Security standard

MDR

The MDR — Regulation (EU) 2017/745 — is the EU law governing the placing of medical devices on the European market. It also covers standalone medical software. Conformity ends with an EU declaration of conformity and the CE marking; devices above class I require a notified body certificate.

Start assessmentRead about the standard
55
controls in Guardiso
28
free-test questions
PL · EN
two languages

What is the MDR?

The MDR (Medical Device Regulation) is Regulation (EU) 2017/745 of the European Parliament and of the Council of 5 April 2017 on medical devices. As a regulation it applies directly in all Member States — without transposition into national law. Since 26 May 2021 it has replaced the MDD 93/42/EEC and AIMDD 90/385/EEC directives, significantly tightening the requirements: stronger clinical evidence, full device traceability (the UDI system), active post-market surveillance and greater transparency through the European EUDAMED database.

Unlike ISO standards, the MDR is law — we speak of regulatory conformity, not certification against a standard. Demonstrating conformity ends with drawing up an EU declaration of conformity and affixing the CE marking. For devices above class I, a notified body takes part in the conformity assessment — an independent organisation designated by a Member State that audits the manufacturer quality system and assesses the technical documentation, then issues a certificate.

Who is it for?

The MDR applies to anyone placing medical devices on the European Union market — manufacturers, authorised representatives of non-EU manufacturers, importers and distributors. Each of these roles has its own obligations set out in Articles 10-16 of the Regulation. A medical device is anything the manufacturer intends for a medical purpose: from plasters and syringes, through CT scanners, to implants.

Crucial for the digital sector: standalone software with a medical purpose (software as a medical device) is a fully fledged medical device. Rule 11 of Annex VIII classifies software providing information for diagnostic or therapeutic decisions into class IIa at minimum — which means mandatory notified body involvement. Applications supporting diagnosis, calculating doses, analysing medical images or monitoring patient physiological parameters are generally within the MDR scope, even if they run entirely in the cloud.

Device classes & conformity assessment routes

The MDR divides devices into four risk classes under the 22 rules of Annex VIII: class I (lowest risk), IIa, IIb and III (highest risk, for example life-sustaining implants). The class determines the conformity assessment route under Article 52 and Annexes IX-XI.

A manufacturer of a class I device (non-sterile, without a measuring function and not a reusable surgical instrument) carries out the conformity assessment alone: compiling the technical documentation, demonstrating conformity with the general safety and performance requirements (GSPR, Annex I) and issuing the declaration of conformity itself. Class IIa, IIb and III devices require a notified body certificate — most commonly via the Annex IX route: a quality management system audit combined with technical documentation assessment (for class III additionally a design dossier assessment for each device). In practice the foundation of this route is a quality system conforming to the harmonised standard EN ISO 13485.

Key manufacturer obligations

Article 10 of the MDR gathers the manufacturer obligations into a single catalogue. The most important pillars of conformity are:

  • A quality management system covering the entire device life cycle (in practice ISO 13485) and a risk management system (in practice ISO 14971).
  • Technical documentation per Annexes II and III — device description, design, verification and validation, the GSPR checklist and the post-market surveillance documentation.
  • A clinical evaluation (Article 61) concluded in a CER, updated throughout the life cycle, plus post-market clinical follow-up (PMCF).
  • A person responsible for regulatory compliance (PRRC, Article 15) with the required qualifications.
  • Post-market surveillance: a PMS plan and a PMS report or periodic safety update report (PSUR) for classes IIa and above.
  • Vigilance: reporting serious incidents within the 15/10/2-day deadlines and field safety corrective actions (FSCA).
  • The UDI system, registration of the operator (SRN number) and devices in EUDAMED, and traceability through the supply chain.

Deadlines & transition periods

The MDR has fully applied since 26 May 2021. For devices holding valid certificates under the old directives, amending Regulation (EU) 2023/607 of 20 March 2023 introduced a conditional extension of the transition periods: class III and implantable class IIb devices may stay on the market until 31 December 2027, and other class IIb, class IIa, and sterile or measuring class I devices until 31 December 2028.

The extension is not automatic: the manufacturer had to lodge a formal MDR conformity assessment application by 26 May 2024 and sign a written agreement with a notified body by 26 September 2024, and the device must not undergo significant changes in design or intended purpose. Regulation 2023/607 also removed the sell-off date, so devices lawfully placed on the market may continue to be made available. For new devices — including new medical software — there are no transition periods: full MDR conformity is required from day one.

How long does it take and what does it cost?

For a class I device the route to CE marking usually takes 3 to 9 months — the main cost is the team effort on the technical documentation, the clinical evaluation and the PMS system. For classes requiring a notified body the realistic horizon is 12-24 months: building an ISO 13485-conformant quality system, compiling the documentation and clinical evidence, and then the notified body process itself, whose duration also depends on capacity — the number of notified bodies designated under the MDR is limited and queues can be long.

The budget includes: notified body fees (quality system audit, technical documentation assessment, surveillance audits), possible studies and tests (laboratory, usability, clinical), regulatory consultant support and your own team time. For software companies the largest item is usually documentation and evidence: the software life cycle per IEC 62304, the risk management file per ISO 14971 and the clinical evaluation. Organising these processes in a tool instead of scattered files genuinely shortens the timeline and lowers the preparation cost.

How does Guardiso help?

Guardiso organises MDR conformity into one manageable system — from a readiness self-assessment, through a register of requirements and evidence, to maintaining post-market surveillance.

  • MDR requirements seeded as controls when you enable the framework — economic operators and the PRRC, GSPR, technical documentation, clinical evaluation, PMS, vigilance, UDI and EUDAMED — with implementation statuses and owners.
  • A free readiness self-assessment: questions mirroring the structure of the Regulation, with hints on what the notified body will demand.
  • Compliance evidence collected in one place — technical documentation, reports, recurring tasks (for example PSUR updates and PMS reviews) with reminders.
  • A risk register supporting device risk management in line with ISO 14971 — linked to the MDR requirements.
  • Cross-mapping to ISO 13485, ISO 14971, IEC 62304 and ISO 27001 — work done once counts towards the requirements of related frameworks.
  • An audit portal: controlled access to documentation and evidence for the auditor or notified body, without files being emailed around.
Official sources
01Select standard›02Complete the self assessment›03Close gaps in Guardiso
—
MDR readiness score
0/28 answered
The score updates live as you answer.

Other standards to assess

ISO 27001GlobalGDPREUNIS 2 (Polish KSC act)EU · PLSOC 2GlobalDORAEUTISAXAutomotiveISO 9001GlobalISO 42001 (AI)GlobalKRIPLPCI DSSGlobalNIST CSFUSANIST 800-53USAHIPAAUSACMMC 2.0USACyber EssentialsUKSOX ITGCUSABIO2NLEU AI ActEUISO 27701GlobalISO 22301GlobalISO 14001GlobalISO 45001GlobalISO 13485MedicalIEC 62304MedicalISO 14971MedicalDCB0129UKMiCAEUIEC 62443GlobalISO 21434Automotive
Browse all 30 standards