EU MDRApril 19, 2026

What Does the MDR Mean for Start-ups?

EU MDR 2017/745 · MDR Art. 15, 83–86 · Annex VIII Rule 11

In our first article we explained why Europe replaced the old Medical Device Directive (MDD) with the Medical Device Regulation (MDR, (EU) 2017/745). The reasons – scandals, technological leaps, the need for harmonisation – are understandable. So are the consequences: greater patient safety, more workload for manufacturers.

But does this equation work for every market participant? Not quite. For start-ups – young, often software-heavy companies with limited capital and little regulatory experience – the MDR is a particular challenge. This article takes an honest look at what that means in practice, where relief exists, and which strategies have proven effective.

1. The Uncomfortable Truth: MDR Changes the Start-up Calculus

Under the MDD, an agile team with a smart idea could reach the market in a manageable timeframe and with a manageable budget. Under the MDR, reality looks different:

  • Certification costs have often doubled or tripled depending on product class.
  • Notified Bodies are overloaded; waiting times of 12 to 24 months for an MDR procedure are not uncommon.
  • Clinical evidence can no longer be "compiled" from literature alone — it must be actively generated, including Post-Market Clinical Follow-up (PMCF).
  • The technical documentation under Annex II and III regularly runs to several thousand pages.

For founders this means: regulatory is not something to "do at the end" — it is a core component of product strategy from day one. Anyone who realises this only at the Seed or Series A round typically loses six to twelve months, and often the confidence of investors who do not see a clearly mapped regulatory path.

2. Rule 11: Why It Hits HealthTech and DTx Start-ups Hardest

The single biggest change for software-driven start-ups is contained in Rule 11 of Annex VIII of the MDR. In simplified terms, it states:

Rule 11 – Summary

Software that provides information used for diagnostic or therapeutic decisions is at least Class IIa. Where such decisions can lead to serious health consequences, the software moves to Class IIb or III.

The effect is dramatic: applications that were classified as Class I under the MDD (no Notified Body needed, self-declaration sufficient) are today almost universally Class IIa or higher. This means:

  • Mandatory involvement of a Notified Body
  • Formal clinical evaluation with robust data
  • A complete quality management system per ISO 13485
  • Ongoing post-market surveillance and regular safety reports (PSUR)

For a digital therapeutics app, a clinical decision-support tool, or an AI-based triage system this is the difference between "we are live in six months" and "we need 18 to 24 months and a seven-figure budget".

3. What Start-ups Must Build Operationally

Regardless of product class, there is a regulatory minimum stack that no one can avoid:

Building BlockStandard / RequirementWhy
Quality ManagementISO 13485Virtually required by the MDR
Risk ManagementISO 14971Mandatory across the entire lifecycle
Software LifecycleIEC 62304For any software as a medical device
UsabilityIEC 62366-1Usability engineering process
Clinical EvaluationMDR Annex XIV + MDCG guidelinesClinical evidence, continuously updated
Post-Market SurveillanceMDR Art. 83–86PSUR, vigilance, PMCF
PRRCMDR Art. 15Person responsible for regulatory compliance

4. Reliefs for Micro and Small Enterprises

The MDR acknowledges that a ten-person start-up cannot run the same regulatory apparatus as Siemens Healthineers. Specifically:

Article 15(2) MDR: Micro and small enterprises (as defined in EU Recommendation 2003/361/EC) do not need to employ the Person Responsible for Regulatory Compliance (PRRC) permanently within the company. The PRRC merely needs to be permanently and continuously available — which allows an external mandate.

This significantly reduces ongoing personnel costs. An external PRRC typically costs a fraction of a full-time position with the required qualifications.

In addition, there are national funding instruments:

  • Germany: programmes such as MedTech Pilot at BfArM, MedTech-Startup-Reallabor, funding via ZIM and EXIST
  • EU level: Horizon Europe, EIC Accelerator for medtech
  • Switzerland: Innosuisse projects for regulatory strategy development

5. What Works in Practice: A Start-up Playbook

1. Clarify classification early — and honestly.

The self-assessment "this is basically Class I" is the most expensive mistake a start-up can make. A sound classification under Annex VIII belongs before the first code commit.

2. Use scope design.

Some products can be kept in a lower class — or even outside the MDR definition of a medical device — through precise claim formulation. This is not a trick; it is legitimate regulatory strategy design.

3. Contact a Notified Body early.

Many start-ups wait too long. A preliminary meeting with a Notified Body before product development is complete often saves months — and prevents costly redesigns.

4. Build a lean but scalable QMS.

An ISO 13485 QMS does not need hundreds of SOPs. It must work and fit the company. Many successful start-ups begin with a digital-first QMS that grows with them.

5. Choose market entry order strategically.

If the EU route is too demanding: UK (UKCA), Switzerland, USA (FDA 510(k) or De Novo) can be faster as first markets. An early market entry elsewhere often funds the later MDR certification.

6. Plan clinical evidence from the start.

Clinical evaluation is not a document — it is a process. Systematically collecting real-world usage data, usability tests, and structured studies from version one onwards means no evidence gap later.

6. The Opportunity Within the Burden

The MDR is demanding — but it shifts the competitive landscape in favour of well-prepared start-ups:

  • Higher market entry barriers mean less accidental competition.
  • Investors now recognise MDR readiness as a quality signal.
  • Hospitals and insurers prefer certified products with robust evidence.
  • Structured development processes lead to better products: fewer bugs, better usability, more robust scaling.

In other words: the MDR is not the end of disruptive medtech start-ups. It is the end of unprepared medtech start-ups.

Conclusion: Plan Realistically, Structure Smartly, Start Early

For founders in the medtech space the key question is no longer "How do we work around the MDR?" — but "How do we integrate it into our company so that it does not slow us down, but differentiates us?".

That requires realistic scheduling, the right team, and the willingness to treat regulatory as a strategic asset, not a cost centre.

In the next article we dive deeper into the topic that start-ups most often underestimate: Rule 11 and the classification of medical software.

Determine Your Product Class Immediately

Use the Medairon MDR Classifier to classify your software under Annex VIII Rule 11 — free and in minutes.

Go to MDR Classifier