Regulatory primer
MDR
Regulation (EU) 2017/745 — Medical Device Regulation · European Union · In force since 26 May 2021
MDR is the EU's regulation of medical devices. It tightened classification rules, expanded the role of notified bodies, and introduced explicit obligations on post-market surveillance + clinical evaluation. For AI in healthcare, MDR's Annex VIII rule 11 classifies most clinical-decision-support software as Class IIa or higher — which routes it into EU AI Act Art. 6(1) high-risk classification.
What it is
MDR replaced the 1993 Medical Device Directive (MDD) + the 1990 Active Implantable Medical Device Directive (AIMDD). The change was structural: directive → regulation (directly applicable), strict reclassification of software, expanded notified-body involvement at every classification step, mandatory post-market surveillance + clinical evaluation reporting.
Software-as-a-Medical-Device (SaMD) was significantly re-classified. Under MDD, much medical software was Class I (self-certified). Under MDR Annex VIII rule 11, software intended to provide information used to take decisions for diagnostic or therapeutic purposes is Class IIa or higher — triggering notified-body conformity assessment, clinical evaluation, technical documentation per Annex II, and periodic safety update reports.
Enforcement is national: each member state designates a competent authority (e.g. BfArM in Germany, ANSM in France, MHRA in UK pre-Brexit). Notified bodies (designated by member states under MDR) perform conformity assessments. Post-market surveillance, incident reporting, and field safety corrective actions flow back through the competent authority.
Who's in scope
- Manufacturers placing medical devices on the EU market, regardless of establishment.
- Authorised representatives (EU-resident representatives of non-EU manufacturers).
- Importers + distributors of medical devices destined for the EU market.
- Notified bodies conducting conformity assessments.
- Software qualifying as a medical device under Art. 2(1) definitions + Annex VIII classification rules.
Key obligations
Art. 10 — manufacturer general obligations
Risk-management system across the device lifecycle (per ISO 14971). Quality-management system (ISO 13485 is the de facto standard). Technical documentation (Annex II). Conformity assessment per Annex IX-XI depending on class. UDI + registration. Post-market surveillance + clinical evaluation.
Annex VIII rule 11 — software classification
Software intended to provide information used to take decisions for diagnostic or therapeutic purposes is Class IIa unless decisions could cause serious deterioration of health (IIb) or could be life-threatening (III). Software intended for monitoring physiological processes is Class IIa unless intended for monitoring vital physiological parameters where alteration could result in immediate danger (IIb).
Annex I — General Safety + Performance Requirements (GSPRs)
Essential safety + performance requirements the device must meet. Risk-management, software-lifecycle processes (IEC 62304), cybersecurity (Annex I §17.2 for programmable systems), human factors / usability (IEC 62366), data integrity.
Art. 61 + Annex XIV — clinical evaluation
Manufacturers conduct + document clinical evaluation throughout the device lifecycle. For implantables + Class III: clinical investigation typically required (with narrow equivalence-based exceptions).
Art. 83 — post-market surveillance system
Manufacturers must plan + establish + document + implement + maintain + update a post-market surveillance system proportionate to the risk class. Output: PMS plan, post-market clinical follow-up plan, periodic safety update reports (PSURs) for Class IIa (every 2 years), IIb (annually), III (annually).
Art. 87-89 — vigilance + incident reporting
Manufacturers report to competent authorities: serious incidents, field safety corrective actions, trends in non-serious incidents that may justify action. Timelines: serious incident within 15 days, immediate threat to public health within 2 days, death/unanticipated serious deterioration within 10 days.
Timeline + applicability
- 26 May 2017Regulation entered into force.
- 26 May 2021Regulation became applicable (postponed by 1 year due to COVID).
- Through 2027/2028Phased transition periods for devices certified under MDD continue. Reg. (EU) 2023/607 extended some deadlines.
- 2 Aug 2027EU AI Act Art. 6(1) extended pathway applies — AI-incorporating MDR devices automatically high-risk under the AI Act.
What's still being worked out
Areas where the regulation's interpretation is genuinely unsettled. Vendor pages skip this; we don't. Your counsel is the right venue for definitive guidance on your deployment.
- Notified-body capacity — fewer designated NBs than under MDD; bottleneck for conformity assessment is well-documented.
- Where Annex VIII rule 11 'decision making for diagnosis or therapy' starts + 'general wellness software' stops. Software intended for lifestyle / wellness purposes is outside MDR but the boundary is fact-specific.
- Cybersecurity expectations under Annex I §17.2 — IEC 81001-5-1 + IMDRF cybersecurity guidance + MDCG 2019-16 inform practice, but interpretive divergence between NBs continues.
- AI / machine-learning specific guidance — MDCG 2019-11 on software qualification + classification is the foundational document; AI-specific MDR guidance remains under development.
- Interaction with EU AI Act — MDR sits in AI Act Annex I, so AI medical devices are simultaneously regulated by both. Concurrent obligations + which regulator leads on which issue are operationally complex.
Sectors most affected
Primary sources
Where Promethean fits
Promethean is not an MDR-classified medical device + does not replace your MDR conformity assessment. It contributes to the post-market surveillance (Art. 83) + technical documentation (Annex II) + cybersecurity-safeguards-under-Annex-I-§17.2 components. Per-decision L12 chain provides: PSUR-quality longitudinal data on system behaviour, change-management evidence (specHash transitions show software-update history), human-oversight evidence (reviewer-gate firings on consequential outputs), fallback-safety evidence (deterministic-default firings under adverse conditions). For Class IIa+ devices, the chain feeds the manufacturer's own PMS + PMCF activities.
What Promethean does NOT solve
- Conformity assessment + CE marking — that's notified-body work.
- Clinical evaluation + clinical investigation (Art. 61 + Annex XIV) — that's clinical-affairs responsibility.
- Quality-management system (ISO 13485 implementation) — that's the operator's QMS programme.
- Cybersecurity testing + vulnerability assessment — Annex I §17.2 expects but Promethean is the audit-trail layer, not the security-testing layer.
- Substantive software-lifecycle processes (IEC 62304) — that's product-engineering process.
FAQ
When is software a medical device under MDR?
Two criteria under Art. 2(1): (1) intended by the manufacturer for a medical purpose (diagnosis, prevention, monitoring, prediction, prognosis, treatment, alleviation of disease/injury; investigation/replacement/modification of anatomy/physiology; control of conception; cleaning/disinfection of devices); (2) the medical purpose is the principal intended action. General-purpose software used incidentally in healthcare contexts isn't a medical device. Wellness/lifestyle software outside the medical-purpose definition isn't a device.
What does Annex VIII rule 11 classify our CDS as?
Class IIa by default for software intended to provide information used to take decisions for diagnostic or therapeutic purposes. Class IIb when those decisions could cause serious deterioration of health. Class III when those decisions could be life-threatening. Class I only applies to a narrow subset (e.g. software intended for general physiological-parameter logging not used in decision-making).
How does MDR interact with EU AI Act?
AI-incorporating MDR-classified medical devices are automatically high-risk under AI Act Art. 6(1) + Annex I. Concurrent regulation. AI Act Art. 6(1) high-risk obligations apply alongside MDR conformity assessment. The Commission has signalled guidance to harmonise the conformity-assessment processes but operational integration is still being worked out by NBs + manufacturers. The Art. 6(1) extended applicability date (2 August 2027) gives industry transition time.
Does the FDA's SaMD framework matter for EU MDR?
Yes for transatlantic manufacturers. FDA's SaMD framework + the 2024 PCCP Final Guidance + the IMDRF SaMD definitions all inform global market practice. MDR + FDA SaMD aren't identical but use shared underlying concepts (clinical-decision-support, intended use, risk-based classification). Manufacturers placing devices in both markets typically maintain a unified technical file with jurisdiction-specific sections.
What does post-market surveillance under Art. 83 actually require?
A documented PMS system proportionate to risk class: a written PMS plan (Annex III), data collection from clinical experience + complaints + similar-device incidents + scientific literature, trend analysis, and periodic reporting via PSURs (Class IIa: every 2 years; Class IIb + III: annually). The substrate-side per-decision evidence is a meaningful input to the PMS plan's data-collection requirement, not a replacement for it.