Technical File (TF) and Quality Management System (QMS) under MDR/IVDR

...make it simple and effective!

What is it and who does it apply to?

The technical file (TF) is the set of documents proving that a medical device is safe and performs as claimed: description, design, risks, testing, clinical evaluation and labelling. The quality management system (QMS) is the organisation that ensures the device is manufactured and monitored consistently over time. CE marking requires both.

It applies to every medical device, from class I to class III, and to in vitro diagnostic devices (classes A to D). For class I devices that do not go through a notified body the file still exists: it is what backs the declaration of conformity signed by the manufacturer, and the competent authority may request it at any time.

The obligation lies with the manufacturer, including anyone who markets under their own brand a device made by someone else. Importers and distributors do not prepare the file, but they must verify that it exists and that the device they place on the market is correctly marked and documented; the authorised representative must have access to it.

What the regulation requires

Regulation (EU) 2017/745 (MDR) sets out the content of the technical documentation in its Annexes II and III: the first covers the device documentation (design, manufacturing, general safety and performance requirements, benefit-risk analysis, verification and validation) and the second covers post-market surveillance. Regulation (EU) 2017/746 (IVDR) follows the same structure for in vitro diagnostic devices.

Article 10 of the MDR lays down the general obligations of manufacturers, including maintaining a quality management system proportionate to the risk class and type of device. The harmonised standard for that system is EN ISO 13485, which is what notified bodies audit.

None of these documents is static: the clinical evaluation, risk management and surveillance plan must be kept up to date throughout the life of the device, and any significant change to the design or intended purpose requires them to be reviewed.

What we do at MeDev Consulting

Technical File (TF)

To obtain the CE marking for a medical device, it is essential to prepare a technical dossier, Technical File, containing detailed and updated information about the product or family of products that justifies a design and manufacturing consistent with the regulation plus a quality system (QMS) that justifies continuity over time.

From MeDev Consulting, we prepare complete TFs for presentation to Notified Bodies (NB).

Technical File Content

The TF must contain the necessary documents to comply with all regulatory requirements (MDR 2017/745):

1. Introduction
2. Product description and specifications
  • Intended use and mode of operation
  • Product identification and risk class
  • Novel features and accessories
  • Technical specifications
3. Information provided by the manufacturer
  • Packaging, labels and instructions for use
4. Design and manufacturing
  • Design stages
  • Manufacturing and validation processes and locations
  • Critical suppliers and subcontractors
5. Safety and performance requirements
  • Methods to demonstrate safety and performance
  • Directives, regulations and harmonized standards
6. Risk analysis and risk management
  • Benefit/risk analysis
  • Adopted solutions
7. Verification and validation
  • Preclinical and clinical data
  • Biocompatibility, electrical safety, EMC
  • Stability, shelf life, performance
  • Clinical evaluation and post-market clinical follow-up (PMCF)

Quality Management System (QMS)

The quality management system includes planning, controlling and improving those elements that influence customer satisfaction and the achievement of desired results.

To achieve CE marking, it is essential to develop and implement a standardizable quality system.

From MeDev Consulting, we design, implement and achieve certification under ISO 13485.

QMS Structure

Strategies

Define policies, objectives and guidelines for the achievement of quality and customer satisfaction aligned with desired results.

Processes

Determine, analyze and implement the required processes and procedures, with monitoring and control activities.

Resources

Define assignments of personnel, equipment and machinery necessary for production, work environment and financial resources.

Structure

Define responsibilities, authorities and communication flow within the organization.

Documents

Establish procedures, forms, records and documentation for the effective operation of processes.

Regulatory Requirement

Include specific regulatory requirements under MDR (EU) 2017/745 for medical devices.

Software as a medical device (SaMD) and IEC 62304

If your product is software (an app, an algorithm, the control module of a device), the technical file has chapters of its own: qualification and classification under MDR rule 11 and guidance MDCG 2019-11, the development life cycle under IEC 62304 (planning, requirements, architecture, verification, software risk management and maintenance) according to its safety class A, B or C, usability (IEC 62366-1) and cybersecurity (MDCG 2019-16).

At MeDev Consulting we qualify the software, determine its risk class and its IEC 62304 safety class, prepare the life-cycle documentation the notified body reviews, integrated into the technical file and the quality system, and validate third-party software (including production and quality-system software) in line with ISO 13485.

How we work

  1. 1

    Assessment

    We review what already exists (design, testing, quality) against what the MDR or IVDR requires and deliver a prioritised gap report.

  2. 2

    Documentation

    We write the technical documentation and the quality system procedures together with your team, without duplicating what is already done well.

  3. 3

    Internal audit

    We simulate the notified body review: an internal QMS audit and a cross-check of the file before submission.

  4. 4

    Notified body support

    We answer the questions and non-conformities raised during the assessment with you until the certificate is issued.

Frequently asked questions

Do I need ISO 13485 to obtain the CE marking for a class I device?

For a class I device without notified body involvement the ISO 13485 certificate is not required, but the MDR does require a quality management system. The standard is the most practical way to demonstrate it and makes the step up easier if the device moves to a higher class or adds functions that require a notified body.

How long does it take to prepare a technical file?

It depends on the risk class, on how mature the design documentation is and on whether the device needs its own clinical evaluation. After an initial assessment of what already exists we propose a firm schedule for your case.

What is the difference between a Technical File and a Design Dossier?

"Design Dossier" was the term used by the former MDD directive for class III devices. The MDR brings everything under the concept of technical documentation (Annexes II and III), with the same core requirements for every class and greater demands on clinical evaluation and post-market surveillance.

I already have ISO 9001: is that enough for the MDR?

It is a good foundation, but not enough. ISO 13485 adds medical-device-specific requirements such as risk management, traceability, design control and post-market surveillance, which the notified body will verify.

Can I keep a device on the market with an MDD (legacy) certificate while I prepare for the MDR?

Yes, within the transition periods of Regulation (EU) 2023/607 and subject to its conditions: a signed contract with a notified body, a quality management system in line with the MDR and no significant changes to the design or intended purpose.

Which documents will the notified body ask for in the first review?

The complete technical documentation of Annexes II and III, the quality manual and procedures, the clinical evaluation and the post-market surveillance plan. In our experience, most non-conformities come from the clinical evaluation and from risk management.

Can MeDev Consulting act as PRRC (person responsible for regulatory compliance)?

Yes. MeDev Consulting can take on the role of person responsible for regulatory compliance (PRRC) externally, an option the MDR provides for micro and small enterprises: they do not need to employ the PRRC, but they must have one permanently and continuously at their disposal.

My product is software: does it need a technical file and IEC 62304 compliance?

Yes. If it has a medical purpose it is a medical device (SaMD) and needs a technical file like any other. IEC 62304 is the harmonised standard for the software life cycle: depending on its safety class (A, B or C) it requires planning the development, documenting requirements and architecture, verifying, managing software risks and controlling maintenance. That documentation is part of the file.

Get your CE Marking with TF & QMS experts

We ensure the regulatory compliance of your medical devices with rigor and professionalism.