- Author
- MDRpilot Editorial Team
- Reviewer
- Independent regulatory review not yet assigned
- Last updated
- Applies to
- EU MDR 2017/745 · ISO 13485:2016
Who needs technical documentation
Every manufacturer placing a device on the EU market, regardless of class. For Class I self-certified devices the manufacturer keeps the documentation available for authorities. For devices that require a notified body, the notified body reviews it. Under Annex IX, notified bodies assess the technical documentation of every Class III and Class IIb implantable device (with limited exceptions), and of a representative sample of other devices: per category of devices for Class IIa and per generic device group for other Class IIb devices.
Structure at a glance
A section-by-section explanation is in the article on Annex II and Annex III.
| Part | Content |
|---|---|
| Annex II, Section 1 | Device description and specification, including variants and accessories |
| Annex II, Section 2 | Information supplied by the manufacturer: label and IFU |
| Annex II, Section 3 | Design and manufacturing information |
| Annex II, Section 4 | General Safety and Performance Requirements |
| Annex II, Section 5 | Benefit-risk analysis and risk management |
| Annex II, Section 6 | Product verification and validation, including clinical evaluation |
| Annex III | PMS plan and PSUR or PMS report |
How the technical documentation connects to the QMS
The technical documentation is an output of the quality management system. Design and development controls (ISO 13485 clause 7.3) produce the design inputs, verification and validation records. Purchasing controls produce supplier information. Feedback, complaints and CAPA produce the post-market data. When a notified body audits the QMS, it follows these links into the technical documentation, and vice versa.
ISO 13485 clause 4.2.3 also requires a medical device file for each device type or family. In practice most manufacturers manage the MDR technical documentation and the medical device file as one structured set.
Keeping it current
- Design changes: assess whether the change is significant, update the affected sections and inform the notified body where required.
- Standards: when a harmonised standard is revised, assess the gap and update the GSPR checklist and test evidence.
- Post-market data: PMS findings feed the risk file, the clinical evaluation and the PSUR or PMS report.
- Regulatory changes: new MDCG guidance or common specifications may change expectations.
Common mistakes
- Device description, IFU and CER use different wording for the intended purpose.
- Evidence is referenced by file name but not held under document control.
- Risk controls are listed without verification evidence.
- The GSPR checklist lists standards that are not applied in the test reports.
- The PMS plan is generic and has no device-specific indicators.
How MDRpilot supports this
MDRpilot structures the technical documentation per product along Annexes II and III, draws the device description from one record, links evidence to GSPR rows and risk controls with user confirmation, flags documents when product data changes, and exports the file as DOCX, PDF or ZIP. It does not decide whether evidence is sufficient; that remains with your team and your notified body.
References
- Regulation (EU) 2017/745 on medical devices (MDR) — EUR-Lex, Publications Office of the European Union.
- ISO 13485:2016 Medical devices — Quality management systems — Requirements for regulatory purposes — International Organization for Standardization.
- Guidance: MDCG endorsed documents and other guidance — European Commission.
Always check the consolidated text of the regulation and the current version of each guidance document before relying on it.
This guide is general information about the regulation and standards named above. It is not legal or regulatory advice for a specific device.
MDRpilot is documentation and workflow software. It is not a medical device, not a notified body and not a regulatory authority. It does not certify devices or guarantee compliance; AI-generated drafts must be reviewed and approved by qualified people in the manufacturer's organisation.
