What is Article 10?
Article 10 is not just a checklist—it represents a shift in regulatory expectations, emphasizing proactive risk management, post-market surveillance, and accountability. In this article, we explore the key responsibilities of manufacturers under Article 10 and why it is crucial for regulatory compliance and market success.
Article 10 lays out the baseline legal and operational responsibilities for all medical device manufacturers wishing to place devices on the EU market. These responsibilities span the entire lifecycle of a device, from design and production to post-market surveillance and corrective actions.
The regulation requires manufacturers to go beyond simple product conformity. They must demonstrate ongoing compliance, implement systematic controls, and respond effectively to real-world performance data.
New to the EU MDR?
Article 10 outlines the core responsibilities of medical device manufacturers under Regulation (EU) 2017/745. For a complete overview of MDR requirements, including device classification, GSPRs, clinical evaluation, technical documentation, UDI, EUDAMED and CE marking, explore our EU MDR for Beginners Guide.
Core Responsibilities Under Article 10
1. Compliance with General Safety and Performance Requirements (GSPRs)
Every device must meet the requirements listed in Annex I of the MDR. These include safety, performance, clinical evaluation, and risk mitigation. The goal is to ensure the device achieves its intended purpose without compromising the health and safety of users and patients.
Manufacturers must document and justify how these requirements are met throughout the device lifecycle.
Understanding the EU MDR GSPRs
Article 10 requires manufacturers to ensure their devices comply with the General Safety and Performance Requirements (GSPRs) set out in Annex I of Regulation (EU) 2017/745. Learn what the GSPRs cover, how to demonstrate conformity, and how they integrate with risk management, clinical evaluation and technical documentation in our EU MDR GSPRs Guide.
2. Implementation of a Quality Management System (QMS)
Manufacturers must establish, document, implement, and maintain a QMS that is proportionate to the risk class and type of device. The QMS must include:
Design and development processes
Supplier and subcontractor control
Manufacturing and release procedures
Post-market surveillance and vigilance activities
CAPA systems
Record retention and traceability mechanisms
The QMS should align with internationally recognized standards such as ISO 13485:2016, although the MDR has additional, more prescriptive requirements.
Building an ISO 13485-Compliant Quality Management System
Article 10(9) requires manufacturers to establish, document and maintain a quality management system that supports regulatory compliance throughout the device lifecycle. Discover how ISO 13485 provides the internationally recognised framework for meeting these requirements in our ISO 13485 Guide.
3. Technical Documentation
Manufacturers are responsible for preparing and maintaining technical documentation as defined in Annex II and Annex III. This includes:
Device description and specification
Labelling and IFU
Design and manufacturing information
Risk management file
Verification and validation data
Clinical evaluation report
PMS and vigilance plans
This documentation must be readily available to Notified Bodies and competent authorities upon request.
Avoid Common MDR Technical Documentation Deficiencies
Article 10 requires manufacturers to prepare and maintain complete, accurate and up-to-date technical documentation throughout the device lifecycle. Discover the most common technical documentation deficiencies identified during Notified Body reviews and learn practical strategies to avoid delays, non-conformities and certification issues in our MDR Technical Documentation Deficiencies Guide.
4. Risk Management Process
In accordance with ISO 14971, manufacturers must implement a risk management system that continues throughout the product lifecycle. The process involves:
Hazard identification
Risk estimation and evaluation
Implementation of risk control measures
Evaluation of overall residual risk
Monitoring of post-market data
The system must be proactive, not reactive. Continuous improvement based on real-world data is expected.
Implementing ISO 14971 Risk Management
Article 10 requires manufacturers to establish and maintain an effective risk management system throughout the entire medical device lifecycle. Discover how ISO 14971 provides the internationally recognised framework for identifying hazards, evaluating risks, implementing risk controls and maintaining an up-to-date Risk Management File in our ISO 14971 Guide.
5. Post-Market Surveillance (PMS) and Vigilance
Manufacturers must have a documented PMS plan in place for every device. The PMS system should collect and analyze data to:
Verify the continued safety and performance of the device
Identify emerging risks or trends
Feed updates into risk management and clinical evaluation
Inform necessary field safety corrective actions (FSCAs)
For higher-risk devices (Class IIa, IIb, III), manufacturers are required to produce a Periodic Safety Update Report (PSUR).
Additionally, serious incidents and FSCA reports must be submitted to EUDAMED within the specified timeframes outlined in Articles 87–91.
Master Post-Market Surveillance Under the EU MDR
Article 10 requires manufacturers to establish, document and maintain a proactive Post-Market Surveillance (PMS) system throughout the medical device lifecycle. Learn how to develop compliant PMS Plans, PMS Reports, PSURs, trend analysis and vigilance processes that support ongoing regulatory compliance in our Medical Device Post-Market Surveillance Guide.
6. Unique Device Identification (UDI)
The UDI system is designed to enhance traceability and transparency. Manufacturers must:
Assign UDI-DI and UDI-PI codes
Affix UDIs on labelling and packaging
Upload UDI-related data to the EUDAMED database
This system improves recall efficiency, surveillance, and counterfeit detection.
Understanding Medical Device UDI Requirements
Article 10 requires manufacturers to implement the Unique Device Identification (UDI) system to improve device traceability, support post-market surveillance and meet EU MDR compliance obligations. Learn how UDI-DI, UDI-PI, labelling requirements and EUDAMED registration work together in our Medical Device UDI for Beginners Guide.
7. Economic Operator Oversight
Manufacturers must identify and monitor all economic operators associated with the device:
Authorised Representative (for non-EU manufacturers)
Importers
Distributors
The manufacturer is ultimately responsible for ensuring that each actor fulfils their regulatory obligations. Contracts, SOPs, and oversight mechanisms should be in place to ensure compliance.
Do You Need an EU Authorised Representative?
Manufacturers based outside the European Union must appoint an EU Authorised Representative (EC Rep) before placing medical devices on the EU market. Learn who requires an EU AR, the legal responsibilities under Article 11 of Regulation (EU) 2017/745, and how to choose the right representative in our EU Authorised Representative Guide.
8. Person Responsible for Regulatory Compliance (PRRC)
As per Article 15, manufacturers must appoint at least one PRRC. This individual must meet specific qualifications and is responsible for:
Ensuring technical documentation and declarations of conformity are up to date
PMS and vigilance reporting
Post-market clinical follow-up (PMCF) when applicable
The PRRC must be permanently and continuously available to the manufacturer, either as an employee or external contractor (in the case of SMEs).
Who Needs a Person Responsible for Regulatory Compliance (PRRC)?
While Article 10 defines the overarching responsibilities of medical device manufacturers, Article 15 requires manufacturers and certain Authorised Representatives to have a qualified Person Responsible for Regulatory Compliance (PRRC) permanently and continuously at their disposal. Learn about PRRC qualifications, statutory responsibilities and outsourcing options in our PRRC Guide.
9. Liability and Insurance
Manufacturers are required to have adequate insurance coverage to compensate for potential harm caused by defective devices. This provision ensures that victims have access to financial redress and that manufacturers remain financially accountable.
Frequently Asked Questions In Relation To EU MDR Article 10
Yes. Article 10(9) requires all manufacturers to establish and maintain a QMS. While Class I devices may have a lighter system, even they must demonstrate adequate control over design, manufacturing, and post-market processes.
The PRRC must have:
A university degree in law, medicine, pharmacy, engineering, or science and one year of professional experience in regulatory affairs or quality systems, or
Four years of professional experience in these areas without a formal degree.
This person ensures MDR compliance on behalf of the manufacturer.
Yes. The PMS requirement applies to all classes of devices. However, the level of scrutiny and documentation escalates with device risk. High-risk devices require PSURs, while Class I devices must maintain PMS reports and act on trends.
Yes. Article 10 applies to all manufacturers placing medical devices on the European market, regardless of device classification. Although the specific regulatory requirements vary according to the device class and intended purpose, every manufacturer must establish appropriate quality management systems, maintain technical documentation, implement risk management, conduct post-market surveillance and ensure ongoing compliance with Regulation (EU) 2017/745.
Yes. Article 10 places ongoing responsibilities on manufacturers throughout the entire lifecycle of a medical device. Technical documentation must be kept up to date to reflect design changes, clinical evidence, post-market surveillance findings, risk management updates and any regulatory changes. Manufacturers should ensure their documentation always represents the current version of the device and remains available for review by Notified Bodies and Competent Authorities.
Non-compliance may lead to:
Suspension or withdrawal of CE certificates
Device recalls or import bans
Regulatory inspections and audits
Legal liability and fines
Reputational damage and market exclusion
Authorities across the EU are empowered to enforce corrective actions swiftly and may publish non-compliance findings publicly.
Summary
Article 10 of the EU MDR is not just a regulatory formality—it is a strategic imperative. It sets the expectations for responsible manufacturing and continuous oversight across the device lifecycle. From design and documentation to market monitoring and risk control, manufacturers must be fully engaged in ensuring patient safety and product reliability.
For many organisations, especially small and medium-sized enterprises (SMEs), these obligations can be daunting. That’s where expert support makes a difference.
At Patient Guard, we help manufacturers:
Build compliant Quality Management Systems
Prepare technical documentation and PMS plans
Serve as your EU Authorised Representative
Train your PRRC or act in that capacity if needed
Need support meeting your Article 10 responsibilities? Contact us today to learn how we can support your path to MDR compliance.
References
This guide is based on the following legislation, international standards and official regulatory guidance relating to Article 10 of Regulation (EU) 2017/745 and the general obligations of medical device manufacturers.
| Organisation | Reference | Why it's relevant |
|---|---|---|
| European Union | Regulation (EU) 2017/745 on Medical Devices (MDR) | Contains Article 10, which establishes the general obligations of manufacturers, including Quality Management Systems, technical documentation, clinical evaluation, risk management, post-market surveillance and regulatory compliance. |
| European Commission | MDCG Endorsed Documents and Other Guidance | Provides official Medical Device Coordination Group (MDCG) guidance supporting implementation of Article 10 requirements, including Quality Management Systems, clinical evaluation, technical documentation, post-market surveillance and vigilance. |
| International Organization for Standardization (ISO) | ISO 13485:2016 – Medical Devices – Quality Management Systems – Requirements for Regulatory Purposes | Defines the internationally recognised Quality Management System requirements that support compliance with Article 10(9) and the ongoing regulatory obligations of medical device manufacturers. |
| International Organization for Standardization (ISO) | ISO 14971:2019 – Medical Devices – Application of Risk Management to Medical Devices | Provides the internationally recognised framework for implementing the lifecycle risk management process expected under Article 10 and throughout the medical device lifecycle. |
| European Commission | EUDAMED – European Database on Medical Devices | Provides official information on EUDAMED, supporting the UDI registration, vigilance reporting and traceability obligations discussed within Article 10. |
| European Commission | Economic Operators | Explains the responsibilities of manufacturers, Authorised Representatives, importers and distributors under the MDR, supporting the discussion of manufacturer accountability and regulatory responsibilities. |
Manufacturer obligations under the MDR continue to evolve through legislation, recognised standards and regulatory guidance. Manufacturers should always consult the latest published legislation, recognised standards and official guidance when implementing and maintaining compliant Quality Management Systems and fulfilling their obligations under Article 10 of Regulation (EU) 2017/745.
David Small BSc (Hons), MSc, MTOPRA
Reviewed by
David Small, BSc (Hons), MSc, MTOPRA
Founder & CEO |
20+ years in medical device regulatory affairs, MDR/IVDR compliance and quality systems.
Patient Guards Recent Posts

Cosmetic Product Safety Report (CPSR): A Complete Guide to UK Cosmetic Compliance
Before a cosmetic product can legally be placed on the UK market, manufacturers and Responsible Persons must demonstrate that it is safe for human use under normal or reasonably foreseeable conditions. The Cosmetic Product Safety Report (CPSR) is one of the most important regulatory documents required under the UK Cosmetics Regulation. This guide explains what a CPSR is, who can prepare one, what information it must contain, how it relates to the Product Information File (PIF) and how it supports legal cosmetic compliance.

IVDR PMPF Explained: A Complete Guide to Post-Market Performance Follow-up
Post-Market Performance Follow-up (PMPF) is a fundamental requirement under the EU In Vitro Diagnostic Regulation (IVDR), ensuring that manufacturers continually monitor the scientific validity, analytical performance and clinical performance of their in vitro diagnostic medical devices after CE marking. This guide explains IVDR PMPF requirements, PMPF Plans, PMPF Reports, Annex XIII expectations and how ongoing performance monitoring supports continued regulatory compliance throughout the device lifecycle.

IVDR Scientific Validity Explained: A Complete Guide for Manufacturers
Scientific Validity is the first pillar of IVDR Performance Evaluation and provides the scientific foundation demonstrating that an analyte or biomarker is associated with a specific clinical condition or physiological state. This guide explains Scientific Validity under Regulation (EU) 2017/746, including literature reviews, Scientific Validity Reports, Annex XIII requirements, evidence appraisal and how Scientific Validity supports successful CE marking.
Patient Guards Related Services
Patient Guards Regulatory Tools
Need Training?
Do you need training on Quality Management Systems or EU MDR/ EU IVDR? then check out our training courses.
Posted on Google![]()
Munna P52 days agoTrustindex verifies that the original source of the review is Google.
Working with the Patient Guard team has been a great experience throughout our MHRA and ISO 13485 documentation journey. Their expertise, structured approach, and practical guidance helped our team build a robust quality management system while keeping us aligned with regulatory expectations. The collaboration was professional, responsive, and focused on finding solutions rather than simply identifying issues. A special thank you to Alex and Steve for their outstanding coordination, responsiveness, and continuous support throughout the project. They were always approachable, provided valuable feedback, and worked closely with our team to resolve challenges efficiently. Their commitment made a significant difference in keeping our documentation effort on track. I highly recommend Patient Guard to any healthcare or MedTech organization looking for experienced regulatory and quality system partners for MHRA, ISO 13485, and broader medical device compliance initiatives. Thank you again to the entire Patient Guard team for being such reliable partners.Posted on Google![]()
Peter Reeve79 days agoTrustindex verifies that the original source of the review is Google.
STEPPER design, manufacture & distribute eyewear across the globe. With the increasingly complex landscape concerning the placing of Mecial Devices onto the market, we realised we needed professional guidance. We found Patient Guard via a simple internet search and are delighted we did! They provide a pragmatic solution to our needs, are totally reliable & always available to answer our (often simplistic) questions. They are highly efficient & responsive to what is a changing picture in our world and nothing is too much trouble. We have a much better understanding of regulatory affairs and our responsibilities as manufacturers & distributors and they support us in navigating the requirements in different territories. Updating our Declaration of Conformity, ensuring our labelling is compliant and acting as our PRRC are the key areas of their service for us.Posted on Google![]()
Derek Timm79 days agoTrustindex verifies that the original source of the review is Google.
For those companıes lookıng to comply to ISO standards and ın partıcular ISO13485 whıch to be honest ıs a nıghtmare I would strongly suggest goıng to the professıonals as ındeed we dıd by joınıng forces wıth Patıent Guard Ltd The staff are fantastıc nothıng ıs too much trouble and as a medıcal supply company we sımply cannot lıve wıthout them Thanks ın partıcular to Alex and Steve for all the hard work and our best regards from Dan Medıca South LımıtedPosted on Google![]()
BMSCriticalCare116 days agoTrustindex verifies that the original source of the review is Google.
Great service, very helpful and always willing to answer any questions we have,Posted on Google![]()
Thomson Software787 days agoTrustindex verifies that the original source of the review is Google.
Alex Lewis of PatientGuard guided us through the ISO13485 process in a thorough, systematic and efficient manner. He was friendly, patient and willing to go the extra mile. Excellent service.Verified by TrustindexTrustindex verified badge is the Universal Symbol of Trust. Only the greatest companies can get the verified badge who has a review score above 4.5, based on customer reviews over the past 12 months. Read more