Home / Glossary
Glossary
Regulatory and technical abbreviations in medical device compliance.
EU Artificial Intelligence Act (Regulation (EU) 2024/1689)
EU regulation classifying AI systems by risk level (unacceptable / high / limited / minimal). AI used as a medical device or in medical diagnosis is typically classified as high-risk under Annex III and requires conformity assessment. Applies from August 2026.
Notified Body
Independent third-party body designated by an EU Member State to assess conformity of regulated products. Under MDR, Class IIa/IIb/III devices and most SaMD require NB assessment before CE marking. Examples: TÜV SÜD, BSI, SGS.
Competent Authority
National regulatory authority responsible for supervising medical devices on the market. Examples: BfArM (Germany), ANSM (France), MHRA (UK). CAs can order market withdrawals and conduct inspections.
Corrective and Preventive Action
Systematic process to identify and eliminate the root cause of non-conformities (corrective) and prevent potential future issues (preventive). A central element of any ISO 13485-compliant QMS. CAPA processes are closely scrutinised during Notified Body audits and must be documented with evidence of effectiveness.
Conformité Européenne
Marking indicating that a product meets EU regulatory requirements and can be placed on the EU market. For medical devices, CE marking requires a Declaration of Conformity plus, for most classes, a Notified Body certificate.
Clinical Evaluation Report
Document demonstrating that a medical device meets clinical safety and performance requirements based on clinical data. Mandatory for all CE-marked devices; must be regularly updated as part of Post-Market Surveillance.
European Database on Medical Devices
EU-wide database for registration of medical devices, economic operators, Notified Bodies, and vigilance data. Manufacturers must register devices and UDIs in EUDAMED. Mandatory registration for most device types is phased in from 2025.
Food and Drug Administration (USA)
US regulatory authority for medical devices. FDA clearance (510(k)) or approval (PMA) is required to market devices in the USA. Not equivalent to CE marking — separate submissions are required for each market.
Failure Mode and Effects Analysis
Systematic risk analysis method identifying potential failure modes of a system, their causes, and effects. Widely used in medical device risk management under ISO 14971. Results feed into the risk evaluation and risk control process.
IEC 62304 — Medical device software: Software life cycle processes
The primary standard for software lifecycle processes in medical devices. Defines three software safety classes (A/B/C) based on potential harm from software failure. Covers development planning, requirements, architecture, unit implementation, testing, maintenance, and SOUP management.
IEC 62366-1 — Medical devices: Usability engineering
Standard defining a process to analyse, specify, develop, and evaluate usability of medical devices as it relates to safety. Requires a Usability Engineering File documenting user research, task analysis, and summative evaluation (user testing with real users in simulated use).
IEC 82304-1 — Health software: General requirements for product safety
Specifically addresses standalone health software (SaMD) not embedded in hardware. Complements IEC 62304 by adding product-level safety requirements: intended use documentation, safety classification at product level, and requirements for the software product itself rather than just the development process.
ISO 13485 — Medical devices: Quality management systems
The primary QMS standard for medical device manufacturers. Specifies requirements for an organization to demonstrate its ability to provide medical devices that consistently meet regulatory and customer requirements. ISO 13485 certification is often a precondition for NB audits.
ISO 14971 — Medical devices: Application of risk management
The foundational risk management standard for all medical devices. Requires a risk management process throughout the device lifecycle: hazard identification, risk estimation, risk evaluation, risk control, and residual risk evaluation. A Risk Management File is mandatory for CE marking.
In Vitro Diagnostic Regulation (Regulation (EU) 2017/746)
EU regulation for in vitro diagnostic medical devices (IVDs) — devices used to examine specimens from the human body (blood tests, genetic tests, etc.). Sister regulation to MDR; applies the same CE marking framework but with IVD-specific classification rules.
Medical Device Coordination Group
Expert group established by the European Commission to provide guidance on MDR and IVDR implementation. MDCG guidance documents (e.g., MDCG 2019-11 on SaMD, MDCG 2019-16 on cybersecurity) are not legally binding but are considered authoritative by Notified Bodies and CAs.
EU Medical Device Regulation (Regulation (EU) 2017/745)
The primary EU regulation for medical devices, replacing the former MDD (93/42/EEC) and AIMDD. Fully applicable since May 2021. Covers device qualification, classification (Classes I–III), technical documentation, clinical evaluation, UDI, EUDAMED registration, and post-market obligations.
Medical Device Software
Any software that qualifies as a medical device or as an accessory to a medical device under MDR. Includes both embedded software (running on a physical device) and standalone software / SaMD. MDSW must comply with the full MDR framework.
Manufacturer Incident Report
Mandatory report submitted by a manufacturer to the competent authority (e.g. BfArM, ANSM) following a serious incident involving a medical device. Under MDR Art. 87, reporting deadlines are 15 days for serious public health threats, 30 days for serious incidents. The MIR includes product identification, incident description, affected patients, and initial root cause analysis.
Post-Market Clinical Follow-up
Ongoing clinical data collection after device market release to confirm safety and performance, detect emerging risks, and support the CER. PMCF is part of the PMS system and is mandatory under MDR. Results must be documented in a PMCF Plan and PMCF Report.
Post-Market Surveillance
Systematic process to collect and analyse real-world data on marketed devices throughout their lifetime. Required by MDR for all device classes. Outputs include the PSUR (periodic safety update) and PMCF reports. Findings must feed back into risk management and technical documentation.
Person Responsible for Regulatory Compliance
Mandatory role under MDR Art. 15. The PRRC ensures that conformity assessment is properly carried out, technical documentation is kept up to date, post-market obligations are fulfilled, and field safety corrective actions are taken when needed. Must have expertise in regulatory affairs.
Periodic Safety Update Report
Summary report required by MDR for Class IIa/IIb/III devices, consolidating the results of PMS activities. Must be submitted to the Notified Body at defined intervals (annually for IIb/III, every 2 years for IIa). The PSUR must include conclusions from the CER and PMCF.
Quality Management System
Documented system ensuring that devices are consistently designed, developed, and manufactured to meet regulatory and customer requirements. Mandatory under MDR and typically certified to ISO 13485. The QMS must cover all aspects of the device lifecycle including design controls, risk management, and post-market activities.
Software as a Medical Device
Software intended to be used for medical purposes without being part of a hardware medical device. Defined by IMDRF and adopted into EU MDR via Article 2(1) and MDCG 2019-11. Examples: AI diagnostic tools, clinical decision support software, mobile health apps with medical claims.
Software Bill of Materials
A structured inventory of all software components, libraries, and dependencies in a product, including version information and known vulnerabilities. Useful for SOUP management under IEC 62304 and for cybersecurity risk assessments.
Software of Unknown Provenance
Any pre-existing software component (open-source library, commercial off-the-shelf module, operating system) incorporated into a medical device software system without full development documentation. IEC 62304 §8 requires manufacturers to identify all SOUP items, document their version, verify their functional and performance requirements, and assess the risk of software failures.
Summary of Safety and Clinical Performance
Public-facing document required for Class III and implantable devices under MDR. Summarises the device's intended purpose, clinical evidence, and safety profile in lay terms. Must be validated by the Notified Body and published in EUDAMED.
Technical Documentation
The complete set of documents demonstrating that a medical device meets MDR requirements. Defined in MDR Annexes II and III. Key sections include: device description, design drawings, risk management file, clinical evaluation, labelling, and post-market surveillance plan.
Unique Device Identification
A system to identify and trace medical devices throughout the supply chain and healthcare. Consists of a Device Identifier (DI) for the device model and a Production Identifier (PI) for the specific unit/batch. UDIs must be registered in EUDAMED and placed on device labels.
Verification & Validation
Verification confirms that the software is built correctly (meets specifications). Validation confirms the right product was built (meets user needs and intended use). Both are required by IEC 62304 and ISO 13485. Evidence must be documented in the Technical Documentation.