The Medical Device Regulation (MDR) has brought significant improvements to the safety and traceability of medical devices. [1] At the same time, it presents manufacturers with a complex challenge: meeting obligations around quality management, risk management, clinical evaluation, post-market surveillance and vigilance. Compliance alone is not enough. You must also be able to demonstrate it to Notified Bodies, regulators and users.
In practice, we see many manufacturers struggling with this demonstrability.
Documentation is scattered across multiple systems, risk analyses exist in isolation from controls, and evidence is only gathered when an audit looms. This blog explores the core MDR obligations and how a structured approach can help you get a grip on these requirements.
The MDR imposes an extensive set of obligations on manufacturers. You need a quality management system that integrates risk management and includes procedures covering the entire lifecycle of the device. Technical documentation must be drawn up and kept up to date for as long as the device is on the market. After market launch, a post-market surveillance system must proactively collect data on safety and performance. [2] Think of post-market surveillance as a continuous monitoring and improvement cycle (PDCA): market signals feed into the risk analysis, which in turn leads to measures.
ISO-13485 provides the structure for this quality management system. The standard requires a process-based approach with documented procedures, records and change control. For each device type or product family, manufacturers compile a dossier containing documents covering the entire lifecycle. If you develop medical devices with software that connects to a healthcare institution's IT-systems, the NEN 7510 series is also directly relevant.
The MDR, ISO-13485, NEN 7510 and related standards intersect at numerous points. A design change affects the risk analysis, the technical documentation, potentially the clinical evaluation and the labelling. When these elements live in separate systems, inconsistencies arise.
We see the same picture at many manufacturers. Technical documentation is stored in SharePoint. Risk analyses live in spreadsheets. Corrective and preventive actions (CAPAs) are handled via email. Post-market surveillance data reside in yet another system. The Person Responsible for Regulatory Compliance (PRRC) or the quality manager has to pull all of this together manually.
This fragmentation means you are no longer in control. You lose oversight, the connections between risks, controls and requirements become obscured and evidence that should be retrievable within five minutes takes hours to piece together. Decisions are made on incomplete information and compliance only becomes demonstrable late in the process, often just before an audit.
This translates directly into common audit findings. Auditors regularly flag outdated procedures without current approvals, incomplete training records, corrective actions lacking documented root-cause analysis or effectiveness reviews and risk management files not updated following new post-market surveillance information. All findings that can be avoided with a structured approach.
The challenge is not a lack of knowledge about the MDR or ISO-13485; this expertise is typically present within organisations. The challenge lies in translating that knowledge into a workable structure where policies, risks, controls and evidence are interconnected.
An integrated approach makes these connections explicit. Take, for example, the risk of unintended exposure of patient data in a software-enabled medical device. This risk is linked directly in the risk register to concrete controls such as encryption and authorisation management. Those controls are then mapped to the relevant requirements from the MDR, ISO-13485 and NEN 7510 (a many-to-many relationship). This way, you can see at a glance which risks have been identified, how they are controlled and which requirements the controls support. One record, one workflow, one piece of evidence covering multiple audit requirements.
To support organisations in achieving this, we have developed the Governance, Risk & Compliance (GRC) Blueprint. The Blueprint is not a standalone GRC-platform where only the compliance team works, but a ready-to-use structure within Atlassian Cloud that fits how organisations already operate: Confluence as the central location for policies, processes and technical documentation; Jira for operational follow-up of controls and improvement actions.
The Blueprint is also modular. You start with the modules that are currently relevant (for example, ISO-13485 and MDR) and expand later with additional frameworks such as NEN 7510, NIS2 or the AI Act, without having to overhaul the existing setup. When an auditor asks how you meet a specific MDR requirement, the answer is not a search through folders but a direct reference to the linked document.
The transitional periods for CE certificates under the MDD have been extended, but that extension is not unlimited. For class III and implantable class IIb devices, the transitional provisions expire on 31 December 2027; for class IIa and other class IIb devices, on 31 December 2028. [3]
These deadlines may seem distant, but the lead time to become compliant and certified easily spans eighteen months. This is due to the audit sequence: the internal audit must be completed before a Notified Body can conduct the external audit. If you want to be MDR-certified for class III devices by the end of 2027, you need to complete the internal audit by Q1 2027 at the latest. That means preparations should start now.
Compliance with the MDR, ISO-13485 and other standards is not about the thickness of your manual, but about demonstrable risk control throughout the entire lifecycle of the medical device. Manufacturers who invest in a structured approach now will be able to show what they do, why they do it and that it works. That is the essence of sustainable compliance: not a one-off documentation exercise, but staying demonstrably in control.
We supports medical device manufacturers in both setting up a workable compliance structure and conducting internal audits. We understand the specific requirements and are happy to help you build a sustainable approach.
Sign up for our free webinar about the MDR on 24 August and discover how to implement medical software that is compliant, secure, and successful.
[1] Regulation (EU) 2017/745 of the European Parliament and of the Council of 5 April 2017 on medical devices.
[2] Article 10 of Regulation (EU) 2017/745 (MDR).
[3] Regulation (EU) 2023/607 of the European Parliament and of the Council of 15 March 2023.