EU MDR Compliance Requirements and Timeline
The Essential Guide to Requirements Management and Traceability
Chapters
- 1. Requirements Management
- Overview
- 1 What is Requirements Management? A Complete Guide
- 2 Why do you need Requirements Management?
- 3 Four Stages of Requirements Management Processes
- 4 Adopting an Agile Approach to Requirements Management
- 5 Status Request Changes
- 6 Conquering the 5 Biggest Challenges of Requirements Management
- 7 Three Reasons You Need a Requirements Management Solution
- 8 Guide to Poor Requirements: Identify Causes, Repercussions, and How to Fix Them
- 9 What Is a Requirements Management Plan? A Practical Guide
- 2. Writing Requirements
- Overview
- 1 Functional requirements examples and templates
- 2 What Is a Product Requirements Document? A Complete PRD Guide
- 3 What Is a User Requirement Specification (URS)? How to Write and Manage One
- 4 Identifying and Measuring Requirements Quality
- 5 How to Write a System Requirements Specification (SRS) Document
- 6 The Fundamentals of Business Requirements: Examples of Business Requirements and the Importance of Excellence
- 7 What Is a Compliance Risk Assessment? Steps, Framework, and Examples
- 8 Adopting the EARS Notation to Improve Requirements Engineering
- 9 Jama Connect Advisor™
- 10 Frequently Asked Questions about the EARS Notation and Jama Connect Advisor™
- 11 How to Write an Effective Product Requirements Document (PRD)
- 12 Functional vs. Non-Functional Requirements
- 13 What Are Nonfunctional Requirements and How Do They Impact Product Development?
- 14 What Is a Software Design Specification? Key Components + Template
- 15 Characteristics of Effective Software Requirements and Software Requirements Specifications (SRS)
- 16 8 Do’s and Don’ts for Writing Requirements
- 17 Project Requirements: Types, Process, and Best Practices
- 3. Requirements Gathering and Management Processes
- Overview
- 1 Requirements Engineering
- 2 Requirements Analysis
- 3 A Guide to Requirements Elicitation for Product Teams
- 4 Requirements Gathering Techniques for Agile Product Teams
- 5 Requirements Gathering in Software Engineering: Process, Techniques, and Best Practices
- 6 Defining and Implementing a Requirements Baseline
- 7 Managing Project Scope — Why It Matters and Best Practices
- 8 Requirements Decomposition and How AI Supports It
- 9 How Long Do Requirements Take?
- 10 How to Reuse Requirements Across Multiple Products
- 11 Requirements Prioritization Techniques: 7 Methods for Engineers
- 4. Requirements Traceability
- Overview
- 1 What Is Traceability in Product Development? A Guide for Regulated Teams
- 2 Tracing Your Way to Success: The Crucial Role of Traceability in Modern Product and Systems Development
- 3 Bidirectional Traceability: What It Is and How to Implement It
- 4 Change Impact Analysis (CIA): A Short Guide for Effective Implementation
- 5 What is Engineering Change Management (ECM)? A Complete Guide
- 6 What is Meant by Version Control?
- 7 Key Traceability Challenges and Tips for Ensuring Accountability and Efficiency
- 8 The Role of a Data Thread in Product and Software Development
- 9 Unraveling the Digital Thread: Enhancing Connectivity and Efficiency
- 10 What is a Traceability Matrix? A Guide to Requirements Traceability
- 11 How to Create and Use a Requirements Traceability Matrix (RTM)
- 12 Requirements Traceability Matrix Pros and Cons: A Practical Guide
- 13 Live Traceability vs. After-the-Fact Traceability
- 14 Overcoming Barriers to Live Requirements Traceability™
- 15 Requirements Traceability, What Are You Missing?
- 16 Requirements Traceability: Links in the Chain
- 17 What Are the Benefits of End-to-End Traceability During Product Development?
- 18 Requirements Volatility: 7 Essential Management Strategies
- 19 FAQs About Requirements Traceability
- 20 What Is AI Traceability? How to Implement It
- 21 Product Traceability for Regulated Industries: A Complete Guide to Audit-Ready Compliance
- 22 What Is the Traceability Information Model?
- 5. Requirements Management Tools and Software
- Overview
- 1 Selecting the Right Requirements Management Tools and Software
- 2 Why Investing in Requirements Management Software Makes Business Sense During an Economic Downturn
- 3 Why Word and Excel Alone is Not Enough for Product, Software, and Systems Development
- 4 Can You Track Requirements in Excel?
- 5 What Is Application Lifecycle Management (ALM)?
- 6 Is There Life After DOORS®?
- 7 Can You Track Requirements in Jira?
- 8 Checklist: Selecting a Requirements Management Tool
- 6. Requirements Validation and Verification
- 7. Meeting Regulatory Compliance and Industry Standards
- Overview
- 1 Understanding ISO Standards
- 2 Understanding ISO/IEC 27001: A Guide to Information Security Management
- 3 What is DevSecOps? A Guide to Building Secure Software
- 4 Compliance Management
- 5 What Is Functional Safety (FuSa)? Standards, Lifecycle, and Where Programs Fail
- 6 Failure Mode and Effects Analysis (FMEA) Explained
- 7 TÜV SÜD: Ensuring Safety, Quality, and Sustainability Worldwide
- 8 What is IEC 62443? A Guide to Industrial Cybersecurity
- 9 DFARS Compliance: A Guide for Defense Contractors
- 10 CMMC vs FedRAMP: What’s Different and Which One Applies to You
- 11 Automotive SPICE (ASPICE) 4.0: A Complete Guide
- 8. Systems Engineering
- Overview
- 1 What is Systems Engineering? A Guide for Modern Engineering Teams
- 2 How Do Engineers Collaborate? A Guide to Streamlined Teamwork and Innovation
- 3 The Systems Engineering Body of Knowledge (SEBoK)
- 4 What Is MBSE? Model-Based Systems Engineering Explained
- 5 Digital Engineering Between Government and Contractors
- 6 Digital Engineering Tools: The Key to Driving Innovation and Efficiency in Complex Systems
- 9. Automotive Development
- Overview
- 1 Understanding IATF 16949: A Quick Guide to Automotive Quality Management
- 2 What Is ISO 21434? Automotive Cybersecurity Engineering Explained
- 3 What Is ISO 26262? A Guide to Functional Safety in Automotive
- 4 What Is ASIL? A Guide to Automotive Safety Integrity Levels in ISO 26262
- 5 What Is SOTIF? A Guide to ISO 21448 for ADAS Safety
- 10. Medical Device & Life Sciences Development
- Overview
- 1 The Importance of Benefit-Risk Analysis in Medical Device Development
- 2 Software as a Medical Device: Revolutionizing Healthcare
- 3 What’s a Design History File, and How Are DHFs Used by Product Teams?
- 4 Navigating the Risks of Software of Unknown Pedigree (SOUP) in the Medical Device & Life Sciences Industry
- 5 What Is ISO 13485? A Guide to Medical Device Quality Management Systems
- 6 What You Need to Know: ANSI/AAMI SW96:2023 — Medical Device Security
- 7 ISO 13485 vs ISO 9001: Understanding the Differences and Synergies
- 8 What Is IEC 62304? A Guide to Medical Device Software
- 9 What Is a Device Master Record (DMR)? Definition and FDA Requirements
- 10 Failure Modes, Effects, and Diagnostic Analysis (FMEDA) for Medical Devices: What You Need to Know
- 11 Embracing the Future of Healthcare: Exploring the Internet of Medical Things (IoMT)
- 12 What Is General Safety and Performance Requirements (GSPR)? What You Need To Know
- 13 What Is IEC 62366? A Guide to Medical Device Usability Engineering
- 14 What Is the Quality Management System Regulation (QMSR)?
- 15 510(k) vs PMA: Differences in FDA Device Approval and Clearance
- 16 EU MDR Compliance Requirements and Timeline
- 11. Aerospace & Defense Development
- Overview
- 1 What is ITAR Compliance? What Engineering Teams Need to Know
- 2 What Is ARP4754A? A Complete Guide to Civil Aircraft and Systems Development Assurance
- 3 Understanding ARP4761A: Guidelines for System Safety Assessment in Aerospace
- 4 What Is DO-254? A Complete Guide to Airborne Hardware Design Assurance
- 5 What Is DO-178C? A Guide to Airborne Software Certification
- 12. Architecture, Engineering, and Construction (AEC industry) Development
- 13. Industrial Manufacturing & Machinery, Automation & Robotics, Consumer Electronics, and Energy
- 14. Semiconductor Development
- 15. AI in Product Development
- Overview
- 1 What Is AI in Product Development? A Complete 2026 Guide
- 2 AI Test Case Generation: A Complete Guide for Regulated QA Teams
- 3 Using AI to Write Software Requirements: What Works and What Doesn’t
- 4 What Is the Model Context Protocol (MCP) for Requirements Management?
- 5 AI for Systems Engineering: Benefits, Risks, and How to Start
- 6 How to Automate Requirements Management
- 7 Artificial Intelligence in Requirements Management
- 16. Risk Management
- 17. Product Development Terms and Definitions
Chapter 10: EU MDR Compliance Requirements and Timeline
Chapters
- 1. Requirements Management
- Overview
- 1 What is Requirements Management? A Complete Guide
- 2 Why do you need Requirements Management?
- 3 Four Stages of Requirements Management Processes
- 4 Adopting an Agile Approach to Requirements Management
- 5 Status Request Changes
- 6 Conquering the 5 Biggest Challenges of Requirements Management
- 7 Three Reasons You Need a Requirements Management Solution
- 8 Guide to Poor Requirements: Identify Causes, Repercussions, and How to Fix Them
- 9 What Is a Requirements Management Plan? A Practical Guide
- 2. Writing Requirements
- Overview
- 1 Functional requirements examples and templates
- 2 What Is a Product Requirements Document? A Complete PRD Guide
- 3 What Is a User Requirement Specification (URS)? How to Write and Manage One
- 4 Identifying and Measuring Requirements Quality
- 5 How to Write a System Requirements Specification (SRS) Document
- 6 The Fundamentals of Business Requirements: Examples of Business Requirements and the Importance of Excellence
- 7 What Is a Compliance Risk Assessment? Steps, Framework, and Examples
- 8 Adopting the EARS Notation to Improve Requirements Engineering
- 9 Jama Connect Advisor™
- 10 Frequently Asked Questions about the EARS Notation and Jama Connect Advisor™
- 11 How to Write an Effective Product Requirements Document (PRD)
- 12 Functional vs. Non-Functional Requirements
- 13 What Are Nonfunctional Requirements and How Do They Impact Product Development?
- 14 What Is a Software Design Specification? Key Components + Template
- 15 Characteristics of Effective Software Requirements and Software Requirements Specifications (SRS)
- 16 8 Do’s and Don’ts for Writing Requirements
- 17 Project Requirements: Types, Process, and Best Practices
- 3. Requirements Gathering and Management Processes
- Overview
- 1 Requirements Engineering
- 2 Requirements Analysis
- 3 A Guide to Requirements Elicitation for Product Teams
- 4 Requirements Gathering Techniques for Agile Product Teams
- 5 Requirements Gathering in Software Engineering: Process, Techniques, and Best Practices
- 6 Defining and Implementing a Requirements Baseline
- 7 Managing Project Scope — Why It Matters and Best Practices
- 8 Requirements Decomposition and How AI Supports It
- 9 How Long Do Requirements Take?
- 10 How to Reuse Requirements Across Multiple Products
- 11 Requirements Prioritization Techniques: 7 Methods for Engineers
- 4. Requirements Traceability
- Overview
- 1 What Is Traceability in Product Development? A Guide for Regulated Teams
- 2 Tracing Your Way to Success: The Crucial Role of Traceability in Modern Product and Systems Development
- 3 Bidirectional Traceability: What It Is and How to Implement It
- 4 Change Impact Analysis (CIA): A Short Guide for Effective Implementation
- 5 What is Engineering Change Management (ECM)? A Complete Guide
- 6 What is Meant by Version Control?
- 7 Key Traceability Challenges and Tips for Ensuring Accountability and Efficiency
- 8 The Role of a Data Thread in Product and Software Development
- 9 Unraveling the Digital Thread: Enhancing Connectivity and Efficiency
- 10 What is a Traceability Matrix? A Guide to Requirements Traceability
- 11 How to Create and Use a Requirements Traceability Matrix (RTM)
- 12 Requirements Traceability Matrix Pros and Cons: A Practical Guide
- 13 Live Traceability vs. After-the-Fact Traceability
- 14 Overcoming Barriers to Live Requirements Traceability™
- 15 Requirements Traceability, What Are You Missing?
- 16 Requirements Traceability: Links in the Chain
- 17 What Are the Benefits of End-to-End Traceability During Product Development?
- 18 Requirements Volatility: 7 Essential Management Strategies
- 19 FAQs About Requirements Traceability
- 20 What Is AI Traceability? How to Implement It
- 21 Product Traceability for Regulated Industries: A Complete Guide to Audit-Ready Compliance
- 22 What Is the Traceability Information Model?
- 5. Requirements Management Tools and Software
- Overview
- 1 Selecting the Right Requirements Management Tools and Software
- 2 Why Investing in Requirements Management Software Makes Business Sense During an Economic Downturn
- 3 Why Word and Excel Alone is Not Enough for Product, Software, and Systems Development
- 4 Can You Track Requirements in Excel?
- 5 What Is Application Lifecycle Management (ALM)?
- 6 Is There Life After DOORS®?
- 7 Can You Track Requirements in Jira?
- 8 Checklist: Selecting a Requirements Management Tool
- 6. Requirements Validation and Verification
- 7. Meeting Regulatory Compliance and Industry Standards
- Overview
- 1 Understanding ISO Standards
- 2 Understanding ISO/IEC 27001: A Guide to Information Security Management
- 3 What is DevSecOps? A Guide to Building Secure Software
- 4 Compliance Management
- 5 What Is Functional Safety (FuSa)? Standards, Lifecycle, and Where Programs Fail
- 6 Failure Mode and Effects Analysis (FMEA) Explained
- 7 TÜV SÜD: Ensuring Safety, Quality, and Sustainability Worldwide
- 8 What is IEC 62443? A Guide to Industrial Cybersecurity
- 9 DFARS Compliance: A Guide for Defense Contractors
- 10 CMMC vs FedRAMP: What’s Different and Which One Applies to You
- 11 Automotive SPICE (ASPICE) 4.0: A Complete Guide
- 8. Systems Engineering
- Overview
- 1 What is Systems Engineering? A Guide for Modern Engineering Teams
- 2 How Do Engineers Collaborate? A Guide to Streamlined Teamwork and Innovation
- 3 The Systems Engineering Body of Knowledge (SEBoK)
- 4 What Is MBSE? Model-Based Systems Engineering Explained
- 5 Digital Engineering Between Government and Contractors
- 6 Digital Engineering Tools: The Key to Driving Innovation and Efficiency in Complex Systems
- 9. Automotive Development
- Overview
- 1 Understanding IATF 16949: A Quick Guide to Automotive Quality Management
- 2 What Is ISO 21434? Automotive Cybersecurity Engineering Explained
- 3 What Is ISO 26262? A Guide to Functional Safety in Automotive
- 4 What Is ASIL? A Guide to Automotive Safety Integrity Levels in ISO 26262
- 5 What Is SOTIF? A Guide to ISO 21448 for ADAS Safety
- 10. Medical Device & Life Sciences Development
- Overview
- 1 The Importance of Benefit-Risk Analysis in Medical Device Development
- 2 Software as a Medical Device: Revolutionizing Healthcare
- 3 What’s a Design History File, and How Are DHFs Used by Product Teams?
- 4 Navigating the Risks of Software of Unknown Pedigree (SOUP) in the Medical Device & Life Sciences Industry
- 5 What Is ISO 13485? A Guide to Medical Device Quality Management Systems
- 6 What You Need to Know: ANSI/AAMI SW96:2023 — Medical Device Security
- 7 ISO 13485 vs ISO 9001: Understanding the Differences and Synergies
- 8 What Is IEC 62304? A Guide to Medical Device Software
- 9 What Is a Device Master Record (DMR)? Definition and FDA Requirements
- 10 Failure Modes, Effects, and Diagnostic Analysis (FMEDA) for Medical Devices: What You Need to Know
- 11 Embracing the Future of Healthcare: Exploring the Internet of Medical Things (IoMT)
- 12 What Is General Safety and Performance Requirements (GSPR)? What You Need To Know
- 13 What Is IEC 62366? A Guide to Medical Device Usability Engineering
- 14 What Is the Quality Management System Regulation (QMSR)?
- 15 510(k) vs PMA: Differences in FDA Device Approval and Clearance
- 16 EU MDR Compliance Requirements and Timeline
- 11. Aerospace & Defense Development
- Overview
- 1 What is ITAR Compliance? What Engineering Teams Need to Know
- 2 What Is ARP4754A? A Complete Guide to Civil Aircraft and Systems Development Assurance
- 3 Understanding ARP4761A: Guidelines for System Safety Assessment in Aerospace
- 4 What Is DO-254? A Complete Guide to Airborne Hardware Design Assurance
- 5 What Is DO-178C? A Guide to Airborne Software Certification
- 12. Architecture, Engineering, and Construction (AEC industry) Development
- 13. Industrial Manufacturing & Machinery, Automation & Robotics, Consumer Electronics, and Energy
- 14. Semiconductor Development
- 15. AI in Product Development
- Overview
- 1 What Is AI in Product Development? A Complete 2026 Guide
- 2 AI Test Case Generation: A Complete Guide for Regulated QA Teams
- 3 Using AI to Write Software Requirements: What Works and What Doesn’t
- 4 What Is the Model Context Protocol (MCP) for Requirements Management?
- 5 AI for Systems Engineering: Benefits, Risks, and How to Start
- 6 How to Automate Requirements Management
- 7 Artificial Intelligence in Requirements Management
- 16. Risk Management
- 17. Product Development Terms and Definitions
EU MDR Compliance Requirements and Timeline
Nearly half of the certificates issued under the European Union Medical Device Regulation (EU MDR) take 13 to 18 months from application to issuance. For most Class III and implantable Class IIb legacy devices, the placement deadline is 31 December 2027, so one round of documentation deficiencies can consume the remaining margin.
The 2023 transition amendment remains in force, while changes to notified body capacity and portfolio decisions have altered the operating environment amid ongoing reform. EU MDR compliance now turns on fixed transition deadlines and technical documentation that reviewers can trace through the full evidence set. This guide covers the deadlines still ahead, the documentation gaps that can stall certification, and how to keep evidence traceable through the next review cycle.
What Is EU MDR Compliance?
EU MDR compliance means demonstrating that a medical device conforms to Regulation (EU) 2017/745 before placing it on the European market. MDR replaced the Medical Device Directive (MDD) and the Active Implantable Medical Devices Directive (AIMDD), extending mandatory conformity assessment to a wider range of devices. MDR applies to devices in Classes I, IIa, IIb, and III, plus certain non-medical products such as cosmetic contact lenses.
Meeting that standard also requires technical documentation demonstrating the General Safety and Performance Requirements (GSPRs): design, manufacture, labeling, risk management, verification and validation, and clinical evaluation. Manufacturers also need a quality management system (QMS), often built around International Organization for Standardization (ISO) 13485:2016, Quality management systems, Requirements for regulatory purposes, and Unique Device Identification (UDI) for supply chain traceability.
The technical documentation stays current over a device’s lifetime through post-market surveillance, alongside the risk management file and clinical evaluation, and the regulation formally interconnects these three processes so evidence from each must reconcile with the other two. Compliance programs often break down at that interconnection.
What Is the EU MDR Implementation Timeline?
Two deadlines matter most right now: 31 December 2027 for Class III and implantable Class IIb legacy devices, and 31 December 2028 for the remaining legacy classes. Both dates come from the amended transition framework in Regulation (EU) 2023/607, after two earlier timeline shifts, first for the pandemic and then for notified body capacity.
When Did EU MDR Take Effect?
The MDR entered into force in 2017, but COVID-19 disruptions across Member States, notified bodies, and manufacturers pushed its original application date back to 2021.
Under the original transition rules, devices with valid MDD or AIMDD certificates could remain on the market if they remained Directive-compliant and showed no significant changes to their design or intended purpose, with a limited transition period and a separate supply-chain window for legacy devices. Those dates proved unworkable as certification queues lengthened, prompting the 2023 amendment.
What Changed With the 2023 EU MDR Amendment?
The 2023 amendment extended transition periods for legacy devices and staggered deadlines by risk class, effective 20 March 2023. The table below summarizes the placement-on-market deadlines it established.
| Deadline | Devices Covered |
| 26 May 2026 (now passed) | Class III custom-made implantable devices |
| 31 December 2027 | Class III devices and Class IIb implantable devices, except sutures, staples, dental fillings, screws, wires, and similar listed components |
| 31 December 2028 | Class IIb non-implantable devices, Class IIa devices, and Class I devices up-classified under MDR, specifically sterile devices, devices with a measuring function, and reusable surgical instruments |
The extensions applied only to safe devices whose manufacturers took defined steps toward compliance, expressed as cumulative conditions:
- Notified body application: An MDR conformity assessment application had to be lodged by 26 May 2024.
- MDR-compliant QMS: An MDR-compliant QMS had to be in place by the same date.
- Written agreement: A signed agreement with a designated notified body was required by 26 September 2024.
- No significant changes: The device’s design and intended purpose must remain unchanged from the certified version.
- Valid certificate: The underlying MDD or AIMDD certificate had to be valid as of 20 March 2023.
Both administrative deadlines have passed, so manufacturers who missed them cannot claim the extended periods for affected legacy devices. The amendment also deleted the sell-off provision, so devices lawfully placed on the market during the transition can stay available without a time limit, as long as their expiration dates hold.
What EU MDR Deadlines Are Still Ahead?
The 31 December 2027 and 31 December 2028 deadlines remain fixed in current legislation, and teams should plan around them. The European Commission published a targeted reform proposal in December 2025, covering certificate validity, notified body assessment timelines, and regulatory cost burdens, but it remains under co-legislative review and leaves the transition deadlines unchanged.
The European Database on Medical Devices (EUDAMED) began mandatory use of its first four modules on 28 May 2026. A separate implementing regulation setting maximum timelines for notified body conformity assessment steps takes effect on 25 February 2027.
Why Do EU MDR Compliance Requirements Trip Up Manufacturers?
Certification pipeline limits and scattered documentation practices are common contributors to MDR compliance breakdowns, and gaps in awareness of the requirements themselves are usually a smaller factor.
How Notified Body Shortages Slow EU MDR Certification
The number of MDR-designated notified bodies remains constrained compared with the MDD era. By the end of 2025, Team-NB members had received roughly 26,000 MDR applications but issued about 14,000 MDR certificates, and combined MDR/IVDR certificate growth slowed to 45% year-over-year. The same survey found an 8% drop in notified bodies’ internal conformity-assessment staff and a 21% drop in subcontractor support, linked to a lighter workload.
The queue is only half the story: manufacturers also control certification time through the speed and quality of document revisions. A complete submission is a controllable lever, unlike the reviewer’s calendar, and manufacturers who understand notified body expectations avoid many of the deficiency letters that add months to review, including certificate withdrawals and portfolio reductions.
How Disconnected Documentation Undermines EU MDR Compliance
Submission quality remains a source of review delays, driven by incomplete submissions and technical documentation so poorly structured that reviewers cannot locate existing information. Both reflect evidence that lives in separate engineering and quality repositories that have never been connected.
Cross-document inconsistencies create review risk when individual evidence files appear acceptable on their own but contradict one another. Recurring patterns include:
- Unaddressed residual risks: Risks identified in the risk management file never appear in the clinical evaluation. The benefit-risk conclusion is therefore unsupported.
- Unanalyzed surveillance data: Post-market data is presented but never analyzed for trends or clinical impact, so it can’t feed risk or clinical conclusions.
Reviewers may also find divergent conclusions across the three documents, where small differences in findings defeat the consistent scientific position they expect.
These gaps compound because manufacturers must keep technical documentation current, and change-control gaps are consistently among the most common failure points. A file assembled by hand for the original submission has to be reassembled and re-reconciled at every audit.
How to Prepare for EU MDR Compliance
Close the gap between the evidence you have and the evidence Annex I demands. Keep that evidence connected after certification, when changes, surveillance findings, and audits continue.
Assess EU MDR Gaps Against Annex I Requirements
The GSPR checklist reaches topics that were less explicit under the MDD, including cybersecurity and nanomaterials, and tightens the risk language by defining reduction of risks “as far as possible” as reduction “without adversely affecting the benefit-risk ratio.” Clean MDD documentation can still carry MDR gaps. A workable gap assessment follows a consistent sequence:
- Applicability: For each GSPR clause, record whether it applies based on intended purpose and technological characteristics, with justification for every clause marked not applicable.
- Mapping: Match existing MDD Essential Requirements evidence to the corresponding GSPR sections, and note MDR-only topics with no MDD counterpart.
- Method of conformity: Identify the harmonized standard, Common Specification, or alternative method demonstrating conformity with each applicable requirement.
- Evidence location: Cross-reference where supporting documents are located, as required in Annex II within the technical documentation.
- Maintenance: Keep the checklist current as standards versions, evidence documents, and the design itself change.
Compliance with a harmonized standard creates a presumption of conformity with the corresponding requirement. European Standard (EN) ISO 14971:2019 with Amendment A11:2021, Medical devices – Application of risk management to medical devices, was added to the harmonized standards list in 2022 and fulfills the risk management requirement in Annex I Chapter I.
Trace EU MDR Requirements Through Risk to Verification
During technical documentation review, reviewers test requirements traceability by following a high-risk user need forward through design outputs and verification tests, then back to clinical validation. A single break in that chain can render the device non-compliant, so the expected structure links user needs mapping to design inputs, design outputs, risk controls, and verification evidence.
Each risk control needs separate proof of implementation and effectiveness. That distinction is a recurring weak point, alongside files where risk acceptability rests on a Risk Priority Number alone. Maintaining the chain in spreadsheets means every design change triggers a manual hunt for affected requirements, risks, and tests.
Monitor EU MDR Post-Market Surveillance Continuously
Certification sits at the midpoint of MDR compliance: manufacturers have ongoing obligations after approval, including a post-market surveillance system proportionate to risk class, as required by Article 83. Class IIa, IIb, and III devices require Periodic Safety Update Reports (PSURs) on schedules tied to their risk class.
Class III and implantable devices also require regular updates to the clinical evaluation and Post-Market Clinical Follow-up (PMCF) evaluation report, while vigilance reporting windows are tighter for serious public health threats, deaths, and unanticipated serious deterioration. Surveillance findings feed the risk management file, clinical evaluation, labeling, and corrective actions, and poorly targeted PMCF plans that don’t align with clinical evaluation data gaps lead to nonconformities during surveillance audits.
How Jama Connect Supports EU MDR Compliance
Jama Connect® is a requirements management and traceability platform built for regulated industries, including medical device development. MDR teams need to maintain traceability as the design changes, and Jama Connect supports that workflow with a pre-built medical device framework aligned to ISO 13485, the FDA Quality System Management Regulation under 21 CFR Part 820, International Electrotechnical Commission (IEC) 62304:2006+A1:2015, Medical device software – Software life cycle processes, and ISO 14971, plus export templates for the design history file and risk management documentation.
Requirements and risk analyses, such as Failure Modes and Effects Analysis (FMEA), stay linked to verification records as the design evolves. Review Center runs structured design and risk reviews with a full electronic audit trail, while Live Traceability™ connects requirements, risks, and verification records across the project. Suspect links flag downstream artifacts affected by upstream changes, and configurable exports help teams keep audit-ready technical documentation current.
Getting Started With EU MDR Compliance
Whatever the Brussels reform proposal delivers, the certification queue keeps rewarding the same behavior: a complete, well-reconciled file moves through review faster than one that comes back for revision. That advantage doesn’t depend on notified body capacity or transition-deadline politics, but on whether your team can show a reviewer the connections between requirements, risk, and verification evidence.
Teams can start a free 30-day trial of Jama Connect to see how a connected evidence trail holds up under review.
Frequently Asked Questions About EU MDR Compliance
What is the current deadline for EU MDR compliance?
Most legacy Class III devices and implantable Class IIb devices must hold MDR certification to be placed on the market after 31 December 2027. The exception is Class III custom-made implantable devices, whose transition deadline was 26 May 2026 and has already passed. Remaining legacy classes follow by 31 December 2028, and new devices have required MDR certification since 26 May 2021. Teams should confirm each legacy device met the 2024 conditions, then prioritize files using a compliance management approach based on certificate status, device risk, revenue exposure, and traceability gaps.
What happens if a device misses its EU MDR deadline?
An expired MDD or AIMDD certificate is not considered valid, and the device can no longer be placed on the EU market. Units already lawfully placed during the transition may continue to be made available without a time limit, because the sell-off restriction was deleted in 2023. Manufacturers should separate inventory already placed from units not yet placed, then decide whether to pursue MDR certification, pause EU placement, or retire the device, and control design changes throughout.
Does EU MDR compliance apply to legacy devices?
Yes, legacy status defers the certification date, but not the obligation, and every device sold in the EU must comply with MDR regulations. A legacy device that undergoes a significant change in design or intended purpose loses transition eligibility entirely, which makes change control during the transition window a compliance activity. Teams should treat each proposed change as a market-access decision and document whether it affects intended purpose, design, clinical claims, risk management, labeling, or supporting evidence.
How does EU MDR differ from the previous MDD?
The MDR is much larger and more detailed than the MDD, and the added volume is substantive. Clinical evidence expectations rose sharply, and UDI labeling, EUDAMED registration, and the Person Responsible for Regulatory Compliance role have no MDD equivalent. MDR also requires stronger traceability from claims and requirements to risks, verification tests, clinical evidence, and post-market surveillance data, coordinated through the same quality management system that supports certification. Jama Connect can help teams keep those relationships visible as evidence changes.
This article was authored by Tom Rish and published on July 31, 2026.
Book a Demo
See Jama Connect in Action!
Our Jama Connect experts are ready to guide you through a personalized demo, answer your questions, and show you how Jama Connect can help you identify risks, improve cross-team collaboration, and drive faster time to market.