Regulatory Affairs

Regulatory affairs support for EU and U.S. MedTech.

CENIT supports medical-device, IVD, and SaMD teams when classification, route-to-market, evidence, technical documentation, or authority interaction needs to be structured before work moves forward.

Scope

Clarify the route before documentation expands.

CENIT helps define the intended use, market route, evidence gaps, and submission sequence before teams invest time in the wrong documentation path.

01 Route and claims

Intended purpose, indications, product configuration, market sequence, regulatory route, and claims boundaries.

02 Evidence and gaps

Existing technical, clinical, performance, risk, usability, cybersecurity, labeling, and QMS evidence mapped against the route.

03 Submission readiness

What must be prepared, remediated, sequenced, reviewed, or held before Notified Body or FDA interaction.

EU and U.S.

Regulatory paths need different evidence logic.

EU MDR/IVDR and U.S. FDA routes often use overlapping evidence, but the structure, terminology, timing, and review expectations are not identical.

European Union EU MDR / IVDR

Classification, conformity-assessment route, GSPR evidence mapping, technical documentation, PMS/PMCF planning, EUDAMED/UDI considerations, and Notified Body response support.

United States U.S. FDA

Product-code and regulation mapping, submission route assessment, 510(k)/De Novo planning, QMSR implications, labeling/UDI considerations, and FDA question-response support.

SaMD and digital health

Software evidence has to match the claim and risk.

For SaMD, AI-enabled functions, connected devices, and cybersecurity-sensitive products, CENIT helps align the regulatory route with software lifecycle documentation, risk controls, verification, usability, and security expectations.

01 Intended use and behavior

Regulatory position, software functions, user interaction, automation level, and claims that create review expectations.

02 Lifecycle evidence

Software architecture, risk controls, SOUP, verification, validation, release logic, and change-control boundaries.

03 Cybersecurity and usability

Security documentation, threat considerations, usability evidence, labeling, and post-market monitoring expectations.

Deliverables

Common regulatory outputs.

Outputs depend on the regulatory question, product stage, and market route. Common examples include:

01 Regulatory strategy memo

Market route, classification assumptions, claims boundaries, decision points, dependencies, and timing.

02 Evidence gap assessment

Prioritized gaps against MDR/IVDR, FDA submission expectations, QMSR, risk, usability, software, or cybersecurity needs.

03 Review-ready structure

Technical documentation or submission sections organized so reviewers can trace claims, risks, evidence, and responses.

Boundaries

Responsibilities that should be scoped separately.

Clear boundaries protect the project. Some work can be coordinated, but should not be implied unless it is explicitly included.

01 QMS ownership

Procedure writing, implementation, training, internal audit, and QMS ownership should be scoped separately.

02 Clinical execution

Clinical investigation operations, PMCF execution, statistics, and CRO management may require specialist partners.

03 Legal and named roles

Importer, distributor, legal representative, PRRC, and U.S. FDA Agent duties should be defined as separate role-based scope.

Working method

How a regulatory affairs engagement starts.

The first step is to define the regulatory question precisely enough to avoid unnecessary work and missed dependencies.

01 Scoping

Product, intended use, market, claims, current evidence, QMS state, deadline, and decision pressure.

02 Regulatory plan

Route, assumptions, owners, document needs, review sequence, and where external specialists may be required.

03 Execution support

Documentation, review, response preparation, authority interaction, handover, or ongoing regulatory support as agreed.

Next step

Clarify the route before the work becomes harder to unwind.

Bring the product type, intended market, claims, current evidence state, and the regulatory decision you need to make.