All guides
    EU RegulationUpdated: July 2026

    EU MDR Technical Documentation Requirements

    The EU Medical Device Regulation, Regulation (EU) 2017/745 (commonly abbreviated MDR), sets the requirements for placing medical devices on the European Union market. Central to those requirements is the technical documentation: the structured body of evidence that demonstrates a device conforms to the regulation. For any manufacturer, this file is the backbone of the CE marking process and the first thing a notified body or competent authority will ask to see.

    This guide is an evergreen reference to what MDR technical documentation must contain, how Annex II and Annex III fit together, and the wider framework (GSPR, UDI, EUDAMED, notified body assessment) that the documentation feeds into.

    What the MDR is

    The MDR entered into force in 2017 and applied from 26 May 2021, replacing the earlier Medical Devices Directive 93/42/EEC (MDD) and the Active Implantable Medical Devices Directive. Unlike a directive, a regulation applies directly and uniformly across all EU member states without national transposition, which is a deliberate move toward harmonised, stricter oversight.

    The MDR raised the bar in several areas that shape documentation directly: broader scope, a reinforced classification system, stronger clinical evidence expectations, mandatory Unique Device Identification (UDI), the EUDAMED database, and far more prescriptive rules on what the technical file must prove and how it must be maintained across the device life cycle.

    What technical documentation must contain

    MDR technical documentation is not a single document but a controlled, versioned dossier. At a high level it must let an assessor reconstruct, without ambiguity, what the device is, how it was designed and made, why it is safe and performs as intended, and how the manufacturer keeps watching it once on the market. The core building blocks are:

    • Device description and specification. What the device is, its intended purpose and intended users, variants and accessories, the classification and its rationale, and previous or similar generations of the device.
    • Information supplied by the manufacturer. Labels, packaging and the instructions for use, in the relevant EU languages.
    • Design and manufacturing information. The design stages applied to the device and the manufacturing processes and their validation, including identification of sites and suppliers.
    • General Safety and Performance Requirements (GSPR). Set out in Annex I, the GSPR are the essential requirements every device must meet. The documentation includes a GSPR checklist mapping each applicable requirement to the solution adopted and to the evidence (standards applied, test reports, records) that demonstrates conformity.
    • Benefit-risk analysis and risk management. The results of the risk management process, showing that residual risks are acceptable when weighed against the clinical benefit.
    • Product verification and validation. Pre-clinical and clinical data, bench testing, biocompatibility, electrical safety, software verification and validation, stability, and any device-specific testing.
    • Clinical evaluation. The clinical evaluation report and the underlying plan and data supporting the intended purpose and the benefit-risk determination.

    Every element must be traceable: each safety claim should point back to the requirement it satisfies and forward to the evidence that proves it. This is exactly the discipline that audit-ready traceability is designed to sustain across engineering changes.

    Annex II and Annex III

    The MDR splits the technical documentation into two annexes that work as a pair. Annex II covers the technical documentation itself, the design and pre-market evidence. Annex III covers the technical documentation on post-market surveillance (PMS): the plans and outputs that keep the device under review after it is placed on the market.

    AspectAnnex IIAnnex III
    FocusTechnical documentationPost-market surveillance documentation
    Life-cycle phaseDesign and pre-marketPost-market, throughout the device life
    Typical contentsDevice description, GSPR mapping, design and manufacturing information, benefit-risk and risk management, verification and validation, clinical evaluationPMS plan, periodic safety update report (PSUR) or PMS report depending on class, post-market clinical follow-up (PMCF), trend reporting
    What it provesThe device was correctly designed and is safe and effective at market entryThe manufacturer keeps monitoring real-world safety and performance and feeds findings back into the file

    The two annexes are not independent. Post-market findings under Annex III feed back into the risk management, clinical evaluation and GSPR conformity captured under Annex II, so the technical file is a living document rather than a one-time submission.

    UDI and EUDAMED

    The MDR introduced a system of Unique Device Identification (UDI) so that devices can be identified and traced through the supply chain. Each device carries a UDI made of a device identifier and a production identifier, and the manufacturer records the relevant data. UDI information is registered in EUDAMED, the European database on medical devices, which brings together registration of devices and economic operators, certificates, clinical investigations, vigilance and market surveillance. The technical documentation must be consistent with what is declared through UDI and EUDAMED.

    Notified body and conformity assessment by class

    The MDR classifies devices by risk into Class I, IIa, IIb and III (with sub-categories such as sterile or measuring Class I devices, and implantable considerations). The classification drives the conformity assessment route and, crucially, how much a notified body is involved:

    • Lower-risk Class I devices (non-sterile, non-measuring, non-reusable surgical) are generally self-declared by the manufacturer, who still compiles and holds the technical documentation.
    • Class Is/Im, IIa, IIb and III devices require the involvement of a notified body, whose scrutiny of the technical documentation and quality management system increases with the risk class. For the highest-risk devices, assessment is deepest and may involve additional expert consultation.

    In every case the manufacturer draws up an EU declaration of conformity and affixes the CE marking only once the applicable route is satisfied. This risk-tiered logic is familiar to any MedTech engineering team, where the depth of evidence scales with device class.

    How ISO 13485 and IEC 62304 relate

    The MDR is the legal requirement; standards are the recognised means of meeting it. ISO 13485 specifies a quality management system for medical devices and underpins the design controls, document control and record keeping that produce and maintain the technical documentation, but conformity to ISO 13485 alone does not equal MDR compliance. For software, IEC 62304 defines the software life cycle processes (development, maintenance, risk and configuration management) whose outputs become the software verification and validation evidence inside the technical file. Applying harmonised standards creates a presumption of conformity with the corresponding GSPR, which is why the GSPR checklist references the standards used.

    Keeping documentation current

    Under the MDR the technical documentation must be kept up to date throughout the device life cycle. Design changes, new clinical data, supplier or process changes, and post-market findings all have to be reflected in the file, with the links between requirements, design and evidence kept intact. When those links break, an audit turns into an archaeology exercise. Maintaining live traceability from requirement to design to verification, as covered in the related article on MedTech FDA & MDR traceability, is what keeps the file defensible between audits rather than reconstructed the week before one.

    FAQ

    What must MDR technical documentation contain?

    It must include the device description and specification, the information supplied by the manufacturer (labelling and instructions for use), design and manufacturing information, a mapping to the General Safety and Performance Requirements in Annex I, the benefit-risk analysis and risk management results, product verification and validation data, and the clinical evaluation. It also includes the post-market surveillance documentation set out in Annex III.

    What is the difference between Annex II and Annex III?

    Annex II covers the technical documentation itself: the design and pre-market evidence proving the device is safe and effective at market entry. Annex III covers the technical documentation on post-market surveillance: the plans and reports (PMS plan, PSUR or PMS report, post-market clinical follow-up, trend reporting) that keep the device under review once on the market. Findings under Annex III feed back into the Annex II file.

    Does ISO 13485 cover MDR technical documentation?

    ISO 13485 specifies a quality management system that underpins the design controls, document control and record keeping needed to produce and maintain the technical documentation, but conformity to ISO 13485 alone does not equal MDR compliance. The MDR is the legal requirement; ISO 13485 (and standards such as IEC 62304 for software) is a recognised means of meeting parts of it.

    When did the MDR replace the MDD?

    Regulation (EU) 2017/745 entered into force in 2017 and applied from 26 May 2021, replacing the Medical Devices Directive 93/42/EEC (MDD) and the Active Implantable Medical Devices Directive. As a regulation it applies directly across all EU member states without national transposition.

    How much is a notified body involved?

    It scales with the device's risk class. Lower-risk Class I devices are generally self-declared by the manufacturer, who still holds the technical documentation. Class Is/Im, IIa, IIb and III devices require a notified body, whose scrutiny of the technical documentation and quality management system increases with the class, being deepest for the highest-risk devices. In all cases the manufacturer issues an EU declaration of conformity and affixes the CE marking.

    Koddex keeps your MDR technical documentation live and traceable, from GSPR to verification evidence, so the file stays audit-ready between assessments rather than rebuilt before each one.

    Other guides