR.
Conformity assessments
As part of the certification process, manufacturers must undertake a conformity assessment. Depending on the class of medical device, there are different routes or requirements for the conformity assessment. Please refer to the EU Commission’s website for more detailed information.
A conformity assessment generally includes auditing the manufacturer’s quality system. It can also entail a technical documentation review (depending on the type of device). After passing a conformity assessment, manufacturers can place a CE (Conformité Européenne) mark on the device.
In addition, the MDR includes increased oversight of medical devices both before and after they are placed on the market.
The regulation also introduces a new pre-market scrutiny mechanism that involves a pool of EU-level experts. The post-market surveillance requirements were also strengthened via improved coordination between EU countries regarding market surveillance and vigilance.
To facilitate MDR compliance, the Regulation places a greater emphasis on quality management systems (QMS).
The requirements for manufacturers’ QMS are covered in Article 10, 9. These include establishing, documenting, implementing, maintaining, updating, and continually improving the QMS.
The QMS should address both the internal processes of the company as well as the processes for the key activities related directly to medical devices.
Finally, the MDR requires that at least one employee within the organization is formally responsible for ensuring the company’s regulatory compliance with the Regulation, for example, a Regulatory Compliance Manager.
Specifically for SaMD companies, the classification focuses on the severity of the condition the software is intended to diagnose, prevent, monitor, treat, or mitigate. Higher classifications (Class IIa, IIb, and III) trigger more stringent requirements, including the mandatory involvement of Notified Bodies.
They are also required to establish a comprehensive QMS and to have a compliance officer. Although not explicitly a separate section, the MDR implicitly emphasizes cybersecurity. As software vulnerabilities can pose significant risks to patient safety, demonstrating robust cybersecurity measures is crucial for regulatory approval.
Compliance Tips for Medical Device Manufacturers
Now that we’ve covered the basics of the EU Medical Device Regulation, let’s explore compliance strategies for medical device manufacturers.
Before diving deep into the specifics of the MDR and the respective action items required to ensure compliance, companies must take stock of the internal situation and status quo.
Consider potential organizational hurdles that could impede progress, for example, staffing and resources, budget, and management awareness and buy-in. As required in the MDR, companies should designate one or more employees who are formally responsible for taking care of MDR compliance.
As a next step, companies should conduct a gap analysis. By thoroughly assessing the current compliance status, manufacturers will gain a comprehensive overview of the status quo and what still needs to be done.
Since the MDR has stricter classification requirements than the MDD, companies should carefully review their product portfolio as part of their gap analysis to understand whether the more rigorous MDR requirements affect their products. The gap analysis should also include assessing available clinical evidence and risk management and identifying any possible gaps.
A critical component of regulatory compliance is proper documentation and record keeping. For MDR compliance, organizations should review the changes to existing technical documentation and ensure that their QMS is updated accordingly to align with MDR standards.
In addition, medical device manufacturers should assess the potential benefits of AI-powered tools and software solutions regarding regulatory compliance.
AI systems can help enhance compliance efforts in several ways, including streamlining compliance processes by automating routine compliance tasks such as documentation and reporting. AI-powered tools also offer automated monitoring, allowing for proactive risk management.
Finally, companies should be sure to invest time into training and building awareness of the MDR and internal compliance practices.
Navigating the MDR as a SaMD Company
To successfully navigate the MDR, SaMD companies need to:
- Understand the classification of their software: Accurately classify the SaMD based on its intended purpose and the potential risks involved.
- Develop a robust QMS: Implement and maintain a comprehensive QMS aligned with ISO 13485, specifically addressing software development practices.
- Plan and execute clinical evaluations: Develop a well-defined clinical evaluation strategy and gather appropriate clinical evidence to demonstrate safety and performance.
- Establish a comprehensive PMS System: Implement a robust Post-Market-Surveillance system to actively monitor the performance and safety of the SaMD post-market.
- Address cybersecurity risks: Integrate cybersecurity considerations into the design, development, and maintenance of the SaMD.
- Ensure data privacy compliance: Comply with the GDPR when handling personal data.
- Engage with notified bodies early: For higher-risk SaMD, engage with Notified Bodies early in the development process to understand their requirements and expectations.
- Stay updated on guidance and interpretations: The MDR is a complex regulation, and guidance documents and interpretations are continuously evolving. Staying informed is crucial.
Practical Steps for Achieving EU MDR Compliance
As companies embark upon their MDR compliance journey, it is critical to develop a detailed implementation plan. For a step-by-step implementation overview, refer to the European Commission’s guide, which details the specific considerations and actions to be completed.
We touched on elements of the implementation guidance in the previous section, including a gap analysis and setting up a suitable QMS to help guide – and document – MDR compliance efforts.
The European Commission recommends assessing the adequacy of QMS to meet the standards required for medical devices under the new Regulation.
The specific regulatory requirements should be built into the QMS, enabling the organization to streamline its compliance efforts, align team members, and retain the appropriate documentation.
Additional steps include conducting a cost/benefit analysis of the product portfolio, building an implementation roadmap (including resource requirements), contacting and vetting potential Notified Bodies, and providing regulatory training.
After defining the roadmap and assessing the Notified Bodies to determine their availability to service the company’s implementation plan, it’s time to implement the various sub-projects and ensure that both the overall and individual responsibilities for MDR implementation have been put into place.
Companies should review the progress and effectiveness of their efforts and work with the Notified Body to align on submission dates to prevent delays in the approval process.
Finally, it is key to review the MDR implementation plan regularly and stay up to date with developing European regulatory guidelines.
Benefits of Daiki’s AI-Powered SaaS Platform for MDR Compliance
Daiki’s AI Governance platform and eQMS support medical device organizations on their MDR compliance journey. With Daiki, you can also simplify the path to ISO 13485 certification (the corresponding ISO standard for medical devices).
While ISO 13485 certification is not explicitly required for MDR compliance, it provides a structured approach to meeting many of the quality management and regulatory requirements of the MDR. Therefore, it’s highly beneficial and often seen as a de facto requirement for demonstrating compliance.
By leveraging Daiki, medical device manufacturers and SaMD companies can minimize consulting costs and ensure cost-effectiveness.
Daiki’s eQMS streamlines the MDR compliance process by simplifying documentation and reporting tasks. Our document and quality management system has clear review processes and version control, ensuring compliance and simplifying the stringent documentation requirements for MDR.
Daiki’s interactive platform guides you through medical device compliance step-by-step, making the complex MDR simple to understand, regardless of your expertise.
Our dynamic AI Copilot provides immediate answers to your compliance questions, saving you research time and accelerating your product launch. It also helps you generate, organize, and manage essential MDR compliance documents, ensuring critical information is easily accessible.
Daiki also helps your team assess training needs and tailors questionnaires, helping your organization streamline audits and technical documentation creation.
Daiki’s sister company, Gradient Zero, became ISO 13485 certified in order to work with a customer in the medical sector. When it was time to recertify, Gradient Zero used the Daiki platform to complete the recertification, saving countless hours and eliminating the need for costly consultants.
Our goal is not just to ensure your compliance with MDR, and ISO 13485, but to also enhance your development process, QMS, and operational efficiency using AI technologies.
If your company plans to develop your own AI systems, the Daiki platform can assist you with both the development and implementation of AI systems, in a responsible and compliant manner.
Conclusion
The EU Medical Device Regulation (MDR) introduces noteworthy changes to the regulation of medical devices in the EU, replacing the previous Directives with a more comprehensive framework. The MDR, which came into force in 2021, emphasizes increased transparency and patient safety.
Among the key changes are stricter clinical evaluation requirements, a broader scope and reclassification of some devices, enhanced traceability through unique device identifiers (UDIs), and the addition of an EU-wide database of medical devices, EUDAMED, for enhanced oversight.
Compliance strategies for manufacturers of medical devices and SaMD include conducting gap analyses, developing a detailed implementation plan, designing and maintaining a robust QMS, and close collaboration with notified bodies.
The complex landscape of medical device regulation can make compliance feel like a moving target. Organizations will benefit from finding the right QMS provider to simplify the MDR compliance process.
Daiki’s eQMS supports medical device manufacturers on their path to compliance, with the help of AI, to streamline and simplify the process of MDR compliance (and ISO 13485 certification), while ensuring data privacy. Get in touch to learn more about how Daiki can support your compliance journey.