EU MDR workflowChange control

EU MDR change assessment workflow

Review this workflow before releasing a medical device change that may affect design, software, intended purpose, manufacturing, QMS, clinical evidence, PMS, UDI data, classification, or the conformity assessment route.

The output is a documented release decision: what changed, whether the change is significant, what MDR files need updates, whether notified-body involvement is needed, and what evidence is retained.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

EU MDR change assessment should start from the proposed change, not from a generic compliance checklist. Capture the device and Basic UDI-DI affected, compare the change with the approved intended purpose, design, software, QMS, risk, clinical, PMS, and UDI baseline, then decide whether it is a and whether the device can proceed under the existing conformity position or needs review, certificate action, or a new MDR conformity assessment step.

Section 1

1. Capture the change and the approved baseline

Open one change record for the device family, model, Basic UDI-DI, certificate or declaration of conformity, software version, manufacturing site, supplier, label, IFU, risk file, clinical evaluation, PMS plan, and technical documentation affected by the proposal.

Compare the proposed change with the baseline that was assessed for conformity. For using MDR transitional provisions, Regulation (EU) 2023/607 keeps the no-significant-change condition focused on design and intended purpose, while MDR PMS, vigilance, and registration obligations still apply.

  • Device and design triggers: new model, changed critical specification, new sensor, energy source, alarm handling, packaging that affects sterility or stability, material/substance change, sterilisation change, or manufacturing/process change that affects conformity.
  • Software triggers: new medical feature, changed algorithm, major architecture change, new interoperability channel, operating-system change requiring device software modification, or user-interface change that changes how medical data is interpreted.
  • Intended-purpose triggers: new indication, new clinical condition, new patient or user population, new anatomical site, new deployment method, expanded claim, or promotional change that changes the use presented to users.
  • Quality and production triggers: QMS change, new or relocated site, supplier substitution, subcontractor change, process validation change, or corrective/preventive action that changes product or process controls.
Section 2

2. Decide whether the change is significant

Treat significance as a documented technical and regulatory judgement. MDCG 2020-3 Rev.1 is guidance for relying on the Article 120 transition; it is not the change-approval procedure for an MDR-certified device. For a legacy device, first ask whether the change concerns design or intended purpose, then apply the relevant intended-purpose, design, software, substance/material, and sterilisation questions. If any applicable branch reaches , do not release the changed device in reliance on that transition.

Do not treat every administrative or supplier change as significant. A manufacturer name, address, authorised-representative, site, supplier, material number, or process-validation change can be outside design or intended purpose when the device specifications and certified conditions remain controlled. The assessment still needs evidence and, where a agreement requires it, notification or prior approval.

  • Likely significant intended-purpose changes include expanded indications, new clinical conditions, new users or patient populations, new anatomical sites, or new delivery/deployment methods.
  • Likely significant design changes include altered operating principle, built-in control mechanism, energy source, alarm system, critical dimensions outside approved specifications, new sensors with a different working principle, or changes that adversely affect safety, performance, usability, or benefit-risk.
  • Likely significant software changes include algorithm changes that may alter diagnosis or therapy, closed-loop replacement of required user input, major architecture or operating-system changes, new medical functionality, new medical data presentation that changes interpretation, or new interoperability channels.
  • Likely significant material or sterilisation changes include certain patient-contacting implant or absorbable material changes, medicinal-substance changes, higher toxicological or biological risk, terminal sterilisation method changes, non-sterile to sterile labelling, or packaging changes that affect sterility, stability, microbiological state, or seal integrity.
Section 3

3. Recheck classification and conformity assessment route

After the significance screen, rerun classification for the changed device. Annex VIII classification is governed by intended purpose, combination use, software that drives or influences another device, duration of use, invasiveness, active-device function, and the highest applicable rule when multiple rules apply.

Then confirm whether the current conformity route still fits. Class I devices may generally follow manufacturer responsibility, subject to the limited role for sterile devices, measuring devices, and reusable surgical instruments. Class IIa, IIb, and III devices require notified-body involvement. For an MDR-certified device, follow the applicable Annex IX, X, or XI change provision and the notified-body contract: substantial QMS or device-range changes and changes that could affect an approved device's safety, performance, or conditions of use may require assessment, a certificate supplement, or a new conformity assessment.

  • Classification output: old class, changed class if any, Annex VIII rule(s), strictest applicable rule, and rationale for combination devices or software.
  • Conformity-route output: current certificate or DoC, applicable MDR annex route, whether the change is within certificate scope, and whether the applicable procedure requires notification, prior approval, a certificate supplement, or a new conformity assessment. Restriction, suspension, or withdrawal is a decision, not an outcome the manufacturer selects in the change record.
  • output: the submitted change package, notified-body decision or written confirmation, assessment report or supplementary report where applicable, and unresolved nonconformities or conditions.
Section 4

4. Update MDR evidence before release

Do not close the change assessment until the affected MDR files have been updated or a reason for no update is recorded. Annex II and Annex III technical documentation should stay aligned with the changed device, including design and manufacture information, GSPR evidence, benefit-risk analysis, risk management, verification and validation, PMS plan, and PMS outputs.

Clinical and PMS files need a separate impact check. MDR requires risk management and clinical evaluation to be aligned and regularly updated; PMCF is a continuous process that updates clinical evaluation and feeds risk management when new preventive or corrective measures are needed.

  • Technical documentation: device description, variants, accessories, Basic UDI-DI, labels and IFU, design/manufacturing data, GSPR checklist, standards/common specifications, verification and validation, software validation, biocompatibility, sterilisation, packaging, shelf-life, and stability evidence.
  • Risk and clinical evidence: hazard analysis, benefit-risk conclusion, clinical evaluation plan/report, equivalence rationale, claims, contraindications, warnings, PMCF plan, PMCF evaluation report, and any clinical investigation rationale affected by the change.
  • PMS and vigilance: PMS plan, PSUR or PMS report as applicable, complaint trend signals, CAPA links, field safety corrective action records, and documented rationale for whether the change affects existing safety or performance signals.
  • UDI and EUDAMED: Basic UDI-DI grouping, UDI-DI assignment, DoC references, product certificate references, EUDAMED device data, and whether a new UDI-DI is required because the change could cause misidentification or traceability ambiguity.
Recommended next step

Review an MDR change before release

Use Sorena to assemble the change baseline, significant-change rationale, classification impact, notified-body path, and updated MDR evidence pack before approving release.

Section 5

5. Retain the decision evidence

The release decision should be inspectable without reconstructing the assessment from meetings. Keep the change request, baseline comparison, significance rationale, classification memo, conformity-route decision, correspondence, updated file list, residual assumptions, and final release or escalation approval together.

For , retain the evidence showing why a change is not significant in design or intended purpose, because MDR transition eligibility depends on that condition. For MDR-certified devices, retain the decision path when the change affects an approved QMS, design, type, intended use, claims, or relevant incorporated substance.

  • Minimum decision record: change description, affected device identifiers, affected regulatory baseline, owner, reviewer, decision date, sources used, significant-change conclusion, classification conclusion, conformity-route conclusion, and release restriction if any.
  • Minimum evidence links: redlined label/IFU, software release notes, design input/output change, verification and validation summary, risk file update, clinical/PMS impact assessment, UDI/EUDAMED impact assessment, QMS/CAPA link, and or competent-authority correspondence where applicable.
  • Escalate instead of releasing when the assessment finds a significant design or intended-purpose change, a changed classification, a new route, insufficient clinical or verification evidence, unresolved PMS/vigilance impact, or missing UDI traceability decision.
Primary sources

References and citations

health.ec.europa.eu
Referenced sections
  • Supports the role of notified bodies when third-party conformity assessment is required for medical devices.
"third-party intervention is required"
health.ec.europa.eu
Referenced sections
  • Supports assessing whether device changes require new UDI-DI or Basic UDI-DI handling and aligning Basic UDI-DI references with certificates and regulatory documentation.
"misidentification of the device"
eur-lex.europa.eu
Referenced sections
  • Article 10(9) requires the manufacturer's quality management system to address procedures for managing modifications to devices covered by the system.
"procedures for management of modifications to the devices covered by the system"
eur-lex.europa.eu
Referenced sections
  • Supports checking legacy-device transition conditions, including the requirement that there are no significant changes in design and intended purpose while MDR PMS, vigilance, and registration requirements apply.
"no significant changes in the design and intended purpose"
Related guides

Explore more topics

Custom-made medical devices under the EU MDR | EU MDR FAQ
Concise EU MDR FAQ on custom-made device definition, mass-produced exclusions, Annex XIII statements, documentation, conformity assessment, PMS, vigilance, and records to retain.
EU MDR Annex II and III Technical Documentation
Build an MDR technical documentation index for Annex II device files and Annex III post-market surveillance evidence, including GSPR, risk, clinical, PMS, UDI, and EUDAMED records.
EU MDR Annex VIII Classification Guide
Classify EU MDR medical devices under Annex VIII using intended purpose, duration, invasiveness, active device and software rules, and conformity assessment impact.
EU MDR Annex XVI products without a medical purpose
EU MDR guide for Annex XVI products: listed groups, common specifications, binding reclassification rules, clinical evidence, notified-body route, transition conditions, UDI, EUDAMED, PMS, and vigilance.
EU MDR Applicability Test
Test whether a product, accessory, software function, or Annex XVI product falls under the EU Medical Device Regulation, and record the evidence for the next classification step.
EU MDR Checklist for Medical Device Compliance
Practical EU MDR checklist covering qualification, classification, conformity assessment, technical documentation, GSPR, clinical evidence, UDI, EUDAMED, PMS, vigilance, QMS, and legacy transition evidence.
EU MDR classification workflow
A concrete EU MDR classification workflow for intended purpose, device or accessory qualification, Annex VIII rule selection, Rule 11 software review, class outcome, and notified body impact.
EU MDR Clinical Evaluation Overview
EU MDR clinical evaluation overview covering Article 61, Annex XIV, clinical data sources, equivalence, PMCF, CER evidence, notified body review, GSPR, and benefit-risk support.
EU MDR Clinical Evaluation Report Template
A cited EU MDR clinical evaluation report template covering intended purpose, GSPR linkage, clinical data appraisal, equivalence limits, PMCF, conclusions, and reviewer signoff.
EU MDR clinical evidence guide
EU MDR guide to clinical evaluation, clinical investigations, equivalence, PMCF, GSPR support, technical documentation, and notified-body review.
EU MDR compliance obligations
EU MDR compliance guide for device qualification, classification, conformity assessment, QMS, technical documentation, UDI, EUDAMED, PMS, vigilance, and legacy transition controls.
EU MDR conformity route workflow
EU MDR workflow for classifying a device, choosing the conformity assessment route, preparing technical and QMS evidence, and reaching certificate, DoC, UDI, EUDAMED, and CE outputs.
EU MDR deadlines and compliance calendar
EU MDR calendar for application, conditional legacy-device transition, UDI carrier dates, mandatory EUDAMED modules, and recurring compliance reviews.
EU MDR Device Classification Guide
Classify an EU MDR medical device by intended purpose, Annex VIII duration, invasiveness, active-device and software rules, then document the conformity route impact.
EU MDR EUDAMED and UDI registration
cited MDR guide to Basic UDI-DI, UDI-DI, EUDAMED device registration, actor roles, labels, technical documentation, and UDI data governance.
EU MDR FAQ: qualification, evidence, UDI, and transition
Concise EU MDR FAQ covering device qualification, software classification, accessories, custom-made devices, clinical evidence, UDI, EUDAMED, notified bodies, significant changes, and legacy transition.
EU MDR Legacy Device Transition
EU MDR legacy-device guide to Article 120 eligibility, class-based end dates, certificate validity, significant changes, surveillance, and evidence.
EU MDR notified body route selection
Choose an EU MDR conformity assessment route by device class, Article 52 option, notified body designation scope, QMS readiness, technical documentation, clinical evidence, and certificate evidence.
EU MDR penalties and enforcement risk
EU MDR guide to Article 113 national penalties, authority measures, recalls, certificate action, and the evidence needed for a country-specific assessment.
EU MDR PMS and Vigilance Guide
EU MDR guide to post-market surveillance, PMCF updates, PMS reports, PSURs, serious incident reporting, FSCA/FSN handling, trend reporting, and evidence records.
EU MDR PMS and vigilance records
Cited EU MDR guide to PMS plans, PMS reports, PSURs, PMCF updates, serious incident and FSCA reporting, trend reporting, and EUDAMED evidence handling.
EU MDR PMS Plan Template for Medical Devices
A cited EU MDR post-market surveillance plan template covering device scope, PMS data sources, PMCF linkage, vigilance, trend reporting, PMSR or PSUR outputs, roles, cadence, and evidence records.
EU MDR QMS and technical file evidence map
Map EU MDR Article 10 QMS duties to Annex II and Annex III technical documentation, PMS, vigilance, UDI records, and notified-body review evidence.
EU MDR QMS requirements under Article 10
EU MDR QMS guide for Article 10 manufacturer controls covering regulatory strategy, design, risk, clinical evaluation, PMS, vigilance, UDI, suppliers, CAPA, and conformity records.
EU MDR qualification and borderline products
EU MDR qualification guide for medical purpose claims, accessories, software, Annex XVI products, and borderline routes to classification and conformity assessment.
EU MDR qualification workflow
A concrete EU MDR workflow for deciding whether a product is a medical device, accessory, Annex XVI product, IVD interface, medicinal-product interface, or non-MDR product before classification and conformity assessment.
EU MDR requirements checklist
Concrete EU MDR requirements for medical-device scope, classification, GSPR, conformity assessment, technical documentation, QMS, clinical evidence, UDI, EUDAMED, PMS, vigilance, and economic-operator records.
EU MDR Rule 11 software classification
Classify MDR medical device software under Rule 11 using intended purpose, diagnosis or therapy decision impact, physiological monitoring, conformity route, clinical evidence, and software-change records.
EU MDR significant changes FAQ: legacy-device transition and notified-body review
FAQ on MDR significant changes for legacy devices, including intended-purpose, design, software, material, sterilisation, clinical, QMS, notified-body, and evidence impacts.
EU MDR SSCP: Devices and Requirements
Decide whether an EU medical device needs an SSCP, see worked class IIa, IIb, and III examples, and check the required content, evidence, publication, and update controls.
EU MDR transition timeline and end dates
EU MDR chronology for 2021 application, 2023 amendments, 2024 eligibility milestones, and conditional 2026, 2027, and 2028 transition endpoints.
EU MDR UDI and EUDAMED registration guide
EU MDR guide to Basic UDI-DI, UDI-DI, UDI carriers, EUDAMED actor and device registration, change impacts, and evidence governance.
EU MDR vigilance reporting workflow
Concrete EU MDR vigilance workflow for incident intake, serious incident assessment, FSCA and FSN handling, trend reporting, EUDAMED caveats, CAPA, PMS, clinical evaluation updates, and records.
How should Basic UDI-DI and UDI-DI be assigned under the EU MDR? | EU MDR FAQ
EU MDR FAQ on Basic UDI-DI grouping, device and package UDI-DIs, UDI carriers, EUDAMED registration, change triggers, and required records.
MDR vs AI Act for medical-device software
Compare MDR and AI Act scope, high-risk classification, conformity assessment, evidence, monitoring, and timing for AI-enabled medical devices.
MDR vs EU Product Liability Directive
Compare MDR compliance evidence with EU product-liability claims, responsible parties, disclosure, presumptions, damage, and the December 2026 transition.
MDR vs GPSR: medical-device boundary checks
Compare MDR medical-device scope with general product-safety fallback questions for borderline, non-medical, and Annex XVI products.
MDR vs IVDR: medical devices and IVDs compared
Compare EU MDR and IVDR scope, classification, conformity routes, technical documentation, clinical or performance evidence, UDI, EUDAMED, PMS, and vigilance.
What should an EU MDR PMCF plan and report cover? | EU MDR FAQ
Under the EU MDR, PMCF is part of PMS and clinical evaluation. See what the plan, activities, report, updates, and retained evidence should cover.
What should manufacturers do when an EU MDR classification changes? | EU MDR FAQ
Concise EU MDR FAQ on classification changes, intended purpose, software, notified-body route impact, certificates, technical documentation, and retained evidence.
When can clinical equivalence be used under the EU MDR?
EU MDR FAQ on clinical equivalence, including technical, biological, and clinical characteristics, access to equivalent-device data, class III and implantable-device limits, clinical evaluation, PMCF, and retained evidence.
When do software or products make medical purpose claims under the EU MDR? | EU MDR FAQ
EU MDR FAQ on medical purpose claims, intended purpose evidence, software qualification, Annex XVI contrasts, and records to keep.
When is a PSUR required under the EU MDR and what should it contain? | EU MDR FAQ
EU MDR FAQ on PSUR scope, content, update cadence, PMS and PMCF links, notified-body handling, EUDAMED submission, and evidence to retain.
When is an accessory regulated under the EU MDR? | EU MDR FAQ
EU MDR FAQ on when an article is a medical device accessory, how intended purpose affects classification, and what evidence to keep.
When is software a medical device under the EU MDR?
EU MDR FAQ on medical device software qualification, Rule 11 and other classification rules, modules, evidence, software changes, UDI, and EUDAMED.
Which EUDAMED modules matter under the EU MDR? | EU MDR FAQ
EU MDR FAQ mapping EUDAMED modules to actor registration, UDI/device data, certificates, clinical investigations, vigilance/PMS, market surveillance, and practical records.