FDA 510(k): how to clear your medical device in the US

FDA 510(k) medical device clearance is the route most manufacturers use to legally place a device on the US market, and it hinges on one argument: that your device is substantially equivalent to a device already being sold legally. That single word — equivalence — decides whether your submission moves through FDA’s review in a matter of months or comes back with an Additional Information request that resets the clock. A 510(k) is not a rubber stamp and it is not a formality bolted onto product launch; it is a technical and legal argument that has to be built correctly from the predicate up.

What a 510(k) actually is

A premarket notification, commonly called a 510(k) after Section 510(k) of the Federal Food, Drug, and Cosmetic Act, is the submission a manufacturer files with FDA to demonstrate that a device is as safe and effective as — substantially equivalent to — a legally marketed predicate device that does not require premarket approval (PMA). The procedural requirements sit in 21 CFR Part 807, Subpart E, which sets out when a submission is required (§ 807.81), what must be included (§ 807.87), the required format (§ 807.90) and how FDA acts on it (§ 807.100). Most manufacturers required to register their establishment under Part 807 must also submit a 510(k) at least 90 days before introducing the device into commercial distribution, unless a specific exemption applies.

Substantial equivalence, under FDA’s own framework, means the device has the same intended use as the predicate and either the same technological characteristics, or different technological characteristics that do not raise different questions of safety and effectiveness — provided the performance data submitted demonstrates the device is as safe and effective as the predicate. It does not mean identical. It means the differences, if any, do not introduce new questions FDA has to resolve from scratch.

Which devices need one

Device classification drives the pathway. Class I devices are largely exempt from 510(k) in practice, though not automatically — exemption status has to be verified against the specific product code, not assumed from the class alone. Class II is where the 510(k) does most of its work: it is the standard premarket pathway for the majority of Class II device types, alongside device-specific exemptions that also need to be checked individually. Class III devices, which sustain or support life, are implanted, or present a potential unreasonable risk, generally require Premarket Approval (PMA) rather than a 510(k) — with a narrowing set of legacy exceptions still working through 510(k). In our experience, the single most common strategic error we see from manufacturers arriving from outside the US is treating device classification as self-evident from how the product is classified in the EU under the MDR. It rarely maps cleanly, and getting the US product code wrong early cascades into every decision that follows — predicate search, testing scope, even which submission type applies.

The three types of 510(k), and when each one applies

Not every 510(k) is built the same way, and choosing the wrong type is a common source of avoidable delay.

The Traditional 510(k) is the default and the most heavily used pathway. It requires a full substantial equivalence comparison against the predicate, complete performance data, and the most comprehensive documentation package of the three. Use it when the device is genuinely new to your company’s portfolio, the predicate relationship is not a simple modification, or the device does not cleanly qualify for either of the other two routes.

The Special 510(k) exists for a narrower case: a manufacturer modifying its own already-cleared device, where the change can be evaluated using the manufacturer’s own design control procedures under 21 CFR Part 820. It is the fastest of the three routes, but it is only available when the modification does not alter the fundamental scientific technology of the device and the existing risk analysis and verification/validation methods can support the change. A manufacturer discovering mid-review that its “minor modification” is not eligible for Special 510(k) treatment loses time it did not need to lose.

The Abbreviated 510(k) relies on FDA guidance documents, special controls, or recognized consensus standards instead of a full head-to-head predicate comparison. Instead of reproducing extensive predicate data, the submitter provides summary reports and declarations of conformity to recognized standards. It works well for device types where FDA has already published clear special controls or a device-specific guidance document, and it can meaningfully shorten what has to be written and reviewed — but only if the device genuinely fits within the guidance’s scope.

Picking among the three is a strategic decision, not an administrative one. Get it wrong and FDA does not gently redirect you; it stops the clock and asks you to justify the choice, or rejects the submission at acceptance review before substantive review even starts.

Refuse to Accept: where most avoidable delay happens

Before FDA reviewers ever evaluate whether your device is substantially equivalent, the submission goes through an acceptance review against the Refuse to Accept (RTA) checklist. This is a binary administrative-completeness gate, not a scientific judgment: FDA checks the submission against the applicable checklist — Traditional, Abbreviated or Special each has its own — covering administrative information, device description, the substantial equivalence discussion, proposed labeling, and, where relevant, sterilization, shelf-life, biocompatibility, software, cybersecurity, electrical safety/EMC and performance data. FDA notifies the submitter within the first calendar days after receipt whether the submission is administratively complete or which specific elements are missing.

Is this a technicality or a real risk? It is both, and that is exactly the problem. A submission bounced at RTA has not failed on the merits — it has failed on completeness, often over something as mechanical as a missing labeling section or an incomplete substantial equivalence table. But the practical effect is identical to a substantive rejection: the review clock has not started, and the manufacturer is back at the start of the queue. We have seen manufacturers with genuinely strong technical files lose months to RTA issues that had nothing to do with whether their device actually worked.

Timelines and user fees

FDA’s stated performance goal under the current Medical Device User Fee Amendments (MDUFA) framework is to reach a decision on the large majority of Traditional 510(k) submissions within roughly 90 FDA days — calendar days net of any time the submission sits on hold while FDA waits for an Additional Information response. That clock-stopping mechanic matters more than the headline number: every Additional Information request pauses the countdown, so a submission that generates two or three rounds of FDA questions can take substantially longer in real time than the stated goal suggests, even though the “FDA days” figure looks compliant on paper. Special 510(k)s are reviewed on a materially shorter track; Abbreviated 510(k)s sit closer to Traditional in practice, depending on how much the guidance-based summary approach actually reduces review burden for that device type.

Submissions are also subject to a Medical Device User Fee, reassessed annually by FDA, with a reduced fee available to businesses that qualify through FDA’s Small Business Determination (SBD) program. Qualification has its own filing deadline ahead of the fiscal year it applies to, and missing that window means paying the standard fee regardless of company size — a detail that catches manufacturers who assume small-business status is automatic.

No predicate? The De Novo pathway

Not every innovative device has a fair predicate to point to, and forcing an equivalence argument onto a device that is not truly equivalent to anything on the market is a losing strategy. For low-to-moderate-risk devices with no legally marketed predicate, FDA’s De Novo classification request lets the agency evaluate the device on its own merits rather than by comparison. If FDA agrees that general and special controls are sufficient to reasonably assure safety and effectiveness, it grants the De Novo request and creates a new device classification and product code — which then becomes a predicate that later devices, including your own next generation, can cite in a standard 510(k). A De Novo request can be filed directly, or after FDA issues a Not Substantially Equivalent (NSE) decision on a prior 510(k) attempt. Recognizing early that De Novo, not a forced 510(k), is the right pathway saves a manufacturer an entire review cycle it did not need to spend.

Practical checklist before you file

  • Confirm the device classification and product code against FDA’s own classification database — not against the EU MDR classification, which does not map directly.
  • Identify and justify one or more predicates that share intended use and, where technology differs, show the difference raises no new safety or effectiveness questions.
  • Decide the submission type — Traditional, Special or Abbreviated — based on what the modification and available guidance actually support, not on which is fastest to write.
  • Run the submission against the applicable RTA checklist before filing, section by section, including labeling, biocompatibility, software and cybersecurity where relevant.
  • Build the substantial equivalence comparison as a structured, side-by-side technical argument, not a narrative summary.
  • Confirm Small Business Determination eligibility and file it ahead of the FDA deadline if it applies to you.
  • Plan for at least one round of Additional Information requests in your commercial timeline — and have the technical team ready to respond inside FDA’s response window.

How ASC Services gets your device cleared

Knowing what FDA requires is the easy part; it is published. What decides whether a 510(k) clears on the first cycle or drags through two or three rounds of Additional Information is the work behind it — and that is where we operate. We run the predicate search and build the equivalence strategy before a single test is commissioned, so the technical program is built around a defensible comparison rather than retrofitted to one. We run a gap analysis of your existing technical file against what the chosen predicate and submission type demand, so testing gaps surface before FDA finds them. We prepare the full submission package — device description, substantial equivalence comparison, labeling, performance data — screened against the same RTA checklist FDA itself uses, and we draft the response when FDA comes back with questions, because how that response is framed often determines whether it closes the issue or opens a second one.

Every submission we prepare is validated and signed off by a qualified ASC regulatory professional before it goes to FDA — not generated and shipped by a tool with no one accountable for it. That is the same standard we apply across two decades and hundreds of approved regulatory dossiers on both sides of the Atlantic: for manufacturers already navigating the EU technical file requirements under the MDR, our guide on why notified bodies reject MDR technical documentation covers the equivalent pressure points on the European side. If you are preparing to bring a device to the US market, talk to us through our contact page, or see the full scope of what we handle for regulated manufacturers on our consultancy services page.

Frequently Asked Questions

How long does FDA 510(k) clearance actually take?

FDA’s stated performance goal for a Traditional 510(k) is a decision within roughly 90 FDA days, but that clock stops every time FDA places the submission on hold for an Additional Information request. A clean submission with no Additional Information rounds can land close to the goal; a submission that generates two or three rounds of questions can run well beyond it in real calendar time, even though it stays within the technical FDA-days goal.

Can I use a predicate device that is not exactly like mine?

Yes — substantial equivalence does not require an identical device. It requires the same intended use and either matching technological characteristics or differences that do not raise new questions of safety and effectiveness, supported by data. A predicate chosen for commercial similarity rather than genuine regulatory alignment is one of the most common reasons submissions stall.

What happens if my 510(k) gets a Refuse to Accept notice?

The submission is administratively incomplete against the applicable RTA checklist and has not entered substantive review. FDA identifies the missing elements; you correct and resubmit. The review clock has not started, so an RTA bounce, while not a rejection on the merits, still costs real time.

What if there is no predicate for my device at all?

That is exactly the case the De Novo classification pathway exists for: FDA evaluates the device on its own merits rather than by comparison, and a successful request creates a new device classification that later submissions, including your own, can then use as a predicate.

AI-generated regulatory files: who validates and signs them (FDA + EU AI Act)

Artificial intelligence can now draft a medical device technical file, a cosmetic safety report or a declaration of conformity in minutes. Under deadline pressure, that speed feels like a gift. But it has quietly changed the question a regulator asks when the file lands on their desk. It is no longer “did you use AI?” — almost everyone does. It is “who reviewed this, and whose name is on it?”

That shift is not theoretical. In 2026 the US FDA issued a warning to a cosmetics laboratory that had relied on AI-generated documentation without meaningful human review. In the European Union, the EU AI Act (Regulation (EU) 2024/1689) turns the same expectation into law: its Article 14 requires effective human oversight of high-risk AI systems — a person who understands the output, can question it, and can override it. On both sides of the Atlantic the direction is identical, and it is only tightening.

The regulator’s question has changed

For years the compliance conversation was about whether a document existed: was there a technical file, a CPSR, a declaration of conformity? Now that AI can produce a plausible version of any of them on demand, the mere existence of the document proves very little. What an inspector wants to know is whether a qualified person stands behind it — because that person is who answers when something is wrong.

This is the single most important thing to understand about AI in regulatory work: the risk was never the technology. The risk is delivering what the technology produces without a professional validating it and signing for it.

What the FDA case actually tells us

The detail that matters in the FDA action is not that AI was used. It is that the output reached a regulatory context without a human who could vouch for it. Regulators are not banning AI; they are refusing to accept unaccountable AI. A submission that is fast but unverified is worse than a slow one, because it carries the appearance of rigour without the substance — and appearances are exactly what an inspection strips away.

Expect the pattern to spread. As more companies lean on generative tools for regulatory content, authorities are learning to look for the fingerprints of unreviewed AI: confident language around claims that do not hold, references that cannot be traced, and gaps where a specific requirement should be.

What the EU AI Act requires: oversight, not a rubber stamp

Article 14 of the EU AI Act sets out human oversight for high-risk AI systems. In plain terms, a person must be able to understand what the system produced, judge whether it is correct, and intervene or stop it — not simply click “accept”. “A human glanced at it” is not oversight. “A qualified professional validated it and takes responsibility for it” is.

Even where a specific regulatory task falls outside the Act’s high-risk list, the principle has already reset expectations across the sector. And it converges with a professional obligation that predates any AI law: the person who signs a regulatory document answers for it. The EU AI Act simply makes the absence of that person visible and, increasingly, unacceptable.

Where unreviewed AI output actually fails

In the files we review, the failure modes of AI-generated regulatory content are consistent:

  • Citations that do not exist. A regulation number, an article or a standard that reads perfectly but corresponds to nothing real — or that has been superseded.
  • Out-of-date limits. A migration limit, a permitted concentration or a classification taken from a version of the rule that no longer applies.
  • Silently dropped requirements. A test, an annex or a labelling element the model simply did not include, so the gap is invisible unless someone checks against the source.
  • Fabricated confidence. Conclusions stated as certain (“this product complies”) that the underlying evidence does not support.

None of these is exotic. Every one is exactly what an inspector, a notified body or a customs authority is trained to find — and exactly what a qualified reviewer catches before it leaves the building.

What “validated and signed” means in practice

At ASC Services we work the opposite way round to a self-service tool:

  • AI prepares the dossier: faster, and covering everything.
  • A qualified regulatory technician reviews every claim against the primary source — the regulation, the standard, the test report.
  • An adversarial check hunts specifically for the failure modes above: the hallucinated citation, the outdated limit, the missing requirement.
  • The technician validates the file and signs it in their own name, with full traceability of what backs each claim.

Our process is built to the EU AI Act and to EN 18286:2026, the European quality-management standard for AI published in 2026 — not yet cited in the Official Journal as a harmonised standard, so it does not yet confer an automatic presumption of conformity; we build to it as good practice, never as a claim of certification. The point is not the technology on the inside. It is the accountable professional on the outside.

Tool versus operated service: who carries the liability

Read the terms of the cheap regulatory-AI tools. Almost all of them make you accept, in the small print, that the responsibility for what you submit is yours. They automate a notification or generate a document; they do not take on the file, and they do not sign it. If the AEMPS, the FDA or customs stops your product, you are alone with an output no one validated.

The laboratory the FDA sanctioned had the tool. What it lacked was someone to validate and sign. That is the whole difference between a tool and a service: when the inspection comes, one leaves you holding the file, and the other answers for it with you.

How to tell a validated service from a wrapper

If you are evaluating an AI-assisted regulatory provider, four questions separate a real service from a thin wrapper around a language model:

  • Does a named, qualified professional sign the deliverable — or only “the platform”?
  • Who responds if an authority challenges the file: them, or you?
  • Can they show the traceability — which source backs each claim?
  • Does their contract accept responsibility, or transfer it to you?

If the answers point back to you, you have bought a tool, not compliance.

It applies to every regulated product

The same logic runs through every sector we work in: an MDR technical file for a medical device, a Cosmetic Product Safety Report, a food-contact declaration of conformity, a safety data sheet. AI can accelerate all of them; none of them should reach an authority without a qualified person validating and signing. The higher the regulatory stakes, the more the signature matters.

Frequently asked questions

Does the EU AI Act ban AI in regulatory work? No. Article 14 requires effective human oversight of high-risk AI systems — a person who understands the output and can intervene. AI plus a qualified human who validates and signs is exactly what it asks for.

Is a signed regulatory file just a formality? No. The signature is who answers for the file in an inspection. “An AI generated it” is not a defence; “a qualified technician validated and signed it” is.

Will using AI make my submission look weaker to a regulator? Not if a professional validates and signs it. What weakens a submission is unreviewed content — inconsistencies and unsupported claims that signal no one checked.

How ASC Services helps

We produce your regulatory documentation with AI, and a qualified technician validates and signs every output — for the EU (AEMPS, EU AI Act) and for the US (FDA). Twenty years and hundreds of approved dossiers, none that you have to answer for alone. Whether it is an MDR technical file, a cosmetic safety report, or regulatory affairs run with AI, we make the speed of AI safe to submit. Talk to our team through our contact page.

EUDAMED importer registration in Spain: how to get your SRN under the MDR

If you import medical devices into the EU through Spain, registering as an economic operator in EUDAMED is not administrative paperwork you can leave until later. Under the Medical Devices Regulation (EU) 2017/745 (MDR), it is a legal precondition before any device you handle reaches the market, and it produces a Single Registration Number (SRN) that identifies you across the entire EU system. This guide covers what you submit, how the AEMPS validates it, what it costs, the mistakes that delay it, and why the SRN is not the same as the Spanish import licence.

Who has to register — and why the importer specifically

Under Article 13 of the MDR an importer is an EU-established economic operator that places a device from a third country on the EU market. Article 31 then requires manufacturers, authorised representatives and importers to register in EUDAMED’s actor module before the device is placed on the market.

The reason the importer is named explicitly is structural. When the manufacturer sits outside the Union, the importer is one of the first operators the regulation can hold accountable inside the EU — the entity an authority contacts, the name that keeps the supply chain traceable. Registration is per legal entity, not per device or per shipment: you register once as an operator, and that identity then attaches to everything you import.

What you actually submit: Annex VI, Part A

Registration runs through the electronic system for economic operators set up under Article 30. The information you provide is listed in Annex VI, Part A, and in practice it covers:

  • the legal entity: name, registered trade name and full address;
  • the type of economic operator (here, importer) and the range of devices concerned;
  • the contact details of the person responsible;
  • the identification of your Person Responsible for Regulatory Compliance (PRRC).

The data has to be consistent with your other records — company registry, tax identifier, the details the manufacturer holds about you. Inconsistencies here are the single most common reason a registration is bounced back for correction.

The SRN: one number for the whole EU

Once the competent authority verifies the data (Article 31(2)), the system issues and assigns you a Single Registration Number. In Spain, the authority that validates the actor registration is the AEMPS. From that point the SRN identifies you in every EUDAMED module, in your dealings with notified bodies, and along the supply chain. It is not a formality you file and forget: it becomes your regulatory identity in the system.

The PRRC: the role behind the registration

The MDR requires economic operators to have a Person Responsible for Regulatory Compliance — someone with the qualifications and authority to ensure conformity, oversee vigilance and keep documentation in order. For a small importer, the PRRC can be someone within the company or engaged externally, but the role is real: it is the person an authority expects to reach when there is a regulatory question. Naming a PRRC who does not actually perform the function is a weakness an inspection will find.

Step by step

  1. Create an EU Login account — the Commission’s authentication used across EUDAMED.
  2. In the actor registration module, submit the Annex VI Part A data for your legal entity and declare your role as importer.
  3. Identify your PRRC and record their details.
  4. Submit the request; the AEMPS reviews and validates it.
  5. On validation, the SRN is issued. Keep it: you quote it in every later EUDAMED action and along the supply chain.

How long it takes, and what it costs

The EUDAMED actor registration itself carries no fee, and the SRN does not expire. What determines the timeline is the quality of the data you submit and the AEMPS validation queue: a clean, consistent submission is validated far faster than one the authority has to send back. And the obligation is continuous — Article 31(4) requires you to update the data within one week of any change: a new address, a change of PRRC, a change of activity or legal entity. An SRN tied to outdated data is a finding waiting to happen.

The mistakes that delay an importer registration

  • Registering the wrong legal entity — a trading name instead of the registered company, or the group parent instead of the entity that actually imports.
  • No real PRRC — a name on the form with no one performing the function.
  • Data that does not match the manufacturer’s records or the company registry.
  • Treating it as a one-off — forgetting the one-week update duty when something changes.
  • Confusing it with the Spanish licence and assuming one covers the other (see below).

EUDAMED registration is not the Spanish import licence

This is where importers most often get caught. The EUDAMED SRN is an EU-level identifier; it does not authorise your facility or your import activity in Spain. To import medical devices into Spanish territory you also need the national prior operating licence for importers, granted by the AEMPS under Real Decreto 192/2023 — a separate procedure we cover in our guide on importing medical devices into Spain. A company importing from outside the EU into Spain typically needs both: the SRN identifies the operator across the EU; the AEMPS licence authorises the activity nationally.

Where EUDAMED registration sits among your other obligations

The actor registration is the first EUDAMED step, not the last. It underpins device registration and UDI (Article 29), the vigilance and market surveillance modules, and, for the Spanish market, the AEMPS communication of commercialisation. Getting the actor registration right and keeping it current is what lets the rest of the system work; a wrong or stale SRN propagates errors into every module that references it. Your general duties as importer — verifying CE marking, the EU Declaration of Conformity, labelling and UDI — are set out in Article 13 and summarised in our guide to the importer’s obligations under the MDR.

Frequently asked questions

Is the EUDAMED SRN the same as my AEMPS import licence? No. The SRN (Article 31) is an EU-wide operator identifier; the AEMPS import licence (RD 192/2023) authorises your activity in Spain. You generally need both.

Do I need an SRN if the device already has a CE mark? Yes. CE marking is the manufacturer’s; importer registration and the SRN are your own obligations under Articles 13 and 31, independent of the device’s CE status.

One SRN per company or per device? Per legal entity. You register once as an operator; the SRN then attaches to the devices you import.

What happens if my details change? You must update EUDAMED within one week (Article 31(4)). An outdated registration is a compliance gap an inspection can act on.

How ASC Services helps

We set up and run your position as importer of record: we register you as an economic operator in EUDAMED, prepare the Annex VI data so it validates first time, obtain your SRN, support your PRRC, and coordinate the AEMPS national import licence so neither the EU nor the Spanish obligation is left half-done — with our Technical Manager validating and signing each regulatory output. Whether you import from Asia or the Americas, we make your position legally sound. Read our guide on the importer’s obligations under the MDR or talk to our team through our contact page.

Importer of medical devices under the MDR: your obligations before you place a device on the market

Buying a CE-marked medical device from outside the EU and reselling it here does not make you a passive middleman. Under the Medical Devices Regulation (EU) 2017/745 (MDR), the importer is an economic operator with its own legal obligations, set out in Article 13. If the manufacturer sits outside the EU, you are one of the first lines of defence the regulation relies on — and you carry liability. This article is the checklist of what you must verify and do before the device reaches the market, distinct from the Spanish AEMPS licensing route covered in our guide on importing medical devices into Spain.

Who is an “importer” under the MDR

An importer is any natural or legal person established in the EU that places a device from a third country on the EU market. The key word is places on the market: the moment a device from outside the Union is first made available here, an EU-established importer must be behind it. This is different from a distributor (who moves devices already on the EU market) and different from the manufacturer’s authorised representative. If your device is made outside the EU, someone has to be the importer of record — and that role has non-delegable duties.

What you must verify before importing (Article 13)

Before placing the device on the market, the importer must verify that:

  • The device bears the CE marking and the manufacturer has drawn up the EU Declaration of Conformity.
  • The manufacturer is identified and, being outside the EU, has designated an authorised representative under Article 11.
  • The device is labelled in accordance with the MDR and accompanied by the instructions for use, in the language(s) required by the Member State.
  • Where applicable, the manufacturer has assigned a Basic UDI-DI and UDI.

If you believe, or have reason to believe, that the device is not in conformity, you must not place it on the market until it is brought into conformity — and you must inform the manufacturer and, for a device presenting a risk, the competent authority.

What you must do once you are importing

  • Add your details: indicate your name, registered trade name and address on the device, its packaging or an accompanying document.
  • Register in EUDAMED: importers register to obtain a Single Registration Number (SRN) and are recorded against the devices they import, so the supply chain is traceable.
  • Storage and transport: ensure conditions do not jeopardise conformity with the general safety and performance requirements (Annex I).
  • Complaints and vigilance: keep a register of complaints, non-conforming devices, recalls and withdrawals, forward this information to the manufacturer and authorised representative, and cooperate on corrective actions.
  • Records: keep a copy of the EU Declaration of Conformity and, where relevant, the certificate, available for the competent authorities.

Frequently asked questions

The device already has a CE mark. Is that enough for me to sell it?

No. CE marking is a manufacturer obligation; as importer you have your own verification and registration duties under Article 13. A CE mark that is present but unsupported by a valid Declaration of Conformity or a designated authorised representative does not make you compliant.

Can the manufacturer’s EU authorised representative act as importer?

They are separate roles with separate duties. One entity can, in some structures, hold more than one role, but the obligations of each role still apply in full and must be documented as such.

How ASC Services helps

We set up and run the importer role for you under the MDR: we verify CE marking, the EU Declaration of Conformity and the manufacturer’s authorised representative, check labelling, IFU and UDI, register you as importer in EUDAMED and obtain your SRN, and put in place the complaints, vigilance and record-keeping system Article 13 requires. Whether you import from Asia or the Americas, we make sure your position as importer of record is legally sound. Talk to us through our contact page or explore our consultancy services.

MDR technical documentation: why notified bodies reject it

In our experience, most MDR technical documentation is not rejected because the device is unsafe. It is rejected because the file cannot prove that it is safe. A notified body reviewer never meets your product on the bench; they meet your Annex II documentation, and if that file has gaps, the CE certificate stops there, no matter how good the device actually is. That gap between «our device works» and «our file demonstrates it works» is where we spend most of our time with manufacturers, and it is worth understanding before you submit rather than after the first deficiency letter arrives.

What the notified body is actually reading

The technical documentation is not a folder you assemble to taste. Annexes II and III of Regulation (EU) 2017/745 fix its contents: device description and variants, the information the design and manufacturing rely on, the general safety and performance requirements, the benefit-risk analysis and risk management, the verification and validation results including the clinical evaluation, and the post-market surveillance file that Annex III demands. Under the Article 52 conformity assessment route, the reviewer works down that structure as a checklist. Every item that is missing, vague or unsupported is not a stylistic quibble; it becomes a formal nonconformity, and each nonconformity turns into a question that adds a review cycle. The manufacturers who clear assessment fastest are rarely the ones with the best devices. They are the ones whose file answers the checklist before it is asked.

The GSPR checklist that says «not applicable» too often

The general safety and performance requirements in Annex I are the backbone of the whole submission, and they are where we see files fall apart first. Each requirement has to be addressed one by one: is it applicable, by what method is it met, and what is the evidence, the harmonised standard or the common specification that proves it. The recurring failure is a GSPR checklist peppered with «N/A» and no justification, or a column that cites a standard without showing the test report behind it. A reviewer reads an unjustified «not applicable» as «not considered». The question you should ask of your own file is blunt: for every single requirement, could a stranger find the evidence from the checklist alone, without emailing your R&D team?

A clinical evaluation that asserts instead of demonstrating

Clinical evaluation under Article 61 and Annex XIV is the second great rejection zone, and the MDR raised the bar sharply from the old directives. Equivalence, the route many manufacturers still lean on, now requires technical, biological and clinical equivalence and, in practice, contractual access to the equivalent device’s own data, which a competitor will almost never grant. We have watched files built entirely on an equivalence claim collapse on that single point. The literature route, done properly, means a documented search protocol, appraisal criteria and an honest treatment of the evidence that goes against you, not a bibliography stapled to the back. If your clinical evaluation report asserts a conclusion the underlying data does not carry, the notified body will find the gap; that is precisely what the guidance in the MDCG documents trains them to look for.

Post-market surveillance treated as an afterthought

Annex III is where a surprising number of otherwise solid files come undone, because manufacturers write it last and write it thin. The post-market surveillance plan, the post-market clinical follow-up under Annex XIV Part B, and the reporting cadence set by Article 86 all have to be in the documentation as a live system, not a promise. Reviewers now open the PMS section early precisely because an empty PMCF plan is a fast signal that the rest of the file may be aspirational too. A PMS plan that merely says the company «will monitor complaints» tells the reviewer nothing about how, against what indicators, or with what trigger for action.

Why non-EU manufacturers get caught out

If your dossier was built for the FDA 510(k) or a Chinese NMPA submission, it is not MDR technical documentation, and reusing it wholesale is one of the most expensive assumptions we correct. The structures do not map: the MDR is built on the GSPR, not on special controls or predicate devices, the risk and clinical expectations differ, and a manufacturer outside the Union also needs an EU authorised representative named under Article 11 before any of it reaches a notified body. Reformatting a US file into Annex II order is not enough; the evidence itself often has to be regenerated to answer European requirements. This is the point where a manufacturer entering the EU market benefits most from a review before submission rather than after. You can see how we handle that entry through the EU authorised representative role, and it pairs with what the importer must verify once the device is on the market.

How long does a notified body take to review technical documentation?

Longer than anyone plans for, and every deficiency letter adds a full cycle on top. The review time you cannot control; the completeness of the file you submit, you can. In practice the single most effective way to shorten the calendar is to close the gaps above before the first submission, because a clean file moves and a file full of «not applicable» stalls. That is the review we do at ASC Services: we read your technical documentation against Annexes I, II, III and XIV the way a notified body will, flag what it cannot yet prove, and tell you what to fix before you file. Tell us about your device and where you are in the process through our contact page, or see the rest of our work in advisory services and our news section.

La FDA inicia un nuevo modelo de inspecciones para dispositivos médicos: qué deben revisar las empresas que comercializan en EE. UU.

La FDA ha anunciado que, a partir del 2 de febrero de 2026, comenzará a aplicar un proceso de inspección completamente actualizado para fabricantes de productos sanitarios que operan en el mercado estadounidense. Este cambio se enmarca en la entrada en vigor del Quality Management System Regulation (QMSR), la norma que sustituye al histórico 21 CFR 820 y que transforma la manera en que la autoridad evalúa los sistemas de calidad de los fabricantes.

Según la notificación oficial enviada por la FDA a los operadores internacionales, las inspecciones dejarán de realizarse bajo la antigua metodología QSIT (Quality System Inspection Technique) y pasarán a ejecutarse conforme al nuevo programa Inspection of Medical Device Manufacturers – Compliance Program CP 7382.850, diseñado para alinearse con el QMSR y con las prácticas regulatorias de otras autoridades globales Bandeja de entrada _ javiervela….

Este cambio tiene implicaciones directas para cualquier empresa que exporte productos sanitarios a Estados Unidos, independientemente de que su sistema de calidad esté basado en ISO 13485. La FDA ha sido clara al indicar que no utilizará los programas de inspección previos (CP 7382.845 y CP 7383.001) a partir de la fecha de aplicación.

Un sistema más cercano a ISO 13485, pero no equivalente

La reforma del 21 CFR 820 busca armonizar los requisitos estadounidenses con la estructura y los principios de la norma internacional ISO 13485, utilizada por la mayor parte del sector fuera de EE. UU. No obstante, la adopción del QMSR no supone una equivalencia completa. Aunque la FDA incorpora por referencia numerosos apartados de ISO 13485, mantiene exigencias propias en aspectos como:

  • Gestión de registros y evidencias asociadas a cada proceso.
  • Documentación específica del diseño y justificación del uso previsto.
  • Requisitos sobre validación de procesos, incluidos procesos informatizados.
  • Expectativas en torno al control de cambios, citadas de forma más estricta que en ISO 13485.
  • Interacción con la normativa estadounidense sobre notificaciones, informes y cumplimiento postcomercialización.

Por tanto, disponer de un sistema de gestión de calidad certificado conforme a ISO 13485 no garantiza, por sí solo, superar una inspección bajo QMSR. La FDA verificará la integración efectiva de estos principios, así como la coherencia entre la documentación técnica, el diseño del producto, las actividades de control de producción y los registros regulatorios mantenidos en Estados Unidos.

Cómo cambian las inspecciones

Las inspecciones bajo el nuevo QMSR tendrán un enfoque más transversal y alineado con la evaluación del ciclo de vida del producto. Se espera que:

  • El inspector solicite trazabilidad de procesos clave, desde el diseño hasta el mercado.
  • Se analicen con más detalle las decisiones técnicas justificadas durante el desarrollo.
  • Se revisen los procedimientos de gestión de riesgos como eje central del sistema.
  • Se evalúe la consistencia entre los procesos internos y la documentación remitida a la FDA.
  • Se verifique la capacidad del fabricante para mantener el control continuo del producto comercializado.

La desaparición de QSIT implica que las inspecciones serán menos esquemáticas y más centradas en la interpretación técnica del sistema de calidad del fabricante, lo que exige una preparación sólida y un alineamiento documental previo.

Qué deben revisar las empresas que exportan a EE. UU.

Ante este nuevo entorno regulatorio, los fabricantes deberían evaluar:

  • La correspondencia entre su sistema ISO 13485 y los requisitos específicos del QMSR.
  • La estructura documental del diseño y el uso previsto del dispositivo.
  • Los registros de fabricación, control de cambios y validación de procesos.
  • La adecuación de los procedimientos de vigilancia poscomercialización.
  • La coherencia entre su documentación técnica y las expectativas particulares de la FDA.

Las empresas que comercializan en Estados Unidos, especialmente aquellas que no se han enfrentado antes a una inspección de la FDA, deben revisar con detalle la forma en que su sistema de calidad demuestra la seguridad, eficacia y consistencia del dispositivo conforme a los criterios nacionales de dicho país.

Asistencia para empresas que comercializan en EE. UU.

ASC Services ofrece apoyo técnico a fabricantes internacionales que necesitan verificar el grado de conformidad de su sistema de calidad frente a los nuevos requisitos de la FDA. Realizamos análisis comparativos entre ISO 13485 y QMSR, revisión de documentación técnica, preparación para inspecciones y adecuación de procedimientos internos para que el fabricante pueda afrontar con seguridad cualquier auditoría bajo el programa actualizado de cumplimiento.

Puede solicitar información o una revisión preliminar escribiendo a web@ascservices.es. Estamos disponibles para apoyar a empresas que operan en Estados Unidos y que desean asegurarse de que cumplen plenamente con las expectativas regulatorias de la FDA tras la implantación del nuevo QMSR.