Papers, forms, and filings-2026 marks the moment all that theory hits real life. For MedTech across Europe, preparation gives way to execution. No more hiding behind drafts; the squeeze is here.
Right now, three major shifts run in parallel. EUDAMED’s first modules are now compulsory. Notified bodies face tighter, more detailed rules on how assessments work. And MDR plus IVDR transition deadlines keep bearing down. The much-discussed regulatory simplification churns through Brussels, but there’s no law yet. Companies have to juggle two jobs at once: meet current mandates, and brace for whatever changes lawmakers might yet deliver.
EUDAMED: four modules mandatory-no excuses
Since 28 May 2026, four EUDAMED modules became mandatory: actor registration, UDI and device registration, notified bodies and certificates, and market surveillance. The remaining two modules-post-market surveillance and vigilance, and clinical investigations-are still under development, their launch dates not yet set.
Forget the idea that this is just pushing paper. EUDAMED demands that your records, device identifiers, certificates, and technical files all match exactly. One incorrect product name, or a Basic UDI-DI out of sync, and suddenly you’re carrying risk you could have skipped. EUDAMED isn’t a box-ticking exercise. It’s a data-governance challenge, and treating it as anything less is a mistake.
Conformity assessments: new structure, new clarity
Commission Implementing Regulation (EU) 2026/977 did away with vague assessment practices. Quotations now must show the total expected cost with a clear breakdown, list potential extra fees, set out timelines, and alert you-along with a written explanation-if the final bill will overshoot the original figure by more than 10%.
Timeframes are no longer a guessing game. Thirty days to review a complete application and sign the contract. One hundred twenty days for the quality-management-system audit. Ninety days for technical documentation or product verification. Twenty days for a certification decision. But here’s the rub: if the manufacturer needs to fix non-conformities or answer questions, the clock pauses. The message? Notified bodies owe you predictability, but only if you supply clean, well-prepared evidence. Sloppy files still mean slow reviews.
IVDR’s next hard date: 26 September 2026
Legacy Class C IVDs using the extended transition had to submit an application to a notified body by 26 May 2026. Now comes the next line in the sand: 26 September 2026-the signed written agreement for conformity assessment has to be in place by then.
| IVD category | Application deadline | Written agreement | End of transition |
| Class D | 26 May 2025 | 26 September 2025 | 31 December 2027 |
| Class C | 26 May 2026 | 26 September 2026 | 31 December 2028 |
| Class B and Class A sterile | 26 May 2027 | 26 September 2027 | 31 December 2029 |
Extensions aren’t blanket permissions. Every single condition must be met-the device has to comply with the old law, mustn’t change in design or intended purpose, and can’t present unacceptable risk. An IVDR-compliant QMS had to be operational by 26 May 2025. Scrutinise eligibility device by device. Guessing, or assuming your entire portfolio slides through, is how companies get locked out of the market.
MDR deadlines: closer than you think
Class III custom-made implantable device derogation? That ended 26 May 2026. For other MDR legacy devices, two dates now matter most: 31 December 2027 for Class III and most Class IIb implantables, and 31 December 2028 for other Class IIb, Class IIa, Class I sterile or measuring devices, and those now needing notified body review for the first time under MDR. All that depends, of course, on meeting every transition requirement.
On paper, these cutoffs seem far away. Reality says otherwise. Conformity assessment, remediation, evidence generation-those eat up months. Waiting until the last minute? That’s how you run straight into a wall of bottlenecks, missing clinical data, or a notified body with no time left for you.
Simplification: progress, but still theory
The Commission’s MDR/IVDR revision aims to trim bureaucracy and make certification more predictable. Proposals range from lighter assessment loads and sharper timelines, to increased digitisation, structured dialogue with notified bodies, improved support for breakthrough technologies, less regulatory overlap between device and AI rules, more real-world evidence, and tighter oversight.
But don’t lose sight: none of it is law. Parliament and Council are still negotiating. Parliament’s draft supports less red tape, but the core safety requirements-clinical evidence, benefit-risk analysis, vigilance, post-market clinical follow-up, and periodic safety reporting-aren’t going anywhere. So track the process, but don’t start rewriting your compliance playbook based on drafts that could shift again.
What matters now
Forget spinning up another siloed compliance project. What’s needed? One unified view of products, evidence, obligations, and deadlines. Leadership teams should focus on these steps:
- Verify both the accuracy and ownership of every EUDAMED record required.
- Confirm transition eligibility for each legacy device or IVD-don’t generalise.
- Map deadlines by device, risk class, and notified body-missed dates kill access.
- Spot and fix missing or inconsistent evidence before the next notified body review.
- Connect clinical, risk, quality, and post-market records-disconnection means delay.
- Watch the MDR/IVDR revision, but don’t treat drafts as settled law.
- Set clear human-review and approval points for every regulatory decision-no autopilot.
The real shift: trusted data, not just documents
MedTech regulation in the EU is moving toward structure, digital records, and verifiable evidence. Yet many teams keep clinical studies, risk files, validation records, post-market data, and requirements scattered across disconnected folders. Storage isn’t the issue. The work is finding the right evidence, proving it fits, and presenting it in a way that stands up to scrutiny-every time.
DocuGenius gives regulatory teams a way to read technical documentation, check evidence against requirements, and turn unstructured content into structured, review-ready results. Automation doesn’t remove the need for experts. What it does is let those experts spend less time searching and more time actually assessing risk, quality, and compliance. The future isn’t a mountain of paperwork. It’s trusted data, ready when you need it-if you build for it now.