What technical documentation does EU MDR require?

MDR Annex II · Annex III · Article 10(4)

The short answer

MDR requires two technical documentation components: Annex II (main technical file) and Annex III (post-market surveillance documentation). There is no prescribed format or template, but the content is strictly defined. Documentation must be available to competent authorities at all times, and must be retained for at least 10 years (15 years for implantable devices) after the last device was placed on the market.

Annex II — Main Technical Documentation

SectionKey contents
1. Device description and specificationIntended purpose, indications, contraindications, UDI, variants, accessories, predecessor devices, generation of device
2. Information supplied by manufacturerLabel, IFU, promotional materials (Annex I Chapter III requirements)
3. Design and manufacturing informationDesign stages, manufacturing processes, materials, sterilisation, subcontractors
4. GSPR checklistGeneral Safety and Performance Requirements from Annex I — all 23 requirements addressed with evidence references
5. Benefit-risk analysis and risk managementISO 14971 risk management file, benefit-risk determination, residual risk acceptability
6. Verification and validationPre-clinical tests, software verification and validation, usability, biocompatibility, performance testing
7. Clinical evaluationCER per Annex XIV, clinical data summary, PMCF plan (or justification for no PMCF)

Annex III — Post-Market Surveillance Documentation

  • PMS Plan: How post-market data is collected, analysed, and actioned (required for all devices)
  • PSUR (Periodic Safety Update Report): Mandatory for Class IIa, IIb, and III; Class IIb/III annually, Class IIa at least every 2 years
  • PMS Report: Required for Class I devices; less detailed than PSUR
  • PMCF Plan: Plan for proactive clinical data collection post-market
  • PMCF Report: Results of PMCF activities; feeds into CER updates

The GSPR checklist explained

Annex I contains 23 General Safety and Performance Requirements. For each requirement, the technical documentation must state:

  • Whether the requirement applies to this device (and justification if not applicable)
  • How the requirement has been demonstrated to be met
  • Which harmonised standard(s) or CS (Common Specification) were used
  • Which evidence document in the technical file demonstrates compliance

The GSPR checklist is often the first document a Notified Body examiner reviews. Gaps here are a common trigger for follow-up questions and audit findings.

Common technical documentation gaps

  • GSPR requirements not linked to specific evidence: Stating "meets requirement" without referencing the actual test report or standard
  • Clinical Evaluation Report not current: CER must be updated regularly; a 3-year-old CER for a Class IIb device will be flagged
  • Risk management not integrated: Risk file exists in isolation without feeding into software requirements, GSPR, and clinical evaluation
  • Software documentation missing: IEC 62304 lifecycle records absent or not referenced in the technical file
  • Labelling non-compliant: Missing MDR-mandated symbols, missing UDI, IFU not updated for MDR requirements
  • PMS data not feeding back: PMS plan exists but complaint data, vigilance events, and literature surveillance are not informing benefit-risk updates

MDR technical documentation vs FDA Design History File

EU MDR (Annex II/III)FDA DHF (21 CFR 820.30)
StructureAnnex II sections 1–7 + Annex III PMSNo prescribed structure; design controls outputs
Clinical evaluationCER mandatory, continuous update required510(k)/PMA submission; less ongoing update requirement
Post-market componentAnnex III — PSUR/PMS Report part of tech docsMDR 803/806 reporting; separate from DHF
Retention10 years (15 years implantables)2 years after device discontinued, at minimum
Access requirementAvailable to competent authorities at all timesAvailable to FDA upon request

Frequently asked questions

How long must technical documentation be retained?

The Person Responsible for Regulatory Compliance (Article 15 MDR) is a named individual with documented qualifications who ensures MDR obligations are met. Required for all manufacturers; can be internal or external.

Can technical documentation be stored electronically?

Yes. Electronic documentation is acceptable provided it is accessible to competent authorities, has version control, and is protected from unauthorised changes. Document management system requirements are part of your QMS.

In which language must technical documentation be provided?

The Annex II/III technical file can be in any language agreed with the NB. However, the Declaration of Conformity must be in the official language(s) of the EU member state(s) where the device is sold. IFU language requirements depend on the target market(s).

Free MDR Classification Tool

Determine your device class in under 5 minutes.

Classify my device →