MDR technical documentation is the file that proves a medical device conforms to Regulation (EU) 2017/745, and its contents are not a matter of judgement: Article 10(4) requires every manufacturer of a device other than a custom-made device to draw up and keep up to date technical documentation that “shall include the elements set out in Annexes II and III”. Annex II lists six sections, from device description to product verification and validation; Annex III adds two more, the post-market surveillance plan and the reports it produces. Notified bodies assess the file against those eight parts, competent authorities can demand it at any time for at least ten years after the last device is placed on the market, and the person responsible for regulatory compliance is personally accountable for keeping it current. This guide walks through the eight parts as the consolidated text of 19 July 2026 sets them out, explains which of them the notified body samples and which it reads for every device, and sets out the six ways a file fails review.

What Article 10(4) requires of MDR technical documentation
The obligation is short and absolute. The documentation “shall be such as to allow the conformity of the device with the requirements of this Regulation to be assessed”, and Annex II opens by requiring it to be presented “in a clear, organised, readily searchable and unambiguous manner”. Two consequences follow. First, a file that contains the evidence but cannot be navigated fails the Annex II opening sentence before its content is read. Second, the structure is fixed by the Regulation, not by the manufacturer’s document-management system: a notified body reviewer will look for eight parts in the order the annexes give them, and a file organised around a company’s own headings costs review days. Article 10(8) then sets the retention period — at least 10 years after the last device covered by the EU declaration of conformity is placed on the market, and at least 15 years for implantable devices — and requires the manufacturer to provide the documentation “in its entirety or a summary thereof” on a competent authority’s request. Our guide to the EU MDR covers the Regulation as a whole.
The six sections of Annex II
| Annex II section | What it must contain | Where files fail |
|---|---|---|
| 1. Device description and specification | 1.1: trade name, intended purpose and users; Basic UDI-DI; patient population and indications; principles of operation; the rationale for qualification as a device; risk class with the Annex VIII rule applied; novel features; accessories; every configuration or variant; key functional elements with labelled drawings; raw materials in contact with the body; technical specifications. 1.2: previous generations and similar devices on the market | Variants listed in the sales catalogue but not in 1.1(i); classification stated without the rule; no similar-device overview |
| 2. Information to be supplied by the manufacturer | A complete set of labels — unit, sales and transport packaging — and the instructions for use, in the languages accepted where the device is sold | One language when the device ships to six Member States |
| 3. Design and manufacturing information | Design stages; complete manufacturing process information including validation, adjuvants, in-process monitoring and final testing — data “fully included”; every site, supplier and subcontractor where design or manufacturing is performed | Process validation referenced but not included; contract manufacturers missing from the site list |
| 4. General safety and performance requirements | The applicable GSPRs and why the rest do not apply; the method used for each; the harmonised standards, common specifications or other solutions applied; the precise identity of the controlled documents evidencing each, cross-referenced to their location in the file | A checklist of ticks without document identifiers; “not applicable” without a reason |
| 5. Benefit-risk analysis and risk management | The benefit-risk analysis under Annex I Sections 1 and 8; the solutions adopted and the results of risk management under Annex I Section 3 | A risk file with no traceability from hazard to control to verification |
| 6. Product verification and validation | 6.1: pre-clinical tests (biocompatibility, characterisation, electrical safety and EMC, software verification and validation, stability and shelf life, performance and safety) with protocols and analysis methods, or a rationale where no new testing was done; the clinical evaluation report, its updates and the clinical evaluation plan; the PMCF plan and evaluation report or a justification. 6.2: additional data for medicinal substances, tissues of human or animal origin, absorbed substances, CMR and endocrine disruptors, sterile devices, measuring function and connected devices | Summary results without protocols; software V&V that does not cover every hardware configuration; a PMCF “not applicable” with no justification |
Section 6 is where most MDR technical documentation review time goes, because it is where the evidence lives. Annex II is explicit that “detailed information regarding test design, complete test or study protocols, methods of data analysis” is required alongside the summaries, and that where no new testing was undertaken “the documentation shall incorporate a rationale for that decision”. The example the Regulation itself gives — biocompatibility tested on identical materials in a previous version legally on the market — is the shape a leverage argument has to take.
The two sections of Annex III
Annex III is the part of MDR technical documentation that did not exist under the Directives, and it is the part that keeps changing after certification. Section 1 is the post-market surveillance plan required by Article 84, and Annex III specifies both what it collects — serious incidents and field safety corrective actions, non-serious incidents and undesirable side-effects, trend data, literature and registers, user and distributor feedback, public information about similar devices — and what it must cover: a proactive collection process that allows comparison with similar products, methods to assess the data, indicators and threshold values for reassessing the benefit-risk analysis, complaint investigation methods, the Article 88 trend-reporting protocol including the statistical method and observation period, communication methods, references to the Article 83, 84 and 86 procedures, corrective-action procedures, traceability tools, and a PMCF plan or a justification for its absence.
Section 2 is the output: the periodic safety update report under Article 86 for class IIa, IIb and III devices, or the post-market surveillance report under Article 85 for class I. Article 86 fixes the cadence — class IIb and III at least annually, class IIa at least every two years — and states that the PSUR “shall be part of the technical documentation”. A file whose PSUR is two years old is a file that is out of date, and Article 10(4) requires it to be “kept up to date”. MDCG 2022-21, published December 2022, gives the PSUR template notified bodies now expect.
What the notified body assesses, and how often
| Class | Assessment of the technical documentation (Article 52) | Basis |
|---|---|---|
| Class III | Every device, Annex IX Section 4 (or Annex X type examination plus Annex XI) | Art 52(3) |
| Class IIb implantable | Every device from Delegated Regulation (EU) 2026/1359, except the listed well-established implantables (sutures, staples, dental fillings, screws, plates, catheters, dental implants and others) | Art 52(4), second subparagraph |
| Class IIb (other) | At least one representative device per generic device group, sampled under MDCG 2019-13 rev.1 (December 2024) | Art 52(4) |
| Class IIa | At least one representative device per category of devices; or Annexes II and III with Annex XI Section 10 or 18 | Art 52(6) |
| Class I sterile, measuring, reusable surgical | Notified body limited to sterility, metrology or reuse; the rest self-declared | Art 52(7) |
| Class I (other) | Self-declared on Annexes II and III; no notified body | Art 52(7) |
Sampling cuts both ways for MDR technical documentation. A class IIa or IIb manufacturer whose file was not sampled at initial certification still has to hold a complete Annex II and III file for every device, because the notified body samples further files during surveillance and the competent authority can request any of them under Article 10(8). “Not sampled yet” is the most common reason a class IIb file is found incomplete three years into a certificate. The notified body fee lists show technical documentation review as a time-based item, which is why file quality is the largest controllable cost in an MDR budget.
Six ways MDR technical documentation fails review
- The GSPR checklist has no document identifiers. Annex II Section 4(d) requires “the precise identity of the controlled documents” for each requirement, cross-referenced to their location. A column of ticks is a finding.
- Protocols are summarised, not included. Section 6.1(b) asks for complete protocols and analysis methods; a table of pass results is not evidence of the method.
- The clinical evaluation is a static document. Section 6.1(c) requires the report “and its updates” plus the plan; a CER dated before the PMCF data it should have absorbed contradicts Article 10(4).
- Sites are incomplete. Section 3(c) requires all sites including suppliers and subcontractors; a sterilisation subcontractor missing from the list is a classic finding.
- Annex III is a plan without outputs. A PMS plan with no PSUR or PMS report behind it, or a PSUR older than the Article 86 cadence.
- Labels and IFU are in one language. Section 2 requires the languages accepted in each Member State where the device is envisaged to be sold; Article 10(11) leaves that to each Member State.
Building MDR technical documentation so it survives
- Adopt the Annex II and III headings as the structure of the MDR technical documentation. Eight parts, numbered as the annexes number them, with a completeness matrix at the front listing every element and where it is.
- Write the GSPR matrix last, from the evidence. Each applicable requirement maps to a method, a standard and a named controlled document with a revision.
- Keep the risk file, the clinical evaluation and the PMS plan as living documents with a review trigger. Article 10(4)’s “keep up to date” is tested by the dates on the front pages.
- Record the classification rule and the qualification rationale in Section 1.1. Both are frequent notified body questions and both are required elements.
- Prepare for the summary. Article 10(8) allows a competent authority to ask for a summary; Annex II refers to “the summary thereof”. Maintain one.
The person responsible for regulatory compliance is, under Article 15(3)(b), responsible for ensuring the technical documentation “are drawn up and kept up-to-date”; the file’s currency is a named person’s duty, not a project’s.
Frequently asked questions
What must MDR technical documentation contain?
The elements of Annex II — device description and specification, information supplied by the manufacturer, design and manufacturing information, the GSPR demonstration, benefit-risk analysis and risk management, and product verification and validation — plus Annex III, the post-market surveillance plan and the PSUR or PMS report. Article 10(4) makes both annexes mandatory.
How long must it be kept?
At least 10 years after the last device covered by the declaration of conformity is placed on the market, and at least 15 years for implantable devices, under Article 10(8). It must be available to competent authorities throughout.
Does the notified body read every file?
For class III, and for class IIb implantables other than the well-established types listed in Article 52(4), yes. For other class IIb and class IIa devices it assesses at least one representative device per generic device group or category, sampled under MDCG 2019-13 rev.1, and samples further files during surveillance.
Is the PSUR part of the technical documentation?
Yes. Article 86 states that the PSUR shall be part of the technical documentation as specified in Annexes II and III, updated at least annually for class IIb and III and at least every two years for class IIa.
Do class I manufacturers need a technical file?
Yes. Article 52(7) requires class I manufacturers to draw up the technical documentation set out in Annexes II and III before issuing the EU declaration of conformity; no notified body reviews it unless the device is sterile, has a measuring function or is a reusable surgical instrument.
Where this leaves you
Treat MDR technical documentation as an eight-part file with a fixed structure and a named owner: build it on the Annex II and III headings, evidence every GSPR with a controlled document, include protocols rather than summaries, keep the clinical evaluation, risk file and PMS outputs on a review cadence, and hold a complete file for every device whether or not the notified body has sampled it yet.
References
- Regulation (EU) 2017/745, consolidated text of 19 July 2026 — Article 10(4) and (8), Article 52, Articles 84 to 86, Annex II and Annex III.
- MDCG guidance documents (European Commission) — MDCG 2019-13 rev.1 on sampling of technical documentation and MDCG 2022-21 on the PSUR.
More on the EU MDR
- MDR technical documentation — you are here
- EU MDR: Regulation (EU) 2017/745 explained
- PRRC: the Article 15 role
- MDR harmonised standards
- Notified body fees under the MDR
- EU MDR transition deadlines
The Technical Documentation Procedure, the six Annex II section templates, the Technical Documentation on Post-Market Surveillance template and the Technical Documentation Completeness Matrix are in the EU MDR Toolkit, or start with the free templates.