Independent learning for medical-device professionals
SearchCommentaryConsulting
LearningMTL-304 · USING STANDARDS FOR REGULATORY COMPLIANCE

Using Standards for EU MDR Compliance

How to turn the MDR's legal requirements into a justified standards strategy, connected engineering evidence and a reviewable technical-documentation structure.

What you will learn

By the end of this topic, you should be able to explain how standards support—but do not replace—the EU MDR; distinguish harmonised from other useful standards; select standards from the device's characteristics and applicable GSPRs; and maintain a traceable chain from legal requirement to technical evidence.

01

Standards are a route to evidence, not the law

Regulation (EU) 2017/745 establishes the binding requirements. Standards provide agreed technical methods, processes, terminology and acceptance frameworks that can help a manufacturer demonstrate conformity. Their use is generally voluntary, but a harmonised European standard whose reference is published in the Official Journal can provide a presumption of conformity for the requirements covered by that reference.

Legal requirement first

Begin with the applicable MDR article or Annex I GSPR. Use a standard only after establishing which part of that legal obligation it addresses, what it does not address and what device-specific evidence is still needed.

Presumption of conformity is limited by the published reference, the standard's scope, any restrictions and the clauses actually applied. A certificate or test report does not demonstrate conformity with unrelated MDR requirements.

02

Start with the device and its MDR obligations

Define the intended purpose, users, use environments, operating principle, patient-contacting materials, energy sources, software, connectivity, accessories, sterile state, measuring function and expected lifetime. Confirm classification and conformity-assessment route, then identify the applicable Annex I requirements and other MDR obligations.

  • Stabilise intended purpose and claims using MTL-102 — Intended Purpose, Users and Use Environments.
  • Record each applicable GSPR and justify requirements judged not applicable.
  • Identify device-specific common specifications, implementing acts and MDCG guidance.
  • Separate product, process, quality-system and lifecycle evidence.
  • Include interfaces, accessories and externally supplied elements in the scope.

MTL-301 — EU MDR and IVDR General Safety and Performance Requirements provides the legal-requirement foundation for this mapping.

03

Select standards by applicability, not familiarity

Create an initial longlist from the current OJEU harmonised-standards list, product-specific standards, recognised state of the art, notified-body expectations, applicable common specifications and the device's hazards and technologies. Then assess each candidate against its scope, exclusions, edition, amendments and relationship to the device.

Device characteristicWhat technology, material, function or process creates the need?
Legal requirementWhich MDR article or Annex I requirement applies?
StandardWhich clauses provide a suitable method or control?
ApplicabilityFull, partial, adapted or not applicable—with rationale
EvidencePlan, analysis, test, inspection, evaluation or controlled record
ConclusionWhat does the evidence demonstrate and what gaps remain?

A non-harmonised international standard may still represent useful state of the art. It simply does not carry the same legal effect as a correctly applied harmonised standard.

04

Build a requirement-to-evidence mapping

The standards strategy should be more than a list. For each applicable MDR requirement, record the selected standard and edition, relevant clauses, harmonisation status, planned method, acceptance criteria, evidence location, responsible owner and residual gap. Where no suitable standard exists, define a justified alternative method.

Requirement

Exact MDR or GSPR reference and the device-specific interpretation.

Method

Standard clause, common specification, guidance or justified internal method.

Application

Full or partial use, deviations, exclusions and configuration covered.

Evidence

Approved protocol, result, report, risk linkage and controlled version.

Keep the GSPR checklist, standards list, risk file, requirements traceability and technical-document index aligned. They are different views of the same conformity argument.

05

Typical standards families for MDR devices

The applicable set depends on the device. Common starting points include the following; always confirm the current edition and OJEU status rather than assuming every cited standard is harmonised.

Quality and risk

EN ISO 13485 for the quality system and EN ISO 14971 for lifecycle risk management.

Electrical and software

IEC 60601 series, IEC 62304, IEC 81001-5-1 and relevant collateral, particular or cybersecurity standards.

Usability and information

IEC 62366-1, ISO 20417 and ISO 15223-1, supported by device-specific labelling requirements.

Biological and sterile barriers

ISO 10993 series, ISO 11607 series and standards for sterilisation method, microbiological control and packaging validation.

Product-specific performance

Standards for injectors, implants, catheters, active devices, software or other technologies as applicable.

Clinical and lifecycle evidence

Standards and guidance supporting clinical investigation, clinical evaluation, PMS and PMCF.

06

Example: an electrically powered infusion device

An infusion device may need ISO 13485 and ISO 14971 across the development system; IEC 60601-1 and applicable collateral and particular standards for basic safety and essential performance; IEC 62304 for software; IEC 62366-1 for usability; IEC 81001-5-1 and other state-of-the-art methods for cybersecurity; ISO 10993 where patient-contacting materials are present; and packaging, transport and labelling standards.

The mapping must remain requirement-led. For example, IEC 60601 evidence may support electrical, mechanical and essential-performance aspects of Annex I, but it does not replace clinical evaluation, biological evaluation, software lifecycle evidence, usability engineering, risk management or the manufacturer's overall GSPR conclusion.

Use MTL-117 — Electrical Safety and Electromagnetic Compatibility and MTL-313 — IEC 60601 Electrical Safety and EMC for the connected engineering work.

07

Place standards evidence inside the technical documentation

The technical documentation should show why the standards set is appropriate and where its conclusions are substantiated. Test reports need an identifiable sample, configuration, method, acceptance criteria, deviations and conclusion. Process standards need device-specific records demonstrating their application—not merely a procedure claiming compliance.

  • Controlled standards-applicability assessment and standards list.
  • GSPR matrix linking requirements, standards, methods and evidence.
  • Plans and reports for risk, usability, software, biological, electrical and clinical work.
  • Traceability from risk controls and design inputs to verification and validation.
  • Assessment of deviations, partial application and residual gaps.
  • Declaration of Conformity citing the standards and other specifications actually applied.

MTL-113 — Design Controls and Technical Documentation explains how these records form a connected evidence chain.

08

Maintain the standards strategy throughout the lifecycle

Monitor new and amended OJEU publications, revised standards, transition dates, corrigenda, common specifications and relevant guidance. Assess changes against the marketed device, open projects, test methods, supplier evidence, risk conclusions and planned submissions.

Do not automatically retest whenever a new edition appears. Perform a documented gap assessment, determine whether the change affects safety, performance or state of the art, and plan proportionate action. Feed post-market information and design changes back into the applicability assessment.

09

Common misconceptions

“Using a harmonised standard guarantees MDR compliance.”

No. It can provide limited presumption of conformity for covered requirements; the manufacturer remains responsible for the whole device and all applicable obligations.

“Only harmonised standards may be used.”

No. Other standards and justified methods may represent suitable state of the art, but their contribution must be explained without claiming presumption of conformity.

“A test-house pass closes the requirement.”

Only if the correct device configuration, edition, clauses, acceptance criteria and unresolved deviations are connected to the applicable requirement and risk conclusions.

“The standards list can be completed at submission.”

Late selection creates avoidable redesign and evidence gaps. Standards influence architecture, inputs, risk controls, suppliers and verification from the beginning.

10

Practical checklist

  • Define the device, claims, classification and conformity-assessment route.
  • Create and approve the device-specific GSPR applicability matrix.
  • Check the current OJEU list and each candidate standard's scope and restrictions.
  • Add necessary non-harmonised and product-specific standards with rationale.
  • Map clauses to requirements, risks, methods, evidence and owners.
  • Resolve gaps and deviations explicitly.
  • Verify that reports identify the tested configuration and controlled standard edition.
  • Review the standards strategy at design gates and before the Declaration of Conformity.
  • Monitor standards and regulatory changes after release.
KEY TAKEAWAYS

Use standards to construct a conformity argument

  1. The MDR and applicable GSPRs define the obligations.
  2. Harmonised standards may provide limited presumption of conformity; their use remains generally voluntary.
  3. Standards selection must follow the device's intended purpose, risks and technology.
  4. A standards list needs clause-level mapping to methods, evidence and gaps.
  5. Non-harmonised standards can still provide valuable state-of-the-art methods.
  6. The strategy must be maintained as standards, devices and post-market knowledge change.
REFERENCES

Authoritative external references