Checklist: Verifying MDR Compliance Before Sourcing

This guide provides a direct checklist for importers to verify supplier MDR compliance. It outlines specific documents, technical file checks, and red flags to review before placing an order for devices subject to EU medical regulations.
- Confirm the manufacturer holds a current EU Declaration of Conformity for the specific device class and model.
- Verify the Notified Body certificate matches the CE marking, technical file, and quality management system scope.
- Check that the technical documentation, risk management file, and post-market surveillance plan are current and aligned with the device.
- Identify red flags such as mismatched registration numbers, missing instructions for use, or delayed conformity assessments.
Importers face direct liability when bringing medical devices into the EU under the current regulatory framework. A supplier’s claim of compliance does not equal legal proof. Before finalizing a purchase order, you need to verify that the device, the manufacturer, and the supporting documentation align with the latest EU requirements. This checklist breaks that verification into practical steps, grouped by theme, so your procurement and regulatory teams can audit a supplier’s position consistently.
Confirming the Manufacturer’s Legal Identity
Start with the manufacturer’s legal standing. The entity issuing the CE marking must be the one responsible for the product under the regulations. You are not just checking a business license; you are checking that the manufacturer has designated a responsible person in the EU and has registered the device with the EUDAMED database.
- Verify the EU Responsible Person. If the manufacturer is outside the EU, they must appoint an authorized representative within the EU. Confirm this person is named in the manufacturer’s documentation and is registered with the competent authority.
- Check EUDAMED Registration. Ask for the unique device identifier and the EUDAMED registration status. While public access to the full database may have restrictions for some data, the manufacturer should be able to confirm the registration is active and matches the device model.
- Validate the CE Marking. The CE mark on the device and packaging must be accompanied by the Notified Body number if the device requires third-party conformity assessment. The number must match the manufacturer’s quality management system certificate.
Red flags to watch for:
- The CE mark lacks the Notified Body number for a Class IIa or higher device.
- The manufacturer cannot provide the name and address of their EU Responsible Person.
- The device model in the registration differs from the model you are ordering.
Reviewing the Technical File and Risk Management
The technical file is the core evidence that the device meets the essential requirements. You do not need to read every line of the technical file, but you must confirm its existence, scope, and currency. The manufacturer must maintain this file for the lifetime of the device and be able to provide it to you upon request or as part of a due diligence audit.
- Request the Technical Documentation. Ask for the technical file or a summary of its contents. It should include design controls, performance testing, and manufacturing processes.
- Check the Risk Management File. Under the regulations, risk management is not a one-time event. Ask for the risk management file that shows the current risk assessment and mitigation strategies.
- Verify Performance Verification. For Class IIa, IIb, III, and IV devices, you need proof that performance has been verified against the intended use. This may include clinical evaluation reports or, for lower-risk devices, performance testing data.
Red flags to watch for:
- The manufacturer refuses to provide the technical file or claims it is “confidential” without offering a summary or third-party verification.
- The risk management plan is dated more than the last major design change.
- Performance testing is outdated or does not cover the specific model you are sourcing.
Verifying Device Certification and Notified Body Involvement
Not all devices require a Notified Body. Class I devices, with some exceptions, can self-declare conformity. However, for Class IIa, IIb, III, and IV devices, a Notified Body must assess the quality management system and, for some classes, the technical file. You must confirm which route applies to your device and whether the supplier’s certification is valid.
- Identify the Device Class. Use the classification rules in Annex I of the regulation to determine the class. This is often the first point of confusion for importers.
- Request the Certificate of Conformity. For devices requiring a Notified Body, ask for the certificate. It should state the scope, the manufacturer’s name, the device class, and the validity period.
- Check the Notified Body’s Status. Verify that the Notified Body listed on the certificate is currently authorized by the European Commission. You can check the public list of Notified Bodies to confirm the body’s authorization status and scope.
Red flags to watch for:
- The certificate scope is broader than the device you are buying.
- The Notified Body number on the certificate is not in the public list of authorized bodies.
- The certificate has expired or is close to expiration without a renewal plan in place.
| Device Class | Notified Body Requirement | Typical Verification Step |
|---|---|---|
| Class I | Not required (except for sterile, reusable, or measuring) | Check self-declaration and technical file |
| Class IIa | Required | Verify QMS certificate and technical file |
| Class IIb | Required | Verify QMS certificate and clinical evaluation |
| Class III | Required | Verify QMS certificate, technical file, and clinical evaluation |
| Class IV | Required | Verify QMS certificate, technical file, and clinical evaluation |
Assessing Quality Management System Compliance
The quality management system (QMS) is the engine of compliance. A manufacturer cannot claim MDR compliance if their QMS is not maintained to the standards required by the regulations. This system covers everything from supplier controls to internal audits and corrective actions.
- Request the QMS Certificate. For Notified Body-assessed devices, this is mandatory. The certificate should be issued by the Notified Body and cover the specific device types.
- Review the Scope of the QMS. Ensure the QMS covers the production, testing, and post-market surveillance of the device you are buying. A generic QMS certificate that does not list the device type is insufficient.
- Check for Internal Audit Records. Ask if the manufacturer conducts regular internal audits of their QMS. This demonstrates that they are actively monitoring their own compliance, not just waiting for an external audit.
Red flags to watch for:
- The QMS certificate is from a body that is not a Notified Body.
- The QMS scope does not include the specific product line.
- The manufacturer has no record of internal audits or corrective actions.
Post-Market Surveillance and Vigilance
Compliance does not end at the point of sale. Manufacturers are required to monitor devices after they are placed on the market. As an importer, you are part of this chain of responsibility. You need to know that the manufacturer is actively monitoring your product and responding to adverse events.
- Request the Post-Market Surveillance Plan. This document should outline how the manufacturer collects and analyzes data on device performance and safety.
- Check the Vigilance Procedure. Ask how the manufacturer handles adverse event reporting. They should have a clear procedure for reporting serious incidents to the competent authorities.
- Verify the Unique Device Identifier (UDI) Implementation. The UDI allows for the tracking of each individual device. Ensure the device you are receiving has the correct UDI format and that it is readable.
Red flags to watch for:
- The manufacturer has no post-market surveillance plan or it is not updated.
- The UDI is missing, malformed, or not scannable.
- The manufacturer cannot explain how they would report an adverse event involving your device.
Final Documentation and Record Keeping
Before you sign the purchase order, gather all the documents you have verified. These documents are your legal protection. Keep a complete file for each device model and batch you import. This file should be readily available in case of a market surveillance authority inquiry.
- Compile the CE Marking Documentation. Include the Declaration of Conformity, the CE marking label, and any Notified Body certificates.
- Store the Technical File Access. Keep a record of where the technical file is stored and how you can access it. The manufacturer should provide a copy or a secure access link.
- Save the QMS Certificate and Registration Proof. Store copies of the QMS certificate, EUDAMED registration confirmation, and EU Responsible Person details.
Red flags to watch for:
- The manufacturer refuses to provide a Declaration of Conformity.
- Documents are in a foreign language without an English translation.
- You cannot locate a specific document after the initial verification.
Use this checklist as a standard operating procedure for every new supplier and every new device model. Regulatory compliance is not a one-time check. Re-verify these points during annual audits and whenever a major design change is announced. By following these steps, you reduce your risk of importing a non-compliant device and protect your business from legal and reputational consequences.
Frequently asked questions
Do I need to verify the Notified Body certificate for Class I devices?
No, Class I devices generally do not require a Notified Body assessment, except for sterile, reusable, or measuring devices. For standard Class I devices, you verify the manufacturer's self-declaration and technical file instead.
What if the supplier’s QMS certificate is valid but the device model is not listed in the scope?
This is a critical red flag. The QMS certificate must cover the specific device type you are importing. If the model is not in the scope, the manufacturer has not demonstrated compliance for that specific product, and you should not source it.
Can I use the supplier’s Declaration of Conformity as my only proof of compliance?
No. The Declaration of Conformity is a statement by the manufacturer. You must verify the underlying evidence, such as the technical file, QMS certificate, and Notified Body assessment, to confirm the declaration is accurate.
How often should I re-verify a supplier’s MDR compliance?
You should re-verify at least annually and whenever a major design change, supplier change, or regulatory update occurs. Keep records of each verification to show due diligence.
What is the role of the EU Responsible Person in my compliance checks?
The EU Responsible Person is the manufacturer's legal representative in the EU. They are responsible for the device's conformity and can be contacted by competent authorities. You must verify their identity and registration as part of your due diligence.


