EU MDR deliverable
What Annex II and Annex III require
The technical documentation is the complete evidence package for a device under EU MDR 2017/745. Annex II sets out the documentation itself; Annex III sets out the post-market surveillance documentation that accompanies it. Both must be present, kept current, and structured so that a notified body reviewer can find each element without hunting.
The MDR is prescriptive about the contents, and the order in Annex II is the order reviewers work in. Departing from it does not breach the regulation, but it costs review time and invites questions that a conforming structure would never raise.
The Annex II sections we build
- Device description and specification — including variants, accessories, the Basic UDI-DI, intended purpose, intended users and patient population, and the principle of operation.
- Information supplied by the manufacturer — labels, packaging and instructions for use in the required languages, compliant with ISO 15223-1 symbols.
- Design and manufacturing information — design stages, manufacturing processes, sites, suppliers and subcontractors.
- General safety and performance requirements — the GSPR checklist, with the method of conformity and the precise evidence reference for every applicable requirement.
- Benefit-risk analysis and risk management — the risk management file to ISO 14971.
- Product verification and validation — pre-clinical and clinical data, biocompatibility to ISO 10993, electrical safety, EMC, software lifecycle to IEC 62304, usability to IEC 62366-1, sterilisation validation, shelf life and stability, and the clinical evaluation report.
The Annex III post-market file
Annex III is where manufacturers most often fall short, because it has to exist at the point of certification rather than being assembled later. It comprises the post-market surveillance plan, and then, depending on class, the PSUR or the PMS report, together with the PMCF plan and evaluation report.
Where technical files fail
- The GSPR checklist points at documents, not evidence. “See design file” is not a reference. A section, a version and a page are.
- Standards cited without a gap analysis. Claiming conformity to a harmonised standard while applying an older edition, or without addressing the clauses that do not apply, is a common deficiency.
- Labelling that does not match the file. The IFU claims an indication the clinical evaluation does not support, or the symbols are from a superseded edition of ISO 15223-1.
- Software treated lightly. Where software is a device or drives one, IEC 62304 lifecycle records and a software safety classification are expected, not a description.
- Versions out of step. The risk file at revision 6, the CER citing revision 4, the GSPR checklist citing revision 3. Reviewers check.
- No UDI framework. Basic UDI-DI assigned late, or inconsistent with the EUDAMED registration.
How the work runs
We begin with a structured gap assessment against Annex II and Annex III, producing a document-by-document status list: present and adequate, present but inadequate, or missing. That list is the project plan. We then write what is missing, remediate what is weak, and build the GSPR checklist last, because it is the index to everything else and can only be accurate once the evidence underneath it is settled.
For manufacturers moving from the MDD, expect the clinical evaluation, the post-market file and the GSPR mapping to carry most of the work. The design and manufacturing sections usually survive with updating.
Frequently asked questions
How long must technical documentation be kept?
At least ten years after the last device covered by it was placed on the market, and fifteen years for implantable devices.
Does a Class I device need technical documentation?
Yes. Annex II and III apply to all classes. Class I manufacturers self-declare, but the file must exist and be available to a competent authority on request.
Can we keep the file in our own structure?
You can, provided a reviewer can locate every Annex II element. In practice, a file that follows the Annex II order is reviewed faster and queried less.
What about the IVDR?
Annex II and III of IVDR 2017/746 follow the same architecture, with performance evaluation replacing clinical evaluation. We prepare both.
Who reviews it?
Your notified body, for anything above Class I. Choosing the body and preparing for its questions is part of the CE marking engagement.
