Glossary

Technical File (Technical Documentation) — EU MDR Annex II requirements

Back to glossary index

What it is

Technical File (Technical Documentation) is the complete, controlled evidence set that demonstrates a device’s conformity with Regulation (EU) 2017/745. It must follow Annex II (structure) and include post-market elements per Annex III. All devices placed on the EU/EEA market require it; Notified Bodies (NBs) review it where applicable, and manufacturers must keep it current throughout the lifecycle (MDR Art. 10(4), Art. 52, Annex II–III).

Annex II structureAnnex III PMSLiving QMS record

Regulatory framework

  • Legal basis: MDR Art. 10(4) (technical documentation), Art. 52 (conformity assessment), Annex II–III (content and PMS documentation), Annex I (GSPRs), Annex VIII (classification), Arts. 27–33 (UDI/EUDAMED).
  • Retention: Keep available to competent authorities for ≥10 years after the last device is placed on the market; ≥15 years for implantables (MDR Art. 10(8)).
  • NB involvement: Class I sterile/measuring, IIa, IIb, III typically require NB review per route (Annex IX–XI). Class I non-sterile/non-measuring may self-declare.

Annex II — core contents (at a glance)

  • Device description & specification: Intended purpose, variants/accessories, classification rationale, UDI basics, previous/similar generations (Annex II §1).
  • Information supplied: Labels/IFU per Annex I Ch. III, symbols, languages (Annex II §2).
  • Design & manufacturing: Design stages, manufacturing processes/sites, validations, key suppliers/subcontractors (Annex II §3).
  • GSPR evidence: Mapping table (methods, standards/common specifications) and objective evidence for each applicable requirement (Annex II §4; Annex I).
  • Risk & benefit–risk: ISO 14971-aligned files, residual risk justifications, risk-control linkage (Annex II §4).
  • Verification & validation: Bench/preclinical, biocompatibility, electrical safety/EMC, software lifecycle & cybersecurity, usability, sterilization/packaging/shelf life; clinical evidence (CER) as applicable (Annex II §6; Annex XIV; IEC/ISO where relevant).
  • Additional sections (as needed): Medicinal substances (MDR Art. 1(8)–(9)), animal/human tissue, CMR/ED substances, reprocessing of SUDs.

Annex III — PMS components

  • PMS plan: Data sources, methods, responsibilities, and escalation (MDR Art. 83; Annex III §1).
  • PMCF: Plan/report where needed, feeding the CER (Annex XIV Part B).
  • Reports: PMS Report (Class I) or PSUR (higher classes) with conclusions on benefit–risk and actions (MDR Art. 85–86).

Process — how to build a defensible file

  • 1) Define purpose & class: Write precise intended purpose/claims, users, settings; then apply Annex VIII to justify classification and assessment route.
  • 2) Map GSPRs: Create the GSPR matrix with clear “applicable/N/A” logic, standards/CS used, and objective evidence.
  • 3) Compile design & manufacturing: Capture design controls, drawings/specs, process validations, supplier controls, and site details.
  • 4) Verify & validate: Plan and execute testing; include software, cybersecurity, usability, sterilization, and packaging integrity where relevant.
  • 5) Clinical evidence: Produce CEP/CER (Annex XIV Part A); define PMCF or justify why not (Annex XIV Part B).
  • 6) Labeling & IFU: Align claims with evidence; ensure language control and UDI implementation.
  • 7) PMS (Annex III): Insert PMS plan, reporting cadence (PMS Report/PSUR), vigilance links, and CAPA integration.
  • 8) Control & maintain: Version under the QMS; update after changes, complaints, or new data; retain per Art. 10(8).

Common pitfalls

  • Weak or missing GSPR mapping; “N/A” without clear justification.
  • Claims in labels/IFU that outpace CER evidence or risk controls.
  • Incomplete manufacturing detail (process validation, supplier files, or sterilization rationale).
  • Software files that ignore lifecycle/cybersecurity (IEC 62304/IEC 81001-5-1/IMDRF) and usability (IEC 62366-1).
  • PMS/PSUR not feeding back into the CER, risk files, and labeling updates.

Quick checks

  • Every applicable Annex I GSPR is covered by objective evidence, with traceability to tests and standards.
  • Verification/validation spans safety, performance, usability, and—if applicable—software and sterilization.
  • CER supports all claims and populations; PMCF is planned or robustly justified.
  • Labels/IFU meet Annex I Ch. III and match risk controls and UDI.
  • PMS plan, PMS Report/PSUR, and vigilance links are current; retention meets Art. 10(8).

FAQ

Which devices need a Technical File?

All devices placed on the EU/EEA market require technical documentation per Annex II–III. Class I may self-declare; higher classes involve an NB per Annex IX–XI.

How detailed should the GSPR matrix be?

List every applicable Annex I requirement, the method/standard used, and the exact evidence location. Provide explicit rationale for each “N/A.”

Do software devices need extra sections?

Yes. Include software architecture, lifecycle (IEC 62304), cybersecurity (e.g., IEC 81001-5-1), SOUP/patching, and usability validation for critical tasks.

How long must I keep the file?

At least 10 years after the last device is placed on the market; 15 years for implantables (MDR Art. 10(8)).

What changes trigger an update or NB review?

Changes affecting intended purpose, safety/performance, risk controls, manufacturing, or labeling typically require file updates—and for many devices, prior NB assessment.