How to Structure a Medical Device Technical File

A medical device technical file is a concise set of documents created by a manufacturer to explain the performance and safety of a particular Medical Device in a clear, well-organized, easily searchable, and unambiguous manner. In order to prove compliance with the general safety and performance criteria of the legislation, the manufacturer must have - and keep up-to-date - this technical documentation, regardless of  medical device class.
Hero image illustrating the structure of a medical device technical file under the EU MDR, showing the key documentation required for CE marking, including device description, General Safety and Performance Requirements (GSPRs), Risk Management File, verification and validation, Clinical Evaluation, Biological Evaluation and Post-Market Surveillance in accordance with Regulation (EU) 2017/745.

Updated: 24th June 2026

Reviewed by: David Small BSc (Hons), MSc, MTOPRA (Founder & CEO)

What is a technical file for a medical device?

Every medical device manufacturer placing products on the European market must maintain technical documentation demonstrating that their device is safe, performs as intended and complies with Regulation (EU) 2017/745 (EU MDR). Commonly referred to as the technical file, this documentation forms the foundation of the conformity assessment process and is one of the first documents reviewed by a Notified Body when assessing a device for CE marking.

A well-structured technical file is far more than a collection of reports and certificates. It provides a clear, organised and traceable record of how a medical device was designed, developed, verified and validated, demonstrating that the manufacturer has met the applicable General Safety and Performance Requirements (GSPRs) and has implemented appropriate risk management, clinical evaluation and post-market surveillance processes.

Under the EU MDR, every manufacturer must establish, maintain and continually update technical documentation appropriate to the device classification and associated risks. Whether your device is a self-declared Class I product or a high-risk Class III implant, the technical file must remain current throughout the entire product lifecycle and be made available to Competent Authorities or your Notified Body upon request.

This article explains how to structure a medical device technical file in accordance with Annex II and Annex III of the EU MDR, outlining the key documentation expected within each section and providing practical guidance to help manufacturers prepare technical documentation that is both compliant and audit-ready.

Does a Medical Device Technical File Require Notified Body Certification?

All devices which are Class I(s), Class I(m), Class I(r), Class IIa, Class IIb, or Class III require certification by a Notified Body.

A Notified Body (NB) must audit the Technical File to gain certification. 

Every medical device placed on the European market under the EU MDR must be supported by compliant technical documentation. However, not every technical file is reviewed by a Notified Body.

For many Class I medical devices, manufacturers can self-declare conformity without undergoing routine Notified Body assessment. However, Class Is (sterile), Class Im (measuring) and Class Ir (reusable surgical instruments) require Notified Body involvement for the aspects relating to sterility, measurement or reusability. Most Class IIa, Class IIb and Class III medical devices require a Notified Body to review the manufacturer’s Quality Management System and technical documentation before CE marking can be granted.

Regardless of device classification, manufacturers are legally required to establish, maintain and keep their technical documentation up to date throughout the product lifecycle. The technical file must be made available to Competent Authorities and, where applicable, to the Notified Body during conformity assessment or surveillance activities.

A well-organised technical file significantly improves the efficiency of regulatory reviews. Documentation should be clearly structured, version controlled and supported by objective evidence demonstrating compliance with the applicable General Safety and Performance Requirements (GSPRs). Cross-referencing related documents, such as the Risk Management File, Clinical Evaluation Report and verification and validation reports, allows reviewers to efficiently assess conformity.

For manufacturers located outside the European Union, the technical documentation must also be accessible to their appointed EU Authorised Representative, who may be required to provide information to Competent Authorities in accordance with the requirements of Regulation (EU) 2017/745.

What Should Be Included in a Medical Device Technical File?

The structure of a medical device technical file is defined primarily by Annex II of Regulation (EU) 2017/745, with Annex III specifying the post-market surveillance documentation that must also be maintained. Together, these annexes ensure manufacturers can demonstrate that their device is safe, performs as intended and continues to comply throughout its lifecycle.

A well-organised technical file should allow a Competent Authority or Notified Body to quickly locate the evidence supporting each aspect of the device’s design, manufacture, verification and ongoing performance. Rather than being a collection of disconnected documents, the technical file should present a logical, traceable record of compliance.

The table below summarises the principal sections typically included within an EU MDR technical file.

Technical File SectionPurposeTypical Documents
1. Device Description & SpecificationDefines the device, intended purpose and key characteristics.Device description, intended purpose, intended user, indications, contraindications, UDI-DI, device variants, technical specifications, accessories.
2. Information Supplied by the ManufacturerDemonstrates that users receive the information necessary to use the device safely.Labels, Instructions for Use (IFU), packaging artwork, symbols, marketing claims (where applicable).
3. Design & Manufacturing InformationExplains how the device has been designed, manufactured and controlled.Design drawings, manufacturing processes, design specifications, Bill of Materials, supplier information, manufacturing sites.
4. General Safety & Performance Requirements (GSPR)Demonstrates compliance with Annex I of the EU MDR.GSPR Checklist, applicable harmonised standards, objective evidence supporting each requirement.
5. Risk ManagementShows how risks have been identified, evaluated, controlled and monitored.Risk Management Plan, Risk Analysis, Risk Evaluation, Risk-Benefit Analysis, Risk Management Report (ISO 14971).
6. Verification & ValidationProvides evidence that the device performs safely and as intended.Verification testing, validation reports, Biological Evaluation, Clinical Evaluation, software validation, electrical safety testing, usability engineering, sterilisation validation and packaging validation.
7. Post-Market SurveillanceDemonstrates continued compliance following commercial release.PMS Plan, PMS Report or PSUR, PMCF Plan, PMCF Evaluation Report, vigilance records and trend analysis.
8. Conformity DocumentsConfirms the device has successfully completed the conformity assessment process.EU Declaration of Conformity, CE Certificate (where applicable), EU Authorised Representative mandate and supporting regulatory documentation.

Although Annex II defines the minimum content expected within the technical documentation, the depth and complexity of each section will vary depending on the device classification, intended purpose, technology and associated risks. For higher-risk medical devices, considerably more evidence is generally required, particularly in relation to clinical evaluation, risk management and post-market surveillance.

A clearly structured technical file not only supports compliance with the EU MDR but also enables more efficient regulatory reviews, helping manufacturers reduce review times and respond more effectively to Notified Body questions during conformity assessment.

Maintaining a Medical Device Technical File Throughout the Product Lifecycle

Creating a compliant technical file is only the beginning of the regulatory process. Under the EU MDR, manufacturers are required to maintain and continually update their technical documentation throughout the entire lifecycle of the medical device to ensure it continues to demonstrate safety, performance and regulatory compliance.

Technical documentation should be treated as a living set of controlled documents rather than a one-time submission prepared solely for CE marking. As new evidence becomes available or changes are made to the device, the technical file should be reviewed and updated to ensure it remains accurate, complete and aligned with the current design and intended purpose.

Common reasons for updating a medical device technical file include:

  • Design or manufacturing changes
  • Changes to the intended purpose or indications for use
  • Software updates or cybersecurity improvements
  • New verification or validation testing
  • Clinical Evaluation Report (CER) updates
  • Biological Evaluation Report (BER) updates
  • Risk Management File revisions
  • Post-Market Surveillance (PMS) findings
  • Post-Market Clinical Follow-up (PMCF) results
  • Vigilance events or Field Safety Corrective Actions (FSCAs)
  • Updates to applicable harmonised standards or common specifications
  • Changes resulting from regulatory inspections or Notified Body reviews

Regularly maintaining technical documentation helps ensure that every part of the technical file remains consistent. For example, if new clinical evidence identifies additional risks, the Clinical Evaluation Report, Risk Management File, GSPR Checklist and Instructions for Use may all require corresponding updates. Maintaining this traceability is essential for demonstrating continued compliance with Regulation (EU) 2017/745.

A robust Quality Management System (QMS), typically certified to ISO 13485, should include documented procedures for document control, design changes, post-market surveillance and regulatory change management. These processes help manufacturers ensure that technical documentation remains current and that changes are implemented consistently across all affected records.

By proactively maintaining the technical file throughout the device lifecycle, manufacturers can simplify Notified Body audits, reduce regulatory risks and demonstrate ongoing compliance with the EU MDR long after CE marking has been achieved.

How has the PMS changed under MDR?

The General Safety and Performance Requirements (GSPRs), which must be revised in response to PMS activities, must be documented and shown by medical device manufacturers.

Manufacturers must now upgrade their PMS system proactively in a thorough and methodical manner, according to Article 2 (60), which lists this as one of the MDR’s general requirements.

The standards for PMS should directly correspond to the risk involved with the equipment, enabling the producer to take corrective or preventive action.

This action ought to be reasonable given the type of device and the most recent clinical evaluation.

This means that an effective PMS programme must offer a wide range of real-world experiences through a Post-Market Clinical Follow-Up (PMCF) beyond the limitations of a re-market study.

This strategy should identify issues before they become serious and ensure that corrective action is taken, all while continuously monitoring the long-term effectiveness of the device.

Importantly, each of these steps must go above and beyond mere compliance to add value and foster a strong sense of confidence in the medical device.

Does the new format require any additional details?

The fundamental Unique Device Identification-Device Identifier (UDI-DI), which must be printed on the device’s label and all higher layers of packaging, must now be included by the makers in the Device description and specification section.

Additionally, there are requirements for the UDI-DI in the case of implantable or reusable surgical equipment so this code number is always readily available.

Manufacturers of Single Use Devices (SUDs) must explicitly state in the risk management paperwork why the device is built in this way; that is, it must be made plain why the item cannot be reprocessed.

Another complication is that manufacturers now have to include information in the technical documentation for all kinds of medical devices, in accordance with Annex II, to describe the stages of design and processes that are applied to their products.

In the past, only Class III devices would make such a request, but now all devices share the same situation.

How is the technical file for a medical device reviewed?

The NB must examine the technical documents in accordance with the device classification for conformity assessment.

Importantly, the NBs evaluate medical devices using a risk-based approach because the benefits must outweigh the hazards or the risks must be minimised to an acceptable level given the present state of the art and the duration of the certificates that have been awarded.

Each device, whether it is a Class III implanted device, a Class III device, a Class IIb implantable device (with a few exclusions), or a Class IIb active device, is evaluated separately. A minimum of one representative device for each generic group is used to evaluate all other class IIb devices, whereas Class IIa devices are evaluated for at least one sample device for each device category.

Class I medical devices that are marketed as sterile, have a measurement function, or are reusable surgical instruments are only assessed for those particular attributes, such as sterility, measurement, or re-use.

Manufacturers can declare the compliance of their products by providing the EU declaration of conformity. NBs are not involved in conformity assessment for any other Class I devices.

Infographic illustrating the structure of a medical device technical file under the EU MDR, showing the eight core sections including device description, manufacturer information, design and manufacturing, General Safety and Performance Requirements (GSPRs), risk management, verification and validation, post-market surveillance and conformity documents required by Annex II and Annex III of Regulation (EU) 2017/745.

The Structure of the Technical File

1. Device Description & Specification

Every technical file begins by clearly defining the medical device and its intended purpose. This section provides the foundation for the entire technical documentation by explaining what the device is, how it functions, who it is intended for and the regulatory classification that applies. All subsequent documentation, including the Clinical Evaluation, Risk Management File and GSPR Checklist, should be consistent with the information presented here.

Typical documents include:

    • Device Description
    • Device Names
    • General Device Description
    • UDI-DI
    • Intended Use
    • Intended Purpose
    • Intended User
    • Indications for Use
    • Intended Environment/Settings for Use
    • Contraindications
    • Principles of Operation
    • Rationale for Qualification as a Medical Device
    • Risk Classification
    • Novel Features
    • Accessories
    • Configurations or Variants
    • Functional Elements
    • Raw Materials
    • Technical Specifications
    • Previous or Similar Generations of the Device

2. Information to be provided by the manufacturer

Manufacturers must provide sufficient information to enable users to operate the device safely and effectively. This section contains all documentation supplied with the product, ensuring that labelling, packaging and Instructions for Use accurately reflect the device’s intended purpose, residual risks and applicable regulatory requirements.

Typical documents include:

  • Device Labels
  • Packaging Labels
  • Shipping Labels
  • Instructions for Use (IFU)
  • Product Packaging Artwork
  • Regulatory Symbols
  • Marketing Claims (where applicable)

3. Design & Manufacturing Information

This section demonstrates how the device has been designed, developed and manufactured under controlled conditions. It provides evidence that appropriate design controls, manufacturing processes and supplier management systems are in place to ensure consistent product quality and regulatory compliance.

Typical documents include:

  • Design Stages
  • Manufacturing Processes
  • Design and Manufacturing Sites
  • Bill of Materials (BOM)
  • Supplier Quality Agreements
  • Design Specifications
  • Design History Documentation
  • Material Safety Data Sheets
  • Engineering Drawings

4. General Safety & Performance Requirements (GSPR)

The GSPR section demonstrates compliance with Annex I of the EU MDR by linking each applicable General Safety and Performance Requirement to the objective evidence contained within the technical documentation. It acts as an index, enabling regulators and Notified Bodies to quickly locate the evidence supporting conformity.

Typical documents include:

  • GSPR Checklist
  • Harmonised Standards Checklist
  • Common Specifications (where applicable)
  • Cross-references to supporting evidence

5. Risk Management File

Risk management is a continuous process carried out throughout the entire product lifecycle. This section demonstrates that hazards have been systematically identified, evaluated and controlled, and that the overall benefits of the device outweigh any residual risks in accordance with ISO 14971.

Typical documents include:

  • Risk Management Plan
  • Hazard Identification
  • Risk Analysis
  • Risk Evaluation
  • Risk Control Measures
  • Benefit-Risk Analysis
  • Residual Risk Evaluation
  • Risk Management Report

6. Verification & Validation

Verification and validation activities provide objective evidence that the device meets its design specifications and performs safely for its intended purpose. The exact testing required will depend on the device technology, classification and intended use, but should collectively demonstrate compliance with the applicable GSPRs.

Typical documents include:

  • Product Verification Reports
  • Product Validation Reports
  • Packaging Validation
  • Sterilisation Validation
  • Software Validation (where applicable)
  • Biological Evaluation Report (BER)
  • Clinical Evaluation Report (CER)
  • Electrical Safety & EMC Testing (where applicable)
  • Usability Engineering Documentation
  • Performance Testing

7. Post Market Surveillance

Technical documentation does not end once CE marking has been achieved. Manufacturers must continually monitor device performance in real-world use and use post-market data to maintain the technical file throughout the product lifecycle.

Typical documents include:

  • Post-Market Surveillance (PMS) Plan
  • PMS Report or Periodic Safety Update Report (PSUR)
  • Post-Market Clinical Follow-up (PMCF) Plan
  • PMCF Evaluation Report
  • Vigilance Records
  • Trend Analysis
  • Corrective and Preventive Actions (CAPA)

8. Conformity Documents

The final section contains the formal regulatory documents confirming that the device has successfully completed the applicable conformity assessment procedure and can be legally placed on the market. These documents should remain aligned with the information contained throughout the rest of the technical file.

Typical documents include:

  • EU Declaration of Conformity
  • CE Certificate (where applicable)
  • EU Authorised Representative Mandate
  • Notified Body Certificates (where applicable)
  • Other Regulatory Certificates and Supporting Documentation

Worked Example: Technical File Structure for a Class IIa Hydrogel Wound Dressing

The exact contents of a technical file will vary depending on the device classification, intended purpose and underlying technology. The example below illustrates how the technical documentation for a Class IIa hydrogel wound dressing may be organised in accordance with Annex II and Annex III of the EU MDR.

Example Device: Hydrogel Wound Dressing (Class IIa)

Technical File SectionExample Documents
Device Description & SpecificationDevice description, intended purpose, intended users, UDI-DI, technical specifications, product variants, shelf life
Information Supplied by the ManufacturerProduct labels, Instructions for Use (IFU), packaging artwork, symbols, translations
Design & Manufacturing InformationManufacturing process, raw material specifications, Bill of Materials (BOM), supplier controls, manufacturing site information
General Safety & Performance Requirements (GSPR)Completed GSPR Checklist with references to supporting evidence and applicable harmonised standards
Risk Management FileISO 14971 Risk Management Plan, Hazard Analysis, Risk Evaluation, Risk Management Report
Verification & ValidationBiological Evaluation Report (BER), packaging validation, shelf-life studies, transport validation, performance testing, Clinical Evaluation Report (CER)
Post-Market SurveillancePMS Plan, PMS Report or PSUR, PMCF justification or PMCF Plan, complaint trending, vigilance records
Conformity DocumentsEU Declaration of Conformity, CE Certificate, EU Authorised Representative mandate, Notified Body correspondence

How the Documentation Works Together

Although each section serves a different purpose, the technical file should present a consistent body of evidence demonstrating that the device is safe and performs as intended.

For example:

  • The Clinical Evaluation Report (CER) should support the intended purpose and clinical claims described in the Device Description.
  • The Risk Management File should identify hazards such as skin irritation, infection risks and incorrect application, together with the controls implemented to reduce those risks.
  • The Biological Evaluation Report (BER) should demonstrate that all patient-contacting materials are biocompatible for their intended duration and nature of contact.
  • The GSPR Checklist should reference the relevant test reports, risk management records, clinical evidence and labelling that demonstrate compliance with each applicable requirement of Annex I.
  • Post-Market Surveillance activities should continually confirm that the dressing continues to perform safely and effectively throughout its commercial lifecycle.

A well-structured technical file therefore tells a single, coherent story. Every section should support the others through clear cross-references and objective evidence, allowing Notified Bodies and Competent Authorities to efficiently assess compliance with Regulation (EU) 2017/745.

How can Patient Guard Help?

Patient Guard established in 2017 has helped hundreds of clients with their MDR and IVDR technical file creation and updates. Our Regulatory experts are experienced and qualified to help you simplify your compliance journey. Contact us to enquire about our technical file CE and UKCA services.

Frequently Asked Questions Abuout EU MDR Medical Device Technical Files

A medical device technical file is a structured collection of documents demonstrating that a medical device complies with Regulation (EU) 2017/745 (EU MDR). It provides objective evidence that the device is safe, performs as intended and satisfies the applicable General Safety and Performance Requirements (GSPRs). The technical file forms the foundation of the conformity assessment process and must be maintained throughout the device lifecycle.

A technical file should contain the documentation required by Annex II and Annex III of the EU MDR, including the device description, labelling, design and manufacturing information, GSPR Checklist, Risk Management File, verification and validation reports, Clinical Evaluation Report (CER), Biological Evaluation Report (BER), Post-Market Surveillance (PMS) documentation and Declaration of Conformity.

Yes. Every medical device placed on the European market under the EU MDR must be supported by compliant technical documentation, regardless of classification. While most Class I devices can be self-declared by the manufacturer, they must still have a complete technical file demonstrating compliance with the applicable regulatory requirements.

No. General Class I medical devices are typically self-declared and do not require routine Notified Body assessment. However, Class Is, Im and Ir devices require Notified Body involvement for the relevant aspects of sterility, measuring function or reusability, while most Class IIa, IIb and III devices undergo a full conformity assessment that includes review of the technical documentation.

Technical documentation should be maintained throughout the entire product lifecycle. Manufacturers should review and update the technical file whenever significant design changes are made, new clinical evidence becomes available, risk management activities identify new hazards, post-market surveillance generates new information or regulatory requirements change.

Annex II specifies the core technical documentation required to demonstrate compliance before CE marking, including device description, design information, risk management, clinical evaluation and verification evidence. Annex III focuses on the post-market surveillance documentation that manufacturers must maintain once the device has been placed on the market.

A GSPR Checklist is a controlled document that identifies each applicable General Safety and Performance Requirement contained within Annex I of the EU MDR and references the objective evidence demonstrating compliance. It enables manufacturers and Notified Bodies to quickly trace each regulatory requirement to the supporting documentation within the technical file.

Common deficiencies include incomplete Clinical Evaluation Reports, inconsistent Risk Management Files, missing verification and validation evidence, weak biological evaluation, poorly completed GSPR Checklists, inadequate post-market surveillance documentation and inconsistencies between different sections of the technical file. Maintaining clear traceability between documents helps reduce these issues.

Yes, provided the devices share the same intended purpose, design principles and applicable regulatory requirements. Manufacturers should clearly identify all covered variants and demonstrate that the supporting evidence remains applicable across the entire device family. Significant differences may require additional testing or separate technical documentation.

Yes. Patient Guard provides technical file preparation, independent technical documentation reviews, gap assessments and remediation services for manufacturers of Class I, IIa, IIb and III medical devices. Our regulatory specialists support every stage of the documentation process, including Risk Management, Clinical Evaluation, Biological Evaluation, GSPR compliance, Post-Market Surveillance and Notified Body submissions.

David Small BSc (Hons), MSc, MTOPRA

David Small BSc (Hons), MSc, MTOPRA

Reviewed by
David Small, BSc (Hons), MSc, MTOPRA
Founder & CEO |
20+ years in medical device regulatory affairs,  MDR/IVDR compliance and quality systems.

Patient Guards Recent Posts

10 Common Technical Documentation Deficiencies Found During EU MDR and IVDR Notified Body Reviews

10 Common Technical Documentation Deficiencies Found During EU MDR and IVDR Notified Body Reviews

Preparing technical documentation for EU MDR or IVDR certification is only half the challenge. Successfully passing a Notified Body review depends on demonstrating consistency across your Quality Management System, Clinical Evaluation, Risk Management, Biological Evaluation, Performance Evaluation and Post-Market Surveillance activities. Discover ten of the most common technical documentation deficiencies identified during MDR and IVDR conformity assessments—and learn how to reduce the likelihood of costly review cycles and certification delays.

Read More »
Patient Guard EU Authorised Representative Services

EU Authorised Representative Services for Medical Device & IVD Manufacturers

Selling medical devices or IVDs in Europe? If your company is based outside the EU, appointing an EU Authorised Representative (EC Rep) is a legal requirement under EU MDR 2017/745 and IVDR 2017/746. Patient Guard provides expert EU Authorised Representative services, EUDAMED support, regulatory guidance, and ongoing compliance management to help manufacturers access and maintain the European market with confidence.

Read More »

Patient Guards Related Services

Patient Guards Regulatory Tools

Need Training?

Do you need training on Quality Management Systems or EU MDR/ EU IVDR? then check out our training courses.

Share this guide:

Most Popular

10 Common Technical Documentation Deficiencies Found During EU MDR and IVDR Notified Body Reviews

Preparing technical documentation for EU MDR or IVDR certification is only half the challenge. Successfully passing a Notified Body review depends on demonstrating consistency across your Quality Management System, Clinical Evaluation, Risk Management, Biological Evaluation, Performance Evaluation and Post-Market Surveillance activities. Discover ten of the most common technical documentation deficiencies identified during MDR and IVDR conformity assessments—and learn how to reduce the likelihood of costly review cycles and certification delays.

Read More »

EU Authorised Representative Services for Medical Device & IVD Manufacturers

Selling medical devices or IVDs in Europe? If your company is based outside the EU, appointing an EU Authorised Representative (EC Rep) is a legal requirement under EU MDR 2017/745 and IVDR 2017/746. Patient Guard provides expert EU Authorised Representative services, EUDAMED support, regulatory guidance, and ongoing compliance management to help manufacturers access and maintain the European market with confidence.

Read More »
patient guard
Patient Guard

Sign up to our newsletter

Be the first to hear industry news and how Patient Guard can help you.

Get the latest updates on medical device regulation

Sign up to our newsletter and we’ll deliver news and insights straight to your inbox.
Patient Guard Regulatory Affairs and Quality Assurance

Get the Medical Device Technical Checklist

Thank you! The checklist is now ready to download.

checklist-tablet